Privacy Policy
Effective: September 3, 2026
critipics (the “Operator”) operates criti.pics (the “Service”) and handles your personal data as described below, in compliance with the Personal Information Protection Act of the Republic of Korea and other applicable laws.
1. Data We Collect
| Data | When | How |
|---|---|---|
| Email address, password (stored hashed), authentication identifier | Sign-up | Entered by you (Supabase Auth) |
| Google account email, name, profile picture URL | If you choose Google sign-in | Google OAuth |
| Photos you upload | Upload | Uploaded by you |
| Ratings, rating cancellations, credit balances and usage | Using the Service | Generated automatically |
| IP address, browser information, access time, request logs | Visiting the Service | Collected automatically (Cloudflare) |
| Bot-detection signals | Sign-up, upload | Cloudflare Turnstile |
EXIF metadata, including GPS location, is removed from photos before they are stored. The visual content of a photo may itself contain personal data; you are responsible for what you upload.
2. Why We Use It
- Identifying you, logging you in, and managing your account
- Providing Service features: uploads, ratings, credits
- Detecting and preventing abuse such as rating manipulation, multiple accounts, and spam
- Handling reports and enforcing the Terms of Service
- Keeping the Service stable and secure, and diagnosing failures
- Meeting legal obligations
3. Retention
- Account data, photos, ratings, credit records: deleted immediately when you delete your account. You can do this yourself from the account page. Deletion removes your photo files, related database records, and your authentication account.
- Access logs: automatically deleted within 30 days under Cloudflare’s log retention policy.
- Where law requires retention for a set period, we keep the data for that period. For example, access records for 3 months under the Korean Protection of Communications Secrets Act.
- Deleted photos stop being served immediately. A copy may remain in the browser cache of someone who already viewed it for up to one day.
4. Sharing With Third Parties
We do not share your personal data with third parties, except where required by a lawful request from a competent authority.
5. Processors and International Transfers
We use the following processors to run the Service. Their servers may be located outside Korea.
| Processor | Purpose | Data transferred | Country | Policy |
|---|---|---|---|---|
| Supabase, Inc. | Authentication and account storage | Email, hashed password, authentication identifier | [Supabase project region, e.g. United States or Singapore] | supabase.com/privacy |
| Cloudflare, Inc. | Hosting, database (D1), photo storage (R2), image transformation, CDN, bot detection (Turnstile) | Photos, rating and credit data, IP address, browser information | United States and Cloudflare’s global network | cloudflare.com/privacypolicy |
| Google LLC | Google sign-in (only if you choose it) | Google account email, name | United States | policies.google.com/privacy |
Data is transferred over the network when you use the Service. If you do not consent to these transfers you may stop using the Service and delete your account, but the Service cannot be provided without them.
6. Your Rights
You may at any time:
- Access your data: your email, credits, photos, and ratings are visible on your account pages.
- Correct your data: passwords can be reset from the login screen. For anything else, contact us below.
- Delete your data: individual photos and ratings can be deleted or cancelled within the Service; your whole account can be deleted from the account page.
- Ask us to stop processing: contact us below.
We do not knowingly collect data from children under 14.
7. Cookies and Browser Storage
To keep you logged in, the Service stores an authentication token in your browser’s localStorage. It is removed when you log out. Cloudflare Turnstile may set its own cookies for bot detection. We do not use cookies for advertising or behavioural tracking.
8. Security
- Passwords are stored one-way hashed by Supabase Auth and cannot be read by the Operator.
- All traffic is encrypted with HTTPS.
- Administrative functions are restricted to designated accounts.
- Secrets such as service keys are stored separately from code in encrypted configuration.
9. Changes
Changes to this policy will be announced within the Service at least 7 days before they take effect (30 days for material changes).