This is a reference translation
The Korean text is the legally binding version of this document. If this translation and the Korean text ever disagree, the Korean text prevails. You can read the original by switching the site language to Korean.
Privacy Policy
Last revised 6 September 2026
레테오디오(LETHE AUDIO) (the “service”) processes your personal data under the Korean Personal Information Protection Act (PIPA), the EU and UK GDPR and other applicable law. The controller is the business named in Section 12.
1What We Collect, and How
- Google account information — signing in is only possible with a Google account. At sign-in Google gives us your email address, name and Google account identifier, which we use to identify the account. We do not collect passwords.
- The audio you upload, with its filename and length — you upload it yourself for processing.
- Usage records — time of processing, tool and model, filename, length, credit deductions and returns, and the time you accepted the terms together with the terms version in force.
- Payment records — what the payment company (Paddle.com Market Ltd.) sends us: whether the payment succeeded, the transaction number, the amount and currency, and the pack bought. We do not receive card numbers, billing addresses or other payment-method details — only the payment company holds those.
- Enquiry email — if you write to us, the sender address and the content.
The service does not store IP addresses, location data, device identifiers or advertising identifiers. Access requests do remain briefly in the operational logs of our hosting provider, Vercel (Section 4).
2Purposes and Legal Bases
We use what we collect only for the purposes below, on the legal basis stated for each.
- Processing your audio and delivering results — uploaded files, filename and length, job records. Basis: performance of a contract (PIPA Art. 15(1)4, GDPR Art. 6(1)(b))
- Identifying your account and keeping you signed in — Google account email, name and identifier. Basis: performance of a contract
- Settling credits, reconciling payments, handling refunds — credit ledger, payment records, refund requests. Basis: performance of a contract · legal obligation (Korean E-Commerce Act Art. 6, GDPR Art. 6(1)(c))
- Checking results when a refund is requested — low-quality copies (14 days). Basis: legitimate interest — verifying defects and preventing refund abuse (PIPA Art. 15(1)6, GDPR Art. 6(1)(f))
- Preventing abuse and keeping the service secure — job records, credit ledger. Basis: legitimate interest
- Answering enquiries — the address and content of your email. Basis: performance of a contract · legitimate interest
Uploaded files and results are not used to train AI models, and are not used for marketing, statistics or profiling. We do not ask for marketing consent and do not send marketing email.
3Retention and Destruction
- Uploaded originals and results — 24 hours after processing finishes, then deleted automatically.
- Low-quality copies (192 kbps MP3) — 14 days, for refund review, then deleted automatically. Opened only when a refund has been requested.
- Account information and usage records — for as long as the account exists.
- Transaction records — payment, refund, credit-ledger and terms-acceptance records are kept for 5 years under Article 6 of the Korean E-Commerce Act; consumer complaint and dispute records such as refund requests and enquiries for 3 years. These periods apply even if you delete your account.
How we destroy data. An automatic job runs every 15 minutes and deletes files past their period from storage — they cannot be recovered. Database records are deleted when their retention period ends. We produce no paper copies.
Deleting your account. On request we delete identifying account data such as email and name and permanently block sign-in. Only records we are legally required to keep remain, in a form that no longer identifies you, for the periods above. Remaining credits are refunded under the Terms.
Verdicts from the discontinued AI Music Detection tool remain in usage records; audio uploaded to that tool was deleted right after analysis and is not retained.
4Processors and Transfers Abroad
We entrust processing to the providers below, all of which are outside Korea (United States). Each processes data only for the purpose entrusted, under a processing agreement that binds it to those obligations.
- Cloudflare, Inc. (United States) · privacy policyData transferred · uploaded originals, results, low-quality copiesWhen and how · sent over encrypted connections at upload and when processing finishesPurpose · file storageRetention · originals and results 24 hours, low-quality copies 14 days
- Modal Labs, Inc. (United States) · privacy policyData transferred · the audio file being processed, job identifierWhen and how · sent when processing startsPurpose · audio processing compute (GPU)Retention · deleted as soon as processing ends (transient)
- Supabase, Inc. (United States) · privacy policyData transferred · account information, usage records, credit ledger, payment and refund recordsWhen and how · stored at sign-up and during usePurpose · database and sign-in authenticationRetention · the periods in Section 3
- Vercel, Inc. (United States) · privacy policyData transferred · request data (IP address, browser information and similar operational logs)When and how · whenever the site is accessedPurpose · web hostingRetention · operational logs for a short period (per Vercel's policy)
- Zoho Corporation (United States) · privacy policyData transferred · the sender address and content of enquiry emailWhen and how · when email is sent or receivedPurpose · sending and receiving enquiry emailRetention · 3 years after the enquiry is handled (consumer complaint and dispute records)
Basis for the transfers. They are necessary to perform the service contract with you (PIPA Art. 28-8(1)3, GDPR Art. 6(1)(b)). We do not rely on separate consent.
Safeguards. Data processing agreements (DPAs) with Cloudflare, Vercel, Supabase and Modal apply, and for data of EEA and UK users the EU Standard Contractual Clauses and the UK transfer addendum contained in those agreements apply. Zoho applies the safeguards in its own privacy policy and terms of service.
If you do not want your data transferred. The service cannot be provided without these transfers, so you may choose not to use it. You can ask for data already transferred to be deleted as described in Section 6, and account deletion is handled under Section 3.
5Disclosure to Third Parties
The two companies below are not our processors; they are independent controllers that process personal data on their own responsibility.
- Paddle.com Market Ltd. (United Kingdom) — handles payment as the Merchant of Record. The name, email, payment method and billing country you enter on the payment screen are processed by that company under its own policy. What we pass to it is only an internal account identifier and the pack to buy. Paddle privacy policy
- Google LLC (United States) — at sign-in you authenticate directly with Google. We give Google no personal data. Google privacy policy
Otherwise we do not disclose or sell personal data to third parties. The only exception is a lawful request from a law-enforcement or other authority that we are legally required to answer.
6Your Rights and How to Exercise Them
You may ask to access, correct or delete your personal data, to restrict its processing, and to withdraw consent. EEA and UK users additionally have the rights to data portability and to object to processing.
- Send requests to support@letheaudio.com. Writing from the Google account email you sign in with is the quickest way for us to verify you.
- We act within 10 days of the request. If that is unavoidably delayed, we tell you why and when to expect a response.
- A legal representative or someone you authorise may make the request for you; please include evidence of that authority.
- If we must refuse a request (for example for records we are legally required to keep), we tell you why, and you may complain to a body listed in Section 11.
California residents. We do not sell personal information or share it for targeted advertising. You may exercise your rights to know, delete and correct as described above, and we do not discriminate against you for doing so.
7Children
Children under 14 may not use the service, and we do not knowingly collect their personal data. If we learn that we have, we delete the account and the data without delay. EEA and UK users must be at least the age set by the law of their country (13 to 16).
8Automated Decisions
We make no solely automated decisions, and do no profiling, that have a significant effect on your rights or obligations. The only automated processing is in your favour — for example credits are returned automatically when a job fails.
9Security Measures
- All transfers use encrypted connections (HTTPS); storage and database providers encrypt data at rest.
- Files can only be reached through a signed temporary URL that expires after 15 minutes.
- The database enforces row-level access control (RLS), so you can see only your own records. The administrative key is used only on the server.
- The credit ledger is append-only — updates and deletes are blocked — and each row carries the hash of the previous one, so any change to past records becomes visible. It exposes tampering rather than making it impossible.
- The operator screens are reachable only by operator accounts registered in the database.
- We collect no payment-method details and do not store the raw messages the payment company sends; only the values we need are kept.
- Visitor counting stores neither IP addresses nor cookies.
10Cookies and Browser Storage
We use no advertising or behavioural-tracking cookies and have added no third-party analytics. The following is everything we use.
- Sign-in session cookie — a strictly necessary cookie set by our authentication provider (Supabase) to keep you signed in. It is cleared when you sign out; blocking it means you cannot sign in.
- Browser storage —
lethe.visit.dayandlethe.visit.skip(a date marker so a repeat visit from the same browser is counted only once a day) andletheplayer.lang(the player’s display language). They hold nothing that identifies you and never leave your browser.
You can clear or block cookies and storage in your browser settings.
11Where to Complain
You may report or seek advice on a privacy violation from the bodies below. If you are unhappy with how we handle your data, please contact us first (Section 12) and we will answer in good faith.
- Personal Information Dispute Mediation Committee (Korea) — 1833-6972, kopico.go.kr
- Privacy Infringement Report Center, KISA (Korea) — 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation (Korea) — 1301, spo.go.kr
- National Police Agency, Cyber Bureau (Korea) — 182, ecrm.police.go.kr
- EEA residents — the data protection authority of your country (list at edpb.europa.eu). UK residents — the Information Commissioner’s Office (ico.org.uk).
12Privacy Officer and Contact
- Controller · 레테오디오(LETHE AUDIO)
- Privacy officer · SEONG JEONG HWAN (owner)
- Email · support@letheaudio.com
- Phone · 070-8027-4438
- Address · 울산광역시 남구 대학로 84-1, 2층 215-1호
Send requests to access, correct or delete your data, complaints, and requests for redress to the contact above.
13Changes to This Policy
When this policy changes, we notify you by updating the “last revised” date and the revision history below. Changes that materially affect your rights are posted at least 7 days before they take effect.
- 6 September 2026First published.