PRIVACY

Privacy Policy

The operator of Refresh Planner processes only the minimum personal data required to provide the service.

Effective September 13, 2026

1. Information processed and purpose

  • Sign-up and login: Email address, display name, and authentication identifier are used to create accounts, verify identity, and maintain login.
  • Analysis and task records: WordPress site addresses, public-post analysis, task status, and completion dates are used to save and retrieve each member's work and compare performance.
  • Convenience settings: Saved site labels, favorites, hold states, and account-deletion request state are used for site switching and task management.
  • Search Console import: Page URLs, clicks, impressions, CTR, and average position obtained through user-approved Google read access or an uploaded CSV are used for priority scoring and before/after comparisons. Google access tokens remain briefly in browser memory and are not stored in the database.
  • Visit statistics: The access date in Korea Standard Time and a random daily visitor identifier are used for unique-visitor statistics.
  • Notifications and diagnostics: Notification status, time, language, device push endpoint, encryption public keys, and recent delivery status are used for background task briefings. Post titles and revenue amounts are not included in notification text.
  • Operations hub: Revenue targets, revenue and ad performance, WordPress connection checks, refresh drafts, and notification settings are stored for planning and later retrieval.
  • Team and agency features: Workspace names, invitation emails, roles, and client sites are used to verify collaboration permissions and manage client content.
  • On-device and security data: Sessions, recent results, installed-app cache, IP address, browser type, and access time may be handled by the browser, hosting provider, or authentication provider.

2. Retention

Account, analysis, task, and imported Search Console records are retained until account closure or a deletion request. Anonymous visit identifiers and error logs are pruned on a 90-day basis when new records are stored. Browser data can be removed by signing out or clearing browser storage. Records required by law may be retained separately for the applicable period.

3. Processors and external services

  • Supabase: Authentication, stored records, scheduled execution, and push-delivery processing.
  • Browser push services: When notifications are enabled, the relevant browser provider, such as Google, Apple, or Mozilla, relays the notification to the device.
  • Google Search Console: Access to managed sites and search performance with user consent.
  • Google AdSense: Ad delivery, frequency control, fraud prevention, and measurement when ads are enabled.
  • OpenAI: If the administrator connects a server AI key, the selected post title, improvement items, and extra instructions are used to generate a refresh draft.

Google and third-party ad providers may use cookies to serve ads based on prior visits. You can manage personalized ads in My Ad Center and read Google's advertising data information.

4. Your rights

You may request access to, correction or deletion of, or restriction of processing for your personal data and analysis records. Requests may be sent using the email address on the signed-in account and are handled after identity verification.

5. Security

Member data is isolated, and authorization policies allow only authenticated requests to access private analysis records. Account details, visitor statistics, and error logs are visible only to the administrator. Passwords are handled securely by the authentication provider and are not stored directly by the operator.

6. Policy changes

If processing items or external services change, this policy and its effective date will be updated.