Privacy Policy
The operating team behind the “What was the first question you asked AI?” service (the “Operator”) complies with the personal-data-protection laws applicable in the jurisdictions where its users reside, and publishes this Privacy Policy to explain how it handles personal information.
Article 1 (Personal Information Collected)
Information users provide directly: the question itself (required); name or nickname (optional); nationality (optional, stored as an ISO country code); the AI tool used (optional); a message (optional); and a 4-digit password used to later delete or edit the Submission (required, stored only in encrypted/hashed form).
Information collected automatically: IP address; the timestamp of submission.
The Operator does not collect any personal information beyond what is listed above, except that third-party advertising providers may separately collect information as described in Article 10.
Article 2 (How Personal Information Is Collected)
Personal information is collected when a user directly enters it on the Submission screen; IP address is generated and collected automatically as part of accessing the Service.
Article 3 (Purpose of Processing)
1. Public archiving and display of Submissions (name/nickname, nationality, AI tool, message, and question).
2. Verifying identity when a user requests deletion or editing (via Deletion ID and password).
3. Preventing abuse and operating the Service (e.g., using IP address to limit repeated or abusive submissions).
4. Producing statistics and improving the Service through de-identified analysis.
5. Providing advertising (see Article 10).
Article 4 (Retention Period)
1. Question, name/nickname, nationality, AI tool, and message: because the Service exists to publicly archive these records, they are kept indefinitely — with no fixed retention period — unless the user requests deletion. By submitting, users agree to this. After 2029-01-01, the Service will stop accepting new Submissions, but previously published Submissions will continue to be archived and displayed.
2. Password (hashed): retained together with the Submission and deleted when the Submission is deleted.
3. Deletion ID: stored in the user's browser (local storage) and no longer shown on that device after 10 minutes; the server retains it together with the Submission.
4. IP address: deleted, or de-identified so it can no longer identify anyone, one year after collection.
Article 5 (Sharing With Third Parties)
The Operator does not share personal information with third parties beyond the scope described in Articles 1 and 3, except: (1) where the user has already consented (e.g., public display of information the user agreed to publish), or (2) where required by law or by a lawful request from an investigative authority following the procedures set out in applicable law.
Article 6 (Outsourcing and Cross-Border Transfer)
1. The Operator outsources database and server infrastructure to Supabase, Inc., which hosts and stores data in the United States (AWS us-east-1, Northern Virginia).
2. As a result, personal information is transferred to and processed in the country where this provider stores data. The Operator takes appropriate contractual and technical measures to keep personal information secure when engaging such providers.
3. Where a user's country of residence differs from the country where data is stored, this transfer may constitute a “cross-border transfer” under that user's local law. Where local law requires separate notice or consent for such a transfer, the Operator complies with that requirement.
Article 7 (Rights of Data Subjects)
1. Users may request access to, correction of, or deletion of their Submission at any time.
2. To exercise this right, email your Deletion ID together with your name or nickname to firstAIquestion@gmail.com.
3. The Operator will act on verified requests without undue delay and may request additional verification where identity cannot otherwise be confirmed.
4. If a user has lost their deletion password, the Operator may assist after an alternative identity-verification process; deletion may not be possible if identity cannot be confirmed.
Article 8 (Destruction of Personal Information)
1. The Operator destroys personal information without delay once its retention period has elapsed or its processing purpose has been achieved, except for the archived Submission content described in Article 4, which is retained without a fixed period as part of the Service's core purpose.
2. Electronic files are deleted using methods that make them permanently unrecoverable.
3. The deletion password is stored only as a one-way hash and is never stored in plain text.
Article 9 (Security Measures)
1. Encryption of the deletion password: the 4-digit password is hashed with bcrypt before storage; no one, including the Operator, can retrieve the original password.
2. Access control: direct access to the database is minimized, and Submissions are created and read only through predefined server-side procedures.
3. Data minimization: only the personal information necessary to provide the Service is collected.
Article 10 (Cookies and Similar Technologies)
1. Essential local storage: the Operator uses browser local storage for essential functionality — for example, storing a Deletion ID and submission time on the user's device so it can be shown again within 10 minutes, or to prevent duplicate submissions. This data stays on the user's device, is never sent to the Operator's server, and can be cleared at any time through browser settings.
2. Advertising cookies: the Operator may use third-party advertising services such as Google AdSense. These providers may use cookies to independently collect information such as browsing activity and device information in order to serve personalized ads.
– Users may opt out of personalized advertising via Google's Ads Settings (https://adssettings.google.com).
– Users may block or delete cookies through their browser settings; doing so may limit some features of the Service.
– See Google's policy on advertising cookies at https://policies.google.com/technologies/ads.
Article 11 (Children Under 14)
Users under the age of 14 may not use the Service, and the Operator does not knowingly collect personal information from children under 14. If it becomes known that a Submission was made by a child under 14, the Operator will delete it without delay in accordance with applicable law.
Article 12 (Data Protection Contact)
Data Protection Contact: SW Cho / Operator
Email: firstAIquestion@gmail.com
Article 13 (Remedies for Rights Violations)
Users may contact the personal-data-protection authority in their own country or region for consultation or to file a complaint. As a general principle: (1) please first contact the Operator (Article 12) to try to resolve the issue directly; (2) if that is not possible, users may file a report with their local data protection authority (for example, the Personal Information Protection Commission in the Republic of Korea, or the relevant supervisory authority in the EU).
Article 14 (Changes to This Policy)
This Privacy Policy may be revised to reflect changes in law, policy, or security technology. Any changes will be announced on the Service at least 7 days before taking effect.