Legal
Privacy Policy
How viewer.run processes account, workspace, server-file, billing, security, and audit data.
Effective date: 2026-05-25
1. Scope
지엑스소프트 processes personal data under applicable privacy law to provide viewer.run. This policy covers accounts, workspaces, server features, support, billing, and operational security.
2. Purposes
Data is processed for registration, email verification, sign-in and account security; authorized file management and collaboration; plans, Team trials, invitations, usage, payments and refunds; access control, audit, support, compatibility analysis, and privacy-conscious improvement.
3. Data processed
Data may include name, email, password hash, provider identifier and account status; organization, role, invitations and permissions; original filename, size, storage reference, timestamps, preview and analysis metadata; plan, term, seats, usage, payment status and amount, order and receipt identifiers; securely hashed IP, User-Agent, cookies, session, path, and security and error records. When you sign in with Google, Kakao, Naver, or Microsoft, we receive your name, email, and provider account identifier within the configured authentication scopes and use them to create, link, and sign in to your account. Card numbers and CVC are not stored.
4. File analysis and auxiliary data
Server DXF files may be analyzed for version, layers, entities, and font candidates; rendered images may be stored as previews and results as sidecar data. Local files are not analyzed or stored by the server unless you explicitly choose a server feature.
5. Retention
Accounts are retained until deletion, server files until authorized deletion, and tokens until expiry, use, or revocation. Audit logs are generally retained for 90 days on Team and 365 days on Enterprise. Contract, payment, security, and dispute data may be kept longer where required by law or legitimate need.
6. Processors and international transfers
Depending on configuration, a payment provider such as Toss Payments, cloud hosting, PostgreSQL, Vercel Blob or S3-compatible storage, SMTP providers, Google/Kakao/Naver/Microsoft, and Sentry may process necessary data. When processing occurs abroad, required data is encrypted in transit and retained according to provider and operational settings. The Company does not use external authentication data for advertising unrelated to authentication or account security and does not sell personal data.
7. Cookies and sessions
Cookies and session identifiers maintain sign-in, protect authentication, and store necessary preferences. Blocking them may prevent account and workspace functions.
8. Your rights
You may request access, correction, deletion, restriction, or other rights available under applicable law. Authorized users can delete server files. Mandatory legal records, security evidence, or active dispute records may not be deleted immediately. Send requests to privacy@gxsoft.co.kr.
9. Security
Measures include password hashing, encrypted transport, token protection, least privilege, server-side role validation, audit records, and filters that prevent credentials, payment data, filenames, and file contents from entering operational logs. Incidents are investigated, notified, and mitigated as required by law.
10. Privacy contact
Company: 지엑스소프트; privacy officer: 최영구; email: privacy@gxsoft.co.kr; phone: 010-4404-1523; support: 평일 10:00~17:00, 공휴일 제외.
11. Changes
Effective date: 2026-05-25. This policy is published in the service. Material changes will be announced before taking effect through the service, email, or another suitable channel.