개인정보처리방침

최종 업데이트: 2026-09-15 · 본 문서는 초안이며 법률 자문을 대체하지 않습니다.

1. 처리 원칙

ManuVera AI는 원고·참고문헌 등 사용자가 입력한 콘텐츠를 자체 서버에 영속 저장하지 않습니다(zero-retention). 작업 데이터(원고·초안·프로젝트 정보·API 키)는 사용자 브라우저(localStorage/IndexedDB)에 보관되며, 클라우드 동기화를 켜면(기본 꺼짐) 원고·프로젝트가 Supabase(본인 계정, RLS 격리)에 저장됩니다. 연구실 기능에서 멤버가 [PI에게 제출]을 직접 누른 원고 판본도 서버(Supabase)에 저장되어 해당 연구실의 연구책임자·매니저가 열람·다운로드할 수 있으며, 제출자는 언제든 회수(삭제)할 수 있습니다(제출 전에는 어떤 원고도 연구실로 공유되지 않습니다). 사용자가 저널 가이드라인 점검에서 [규정 DB에 등록]을 직접 누르면 그 저널 투고 규정에서 뽑은 사실 정보(저널명·단어 수 제한·초록 구조·참고문헌 스타일·필수 진술 등)만 서버에 저장되어 다른 사용자에게 재사용됩니다 — 규정 원문·원고·등록자 정보는 저장하지 않습니다. [URL에서 가져오기]를 누르면 서버가 그 공개 페이지를 그때 한 번 읽어 화면에 전달할 뿐 저장·기록하지 않으며, 자동 접근을 막는 사이트는 읽지 않습니다. 또한 분석 실행 시 원고·API 키는 사용자가 지정한 백엔드를 경유해 선택한 AI 제공사로 전송됩니다(백엔드는 요청 본문·키를 저장·로깅하지 않음).

2. AI 학습에 사용하지 않음

당사는 사용자가 입력한 원고·참고문헌·검토 요청 내용을 AI 모델의 학습·미세조정·평가용 데이터셋 구축에 사용하지 않습니다. 당사는 모델을 직접 학습시키지 않으며, 클라우드 동기화로 저장된 원고에 대해서도 같습니다.

제3자 AI 제공사로 전송되는 부분(제5조)은 사용자 본인 또는 소속 연구실의 API 키로 호출되므로, 해당 제공사가 이를 학습에 사용하는지는 사용자의 제공사 계정 정책·설정에 따릅니다. 당사는 학습 사용을 허용하는 어떤 설정도 요청·추가하지 않으며, 제공사 콘솔에서 학습 거부(opt-out) 또는 미학습·미보존(zero-retention) 등급을 사용하실 것을 권장합니다.

3. 운영자의 접근 범위

클라우드 동기화를 켜면 원고·분석 결과가 당사가 운영하는 Supabase 프로젝트에 저장됩니다. 이용자 사이에는 행 수준 보안(RLS)으로 격리되어 다른 이용자는 접근할 수 없습니다. 다만 당사(운영자)는 해당 저장소의 관리 권한을 보유하므로 기술적으로 접근이 가능합니다. 당사는 다음 경우에 한해 접근합니다 — ① 이용자가 요청한 장애·데이터 복구 지원 ② 보안 사고 대응 ③ 법령에 따른 요구.

원고를 당사 서버에 두지 않으려면 [설정 → 보안]에서 클라우드 동기화를 끄십시오(기본값 꺼짐). 끄면 업로드·동기화가 모두 차단되고, 이미 저장된 사본은 같은 화면에서 삭제할 수 있습니다. 검토·생성 요청을 중계하는 백엔드는 요청 본문을 저장·로깅하지 않으며, 원고가 담긴 저장소에 접근하지 않습니다 (백엔드가 다루는 것은 결제·크레딧·연구실 구성·피드백 정보입니다).

4. 수집·이용 항목

5. 제3자 전송

검토·생성 시 원고는 사용자가 지정한 백엔드를 경유해(브라우저에서 제공사로 직접 호출하는 경로는 로컬 개발 환경에서만 사용) 사용자가 선택한 AI 제공사(Anthropic·OpenAI·Google)로 전송됩니다. 백엔드는 요청 본문·원고를 저장·로깅하지 않습니다(zero-retention). 문헌 검색·DOI 검증·인용 서식 변환 시 참고문헌 문자열·검색어가 브라우저 또는 당사 백엔드를 거쳐 다음 공개 학술 DB로 전송됩니다 — CrossRef · PubMed(NCBI) · Europe PMC · OpenAlex · Semantic Scholar · arXiv · DOAJ · ORCID(전송 대상은 참고문헌 항목·제목·검색어와 논문·저자 식별자(DOI·PMID·ORCID iD)이며 원고 본문 전체가 아닙니다). 이들 DB는 대부분 국외에 소재합니다. 각 제3자의 데이터 처리 정책이 적용됩니다. 국외 이전: 분석 시 원고·입력 텍스트가 국외(미국 등 AI 제공사 소재지)로 이전될 수 있으며, 클라우드 동기화를 켜면 Supabase(호스팅 국가)로 저장·이전될 수 있습니다. 국외 이전에 동의하지 않으시면 일부 분석·동기화 기능 이용이 제한될 수 있습니다. 민감정보 주의: 원고에 환자·피험자 식별정보나 IRB 관련 개인정보가 포함된 경우 비식별 처리 후 업로드를 권장합니다.

6. 쿠키 및 분석 도구

서비스 개선과 방문 통계 파악을 위해 Google Analytics(GA4)를 사용합니다. 방문 페이지·기기·국가·유입경로 등 익명 통계(IP 익명화 적용)를 수집하며 개인을 식별하지 않습니다. 분석 쿠키는 이용자가 동의한 경우에만 설정되고(동의 전에는 쿠키 없이 익명 집계), 사이트 하단 배너에서 동의·거부를 선택할 수 있습니다. 브라우저 설정에서 쿠키를 차단하거나 Google의 차단 부가기능으로 거부할 수 있습니다. Google의 데이터 처리는 Google 개인정보처리방침을 따릅니다.

7. 보관·삭제

로컬 데이터는 사용자가 브라우저에서 직접 삭제할 수 있습니다(각 화면의 삭제 기능, 브라우저 저장소 초기화). 클라우드 동기화를 켠 경우 Supabase에 저장된 원고·프로젝트는 [설정 → 보안]의 「이 브라우저의 데이터 모두 삭제」 실행 시 함께 삭제할 수 있습니다(별도 확인을 거칩니다). 동기화를 켜지 않으면 당사 서버에 원고가 영속 저장되지 않습니다.

8. 보유·이용 기간 및 파기

파기 방법: 전자적 파일은 복구할 수 없는 방법으로 삭제합니다.

9. 만 14세 미만 아동

본 서비스는 학술 원고의 작성·검토를 위한 것으로 만 14세 미만은 이용할 수 없으며, 만 14세 미만 아동의 개인정보를 수집하지 않습니다.

10. 광고성 정보 전송

장애·정책 변경·보안 공지 등 서비스 이용에 필요한 안내는 수신동의 없이 발송할 수 있습니다. 그 밖의 광고성 정보는 사전 수신동의를 받은 경우에만 발송하며, 발송 시마다 수신거부 방법을 함께 안내합니다.

11. 개인정보 보호책임자 · 이용자 권리

개인정보 보호책임자: ManuVera 운영 책임자 · bjung@yonsei.ac.kr. 이용자는 자신의 개인정보·업로드 원고에 대해 열람·정정·삭제·처리정지를 요청할 수 있습니다(서비스 내 삭제 기능 또는 위 메일).

English — Privacy Policy

Last updated: 2026-09-15 · This is a draft and does not constitute legal advice.

1. Principles

ManuVera AI does not persistently store (zero-retention) user-entered content such as manuscripts and references on its own servers. Working data (manuscripts, drafts, project info, API keys) is kept in your browser (localStorage/IndexedDB); if you enable cloud sync (off by default), manuscripts and projects are stored in Supabase (your own account, RLS-isolated). In the lab feature, a manuscript version a member explicitly submits via [Submit to PI] is also stored on the server (Supabase) so that lab’s PI and managers can view and download it; the submitter can withdraw (delete) it at any time (nothing is shared with the lab before submission). When a user presses [Register rules in DB] on the Author Guidelines screen, only the factual information extracted from that journal’s author guidelines (journal name, word limits, abstract structure, reference style, required statements) is stored on the server for reuse by other users; the guideline text, the manuscript, and the registering user’s identity are not stored. When you press [Fetch from URL], the server reads that public page once and passes its text to your screen without storing or logging it; sites that disallow automated access are not read. During analysis, manuscripts and API keys are sent through the backend you designate to your chosen provider (the backend does not store or log request bodies or keys).

2. Not used for AI training

We do not use manuscripts, references, or review requests you enter to train, fine-tune, or evaluate AI models. We do not train models ourselves, and the same applies to manuscripts stored through cloud sync.

Content sent to third-party AI providers (Section 5) is called with your own or your lab’s API key, so whether that provider uses it for training depends on your provider account policy and settings. We neither request nor enable any setting that permits training use, and we recommend enabling opt-out or a zero-retention tier in your provider console.

3. Operator access

If you enable cloud sync, manuscripts and analysis results are stored in a Supabase project we operate. Users are isolated from one another by row-level security (RLS), so no other user can reach your data. However, we (the operator) hold administrative rights over that store and therefore have technical access. We access it only in these cases: (1) fault or data-recovery support you request, (2) security-incident response, (3) a requirement under applicable law.

To keep manuscripts off our servers, turn cloud sync off under [Settings → Security & Privacy] (it is off by default). With it off, uploads and sync are blocked entirely, and any copy already stored can be deleted on the same screen. The backend that relays review/generation requests does not store or log request bodies and does not access the manuscript store (it handles payment, credit, lab-membership, and feedback data).

4. Data collected

5. Third-party transfer

During review/generation, manuscripts are sent through the backend you designate (direct browser-to-provider calls are used only in local development) to the AI provider you select (Anthropic / OpenAI / Google). The backend does not store or log request bodies/manuscripts (zero-retention). For literature search, DOI verification, and citation-style conversion, reference strings and search queries are sent from your browser, or via our backend, to these public scholarly databases — CrossRef, PubMed (NCBI), Europe PMC, OpenAlex, Semantic Scholar, arXiv, DOAJ, and ORCID (what is sent is reference entries, titles, queries, and work/author identifiers such as DOI, PMID and ORCID iD — not the full manuscript body). Most of these are located outside Korea. Each third party data policy applies. Cross-border transfer: during analysis, manuscripts/inputs may be transferred abroad to the AI provider (e.g., located in the US); with cloud sync on, data may be stored/transferred to Supabase (its hosting country). If you do not consent to cross-border transfer, some analysis/sync features may be unavailable. Sensitive data: if your manuscript contains patient/subject identifiers or IRB-related personal data, we recommend de-identifying it before upload.

6. Cookies & analytics

We use Google Analytics (GA4) for service improvement and visit statistics. It collects anonymous statistics (with IP anonymization) — pages viewed, device, country, referral source — and does not identify individuals. Analytics cookies are set only with your consent (before consent, aggregation runs without cookies); you can accept or decline via the banner at the bottom of the site. You may also block cookies in your browser settings or opt out with the Google Analytics opt-out add-on. Processing by Google follows the Google Privacy Policy.

7. Retention & deletion

You can delete local data directly in your browser (delete actions on each screen, clearing browser storage). If cloud sync is enabled, manuscripts/projects stored in Supabase can be deleted under [Settings → Security & Privacy]. If sync is off, no manuscripts are persistently stored on our servers.

8. Retention periods & destruction

Method of destruction: electronic files are deleted by means that make recovery impossible.

9. Children under 14

This service is for preparing and reviewing academic manuscripts. It may not be used by anyone under the age of 14, and we do not collect personal data from children under 14.

10. Marketing messages

Notices necessary to use the service — outages, policy changes, security advisories — may be sent without separate consent. Any other promotional message is sent only with prior opt-in consent, and every such message includes instructions for opting out.

11. Data protection officer & your rights

Data protection officer: ManuVera operator · bjung@yonsei.ac.kr. You may request access, correction, deletion, or suspension of processing of your personal data and uploaded manuscripts (via in-app delete features or the email above).