Sutory · Privacy Policy

Privacy Policy

Effective: 2026-07-10 · Version 2026-07-10

1. Purposes of Processing

Sutory (the "Company") processes personal data for the purposes set out below in order to provide the Sutory service. If the purposes change, the Company will obtain separate consent in accordance with Article 18 of the Korean Personal Information Protection Act (PIPA).

  • Member identification and authentication (Apple / Google social login)
  • Delivery of the AI companion and personal-wiki services (chat, graph, schedules, notifications)
  • Processing of paid-service payments and prevention of fraudulent use
  • Ensuring service reliability (security logs, incident tracing)
  • Compliance with statutory obligations (e.g. transaction-record retention under the Act on the Consumer Protection in Electronic Commerce)

2. Items Processed

2-1. Mandatory items (collected at sign-up)

  • Social identifier: Apple sub or Google sub (the permanent ID issued by each provider)
  • Email address (including Apple Private Relay aliases)
  • Name or nickname (display name provided by the social provider)

2-2. Generated during service use

  • TOMI: when this feature is enabled for the service, we process existing conversations under your AI-processing consent to derive readiness, source references and invitation preferences. You can start a TOMI assessment on signup day. If you start an assessment, we store the situation you describe at the start, questions, answers, result versions, corrections and the Tory name saved when the assessment began. Selected context and answers are processed by the AI processors listed in section 6 of the privacy policy. Results are private by default; future conversation use requires your explicit choice. The assessment stores ratings on 20 fixed Mini-IPIP items and five scale values. AI selects written questions and questions about optical illusions using your authorized conversation knowledge graph. You can answer or explicitly skip these questions. Answers to these AI questions do not change the fixed scale scores or which authored character is chosen. We retain the calculation result and a hash of the core inputs for repeatability. If you create a public link, anyone with it can see only the character, the card’s scores, the Latent, Awakened or Resonant expression label and, on a member card with a byline, the Tory name saved when the assessment began. Renaming Tory later does not change that saved name. Account identity, optional profile details, individual item ratings, written answers, private interpretations, original conversations and graph content remain private. Saving an image alone does not create a public link. Questions, saved answers and conclusions are also kept in your private knowledge graph with sources and versions. Actual experiences, hypothetical answers and AI interpretations remain distinguishable. Authorized memories and new answers inform later questions and private interpretations; fixed scale scoring remains unchanged. A hash of all inputs and the frozen memory snapshot identifies matching versioned inputs; for a match, we reuse the stored interpretation. Activity records are excluded from ordinary memory lists, graph views and automatic recall. The service pays for this activity’s AI work without reducing the Free plan’s usage budget or Pro’s image-generation budget. Members can repeat without watching ads, and there is no assessment-count limit. For service cost audits and abuse prevention, we separately record starts, AI call categories, estimated or settled costs and times; this audit ledger contains no question or answer content. In TOMI, Tory asks about the reasons behind choices and shares observations grounded in the answers. After the fixed items, Tory reviews answers and authorized context, selects situations or needed probes, and explains evidence, exceptions and unresolved areas. Assessment stage, question selections, transitions, assessment purposes, citations and unresolved items are stored with the assessment. We also store the progression plan and any links from a question to the earlier answers it quotes. Tory’s observations are not recorded as facts stated by the participant. Guests receive the full assessment and sharing before signup. Saving guest results to your account and using them in conversations are separate choices. The service does not provide a medical diagnosis or a validated accuracy percentage. Member assessments add verification questions for distinct previously shared experiences, so their length grows with usable evidence. These additional member questions do not apply to guest assessments.
  • While a language-learning answer is being submitted, the device temporarily stores account, lesson and question identifiers, the selected answer number and a request ID for retries. This lets the service recover the same answer after a connection failure. The app uses secure storage; the web uses browser local storage. This recovery record contains no question text or recordings. It is removed after the answer is saved and the screen refreshes, or when you log out. If a device storage error prevents removal, cleanup is needed once storage works again. Removing the recovery record does not delete learning records already stored on the server. During live conversation, the device temporarily stores account, lesson and request identifiers, a transcript, the point confirmed as saved by the server and recorded usage time. The app uses secure storage; the web uses browser local storage. This allows another save attempt when you reopen that lesson. Connection keys and original audio are not retained. The recovery record is removed once the server confirms the transcript and usage time, or when you log out or delete the lesson. Content may be lost if the app or page closes before it is saved on the device.
  • Language learning stores the learning and explanation languages, lessons and questions, answers and grading results, hint and explanation access, completion status, times and time zones. These records support progress, mistake notes and reports for every ten completed sessions, and prevent duplicate learning notifications you have opted into. Questions, answers, explanations and reports also enter your private knowledge graph with their sources; practice sentences are not treated as events from your life. Deleting a session removes its answers, explanations and graph records and invalidates affected reports. Identifiers, sequence numbers and times used to prevent duplicate processing, notification history and report acknowledgements may remain until the account is permanently deleted. When you report a problem with a learning activity, we store your message, references identifying its session and question, the course version, learning language and explanation language in the support inbox to investigate it. The report is deleted when you delete that session or permanently delete your account.
  • When you request pronunciation feedback, we send the recording to Microsoft Azure Speech. The original recording file is not kept in learning records. We store the recognized text, pronunciation results, request time and usage, and add learning records to your private knowledge graph. Deleting the session removes its text, assessments and graph records. Deduplication information and usage records may remain until the account is permanently deleted.
  • When available, real-time conversation practice sends audio and the lesson scenario and examples to Google Gemini Live. Learning records store recognized speech, Tory’s replies, request and end times, and usage instead of the original recording. The conversation enters your private knowledge graph only as roleplay learning records, not as facts about your life. A connection request initially deducts one minute from your Pro voice allowance; if the duration reported by the app at the end is longer, the extra time is deducted from that allowance. The initial deduction may remain even if the connection outcome cannot be confirmed. Deleting the lesson removes its conversation and graph records, but aggregate voice usage may remain until the account is permanently deleted.
  • Memory sources and revision history: we record the timezone and service channel (app, web or voice) when each message is created. For a new Tory response to a question, we also store the question’s identifier within the same account and conversation. We do not infer these links for older messages. Memories and their relationships retain the source kind: your statement, Tory’s response, AI extraction, a tool result, imported material or an uploaded file. They also retain known recording, event and original-source times with their timezones. Where available, we also store the AI model, prompt version, model-reported confidence, original-source identifiers and an excerpt of up to 200 characters. Confidence is not a probability of factual accuracy. When you explicitly describe a feeling of your own, we may store it as an emotion tag with your original words and their known time. The tag is not a diagnosis or an inference about your personality or current mood. Sources for manually saved or edited content retain a bounded excerpt, operation time, source kind, timezone and channel. Links between sources and derived memories store identifiers only. Earlier content and corrections remain as separate history records for explaining, correcting and deleting memories. Unknown historical details are not filled with guesses. Stored source and history data are private account data retained until the relevant content is deleted. On account closure, they are permanently deleted after the existing 30-day grace period. File sources and photo information: we store an uploaded file’s original name, file type (MIME), verified size in bytes, the time its upload is accepted and its stored version identifier. We retain the upload timezone and channel when known. We also store extracted text with its document locations and links from messages to their attachments. When photo metadata provides a capture date and local time, we retain the recorded values; a UTC offset is retained only if present in the original. We do not infer the capture timezone from the upload or display timezone. The setting for using photo capture locations in saved memories is off by default. Only when it is on do we extract GPS coordinates into separate data for search indexing or AI processing. Turning the setting off deletes the extracted GPS coordinates and all memories and revision history derived from photos whose coordinates were extracted and saved. We analyze the kept photos again without location data and may create new memories from them. The original uploaded image remains unchanged and may still contain location metadata. After the 30-day account closure grace period, we delete original files, their attachment links and derived data. The storage service retains recovery copies of deleted files for up to 7 more days before automatically removing them.
  • TOMI guest activity can start without signup. It includes 20 fixed Mini-IPIP items, 16 AI questions (including four optical-illusion questions presented with images or a text alternative), optional follow-ups and private interpretation. Separate AI-processing consent is required before starting; the AI processors listed in section 6 of the privacy policy receive answers. After the result you may enter birth year (1940 to the current year minus 7), gender and occupation in your own words, up to 60 characters. Every field can be skipped. These optional profile details provide context for questions and private interpretation only in a later attempt before the same session expires; they do not change the current result, score arithmetic or character calculation. The validated IANA timezone selected at session creation is fixed. The tory_brain_guest cookie contains only a random token; it is HttpOnly, Secure, SameSite=Lax and limited to the API host and /api/brain-type/guest. The server stores a hash of the random access token. The server also stores optional profile details, timezone, consent version, locale, questions, answers, private interpretation, result, completed-attempt history, processing state, expiry and any public share token you create. No guest graph is created. Abuse prevention and service cost audits record restart requests, single-use reward confirmation state and times, plus AI module, model, token counts and estimated or settled cost; AI usage records contain no questions, answers or raw IP. Access and sharing end at 23:59:59 on the session’s creation day in its fixed timezone. Cleanup runs every five minutes and removes expired sessions, history, AI usage and reward records, usually within five minutes of expiry; delays are possible. Resume, timezone changes, retries and rewards never extend this deadline. We transfer completed attempts only after all three requirements are met: you explicitly choose to save to your account; you sign up or log in; and you give current consent. We move their questions, answers, private interpretations, results and optional profile context into new private assessments and linked projections in your graph. Guest records and cookie are removed without overwriting existing member assessments. Public links are your choice and show only the previewed character, the card’s scores and the Latent, Awakened or Resonant expression label. Guest cards have no name byline; optional profile details, individual answers, private interpretation, account identity and graph data are excluded. Downloading an image does not create a link. When you start another attempt after receiving an ad reward, the previous result’s public link is turned off. Guest links expire at 23:59:59 on the session’s creation day in its fixed timezone. Links retained on import are an exception: they follow member rules. A separate start-abuse ledger keeps only a keyed IP hash and start/expiry times, without raw IP or answers. Independently of the session deadline, those entries count for 24 hours and are removed at the next five-minute cleanup; session deletion does not reset them. Section 11 describes optional ads and rewarded repeats. In TOMI, Tory asks about the reasons behind choices and shares observations grounded in the answers. After the fixed items, Tory reviews answers and authorized context, selects situations or needed probes, and explains evidence, exceptions and unresolved areas. Assessment stage, question selections, transitions, assessment purposes, citations and unresolved items are stored with the assessment. We also store the progression plan and any links from a question to the earlier answers it quotes. Tory’s observations are not recorded as facts stated by the participant. Guests receive the full assessment and sharing before signup. Saving guest results to your account and using them in conversations are separate choices. The service does not provide a medical diagnosis or a validated accuracy percentage. Member assessments add verification questions for distinct previously shared experiences, so their length grows with usable evidence. These additional member questions do not apply to guest assessments.
  • Members and guests must provide a birth year, gender selection and occupation before starting TOMI. Gender includes “Prefer not to say”. Occupation is free text of up to 60 characters. New birth-year entries range from 1940 to the current year minus 7. Members reuse the birth year already on their account; if none is stored, they can enter one and save it to the account. Gender and occupation are also saved to the account. Guests save these details only in their own session. The AI processors listed in section 6 of the privacy policy use these details as context for questions and private interpretation in this TOMI. We do not use these details to infer traits or ability or to calculate scores or characters. Saved results stay unchanged, and public cards exclude these details.
  • Companion profile: we store the required name chosen during onboarding, an optional photo, and the next permitted name and photo change times with your account. These times enforce one year between name confirmations or changes and one month between photo additions or replacements. You may add a photo later or remove it; removal does not reset the existing replacement deadline.
  • When you join AI SNS, we store your SNS nickname, posts, comments, AI replies, publication and automatic-reply settings, friend invitations and acceptance, follows, blocks, and reports with timestamps. Classified conversation material, private drafts, correction and exclusion requests, approved versions and reply-attempt counts support authoring, disclosure controls and cost limits. Other participants see published content and your SNS nickname. Your private AI name and photo require a separate disclosure choice. Friendship or following does not disclose private conversations or memories. Report handling records the reviewer’s hide, dismiss or restore decision, reason and time; only authorized operators can read the review records.
  • Conversation content and notes: text you enter and speech-to-text transcripts
  • Graph data: nodes, edges, tags, and relationships
  • Schedule data: title, start/end time, location text (entered by you or imported via Google Calendar)
  • Voice data: transient audio used for STT processing — deleted immediately after processing, never stored permanently
  • Image data: reference photos you upload and AI-composed images
  • Subscription data: plan, payment status, invoice ID (Paddle payment metadata)
  • Usage logs: per-feature call counts, AI tokens/cost (for quota management)
  • Recommendation interactions: the fact that you tapped a recommendation card in chat (card type, title, and the link’s domain). Full URLs are not stored; used only to improve recommendation relevance.
  • Expression flags: when sexual, illegal, threatening, or harassing expressions are automatically detected in a conversation, we store an excerpt of that sentence (up to 200 characters), its kind, severity, and time for administrator review. If confirmed, an administrator note and any chat restriction are kept alongside (enforcement under Terms Articles 5 and 12).
  • Feature introduction and usage records: to introduce a feature you have not tried or have not used lately at most once a day, we store which feature you opened or completed and when (menu entry and completion time, feature name only), which feature was introduced when and whether you tapped it, and your “not interested” / “stop suggestions” settings. No conversation or file content is stored.
Tory Mind Indicator

2-3. Automatically collected items

  • IP address (security logs, retained for 30 days)
  • User-Agent and device ID (session management)
  • Cookies and LocalStorage: authentication token (tory-auth), one-time OAuth state tokens
  • Server access logs (request path, status code, response time)

2-4. Collected at payment (where applicable)

  • Payment-method details are not stored by the Company. They are held by our payment processor Paddle in line with PCI-DSS requirements.
  • The Company only receives and stores the transaction identifier, amount, currency, and timestamp from Paddle.

3. Location-Based Information (Location Information Act §§16, 18)

The Company may temporarily process the device location of users on its mobile app to provide location-based features (such as nearby lunch suggestions and schedule reminders). For users who have agreed to the separate location-based terms required by the Korean Act on the Protection, Use, etc. of Location Information, processing follows the principles below (see Location-Based Services Terms).

  • When collected: with location permission granted, (i) when the app is opened or brought back to the foreground (at most once every 30 minutes), and (ii) when a location-aware feature such as nearby lunch suggestions is used.
  • Scope of storage: precise GPS coordinates are not stored. Only the city and region names, approximate coordinates truncated to two decimal places (about 1 km), and the time of the last update are saved to the account, and each new reading overwrites the previous one.
  • Purpose: used solely to provide location-aware suggestions — nearby lunch recommendations and local weather in the morning briefing.
  • Retention: deleted together with the account when the user closes it (permanently after the 30-day grace period). Users can stop further collection by revoking location permission on their device.
  • Disclosure to third parties: location data is not shared externally. The one exception: if you turn on AI feed participation and approve an individual post, the place name contained in that post becomes visible to other participants (no name or other identifying information is included). Coordinates are transmitted to an external map API (Google Places) to perform proximity search; that provider processes the request on the Company’s behalf.
  • IP address: used for security, access logs and abuse prevention. Country checks for separately consented guest advertising process the IP as described in Section 11.
  • Withdrawing permission: users can revoke location permission in their device settings at any time. Doing so disables only location-aware features; the rest of the service continues to function normally.
  • Users under 14: because the Company blocks sign-ups by anyone under 14, no location data is processed for users under that age (Location Information Act §25).

4. Retention and Use Periods

  • Members’ TOMI details are stored in their account. You can clear gender and occupation through the form after a result. When account closure is processed, we deactivate the account immediately and permanently delete these details 30 days later. Copies captured in an assessment are removed when you delete that assessment. Guest details become inaccessible at 23:59:59 on the session’s creation day in the timezone fixed at creation. Cleanup runs every five minutes, usually removing expired details within five minutes of expiry; delays are possible. Guest deletion or import also removes the session details. Context in imported assessments follows member assessment retention.
  • Companion names, photos and change deadlines are retained with the account. Account closure disables access, followed by permanent deletion with the account after the existing 30-day grace period.
  • AI SNS: deleting a post or comment withdraws it from public display; you can remove friendships and follows. Account deletion disables SNS access immediately and permanently deletes linked posts, comments, drafts, relationships, reports and generation records after 30 days.
  • Assessments stored in a member account: Assessment questions, answers, results, corrections and their use preference remain until you delete that assessment or your account. Readiness references and invitation preferences remain until account deletion. Account closure deactivates access immediately and permanently deletes these records after 30 days.
  • Member account and content: deleted immediately upon account withdrawal. After a 30-day grace period, recovery is no longer possible (soft-delete → hard-delete).
  • Raw voice audio: deleted immediately after STT processing (never retained).
  • AI-composed images: automatically deleted after 7 days (copies downloaded by the user are separate).
  • Payment records: retained for 5 years under Article 6 of the Act on Consumer Protection in Electronic Commerce.
  • Consumer-complaint and dispute records: retained for 3 years under Article 6 of the same Act.
  • Access logs and security logs: retained for 3 months under Article 15-2 of the Protection of Communications Secrets Act.
  • Expression flags: deleted 1 year after detection or upon account withdrawal. Administrator note and chat restriction: deleted upon account withdrawal.
  • Feature introduction records: deleted 1 year after the introduction or upon account withdrawal. Feature introduction settings: deleted upon account withdrawal.

5. Disclosure to Third Parties

The Company does not disclose your personal data to external parties as a general rule. The following are the only exceptions:

  • where you have given prior consent;
  • where required by law, or where an investigative agency requests it in accordance with the procedures and methods prescribed by law; or
  • where pseudonymised data is provided for statistical or academic-research purposes.

6. Outsourced Processing (Subprocessors)

The Company outsources certain processing tasks to the subprocessors listed below. The outsourcing contracts contain security obligations required by Article 26 of the Korean Personal Information Protection Act.

SubprocessorTaskLocation
Microsoft (Azure)Server / DB / storage hosting, authentication (B2C)South Korea (Azure Korea Central)
OpenAI, L.L.C.GPT-5.6 family chat, summarization, translation, image synthesisUnited States
Anthropic PBCClaude Sonnet 5 chat (fallback and hard tasks)United States
Google LLCGemini family voice synthesis, translation, video understanding, image compositionUnited States
OpenAI Realtime (Whisper)Real-time speech-to-textUnited States
xAI Corp.Grok 4.3 real-time trend and news searchUnited States
Paddle.com Market Ltd.Global payment processing, tax calculation, invoicingUnited Kingdom / EU
Apple Inc.Social login (Sign in with Apple)United States
Google LLCSocial login (Google OAuth) and Calendar / Gmail integration (where the user explicitly consents)United States

Any change in subprocessors will be announced through advance revision of this policy. With every AI subprocessor, the Company uses channels covered by no-training agreements, which forbid using your data for model training.

7. International Data Transfers (PIPA §28-8)

Among the subprocessors listed in Section 6, the ones located in the United States, United Kingdom, and EU receive transferred personal data. Your consent to this policy is treated as consent to such transfers. To withdraw consent, please delete your account. Guest advertising requires the separate consent in Section 11; consent to this policy does not replace it.

RecipientItems transferredTiming / methodPurposeRetention
OpenAIConversation text and metadataReal-time HTTPSAI response generationDiscarded immediately after delivery (no-training)
AnthropicConversation textReal-time HTTPSAI response generationDiscarded immediately after delivery (no-training)
Google (Gemini)Conversation text and voiceReal-time HTTPSAI response / TTSDiscarded immediately after delivery (no-training)
xAISearch topic textReal-time HTTPSReal-time trend and news searchDiscarded immediately after delivery (no-training)
PaddlePayment metadata and emailHTTPS at time of paymentPayment processingStatutory retention under tax / accounting law
Apple, GoogleSocial identifierHTTPS at authenticationSocial loginFor the lifetime of the account

8. Rights and Obligations of Data Subjects, and How to Exercise Them

You may exercise the following rights at any time, either through the Settings screen or by contacting the Data Protection Officer (Section 14).

  • Right of access: download directly via Settings → Data Export (JSON / Markdown).
  • Right to rectification or erasure: edit your profile and content directly in Settings, or withdraw your account.
  • Right to restriction of processing: request by email to the Data Protection Officer.
  • Right to data portability: data exports are provided as standard JSON.
  • Right to object to and to receive an explanation of automated decisions (PIPA §37-2, added in 2024): AI outputs are reference information only — the Company does not make automated decisions with legal or financial effect. If you nonetheless object, please contact the Data Protection Officer and we will review and reply.

9. Procedure and Method for Destruction

The Company destroys personal data without delay once the retention period elapses or the processing purpose has been achieved.

  • Electronic form: permanently deleted in an irrecoverable manner (NULLifying database columns and automatic disposal once backup retention expires).
  • Paper documents: shredded or incinerated.
  • Data transmitted to AI subprocessors: destroyed immediately under the outsourcing contract (no-training, no-retention options applied).

10. Safeguards

  • Administrative: internal management plan, regular security training, principle of least access.
  • Technical: TLS 1.3 in transit, AES-256 at rest, Row-Level Security multitenant isolation, password hashing (Argon2id), short-lived JWTs.
  • Physical: reliance on the ISO 27001 / SOC 2 controls of Azure data centres.
  • Logging and monitoring: anomaly detection on access, notification within 72 hours of any security incident (per GDPR / PIPA).

11. Automatic Collection Devices (Cookies / LocalStorage)

Authenticated sessions use the LocalStorage items below. The guest assessment cookie is described in Section 2; optional advertising requires the separate consent and processing described here.

  • TOMI guest ads may appear only after separate opt-in, for adults aged 18+ with a Korean or English interface and an IP country confirmed as South Korea or the United States. Declining does not block the initial assessment. Neither country lookup nor Google ad code loads before consent. After consent, we send the IP to ipwho.is to check the country; we do not separately store the raw IP or country from that lookup. Where ads are permitted, Google may process IP, browser information and cookies. Each provider processes data under its own privacy policy; our guest-record local-day expiry does not govern provider retention. We request non-personalized ads; Google may still use cookies for frequency limits and aggregate reporting. We do not send answers, results, birth year, age band, gender or occupation as ad-targeting data. Standard ads use manual placements on guest web start, question and result pages. There are no auto ads or ads on signup/login, member screens, the app or app WebViews. Ads are off if you are under 18 (including ages 14–17) or your age is unknown. EEA, UK and Switzerland remain off until a certified consent management platform (CMP) is in place. Deployments without ad identifiers keep ads disabled. After completing an assessment, starting another attempt that day requires a reward from a Google Ad Manager rewarded ad. Even after consenting to standard ads, you choose separately whether to watch a rewarded ad. We process the browser reward-completion notification and a one-use confirmation. Missing configuration, no ad, cancellation or an ungranted reward does not unlock a repeat; return the next local day instead. Resuming an unfinished assessment or retrying failed work requires no reward. Members can repeat without ads.
  • tory-auth: authenticated session (access / refresh tokens and expiry).
  • tory-oauth-state: one-time OAuth login state (deleted immediately after the callback).

You may delete these items at any time through your browser settings.

12. Protection of Minors (PIPA §22-2 · COPPA)

The Company blocks sign-ups by children under the age of 14. This measure satisfies both Article 22-2 of the Korean Personal Information Protection Act and the U.S. Children’s Online Privacy Protection Act (COPPA, under 13).

  • Where blocked: the consent step of sign-up requires a year of birth; if the user is determined to be under 14, sign-up is rejected outright and no input data is stored.
  • Default protection from social providers: Apple ID and Google accounts are issued only to users aged 13+ under each provider’s terms, giving us a first line of defence.
  • Post-hoc detection: if a user is found to be under 14 after sign-up, the Company immediately suspends the account and destroys all personal data collected within 7 days. We notify the registered email of the destruction.
  • Rights of legal guardians: a legal guardian who discovers that the Company is processing personal data of a child under 14 may immediately require destruction, access, or cessation of use through the Data Protection Officer.

13. Marketing Use

We do not use member conversations or assessment responses as ad-targeting data. Guest web advertising follows the separate consent and limits in Section 11. We send service-operation notifications, including payment, security and app-installation guidance.

14. Data Protection Officer

  • Officer: Min-kyung Kim (CEO)
  • Email: privacy@tory.my
  • Company: Sutory · Business registration number: 633-02-03631
  • Response time: within 7 business days
  • Dispute resolution: Personal Information Dispute Mediation Committee (1833-6972), Privacy Infringement Report Centre (118), Supreme Prosecutors’ Office Cyber Investigation (1301), National Police Agency Cyber Bureau (182)

15. Change History

  • 2026-07-10 · Added xAI (real-time search) as a subprocessor, refreshed AI model names, introduced separate consent for third-party AI processing
  • 2026-05-27 · Added an English translation (Korean original remains authoritative; other-language bodies are provided for convenience).
  • 2026-05-13 · Added an explicit location-information processing section (§3), added protection of minors (§12 COPPA / PIPA §22-2), and corrected the Data Protection Officer email domain.
  • 2026-05-12 · Initial release.