Grimoire
KOEN
SubscribeManagePaymentsLog in

Privacy Policy

Last revised: 2026-07-10

This English text is a translation provided for convenience. The Korean-language version is the official document and prevails in the event of any discrepancy.

Biblio (the “Company”) complies with the Personal Information Protection Act and other relevant laws, and collects, uses, stores, and destroys users’ personal information as described below. The Company collects only the minimum personal information necessary to provide the service.

1. Personal Information Collected

The Company uses only Google account (OAuth) login for member authentication and does not collect passwords.

  • Member information (required): email address, login provider identifier (Google), service user identifier (account unique number)
  • Payment/subscription information: payment records (payment approval number, payment method provider, payment amount/currency, payment date and time), subscription status, and coupon (pass) issuance/use history. However, payment method information such as credit card numbers is handled by the payment gateway and is not stored on the Company’s servers.
  • Bank transfer application: name, phone number, expected deposit date, and refund bank account (bank name, account number); for individuals, also nickname, channel URL, and Steam UID; for enterprises, company name, business registration number, and tax-invoice email. The refund account is collected in advance solely to process any refund.
  • Device/security information (automatically collected during service use): device identifier (HWID), device name, access IP address, and access/active session records. Used for license authentication (device-count limits) and for preventing fraudulent use and automated attacks (rate limiting).
  • For enterprise (team) license use: company name, business registration number, contact person’s name and email, and inquiry content (collected during enterprise inquiries and team seat invitations).
  • Collection methods: sign-up (Google login), payment and coupon registration/gifting, enterprise inquiry/invitation, and automatic generation during service use.

2. Purpose of Collection and Use

  • Service provision, fee payment and settlement, and management of subscription and coupon issuance/use history
  • Member identification, license and device management, customer consultation and complaint handling, and delivery of notices
  • Prevention of fraudulent use and securing service stability (blocking abnormal access/automated attacks, reconciling usage records)

3. Retention and Use Period

In principle, personal information is destroyed without delay upon a member’s withdrawal. However, where retention is required under relevant laws, and where necessary to prevent fraudulent use and respond to disputes, it is retained for a certain period as follows.

  • Records on payment and supply of goods, etc.: 5 years (Act on Consumer Protection in Electronic Commerce, etc.)
  • Records on consumer complaints or dispute handling: 3 years (Act on Consumer Protection in Electronic Commerce, etc.)
  • Access/authentication records for preventing fraudulent use and for security (license issuance/device authentication logs, etc.): until the purpose of preventing fraudulent use is achieved (up to 3 years)

Personal information whose retention period has elapsed or whose processing purpose has been achieved is destroyed without delay. The destruction procedure and method are as follows.

  • Destruction procedure: after the purpose is achieved, information that must be retained under relevant laws is stored separately, then destroyed once the retention period elapses.
  • Destruction method: personal information in electronic file form is deleted using a technical method that prevents recovery, and printed materials are shredded or incinerated.

4. Consignment of Personal Information Processing

For smooth service provision, the Company consigns personal information processing tasks to external specialized providers as below, and stipulates in the consignment contract that personal information is managed safely in accordance with relevant laws.

  • Google LLC (Firebase): member authentication and data storage/operation
  • Korea PortOne Inc. (PortOne): domestic payment processing and payment reconciliation
  • Paddle.com Market Ltd.: overseas payment processing (Merchant of Record)
  • Twilio (SendGrid): sending emails (coupon gifts, enterprise invitations, notices)
  • Cloudflare, Inc.: website hosting

5. Provision to Third Parties

The Company does not use users’ personal information beyond the scope disclosed in Article 1, nor provide it externally. The following, however, are exceptions.

  • Where the user has consented in advance
  • Where there is a legal basis, or where an investigative agency requests it in accordance with the procedures prescribed by law

6. Measures to Ensure Safety

Pursuant to Article 29 of the Personal Information Protection Act, the Company takes the following measures to ensure safety.

  • Administrative measures: minimizing personal information access rights, access control, and management of handlers
  • Technical measures: encryption of transmission sections (HTTPS), access rights control, blocking of unauthorized access/automated attacks, and inspection/reconciliation of usage records
  • Payment method information (card numbers, etc.) is not stored by the Company and is handled by a PCI-DSS compliant payment gateway.

7. Personal Information of Children Under 14

The Company does not accept membership from children under the age of 14. If it is confirmed that a child under 14 has signed up through identity theft or the like, the relevant information is destroyed without delay, and a legal representative may exercise the related rights.

8. Rights of Users and Legal Representatives and How to Exercise Them

Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information. To exercise these rights, contact the Personal Information Protection Officer below in writing, by email, etc., and the Company will act without delay.

9. Personal Information Protection Officer and Reporting Infringements

  • Personal Information Protection Officer: 한택규
  • Contact: 23rd@biblio-ent.com / 010-8558-1063

If you need to report or seek consultation about personal information infringement, you may contact the following agencies (Korea).

  • Personal Information Infringement Report Center (KISA): privacy.kisa.or.kr / 118 (no area code)
  • Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
  • National Police Agency Cyber Investigation Bureau: ecrm.police.go.kr / 182 (no area code)

This policy applies to the Grimoire service and may be revised in accordance with changes in laws or the service. Any revision will be announced in advance.

TermsPrivacy PolicyCancellation & RefundFor BusinessSupport

CONTACT US

  • Address: 경기도 용인시 처인구 금령로 75, 중앙빌딩 5층 (김량장동)
  • Phone: 010-8558-1063
  • Email: 23rd@biblio-ent.com

COMPANY INFO

  • Company: 비블리오 (Biblio)
  • CEO: 한택규
  • Business Reg. No.: 708-34-01485
  • Mail-order Sales Reg. No.: 제2026-용인처인-01490호
  • Privacy Officer: 한택규
  • Hosting Provider: Cloudflare, Inc.

Copyright © 2026 Biblio. All rights reserved.