Blend Privacy Policy

Effective date: August 8, 2026 · Version: v1.1

The Korean version is the official text. In case of discrepancy, the Korean version prevails.

MIN ("Company") establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act (PIPA) to protect users' personal data and handle related grievances promptly. Blend (the "Service") is an anonymous, BYOK unified multi-AI workspace with no sign-up or login; the Company processes personal data to the minimum extent. This policy is based on the production code.

1. Purposes of Processing

The Company processes only anonymous/statistical data for: (1) operating and improving the Service (anonymous usage statistics, service stability); (2) preventing abuse (abnormal traffic/misuse); (3) providing Paid Services (payment processing via processors and retention of transaction records); (4) grievance handling.

Note: With no sign-up, the Company collects no personal data for identity verification or marketing profiling.

2. Personal Data Items Processed

2.1 Anonymous data sent to servers during use

ItemPurposeRetention
Random identifier (UUID)Anonymous retention stats. Not linked to name/email/device90 days
Country code (2-letter)Country distribution. Derived from IP by Cloudflare; raw IP not stored90 days
OS classDevice stats (from User-Agent, client-side)90 days
AI provider/model nameUsage distribution90 days
Input/output token counts, cost (numbers)Cost statistics. Message content not sent90 days
Events (e.g., menu click)Anonymous feature-usage stats30 days
Error diagnosticsDetecting and fixing service errors. Sends only the screen/feature name, error type, HTTP status, AI provider/model, language, app version and a per-session temporary identifier — never your conversation content, file names or file contents30 days

Users may disable this in [Settings → Analytics].

2.2 At payment — Card and other payment data is collected directly by the payment processor; the Company does not collect or store it. The Company processes only the result (order ID, amount, time, product name).

2.2.1 Email for receipts and login — The email entered at checkout is used to (i) send payment receipts and refund guidance, and (ii) verify your identity when logging in on another device/browser (verification code). Receipt and code emails are sent by the Company's payment worker. The Company does not store the raw email on its servers; for cross-device login identification it keeps only a one-way hash (SHA-256) of the email plus your plan tier and expiry for the subscription period (up to 400 days) — the hash cannot be reversed or enumerated. Codes are auto-deleted within 10 minutes. After login, the email is stored only in the user's browser (localStorage) for display and staying logged in (auto-renew), deleted on logout, and never sent to Company servers. The payment data and raw email are held by the Merchant of Record (Polar). This email is not used for any other purpose (e.g., marketing/profiling).

2.3 Data the Company does NOT process

  • Account info: no name/password/phone/birthdate (no sign-up/login). Email is processed only per 2.2.1 (receipts/restore); the raw email is not stored on servers (only a one-way restore hash).
  • API keys: stored encrypted (AES-256-GCM) in the user's browser localStorage (master key kept non-extractable in IndexedDB); never sent to servers.
  • Chat content: the processing path depends on how the Service is used. (i) With BYOK (your own API key), chat is sent directly from the user's browser to the chosen AI Provider and does not pass through Company servers. (ii) With Managed use (subscribers without a key) and Free Trial (Gemini/Groq), chat passes through the Company's proxy server (Cloudflare Workers) to third-party AI Providers. In both cases the Company does not store chat content, processing only anonymous data for license verification and usage/cost counting (see Articles 6 and 7).
  • Uploaded documents, RAG indexes, embeddings: stored only in the user's browser IndexedDB.
  • Meeting/audio files: uploaded directly to the chosen AI Provider's file API and auto-deleted shortly per that provider's policy.

3. Retention Period

  • Anonymous statistics: auto-deleted after 90 days (some events 30 days).
  • Payment/transaction records: retained by the processor per Article 6 of the E-Commerce Act (contract/withdrawal/payment 5 years; complaints/disputes 3 years).

No personal data beyond the above anonymous statistics is stored on Company servers. Data on the user's device can be erased instantly by clearing browser site data.

4. Provision to Third Parties

The Company does not provide personal data to third parties, except where required by law or upon a lawful request from investigative authorities.

5. Processing Consignment

ProcessorTaskCountry
Cloudflare, Inc.Edge hosting, KV storage, anonymous statistics; relaying user chat to third-party AI and license verification for Managed/Free Trial use (chat not stored)USA
Vercel, Inc.Static hosting, anonymous pageview analyticsUSA
Polar Software Inc.Payment processing as Merchant of Record (payment, taxes, refunds)Sweden/USA, etc.
Resend, Inc.Sending receipt, refund-guidance, and plan-restore verification-code emails (email body not stored)USA

Per Article 26 of PIPA, consignment contracts document the ban on out-of-purpose processing, safeguards, re-consignment limits, and oversight.

6. Overseas Transfer

Data transferred overseas via consignment is limited to the anonymous statistics (2.1), payment-result data, the restore email hash under 2.2.1 (raw email not transferred), and user chat content when using Managed or Free Trial.

RecipientCountryItemsPurpose
CloudflareUSAAnonymous stats, access logs, restore email hashHosting/statistics/restore
VercelUSAAnonymous eventsHosting/analytics
Polar Software Inc.Sweden/USA, etc.Payment-result dataPayment processing (MoR)
ResendUSAReceipt & restore verification-code emailsSending receipts/refund guidance/restore codes
Third-party AI Providers (Managed/Trial relay)USA, China, France (EU), CanadaUser chat content (input/output)Generating AI responses for Managed/Free Trial

Specific recipients: OpenAI, Anthropic, Groq (USA), DeepSeek (China), Mistral (France/EU), Cohere (Canada), Google (USA).

Users may refuse overseas transfer (blend@ai4min.com); refusal may make parts of the Service unavailable.

7. Data Sent Directly to AI Providers, and Auto-Matching

① When chatting, the transmission path of the user's input depends on how the Service is used. (a) BYOK (your own key): the input is sent directly from the user's browser to the AI Providers below and Company servers do not receive it. (b) Managed (subscribers without a key): the Company's managed proxy server relays the chat to the AI Providers below using keys held by the Company, verifying license validity and enforcing usage/cost limits in the process. (c) Free Trial: the Company's trial proxy server relays the chat to Google (Gemini) or Groq using the Company's trial keys. In both (b) and (c), the Company does not store chat content, recording only anonymous aggregate data such as usage counts, token counts, and cost.

AI ProviderHQPrivacy Policy
OpenAI, L.L.C.USAopenai.com/policies/privacy-policy
Anthropic, PBCUSAanthropic.com/legal/privacy
Google LLCUSApolicies.google.com/privacy
DeepSeekChinadeepseek.com
Groq, Inc.USAgroq.com
Mistral AIFrance (EU)mistral.ai/terms
Cohere Inc.Canadacohere.com/privacy

② When using auto AI matching (optional), the input query (up to 2,000 chars) is sent to the Company's classification server (Cloudflare Workers) for temporary analysis to pick the best model. The query text is not stored; only the result (category), a hash of the query, and its length are recorded as anonymous statistics. Selecting a model manually avoids this transfer.

③ Users should review each AI Provider's privacy policy; the Company is not responsible for AI Providers' data processing.

8. Data Subject Rights and How to Exercise Them

① Users may exercise rights to access, correct, delete, suspend processing, and withdraw consent. As an anonymous service, users can instantly erase all on-device data (chats, API keys, indexes, identifier) by clearing browser site data. ② Inquiries/requests regarding server-side anonymous statistics go to blend@ai4min.com; the Company acts within:

RightDeadlineBasis
Accesswithin 10 daysEnforcement Decree Art. 42
Correction/Deletionwithin 10 daysArt. 43
Suspensionwithin 10 daysArt. 44
Withdrawal of consentimmediatelyPIPA Art. 37

③ Because the random identifier is not linked to an individual, it may be technically impossible for the Company to single out and delete one user's records; such data is auto-deleted upon expiry.

9. Destruction

Server-side anonymous statistics are auto-deleted after the retention period (90/30 days). On-device data can be deleted by the user directly.

10. Security Measures

  • Key encryption: API keys are encrypted with AES-256-GCM using a non-extractable browser-bound key and stored in localStorage; the key never leaves the browser via any API.
  • Transport: all traffic is HTTPS-encrypted, with a strict CSP blocking script injection.
  • Storage: server-side (Cloudflare) data is encryption-at-rest, auto-deleted after 90 days, and contains no PII fields.
  • Same-origin isolation of browser data.

11. Cookies and Automatic Collection

The Company uses no advertising or cross-site tracking cookies. Browser storage (localStorage/IndexedDB) is used solely to store the user's settings, chats, and preferences on the user's device; users may refuse or delete it via browser settings.

12. Automated Decision-Making

Per Article 37-2 of PIPA and the PIPC "AI-Era Privacy Guidelines" (2025): ① Auto AI matching analyzes the user's query to recommend a suitable model (final choice is the user's). Processing and server-transfer scope are as in Article 7(2); the query text is not stored. ② Rights: switch from auto-recommendation to manual selection, disable auto-matching, and request human review — via [Settings] or blend@ai4min.com.

13. Privacy Officer

14. Remedies for Rights Infringement

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
  • KISA Privacy Infringement Report Center: 118 / privacy.kisa.or.kr
  • Supreme Prosecutors' Office Cybercrime: 1301
  • National Police Agency Cyber Bureau: 182

15. Changes to This Policy

This policy takes effect on August 8, 2026. Changes are announced in-service at least 7 days in advance (30 days for material changes).

Impormasyon ng Negosyo

Kompanya
MIN
Business Reg. No.
142-09-32639
Kinatawan
Jesik Min
Address
113 Seonbugwangjangnam-ro, Danwon-gu, Ansan-si, Gyeonggi-do, Republic of Korea