Privacy
Privacy Policy
Last updated: September 28, 2026
1. General Provisions
Waytive (hereinafter the “Company”) establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
This Policy applies to the website operated by the Company (waytive.ai), the account service (app.waytive.ai), the macOS desktop apps Waytive Warp, Waytive Shot, and Waytive X, and related inquiry and customer-support channels.
The Company's services provide both features processed only on the user's device and features that pass through the Company's servers. Where personal information is processed for each feature is explained separately in Article 8 and Article 9.
2. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. The personal information processed is not used for any purpose other than the following, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
- Confirming the intent to register as a member, identifying and authenticating users, maintaining and managing membership, and preventing unauthorized use of the service
- Providing the service, providing content, and synchronizing user settings and stored data
- Applying for, paying for, and settling paid subscriptions, processing withdrawals and refunds, and issuing tax invoices and performing accounting
- Receiving customer inquiries and notifying processing results, and delivering notices
- Service usage statistics and quality improvement, and development of new features
- Retention of access logs, and detection of and response to unauthorized use and security incidents
- Fulfillment of statutory obligations and handling of disputes
3. Categories of Personal Information Processed
The Company processes the minimum personal information necessary to provide the service.
- Membership registration and account management — email address, password (stored in encrypted form), user identifier, account identification information received from the relevant provider when social login is used, email verification status, and subscription tier
- Paid subscriptions and payments — plan, subscription status, renewal date, payment amount and currency, order and payment identifiers, payment result, refund and cancellation status, and billing email address. The Company does not collect or store the original numbers of payment instruments, such as credit card numbers, card expiration dates, or CVCs.
- Customer inquiries — name, email address, inquiry content, access IP address and country, processing history, and materials attached by the user
- Information automatically generated and collected in the course of using the service — access IP address, access date and time, service usage records, browser and operating system information, information for device identification, authentication and session records, and error and usage records
- Content the user stores in the service — settings and data registered directly by the user, such as a user dictionary
- Voice and screen data — as set forth in Article 8.
The Company does not collect sensitive information concerning ideology or beliefs, political opinions, health, sex life, or the like, or resident registration numbers.
4. Processing and Retention Periods
The Company processes and retains personal information within the retention and use period prescribed by law or the retention and use period consented to by the data subject at the time the personal information is collected.
- Member information — until membership withdrawal. However, where necessary to prevent unauthorized use, handle disputes, or fulfill statutory obligations, the information is retained until the relevant grounds cease.
- Customer inquiry records — 3 years after completion of inquiry handling
- Access logs — 3 months in accordance with the Protection of Communications Secrets Act
In accordance with the Act on Consumer Protection in Electronic Commerce and its Enforcement Decree, the Company retains the following transaction records for the periods prescribed by law.
- Records of contracts or withdrawal of offers, etc.: 5 years
- Records of payment and of the supply of goods, etc.: 5 years
- Records of consumer complaints or dispute handling: 3 years
Records whose retention period has expired are destroyed without delay. However, if another law requires a longer retention period, the records are retained until the period prescribed by that law. Original numbers of payment instruments are not retained by the Company and are therefore not included in the records subject to the retention above.
5. Provision of Personal Information to Third Parties
The Company processes the personal information of data subjects only within the scope specified in Article 2, and provides personal information to third parties only when it has obtained the data subject's consent or when Article 17 and Article 18 of the Personal Information Protection Act apply.
Payments through Paddle. When paid checkout launches, Paddle is the Merchant of Record for Waytive Pro. You enter your email, billing address and payment details directly in Paddle Checkout. Waytive and Paddle exchange customer, transaction and subscription identifiers, billing periods, amounts, currencies and processing results necessary to provide subscriptions and handle payments, cancellations and refunds. Waytive does not store card numbers or CVCs. Paddle processes buyer information under its own privacy policy. See Paddle’s privacy policy for its processing purposes, international transfers, retention and privacy rights.
Installer files and update files for the desktop apps are distributed through GitHub. When a user downloads those files, GitHub may process access information on its own; this is not the Company providing personal information, but the user accessing that business operator's service directly.
6. Entrustment of Personal Information Processing
To provide the service smoothly, the Company entrusts personal information processing as follows in accordance with Article 26 of the Personal Information Protection Act.
- Cloudflare — Entrusted work: website hosting and content delivery, and web analytics that does not use cookies. Entrusted items: access IP address, browser and device information, and access logs
- Supabase — Entrusted work: account authentication and database operation. Entrusted items: account identification information, authentication and session records, and stored data necessary to provide the service
- Resend — Delivery of customer inquiry email; sender name and email, inquiry content, IP address and country included in the message
- Google (Gmail) — Receipt and handling of customer support email forwarded through Cloudflare Email Routing; message contents and sender information
- Render — Entrusted work: application hosting. Entrusted items: access IP address, request logs, and data necessary to provide the service, as processed in the course of using the application
- our voice transcription processor — Entrusted work: cloud speech-transcription processing. Entrusted items: voice data transmitted pursuant to Article 8 and transcription results
Paddle checkout and its processing of buyer information are described in Article 5.
When concluding an entrustment contract, the Company specifies in the contract, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information for purposes other than performing the entrusted work, technical and administrative protective measures, restrictions on re-entrustment, management and supervision of the trustee, and liability including damages, and supervises whether the trustee processes personal information securely.
If the content of the entrusted work or the trustee changes, the Company will disclose it without delay through this Policy.
7. Overseas Transfer of Personal Information
To provide the service, the Company transfers personal information overseas as follows in accordance with Article 28-8 of the Personal Information Protection Act.
- Recipient — Cloudflare, Supabase, Render, Resend, Google (Gmail), our voice transcription processor
- Storage regions and international processing — The production Supabase project’s primary database region is Seoul, South Korea (ap-northeast-2), verified September 22, 2026. This does not mean every Supabase operation, authentication log, support service or subprocessor is confined to Korea. Render application hosting was confirmed in the United States. Cloudflare operates globally; email and other provider processing locations depend on the service and its subprocessors. The primary database location must not be interpreted as the location of all processing
- Time and method of transfer — transmitted at the time of using the service through an information and communications network via encrypted communications
- Items of personal information transferred — the same as the entrusted items for each trustee in Article 6.
- Purpose of use by the recipient — the same as the entrusted work for each trustee in Article 6.
- Retention and use period of the recipient — until the termination of the entrustment contract or until the end of the retention period determined by the Company
A data subject may refuse the overseas transfer of personal information. However, because the transfer above is essential to providing the service, refusing the transfer may restrict membership registration and use of the service. Please notify us of any refusal at the contact details in Article 14.
The Company takes protective measures for overseas transfers in accordance with Article 28-8(4) of the Personal Information Protection Act, and stipulates by contract that the recipient process personal information securely and manages and supervises the recipient.
Provider information: Supabase primary regions, Cloudflare international processing, Resend privacy policy. These provider policies explain their processing and do not replace this Company’s disclosure of the services it uses.
8. Processing of Voice and Screen Data
Voice processing in Waytive Warp. Waytive Warp provides two transcription paths, which the user may select in settings.
- Local transcription — processed only on the device using a Whisper model downloaded to the user's device. Voice data is not transmitted to the Company's servers.
- Cloud transcription — voice data is transmitted to the Company's servers through the Waytive Warp API, our voice transcription processor performs the transcription, and the transcribed text is returned. On this path, voice data is transferred overseas, and matters relating thereto follow Article 7.
Voice data transmitted in cloud transcription is processed only to the extent necessary to return the transcription result, and is not retained on the Company's servers after processing.
Screen data in Waytive Shot. Screen images captured by Waytive Shot, edited content, and screen-recording files are stored on the user's device. Unless the user expressly requests it, the Company does not transmit captured screen content to its servers or retain it.
The Company does not use the user's voice data, transcription results, or screen-capture content to train artificial intelligence models.
Waytive X: workspaces, AI connections, and remote access
Local work data. Waytive X stores workspace settings, session and chat history, and provider account metadata on your Mac. Connected tools may read or change files in the workspace you select and send prompts, selected code or files, and tool results to the AI provider or integration you choose. These features are not entirely offline.
Credentials and providers. Waytive account credentials are stored in macOS Keychain. External provider credentials are stored using Keychain or provider-specific local credential files, depending on the connection. They are used to authenticate requests to that provider. The provider's own terms and privacy policy govern its processing, retention, and account deletion; disconnecting it in Waytive X does not cancel its subscription or delete its account.
Optional remote connection. If you enable remote access and pair another device, workspace state, chat or terminal content, and remote commands may pass between your devices through a relay. Relay payloads are encrypted between the paired devices. The relay handles routing identifiers, authentication data, and connection metadata; payload encryption does not hide all connection metadata.
Deletion. Removing an app does not necessarily remove its Application Support files, Keychain entries, or credentials held by external tools. Remove saved connections and local work history you no longer need, and request deletion of data held by an external provider through that provider. Contact support@waytive.ai for help locating Waytive X local data.
9. Desktop App Device Permissions and Local Storage
The desktop apps may request permissions of the macOS operating system in order to perform their functions. Each permission must be granted directly by the user and may be withdrawn at any time in the operating system's settings.
- Microphone — audio input for voice transcription
- Screen Recording — screen capture and screen recording
- Accessibility — entering transcribed text into the app the user is using
The desktop apps store Waytive login information on the device in encrypted form, and store user settings, user dictionaries, downloaded transcription model files, and the like on the device. Local data may remain until the user deletes it separately. Data transmitted through account connections, synchronization, AI, or remote connections is described for each feature and in Article 8.
10. Procedures and Methods for Destroying Personal Information
When personal information becomes unnecessary, such as upon the lapse of the retention period or achievement of the processing purpose, the Company destroys the relevant personal information without delay. However, if the personal information must be preserved under another law, the Company preserves it by transferring it to a separate database or storing it in a different location.
Destruction procedure. The Company selects the personal information for which a ground for destruction has arisen and destroys it after obtaining approval from the Personal Information Protection Officer.
Destruction method. Information in electronic file form is deleted using a technical method that makes recovery and regeneration impossible, and personal information printed on paper is destroyed by shredding or incineration.
11. Rights and Duties of Data Subjects and Legal Representatives, and How to Exercise Them
A data subject may at any time exercise the following rights against the Company.
- Request to access personal information
- Request for correction if there is an error, etc.
- Request for deletion
- Request to suspend processing
- Withdrawal of consent to the processing of personal information
- Refusal of, or request for an explanation of, an automated decision. The Company does not currently make automated decisions that have a legal effect on the data subject or a similarly significant effect.
Rights may be exercised against the Company in writing, by email, or the like, and the Company will take action without delay. Members may directly view or correct personal information, or apply for membership withdrawal, on the account settings screen.
If a data subject requests correction of an error, etc. in personal information, the Company will not use or provide the relevant personal information until the correction is completed.
Rights may also be exercised through an agent, such as the data subject's legal representative or a person who has been delegated. In that case, you must submit the power of attorney in Form No. 11 attached to the Public Notice on the Methods of Processing Personal Information.
Requests to access personal information and to suspend processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act. Requests to correct and delete personal information may not demand deletion where another law specifies that personal information as an item to be collected.
The Company verifies that the person requesting the exercise of rights is the data subject or a duly authorized agent.
12. Installation and Operation of Automatic Collection Devices, and How to Refuse Them
The Company's website (waytive.ai) does not use cookies and does not store information in the browser's local storage or session storage.
The Company uses Cloudflare web analytics to compile website visit statistics. This analytics does not use cookies and does not create fingerprint information that identifies the user, and records only aggregate metrics such as page views, referral paths, country, and browser type. It does not build a profile of an individual user or track activity on other websites.
The account service (app.waytive.ai) uses essential cookies for maintaining login, session security, and prevention of request forgery. These cookies are strictly necessary to provide the service and are not used for advertising purposes. The user may refuse the storage of cookies in the web browser's settings, but in that case the use of features that require login may be restricted.
The Company does not use cookies for advertising networks, cross-site tracking, or affiliate marketing. The desktop apps store settings inside the device, not in browser cookies.
13. Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of personal information.
- Administrative measures — establishment and implementation of an internal management plan, and minimization of and training for personnel who handle personal information
- Technical measures — management of access rights to the personal information processing system, installation of an access-control system, encrypted storage of authentication information such as passwords, encrypted storage of desktop-app login information, encryption of transmission, retention of access logs and prevention of forgery or alteration, and installation and updating of security programs
- Physical measures — access control to systems where personal information is processed. The Company does not operate its own computer room, and uses facilities provided by the trustees in Article 6 for infrastructure.
The Company strives to protect personal information, but there is no method that guarantees complete security for transmission over the Internet and electronic storage.
14. Personal Information Protection Officer and Access Requests
The Company has designated a Personal Information Protection Officer as follows to take overall responsibility for personal information processing and to handle complaints and provide remedies relating to the processing of personal information.
- Personal Information Protection Officer — 전준호 (Junho Jeon)
- Contact — Email support@waytive.ai
A data subject may inquire of the Personal Information Protection Officer about all matters concerning personal information protection inquiries, complaint handling, remedies, and the like that arise while using the Company's services. The Company will respond to and handle the data subject's inquiries without delay.
A data subject may request access to personal information under Article 35 of the Personal Information Protection Act at the contact details above. The Company will endeavor to process the data subject's access request promptly.
15. Remedies for Infringement of Rights
A data subject may apply for dispute resolution or consultation, etc., to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency, and the like, in order to receive a remedy for an infringement of personal information. For other reports and consultations regarding personal information infringement, please contact the following agencies.
- Personal Information Infringement Report Center — (without area code) 118 / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee — 1833-6972 / www.kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation Division — (without area code) 1301 / www.spo.go.kr
- National Police Agency Cyber Investigation Bureau — (without area code) 182 / ecrm.police.go.kr
A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
16. Notice for Users in the European Economic Area and the United Kingdom
The Company is located in the Republic of Korea, and the Company in the Republic of Korea bears responsibility for the processing of personal information. However, personal information may actually be stored and processed on the facilities of overseas trustees in accordance with Article 7.
Transfers of personal information from the European Economic Area (EEA) and the United Kingdom to the Republic of Korea are based on the adequacy decision recognizing the Republic of Korea's level of personal information protection. Accordingly, those transfers do not require separate additional safeguards such as Standard Contractual Clauses. Transfers from the Republic of Korea to a third country follow Article 7.
Users residing in the European Economic Area or the United Kingdom may, as provided by applicable law, request access to, correction of, deletion of, restriction of processing of, portability of, objection to, and withdrawal of consent regarding personal information. These rights may be requested at the contact details in Article 14 or at privacy@waytive.ai.
A user has the right to lodge a complaint with the supervisory authority of the place of residence, place of work, or place where the infringement occurred. A list of European Union supervisory authorities may be found at the European Data Protection Board (edpb.europa.eu), and the supervisory authority of the United Kingdom is the Information Commissioner's Office (ico.org.uk).
17. Personal Information of Children Under the Age of 14
The Company does not provide services directed at children under the age of 14 and does not collect the personal information of children under the age of 14.
If the Company learns that it has collected the personal information of a child under the age of 14 without the consent of a legal representative, it will destroy that personal information without delay in accordance with Article 22-2 of the Personal Information Protection Act.
A legal representative may notify or inquire with us using the contact information in Article 14, and the Company will take the necessary measures after verification and inform the representative of the result.
18. Effective Date and Changes to This Policy
This Privacy Policy applies from September 28, 2026. This revision adds information about Paddle checkout and buyer data processing.
If content is added, deleted, or modified due to changes in law, policy, or security technology, the reason for and content of the change will be announced on the website before the effective date of the change. If a change is disadvantageous to users, it will be announced at least 30 days before the effective date.