Legal

Privacy Policy

FIRST FLUKE (hereinafter the "Company"), in connection with PromptOps (hereinafter the "Service") that it operates, establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (PIPA) in order to protect users’ personal information and rights and to promptly and smoothly handle related grievances. The Service is a developer tool that provides prompt management and version control, multi-LLM execution and quality evaluation, import and synchronization of prompts within GitHub repositories, and usage analytics.

Published: 2026-06-26Effective: 2026-06-26
This English translation is provided for reference only. The Korean-language version of this Privacy Policy is the legally binding version; in case of any conflict, the Korean version prevails.

Article 1 (Operator Information)

ItemDetails
Trade nameFIRST FLUKE
RepresentativeKim Ga-hyeon
Business registration number711-23-02368
Mail-order business report number2025-Seoul Gwanak-0512
Business address25 Jowon-ro, Gwanak-gu, Seoul, Republic of Korea
Business type / categoryInformation and communications / application software development and supply
Contact emailsupport@promptsops.com
Service URLhttps://www.promptsops.com

Article 2 (Notice on the Collection and Use of Personal Information)

The Company collects the minimum personal information necessary to use the Service.

Paragraph 1 — Personal information processed with the data subject’s consent

A. Account registration and member management

CategoryPurpose of processingItems collectedRetention and use period
Email sign-up (required)Member identification, identity verification, login authenticationEmail, password (one-way hashed by Supabase Auth; plaintext not stored)Until account withdrawal
Email sign-up (optional)Profile displayName, profile imageUntil account withdrawal
Social login (Google)Social account-based member identification and authenticationEmail, name, profile image, provider unique IDUntil account withdrawal
Email verificationConfirmation of ownership of the sign-up emailEmail, verification tokenDestroyed immediately upon completion of verification

B. GitHub repository integration service

When a user connects a GitHub repository for which the user has authorization through the GitHub App, the Company processes the data below within the scope of permissions granted by the user (read/write repository contents, create and manage pull requests).

CategoryPurpose of processingItems collectedRetention and use period
Installation integrationIdentification of connected repositories and access authenticationGitHub App installation ID, connected account login name and type (User/Organization), selected repository ID and name, permission snapshotUntil disconnection or account withdrawal
Prompt importAutomatic detection and import of prompts within the repositorySource file contents of the repository specified by the user (text identified as prompts), file paths, commit informationUntil disconnection or account withdrawal
Change synchronizationCreation and management of pull requests for changesPrompt content authored and synchronized by the user, PR creation and merge historyUntil disconnection or account withdrawal
  • Collection method: GitHub REST API queries and repository push webhooks (receipt of signature-verified events).
  • Upon uninstalling the app on the GitHub side or disconnecting the integration, the Company destroys the relevant installation identifier and integration data without delay (see Articles 7 and 12).

C. LLM execution and BYOK

CategoryPurpose of processingItems collectedRetention and use period
LLM playground and evaluation executionPrompt execution, A/B comparison, quality evaluationPrompts, system prompts, variables, and conversation context entered by the user, model settings, execution resultsUntil account withdrawal (not used to train external AI models)
BYOK (user-provided API key)Model invocation using the user keyExternal LLM provider API keys (stored with symmetric-key encryption), key identification prefixUntil deletion by the user or account withdrawal

D. AI analysis and generation service

CategoryPurpose of processingItems collectedRetention and use period
Import analysisIdentification of prompts in repository source and inference of metadataSource text under analysis, AI analysis results (confidence and rationale)Until account withdrawal (not used to train external AI models)
Usage and activity recordsPersonalization and usage/cost analysisExecuted model, token count, cost, latency, status, favorites, feature-level usage patternsUntil account withdrawal

E. Paid service use

CategoryPurpose of processingItems collectedRetention and use period
Payment processingPlan payment, refunds, settlementMember identifier transmitted to the payment processor (Polar), and customer ID, subscription ID, and transaction status returned from the payment processor (payment information such as card numbers is handled directly by the payment processor and is not retained by the Company)5 years under the E-Commerce Act

Paragraph 2 — Personal information processed without the data subject’s consent

For personal information that may be processed without the data subject’s consent, the Company discloses the items and the legal basis for processing as follows.

Legal basis for processingItems processed
Personal Information Protection Act (PIPA) Article 15(1)4 (conclusion and performance of a contract)Email, password hash
Personal Information Protection Act (PIPA) Article 15(1)6 (legitimate interests)Access IP, session tokens, User-Agent (browser/device/OS) information, and error logs for the purpose of preventing misuse and ensuring security
Protection of Communications Secrets Act Article 15-2(2)Access logs

Article 3 (Matters Concerning the Processing of Sensitive Information)

The Company does not separately collect users’ sensitive information.

However, content voluntarily entered by a user during prompt authoring, execution, or analysis may include sensitive information (such as health, political views, religion, or beliefs) or identifying information of third parties. In such cases, the information is processed in accordance with the entrustment procedures in Article 8 and the cross-border transfer procedures in Article 9. Users are requested to refrain from entering their own or third parties’ sensitive or identifying information when providing input to an LLM.

Article 4 (Matters Concerning the Processing of Personal Information of Children Under 14)

The Company does not accept account registration by children under the age of 14. If the Company becomes aware of an account confirmed to belong to a child under 14, it immediately suspends the account and destroys the related information.

Article 5 (Matters Concerning the Processing of Pseudonymized Information)

The Company does not separately generate or process pseudonymized information. If the Company processes pseudonymized information in the future for purposes such as statistical compilation, scientific research, or archiving in the public interest, it will amend this Policy in advance and provide notice.

Article 6 (Installation and Operation of Automatic Personal Information Collection Devices and Processing of Behavioral Information)

Paragraph 1 — Use of Cookies

The Company uses "cookies" to maintain login sessions and to improve the convenience of using the Service.

  • Purpose of cookie use: maintaining login sessions and improving service convenience
  • How to refuse cookies: You can refuse cookie storage in your browser settings (Chrome: Settings > Privacy and security > Cookies / Safari: Preferences > Privacy / Edge: Settings > Cookies and site permissions). However, doing so may make it difficult to use some services, such as login.

Paragraph 2 — Behavioral Information and Analytics Tools

The Company does not provide online targeted advertising and does not collect advertising identifiers (ADID/IDFA). However, to improve service quality and ensure stability, the Company operates the following analytics and monitoring tools.

  • Microsoft Clarity (session analytics): usability analysis through page clicks, scrolls, and session replay (heatmap and session replay). Sensitive areas such as input fields are masked, and the data is not used for advertising purposes.
  • Vercel Analytics: aggregate statistics such as page views, devices, and referral paths.
  • Sentry: service error and performance monitoring.

Article 7 (Retention and Use Period of Personal Information and Destruction)

Paragraph 1 — Retention and Use Period

When personal information becomes unnecessary due to the expiration of the retention period, the achievement of the processing purpose, or similar reasons, the Company destroys the relevant personal information without delay.

Purpose of processingRetention period
Member managementDestroyed immediately upon account withdrawal
GitHub integration information (including installation ID and integration data)Destroyed immediately upon disconnection or account withdrawal
Prompts, versions, datasets, and evaluation dataDestroyed upon account withdrawal (or upon deletion by the user)
BYOK API keysDestroyed immediately upon deletion by the user or account withdrawal
LLM execution/analysis input and result recordsDestroyed immediately upon account withdrawal
Audit logsAutomatically destroyed after 90 days (users may delete immediately)

Paragraph 2 — Mandatory Retention Periods Under Applicable Laws

Items that must be retained under applicable laws are stored separately and destroyed upon expiration of the retention period.

Item retainedLegal basisRetention period
Records on contracts or withdrawal of subscriptionthe E-Commerce Act5 years
Records on payment and supply of goodsthe E-Commerce Act5 years
Records on consumer complaints or dispute resolutionthe E-Commerce Act3 years
Records on labeling and advertisingthe E-Commerce Act6 months
Access logsthe Protection of Communications Secrets Act Article 15-2(2)3 months
Consent records are retained separately as legal evidentiary material to prove the fact of consent, and contain only the minimum information necessary to identify the data subject.

Paragraph 3 — Destruction Procedure and Method

  • Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Privacy Officer.
  • Destruction method: Personal information recorded in electronic file form is destroyed using technical methods that prevent the records from being reproduced (permanent deletion, overwriting), and information recorded on paper documents is shredded or incinerated.

Article 8 (Entrustment of Personal Information Processing)

For the smooth processing of personal information, the Company entrusts personal information processing tasks as follows. When entering into entrustment contracts, in accordance with Article 26 of the Personal Information Protection Act (PIPA), the Company specifies in the contract or terms matters such as the prohibition of processing personal information beyond the purpose of the entrusted work, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of the trustee, and liability for damages, and supervises whether the trustee processes personal information securely.

TrusteeEntrusted workRetention and use period
Supabase, Inc.Database hosting and member authenticationUntil account withdrawal or termination of the entrustment contract
Vercel, Inc.Application hosting and traffic analyticsUntil termination of the entrustment contract
Upstash, Inc.Cache (short-term storage) processingDestroyed upon cache expiration (short term)
Polar Software Inc.Paid payment and subscription managementRetention period under applicable laws
OpenRouter, Inc.LLM call routing (gateway)Destroyed immediately after processing
OpenAI, L.L.C.LLM prompt execution processingDestroyed immediately after processing
Anthropic, PBCLLM prompt execution processingDestroyed immediately after processing
Google LLCLLM (Gemini) execution processing and social login authenticationDestroyed after processing/authentication is completed
GitHub, Inc.Repository prompt import and synchronization processingDestroyed upon disconnection
Resend, Inc.Sending sign-up verification and notification emailsDestroyed immediately after sending
Functional Software, Inc. (Sentry)Service error and performance monitoringPer Sentry’s retention policy
Microsoft Corporation (Clarity)Usability analysis (session replay and heatmap)Per Clarity’s retention policy
Inngest, Inc.Background job (email, synchronization, evaluation, etc.) processingDestroyed after processing

If the content of the entrusted work or the trustee changes, the Company will disclose it through this Privacy Policy.

Article 9 (Cross-Border Transfer of Personal Information)

Within the scope essential for performing the service provision contract, and in accordance with Article 28-8(1)3(a) of the Personal Information Protection Act (PIPA), the Company transfers personal information abroad by disclosing and giving prior notice through this Policy. All trustees below are located in the United States, and transmissions are encrypted with HTTPS/TLS.

Transferee / CountryItems transferredPurpose of transferRetention periodPrivacy policy
Supabase, Inc. / United StatesMember information, service usage dataDB hosting and member authenticationUntil account withdrawalhttps://supabase.com/privacy
Vercel, Inc. / United StatesAccess IP, request metadata, aggregate analyticsHosting and traffic analyticsPer Vercel’s policyhttps://vercel.com/legal/privacy-policy
Upstash, Inc. / United StatesCache keys and values (short term)Cache processingDestroyed upon cache expirationhttps://upstash.com/trust/privacy.pdf
Polar Software Inc. / United StatesMember identifier, subscription and payment statusPayment and subscription processingPeriod under applicable lawshttps://polar.sh/legal/privacy
OpenRouter, Inc. / United StatesLLM input content (prompts, variables, context)LLM call routingDestroyed immediately after the API responsehttps://openrouter.ai/privacy
OpenAI, L.L.C. / United StatesLLM input content (prompts, variables, context)LLM executionDestroyed immediately after the API responsehttps://openai.com/policies/privacy-policy
Anthropic, PBC / United StatesLLM input content (prompts, variables, context)LLM executionDestroyed immediately after the API responsehttps://www.anthropic.com/legal/privacy
Google LLC / United StatesLLM input content / email, name, and unique ID for social loginLLM execution and social loginDestroyed immediately after the API response / destroyed after authenticationhttps://policies.google.com/privacy
GitHub, Inc. / United StatesRepository read/write requests via OAuth token, imported source contentRepository import and synchronizationDestroyed upon disconnectionhttps://docs.github.com/site-policy
Resend, Inc. / United StatesRecipient email, verification and notification linksEmail sendingDestroyed after sendinghttps://resend.com/legal/privacy-policy
Functional Software, Inc. (Sentry) / United StatesError stack traces and performance trace dataError and performance monitoringPer Sentry’s policyhttps://sentry.io/privacy
Microsoft Corporation (Clarity) / United StatesUsability data such as session replay, clicks, and scrollsUsability analysisPer Clarity’s policyhttps://privacy.microsoft.com
Inngest, Inc. / United StatesJob event payloads (workspace and user identifiers, etc.)Background job processingDestroyed after processinghttps://www.inngest.com/privacy

Paragraph 1 — Processing of LLM Input Content

  • No use for AI model training: Under their respective provider policies, OpenAI, Anthropic, Google, and others do not use API input data to train or fine-tune their own AI/ML models without the user’s prior permission. However, because provider policies may change, users are advised to exercise caution at the time of input.
  • Abuse monitoring logging: Each AI provider may retain some logs for a limited period for the purpose of preventing abuse of the service.

Paragraph 2 — How to Refuse Cross-Border Transfer

Users may request withdrawal of consent to cross-border transfer at support@promptsops.com. However, features that necessarily involve cross-border transfer (LLM execution, GitHub integration, social login, payment, etc.) may be restricted upon withdrawal of consent.

Article 10 (Provision of Personal Information to Third Parties)

Paragraph 1 — Principle

The Company processes the data subject’s personal information only within the scope specified in Article 2, and provides personal information to third parties only when the user’s separate prior consent or a special requirement under applicable laws arises.

Paragraph 2 — Cases Where Provision Is Permitted Without Prior Consent

  1. Where there is a special provision in another statute, or where it is unavoidable in order to comply with a legal obligation
  2. Where provided pursuant to a court production order or a warrant issued by a judge
  3. Where an investigative agency requests it for investigative purposes in accordance with the procedures and methods prescribed by law
  4. Where it is clearly deemed necessary for the urgent life, bodily, or property interests of the data subject or a third party

Article 11 (Measures to Ensure the Security of Personal Information)

In accordance with Article 29 of the Personal Information Protection Act (PIPA), the Company takes the technical, managerial, and physical measures necessary to ensure security as follows.

Paragraph 1 — Managerial Measures

  • Minimizing the number of personnel who handle personal information and operating with separated privileges
  • Operating internal handling procedures for responding to personal information breaches

Paragraph 2 — Technical Measures

  • One-way encryption of passwords (Supabase Auth)
  • Symmetric-key encrypted storage (AES-256-GCM) of BYOK external LLM API keys
  • One-way hash (SHA-256) storage of service API keys, retaining only the identification prefix
  • Encryption of communication channels (HTTPS/TLS)
  • Access control through granting, changing, and revoking database access privileges, and row-level security (RLS)
  • Prevention of forgery and tampering through signature (HMAC-SHA256) verification when receiving external webhooks
  • Review of access records

Paragraph 3 — Physical Measures

  • Servers are operated on cloud infrastructure with externally controlled access

Article 11-2 (Notification and Reporting of Personal Information Leakage, etc.)

In accordance with Article 34 of the Personal Information Protection Act (PIPA), when the loss, theft, leakage, forgery, alteration, or damage of personal information (hereinafter "leakage, etc.") has occurred or the Company becomes aware that it has occurred, the Company notifies the relevant data subject of the following matters without delay and, where the statutory thresholds are met, reports to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA).

  1. The items of personal information subject to the leakage, etc.
  2. The time at which the leakage, etc. occurred and the circumstances thereof
  3. Information on measures that the data subject can take to minimize the damage that may result from the leakage, etc.
  4. The Company’s response measures and damage remedy procedures
  5. The department and contact information to which reports may be submitted if damage occurs to the data subject, and how to claim damages and apply for dispute mediation

Article 12 (Rights and Obligations of Users and Legal Representatives and How to Exercise Them)

Paragraph 1 — Types of Rights

  1. Request to access personal information
  2. Request for correction in the event of errors, etc.
  3. Request for deletion
  4. Request to suspend processing
  5. Request to withdraw consent
  6. Request to transmit personal information (Personal Information Protection Act (PIPA) Article 35-2)

Paragraph 2 — How to Exercise Rights

  • Viewing and editing member information: account settings within the Service
  • Viewing audit logs: Workspace settings → Audit screen
  • Disconnecting GitHub integration: Settings within the Service → Disconnect (upon disconnection, the stored installation identifier and integration data are immediately destroyed)
  • Deleting BYOK keys: Settings within the Service → API key management
  • Exporting (transmitting) personal information: the export (CSV/JSON) feature within the Service
  • Account withdrawal and deletion of all personal information: immediate and permanent deletion directly via Settings → Danger zone / Account withdrawal within the Service (including workspaces, integration tokens, and content). Requests may also be made at support@promptsops.com
  • Exercising other rights: submit a request to support@promptsops.com

The Company processes requests without delay from the date of receipt and may carry out an identity verification procedure.

Paragraph 3 — Exercise of Rights by Legal Representatives

Rights concerning the personal information of children under the age of 14 must be exercised directly by their legal representative. However, the Company does not accept account registration by children under the age of 14.

Paragraph 4 — Grounds for Restricting the Exercise of Rights

The Company may refuse a user’s request to exercise rights where there is a legal basis under statutes such as Article 35(4) and Article 37(2) of the Personal Information Protection Act (PIPA), in which case it notifies the user of the grounds without delay. Where a data subject requests the correction or deletion of errors, etc. in personal information, the Company does not use or provide the relevant personal information until the correction or deletion is completed.

Article 13 (Matters Concerning Automated Decisions)

The Company does not make automated decisions that significantly affect the rights or obligations of data subjects, as set forth in Article 37-2 of the Personal Information Protection Act (PIPA).

However, the following features involve inference and result generation using generative artificial intelligence.

  • AI-based prompt quality evaluation and score calculation
  • Automatic detection and analysis of prompts within GitHub repositories
  • Generation of LLM execution results and prompt suggestions

The outputs of the above features are reference material to assist the user’s own review and judgment, and do not automatically render decisions or dispositions with legal effect. In accordance with Article 37-2 of the Personal Information Protection Act (PIPA), users may request an explanation of the criteria and procedures of automated processing or, where they consider that such processing significantly affects their rights or obligations, may refuse it or request re-processing by a human, and the Company processes requests submitted to support@promptsops.com.

Article 14 (Criteria for Determining Additional Use and Provision)

As a rule, the Company does not engage in additional use or provision under Article 15(3) and Article 17(4) of the Personal Information Protection Act (PIPA). Where additional use or provision is unavoidably necessary, the Company processes it by comprehensively considering (i) the relevance to the original purpose of collection, (ii) the predictability in light of the circumstances of collection and processing practices, (iii) whether it unfairly infringes on the interests of the data subject, and (iv) whether security measures such as pseudonymization or encryption have been taken.

Article 15 (Matters Concerning the Operation and Management of Visual Information Processing Devices)

The Company does not operate fixed or mobile visual information processing devices (such as CCTV).

Article 16 (Privacy Officer and Methods of Remedy for Infringement of User Rights)

Paragraph 1 — Privacy Officer

The Company designates a Privacy Officer as below to take overall responsibility for personal information processing tasks and to handle data subjects’ complaints relating to personal information and remedy of damages.

ItemDetails
NameKim Ga-hyeon
TitleRepresentative
Emailsupport@promptsops.com

Paragraph 2 — Agencies for Remedy of Rights Infringement

To obtain remedy for personal information infringement, data subjects may apply to the agencies below for dispute resolution, counseling, etc.

AgencyContactWebsite
Privacy Infringement Report Center118 (no area code)privacy.kisa.or.kr
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
Supreme Prosecutors’ Office Cyber Investigation Division1301 (no area code)www.spo.go.kr
National Police Agency Cyber Investigation Bureau182 (no area code)ecrm.cyber.go.kr

Paragraph 3 — Department for Receiving and Handling Access Requests, etc.

ItemDetails
Receiving and handling departmentPrivacy Protection Team
Person in chargeKim Ga-hyeon (Representative)
Emailsupport@promptsops.com

Article 17 (Legal Notice and Disclaimer)

Paragraph 1 — Not a Substitute for Professional Advice

All outputs provided by the Service, including AI responses, quality evaluations, and analysis results, are intended for general information and decision-making support, and do not substitute for professional advice in fields such as law, tax, and copyright.

Paragraph 2 — Limitations of AI Outputs

AI outputs are inference results of generative artificial intelligence models, may be inaccurate or contrary to fact, and may not immediately reflect the latest information. The Company is not liable for damages arising from decisions based on AI outputs.

Paragraph 3 — Copyright

Copyright in the Service’s UI, design, and code belongs to the operator, FIRST FLUKE. Copyright in content and prompts that users enter or upload to the Service belongs to the users.

Article 18 (Changes to the Privacy Policy)

This Privacy Policy applies from its effective date. If there are additions, deletions, or corrections to its contents pursuant to statutes or policy, the Company will give notice through announcements from 7 days before the effective date of the changes. However, in the case of changes that significantly affect users’ rights, notice will be given from 30 days before the effective date.