Back to home

Privacy Policy

Last updated: 2026-06-27

CODFY Co., Ltd. (the "Company") operates the end-to-end encrypted messenger "Signito" (the "Service") and, under Article 30 of Korea’s Personal Information Protection Act, explains how it processes and protects your personal information as follows. The Company processes only the minimum needed to run the Service and does not collect your date of birth, legal name, email, or phone number. The contents of your messages and files are end-to-end encrypted and cannot be read by the Company.

1. Purposes of Processing

The Company processes personal information only for the purposes below. If the purpose changes, we take the necessary measures, such as obtaining separate consent, under Article 18 of the Act.

  • Sign-up and account management: identification and authentication, maintaining membership, and preventing abuse
  • Service delivery: relaying messages and files, and sending push notifications
  • Premium (paid) operation: verifying in-app purchases and managing Premium entitlements
  • Improvement and security: troubleshooting and blocking abnormal traffic such as DDoS attacks

2. Personal Information We Process

Based on performance of the service contract (Article 15(1)4 of the Act), the Company processes the items below without separate consent. Passwords and recovery codes are stored only as a non-reversible hash.

  • Required (contract): login ID, password and recovery code (stored hashed), nickname
  • Optional: profile image, status message
  • Generated automatically while using the Service: device type (Android/iOS), push token, sign-in token, access logs (IP address and access time), and the in-app purchase transaction identifier, product identifier, and entitlement status

3. End-to-End Encryption (What We Cannot Access)

Message bodies and attachments are end-to-end encrypted on the sending device before transmission and storage; the server holds no decryption keys and cannot read their contents. The server processes only the public encryption keys needed for delivery and minimal metadata (room identifier, timestamp, etc.). Access logs are not stored in association with any specific account; they are used only to keep the Service stable — for example, to block abnormal traffic such as DDoS attacks — and are automatically deleted after at most 7 days.

4. Retention Period

In principle the Company retains personal information until you withdraw membership, after which it is destroyed without delay. Messages auto-expire and are deleted once the retention period you set passes, and we offer optional automatic account deletion after a period of inactivity.

On withdrawal, all personal information held by the Company is destroyed and is not retained separately. Records of in-app purchase transactions are kept by the payment processors, Apple and Google, under their respective store policies; the Company does not hold those records.

5. Destruction of Personal Information

When the retention period expires or the purpose is achieved and the data is no longer needed, the Company selects the data, obtains the privacy officer’s approval, and destroys it without delay. Electronic files are permanently deleted in an unrecoverable manner, and printouts are shredded or incinerated.

6. Provision to Third Parties

The Company does not provide or sell your personal information to third parties. We may disclose it only where specifically required by law or upon a lawful request from an investigative authority (e.g., a warrant), in accordance with applicable law.

7. Outsourced Processing

To provide the Service, the Company outsources the following processing. Under Article 26 of the Act, the relevant contracts prohibit use beyond the purpose and require safeguards, and the Company supervises each processor.

  • Amazon Web Services, Inc. — cloud infrastructure (data storage and transport)
  • Apple Inc. and Google LLC — in-app purchase processing and receipt verification (the stores handle payment-method details such as card numbers; the Company does not hold them)
  • Apple Push Notification service and Firebase Cloud Messaging (Google) — push notification delivery

8. Cross-Border Transfer

To provide the Service, the Company transfers personal information abroad (for processing and storage) as below, in accordance with Article 28-8 of the Act. The legal basis for the transfer is Article 28-8(1)3 of the Act (overseas processing/storage to perform the contract and enhance convenience). Messages and attachments are transferred end-to-end encrypted, so the recipient cannot read their contents either.

The cross-border transfer is essential to providing the Service; to refuse it, you must delete your account in the app’s settings, in which case the Service can no longer be used.

  • Recipient: Amazon Web Services, Inc. (privacy@amazon.com) / Items: account and profile data, encrypted messages and attachments, access logs / Countries: the regions where the Service runs (currently the Republic of Korea; more as we expand globally) / When and how: transmitted over TLS while you use the Service / Purpose: cloud storage and transport / Retention: until membership withdrawal or expiry of the retention period
  • Recipient: Apple Inc., Google LLC (contact: see each company’s privacy policy) / Country: United States / Items: push token, in-app purchase receipt / When and how: transmitted over TLS while you use the Service / Purpose: notification delivery and payment verification / Retention: until the purpose is achieved

9. Security Measures

The Company takes the following measures to keep personal information secure.

  • Administrative: establishing and operating an internal management plan, and minimizing and controlling access rights
  • Technical: end-to-end encryption of messages and files, non-reversible hashing of passwords and recovery codes, TLS in transit, and access control with logging and review
  • Physical: encryption keys are kept securely in each operating system’s secure storage, and the cloud provider’s data-center physical security and access controls apply

10. Children Under 14

The Service is for users aged 14 and over. The Company does not knowingly process the personal information of children under 14, and if we learn that such data has been collected, we delete it without delay.

11. Your Rights and How to Exercise Them

You may at any time request access to, correction, deletion, or suspension of processing of your personal information, and withdraw consent. You can edit your profile and delete your account (withdraw membership) directly via Settings → My Profile in the app; other requests may be submitted in writing or by email to the privacy officer below. We respond within 10 days of receiving a request.

12. Items That Do Not Apply

The Company does not use cookies or other automatic collection tools for advertising or analytics, and does not collect behavioral data. We do not process sensitive or pseudonymized data, make automated decisions affecting users, operate CCTV, or fall under the domestic-representative requirement.

13. Privacy Officer

The Company has designated a privacy officer below to oversee personal-information processing and handle inquiries and complaints.

  • Privacy Officer: Seongwook Jeong
  • Contact: support@codfy.io / 1551-5730

14. Remedies for Rights Infringement

For dispute resolution or counseling regarding privacy infringement, you may contact the agencies below.

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors’ Office Cyber Investigation: 1301 (www.spo.go.kr)
  • National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)

15. Changes to This Policy

This Privacy Policy applies from its effective date (the “last updated” date at the top of this page). If we change it, we will announce the changes on this site or in the Service before they take effect.