Privacy Policy
Educational Space Inc. (주식회사 교육공간, Business Registration No. 405-88-03364, “we”, “our”, or “us”) operates the SolBridge (쏠브릿지) service. This Privacy Policy is established and disclosed under Article 30 of the Personal Information Protection Act of the Republic of Korea to protect the personal information of data subjects and to handle related grievances promptly.
Article 1. Purposes of Processing
| Category | Purpose |
|---|---|
| Account management | Verifying sign-up intent, identification and authentication, maintaining membership, preventing misuse |
| Learning services | Distributing assignments and assessments, collecting smart-pen handwritten answers, AI automatic grading, providing results and explanations |
| Learning diagnostics | Diagnosing weak concepts from incorrect answers, recommending concept cards and similar problems |
| School operations support | Class organization, teacher–student assignment, achievement statistics |
| Notices | Announcements, assignment deadline notifications (push) |
We do not use personal information for purposes other than those stated above. If the purpose changes, we will take necessary measures such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
Article 2. Items Processed and Retention Periods
1. Account information
| Type | Items | Collection method | Retention period |
|---|---|---|---|
| Required | Email or user ID, password (stored encrypted), name, role (student / teacher / administrator) | Entered at sign-up, or issued by a teacher of the affiliated institution | Until account withdrawal |
| Optional | Gender, date of birth, mobile number, profile image | Entered at sign-up or profile update | Until withdrawal or user deletion |
| Optional | School name, school level, grade | Same as above | Same as above |
| Optional | Guardian contact number | Same as above | Same as above |
Optional items may be left blank without any restriction on service use.
2. Learning data
| Items | Collection method | Retention period |
|---|---|---|
| Smart-pen handwritten answers (images, stroke coordinates) | Collected automatically via smart-pen connection | For the period the affiliated institution manages learning records |
| Grading results, scores, error analysis, teacher feedback | Generated during service use | Same as above |
| Submission history, learning progress records | Generated automatically | Same as above |
Learning data may be retained after withdrawal so that the affiliated institution can manage learning records. If a data subject requests destruction, we destroy it without delay under Article 8.
3. Automatically collected information
| Items | Retention period |
|---|---|
| Access logs, IP address, device information, service usage records | 3 months |
| Failed login count and account lock time (unauthorized access prevention) | Reset when the lock is released |
| Push notification token | Until the app is deleted or notifications are declined |
| Error diagnostic data (error message, screen path, device and browser information) | 1 year |
4. Retention required by law
| Items | Legal basis | Period |
|---|---|---|
| Access records | Protection of Communications Secrets Act | 3 months |
| Records of consumer complaints and dispute resolution | E-Commerce Act | 3 years |
We do not currently offer paid services and therefore do not collect payment information.
Article 3. Personal Information of Children Under 14
We do not accept sign-ups from children under the age of 14.
Even where a teacher of an affiliated institution issues student accounts, we provide the service only to students aged 14 or older, and the institution verifies this when issuing accounts.
If we become aware that personal information of a child under 14 has been collected, we destroy it without delay.
Article 4. Provision to Third Parties
We process personal information only within the scope of the purposes stated in Article 1, and provide it to third parties only where Articles 17 and 18 of the Personal Information Protection Act apply, such as with the data subject’s consent or under specific provisions of law.
| Recipient | Purpose | Items | Period |
|---|---|---|---|
| Teachers and administrators of the educational institution the user belongs to | Learning guidance, assignment management, achievement review | Name, grade, submission history, handwritten answers, grading results | Until the affiliation ends |
We do not provide personal information to any other third party.
Article 5. Outsourcing of Processing
| Processor | Outsourced work | Retention period |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (servers, database, file storage), authentication email delivery | Until the contract ends or the account is withdrawn |
| Vercel Inc. | Web service hosting | Same as above |
| Google LLC | Push notifications (FCM), social login | Same as above |
| Apple Inc. | Social login (Sign in with Apple) | Same as above |
| Anthropic PBC | AI automatic grading and error analysis | Same as above |
| Functional Software, Inc. (Sentry) | Service error diagnostics and stability monitoring | Same as above |
When entering into outsourcing agreements, we stipulate responsibilities including compliance with personal information protection instructions, restrictions on sub-processing, technical and managerial safeguards, and liability for damages, and we supervise the processors’ compliance.
Article 6. Cross-Border Transfer of Personal Information
Under Article 28-8 of the Personal Information Protection Act, we transfer personal information overseas as follows.
| Recipient | Country | Time and method | Items | Purpose | Retention period |
|---|---|---|---|---|---|
| Anthropic PBC | United States | TLS-encrypted transmission at grading request | Student handwritten answer images, recognized answer text | AI automatic grading and error analysis | Limited to the time of AI inference |
| Google LLC | United States | TLS-encrypted transmission during service use | Push notification token, social login identifier | Notification delivery, login authentication | Until the contract ends |
| Apple Inc. | United States | TLS-encrypted transmission at login | Social login identifier | Login authentication | Same as above |
| Functional Software, Inc. (Sentry) | United States | TLS-encrypted transmission when an error occurs | Error message, screen path, device and browser information | Service error diagnostics | 1 year |
| Vercel Inc. | United States | TLS-encrypted transmission on web access | Access logs, IP address | Web service hosting | Until the contract ends |
Data subjects may refuse the cross-border transfer of their personal information. To do so, please contact us using the details in Article 10 and we will act without delay. Note that AI automatic grading requires cross-border transfer, so refusing may restrict the use of that feature.
Account information, original handwritten answers, and grading results are stored in the Republic of Korea (AWS Seoul region). The transfers above occur only at the time of each processing operation. We also use an overseas provider to generate search indexes for problem, solution, and concept text; that data contains no personal information.
Article 7. Destruction of Personal Information
We destroy personal information without delay (within 5 days of the triggering event) once the retention period has elapsed or the processing purpose has been achieved.
- Procedure — We identify the personal information subject to destruction and destroy it with the approval of the Data Protection Officer.
- Method — Electronic files are permanently deleted so that they cannot be recovered or reproduced; printed materials are shredded or incinerated.
- Where retention is required by law — Such information is stored in a separate database and destroyed after the statutory period.
Article 8. Rights of Data Subjects and How to Exercise Them
Data subjects may exercise the following rights at any time.
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
- Request data portability
Access and correction can be performed directly under Profile → Account settings in the app or on the web. Other rights may be exercised by email or in writing to the Data Protection Officer in Article 10. We take action within 10 days of receiving a request and notify you of the result. Where a correction is requested, we do not use or provide the relevant personal information until the correction is complete. Rights may be exercised through a legal representative or an authorized agent.
Account Deletion
You may delete your account at any time in either of the following ways.
- In the app or on the web: Profile → Delete Account
- By email: send a deletion request from your registered email address to privacy@esamath.org
Deleting your account removes your account and profile information. Assignments, handwritten answers, and grading results you have already submitted may be retained so that your affiliated institution can manage learning records; if you also want these destroyed, please state so in your deletion request and we will destroy them without delay. Records we are legally required to keep are retained only for the statutory period and then destroyed.
Article 9. Security Measures
Managerial measures
- Minimizing the number of personnel who handle personal information and granting differentiated access rights
- Designating a Data Protection Officer and establishing an internal management plan
Technical measures
- One-way encrypted storage of passwords
- Encryption in transit (HTTPS/TLS)
- Login attempt limits — temporary account lock after consecutive failures
- Access control and permission management for databases and file storage
- Authentication and access restriction for administrative systems
- Retention of access records and prevention of forgery or alteration
Physical measures
- Compliance with the physical security controls of our cloud providers’ data centers
We do not currently hold ISMS-P or CSAP certification.
Article 10. Data Protection Officer
We have designated a Data Protection Officer who is responsible for overseeing personal information processing and for handling complaints and remedies related to that processing.
| Role | Details |
|---|---|
| Data Protection Officer | Lee Jihoon / Head of Development |
| Contact | privacy@esamath.org / +82-62-575-6637 |
Data subjects may direct any inquiries, complaints, or requests for remedy relating to personal information protection to the contact above, and we will respond without delay.
Article 11. Remedies for Infringement of Rights
Data subjects may apply for dispute resolution or consultation with the following bodies to obtain remedies for personal information infringement.
| Organization | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | +82-1833-6972 | www.kopico.go.kr |
| Privacy Infringement Report Center | +82-118 | privacy.kisa.or.kr |
| Supreme Prosecutors' Office | +82-1301 | www.spo.go.kr |
| National Police Agency | +82-182 | ecrm.police.go.kr |
Article 12. Changes to This Policy
This Privacy Policy is effective as of July 26, 2026. If content is added, deleted, or modified due to changes in law, policy, or security technology, we will announce the changes on this page before they take effect.
Previous policy in effect: July 11, 2026 – July 25, 2026
Content Policy
This Content Policy describes what content is allowed in the SolBridge (쏠브릿지) app and the standards users must follow.
1. Allowed Content
Users may post and share educational content such as assignments, feedback, class discussions, and school-related materials.
2. Prohibited Content
- Harassment, bullying, hate speech, or threats.
- Sexually explicit, violent, or otherwise harmful material.
- Spam, scams, or misleading information.
- Content that infringes intellectual property rights.
- Any illegal content or activity.
3. Reporting and Enforcement
We may review, remove, or restrict content that violates this policy. Accounts may be suspended or terminated for repeated or severe violations.
4. User Responsibility
Users are responsible for the content they submit. By using the app, users agree that their content must follow applicable laws, school rules, and this policy.
5. Contact
To report policy violations, contact privacy@esamath.org