Vol. 2May 2026

Privacy Policy

Effective date: April 21, 2026

PubStation Co., Ltd. (hereinafter "Company") takes the privacy of users of its service Pagera (https://pagera.app) seriously and complies with applicable laws including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection. This policy explains what information we collect and how we use and protect it.


1. Information We Collect

The Company collects the following information to provide its services.

At account registration (required)

  • Email address, Firebase authentication identifier (UID), authentication provider (Google / email)
  • Nickname, profile image (collected automatically when using social login)

Automatically collected during service use

  • Reading history (books read, chapters, time spent, scroll position), bookmarks, highlights, vocabulary lists, translation request history
  • IP address, browser information, device identifier (fingerprint)
  • Traffic source (UTM parameters, referrer), first landing page
  • Cookies (session maintenance, analytics, ad measurement)

When using the service without an account

  • IP address and fingerprint are used to enforce the daily free-read limit of one book (a pseudo-identifier that works even without a registered account)

2. How We Use Your Information

  • User identification, authentication, account registration and deletion
  • Book recommendations, reading progress storage, translation request and completion notifications
  • Service usage analytics, quality improvement, new feature development
  • Ad performance measurement and marketing channel analysis
  • Fraud prevention and enforcement of Terms of Service
  • Compliance with legal obligations

3. Retention Period

  • Immediate deletion upon account withdrawal is our default (member data is marked deletedAt and permanently deleted within 30 days).
  • Where required by law (e-commerce regulations, communications privacy laws, etc.), records are retained for the following periods:
    • Records related to display and advertising: 6 months
    • Records related to contracts or withdrawal of subscription: 5 years
    • Records related to payment and supply of goods: 5 years
    • Records related to consumer complaints or dispute resolution: 3 years
    • Access logs: 3 months

4. Sharing with Third Parties

The Company does not disclose personal information to third parties as a general rule. Exceptions apply only when required by law enforcement authorities pursuant to applicable law, or when the user has given prior consent.


5. Data Processing Subcontractors

The Company entrusts certain processing activities to the following vendors to provide a stable service.

Vendor Processing activity Location
Google Cloud Platform Server hosting, database, and storage (Cloud Run, Cloud SQL, GCS) Seoul (asia-northeast3)
Firebase (Google) Authentication, hosting Global
Google Analytics 4 Website usage analytics Global
Microsoft Clarity Session recording and usability analysis Global
Resend Transactional email delivery Global

By completing account registration, you consent to cross-border data transfers to the vendors above. If you do not consent, please do not create an account.


6. Cookies

The Company uses the following cookies.

Cookie name Purpose Retention
__session Firebase authentication session 14 days
pagera_utm Traffic source tracking (first-touch) 180 days
_ga / _ga_* Google Analytics visitor identification Up to 2 years
_clck / _clsk Microsoft Clarity session identification Up to 1 year

You can disable cookies in your browser settings; doing so may limit certain features.


7. Your Rights

You have the right to:

  • Access your personal information
  • Request correction or deletion of inaccurate data
  • Request restriction of processing
  • Delete your account (My Page → Settings → Account → Delete account)
  • Request a download of your stored data (by email request)

To exercise any of these rights, please email pubstation@pubstation.co.kr and we will respond without delay.


8. Security Measures

  • TLS 1.3 encryption for all data in transit
  • One-way password hashing via Firebase Auth
  • Least-privilege IAM-based access control for administrators
  • Regular security audits and vulnerability patching

9. Privacy Officer

If you need to report a privacy concern, you may also contact the following Korean authorities:

  • Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
  • Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
  • Supreme Prosecutors' Office Cyber Investigation Division (spo.go.kr / 1301)
  • National Police Agency Cyber Investigation Bureau (ecrm.cyber.go.kr / 182)

10. Amendments

This policy may be revised as laws or services change. We will post notice on this page at least 7 days before any change takes effect. For significant changes, we will notify registered members by email.

Effective date: April 21, 2026