Privacy Policy
Effective date: September 27, 2026
The revised Privacy Policy takes effect on September 27, 2026. Until then, the current policy applies. View the current policy
Article 1 (Purpose of Processing Personal Information)
Xakar (the “Company”) processes personal information for the following purposes. The personal information processed will not be used for any purpose other than those listed below, and if the purpose changes, prior consent will be obtained.
- User registration and identity verification
- Provision of the Service and operation of content packaging features
- Credit payments and transaction history management
- Customer inquiry response and dispute handling
- Service improvement and statistical analysis
Legal bases for processing (European Economic Area users) — for users in the EEA, the Company processes personal information on the following bases under Article 6 of the GDPR.
- Registration and identity verification, provision of the Service, credit payments — performance of a contract (Art. 6(1)(b))
- Statutory retention of payment and transaction records — compliance with a legal obligation (Art. 6(1)(c))
- Responding to inquiries, service improvement and statistics, security through access logs — legitimate interests (Art. 6(1)(f))
Article 2 (Items of Personal Information Collected)
Required items
- Email address (for registration and identity verification)
- Service usage records (packaging history and credit transaction records)
- Access IP, browser information, and access date/time
Items collected at payment
- Payment method information (processed by the card company or payment provider; not directly stored by the Company)
- Payment amount and transaction date/time
Automatically collected items
- Cookie and session information (to maintain authentication status)
An email address is required to enter into the contract and to provide the Service. If it is not provided, registration and use of the Service are not possible. The remaining items are generated automatically while using the Service or are collected only at payment.
Article 3 (Retention and Use Period of Personal Information)
Personal information is retained and used until membership withdrawal. However, when a certain retention period is required under applicable laws, the information is stored separately for the following periods.
- Records on contracts and withdrawal of subscription: 5 years (Electronic Commerce Act)
- Records on payment and supply of goods/services: 5 years (Electronic Commerce Act)
- Records on consumer complaints and dispute handling: 3 years (Electronic Commerce Act)
- Login records: 3 months (Protection of Communications Secrets Act)
- Learning records: completion outcomes (completed / passed / failed) and each learner's latest progress are retained until the service agreement ends; other learning activity records (playback, pause, etc.) for 24–36 months depending on plan
Article 4 (Provision of Personal Information to Third Parties)
The Company does not, in principle, provide users' personal information to third parties. However, the following cases are exceptions.
- Where the user has given prior consent
- Where required by law or upon a lawful request from an investigative authority
Article 5 (Outsourcing of Personal Information Processing)
The Company entrusts the following personal information processing tasks for the operation of the Service.
- Supabase Inc. — user authentication and database operation
- Vercel Inc. — service hosting and server operation
- Lemon Squeezy (Merchant of Record) — payment processing, tax calculation and remittance, and invoice issuance. Payment-related personal information (email, billing country, payment amount) is shared with Lemon Squeezy to the extent necessary for completing the transaction.
- Plus Five Five, Inc. (Resend) — delivery of inquiry notification emails. The name, email address, phone number and message entered in the contact form are included in the notification email.
Article 6 (User Rights)
Users may exercise the following rights at any time.
- Request access to personal information
- Request correction of errors in personal information
- Request deletion of personal information (membership withdrawal)
- Request suspension of personal information processing
To exercise these rights, please submit a request via our contact form or by email to support@xakar.app, and the Company will take action without delay.
Some rights can be exercised directly within the Service. Packaging history can be deleted at any time using the “Clear history” button on the My Packages screen, and membership withdrawal can be completed on the Settings screen. However, payment and credit transaction records subject to a statutory retention obligation are stored separately from other information for the periods stated in Article 3 and then destroyed.
Additional rights for European Economic Area users — in addition to the rights above, users in the EEA may exercise the following.
- Data portability — the right to receive personal information in a structured, commonly used and machine-readable format (GDPR Art. 20)
- Objection to processing — where processing is based on legitimate interests (Art. 21)
- Withdrawal of consent — withdrawal does not affect the lawfulness of processing carried out beforehand (Art. 7(3))
The Company does not carry out automated decision-making, including profiling, that produces legal effects concerning users or similarly significantly affects them (Art. 22).
Article 7 (Personal Information Related to Credit Payments and Refunds)
All payments are processed by Lemon Squeezy, which acts as the Merchant of Record. Lemon Squeezy independently handles payment processing, tax calculation, and invoice issuance. The Company does not directly store sensitive payment information such as card numbers. Credit transaction records (top-up amount, deduction history, balance) are retained for the purpose of resolving disputes related to use of the Service.
As a general rule, topped-up credits are not refundable after purchase is completed, and transaction records related to such payments are retained for the period required by law.
Article 8 (Use of Cookies)
The Service uses only essential cookies required for sign-in status maintenance and security. No marketing or analytics cookies are used. Essential cookies cannot be disabled as they are necessary for the Service to function.
Article 9 (Chief Privacy Officer)
The Company designates a person responsible for personal information protection who oversees the overall handling of personal information.
Inquiries about the processing of personal information and requests to exercise your rights may be submitted to the following.
- Controller: Xakar
- Contact: support@xakar.app
Article 10 (Processing of Learner Personal Information)
With respect to learners' personal information (completion records, learning activity records, and the like) generated on learning sites and learning content that a User operates through the Service, the Company acts as a processor, and the User who operates the site is the controller.
- The purposes and retention periods of such processing are determined by the User who operates the site, and the Company processes the information on that User's instructions.
- Learner requests for access, correction, deletion, or suspension of processing are received by the User who operates the site. If such a request is submitted directly to the Company, the Company will refer it to that User.
- The Company deletes learning records only at the request or on the instruction of the User, and does not modify or delete them on its own initiative.
- Even if a learner withdraws membership from the Company, learning records remaining on sites operated by other Users are maintained under those Users' control. To have them deleted, please contact the operator of the site concerned.
- If the User operating a site withdraws membership, the learning records of that site are deleted together with the site and its content.
Article 11 (Overseas Transfer of Personal Information)
The Company uses infrastructure operated by providers located outside Korea, and personal information is therefore transferred overseas as set out below. These transfers fall under Article 28-8(1)3 of the Personal Information Protection Act as transfers necessary for the performance of the contract and for the convenience of users, and are made without separate consent by being disclosed in this policy.
Time and method of transfer — transmitted over the network on an ongoing basis at the time the Service is used.
- Supabase Inc. (United States) — Purpose: user authentication and database operation / Items: email address, service usage records, access IP, browser information and access date/time / Retention: until account deletion or termination of the processing agreement / Contact: privacy@supabase.com
- Vercel Inc. (United States · 440 N Barranca Avenue #4133, Covina, CA 91723) — Purpose: service hosting, server operation and aggregate traffic statistics / Items: access IP, browser information, access date/time / Retention: until termination of the processing agreement / Contact: privacy@vercel.com
- Sold Through Link, LLC (f/k/a Lemon Squeezy LLC, United States · 222 South Main Street Suite 500, Salt Lake City, UT 84101) — Purpose: payment processing, tax calculation and filing, receipt issuance / Items: email address, billing country, payment amount / Retention: for the period required by applicable law / Contact: hello@lemonsqueezy.com
- Plus Five Five, Inc. (Resend, United States · 2261 Market Street #5039, San Francisco, CA 94114) — Purpose: delivery of inquiry notification emails / Items: name, email address, phone number, message / Retention: until the sending log retention period elapses or the processing agreement terminates / Contact: support@resend.com
You may refuse the overseas transfer of your personal information. However, because these transfers are essential to providing the Service, refusing them means discontinuing use of the Service by deleting your account.
Article 12 (Procedures and Methods for Destroying Personal Information)
The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved.
- Destruction procedure — personal information whose purpose has been achieved is classified for destruction and destroyed. Information that must be retained under other statutes is moved to a separate database, kept apart from other personal information for the periods stated in Article 3, and then destroyed.
- Destruction method — personal information stored as electronic files is deleted by technical means that make recovery impossible; personal information printed on paper is shredded or incinerated.
- Automatic destruction — separately stored information whose retention period has elapsed is destroyed automatically through scheduled maintenance.
Article 13 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to keep personal information secure.
- Access control — the number of staff who can access personal information is kept to a minimum, and row-level security is applied at the database level so that each user can access only their own information.
- Encryption in transit — all communication between users and the Service is encrypted with HTTPS (TLS).
- Password protection — passwords are stored using one-way hashing and cannot be decrypted; the Company cannot read the original values.
- Access logs — access records for the personal information processing system are retained, and sign-in records are kept for three months in accordance with the Protection of Communications Secrets Act.
- Separate storage — transaction records of withdrawn members that must be retained by law are stored separately from the operational database.
Article 14 (Remedies for Infringement of Rights)
If you have a concern about how your personal information is handled, please tell us first through the contact form. The Company will look into it and respond without delay.
The Company is based in the Republic of Korea and processes personal information under Korean law. The bodies below are therefore Korean; their telephone numbers can only be dialled within Korea.
- Personal Information Dispute Mediation Committee — 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Center — 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office, Cyber Investigation Division — 1301 (www.spo.go.kr)
- National Police Agency, Cyber Investigation Bureau — 182 (ecrm.police.go.kr)
If your rights or interests are infringed by a disposition or omission by the Company in response to a request under Articles 35 (access), 36 (correction or deletion) or 37 (suspension of processing) of the Personal Information Protection Act, you may request an administrative appeal as provided by the Administrative Appeals Act.
If you live outside Korea, you may in addition have the right, under the law of your own country, to lodge a complaint with your local data protection authority.
Users in the European Economic Area have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their residence, place of work or of the alleged infringement, under Article 77 of the GDPR. A list of supervisory authorities is available on the European Data Protection Board (EDPB) website.
Article 15 (Changes to This Privacy Policy)
This Policy may be revised in accordance with changes in laws or the Service. In the event of any revision, notice will be provided within the Service starting at least 7 days before the effective date.
