Privacy Policy
v2026-07-08
# Privacy Policy

Last Revised: 2026-06-08
Effective Date: 2026-06-08

---

rulyfi (룰리파이) (hereinafter the "Company") values the personal information of its users and complies with applicable laws and regulations, including the Personal Information Protection Act (개인정보 보호법) and the Act on Promotion of Information and Communications Network Utilization and Information Protection (정보통신망 이용촉진 및 정보보호 등에 관한 법률). This Privacy Policy (hereinafter this "Policy") explains for what purposes and by what means a user's personal information is collected, used, retained, and destroyed in the Rulyfi service operated by the Company (hereinafter the "Service").

---

## Article 1 (Categories of Personal Information Collected)

The Company collects the minimum personal information necessary to provide the Service.

### 1. Items Collected at Sign-Up

Required items
- Email address
- Password (stored in encrypted form)

Optional items
- Profile name or nickname

The Company does not collect date of birth; whether the user is at least 18 years old is verified solely through the user's self-certification (consent checkbox) at sign-up.

### 2. Items Collected When Using Paid Services

Payment information (credit card number, billing address, payment country, etc.) is not collected or stored directly by the Company; it is collected and processed by the payment service provider (Merchant of Record). The Company receives only the following information from the payment service provider:
- Payment status (success/failure/refund)
- Payment amount and currency
- Payment country
- Payment identifier issued by the payment service provider

### 3. Items Automatically Collected in the Course of Using the Service

- IP address
- Date and time of access
- Browser type and OS information
- Device identification information

### 4. Data Generated by the User Within the Service

- Backtest and scan request information (selected symbol, market, timeframe, indicators, parameters, entry/exit conditions, trade direction)
- Backtest and scan result information (return rate, number of trades, Sharpe ratio, maximum drawdown, and other performance metrics)
- Strategy configuration and saved records (indicator combinations, card settings, favorites)
- Frequency and patterns of feature usage within the Service

## Article 2 (Methods of Collecting Personal Information)

The Company collects personal information by the following methods:
1. Information entered directly by the user when signing up, paying for a paid service, or submitting a customer inquiry
2. Information automatically generated and collected in the course of using the Service
3. Payment-related information received from the payment service provider

## Article 3 (Purposes of Processing Personal Information)

The Company uses the personal information it collects for the following purposes:

1. Membership registration and management: identity verification, prevention of duplicate registration, verification that the user is at least 18 years old, prevention of fraudulent use, and account recovery
2. Provision of the Service: provision of backtesting and scanner features, saving of strategies, and retention of user settings
3. Operation of paid services: payment processing, subscription status management, issuance of receipts, and refund processing
4. Customer support: responding to inquiries, processing error reports, and delivering notices
5. Service improvement: analysis of usage patterns, error detection, and development of new features (in a form that does not identify individuals)
6. Security and prevention of fraudulent use: detection of abnormal access, prevention of abuse, and investigation of violations of applicable laws and regulations
7. Compliance with laws and regulations: fulfillment of statutory obligations and response to lawful requests from investigative or supervisory authorities
8. Generation of statistical data and service improvement: The Company may process the backtest and strategy scan request and result data performed by users in the Service into anonymized aggregate statistics that cannot identify any individual, and use such data for service improvement and internal analysis. Such processed anonymized statistics constitute **anonymized information under Article 58-2 of the Personal Information Protection Act (개인정보 보호법)** and cannot identify any specific individual.

## Article 4 (Period of Processing and Retention of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by applicable laws or the retention and use period consented to by the user.

| Item | Retention Period | Basis |
|---|---|---|
| Member information (email, etc.) | Until withdrawal of membership | Personal Information Protection Act (개인정보 보호법) |
| Payment-related information | 7 years | Article 85-3 of the Framework Act on National Taxes (국세기본법), Value-Added Tax Act (부가가치세법) |
| Records of consent to the terms of service and privacy policy (including version) | Permanent (anonymized after withdrawal) | Preservation of legal evidence |
| Records of customer inquiries and dispute handling | 3 years | Act on Consumer Protection in Electronic Commerce (전자상거래 등에서의 소비자보호에 관한 법률) |
| Access logs, IP addresses | 3 months | Protection of Communications Secrets Act (통신비밀보호법) |
| Activity logs (records of Service use) | 180 days | Chargeback dispute response (retention period within the Visa/MC 540-day window) |
| Records of fraudulent use | 1 year | Prevention of recurrence of abuse |
| Backtest and scan job data | 30 days (thereafter archived in anonymized form) | Operational analysis and market statistics |
| Backtest and scan result data | Per-tier limit by user grade (Free 1 / Pro 4 / Premium 20) | User data retention policy |
| Records of automated trading signal transmission | 1 year (thereafter retained in anonymized form) | In preparation for the 10-year statute of limitations for tort under the Civil Act (민법) |

Provided that, where applicable laws and regulations prescribe a separate retention period, the information shall be retained until the end of such period.

### Policy on Processing Upon Withdrawal of Membership

After a request to withdraw membership, following a 30-day grace period (to prevent mistakes), the information is processed as follows:

1. Immediate permanent deletion — identifiable information:
   - Email address, name, nickname, password hash
   - IP address, device identification information
   - Profile image and other directly identifiable items

2. Retention until the statutory retention period after anonymization — items subject to the statutory retention obligations in the table above:
   - The user identifier (user_id) is replaced with an irreversible hash value
   - Transaction-fact information such as payment amount, time, and transaction ID is retained
   - The fact and time of automated trading signal transmission, and the time and version of consent to the terms of service, are retained
   - Anonymized information constitutes anonymized information under Article 58-2 of the Personal Information Protection Act (개인정보 보호법) and cannot identify any specific individual

3. Immediate anonymization or deletion — data subject to statistical processing:
   - Backtest and scan data have already been processed in advance into anonymized aggregate statistics, and the originals are automatically deleted upon expiration of the 30-day retention period.

## Article 5 (Provision of Personal Information to Third Parties)

As a general rule, the Company does not provide users' personal information to outside parties. The following cases, however, are exceptions:

1. Where the user has consented in advance
2. Where there is a special provision in applicable laws or regulations
3. Where an investigative or supervisory authority so requests for the purpose of investigation or inspection in accordance with the procedures and methods prescribed by law
4. Where the information is provided, processed into a form that cannot identify any specific individual, for the purposes of statistical compilation, academic research, or the public interest

## Article 6 (Outsourcing of Personal Information Processing)

The Company outsources part of the work necessary to provide the Service to external specialized companies.

| Outsourced Company | Outsourced Work | Country of Location |
|---|---|---|
| Supabase, Inc. | Database and authentication infrastructure | United States |
| Amazon Web Services, Inc. | Backtest and scanner Lambda execution, queues, object storage | Japan (Tokyo region) |
| Cloudflare, Inc. | CDN, DNS, web hosting, email routing | United States |
| Plus Five Five, Inc. (Resend) | Transactional email delivery (sign-up confirmation, password reset, operational notifications) | United States |
| Dodo Payments Inc. | Payment processing, tax processing, receipt issuance (Merchant of Record) | United States |
| ZASolution (Affonso) | Affiliate referral tracking and commission settlement | Germany |

When entering into an outsourcing agreement, the Company specifies in the contract, in accordance with Article 26 of the Personal Information Protection Act (개인정보 보호법), the prohibition of processing personal information for purposes other than performing the outsourced work, technical and managerial protective measures, restrictions on sub-outsourcing, and management and supervision of the outsourced party.

## Article 7 (Cross-Border Transfer of Personal Information)

This Service is intended for users worldwide, and in the course of providing the Service, personal information may be transferred overseas as follows:

| Items Transferred | Transferee | Contact | Country of Transfer | Time and Method of Transfer | Purpose of Use | Retention Period |
|---|---|---|---|---|---|---|
| Email, Service usage data | Supabase, Inc. | privacy@supabase.com | United States | At the time of sign-up and Service use, via encrypted network transmission | Data storage and authentication | Until withdrawal of membership |
| Backtest/scan request data | Amazon Web Services, Inc. | aws-korea-privacy@amazon.com | Japan | At the time of backtest/scan execution, via encrypted network transmission | Lambda execution, queues, object storage | 30 days |
| IP address, traffic metadata | Cloudflare, Inc. | privacyquestions@cloudflare.com | United States | At the time of accessing the Service, automatically | CDN, DNS, web hosting | In accordance with Cloudflare's policy |
| Email address (recipient) | Plus Five Five, Inc. (Resend) | support@resend.com | United States | At the time of transactional email delivery | Sign-up confirmation, password reset, etc. | In accordance with Resend's policy |
| Payment information, email, IP | Dodo Payments Inc. | legal@dodopayments.com | United States | At the time of paid payment, via encrypted network transmission | Payment processing (Merchant of Record) | Up to 10 years from the date of payment completion (the period prescribed by the tax and payment laws of each country) |
| Visit records (IP, browser information, referral identifier cookie), email and user ID at sign-up, payment amount and product information at payment | ZASolution (Affonso) | hello@affonso.io | Germany (hosted in Frankfurt, EU) | At the time of accessing the Service, sign-up, and payment, via encrypted network transmission | Affiliate referral tracking and commission settlement | In accordance with Affonso's policy |

In accordance with Article 28-8 of the Personal Information Protection Act (개인정보 보호법), the Company obtains the user's separate consent—distinct from the user's other consents given at sign-up—to the cross-border transfers described above. If the user does not consent to the cross-border transfer, sign-up and use of the Service may be restricted, because the overseas infrastructure (database, computation, email, etc.) necessary to provide the Service cannot be used.

## Article 8 (Rights of the Data Subject)

In accordance with the Personal Information Protection Act (개인정보 보호법) and related laws and regulations, the user may exercise the following rights:

1. Right to request access to personal information
2. Right to request correction in the event of errors, etc.
3. Right to request deletion (excluding, however, information subject to a retention obligation under applicable laws and regulations)
4. Right to request suspension of processing
5. Right to data portability (where applicable)
6. Right to withdraw consent (in which case use of the Service may be restricted)

To exercise the above rights, the user may submit a request to support@rulyfi.com in writing, by email, by fax, or otherwise, and the Company will take action without delay (statutory deadline: within 10 days).

Where a user requests correction of an error in personal information, the Company will not use or provide the relevant personal information until the correction is completed.

Where an agent of the user exercises rights, the Company may require a power of attorney in accordance with the Enforcement Rules of the Personal Information Protection Act (개인정보 보호법 시행규칙).

## Article 9 (Procedures and Methods for Destruction of Personal Information)

The Company destroys the relevant information without delay after the retention period of the personal information has elapsed or the purpose of processing has been achieved.

Destruction procedure
1. Information entered by the user is stored for a certain period after the purpose is achieved, in accordance with internal policies and other applicable laws and regulations, and is then destroyed.
2. Personal information is not used for any purpose other than the purpose of retention, except as required by law.
3. Upon withdrawal of membership, after a 30-day grace period, identifiable information is permanently deleted, and information subject to a statutory retention obligation is anonymized and retained until the end of the retention period (see Article 4 for detailed procedures).

Destruction method
1. Information in the form of electronic files: permanently deleted by a method that makes recovery and reproduction impossible
2. Personal information printed on paper: shredded with a shredder or incinerated
3. Anonymization: identifiers (user_id, email, etc.) are replaced with irreversible one-way hash values, and auxiliary identifiable items (IP, device information, etc.) are permanently deleted together with them. After processing, the data is classified as anonymized information under Article 58-2 of the Personal Information Protection Act (개인정보 보호법).

## Article 10 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to process users' personal information securely:

1. Technical measures
   - Encrypted storage of passwords (one-way hashing such as bcrypt)
   - HTTPS/TLS encryption during network transmission
   - Database access control and logging
   - Regular security updates and vulnerability assessments
2. Managerial measures
   - Minimization of personal information processing privileges and designation of responsible personnel
   - Training of personnel who process personal information
   - Establishment and implementation of an internal management plan
3. Physical measures
   - Compliance with the physical security systems of the data centers of outsourced companies (Supabase, AWS, Cloudflare, etc.)

## Article 11 (Cookies and Automatic Collection Technologies)

1. The Company does not use tracking cookies other than technical cookies essential for providing the Service and the affiliate referral cookie described in Paragraph 3 below.
2. Session cookies for member authentication (to maintain login) are essential for using the Service and are automatically deleted upon logout or session expiration.
3. For affiliate (partner) referral tracking, a script operated by Affonso (ZASolution, Germany) may store a referral identifier cookie (affonso_referral, valid for 90 days). This cookie is used solely to attribute visits, sign-ups, and payments made through an affiliate link to the referring partner for commission settlement, and is not shared with advertising networks. Users may block or delete cookies in their browser settings; blocking them does not restrict use of the Service.

## Article 12 (Personal Information of Children Under the Age of 18)

1. This Service is intended only for users aged 18 or older, and sign-up by persons under the age of 18 is not permitted.
2. If the Company becomes aware that a user is under the age of 18, it will immediately terminate the relevant account and destroy the related personal information.
3. If a guardian becomes aware that the personal information of their child (under the age of 18) has been collected, the guardian may report this to support@rulyfi.com and request its deletion.

## Article 13 (Chief Privacy Officer and Point of Contact)

The Company has designated a Chief Privacy Officer to protect users' personal information and to handle complaints related to personal information.

**Chief Privacy Officer**
- Name: Lee Junyoung (이준영)
- Position: Representative
- Contact: support@rulyfi.com

For inquiries, complaint handling, and remedy for damages related to personal information, you may contact the above point of contact, and the Company will respond and take action without delay.

## Article 14 (Remedies for Infringement of Rights)

To obtain remedy for infringement of personal information, users may seek assistance from the following organizations.

Domestic users
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Personal Information Infringement Report Center: 118 / privacy.kisa.or.kr
- Cyber Crime Investigation Division of the Supreme Prosecutors' Office: 02-3480-3573 / www.spo.go.kr
- Cyber Bureau of the National Police Agency: 182 / cyberbureau.police.go.kr

Users residing in the EU
- You have the right to lodge a complaint with the data protection authority (Data Protection Authority) of your own country.
- Where an EU representative has not been separately designated, you may contact support@rulyfi.com directly.

Users in other countries
- You may lodge a complaint with the personal information protection supervisory authority of your country of residence.
- You may contact support@rulyfi.com directly.

## Article 15 (Changes to the Privacy Policy)

1. This Policy applies from its effective date, and in the event of any addition, deletion, or correction of its contents in accordance with laws, regulations, or policy, the Company will give notice through notices within the Service from 7 days before the changes take effect.
2. In the case of changes that materially affect users, the Company will give notice from 30 days before the effective date and will individually notify users at the email addresses they have registered.
3. Where a material change requiring user consent arises with respect to the collection and use of personal information, provision to third parties, etc., the Company will request renewed consent.

---

## Addendum

This Privacy Policy takes effect on 2026-06-08.

Company Information
- Trade name: rulyfi (룰리파이)
- Representative: Lee Junyoung (이준영)
- Business Registration Number: 420-27-02209
- Address: Unit 201, 9-1 Dongsomun-ro 26na-gil, Seongbuk-gu, Seoul (Dongseon-dong 3-ga) (서울특별시 성북구 동소문로26나길 9-1, 201호 (동선동3가))
- Phone: 010-6547-0825
- Email: support@rulyfi.com