Privacy Policy

Last Updated: 2026-07-02

Effective Date: 2025-01-15

SDK Co., Ltd. ("Company", "we", "our", "us"), the operator of SDK.ac (the "Service"), respects your privacy and is committed to handling personal data lawfully, fairly, and transparently. This Privacy Policy describes what information we collect, how we use it, the third parties we share it with, your rights under applicable laws — including the Personal Information Protection Act of the Republic of Korea ("PIPA") and the EU General Data Protection Regulation ("GDPR") — and how to exercise those rights. By accessing or using SDK.ac, you acknowledge that you have read and understood this Policy.

1. Scope of this Policy

This Policy applies to the website hosted at https://sdk.ac, all subdomains, and any associated services we operate (collectively, the "Service"). It does not apply to third-party websites, AI assistants, or advertisers that we link to or that may appear in advertising served on the Service. In particular, when you copy a prompt generated by one of our tools and paste it into a third-party AI service (such as ChatGPT, Claude, or Gemini), your use of that service is governed exclusively by that provider's own privacy policy. We encourage you to review the privacy notices of those third parties before providing them with personal data.

2. Personal Information We Collect

We have intentionally designed SDK.ac to collect as little personal data as possible. Specifically: - Account Data: SDK.ac does not require an account. There is no sign-up flow, no e-mail collection, and no password. We therefore hold no account records about you. - Tool Inputs: Text, code, or other content you enter into a tool is processed in your browser (see Section 3). We do not transmit, log, or store the contents of your inputs on our servers. - Preferences: Your theme and language choices are stored only in your browser's localStorage and never reach our infrastructure. - Analytics Data (automatic): Aggregated, pseudonymised metrics such as page views, referring URL, approximate country (derived from a truncated IP address), browser family, operating system, screen size, and language preference. - Advertising Data: Cookies and similar identifiers set by Google AdSense as described in Section 7. - Diagnostic Logs: Cloudflare, our edge provider, automatically logs HTTP request metadata (timestamp, method, path, response status, edge location, anonymised IP) for a short retention window for security, abuse prevention, and capacity planning. - Communication Data: When you contact us by e-mail, we receive your e-mail address, the content of your message, and any attachments you choose to send. We do not knowingly collect special categories of personal data (e.g., health, religion, biometrics), government identifiers, payment-card numbers, or precise geolocation.

3. How Text You Submit to Our AI Tools Is Processed

This section addresses the question users most often ask us: what happens to the text I type into a tool? - Processing happens on your device. Our tools (AI translator, text summarizer, prompt generator, image prompt builder, code explainer, email writer, hashtag generator, writing assistant) run their logic in your browser. The text you enter is used transiently in your device's memory to produce the output, and is discarded when you clear the input or leave the page. - We do not store your text. No tool input is transmitted to, logged by, or stored permanently on our servers. There is no server-side database of user text. - We do not train on your text. Your inputs are never used to train, fine-tune, or evaluate any machine-learning model, by us or on our behalf. - Third-party AI services are your choice. Where a tool generates a prompt intended for an external AI assistant, the prompt leaves your device only when you yourself copy it and paste it into that assistant. From that point, the processing of the text — including any transmission to an AI model API and any retention — is governed by the third-party provider's terms and privacy policy, not this one. If we ever introduce a tool that sends your text to an AI model API directly, we will say so clearly on the tool page before you submit anything, transmit the text over encrypted connections solely to generate your result, and not store it permanently.

4. Purposes of Use and Legal Bases

We use the limited information we collect for the following purposes, each tied to a legal basis under GDPR and a lawful ground under PIPA: - Providing the Service (performance of a contract / legitimate interest): rendering pages, executing tool logic in your browser, and delivering assets through our CDN. - Securing the Service (legitimate interest): detecting and mitigating abuse, denial-of-service attacks, and scraping using Cloudflare's edge security. - Improving the Service (legitimate interest, with consent where required): aggregated analytics that show us which tools are used, where users get stuck, and which pages are slow. - Showing Advertising (consent / legitimate interest depending on jurisdiction): serving advertisements through Google AdSense to fund the free Service. - Responding to You (consent / legitimate interest): replying to e-mails, bug reports, and business inquiries. - Legal Compliance (legal obligation): meeting requirements under PIPA, GDPR, Korean telecommunications and network laws, and lawful requests from competent authorities.

5. Cookies and How to Refuse Them

We use a small number of cookies and browser-storage technologies: - Strictly Necessary: minimal cookies set by our edge provider to balance traffic and mitigate bots. These cannot be disabled if you wish to use the Service. - Functional (localStorage): theme and language preferences. This data never leaves your device. - Analytics: Google Analytics cookies as described in Section 6. - Advertising: Google AdSense/DoubleClick cookies as described in Section 7. You can refuse cookies at any time. Every major browser lets you block or delete cookies: in Chrome, Settings → Privacy and security → Cookies; in Safari, Preferences → Privacy; in Firefox, Settings → Privacy & Security; in Edge, Settings → Cookies and site permissions. You may also enable tracking protection (Safari ITP, Firefox ETP, Brave Shields). Blocking cookies does not break our tools — they run in your browser regardless — though some preferences may not persist between visits.

6. Google Analytics

We use Google Analytics 4, provided by Google LLC, to understand aggregate usage of the Service. Google Analytics uses cookies in the "_ga" family to distinguish visitors; these expire after at most 24 months. We have configured IP anonymisation, do not send tool inputs or any user-generated text to Analytics, and use the data solely in aggregate (e.g., "the summarizer had N visits this week"). Google processes this data on our behalf under its data-processing terms. You can prevent Google Analytics from running by installing the official opt-out browser add-on at https://tools.google.com/dlpage/gaoptout, or by blocking analytics cookies as described in Section 5.

7. Google AdSense, DoubleClick Cookies, and Opt-Out

The Service is funded by advertising served through Google AdSense. - Google, as a third-party vendor, uses cookies — including the DoubleClick (DART) cookie — to serve ads on the Service based on your visits to this and other websites. - These cookies allow Google and its partners to serve personalised ads, cap ad frequency, and measure ad performance. A list of Google's advertising cookies and their lifetimes is available in Google's advertising privacy documentation. - Opt-out: You may opt out of personalised advertising by visiting Google's Ads Settings at https://www.google.com/settings/ads. You may additionally opt out of many other third-party vendors' personalised ads at https://www.aboutads.info/choices. - Where required by law (EU, UK, Korea and other jurisdictions), a consent banner is shown before any personalised advertising cookies are set, and you may refuse or later withdraw consent through that banner. - If you opt out, you will still see ads, but they will not be personalised to your interests.

8. Third-Party Processors and International Transfers

We share the minimum necessary information with the following processors, each acting under agreements requiring confidentiality and purpose limitation: - Cloudflare, Inc. — content delivery, DDoS mitigation, edge logging. Data: HTTP request metadata, anonymised IP. Region: global edge network. - Google LLC (Google Analytics 4) — aggregated traffic analytics. Data: anonymised IP, page views, device/browser metadata. - Google LLC (Google AdSense) — advertisement delivery and consent management. Data: advertising cookies, ad interaction events. We do not sell, rent, or lend your personal data. Some processors operate globally and may process data outside the Republic of Korea or the European Economic Area, including in the United States. Where such transfers occur, we rely on safeguards including Standard Contractual Clauses adopted by the European Commission, the EU-US Data Privacy Framework where applicable, and the cross-border transfer disclosure requirements of PIPA.

9. Retention of Personal Information

We retain personal data only for as long as necessary for the purpose for which it was collected: - Tool inputs: not retained at all — they never reach our servers. - Preferences (localStorage): retained in your browser until you clear them; we never hold a copy. - Analytics data: retained in aggregate form for up to 26 months, after which it is deleted or further anonymised. - Edge diagnostic logs: retained by Cloudflare for a short rolling window (typically under 30 days). - E-mail correspondence: retained for up to 3 years after the last exchange, to maintain context for follow-up inquiries and to satisfy Korean commercial record-keeping requirements, then deleted. When a statutory retention period under Korean law applies (e.g., records of consumer complaints and dispute resolution: 3 years under the Act on the Consumer Protection in Electronic Commerce), we retain the relevant records for the statutory period only and then destroy them without undue delay.

10. Your Rights

Subject to applicable law, you have the right to: - Access the personal data we hold about you and receive a copy; - Rectify inaccurate or incomplete data; - Erase your data ("right to be forgotten") where there is no overriding legal basis for retention; - Restrict or object to processing, including objecting to processing based on legitimate interest; - Data portability — receive data you provided in a structured, machine-readable format; - Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; - Lodge a complaint with a supervisory authority — in Korea, the Personal Information Protection Commission (privacy.go.kr) or the Korea Internet & Security Agency (KISA, 118); in the EU, your national data protection authority. Because we deliberately hold almost no personal data, most requests can be satisfied instantly: tool inputs and preferences exist only in your own browser, and clearing your browser's site data removes them completely. For anything else (e.g., deletion of e-mail correspondence), contact us as described in Section 11. We respond to verified requests within the timeframes required by GDPR (one month) and PIPA (10 days for access requests), free of charge except where requests are manifestly unfounded or excessive.

11. Privacy Officer and Contact

The Company has designated a privacy officer (개인정보 보호책임자) responsible for handling personal-data inquiries, complaints, and remedies: - Privacy Officer: Privacy Team, SDK Co., Ltd. - E-mail: contact@sdk.ac (include "Legal" or "Privacy" in the subject line) - Address: 4F, 127 Namseong-ro, Jeju-si, Jeju Special Self-Governing Province, Republic of Korea We will confirm receipt of privacy inquiries promptly and provide a substantive response within the statutory deadlines. If you believe your inquiry has not been handled adequately, you may contact the Personal Information Protection Commission of Korea (privacy.go.kr / 국번없이 182) or, in the EU, your local supervisory authority.

12. Children's Privacy

The Service is a general-audience website and is not directed at children under 14 (Korea) or under 16 (EU). We do not knowingly collect personal data from children. Because the Service requires no account and stores no tool inputs, the risk of collecting a child's personal data is inherently minimal. If you believe a child has nevertheless provided us with personal data by e-mail, contact us at contact@sdk.ac and we will delete it promptly.

13. Security Measures

We take administrative, technical, and physical measures appropriate to the low volume and low sensitivity of the data we handle: all traffic is encrypted with TLS; there is no server-side database of user content that could be breached; internal access to analytics and correspondence is limited to authorised personnel on a need-to-know basis; and our infrastructure providers (Cloudflare, Google) maintain industry-standard certifications including ISO 27001 and SOC 2. No method of transmission over the Internet is 100% secure, but our architecture minimises risk by minimising the data that exists in the first place.

14. Changes to this Policy

We may update this Policy to reflect changes in law, technology, or our practices. When we make material changes, we will post the updated Policy on this page at least seven (7) days before it takes effect (thirty (30) days for changes that materially affect your rights), and update the "Last Updated" date at the top. Your continued use of the Service after the effective date of an updated Policy constitutes acknowledgement of the changes. Previous versions are available on request at contact@sdk.ac. This Policy is effective as of 2025-01-15 and was last updated on 2026-07-02.