Skip to main content
AboutClassesReviews
Student Space
FAQ

Privacy Policy

Privacy Policy for the LifeHealer service operated by Life Lab (인생연구소)

This English translation is provided for convenience. In case of any discrepancy, the Korean version prevails.

Life Lab (인생연구소) (the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (Korea) (개인정보 보호법, the “PIPA”) and Article 31 of its Enforcement Decree, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

This Policy applies to the services provided on “LifeHealer” (lifehealer.co, the “Site”) operated by the Company. The Site may operate various program brands, including Binge Eating Lab, and this Policy also applies to the processing of personal information in connection with those programs.

Effective date: April 18, 2026

Table of Contents

  1. Purposes of Processing Personal Information
  2. Personal Information We Process
  3. Processing and Retention Period of Personal Information
  4. Provision of Personal Information to Third Parties
  5. Outsourcing of Personal Information Processing
  6. Cross-Border Transfer of Personal Information
  7. Procedures and Methods for Destroying Personal Information
  8. Rights and Obligations of Data Subjects and Legal Guardians, and How to Exercise Them
  9. Installation, Operation, and Refusal of Automatic Collection Devices
  10. Measures to Ensure the Security of Personal Information
  11. Privacy Officer
  12. Remedies for Infringement of Data Subjects' Rights
  13. Processing of Personal Information of Children Under 14
  14. Changes to This Privacy Policy

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than the following, and if the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of the PIPA.

1. Membership registration and management

The Company processes personal information to confirm the intent to register, identify and authenticate Members for membership-based services, maintain and manage membership status, prevent fraudulent use of the Service, send various notices, and handle grievances.

2. Provision of digital content and consulting services

The Company processes personal information to provide e-books (digital content), provide group consulting and 1:1 personalized consulting programs, operate the student community, operate the 1:1 question board, provide content, and provide personalized services.

3. Payment and settlement for goods or services

The Company processes personal information for payment for goods, payment and settlement of fees, refund processing, and issuance of tax invoices.

4. Customer support and complaint handling

The Company processes personal information to confirm inquiries, contact and notify data subjects for fact-finding, and communicate results.

5. Marketing and advertising (with optional consent)

The Company processes personal information to develop new services and provide personalized services, provide event and advertising information and opportunities to participate, verify the effectiveness of services, identify access frequency, and compile statistics on Members' use of the Service. Processing for this purpose is carried out only with the data subject's separate consent.

Article 2 (Personal Information We Process)

The Company processes the following items of personal information.

1. Items collected for membership registration and use of the Service

  • Email sign-up: name, email address, password (stored encrypted)
  • Kakao social login: Kakao account (email), Kakao member unique identifier, profile information (nickname, profile photo)

2. Items collected at payment

Payment method information is processed through the payment gateway provider (Toss Payments). The Company receives and retains only the minimum information necessary for payment processing, such as the payment approval result and payment method identification information. Sensitive payment information such as card numbers, expiration dates, passwords, and CVC codes is not stored on the Company's servers.

3. Items automatically generated and collected during use of the Service

IP address, cookies, service usage records, access logs, device information (browser type, OS information), records of improper use

4. Items collected for customer support and complaint handling

Name, email, mobile phone number, contents of the inquiry

5. Processing of sensitive information (with separate consent)

Given the nature of the Company's services, data subjects may voluntarily write and provide health-related information about themselves (binge eating experiences, eating-related conditions, psychological and emotional states, etc.) when writing reviews, asking 1:1 questions, or using consulting. Such information may constitute sensitive information under Article 23 of the PIPA, and the Company collects and uses it only with the data subject's separate consent.

  • Items collected: health-related information (binge eating experiences, eating-related conditions, psychological and emotional states, etc.) written directly by the data subject in reviews, 1:1 questions, or consulting
  • Purpose of collection: posting reviews, answering 1:1 questions, providing consulting services
  • Retention and use period: until membership withdrawal or withdrawal of consent (author information is anonymized upon withdrawal)
  • Right to refuse consent: Data subjects may refuse consent to the collection and use of sensitive information. Refusal does not restrict use of the Service, including membership registration and content purchases; however, the review and 1:1 question features will be unavailable.

Such information is never used for any purpose other than the above and is not provided to third parties.

[Collection methods]

  • Direct entry by users through website registration, service applications, the inquiry board, email, telephone, etc.
  • Automatic collection through Kakao social login
  • Collection of information automatically generated during use of the Service

Article 3 (Processing and Retention Period of Personal Information)

① The Company processes and retains personal information within the retention and use period prescribed by law or agreed to by the data subject at the time of collection.

② The processing and retention periods for each category of personal information are as follows.

1. Membership registration and management: until membership withdrawal

However, in the following cases, the information is retained until the relevant matter is concluded.

  • Where an investigation or inquiry into a violation of applicable laws is in progress: until the investigation or inquiry is concluded
  • Where claims or obligations arising from use of the Service remain: until they are settled

2. Provision of digital content and consulting services: until the service is fully supplied

However, where retention is required by applicable laws, the information is retained until the end of that period.

3. Mandatory retention under applicable laws

Information retainedRetention periodLegal basis
Records on contracts or withdrawal of offers5 yearsAct on the Consumer Protection in Electronic Commerce (Korea)
Records on payment and supply of goods5 yearsAct on the Consumer Protection in Electronic Commerce (Korea)
Records on consumer complaints or dispute handling3 yearsAct on the Consumer Protection in Electronic Commerce (Korea)
Records on labeling and advertising6 monthsAct on the Consumer Protection in Electronic Commerce (Korea)
Books and supporting documents for all transactions prescribed by tax law5 yearsFramework Act on National Taxes
Records on electronic financial transactions5 yearsElectronic Financial Transactions Act
Website visit records (login records)3 monthsProtection of Communications Secrets Act

③ Re-registration policy

After withdrawing membership, you may re-register at any time with the same email address or Kakao account. However, because account information is destroyed upon withdrawal, and reviews, 1:1 questions, purchase records, and similar data are retained only after being anonymized so that the author cannot be identified (see Article 7 ④), your previous usage records will not be linked to the new account even if you re-register.

Article 4 (Provision of Personal Information to Third Parties)

① The Company processes data subjects' personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the PIPA, such as with the data subject's consent or under special provisions of law.

② The Company does not currently provide data subjects' personal information to third parties. If provision to a third party becomes necessary in the future, the Company will notify data subjects of the recipient, the recipient's purpose of use, the items of personal information provided, and the recipient's retention and use period, and obtain prior consent before providing the information.

Article 5 (Outsourcing of Personal Information Processing)

① To provide services smoothly, the Company outsources personal information processing as follows.

ProcessorOutsourced work
Toss Payments Co., Ltd. (주식회사 토스페이먼츠)Payment processing, payment fraud prevention, issuance of sales slips, refund processing
Supabase, Inc.Member authentication system and database hosting and management
Vercel Inc.Website hosting and serverless application operation
Kakao Corp. (주식회사 카카오)Kakao social login integration
Google LLCSending service emails such as notices and receipts (Gmail SMTP)
Functional Software, Inc. (Sentry)Collection and analysis of service error records (for incident response)
Cloudflare, Inc.Encrypted storage of backup data (for disaster recovery)

② When entering into an outsourcing agreement, the Company specifies in the contract or other documents, in accordance with Article 26 of the PIPA, matters such as the prohibition on processing personal information for purposes other than the outsourced work, technical and administrative protection measures, restrictions on sub-outsourcing, management and supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely.

③ If the outsourced work or the processor changes, the Company will disclose the change without delay through this Privacy Policy.

Article 6 (Cross-Border Transfer of Personal Information)

① The Company transfers personal information abroad (outsourced processing and storage) as follows in order to enter into and perform its contracts with data subjects, and discloses the relevant matters under Article 28-8(1)(3)(a) and Article 28-8(2) of the PIPA.

CategoryDetails
RecipientSupabase, Inc.
Contactprivacy@supabase.com
Destination countryUnited States (region details: global infrastructure including AWS Asia-Pacific)
Timing and methodTransmitted as needed via information and communications networks upon registration and use of the Service
Items transferredEmail address, encrypted password, name, Kakao social login identifier, service usage records, IP address
Purpose of useMember authentication system and database hosting and management
Retention and use periodUntil membership withdrawal (or, where a retention period is required by applicable laws, until the end of that period)
CategoryDetails
RecipientVercel Inc.
Contactprivacy@vercel.com
Destination countryUnited States (global edge network)
Timing and methodTransmitted as needed via information and communications networks when accessing the Site and using the Service
Items transferredIP address, cookies, device and browser information, service usage records
Purpose of useWebsite hosting and content delivery (CDN)
Retention and use periodThe period under the processor's log retention policy (generally within 30 days)
CategoryDetails
RecipientGoogle LLC
Contacthttps://support.google.com/policies
Destination countryUnited States
Timing and methodTransmitted as needed via information and communications networks (SMTP) when sending service emails such as notices and receipts
Items transferredRecipient email address, name, and the order number, product name, and payment amount included in the email body
Purpose of useSending service notice emails and payment receipts
Retention and use periodUntil deleted from the mailbox of the sending account
CategoryDetails
RecipientFunctional Software, Inc. (Sentry)
Contactcompliance@sentry.io
Destination countryUnited States
Timing and methodTransmitted as needed via information and communications networks when a service error occurs
Items transferredTime of the error, screen, and technical information. The Company removes (masks) identifying information such as email addresses and phone numbers before transmission.
Purpose of useDetection of service failures and analysis of their causes
Retention and use periodThe period under the processor's retention policy (generally within 90 days)
CategoryDetails
RecipientCloudflare, Inc.
Contactprivacyquestions@cloudflare.com
Destination countryUnited States
Timing and methodOnce a day, encrypted backup files are transmitted and stored via information and communications networks
Items transferredAll items collected under Article 2 (backup target data). Encrypted with AES-256 before transmission, so the processor cannot read the contents.
Purpose of useBackup storage for data recovery in the event of a failure or incident
Retention and use period30 days from the date the backup is created (automatically deleted thereafter)

② Under Articles 28-8 and 37 of the PIPA, data subjects have the right to refuse the cross-border transfer of their personal information. However, because the Service operates on the basis of the overseas outsourced processing described above, refusing the cross-border transfer may restrict membership registration and use of the Service. If you wish to refuse the cross-border transfer, you may contact the Privacy Officer listed in Article 11.

③ In connection with cross-border transfers, the Company implements the protective measures required under Article 28-8(4) of the PIPA and Article 29-10 of its Enforcement Decree (contractual safeguards, technical and administrative measures such as encryption, grievance handling procedures, etc.).

Article 7 (Procedures and Methods for Destroying Personal Information)

① When personal information becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing, the Company destroys it without delay.

② Where personal information must continue to be retained under other laws even though the retention period consented to by the data subject has expired or the purpose of processing has been achieved, the Company moves the personal information to a separate database (DB) or stores it in a different location.

③ The procedures and methods for destroying personal information are as follows.

1. Destruction procedure

The Company selects the personal information for which a ground for destruction has arisen and destroys it with the approval of the Privacy Officer.

2. Destruction method

  • Information in electronic file form: deleted using a technical method that makes the records unrecoverable (e.g., permanent deletion)
  • Personal information printed on paper: shredded or incinerated

④ Items retained in anonymized form after membership withdrawal

When a Member withdraws, account information is destroyed, but the records below, which have already been disclosed to other users or are needed for service operation and settlement, are retained after being anonymized so that the author cannot be identified. Once anonymized, the records cannot identify a specific individual and therefore do not constitute personal information under the PIPA.

Retained itemAnonymizationReason for retention
ReviewsAccount link removed, author name masked (e.g., Kim ○○). Body text retainedPosts already disclosed to other users
1:1 questions and answersAccount link removed, author name masked. Body text retainedMaintaining the answer history for the same inquiry
Purchase recordsAccount link removed, email deleted, name masked. Product name, amount, and date/time retained5-year retention obligation under the E-Commerce Act and the Framework Act on National Taxes
Consent historyAccount link removed. Consent items, version, and time retainedEvidence of consent

⑤ Even if you re-register with the same email or Kakao account after withdrawal, the anonymized records above will not be linked to the new account.

Article 8 (Rights and Obligations of Data Subjects and Legal Guardians, and How to Exercise Them)

① Data subjects may exercise the following rights against the Company at any time.

  1. Request access to personal information
  2. Request correction of errors
  3. Request deletion
  4. Request suspension of processing
  5. Withdraw consent

② The rights under Paragraph 1 may be exercised against the Company in writing, by email, by fax, or by other means under Article 41(1) of the Enforcement Decree of the PIPA, and the Company will take action without delay (within 10 days).

③ The rights under Paragraph 1 may be exercised through an agent, such as the data subject's legal guardian or a person delegated by the data subject. In this case, a power of attorney in the form of Annex Form No. 11 of the Notice on Methods of Processing Personal Information must be submitted.

④ Requests for access to, and suspension of processing of, personal information may be restricted under Articles 35(4) and 37(2) of the PIPA.

⑤ Correction or deletion of personal information may not be requested where the personal information is specified as subject to collection under other laws.

⑥ When a request for access, correction or deletion, or suspension of processing is made, the Company verifies whether the person making the request is the data subject or a legitimate agent.

⑦ Right to refuse automated decisions and request an explanation: The Company does not currently process personal information through fully automated decision-making about data subjects (Article 37-2 of the PIPA). If such processing is introduced in the future, the Company will reflect it in this Policy, notify data subjects, and establish procedures for refusing such decisions and requesting an explanation as prescribed by law.

Article 9 (Installation, Operation, and Refusal of Automatic Collection Devices)

① The Company uses ‘cookies,’ which store and retrieve user information from time to time, in order to provide personalized services to users.

② Purpose of cookies: maintaining login status, improving the Service through analysis of service usage records, and providing personalized services.

③ Installation, operation, and refusal of cookies: Users have the option to accept or refuse cookies. By configuring browser settings, users may allow all cookies, require confirmation each time a cookie is saved, or refuse all cookies.

  • Example (Chrome): [Settings] menu at the top right of the browser → [Privacy and security] → [Cookies and other site data]
  • However, if you refuse cookies, use of services that require login may be restricted.

④ External fonts (Google Fonts): Some of the Site's fonts are downloaded directly by the user's browser from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), operated by Google LLC. In this process, the user's IP address and browser information may be transmitted to Google LLC (United States). The Company does not collect or store this information. You may block it using your browser's script or external request blocking features (in which case fonts will be displayed in the default typeface).

⑤ Collection and use of behavioral information and personalized advertising: The Company collects and uses behavioral information as described below only with the user's prior consent. Declining does not restrict use of the Service in any way.

Items collectedWebsite visit history, products and pages viewed, checkout initiation, purchase status and payment amount, advertising identifiers, device and browser information
Collection methodAfter the user consents, via the advertising identification script installed on the website (Meta Pixel) and transmission from the Company's server (Meta Conversions API)
Purpose of useMeasuring advertising performance, providing ads relevant to the user's interests, and excluding those who have already purchased from repeated ads
RecipientMeta Platforms, Inc. (United States)
Email handlingThe email address used for purchase confirmation is not transmitted in its original form; it is converted to an irreversible form (SHA-256 hash) before transmission.
Retention and use periodUp to 180 days from collection (subject to the recipient's policy)

⑥ How to refuse or withdraw: If you select [Do not agree] in the notice displayed on your first visit to the Site, behavioral information will not be collected. Even if you have already agreed, deleting your browser's site data (storage and cookies) resets your consent so you can choose again. You can also block personalized ads across the board in the advertising settings of the device you are using.

  • Android: Settings → Privacy → Ads → Delete advertising ID
  • iPhone and iPad: Settings → Privacy & Security → Tracking → turn off “Allow Apps to Request to Track”
  • Web: each browser's cookie and site data blocking settings

Article 10 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information under Article 29 of the PIPA and Article 30 of its Enforcement Decree.

1. Administrative measures

  • Establishing and implementing an internal management plan
  • Minimizing and regularly training personnel who handle personal information
  • Regular self-inspection and supervision

2. Technical measures

  • Managing access rights to personal information processing systems
  • Installing and operating access control systems
  • One-way encrypted storage of passwords (using hash functions)
  • Encryption of personal information (SSL/TLS applied in transit)
  • Installing, and regularly updating and inspecting, security programs
  • Retaining access records and preventing forgery or alteration

3. Physical measures

  • Access control for computer rooms, data storage rooms, etc.

Article 10-2 (Notification and Reporting of Personal Information Breaches)

Under Article 34 of the PIPA and Articles 39 and 40 of its Enforcement Decree, the Company takes the following measures in the event of loss, theft, or leakage of personal information (a “Breach”).

① When the Company becomes aware of a Breach, it will, absent justifiable cause, notify the affected data subjects of the following within 72 hours in writing, by telephone, text message, email, or similar means.

  • The items of personal information affected by the Breach
  • When and how the Breach occurred
  • Information on what data subjects can do to minimize potential harm from the Breach
  • The Company's response measures and remedy procedures
  • The department and contact information for reporting any harm suffered by data subjects

② If confirmation of the affected personal information is delayed and not all of the above can be specified, the Company will first notify what has been confirmed and provide the remaining information without delay as it is confirmed.

③ In any of the following cases, in addition to the notification above, the Company will report the fact and the results of its measures to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours.

  • Personal information of 1,000 or more data subjects is affected by the Breach
  • Sensitive information or unique identification information is affected by the Breach
  • Personal information is leaked from a personal information processing system due to unlawful access from outside

④ Where individual notification is impossible, such as when the data subject's contact information is unknown, the Company substitutes notification by posting the above information on the main screen of the Site or the Privacy Policy screen for 30 days or more.

⑤ Immediately upon becoming aware of a Breach, the Company first implements measures to minimize harm, such as blocking the leakage path, guiding password resets, and revoking access rights, and the Privacy Officer under Article 11 manages and supervises the progress.

Article 11 (Privacy Officer)

① The Company designates a Privacy Officer as follows, who has overall responsibility for personal information processing and handles data subjects' complaints and remedies related to personal information processing.

▶ Privacy Officer and grievance handling contact

  • Name: Raegyung Yug (육래경)
  • Position: Representative
  • Phone: 010-2586-3813
  • Email: ceo@lifehealer.co

② Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from their use of the Company's services to the Privacy Officer. The Company will respond to and handle data subjects' inquiries without delay.

Article 12 (Remedies for Infringement of Data Subjects' Rights)

Data subjects may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the KISA Personal Information Infringement Report Center, and other bodies in order to obtain remedies for infringement of their personal information.

OrganizationContactWebsite
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
Personal Information Infringement Report Center118 (no area code)privacy.kisa.or.kr
Supreme Prosecutors' Office, Cybercrime Investigation Division1301 (no area code)www.spo.go.kr
Korean National Police Agency, Cyber Bureau182 (no area code)ecrm.police.go.kr

A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the PIPA may file for administrative appeal as prescribed by the Administrative Appeals Act.

Article 13 (Processing of Personal Information of Children Under 14)

① As a rule, the Company does not allow children under 14 to register as members and does not collect personal information from children under 14.

② Where it is unavoidably necessary to collect personal information from a child under 14, the Company collects and uses it after obtaining the consent of the child's legal guardian under Article 22-2 of the PIPA, and may collect the minimum information from the child, such as the legal guardian's name and contact information, in order to obtain that consent.

Article 14 (Changes to This Privacy Policy)

① This Privacy Policy applies from its effective date. If there are additions, deletions, or corrections in accordance with laws or policies, the Company will announce the changes through the Site's notice board at least 7 days before they take effect.

② However, for changes that materially affect data subjects' rights, such as changes to the items of personal information collected or the purposes of use, the Company will give notice at least 30 days in advance and, where necessary, obtain the data subject's consent again.

③ Revision history

VersionAnnouncedEffectiveSummary
v2.1April 18, 2026April 18, 2026Removed the dormant account clause; specified the re-registration policy
v2.0April 17, 2026April 17, 2026Complete revision reflecting the April 2025 Personal Information Protection Commission drafting guidelines (new clauses on cross-border transfer, dormant accounts, automated decisions, and behavioral information)
v1.0March 18, 2026March 18, 2026Initial enactment

Business name: Life Lab (인생연구소)

Representative: Raegyung Yug (육래경)

Business registration number: 509-03-54682

Mail-order business registration number: 2026-Daejeon Yuseong-0555 (제2026-대전유성-0555호)

Address: 50 Dunji-ro, 4F Room 402, Sugarman Work No. 157 (Dunsan-dong, Dunsan Top Class), Seo-gu, Daejeon, Republic of Korea (대전광역시 서구 둔지로 50, 4층 402호 슈가맨워크 157번(둔산동, 둔산탑클래스))

Phone: 010-2586-3813

Email: ceo@lifehealer.co