Selfaria
Privacy Policy
Effective date: 2026-06-16
Woori Creative ("the Company") complies with the Korean Personal Information Protection Act and related laws and treats your personal information with care. Selfaria ("the Service") offers free personality tests and a free BaZi (Four Pillars) chart that require no login, scoring your survey answers or calculating your entered birth date and time on the Company's own server using fixed rules. A social sign-in is required only for paid features (topping up and using tickets for features such as 'AI compatibility analysis', 'AI deep report', and 'AI BaZi reading'); the items collected in that case are described in Section 1 below. The Company processes only the minimum information needed to provide the Service, and survey scoring or BaZi chart calculation itself does not transmit your information to any external artificial intelligence (AI). Only when you yourself request and consent to the 'AI compatibility analysis', 'AI deep report', or 'AI BaZi reading' feature does the Company transmit the information needed for the analysis to an external AI provider; the specific items, processor, and overseas transfer are described in Section 5 below.
1. Personal Information Collected and How
- Survey answers: the numeric score you choose for each item. We do not collect identifying information such as your name or contact details; answers are processed only as numbers.
- BaZi birth date and time (if you use the BaZi chart feature): the birth date and time (solar or lunar) and gender you enter yourself, and the birthplace longitude you may optionally enter. The BaZi chart calculated from this (pillars, elements, Ten Gods, luck cycle, etc.) is used only to process your request and to store your 'AI BaZi reading' result, with no separate sign-up or identity verification required.
- Access code: a random code issued so you can save and re-view your progress. Only a one-way hash of the code — not the code itself — is stored on the server, so the stored value cannot be reversed back into the code.
- Nickname: a display name you choose when your access code is issued (e.g. 'Alex'). It does not need to be your real name and is used only to label you in your Keep and as the name for each person in 'AI compatibility analysis' results. It does not identify you unless you enter identifying information yourself.
- Social account information (only if you sign in): if you sign in with Google or Kakao to use paid features, the Company receives the account's unique identifier and display name from that provider, and your email address if you consent. If you only use the free tests, no social account information is collected at all.
- Automatically collected data: your access IP address and usage records (access time, processing time, success/failure, and similar metadata). This is used to prevent abuse and to address errors; the specific content of your answers is not logged.
2. Purpose of Use
- Rule-based scoring of survey answers and delivery of results (type, index, report)
- Providing 'AI compatibility analysis' based on two people's results when you yourself request and consent to it (including the outsourcing and overseas transfer described in Section 5)
- Providing an 'AI deep report' based on your own results and answers when you yourself request and consent to it (including the outsourcing and overseas transfer described in Section 5)
- Providing an 'AI BaZi reading' based on the BaZi chart calculated from your entered birth date and time when you yourself request and consent to it (including the outsourcing and overseas transfer described in Section 5)
- Using the nickname you set at issuance to label your Keep and to name each person in 'AI compatibility analysis' results (each person's nickname comes from their own access code)
- Storing the 'AI compatibility analysis' result and both nicknames in both the requester's and the partner's Keep so that both sides can view it again
- Resuming progress and re-viewing results via the access code
- Identifying paid-feature users via their social account, attributing ticket purchases to the account, restoring the access code on other devices, and providing account features such as nickname changes
- Preventing abuse and excessive traffic (IP-based usage limits)
- Understanding service operations and handling errors (statistics that cannot identify content)
3. Retention and Use Period
The Company destroys information without delay once its purpose is achieved. Retention periods by item are as follows.
- Survey answers, results, access-code hash, and nickname: automatically deleted after 90 days with no use, counted from the last time the access code is used (each use renews the period to 90 days). The nickname is stored with the access code and is deleted along with it. One-off responses taken without an access code are deleted 90 days after issuance. A lost access code cannot be recovered.
- AI compatibility analysis and AI deep report results and the nicknames shown in them: automatically deleted after 90 days with no use from creation (for compatibility analysis, this applies to both the requester's and the partner's Keep), and deleted along with the related access code when it is deleted.
- BaZi chart and AI BaZi reading results: automatically deleted after 90 days with no use from creation, and deleted along with the related access code when it is deleted.
- Social account information (account identifier, display name, email): retained until you request account deletion, then destroyed without delay. Sign-in sessions are deleted automatically 90 days after last use.
- IP-based usage counts: about 2 days (the period needed to run usage limits)
- Access and error logs: kept only as long as needed for operations and security, then deleted
4. Provision to Third Parties
The Company does not provide your personal information to outside parties. It may do so only where specifically required by law, or where an investigative agency requests it through lawful procedures.
5. Outsourcing and Overseas Transfer
The Company performs most processing, including regular survey scoring, directly on servers it operates, without outsourcing it or transferring it overseas.
Only when you yourself request and consent to the 'AI compatibility analysis', 'AI deep report', or 'AI BaZi reading' feature does the Company outsource processing and transfer data overseas as follows, in order to generate the analysis.
- Processor (recipient): Anthropic, PBC (United States)
- Outsourced work and purpose: generating the compatibility analysis text based on two people's survey results (for the 'AI deep report,' generating the report text based on the requester's own survey results and answers only; for the 'AI BaZi reading,' generating the reading text based only on the BaZi chart calculated from your entered birth date and time)
- Items transferred: type codes, per-axis scores (numbers), and the answer values of some items (numbers). No information that can identify you — such as names, contact details, or access codes — is transmitted.
- Destination, timing, and method: to the United States, over encrypted transport (HTTPS), at the moment you run the feature.
- Recipient's retention and use period: the period needed to process the analysis request (data may be retained for a certain period under the processor's policy). The processor states that data sent via its API is not used to train its AI models.
You may refuse this overseas transfer by not using the 'AI compatibility analysis', 'AI deep report', and 'AI BaZi reading' features; all other features of the Service, such as regular scoring, viewing results, and the free BaZi chart, remain fully available.
If additional outsourcing or overseas transfer later arises (for example, from introducing advertising or analytics tools), the Company will reflect the recipient and the scope of work in this policy and give notice in advance.
6. Your Rights and How to Exercise Them
You may request access to, correction of, deletion of, or suspension of processing of your personal information at woolee.dev@gmail.com. Because the Company collects no identifying information, a given set of answers can only be located via its access code; without the access code, individual answers cannot be identified or deleted.
7. Destruction of Personal Information
Information past its retention period is deleted through automated procedures in a manner that cannot be recovered. The access-code hash and answers are destroyed automatically once 90 days have passed since their last use.
8. Security Measures
- Encryption in transit (HTTPS)
- One-way hash storage of the access code (the original is not stored). Only for access codes linked to a social account, an encrypted copy of the code is kept to allow restoring it on other devices; the encryption key is stored separately from the database, so a database leak alone cannot decrypt it.
- One-way hash storage of sign-in session tokens (originals are not stored)
- No collection of identifying information; answers handled only as numbers
- Least-privilege access and usage limits to prevent abuse
9. Cookies and Automatic Collection
The Service uses no advertising cookies or analytics tools to track users. Essential cookies (httpOnly) are used to keep your access code and, for paid features, your sign-in session; they are used for authentication only. The Service may use your browser's temporary storage (sessionStorage) to briefly display results; this disappears when the browser closes and is not sent to the server.
If third-party services such as advertising (e.g., Google AdSense) are introduced in the future, those services may use cookies or identifiers; at that point this policy will be updated and notice given.
10. Privacy Officer
For inquiries, complaints, or remedies regarding the handling of personal information, please contact:
- Privacy Officer: operator of Selfaria
- Email: woolee.dev@gmail.com
11. Remedies for Rights Infringement
If you need advice or to report a personal-information infringement, you may contact the following Korean authorities.
- Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- Privacy Infringement Report Center (privacy.kisa.or.kr / 118)
- Supreme Prosecutors' Office Cybercrime (spo.go.kr / 1301), National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)
12. Duty of Notice
If this policy changes, notice will be given within the Service from 7 days before the effective date (30 days before for changes that materially affect user rights).
