Legal
Privacy Policy
How AccountMade collects, uses, shares, retains, and protects personal data.
Effective: September 7, 2026 Version: 2026.09.07
1. Who we are
AccountMade is operated by The Plain Works Co.,Ltd., business registration number 293-87-03653, at 901-C32 126, Wolbong-ro, Seobuk-gu, Cheonan-si, Chungcheongnam-do, Republic of Korea. We are the controller of account, website, billing-support, and service-administration data. JINYONG KIM is our Privacy Lead.
For Customer Content processed on a business customer's instructions, the customer is the controller or business and we are its processor or service provider under the DPA.
2. Scope and market
This Policy covers AccountMade websites, applications, support, shared content hosted by us, and related communications. AccountMade is a business-to-business service offered only in the United States and Canada, excluding Quebec. It is not currently offered or targeted in the EU, EEA, or UK.
3. Data we collect
We collect:
- Account Data: name, business email, organization, role, authentication identifiers, settings, invitations, and consent records;
- Customer Content: sources, claims, prompts, questionnaire or RFP material, generated output, shared decks, and data selected through connected systems;
- Usage and Device Data: pages and features used, timestamps, browser and device information, IP address, approximate region, referrer, and diagnostic events;
- Integration Data: OAuth grants, scopes, object identifiers, sync status, and encrypted credentials or tokens needed for a connection;
- Billing Data: Paddle customer, subscription, invoice, tax, entitlement, credit grant, credit reservation, trial, refund, and transaction references, but not complete card or bank credentials;
- Support and Communications: messages, attachments, call or chat context, survey responses, and notification preferences; and
- Security Data: sign-in, audit, access, abuse, rate-limit, and incident records.
We obtain data from you, workspace administrators, connected systems you authorize, service providers, and normal interaction with the Service.
4. Restricted data
The Service is not designed for restricted data: protected or regulated health data; full payment-card data or bank credentials; government identifiers or identity documents; passwords, private keys, access tokens, or session secrets; biometric identifiers; precise geolocation; FCRA or GLBA regulated data; children's data; classified or export-controlled data; or highly sensitive genetic, health, or employment data. Do not submit such data unless a separate written agreement expressly approves the category and controls.
5. How we use data
We use data to provide and personalize the Service; authenticate users; sync selected systems; generate requested output; operate sharing; bill and administer subscriptions; provide support; secure, debug, and monitor the Service; prevent fraud and abuse; analyze aggregate product performance; communicate service and product information; enforce agreements; and comply with law.
Personal data is not sold. We do not share it for cross-context behavioral advertising or targeted advertising. We do not make solely automated decisions producing legal or similarly significant effects.
6. AI processing
For enabled AI features, we send the minimum necessary prompt and Customer Content to the commercial API provider identified on the Subprocessors page. Active AccountMade providers are OpenAI and Google Gemini. Neither Plain Works nor those providers may use Customer Content to train general-purpose models under our approved commercial configuration. We disable provider storage where supported and limit ordinary provider-side abuse-monitoring retention to no more than 30 days unless a verified zero-retention setting applies. Do not send restricted data through AI features.
OpenRouter is implemented as an inactive candidate routing service and will not process Customer Content unless qualification and activation are completed. Candidate requests are restricted to a named provider allowlist, disallow fallback routing, set data_collection to deny, and require a Zero Data Retention endpoint with zdr set to true. OpenRouter documents these controls in its provider-routing and Zero Data Retention documentation. We will update the active subprocessor list before enabling that route for Customer Content.
7. Analytics, cookies, and similar technologies
We use strictly necessary cookies or local storage for authentication, security, preferences, routing, and session continuity. We may use PostHog for in-product analytics and Google Analytics 4 (GA4) on public marketing and documentation pages. GA4 collection is configured without advertising personalization, Google Signals, user IDs, or intentional collection of names, email addresses, free-form content, or query-string secrets. GA4 event-level retention is set to 14 months.
Where a consent control is shown, optional analytics follows that choice. We also honor Global Privacy Control for optional analytics where technically detected. Browser Do Not Track is not a uniform legal standard. Blocking optional storage may reduce analytics but should not prevent core account functions. The former Cookie Policy is incorporated into this section.
8. How we disclose data
We disclose data only as needed to:
- infrastructure, communications, analytics, support, and AI providers listed on the Subprocessors page;
- Paddle, which independently controls payment-transaction data as merchant of record;
- customer-selected integrations and destinations under your instructions;
- professional advisers, auditors, insurers, and transaction counterparties under confidentiality duties;
- authorities or other parties when reasonably necessary to comply with law, protect rights or safety, or investigate abuse; and
- a successor in a merger, financing, reorganization, or asset transfer, subject to this Policy or notice of changed practices.
Public or bearer-link content is disclosed according to the sharing configuration selected by the customer.
9. International processing
We operate from the Republic of Korea and use providers in the United States, Korea, and global infrastructure locations. Data may therefore be processed outside your state, province, or country. We use contracts, access controls, encryption, provider due diligence, and other safeguards appropriate to the processing. Our DPA describes transfers of Customer Personal Data.
10. Retention
We retain data for the shortest period reasonably needed for the purposes above:
| Data | Normal period |
|---|---|
| Active account and workspace data | Life of the account or workspace |
| Authenticated account-deletion request | 14-day cancellation window, then scheduled deletion |
| Deleted workspace content and trash | Up to 30 days |
| Isolated backups after live deletion | Overwritten within up to 35 days |
| Security, authentication, and ordinary audit logs | 90 days, unless a contracted enterprise audit feature requires longer retention |
| Plan-dependent version history | 7 days, 90 days, 1 year, or a contracted custom period shown in the plan |
| Trial workspace recovery | Up to 30 days after trial expiry, unless converted or deleted sooner |
| GA4 event-level analytics | 14 months |
| Support records | 24 months after closure or last activity |
| DSAR export download object | 7 days |
| Billing, tax, refund, and accounting records | 5 years, or longer if mandatory law requires |
| Marketing leads with no active relationship | 24 months after last meaningful activity |
| Opt-out suppression | Minimal record while needed to honor the opt-out |
Legal holds, fraud prevention, disputes, security investigations, and mandatory recordkeeping may extend a period only for affected records. Backup copies are isolated from ordinary use and are not restored merely to recover deleted content.
11. Rights and choices
Depending on applicable U.S., Canadian, or Korean law, you may request access, correction, deletion, portability, restriction, or information about disclosures; withdraw consent where processing relies on consent; opt out of marketing; or appeal a denied request. We do not discriminate for exercising a privacy right. Authorized agents must provide authority, and we may verify identity and jurisdiction.
If the request concerns Customer Content controlled by a customer, contact that customer first; we will assist it under the DPA. Submit requests or appeals to legal@accountmade.com. You may also complain to the competent privacy regulator, including Korea's Personal Information Protection Commission or the Office of the Privacy Commissioner of Canada where applicable.
12. Security
We use access controls, encryption in transit, provider-managed encryption at rest, secret management, logging, backups, vulnerability management, and incident procedures described in the Security Overview. No system is perfectly secure. Do not send credentials or restricted data through support channels.
13. Children
AccountMade is for business users at least 18 years old. We do not knowingly collect personal data from children and do not permit customers to submit children's data.
14. Changes
We may update this Policy to reflect product, vendor, legal, or operational changes. We will post the new date and provide reasonable notice of material adverse changes where appropriate.
15. Contact
The Plain Works Co.,Ltd.
Business registration number: 293-87-03653
901-C32 126, Wolbong-ro, Seobuk-gu, Cheonan-si, Chungcheongnam-do, Republic of Korea
Privacy and rights requests: legal@accountmade.com
Support: hello@accountmade.com
Privacy Lead: JINYONG KIM