Privacy Policy
Effective: April 19, 2026
Version: 1.0
5DO (5th Density Oscillator, "Service") is operated by SPINIT ("we", "our", "us"). This Privacy Policy explains how we collect, use, store, and share information when you use the Service.
1. Information We Collect
Required
- Email address — account identification and login
- Profile info — name and profile image provided by Google/Kakao OAuth when you sign in with those providers
- Language preference — Korean or English
Optional (when using Soul Code)
- Date of birth (solar/lunar), time of birth, place of birth
- Gender, blood type, MBTI
- Free-text Intention input
Payment (for paid subscriptions)
- Masked card info (partial number, expiration), payment history, subscription status
- Full card numbers are stored directly by Toss Payments per PCI-DSS; 5DO does not store them.
Automatically Collected
- IP address — used solely for default language detection (KR IP → Korean default)
- Usage logs — playback history, favorites (mostly stored locally via localStorage)
- Device info — device type, browser
2. How We Use Information
- Account creation and authentication
- Billing and subscription management
- Personalization of AI soul analysis (Soul Code)
- Generating the Daily Resonance report
- Customer support and notification emails
- Service improvement and anonymized analytics
3. Retention
- Data is retained while your account is active.
- On account deletion, data is destroyed immediately; backups are purged within 30 days.
- Payment records: retained for 5 years per Korean e-commerce law.
- Soul Code analyses: deleted immediately upon user request.
4. Third-Party Processors
We do not sell personal data and do not share it for advertising purposes. We use the following processors to provide the Service:
| Processor | Purpose | Country |
| Supabase Inc. | Database, auth, storage | USA |
| Anthropic PBC | AI soul analysis (Claude API) | USA |
| Toss Payments | Payment processing, recurring billing | Korea |
| Google LLC | OAuth sign-in (optional) | USA |
| Kakao Corp. | OAuth sign-in (optional) | Korea |
| Render.com | Server hosting | USA |
| Resend | Transactional email | USA |
| ElevenLabs / TypeCast | Pre-rendered meditation narration | USA / Korea |
International Data Transfer
- Transfers: to the overseas processors listed above.
- Purpose: necessary for providing the Service.
- Legal basis: user consent (indicated by acceptance of this policy).
5. Cookies & Local Storage
- Cookies: maintain login session (Supabase Auth).
- localStorage: language selection, favorites, playback history, UI settings, Soul Code cache.
- You may block these in your browser, but some features will be limited.
6. Your Rights
You may at any time request:
- Access to your personal data
- Correction or deletion
- Suspension of processing
- Account deletion (in-app profile settings or by emailing us)
7. Children Under 14
5DO does not knowingly collect data from children under 14. If we learn we have collected such data, we will delete it immediately.
8. Security
- TLS (HTTPS) encryption in transit
- Hashed password storage via Supabase Auth standards
- Least-privilege access control and audit logs
- Row-Level Security (RLS) on database tables
9. Data Protection Officer
10. Changes to This Policy
We may update this policy to reflect changes in the law or the Service. Material changes will be announced via in-app notice or email before taking effect.