Privacy Policy

Effective date: 2026-06-24

This English version is provided for convenience only. The Korean version of this Privacy Policy is the official and governing text; in case of any discrepancy, the Korean version prevails.

Flux (the "Service"), operated by POSTMEDIA Co., Ltd. (the "Company"), establishes this Privacy Policy in accordance with the Personal Information Protection Act (PIPA) of the Republic of Korea to protect the personal information of its users and safeguard their related rights. The Service is an internal RAG platform in which data is processed in isolation on a per-organization basis. The Service is intended for employees and organization members aged 14 or older and is not directed at children under the age of 14.

1. Personal Information We Collect

The Service collects the following items.

Sign-up & Authentication

  • Required: email address, password (stored as a one-way hash), name
  • Optional: profile image
  • When using social login (Google): email, name, profile image, and OAuth tokens
  • When two-factor authentication is enabled: TOTP secret, backup codes (stored as one-way hashes)
  • Demo (trial) sign-up also collects email and name in the same way as a regular sign-up.

Contact Inquiry

  • When submitting a contact inquiry: name, email, company name, phone number, job title, and inquiry content, together with automatically collected data (hashed IP and User-Agent).

Automatically Collected

  • IP address (for embedded chat, stored as a one-way hash; access logs for authentication and security audit purposes are retained in original form), session tokens, browser/device information (User-Agent), access timestamps, language settings
  • Service usage records: audit logs (activity history), token usage and response times
  • Service usage behavior data: page-view paths (normalized after removing personal identifiers and search terms) and feature-usage events. By default this is aggregated anonymously (only counts aggregated by time unit are stored without identifiers); where user-level analysis is enabled, it may be collected with a pseudonymous identifier (a one-way hash of the user identifier and a session identifier).

In the Course of Using the Service

  • Documents uploaded by users, chat (chatbot) content, and message feedback
  • Embedded (third-party site) chat: anonymous session identifier, hashed IP, and hashed source of the embedding page

2. Purpose of Collection and Use

  • Member identification and authentication, login/session management, and security (2FA, anomalous-access detection)
  • Provision of services such as the RAG chatbot, document management, and agents
  • Usage/cost management and quota notifications
  • Customer support and delivery of notices/alerts
  • Service improvement and statistical analysis: understanding usage trends and improving the Service based on anonymous aggregate page-view and feature-usage events
  • Compliance with legal obligations and dispute response (audit logs)

The processing of anonymous aggregate usage-behavior data is based on the legitimate interest ground under PIPA. We perform only the minimum non-identifying aggregation necessary to achieve the purpose of service-quality improvement (necessity); we do not identify individuals and do not store raw IPs or original view-path text, thereby minimizing any infringement of user rights (balance); and we disclose in advance the fact of collection, the items, and the opt-out method through this Policy (predictability).

3. Retention and Use Period

  • Member information: until membership withdrawal. Upon withdrawal, member identifying information is destroyed without delay; however, identifying information may be de-identified and retained solely in audit logs for audit-trail purposes. Organization (employer)-owned data is governed by the organization’s management policy as set out in Section 6.
  • Demo (trial) organizations: automatically deleted 90 days after creation (DEMO_ORG_TTL_DAYS in the current deployment), together with their associated documents, search indexes, knowledge graph, and files.
  • Session information: 7 days after issuance (auto-expiry); invalidated immediately upon password reset or withdrawal.
  • Embedded chat conversations: marked inactive 30 days after last access, then permanently deleted after a further 7 days.
  • Incomplete uploads (unconfirmed files): deleted after 24 hours.
  • Contact inquiries: retained for 1 year(s) after the response is completed, then destroyed.
  • Aggregate usage-behavior statistics (page-view/event counts): automatically deleted after 90 days of retention.
  • User-level usage-behavior events (when enabled): automatically deleted after 180 days of retention (distinct from the 90-day aggregate statistics above).
  • Access logs / audit logs: retained for 3 years (in compliance with applicable laws and notifications); destroyed once the retention period elapses.
  • Where retention is required by applicable law, the information is retained for the corresponding period.

4. Procedures and Methods of Destruction

The Service destroys personal information without delay once the retention period has elapsed or the processing purpose has been achieved.

Destruction Procedure

  • When the retention period elapses or the purpose is achieved, an automated scheduler periodically selects and deletes the data to be destroyed (e.g., expired sessions, incomplete uploads, inactive embedded conversations, statistics past their retention period).
  • Information subject to a statutory retention obligation is stored separately and then destroyed once the retention period has elapsed.

Destruction Method

  • Information in electronic form is permanently erased in a manner that prevents restoration or recovery (deletion of database records and permanent removal of object-storage, vector, and graph data).
  • Upon withdrawal, the account and personal identifying information are deleted. However, shared content owned by the organization (documents, conversations, etc.) is governed by the organization’s retention policy.

5. Outsourcing and Overseas Transfer of Personal Information

A. Outsourcing to External AI Providers via Organization API Keys

Where an organization (the using party) registers an external provider’s API key to use a given feature, data entered by users (such as questions and document excerpts) may be transmitted to and processed by the providers below. Many providers operate servers overseas, so an overseas transfer of personal information may occur.

  • Large Language Models (LLM): OpenAI, Anthropic, Google, Groq, OpenRouter, Cohere, Mistral
  • Embedding & Reranking: Cohere
  • Web Search: Tavily, Serper, SerpAPI
  • Email Delivery: Resend

If only self-hosted (internal) models (e.g., Qwen3, SigLIP2) are used, the relevant data is not transmitted externally. Each external provider’s data-processing practices are governed by that provider’s own terms. Organization administrators can control which external providers are used in the settings.

In addition, when a contact inquiry is received, the inquirer’s email and name are transmitted to the email-delivery provider (Resend, United States) in order to send an automated reply to the inquirer and a notification email to the operator. Member authentication and notification emails may also be sent via the same provider.

The PIPA Article 28-8 overseas-transfer disclosures for the above external providers are as follows.

  • Items transferred: processing-request data such as the user’s questions/search queries and document excerpts (only where the organization has enabled the relevant external-provider feature)
  • Country of transfer: varies by provider, with many operating servers overseas, including the United States. The country for each provider used by an organization follows that provider’s policy.
  • Time and method of transfer: encrypted transmission (HTTPS) to each provider’s API in real time during service use
  • Recipient: the LLM, embedding, web-search, and email providers listed above
  • Recipient’s purpose and retention/use period: to perform the requested processing (response generation, search, email delivery), for the period set by each provider’s data-processing/retention policy
  • How to refuse: if an organization administrator configures the service not to use external providers (using only self-hosted models), the relevant overseas transfer does not occur.

B. Overseas Transfer for Service-Operation Analytics (Google Analytics)

For operational statistical analysis, the Service may mirror and transmit self-collected anonymous aggregate usage-behavior data to Google Analytics (GA4). This constitutes an overseas transfer under PIPA Article 28-8, and the relevant disclosures are as follows.

  • Items transferred: page-view paths and feature-usage events, IP address, page URL, device/browser information, and Google Analytics cookie-based identifiers (e.g., _ga)
  • Country of transfer: United States
  • Time and method of transfer: transmitted in real time directly from the user’s browser via Google’s analytics script (gtag.js) during service use
  • Recipient: Google LLC (Google Analytics), privacy policy: https://policies.google.com/privacy
  • Recipient’s purpose and retention/use period: analysis of service-usage statistics and service improvement, for the period set by the Google Analytics data-retention setting (up to 14 months)
  • How to refuse: block cookies in your browser, or use the Google Analytics Opt-out Add-on (https://tools.google.com/dlpage/gaoptout)

Service-operation analytics targets only anonymous aggregates that do not identify individuals; information that can directly identify a user, such as name, email, or original IP, is not transmitted to Google.

6. Rights of Data Subjects and How to Exercise Them

Under PIPA Articles 35 through 37, users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information.

  • Password change, two-factor authentication, session management: Settings → Security
  • Correction of name, profile, etc.: Settings → Account/Profile
  • Membership withdrawal (deletion of account and related data): Settings → Account
  • Refusing collection of the Service’s own anonymous aggregate usage data: organization administrators can disable analytics collection (opt-out) in the settings, and users can immediately stop it by enabling their browser’s Global Privacy Control (Sec-GPC) signal. Google Analytics (GA4) in Section 5 is a separate system operated via Google’s gtag.js; to refuse GA4 collection, please block cookies in your browser or use the Google Analytics Opt-out Add-on.
  • Other access/correction/processing-suspension requests: apply via the contact below

Procedure and Processing Timeline

  • Rights may be exercised by request to master@onflux.ai, subject to a procedure to verify that the requester is the data subject or a duly authorized agent (login-based or email-based identity verification).
  • The Service will take action within 10 days of receiving a request for access, correction, deletion, or suspension of processing, or, where it cannot do so for legitimate reasons, will notify the requester of those reasons and how to object.
  • Suspension of processing is divided into partial suspension (opt-out of usage-behavior collection) and full suspension (membership withdrawal); processing that is indispensable for providing the Service may be partially restricted in accordance with the law.

However, data owned and managed by the organization (employer) — such as shared documents and intra-organization conversations — cannot be deleted by an individual alone, pursuant to the proviso of PIPA Article 36(1) and related provisions, and is governed by the organization’s management policy.

7. Automated Decision-Making

Responses generated by the Service’s RAG chatbot and agents are assistive tools premised on review and use by the user; they do not, in themselves, constitute a fully automated decision under PIPA Article 37-2 that produces legal effects on or similarly significantly affects the data subject. Responsibility for verifying the accuracy of generated responses is as provided in the Terms of Service.

Automated processing such as anomalous-access detection and request-rate limiting for security purposes is intended to protect the Service, and measures that may significantly affect a user, such as account suspension, are carried out following administrator review. If we introduce a feature that constitutes a fully automated decision in the future, we will disclose its criteria and the data subject’s right to refuse and to request an explanation in advance.

8. Measures to Ensure the Security of Personal Information

  • One-way encryption of passwords; AES-256-GCM encrypted storage of external LLM/search API keys
  • Encryption in transit (HTTPS) and application of security headers
  • Per-organization access control and data isolation: an application-level organization filter is the primary security boundary, with database row-level security (RLS) selectively applied to core data
  • Support for two-factor authentication (TOTP) and audit logging
  • One-way hashing of embedded (third-party) chat IPs. Access-log IPs for authentication and security-audit purposes are retained in original form to trace unauthorized access, but are protected through access-permission controls and retention-period limits.
  • Establishment of an internal management plan and regular security reviews

9. Cookies and Other Automatic Collection Devices

The Service uses essential cookies (session tokens) to maintain login sessions. These cookies are essential to providing the Service, and login functions cannot be used if they are refused. The Service also uses Google Analytics (GA4) analytics cookies (e.g., _ga) for usage statistics (see Section 5). We do not use cookies for advertising or retargeting purposes.

Among usage-behavior analyses for service improvement, our self-collection is by default performed as an anonymous aggregate that does not identify users, without cookies or tracking identifiers (storing page-view/event counts aggregated by time unit), and we do not place any separate advertising analytics cookie. However, where user-level analysis is enabled, events may be collected with a pseudonymous identifier (a one-way hash of the user identifier and a session identifier); even then, directly identifying information such as name, email, or original IP is not stored for analytics purposes.

The Google Analytics (GA4) described in Section 5 is collected and transmitted directly from the user’s browser via Google’s gtag.js; in this process Google sets analytics cookies (e.g., _ga), and information such as IP address, page URL, and device/browser details is transmitted to Google (see Section 5 for the overseas-transfer disclosure).

10. Personal Information Protection Officer and Operator

The operator of the Service and the Personal Information Protection Officer who oversees personal-information processing and handles complaints and remedies for data subjects are as follows.

  • Operator (Company): POSTMEDIA Co., Ltd.
  • Representative: Seungmo Hong
  • Business Registration No.: 120-81-27660
  • Address: 174-10 Jagok-ro, Gangnam-gu, Seoul, Republic of Korea
  • Personal Information Protection Officer: Hyuncheol Lim / General Manager
  • Department: AI Lab
  • Contact: master@onflux.ai

Reports and consultations regarding infringement of personal information may be directed to the Personal Information Dispute Mediation Committee (1833-6972), the Privacy Infringement Report Center (118), the Supreme Prosecutors’ Office (1301), or the National Police Agency (182).

11. Duty to Notify

If this Policy is changed, we will provide notice of the changes and the effective date within the Service at least 7 days before the effective date. Changes that materially affect data subjects’ rights (such as to collected items, purpose of use, retention period, or outsourcing/overseas-transfer recipients) will be notified 30 days before the effective date and, where feasible, communicated individually via email or similar means.