Privacy Policy
This is an English translation provided for convenience. The Korean version is the legally binding text. If the two differ, the Korean version prevails.
Effective: 2026-08-20 · Last updated: 2026-09-07 · Related: Terms of Service and investment disclosure · 한국어
Notice of change (2026-09-07): We clarified the deletion steps when a member leaves, to match how deletion actually works (Articles 3 and 8). The items collected, the purposes of use and the retention periods did not change.
Confluence Zone (the "Service") complies with the Personal Information Protection Act of Korea and other applicable laws,
and collects and uses your personal information only to the minimum extent necessary.
This policy explains what information is collected and why, and how it is kept and destroyed.
The Korean text of this policy is the authoritative version. Translations are provided for
convenience only. If a translation differs from the Korean text, the Korean text prevails.
Article 1 (Personal information collected and how)
- Guests (not signed in): No personal information is collected on our servers.
Watchlists and display settings are stored only in your browser (localStorage) and are not sent to the server.
- Members (social sign-in): The member identifier and nickname (profile name) passed to us by the
sign-in provider (Google, Kakao or Naver). This is limited to the items you agreed to on the provider's screen.
The Service does not ask for contact details or profile photos.
If you link several social accounts to one account, the member identifier from each provider is kept together.
- Email address (optional): Collected only when you enter it yourself and agree on My Page.
If you turn on email delivery, it is used to receive alert emails when conditions are met.
You can delete (destroy) it on My Page at any time. Not entering it does not limit your use of the Service.
- The temporary (nickname) sign-in from the earlier beta period was discontinued in August 2026, when social sign-in
officially replaced it. Information collected through temporary sign-in (nickname) is also destroyed immediately when the account is deleted.
- Service usage data (members): The watchlist saved to your account (including its order),
tickers registered for condition alerts, and the record of alerts sent.
- Collected automatically: When you access the Service, your IP address, access time and browser information
are recorded in the server logs.
- Payment information (membership): Overseas web payments take place in a checkout provided by Whop
(Whop Inc., United States), a global Merchant of Record. The checkout is shown inside the Service screen or opens
on whop.com. Original payment details such as card numbers are collected directly from you by Whop and the
payment networks. The Service does not receive or store them. The Service keeps only the information needed
to manage subscriptions: subscription status, plan, expiry date, the Whop membership identifier (sent to the
Service by Whop when a payment is confirmed), and, if you paid directly outside the Service screen (on the Whop
platform), the order email address you tell us so the membership can be applied.
Article 2 (Purposes of use)
- Identifying members and keeping them signed in (sessions), and connecting linked social accounts to the same account
- Saving watchlists to the account and syncing them across devices
- Registering, evaluating, recording and sending condition alerts
- Sending alert emails when you have turned on email delivery
- Membership payments, subscription management and refunds (at launch)
- Responding to inquiries, keeping the Service stable (handling errors and abuse), and de-identified statistics
Article 3 (Retention period)
- In principle, information is destroyed without delay once its purpose is achieved or the member leaves.
When a request to leave is received, the account, watchlist, presets, registered email, alert registrations and
alert records are deleted immediately, unless there is a server problem.
If a server failure leaves part of the cleanup unfinished, we tell you it is in progress and retry automatically until it is complete.
To delete only your registered email, you can do so immediately on My Page.
- Where the law requires retention, the information is kept separately for the required period:
| Item | Period | Legal basis |
| Records of contracts and withdrawal of offers | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records of payments and supply of goods | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records of consumer complaints and dispute handling | 3 years | Act on Consumer Protection in Electronic Commerce |
| Access records (sign-in records) | 3 months | Protection of Communications Secrets Act |
- Server access logs (including IP addresses) are kept for up to 3 months for security and incident response and
then deleted on a rolling basis (the server log retention period is set to 90 days and deleted automatically).
Article 4 (Children under 14)
The Service does not collect personal information from children under 14. Any account confirmed to belong to a
child under 14 is deleted without delay.
Article 5 (Provision to third parties)
The Service does not provide your personal information to third parties.
Exceptions are when you have given separate consent, or when there is a lawful request based on law.
Article 6 (Outsourcing of processing)
| Processor | Outsourced task |
| Smileserv (iwinv, Korea) | Server infrastructure hosting (data stored in the Republic of Korea) |
| [Domestic payment gateway (PG): to be confirmed if domestic payments are added] | Payment processing and billing |
Whop, which handles overseas web payments, is not a processor. It is a global Merchant of Record that handles
sales on its own platform. The details are explained in Article 7 (Transfer abroad).
Outsourcing contracts include compliance with personal information protection laws. If a processor changes,
this policy is updated and the change is announced.
Article 7 (Transfer abroad)
Personal information held by the Service is transferred abroad only in the two cases below (sending alert emails,
and processing overseas payments).
Google and Apple sign-in are procedures in which each company collects authentication information directly from you.
They are not a feature that transfers personal information held by the Service to those companies.
| Recipient (contact) | Country | Items | When and how | Purpose | Retention and use period |
Google LLC Google support | United States | Registered email address and alert email content |
Each time a condition alert is sent after you turn on email alerts, sent over SMTP with TLS |
Sending alert emails through the Gmail sending servers
(only when you have turned on alert emails. If you turn them off, no transfer takes place) |
Only at the time of sending. Processing on Google's side follows the Google Privacy Policy |
Whop Inc. Whop Privacy Policy | United States | The Service's internal member ID and the selected plan |
When you open the overseas checkout on the Service screen after signing in, sent over an API connection with TLS |
Connecting the payment to your Service account automatically, so the membership is applied automatically when the payment is confirmed
(overseas payment on the Service screen is only available while signed in, and this transfer is required to show the checkout) |
Within the scope of subscription management. Processing on Whop's side follows the Whop Privacy Policy |
The checkout for overseas web payments is provided by Whop (Whop Inc., United States), a global Merchant of Record.
Even when it is shown inside the Service screen, the name, email and card details you enter are collected directly
from you by Whop. This is not a transfer abroad of personal information held by the Service, and the Service does
not receive this information. After a payment is confirmed, Whop notifies the Service of the subscription status
(membership status, plan, expiry date and the Whop membership identifier), and the Service keeps it only to manage
the subscription (Article 1).
Price charts for US stocks are shown with an embedded widget provided by TradingView (TradingView, Inc., United States;
TradingView Privacy Policy).
Your browser loads the widget directly from TradingView's servers, and in doing so TradingView may directly collect
access information such as your IP address. This is not a transfer of personal information held by the Service.
Turning on email alerts is a request for alerts that include the transfer above. If you do not want this, turn off
email delivery. In that case only email alerts are unavailable, and you can keep using the rest of the Service.
Proceeding with an overseas payment on the Service screen is a request for a payment that includes the Whop transfer
in the table above, and this transfer is required to connect the payment to your account. If you do not want this,
you can choose not to use overseas payments.
Kakao and Naver sign-in are handled by Korean companies.
Article 8 (How information is destroyed)
- Electronic files are deleted in a way that cannot be recovered.
- You can ask to leave in My Page (MY) in the app, or the Membership tab, then Delete account.
Unless there is a server problem, the account, watchlist, alert registrations, alert records and registered email are deleted immediately.
If you have a Whop subscription, we first confirm that automatic renewal has stopped. If this confirmation fails, the account is kept and we guide you to retry or contact support.
Even if a server failure leaves part of the cleanup unfinished, the deletion request stays in place and is retried automatically until it is complete. Contact: support@conf-zone.com.
Article 9 (Your rights)
- You can ask to access, correct or delete your personal information, or to stop its processing.
- How to do this: the in-app account deletion feature, or the contact of the privacy officer below. We tell you the
result within 10 days of receiving the request.
- Even after you withdraw consent (leave), you can keep using the basic features of the Service as a guest.
Article 10 (Cookies)
The Service uses only an essential cookie (cz_session) to keep you signed in.
It does not use advertising, tracking or third-party analytics cookies. If you block cookies, you cannot sign in,
but guest features work normally.
Article 11 (Security measures)
- HTTPS (TLS) encryption on every connection
- Signed session tokens (HMAC-SHA256) and HttpOnly, Secure cookies
- Server access control (SSH key authentication only, minimal firewall openings)
- Minimum collection: unnecessary information such as contact details is not collected in the first place,
and email is kept only when you choose to register it
Article 12 (Privacy officer)
- Privacy officer: Seungdo Lee (Representative)
- Contact: support@conf-zone.com
To report or get advice about a privacy violation, you can contact the following Korean agencies:
the Personal Information Infringement Report Center (118, no area code), the Personal Information Dispute Mediation
Committee (1833-6972), and the Korean National Police Agency Cyber Investigation Bureau (182, no area code).
Article 13 (Changes to this policy)
If this policy changes, we announce it in the Service 7 days before it takes effect (30 days for significant changes).
Supplementary provision: This policy takes effect when the Service officially launches. Data from the rehearsal period before that is treated by the same standards.
← Home ·
About & methodology ·
Terms of Service ·
한국어