pillsang

All Catcher Chrome Extension Privacy Policy

All Catcher Chrome Extension Privacy Policy

Effective date: September 1, 2026 (first issued May 14, 2026 ยท fully revised September 1, 2026)

English

In providing the All Catcher Chrome extension (the "Extension"), Pillsang Co., Ltd. (the "Company") handles personal information lawfully and keeps it secure, in compliance with the Personal Information Protection Act of Korea and related legislation, so as to protect the freedom and rights of data subjects. Accordingly, and pursuant to Article 30 of that Act, the Company establishes and discloses the privacy policy below to explain the procedures and standards for handling personal information and to deal with related complaints promptly and smoothly.

The main body of this policy applies to every user regardless of their country of residence. California residents will find an additional notice of their rights in Article 13.

At a glance

What we collectGoogle account identifier, email address, visited URLs, AI threat-probability score
WhyHarmful-site detection and security services, handling false-positive reports, improving the AI model
How long we keep it3 years from the date of collection
Sharing with third partiesAs a rule, not shared
Processors / overseas transferNo processors / token re-verification transfer to Google (USA)
Complaints handled byManagement Support Team ยท cs@pillsang.com

Contents

  1. Purposes, items collected, and retention periods
  2. Personal information of children under 14
  3. Providing personal information to third parties
  4. Entrusting the processing of personal information
  5. Transfer of personal information abroad
  6. Destroying personal information
  7. Rights of data subjects and legal representatives, and how to exercise them
  8. Measures to keep personal information safe
  9. Devices that collect personal information automatically
  10. Behavioral information
  11. Privacy Officer and requests for access
  12. Remedies for infringement of your rights
  13. Notice for California residents (CCPA/CPRA)
  14. Changes to this privacy policy

Article 1. Purposes, items collected, and retention periods

(1) The items of personal information the Company handles, the purposes, and the retention periods are as follows.

ServicePurposeItems collectedRetention periodLegal basis
Harmful-site detection service Providing harmful-site detection and security services
Maintaining per-user detection history
Receiving and handling reports of wrong decisions
Improving the accuracy of the AI model and correcting detection errors
[Required]
Google account identifier (ID)
Email address
Visited URLs (initial URL, final URL, domain name)
AI threat-probability score
3 years from the date of collection Consent of the data subject

(2) The personal information handled is not used for any purpose other than those stated above. If the purpose of use changes, the Company will take the necessary steps, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.

(3) The Company processes and retains personal information within the retention and use period prescribed by law, or within the period consented to by the data subject at the time of collection.

Article 2. Personal information of children under 14

(1) The Extension is not directed at children under the age of 14.

(2) The Company does not knowingly collect the personal information of children under 14, and destroys such information immediately if it is confirmed that the user is under 14.

Article 3. Providing personal information to third parties

(1) The Company processes personal information only within the scope of the purposes stated above, and provides it to a third party only where the data subject has consented or where a specific provision of law applies under Articles 17 and 18 of the Personal Information Protection Act; otherwise it does not provide personal information to third parties.

(2) However, in an emergency โ€” a disaster, an infectious disease, or an incident posing an imminent risk to life or health โ€” the Company may provide personal information to the relevant authorities without the data subject's consent. In such a case the Company provides only the minimum personal information necessary under the governing law, and will not provide it for any other purpose.

Article 4. Entrusting the processing of personal information

(1) The Company currently does not entrust the processing of personal information to any outside party.

(2) Should such entrustment become necessary, the Company will disclose the entrusted work and the trustee without delay through this privacy policy.

Article 5. Transfer of personal information abroad

(1) To strengthen the security of sign-in authentication, the Company sends the user's access token to Google's authentication server to re-verify its validity. Personal information is transferred abroad in that step as follows.

RecipientCountryItemsDate and method of transferPurposeRetention period
Google LLC
(contact: googlekrsupport@google.com)
United States Access token At the moment of sign-in authentication, sent by the Company's server through an API call to Google's authentication server Re-verifying the validity of the Google account authentication token (security) Used immediately for verification and not stored separately

(2) A data subject may refuse the above overseas transfer by contacting the Company's Privacy Officer (cs@pillsang.com). Please note that refusing it may restrict the use of sign-in and harmful-site detection.

(3) Separately, during the Extension's sign-in flow there is a step in which your browser communicates directly with Google's servers to authenticate your Google account (Chrome's built-in identity feature and the Google account verification procedure). That communication takes place directly between your device and Google; the Company neither collects nor transfers that information. Any information Google receives in that step (for example, your IP address) is governed by Google's own privacy policy, not the Company's.

Article 6. Destroying personal information

(1) When personal information becomes unnecessary โ€” because the retention period has passed, the purpose has been achieved, and so on โ€” the Company destroys it without delay.

(2) Where personal information must continue to be preserved under other legislation even though the consented retention period has passed or the purpose has been achieved, the Company moves that information to a separate database or stores it in a different location.

(3) The procedure and method of destruction are as follows.

  • Procedure โ€” The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Privacy Officer.
  • Method โ€” Personal information recorded and stored in electronic files is destroyed so that the record cannot be reproduced; personal information recorded on paper is shredded or incinerated.

(4) Separately, some data such as detection history is stored in your browser's local storage (chrome.storage) in order to provide the service, and is removed together with the Extension when you delete it or clear the browser's data.

Article 7. Rights of data subjects and legal representatives, and how to exercise them

(1) A data subject may at any time exercise rights against the Company, such as requesting access to, correction of, deletion of, or a halt to the processing of their personal information.

(2) These rights may be exercised in writing, by email, by fax, and so on, pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on the request without delay.

(3) These rights may also be exercised through a representative, such as the data subject's legal representative or a duly authorized agent. In that case a power of attorney in the form of Attachment 11 to the Public Notice on the Methods of Processing Personal Information (No. 2023-12) must be submitted.

(4) A request for access or for a halt to processing may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act.

(5) Correction or deletion cannot be requested for personal information that other legislation expressly specifies as subject to collection.

(6) You may refuse consent to collection. If you do, the Extension's harmful-site detection may not work properly.

Article 8. Measures to keep personal information safe

The Company takes the following measures to keep personal information secure.

  • Administrative โ€” establishing and carrying out an internal management plan; keeping the number of staff who handle personal information to a minimum
  • Technical โ€” encryption in transit (HTTPS/TLS), access-rights management for the personal information processing system, an access control system, installing and updating security software, on-device AI inference
  • Physical โ€” access control for the server room, document storage, and similar areas
About on-device AI processing The AI inference used to judge harmful content (analysis of images on the pages you visit) runs on your own device, and the source images used for analysis are never sent to a server. However, the visited URL and the AI threat-probability score are stored on the Company's servers for detection-history management and model improvement.

Article 9. Devices that collect personal information automatically

(1) The Company does not use "cookies", which store and repeatedly retrieve information about your use.

(2) However, the Extension automatically collects and processes the following in order to provide the harmful-site detection service.

  • Through Chrome's webNavigation API, the visited URL and the AI detection result are collected automatically when you navigate to a page.
  • To block harmful content (by blurring it and so on), image content on the visited page is analyzed by AI on your own device. The image analysis runs on-device and the source images are not sent to a server.

(3) This automatic collection is technical processing essential to providing the service, and duplicate collection within a set interval for the same domain is prevented (2 minutes per domain, 30 minutes per URL). If you do not want this collection, you may disable or remove the Extension.

Article 10. Behavioral information

The Company does not collect or process users' behavioral information for online tailored advertising.

Article 11. Privacy Officer and requests for access

(1) The Company has designated the Privacy Officer below to take overall responsibility for the handling of personal information and to deal with data subjects' complaints and remedies relating to it.

(2) A data subject may submit a request for access to personal information under Article 35 of the Personal Information Protection Act to the department below. The Company will endeavour to handle such requests promptly.

RoleDepartmentName (position)Contact
Privacy OfficerManagement Support TeamKang Pilsang (CEO)cs@pillsang.com
Requests for accessManagement Support TeamKang Pilsang (CEO)cs@pillsang.com

(3) You may direct any enquiry, complaint, or request for remedy relating to privacy that arises while using the Company's services to the Privacy Officer and the department in charge. The Company will answer and act on your enquiry without delay.

Article 12. Remedies for infringement of your rights

(1) The Company works to guarantee data subjects' right to control their own personal information and to provide advice and redress for privacy infringements. Please contact the department in charge if you need to report an issue or seek advice.

(2) To seek redress for an infringement of your personal information, you may apply to the following Korean bodies for dispute resolution or advice. The telephone numbers are dialled from within Korea.

BodyTelephoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
Privacy Infringement Report Center (Korea Internet & Security Agency)118privacy.kisa.or.kr
Supreme Prosecutors' Office1301www.spo.go.kr
National Police Agency182ecrm.cyber.go.kr

Article 13. Notice for California residents (CCPA/CPRA)

This section applies to California residents and supplements the general provisions above (categories collected, purposes, and retention periods), which apply equally to California residents. It is provided pursuant to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

1. Categories of Personal Information We Collect

Category (CCPA)ExamplesCollected
IdentifiersGoogle account identifier, email address, access token (used server-side to re-verify authentication with Google)Yes
Internet or other electronic network activityVisited URLs (initial/final URL, domain), on-device AI threat-probability scoreYes
Sensitive personal informationNone collected. CCPA's definition of "sensitive personal information" is limited to specific categories (e.g., government ID numbers, precise geolocation, biometric identifiers, account log-in credentials combined with a password). We do not collect any of these.No
Geolocation, biometric, commercial, financial informationNo

2. Sources of Collection

We collect the above categories directly from your use of the Extension (via Chrome's webNavigation API and on-device AI inference). Your browser also communicates directly with Google to obtain a Google authentication token (via Chrome's built-in identity feature); this direct browser-to-Google communication is not initiated or mediated by us, and any information Google receives in that step (e.g., your IP address) is governed by Google's own privacy policy, not ours.

3. Purpose of Collection and Use

  • Detecting and blocking malicious or harmful websites
  • Maintaining per-user detection history and handling false-positive reports
  • Improving the accuracy of our on-device AI detection model

4. Disclosure, Sale, and Sharing of Personal Information

We do not sell personal information and do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.

As a security measure, our server sends your access token to Google's authentication server to re-verify its validity, as described in Article 5 (Transfer of personal information abroad) above. This is a disclosure for a business purpose (security verification with the identity provider), not a sale or share.

Note: The general provisions above also describe a limited disclosure to authorities without consent in emergencies (e.g., disasters, epidemics, imminent risk to life). Such legally-required disclosures are excluded from the definitions of "sale" and "share" under the CCPA/CPRA and do not affect the statement above.

5. Retention

Personal information described above is retained for 3 years from the date of collection, consistent with the retention period stated in the general provisions above.

6. Your California Privacy Rights

  • Right to Know โ€” the categories and specific pieces of personal information we have collected about you
  • Right to Delete โ€” deletion of personal information we have collected from you, subject to certain exceptions
  • Right to Correct โ€” correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing โ€” not applicable, as we do not sell or share personal information
  • Right to Limit Use of Sensitive Personal Information โ€” not applicable, as we do not collect sensitive personal information
  • Right to Non-Discrimination โ€” we will not deny goods or services, charge different prices, or provide a different level of quality because you exercised a CCPA right

7. Minors

The Extension is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Because we do not sell or share personal information (see Section 4), the CCPA/CPRA's opt-in requirements for the sale/sharing of minors' personal information do not apply to our processing.

8. Global Privacy Control

Because we do not sell or share personal information, honoring an opt-out preference signal such as Global Privacy Control (GPC) has no practical effect on our processing; we do not sell or share data regardless of any such signal.

9. How to Submit a Request

You may submit a verifiable consumer request via email: cs@pillsang.com. As a small business providing a free browser extension (rather than a business subject to the CCPA's toll-free-number requirement), we designate this email address as our sole and dedicated request channel.

You may also designate an authorized agent to submit a request on your behalf. We will verify your identity (or your agent's authority) using the information you provide before processing your request. We will respond within 45 days of receiving a verifiable request; this period may be extended once by an additional 45 days when reasonably necessary, with notice to you. If we deny your request in whole or in part, you may appeal by replying to our response email within a reasonable time; we will respond to your appeal within 60 days, which may be extended by an additional 45 days when reasonably necessary, with notice to you.

10. Contact / Effective Date

This California Notice was last updated on September 1, 2026. For questions, contact the Data Protection Officer at cs@pillsang.com.

Article 14. Changes to this privacy policy

(1) This privacy policy takes effect on September 1, 2026.

(2) Revision history:

  • May 14, 2026 โ€” first issued and brought into effect
  • July 2, 2026 โ€” CCPA/CPRA notice for California residents added
  • September 1, 2026 โ€” full revision (articles restructured; Korean, English, and Japanese editions provided)

(3) Earlier versions of this privacy policy are available in Korean, further down the Korean edition of this page.

(4) If anything is added, removed, or amended because of a change in law, policy, or the service itself, we will give notice on this page from seven days before the change takes effect.

Pillsang Co., Ltd. ยท Contact: cs@pillsang.com