WorksCove ERD
Home Pricing Blog About Contact
Sign In Try It Free

Privacy Policy

Last updated: April 9, 2026

1. Overview

This Privacy Policy explains how we collect, use, retain, disclose, delete, and otherwise handle personal information when you use WorksCove ERD and related billing, support, and collaboration features.

This Policy should be read together with our Terms of Service. Where the Terms explain workspace ownership and service rules and this Policy explains data handling, both apply together.

2. Information We Collect

2.1 Account and Profile Information

  • Name, email address, username, password hash, and optional profile details.
  • OAuth provider details when you sign in through supported social login (e.g., Google, GitHub).
  • Workspace invitation and membership information, including invited email addresses and seat status.

2.2 Workspace and Project Information

  • Project data, schema content, versions, shares, workspace settings, collaboration state, and project metadata.
  • Personal usage artifacts such as edit history, collaboration tokens, and editing sessions when those features are used.

2.3 AI Assistant Information

  • When you use the AI assistant feature, your ERD schema data (such as table names, column names, data types, and relationships), project name, DBMS information, and conversation prompts are sent to our AI service provider (currently OpenAI, Inc.) to generate responses.
  • AI conversation history and suggestion logs are stored on our servers and associated with your account.
  • If you register your own AI API key, the key is stored in encrypted form and used to authenticate AI requests. When you use your own API key, the account settings and data processing policy of that AI service provider may also apply.

2.4 Billing and Payment Information

  • Subscription selections, plan changes, renewal state, cancellations, refunds, invoices, and payment history.
  • Tokenized or reference billing information provided by payment processors such as Paddle and TossPayments.
  • We do not store full payment card numbers on our own systems.

2.5 Security, Device, and Support Information

  • IP address, browser or user agent, session data, login attempt data, and security or audit logs.
  • Support inquiries, replies, and related operational communications.

2.6 Optional and Required Information

Some information (name, email, password) is required to create and maintain an account. Other information (profile details, avatar) is optional. You may decline to provide optional information; doing so will not affect core service functionality, but certain optional features may be limited.

3. How We Use Information

We use information to:

  • Provide, operate, maintain, and secure the service.
  • Enable project storage, collaboration, sharing, AI-assisted features, and workspace administration.
  • Process subscriptions, payments, invoices, refunds, taxes, and related accounting obligations.
  • Respond to support requests, troubleshoot problems, and improve the service.
  • Detect, prevent, investigate, and respond to fraud, abuse, unauthorized access, and legal violations.
  • Comply with legal, tax, accounting, security, and recordkeeping obligations.
  • Generate product analytics, improve service quality, and compile statistical metrics based on aggregated, de-identified usage data.

3.1 Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area or the United Kingdom, we process your personal information on the following legal bases under the GDPR:

  • Contract performance: Account management, service delivery, workspace operation, billing, and payment processing.
  • Legitimate interest: Security monitoring, fraud prevention, service improvement, abuse detection, and product analytics. Processing on the basis of legitimate interest is carried out within the scope of your reasonable expectations, and you may object on grounds relating to your particular situation.
  • Legal obligation: Tax recordkeeping, regulatory compliance, and law enforcement responses.
  • Consent: Marketing communications and the use of optional features such as the AI assistant. We do not use identifiable personal information, project data, or content for separate AI model training or improvement. You may withdraw consent at any time without affecting the lawfulness of prior processing.

3.2 Automated Processing

The AI assistant feature provides suggestions based on automated processing of your ERD data. These suggestions are advisory only and do not produce legal effects or similarly significant decisions affecting you. You are not subject to decisions based solely on automated processing.

4. Team Workspaces and Organizational Control

If you join or use a team workspace, the workspace owner or customer organization may control the workspace and its assets. That means:

  • Projects, versions, share assets, and other workspace resources created in a team workspace may remain available to that workspace after a member leaves or deletes an individual account.
  • Workspace owners or authorized administrators may continue to access team workspace assets as part of their legitimate administration of the workspace.
  • Deleting a member account does not necessarily require deletion of team workspace assets created during that membership.
  • For third-party personal data uploaded by a customer into a team workspace, the workspace owner or organization acts as the Controller, responsible for obtaining consent for collection and use, verifying the lawfulness of processing, and responding to data-subject rights requests. We act as a Processor or sub-processor as defined by applicable law.

5. Sharing, Disclosure, and Processing Entrustment

We do not sell personal information. We may disclose or entrust processing of information only as needed to the following categories of recipients:

  • Service providers who help us operate the platform, such as hosting and email providers.
  • Payment processors, refund handlers, and tax or accounting service providers involved in billing operations.
  • AI service providers who process data to deliver AI-assisted features.
  • Authentication providers who facilitate social login.
  • Law enforcement, regulators, courts, or other parties when disclosure is required by law or necessary to protect rights, property, users, or the service.
  • A successor entity in connection with a merger, acquisition, reorganization, or sale of assets, subject to applicable law.

The restrictions in this section apply only to identifiable personal information. Information that has been de-identified or anonymized to a point where it can no longer reasonably identify a specific individual, or aggregate or statistical information derived by combining data from multiple members, may be used for lawful purposes such as service improvement, statistical analysis, security enhancement, and market analysis. We do not attempt to re-identify such information, and we do not use identifiable personal information, project data, or content for separate AI model training or improvement.

5.1 Third-Party Service Providers

Provider Purpose Data Processed
Amazon Web Services (AWS) Cloud hosting, file storage All service data, uploaded files
OpenAI, Inc. AI assistant feature ERD schema data, project name, DBMS information, conversation prompts, user-provided AI API key (where applicable)
Paddle.com Market Ltd. Payment processing (international) Billing information, payment data
TossPayments (Korea) Payment processing (Korea) Billing information, payment data
MailPlug (Korea) Transactional email delivery Email address, name
Google LLC OAuth authentication OAuth tokens, email (if Google login is used)
GitHub, Inc. OAuth authentication OAuth tokens, email (if GitHub login is used)

6. Retention, Deletion, and De-identification

6.1 Retention Schedule

Category Retention Period Basis
Account and profile information Duration of active membership; deleted or de-identified upon account deletion Service provision
Free accounts inactive for 12 months or more Deactivated, or data deleted or de-identified, after prior notice Korean PIPA Article 39-6
Billing, payment, tax, and invoice records 5 years after the transaction Tax law (Korean Framework Act on National Taxes)
Security and audit logs 1 year Security, fraud prevention
Login attempt records 90 days Security monitoring
AI conversations and suggestion logs Deleted upon account deletion Service provision
User-provided AI API key Deleted when AI settings are deleted or upon account deletion AI request authentication
Consumer complaint and dispute records 3 years Consumer protection law (Korean E-Commerce Act)
Email verification and password reset tokens 24 hours / 1 hour respectively (auto-expire) Security
Session data 12 hours (auto-expire) Security

For free accounts that have been inactive for 12 months or more, we will notify you by email to your registered address and by in-service notification at least 30 days before the scheduled deactivation, deletion, or de-identification. The notice will include the scheduled date, the categories of data affected, and the actions you may take to avoid deactivation (such as logging in or submitting a separate retention request). If you log in to the service or submit a retention request before the scheduled date, deactivation or deletion will not be carried out.

Short-lived verification, reset, and session data may expire automatically under our security controls.

6.2 Account Deletion Conditions

  • If a paid subscription is still active, account deletion may be blocked until the subscription is canceled or has expired.
  • If you are the owner of a workspace with active members, you must remove all active members before account deletion can proceed.

6.3 What Happens When Account Deletion Is Processed

  • Access to the account is revoked immediately.
  • Personal profile fields, credentials, sessions, notification settings, and similar personal account data may be deleted or de-identified.
  • Personal usage artifacts such as personal edit history, AI conversations, AI suggestion logs, collaboration tokens, and editing sessions may be deleted or detached from your account where appropriate.
  • Support records, logs, and metadata directly tied to your account may be deleted, minimized, or de-identified where operationally and legally appropriate.

6.4 Data That May Remain After Deletion

  • Team workspace assets may remain with the workspace owner or organization under the workspace ownership policy.
  • Billing, refund, subscription-change, invoice, tax, and accounting records may be retained as required by law or legitimate business recordkeeping needs (up to 5 years).
  • Minimum audit, abuse-prevention, and security records may be retained as needed to protect the service and comply with law (up to 1 year).
  • De-identified or aggregated information that no longer reasonably identifies you may be retained.

6.5 Personal Workspaces

If a deleted account is the sole owner of a personal workspace or other owned workspace that is being closed, the related workspace data may be deleted as part of that closure.

6.6 Destruction Methods

When personal information is no longer needed and the retention period has expired, electronic records are permanently deleted using methods that prevent recovery. Physical records, if any, are shredded or incinerated.

7. Security

We use technical and organizational safeguards appropriate to the nature of the data and service, including access controls, encryption in transit, password hashing, session controls, logging, and abuse-prevention measures. No service can guarantee absolute security.

7.1 Data Breach Notification

If we become aware of a personal information breach that is likely to cause harm to users, we will notify affected individuals without undue delay as required by applicable law. The notification will include the nature of the breach, the types of information affected, and the measures taken or proposed to address it. For breaches that meet statutory reporting thresholds under Korean data-protection law (for example, leakage affecting 1,000 or more data subjects, or leakage involving sensitive information or unique identifying information), we will additionally report to the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) within 72 hours of becoming aware. For users in the EEA or the United Kingdom subject to the GDPR, we will report to the competent supervisory authority within the same time frame.

8. International Data Transfers

We may process information in countries other than the country where you reside. Specifically, personal information may be transferred to the following countries and recipients:

Recipient Country Items Transferred Purpose
OpenAI, Inc. United States ERD schema data, project name, DBMS information, AI conversation prompts, user-provided AI API key (where applicable) AI assistant feature processing
Paddle.com Market Ltd. United Kingdom / United States Billing and payment information International payment processing
Google LLC United States OAuth authentication tokens, email Social login authentication
GitHub, Inc. United States OAuth authentication tokens, email Social login authentication

We apply contractual and operational safeguards as required by applicable law to protect transferred data. Where a data processing agreement is available from the recipient, we use it.

You have the right to refuse the cross-border transfer of your personal information. You may submit your refusal to [email protected] or to the contact addresses set out in Section 13, together with documents sufficient to verify your identity. We will respond to your request within a reasonable period of receipt (ordinarily within 10 days), and the features that depend on the relevant transfers (such as the AI assistant, international payment processing, and social login) will be permanently disabled either immediately or at a time agreed with you. For paid subscriptions that include disabled features, refunds may be considered on a pro-rata basis after deducting the period already used; the specific calculation method and refund eligibility will follow the policies of the relevant payment processor and applicable law. If you withdraw your refusal, we will reactivate the affected features after a fresh consent process.

9. Your Rights and Choices

Depending on your location and applicable law, you may have rights to:

  • Access, correct, or update your personal information.
  • Request deletion of your account and personal information, subject to the limitations described in this Policy.
  • Export your project data (SQL, Excel) from within the service before cancellation or deletion.
  • Be informed of the collection and use of your personal information.
  • Opt out of marketing communications at any time. Withdrawal of marketing consent does not affect your use of the service. Transactional communications (such as billing confirmations, security alerts, and service announcements) are not considered marketing.

To exercise these rights, contact us at the addresses listed in Section 13. We will respond to your request within 10 days of receipt. Where there is a justified reason, we may extend the response period together with notice of the reason, to the extent permitted by applicable law (up to 30 days under Korean PIPA). We may request additional information for identity or authority verification, and the time during which we await your response will not count toward the response deadline. We may decline or charge a reasonable fee for requests that are manifestly unfounded, repetitive, or restricted by law, with notice of the reason.

10. Children's Privacy

The service is not directed to children under 16 years of age. Even where applicable law permits a lower minimum age of consent, we reserve the right to apply stricter age requirements at our discretion.

At sign-up we rely on the user's self-declaration and acceptance of these Terms and this Policy; we do not perform any separate age verification. You are therefore responsible for representing and warranting at sign-up that you are at least 16 years of age, and any liability arising from a false declaration rests with you or, where applicable, your parent or legal guardian.

If we learn that personal information of a child below the applicable minimum age has been collected in violation of this Policy, or if we receive a notification supported by reasonable grounds from a parent or legal guardian, we will, without undue delay, deactivate the account in question and delete or de-identify the related personal information. Parents or legal guardians may submit such a notification, together with documents sufficient to verify identity, to [email protected].

11. Cookies and Similar Technologies

We use cookies, session identifiers, and similar technologies for the following purposes:

  • Session cookies: Used to maintain your login state and session security. These expire after 12 hours of inactivity.
  • Preference cookies: Used to store your language and display preferences.
  • Security tokens: Used for CSRF protection and abuse prevention.

We do not use third-party tracking or analytics cookies.

You may configure your browser to reject cookies, but doing so may impair service functionality such as maintaining your login session.

12. Changes to This Policy

We may update this Policy from time to time. Routine changes will be communicated through the service, by email, or by posting an updated version on this page with a new effective date at least 7 days before the changes take effect. Changes that are unfavorable to members or that may have a material impact on members (such as expansion of processing purposes, extension of retention periods, expansion of third-party disclosure, or restriction of member rights) will be communicated by the same means at least 30 days before the effective date, with a clear statement of the reasons for the change and the effective date.

Your continued use of the service after the effective date will be deemed acceptance of the updated Policy. If you do not agree to the revised Policy, you may discontinue use of the service or close your account before the announced effective date, in which case we will delete or de-identify your personal information to the extent permitted by applicable law. We will treat continued use after the effective date as acceptance only where you have not expressly objected.

13. Contact Information and Dispute Resolution

13.1 Privacy Protection Officer

Name: Minwoo Jeong (정민우)

Title: CEO (대표이사)

Email: [email protected]

13.2 Contact

If you have questions about this Policy, deletion requests, billing records, or workspace ownership handling, contact us at:

Company: NewBreed Co., Ltd.

CEO: Minwoo Jeong

Business Reg. No.: 184-87-00968

E-commerce License: 2018-강원원주-00602

Customer Service: (+82) 1661-2697

Email: [email protected]

Seoul: 1138, Gasan Tera Tower, 78 Digital-ro 10-gil, Geumcheon-gu, Seoul 08517, Korea

Wonju: 401, H Tower, 19 Hyeoksin-ro, Wonju-si, Gangwon 26460, Korea

13.3 Dispute Resolution

If you believe your personal information rights have been violated, you may file a complaint with the following organizations. If you are located in the EEA or UK, you may also lodge a complaint with your local data protection authority.

  • Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회): kopico.go.kr, 1833-6972
  • KISA Privacy Violation Report Center (개인정보침해신고센터): privacy.kisa.or.kr, 118
  • Supreme Prosecutors' Office Cyber Investigation Division (대검찰청 사이버수사과): spo.go.kr, 1301
  • National Police Agency Cyber Bureau (경찰청 사이버수사국): ecrm.police.go.kr, 182
Back to Home
WorksCove ERD

Simple and powerful database design tool

Product

  • Pricing
  • App

Company

  • Blog
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy

NewBreed Co., Ltd. | CEO Minwoo Jeong | Business Reg. No.: 184-87-00968

Seoul: 1138, Gasan Tera Tower, 78 Digital-ro 10-gil, Geumcheon-gu, Seoul 08517, Korea

Wonju: 401, H Tower, 19 Hyeoksin-ro, Wonju-si, Gangwon 26460, Korea

Customer Service: (+82) 1661-2697 | Email: [email protected]

E-commerce License: 2018-강원원주-00602

English | 한국어 | 日本語

© 2026 NewBreed. All rights reserved.