Privacy Policy

Effective date: June 24, 2026

This English version is provided for reference only. In the event of any conflict, the Korean version (개인정보처리방침) prevails.

Foundry ("we", "the Company", or "the Service") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act ("PIPA") of the Republic of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly. This policy applies to openfoundry.co and related services we provide.


1. General Provisions

  • Controller: PoSTMEDIA Co., Ltd. (Representative: Seungmo Hong, Business registration no.: 120-81-27660, Address: 174-10 Jagok-ro, Gangnam-gu, Seoul, Republic of Korea)
  • Service: openfoundry.co — a platform for storing and collaborating on AI models, datasets and spaces, synthetic data generation (Data Forge), and GPU computing (Reactors).
  • We comply with PIPA and related laws to protect data subjects' rights and freedoms.

2. Personal Information We Collect

1. Account registration (entered by the user)

  • Required: email address, username, name, password
    • Passwords are stored one-way encrypted (bcrypt hash); we cannot recover the plaintext.
  • Optional (if set by the user): two-factor authentication (2FA) secret, external integration tokens (HuggingFace token, Data Forge API key)
    • These optional items are stored encrypted (AES-256-GCM).

2. Sales/onboarding inquiry (when using the inquiry form)

  • Name, organization, email address, role, inquiry content

3. Information generated/collected automatically during use

  • Download statistics: a one-way hash (SHA-256) of the access IP address (the raw IP is not stored)
  • Usage analytics: a cookieless anonymous identifier (a hash of access IP + browser info + salt that is rotated and discarded daily; raw IP/browser info is not stored)
  • Access/usage logs: emails, IPs, and user identifiers are masked in logs.

We do not collect sensitive information (race, beliefs, political views, health, sex life) or unique identifiers (e.g., resident registration numbers).

3. Purposes of Collection and Use

  • Member identification, authentication, and account management
  • Service provision: model/dataset/space storage and collaboration, synthetic data generation, GPU computing, notifications
  • Service security, prevention of fraud/abuse, access control
  • Responding to onboarding inquiries
  • Statistical analysis for service improvement (anonymous/statistical purposes)

We do not use personal information for purposes other than those above; if purposes change, we obtain separate consent and take necessary measures.

4. Retention and Use Period

In principle, personal information is destroyed without delay once the purpose of collection and use is achieved. However, the following is retained for the stated periods.

ItemRetention period
Member account informationUntil membership withdrawal (destroyed immediately upon withdrawal)
Password reset token30 minutes after issuance
Email verification token24 hours after issuance
Organization invitation30 days after issuance
Inquiry information1 year after handling (or 1 year from receipt)
Download statistics (hashed IP)Retained for statistical purposes

Where retention is required by law, we may retain information for the period prescribed by such law.

5. Destruction Procedure and Method

  • Procedure: When a user requests withdrawal or the retention period elapses, we destroy the relevant personal information without delay.
  • Method: Electronic files are permanently deleted so they cannot be recovered. Upon withdrawal, the member's database records, the storage objects (models/datasets/spaces) uploaded by the user, and identifiers (slugs) are deleted together via cascade. Inquiry information is automatically deleted by a scheduled job once the retention period (1 year) elapses.

6. Consignment of Processing

We consign personal information processing as follows to provide our services smoothly. Consignment contracts stipulate the measures required under PIPA Article 26.

ConsigneeConsigned work
Google LLC (Gmail SMTP)Sending emails (signup verification, password reset, notifications, inquiry replies, etc.)
Wasabi Technologies / Amazon Web Services (S3-compatible storage)Storing uploaded files, avatars, and other content
Upstash, Inc.Rate limiting

If the operator uses its own infrastructure (self-hosted SMTP/MinIO/Redis), the above consignees do not apply; update this section to reflect the actual configuration.

Separately, importing models/datasets from huggingface.co communicates with that external service only when the user explicitly requests it.

7. Overseas Transfer of Personal Information

We may transfer personal information overseas (as consignment) as follows.

TransfereeCountryItemsTime & methodPurposeRetention period
Wasabi/AWS S3 (object storage)Japan (ap-northeast-3, Osaka region)Uploaded files, avatars, etc.Network transmission during useContent storageUntil withdrawal/deletion
Google LLC (Gmail SMTP)USARecipient email address, email bodyNetwork transmission when sendingEmail deliveryUntil sending is processed
Upstash, Inc.USAHashed identifiers/request countersNetwork transmission during processingRate limitingUntil processing

Data subjects may refuse the overseas transfer of personal information; some services may be restricted upon refusal. Refusals or inquiries may be requested via the method in Section 8.

8. Rights of Data Subjects and How to Exercise Them

Data subjects may exercise the following rights at any time:

  1. Request to access personal information
  2. Request to correct errors
  3. Request to delete
  4. Request to suspend processing
  • Access/correction: View and edit directly under Settings > Profile.
  • Deletion (withdrawal): Withdraw (delete all data) directly under Settings > Account.
  • Other requests: Request via the contact in Section 10 or the inquiry form; we will act without delay.

9. Cookies

We use the minimum cookies necessary to provide the Service.

CookiePurposeCategory
csrf_tokenPrevent forged requests (CSRF)Essential
Auth tokens (access/refresh)Maintain login sessionEssential
NEXT_LOCALEStore language preferenceFunctional
  • We do not use tracking cookies for advertising/behavioral information.
  • Usage analytics is performed cookielessly and anonymously (Section 2.3).
  • You may refuse cookies via browser settings, but some services such as login may be restricted.

10. Privacy Officer

Data subjects may direct all privacy-related inquiries to the contact above; we will respond and act without delay.

11. Remedies for Infringement

You may apply for dispute resolution or counseling to the following bodies:

  • Personal Information Dispute Mediation Committee: 1833-6972 (privacy.go.kr)
  • Privacy Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)

12. Changes to This Policy

This policy applies from the effective date. If there are additions, deletions, or modifications due to changes in law or the service, we will notify the changes via in-service announcement at least 7 days before they take effect (30 days for material changes disadvantageous to users).

  • Effective date: June 24, 2026
  • (Revision history: none — initial version)