Zum Inhalt springen
GEHEIM // NUR FÜR DIENSTGEBRAUCH - SCP-STIFTUNG EINDÄMMUNGSNETZWERK - NUR AUTORISIERTES PERSONAL
SITE-19 — 격리 작전 단말요원 게스트 요원L0SPARK 0
← SCP-CHAT

PRIVACY · SINGAPORE PDPA

Datenschutzrichtlinie

Hyeonseok Oh (오현석) verarbeitet personenbezogene Daten für SCP-CHAT nach dem Personal Data Protection Act 2012 (PDPA) Singapurs. Primäre Anwendung und Datenbank laufen in Singapore (OVHcloud). Zur Leistungserbringung können Daten an Auftragsverarbeiter außerhalb Singapurs übermittelt werden.

Gültig ab · 2026-07-17

Rechtsverbindlich ist die englische Fassung; diese Seite wird auf Englisch bereitgestellt.

1. Controller and contact

Personal data controller: Hyeonseok Oh (오현석) (individual operator). Service domain: scpchat.space.

Public Data Protection Officer (DPO) contact: [email protected]. Use this address for access, correction, withdrawal of consent, deletion, overseas-transfer questions, and breach concerns. General support: [email protected].

The DPO contact is monitored during Singapore business hours. Written privacy requests are accepted by email.

2. Information we collect

  • Account: email, Google account identifiers (when OAuth is used), display handle, birth year, timestamps and policy versions for Terms and Privacy consent
  • Content: operation records (turns and resolutions), generated codex documents, reports, uploaded avatars and similar media
  • Service records: access times, IP, device/browser data, error and security logs, usage and plan status, product events (allowed keys only; content bodies excluded)
  • Billing-related: minimum identifiers needed for subscription status and entitlements. Card numbers and payment-instrument details are processed by the Merchant of Record payment partner and are not stored on our servers
  • Support: inquiry content and attachments needed to resolve issues

Passwords are stored as one-way hashes, not recoverable plaintext. We do not collect Google passwords. We do not intentionally collect high-risk identifiers such as national ID numbers, passport numbers, or full payment-card numbers.

3. Purposes and consent

We process personal data only as needed for the following purposes:

  • Account creation and authentication, session maintenance, and 18+ eligibility checks
  • Containment operations, operation and document storage, and related features
  • Safety-policy enforcement, abuse and fraud prevention, and security monitoring
  • Paid subscription entitlements and customer support
  • Service stability and quality improvement (including aggregated or de-identified analysis)
  • Legal obligations and dispute handling

At signup we collect separate consents for the Terms and this Privacy Policy. Refusing required processing may make account service unavailable. We do not currently send marketing emails by default; if introduced later, we will obtain separate consent.

Under PDPA, personal data is used and disclosed only for purposes a reasonable person would consider appropriate in the circumstances and within notified/consented purposes. We do not use user content for ad targeting or sell personal data. We do not use user content to train our own models (training).

4. Processing locations, processors, and overseas transfers

The primary application and operational database are stored and processed in OVHcloud’s Singapore region. To provide the service, some personal data may be transferred to or accessed by data intermediaries or independent controllers in countries or regions outside Singapore. Under the PDPA Transfer Limitation Obligation, we require contractual controls, access limits, minimum transfer, and reasonable safeguards comparable to PDPA protection.

Key overseas transfer and processing items:

  • OVHcloud (hosting & DB) — Data: accounts, content, logs. Country/region: Singapore. Purpose: hosting and storage. Retention: Section 5. Method: continuous encrypted storage and processing.
  • Moderation API providers (when configured) — Data: text under review. Country/region: provider operating region (e.g. United States). Purpose: safety classification. Retention: as needed for the check. Method: HTTPS API.
  • Google — Data: OAuth identifiers on login; usage measurement if a measurement ID is enabled. Country/region: United States and other Google infrastructure. Purpose: authentication and optional site measurement. Retention: Google policy and configuration. Method: OAuth/SDK.
  • Merchant of Record payment partner (Lemon Squeezy, Creem, or similar selected partner) — Data: email, subscription/transaction identifiers, minimum billing data. Country/region: partner operating regions (primarily United States / European Economic Area). Purpose: payment, tax, receipts, refunds. Retention: partner payment and tax retention periods. Method: checkout redirect and webhooks. Card data is handled directly by the partner.
  • Object storage (S3-compatible, when configured) — Data: uploaded file metadata and objects such as avatars. Country/region: configured region (e.g. ap-northeast-2). Purpose: media storage. Retention: until account/content deletion or replacement. Method: server-side API.
  • Email, security, and infrastructure helpers — Data: support mail, ops alerts, security signals. Country/region: each vendor’s operating region. Purpose: support delivery, availability, breach detection. Retention: as needed for those purposes and security.

From a user perspective (including users in Korea), primary account and operation-record storage is in Singapore, so using the service includes overseas storage and processing. Overseas transfers for hosting and processing are disclosed in this policy and covered by Privacy Policy consent at signup. If processors or transfer countries change materially, we update this page before the change takes effect.

5. Retention, destruction, and deletion

  • Accounts, operation records, documents, uploads: while the account is active or until the user deletes them
  • Security and access logs: generally within 90 days; longer only as needed for incident investigation or legal duty
  • Product events (excluding content bodies): raw events cleaned per ops policy after aggregation
  • Live data deletion: on confirmed delete requests we invalidate sessions and hide content immediately, then remove data from the account graph asynchronously
  • Encrypted backups: expire within 30 days under rotation
  • Payment records: retention follows the Merchant of Record and tax/accounting duties of the partner and applicable law

Destruction methods: database row deletion or irreversible de-identification, object-storage object deletion, and backup rotation expiry. Legal claims, fraud prevention, safety evidence, or statutory retention may place a limited legal hold; data is destroyed after the hold ends. Only de-identified safety evidence may remain under a configured retention policy.

6. Cookies and similar technologies

We may use cookies or similar technologies for login sessions, CSRF and same-origin protection, basic preferences, product analytics identifiers (when signed in), and optionally Google Analytics measurement. Essential cookies are required to run the service; optional measurement can be disabled via configuration. Browsers can reject cookies, but core features such as login may stop working.

7. Your rights

You may request access to personal data, correction of inaccurate data, withdraw consent, export account data, and deletion. Prefer the export/delete tools in account settings, or email the DPO.

Withdrawing consent does not affect the lawfulness of processing before withdrawal. Withdrawing required processing consent may end service. Under PDPA we respond to access and correction requests within a reasonable time, typically aiming to complete within 30 days after confirming the request. Identity checks use the minimum data needed.

Complaints about personal-data handling: [email protected]. If unresolved after internal review, you may contact the Singapore Personal Data Protection Commission (PDPC) or another competent authority.

8. Security and breach response

We use transport encryption (TLS), least privilege, secret separation, same-origin protections, rate limits, safety filters, and access logs. Processors are bound by purpose limits, protection, retention limits, and breach-notification duties.

If a personal-data breach occurs or is reasonably believed to have occurred, we assess it promptly. Under the PDPA Data Breach Notification Obligation, notifiable breaches are reported to the PDPC as soon as practicable and no later than 3 calendar days from the day we determine notification is required, and to affected users when needed. Assessments and actions are recorded.

9. Age eligibility and policy changes

SCP-CHAT is for users aged 18 and over. We do not intentionally collect accounts from minors. If minor data is confirmed, we restrict and delete the account.

Material changes (purposes, overseas processors/countries, retention, how to exercise rights) are announced in-product or by updating this page before they take effect, with a refreshed effective date. Where continued use means acceptance of the new policy, we state that. PDPA guidance is available from Singapore PDPC.