Privacy Policy

Effective date: 2026-07-19

1. Overview and core principle

This Privacy Policy explains how Utilo (the “Service”, operated by 맘소프트 momsoft) handles personal data, in line with the Korean Personal Information Protection Act (PIPA), the EU/UK GDPR, and other applicable laws. Our core principle is data minimization and in-browser processing.

Every tool on the Service (image, PDF, conversion, calculation, and so on) processes the files and inputs you select entirely within your browser (on your device). Those files and their contents are never uploaded, transmitted, or stored on our servers or any third party, and we neither collect nor access them.

2. Personal data we process and how it is collected

We do not collect the contents or results of your files.

3. Purposes of processing

4. Legal bases

Under PIPA: your consent (e.g., advertising cookies), performance of a contract (paid features), legal obligations, and legitimate interests (security and operational logs). Under the GDPR (where applicable): Art. 6(1)(a) consent, (b) contract, (c) legal obligation, and (f) legitimate interests. Personalized advertising relies on consent obtained via a consent management platform (CMP).

5. Retention

Access logs are kept only as long as necessary for operation and security (per our host/CDN policies, typically short). Advertising and analytics data are retained under each third party’s policy. Payment-related records are kept for the period required by applicable law (e.g., e-commerce law) and then destroyed. When a purpose is fulfilled or a period elapses, the data is destroyed without undue delay.

6. Disclosure to third parties

We do not, as a rule, provide your personal data to third parties, except where there is a legal basis, where you have consented, or as part of the processors described in Section 7.

7. Processors and international transfers

To operate the Service we use the processors below; some may be located outside Korea (e.g., the United States). For international transfers we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs).

ProcessorPurposeLocation
Cloudflare, Inc.Hosting, CDN, security (access logs)US / global
Kakao Corp. (Kakao AdFit)Ad delivery & measurementSouth Korea
Google LLC (Google Analytics)Usage statistics & traffic analysis (when enabled)US
Payment provider (Merchant of Record)Payment processing (for purchases)Provider-dependent
Sentry (Functional Software, Inc.)Error diagnostics (when enabled)US

Certain tools load external resources: public exchange-rate data (exchange rates for currency conversion), unpkg.com (loading the in-browser video engine), and Hugging Face (loading the background-removal AI model). When you use those specific tools, your browser connects to those providers (which may see your request IP), but your files are not sent — only code, models, or rate data are fetched.

8. Cookies and opt-out

On our own, we use only functional browser storage (theme, license, etc.), which is not an advertising or tracking cookie. To serve advertising, Kakao AdFit may use cookies and advertising identifiers; you can opt out of personalized ads via Kakao’s personalized-advertising settings. You can also block or delete cookies in your browser settings and opt out at aboutads.info and youronlinechoices.eu. Google Analytics can be opted out of with the Google Analytics opt-out browser add-on. Visitors in the EEA, the UK and Switzerland are asked for cookie and advertising consent through a consent management platform (CMP / Consent Mode v2).

9. Your rights

You may at any time request access to, correction of, deletion of, or restriction of the processing of your personal data, and where applicable data portability, objection to processing, and withdrawal of consent. Because we do not store your files or identifying data on our servers, settings and licenses stored in your browser can be removed by you directly (by clearing browser storage). To exercise your rights, contact [email protected]; we will act without undue delay as required by law. Users covered by the GDPR also have the right to lodge a complaint with a supervisory authority.

10. Children

The Service is not directed to children under 14 (or under 16 where the GDPR applies), and we do not knowingly collect children’s personal data.

11. Security measures

End-to-end HTTPS (TLS) encryption; data minimization by design through in-browser processing; access controls; and security response headers.

12. Privacy officer and contact

13. Remedies

In Korea you may contact: the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), the Privacy Infringement Report Center (privacy.kr, 118), the Supreme Prosecutors’ Office Cybercrime Division (1301), or the National Police Agency Cyber Bureau (182). In the EEA/UK you may lodge a complaint with your local supervisory authority.

14. Changes

We may update this Policy to reflect changes in law or the Service, and will announce changes on this page. Effective date: 2026-07-19.