CoMente (the “Company”) establishes and publishes this Privacy Policy (the “Policy”) to protect users’ personal information and promptly handle related complaints in accordance with the Personal Information Protection Act and other applicable laws. This Policy applies to the Summet website, desktop applications, mobile applications, and related services provided by the Company.
Article 1 (Personal Information Processed)
The Company may process the following personal information.
1. Sign-up and account management
The Company may process the following information for sign-up, login, identity verification, and account management.
- Required items: name, email address, phone number, password or authentication information, user identifier, login history
- Optional items: name, profile image
2. Information generated or processed while using the Service
The Company may process the following information while providing the Summet service.
- Meeting recording audio files
- Microphone audio, camera video, and meeting participation information when using video meetings
- Text conversion records
- Documents, images, photos, videos, audio files, and other attachments uploaded or attached by users
- Memos, prompts, and Q&A content written by users
- AI summaries, meeting minutes, memos, Q&A, PDF/PPT files, and other generated outputs
- Service settings, synchronization information, push tokens, notification receipt/open records, and device identifiers
- Access date and time, service usage records, click logs, and error logs
- IP address, device information, browser information, and operating-system information
- Input values used when AI Features run, such as transcript text, memo content, prompts, and portions of uploaded documents
- When users use Gmail integration, connected email account information, email subjects, sender and recipient information, email bodies, attachments, thread information, labels, and related metadata
- When users use Google Workspace integration, schedule information, document information, file information, Drive metadata, contact information, and other work data within the scope consented to by the user
- When users use the AI translated phone call feature: SMS phone verification information for sign-up and account management, outbound and inbound phone numbers, call connection status, call duration, call session identifiers, and voice audio during calls (temporarily processed for real-time speech transcription, translation, and text-to-speech)
3. Payment and subscription use
The Company may process the following information for Paid Services, subscriptions, recurring payments, and refunds.
- Payment Channel information
- Payment approval and cancellation history
- Subscription status and payment history
- For website payments: Payment Channel, email address, country or region, Paddle customer, transaction and subscription identifiers
- For Apple App Store in-app payments, transaction identifiers, product identifiers, receipt verification information, subscription status, and payment or refund status information
- For Google Play in-app payments, order numbers, purchase tokens, product identifiers, subscription status, and payment or refund status information
- Payment-related verification information necessary for customer support or dispute handling
As a rule, the Company does not directly store sensitive payment information such as full credit card numbers, card passwords, or CVC/CVV values. Such information may be processed by the relevant payment provider or App Market.
4. Customer support and inquiries
- Inquirer email address
- Inquiry content
- Consultation and handling history
- Attached materials
Article 2 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes.
- Sign-up, login, identity verification, and account management
- Providing service features such as meeting recording, speech transcription, video meetings, AI translated phone calls, summaries, Q&A, translation, meeting minutes, and document generation
- Storing user settings, synchronization, push notifications, and app operation
- Customer support, inquiry response, and notices
- Providing Paid Services, payment processing, purchase verification, subscription status confirmation, refunds, accounting and settlement, and preventing duplicate, fraudulent, or erroneous payments
- Service improvement, feature development, quality enhancement, security, and incident response
- Compliance with legal obligations, dispute handling, and prevention of unauthorized use
- Providing email summaries, schedule integrations, document and file integrations, and productivity features through integrations with Gmail, Google Workspace, and other external work tools
Article 3 (Data Processing Method within the Service)
- The Company may use Firebase for member authentication, user identification, settings synchronization, push notifications, and app operation support.
- The Company may use external cloud infrastructure such as Amazon Web Services (AWS) for server operation, storage, backup, network, security, incident response, and performance optimization.
- When users use AI summaries, Q&A, translation, meeting minutes, document generation, or similar features, the Company may process transcript text, memo content, prompts, portions of uploaded files, Q&A inputs, and related data.
- The Company may use external AI service providers such as OpenAI (GPT), Anthropic (Claude), and Google (Gemini) to perform AI Features requested by users, and relevant data may be transmitted to and processed by such providers within the necessary scope.
- The Company handles personal information within the minimum scope necessary for processing purposes, and minimal technical logs may be temporarily generated for service operation, security, and incident response.
- If users do not use external AI Features, transmission to external AI service providers may not occur, but processing through external infrastructure such as Firebase or AWS may still occur for basic service provision, including authentication, storage, synchronization, security, and server operation.
- When users use Gmail integration, the Company may process Gmail-related data within the scope necessary for email summaries, meeting integration, task organization, draft replies, search, or other functions requested by the user.
- When users use Google Workspace integration, the Company may integrate schedules, documents, files, contacts, or other work data to provide work assistance, meeting preparation, record organization, search, recommendation, and document generation.
- The Company activates Gmail or Google Workspace integrations only within the scope explicitly selected or consented to by users, and processes related information only within the minimum scope necessary to perform those features.
- The Company may process transaction identifiers, order information, receipt verification information, or subscription status information provided by each Payment Channel to provide Paid Services, confirm payment status, verify purchases, confirm auto-renewal, reflect refund or cancellation status, and prevent duplicate or fraudulent payments.
- When the user enables “Privacy protection mode” in settings, the Company may mask selected patterns in AI chat messages on the user’s device or browser (email, phone number, resident ID pattern, card number pattern, bank account pattern, address pattern) by replacing matched text with tokens before sending the message to external AI providers. This masking runs on the device or browser; the on/off state and selected item types are stored in device or browser storage. Masking is not applied when the mode is off.
- The Company may provide the AI translated phone call feature through mobile phone number verification (SMS), public switched telephone network (PSTN) call connection, and real-time processing of call audio for speech-to-text, translation, and text-to-speech, using external providers such as Twilio, Soniox, and OpenAI.
- Retention of call recordings and call records: If you use the call saving features (call recording, call memo), the recording file and its transcription and summary are stored in your own library and retained until you delete them or withdraw your membership. You may delete individual recordings and records at any time from the corresponding screen in the app or on the web, and call recordings and call records are deleted together with your account upon withdrawal. If you use only real-time interpretation without the saving features, audio processed temporarily for interpretation is destroyed without delay once the purpose is achieved.
- Personal information of the other party to a call: Because of the nature of a phone call, the phone number and voice of the person you speak with may also be processed and stored when you use the AI translated phone call and call saving features. The Company processes such information solely to provide you with the call feature and its outputs (transcription, translation, summary), and does not use it for any other purpose or provide it separately. You must use the recording feature without infringing the rights of the other party under applicable laws and, where required, inform them that the call is being recorded. The other party’s information is deleted together with the relevant call record or upon your withdrawal.
Article 4 (Retention and Use Period)
As a rule, the Company destroys personal information without delay once the purpose of processing has been achieved. However, certain information may be retained for the periods below when required by applicable laws or service operation.
- Member information: until membership withdrawal
- Content created or uploaded by the user (recordings, call recordings, transcripts, meeting minutes, documents, chats, attachments, etc.): until the user deletes it individually or withdraws membership
- Payment and transaction records: until the retention period required by applicable laws
- Customer inquiry and consultation records: five years after handling is completed
- Records for prevention of unauthorized use and security response: until the purpose is achieved
- Service operation logs and analytics data: retained within the scope of operational purposes and then deleted or de-identified
Article 5 (Destruction Procedure and Method)
- When personal information becomes unnecessary due to expiration of the retention period or achievement of the processing purpose, the Company destroys such personal information without delay.
- As a rule, the Company processes and stores personal information in electronic form, and electronically stored personal information is deleted using secure methods so that it cannot be restored or reproduced. If personal information is exceptionally recorded on paper documents, it is destroyed by shredding, incineration, or similar methods.
Article 6 (Provision of Personal Information to Third Parties)
As a rule, the Company does not provide users’ personal information to external parties. Exceptions apply in the following cases.
- Where the user has given prior consent
- Where a special provision of law exists or provision is unavoidable to comply with a legal obligation
- Where an investigative agency or other public authority requests information through lawful procedures under applicable laws
- Where related data is transmitted to an external AI service provider within the scope necessary to perform an AI Feature requested by the user
- Where the user purchases a Paid Service through Paddle Checkout, in which case information necessary for payment is provided to Paddle.com Market Limited as Merchant of Record, as follows:
- Recipient: Paddle.com Market Limited (Ireland)
- Purpose: payment, recurring billing, invoicing, tax calculation, collection and remittance, refunds, fraud prevention, and buyer support as Merchant of Record
- Items: email address, country or region, transaction and subscription identifiers, payment status, purchased product information, and the minimum other information needed to process the payment (the Company does not provide full card numbers, CVC, or similar sensitive data; Paddle collects those directly)
- Retention: for the period required by Paddle’s policies and applicable laws
Article 7 (Entrustment of Processing and Use of External Services)
The Company may use external service providers or entrust related tasks to provide the Service smoothly.
- Firebase: member authentication, data storage, push notifications, app operation support
- Amazon Web Services (AWS): server operation, data storage, backup, network and infrastructure management
- OpenAI: GPT-based AI Feature processing
- Anthropic: Claude-based AI Feature processing
- Google (Gemini): AI Feature processing and related service operation support
- Google Workspace / Gmail: email integration, schedule integration, document and file integration, work productivity features
- Apple App Store: iOS in-app payments, subscription management, payment status provision, and related procedures
- Google Play: Android in-app payments, subscription management, payment status provision, and related procedures
- Twilio: mobile phone number SMS verification, public telephone network (PSTN) call initiation and connection, call audio streaming, and call quality
- Soniox: real-time speech-to-text and text-to-speech (TTS) for calls and recordings
- Other providers notified through service screens, the website, or separate policies: email sending, log analysis, customer support, real-time communication, video-meeting quality, voice-call quality, and similar tasks
The Company performs management and supervision obligations for processors or external service providers in accordance with applicable laws.
Article 8 (Overseas Transfer of Personal Information)
During service provision, some personal information or related data may be processed through providers or infrastructure located overseas.
1. Overseas transfer related to infrastructure and authentication
- Recipient: Firebase, Amazon Web Services (AWS)
- Destination country: United States and other countries where the providers operate
- Transferred items: account information, user identifiers, service usage records, device information, stored data, and information necessary for service operation
- Purpose: member authentication, data storage, synchronization, push notifications, server operation, backup, security, and incident response
- Timing and method: transmitted from time to time through information and communications networks during sign-up, login, or service use
- Retention and use period: until the processing purpose is achieved or for the period required by applicable laws and provider policies
2. Overseas transfer related to AI Features
- Recipient: OpenAI, Anthropic, Google
- Destination country: United States and other actual processing countries
- Transferred items: transcript text, memo content, prompts, Q&A inputs, portions of uploaded files, and information entered or submitted by the user to perform AI Features
- Purpose: performing requested features such as AI summaries, Q&A, translation, meeting minutes, and document generation
- Timing and method: transmitted from time to time through information and communications networks when the user runs the relevant feature
- Retention and use period: until the processing purpose is achieved or for the period under each provider’s policies and applicable laws
3. Overseas transfer related to Paddle website payments
- Recipient: Paddle.com Market Limited (Ireland)
- Destination country: Ireland, the United States, and other actual processing countries of Paddle
- Transferred items: payment-related identifiers, transaction information, payment status information, Paddle transaction and subscription identifiers, or other information necessary for payment processing
- Purpose: payment processing, recurring billing, tax processing, refunds, and buyer support as Merchant of Record
- Timing and method: transmitted from time to time through information and communications networks when a Paddle payment or refund is requested
- Retention and use period: until the processing purpose is achieved or for the period required by applicable laws and Paddle’s policies
Provision to Paddle is described in Article 6 (third-party provision) together with this paragraph.
4. Processing related to Apple App Store in-app payments
- Recipient: Apple
- Destination country: United States and other actual data-processing countries of Apple
- Transferred items: transaction identifiers, product identifiers, receipt verification information, subscription status, payment or refund status information
- Purpose: in-app payment processing, purchase verification, subscription management, and reflecting refund or cancellation status
- Timing and method: transmitted from time to time through information and communications networks when the user purchases, renews, cancels, or requests a refund for a Paid Service in the iOS application
- Retention and use period: until the processing purpose is achieved or for the period required by applicable laws and Apple policies
5. Processing related to Google Play in-app payments
- Recipient: Google
- Destination country: United States and other actual data-processing countries of Google
- Transferred items: order number, purchase token, product identifier, subscription status, payment or refund status information
- Purpose: in-app payment processing, purchase verification, subscription management, and reflecting refund or cancellation status
- Timing and method: transmitted from time to time through information and communications networks when the user purchases, renews, cancels, or requests a refund for a Paid Service in the Android application
- Retention and use period: until the processing purpose is achieved or for the period required by applicable laws and Google policies
6. Overseas transfer related to Google Workspace / Gmail integration
- Recipient: Google
- Destination country: United States and other actual data-processing countries of Google
- Transferred items: email account information, email subjects, sender and recipient information, bodies, attachments, schedule information, document information, file information, contact information, and related metadata within the scope consented to by the user
- Purpose: email integration, schedule integration, document and file integration, search, summaries, draft writing, and work productivity features
- Timing and method: transmitted from time to time through information and communications networks when the user activates or uses Google Workspace or Gmail integration
- Retention and use period: until the processing purpose is achieved or for the period required by applicable laws and provider policies
7. Overseas transfer related to AI translated phone calls and SMS verification
- Recipient: Twilio, Soniox, OpenAI
- Destination country: United States and other actual processing countries of each provider
- Transferred items: mobile phone number, SMS verification information, outbound and inbound phone numbers, call status and session information, call audio, and text generated for transcription, translation, and speech synthesis
- Purpose: mobile phone verification, PSTN call connection, and real-time translated voice call features
- Timing and method: transmitted from time to time through information and communications networks during sign-up, phone verification, or use of the AI translated phone call feature
- Retention and use period: until the processing purpose is achieved or for the period required by applicable laws and each provider’s policies
Where required by applicable laws, the Company separately notifies or obtains consent for overseas transfers.
Article 9 (User Rights and How to Exercise Them)
Users may exercise the following rights against the Company at any time.
- Request access to personal information
- Request correction if there is an error
- Request deletion
- Request suspension of processing
- Withdraw consent
Users may exercise these rights through service settings, customer support, or the contact below, and the Company will take action without delay in accordance with applicable laws.
Account and Related Data Deletion
- The app or service name shown in the store listing is Summet, and the developer or company name is CoMente.
- How to request deletion: sign in to the Summet app and select Delete Account in the settings screen to request deletion of the account and related data.
- If a member cannot access the app or needs additional support, the member may send an account deletion request to the contact email below (help@comente.io).
- If a member wants to delete only some data without deleting the account, the member may use in-app deletion controls for individual records or files, or send a specific data deletion request to the contact email below (help@comente.io).
- Data deleted: member account information, meeting minutes, transcription records, documents, chats, files, and related service data created or uploaded by the user.
- Data that may be retained: payment and transaction records, dispute-handling records, records for preventing unauthorized use and security incidents, and information that must be retained under applicable laws.
- Additional retention period: payment and transaction records and customer inquiry or consultation records may be retained for up to five years under applicable laws or for dispute-handling purposes. Records for preventing unauthorized use and responding to security incidents may be retained until the relevant purpose is achieved and then destroyed or de-identified.
Article 10 (Measures to Secure Personal Information)
The Company takes the following measures to secure personal information.
- Minimization of access rights to personal information
- Access control and authentication procedures
- Security measures such as encryption during transmission
- Log monitoring and abnormal-activity detection
- Security updates and vulnerability response
- Management and supervision of processors and external service providers
Article 11 (Personal Information Processing Related to AI Features)
- The Company may process input data and generated outputs within the scope necessary to provide AI Features requested by users.
- The Company may use AI service providers such as OpenAI (GPT), Anthropic (Claude), and Google (Gemini), and relevant data may be transmitted to such providers within the scope necessary to perform the feature.
- If the Company intends to use user data for independent AI training or improvement beyond service provision purposes, it will provide separate notice or obtain consent in accordance with applicable laws.
- Users may change consent status or make inquiries through app settings, service screens, or customer support.
- The Company accesses and processes Gmail or Google Workspace information only within the scope explicitly integrated or authorized by the user, and does not use such information for independent advertising or promotion purposes beyond the purpose of providing the feature.
Article 11-2 (Limited Use of Google User Data — Google API Services User Data Policy)
Summet’s use and transfer to any other app of information received from Google APIs (including Gmail, Google Drive, Google Docs, Google Sheets, Google Slides, and Google Calendar) will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- The Company uses Google user data only to provide and improve user-facing features that the user explicitly requests (such as email summaries and reply drafts, calendar integration, Drive file search and integration, and assistance with creating or editing Docs, Sheets, and Slides).
- The Company does not use Google user data for advertising and does not sell Google user data to third parties.
- The Company does not allow humans to read Google user data, except: (a) with the user’s explicit consent; (b) for security purposes (such as investigating abuse); (c) to comply with applicable law; or (d) for internal operations where the data has been aggregated and anonymized so that it cannot identify any individual.
- The Company processes Google user data only transiently and to the minimum extent necessary to provide the requested feature, and does not retain data that is no longer needed.
- The Company does not retain or transfer AI/ML models trained on Google user data, and does not use such data for general model training.
Article 11-3 (Marketing and Event Notifications)
- The Company may obtain separate opt-in consent before sending promotional push notifications for events, promotions, discounts, or similar commercial communications.
- Optional items: marketing/event notification consent status, consent/withdrawal timestamps, dates of consent reminders
- Purpose: informing users about events, promotions, benefits, and related customer communications
- How to consent: optional consent at sign-up, or by turning on "Event & promotion notifications" in Settings > Notification settings in the app or on the web
- How to withdraw: users may withdraw consent anytime in Settings > Notification settings in the app or on the web without affecting access to the Service. When consent or withdrawal is processed, the Company notifies the user of the result and the date.
- Promotional notifications start with "(광고)" (Korean for "advertisement"; "(광고) [Ad]" for users whose app or web language is English) and state how to unsubscribe.
- Every 2 years from the date of consent, the Company notifies consenting users of their consent (including the consent date) and how to keep or withdraw it.
- Informational notifications (maintenance, updates, required notices) may be sent separately from marketing consent and can be turned off by type in notification settings in the app or on the web
- The Company does not send promotional notifications between 9:00 p.m. and 8:00 a.m. Korea Standard Time (KST, UTC+9), and discards promotional notifications not delivered to a device before 9:00 p.m. KST.
Article 11-4 (Personal Information of Children Under 14)
- The Company does not provide its services to children under the age of 14 and does not accept membership registration from children under 14.
- Users must confirm that they are 14 years of age or older when registering, and the Company does not approve registrations that have not passed this confirmation step.
- If the Company becomes aware that personal information of a child under 14 has been collected without the consent of a legal representative, it will destroy such information and delete the related account without delay.
- If you believe personal information of a child under 14 has been collected, please notify us at help@comente.io.
Article 11-5 (Automatic Collection Devices and Right to Refuse)
- The Company uses cookies on its website to keep users signed in, to protect against security threats (CSRF), and to store user settings.
- The types and purposes of cookies used are as follows.
- a. Session cookie (sessionid): maintains the sign-in state and identifies the session. It expires when the browser is closed or the user signs out.
- b. Security cookie (csrftoken): prevents cross-site request forgery (CSRF) attacks.
- c. Local storage for settings: stores values chosen by the user, such as language and privacy protection mode settings, on the device or browser.
- The Company does not use third-party advertising or analytics cookies for ad identification, behavioral data collection, or user tracking.
- You may refuse or delete cookies through your browser settings. However, if you refuse essential cookies required to maintain the sign-in state, some services such as logging in may be restricted.
- How to manage cookies: (Chrome) Settings → Privacy and security → Third-party cookies / (Edge) Settings → Cookies and site permissions / (Safari) Preferences → Privacy.
Article 12 (Privacy Officer and Contact)
The Company may designate a privacy officer or responsible department as follows to oversee personal information processing and handle user complaints and remedies related to personal information processing.
· Privacy Officer: Seongwon Cho
· Email: help@comente.io
· Phone: +82-70-8064-3194 (weekdays 10:00–18:00 KST)
Article 12-2 (Remedies for Infringement of Rights)
You may apply for dispute resolution or consultation with the organizations below to obtain relief from personal information infringement. These organizations are separate from the Company; please contact them if you are not satisfied with the Company’s own complaint handling and remedy results, or if you need more detailed assistance.
- Personal Information Dispute Mediation Committee: +82-1833-6972 / www.kopico.go.kr
- Korea Internet & Security Agency Privacy Infringement Report Center: 118 / privacy.kisa.or.kr
- Supreme Prosecutors’ Office Cyber Investigation Division: 1301 / www.spo.go.kr
- National Police Agency Cyber Bureau: 182 / ecrm.police.go.kr
In addition, a person whose rights or interests have been infringed by a disposition or omission by the head of a public institution regarding a request under Articles 35 (access), 36 (correction or deletion), or 37 (suspension of processing) of the Personal Information Protection Act may request an administrative appeal under the Administrative Appeals Act.
Article 13 (Changes to this Policy)
This Policy may be amended due to changes in laws, services, or internal policies. If there are material changes, the Company will notify users in advance or afterward through service screens, the website, or other appropriate methods.