Privacy Policy
JumpingHigh Inc. (주식회사 점핑하이) (hereinafter the “Company”) values the personal information of users of Roundroom (hereinafter the “Service”) and complies with Korea's Personal Information Protection Act and other applicable laws. Effective date: July 29, 2026 · Version: 2026-07-29.1
1. Personal Information We Collect
- Member authentication (Google sign-in): email address, name, profile identifier
- Service usage data: meeting agendas, attached documents and their extracted text (including OCR), AI team member statements and meeting results (minutes), selected roles, language, and meeting mode
- Payment information: subscription payment details (order number, amount, payment date and time) processed through Polar (payment processor / Merchant of Record). Payment method details such as card numbers are handled by Polar, and the Company does not retain them.
- Automatically collected items: access logs, browser and device information, cookies (to maintain login sessions)
2. Purpose of Collecting and Using Personal Information
- Member identification and authentication, and provision of the Service (running meetings, organizing and storing results)
- Plan payments and recurring billing, and handling refunds and inquiries
- Service operation and security, prevention of misuse, usage statistics analysis, and quality improvement
3. Entrustment of Processing and Provision to Third Parties (Including Overseas Transfers)
To provide the Service, the Company entrusts the processing of personal information as set out below, and some processing takes place overseas.
| Processor | Entrusted Work | Transfer Country |
|---|---|---|
| Supabase Inc. | Member authentication and database | South Korea (Seoul region) |
| Vercel Inc. | Web hosting and server execution | United States |
| Functional Software, Inc. d/b/a Sentry | Error and performance monitoring and incident diagnosis | United States |
| Google LLC (Google Analytics) | Consent-based web analytics | United States, etc. |
| Meta Platforms, Inc. (Meta Pixel / Conversions API) | Consent-based conversion measurement, attribution, and campaign optimization | United States, etc. |
| Google LLC (Google Cloud Vertex AI) | Secure meeting AI processing and document OCR | United States, etc. |
| KIE.ai · evolink.ai | Standard meeting AI processing | Overseas |
| Polar Software, Inc. | Payment processing (Merchant of Record) and overseas tax filing | United States, etc. |
For standard meetings, meeting agendas and documents may be transmitted to and processed by the AI providers listed above. Secure meetings are processed only within a dedicated Google Cloud Vertex AI environment and are not transmitted to any separate third-party AI API. The transfer occurs at the time the Service is used (running meetings, attaching documents), and the items transferred are the meeting agendas, documents, and text necessary for that processing.
When an error or performance event occurs, filtered diagnostic information—such as error messages, stack traces, timestamps, request URLs and paths, browser and device information, and performance measurements—may be transmitted to Sentry's United States ingest systems. IP addresses, user identifiers, email addresses, and authentication tokens are removed or filtered from retained monitoring data. Session Replay and Profiling are disabled.
4. Retention and Use Period
- Member information: until the member withdraws. Upon withdrawal, it is destroyed without delay.
- Meeting data: until the user deletes it or withdraws membership.
- Payment and transaction records: retained for the periods prescribed by applicable laws such as Korea's Act on the Consumer Protection in Electronic Commerce, etc. (e.g., 5 years for contracts and withdrawal of subscription, 5 years for payment) and then destroyed.
- Sentry error and performance monitoring data: retained for up to 90 days. Some de-identified or pseudonymized samples may be retained for an additional period under Sentry's policies; the data is deleted when the contract ends or upon a valid deletion request.
5. Rights of Users
Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information, and may withdraw consent by withdrawing membership. Requests may be submitted using the contact details below.
6. Measures to Ensure Security
The Company takes reasonable protective measures, including management of access rights to personal information, encryption of transmission channels (HTTPS), and non-retention of payment method details (entrusted to Polar).
7. Cookies
Necessary cookies for sign-in, security, billing state, and consent preferences are always used. With analytics consent, Google Analytics runs server-side without a Google browser tag or cookie and receives a rotating pseudonymous client/session identifier, event name, page path, locale, and campaign parameters in the United States and other countries for usage analytics. Only with marketing consent, Meta Pixel in the browser and the server-side Conversions API may send visited URLs and query parameters, campaign parameters, browser and device data, conversion events, and pseudonymous identifiers to the United States and other countries for conversion measurement, attribution, and campaign optimization. Meeting agendas, attached documents, and card numbers are not sent for these optional measurement purposes.
Consent-choice records are retained for the period necessary to demonstrate compliance with applicable law. Optional analytics and advertising data and identifiers are retained only for the shortest period configured by the Company or required under the relevant provider contract and policy, and are then deleted or aggregated.
Analytics and marketing consent is optional, and rejecting it does not prevent use of the Service's core features. Users can change or withdraw consent at any time through “Cookie settings” in the footer. Optional tracking stops after withdrawal; withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.
8. Personal Information Protection Officer and Inquiries
- Business operator: JumpingHigh Inc. (주식회사 점핑하이) (Representative: Ha-i Yoon)
- Email: contact@roundroom.app
9. Duty of Notice
If there is any addition, deletion, or amendment to this policy, the Company will announce it within the Service from 7 days before it takes effect.