Privacy Policy
This is an English translation of the Korean Privacy Policy (개인정보처리방침). If the two differ, the Korean version prevails.
1990Company (the "Company") provides the K-OTP website (k-otp.dev), console (app.k-otp.dev), documentation (docs.k-otp.dev) and OTP API (api.k-otp.dev) (together, the "Service"). To protect the personal information of data subjects under the Personal Information Protection Act ("PIPA") and other applicable laws of Korea, and to handle related complaints promptly, the Company publishes this Privacy Policy.
Effective date: 2026-10-02
1. Purposes of processing
The Company processes personal information for the purposes below. It does not use it for any other purpose, and if a purpose changes, it takes the required steps, such as obtaining separate consent under Article 18 of PIPA.
- Membership: identifying and signing in members with sign-in links and codes sent by email, managing accounts, inviting organization members, preventing abuse, and sending service notices and notifications
- Providing the Service: issuing and managing apps and API keys, sending and verifying codes at Customers' requests, and providing delivery status and usage
- Payments and settlement: selling credits, granting, using and refunding credits, and keeping those records
- Promotions: granting signup bonus and referral program free credits, preventing duplicate or fraudulent claims, and sending expiry reminders
- Support: reviewing inquiries, investigating, and replying
- Security and reliability: limiting sign-in requests, responding to incidents, preventing security incidents, and meeting legal obligations
2. Personal information processed and how it is collected
The Company does not collect resident registration numbers or other unique identifiers, sensitive information, or passwords.
- Sign-up and sign-in (entered by the member in the console)
- Required: email address, name (set from the part of the email address before the @ when the account is created; the member can change it)
- Optional: profile image, passkeys (the public key created by the device and authenticator details; fingerprints, face data and other biometrics stay on the member's device and are never sent to the Company)
- Sign-in credentials: the token of the sign-in link and the 6-digit sign-in code sent by email. They are stored only as hashes and can be used once within 15 minutes. Code records are keyed by a hash of the email address instead of the address.
- Session data: session token, IP address, browser details (User-Agent), session creation and expiry time, last used organization
- Organizations and use of the Service (entered by members or created while using the Service)
- Organization name and URL (slug), organization logo (optional), members and their roles, email addresses of invited people (entered by the inviting member)
- App names, API key details (the key itself is not stored; only its hash and its first and last few characters for display), allowed origins and rate limit settings per key
- Notifications and notification preferences, language
- Credit payments (created during payment or received from the payment provider)
- Payment method details (such as card numbers) are entered by the member directly on the payment provider's (Polar's) checkout page; the Company never receives or stores them.
- Sent by the Company to the payment provider: the paying member's email address, and organization, member and credit pack identifiers
- Stored by the Company: the payment provider's order number and customer identifier, product, amount and currency, payment time, the paying member and organization, refunds (amount, reason, status and who handled it)
- Credit ledger: records of credits granted, used, clawed back on refunds, and free credits granted and expired, per organization
- Free credits and the referral program (created while using the Service)
- Preventing duplicate or fraudulent signup bonuses: a hash (HMAC) of the normalized (e.g. lower-cased) email address, a hash (HMAC) of the sign-up request's IP address range (/24 for IPv4, /48 for IPv6), and the email domain. The email address and IP address themselves are not stored separately for this purpose.
- Referral program: each organization's referral code, accounts that signed up through a referral link and when the link was visited, a hash (HMAC) of the IP address range at sign-up, the referring and referred organizations, and decisions to grant, refuse or take back rewards. To detect self-referrals, the session IP address ranges of the two organizations' owners are compared; no IP address is stored beyond the result.
- Records of free credit expiry reminders (number of recipients)
- Support inquiries (provided by the person by email)
- Name, email address, the inquiry and anything sent with it
- Information generated or collected automatically
- IP address, access time, browser details, cookies (Section 11), request paths, response statuses, errors and other usage logs
- Sign-in rate limit records: counts per IP address and request path, and counts of sign-in emails and failed codes per hash of the email address
Personal information of Customers' end users (Customers being members who use the API) is described separately in Section 4.
3. Processing and retention periods
The Company processes and keeps personal information within the period set by law or consented to by the data subject, and destroys it without delay once that period ends or the purpose is fulfilled.
- Member information (Section 2, items 1 and 2): until the account is deleted
- Sign-in links and codes: 15 minutes after they are sent (they stop working once used)
- Sessions: at most 30 days. Sessions are deleted on sign-out, and the remaining session records are deleted with the account.
- Organization information: until the organization is deleted. App and API key records are not deleted but kept as revoked, so they still match the credit usage records; when a member deletes their account, the records are unlinked from that member.
- Payment and refund records and the credit ledger (Section 2, item 3): 5 years. When a member deletes their account, the records are unlinked from that member and kept for the period required by law. Records past their retention period are destroyed without delay.
- Signup bonus abuse-prevention hashes (Section 2, item 4): 2 years from the day the grant record is created. They are kept for that period even after the account is deleted, to prevent the same person from claiming twice, and then deleted.
- Referral program records (Section 2, item 4): the record of a sign-up through a referral link (including the IP address range hash) is kept until the account is deleted. Reward decisions are kept as records of free credits granted and taken back, and are unlinked from a member who deletes their account.
- Support inquiry records (Section 2, item 5): 3 years
- Sign-in rate limit records: deleted once the limit window (at most 24 hours) has passed
The following are kept for the periods required by law:
- Records of contracts and withdrawals of offers: 5 years (Act on the Consumer Protection in Electronic Commerce)
- Records of payments and supply of goods: 5 years (same Act)
- Records of consumer complaints and dispute resolution: 3 years (same Act)
- Service access records (logs, access location information): 3 months (Protection of Communications Secrets Act)
4. Personal information of Customers' end users
When a Customer asks the OTP API to send a code, the Company processes personal information of the users of the Customer's service ("end users") on the Customer's behalf. The Customer is the controller of this information; the Company is a processor and processes it only as needed to carry out the Customer's requests.
- Items: the end user's mobile phone number, the code, the message content, metadata the Customer puts in the request, and the IP address of the device that calls the API (used only for rate limiting)
- How it is processed
- Code issue records store only a hash (HMAC) of the phone number, never the number itself.
- Codes are stored only as hashes and are never returned by the API or shown in the console.
- The recipient and sender numbers and metadata of delivery records are stored encrypted, together with a hash and a partly masked value for lookups. About 24 hours after a delivery reaches a final status (delivered, failed, cancelled, unknown), the recipient and sender numbers, their hashes, encrypted and masked values, and metadata outside the allow list are deleted. Delivery status, times, delivery route and identifiers are kept for settlement and incident investigation.
- Rate limits are counted only on hashes (HMAC) of phone numbers and IP addresses; the originals are not stored.
- Phone numbers and message content are sent to the SMS and AlimTalk delivery provider (Section 6) for delivery.
- Retention: number data in delivery records is deleted as described in item 2. Code issue records (including the phone number hash) are kept for one year from issue for credit settlement and usage reporting, then destroyed. Credit amounts used remain separately in the credit ledger described in Section 3, item 2.
- End users should send requests to access, correct or delete their information to the Customer that runs the service. Requests sent to the Company are forwarded to the Customer, and the Company helps the Customer respond.
5. Provision to third parties
The Company provides personal information to third parties only in the cases set out in Articles 17 and 18 of PIPA, such as with the data subject's consent or where a law specifically requires it.
Personal information currently provided to third parties: None
6. Processors
The Company entrusts the following processing to provide the Service:
- Smileserv Inc. (IWINV): sending SMS and KakaoTalk AlimTalk messages at Customers' requests
- Cloudflare, Inc.: hosting and content delivery (CDN) of the website, console and API, serverless runtime (Workers), message queues and state storage for delivery processing (Queues, Durable Objects), storage of profile images and organization logos (R2), database connections (Hyperdrive), service logs
- Smileserv Inc. (IWINV): the server environment of the database that stores member, payment and delivery records (Republic of Korea)
- Polar Software Inc.: processing credit payments (including collecting payment method details) and refunds
- Email delivery: sign-in emails, invitations, notifications and free credit expiry reminders are sent from a mail system the Company operates itself. If this is entrusted to an outside provider, this Policy will be amended and announced.
Under Article 26 of PIPA, the Company's processing agreements set out in writing that processors may not process information beyond the entrusted work, must take technical and managerial safeguards, may subcontract only with restrictions, are supervised by the Company, and are liable for damages, among other things; the Company supervises their processing. Any change to the entrusted work or the processors is published in this Privacy Policy without delay.
7. International transfers
To provide the Service (perform the contract), the Company transfers personal information abroad under Article 28-8(1)(3) of PIPA as follows:
- Cloudflare, Inc.
- Contact: dpo@cloudflare.com
- Countries: the United States (headquarters) and Cloudflare's data centers worldwide. Profile images and organization logos are stored in the Asia-Pacific region.
- When and how: over the network whenever the Service is used
- Items: the personal information in Section 2 that is carried in requests to the Service (email address, name, IP address, browser details, cookies, usage logs, profile images and organization logos, etc.), and end users' phone numbers and message content entrusted by Customers (while a delivery is processed)
- Purpose: the work entrusted in Section 6 (hosting, content delivery, serverless runtime, message queues, file storage, service logs)
- Retention: the periods in Sections 3 and 4, or until the processing agreement ends
- Polar Software Inc.
- Contact: privacy@polar.sh
- Countries: the United States and other countries where Polar stores information
- When and how: over the network when the member starts a credit purchase
- Items: the paying member's email address, organization, member and credit pack identifiers, and the payment method and billing details the member enters on Polar's checkout page
- Purpose: processing credit payments and refunds
- Retention: until the payment purpose is fulfilled or the processing agreement ends (or for any period the law requires)
To refuse these transfers, delete your account (Cloudflare) or do not buy credits (Polar). The whole Service runs on Cloudflare, so refusing the transfer to Cloudflare means the Service cannot be used; refusing the transfer to Polar means paid credits cannot be bought. Questions about refusing a transfer can be sent to the contact in Section 12.
8. Destruction
- Procedure: personal information whose retention period has ended or whose purpose has been fulfilled is destroyed without delay. Information that must be kept under law is stored and managed separately from other personal information.
- Method: electronic information is destroyed so that it cannot be restored, such as by deleting it from the database; paper documents are shredded or incinerated.
9. Rights of data subjects and legal representatives
- Data subjects may at any time ask the Company to access, correct, delete or stop processing their personal information, or withdraw consent.
- In the console: under General in the account settings (app.k-otp.dev/settings/general) you can change your name, email address, profile image and language, and delete your account. When you ask to delete your account, a confirmation link is emailed to you; the account is deleted when you open that link in the same browser within one hour. Organization details can be changed in the organization settings. An organization that has apps, a credit balance or payments cannot be deleted in the console; ask by email instead.
- Other requests can be made by email (support@k-otp.dev) or in writing, and the Company acts on them without delay (access requests within 10 days).
- Rights can also be exercised through a representative, such as a legal representative or a person authorized by the data subject, who must submit a power of attorney.
- Information that the law requires to be kept cannot be deleted on request, and access or suspension requests may be limited in the cases set by law, such as where they could infringe the rights of others.
- The Company verifies that the person making a request is the data subject or a legitimate representative.
10. Safeguards
The Company takes the following measures to keep personal information secure:
- Managerial: the people who can access personal information and their permissions are kept to a minimum, and database accounts are separated by purpose so that each account reaches only the data it needs.
- Technical
- No passwords are used. Sign-in links and codes are stored only as hashes, expire after 15 minutes and work once. Failed codes and sign-in email requests are limited per IP address and per email address.
- API keys are stored only as hashes; the key itself is shown once when it is issued.
- Code issue records store end users' phone numbers and codes only as hashes; number data in delivery records is stored encrypted and deleted as described in Section 4.
- Email addresses and IP address ranges used to prevent abuse are stored only as hashes (HMAC).
- Traffic to the website, console and API is encrypted with TLS. The database has no port open to the internet and is reached only through an encrypted tunnel over TLS.
- Payment method details are handled by the payment provider and never stored by the Company.
- Physical: physical access to servers and data centers is controlled by the processors in Section 6.
11. Cookies
The Company uses cookies to store information the Service needs. A cookie is a small text file a website stores in your browser. The Company does not use cookies for analytics or advertising.
- Website (k-otp.dev)
consent: your answer to the cookie notice (30 days)locale_banner_seen: whether you answered the language suggestion (1 year)
- Console (app.k-otp.dev)
better-auth.session_token(with the__Secure-prefix over HTTPS): keeps you signed in (up to 30 days)better-auth-passkey: checks a passkey registration or sign-in in progress (only during that step)kotp_sign_in_request: tells whether the browser that opens a sign-in link is the one that asked for it (15 minutes)kotp_ref: the referral code and visit time from a referral link, to credit the referral at sign-up (30 days)NEXT_LOCALE: language of the console and its emails (1 year)locale_banner_seen: whether you answered the language suggestion (1 year)sidebar-collapsed: whether the sidebar is collapsed (1 year)- Your color theme (light or dark) is kept in browser storage (localStorage).
You can refuse or delete cookies in your browser settings. Without cookies, parts of the Service, such as signing in to the console, will not work.
12. Privacy officer
The Company has designated the following privacy officer, who oversees personal information processing and handles complaints and remedies. Requests to access personal information are also received and handled at this contact.
- Name: Jungrae Kim (김정래)
- Title: Personal Information Officer (개인정보처리담당자)
- Email: support@k-otp.dev
- Phone: +82-2-877-1990
Company: 1990Company, CEO Jungrae Kim (김정래), business registration number 163-31-01584, 601, 7, Cheonjung 1-gil, Dongnam-gu, Cheonan-si, Chungcheongnam-do, South Korea (충청남도 천안시 동남구 천정1길 7, 601), phone +82-2-877-1990, email support@k-otp.dev
13. Remedies
Data subjects may apply for dispute resolution or counseling about infringements of their personal information to the following bodies:
- Personal Information Dispute Mediation Committee: 1833-6972 (in Korea), www.kopico.go.kr
- Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (in Korea), privacy.kisa.or.kr
- Supreme Prosecutors' Office: 1301 (in Korea), www.spo.go.kr
- Korean National Police Agency: 182 (in Korea), ecrm.police.go.kr
14. Changes
This Privacy Policy applies from 2026-10-02. Additions, deletions or changes are announced on the website at least 7 days before they take effect, and changes important to data subjects' rights, such as changes to the items collected or the purposes of use, at least 30 days before.