SsamPin

Privacy Policy

Last updated: August 14, 2026

SsamPin does not operate its own server for storing user data, and all active data is stored on your PC by default. However, when you use Google integrations (Calendar, Drive backup, Tasks) or certain online collaboration features (consultation booking, assignment collection, e-signature, surveys, etc.), some data is transmitted to external services as needed to provide those features. See Sections 3, 5, and 11 below for details.

1Information We Process

A. Student and class information entered by the teacher — The information below is entered directly by the teacher for professional purposes and is as a rule stored only on the teacher's computer. However, if the teacher uses a collaboration feature (assignment collection, surveys, consultation booking, e-signature), the fields that feature needs are stored in the cloud (Section 11). Every field is optional — the app works without them, so teachers enter only what they need.

  • Basic student information — name, student number, date of birth, student contact number, up to two guardian contact numbers with their relationship (father, mother, etc.), and enrollment status (enrolled, transferred, on leave, etc.) with a reason note
  • Attendance records — date, class period, attendance type (absence, late arrival, early leave, missed class), reason, whether supporting documents were submitted, and whether it was reported to NEIS
  • Observation and counseling records — category, record content, date, counseling method, and follow-up actions
  • Class management data — timetable, seating charts, curriculum progress, assignment submission status, survey/checklist responses, and assessment records

Retention: retained until the teacher deletes it in the app or uninstalls the app; running the school-year wrap-up moves it to the archive. Deleting an item removes it from the corresponding JSON file immediately.

B. Information processed through Google integrations — SsamPin processes the following only when you explicitly enable a specific Google integration feature. If you do not use any integration feature, none of the information below is processed.

  • Google account email address — used to identify the connected account
  • Google Calendar event data (when Calendar sync is enabled) — title, date, time, location
  • SsamPin app-data backup files (when App-Data Backup is enabled) — a JSON copy of the timetable, seating, memos, to-dos, and other data you create inside SsamPin, stored in a hidden app-specific folder (appDataFolder) on your Google Drive. This folder is invisible to other Google apps (Drive web UI, Docs, etc.).
  • Google Tasks data (when Tasks sync is enabled) — title, completion status, due date, notes

2How We Use Your Information

The information processed is used solely for the following purposes:

A. Student and class information (Section 1.A)

  • Checking and recording attendance, and organizing material for the official school record
  • Recording student observations and counseling, and following up on them
  • Managing class operations (timetable, seating, curriculum progress, assignments, assessment)
  • Arranging guardian consultation schedules and contacting families

All of the above serve the teacher's professional duties of class management and student guidance, and are not used for any other purpose.

B. Google integration information (Section 1.B)

  • Two-way synchronization of events between the SsamPin app and Google Calendar
  • Backup and restoration of SsamPin app data to a dedicated Google Drive folder so you can use the same data across multiple devices
  • Two-way synchronization of to-dos between SsamPin and Google Tasks (enabling use with the mobile Google Tasks app)

Your information is never used for marketing, advertising, third-party analytics, machine-learning model training, or any purpose other than directly delivering the features above.

3How We Store Your Information

SsamPin is designed with a serverless architecture:

  • Local storage by default: Active user data is, as a rule, stored on your PC (userData/data/*.json). Data exchanged with students and guardians through the collaboration features is the exception; its scope is set out in Section 11.
  • No SsamPin developer servers: The SsamPin developer does not operate any server that stores or processes user data.
  • Google Drive appDataFolder: When the "App-Data Backup" feature is enabled, a copy of your SsamPin data is stored in a hidden app-specific folder on your own Google Drive. This folder uses your Google Drive quota but is inaccessible via the regular Drive interface — only the SsamPin app can access it.
  • Encrypted storage: OAuth tokens are encrypted and stored in the OS keychain using Windows DPAPI (Electron safeStorage).
  • Direct communication: The app communicates directly with the Google Calendar, Drive, and Tasks APIs from your PC, without passing through any intermediate servers.
  • Transit security: All communication with Google APIs is encrypted in transit via HTTPS (TLS).

4Data Retention and Deletion

  • SsamPin retains data only while each Google integration feature is active. Data is immediately deleted when you disconnect an integration or uninstall the app.
  • Google account disconnect: Pressing "Disconnect" in Settings > Google Integration removes OAuth tokens and all events/tasks imported from Google from local storage. Locally created timetables, memos, and to-dos are preserved.
  • App-Data Backup deletion: The "Delete all cloud data" button in the Backup card permanently deletes all backup files stored in the Google Drive app-specific folder.
  • Google Tasks sync off: Toggling Tasks off stops synchronization but preserves locally stored to-dos. When you delete or archive a to-do inside SsamPin, the corresponding item in Google Tasks is also deleted immediately.
  • Uninstalling the app deletes all locally stored data (SsamPin's JSON files). Backup copies in the Google Drive app folder remain, so run "Delete all cloud data" beforehand if you want to remove them as well.
  • You can also directly revoke the app's access from your Google Account permissions page. SsamPin will no longer be able to access your account on the next sync attempt.

5Third-Party Disclosure

  • We do not sell your data, or provide or share it for any third party's own purposes.
  • SsamPin communicates directly with the Google Calendar, Drive, and Tasks APIs. In addition, when you use online collaboration features (consultation booking, assignment collection, e-signature, surveys, etc.), some data is transmitted to and stored on a cloud backend (Supabase) as needed to provide those features. In addition, when you ask the in-app AI assistant a question, that question and the preceding conversation are sent to Upstage Inc. and Google LLC to generate an answer. This is a processing consignment for feature delivery, not third-party provision; see Section 11 for details. No data is sent to external services other than those listed in Section 11.
  • We do not transfer user data to advertisers, data brokers, or information resellers.
  • We do not use user data for serving advertisements, credit assessment, lending decisions, or any other purposes beyond the app's core functionality.
  • We do not use user data to train any machine-learning (ML) model, including SsamPin itself.

6OAuth Scopes Requested

When you connect your Google account, SsamPin may request the following scopes and uses them only as described:

  • .../auth/userinfo.email — retrieves the email address of the signed-in Google account to display it as the "Connected Account" in the Settings screen and to verify account consistency on re-login. Other profile information (name, picture, etc.) is not requested.
  • .../auth/calendar — required to read and write events on the Google Calendars you select. Calendars you do not select are not accessed.
  • .../auth/drive.file — accesses only the app-specific folder (appDataFolder) SsamPin creates. Your other Drive files (documents, photos, etc.) remain inaccessible to SsamPin.
  • .../auth/tasks — required for two-way synchronization of to-dos with the Google Task List you select. Requested only after an additional consent dialog when you enable Tasks sync.

SsamPin uses these scopes in accordance with the Limited Use requirements of the Google API Services User Data Policy, and does not use the data for any purpose other than delivering the features above.

7Data Subject Rights and How to Exercise Them

Data subjects may at any time request access, correction, deletion, or suspension of processing of their personal information (Articles 35–37 of the Personal Information Protection Act).

A. What you can do inside the app

  • Disconnect your Google account in Settings > Google Integration (all OAuth tokens are deleted immediately)
  • Turn off App-Data Backup or run "Delete all cloud data"
  • Turn off Google Tasks to stop synchronization
  • Revoke access directly from the Google Account app permissions page
  • View, correct, and delete student and class information directly on the app screens (Section 1.A)

B. Requests by students and guardians — Information about students is processed by teachers for the professional purposes of their school, so requests for access, correction, deletion, or suspension of processing are handled fastest by the teacher in charge or the school. For information held by the online collaboration features (consultation booking, e-signature, surveys), you may also contact us at the address below.

C. Where to file and how long it takes

  • Contact: pblsketch@gmail.com (Personal Information Protection Officer, Section 15)
  • Response time: we act on the request and notify you of the result within 10 days of receiving it. If we cannot meet that deadline, we notify you of the reason and the expected timeframe first.
  • Requests may also be made through a legal representative or an authorized agent. Deletion or suspension may be restricted where other laws require retention; in that case we will explain the reason.

8Contact

For questions about our privacy practices, please contact us:

9Google API Services User Data Policy Compliance

SsamPin's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10AI Bridge (External AI Integration)

Only when you explicitly connect the AI Bridge feature, SsamPin connects the student, seating, and observation data stored on your computer with external AI tools (MCP clients such as Claude, Codex/GPT, Antigravity/Gemini). This data is passed directly from your computer to the external AI tool without going through any intermediate server.

  • Before being sent to an external AI, identifying information such as real names, contact details, and dates of birth is replaced with opaque tokens. However, tokenization alone does not guarantee complete anonymity, and individuals may still be re-identified from the context of the observations.
  • Exposing raw observation content (get_observations) and writing (add_observation) are disabled by default, and operate only when you explicitly turn on the corresponding gate (or per-student, per-period, per-purpose consent). When enabled, raw observation content (which may include sensitive information) may be sent to the external AI.
  • Data passed to a connected external AI tool is subject to that provider's policies (Anthropic, OpenAI, Google, etc.). SsamPin is not involved in the external AI provider's data processing.
  • All bridge access is recorded in a local audit log (raw values are not recorded), and consent can be withdrawn at any time.

For more details, see the AI Bridge information page.

11Processing Consignment (Collaboration Features Using External Servers)

Most SsamPin features work offline, with data stored only on your PC. However, when you use certain collaboration features that must exchange information online with students and guardians, some data is transmitted to and stored on a cloud backend (Supabase Inc.) as needed to provide that feature. This is not the provision or sale of information to a third party, but a processing consignment for delivering the feature. These features operate only when a teacher explicitly uses them; if not used, no data is transmitted.

  • Consultation booking — the schedule and target class/student numbers, and the student number at the time of booking. The booker's contact details and memo are encrypted on your device before transmission and storage.
  • Assignment collection — assignment information and submission status (student name and number). Because students submit by picking their own name from a list, the target roster (name, number, grade, class) is stored when the teacher creates the assignment and is shown to anyone holding the submission link. Submissions are stored as links in the teacher's Google Drive. Teacher identity is verified via the Google account.
  • E-signature — the signer's name, submitted fields, and the signature image (cloud storage). As with assignment collection, signers pick their own name from a list, so the target roster (name, affiliation) is stored when the teacher creates the signature request and is shown to anyone holding the signing link. Access IP and device information (User-Agent) are stored only as hashes, not in raw form.
  • Surveys / checklists — student number and response content.
  • Classroom screen-share delivery receipts — only technical information such as board identifiers and access timestamps; memo content is not transmitted.
  • Google integration token storage — the teacher's email and encrypted OAuth tokens (AES-256-GCM).
  • AI assistant (support chatbot) — the question you type, the immediately preceding conversation, and the name of the screen you are viewing are transmitted in order to generate an answer. Data stored in the app — student rosters, attendance, observation and counseling records — is not transmitted. However, personal information you type into the question itself is transmitted with it, so we recommend not including student names or contact details in your questions.
  • Reports to the developer (bug reports and suggestions) — what you send via "Send feedback" in the sidebar or the report form in the AI assistant. The text you write, a reply email address (only if you provide one), the immediately preceding conversation, and any screenshots you attach (up to 3) are stored and emailed to the developer. When the AI assistant judges your message to be a bug or a feature request, it records that question and the preceding conversation at the moment it opens the report form — the record remains even if you close the form, and we will delete it on request via the contact below. Screenshots may capture student names, so please check before attaching.

Consignees: Supabase Inc. (cloud infrastructure); Upstage Inc. (AI assistant answer generation); Google LLC (AI assistant question retrieval and fallback answer generation). Purpose: providing the collaboration features above and the AI assistant. Retention/Deletion: data is deleted when you remove it within each feature or when its retention period (e.g., real-time link expiry) passes. AI assistant conversations are retained to improve answer quality and are deleted on request. Data in transit is encrypted via HTTPS (TLS).

12Protection of Children Under 14

SsamPin's users are limited to teachers and other education professionals, and the SsamPin developer does not collect personal information directly from children under the age of 14. Information about students is entered and processed by teachers for work purposes; responsibility for its lawful processing rests with the teacher (and their school/institution) under Section 3 of the Terms.

  • Student information is Student information held by the app itself (attendance, observation and counseling records) is stored only on the teacher's PC and is not separately collected by the developer. However, when the collaboration features below are used, that data is stored with our cloud consignee (Section 11).
  • In online collaboration features (consultation booking, surveys, checklists), students are identified only by student number, not by real name, and contact details or memos are encrypted on the user's device before transmission (Section 11).
  • Assignment collection and e-signature do, by their nature, include a student's name, and that name is stored in the cloud unencrypted (for e-signature, together with the signature image). Because both features require a student to pick their own name from a list, the entire target roster — not only those who submitted — is stored and shown to anyone holding the link. Teachers are expected to use these features only to the extent necessary and to delete the data once the purpose is fulfilled.
  • When data is sent to an external AI (Section 10), identifying information such as names, contact details, and dates of birth is pseudonymized with opaque tokens.

Basis: Article 22-2 of the Personal Information Protection Act (processing of personal information of children under 14).

13Overseas Transfer of Personal Information

Some of SsamPin's collaboration features, Google integrations, and the AI assistant consign personal information processing to companies whose servers are located overseas, and personal information may be transferred abroad in the process. If a teacher does not use these features, no information is transferred overseas.

  • Supabase Inc. (USA) — cloud storage and processing of collaboration feature data (consultation booking, assignment collection, e-signature, surveys, etc.; Section 11)
  • Vercel Inc. (USA) — hosting of the web pages used by collaboration features
  • Google LLC (USA) — (i) processing of Calendar, Drive backup, and Tasks data when you enable Google integration (Sections 1 and 6); (ii) processing of your question text to retrieve relevant help articles, and fallback answer generation, when you use the AI assistant (Section 11)
  • Upstage Inc. (a Korean company; processing infrastructure in the USA) — answer generation when you use the AI assistant (Section 11). Under its own privacy policy, Upstage sub-consigns system operation and data storage of submitted conversations to Amazon Web Services, Microsoft Azure, and Google (all in the USA), so information may be transferred abroad in that process.

The items, purposes, and retention/use periods of the transferred data follow Sections 1, 2, 4, and 11, and data in transit is encrypted via HTTPS (TLS). Basis: Article 28-8 of the Personal Information Protection Act (overseas transfer of personal information).

14Security Measures for Personal Information

SsamPin takes the following measures to prevent personal information from being lost, stolen, leaked, forged, altered, or damaged. Basis: Article 29 of the Personal Information Protection Act (duty to take security measures).

A. Technical measures

  • Encryption in transit — all communication is encrypted with HTTPS (TLS), and HTTP requests are forced to HTTPS (HSTS applied).
  • Encryption at rest — Google OAuth tokens are stored in the OS keychain (Windows DPAPI / Electron safeStorage), and tokens kept in the cloud are encrypted with AES-256-GCM. Contact details and memos in consultation booking are encrypted on your device before transmission.
  • Access control — cloud data is protected by row-level security (RLS) and column-level privileges. Teacher admin keys and survey PIN hashes cannot be read by public requests, and listing of the signature-image bucket is blocked. The app reads bookings and survey responses only through a path that verifies the admin key of that schedule or survey.
  • Minimizing identifiers — the access IP and device information (User-Agent) for e-signatures are stored only as hashes, and identifying information sent to external AI tools is pseudonymized with opaque tokens (Section 10).
  • Web security headers — Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy response headers are applied to block script injection (XSS) and clickjacking.

B. Administrative measures

  • The number of people handling personal information is kept to one — the developer/operator (Protection Officer, Section 15) — and no one else is granted access.
  • Server-only secret keys are never included in the code delivered to users' browsers and are used only on the server.
  • External security scanning tools are used to check response headers, access control, secret exposure, and sensitive file exposure, and findings are fixed and deployed.

C. Physical measures

  • SsamPin operates no physical servers of its own. The original student and class information resides on the computer the teacher manages, and its physical security (screen lock, separate accounts, etc.) is managed by the teacher and their school.
  • Physical security of the cloud infrastructure used by the collaboration features follows the data-center protections of the respective providers (Supabase, Vercel, Google; Sections 11 and 13).

15Personal Information Protection Officer

SsamPin designates the following Personal Information Protection Officer to oversee personal information processing and to handle inquiries and complaints from data subjects.

Data subjects may direct inquiries or reports about privacy infringement to the following Korean authorities:

  • Privacy Infringement Report Center — privacy.kisa.or.kr / 118
  • Personal Information Dispute Mediation Committee — kopico.go.kr / 1833-6972
  • Supreme Prosecutors' Office Cybercrime Division — spo.go.kr / 1301
  • National Police Agency Cyber Bureau — cyberbureau.police.go.kr / 182

This privacy policy may be updated. Changes will be posted on this page with an updated revision date.