개인정보 처리방침
HxAi Privacy Notice
This notice says what HxAi holds about you, who else sees it, where it is kept, how long it stays, and what you can do about it. It is a draft: nobody with legal standing has reviewed it, the version below says so, and no revision of this document has been published. Where this product does something badly or not at all, this notice says so rather than describing the version of itself it would like to be.
- 버전
- draft-1-pending-owner-signoff
- 발효일
- 아직 번호가 매겨진 개정본으로 공표되지 않았습니다.
이 문서는 법적 자격을 갖춘 사람이 검토한 적이 없습니다. 논의해야 할 지점을 열어 두는 대신 하나씩 드러내려고 작성했으며, 위 버전 표기가 확정된 약정이 아니라는 사실을 그대로 보여 줍니다. 여기에 적힌 내용은 이 제품이 지금 실제로 동작하는 방식입니다.
What HxAi holds about you
Your account: the email address you signed up with, whether it has been verified, the fact that you confirmed you are 18 or older and when, the sign-in method you chose, and — if you signed in with Google or Kakao — the account identifier that provider returns. No password is ever visible to this product.
Your profile: the handle, display name, biography, avatar and language preference you set. All of it is yours to edit, and the profile is public unless a moderation decision or account closure hides it.
Your learning: the courses you enroll in, your progress through lessons, your assessment attempts and results, your assignment submissions, and the completion records and certificates you earn. Where you learn inside an organization, that organization's owners and admins see your enrollment, progress, results and certificates — and never your raw answers, submission text or instructor feedback unless they are also your instructor.
What you write and publish: courses, lessons, media and slides if you are a creator; posts, comments, reactions and community memberships; events you organize or RSVP to; and direct messages, which are between you and the people in the conversation.
Your AI use: the questions you ask the tutor, the answers it gave, what it drew on, and a record of how much you used it.
Safety records: reports you file, reports about you, the evidence attached to them, the decisions moderators reach, and appeals.
Technical records: the requests your browser makes, which carry your IP address and the usual headers, and application logs that identify a request and a pseudonymous actor rather than naming you.
Learning measurement: a small number of completion events, each carrying an event name from a fixed list of four, a pseudonymous actor identifier, the workspace and course the completion belongs to, the moment, your locale, and — on a weekly qualification only — three counts. The columns these events may carry are restricted by the database itself, so no message, answer, submission or secret link can be recorded by a careless writer rather than merely not being recorded yet.
Where it is processed
HxAi runs in the United States and the data is stored there. The sentence below is quoted from this product's own processor register rather than written for this page, and it includes the part nobody here can verify: the tier that serves the requests has no region recorded anywhere in this product's configuration or documentation, so this notice does not claim one for it.
If you are reading this outside the United States — and this product is published in Korean as well as English — then using it means your data is processed in the United States.
HxAi stores its data in one United States region: production data is in `us-east-1` and the hosted development project is in `us-west-2`. That placement is recorded in this product's architecture decisions and runbooks and is configured in the hosting provider's own console, not in any file in this repository. The application tier that reads the data has no region recorded anywhere — neither stated in a document nor set in configuration — so this product does not claim one, and the two identity providers a person may choose to sign in with process that sign-in on their own terms, in places this product does not select.
Who else processes it
HxAi is run by a small operation on other companies' infrastructure, and the register below is the whole list rather than the notable part of it. It is split in two on purpose. The first section is the companies that receive data as a consequence of this product running, with no switch left to throw. The second is companies named in this product's configuration, schema or documentation whose live routes are not selected by repository defaults. A deployed environment can select them, so its mode and slot configuration must be verified before relying on a claim that no video, audio or prompt has reached them.
Naming the second group here rather than beside the first is the difference between a disclosure and a claim. The categories beside those companies are what would reach them if the gates their entries name were opened, and this notice will change before that happens.
No data-processing agreement has been executed with any of them. That is stated in every row rather than left as a blank column, and executing them is the operator's outstanding work.
Third parties that process data today
Every party in this section receives data as a direct consequence of HxAi running, with no switch left to throw. The categories beside each one are what reaches it today, and the evidence column names the file and line that makes the flow a fact rather than an assumption.
Supabase (Supabase, Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- account and authentication records, including email addresses and OAuth subjects
- profile, learning, enrollment, assessment and certificate data
- direct messages, social posts and community membership
- AI tutor runs, transcripts and retrieval corpora
- moderation cases, evidence and audit records
- uploaded files in seven storage buckets — avatars, course images, course files, course slides, assignment submissions, social attachments and export archives
- queued jobs and outbox rows carrying recipient identifiers
- Where
- us-east-1 for production data; us-west-2 for hosted development. This is stated in this product's documentation and is configured in the provider's own console rather than in any file this product can show you.
- Whether it processes anything today
- Every relation, every bucket, every queue and every authentication record this product has. There is no second store: public, private, storage and the queue schema are all one hosted Postgres project.
- Agreement
- None executed. What is owed: Supabase's data processing addendum, plus its sub-processor list, which this register must then reflect — a hosted Postgres platform runs on infrastructure of its own and those companies are sub-processors of this product's data whether or not anybody names them.
Vercel (Vercel Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- every HTTP request, including path, headers and IP address
- session cookies in transit
- structured application logs, which carry a request id and a pseudonymous actor context
- request bodies in transit — every form post, every AI prompt, every uploaded object's signed request
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- It serves myhxai.com. Every request a person makes reaches this product through it, and every log line the product writes is collected by it.
- Agreement
- None executed. What is owed: Vercel's data processing addendum and its sub-processor list, which for a hosting tier is where the region question is actually answered.
GitHub (GitHub, Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- the repository's source, migrations and synthetic seed fixtures
- commit and pull-request metadata, including contributor identities and email addresses
- CI job logs and uploaded test artifacts
- no learner, member or production data — the repository holds none and every seeded actor is a fixture at @hxai.local
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- It holds the source. One workflow runs on every pull request, every push to main, and once a week; on pull requests it enumerates the pull request's commits through the REST API to scan them for secrets.
- Agreement
- None executed. What is owed: GitHub's data protection agreement, which covers contributor personal data rather than learner data.
Google (Google LLC)
- Relationship
- Decides for itself what it does, on its own terms with you
- What reaches it
- the sign-in event itself, and the account chosen for it
- the verified email address and provider subject returned to this product
- no learning, social, message or assessment data — the OAuth flow carries identity and nothing else
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- The provider is enabled and the flow is live: a person who signs in with Google authenticates against Google before this product sees anything.
- Agreement
- None executed. What is owed: Not a DPA. The instrument is Google's API and OAuth terms plus a controller-to-controller disclosure in the privacy notice, because an identity provider deciding its own purposes is not processing on this product's instructions.
Kakao (Kakao Corp.)
- Relationship
- Decides for itself what it does, on its own terms with you
- What reaches it
- the sign-in event itself, and the account chosen for it
- the verified email address and provider subject returned to this product
- no learning, social, message or assessment data
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- The provider is enabled and the flow is live, on the same terms as Google's.
- Agreement
- None executed. What is owed: Not a DPA, for the reason Google's row states: Kakao's developer terms plus a controller-to-controller disclosure.
Third parties that would process data, and process none today
No party in this section is selected by the repository's default provider path. Live code paths exist, so deployed mode and slot configuration must be verified before relying on the claim that none has received data: the categories beside each one are what WOULD reach it when its executable gates are opened, and naming them here rather than beside today's processors is the difference between a disclosure and a claim.
OpenRouter (OpenRouter, Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- tutor prompts and the course content grounding them
- authoring and translation drafts submitted for assistance
- text submitted for semantic search embedding
- moderation candidates submitted for classification
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- A live route exists but repository defaults do not select it. Deployed mode and complete slot configuration determine whether data is sent; verify that environment before relying on this draft, and change this notice before enablement.
- Agreement
- None executed. What is owed: OpenRouter's data processing terms, together with the zero-data-retention routing commitment the adapter already asserts on every request — the agreement is what makes that assertion enforceable rather than merely sent.
Mux (Mux, Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- uploaded source video, which for this product means a creator's recorded lessons
- playback and delivery metadata
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- A live route exists but repository defaults do not select it. Deployed mode and complete slot configuration determine whether data is sent; verify that environment before relying on this draft, and change this notice before enablement.
- Agreement
- None executed. What is owed: Mux's data processing addendum.
Deepgram (Deepgram, Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- lesson audio submitted for transcription
- the resulting caption tracks, in English and Korean
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- A live route exists but repository defaults do not select it. Deployed mode and complete slot configuration determine whether data is sent; verify that environment before relying on this draft, and change this notice before enablement.
- Agreement
- None executed. What is owed: Deepgram's data processing addendum.
Better Stack (Better Stack, Inc.)
- Relationship
- Handles data on HxAi's instructions
- What reaches it
- opaque account-deletion request and actor identifiers used only for disaster-recovery reconciliation
- request, recovery-window, receipt-acceptance, key-provenance, and HMAC signature metadata retained for 90 days
- Where
- Not stated anywhere. Neither this product's documentation nor its configuration records where this company processes, so this notice does not claim a place for it.
- Whether it processes anything today
- A live route exists but repository defaults do not select it. Deployed mode and complete slot configuration determine whether data is sent; verify that environment before relying on this draft, and change this notice before enablement.
- Agreement
- None executed. What is owed: Better Stack's data processing agreement.
What is never sent to an analytics vendor
There is no analytics company in this list because there is no analytics company. The sentence below is quoted from the module that holds this product to it, so the claim on this page and the test that enforces it cannot become two different claims.
Direct messages, AI tutor conversations, quiz answer keys, instructor notes and learner submissions are excluded from search and from every measurement, by rules the database enforces rather than by a filter somebody remembered to write.
This product measures learning with its own instrumentation and sends nothing to an analytics vendor: there is no analytics SDK, no measurement tag, no session recorder and no experiment platform in the application or in the bytes the browser receives. The four shapes such a vendor would take are declared as absent with reasons rather than implied, and a test fails the day any of them appears.
How long it is kept
HxAi keeps a retention policy — forty-three classes of data, each with an active retention, a deletion behaviour and a maximum residual period. It is published as an engineering document and is mirrored in code so the two cannot disagree.
Nothing in this product executes those periods on a schedule. There is no job that runs on a clock and expires anything by itself. What actually happens is that data lives until an act removes it: closing your account runs the purge described below, an export archive expires seven days after it is built, and a moderation record or a completion event otherwise stays until an account purge anonymizes it. The periods in the policy are what a sweep would use if one existed, and saying that plainly is the only honest way to publish them.
The retention numbers themselves are marked as proposed and are waiting on the operator's approval, which has not been given. This notice does not present an unapproved number as a commitment.
One backup period is published in the retention policy as 35 days. This product cannot verify it: the backups belong to the hosting platform and nothing in this repository states or configures a retention for them. It is recorded here as unverified rather than repeated as fact.
What happens when you leave
Closing your account starts a 30-day recovery period. Sign-in and your public profile are blocked at once; the account can be brought back until the period ends. After it ends the purge runs, one class of data at a time, and each step writes a receipt.
What goes: your profile, your follows, reactions, bookmarks, shares and mentions, your feed rows, your notifications and the addresses they were sent to, your lesson progress and quiz attempts, your AI usage record, your direct messages and your sign-in identity.
What survives, said plainly rather than left for you to discover. Your account row itself is kept and anonymized rather than deleted, because several records that must not be broken point at it. A course you published personally, if nobody accepted your offer to take it over, passes to an anonymous platform custodian and keeps serving the learners already in it, without your name. Abuse and moderation evidence is kept for the period its class sets, because deleting it on request would make reporting somebody a way to erase the record of it. Completion events are anonymized in place rather than removed, and aggregate counts, which contain no identifier of any kind, are unaffected.
One exception this notice names because it is a known defect rather than a policy: if you applied to become a creator or to run an organization, the statement you wrote about yourself in that application currently survives the purge. It should not, the operator's own retention policy says it should not, and a separate piece of work is open to fix it. It is written here because a privacy notice that quietly omitted it would be the more comfortable choice and the wrong one.
The last message HxAi sends you is the confirmation that the deletion finished, and it is sent in English regardless of the language you used the product in. That is not a preference: your profile — the only place your language was recorded — is deleted before that message is written, so there is nothing left to read it from.
What you can do about it
Two of these are controls you operate yourself, right now, from your account settings: take a copy of your data, and close your account. The rest are described honestly, including the ones this product does not currently serve at all.
The copy you can take covers your profile, workspace memberships, learning, certificates, authored content, social content, direct messages and AI history. It is built into an archive with a manifest that lists every category left out and why, it is handed to you through a link that expires in minutes, and the archive itself is deleted after seven days.
- Knowing what is held about you
- You can obtain a copy of your data through the export in your account settings, which is the only access route this product currently offers; the export's manifest lists every category it leaves out, and some of those — moderation records about you and messages other people wrote to you — cannot be reached by any other means today.
- Taking a copy with you
- You can ask for a portable copy of your profile, learning, certificates, authored content, social content and AI history from your account settings at any time; the archive is built for you, downloadable through a short-lived link, and deleted after seven days.
- Having it deleted
- You can close your account from your account settings; it becomes recoverable for 30 days, during which sign-in and your public profile are blocked, and after that your personal, authentication, AI and direct-message data is purged, with the exceptions this notice lists — a course you published may continue to serve its enrolled learners under an anonymous former-creator custodian, and abuse evidence may be kept for its stated period.
- Correcting it
- You can edit your own profile at any time from your profile settings. This product does not currently operate a wider correction process: there is no route for asking that a moderation record, an acceptance record or a learning record be changed, and this notice says so rather than implying one.
- Objecting to how it is used
- There is currently no channel for objecting to processing, which this notice states plainly rather than implying one; the contact address below is the route once it is published, and until then the honest answer is that this product cannot receive an objection.
- Complaining about any of this
- There is currently no channel for raising a complaint about how your data is handled, and the product no longer tells you otherwise: every message that used to say “contact support” now says there is nowhere to write. The contact address below is the route once it is published.
How to reach somebody about this
Export and account closure need no contact address — both are controls you press yourself. For anything else, this is the current state of the channel, stated rather than papered over with an address nobody reads.
HxAi does not yet publish a contact address for data-protection requests. Export and account deletion are available from your account settings and do not need one; anything else — an objection, a complaint, or a question about what is held about you — has no channel today, and this is stated here rather than answered with an address nobody reads.

