시행일: 2026년 7월 12일
최종 업데이트: 2026년 7월 19일
wwwERD(이하 “서비스”)는 개인 운영자(이하 “운영자”)가 제공하는 웹 기반 ERD·데이터베이스 모델링 서비스입니다. 운영자는 이용자의 개인정보를 중요하게 생각하며, 「개인정보 보호법」, 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 등 관련 법령을 준수합니다. 본 개인정보처리방침(이하 “본 방침”)은 운영자가 웹사이트 및 애플리케이션을 통해 수집·이용하는 개인정보의 항목, 목적, 보유 기간, 보호 조치, 이용자의 권리 등을 안내합니다.
- 공식 웹사이트: https://wwwerd.devzest.xyz
- 문의 이메일: [email protected]
본 방침이 변경되는 경우 서비스 내 공지 또는 이메일 등 합리적인 방법으로 고지하며, 법령상 동의가 필요한 변경에 대해서는 동의를 받습니다.
1. 수집하는 개인정보 항목 및 수집 방법
1.1 이용자가 직접 제공하는 정보
| 구분 | 수집 항목 | 필수 여부 |
|---|---|---|
| 이메일 회원 가입·로그인 | 이메일 주소, 비밀번호, 이름(표시명) | 필수 |
| 소셜 로그인(예: Google) | 소셜 제공자가 허용한 범위의 식별 정보·이메일·이름 등 | 필수(해당 방식 이용 시) |
| 프로필 수정 | 이름 등 이용자가 변경한 계정 정보 | 선택·변경 시 |
| 비밀번호 변경 | 현재 비밀번호, 새 비밀번호(로컬 계정에 한함) | 해당 기능 이용 시 필수 |
| 피드백·문의 | 제목, 내용, 유형, (선택) 연결 프로젝트 정보, 비로그인 시 guest 식별자 등 | 해당 기능 이용 시 |
※ 비밀번호는 복호화할 수 없는 방식으로 안전하게 저장되며, 평문 비밀번호를 보관하지 않습니다.
※ 소셜 계정으로 가입한 이용자는 서비스에 로컬 비밀번호를 두지 않을 수 있으며, 이 경우 비밀번호 변경 기능이 제공되지 않을 수 있습니다.
1.2 서비스 이용 과정에서 자동으로 생성·수집되는 정보
| 구분 | 수집 항목 예시 |
|---|---|
| 기기·접속 정보 | IP 주소, User-Agent(브라우저·OS 정보), 접속 일시 |
| 인증·세션 정보 | 액세스 토큰·리프레시 토큰 관련 세션 기록, 로그인·로그아웃·토큰 갱신 이력 |
| 쿠키·유사 기술 | 인증 유지용 쿠키(예: HttpOnly 리프레시 토큰), 서비스 운영에 필요한 쿠키 |
| 로그·오류 정보 | 서비스 오류 로그, 요청 경로·상태 코드 등 안정성 확보를 위한 기술 로그 |
| 이용 기록 | 프로젝트·모델 등 기능 이용에 따른 서버 로그, 보안 이벤트 |
| MCP 연결 정보 | 연결한 외부 AI 클라이언트 이름, 승인 범위, 허용 프로젝트, 연결·폐기·마지막 사용 시각, Tool 실행 결과·소요시간·오류 코드 |
1.3 이용자가 서비스에 저장하는 콘텐츠(사용자 생성 콘텐츠)
이용자가 작성·업로드하는 ERD 프로젝트, 논리/물리 모델, 테이블·관계·DDL, 버전 기록, 메모 등 모델링 데이터는 서비스 제공을 위해 저장·처리됩니다. 이러한 콘텐츠에 개인정보가 포함되는 경우, 해당 정보는 이용자가 직접 입력한 범위에서 처리됩니다.
1.4 수집 방법
- 웹사이트·서비스 화면 입력
- 회원가입·로그인·프로필·피드백 등 기능 이용
- 소셜 로그인 제공자와의 연동(이용자 동의·인증 후)
- 서비스 이용 중 자동 생성(쿠키, 로그, 세션 등)
- 고객 문의·이메일 등 통신
2. 개인정보의 이용 목적
운영자는 수집한 개인정보를 다음 목적 범위에서 이용합니다.
- 회원 관리: 가입·본인 확인, 계정 식별, 소셜 계정 연동, 회원 탈퇴 처리
- 서비스 제공: 프로젝트·모델 저장 및 조회, DDL 생성·가져오기, 버전 기록, 게스트 체험 등 핵심 기능 제공
- 인증·보안: 로그인 유지, 토큰 발급·갱신·폐기, 부정 이용·계정 탈취 탐지 및 방지, 모든 기기 로그아웃 등
- 고객 지원: 피드백·문의 응대, 서비스 장애·오류 대응
- 서비스 개선: 기능 개선, 품질·성능 분석, 통계(개인을 식별하지 않는 형태 포함)
- 공지·정책 안내: 약관·방침 변경, 중요 서비스 고지
- 법령 준수: 관련 법령상 의무 이행, 분쟁 대응
- 이메일 발송: 가입·인증·보안 및 중요 서비스 안내 이메일 전송
- MCP 연동: 이용자가 선택한 외부 AI 서비스에 프로젝트 조회·분석·변경 Tool을 제공하고 연결 권한·보안·실행 이력을 관리
운영자가 본 방침에 명시되지 않은 목적으로 개인정보를 이용하려는 경우, 관련 법령에 따라 별도의 동의를 받습니다.
3. 개인정보의 제3자 제공
운영자는 원칙적으로 이용자의 개인정보를 외부에 제공하지 않습니다. 다만 다음의 경우에는 예외로 합니다.
- 이용자가 사전에 동의한 경우
- 법령에 근거가 있거나 수사·조사 기관이 법령이 정한 절차와 방법에 따라 요청한 경우
- 서비스 계약의 이행을 위해 필요한 범위에서 관련 법령이 허용하는 경우
3.1 이용자가 선택한 외부 AI 서비스로의 전송
이용자가 MCP 연결을 직접 승인하면, 선택한 프로젝트의 이름·DBMS·테이블·컬럼·관계·설명·DDL 등 프로젝트 데이터와 Tool 결과가 ChatGPT, Claude, Codex 등 이용자가 선택한 외부 AI 서비스로 전송될 수 있습니다. 전송 범위는 OAuth 동의 화면에서 선택한 권한과 프로젝트로 제한되며, 모델 변경은 외부 MCP 클라이언트의 Tool 승인 후 적용됩니다. 이용자는 설정 > MCP 연결 관리에서 허용 프로젝트를 변경하거나 연결을 즉시 폐기할 수 있습니다. 외부 AI 서비스가 수신한 데이터에는 해당 제공자의 약관·개인정보처리방침과 보유 정책이 적용됩니다.
4. 개인정보 처리의 위탁
운영자는 서버·데이터베이스 등 서비스의 핵심 저장·처리 업무를 외부 업체에 위탁하지 않으며, 해당 서버는 대한민국에 있습니다. 다만 이메일 발송과 소셜 로그인 제공을 위해 아래 외부 서비스를 이용합니다.
| 외부 서비스 제공자 | 이용 업무 | 처리되는 정보 | 처리 및 보유 |
|---|---|---|---|
| Google LLC (개인용 Gmail SMTP) | 가입·인증·보안·서비스 안내 이메일 발송 | 수신 이메일 주소, 발신·수신 정보, 이메일 제목·본문 및 전송기록 | 이메일 전송에 필요한 기간 및 Google의 정책에 따른 기간 |
| Google LLC (Google OAuth) | 이용자가 선택한 Google 로그인 인증 | Google 계정 식별자, 이메일 주소, 이름, 인증 요청·응답 및 접속정보 | 인증과 계정 연동에 필요한 기간 및 Google의 정책에 따른 기간 |
개인용 Gmail은 Google이 운영자의 지시에 따라서만 개인정보를 처리하는 전용 수탁 서비스가 아니며, Google의 이용약관 및 개인정보처리방침이 함께 적용됩니다. Google은 전 세계에 서버를 운영하므로 위 정보가 대한민국 밖에서 처리될 수 있습니다. 자세한 내용은 제10조에서 안내합니다.
향후 별도의 개인정보 처리 위탁이 발생하는 경우, 운영자는 수탁자·위탁 업무 내용을 본 방침에 공개하고 관련 법령에 따른 관리·감독 조치를 이행합니다.
5. 쿠키 및 유사 기술
5.1 쿠키의 사용
운영자는 서비스 제공을 위해 쿠키 및 이와 유사한 기술을 사용할 수 있습니다.
- 필수 쿠키: 로그인 상태 유지(예: HttpOnly 리프레시 토큰), 보안, 기본 기능 동작
- 기능·성능 쿠키(사용 시): 설정 기억, 오류 분석, 서비스 품질 개선
5.2 쿠키 거부
이용자는 브라우저 설정으로 쿠키 저장을 거부하거나 삭제할 수 있습니다. 다만 필수 쿠키를 거부하는 경우 로그인 유지 등 서비스 이용이 제한될 수 있습니다.
5.3 제3자 사이트
서비스에 포함된 제3자 링크·서비스에는 해당 제3자의 개인정보 처리방침이 적용될 수 있습니다. 운영자는 제3자 사이트의 정책에 대해 책임을 지지 않으므로 이용 전 해당 정책을 확인하시기 바랍니다.
6. 개인정보의 보유 및 이용 기간
- 운영자는 개인정보 수집·이용 목적이 달성되면 지체 없이 파기합니다.
- 회원 탈퇴 시 계정 및 관련 서비스 데이터(프로젝트·모델 등)는 복구할 수 없도록 삭제하는 것을 원칙으로 합니다. 단, 관련 법령에 따라 일정 기간 보관이 필요한 정보는 해당 기간 동안 보관 후 파기합니다.
- 항목별 보유기간은 다음과 같습니다. 법령에 따라 별도 보관이 필요한 경우에는 해당 정보만 다른 정보와 분리하여 법정 기간 동안 보관합니다.
| 처리 정보 | 보유기간 |
|---|---|
| 계정 및 프로필 정보 | 회원 탈퇴 시까지 |
| 프로젝트·모델 등 이용자 콘텐츠 | 이용자가 삭제하거나 회원 탈퇴할 때까지 |
| 인증 세션 및 토큰 정보 | 세션 만료·로그아웃·회원 탈퇴 시까지 |
| MCP OAuth 연결·토큰 정보 | 연결 폐기·토큰 만료·전체 로그아웃·회원 탈퇴 시까지. 토큰 원문은 저장하지 않음 |
| MCP 변경 미리보기·DDL 결과 | 생성 후 즉시 만료 처리되며 payload는 최대 7일 |
| MCP Tool 실행 메타데이터 | 생성일로부터 90일. Tool명·프로젝트·결과·소요시간·오류 코드만 보관하며 입력 원문은 보관하지 않음 |
| 접속·보안·오류 로그 | 생성일로부터 최대 3개월 |
| 피드백·문의 및 답변 기록 | 문의 처리 완료 후 3년. 이용자가 더 이른 삭제를 요청하고 보관할 정당한 필요가 없으면 지체 없이 삭제 |
| 이메일 발송 정보 | 발송 완료 및 관련 목적 달성 시까지. 단, 개인 Gmail에 남는 기록은 Google 정책 또는 운영자가 해당 메일을 삭제할 때까지 |
7. 개인정보의 파기 절차 및 방법
- 파기 절차: 목적 달성 또는 보유 기간 경과 후 운영자의 방침과 관련 법령에 따라 파기합니다. 법령상 보관이 필요한 정보는 별도 분리 보관 후 해당 기간 종료 시 파기합니다.
- 파기 방법: 전자 파일은 복구·재생이 불가능한 기술적 방법으로 삭제하고, 출력물 등 종이 문서는 분쇄 또는 소각합니다.
8. 이용자의 권리와 행사 방법
이용자(또는 법정대리인)는 언제든지 다음 권리를 행사할 수 있습니다.
- 개인정보 열람 요구
- 정정·삭제 요구
- 처리 정지 요구
- 동의 철회 및 회원 탈퇴
권리 행사는 서비스 내 계정·프로필 기능, 회원 탈퇴 기능 또는 아래 문의 창구를 통해 요청할 수 있으며, 운영자는 관련 법령이 정한 바에 따라 지체 없이 조치합니다. 다만 법령상 보관 의무가 있는 경우 등 정당한 사유가 있으면 요청을 제한할 수 있습니다.
9. 개인정보의 안전성 확보 조치
운영자는 개인정보의 분실·도난·유출·위조·변조 또는 훼손을 방지하기 위해 다음 조치를 취합니다.
| 구분 | 조치 내용 |
|---|---|
| 기술적 조치 | 전송 구간 암호화(HTTPS 등), 비밀번호 등 중요 정보의 암호화 저장, 접근 통제, 보안 취약점 대응 |
| 관리적 조치 | 개인정보 취급 최소화, 접근 권한 관리, 운영자 본인의 보안 관리 |
| 물리적 조치 | 서버·인프라에 대한 접근 통제 |
10. 국외 이전
서비스의 자체 서버와 데이터베이스는 대한민국에 있습니다. 다만 개인용 Gmail SMTP와 Google OAuth를 이용하는 과정에서 개인정보가 다음과 같이 국외에서 처리될 수 있습니다.
| 이전받는 자 | 이전 국가 | 이전 항목 | 목적 | 시기 및 방법 | 보유기간 |
|---|---|---|---|---|---|
| Google LLC 및 그 계열사·서비스 제공자 | 미국을 포함하여 Google이 서버를 운영하는 국가 | 수신 이메일 주소, 이메일 제목·본문, 발신·수신 및 전송기록 | 가입·인증·보안·중요 서비스 안내 이메일 발송 | 이메일 발송 시 암호화된 네트워크를 통해 전송 | 이메일 전송에 필요한 기간 및 Google 정책에 따른 기간 |
| Google LLC 및 그 계열사·서비스 제공자 | 미국을 포함하여 Google이 서버를 운영하는 국가 | Google 계정 식별자, 이메일 주소, 이름, 인증 요청·응답, IP 주소 등 접속정보 | 이용자가 선택한 Google 로그인 인증 및 계정 연동 | Google 로그인 이용 시 암호화된 네트워크를 통해 전송 | 인증과 계정 연동에 필요한 기간 및 Google 정책에 따른 기간 |
Google은 전 세계에 서버를 운영하며 개별 정보가 처리되는 국가를 운영자에게 특정하여 제공하지 않을 수 있습니다. Google의 처리 방식과 보유기간에 관한 자세한 내용은 Google 개인정보처리방침에서 확인할 수 있습니다.
이용자는 Google 로그인을 사용하지 않고 이메일 계정으로 가입하여 OAuth 관련 국외 처리를 거부할 수 있습니다. 다만 서비스 운영에 필수적인 가입·인증·보안 안내 이메일의 Google SMTP 처리를 거부하는 경우 이메일 가입 또는 관련 기능 이용이 제한될 수 있습니다. 국외 처리에 동의하지 않는 이용자는 서비스를 이용하지 않거나 회원 탈퇴를 요청할 수 있습니다.
11. 아동의 개인정보
서비스는 원칙적으로 만 14세 미만 아동을 대상으로 하지 않으며, 만 14세 미만의 회원가입을 허용하지 않습니다. 만 14세 미만 아동의 개인정보가 수집된 사실을 알게 된 경우 운영자는 지체 없이 삭제 등 필요한 조치를 합니다.
12. 개인정보 보호책임자 및 문의
운영자는 개인정보 보호 관련 업무와 이용자 불만 처리를 위해 아래 창구를 둡니다.
- 개인정보 보호 담당: wwwERD 운영자(개인)
- 웹사이트: https://wwwerd.devzest.xyz
- 이메일: [email protected]
- 기타: 서비스 내 피드백·문의 기능
이용자는 개인정보 침해에 대한 신고·상담을 위해 다음 기관에 문의할 수도 있습니다.
- 개인정보침해신고센터: privacy.kisa.or.kr / (국번없이) 118
- 개인정보 분쟁조정위원회: www.kopico.go.kr
- 대검찰청 사이버수사과: www.spo.go.kr
- 경찰청 사이버수사국: ecrm.police.go.kr
13. 개인정보처리방침의 변경
본 방침의 내용 추가·삭제·수정이 있을 경우 개정 최소 7일 전(이용자에게 불리한 변경 등 중요한 사항은 최소 30일 전)부터 서비스 내 공지 또는 이메일 등으로 고지합니다. 법령상 동의가 필요한 변경에 대해서는 동의를 받습니다.
부칙
본 방침은 2026년 7월 12일부터 적용됩니다.
Effective date: July 12, 2026
Last updated: July 19, 2026
wwwERD (the “Service”) is operated by an individual operator (the “Operator,” “we,” “us,” or “our”). This Privacy Policy (the “Policy”) explains how we collect, use, store, share, and protect personal information when you use the wwwERD website and related applications or features.
- Official website: https://wwwerd.devzest.xyz
- Contact email: [email protected]
We treat personal information as important. This Policy describes the purposes and methods of our processing and the measures we take to protect that information.
If we modify this Policy, we will provide notice through the Service (for example, by posting on the website or by email). Where required by law, we will obtain your consent.
1. Information We Collect and How We Collect It
1.1 Information you provide
| Category | Examples of data | Required? |
|---|---|---|
| Email sign-up / login | Email address, password, display name | Required |
| Social login (e.g., Google) | Identifier, email, name, and other data permitted by the provider | Required when using that method |
| Profile updates | Name and other account fields you change | Optional / when updated |
| Password change | Current password, new password (local accounts only) | Required for that feature |
| Feedback / support | Title, message, type, optional linked project, optional guest identifier for unauthenticated users | When you use the feature |
Notes:
- Passwords are stored using secure one-way methods. We do not store plaintext passwords.
- Accounts registered with a social provider may not have a local password. In that case, password-change features may be unavailable.
1.2 Information collected automatically while you use the Service
| Category | Examples |
|---|---|
| Device / connection | IP address, User-Agent (browser/OS), access timestamps |
| Authentication / session | Access and refresh token session records; login, logout, and token refresh history |
| Cookies and similar technologies | Cookies needed for authentication (e.g., HttpOnly refresh tokens) and core operation |
| Logs and diagnostics | Error logs, request paths, status codes, and other technical logs for reliability and security |
| Usage records | Server logs related to project/model features and security events |
| MCP connection records | External AI client name, approved scopes, allowed projects, connection/revocation/last-used timestamps, and Tool outcome, duration, and error code |
1.3 User-generated content
Content you create or upload—such as ERD projects, logical/physical models, tables, relationships, DDL, snapshots, and notes—is stored and processed to provide the Service. If that content includes personal information, it is processed only to the extent you include it.
1.4 Collection methods
- Forms and screens on the website or Service
- Account, profile, authentication, and feedback features
- Social login providers (after you authorize them)
- Automatic generation during use (cookies, logs, sessions)
- Email or other communications with support
2. How We Use Collected Information
We use personal information for the following purposes:
- Account administration — registration, identification, social account linking, and account deletion
- Service delivery — storing and retrieving projects/models, DDL export/import, snapshots, guest/try mode, and related features
- Authentication and security — session maintenance, token issuance/rotation/revocation, detecting and preventing abuse or account takeover, logout-all, and similar controls
- Customer support — responding to feedback and inquiries; addressing incidents and defects
- Product improvement — improving features, quality, and performance; statistics (including de-identified forms where applicable)
- Notices — policy updates and important service communications
- Legal compliance — meeting legal obligations and handling disputes
- Email delivery — sending registration, authentication, security, and important Service notices
- MCP integration — providing project reading, analysis, and change Tools to an external AI service chosen by you, and managing connection permissions, security, and activity records
If we wish to use information for purposes not described in this Policy, we will obtain consent where required by law.
3. Sharing Personal Information
We do not share personal information with third parties except in the following cases:
- You have given prior consent
- Disclosure is required by law, or by investigative authorities following lawful procedures
- Sharing is necessary to perform the Service agreement within the limits permitted by law
3.1 Transfer to an external AI service you choose
When you explicitly approve an MCP connection, project names, DBMS details, tables, columns, relationships, descriptions, DDL, and Tool results for the projects you select may be transmitted to an external AI service you choose, such as ChatGPT, Claude, or Codex. The transfer is limited by the OAuth scopes and project allowlist selected on the consent screen. Model changes are applied only after approval in the external MCP client's Tool confirmation UI. You can change allowed projects or immediately revoke a connection under Settings > MCP connections. Data received by the external AI service is governed by that provider's terms, privacy policy, and retention practices.
4. Processors and Service Providers
We do not outsource the core hosting or database storage of the Service, and those servers are located in the Republic of Korea. We do, however, use the following external services for email delivery and social login.
| External provider | Function | Information processed | Processing and retention |
|---|---|---|---|
| Google LLC (consumer Gmail SMTP) | Registration, authentication, security, and Service-notice emails | Recipient email address, sender/recipient data, email subject and body, and transmission records | As needed to transmit the email and according to Google's policies |
| Google LLC (Google OAuth) | Google sign-in selected by the user | Google account identifier, email address, name, authentication request/response data, and connection data | As needed for authentication and account linking and according to Google's policies |
Consumer Gmail is not a dedicated processor service that processes personal information solely on our instructions. Google's terms and privacy policy also apply. Because Google operates servers worldwide, this information may be processed outside the Republic of Korea. Section 10 provides more information.
If we later engage any other processor, we will update this Policy with the processor's name and entrusted work and implement the safeguards required by applicable law.
5. Cookies, Beacons, and Similar Technologies
5.1 Use of cookies
We may use cookies and similar technologies to:
- Strictly necessary cookies — keep you signed in (e.g., HttpOnly refresh tokens), security, and core functionality
- Performance / functionality cookies (if used) — remember preferences, measure errors, and improve the Service
These technologies help us evaluate, improve, and deliver a better experience.
5.2 Your choices
You can refuse or delete cookies in your browser settings. If you block essential cookies, parts of the Service (such as remaining signed in) may not work.
5.3 Third-party sites and services
Our website or Service may contain links to third-party sites or services. Their privacy practices may differ. You should review the privacy policy of any third party you visit. We are not responsible for third-party policies.
6. Retention Period
- We retain personal information only as long as needed for the purposes described in this Policy, then delete or anonymize it without undue delay.
- When you delete your account, we delete the account and associated service data (including projects and models) so they cannot be restored, except where retention is required by law.
- The following periods apply. If law requires separate retention, we isolate and retain only the required information for the statutory period.
| Information | Retention period |
|---|---|
| Account and profile information | Until account deletion |
| Projects, models, and other user content | Until deleted by the user or account deletion |
| Authentication sessions and token data | Until session expiration, logout, or account deletion |
| MCP OAuth connection and token data | Until connection revocation, token expiration, logout-all, or account deletion. Raw token values are not stored |
| MCP change previews and DDL artifacts | Immediately unusable after expiration; payload retained for up to 7 days |
| MCP Tool execution metadata | 90 days from creation. Only Tool, project, outcome, duration, and error code are retained; raw input is not stored |
| Access, security, and error logs | Up to 3 months from creation |
| Feedback, inquiries, and responses | 3 years after the inquiry is resolved; deleted earlier on request unless continued retention is reasonably necessary |
| Email delivery data | Until delivery and the related purpose are complete; records remaining in consumer Gmail persist according to Google's policy or until deleted by the Operator |
7. Destruction Procedures and Methods
- Procedure: After the purpose is achieved or the retention period ends, we destroy personal information according to internal policies and applicable law. Legally required records are stored separately and destroyed when the statutory period ends.
- Methods: Electronic files are deleted using technical measures that make recovery practically impossible. Paper records are shredded or incinerated.
8. Your Rights and Choices
Depending on applicable law, you may:
- Access your personal information
- Request correction or deletion
- Request restriction or temporary suspension of processing
- Withdraw consent and close your account
You can exercise these rights through account/profile features, account withdrawal, or by contacting us using the details below. We will respond without undue delay as required by law, except where we may lawfully refuse a request (for example, statutory retention obligations).
If you reside in certain jurisdictions (for example, California or the EEA/UK), additional rights may apply under local law. Contact us to exercise those rights.
9. Security
We take personal information security seriously and implement measures designed to protect against unauthorized access, disclosure, use, or alteration, including:
| Type | Examples |
|---|---|
| Technical | Encrypted transport (e.g., HTTPS), encryption of sensitive credentials, access controls, vulnerability response |
| Organizational | Least-privilege access, operator security practices |
| Physical / infrastructure | Controlled access to servers and infrastructure |
No method of transmission or storage is completely secure. We continuously work to improve our safeguards, but we cannot guarantee absolute security.
10. International Transfers
The Service's own servers and databases are located in the Republic of Korea. Personal information may nevertheless be processed overseas when we use consumer Gmail SMTP and Google OAuth.
| Recipient | Countries | Information | Purpose | Timing and method | Retention |
|---|---|---|---|---|---|
| Google LLC and its affiliates/service providers | The United States and other countries where Google operates servers | Recipient email address, email subject and body, sender/recipient data, and transmission records | Registration, authentication, security, and important Service-notice emails | Encrypted network transfer when an email is sent | As needed for transmission and according to Google's policies |
| Google LLC and its affiliates/service providers | The United States and other countries where Google operates servers | Google account identifier, email address, name, authentication request/response data, IP address, and other connection data | Google sign-in and account linking selected by the user | Encrypted network transfer when Google sign-in is used | As needed for authentication/account linking and according to Google's policies |
Google operates servers worldwide and may not identify to the Operator the particular country in which each item is processed. See the Google Privacy Policy for details about Google's processing and retention.
You may decline OAuth-related overseas processing by registering with an email account instead of Google sign-in. If you decline the Gmail SMTP processing necessary for registration, authentication, or security notices, email registration or related Service functions may be unavailable. A user who does not agree to overseas processing may refrain from using the Service or request account deletion.
11. Children
The Service is not directed to children under 14, and we do not knowingly allow registration by children under 14. If we learn that we have collected personal information from a child under 14, we will delete it promptly.
12. Contact / Privacy Inquiries
For privacy questions, requests, or complaints, contact:
- Privacy contact: wwwERD Operator (individual)
- Website: https://wwwerd.devzest.xyz
- Email: [email protected]
- In-product: feedback / contact features in the Service
13. Changes to This Policy
We may amend this Policy from time to time. We will post the updated Policy and, for material changes, provide advance notice (for example, at least 7 days, or longer where required by law or where the change is disadvantageous to users). Where law requires consent, we will obtain it.
Appendix
This Policy is effective as of July 12, 2026.