This policy explains what personal data SimCode (operated by Iotmaker (아이오티메이커)) collects and how it is used. We collect the minimum needed to run a learning service.
1. Data We Collect
Account — email address; display language; if you sign in with Google or GitHub, the identifier and username provided by that provider.
Learning records — course enrollments, lesson completion, per-lesson summaries (questions attempted/correct, next review date), daily activity counts. Detailed per-question answers are stored locally on your device, not on our servers.
Purchases — course pass orders (course, period, amount, payment provider reference). Card numbers are handled by the payment processors (Toss Payments, Paddle) and never reach our servers.
Code — if you connect GitHub, your code is backed up to your own GitHub repository. Otherwise, files you explicitly choose to save are stored in our database.
AI usage — request counts for quota enforcement. If you register a personal LLM API key, it is stored server-side encrypted and used only to call the provider you chose.
2. How We Use Data
To provide the service (sync progress across devices, restore purchases), process payments, enforce single-session and usage limits, and improve courses through aggregate statistics. We do not sell personal data or use it for third-party advertising.
AI providers (e.g., OpenAI, Google) — lesson text you submit for AI tutoring/grading is sent to the provider to generate a response; it is not used by us for other purposes.
4. Retention and Deletion
Account and learning data are kept while your account exists.
Deleting your account (Account → Withdraw) permanently deletes your profile, learning records, enrollments, and stored code from our systems. Payment records are retained where required by tax and commerce law.
Local data on shared devices is cleaned when you log out with the delete option.
5. Your Rights
You can view and export your learning data in the app (Learning History → Export), change your email preferences, and delete your account at any time. For access, correction, or deletion requests, contact badajsy@gmail.com. We respond within 30 days.
6. Security
Data is encrypted in transit (TLS). Database access is restricted by row-level security so users can only read their own records. Personal API keys are stored encrypted and are never sent to the browser.
7. Children
SimCode is designed for learners including students. Where required, a parent or guardian should approve account creation for children under the applicable digital-consent age. We collect only an email address for such accounts.
8. Changes and Contact
Material changes to this policy will be announced in the service. Data controller: Iotmaker (아이오티메이커). Contact: badajsy@gmail.com.