Legal
Privacy Policy
FIRST FLUKE (hereinafter the "Company"), in connection with PromptOps (hereinafter the "Service") that it operates, establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (PIPA) in order to protect users’ personal information and rights and to promptly and smoothly handle related grievances. The Service is a developer tool that provides prompt management and version control, multi-LLM execution and quality evaluation, import and synchronization of prompts within GitHub repositories, and usage analytics.
Article 1 (Operator Information)
| Item | Details |
|---|---|
| Trade name | FIRST FLUKE |
| Representative | Kim Ga-hyeon |
| Business registration number | 711-23-02368 |
| Mail-order business report number | 2025-Seoul Gwanak-0512 |
| Business address | 25 Jowon-ro, Gwanak-gu, Seoul, Republic of Korea |
| Business type / category | Information and communications / application software development and supply |
| Contact email | support@promptsops.com |
| Service URL | https://www.promptsops.com |
Article 2 (Notice on the Collection and Use of Personal Information)
The Company collects the minimum personal information necessary to use the Service.
Paragraph 1 — Personal information processed with the data subject’s consent
A. Account registration and member management
| Category | Purpose of processing | Items collected | Retention and use period |
|---|---|---|---|
| Email sign-up (required) | Member identification, identity verification, login authentication | Email, password (one-way hashed by Supabase Auth; plaintext not stored) | Until account withdrawal |
| Email sign-up (optional) | Profile display | Name, profile image | Until account withdrawal |
| Social login (Google) | Social account-based member identification and authentication | Email, name, profile image, provider unique ID | Until account withdrawal |
| Email verification | Confirmation of ownership of the sign-up email | Email, verification token | Destroyed immediately upon completion of verification |
B. GitHub repository integration service
When a user connects a GitHub repository for which the user has authorization through the GitHub App, the Company processes the data below within the scope of permissions granted by the user (read/write repository contents, create and manage pull requests).
| Category | Purpose of processing | Items collected | Retention and use period |
|---|---|---|---|
| Installation integration | Identification of connected repositories and access authentication | GitHub App installation ID, connected account login name and type (User/Organization), selected repository ID and name, permission snapshot | Until disconnection or account withdrawal |
| Prompt import | Automatic detection and import of prompts within the repository | Source file contents of the repository specified by the user (text identified as prompts), file paths, commit information | Until disconnection or account withdrawal |
| Change synchronization | Creation and management of pull requests for changes | Prompt content authored and synchronized by the user, PR creation and merge history | Until disconnection or account withdrawal |
- Collection method: GitHub REST API queries and repository push webhooks (receipt of signature-verified events).
- Upon uninstalling the app on the GitHub side or disconnecting the integration, the Company destroys the relevant installation identifier and integration data without delay (see Articles 7 and 12).
C. LLM execution and BYOK
| Category | Purpose of processing | Items collected | Retention and use period |
|---|---|---|---|
| LLM playground and evaluation execution | Prompt execution, A/B comparison, quality evaluation | Prompts, system prompts, variables, and conversation context entered by the user, model settings, execution results | Until account withdrawal (not used to train external AI models) |
| BYOK (user-provided API key) | Model invocation using the user key | External LLM provider API keys (stored with symmetric-key encryption), key identification prefix | Until deletion by the user or account withdrawal |
D. AI analysis and generation service
| Category | Purpose of processing | Items collected | Retention and use period |
|---|---|---|---|
| Import analysis | Identification of prompts in repository source and inference of metadata | Source text under analysis, AI analysis results (confidence and rationale) | Until account withdrawal (not used to train external AI models) |
| Usage and activity records | Personalization and usage/cost analysis | Executed model, token count, cost, latency, status, favorites, feature-level usage patterns | Until account withdrawal |
E. Paid service use
| Category | Purpose of processing | Items collected | Retention and use period |
|---|---|---|---|
| Payment processing | Plan payment, refunds, settlement | Member identifier transmitted to the payment processor (Polar), and customer ID, subscription ID, and transaction status returned from the payment processor (payment information such as card numbers is handled directly by the payment processor and is not retained by the Company) | 5 years under the E-Commerce Act |
Paragraph 2 — Personal information processed without the data subject’s consent
For personal information that may be processed without the data subject’s consent, the Company discloses the items and the legal basis for processing as follows.
| Legal basis for processing | Items processed |
|---|---|
| Personal Information Protection Act (PIPA) Article 15(1)4 (conclusion and performance of a contract) | Email, password hash |
| Personal Information Protection Act (PIPA) Article 15(1)6 (legitimate interests) | Access IP, session tokens, User-Agent (browser/device/OS) information, and error logs for the purpose of preventing misuse and ensuring security |
| Protection of Communications Secrets Act Article 15-2(2) | Access logs |
Article 3 (Matters Concerning the Processing of Sensitive Information)
The Company does not separately collect users’ sensitive information.
However, content voluntarily entered by a user during prompt authoring, execution, or analysis may include sensitive information (such as health, political views, religion, or beliefs) or identifying information of third parties. In such cases, the information is processed in accordance with the entrustment procedures in Article 8 and the cross-border transfer procedures in Article 9. Users are requested to refrain from entering their own or third parties’ sensitive or identifying information when providing input to an LLM.
Article 4 (Matters Concerning the Processing of Personal Information of Children Under 14)
The Company does not accept account registration by children under the age of 14. If the Company becomes aware of an account confirmed to belong to a child under 14, it immediately suspends the account and destroys the related information.
Article 5 (Matters Concerning the Processing of Pseudonymized Information)
The Company does not separately generate or process pseudonymized information. If the Company processes pseudonymized information in the future for purposes such as statistical compilation, scientific research, or archiving in the public interest, it will amend this Policy in advance and provide notice.
Article 6 (Installation and Operation of Automatic Personal Information Collection Devices and Processing of Behavioral Information)
Paragraph 1 — Use of Cookies
The Company uses "cookies" to maintain login sessions and to improve the convenience of using the Service.
- Purpose of cookie use: maintaining login sessions and improving service convenience
- How to refuse cookies: You can refuse cookie storage in your browser settings (Chrome: Settings > Privacy and security > Cookies / Safari: Preferences > Privacy / Edge: Settings > Cookies and site permissions). However, doing so may make it difficult to use some services, such as login.
Paragraph 2 — Behavioral Information and Analytics Tools
The Company does not provide online targeted advertising and does not collect advertising identifiers (ADID/IDFA). However, to improve service quality and ensure stability, the Company operates the following analytics and monitoring tools.
- Microsoft Clarity (session analytics): usability analysis through page clicks, scrolls, and session replay (heatmap and session replay). Sensitive areas such as input fields are masked, and the data is not used for advertising purposes.
- Vercel Analytics: aggregate statistics such as page views, devices, and referral paths.
- Sentry: service error and performance monitoring.
Article 7 (Retention and Use Period of Personal Information and Destruction)
Paragraph 1 — Retention and Use Period
When personal information becomes unnecessary due to the expiration of the retention period, the achievement of the processing purpose, or similar reasons, the Company destroys the relevant personal information without delay.
| Purpose of processing | Retention period |
|---|---|
| Member management | Destroyed immediately upon account withdrawal |
| GitHub integration information (including installation ID and integration data) | Destroyed immediately upon disconnection or account withdrawal |
| Prompts, versions, datasets, and evaluation data | Destroyed upon account withdrawal (or upon deletion by the user) |
| BYOK API keys | Destroyed immediately upon deletion by the user or account withdrawal |
| LLM execution/analysis input and result records | Destroyed immediately upon account withdrawal |
| Audit logs | Automatically destroyed after 90 days (users may delete immediately) |
Paragraph 2 — Mandatory Retention Periods Under Applicable Laws
Items that must be retained under applicable laws are stored separately and destroyed upon expiration of the retention period.
| Item retained | Legal basis | Retention period |
|---|---|---|
| Records on contracts or withdrawal of subscription | the E-Commerce Act | 5 years |
| Records on payment and supply of goods | the E-Commerce Act | 5 years |
| Records on consumer complaints or dispute resolution | the E-Commerce Act | 3 years |
| Records on labeling and advertising | the E-Commerce Act | 6 months |
| Access logs | the Protection of Communications Secrets Act Article 15-2(2) | 3 months |
Paragraph 3 — Destruction Procedure and Method
- Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Privacy Officer.
- Destruction method: Personal information recorded in electronic file form is destroyed using technical methods that prevent the records from being reproduced (permanent deletion, overwriting), and information recorded on paper documents is shredded or incinerated.
Article 8 (Entrustment of Personal Information Processing)
For the smooth processing of personal information, the Company entrusts personal information processing tasks as follows. When entering into entrustment contracts, in accordance with Article 26 of the Personal Information Protection Act (PIPA), the Company specifies in the contract or terms matters such as the prohibition of processing personal information beyond the purpose of the entrusted work, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of the trustee, and liability for damages, and supervises whether the trustee processes personal information securely.
| Trustee | Entrusted work | Retention and use period |
|---|---|---|
| Supabase, Inc. | Database hosting and member authentication | Until account withdrawal or termination of the entrustment contract |
| Vercel, Inc. | Application hosting and traffic analytics | Until termination of the entrustment contract |
| Upstash, Inc. | Cache (short-term storage) processing | Destroyed upon cache expiration (short term) |
| Polar Software Inc. | Paid payment and subscription management | Retention period under applicable laws |
| OpenRouter, Inc. | LLM call routing (gateway) | Destroyed immediately after processing |
| OpenAI, L.L.C. | LLM prompt execution processing | Destroyed immediately after processing |
| Anthropic, PBC | LLM prompt execution processing | Destroyed immediately after processing |
| Google LLC | LLM (Gemini) execution processing and social login authentication | Destroyed after processing/authentication is completed |
| GitHub, Inc. | Repository prompt import and synchronization processing | Destroyed upon disconnection |
| Resend, Inc. | Sending sign-up verification and notification emails | Destroyed immediately after sending |
| Functional Software, Inc. (Sentry) | Service error and performance monitoring | Per Sentry’s retention policy |
| Microsoft Corporation (Clarity) | Usability analysis (session replay and heatmap) | Per Clarity’s retention policy |
| Inngest, Inc. | Background job (email, synchronization, evaluation, etc.) processing | Destroyed after processing |
If the content of the entrusted work or the trustee changes, the Company will disclose it through this Privacy Policy.
Article 9 (Cross-Border Transfer of Personal Information)
Within the scope essential for performing the service provision contract, and in accordance with Article 28-8(1)3(a) of the Personal Information Protection Act (PIPA), the Company transfers personal information abroad by disclosing and giving prior notice through this Policy. All trustees below are located in the United States, and transmissions are encrypted with HTTPS/TLS.
| Transferee / Country | Items transferred | Purpose of transfer | Retention period | Privacy policy |
|---|---|---|---|---|
| Supabase, Inc. / United States | Member information, service usage data | DB hosting and member authentication | Until account withdrawal | https://supabase.com/privacy |
| Vercel, Inc. / United States | Access IP, request metadata, aggregate analytics | Hosting and traffic analytics | Per Vercel’s policy | https://vercel.com/legal/privacy-policy |
| Upstash, Inc. / United States | Cache keys and values (short term) | Cache processing | Destroyed upon cache expiration | https://upstash.com/trust/privacy.pdf |
| Polar Software Inc. / United States | Member identifier, subscription and payment status | Payment and subscription processing | Period under applicable laws | https://polar.sh/legal/privacy |
| OpenRouter, Inc. / United States | LLM input content (prompts, variables, context) | LLM call routing | Destroyed immediately after the API response | https://openrouter.ai/privacy |
| OpenAI, L.L.C. / United States | LLM input content (prompts, variables, context) | LLM execution | Destroyed immediately after the API response | https://openai.com/policies/privacy-policy |
| Anthropic, PBC / United States | LLM input content (prompts, variables, context) | LLM execution | Destroyed immediately after the API response | https://www.anthropic.com/legal/privacy |
| Google LLC / United States | LLM input content / email, name, and unique ID for social login | LLM execution and social login | Destroyed immediately after the API response / destroyed after authentication | https://policies.google.com/privacy |
| GitHub, Inc. / United States | Repository read/write requests via OAuth token, imported source content | Repository import and synchronization | Destroyed upon disconnection | https://docs.github.com/site-policy |
| Resend, Inc. / United States | Recipient email, verification and notification links | Email sending | Destroyed after sending | https://resend.com/legal/privacy-policy |
| Functional Software, Inc. (Sentry) / United States | Error stack traces and performance trace data | Error and performance monitoring | Per Sentry’s policy | https://sentry.io/privacy |
| Microsoft Corporation (Clarity) / United States | Usability data such as session replay, clicks, and scrolls | Usability analysis | Per Clarity’s policy | https://privacy.microsoft.com |
| Inngest, Inc. / United States | Job event payloads (workspace and user identifiers, etc.) | Background job processing | Destroyed after processing | https://www.inngest.com/privacy |
Paragraph 1 — Processing of LLM Input Content
- No use for AI model training: Under their respective provider policies, OpenAI, Anthropic, Google, and others do not use API input data to train or fine-tune their own AI/ML models without the user’s prior permission. However, because provider policies may change, users are advised to exercise caution at the time of input.
- Abuse monitoring logging: Each AI provider may retain some logs for a limited period for the purpose of preventing abuse of the service.
Paragraph 2 — How to Refuse Cross-Border Transfer
Users may request withdrawal of consent to cross-border transfer at support@promptsops.com. However, features that necessarily involve cross-border transfer (LLM execution, GitHub integration, social login, payment, etc.) may be restricted upon withdrawal of consent.
Article 10 (Provision of Personal Information to Third Parties)
Paragraph 1 — Principle
The Company processes the data subject’s personal information only within the scope specified in Article 2, and provides personal information to third parties only when the user’s separate prior consent or a special requirement under applicable laws arises.
Paragraph 2 — Cases Where Provision Is Permitted Without Prior Consent
- Where there is a special provision in another statute, or where it is unavoidable in order to comply with a legal obligation
- Where provided pursuant to a court production order or a warrant issued by a judge
- Where an investigative agency requests it for investigative purposes in accordance with the procedures and methods prescribed by law
- Where it is clearly deemed necessary for the urgent life, bodily, or property interests of the data subject or a third party
Article 11 (Measures to Ensure the Security of Personal Information)
In accordance with Article 29 of the Personal Information Protection Act (PIPA), the Company takes the technical, managerial, and physical measures necessary to ensure security as follows.
Paragraph 1 — Managerial Measures
- Minimizing the number of personnel who handle personal information and operating with separated privileges
- Operating internal handling procedures for responding to personal information breaches
Paragraph 2 — Technical Measures
- One-way encryption of passwords (Supabase Auth)
- Symmetric-key encrypted storage (AES-256-GCM) of BYOK external LLM API keys
- One-way hash (SHA-256) storage of service API keys, retaining only the identification prefix
- Encryption of communication channels (HTTPS/TLS)
- Access control through granting, changing, and revoking database access privileges, and row-level security (RLS)
- Prevention of forgery and tampering through signature (HMAC-SHA256) verification when receiving external webhooks
- Review of access records
Paragraph 3 — Physical Measures
- Servers are operated on cloud infrastructure with externally controlled access
Article 11-2 (Notification and Reporting of Personal Information Leakage, etc.)
In accordance with Article 34 of the Personal Information Protection Act (PIPA), when the loss, theft, leakage, forgery, alteration, or damage of personal information (hereinafter "leakage, etc.") has occurred or the Company becomes aware that it has occurred, the Company notifies the relevant data subject of the following matters without delay and, where the statutory thresholds are met, reports to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA).
- The items of personal information subject to the leakage, etc.
- The time at which the leakage, etc. occurred and the circumstances thereof
- Information on measures that the data subject can take to minimize the damage that may result from the leakage, etc.
- The Company’s response measures and damage remedy procedures
- The department and contact information to which reports may be submitted if damage occurs to the data subject, and how to claim damages and apply for dispute mediation
Article 12 (Rights and Obligations of Users and Legal Representatives and How to Exercise Them)
Paragraph 1 — Types of Rights
- Request to access personal information
- Request for correction in the event of errors, etc.
- Request for deletion
- Request to suspend processing
- Request to withdraw consent
- Request to transmit personal information (Personal Information Protection Act (PIPA) Article 35-2)
Paragraph 2 — How to Exercise Rights
- Viewing and editing member information: account settings within the Service
- Viewing audit logs: Workspace settings → Audit screen
- Disconnecting GitHub integration: Settings within the Service → Disconnect (upon disconnection, the stored installation identifier and integration data are immediately destroyed)
- Deleting BYOK keys: Settings within the Service → API key management
- Exporting (transmitting) personal information: the export (CSV/JSON) feature within the Service
- Account withdrawal and deletion of all personal information: immediate and permanent deletion directly via Settings → Danger zone / Account withdrawal within the Service (including workspaces, integration tokens, and content). Requests may also be made at support@promptsops.com
- Exercising other rights: submit a request to support@promptsops.com
The Company processes requests without delay from the date of receipt and may carry out an identity verification procedure.
Paragraph 3 — Exercise of Rights by Legal Representatives
Rights concerning the personal information of children under the age of 14 must be exercised directly by their legal representative. However, the Company does not accept account registration by children under the age of 14.
Paragraph 4 — Grounds for Restricting the Exercise of Rights
The Company may refuse a user’s request to exercise rights where there is a legal basis under statutes such as Article 35(4) and Article 37(2) of the Personal Information Protection Act (PIPA), in which case it notifies the user of the grounds without delay. Where a data subject requests the correction or deletion of errors, etc. in personal information, the Company does not use or provide the relevant personal information until the correction or deletion is completed.
Article 13 (Matters Concerning Automated Decisions)
The Company does not make automated decisions that significantly affect the rights or obligations of data subjects, as set forth in Article 37-2 of the Personal Information Protection Act (PIPA).
However, the following features involve inference and result generation using generative artificial intelligence.
- AI-based prompt quality evaluation and score calculation
- Automatic detection and analysis of prompts within GitHub repositories
- Generation of LLM execution results and prompt suggestions
The outputs of the above features are reference material to assist the user’s own review and judgment, and do not automatically render decisions or dispositions with legal effect. In accordance with Article 37-2 of the Personal Information Protection Act (PIPA), users may request an explanation of the criteria and procedures of automated processing or, where they consider that such processing significantly affects their rights or obligations, may refuse it or request re-processing by a human, and the Company processes requests submitted to support@promptsops.com.
Article 14 (Criteria for Determining Additional Use and Provision)
As a rule, the Company does not engage in additional use or provision under Article 15(3) and Article 17(4) of the Personal Information Protection Act (PIPA). Where additional use or provision is unavoidably necessary, the Company processes it by comprehensively considering (i) the relevance to the original purpose of collection, (ii) the predictability in light of the circumstances of collection and processing practices, (iii) whether it unfairly infringes on the interests of the data subject, and (iv) whether security measures such as pseudonymization or encryption have been taken.
Article 15 (Matters Concerning the Operation and Management of Visual Information Processing Devices)
The Company does not operate fixed or mobile visual information processing devices (such as CCTV).
Article 16 (Privacy Officer and Methods of Remedy for Infringement of User Rights)
Paragraph 1 — Privacy Officer
The Company designates a Privacy Officer as below to take overall responsibility for personal information processing tasks and to handle data subjects’ complaints relating to personal information and remedy of damages.
| Item | Details |
|---|---|
| Name | Kim Ga-hyeon |
| Title | Representative |
| support@promptsops.com |
Paragraph 2 — Agencies for Remedy of Rights Infringement
To obtain remedy for personal information infringement, data subjects may apply to the agencies below for dispute resolution, counseling, etc.
| Agency | Contact | Website |
|---|---|---|
| Privacy Infringement Report Center | 118 (no area code) | privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) | www.kopico.go.kr |
| Supreme Prosecutors’ Office Cyber Investigation Division | 1301 (no area code) | www.spo.go.kr |
| National Police Agency Cyber Investigation Bureau | 182 (no area code) | ecrm.cyber.go.kr |
Paragraph 3 — Department for Receiving and Handling Access Requests, etc.
| Item | Details |
|---|---|
| Receiving and handling department | Privacy Protection Team |
| Person in charge | Kim Ga-hyeon (Representative) |
| support@promptsops.com |
Article 17 (Legal Notice and Disclaimer)
Paragraph 1 — Not a Substitute for Professional Advice
All outputs provided by the Service, including AI responses, quality evaluations, and analysis results, are intended for general information and decision-making support, and do not substitute for professional advice in fields such as law, tax, and copyright.
Paragraph 2 — Limitations of AI Outputs
AI outputs are inference results of generative artificial intelligence models, may be inaccurate or contrary to fact, and may not immediately reflect the latest information. The Company is not liable for damages arising from decisions based on AI outputs.
Paragraph 3 — Copyright
Copyright in the Service’s UI, design, and code belongs to the operator, FIRST FLUKE. Copyright in content and prompts that users enter or upload to the Service belongs to the users.
Article 18 (Changes to the Privacy Policy)
This Privacy Policy applies from its effective date. If there are additions, deletions, or corrections to its contents pursuant to statutes or policy, the Company will give notice through announcements from 7 days before the effective date of the changes. However, in the case of changes that significantly affect users’ rights, notice will be given from 30 days before the effective date.