This English translation is provided for convenience. In case of any discrepancy, the Korean version prevails.
Life Lab (인생연구소) (the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (Korea) (개인정보 보호법, the “PIPA”) and Article 31 of its Enforcement Decree, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
This Policy applies to the services provided on “LifeHealer” (lifehealer.co, the “Site”) operated by the Company. The Site may operate various program brands, including Binge Eating Lab, and this Policy also applies to the processing of personal information in connection with those programs.
Effective date: April 18, 2026
Table of Contents
- Purposes of Processing Personal Information
- Personal Information We Process
- Processing and Retention Period of Personal Information
- Provision of Personal Information to Third Parties
- Outsourcing of Personal Information Processing
- Cross-Border Transfer of Personal Information
- Procedures and Methods for Destroying Personal Information
- Rights and Obligations of Data Subjects and Legal Guardians, and How to Exercise Them
- Installation, Operation, and Refusal of Automatic Collection Devices
- Measures to Ensure the Security of Personal Information
- Privacy Officer
- Remedies for Infringement of Data Subjects' Rights
- Processing of Personal Information of Children Under 14
- Changes to This Privacy Policy
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than the following, and if the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of the PIPA.
1. Membership registration and management
The Company processes personal information to confirm the intent to register, identify and authenticate Members for membership-based services, maintain and manage membership status, prevent fraudulent use of the Service, send various notices, and handle grievances.
2. Provision of digital content and consulting services
The Company processes personal information to provide e-books (digital content), provide group consulting and 1:1 personalized consulting programs, operate the student community, operate the 1:1 question board, provide content, and provide personalized services.
3. Payment and settlement for goods or services
The Company processes personal information for payment for goods, payment and settlement of fees, refund processing, and issuance of tax invoices.
4. Customer support and complaint handling
The Company processes personal information to confirm inquiries, contact and notify data subjects for fact-finding, and communicate results.
5. Marketing and advertising (with optional consent)
The Company processes personal information to develop new services and provide personalized services, provide event and advertising information and opportunities to participate, verify the effectiveness of services, identify access frequency, and compile statistics on Members' use of the Service. Processing for this purpose is carried out only with the data subject's separate consent.
Article 2 (Personal Information We Process)
The Company processes the following items of personal information.
1. Items collected for membership registration and use of the Service
- Email sign-up: name, email address, password (stored encrypted)
- Kakao social login: Kakao account (email), Kakao member unique identifier, profile information (nickname, profile photo)
2. Items collected at payment
Payment method information is processed through the payment gateway provider (Toss Payments). The Company receives and retains only the minimum information necessary for payment processing, such as the payment approval result and payment method identification information. Sensitive payment information such as card numbers, expiration dates, passwords, and CVC codes is not stored on the Company's servers.
3. Items automatically generated and collected during use of the Service
IP address, cookies, service usage records, access logs, device information (browser type, OS information), records of improper use
4. Items collected for customer support and complaint handling
Name, email, mobile phone number, contents of the inquiry
5. Processing of sensitive information (with separate consent)
Given the nature of the Company's services, data subjects may voluntarily write and provide health-related information about themselves (binge eating experiences, eating-related conditions, psychological and emotional states, etc.) when writing reviews, asking 1:1 questions, or using consulting. Such information may constitute sensitive information under Article 23 of the PIPA, and the Company collects and uses it only with the data subject's separate consent.
- Items collected: health-related information (binge eating experiences, eating-related conditions, psychological and emotional states, etc.) written directly by the data subject in reviews, 1:1 questions, or consulting
- Purpose of collection: posting reviews, answering 1:1 questions, providing consulting services
- Retention and use period: until membership withdrawal or withdrawal of consent (author information is anonymized upon withdrawal)
- Right to refuse consent: Data subjects may refuse consent to the collection and use of sensitive information. Refusal does not restrict use of the Service, including membership registration and content purchases; however, the review and 1:1 question features will be unavailable.
Such information is never used for any purpose other than the above and is not provided to third parties.
[Collection methods]
- Direct entry by users through website registration, service applications, the inquiry board, email, telephone, etc.
- Automatic collection through Kakao social login
- Collection of information automatically generated during use of the Service
Article 3 (Processing and Retention Period of Personal Information)
① The Company processes and retains personal information within the retention and use period prescribed by law or agreed to by the data subject at the time of collection.
② The processing and retention periods for each category of personal information are as follows.
1. Membership registration and management: until membership withdrawal
However, in the following cases, the information is retained until the relevant matter is concluded.
- Where an investigation or inquiry into a violation of applicable laws is in progress: until the investigation or inquiry is concluded
- Where claims or obligations arising from use of the Service remain: until they are settled
2. Provision of digital content and consulting services: until the service is fully supplied
However, where retention is required by applicable laws, the information is retained until the end of that period.
3. Mandatory retention under applicable laws
| Information retained | Retention period | Legal basis |
|---|
| Records on contracts or withdrawal of offers | 5 years | Act on the Consumer Protection in Electronic Commerce (Korea) |
| Records on payment and supply of goods | 5 years | Act on the Consumer Protection in Electronic Commerce (Korea) |
| Records on consumer complaints or dispute handling | 3 years | Act on the Consumer Protection in Electronic Commerce (Korea) |
| Records on labeling and advertising | 6 months | Act on the Consumer Protection in Electronic Commerce (Korea) |
| Books and supporting documents for all transactions prescribed by tax law | 5 years | Framework Act on National Taxes |
| Records on electronic financial transactions | 5 years | Electronic Financial Transactions Act |
| Website visit records (login records) | 3 months | Protection of Communications Secrets Act |
③ Re-registration policy
After withdrawing membership, you may re-register at any time with the same email address or Kakao account. However, because account information is destroyed upon withdrawal, and reviews, 1:1 questions, purchase records, and similar data are retained only after being anonymized so that the author cannot be identified (see Article 7 ④), your previous usage records will not be linked to the new account even if you re-register.
Article 4 (Provision of Personal Information to Third Parties)
① The Company processes data subjects' personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the PIPA, such as with the data subject's consent or under special provisions of law.
② The Company does not currently provide data subjects' personal information to third parties. If provision to a third party becomes necessary in the future, the Company will notify data subjects of the recipient, the recipient's purpose of use, the items of personal information provided, and the recipient's retention and use period, and obtain prior consent before providing the information.
Article 5 (Outsourcing of Personal Information Processing)
① To provide services smoothly, the Company outsources personal information processing as follows.
| Processor | Outsourced work |
|---|
| Toss Payments Co., Ltd. (주식회사 토스페이먼츠) | Payment processing, payment fraud prevention, issuance of sales slips, refund processing |
| Supabase, Inc. | Member authentication system and database hosting and management |
| Vercel Inc. | Website hosting and serverless application operation |
| Kakao Corp. (주식회사 카카오) | Kakao social login integration |
| Google LLC | Sending service emails such as notices and receipts (Gmail SMTP) |
| Functional Software, Inc. (Sentry) | Collection and analysis of service error records (for incident response) |
| Cloudflare, Inc. | Encrypted storage of backup data (for disaster recovery) |
② When entering into an outsourcing agreement, the Company specifies in the contract or other documents, in accordance with Article 26 of the PIPA, matters such as the prohibition on processing personal information for purposes other than the outsourced work, technical and administrative protection measures, restrictions on sub-outsourcing, management and supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely.
③ If the outsourced work or the processor changes, the Company will disclose the change without delay through this Privacy Policy.
Article 6 (Cross-Border Transfer of Personal Information)
① The Company transfers personal information abroad (outsourced processing and storage) as follows in order to enter into and perform its contracts with data subjects, and discloses the relevant matters under Article 28-8(1)(3)(a) and Article 28-8(2) of the PIPA.
| Category | Details |
|---|
| Recipient | Supabase, Inc. |
| Contact | privacy@supabase.com |
| Destination country | United States (region details: global infrastructure including AWS Asia-Pacific) |
| Timing and method | Transmitted as needed via information and communications networks upon registration and use of the Service |
| Items transferred | Email address, encrypted password, name, Kakao social login identifier, service usage records, IP address |
| Purpose of use | Member authentication system and database hosting and management |
| Retention and use period | Until membership withdrawal (or, where a retention period is required by applicable laws, until the end of that period) |
| Category | Details |
|---|
| Recipient | Vercel Inc. |
| Contact | privacy@vercel.com |
| Destination country | United States (global edge network) |
| Timing and method | Transmitted as needed via information and communications networks when accessing the Site and using the Service |
| Items transferred | IP address, cookies, device and browser information, service usage records |
| Purpose of use | Website hosting and content delivery (CDN) |
| Retention and use period | The period under the processor's log retention policy (generally within 30 days) |
| Category | Details |
|---|
| Recipient | Google LLC |
| Contact | https://support.google.com/policies |
| Destination country | United States |
| Timing and method | Transmitted as needed via information and communications networks (SMTP) when sending service emails such as notices and receipts |
| Items transferred | Recipient email address, name, and the order number, product name, and payment amount included in the email body |
| Purpose of use | Sending service notice emails and payment receipts |
| Retention and use period | Until deleted from the mailbox of the sending account |
| Category | Details |
|---|
| Recipient | Functional Software, Inc. (Sentry) |
| Contact | compliance@sentry.io |
| Destination country | United States |
| Timing and method | Transmitted as needed via information and communications networks when a service error occurs |
| Items transferred | Time of the error, screen, and technical information. The Company removes (masks) identifying information such as email addresses and phone numbers before transmission. |
| Purpose of use | Detection of service failures and analysis of their causes |
| Retention and use period | The period under the processor's retention policy (generally within 90 days) |
| Category | Details |
|---|
| Recipient | Cloudflare, Inc. |
| Contact | privacyquestions@cloudflare.com |
| Destination country | United States |
| Timing and method | Once a day, encrypted backup files are transmitted and stored via information and communications networks |
| Items transferred | All items collected under Article 2 (backup target data). Encrypted with AES-256 before transmission, so the processor cannot read the contents. |
| Purpose of use | Backup storage for data recovery in the event of a failure or incident |
| Retention and use period | 30 days from the date the backup is created (automatically deleted thereafter) |
② Under Articles 28-8 and 37 of the PIPA, data subjects have the right to refuse the cross-border transfer of their personal information. However, because the Service operates on the basis of the overseas outsourced processing described above, refusing the cross-border transfer may restrict membership registration and use of the Service. If you wish to refuse the cross-border transfer, you may contact the Privacy Officer listed in Article 11.
③ In connection with cross-border transfers, the Company implements the protective measures required under Article 28-8(4) of the PIPA and Article 29-10 of its Enforcement Decree (contractual safeguards, technical and administrative measures such as encryption, grievance handling procedures, etc.).
Article 7 (Procedures and Methods for Destroying Personal Information)
① When personal information becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing, the Company destroys it without delay.
② Where personal information must continue to be retained under other laws even though the retention period consented to by the data subject has expired or the purpose of processing has been achieved, the Company moves the personal information to a separate database (DB) or stores it in a different location.
③ The procedures and methods for destroying personal information are as follows.
1. Destruction procedure
The Company selects the personal information for which a ground for destruction has arisen and destroys it with the approval of the Privacy Officer.
2. Destruction method
- Information in electronic file form: deleted using a technical method that makes the records unrecoverable (e.g., permanent deletion)
- Personal information printed on paper: shredded or incinerated
④ Items retained in anonymized form after membership withdrawal
When a Member withdraws, account information is destroyed, but the records below, which have already been disclosed to other users or are needed for service operation and settlement, are retained after being anonymized so that the author cannot be identified. Once anonymized, the records cannot identify a specific individual and therefore do not constitute personal information under the PIPA.
| Retained item | Anonymization | Reason for retention |
|---|
| Reviews | Account link removed, author name masked (e.g., Kim ○○). Body text retained | Posts already disclosed to other users |
| 1:1 questions and answers | Account link removed, author name masked. Body text retained | Maintaining the answer history for the same inquiry |
| Purchase records | Account link removed, email deleted, name masked. Product name, amount, and date/time retained | 5-year retention obligation under the E-Commerce Act and the Framework Act on National Taxes |
| Consent history | Account link removed. Consent items, version, and time retained | Evidence of consent |
⑤ Even if you re-register with the same email or Kakao account after withdrawal, the anonymized records above will not be linked to the new account.
Article 8 (Rights and Obligations of Data Subjects and Legal Guardians, and How to Exercise Them)
① Data subjects may exercise the following rights against the Company at any time.
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
- Withdraw consent
② The rights under Paragraph 1 may be exercised against the Company in writing, by email, by fax, or by other means under Article 41(1) of the Enforcement Decree of the PIPA, and the Company will take action without delay (within 10 days).
③ The rights under Paragraph 1 may be exercised through an agent, such as the data subject's legal guardian or a person delegated by the data subject. In this case, a power of attorney in the form of Annex Form No. 11 of the Notice on Methods of Processing Personal Information must be submitted.
④ Requests for access to, and suspension of processing of, personal information may be restricted under Articles 35(4) and 37(2) of the PIPA.
⑤ Correction or deletion of personal information may not be requested where the personal information is specified as subject to collection under other laws.
⑥ When a request for access, correction or deletion, or suspension of processing is made, the Company verifies whether the person making the request is the data subject or a legitimate agent.
⑦ Right to refuse automated decisions and request an explanation: The Company does not currently process personal information through fully automated decision-making about data subjects (Article 37-2 of the PIPA). If such processing is introduced in the future, the Company will reflect it in this Policy, notify data subjects, and establish procedures for refusing such decisions and requesting an explanation as prescribed by law.
Article 9 (Installation, Operation, and Refusal of Automatic Collection Devices)
① The Company uses ‘cookies,’ which store and retrieve user information from time to time, in order to provide personalized services to users.
② Purpose of cookies: maintaining login status, improving the Service through analysis of service usage records, and providing personalized services.
③ Installation, operation, and refusal of cookies: Users have the option to accept or refuse cookies. By configuring browser settings, users may allow all cookies, require confirmation each time a cookie is saved, or refuse all cookies.
- Example (Chrome): [Settings] menu at the top right of the browser → [Privacy and security] → [Cookies and other site data]
- However, if you refuse cookies, use of services that require login may be restricted.
④ External fonts (Google Fonts): Some of the Site's fonts are downloaded directly by the user's browser from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), operated by Google LLC. In this process, the user's IP address and browser information may be transmitted to Google LLC (United States). The Company does not collect or store this information. You may block it using your browser's script or external request blocking features (in which case fonts will be displayed in the default typeface).
⑤ Collection and use of behavioral information and personalized advertising: The Company collects and uses behavioral information as described below only with the user's prior consent. Declining does not restrict use of the Service in any way.
| Items collected | Website visit history, products and pages viewed, checkout initiation, purchase status and payment amount, advertising identifiers, device and browser information |
| Collection method | After the user consents, via the advertising identification script installed on the website (Meta Pixel) and transmission from the Company's server (Meta Conversions API) |
| Purpose of use | Measuring advertising performance, providing ads relevant to the user's interests, and excluding those who have already purchased from repeated ads |
| Recipient | Meta Platforms, Inc. (United States) |
| Email handling | The email address used for purchase confirmation is not transmitted in its original form; it is converted to an irreversible form (SHA-256 hash) before transmission. |
| Retention and use period | Up to 180 days from collection (subject to the recipient's policy) |
⑥ How to refuse or withdraw: If you select [Do not agree] in the notice displayed on your first visit to the Site, behavioral information will not be collected. Even if you have already agreed, deleting your browser's site data (storage and cookies) resets your consent so you can choose again. You can also block personalized ads across the board in the advertising settings of the device you are using.
- Android: Settings → Privacy → Ads → Delete advertising ID
- iPhone and iPad: Settings → Privacy & Security → Tracking → turn off “Allow Apps to Request to Track”
- Web: each browser's cookie and site data blocking settings
Article 10 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information under Article 29 of the PIPA and Article 30 of its Enforcement Decree.
1. Administrative measures
- Establishing and implementing an internal management plan
- Minimizing and regularly training personnel who handle personal information
- Regular self-inspection and supervision
2. Technical measures
- Managing access rights to personal information processing systems
- Installing and operating access control systems
- One-way encrypted storage of passwords (using hash functions)
- Encryption of personal information (SSL/TLS applied in transit)
- Installing, and regularly updating and inspecting, security programs
- Retaining access records and preventing forgery or alteration
3. Physical measures
- Access control for computer rooms, data storage rooms, etc.
Article 10-2 (Notification and Reporting of Personal Information Breaches)
Under Article 34 of the PIPA and Articles 39 and 40 of its Enforcement Decree, the Company takes the following measures in the event of loss, theft, or leakage of personal information (a “Breach”).
① When the Company becomes aware of a Breach, it will, absent justifiable cause, notify the affected data subjects of the following within 72 hours in writing, by telephone, text message, email, or similar means.
- The items of personal information affected by the Breach
- When and how the Breach occurred
- Information on what data subjects can do to minimize potential harm from the Breach
- The Company's response measures and remedy procedures
- The department and contact information for reporting any harm suffered by data subjects
② If confirmation of the affected personal information is delayed and not all of the above can be specified, the Company will first notify what has been confirmed and provide the remaining information without delay as it is confirmed.
③ In any of the following cases, in addition to the notification above, the Company will report the fact and the results of its measures to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours.
- Personal information of 1,000 or more data subjects is affected by the Breach
- Sensitive information or unique identification information is affected by the Breach
- Personal information is leaked from a personal information processing system due to unlawful access from outside
④ Where individual notification is impossible, such as when the data subject's contact information is unknown, the Company substitutes notification by posting the above information on the main screen of the Site or the Privacy Policy screen for 30 days or more.
⑤ Immediately upon becoming aware of a Breach, the Company first implements measures to minimize harm, such as blocking the leakage path, guiding password resets, and revoking access rights, and the Privacy Officer under Article 11 manages and supervises the progress.
Article 11 (Privacy Officer)
① The Company designates a Privacy Officer as follows, who has overall responsibility for personal information processing and handles data subjects' complaints and remedies related to personal information processing.
▶ Privacy Officer and grievance handling contact
- Name: Raegyung Yug (육래경)
- Position: Representative
- Phone: 010-2586-3813
- Email: ceo@lifehealer.co
② Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from their use of the Company's services to the Privacy Officer. The Company will respond to and handle data subjects' inquiries without delay.
Article 12 (Remedies for Infringement of Data Subjects' Rights)
Data subjects may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the KISA Personal Information Infringement Report Center, and other bodies in order to obtain remedies for infringement of their personal information.
| Organization | Contact | Website |
|---|
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) | www.kopico.go.kr |
| Personal Information Infringement Report Center | 118 (no area code) | privacy.kisa.or.kr |
| Supreme Prosecutors' Office, Cybercrime Investigation Division | 1301 (no area code) | www.spo.go.kr |
| Korean National Police Agency, Cyber Bureau | 182 (no area code) | ecrm.police.go.kr |
A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the PIPA may file for administrative appeal as prescribed by the Administrative Appeals Act.
Article 13 (Processing of Personal Information of Children Under 14)
① As a rule, the Company does not allow children under 14 to register as members and does not collect personal information from children under 14.
② Where it is unavoidably necessary to collect personal information from a child under 14, the Company collects and uses it after obtaining the consent of the child's legal guardian under Article 22-2 of the PIPA, and may collect the minimum information from the child, such as the legal guardian's name and contact information, in order to obtain that consent.
Article 14 (Changes to This Privacy Policy)
① This Privacy Policy applies from its effective date. If there are additions, deletions, or corrections in accordance with laws or policies, the Company will announce the changes through the Site's notice board at least 7 days before they take effect.
② However, for changes that materially affect data subjects' rights, such as changes to the items of personal information collected or the purposes of use, the Company will give notice at least 30 days in advance and, where necessary, obtain the data subject's consent again.
③ Revision history
| Version | Announced | Effective | Summary |
|---|
| v2.1 | April 18, 2026 | April 18, 2026 | Removed the dormant account clause; specified the re-registration policy |
| v2.0 | April 17, 2026 | April 17, 2026 | Complete revision reflecting the April 2025 Personal Information Protection Commission drafting guidelines (new clauses on cross-border transfer, dormant accounts, automated decisions, and behavioral information) |
| v1.0 | March 18, 2026 | March 18, 2026 | Initial enactment |
Business name: Life Lab (인생연구소)
Representative: Raegyung Yug (육래경)
Business registration number: 509-03-54682
Mail-order business registration number: 2026-Daejeon Yuseong-0555 (제2026-대전유성-0555호)
Address: 50 Dunji-ro, 4F Room 402, Sugarman Work No. 157 (Dunsan-dong, Dunsan Top Class), Seo-gu, Daejeon, Republic of Korea (대전광역시 서구 둔지로 50, 4층 402호 슈가맨워크 157번(둔산동, 둔산탑클래스))
Phone: 010-2586-3813
Email: ceo@lifehealer.co