READING & Privacy Policy

READING & Privacy Policy

iPortfolio Inc. (the "Company") establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act, in order to protect the personal data of data subjects and to handle related grievances promptly and smoothly.

The Company's Privacy Policy may change from time to time in line with changes in government legislation and guidance and in the Company's terms and internal policies. Where the Company amends the Privacy Policy, it will announce the amendment through a notice on the Website (or by individual notice).

1. Personal data we collect

The Company collects the following personal data for purposes such as membership registration, consultation, and service applications.

PurposeCategoryPersonal data items
Membership registrationMembership registration (common)[Required] Name, user ID, password, email, mobile telephone number
Membership registration and simple sign-in linkage (social accounts)Kakao simple sign-up[Required] Profile information (nickname / profile picture), sign-in identifier
[Optional] Kakao account (email, mobile telephone number)
Membership registration and simple sign-in linkage (social accounts)Apple simple sign-up[Required] Email (where "Hide My Email" is enabled, the randomly assigned email is collected), sign-in identifier
Membership registration and simple sign-in linkage (social accounts)Whale Space simple sign-up[Required] User type (student / teacher), sign-in identifier
[Optional] Whale Space account (email)
Provision of goods or servicesProduct orders[Required] Payment information, payment records
Provision of goods or servicesProduct orders (where a delivered product is ordered)[Required] Payment information, payment records, delivery information (recipient name, recipient mobile telephone number, recipient address)
Provision of goods or servicesWhen using the Service (entering and editing member information)[Required] Child's name, child's date of birth
[Optional] Parent's name, name of school / kindergarten
Consultation and service applications-Name, mobile telephone number, email, date of birth, content of the consultation, order information
Use of AI services, and improvement of their performance and algorithms-Conversation information exchanged with the AI (conversation content including audio and the like), service usage behaviour information (input and outputs)
Information collected and generated automatically through use of the Service-Service visit and usage records, learning information, purchase history, browser information, device information (operating system, model name, device unique number, OS version, app version), IP address, and the user's voice information when recording

2. How we collect personal data

The Company collects personal data by the following means.

3. Purposes of collection and use of personal data

The Company uses the personal data it collects for the following purposes.

  1. Performance of the contract for provision of the Service and settlement of charges for the Service provided: provision of content, provision of specific tailored services, purchase and payment of charges, identity verification for financial transactions, and financial services
  2. Member management: identity verification for use of membership-based services, individual identification, confirmation of intent to join, confirmation of whether the legal guardian has consented where the personal data of a child under the age of 14 is collected, handling of complaints and other grievances, and delivery of notices
  3. Use for new service development, marketing, and advertising: development of new services and provision of tailored services, provision of services and placement of advertising based on demographic characteristics, verification of service effectiveness, provision of event information and participation opportunities, provision of commercial information, measurement of access frequency, improvement of service quality, and service usage statistics

4. Retention and use period of personal data

In principle, once the purposes of collection and use of personal data have been achieved, the Company destroys the data without delay. However, where retention is required under applicable laws, the Company retains member information for the periods prescribed by those laws, as follows.

  1. Records on contracts or withdrawal of purchase: 5 years (Act on Consumer Protection in Electronic Commerce)
  2. Records on payment and the supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
  3. Records on consumer complaints or dispute handling: 3 years (Act on Consumer Protection in Electronic Commerce)
  4. Records on identity verification: 6 months (Act on Promotion of Information and Communications Network Utilization and Information Protection)
  5. Records of visits: 3 months (Protection of Communications Secrets Act)

5. Procedure and method for destruction of personal data

In principle, once the purposes of collection and use of personal data have been achieved, the Company destroys the data without delay. The procedure and method are as follows.

  1. Destruction procedure
  1. Destruction method

6. Provision of personal data to third parties, and processing on our behalf

  1. Provision of personal data to third parties
  1. Entrusted processing of personal data (processing on our behalf)

For a smooth and convenient service, the Company entrusts the processing of personal data to external specialist providers, within a minimum and limited scope. When entering into an entrustment agreement, the Company separately stipulates the relevant matters so that personal data is managed securely.

ProcessorEntrusted workRetention and use period
  1. Overseas transfer of personal data in connection with AI services

The Company transfers personal data overseas in order to provide AI services smoothly. The Company uses more than one AI service provider in order to operate the service reliably and to improve quality, and may use any of the providers below selectively, depending on the circumstances of the AI service provider. You may refuse the overseas transfer, but use of AI features may then be restricted. The other basic learning services can still be used as normal.

Overseas processorEntrusted workRetention and use period
OpenAIGenerating AI conversations, generating reports, generating letter content, providing AI learning feedbackRetained for up to 30 days for abuse monitoring purposes, then destroyed
Anthropic, PBCGenerating AI conversations, generating reports, generating letter content, providing AI learning feedbackRetained for up to 7 days for abuse monitoring purposes, then destroyed
Google LLCGenerating AI conversations, generating reports, generating letter content, providing AI learning feedbackRetained for up to 55 days for abuse monitoring purposes, then destroyed

Note - Legal basis for the overseas transfer: Article 28-8(1)(3)(a) of the Personal Information Protection Act (entrustment of processing or storage overseas for the performance of a contract).

Note - Privacy policies of each processor: OpenAI Privacy Policy (https://openai.com/policies/privacy-policy), Anthropic Privacy Policy (https://www.anthropic.com/privacy), Google Cloud Privacy (https://cloud.google.com/terms/cloud-privacy-notice)

7. Rights of users and legal guardians, and how to exercise them

  1. Users and legal guardians may at any time view or amend the registered personal data of themselves or of the child under the age of 14 concerned, and may also request cancellation of membership.
  2. To view or amend the personal data of a user or of a child under the age of 14, click "Edit personal data" (or "Edit member information" and the like); to cancel membership (withdraw consent), click "Withdraw from membership". After completing identity verification you may view, correct, or withdraw directly.
  3. Alternatively, if you contact the Privacy Officer in writing, by telephone, or by email, we will act without delay.
  4. Where you request correction of an error in your personal data, we will not use or provide the personal data concerned until the correction is complete. Where incorrect personal data has already been provided to a third party, we will notify the third party of the outcome of the correction without delay so that the correction is made.
  5. Personal data terminated or deleted at the request of a user or legal guardian is handled by the Company as stated in "Retention and use period of the personal data we collect", and is processed so that it cannot be viewed or used for any other purpose.

8. Measures to secure personal data

To prevent users' personal data from being lost, stolen, leaked, altered, forged, or damaged, the Company implements the following technical and administrative protective measures in accordance with the Personal Information Protection Act and other applicable laws.

  1. Minimising and training personnel who handle personal data
  1. Establishing and implementing an internal management plan
  1. Access control for the personal data processing system
  1. Encryption of personal data
  1. Technical countermeasures against hacking, malicious code, and the like
  1. Retention of access logs, and prevention of alteration and forgery
  1. Physical security measures

9. Protection of the personal data of children under the age of 14

  1. Obligation to obtain the legal guardian's consent
  1. Procedure for obtaining consent, by member type
  1. Procedure for obtaining consent for institutional members (schools, academies, libraries, and the like)

Where an institution creates accounts for students under the age of 14, the Company has a duty under Article 22-2 of the Personal Information Protection Act to confirm that the legal guardian's consent has been lawfully obtained. To that end, the Company carries out the following steps.

  1. The institution must obtain the prior consent of the legal guardian in accordance with applicable laws before creating student accounts, and must retain the consent form.
  2. The Company requests the institution to confirm whether the legal guardian's consent has been obtained, and the institution must submit to the Company a copy of the consent form or material evidencing that consent was obtained.
  3. The Company may restrict provision of the Service, or hold the creation of an account, in respect of any student account for which it has not been confirmed that consent was obtained.
  4. The Company includes in its service agreement with the institution provisions on the duty to obtain the legal guardian's consent and on the verification procedure, and periodically confirms whether the institution has performed its obligations.
  1. Guaranteeing the rights of legal guardians

10. Installation, operation, and refusal of cookies and automatic collection devices

  1. Purposes for which cookies and automatic collection devices are used
  1. List of cookies and tracking tools in use
CategoryProviderPurposeCookie nameRetention period
EssentialThe Company (first party)Maintaining sign-in state and normal operation of the ServiceJSESSIONID, SESSION, uuidSession to 1 year
FunctionalThe Company (first party)Recording whether cookie consent was givenacceptCookie1 year
AnalyticsGoogle LLCAnalysis of service usage statistics (number of visitors, page views, time on site, and the like)_ga, _gid, ga*24 hours to 2 years
AnalyticsMicrosoft Corp.Analysis of user behaviour (clicks, scrolling, and other heat-map analysis)_clck, _clsk, MUID1 day to 1 year
AdvertisingGoogle LLCMeasurement of advertising conversions_gcl_au90 days
AdvertisingMeta Platforms, Inc.Tracking and measurement of advertising conversions_fbp90 days
  1. How cookies are installed, operated, and refused

11. Privacy grievance service

To protect customers' personal data and to handle complaints relating to personal data, the Company designates the following department and Privacy Officer.

  1. Privacy Officer details and contact information

You may report any personal data protection grievance arising from your use of the Company's services to the Privacy Officer or to the responsible department. The Company will respond to reports from users promptly and fully.

12. Changes to this Privacy Policy

This Privacy Policy applies from 8 June 2026.

Announced 28 May 2026

Effective 8 June 2026

(Remainder of page intentionally left blank)


Annex: Sign-up consent forms

These are separate published documents linked from the sign-up screen, not part of the Privacy Policy body above. They are translated here because they are the consent documents users actually see, and because an English sign-up flow cannot go live without them.

Annex A. Consent to the collection and use of personal data (required)

Source: https://www.readingn.com/policy/collectedinfo

Consent to the collection and use of personal data (required)

PurposeItemsRetention period
Identity verificationName, user ID, password, date of birth, telephone number, emailUntil consent is withdrawn or membership is cancelled
Performance of the contract for provision of the Service and settlement of charges for the Service providedUser ID, password, date of birth, telephone number, email, service usage recordsUntil consent is withdrawn or membership is cancelled
Member managementUser ID, password, date of birth, telephone number, email, service usage records and device informationUntil consent is withdrawn or membership is cancelled
Development of new services and provision of tailored servicesName, user ID, telephone number, email, service usage records and device informationUntil consent is withdrawn or membership is cancelled

You have the right to refuse consent to the collection and use of your personal data; if you refuse, membership registration will be restricted.