/개인정보

거의 아무것도 몰라요.
일부러요.

Spookat이 아는 건 방문자가 직접 입력한 것뿐이에요. 쿠키 배너에 추가할 것도, 공개해야 할 추적도, 팔 것도 없어요. 무슨 일이 일어나는지 단계별로 정확히 설명할게요.

방문자의 하루, 로그로 보기.

  1. 페이지 로드0저희 API 요청 수. cdn.spookat.com의 정적 런처 파일 하나 말고는 없어요.
  2. 스크롤, 읽기, 이탈0왔었는지도 몰라요. 픽셀도, 비컨도 없어요.
  3. 런처 클릭1채팅을 불러오는 요청. 아직 아무것도 저장 안 해요.
  4. 메시지 전송✉이제 저장해요. 팀이 답할 수 있도록요.
  5. 보관 기간 만료∅Spookat에서 자동으로 사라져요. 플랜별 30/90/365일. 그로부터 30일 후 백업에서도 사라져요.

저장하는 것

  • 메시지. 팀이 읽고 답할 수 있도록
  • 이름이나 이메일. 방문자가 입력했을 때만
  • 채팅이 온 사이트, 그리고 보낸 순간의 페이지, 브라우저, 국가
  • 타임스탬프, 그리고 답한 팀원
  • cool guy 플랜: 앱에서 넘겨준 로그인 사용자 ID

절대 건드리지 않는 것

  • 쿠키와 핑거프린팅. 브라우저 저장소에는 채팅 토큰 하나만, 그것도 메시지를 쓴 뒤에만 저장해요
  • 방문 기록, 세션, 채팅 전의 행동
  • IP 주소. 전달과 요청 제한에 쓰지만, 절대 기록하지 않아요
  • 분석, 히트맵, 세션 리플레이
  • 광고, 데이터 판매, 채팅으로 AI 학습

spookat.com은 셀프 호스팅 Umami를 써요. 쿠키 없음, 원본 IP 저장 안 함. 사이트에 설치된 위젯은 분석을 전혀 하지 않아요.

데이터가 가는 곳.
솔직하게.

메시지는 연결한 곳으로 가요. 거기 도착하면 저희 규칙이 아니라 그곳의 규칙이 적용돼요. 아닌 척하느니 솔직하게 말할게요.

봇은
명찰을 달아요.

AI 에이전트를 연결하면 방문자는 항상 알 수 있어요. 끌 수 있는 설정이 아니에요.

  1. 모든 AI 메시지에는 어떤 스타일에서든 AI 라벨이 붙어요.
  2. 에이전트는 사람 이름으로 글을 올릴 수 없어요. 저희 API가 거부해요.
  3. 팀은 모든 대화를 볼 수 있어요. 에이전트가 한 말도 전부요.
  4. 저희가 직접 대화에 AI를 돌리는 일은 없어요. 예외는 cool guy 플랜 이상의 선택 기능인 의도 태그뿐이에요.

내 데이터, 내 버튼.

아래 개인정보 처리방침은 영어로 작성되어 있으며, 영어 원문이 우선해요.

privacy policy

Draft, effective [EFFECTIVE DATE]. The plain-words version is everything above this line. This part says the same thing the way the law wants it said.

1. who we are

Spookat is run by [COMPANY NAME], a sole trader registered in Poland (jednoosobowa działalność gospodarcza), NIP [NIP], [ADDRESS] (“Spookat”, “we”). Write to us at hello@spookat.com. We have not appointed a data protection officer; we are not required to.

2. two roles

3. what we collect, why, and for how long

what why legal basis how long
visits to spookat.com, counted by our self-hosted Umami: page, referrer, browser, device type, country to see which pages work legitimate interest, Art. 6(1)(f) GDPR aggregated statistics, no profile of you
waitlist: your email and, if the link had one, the utm_source you came from to send you an invite consent, Art. 6(1)(a) until you sign up or ask us to delete it, and at most 12 months
account: email, name, and, if you sign in with GitHub, Google or Discord, your account id there and its sign-in tokens, encrypted to run your account contract, Art. 6(1)(b) while the account exists, then deleted within 30 days; backups age out 30 days after that
billing: plan, country, invoice data we get back from Paddle to know what you paid for and keep tax records contract and legal obligation, Art. 6(1)(b) and (c) as long as Polish tax and accounting law requires (generally 5 years after the end of the year)
support: what you send to hello@spookat.com to help you contract or legitimate interest as long as the conversation needs, and at most 24 months

Umami on spookat.com sets no cookies and stores no IP address. It counts visits with a salted hash that rotates, so it can’t recognise you over time. It runs on our own server under spookat.com/u/, so no third party sees your visit.

We use IP addresses only in memory, to deliver pages and to rate-limit abuse. We never write them to a database, a log or an error report. Cloudflare (below) carries all traffic to our sites, the widget’s included, as our network proxy and CDN, so it sees IP addresses in transit.

Card and payment details never reach us. Paddle (see below) sells the subscription as merchant of record and handles payment as an independent controller, under Paddle’s privacy policy.

4. who else gets data

We share data only with the services we need to run Spookat, each under a contract that binds them to protect it:

who what for where
Paddle.com Market Limited billing, merchant of record United Kingdom
Postmark (ActiveCampaign, LLC) transactional email: sign-in links, notices, reply follow-ups United States
Backblaze, Inc. encrypted backups EU region
[VPS PROVIDER] hosting [REGION], EU
Cloudflare, Inc. network proxy and CDN in front of our sites, IP addresses in transit United States, global network
OpenRouter, Inc. intent tags, only if a customer turns them on United States

Slack and Discord get chat messages only when a customer connects their own workspace or server to Spookat. That is the customer’s choice, and Slack’s or Discord’s terms and retention settings apply there.

Signing in with GitHub, Google or Discord is optional; an emailed link always works. If you choose one, that provider sends us your account email, whether it verified it, your name and your profile picture link, and sees that you signed in to Spookat. Its own privacy policy applies on its side. Discord is also the one a customer connects their server with, above.

Transfers outside the EEA rely on an adequacy decision (United Kingdom) or on the European Commission’s Standard Contractual Clauses (United States).

5. cookies

spookat.com sets no cookies. The Spookat widget sets no cookies either: after a visitor sends a first message, it keeps one chat token in that browser’s storage so the conversation survives a reload. The dashboard at app.spookat.com uses one strictly necessary cookie to keep you signed in.

6. your rights

You can ask us for access to your data, a copy of it (portability), to correct it, to delete it, to restrict or object to how we use it, and you can withdraw consent at any time without affecting what happened before. Write to hello@spookat.com; we answer within one month.

You can also complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

7. country lookup

We turn an IP address into a country with an offline database that runs on our own server. The IP address is never sent anywhere and never stored. IP to country data by DB-IP.com, licensed under CC BY 4.0.

8. changes

If this policy changes in a way that matters, we update this page and email customers before the change applies.

기본값은 조용함.

사전 신청