WINDOLET / Policies
Privacy Policy
Current website data practices and the proposed practices for the desktop software are explained separately.
- Service name
- Windolet
- Country of operation
- Republic of Korea
- Legal operator name
- To be published before sales open
- Contact email
- windolet.team@gmail.com
Windolet is the service name. It is not presented as a verified registered business name or the operator’s legal name.
1. The current website
The current website code has no registration or payment-information form and no advertising or analytics scripts. Language selection changes the URL without advertising cookies or local storage for language preferences. Fonts are served by the site, and pixel illustrations are rendered in the browser.
The website is hosted on Cloudflare Pages. Cloudflare may process connection data such as IP address, access time, requested URL and browser information to deliver pages and protect against abuse. Optional Cloudflare Web Analytics is disabled. The specific fields and retention of hosting connection logs will be added after confirmation.
The letter preview runs only within this browser. It does not send preview letters to another user or messaging server and does not collect Google login details or license keys.
2. Planned software data
The following items describe the development plan, not information collected by this homepage. Actual fields, necessity, collection methods and legal bases will be disclosed before the features launch. Processing will be limited to necessary data, with consent for optional processing where required.
- Google account identifier and email: sign-in, account identification and entitlement recovery. The planned flow does not require submitting a Google password to Windolet.
- Purchase and license records: transaction reference, product, payment status, entitlement and key activation status. The planned website does not collect the full card number entered at Paddle checkout.
- Connection records: invite code, the two accounts that accepted the connection and connection status. This may include recipient and delivery status needed for messages or files.
- Messages and files the user chooses to send: content needed for delivery to the recipient. Server routing, offline retention and encryption arrangements are not yet finalized.
3. External services and overseas processing
The support address uses Google’s Gmail. The sender’s email address and message are transmitted and stored through Gmail to review and reply to inquiries. Specific retention and deletion rules for inquiry records will be added once confirmed.
Cloudflare is the selected website host, and GitHub is the destination for release-download links. Google sign-in and Paddle purchases are planned for launch. When you visit an external site, its own privacy policy also applies. These providers are not all automatically classified as Windolet’s processors.
Depending on the service design, personal information may be processed outside the Republic of Korea. Recipients, countries, purposes, fields, timing, methods, retention, legal basis and refusal options and consequences will be disclosed after the actual contracts and data flows are confirmed. Required overseas-transfer procedures must be in place before that processing starts.
4. Retention and deletion
Retention periods for accounts, access logs, licenses, messages, files and support records are not yet final. The planned approach is deletion or anonymization when a purpose ends, with separately disclosed grounds, periods and restricted use for records that must legally be kept.
Before launch, deletion procedures will distinguish server records, device-local data and backups. Files or messages independently saved by a recipient may be outside Windolet’s ability to recall or delete. Instant complete deletion or undefined indefinite storage is not promised.
5. Your rights and requests
Depending on applicable law, you may request access, correction, deletion, restriction of processing or withdrawal of consent. Identity checks will be limited to what is necessary for the request. If a legal reason prevents compliance, the reason and available ways to challenge it will be explained.
Send privacy requests to the contact email at the top of this document. The legal identity of the privacy contact will be finalized before sales. There is no separate website request form. Email inquiries involve processing the sender’s email address and message so a reply can be provided.
6. Safeguards and minors
Necessary safeguards such as access restrictions, protection of credentials and secure transport will be designed into the service. Server, logging and encryption arrangements are not yet verified, so end-to-end encryption or absolute operator inability to access content is not claimed.
Age eligibility and procedures for required parental consent will be finalized before launch. Features collecting a child’s personal information should not be offered until the procedures required by applicable law, including legal-guardian consent where needed, are in place.
7. Policy updates
Once the actual features and providers are confirmed, the policy will specify data fields, legal bases, retention, overseas transfers and an effective date. Material changes will be announced through the website or another accessible channel, with new consent where required.