SOLVE · SOLVEBOOKS
Privacy Policy
- Announced
- Effective
- Contact
- contact@testbank.ai
Testbank Inc. (the "Company") complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws, processes personal data lawfully, and manages it safely. For users in Taiwan, this Privacy Policy also provides the notifications required under Article 8 of the Personal Data Protection Act (PDPA) of Taiwan. This Policy explains which personal data the Company collects, for which purposes, how long it is retained, where it is stored, to whom it is provided, and how you can exercise your rights.
This Privacy Policy is published in Korean, English, and Traditional Chinese. The English and Traditional Chinese versions are translations provided for convenience; in the event of any inconsistency, the Korean version prevails.
Data Controller — Who Collects Your Personal Data
Your personal data is collected and processed by the following company (the data controller):
| Item | Details |
|---|---|
| Service | SOLVE (mobile app) · SOLVEBOOKS (https://books.solve.im) |
| Company | Testbank Inc., a company incorporated under the laws of the Republic of Korea |
| Representative | Hyunwook Choi |
| Address | 5F-501, 23, Teheran-ro 25-gil, Gangnam-gu, Seoul, Republic of Korea |
| Telephone | +82-70-4138-1102 |
| Privacy inquiries | contact@testbank.ai |
Categories of Personal Data We Collect
The Company collects and uses personal data within the minimum scope necessary to provide the Service. Depending on how you sign up and which features you use, the following categories of personal data are processed:
| Category | Items |
|---|---|
| Account information | Name, e-mail address, mobile phone number (where sign-up or verification based on a phone number is used) |
| Social sign-in information | OAuth authentication information and profile provided by Apple, Google, or Kakao when you sign in with a social account (e.g., user identifier, e-mail address) |
| Device and log information | Device identifier (UUID), app/OS version, IP address, access and usage logs, cookies |
| Learning and content data | User ID, content IDs, reading and sync records, activation tokens and history, study notes and handwriting data, uploaded PDF metadata (file name, size) |
| Customer support records | Name, contact details, inquiry details, consultation history, attachments (e.g., screenshots) |
| Purchase records (where you make a purchase) | Order number, payment date and time, payment method, payment amount |
| Notifications (optional, with consent) | Push notification token |
| Phone verification records (where used) | Mobile phone number, verification-code sending and verification history |
The Company does not collect your age or date of birth at sign-up.
Purposes of Collection and Use
The Company uses personal data for the following purposes:
- Membership management — verifying and authenticating your identity, maintaining and managing membership status, preventing fraudulent sign-up, and delivering notices
- Service provision — e-book reading, activation of purchased content, storage and syncing of learning records, study notes, and handwriting data, storage of uploaded files, and service quality improvement
- Payment and refunds (where applicable) — payment and settlement, cancellation and refunds, and checking fraudulent transactions
- Customer support — receiving and handling inquiries and complaints, and keeping records of consultations
- Statistics and analytics — traffic statistics, usage and crash analysis, and service improvement
- Marketing (only with your separate consent) — information about events, feature updates, and new services
Retention Period
In principle, the Company retains your personal data until you withdraw from membership (delete your account) or until the purpose of processing is achieved, and then destroys it without delay. The following data is retained for the specific period stated below:
- Verification-code sending and verification history — 6 months from the date of sending
- Customer consultation records — until a destruction request is made or the related dispute is resolved
- Marketing data collected with consent — until you withdraw consent or withdraw from membership
Exceptionally, where the laws of the Republic of Korea require continued retention, the relevant data is stored separately from other personal data for the statutory period and used only for the purpose of such retention:
| Legal basis (Republic of Korea) | Records | Period |
|---|---|---|
| Commercial Act, Article 266 | Personal data included in important documents concerning commercial books and business / in slips or similar documents | 10 years / 5 years |
| Framework Act on National Taxes, Article 85-3 | Books and evidentiary documents concerning transactions (name, resident registration number, telephone number, billing address, payment records, etc.) | 5 years |
| Credit Information Use and Protection Act, Article 20 | Records on the collection, processing, and use of credit information | 3 years |
| Act on the Consumer Protection in Electronic Commerce, Article 6 (and Article 6 of its Enforcement Decree) | Records on contracts and withdrawal of offers (5 years); payment and supply of goods (5 years); consumer complaints and dispute handling (3 years); display and advertising (6 months) | 5 years / 5 years / 3 years / 6 months |
| Protection of Communications Secrets Act, Article 15-2 (and Article 41 of its Enforcement Decree) | Telecommunication dates and times, start and end times, subscriber numbers, usage counts, originating base-station location data (12 months); computer communications and internet log records, access-location tracking data (3 months) | 12 months / 3 months |
When personal data becomes unnecessary — for example, upon expiry of the retention period or achievement of the processing purpose — the Company destroys it without delay with the approval of the Chief Privacy Officer. Electronic files are destroyed so that the records cannot be restored, and paper documents are shredded or incinerated.
Where Your Data Is Stored — Cross-Border Transfer
Your personal data is stored and processed on servers located in the Republic of Korea (Amazon Web Services, Seoul Region).
If you use the Service from outside the Republic of Korea — including from Taiwan — your personal data is transmitted to, stored in, and processed in the Republic of Korea as described above.
The Company uses Amazon Web Services (AWS) for service operation, and some systems run on AWS’s global infrastructure. Important member personal data is stored in databases located in the Republic of Korea region and is not transferred abroad for storage; however, in the course of AWS’s operational and technical support, personal data may be accessed or processed from outside Korea (e.g., the United States). The Company also uses Google Firebase to analyze service-usage logs.
Overseas recipients (transfer for processing and storage)
| Recipient / Contact | Country | Personal data items | Purpose | Retention |
|---|---|---|---|---|
Amazon Web Services, Inc. 410 Terry Avenue North, Seattle, WA 98109, USA / aws-korea-privacy@amazon.com | USA | Service usage records (logs) | Statistical analysis of service use and visits; storage of system backup information for contingencies | Until membership withdrawal or expiry of the statutory retention period |
Google LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA / googlekrsupport@google.com | USA | Service usage logs; Firebase (push notification information, app analytics information, device ID/token); GA4 (web/app visits and usage, page views, event information, device information); Google Sign-In (OAuth authentication information) | Statistical analysis of service use and marketing measurement; push notification delivery and app feature analysis/improvement; OAuth-based user identification and sign-in | Until membership withdrawal or expiry of the statutory retention period |
Mixpanel, Inc. One Front Street, 28th Floor, San Francisco, CA 94111, USA / compliance@mixpanel.com | USA | Cookie information, web/app usage event information | Analysis of user behavior patterns and service improvement | Until membership withdrawal or expiry of the statutory retention period |
Meta Platforms, Inc. (Pixel) 1 Meta Way, Menlo Park, CA 94025, USA / dpfinquiry@support.facebook.com | USA | User behavior records, user_id, event information, device information | Advertising performance tracking and tailored advertising | Until membership withdrawal or expiry of the statutory retention period |
AppsFlyer Ltd. 14 Maskit St., Herzliya, Israel / privacy@appsflyer.com | Israel | Device ID, advertising ID (ADID/IDFA), app install and launch records | Mobile app advertising attribution measurement | Until membership withdrawal or expiry of the statutory retention period |
Microsoft Corporation (Clarity) One Microsoft Way, Redmond, WA 98052, USA / privacy@microsoft.com | USA | Session recording data, click/scroll history, device and browser information | User experience (UX) analysis and service interface improvement | Until membership withdrawal or expiry of the statutory retention period |
Apple Inc. (Sign in with Apple) One Apple Park Way, Cupertino, CA 95014, USA / dpo@apple.com | USA | OAuth authentication information | OAuth-based user identification and sign-in | Until membership withdrawal or expiry of the statutory retention period |
Timing and method of transfer: transmitted over the network at the time of service use. Legal basis: Articles 26 and 28-8(1)3 of the Personal Information Protection Act of the Republic of Korea (outsourcing of processing / storage).
If you do not wish your personal data to be transferred as described above, you may withdraw from membership in the app or on the website, or request withdrawal by contacting the customer support e-mail. Please note that if you refuse the transfer described above, use of the Service is not possible.
Provision to Third Parties and Data Processors
1. Provision to third parties (with your consent)
The Company provides personal data to third parties only with your consent or where permitted by law, and only within the minimum necessary scope. The following provision applies when you use the corresponding features (currently offered for users in Korea):
| Recipient | Items | Recipient’s purpose | Retention |
|---|---|---|---|
| Partners (Hackers Language Institute, YBM NET) | User identifier, order/pass number, usage status (active/inactive) | Verification of content licenses, cooperation in customer support | Until the purpose is achieved |
| Payment processors (Toss Payments, Naver Financial (Naver Pay)) | Name, mobile phone number, order number, payment amount and date, payment method | Payment processing, cancellation and refunds, fraud prevention | Statutory retention period (e.g., e-commerce laws) |
In addition, where other laws specifically so provide (e.g., criminal procedure or telecommunications laws), where it is clearly necessary for the urgent protection of the life, body, or property of the data subject or a third party, where necessary for criminal investigation and prosecution, or where urgently required for public safety, the Company may provide the minimum necessary personal data to the competent authorities without consent, in accordance with the Personal Information Protection Act of the Republic of Korea.
2. Data processors (outsourcing of processing)
For the smooth handling of personal data processing work, the Company entrusts the following work to the following processors:
| Processor | Entrusted work |
|---|---|
| Channel Corporation | Receiving customer inquiries and operating consultations via Channel Talk |
| Aligo (JNS Communications) | Sending text messages (SMS/LMS) and KakaoTalk notification messages ※ Sub-processor for notification messages: Kakao Corp. |
| Toss Payments Co., Ltd. | Payment processing |
| Naver Financial Corp. (Naver Pay) | Payment processing |
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure operation, data storage |
| Google LLC | Statistical analysis of service traffic via Firebase Analytics App crash analysis via Firebase Crashlytics Analysis of web/app visits and usage, page views, events, and device information via GA4 Google Sign-In (OAuth authentication) processing |
| Mixpanel, Inc. | Analysis of user behavior patterns and service improvement |
| Meta Platforms, Inc. (Pixel) | Advertising performance tracking and tailored advertising |
| AppsFlyer Ltd. | Mobile app advertising attribution measurement |
| Microsoft Corporation (Clarity) | User experience (UX) analysis and interface improvement |
| Apple Inc. (Sign in with Apple) | OAuth-based user identification and sign-in |
When concluding outsourcing contracts, the Company specifies in the contract documents, in accordance with Article 26 of the Personal Information Protection Act of the Republic of Korea, matters such as the prohibition of processing beyond the entrusted purpose, technical and managerial safeguards, restrictions on re-outsourcing, supervision of the processor, and liability for damages, and supervises whether the processor handles personal data safely. Where a processor re-entrusts the Company’s processing work, it obtains the Company’s consent, and the Company discloses the sub-processor and the re-entrusted work through this Privacy Policy. If the entrusted work or a processor changes, the Company will disclose the change through this Privacy Policy without delay.
Your Rights and How to Exercise Them
You may exercise the following rights against the Company at any time. For users in Taiwan, these correspond to the rights guaranteed under Article 3 of the Personal Data Protection Act of Taiwan:
- The right to inquire about and review (access) your personal data
- The right to request a copy of your personal data
- The right to request supplementation or correction
- The right to request that collection, processing, or use be stopped (suspension of processing)
- The right to request deletion
- The right to withdraw consent at any time (including consent to marketing)
- How to exercise: send your request to contact@testbank.ai. The Company will act on it without delay and respond within 10 days of receiving the request (for data transmission requests, without delay).
- Rights may also be exercised through an agent, such as your legal representative or a person delegated by you. In that case, a power of attorney must be submitted.
- For children under 14, rights must be exercised by the legal representative; a data subject who is a minor aged 14 or older may exercise rights personally or through a legal representative.
- The Company verifies that the person exercising a right is the data subject or a legitimate agent.
- Requests for access or suspension of processing may be limited under applicable laws (Articles 35(4) and 37(2) of the Personal Information Protection Act of the Republic of Korea). Deletion cannot be requested for personal data whose collection is required under other laws.
- Withdrawing marketing consent: you may opt out of marketing messages at any time via the in-app [My Info > Notification Settings] menu (turning off individual channels) or the unsubscribe link included in messages.
※ Opt-out processing may take up to 3 business days.
| Role | Contact person | Contact |
|---|---|---|
| Privacy department | Development Department | contact@testbank.ai |
Consequences of Not Providing Personal Data
You are free to choose whether to provide personal data. However, the items required for sign-up and service provision (account information and device/log information) are essential for concluding and performing the service contract; if you do not provide them, sign-up for or use of the Service may not be possible.
Choosing not to provide optional items (such as marketing consent or the push notification token) does not restrict your use of the core Service. If you do not consent to the storage and processing of your data in the Republic of Korea described in Section 5, the Company is unable to provide the Service; in that case you may refrain from signing up or withdraw from membership at any time.
Security Measures
The Company takes the following measures to ensure the security of personal data:
- Managerial measures — establishing and implementing an internal management plan, operating a dedicated organization, regular staff training on privacy and information security, and periodic checks of compliance with security regulations
- Technical measures — managing access rights to personal data processing systems, installing access-control systems and related safeguards, encrypting personal data databases, retaining and inspecting access records, installing and updating security software, and checking and remedying vulnerabilities of processing systems
- Physical measures — controlling access to data storage rooms and similar facilities, keeping documents and auxiliary storage media in secure, locked locations, and periodically managing access records
Children’s Personal Data
- The Company does not collect age or date-of-birth information at sign-up, and the Service is operated for general users.
- If it is confirmed that a child under the age of 14 has used the Service without the consent of a legal representative, the Company may restrict or delete the relevant account.
- Where a child’s personal data is needed for a specific service or event, the Company obtains the prior consent of the legal representative and collects and uses only the minimum information.
Contact and Complaints
The Company has designated the following Chief Privacy Officer and department, which are responsible for personal data processing overall and handle complaints and remedies related to personal data. The Company will answer and handle your inquiries without delay:
| Role | Contact person | Contact |
|---|---|---|
| Chief Privacy Officer | Jihun Kim, CTO | jihun.kim@testbank.ai |
| Privacy department | Development Department | contact@testbank.ai |
| Personal data access requests | Jihun Kim, CTO | contact@testbank.ai |
You may also apply for dispute resolution or consultation to the following institutions of the Republic of Korea:
- Personal Information Dispute Mediation Committee: +82-1833-6972 (www.kopico.go.kr)
- KISA Personal Information Infringement Report Center: +82-118 (privacy.kisa.or.kr)
- Korean National Police Agency: +82-182 (ecrm.cyber.go.kr)
Changes to This Privacy Policy
- This Privacy Policy applies from July 10, 2026. (Established on August 1, 2022 → amended on October 27, 2025 → amended on July 10, 2026)
- Previous versions of the Privacy Policy (in Korean) are available below:
- Applied from October 27, 2025 to July 9, 2026 (Korean)
- Applied from August 1, 2022 to October 26, 2025 (Korean)
This Policy is published in Korean, English, and Traditional Chinese. In the event of any inconsistency between the versions, the Korean version prevails.