Winging Builder Privacy Policy

WilconAI Co., Ltd. (hereinafter referred to as the “Company”) complies with the Personal Information Protection Act and other relevant laws, and is committed to protecting users’ personal information and safeguarding their rights in connection with the Winging Builder service.
This Policy applies to all users of the Winging Builder service and sets forth the standards regarding the collection, use, retention, and provision of personal information processed during the provision and operation of the service.

Article 1 (Purpose)

The purpose of this Privacy Policy is to establish standards for the safe processing and protection of users’ personal information in connection with the Winging Builder service provided by the Company, in accordance with the Personal Information Protection Act and other relevant laws.
Through this Policy, the Company clarifies the purposes of collection and use of personal information, items and methods of collection, retention and use period, third-party provision and outsourcing matters, users’ rights and the methods to exercise them, and security measures. The Company respects users’ rights and processes only the minimum personal information necessary.

Article 2 (Definitions)

  1. “User” refers to any individual who uses the Winging Builder service and is classified as follows:
    1. Enterprise User: An individual entrepreneur or corporation that subscribes to Winging Builder and creates/manages AI agents.
    2. Website Visitor: A general user who accesses the website or application built by an Enterprise User and interacts with an AI agent.
  2. Unless otherwise specified, “User” shall include both Enterprise Users and Website Visitors.

Article 3 (Items of Personal Information Collected)

[Enterprise Users]
  • Required at sign-up: Email and authentication credentials
  • Optional profile information: Name, phone number, company name, department, position, website address, etc.

[Common – Enterprise Users & Website Visitors]
  • Automatically collected: Access logs, IP address, browser information, etc
  • User-provided: Uploaded or input documents, URLs, conversation content, etc

Article 4 (Methods of Collection)

[Enterprise Users]
  • Direct input during sign-up
  • System logs generated during service use.
  • Customer support, inquiries, and event participation.

[Website Visitors]
  • Inputs during interactions with AI agents
  • Automatically collected logs while using the website
  • Pop-ups/forms (e.g., email, phone number)

Article 5 (Purposes of Use of Personal Information)

[Enterprise Users]
  • Membership management (sign-up, authentication, notifications, etc.)
  • Service provision and operation: AI agent building, data processing, technical support.
  • Billing management: Subscription payment, tax invoice issuance, etc.
  • Marketing: Feature updates, event notifications.

[Website Visitors]
  • Consultations and information provision via AI agents
  • Storage and retrieval of consultation history
  • Handling of visitor inquiries
  • Transmission to the relevant enterprise for follow-up purposes (with prior consent)

Article 6 (Retention and Use Period of Personal Information)

[Enterprise Users]
  • Retained during the service usage period and deleted immediately upon withdrawal.
  • However, certain items are retained for the statutory period:
    1. Contract/withdrawal of subscription: 5 years
    2. Payment records: 5 years
    3. Dispute resolution: 3 years

[Website Visitors]
  • Conversation history and input data are retained for up to 1 year for AI service quality improvement and support purposes, and may be deleted earlier upon enterprise request.
  • Retained separately if legally required.

Article 7 (Provision of Personal Information to Third Parties)

The Company does not provide personal information to external parties except in the following cases:
  1. When prior consent is obtained from the user
  2. When required by law or requested by investigative authorities
  3. When website visitor information is provided to the relevant Builder client enterprise (with prior consent)
For purchases made through Paddle, Paddle acts as the Merchant of Record and independently processes buyer and payment information in accordance with the Paddle Privacy Notice.

Article 8 (Outsourcing of Personal Information Processing)

[Common]
Service ProviderDetails of Delegated Processing
Microsoft Azure, Amazon Web Services, Google Cloud Platform, MongoDB AtlasCloud infrastructure, service operation, and data storage
OpenAIAI-powered features and response generation
Google, Microsoft Clarity, SentryEmail communications, service analytics, and error monitoring


[International Processing and Transfers]
Recipient / CountryData / Transfer MethodPurpose / Retention
OpenAI / United States and the locations listed in OpenAI’s subprocessor noticePrompts and conversation content, transmitted securely when AI features are usedAI response generation / Deleted after processing within the retention period configured for the Company’s account
Google Workspace / United States and the locations listed in Google’s subprocessor noticeEmail inquiry data, transmitted securely when the User contacts the CompanyCustomer communications / For the support relationship and the Company’s configured email retention period
Google Analytics, Microsoft Clarity / United States and the locations listed in each provider’s subprocessor noticeIdentifiers and usage logs, transmitted securely only after Analytics consentService analytics / Until consent is withdrawn, followed by deletion within each service’s configured deletion cycle
Sentry Error Monitoring / United States and the locations listed in Sentry’s subprocessor noticeError diagnostics, device information, and relevant user context, transmitted securely when an error occursSecurity and service reliability / For the service contract and Sentry’s configured deletion cycle
Sentry Session Replay / United States and the locations listed in Sentry’s subprocessor noticeMasked interaction and replay data, transmitted securely only after Session Replay consentError diagnosis / Until consent is withdrawn, followed by deletion within Sentry’s configured deletion cycle
Paddle / United Kingdom, United States, and the location of the applicable Paddle entityBuyer, account, and transaction information, collected or transmitted securely during checkoutPayment, tax, invoicing, and refunds / For the transaction relationship and any additional period required by applicable tax and transaction laws
Users may disable optional analytics and replay transfers through Cookie Preferences. If information required for AI or payment processing is not transferred, the requested AI or payment feature cannot be provided. The Company applies contractual and organizational safeguards where required by applicable law.

※ If the list of service providers changes, users will be notified via this Privacy Policy or service notice.

Article 9 (Procedures and Methods of Personal Information Destruction)

[Common]
  • Destruction procedures: Personal information is stored for a certain period after the purpose of collection/use has been achieved, in accordance with internal policies or laws, and is then destroyed.
  • Destruction methods:
    1. Electronic files: Permanently deleted using technical methods to prevent recovery
    2. Printed documents: Shredded or incinerated

[Website Visitors]
  • Conversation history and input information are destroyed within 1 year of retention, and may be deleted earlier upon enterprise request.

Article 10 (User Responsibility and Prohibition of Uploading Sensitive Information)

The Company notifies users of their responsibility regarding sensitive personal information. If a user uploads sensitive personal information without deletion or masking, the user shall bear full responsibility, and the Company shall not be liable. Prohibited sensitive information includes, but is not limited to:
  • Beliefs, political opinions, union/party membership, health/sexual life, genetic/biometric data, criminal records, etc.
  • Resident registration numbers, foreigner registration numbers, passport numbers, driver’s license numbers, etc.
  • Bank account numbers, credit card numbers, passwords, security card/OTP numbers, etc.
  • Scanned copies of ID cards (resident registration card, driver’s license, passport, etc.)
  • Medical/health-related information (diagnosis, medical history, prescriptions, disability registration, etc.)

[Website Visitors]
  • Conversation history and input information are destroyed within 1 year of retention, and may be deleted earlier upon enterprise request.

Article 11 (Users’ Rights and How to Exercise Them)

Users may exercise the following rights regarding their personal information at any time:
  • Request to access, correct, or delete personal information
  • Request to suspend processing or withdraw consent

Article 12 (Measures to Ensure Security of Personal Information)

The Company implements the following measures to protect personal information:
  • Encrypted storage
  • Minimization and monitoring of access rights
  • Intrusion prevention and server security enhancement
  • Anti-tampering measures for logs

Article 13 (Personal Information Protection Officer)

  • Name: Jeong-Eun Ha
  • Title: Personal Information Protection Officer
  • Contact: +82-31-781-6900
  • Email: [email protected]

Article 14 (Changes to the Privacy Policy)

This Policy may be revised due to changes in laws or service policies. Any changes will be notified via the service interface or the official website.

Article 15 (Procedure for Reporting Rights Infringement)

  • If a User believes that their personal information has been infringed, they may report the infringement to the Company.
  • Reports of rights infringement may be submitted to the Customer Center or by email ([email protected]), and the Company shall promptly verify the facts and take necessary action without delay.
  • When a report of rights infringement is received, the Company shall notify the reporting party of the outcome of the handling process.

Article 16 (Effective Date)

This Privacy Policy shall take effect as of July 23, 2026.
WilconAI Co., Ltd. | CEO Jung-eun Ha
Business Registration Number : 856 - 81 - 03452
Mail-order-sales registration number : 2025-SeongnamBundangB-0647
Address : 503, 13, Seohyeon-ro 180beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
[email protected]+82 031-708-8088
Copyright © WilconAI Co.,Ltd. All rights reserved.