Privacy Policy
Last updated: May 16, 2026 (Effective date)
On this page
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Data Processors (Subprocessors)
- 5. Sharing with Third Parties
- 6. International Data Transfers
- 7. Data Retention
- 8. Your Rights
- 9. Security
- 10. Children
- 11. Cookies and Automatic Collection
- 12. Data Protection Officer
- 13. Updates to This Policy
- 14. Company Information
This Privacy Policy is drafted in compliance with the Republic of Korea's Personal Information Protection Act (PIPA), the Act on Promotion of Information and Communications Network Utilization and Information Protection ("Network Act"), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA, as amended by CPRA) where applicable.
1. Introduction
This Privacy Policy explains how Tyranno Apartment ("Tyranno Apartment", "we", "us"), the operator of the Servan service ("Servan", the "Service") and the Data Controller, collects, uses, shares, and protects information about you ("Data Subject") across our mobile, desktop, and web applications, our backend API, and our MCP server integrations.
By using Servan, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account information
- Email address (required, via Firebase Authentication).
- Display name and profile photo provided through your identity provider (Google, Apple, GitHub, etc.) or set manually.
- Team membership, team role, and workspace identifiers you create or are invited to.
2.2 Team and workspace content
- Knowledge Base pages, spaces, sections, and revisions you create, edit, or generate.
- Reports, dispatches, comments, and chat threads inside a team workspace.
- Files, images, and attachments you upload.
- Knowledge graph metadata derived from your content (entity links, references).
2.3 Integration data
- OAuth access and refresh tokens for connected providers (Slack, Jira, GitHub, Confluence, Notion, and others you authorize).
- Inbound webhook payloads, channel messages, issue updates, pull-request events, and page contents the integration brings into Servan.
- Resource selectors you configure (e.g. specific Notion pages shared with our integration, Slack channels you subscribe to, GitHub repositories you install the app on).
2.4 Payment information
- Subscriptions are processed by Stripe (web), Apple In-App Purchase (iOS/macOS), or Google Play Billing (Android).
- We do NOT store full credit-card numbers on our servers. Card data is held by the payment processor.
- We retain subscription status, plan tier, billing email, and transaction identifiers required to manage entitlements.
2.5 Device, usage, and diagnostics
- Device identifiers and Firebase Cloud Messaging (FCM) tokens, used only to deliver push notifications you have enabled.
- Crash reports and performance traces via Firebase Crashlytics and Firebase Performance Monitoring.
- Aggregated usage analytics (feature usage counts, latency) used to improve product quality.
- IP address and request metadata captured by our infrastructure for security and abuse prevention.
2.6 Collection methods
We collect personal data (1) when you directly provide it (sign-up, in-app input), (2) automatically through integrations you authorize, and (3) automatically generated through service usage (cookies, logs, IP addresses).
3. How We Use Your Information
- Operate the Service — authentication, Knowledge Base management, search, dispatch, billing, and account administration.
- AI processing — with your action or consent, we transmit relevant content to AI providers (Google Gemini, OpenAI, Anthropic Claude via MCP) to generate KB pages, detect conflicts, summarize threads, embed text, and answer your queries.
- RAG indexing — we generate vector embeddings of your content and store them in our pgvector index so search and AI features can retrieve relevant snippets.
- Integration sync — we read from and (when authorized) write back to external KBs to keep content synchronized.
- Billing and entitlements — manage subscriptions through Stripe, Apple, and Google.
- Notifications — push and email notifications you have subscribed to.
- Service monitoring — diagnose issues, detect abuse, and meet legal obligations.
4. Data Processors (Subprocessors)
To deliver the Service reliably, we entrust personal-data processing to the following subprocessors. Processing terms include the safeguards required by PIPA Article 26 and GDPR Article 28.
| Subprocessor | Function | Retention |
|---|---|---|
| Google Cloud Platform (Google LLC) | Hosting, database (Cloud SQL), authentication (Firebase Auth), push notifications (FCM), storage | Until account deletion or end of subprocessing |
| Vertex AI (Google LLC) | Text embedding generation (e.g. text-embedding-004) | Until account deletion or end of subprocessing |
| Google Gemini API (Google LLC) | KB draft generation, conflict detection, auto-approval evaluation | Until account deletion or end of subprocessing |
| OpenAI, L.L.C. | Auxiliary LLM processing (summarization, fallback embedding) | Until account deletion or end of subprocessing |
| Anthropic, PBC (Claude API) | User-selected LLM processing via MCP tool calls | Until account deletion or end of subprocessing |
| Stripe, Inc. | Payment processing (Pro/Business plans, web) | Statutory retention (e.g. KR E-Commerce Act 5y) or end of subprocessing |
| Apple Inc. / Google LLC | Mobile In-App Purchase (IAP) | Statutory retention or end of subprocessing |
We update this list when subprocessors change and post a notice at least 30 days in advance on our Subprocessors page.
5. Sharing with Third Parties
We do NOT share your personal information with third parties without your consent. When you explicitly connect an external integration (Slack, Jira, GitHub, Confluence, Notion, etc.), data flows are exchanged with that service under its own terms. This is treated as your explicit consent-based integration, not as third-party disclosure. Disconnecting an integration immediately stops that data flow.
We may disclose data when legally required by a valid law-enforcement request or court order.
We do NOT sell your personal information (CCPA "sale" defined). We do NOT show third-party advertising in Servan, and we do NOT share data with marketing data brokers.
6. International Data Transfers
We transfer personal data internationally as listed below. By agreeing to this Privacy Policy at sign-up, you consent to these transfers under PIPA Article 28-8. For GDPR Data Subjects, transfers rely on Standard Contractual Clauses (SCCs) and supplementary safeguards.
| Recipient | Country | Items | Method | Retention |
|---|---|---|---|---|
| Google LLC (Gemini, Vertex AI, GCP) | United States | User content, embeddings, metadata, account identifiers | Real-time API calls (HTTPS/TLS) | Discarded after processing per provider policy |
| OpenAI, L.L.C. | United States | User content (when summarization/embedding is requested), metadata | Real-time API calls (HTTPS/TLS) | Discarded after processing per provider policy |
| Anthropic, PBC | United States | MCP tool-call payloads, user content | Real-time API calls (HTTPS/TLS) | Discarded after processing per provider policy |
| Stripe, Inc. | United States | Billing email, transaction IDs, subscription state | At time of payment (HTTPS/TLS) | Statutory retention |
Where the LLM provider offers an opt-out, we opt out of training their public models on your content.
7. Data Retention
- Active accounts: data is retained for as long as your subscription is active and you have not requested deletion.
- Deleted accounts: when you delete your account, personal data and team content owned by you is removed from production systems, with a 30-day retention period in encrypted backups before full purge.
- Legal records: tax invoices and other records required by law (e.g. KR E-Commerce Act — transaction records 5y, consumer complaint records 3y; Telecommunications Privacy Act — login logs 3 months) are retained for the period prescribed.
8. Your Rights
Subject to your local privacy law (PIPA, GDPR, CCPA), you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete your account and request erasure of your personal data.
- Object to or restrict processing.
- Withdraw consent for optional processing (e.g. AI analysis) at any time.
- Data portability — export your Knowledge Base content.
- Claim damages for harm caused by our processing (in Korea, via the Personal Information Dispute Mediation Committee).
- Lodge a complaint with your supervisory authority — Korea's Personal Information Protection Commission (1833-6972) or your local DPA.
- CCPA-specific (California residents): right to know, right to delete, right to opt out of "sale/sharing" (we do not sell or share), right to non-discrimination.
Exercise your rights via (1) email to support@tyrannoapartment.com or (2) the in-app "Profile → Download data / Delete account" menu. We respond within 10 days (PIPA) or 30 days (GDPR/CCPA). Identity-verification procedures are described on our DSAR page.
9. Security
- Encryption in transit: all client-server traffic is protected with TLS 1.2 or higher.
- Encryption at rest: Cloud SQL, Firestore, and Cloud Storage are encrypted at the platform level using Google Cloud KMS.
- OAuth tokens: integration access and refresh tokens are stored in Cloud SQL and protected by database-level at-rest encryption and TLS in transit. You can disconnect an integration at any time, which immediately revokes and discards the tokens. (Column-level encryption is on our security-hardening roadmap.)
- Access controls: backend operator access is governed by least-privilege IAM, VPC isolation, and audit logging.
- Two-factor authentication: available through Firebase Authentication and through your upstream identity provider.
- Backups: GCP automated backups retained for 30 days then purged.
- Incident response: in case of a personal-data breach we will notify affected Data Subjects and the relevant supervisory authority within 72 hours of becoming aware of it.
No system is 100% secure. Please use a strong password and enable any available account-security features.
10. Children
Servan is not directed to children. We do not knowingly collect personal information from children under 13 (under GDPR/COPPA) or under 14 (under the Republic of Korea's Network Act and PIPA). If we discover that a child has provided personal information, we will delete it and terminate the account.
11. Cookies and Automatic Collection
We use essential cookies (authentication, session) and analytics cookies (Firebase Analytics, Performance Monitoring). We do NOT use marketing/advertising cookies. See our Cookie Policy for details and opt-out options.
12. Data Protection Officer
We have appointed a Data Protection Officer (DPO) responsible for overseeing privacy compliance and handling Data Subject inquiries.
- DPO Name: GiYeong UM
- Title: Tyranno Apartment Data Protection Officer
- Email: support@tyrannoapartment.com
- Contact method: email only; we respond within 10 business days
If you have concerns that we have not addressed, you may contact your local data-protection authority — in Korea: Personal Information Protection Commission (privacy.kisa.or.kr, 118).
13. Updates to This Policy
We may update this Privacy Policy. Material changes will be announced through the Service or by email at least 30 days before they take effect; minor changes 14 days in advance. The "Effective date" at the top indicates the most recent revision. Previous versions are available on request to support@tyrannoapartment.com.
14. Company Information
- Company: Tyranno Apartment
- Representative: Eunsook Choi
- Business registration number: 888-25-01421
- Mail-order business registration number: 2023-서울송파-0551
- Business address: 120 Wiryegwangwang-ro, Songpa-gu, Seoul, Republic of Korea
- Email: support@tyrannoapartment.com
- Service: https://servan.dev
Note: This document is provided as general guidance. For specific legal advice, please consult a qualified attorney.