This Privacy Policy explains how Zero to One Flow (021flow) collects, uses, shares, and protects personal information when you use OurVerse.
1. Data Controller
Trade Name
Zero to One Flow (021flow)
Representative
Sungtae Ryu
Data Protection Officer
Sungtae Ryu (Representative)
2. Personal Information We Collect
- Account information: email, name or nickname, login identifier
- Authentication information: social login provider identifiers, token-related metadata
- Payment-related information: payment status, subscription plan, billing dates, receipt/order identifiers, Paddle customer ID or transaction ID
- Service usage information: access logs, IP address, browser/device information, usage, error logs
- Customer support information: inquiry content, email, attachments, support records
- Cookies and similar technologies
- Content or files you input into the service, where applicable
We do not directly store sensitive payment instrument data such as card numbers or CVC; such data is handled by Paddle and its payment processors.
3. Purposes of Use
- Account registration and management
- Providing the service
- Verifying paid plan and subscription status
- Payment, billing, refunds, and tax/accounting processing
- Customer support and notices
- Security, fraud prevention, and incident response
- Service improvement, statistics, and analytics
- Compliance with legal obligations
4. Sharing & Processing by Third Parties
| Recipient / Processor | Data | Purpose | Retention | Cross-border |
|---|---|---|---|---|
| Paddle.com | Payment/order data, email | Payment processing, tax, receipts, refunds, billing support | Per Paddle policy | Yes |
| Amazon Web Services, Inc. (AWS) | Service/usage data, logs | Cloud hosting, content delivery, operation | Until end of the outsourcing contract | Yes |
| Google LLC (Google Analytics, Firebase Analytics) | Usage, device, log data | Analytics and service improvement | Up to 14 months | Yes |
| Google LLC / Apple Inc. (social sign-in) | Login identifiers (OAuth) | Authentication | Until account deletion or per provider policy | Yes |
| MongoDB, Inc. (MongoDB Atlas) | Account, content data | Database hosting and storage | Until account deletion or end of the outsourcing contract | Yes |
5. Cross-Border Transfers
Because we use overseas providers (e.g., Paddle, cloud, AI APIs, analytics), some personal information may be transferred and processed outside the Republic of Korea. For each provider we will disclose: recipient, country, items transferred, purpose, timing/method, retention/use period, and how to refuse (and the effect of refusing).
The recipients, items, purposes, and retention periods are as listed in the table in Section 4. Transfers occur over encrypted networks at the time you use the service. You may refuse cross-border transfers by contacting us at the email above; however, refusal may make it impossible to provide part or all of the service.
6. Retention Period
- We delete personal information without undue delay upon account withdrawal.
- Records on contracts and withdrawal of offers, and records on payment and supply of goods/services: 5 years (Act on Consumer Protection in Electronic Commerce).
- Records on consumer complaints and dispute resolution: 3 years (same Act).
- Records on display and advertising: 6 months (same Act).
- Website access logs: 3 months (Protection of Communications Secrets Act).
- Analytics data (Google Analytics): retained up to 14 months.
- Backup data is deleted within 30 days.
- A minimal set of records may be retained to prevent fraud and abuse.
7. Your Rights
- Access, correction, deletion, and suspension of processing
- Withdrawal of consent and account withdrawal
- Requests can be made at [email protected]
8. Cookies
- We use cookies to keep you signed in, remember preferences, and understand usage.
- We distinguish essential cookies from analytics cookies. Essential storage (sign-in, learning progress) works regardless of your choice.
- Analytics tools load only after you agree in the consent banner. Until then they are not loaded at all, and they are never loaded inside the children's Explore screen unless consent was already given.
- You can change or withdraw your choice at any time via “Cookie settings” in the footer, or refuse cookies in your browser settings.
9. Security Measures
- Access control and least-privilege permissions
- Encryption in transit and at rest where appropriate
- Logging and monitoring
- Backups and security updates
- Administrative access controls
10. Children's Privacy
OurVerse is an educational service that may be used by children, typically with a parent's or guardian's involvement. Where a child is below the age of consent under applicable law (e.g., under 14 in Korea), account creation and payment should be carried out by a parent or legal guardian.
We do not knowingly collect personal information directly from children under 14. Accounts and payments must be created and made by a person aged 14 or older, such as a parent or legal guardian. If we learn that personal information of a child under 14 has been collected without the required legal guardian's consent, we will delete it without undue delay.
11. Changes to This Policy
We will announce material changes to this policy in advance through the service, and the effective date is shown at the bottom of this page.
Effective Date: July 24, 2026