Privacy Policy
Effective date: 2026-10-08
CGWEB Inc. ("the Company") complies with applicable privacy laws including the Personal Information Protection Act of Korea, and processes personal information as follows. This policy applies to OnBinder (onbinder.com).
1. Information We Collect
When applying for API access we collect a name (or service name) and email; for social login, the email, name and profile from your Google account; for newsletters, an email address; for revenue-share payouts, settlement account details (bank, account number, account holder) and tax details (resident or alien registration number for individuals; business registration number and trade name for businesses); for content requests, a contact email and the request itself; where a product order occurs, the recipient's name, phone number and delivery address; and, through member activity, your nickname, comments and likes. Access logs, IP address (stored hashed), cookies, referrer and UTM parameters, ad click identifiers, browser and device information (User-Agent) and API call records are generated and collected automatically as you use the service. What we collect when you use Fortune & Saju readings is set out separately in section 13. When you use the mobile app, an installation identifier created by the app, the push notification token, app version, device OS and time zone, notification consent records and app usage events (screen views, reading requests, ad views, purchase starts and so on) are generated and collected; when you sign in with an Apple account, we collect the account identifier and email Apple provides (a relay address if you chose to hide your email) and your name (first sign-in only). Details are in section 14. Resident and alien registration numbers are required for filing payment statements under Articles 164 and 164-3 of the Income Tax Act, and Article 68(3) of the Enforcement Decree of the Framework Act on National Taxes allows withholding agents to process them; resident registration numbers are processed under Article 24-2(1)(1) and alien registration numbers under Article 24(1)(2) of the Personal Information Protection Act.
2. Purpose of Use
Collected information is used only to provide the service (API key issuance, authentication, usage management), process payments and member revenue-sharing settlement (payout transfers, income tax withholding and payment statement filing, receipt of tax invoices), receive and handle content requests, respond to inquiries, send newsletters, serve ads and measure performance, analyze visit/referral statistics for service improvement, and prevent abuse.
3. Retention Period
Personal data is destroyed without delay once the purpose of collection has been achieved. Electronic files are deleted permanently by means that prevent recovery; any printed material is shredded or incinerated. When a member closes their account, the account and activity records are deleted immediately (Fortune & Saju readings are unlinked from the account as described in section 13), and recipient details for product orders are destroyed once delivery, exchange and return handling is complete. Data that the law requires us to keep (records of contracts and withdrawal of subscription for 5 years, payment and supply records for 5 years, consumer complaint and dispute records for 3 years, and similar) is retained for the required period and then destroyed. For revenue-share payouts, the resident registration number and account number are kept for 5 years (Article 85-3 of the Framework Act on National Taxes), and the account holder's name and business details for 10 years (Article 33 of the Commercial Act), counted from the payment statement filing deadline (10 March of the year after payment), and then destroyed; the details of payout requests that are rejected or canceled are destroyed immediately. Registered settlement account and tax details are deleted immediately when a member closes their account; details of payouts requested before closure and still in progress are kept until the payout is completed or rejected and then follow the rules above. In addition, after account closure a one-way hash of the login provider and account identifier is kept for 30 days to prevent abusive re-registration, then destroyed.
4. Processing Delegation and Third-Party Provision
We entrust the following work as needed to run the service: payment processing (Toss Payments), email delivery (Google, Gmail SMTP), spam and automated-request prevention on enquiries and requests (Google reCAPTCHA), visit analytics (Google Analytics) and AI generation of Fortune & Saju readings (OpenAI). For purchases made through Paddle, Paddle acts as Merchant of Record and handles payment data directly. Google AdSense advertising shown on the service is not an entrustment: the advertising provider collects information directly from the user's device, and the items and purposes are described in section 12. Some content also carries embeds of official YouTube, X or Instagram posts. Such an embed is loaded from that platform only when the user taps [Load here] on the page; at that moment the user's IP address and browser information are sent to that platform (Google LLC, X Corp. and Meta Platforms, Inc. respectively, all in the United States) and are handled under that platform's own privacy policy. Nothing - not even a preview image - is sent before the tap, and we do not separately collect user information in this process. We do not otherwise provide personal data to third parties except where required by law (for example, filing payment statements for withheld revenue-share payouts with the National Tax Service under the Income Tax Act). For the mobile app we entrust push notification delivery (Expo - relaying notification tokens and contents through Expo Push Service) and app integrity checks (Google - Firebase App Check). Advertising inside the app (Google AdMob) works like AdSense, with the advertising provider collecting information directly on your device, and is governed by section 12. In-app purchases are processed directly by Apple App Store and Google Play as sellers; the Company receives only the transaction identifier, product, quantity and refund status the store confirms.
5. Cross-Border Transfer
Personal data is transferred abroad as follows. (1) Recipient: Google LLC · Country: United States · Items: email address and message content (email delivery), cookies, device information and access logs (analytics, advertising, spam prevention) · When and how: transmitted over the network at the time the relevant feature is used · Purpose: email delivery, visit analytics, advertising, spam prevention · Retention: per each service's policy. (2) Recipient: Paddle.com Market Ltd · Country: United Kingdom and United States · Items: buyer email and payment/billing information · When and how: transmitted over the network at the time of payment · Purpose: payment processing and tax filing · Retention: the period required by law. (3) Recipient: OpenAI OpCo, LLC · Country: United States · Items: the values a Fortune & Saju reading needs (the calculated stems and branches with the age ranges of the luck cycles; the chosen sign, period, topic and trigram; the hour of birth and gender) and the generated reading text. Your date of birth itself and anything that identifies you, such as your email or IP address, are not sent · When and how: transmitted over the network when the reading is generated · Purpose: AI generation of readings · Retention: per OpenAI's policy. You may refuse these transfers by contacting us through the enquiry page, although the related features (payment, email delivery, readings) may then be unavailable. (4) Recipient: 650 Industries, Inc. (Expo) · Country: United States · Items: push notification token and notification title/body · When and how: sent over the network when a notification is delivered · Purpose: mobile app push notifications · Retention: per Expo's policy. (5) Recipient: Apple Inc. · Country: United States · Items: Apple sign-in account identifier, in-app purchase transaction identifier · When and how: sent over the network at sign-in and payment · Purpose: sign-in verification, payment confirmation and refunds · Retention: per Apple's policy. Transfers to Google LLC (item 1) additionally include Google sign-in verification for the mobile app, Google Play payment confirmation, Firebase App Check and AdMob advertising.
6. Cookies and Analytics
We use cookies for language settings and session management, and may use Google Analytics for service improvement and Google AdSense cookies for serving ads. Interest-based advertising and behavioral information are described in Article 12. You can refuse cookies in your browser settings, in which case some features may be limited.
7. Your Rights
You may request access to, correction or deletion of, or suspension of processing of your personal information at any time. Requests via the contact page or the posted contact details are handled without delay.
8. Security Measures
API keys are stored only as cryptographic digests (the raw key is not stored), sensitive information such as settlement accounts and resident registration numbers is stored encrypted (the full resident registration number is never shown again once registered, except that the withholding receipt shows the date of birth and gender digit, and withholding tax filing data can be downloaded only by authorized administrators, with each download logged), transport is encrypted with HTTPS, and access to personal information is limited to the minimum necessary personnel.
9. Privacy Officer and Notices
The privacy officer is the representative of the Company and can be reached via the contact page. Changes to this policy are announced on the Service 7 days before taking effect. If a translated version conflicts with the Korean version, the Korean version prevails.
10. Personal Information of Children Under 14
The Company does not provide the Service to children under 14 and does not knowingly collect personal information from children under 14. If we learn that such information has been collected, we destroy it without delay.
11. Remedies for Rights Violations
You may seek counseling or dispute mediation for privacy violations from the following bodies (Republic of Korea): the Personal Information Dispute Mediation Committee (kopico.go.kr, +82-1833-6972), the Privacy Infringement Report Center (privacy.kisa.or.kr, 118), the Supreme Prosecutors' Office Cybercrime Division (1301), and the National Police Agency Cyber Bureau (182).
12. Interest-Based Advertising and Behavioral Information
The Company serves Google AdSense ads on the Service, and third-party advertisers such as Google may collect and use behavioral information (web visit/navigation paths, ad view/click history, etc.) via cookies and advertising identifiers to provide interest-based ads. Such information is processed under each advertiser's privacy policy, and the Company does not control the items or purposes of behavioral information collected directly by advertisers. The Company also collects and analyzes behavioral information such as visit/referral paths on its own for service improvement. You can opt out of interest-based ads and behavioral information collection through Google Ads Settings (adssettings.google.com), the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout), or your browser's cookie-blocking settings.
13. Fortune & Saju Readings
When you use the Fortune & Saju readings feature, personal data is handled as follows. (1) Items: for a fortune, the sign, period and topic you choose and the trigram you draw; for a Saju reading, the date of birth you enter (solar or lunar), the hour of birth and gender. We do not ask for your name. To apply the daily limit and prevent abuse, we also store hashed versions of a random identifier kept in your browser and of your IP address. (2) What is stored: your date of birth is used only to calculate the stems and branches (the four pillars) and is not stored as entered. What we store is the calculated stems and branches, the reading, the hour of birth and gender, and a hash made from your input with a server secret key so the same input can be recognised again (the input cannot be recovered from that value alone). (3) Purposes: generating, showing and sharing readings; avoiding duplicate generation for the same input; applying the daily limit and preventing abuse; keeping members' reading records and charging or refunding credits. (4) Link to your account: a reading you receive while signed in is linked to your member account, and if you paid with credits, the credit charge and any refund are recorded; these records (including the reading number) stay in the credit ledger even if you remove or delete the reading. In My site records, members can view their readings again, change whether they are public, and remove a reading from their records or delete it. (5) Publication: only readings you choose to make public appear in the public list, without your name; Saju readings are private by default. Because the four pillars are derived from the time of birth, your date of birth can be inferred from a Saju reading you make public. (6) Retention: the hashes of the browser identifier and IP address are deleted after 30 days, and unfinished or failed requests after 7 days (a request whose credit refund is not yet complete is deleted once the refund is done). Completed readings are kept for the public list and share links; members can delete them themselves, and others can ask for deletion under section 7. A reading a member removes from their records is unlinked from the account; a deleted reading is emptied at once and what remains is deleted by the next day at the latest. A reading received on the same day stays linked until the next day, because the daily limit counts it. When a member closes their account, their readings are unlinked and remain without a name. (7) AI processing: readings are written by OpenAI's AI, which receives only the items listed in section 5, never your date of birth itself or anything that identifies you. (8) Good & careful days and name energy: we take your time of birth and, for name energy, only the initial sound of each syllable of your name, and calculate the result on the spot. We never take your full name and never send it to AI. If you are signed in, the result is kept privately in My site records (results for visitors who are not signed in are not kept). We keep the calculated signs and birth time slot, the initial sounds for name energy, the date the calculation was based on and the result computed then; the birth date itself is not kept as entered. We also keep a hash value created in the same way as in item (2), so that the same calculation can be recognised again. Only the 20 most recent records per member are kept and older ones are removed. If you switch a record to public it is listed without your name, you can detach or erase it at any time, and it is deleted when you close your account.
14. Mobile app
When you use the mobile app (Fortune & Saju app), personal data is handled as follows. (1) Installation identifier: a random identifier created when the app is installed is kept in the device's secure storage and sent to the server, and is used for guests' daily usage limits and to tell devices apart. Deleting the app creates a new identifier (on iOS it may survive reinstallation because of how secure storage works). (2) Push notifications: if you allow notifications, the notification token is stored on the server and notifications are sent through Expo Push Service. Each kind (reading done, daily fortune, marketing) can be switched on and off in the app settings; marketing notifications require separate consent and the time of consent is stored. The token is deleted when you turn notifications off or do not open the app for 180 days, and delivery records are deleted after 90 days. (3) App usage events: usage records such as screen views, reading requests, ad views and purchase starts are collected for usage statistics and service improvement and deleted after 90 days. Advertising identifiers (IDFA/GAID) are not collected. (4) Sign-in: you sign in with a Google or Apple account, the same member account as the web. For Apple sign-in only the email Apple provides is stored. App sessions expire after 30 days and are deleted on sign-out, account deletion in the app or withdrawal on the web. (5) Advertising: the app carries Google AdMob ads. When you watch a rewarded ad to the end, Google notifies the Company's server, and the Company keeps the transaction identifier and whether the reward was granted for 90 days. Ads are served in non-personalized form; if personalized ads are introduced, separate consent is obtained in the app. (6) In-app purchase: credit top-ups are processed through Apple App Store or Google Play in-app purchase, and the Company stores the transaction identifier, product, quantity and refund status the store confirms together with the receipt sent by the app (payment records are kept for 5 years under applicable law). Payment instrument details such as cards are handled by the store and not received by the Company. (7) App integrity check: to prevent abuse, Firebase App Check may verify that the app is a genuine distribution, in which case a device attestation token is sent to Google. (8) Account deletion: you can delete your account from the My screen in the app; the process is the same as withdrawal on the web (see the account deletion page). (9) Fortune & Saju readings are handled as described in section 13.
Data controller: CGWEB Inc. (씨지웹주식회사) · Website: onbinder.com
- Company
- 씨지웹주식회사
- Representative
- 신익희
- Address
- 경기도 안양시 동안구 시민대로 230 (평촌아크로타워)
- Phone
- 0505-740-0505
- [email protected]
- Business registration no.
- 123-86-31154
- Data protection officer
- 신익희
- Title
- 개인정보보호팀장
- Officer contact
- 0505-740-0505