Privacy Policy
Last Updated: May 1, 2026
Effective Date: May 1, 2026
Our Commitment to Privacy
We collect only what we need. — We collect only the minimum information necessary to provide the Services and do not request unnecessary personal data.
We do not view your browsing data. — The YT Summary extension does not collect the websites you visit or your browser activity. We process only the YouTube video information for which you have explicitly requested a summary.
We do not collect data from YouTube. — The Company does not automatically collect (scrape, crawl) captions or content from YouTube or any other platform. Only when you voluntarily submit caption text obtained directly from your browser do we perform AI summarization on that text.
We do not sell your data. — Your personal information is not a product. We do not sell or share your data with third parties for advertising purposes.
1. Introduction
DaKi (the "Company", "we", "us", or "our") operates the website https://daki.app and related applications (collectively, the "Services"). We currently provide the following individual services:
| Service | Type | Status |
|---|---|---|
| YT Summary | Web App / Chrome Extension | Active (mobile apps coming soon) |
This Privacy Policy describes how the Company collects, uses, retains, shares, and protects the personal information of users ("user", "you"). By using the Services, you are deemed to consent to this Policy.
This Policy complies with the Republic of Korea's Personal Information Protection Act, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable laws.
Sections 2 through 12 below apply commonly to all services. Service-specific privacy practices are addressed separately in the Supplements.
2. Information We Collect
2.1 Information You Provide Directly
| Item | Details | Purpose |
|---|---|---|
| Account information | Email address, name, profile picture URL (provided when signing in via Google · Kakao · Naver · LINE OAuth) | Account creation and authentication |
| Payment information | Transaction ID, subscription status, purchase history | Payment processing and subscription management |
| Customer inquiries | Email address, inquiry content | Customer support |
Note: Sensitive payment information such as credit card numbers and bank accounts is not collected or stored by the Company. Payments are processed through Paddle.com (mobile app payments will be handled separately by Apple App Store / Google Play Store policies at the time of release).
2.2 Information Collected Automatically During Service Use (Common)
| Item | Details | Purpose |
|---|---|---|
| Usage records | Service usage time, frequency of use | Service provision and usage management |
| Device information | Browser type, operating system, language settings, IP address | Service optimization and security |
Additional information collected for each service is described in the Supplements below.
3. How We Use Your Information
- Service provision and operation: Providing and operating the core features of each service
- Account management: User authentication, login session management, subscription status verification
- Payment processing: Subscription and credit purchase, payment status verification, refund processing
- Customer support: Responding to user inquiries, providing technical support
- Service improvement: Usage pattern analysis, feature enhancement, performance optimization
- Security maintenance: Preventing fraudulent use, detecting abnormal access, ensuring service stability
- Legal compliance: Compliance with applicable laws and regulations
- Marketing communications (opt-in): Only with your express consent, we may send marketing messages regarding new features, promotions, referral programs, events, and similar matters. Consent may be withdrawn at any time and will be honored immediately via the unsubscribe link in the email or through your in-app settings. Transactional and legal notices (e.g., payment receipts, terms updates, security notifications) are not marketing and are sent regardless of marketing consent.
The Company does not use collected personal information for purposes other than those specified above. If purposes change, we will obtain your consent in advance.
4. Information Sharing
The Company does not sell your personal information to third parties without your consent. However, we share the minimum necessary information with the following third parties to provide the Services.
4.1 Common Third-Party Sharing
| Third Party | Information Shared | Purpose | Privacy Policy |
|---|---|---|---|
| Paddle.com (Merchant of Record) |
Email address, transaction information | Payment processing, tax collection, invoicing | Paddle Privacy Policy |
| Google (OAuth) |
Email, name, profile picture | User authentication (Google Sign-In) | Google Privacy Policy |
| Kakao (OAuth) |
Email, nickname, profile picture | User authentication (Kakao Login) | Kakao Privacy Policy |
| Naver (OAuth) |
Email, nickname, profile picture | User authentication (Naver Login) | Naver Privacy Policy |
| LINE (OAuth) |
Name, profile picture (email if user consents) | User authentication (LINE Login) | LINE Privacy Policy |
Additional third-party sharing for each service is described in the Supplements below.
4.2 Other Sharing Reasons
- Legal requirements: Where necessary to respond to court orders, subpoenas, or lawful requests from government authorities
- Business transfer: In connection with a merger, acquisition, or asset sale, your information may be transferred. We will provide prior notice in such cases.
- Rights protection: Where necessary to protect the rights, property, or safety of the Company, users, or others
5. Cookies & Local Storage
The daki.app website does not currently use cookies or third-party tracking technologies. If we introduce analytics tools in the future, we will update this Policy and seek appropriate consent.
For details on local storage used by individual services (extension, app, etc.), please refer to the Supplements below.
6. Data Retention
The Company retains personal information only for as long as necessary to fulfill the purpose of collection and destroys it without delay once that period elapses.
| Information Type | Retention Period | Basis |
|---|---|---|
| Account information (email, name) | Deleted immediately upon account deletion | User request |
| Summary history and usage records | Deleted within 30 days after account deletion | Service provision |
| Payment and transaction records | 5 years | Korean E-Commerce Act, Article 6 |
| Access log records | 3 months | Korean Communications Privacy Act, Article 15-2 |
| Consumer complaints and dispute records | 3 years | Korean E-Commerce Act, Article 6 |
Destruction methods: Electronic files are deleted using technical methods that prevent recovery; printed materials are shredded or incinerated.
7. How We Protect Your Information
The Company implements industry-standard technical and managerial safeguards to protect your personal information:
- Encryption in transit: All data transmissions are encrypted via the HTTPS (TLS 1.2+) protocol.
- Authentication security: We use a JWT (JSON Web Token) based authentication system; refresh tokens are hashed before storage.
- Access control: Access to databases and servers is restricted to authorized personnel.
- Server security: We apply firewalls, intrusion detection systems, and regular security updates.
- Payment security: Because payments are processed through Paddle (PCI-DSS compliant), no payment card information is stored on our servers.
However, transmission and electronic storage over the Internet cannot be guaranteed to be 100% secure, and the Company does not guarantee absolute security.
8. International Data Transfers
Your information is processed and stored on servers located in the Republic of Korea. However, for service provision, data may be transferred internationally in the following cases:
- API calls for AI summary generation (AI service providers located in the United States)
- Payment processing (Paddle, located in the United Kingdom)
- User authentication (Google in the U.S., Kakao and Naver in Korea, LINE in Japan)
For international transfers, the Company ensures equivalent levels of data protection through appropriate safeguards (e.g., EU Standard Contractual Clauses). Users accessing the Services from countries outside the Republic of Korea acknowledge that data may be transferred to Korea and the above countries.
9. Your Rights
You may exercise the following rights regarding your personal information, and the Company will respond without undue delay:
- Right of access: You may request a copy of personal information held by the Company.
- Right of rectification: You may request correction of inaccurate or incomplete personal information.
- Right of erasure: You may request deletion of personal information no longer necessary.
- Right to restrict processing: Under certain conditions, you may request restriction of processing.
- Right to data portability: You may request to receive your personal information in a structured, machine-readable format or to have it transmitted to another controller.
- Right to withdraw consent: You may withdraw consent at any time for processing based on consent. Withdrawal may limit your use of certain services.
To exercise these rights, contact contact@daki.app. The Company will process requests within 10 business days following identity verification.
10. Additional Notice for EU/EEA Users (GDPR)
If you reside in the European Economic Area (EEA) or the United Kingdom, the following additional rights and information apply under the EU General Data Protection Regulation (GDPR).
10.1 Legal Bases for Processing
- Consent: Where you have explicitly consented to specific purposes (e.g., account creation)
- Contract performance: Where necessary to perform our service agreement (e.g., providing the summary feature, processing payments)
- Legal obligation: Where necessary to comply with applicable laws
- Legitimate interests: Where necessary for our legitimate business purposes that do not override your rights (e.g., security maintenance, service improvement)
10.2 Rights Under GDPR
In addition to the rights described in Section 9, EU/EEA users have the following rights:
- Right to object: You may object to processing based on legitimate interests or direct marketing. The Company sends direct marketing only with your express consent and will cease such processing immediately upon your objection.
- Right regarding automated decision-making: You may object to decisions based solely on automated processing. (The Company does not currently make automated decisions that produce legal or similarly significant effects.)
- Right to lodge a complaint: You may lodge a complaint with the data protection supervisory authority of your place of residence.
11. Additional Notice for California Residents (CCPA/CPRA)
If you are a California resident, the following additional rights apply under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
11.1 Categories of Personal Information Collected
- Identifiers: Email address, name, IP address, unique account identifier
- Commercial information: Purchase history, subscription status
- Internet activity information: Service usage records, summary request history
11.2 Rights Under CCPA
- Right to know: The right to know what personal information the Company collects, its sources, purposes, and recipients
- Right to delete: The right to request deletion of personal information collected by the Company
- Right to opt-out of sale: The right to opt-out of the sale of personal information. The Company does not sell user personal information.
- Right to non-discrimination: We do not deny services or charge different prices for exercising privacy rights.
11.3 How to Exercise Your Rights
Contact contact@daki.app to exercise your rights. The Company will respond within 45 days following identity verification.
12. Children's Privacy
The Services are not intended for children under 16 (EU/EEA), under 14 (Republic of Korea), or under 13 (United States). The Company does not intentionally collect personal information from children.
If we become aware that a child has provided personal information without parental or guardian consent, please contact contact@daki.app and we will delete such information immediately.
13. Links to Other Websites
The Services may contain links to third-party websites not operated by the Company. Clicking a third-party link will take you to that party's site. The Company has no control over and bears no responsibility for the content, privacy policies, or practices of third-party sites. Please review the privacy policy of any such site directly.
Service-Specific Supplements
The following supplements apply only when using the relevant service. Where they conflict with the common Policy, the supplements shall prevail.
Supplement A: YT Summary Privacy Practices
A.1 Additional Information Collected
| Item | Details | Purpose |
|---|---|---|
| Summary usage records | Summary request history, summary mode, AI model selection | Service provision and usage management |
| Content data | YouTube video caption text, video title, channel information directly submitted by the user | AI summary generation and caching |
Source of data: Content data (caption text, etc.) is extracted from the user's browser or client device and transmitted to the Company's servers at the user's request. The Company does not automatically collect captions or content from YouTube or any other third-party platform.
Information We Do Not Collect
- YouTube account credentials or passwords
- Your YouTube viewing history or subscription list
- Browser visit history beyond the videos for which summaries are requested
- Location information (GPS, Wi-Fi based location)
- Contacts, photos, files, or other personal data on your device
A.2 Third-Party AI Service Sharing
YT Summary shares data with the following third-party AI service providers to deliver the AI summary feature.
| Third Party | Information Shared | Purpose | Privacy Policy |
|---|---|---|---|
| Google (Gemini AI) | Video caption text (de-identified) | AI summary generation | Google Privacy Policy |
| OpenAI (GPT) | Video caption text (de-identified) | AI summary generation | OpenAI Privacy Policy |
| Anthropic (Claude) | Video caption text (de-identified) | AI summary generation | Anthropic Privacy Policy |
| DeepSeek | Video caption text (de-identified) | AI summary generation | DeepSeek Privacy Policy |
| xAI (Grok) | Video caption text (de-identified) | AI summary generation | xAI Privacy Policy |
Important: Data transmitted to AI service providers does not include personally identifiable information such as your name or email. Only the video caption text necessary to generate a summary is transmitted.
A.3 Client-Side Local Storage
Chrome Extension
The YT Summary extension stores the following data necessary for service provision in the browser's local storage (chrome.storage):
- Authentication tokens (JWT access/refresh tokens)
- User language and font size settings
- Summary mode settings and cache
The extension does not use advertising cookies, tracking pixels, or third-party analytics tools.
※ Mobile app (iOS / Android) local storage practices will be separately announced at the time of release.
A.4 Specific Purposes (YT Summary)
- AI-based video summary generation and provision
- Summary history management and cross-device synchronization
- AI follow-up chat feature
14. Changes to This Policy
The Company may modify this Policy from time to time due to legal changes, service changes, or business needs. For material changes:
- We will post a notice or pop-up within the Services.
- We will send notice of changes to your registered email address.
- We will update the "Last Updated" date at the top of this page.
If you continue to use the Services after the modified Policy takes effect, you are deemed to have agreed to the modified Policy.
14.5 Language
This Policy may be provided in English, Japanese, Thai, and Traditional Chinese in addition to Korean. In the event of any discrepancy between language versions, the Korean version shall prevail. Other language versions are provided for the convenience of users only.
15. Contact Us
If you have any inquiries, requests, or complaints regarding this Privacy Policy, please contact us at:
- Email: contact@daki.app
- Website: https://daki.app
The Company will respond to inquiries within 10 business days.