Soram Privacy Policy
This Policy is a public notice explaining what personal data Soram processes, on what basis and for what purpose, where it is sent, and how long it is retained. Soram does not seek blanket consent to the Policy itself; processing that legally requires consent is presented as separate, purpose-specific consent. This translation is for convenience; if it differs from the Korean version, the Korean version prevails to the extent permitted by applicable law.
Beta operation notice — this document applies to the current beta service. Unverified public information is identified in the body, and affected optional features are not offered until verification is complete.
1. Operator and privacy contact
Operator: 주홍범
Privacy officer: Not confirmed (must be confirmed before publication)
Email for access, correction, deletion, restriction, and privacy complaints: heterotopia@disroot.org
Privacy contact phone number: Not provided (must be entered before release)
The privacy officer is responsible for personal-data processing, rights requests, and complaints.
Unconfirmed or unavailable fields are not inferred values and are being verified and completed during beta operation.
2. Purposes and categories of personal data
- [Processed without consent — PIPA Article 15(1)(4), contract formation and performance] Account: OAuth provider ID and approved-scope name, email, profile image, and account state — identification, sign-in, linking, and support
- [Processed without consent — Articles 15(1)(4), 15(1)(2), and 29, contract performance and statutory safeguards] Authentication and session: token identifiers, cookies, sign-in time, and security events — continuity, access control, and abuse prevention
- [Processed without consent — Article 15(1)(4), performance of the feature requested by the user] Interpretation conversation: languages, text, audio chunks, translations, room/session/turn IDs, and usage — realtime interpretation and recovery
- [Processed without consent — Article 15(1)(4), performance of the feature requested by the user] Seminar: settings, captions, utterances, glossaries, issues, refinement requests, results, and edited drafts — captions, review, download, and recovery
- [Processed without consent — Article 15(1)(4), contract formation and performance] Registration evidence: agreed Terms version, presented and acknowledged Policy and AI-notice versions, age confirmation, and confirmation time — proof of eligibility and applicable documents
- [Separate consent — Article 15(1)(1)] Personal Voice: enrollment audio, voice profile, upstream voice ID, state, metadata, processing-consent version (Not confirmed (feature is blocked while missing)), overseas-transfer-consent version (Not confirmed (feature is blocked while missing)), and acceptance times — model creation and synthesis, consent evidence, and deletion handling. After separate consent and server validation, the displayed notice is stored as an immutable enrollment-level record.
- The provider purpose for Personal Voice features and models is not yet verified. Personal Voice is not offered until authentication or identification use is confirmed in writing.
- [Processed without consent — Articles 15(1)(4), 15(1)(2), and 29] Diagnostics and usage: internal IDs, error code, stage, latency, and minimal connection data — incident analysis, security, quota enforcement, and service delivery. Categories, periods, and deletion-verification details follow the retention and deletion rules below.
3. Retention and deletion
When the purpose ends, a period below expires, or a valid deletion request is completed, the responsible deletion process or role permanently deletes electronic files so they cannot be restored or reproduced. A restored backup is subject to re-deletion.
- Beta operation item: dataset-level retention and deletion rules are being verified and completed; unresolved optional features are not offered.
- Temporary browser backups of seminar refinement drafts: assigned a 24-hour expiry and automatically removed on the next visit to the relevant screen; they may remain in localStorage until then.
4. Google and Kakao sign-in
You are redirected to Google or Kakao for authentication. Soram does not receive your social-account password; it receives the provider-specific account identifier and profile information within the scope you authorize.
The sign-up flow creates a new account with a new provider account only after Terms agreement and minimum-age confirmation. If that provider account is already registered, Soram neither creates an account nor signs it in and instead shows existing-account guidance.
The sign-in flow authenticates only a provider account already connected to Soram and does not create a new account. An unregistered account receives sign-up guidance, and an account from another provider is not linked automatically merely because its email address matches.
Short-lived security cookies protecting OAuth state, PKCE verifier, nonce, and the sign-in or sign-up intent expire within minutes and are cleared when authentication ends. Each provider’s independent processing is governed by that provider’s privacy policy.
5. Processing providers and international transfers
When a relevant feature is used, personal data is transferred continuously or as needed to the providers in the public list below over encrypted HTTPS, WSS, and database connections.
Personal Voice disclosure — recipient: Not confirmed (feature is blocked while missing); contact: Not confirmed (feature is blocked while missing); countries: Not confirmed (feature is blocked while missing); retention: Not confirmed (feature is blocked while missing). The UI and server block enrollment if a consent version or required value is empty or a submitted version differs.
Processor entities, processing countries, subprocessors, retention/deletion, and training-use terms are being checked and completed against contracts, DPAs, and provider consoles. Optional features whose review is incomplete are not offered.
- Beta operation item: processor-level overseas-transfer and outsourcing information is being verified and completed; unverified optional features are not offered.
6. Cookies and browser storage
Soram uses HttpOnly cookies for authentication and security, a language-preference cookie, sessionStorage, and localStorage. Authentication session cookies last no more than 30 days; the separate language-preference cookie may last up to one year.
sessionStorage may hold up to 200 recent messages, including source text, translations, and playback-related values, and generally disappears when the tab or window closes. localStorage may hold up to five recent room codes, roles, participant keys, and language pairs with a five-minute expiry, plus plaintext seminar refinement backups with a 24-hour expiry. Expired items are removed by lazy prune on the next visit. After successful sign-out or account withdrawal, chat, remote, seminar, entry-intent, recent-room, participant-key, and refinement-draft user-content keys are explicitly cleared, while device preferences such as language are retained.
You can use your browser’s site-specific cookie and site-data settings to delete Soram cookies and stored data, including sessionStorage and localStorage, or block cookies and site-data storage to refuse automatic collection and storage. Deleting or blocking them may limit or reset sign-in continuity, session recovery, language preferences, recent rooms, seminar draft recovery, and other features.
7. Your rights and deletion requests
You may request access, correction, deletion, restriction, withdrawal of consent, and account withdrawal. Contact: heterotopia@disroot.org, Not provided (must be entered before release)
Soram may verify the requester’s identity. A request may be limited where needed to protect another person’s rights or meet a legal retention duty, and Soram will explain the reason and outcome.
You can delete browser-only data through browser settings. The database records both the registration legal-document and minimum-age confirmation and an immutable enrollment-level record of the Personal Voice processing/overseas-transfer versions, server acceptance times, and displayed disclosure snapshot. Upstream deletion API calls are linked to both the dedicated Personal Voice deletion flow and account withdrawal.
8. Security safeguards
Soram applies encrypted transport, HttpOnly/Secure/SameSite cookies, access controls, token expiry, and data minimization. Structured realtime diagnostics permit only approved fields and exclude conversation content.
Operational verification records for access reviews, key management, supplier checks, backup deletion, and incident response are maintained in the public lists above and internal operations records.
9. Children
During registration, the user directly confirms that they are at least 14; OAuth authentication cannot start without that confirmation. Soram does not currently collect date of birth or offer a parental-consent path, so users under 14 cannot register.
10. Changes to this Policy
If this Policy changes, Soram will announce the effective date and material changes. A change requiring separate consent will follow applicable requirements.
This Policy applies to the current beta service. Unverified public information about processors, retention/deletion rules, and the biometric purpose of Personal Voice will continue to be completed; affected optional features are not offered until verification is complete.
This English translation is for convenience. If it conflicts with the Korean version, the Korean version prevails to the extent permitted by applicable law.