로그인/가입하기

Legal

한국어·EN

Privacy Policy

This policy explains how OpusLog handles data for the web service and connected AI tools.

Effective date: June 20, 2026

1. What OpusLog Collects

  • Account information such as email address, display name, and login provider identifiers.
  • User-created archive data such as programs, repertoire entries, works, notes, roles, dates, venues, collaborators, and visibility settings.
  • Poster or program files that you upload for import, including extracted text needed to create a reviewable draft.
  • OAuth connection records for AI tools, including client identifiers, granted scopes, issue time, expiry time, and revocation status. OpusLog does not expose OAuth access tokens through MCP tool responses.
  • Basic operational logs needed for security, abuse prevention, debugging, and service reliability.
  • Product analytics events about in-service activity (such as sign-up, profile publishing, program import, and CV export) together with first-touch acquisition source (referrer and campaign parameters). See section 7.

2. How OpusLog Uses Data

  • To authenticate you and provide access to your personal OpusLog account.
  • To create, search, update, and organize your private programs and repertoire.
  • To process uploaded posters or program text into drafts that you can review before saving.
  • To authorize connected AI tools such as ChatGPT or Codex with the scopes you approve.
  • To maintain security, prevent abuse, investigate errors, and improve product reliability.

3. Connected AI Tools

  • When you connect an AI tool through OAuth, that tool can call only the OpusLog capabilities covered by the scopes you approved, such as reading your archive or creating private records.
  • Publishing requires an explicit publish action. Permanent deletion is treated as a separate high-risk capability and is not part of the default public AI tool surface.
  • MCP responses are designed to return only data needed for the current request. They should not include passwords, OAuth tokens, internal account identifiers, stack traces, or debug logs.

4. Sharing and Visibility

  • Programs and repertoire are private by default unless you choose to publish or share them.
  • Published or unlisted programs may be visible to people with access to the public page or link.
  • OpusLog does not sell personal data.

5. Retention and Deletion

  • Account and archive data are retained while your account remains active or as needed to provide the service.
  • You can edit or remove user-created archive records from the product. OAuth connections can be revoked from account settings.
  • Some security and operational logs may be retained for a limited period where needed for reliability, fraud prevention, legal compliance, or abuse investigation.

6. Security

  • OpusLog uses OAuth authorization, scoped access, token expiry, and server-side authorization checks for connected AI tools.
  • Access to production systems and operational data is limited to what is needed to run and protect the service.
  • No online service can guarantee absolute security, but OpusLog is designed to minimize unnecessary exposure of private archive data.

7. Product Analytics

  • Purpose: during the alpha, OpusLog measures product usage to understand how people arrive and which features help, so the service can be improved.
  • What is collected: event name and time, the action’s basic metadata (for example import method and match rate, CV format, sign-up method), an account/profile reference, and first-touch acquisition source (landing path, referrer, and UTM/campaign parameters). Aggregate, cookieless page views are also collected via Vercel Web Analytics.
  • Cross-border transfer: analytics data is stored in OpusLog’s own database (Neon, Singapore region). Aggregate page-view analytics is processed by Vercel. OpusLog does not currently use a separate third-party product-analytics processor; if one is added, this policy and the consent flow will be updated first.
  • Retention and deletion: when an account is deleted, analytics events are unlinked from the account and profile (anonymized) so they can no longer be tied to an individual.

8. Contact

  • For privacy questions, account deletion requests, or security concerns, contact admin@opuslog.org.

We update this page when our data practices change materially.

© 2026
서비스 소개업데이트출처·감사개인정보이용약관