← My account

MEMBER PRIVACY / member-2026-10-01-v2

Member sign-in privacy notice

Member sign-in is being prepared and does not currently collect Google account information. The notice below describes the planned service.

1. Sign-in is optional

Guests can register tester interest by product. Members can view and withdraw applications linked to their own accounts. Membership does not determine selection priority.

2. Data and purposes

Google sign-in and the authentication service may process the account identifier, verified email, basic profile such as name and profile image provided by Google, and session information. CASTLE FIVE uses a hash of the authenticated account identifier, email, membership information and ownership links to applications. To confirm consent, it also stores a hash of the confirmation identifier, notice version, a hash identifying the processing notice content, notice language, acknowledgement time and recording time. Purposes are session continuity, account verification, access to participation records and confirmation of consent.

When the first sign-in completes, membership information and the consent confirmation record are stored together for the account newly verified by that sign-in. These records are created even if you do not apply to be a tester. Consent for application processing and account linking is requested separately when applying or linking. Member identifiers and emails are not sent to visit measurement.

3. Cookies and guest application links

The service uses authentication session cookies and a consent confirmation cookie lasting up to 10 minutes. This 10-minute cookie confirms consent during sign-in; it does not define how long the consent confirmation record is retained on the server after sign-in completes. The server record follows the membership retention period below.

Guest linking cookies are encrypted; the server stores a hash and expiry instead of the original value. Linking cookies are kept for up to seven days within the linking window first opened for that product in this browser. Reapplying does not extend the window. If a window is already open, a later new application may have a shorter period available for linking. Server-side linking proof also expires within seven days of the original application and is not extended by repeat requests. Linking requires verified email, possession of the application proof and an explicit request. Matching an entered email alone does not link past applications.

4. Retention, withdrawal and erasure

CASTLE FIVE membership information, consent confirmation records and application ownership links are retained for up to 6 months from the first membership consent. Signing in again, applying or linking an application does not extend this period. Retention of the application information itself follows the registration notice. Withdrawing participation is distinct from erasing personal data.

Request account and authentication data erasure using the contact below. Deleting CASTLE FIVE membership records alone does not erase every provider account, session or backup; the outcome is confirmed after checking each processing scope. If sign-in is interrupted and a provider account is not linked to a CASTLE FIVE membership record, the account and its related sessions become eligible for cleanup 24 hours after account creation. The following hour is the processing window for scheduled checks and deletion. This is not a guarantee of physical deletion within 25 hours. If an outage or another issue delays confirmation, member sign-in is closed while verification and recovery are carried out. Separately approved system and administrator accounts required for service operation are distinguished from these temporary accounts. Ordinary members are not made exceptions to extend the six-month period from first consent. Temporary-account cleanup policy: orphan-24h-plus-1h-2026-10-03-v1. Member sign-in opens after this policy, deletion at the end of retention and backup handling are verified in the actual service.

Registration privacy notice ↗

5. Service providers and contact

The planned service uses Neon for authentication and storage, Vercel for hosting, Cloudflare for administrator access and security checks, and Google for account verification. Member sign-in opens after processing regions, processors, international transfers and authentication retention are covered by confirmed notices and settings, with deletion procedures tested in the actual service and ongoing operational checks in place.

The planned sign-up check uses a Cloudflare relay and signature verification in Neon. Cloudflare forwards the signed sign-up check request, which may contain email, the authentication account identifier and basic profile, to Neon for signature and sign-up eligibility verification. IP address and browser information may also pass through this route if the authentication provider includes them in the request body. The relay and sign-up verification application code does not log the request body or signature or retain them in storage. This does not mean that Cloudflare, Neon or other platforms have no security or network logs. Member sign-in opens after actual processing regions, processor arrangements, international transfers and retention conditions for this relay are covered by confirmed notices and tested in the actual service. This connection is currently for a private representative-only trial; public membership data collection has not been opened.

Privacy officer: 대표 정성오
Contact: [email protected]