nidavellir

Privacy Policy

Effective date: 2026-06-27

This policy explains what personal data nidavellir collects, why, how long we keep it, and with whom we share it.

1. Data Controller

Controller: Zero to One Flow (021flow) (Rep. Sungtae Ryu) · Email: [email protected] · Data Protection Officer: Sungtae Ryu (the Representative) · Contact: [email protected], 070-8676-0210

2. Data We Collect

  • Account data: email, name or nickname, login identifier.
  • Authentication data: social-login provider identifier, token metadata.
  • Billing data: payment status, plan, billing dates, receipt/order identifiers, Paddle customer/transaction ID (we do not store card numbers, CVC or other payment-instrument details).
  • Usage data: access logs, IP address, browser/device info, usage and error logs.
  • Support data: inquiry content, email, attachments, support history.
  • Cookies and similar technologies.
  • Your content: proposals, documents, prompts and files you input into the Service.

3. How We Use It

  • Account registration and management.
  • Providing and operating the Service.
  • Verifying plan/subscription status; billing, refunds and tax/accounting.
  • Customer support and notices.
  • Security, abuse prevention and incident response.
  • Service improvement, statistics and analytics.
  • Compliance with legal obligations.

4. Processors and Third Parties

We rely on the following processors (recipient · data · purpose · retention · cross-border):

  • Payments: Paddle.com Market Limited (Paddle) — payment status/order IDs · payment, tax, receipts, refunds, payment-related support · as required by law · cross-border (EU/UK).
  • Hosting/infrastructure: Amazon Web Services, Inc. (AWS) and Cloudflare, Inc. (DNS/content delivery) — access/service data · hosting and delivery · for the service term · cross-border (US and others).
  • Email delivery: Amazon Web Services, Inc. (Amazon SES or equivalent email infrastructure) — email/send metadata · invites, notifications and notices · minimal period after sending · cross-border (US and others).
  • Analytics: Google LLC (Google Analytics, Google Tag Manager) — usage/device data · statistics and analytics · up to 14 months · cross-border (US).
  • Auth providers: Google LLC, Apple Inc. — auth identifier · social login · until account deletion · cross-border (US).
  • AI APIs: Anthropic, PBC; OpenAI, LLC; Google LLC (Gemini); ElevenLabs, Inc. (voice synthesis) — text/content you submit for generation · producing results · transient (retention per each provider's policy) · cross-border (US).
  • Database/storage: Amazon Web Services, Inc. (S3, CloudFront, including our self-managed MongoDB) — account/content data · storage and delivery · for the service term · cross-border (US and others).

We do not sell your personal data, except where required by law.

5. International Transfers

Using Paddle (UK/EU), cloud hosting (AWS and Cloudflare, US and others), AI APIs (Anthropic, OpenAI, Google, ElevenLabs — US) and analytics (Google, US) may involve transferring data internationally. The recipient, destination country, data, purpose, method (network transmission when you use the Service) and retention follow the processor list in section 4. You may refuse such transfers, but some essential features (e.g. payment) may then be unavailable.

6. Retention

We delete your personal data when you close your account or once the purpose is fulfilled. However, payment/transaction/dispute records may be retained for statutory periods (e.g. Korean e-commerce law); backups are purged on a rolling schedule within 30 days; and minimal records may be kept to prevent abuse.

7. Your Rights

You may request access to, correction of, deletion of, or restriction of processing of your personal data, withdraw consent, or close your account by contacting [email protected].

8. Cookies

We use essential cookies for sign-in and preferences (language/region); any analytics/marketing cookies are identified separately. You can refuse cookies in your browser, though some features may not work.

9. Security Measures

We apply reasonable safeguards including access controls, encryption in transit, log management, backups, security updates and administrator access controls.

10. Children

The Service is intended for adults/business users and is not directed to children under 14 (or the applicable age in your country). If we learn we have collected a child's data, we delete it promptly.

11. Changes and Contact

This policy applies from its effective date; we announce changes in-product or by email in advance. Privacy questions: [email protected]


Back to pricing
Privacy Policy · 개인정보처리방침 · nidavellir