Skip to content

Privacy

Execemy Privacy Policy

Version: 2026-10-02.1
Effective date: 2026-10-02

1. Operator, scope and contact

Execemy is operated by The Plain Works Co.,Ltd. (주식회사 더 플레인웍스). Business registration: 293-87-03653. Representative: JINYONG KIM.

Postal contact for support, corrections and privacy requests: 901-C32 126, Wolbong-ro, Seobuk-gu, Cheonan-si, Chungcheongnam-do, Republic of Korea (31166). Korean address: 충청남도 천안시 서북구 월봉로 126, 901-씨32호(쌍용동). Mark privacy requests “Execemy — Privacy request.” Electronic support is available through the support page.

This policy covers the hosted publication, reader, search, newsletter, optional account/save functions and communications we operate. It also explains handling of identifiable information in source research and contributions. Independent websites linked from a Breakdown have their own privacy practices.

We determine the purposes of our publication, audience and administration processing. Reading an article does not appoint us to process your organization's data as a contracted business processor.

2. Information and purposes

Information and sourcePurpose
Account email and Supabase authentication identifier; saved items and reading progress/completion when an account feature is usedCreate and secure the account; sync saved items and reading place across devices; let the reader delete those records or the account
Newsletter email address, selected topic/source, consent and consent time, and pending/confirmed/unsubscribed statusSend only the opted-in publication updates, confirm the address, and honor unsubscribe choices
Necessary request and security information handled by the hosted web application and Supabase AuthServe requests, authenticate sessions, protect the service and diagnose failures
Allowlisted readership events only after explicit analytics consentUnderstand aggregate use of content and improve the reader experience
Messages, corrections, rights reports and attachments you choose to send through a contact channel the controller providesRespond to inquiries, evaluate corrections and resolve rights disputes; the web application does not collect or store support correspondence
Identifiable professional information in public or permissioned source materialResearch and publish relevant, sourced business explanations, with applicable rights and privacy safeguards
Contact, invoice and permission records for an actually agreed commercial relationshipAdminister the specific license or project, payments and required records

Required fields are identified at collection. Ordinary public reading does not require submitting a resume, employer evaluation, precise location, government identifier or sensitive health information. Do not send passwords or confidential third-party documents in a correction request.

Research about a business is not automatically nonpersonal merely because a person's role is professional. Publicly available information remains subject to applicable law. We do not enroll people mentioned in a source into our marketing list.

3. Legal bases and sensitive information

We use information for the requested publication feature, lawful administration/security, responding to inquiries and meeting legal requirements. Where consent is required, we obtain it separately for the relevant purpose. Where another basis is available, including a permitted, appropriately assessed legitimate interest or contract performance, we apply it only within its conditions.

Newsletter consent, optional tracking, permission to publish a contribution and permission to contact you about other products are distinct choices. An optional saved topic does not authorize an employment, financial eligibility or sensitive-personality assessment.

We may use genuinely anonymous audience statistics to improve and operate the publication. A hashed email or stable reader identifier remains personal or pseudonymous information where it can be connected to someone; it is not made anonymous by a label.

4. AI, personalization and content visibility

Public facts and source materials are assessed for relevance, rights and privacy. We do not publish private contact details merely because they appear in a source. A person mentioned in a Breakdown may contact us about inaccurate or unlawfully disclosed personal information; we consider the applicable publication, archival and privacy rights rather than promise automatic removal of every public-interest reference.

Private correction messages are used to assess the issue. We do not publish your full message, contact details or attachments without an appropriate basis and, where needed, permission. If you choose to contribute material for publication, we explain the selected attribution and publication scope. Search engines and third parties may copy publicly published material; deletion of our copy cannot guarantee removal everywhere.

5. Providers, disclosures and international transfers

We may use providers for site delivery, authentication if offered, email delivery, support, analytics and editorial production. Providers receive only the categories required for their actual role. Reader emails and private submissions are not automatically inputs to editorial AI tools.

Recipient legal entity and contactFunction and roleInformation and processing country/countriesTransfer timing/method and applicable basisRetention, access and any AI use
Supabase (project region: us-east-1; Auth and PostgreSQL)Authentication, account data, saved items, reading progress, newsletter records and consent choiceAccount email and identifier, saved items, reading progress, newsletter status and authentication dataHosted Supabase project in the United States; requests are sent by the hosted applicationSupabase retention and backup controls apply; account deletion and unsubscribe actions described below remove the applicable application records
VercelHosting and delivery of the Next.js application and server requestsRequest metadata and the data needed to serve the requested page or operationHosted application and infrastructure processing; processing locations follow the provider service termsVercel infrastructure retention and account controls apply
ResendDelivery of newsletter confirmation and related opt-in emailRecipient email address and confirmation or unsubscribe linksEmail delivery from the verified `mail.execemy.com` sending domainResend delivery and account retention controls apply; no open or click tracking is configured by this application
PostHogOptional product analytics, performance measurements, exception capture and masked session replay, only after analytics consentAllowlisted content IDs, page paths and UTM values, activation/signup/newsletter events, web vitals and replay data with text and inputs maskedPostHog US Cloud (`us.i.posthog.com` and `us-assets.i.posthog.com`) through the same-origin `/ingest` proxyPostHog project retention controls apply; telemetry is disabled if the project key is not configured

We distinguish providers acting on our instructions from independent recipients. We require appropriate protections for entrusted processing. A commercial partner does not receive the newsletter subscriber list just because it sponsors or licenses content.

Supabase is configured in us-east-1. Vercel, Resend and PostHog may process data in the United States or other locations described in their current service terms. International processing is subject to the providers’ contractual safeguards and applicable rights.

We may disclose proportionate information to confidential professional advisers, for valid legal process, to protect rights or safety where lawful, or in protected due diligence and a genuine business transfer. Required notices and privacy choices continue to apply.

The application does not configure a sale, sharing or targeted-advertising recipient. Optional consented analytics are sent through the same-origin PostHog proxy. DNT and Global Privacy Control keep optional analytics off. PostHog is not initialized when `NEXT_PUBLIC_POSTHOG_KEY` is unset.

6. Cookies, analytics and communications

Newsletter signup describes the messages requested. Each newsletter email includes an unsubscribe link. Account deletion removes newsletter rows for the account email, including separately consented subscriptions. While an account exists, use a message's unsubscribe link or the subscription control on `/en/account` to stop pending or confirmed updates. No marketing mail is sent before address confirmation. Authentication verification and password-reset email are service messages initiated by the reader.

We use necessary storage for functions such as security, consent choices and optional account sessions. Optional analytics, embedded content and email measurement follow the practices below and applicable consent or opt-out requirements.

The app sets Supabase Auth session cookies for a signed-in session, and the `execemy_analytics_consent` cookie when a choice is saved (HTTP-only, SameSite=Lax, path `/`; no explicit max-age is set). Client code may also set `execemy.analytics-consent` in local storage and `execemy.analytics-session-authorized` in session storage to gate optional events. The reader stores a local reading-position copy and a one-time reader hint in local storage. These are not advertising cookies. Browser session and local-storage expiry/removal is controlled by the browser unless the user clears it earlier. Optional consent can be changed using the Analytics: on/off control in the site footer; the first-visit banner also offers “No thanks” and “Allow analytics.”

When the reader selects “Allow analytics,” allowlisted events (including page views, content views, activation and reader interactions) may be sent to PostHog. Event properties exclude raw email addresses. Session replay masks page text and form inputs. Telemetry removes query strings and URL fragments, and redacts email addresses and credentials from captured errors. Analytics are otherwise off, including when Do Not Track or Global Privacy Control is signaled. No email open pixels or link tracking are configured.

Manage analytics choices using the Analytics control in the site footer or the first-visit banner. Clear the `execemy_analytics_consent` cookie and `execemy.analytics-consent` local-storage item in browser settings to remove the stored choice. Global Privacy Control keeps optional analytics off. A refusal does not prevent ordinary public reading.

7. Retention and deletion

CategoryRetention
Newsletter detailsUntil the reader unsubscribes or deletes the subscription. Pending confirmation links expire after 24 hours; the pending record can be removed by a new signup or unsubscribe. No inactive-subscriber cleanup job is configured.
Account, saved items, reading progress and completionUntil the reader deletes those records or deletes the account. Account deletion immediately removes the Supabase Auth user and associated saved and reading records.
Security and diagnosticsNo product-level security-log retention period is configured. Infrastructure logging follows the applicable Vercel and Supabase service settings.
Optional analyticsPostHog retention controls apply; no email-interaction data is collected.
Support, corrections, permissions and rights reportsNo in-product support inbox or retention job is implemented. Information sent through a contact channel must be managed by the controller under the launch retention policy.
Research/source records containing personal informationEditorial source records are not managed by the reader account database; source records are retained while required to support the published explanation and correction history.
Residual backupsApplication code does not set a separate backup expiry schedule. Supabase backup availability and expiry follow the selected project plan and provider settings; the controller must verify those settings.
Suppression recordsMinimal information while necessary to honor the opt-out and applicable duties

We delete or irreversibly de-identify data when no longer needed, unless a specific legal obligation or properly limited dispute/security basis supports retention. We restrict retained records to that purpose. A desire to keep a public archive does not justify keeping every private reader message forever.

For an actual transaction covered by Korean e-commerce record rules, the necessary subset is retained for six months for advertising, five years for contracts/withdrawals and payment/supply, and three years for consumer complaints/disputes. These periods do not authorize retention of unrelated reader activity. Electronic deletion uses suitable irreversible methods; physical records, if any, are securely destroyed. Restored backups remain subject to prior deletion and opt-out controls.

8. Privacy rights and requests

Depending on applicable law, you may request access, correction, deletion, portability, restriction, an applicable objection or opt-out, withdrawal of consent or information about disclosures. To delete saved items or reading history, sign in at `/en/account` and choose Delete my reading data. To delete the account, sign in at `/en/account`, choose Delete account, type `DELETE`, and confirm; this removes the authentication user, saved and reading records, and newsletter rows for the account email. To unsubscribe while keeping the account, use a message's unsubscribe link or the account subscription control. To change analytics consent, use the Analytics control in the footer. Other rights requests and appeals may be mailed to the operator’s postal contact, listed in section 1.

We verify identity and authority proportionately, respond within applicable deadlines and explain any legal limitation, denial or permitted extension. We do not require unrelated identity documents for a routine unsubscribe. Agents and lawful representatives may act with appropriate authority. Ordinary rights requests are free, subject only to exceptions allowed by law and disclosed in advance.

You may also seek relief through the Korean Personal Information Protection Commission or the competent authority in your jurisdiction. Exercising a privacy right does not reduce an unrelated right to read a public Breakdown.

Where applicable law provides rights concerning a decision made solely through automated processing that significantly affects you, you may request the required explanation, review or other safeguard through the privacy contact. Ordinary content relevance or a fictional response is not, merely by that label, an official employment, credit, medical or similar determination.

9. Security and incident handling

We maintain safeguards appropriate to the information and applicable law, limit access for authorized purposes and fulfill applicable incident duties. This is not a promise of perfect security, a specific certification or a fixed human response time.

We act on personal-information incidents and provide notices and reports when required by applicable law. Actual breaches, legally defined possible-breach circumstances and regulatory reporting triggers are assessed separately. A suspected incident is not ignored solely because a complete forensic conclusion is unavailable; an unsuccessful blocked attempt is not automatically a reportable breach.

10. Eligibility, changes and contact

Children, security and updates

The code does not implement an age gate or guardian-consent flow. Account and newsletter features are intended for readers aged 14 and older. The hosted application does not intentionally operate a child-directed profiling or marketing service.

We update this policy when practices change and provide the notice or obtain consent required for a material change. An updated policy does not retroactively authorize an unrelated use of information. Contact the controller through the contact in section 1.

Previously collected information and provider changes

A change in this notice or in a provider list does not, by itself, authorize a materially different use of information already collected. We obtain any necessary new permission or establish another applicable legal basis before that use. Where an earlier binding privacy or retention commitment is more protective, we comply with it or complete a lawful change process before using a conflicting route. We do not copy private content across products solely because they share an operator.

Information about newly enabled features is supplied before their collection or use. A listed possible feature is not authority to collect every category from every visitor. Any legally required local-language notice and mandatory rights prevail over a translation inconsistency.