SceltoSeoul.
Privacy

What we hold, and what never leaves your phone.

We are pre-launch, so this describes what the questionnaire and the waitlist actually do today — not what a finished product might do later. When that changes, this page changes with it.

Last updated 14 August 2026 · pre-launch

What we store

Five things — six only if you opt in on the health screen, and one more only when you choose to keep shelf notes — and nothing else:

  • Your email address — only once you reserve a place on the waitlist. You can run the analysis and read your result without giving it to us.
  • Your analysis answers, minus the health screen — how your skin behaves, your two concerns, the texture you prefer, your budget, the Seoul districts you plan to shop, your travel month, your age range, and how familiar you already are with K-beauty.
  • The skin profile we derive from them — the segment name, your budget converted to won, and a single yes/no flag saying the plan should be built conservatively.
  • The health categories you ticked — only with your separate consent — the health screen carries its own consent checkbox, apart from the email consent. Agree and we store just the category names you selected (for example “rosacea”) and the time you agreed, so your plan can exclude exactly the ingredients that matter for them. If you would rather not share, untick those boxes — nothing from that screen is sent, and the analysis continues without it.
  • Your shelf notes — only if you write them — on your account page you can mark what you actually bought and how it went: a bought checkmark, a three-way verdict, and an optional note in your own words. The note is stored encrypted, it is never shown to anyone else or published anywhere, and we use it to sharpen your own future plans. Delete it any time by clearing the field, or ask us to erase all of it.
  • Pseudonymous usage events — page views and how far through the analysis people get, tagged with a random session id your browser generates. We set no cookies for tracking, and no third-party tracking scripts run on this site.

One thing rides along with that last item. To prevent abuse, we also store a salted one-way hash of your IP address with these events. We cannot recover your address from it, we never store the address itself, and we use it only to refuse traffic that is hammering the site. That is why the events are pseudonymous rather than anonymous, and we would rather say so than round the claim up.

What never reaches us

One screen of the analysis asks about pregnancy and breastfeeding, skin conditions, prescription treatments, and ingredient allergies. By default, those answers are never transmitted — they are held in your browser, used there to shape the result on your screen, and discarded when you close the tab. The only thing that travels is the yes/no conservative flag above, with no reason attached to it.

The one exception is the separate opt-in described above, and it is as narrow as we could make it: category names, the consent time, and — if you named ingredients you react to — the ingredient names your browser was able to match. The sentence you typed into that field never leaves your browser: it is read on your device against a list of ingredient names, and only the names that matched are sent. Anything that matched nothing stays with you, and we are told only how many such entries there were, so your plan can admit what it could not read. Beyond that one sanctioned shape, the server refuses any submission that carries the health answers at all, rather than accepting it and stripping them out.

Why we hold it

  • To send you the skin read you asked for.
  • To tell you when we open, and to honour the launch price we promised you.
  • To improve the service — which questions people abandon, which segments people fall into, whether a page is worth keeping.

Legal basis

Consent — the checkbox beside the email field. Without it there is no row: the API refuses the submission rather than saving it and asking later. You can withdraw consent whenever you like, and withdrawing it does not undo anything that was lawful before you did.

How long

Until you unsubscribe or ask us to delete it. There is no fixed expiry and no archive kept afterwards — when the row goes, the answers and the derived profile go with it.

Stopping and deleting

To stop the emails, or to have everything we hold about you deleted, reply to any email we send you and say so. We delete the address, the answers and the profile built from them, and close the sign-in account that held them — nothing left behind.

Ask us what we hold and we will tell you, in the same way. These are your rights under Korean personal-information law and, if you are in the EU or UK, under the GDPR.

Who else sees it, and where they are

Three companies process data on our instructions, and no one else does. None of them is a Korean company, though the database itself runs on servers in Seoul — so your stored answers stay in Korea, while serving the site and delivering email happen abroad. Korean law asks us to name them here, and we do:

  • Supabase Pte. Ltd (privacy@supabase.io) — the database host. Stores the rows: your email address, your analysis answers, the profile derived from them, and, only with the health-screen consent, the categories you ticked, the time you agreed, and the ingredient names your browser matched. It holds them until you ask us to delete them. The servers are in Seoul; the company is incorporated in Singapore.
  • Vercel Inc. (privacy@vercel.com) — the site host. Serves these pages and receives your submission on its way through, so it sees your IP address in the request itself; what reaches the database is only the hash. It processes from the United States, and keeps request logs only.
  • Plus Five Five, Inc., doing business as Resend (privacy@resend.com) — the email service. Delivers our mail, so it handles your address and the message we send you. Nothing from the health screen is in that message. It processes from the United States, and holds the address for as long as the sending record exists.

All of it travels over encrypted connections, at the moment you load a page and at the moment you submit. If you would rather no foreign company handled your data, we cannot run the service for you — there is no path through it that avoids them. Reply to any email from us and we will delete what we hold; that is the whole of the refusal, and the effect is that we keep nothing further and send you nothing.

What we never do

We do not sell, rent or trade your data. We run no advertising and carry no ad-network pixels. We do not buy data about you elsewhere and join it to what you told us. Brands cannot pay to reach you through us — the same rule that governs how we are paid.

Changes

The service is young and this page will move with it. The date at the top is the honest one. If a change materially affects what we do with data you already gave us, we will email you rather than quietly edit this page.