Privacy Policy
H&G Partners Co., Ltd.(the “Company”) complies with the Personal Information Protection Act and other applicable law, and uses this Policy to explain what information IdleLink (the “Service”) processes, why, and how it is protected.
This English text is an unofficial translation provided for convenience. The Korean version is the binding original, and where the two differ the Korean prevails. This Policy takes effect at public launch; the effective date and the itemised retention periods will be fixed and posted here at that time. The Service is currently in a limited trial among acquaintances.
1. General — local-first by design
The Service is designed local-first: as a matter of principle the user’s content — files, remote screens, messages — moves only between the user’s own devicesand is not stored on the Company’s servers. Some connection and diagnostic information is processed on the Company’s servers for account management, device linking and error diagnosis; those items are listed in full in Article 2. The Service is intended for users aged 14 and over, and where the law of the user’s country of residence sets a higher minimum age for consent to the processing of personal data, that age applies (13 to 16 across the EEA depending on the country; 13 in the United States).
2. Personal information collected
- Account information(when account features are used): the email address and profile name provided through social sign-in.
- Beta application information(when applying for the beta): the applicant’s email address (before any account exists), the connecting IP address, verification metadata used to block automated sign-ups, and the double opt-in confirmation status and time.
- Device and connection information: device name, anonymous device identifier, the connection address assigned by the Company, group identifier, app version, connection time and recent online status.
- Remote-control readiness diagnostics(when remote control is used): encoder and session state, screen-transmission readiness values, connection diagnostics, and the device’s local network (LAN) IP address.
- Error diagnostics(installed builds only, and can be switched off in settings): error type, error messages and technical logs with certain identifying details masked, app version, anonymous device identifier, and the device name and account email address associated with that identifier.
Before transmission, the account name contained in user folder paths, IPv4 addresses, and certain tokens and invite codes issued by IdleLink are masked automatically. - Local storage: browser storage (localStorage) used to keep you signed in and to retain app settings — display name, avatar and settings are stored only on the user’s device.
3. What is not collected
The Company neither collects nor reads the contents of files, photos and videos, remote-control screens, or the body of messages. Where a direct connection between devices is not possible and a relay server is used, this content passes through encrypted and is not retained on the server afterwards.
4. Purposes of processing
The information collected is used only to establish and broker connections between devices, to manage accounts and verify identity, to provide the Service and respond to incidents, to analyse errors and improve quality, to diagnose remote-control connection state, and to notify users of important matters.
5. Retention and destruction
Device and connection information and remote-control diagnostics are overwritten with current values on the next connection, and are destroyed when the device leaves the group or the member withdraws. Account information is retained until withdrawal. Error diagnostics are destroyed within 180 days of collection. Beta applications that never complete email confirmation are destroyed without delay once the confirmation link expires (7 days from application); the email address of a confirmed applicant is retained until the beta ends or the account is converted to the live service or withdrawn. Where other law requires retention, the data is stored separately for that period. Itemised retention periods will be fixed and posted at public launch.
6. Processing entrusted to others, and transfers abroad
The Company entrusts hosting of its relay, connection and account servers to Amazon Web Services, Inc., and the processing and storage of core personal information such as account, device and connection data takes place domestically (AWS Seoul region).
However, beta application (email registration) and the operation of the Service involve the transfers abroad set out below. These are necessary to perform the contract with the user (participation in the beta); accordingly, under Article 28-8(1)3 and Article 28-8(2) of the Personal Information Protection Act, the following is disclosed rather than separately consented to. If you do not agree to transfer abroad, you may choose not to use the beta application feature.
Resend, Inc. (United States)
- Recipient and contact: Resend, Inc. · [email protected]
- Items transferred: the beta applicant’s email address, and logs of email sending, delivery, bounce and receipt status
- Purpose of transfer: sending transactional email such as beta confirmation and invite codes
- Country, timing and method: United States (Resend, Inc.), with the data-processing region in Japan (Tokyo). Transmitted over an HTTPS API at the time of application and sending
- Retention and use period: until the sending purpose is fulfilled or the processing agreement ends
Cloudflare, Inc. (United States · global edge)
- Recipient and contact: Cloudflare, Inc. · [email protected]
- Items transferred: connecting IP address, Turnstile verification tokens and metadata used to block automated sign-ups, and HTTP request information
- Purpose of transfer: website hosting, prevention of fraudulent sign-ups, and routing of enquiry email
- Country, timing and method: United States and the global edge network, processed at the edge whenever a request or verification occurs
- Retention and use period: until the processing agreement ends or the log retention period elapses
Additional technical information — STUN lookups of your public IP for connection optimisation, weather lookups and the like — may also be passed to services abroad, as set out in Article 7. Any change to entrusted processing or transfers abroad will be disclosed in advance through this Policy.
7. Provision to third parties, and external technical services
The Company does not sell or provide users’ personal information to third parties. The following transfers do occur as a consequence of how the Service works.
- When a connection is established between devices, whether direct or relayed, the user’s device name and IP address are passed to the other device (only to a party in the same group or connected by invitation).
- If same-network discovery is enabled, the device name may be advertised to other devices on that network; the feature can be switched off in settings.
- To optimise connections, the public IP address is briefly sent to STUN servers, which exist only to report it. Since 2 August 2026 the Company operates its own STUN serverand uses it first, with a Cloudflare STUN server used alongside it for the comparison needed to determine the NAT type. These servers answer public-IP lookups only and do not relay content such as screens or files.
- If the weather widget is used, location information and IP are passed to an external service for weather and place-name lookup (an optional feature).
- Cloudflare Turnstile is used during beta application to block automated sign-ups, and the connecting IP and verification token are passed to Cloudflare (see the transfers abroad in Article 6).
8. Automatic collection, and how to refuse it
The Service uses browser storage on the user’s device to keep you signed in and to retain app settings. Users may refuse or delete this by clearing it in the app or browser settings; doing so resets the signed-in state and personal settings. Automatic sending of error diagnostics can be switched off at any time on the settings screen of an installed build.
9. Rights of users and legal representatives
Users may at any time request access to, correction or deletion of, or suspension of the processing of their personal information, or withdraw consent. The legal representative of a child under 14 may exercise these rights on the child’s behalf. Requests may be made to the privacy officer named below, and the Company will act on them without delay.
10. Security measures
The Company applies encryption in transit, an encryption option for backup data, access control on its servers, and retention and review of access logs. It also applies data-minimisation before error diagnostics are sent, automatically masking the account name contained in user folder paths, IPv4 addresses, and certain tokens and invite codes issued by IdleLink. On becoming aware of a breach of personal information, the Company notifies and reports it without delay in accordance with applicable law.
11. Privacy officer and remedies
Privacy officer: JAE HWA HONG · contact: [email protected]
Reports and enquiries about infringement of personal information may be made to the Personal Information Dispute Mediation Committee (1833-6972), the Privacy Infringement Report Centre (118),
the Supreme Prosecutors’ Office (1301) or the National Police Agency (182).
H&G Partners Co., Ltd. · CEO JAE HWA HONG · Business reg. 466-86-01862
Room 732, 11, Gukjegeumyung-ro 8-gil, Yeongdeungpo-gu, Seoul, Republic of Korea · [email protected]