Privacy Policy
Privacy Policy
Effective and last updated 2026-09-01 · SEONIK
1. Service structure and principles
SEONIK is an accountless startup research service. It does not provide member accounts, profiles, or personal lists, schedules, and Research rooms that are permanently stored on its servers, and it does not store research questions in user profiles. Current-tab conversations and Research rooms stored only in the browser are provided under the retention rules below. Research questions and follow-ups are processed transiently by the server to produce a response; SEONIK does not create an account-based server conversation record or permanent applicant profile. To continue after refresh, questions, answers, signed condition state, and result references are temporarily stored in sessionStorage for the current tab. The entry is removed when the tab closes, when you clear it, or after two hours of inactivity, whichever comes first. Some browsers can restore a closed tab's session state, so explicit deletion and the inactivity expiry are the most reliable controls. If browser storage is blocked, Research continues in memory-only mode without refresh restore. The original text of research questions is not sent to Google Analytics 4 (GA4).
2. Purpose and basis for analytics
SEONIK may use GA4 to understand visits, traffic sources, Research feature usage and no-result flows, and to improve service quality. Analytics begins only after you explicitly select “Allow analytics.” Before a choice, and after a decline, SEONIK does not load the Google tag or send Analytics requests or consent pings. Declining does not limit search, answers, official sources, follow-ups, or any other core feature.
3. Information processed after consent
After consent, Google may process a GA client identifier; page and referrer paths with query strings and hashes removed; campaign source, medium and name that pass strict validation; language; general device, browser and operating-system information; approximate country or broad region derived by Google from an IP address; event time; and allowlisted Research usage events and categorical values. Product events are limited to Research start, completion and no-result; official-source opening; follow-up use; helpful or needs-improvement feedback; and opening About SEONIK, the Privacy Policy, or the Terms. Answer feedback sends only the selected category and whether an official source was present, never the question or answer text. Feedback on an answer displaying a Google-grounded result is not sent to Analytics.
4. Information not sent as Analytics event values
SEONIK does not send the original research question, name, email, phone number, exact address, business registration number, the original text of a business idea, member ID or User-ID, a fixed visitor ID, an advertising profile, the full official-source URL, or the original announcement title as custom Analytics values. Google Signals, advertising storage, advertising user data, ad personalization, remarketing, and Google Ads linking are not used.
5. Cookies and consent storage
Only after consent may GA4 create _ga and _ga_* Analytics cookies. SEONIK configures a maximum lifetime of 60 days from initial creation and does not refresh cookie expiration on every page visit. SEONIK uses seonik:research-session:v1 in sessionStorage for current-tab Research continuity and seonik:workspace-research-sessions:v1 for the Research room list. The 18-or-older confirmation and current Terms acceptance for external-AI Research are stored in sessionStorage under seonik:research-eligibility:v2 and in a signed HttpOnly session cookie named seonik_research_eligibility to prevent client-side forgery. The cookie includes only the current Terms version, contains no date of birth, name, or question, and becomes unusable when the browser session ends or its 12-hour server signature expires. A room title can contain structured search conditions, a sanitized shortened first question, or a user-edited title; the title and room order are not sent to SEONIK servers or Google. Appearance uses seonik-theme in localStorage. The interface-language preference stores only System, Korean, or English under seonik:language-preference:v1. System mode uses English for an English browser and Korean for every other browser language; the browser-language value itself is neither stored nor sent externally. The site text size, Korean and English fonts, answer width, line and paragraph spacing, information density, and source display chosen in Settings are stored only under seonik:reading-preferences:v1. Official-source link behavior, input-suggestion visibility, and reduced motion are stored only under seonik:interaction-preferences:v1. These preferences are not combined with, or sent alongside, a Research question, answer, clicked link, or identifier, and are not sent to SEONIK servers or Google. Your analytics choice is kept for 180 days under seonik:analytics-consent:v1. If storage fails or the choice expires, analytics stays off and the choice is requested again. See the Cookie and Similar Technologies Notice for each item's purpose and retention. You may change your choice at any time under Settings > Privacy & analytics. Withdrawal stops future collection and attempts to remove SEONIK Analytics cookies in the current browser. It does not immediately delete information previously sent to Google.
6. International transfer to Google
Recipients are Google LLC and the Google affiliates and subprocessors published by Google. The transferred categories are those in section 3, and the purposes are measuring visits, acquisition and feature usage, providing reports, and maintaining, securing and improving the service. After you allow analytics, information is transferred over encrypted internet connections when a page or allowed event occurs. Under Google's data-processing terms it may be processed in the United States and other countries where Google or its subprocessors maintain facilities. The actual location may vary with request routing and Google's global infrastructure; current data-centre and subprocessor locations are available through the official links below. The GA4 property's user and event data retention setting is 2 months, as confirmed by the user. This setting may not apply in the same way to standard aggregated reports, and Google's deletion or legal retention follows its official terms and policies. Browser Analytics cookies have a maximum lifetime of 60 days. You may refuse the transfer by declining or later withdrawing analytics consent. Declining has no effect on core service access.
7. Essential operational logs
The following international processing is necessary independently of Analytics consent. Each transfer occurs through TLS-encrypted internet connections when a user opens a page or requests Research. Vercel, Inc. (privacy@vercel.com; United States) may process request time, path, response status, error metadata, IP address, and User-Agent for hosting, CDN, server functions, security, and incident response. Primary processing is in the United States and may also occur in published subprocessor locations. Runtime logs visible under the current paid Pro plan are retained for one day. Other service-generated information required for security or legal obligations may be processed until the relevant purpose or legal retention period ends under Vercel's Privacy Notice. Upstash, Inc. (privacy@upstash.com; United States and Japan) processes a daily rotating HMAC identifier instead of the raw IP address, request and cost counters, and expiry times for distributed rate limiting and the AI cost ledger. The current Production connection has primaryRegion hnd1 (Tokyo, Japan) and no additional read region. It receives no raw question, answer, name, contact details, or raw IP address. Daily keys expire after the relevant date. A monthly cost-ledger entry expires 62 days after its last update and can therefore remain for up to approximately 93 days. Upstash corporate operations and published subprocessors may process data in the United States and the relevant subprocessor locations. SEONIK updates this policy and release evidence before a changed region or subprocessor is used publicly. Neon, Inc. (privacy@neon.tech; AWS Singapore, ap-southeast-1) processes structured search filters and query results for the public official-information database. It does not persist the raw question, answer, or a member profile. Official-information records remain during public-data synchronization and service operation; query operational logs are processed until the retention purpose ends under Neon's contract and security policy. These processors support the service requested by the user, security, request limits, and cost controls. SEONIK does not use their logs for advertising profiles or research-question histories, and access is restricted to operationally necessary permissions. SEONIK will update this policy when the relevant country or subprocessor lists change. You may refuse this essential international processing by not using the site or Research. Refusing Vercel processing makes the site unavailable; refusing Upstash processing makes Research requiring abuse and cost control unavailable; and refusing Neon processing may limit official-information results. Contact seonik.official@gmail.com to object, ask about available alternatives, or exercise privacy rights. To prevent AI API cost abuse, SEONIK may use a daily rotating pseudonymous identifier created by applying a server-secret HMAC to the access IP and date. The budget ledger does not store the raw IP or research question, and the identifier is not used for advertising, personalization, or user-behavior analytics. Each monthly ledger automatically expires 62 days after its last update, so an entry created at the start of a month may remain for up to approximately 93 days.
8. Research content and official sources
Do not enter names, email addresses, contact details, business registration numbers, account information, health information, or other personal or sensitive information in the search box. A selected region, support area, and startup stage are structured conditions used to make the question more specific and are processed transiently with the transformed question. SEONIK internally adjusts research scope and response length according to the question. These conditions and processing are not used to automatically determine eligibility or selection prospects and are not turned into a separate permanent user profile. Optional voice dictation uses speech recognition provided by the browser or operating system. SEONIK does not receive or store the original audio, but, depending on your environment, the browser or operating-system vendor may process audio on-device or through its own servers and overseas facilities. The vendor, processing country, and retention depend on your product and settings, so review that vendor's privacy notice before granting microphone access. Dictation runs only after you explicitly allow microphone access and start it. The transcript is not submitted automatically and enters the ordinary Research flow only after you review, edit, and submit it. Answers and information cards are organized from public official sources. When you open an external source, that site's privacy policy and terms apply. If you choose Share, the SEONIK answer and validated official sources may be sent to the operating-system or external sharing app you select; processing after that point follows that app's privacy policy and terms. Google-grounded results, Search Suggestions, and their Links are excluded from SEONIK's share payload. Always verify eligibility, audience, deadlines, required documents, operating status, and application details on the original source.
9. Choices, rights, deletion, safeguards, and contact
You may allow, decline, or later withdraw analytics consent, and may delete cookies and site data in browser settings. You may request access to, correction or deletion of, restriction of processing for, or withdrawal of consent concerning personal information. If applicable law limits a request, SEONIK will explain the reason. Core features remain available after decline or withdrawal. Browser-stored conversations and preferences are removed when you delete them or when their stated retention period expires. Questions and answers processed transiently by the server are not kept as a permanent conversation record. Limited operational logs and analytics information that must be retained are deleted in a manner designed to prevent recovery when the purpose is complete, the configured retention period expires, or the provider's applicable policy requires deletion, or are retained only in de-identified aggregate form. SEONIK applies encrypted transmission, server-side secret management, access restrictions, input-length and request-rate limits, minimized operational logs and controls against recording sensitive data, and security checks. Natural-language screening cannot guarantee that every piece of personal information entered by a user will be detected or removed, so do not enter personal or sensitive information or trade secrets. Stopping Research stops SEONIK from waiting for and displaying that response and attempts to cancel the request where possible. It does not guarantee that processing already delivered to an external processor before the stop action ends immediately. The department responsible for privacy and grievances is SEONIK Operations, reachable at seonik.official@gmail.com. If an AI answer appears inaccurate, inappropriate, or to contain personal information, you may report or contest it by sending the time of occurrence and issue category. Do not include the original question, answer, or unnecessary personal information in the report.
10. External AI processing, international transfer, and data minimization
SEONIK Research Engine 1.0 uses Google LLC's paid Gemini API for question understanding, research planning, tool selection, evidence-sufficiency evaluation, and composition and verification of answers based on SEONIK official information. When current public-web information is needed, Google Search Grounding generates a separate Grounded Result and Search Suggestions. SEONIK does not feed that search-based result back into question understanding, official-source retrieval, calculations, or SEONIK's final synthesis; it displays the provider result unchanged in a separate area. The Upstage Co., Ltd. API integration remains an inactive recovery path used only after an explicit operator switch. SEONIK will update this policy and the service notice before changing the active provider. Data sent over encrypted server-to-server connections is limited to a question screened for sensitive information and minimized to what is necessary, canonical official-information records and Evidence necessary for that question, and necessary tool descriptions. Natural-language screening cannot guarantee that every piece of personal information entered by a user will be detected or removed. API keys, authentication tokens, cookies, email or user IDs, IP addresses, raw analytics identifiers, unnecessary full conversation history, and raw database rows are not included in model input. SEONIK's cost and operational ledger stores only minimum metadata such as model, tokens, cost, latency, and success or failure status, rather than the full question or raw model answer. When Gemini is active, recipients are Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; privacy inquiry: https://support.google.com/policies/troubleshooter/7575787) and its published affiliates and subprocessors. The transferred categories are the minimized question, official evidence and tool instructions needed for that question, the generated result, and operational metadata such as token counts and request status. For question understanding, Google Search Grounding, answer generation, security, and abuse prevention, transfer occurs through TLS-encrypted server-to-server connections when the user requests Research, to the United States and the processing countries in Google's published subprocessor list. SEONIK links the current list below and updates this policy when the list changes. Paid Gemini API inputs and outputs are not used to improve Google products by default. SEONIK sends store:false to the Interactions API and does not use user questions or generated answers to train or fine-tune its own or any third-party model. Under Google's official abuse-monitoring policy, ordinary Gemini API prompts, context, and output may be retained for 55 days for policy enforcement, security, and required legal disclosures. Optional developer API Logging remains disabled and SEONIK does not share log datasets with Google. Google Search Grounding separately retains prompts, context, and output for 30 days to create and debug Grounded Results and Search Suggestions. A longer period may apply where law requires preservation. When Upstage is active, its applicable account tier and official privacy policy govern provider processing. SEONIK does not promise provider-side zero retention or zero training beyond the verified provider configuration and applicable terms. To refuse Gemini processing, do not submit a Research question. Gemini-based web research and answers will then be unavailable, and an alternative-provider path is not guaranteed. If an AI answer appears inaccurate, inappropriate, or to contain personal information, you may report or contest it without sending the original question or answer by providing the time of occurrence and issue category to seonik.official@gmail.com. Privacy and international-transfer inquiries may be sent to the same address or Google's official privacy contact channel. Under Google's API terms, Research is available only to users aged 18 or older. Public availability is currently restricted to connections from South Korea and is not marketed or directed to minors. SEONIK stores only the confirmation in browser sessionStorage and a signed HttpOnly session cookie; it does not collect or transmit a date of birth or identity information to Google. Because self-attestation is not identity-based age verification, suspected or reported underage access is blocked and reviewed operationally. Do not enter your own or another person's personal or sensitive information, credentials, trade secrets, or information you do not want transmitted externally. Material changes to the provider, account tier, or processing method will be reflected in the policy and service notice before they take effect.
11. Changes
This policy was revised on 2026-09-01 and takes effect on 2026-09-01. Material changes will be announced through the service before they take effect where required. The previous policy is retained in the repository history.
Official references
- Google Analytics Terms of Service
- Google Ads Data Processing Terms
- Google advertising and analytics international data transfers
- Google subprocessors
- How Google uses information from partner sites and apps
- Google Analytics data retention
- Vercel Privacy Notice
- Vercel runtime-log retention
- Upstash Data Processing Addendum
- Upstash subprocessors
- Vercel and connected storage regions
- Neon Privacy Policy
- Neon regions
- Upstage Terms of Service
- Upstage Privacy Policy
- Gemini API Additional Terms
- Gemini API data logging and sharing policy
- Gemini API zero data retention guidance
- Gemini API abuse monitoring and 55-day retention
- Google Privacy Policy
- Google Cloud subprocessors
- Google privacy inquiry