Thinkfree Developers Privacy Policy
Language. This Privacy Policy is originally prepared in English. Translations into other languages may be provided for convenience only. In the event of any conflict, discrepancy, or inconsistency between the English version and any translated version, the English version shall prevail, to the extent permitted by applicable law.
Version: 2026-09-22
Effective date: 2026-09-22
This Privacy Policy explains how Thinkfree Inc. (Thinkfree, we, us, or our) processes personal information when you use the Thinkfree Developers website, Developer Console, documentation, Playground, application programming interfaces, Cloud Office, and related developer services (collectively, the Service).
This policy is specific to Thinkfree Developers. Other Thinkfree products and third-party services have their own privacy notices.
1. Controller and contact
Thinkfree Inc. is the controller responsible for personal information processed for the Service.
Thinkfree Inc.
5th Floor, Hancom Tower, 49 Daewangpangyo-ro 644beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do 13493, Republic of Korea
Privacy contact: contact@thinkfree.com
Chief Privacy Officer: Jihoon Park, Strategic Growth Division / Division Manager
Privacy requests and complaints: contact@thinkfree.com
The Thinkfree corporate Privacy Policy applies to other Thinkfree services.
2. Information we process
We process the following categories when you use the corresponding feature.
Account and authentication: Sign-in email, password hash, OAuth provider and provider account identifier, verified provider email, sign-in timestamps (from you or Google/GitHub).
Optional profile: Name, profile image, company email and verification status, company name, company website, job title.
Service credentials and configuration: API Key hash and protected secret, API Key name/status, storage connection key, encrypted storage credentials and settings.
Document workflow: Filename, object key or document path, uploaded document content, file metadata, viewer/editor mode, session and save lifecycle, error information.
License and service records: License request, company details supplied with the request, license status and history, required acknowledgements.
Payment and purchase records: Purchase history, subscription status, plan and credit balance, credit usage history, and billing records. Card details are processed directly by our payment provider (Paddle) and are not stored by Thinkfree.
Security and technical data: IP address, request ID, session identifier, authentication attempts, CAPTCHA records, access and error logs, browser and device information.
Communications: Email address and the contents of support, security, or service communications.
Passwords are stored as one-way hashes. Storage credentials and retrievable API Key secrets are encrypted separately. We use an OAuth access token only to obtain the verified provider profile needed for sign-in or account linking, and we do not retain the provider access or refresh token in the account database after that flow completes.
We do not intentionally collect sensitive personal information through normal account registration. Do not place sensitive or regulated personal information in documents unless Thinkfree has expressly agreed to support that use.
3. Why we process information
We process information to create and secure accounts, provide the Developer Console and APIs, open/edit/save/download documents, detect abuse and protect the Service, send transactional messages, support users, and comply with law.
To process payments and manage subscriptions. We process purchase, subscription, and credit records to fulfill purchases, manage billing and renewals, and handle refunds and disputes (legal basis: contract performance; legal obligations for tax and accounting).
Where applicable law requires consent for a separate purpose, we will request that consent separately. We do not sell personal information or use Thinkfree Developers account data for targeted advertising.
4. Customer Content and connected storage
When you connect storage, Thinkfree processes the credentials and settings needed to perform the operations you request. The source document normally remains in the connected storage, while Thinkfree Office processes working data needed to open, edit, and save it.
When you use Upload & Edit, the Service stores the uploaded document in Thinkfree-managed object storage for that workflow. The object is isolated by account and session identifiers and is scheduled for automatic deletion under the retention rule described below.
We do not use Customer Content to train a general-purpose artificial-intelligence model unless a separate feature and notice expressly says so and provides any consent required by law.
5. Retention and deletion
We keep information only for as long as needed for the purpose described above, to meet legal obligations, or to resolve security incidents and disputes. Current operational periods include:
-
Login session: expires after 96 hours without authenticated activity
-
Email verification / password reset / email sign-in setup request: link expires after 30 minutes
-
CAPTCHA challenge: expires after 5 minutes
-
Authentication rate-limit and login-throttle record: removed after one day inactive
-
Completed email-delivery outbox record: removed after 7 days
-
Upload & Edit document object: browser access expires after 24 hours
-
Production access and operational logs: generally retained for 90 days
-
Account, profile, API Key, storage connection, license, agreement, and document-workflow records: kept while active, then deleted or retained only as required
-
Payment and refund records: retained for the period required by applicable tax, accounting, and e-commerce consumer protection laws
When the purpose and required retention period end, we identify the affected records and delete or irreversibly anonymize them without undue delay, unless law requires continued retention. Backups may retain deleted information for a limited recovery cycle while access remains restricted.
6. Service providers and other recipients
We disclose information only as needed for the Service, under appropriate contractual or legal controls.
Amazon Web Services: Hosting, network delivery, object storage, security logging, backup, and transactional email
Google: OAuth authentication when you choose Google sign-in or linking
GitHub: OAuth authentication and verified-email lookup when you choose GitHub sign-in or linking
Paddle: Payment processing for plan, credit, and license purchases. Paddle acts as the merchant of record and processes payment and billing information under its own terms and privacy notice.
Storage provider selected by you: Document and metadata operations for a storage connection you configure
Professional advisers, authorities, or a successor organization: Legal compliance, protection of rights and security, or a lawful corporate transaction
Google, GitHub, Paddle, and a storage provider you select process information under their own terms and privacy notices. We do not disclose storage credentials to other Developer Console users.
7. International transfers
The production Service currently uses infrastructure in the Republic of Korea. A provider you choose, including Google, GitHub, Paddle, or a storage provider, may process information in other countries. Those countries may have different data protection laws.
When applicable law requires a transfer mechanism, Thinkfree uses legally recognized safeguards, which may include an adequacy decision, contractual protections, or the European Commission's Standard Contractual Clauses. You can contact us for information about safeguards relevant to your data.
8. Cookies and browser storage
The Developer Console uses strictly necessary session cookies for authentication, security, OAuth state, and request protection. Blocking these cookies prevents sign-in and authenticated features from working.
The Console also stores the last successful sign-in method in browser local storage so it can label the corresponding button the next time you visit. This value is not an OAuth token and you can remove it by clearing site data in the browser. We do not currently use Thinkfree Developers cookies for targeted advertising.
9. Security
We use technical and organizational safeguards designed for the nature of the information, including access controls, encryption in transit, protected storage for credentials, one-way password hashing, network restrictions, audit records, and security monitoring. No internet service can guarantee absolute security. Protect API Keys, connected-storage credentials, and generated document URLs, and notify us if you suspect unauthorized access.
10. Your choices and rights
Depending on your location, you may have rights to know, access, correct, delete, restrict, object, receive portable data, withdraw consent, and appeal or complain to a data protection authority.
You can update supported profile information and revoke or delete API Keys in the Developer Console. To request account deletion or exercise another privacy right, email contact@thinkfree.com. We may verify identity and authority before completing a request.
Residents of the European Economic Area, United Kingdom, or Switzerland can also contact their local supervisory authority. In the Republic of Korea, privacy complaints can be made through the Personal Information Infringement Report Center at 118 or the Personal Information Dispute Mediation Committee at 1833-6972.
11. Children
The Service is intended for adults and business developers. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children through the Service. Contact us if you believe a child has provided personal information.
12. Automated decisions
We use automated controls to rate-limit requests, request a CAPTCHA, block repeated failed sign-in attempts, and protect the Service. These controls can temporarily delay or block access but do not make decisions that produce legal or similarly significant effects about an individual. Contact us if you believe a security control was applied incorrectly.
13. Changes to this policy
Each revision receives a new version and effective date. We keep earlier versions available from Legal documents. If a change materially affects how we process personal information, we will provide notice through the Service, by email, or by another appropriate method before the change takes effect when required by law.
14. Questions and complaints
Send privacy questions, requests, or complaints to contact@thinkfree.com. You can also write to the address in Controller and contact.