Privacy Policy

Last updated: August 12, 2026

HeyJames Inc. (the "Company") complies with the Personal Information Protection Act (PIPA), the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other applicable Korean laws regarding the protection of personal information. This Privacy Policy applies to the heyjames service operated by the Company (including https://heyjames.ai).

1. Personal Information Collected and Methods of Collection

A. Items Collected

At sign-up (required):

  • Email address, password (stored as a one-way hash), name

When using social login (Google, Kakao):

  • Email, name or nickname, profile image URL, social provider identifiers (provider, uid). Where a Kakao account does not supply an email address, the Company automatically generates and stores a placeholder email for identification purposes.

When paying for courses, membership, consulting, or sprint:

  • Payment authorization result, card brand, masked card number (e.g., 1234-****-****-1234), payment identifiers (orderId, paymentKey), and billing key for membership recurring payments. Full card numbers, CVC, and passwords are not stored by the Company and are processed by Toss Payments.

When using the Self-Serve Estimate (/scoping):

  • The service description and conversation entered by the user, reference images attached by the user, audio files recorded when voice input is used, and the feature list, screen layout, estimated number of sessions, and estimated price produced by the AI. If the session is started while logged in, the account's name, email, and phone number are stored with that estimate record. Conversation content and attachments are transmitted to external AI APIs (Anthropic, OpenAI) to generate responses; audio files are transmitted to OpenAI for transcription and are deleted from the Company's servers immediately after conversion.

When taking part in a live session (video meeting):

  • Video meeting access records, audio and video transmitted during the session, recording files where the Company records the session, live captions and transcripts converted from speech together with their translations, and chat messages exchanged during the session. Recording and transcription are carried out only after prior notice, and the Member may decline.

When using the AI chatbot or the KakaoTalk channel:

  • Text entered by the user (questions/prompts), session identifiers, response output, and the sender identifier assigned by Kakao when the KakaoTalk channel is used. Conversation content is transmitted to external AI APIs (Anthropic, OpenAI) to generate responses.

When contacting support or applying for 1:1 consulting:

  • Name, email, phone (optional), inquiry content, desired completion timeline (optional), budget range (optional), referral source (optional), pre-consulting Q&A responses (qa_history), and business idea description (for sprint applications)

When requesting and carrying out a build project:

  • Name, email, phone number, the verification code where phone verification is used (discarded immediately after verification), the description of the service to be built and any additional requests, reference images and documents attached, and the feature specification and change request history

When issuing tax invoices and confirming payments:

  • Business name, business registration number, representative's name, business address, business type and category, contact email, and depositor name and payment records. Where a copy of a business registration certificate is uploaded to use the automatic input feature, that image or PDF file is transmitted to an external AI API (Anthropic) for reading.

When applying as a sub-merchant (/toss):

  • Business name, business registration number, contact name, contact email, contact phone, website URL, monthly transaction volume, payment methods

When completing the post-signup survey (optional):

  • Age range, current status/role, experience level, technical background, learning goals, income preferences, pain points, referral source

Automatically collected during service use:

  • IP address, User-Agent (browser/OS), cookies and visitor identifiers, visit timestamps, pages visited, referrer, service usage records, records related to fraud or abuse, and behavioural data used to measure advertising performance (conversion events such as visits, views, applications, and payments)

B. Methods of Collection

  • Direct input by the user during sign-up, payment, inquiries, and other service usage
  • Automated collection via cookies, server logs, and similar tools

2. Purposes of Collection and Use

The Company uses collected personal information for the following purposes.

A. Performance of the Service Contract

  • Course access, members-only content delivery, consulting booking and meeting link delivery, sprint program operation
  • Payment processing, issuance of receipts/tax invoices, refund processing
  • Learning progress tracking, enrollment and completion management, reviews and practice submissions
  • Generating AI chatbot responses, automated comment bot responses, and consulting briefs
  • Calculating the estimated number of sessions and price in the Self-Serve Estimate, providing recording, captions, and transcripts for live sessions, recording and drawing down Credit, and issuing tax invoices

B. Member Management

  • Identity verification for membership service use
  • Prevention of fraudulent or unauthorized use
  • Verifying age 14+ eligibility and registration intent
  • Handling customer inquiries, retaining records for dispute resolution, delivering notices
  • Managing points, coupons, and referral codes

C. Marketing and Statistics (with separate consent)

  • Delivering announcements about new services, events, and promotions via email or notifications
  • Analyzing service usage statistics, developing and improving new features
  • Personalized recommendations of courses and content

3. Retention and Use Periods

In principle, the Company destroys personal information without delay once the collection and use purpose has been fulfilled. The following information is retained for the specified periods.

A. Retention under Company Internal Policy

  • Member account information: until withdrawal (destroyed upon withdrawal)
  • AI chatbot conversation logs: up to 6 months (for service quality and abuse prevention)
  • Fraud-prevention records: 1 year
  • Self-Serve Estimate conversations, attached images, and generated quotes: up to 1 year (to preserve the basis of the quote and carry it into consultation). Where the estimate leads to a booking or contract, the retention period for that contract record applies.
  • Live session recordings and transcripts: up to 6 months after the session ends (for user review and dispute handling). Destroyed immediately upon a user's deletion request.
  • Audio files uploaded through voice input: destroyed immediately after transcription (not retained separately)

B. Retention under Applicable Laws

  • Records on contract or withdrawal: 5 years (E-Commerce Act)
  • Records on payment and supply of goods: 5 years (E-Commerce Act)
  • Records on consumer complaints or disputes: 3 years (E-Commerce Act)
  • Records on advertising and labeling: 6 months (E-Commerce Act)
  • Website visit logs (IP, etc.): 3 months (Protection of Communications Secrets Act)

4. Destruction Procedures and Methods

When the retention period expires or processing purpose is fulfilled and the information is no longer needed, the Company destroys it without delay.

A. Destruction Procedure

User-entered information is transferred to a separate database (or physical storage for paper records) after the purpose is fulfilled and is destroyed after the retention period or immediately, in accordance with internal policies and applicable laws.

B. Destruction Methods

  • Electronic files are deleted via technical methods that prevent reproduction (soft delete followed by permanent deletion, column anonymization).
  • Printed personal information is shredded or incinerated.

5. Provision of Personal Information to Third Parties

The Company does not provide users' personal information to third parties in principle. The following are exceptions.

  • When the user has given prior consent
  • When required by law or upon request from investigative agencies following lawful procedures
  • When provided in an anonymized form (e.g., statistics, research, market analysis) that does not allow identification of individuals

6. Outsourced Processing of Personal Information

The Company outsources certain personal information processing as listed below, and ensures safe management of personal information through contractual provisions in accordance with applicable laws.

Processor Outsourced Task Items Outsourced
Toss Payments Approving/canceling card and easy-payment transactions, issuing/using billing keys for recurring payments, tax invoices Payment data, order identifiers, masked card numbers, payment amounts
Resend (Resend, Inc.) Transactional emails (sign-up confirmation, password reset, payment/refund/operational notices) Email address, name, identifiers contained in email body
Anthropic (Anthropic, PBC) AI chatbot responses, automated comments, automatic brief generation, Self-Serve Estimate conversations and quote calculation, automatic reading of business registration certificates User-input questions/prompts, conversation context, image and document files attached by users
OpenAI (OpenAI, OpCo, LLC) Generating content embeddings for search and recommendation, transcribing voice input (Whisper), Self-Serve Estimate conversations (when the alternate model is used) Course/content text, user search queries, audio files recorded by users, Self-Serve Estimate conversation content
Google LLC Google social login (OAuth), registering consulting meeting schedules via Google Calendar Email, name, profile image, schedule information (title/time)
Gumlet (Gumlet Inc.) Hosting, streaming, and processing course video content Course video files, viewer IP and device information (temporary)
Kakao Corp. Kakao social login (OAuth), customer support through the KakaoTalk channel Kakao account identifier, email, nickname, profile image, channel conversation content
LiveKit, Inc. Relaying video and audio for live sessions and processing recordings Session participant identifiers, audio and video transmitted during the session
Deepgram, Inc. Speech recognition (captions and transcripts) for live sessions Audio streams transmitted during the session
MiniMax (Shanghai MiniMax Technology Co., Ltd.) Speech synthesis (TTS) for live sessions and role-play features Text to be converted into speech
Solapi (Nurigo Co., Ltd.) Sending KakaoTalk alert messages and SMS, sending phone verification codes Recipient phone number, name, booking and payment details contained in the message
Popbill (Linkhub Co., Ltd.) Issuing electronic tax invoices and transmitting them to the National Tax Service Business name, business registration number, representative's name, business address, business type and category, contact email, supply amount
Amazon Web Services (AWS) Cloud storage of attachments and session recordings (Seoul region) Images and documents uploaded by users, session recording files
PostHog, Inc. Analysing service usage behaviour and improving features Visitor identifier, device and browser information, page navigation and click records
Meta Platforms Ireland Ltd. Measuring advertising performance and serving personalised advertising (Meta Pixel) Visitor identifier, cookies, conversion events (the fact and amount of sign-ups, applications, and payments)

7. Cross-Border Transfer of Personal Information

To provide the Service, the Company transfers certain personal information abroad as listed below. By signing up and using the Service, users are deemed to have consented to such transfers.

Recipient Country Items / Purpose Time, Method, and Retention
Resend, Inc. United States Email address, name, email body / Sending transactional emails Transmitted via network at time of email sending / Delivery logs retained up to 30 days
Anthropic, PBC United States AI input text (questions/prompts), attached image and document files / Generating AI responses, Self-Serve Estimate, automatic document reading Transmitted at time of API call / Not used for training per Anthropic API policy; short-term retention for abuse monitoring (up to 30 days)
OpenAI, OpCo, LLC United States Content/search query text, audio files recorded by users, Self-Serve Estimate conversation content / Generating embeddings, transcribing speech into text Transmitted at time of API call / Not used for training under OpenAI's default policy; short-term retention (up to 30 days)
Google LLC United States Google account identifiers, email, calendar event information / Social login and schedule registration Transmitted at time of login/event creation / Retained per Google's policies
Gumlet Inc. Singapore/India (with global CDN) Course video files, viewer device info / Video hosting and streaming Transmitted at upload/streaming / Retained during the course operation period
LiveKit, Inc. United States Session participant identifiers, audio and video transmitted during the session / Relaying and recording video and audio for live sessions Transmitted in real time during the session / Not stored on the relay server; recordings are forwarded to the Company's Seoul-region storage and then deleted
Deepgram, Inc. United States Audio streams transmitted during the session / Generating live captions and transcripts Transmitted in real time during the session / Not used for training under Deepgram's policy and not retained after real-time processing
MiniMax (Shanghai MiniMax Technology Co., Ltd.) China Text to be converted into speech / Speech synthesis (TTS) Transmitted at the time of the synthesis request / Not retained after synthesis
PostHog, Inc. United States Visitor identifier, device and browser information, page navigation and click records / Analysing service usage behaviour Transmitted as pages are used / Retained in accordance with PostHog's policy
Meta Platforms Ireland Ltd. Ireland (including the United States via affiliated companies) Visitor identifier, cookies, conversion events / Measuring advertising performance and serving personalised advertising Transmitted when advertising traffic arrives and conversions occur / Retained in accordance with Meta's policy

Users may refuse cross-border transfers, but in that case the features provided by the relevant processors (e.g., social login, AI chatbot, Self-Serve Estimate, live session captions and recording, video streaming) cannot be used. Transfers for advertising measurement (Meta) and usage analytics (PostHog) can be blocked directly in the browser using the methods described in Section 9, and blocking them does not restrict use of the Service. For all other refusals, please write to james@heyjames.ai.

8. Rights of the Data Subject and How to Exercise Them

Users may exercise the following rights regarding their personal information at any time.

  • Right to access and rectify: My Page > Edit Profile, or contact james@heyjames.ai
  • Right to suspend processing: Submit a request via customer support; the Company will respond within 10 days unless legally restricted
  • Right to withdraw (account deletion): Submit a withdrawal request via My Page or customer support
  • Remedies for rights infringement: See Section 14 of this Policy

When exercising these rights, the Company verifies the identity of the user or their authorized agent. For users under 14, the legal guardian may exercise these rights; however, this Service does not allow sign-up by anyone under 14.

9. Cookies and Automatic Collection Devices

The Company uses 'cookies' and similar technologies to provide personalized services. Cookies are small text files sent by the website to the user's browser and stored on the user's device.

A. Purposes of Cookies

  • Maintaining login state (session cookies)
  • Analyzing visit frequency and navigation paths
  • Identifying user interests to recommend courses and content
  • Measuring advertising performance and serving personalised advertising (Meta Pixel), and analysing service usage behaviour (PostHog)

B. Behavioural Data and Personalised Advertising

The Company collects behavioural data (conversion events such as visits, views, applications, and payments) through the Meta Pixel in order to measure advertising performance and serve personalised advertising, and analyses usage behaviour through PostHog in order to improve the Service. For these purposes the Company does not transmit information that directly identifies a user, such as name or contact details; only cookie- and visitor-identifier-level information is transmitted. Users may refuse this through browser cookie-blocking settings, ad-blocking extensions, or the ad settings of their Meta account (www.facebook.com/adpreferences), and refusing does not restrict use of the Service.

C. How to Refuse Cookies

Users may refuse cookie storage through their browser settings (e.g., Chrome > Settings > Privacy and security > Cookies and other site data). Refusing cookies may affect certain service features such as maintaining login.

10. Measures to Ensure the Safety of Personal Information

The Company implements the following technical, administrative, and physical measures to prevent loss, theft, leakage, alteration, or destruction of users' personal information.

  • Administrative: Minimizing personnel who handle personal information, conducting regular internal training, and separating access permissions
  • Technical: One-way encryption (bcrypt) of passwords; payment data processed by the PG (with only masked values retained); HTTPS (TLS) applied across all channels
  • Access Control: Granting access only to authorized personnel, retaining operational access logs, operating intrusion prevention systems
  • Backup and Recovery: Regular database backups, prompt recovery in case of incidents
  • Physical: Operating infrastructure (cloud data centers) with access controls and security facilities

11. Privacy Officer

The Company designates the following Privacy Officer to be responsible for personal information processing and to handle related complaints and remedies.

Privacy Officer

Name: Sunghoon Lee

Position: CEO

Phone: +82-10-9391-6522

Email: james@heyjames.ai

12. Personal Information of Children Under 14

The Company does not allow sign-up by children under the age of 14 and does not collect their personal information. If it is found that a child under 14 has signed up without parental consent, the Company will promptly delete the account and related information.

13. Changes to this Privacy Policy

This Privacy Policy is effective from the date stated, and any changes due to legal or policy reasons will be announced via in-service notice or email at least 7 days before the effective date (at least 30 days in advance for material changes).

14. Remedies for Rights Infringement

For reporting or consultation regarding personal information infringement, please contact the following Korean agencies.

  • Personal Information Infringement Report Center (KISA): 118 / privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
  • Supreme Prosecutors' Office Cyber Investigation Division: 1301
  • National Police Agency Cyber Bureau: 182 / ecrm.police.go.kr

This Privacy Policy is effective from August 12, 2026. The previous version (effective June 23, 2026) ceases to be effective at the same time.

Business Information and Contact

Company: HeyJames Inc.

CEO: Sunghoon Lee

Business Reg. No.: 362-81-00644

Mail-Order License: 2024-Seoul Dongjak-0832

Address: 2803, 43 Boramae-ro 5-gil, Dongjak-gu, Seoul, Republic of Korea

Phone: +82-10-9391-6522

Email: james@heyjames.ai