Privacy Policy

Medifact values your personal data and is committed to protecting it securely.

Effective Date: July 3, 2026

Medifact (hereinafter referred to as the "Operator") values the personal information of users (hereinafter referred to as "Members" or "Guests") in operating 'Medifact' (hereinafter referred to as the "Service"), an AI-powered medical fact-checking and academic literature cross-reference verification web platform, and complies with relevant laws including the "Personal Information Protection Act".

This Privacy Policy is designed to inform you of how the Operator collects, uses, provides, and destroys users' personal data, and what measures are taken to protect their rights.

01. Purpose of Processing Personal Data

The Operator processes personal data for the following purposes. The processed personal data will not be used for purposes other than the following, and if there are any changes, necessary measures such as obtaining prior consent will be implemented.

  • Member Registration and Management: Confirmation of intent to sign up, user identification and authentication, qualification maintenance and management, prevention of unauthorized use, and various notices.
  • Service Provision and Settlement: AI-powered medical fact-checking, provision of cross-referenced paper verification reports, storage and management of personal verification history, credit recharge, and transaction processing.
  • Service Improvement: Development of new features, customized information provision, and analysis of usage statistics and access logs to enhance system performance.

02. Items and Methods of Collection

A. Items of Personal Data Collected

  • Registration: Email address, password (Required)
  • Payment: Credit card info, PayPal account details, and unique transaction identifiers.
  • Usage: Text inputs or URLs requested for fact-checking, generated AI analysis results, credit usage history.
  • Automated: Service usage history, access logs, cookies, connection IP, and device info (OS version, browser type, etc.).

B. Methods of Collection

Direct entry through the website (registration and payment checkout), inputting claims into the fact-checking engine, and automatic generation via server log systems.

03. Retention and Use Period of Personal Data

The Operator processes and retains personal data within the period agreed upon at the time of collection or specified under relevant laws.

  • Registration & Account Management Until account withdrawal
  • Records on Payment and Billing Email (buyer_email) 5 years (Electronic Commerce Act, Framework Act on National Taxes)
  • Hashed Email (SHA-256) for Preventing Re-registration Abuse 30 days (Preventing abuse)
  • Records on Consumer Complaints/Disputes 3 years (Act on Consumer Protection in Electronic Commerce)
  • Website Visit and Access Logs 3 months (Protection of Communications Secrets Act)

04. External AI Infrastructure Transmission & Safety

Medifact utilizes the **Medifact AI Engine (integrated with enterprise cloud infrastructure APIs)** for real-time medical claim fact-checking and natural language processing.

  • Source Data Isolation: The text or URL content requested for fact-checking is sent to external AI infrastructure servers for analysis. No Personally Identifiable Information (PII), such as email, name, or ID, is included in this payload.
  • Enterprise Data Security: In accordance with enterprise cloud API standards (Google Cloud, etc.), transmitted data is securely protected and never utilized for training public third-party models.

05. Delegation of Personal Data Processing

The Operator delegates personal data processing as follows to ensure smooth operations:

Delegatee Delegated Work Delegation Period
Google LLC (Google Cloud) Hosting infrastructure and NLP analysis API integration for Medifact AI Engine, GCS database backup storage Until membership withdrawal or termination of delegation contract
PayPal Payment gateway processing and transaction security management

06. Rights and Obligations of Users

Users can exercise their rights as personal information subjects at any time:

  • Users may request access to, correction of, deletion of, or suspension of processing for their personal information.
  • These requests can be made via email or support channels, and the Operator will process them without delay.
  • If a correction or deletion of errors is requested, the Operator will not use or provide the target personal information until the request is fulfilled.

07. Destruction of Personal Data

The Operator destroys personal information without delay once the retention period expires or the purpose of processing is achieved.

  • Procedure: Personally identifiable information (name, email, specialty) is permanently deleted or anonymized upon withdrawal. However, billing emails are archived separately for financial audits, and a one-way SHA-256 hash of the email address is stored for 30 days in isolation to prevent re-registration abuse before permanent destruction.
  • Method: Electronic files are permanently deleted to prevent recovery, and paper documents are shredded.

08. Security Measures

The Operator implements the following measures to secure personal information:

  • Administrative: Formulating internal management plans, minimizing authorized personnel, and conducting regular security training.
  • Technical: One-way encryption for passwords, secure encryption for API Keys, and transmission encryption (HTTPS/SSL).
  • Physical: Controlling physical access to hosting infrastructure and backup storage.

09. Privacy Officers

The Operator has designated a privacy officer to protect personal data and handle complaints:

Privacy Officer Hyosung Choi (Privacy Manager)
Support Email contact@medifact.today

10. Amendments

This Privacy Policy is effective from the date of implementation. In case of any modifications, the Operator will notify users through notices 7 days before the implementation of the changes.