Privacy
Effective · [settled before launch]
Draft — not yet reviewed by a lawyer. The text describes what the system actually does today; [settled before launch] marks facts not yet fixed.
The Korean text is the original; where a translation differs, the Korean text prevails.
[settled before launch] (the "Operator") runs Kallimachos (the "Service") and publishes this policy under Article 30 of the Personal Information Protection Act of Korea.
Article 1 — What we collect, and how
- Account — your email address, given by you through the email sign-in link or Google sign-in. With Google we receive only the address and whether Google has verified it.
- Usage records — when the account was created, when sessions were created, the name / creation time / last-used time of credentials (tokens), and the optional first-run answers (what you do, how you heard of us).
- Knowledge data — the search index and knowledge graph you build on your own machine and upload: Entity names and descriptions · Relations between entities · Chunk text used for search (parts of your notes) · Document paths and titles. Because it is extracted from your notes it can contain the content of your notes themselves. The server stores it and returns it as search results to your own AI clients.
- Billing — subscription status and period, and the reference issued by the payment processor. Card numbers and other payment details are handled by the processor; the Operator never stores them.
- Automatically — server access logs. Logs are kept by the front web server; for the marketing site (
https://kallimachos.dev) and the app server (https://app.kallimachos.dev) it records IP address, request path, time and processing time, and is configured to drop the query string (sign-in tokens live there). The MCP server (https://mcp.kallimachos.dev) records not even the path, because the path itself is the secret. When a request is rejected as malformed, only the IP, time and status are recorded — never the request line. Separately, the MCP application writes one line per request recording the HTTP method, response status and processing time — no URL, no IP, no query content.
What is never uploaded — A mirror of your whole vault folder · Your raw Claude conversations — only the distilled documents · Any LLM call on the server — extraction runs on your machine. The Service uses no advertising or analytics trackers and never calls an LLM on the server.
Article 2 — Why
- Identifying your account, signing you in, sending sign-in links
- Storing your knowledge data and serving it to your own AI clients
- Managing the subscription, billing, and VAT reporting
- Keeping the Service stable and secure — abuse prevention, incident analysis
- Meeting legal obligations
Article 3 — How long
| Data | Retention |
|---|---|
| Account · usage records · knowledge data · credentials | Erased immediately when you delete the account |
| Sign-in links | Valid 15 minutes, purged within 24 hours of expiry |
| Sessions | 30 days, or on log-out |
| Server access logs | Up to 90 days |
| Disaster-recovery copies | Rotated out within 30 days — account deletion reaches the copies within that window |
| Contract, withdrawal and payment records | 5 years — Act on Consumer Protection in Electronic Commerce, Art. 6 and Enforcement Decree Art. 6 |
Article 4 — Sharing with third parties
The Operator does not provide your personal data to third parties, except where a law requires it or you separately consent.
Article 5 — Processors
| Processor | Task |
|---|---|
| [settled before launch] ([settled before launch]) | Server operation and data storage |
| [settled before launch] | Payment processing and billing |
| [settled before launch] | Delivery of sign-in link emails |
| Google LLC | Google sign-in — only if you choose it |
Article 6 — Cross-border transfer
The servers are located in [settled before launch]. If that is outside Korea, this policy discloses the items required by Article 28-8(2) of the Act, as permitted by Article 28-8(1)3(a).
| Required disclosure (Art. 28-8(2)) | Detail |
|---|---|
| 1. Data items transferred | Everything in Article 1 |
| 2. Country, timing and method | [settled before launch] · when you use the Service · over the network (TLS) |
| 3. Recipient's name and contact | [settled before launch] · [settled before launch] |
| 4. Recipient's purpose and retention | Purposes in Article 2 · periods in Article 3 |
| 5. How to refuse the transfer, and what refusing means | Tell us at thbeem94@gmail.com and we act immediately. Because the servers are in that country, refusing means the cloud service cannot be used — delete the account and use the free self-host build, and nothing is transferred. |
Google sign-in sends your email address to Google LLC (United States, privacy@google.com). Use the email sign-in link if you do not want that transfer.
Article 7 — Your rights
- Access — account details are in the account menu; the home screen shows the size of the uploaded knowledge data. The original of that data is on your own machine.
- Erasure — account menu → "Delete account". Sessions, credentials, the subscription and the knowledge data are erased immediately; the subscription is canceled first.
- Correction, suspension and anything else — thbeem94@gmail.com. We act without delay and tell you the result.
- Children under 14 may not use the Service and we do not knowingly collect their data.
Article 8 — Erasure
When a retention period ends or the purpose is fulfilled, data is erased without delay, in a way that cannot be recovered. No paper records are kept.
Article 9 — Security
- Encryption in transit (TLS)
- Sign-in links, sessions and credentials are stored only as hashes — a leaked database cannot be used to sign in
- Session cookies are HttpOnly · Secure · SameSite
- Storage isolated per user; access limited to the Operator
- Access logs kept and reviewed
Article 10 — Cookies and browser storage
| Name | Purpose | Lifetime |
|---|---|---|
kal_session | Keeps you signed in | 30 days or log-out |
kal_oauth | Forgery protection during Google sign-in | 10 minutes |
kal.lang (localStorage) | Display language | Until you clear it |
kal.next · kal.plan (sessionStorage) | Where to return after sign-in | Until the tab closes |
No tracking or advertising cookies. If your browser rejects cookies you cannot stay signed in.
Article 11 — Data protection officer
[settled before launch] · thbeem94@gmail.com
Article 12 — Remedies
- Personal Information Infringement Report Center (KISA) — 118 · privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee — 1833-6972 · kopico.go.kr
- Supreme Prosecutors' Office — 1301 · National Police Agency — 182
Article 13 — Changes
Changes are posted on this page 7 days before they take effect. Material changes — new data items or purposes — are also sent to your account email.
Article 14 — Operator
[settled before launch] · [settled before launch] · [settled before launch] · thbeem94@gmail.com
← Home