Privacy Policy / Version 2026.09.17
Privacy Policy
Effective September 17, 2026
Sales (the “Operator”) processes only the information needed to operate ITLAND and its projects. The Operator does not sell personal information. Advertising use and external service providers are disclosed below.
1. Scope
This Policy applies to itland.site, Queue Zero, TENMATH and future projects directly provided by ITLAND. LUMIA is a read-only archive and does not provide separate registration or payment features.
2. Information processed
| ITLAND account | Username, hashed password, display name, Queue Zero callsign and friend code, registration time and most recent sign-in time. One account works across ITLAND projects, and records created while signed in are linked to the account. Email and phone number are optional and collected only when a user wants account recovery. |
|---|---|
| Play records | Game mode, score, round records, error count, device league, ranking records, friend challenge records and creation time. |
| Usage analytics | Page path, referring domain, visits, feature starts and completions, ad views, prints, PDF downloads, registration events and an anonymous visitor hash. These events provide activity points, streaks, daily missions, shared achievements, weekly summaries and next-project recommendations. A random identifier is stored in a browser cookie, while only its SHA-256 hash is retained on the server. When a user signs in, prior anonymous activity from the same browser is linked to the account. IP address and browser information are used only to create a temporary hash for daily visitor counts and are not stored in raw form in the analytics database. Problem answers, scores, camera photos and typed sentences are not included in usage analytics. |
| ITTY progression | Daily check-in dates, total experience, unlocked costumes and the currently equipped costume are stored for signed-in members. Project start and completion counts and activity points are used to check costume unlock conditions. Problem answers and conversation content are not used as progression conditions. |
| ITTY conversations | Messages entered by a user, ITTY responses, recent conversation context, current page category, the model used and random conversation and request IDs. Conversations are linked to an account when the user is signed in. Messages are sent first to the Operator’s configured local model and only sent to the OpenAI API if that connection fails. IP addresses are not stored with conversation data. Do not enter passwords, email addresses, phone numbers or other personal information. |
| Server access logs | IP address, browser information, access time and request path may be recorded in server logs for security and incident response. |
| User inquiries | When a user contacts the Operator by email, the email address, username, friend code and inquiry content that the user chooses to provide. |
3. Purposes of processing
- Account creation, sign-in, record synchronization and account recovery
- Saving game results, calculating rankings and providing friend challenges and sharing
- Providing activity points, streaks, missions, achievements, weekly summaries and personalized next actions
- Providing ITTY experience, costume rewards and the Collection through check-ins and play
- Explaining the current page and generating free-form ITTY conversation responses
- Understanding service usage and improving features
- Preventing abuse, diagnosing failures and maintaining system security
- Handling inquiries and responding to user-rights requests
4. Retention
| Account and play records | Until an account-deletion request is completed. Where retention is required by law, data is separately retained for that period and then deleted. |
|---|---|
| ITTY progression | Until an account-deletion request is completed. Deleting an account also deletes check-ins, experience, unlocks and equipped-costume information. |
| Sign-in sessions | Up to 90 days after issue or until sign-out. |
| Usage analytics | Up to 400 days. A daily visitor hash cannot be linked to the next day. The anonymous repeat-visit hash is a one-way transformation of a random cookie, and the original identifier is not stored in the database. |
| ITTY conversations | Conversation text and responses are retained to improve the service and review conversation flow and are not automatically deleted. The latest 12 messages are also kept in local storage so the same browser can continue a conversation. Usage logs containing provider, model, success state, token count and response time are retained for up to 180 days. |
| Server access logs | Rotated for up to 14 days. |
| Inquiry records | Up to three years after the inquiry is resolved, where needed to handle disputes. |
5. Third parties and service providers
The Operator does not sell personal information and does not ordinarily provide it to third parties. ITTY conversations are processed first by a local model managed by the Operator and sent to OpenAI only when that model cannot be reached. The following providers support the service.
| Amazon Web Services | Web-server and Seoul-region database hosting, data storage and system operations. |
|---|---|
| OpenAI | Generating ITTY free-form conversation responses when the local model connection fails. A user’s message, limited recent conversation and current page category are transmitted for API processing. |
| Google Gmail | Receiving and answering inquiries when a user chooses to contact the Operator by email. |
| Google AdSense | Advertising on LUMIA editorial detail pages and in the PDF download flow, frequency management, abuse prevention and ad-performance measurement. Google may process cookies or similar technologies and device or connection information. |
| Kakao AdFit | Alternative banners on LUMIA editorial detail pages and advertising in TENMATH print and PDF preparation screens, abuse prevention and ad-performance measurement. Kakao may process cookies or similar technologies and device or connection information. |
6. Browser storage
Sign-in state is maintained with an HttpOnly session cookie. Visits, conversions and repeat visits used for service improvement and progression are counted with a random HttpOnly anonymous analytics cookie retained for up to 400 days; it cannot reveal a person’s name or contact details. Recently used projects and limited activity counts are also kept in local storage to restore signed-out screens. ITTY stores first-greeting state, visited-page guidance, automatic bubble settings, a random conversation ID and the latest 12 messages in local storage. Queue Zero stores game settings, local records, offline upload queues and its sign-in token in browser local storage. TENMATH stores score, time, difficulty, correct answers by operation and print or PDF usage in the browser; when signed in, it also saves the same information to account records and the server for percentile calculation. Individual problem content and answers are not sent to the server. Clearing browser data removes local records and the recently used list. Google AdSense or Kakao AdFit may use cookies or similar technologies in LUMIA editorial and PDF download flows and in the TENMATH output-preparation flow to provide ads and prevent abuse.
7. User rights
Users may request access, correction, deletion or suspension of processing for their information. Providing the account username, registered email address or phone number, and friend code where possible helps the Operator verify identity and respond without delay. Deleting an account also deletes its profile, server play records, rankings and challenge records.
8. Users under 14
Only users aged 14 or older may create an ITLAND account. Users under 14 should not create an account or enter an email address or phone number. They may use account-free features such as TENMATH under a guardian’s supervision.
9. Security measures
- One-way password hashing and authentication-token hash storage
- HTTPS, administrator access controls and request-rate limits
- Isolation of internal API ports and restricted database access
- Review of administrator activity and server logs
10. Contact and rights requests
11. Changes to this Policy
Changes to processed information or service structure will be announced on this page before they take effect. Changes that materially affect user rights will also be announced in the service interface.