LangTwo Privacy Policy

Effective Date: 2026-08-05Version: v1.1.0

1. Purposes and Legal Bases for Processing Personal Information

LangTwo (langtwo.com, hereinafter referred to as the “Company”) processes personal information solely for the following purposes and on the following legal bases, in accordance with the Personal Information Protection Act (“PIPA”) and other applicable laws and regulations. If the purpose of processing changes, the Company will obtain separate consent in advance or use the information only to the extent permitted by applicable laws and regulations.
CategoryPurpose of ProcessingLegal Basis
Member ServicesMember identification and authentication; provision, maintenance, and improvement of AI-based language learning services; customer supportPerformance of a contract
Payment and SettlementSubscription fee payments and refunds; issuance of tax invoices; PayPal payment processingPerformance of a contract
Marketing and PromotionsAnnouncements regarding new features; recommendations for personalized learning contentConsent of the data subject
Service ImprovementAnalysis of learning patterns; improvement of AI scenario quality; enhancement of usabilityLegitimate interests
Legal ComplianceDetection of fraudulent transactions; dispute resolution; responding to requests from regulatory authoritiesLegal obligation

2. Categories and Methods of Collection

The categories of personal information collected by the Company and the methods of collection are as follows.

2.1 Information Collected Directly

CategoryRequired ItemsOptional Items
Account RegistrationEmail address (ID)Password (only when social login is not used)
Social LoginGoogle account information (email address and profile)-
PaymentPayPal transaction authorization number and payment informationAddress for receipt of tax invoices

2.2 Automatically Collected Information

Information Collected through Google Analytics 4 (GA4):
  • IP address (automatically anonymized in the EU), browser and operating system information
  • Device information (mobile/desktop, screen resolution)
  • Approximate geographic location (at the country/city level)
  • Page views, session duration, bounce rate, and referring websites
Information Collected through Amplitude:
  • User behavioral events (clicks, page views, and feature usage)
  • Session data (access and duration data) and anonymized device ID
  • Application version, operating system version, and user journey analysis data
  • Custom events (learning progress, Today Energy usage, etc.)
Learning Data Collected:
  • Scenario conversation messages (all conversations between the AI and the user)
  • Learning session information (start/end times and progress)
  • AI assessment and feedback data, and translation practice results
  • Review questions and correct-answer rates, daily learning goals and achievement levels
  • AI token usage (for cost management and service optimization)
Service Operation Information Collected:
  • Device notification tokens (for sending push notifications such as learning reminders; collected only when notification permissions have been granted)
  • Device time zone (for calculating learning streaks and determining notification times)

3. Retention and Use Period

The Company retains personal information only for the retention period prescribed by law or for the period agreed to by the user, and destroys the information without delay once the applicable period has expired.
ItemRetention PeriodApplicable Law or Internal Policy
Basic Member Information3 months after account withdrawalPrevention of misuse for re-registration (internal policy)
Learning Data1 year after account withdrawalService quality improvement (internal policy)
Payment and Settlement Records5 yearsArticle 6 of the Act on the Consumer Protection in Electronic Commerce
Records of Indications and Advertisements6 monthsArticle 6 of the Act on the Consumer Protection in Electronic Commerce
Electronic Financial Transaction Records5 yearsElectronic Financial Transactions Act
Logs and Access Records3 monthsProtection of Communications Secrets Act
Dormant AccountsSeparately stored after 1 year of inactivity → destroyed after 3 yearsCompliance with the 2023 PIPA amendments
Fraudulent Transaction Records5 yearsInternal policy
Device Notification TokensDestroyed immediately upon withdrawal of notification permission or account withdrawalInternal policy
Device Time Zone3 months after account withdrawalSame as basic member information

4. Provision of Personal Information to Third Parties and Entrustment of Processing

4.1 Domestic Entrustment

Entrusted PartyEntrusted TaskRetention Period
PayPalElectronic payment processing and subscription managementUntil termination of the contract
To be determinedSending SMS and Kakao notification messagesDeleted immediately after delivery is completed
The Company enters into written agreements with all entrusted parties pursuant to Article 26 of the Personal Information Protection Act and regularly manages and supervises them.

4.2 Cross-Border Transfers

Google Analytics 4:
  • Entrusted party/country: Google LLC / United States
  • Transferred items: Cookie-based logs, access IP addresses (anonymized), and website usage patterns
  • Timing and method of transfer: Transmitted via TLS encryption when the service is used; stored in the Americas region
  • Legal basis: Prior consent of the data subject
  • Method of refusal: Google Analytics Opt-out Add-on or blocking browser cookies
Amplitude:
  • Entrusted party/country: Amplitude Inc. / United States
  • Transferred items: Analytical information, including service usage records and event data (anonymized)
  • Timing and method of transfer: Transmitted via TLS encryption when the service is used; stored in the Americas region
  • Legal basis: Prior consent of the data subject
  • Method of refusal: Blocking cookies through browser settings or discontinuing use of the service
OpenAI:
  • Entrusted party/country: OpenAI Inc. / United States
  • Transferred items: Learning conversation content (excluding personally identifiable information) and AI prompt data
  • Timing and method of transfer: Transmitted through API communications when AI features are used; processed in the Americas region
  • Legal basis: Processing necessary to provide the service
  • Retention period: Deleted immediately after processing is completed (in accordance with OpenAI API policies)
If the details of any cross-border transfer change, the Company will provide individual notice through a website announcement and email.

5. Rights of Data Subjects

Users may request the following at any time.

5.1 List of Data Subject Rights

  • Request access to and provision of copies of personal information
  • Request the correction or deletion of errors or changes
  • Request the restriction of processing
  • Request data portability – provision in a machine-readable format
  • Request an explanation of and object to automated decision-making (including AI recommendations and personalized content)

5.2 Procedure for Exercising Rights

Method of Request: Submit a request to admin@langtwo.comProcessing Period: The Company will notify the requester of the result within 10 days of receiving the requestFees: Requests are generally free of charge; however, a reasonable fee may be charged for requests that are clearly unfounded or excessive

5.3 Additional Rights of EU Residents (GDPR)

  • Right to erasure: Request the complete deletion of personal information
  • Right to restriction of processing: Request the temporary suspension of processing under certain conditions
  • Right to object: Object to processing based on legitimate interests

6. Collection of Cookies and Other Online Identifiers

6.1 Purposes of Using Cookies

  • Strictly Necessary Cookies: Maintaining login status, security, and basic service functions
  • Analytics Cookies: Improving the service through GA4/Amplitude
  • Functional Cookies: Saving language settings and learning progress
  • Marketing Cookies: Providing personalized content (if advertising features are added in the future)

6.2 Cookie Management

Method of Refusal: Users may block or delete cookies through their browser settings (Tools ▶ Internet Options ▶ Privacy).Impact: Blocking cookies may limit certain personalized services.Consent Management: Consent for each category may be managed through “Cookie Settings” at the bottom of the website.

7. Procedures and Methods for Destroying Personal Information

7.1 Grounds for Destruction

  • Fulfillment of the processing purpose, expiration of the retention period, or a user’s request

7.2 Destruction Procedure

  1. Separate Storage: Move the data subject to destruction to a separate database
  2. Review Process: Review the appropriateness of destruction in accordance with internal policies and applicable laws
  3. Execution of Destruction: Completely destroy the information immediately or after retaining it for a specified period

7.3 Methods of Destruction

  • Electronic Files: Permanently delete using an irrecoverable method (AES-256)
  • Printed Materials: Shredding or incineration
  • Cloud Storage: Complete deletion in accordance with AWS secure deletion policies

8. Measures to Ensure the Security of Personal Information

8.1 Technical Measures

  • Encryption during transmission and storage (TLS 1.3, AES-256)
  • Database access controls and authorization management
  • 24×365 intrusion detection and log monitoring
  • Regular security updates and vulnerability assessments

8.2 Administrative Measures

  • Quarterly internal and external audits
  • Application of the principle of least privilege
  • Regular security training for employees and officers
  • Retention of access records for personal information processing systems for 2 years

8.3 Physical Measures

  • Redundancy of server rooms and backup centers
  • Access controls and CCTV installation
  • Compliance with AWS infrastructure security policies

8.4 Response to Personal Information Breaches

In the event of an incident, such as a personal information breach, the Company will notify the supervisory authority and the data subjects within 24 hours.

9. Protection of Minors’ Personal Information

9.1 Age Restrictions

  • No age-verification procedure is currently in place (only email addresses are collected)
  • Children under the age of 13 are not encouraged to use the service
  • A separate notice will be provided if an age-verification system is introduced in the future

9.2 Parental Rights

If the collection of personal information from a child under the age of 13 is confirmed:
  • Information collected without parental consent will be deleted immediately
  • Parents may request access to, correction of, or deletion of their child’s personal information

10. Personal Information Protection Officer

10.1 Personal Information Protection Officer

  • Name: 남대현
  • Position: Representative
  • Contact Information: admin@langtwo.com, 070-8983-4695
  • Address: Room 201-S38, 11-3 Euncheon-ro, Gwanak-gu, Seoul, Republic of Korea

10.2 Inquiries Regarding Personal Information

Please direct inquiries regarding the processing of personal information, complaint handling, and remedies for damages to the contact information provided above.

10.3 Remedies for Infringement of Rights and Interests

If a dispute concerning personal information cannot be resolved or remedies for damages are required:
  • Personal Information Dispute Mediation Committee: privacy.go.kr, 1833-6972
  • Personal Information Protection Commission: privacy.go.kr, 02-2100-2820
  • Supreme Prosecutors’ Office: spo.go.kr, 1301
  • Korean National Police Agency: cyberbureau.police.go.kr, 182

11. Procedure for Amending and Notifying Changes to This Policy

11.1 Amendment Procedure

When making material changes to purposes, collection items, retention periods, provision to third parties, or other significant matters, the Company will:
  1. Provide advance notice through the website announcements at least 7 days before the changes take effect
  2. Provide individual notice by email for material changes
  3. Implement the amended policy and retain the previous version

11.2 Version Management

  • Previous versions will be retained and available for review for 5 years
  • Version history may be reviewed on the website

12. Miscellaneous

12.1 Governing Law

This Privacy Policy has been prepared in accordance with the laws and regulations of the Republic of Korea. For users located outside Korea, the data protection laws and regulations of the applicable country may also apply.

12.2 Language

The Korean version of this Privacy Policy is the original version. In the event of any conflict between the Korean version and a version translated into another language, the Korean version will prevail.
Effective Date: January 15, 2025Contact: admin@langtwo.comThis Privacy Policy will be regularly reviewed and improved to protect users’ personal information securely.