BackendX Privacy Policy

Effective Date: September 7th, 2026 Last Updated: September 7th, 2026

BackendX Inc. (주식회사 백엔드엑스) ("Company") complies with the Personal Information Protection Act of the Republic of Korea ("PIPA") and other applicable laws.

BackendX is a software-as-a-service (SaaS) platform that enables users to generate, deploy, and manage backend services online. This Privacy Policy describes how the Company collects, uses, and protects personal information of users of the BackendX Service ("Service").

This Policy applies to users located both inside and outside the Republic of Korea.


Scope of This Policy and Processing Roles

The Company processes personal information in three distinct roles. This Policy applies in full only to the first.

  1. Platform data — the Company as controller. Personal information of Users themselves: account and billing data, user-submitted requirements and interview conversations, deployment-questionnaire and acceptance records, and usage data (Section 1). The Company determines the purposes and means of this processing, and this Policy governs it.
  2. End-User Personal Data — the Company as processor. Personal data of the end-users of a generated service deployed through the Company (Managed Hosting or Customer-Cloud (Company-Operated)) is controlled by the User who operates that service; the Company processes it only on the User's behalf under the Data Processing Agreement (the "DPA"; see Section 12 of the Terms of Use). The DPA — not this Policy — governs that processing, including its sub-processors, international transfers, retention, deletion, and breach notification. End-users should direct privacy inquiries and rights requests to the operator of the service they use; requests received by the Company are routed to that operator under the DPA. The specific scope of processing, personal-data categories, retention periods, sub-processors, and cross-border transfers are governed by the DPA between the User and the Company and by the deployment questionnaire for each project.
  3. Independent-controller exception. Solely for the security, abuse-prevention, and legal-compliance processing described in Section 10 of the Terms of Use (including reactive inspection and responses to lawful demands), the Company acts as an independent controller to the narrow extent required, subject to the safeguards described there and in Section 8 of the DPA.

Where an item described below (such as the encrypted error-event captures in Section 1.A) contains End-User Personal Data, the Company holds that data as processor under the DPA; the descriptions in this Policy are provided for transparency.


1. Purposes of Processing, Categories of Personal Information, and Retention Periods

The Company collects and uses personal information only to the minimum extent necessary to provide the Service.

A. Personal Information Processed Without the Data Subject's Consent

The Company processes the following personal information without the data subject's consent, on the legal bases stated below.

Legal BasisCategoryPurpose of ProcessingItems CollectedRetention Period
PIPA Art. 15(1)(iv) (performance of a contract)Account identification and managementAccount creation, maintenance, and management; user identification; login and authentication; management of Service access rights; account security and Service provisionEmail address; account ID and other account identifiers; login and authentication information; account creation and change recordsUntil account deletion
PIPA Art. 15(1)(iv) (performance of a contract)Registration eligibility verificationVerification of registration eligibility and age of majority under the Terms of UseAge-of-majority attestation record; time of attestation; applicable Terms versionUntil account deletion
PIPA Art. 15(1)(iv) (performance of a contract)AI-powered service generation and project managementRequirements analysis; AI interviews; specification authoring; generation of backend code, tests, and infrastructure definitions; regeneration; maintenance and management of the generated serviceUser-submitted Requirements; configuration data; text inputs; interview conversations; project settings; generation and modification instructions; task request historyUntil deletion of the associated project. This information constitutes the operating specification of the generated service and is retained while the project exists. An Account may be deleted only after the User has deleted the projects they own (Terms of Use Section 6); membership in projects owned by others is removed upon account deletion.
PIPA Art. 15(1)(iv) (performance of a contract)Deployment screening, consent, and Output delivery managementDeployment eligibility screening; review of deployment-questionnaire answers; management of acceptance of the Terms, DPA, and Billing Policy; management of the User's privacy and breach-response contacts; identification of Outputs and confirmation of delivery; dispute handlingDeployment-questionnaire answers and acceptance records with version, timestamp, and IP address; automated-classification outcomes; delivered-artifact identifiers such as commit hashes and image digestsUp to 5 years
PIPA Art. 15(1)(iv) (performance of a contract)GitHub integration and Output deliveryOptional GitHub repository integration; collaborator invitations; source-code mirroring and Output deliveryGitHub account information; GitHub user identifiers; repository collaboration and integration informationUntil the User revokes GitHub integration or deletes the account
PIPA Art. 15(1)(iv) (performance of a contract)Customer-Cloud deployment and customer-provided storage integrationProvisioning, deployment, running, monitoring, and operational assistance of the generated service in the Customer-Cloud; operation of customer-provided file-storage featuresCloud-provider information; cloud access tokens; AWS access key IDs and secret access keys; Amazon S3 access keys for the User's storage bucket; Google Cloud service-account keys or equivalent credentials; storage-bucket information; deployment configuration and permission-related information (stored in an encrypted secrets store and used only as described in the Terms of Use)Until the User deletes the credentials or deletes the associated project or account
Korea Act on Consumer Protection in Electronic Commerce Art. 6 (payment and contract records)Subscription, payment, and billing managementManagement of Subscription, Seat, and Change-Run purchases and use; payment, billing, refund, and cancellation processing; preservation of transaction recordsAccount identifiers; project, plan, Seat, and Change-Run usage records; subscription and usage records; payment and billing information; transaction identifiers; invoice and receipt information; payment status. The Company does not store full payment-card numbers; they are handled by the payment processor.5 years from the date of transaction
PIPA Art. 15(1)(iv) (performance of a contract)Service operation and usage managementService provision; task processing; measurement of usage such as API call volume and database storage; management of plan limits and overage chargesService usage records; task request history; project identifiers; subscription, plan, Seat, and Change-Run usage records; API call volume; database storage volume; other usage recordsFor the duration of Service use and the existence of the project; thereafter only for as long as necessary for statutory retention or dispute resolution
PIPA Art. 15(1)(iv) (performance of a contract)Error-event capture (deployments through the Company)Error diagnostics and the operations dashboard for the User's own project in respect of generated services deployed through the Company (Managed Hosting or Customer-Cloud (Company-Operated)) (Terms of Use Section 10.3)Metadata of error events (HTTP responses with status 400 and above) such as status code, HTTP method, route template, error fingerprint, trace identifier, and timestamp and, where necessary for error diagnostics, the request and response bodies and stack trace (credential-redacted at capture time and encrypted with a per-project key). To the extent these records contain end-user personal data of the generated service, the Company processes them as processor under the DPA.Approximately 14 days in the log store; derived incident records until project deletion
Korea Act on Consumer Protection in Electronic Commerce Art. 6Consumer complaint and dispute handlingHandling of consumer complaints, refund requests, payment disputes, and Service-related inquiries and disputesAccount identifiers; contact details such as email address; contents of inquiries, complaints, and disputes; related project, subscription, payment, and support records3 years
Korea Protection of Communications Secrets Act Art. 15-2Retention of access recordsRetention of computer-communication and internet log records and access-tracing data; security and abuse preventionIP address; access time; access records; login and connection records3 months
PIPA Art. 15(1)(vi) (legitimate interests)Service security, stability, and prevention of misuseMaintaining Service security and stability; fault detection and analysis; performance management; prevention of account takeover, unauthorized access, Service abuse, and violations of the TermsError logs; system logs; traffic-related metadata; Service usage records; IP address; access time; browser type; device information; container resource metrics (CPU, memory, network); service-liveness signals; security and abuse-detection outputsError logs, system logs, traffic-related metadata, and security and abuse-detection outputs: up to 12 months. IP addresses, access times, and access records: 3 months
PIPA Art. 15(1)(vi) (legitimate interests)Management of generated-service source repositoriesStorage, recovery, re-delivery, and project-restoration support for generated codePersonal information that may be contained in generated source code and configuration files (only where the User has entered personal information in Requirements or configuration data)Deleted after a grace period (currently 30 days) following project deletion
PIPA Art. 15(1)(vi) (legitimate interests)Automated illegality and risk detectionDetection of illegal use, Service abuse, violations of the Terms, and legal riskThe minimum items of Requirements, interview conversations, and configuration data necessary for analysis; automated-classification outcomes; potential-violation flags; review recordsUp to 12 months
PIPA Art. 15(1)(vi) (legitimate interests)MCP server usage analytics and version checkProduct improvement through analysis of tool usage and errors in the MCP server distributed by the Company (@backendx/mcp); management of supported-version compatibilityName of each tool invoked; whether the invocation succeeded or failed and any error code; package version; client ID and session ID randomly generated per process; package version and access records of version-check requests. Prompts, generated code, authentication tokens, tool arguments and results, and account identifiers such as email addresses are not collected.Usage analytics: up to 14 months, per the data-retention setting of the Google Analytics 4 property; version-check access records: as stated in the access-record row above

B. Personal Information Processed With the Data Subject's Consent

The Company processes the following personal information with the data subject's consent. Consent is optional, and declining to consent does not restrict use of the Service. Users may withdraw consent at any time (Section 7) without affecting the lawfulness of processing carried out before withdrawal.

Legal BasisCategoryPurpose of ProcessingItems CollectedRetention Period
PIPA Art. 15(1)(i) (consent of the data subject); Korea Act on Promotion of Information and Communications Network Utilization and Information Protection Art. 50 (restrictions on transmission of advertising information for profit)Marketing and advertising communicationsSending advertising information by email, such as announcements of new features and services, event and promotion information, and newslettersEmail address; account identifiers; time and method of consent to receive marketing communicationsUntil withdrawal of consent or account deletion

C. California Notice at Collection

For California residents, this section serves as the notice required by the California Consumer Privacy Act (Cal. Civ. Code §1798.100(a)). The Company collects the categories of personal information listed in Sections 1.A and 1.B from the sources described in those sections, for the purposes and retention periods stated for each item. The Company does not sell or share personal information as those terms are defined by the CCPA/CPRA and does not use sensitive personal information for purposes other than those permitted under Cal. Civ. Code §1798.121 without providing the right to limit. California residents may exercise the rights described in Section 7 at any time.


2. Automated Analysis and Use of AI Tools

  1. To prevent illegal activities, abuse, and violations of the Terms, the Company may analyze user-submitted requirements and configurations using automated methods.
  2. For this purpose, the Company may use third-party AI tools solely as auxiliary means to assess potential illegality.
  3. Only the minimum information necessary for analysis is used. Third-party AI providers engaged for this purpose are contracted and configured to prohibit use of transmitted content to train external AI models, subject to the providers' configuration options and constraints selected by the Company to minimize such use.
  4. Automated analysis results are used as supporting indicators only and do not constitute final legal determinations.
  5. Automated decision-making disclosure (GDPR Art. 13(2)(f) / 22). The logic of automated analysis uses a combination of rule-based checks and third-party AI classification to flag potential Acceptable Use Policy violations. The analysis produces indicators of likely-violating activity, not final decisions. Any decision that produces legal or similarly significant effects for the User — including suspension, restriction, or termination of access to the Service — will include human review before enforcement, and the User may contest such a decision by contacting the Chief Privacy Officer at privacy@backendx.ai. The envisaged consequence of an adverse decision is restriction or termination of Service access and, where relevant, notification to competent authorities as required by law.
  6. No training of the Company's own models. The Company does not operate or train its own generative AI models. The Company does not use Requirements, interview conversations, configurations, or other customer content to train any AI model (whether the Company's own model or any third-party model), except where specific additional consent has been obtained from the User.

3. Procedures and Methods for Destruction of Personal Information

Upon account or project deletion, personal information is deleted without undue delay, unless retention is required by the laws cited above or is necessary to resolve an active dispute.

The procedures and methods for destroying personal information are as follows.

  • Destruction procedure: the Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Company's Chief Privacy Officer.
  • Destruction method: deletion is performed in stages. Access is deactivated immediately, and associated artifacts (secrets entries, delivery repositories and mirrors, deployed instances and their per-project databases, and source repositories after the grace period stated in Section 1) are purged through asynchronous cleanup processes.

Retained records are segregated and access-controlled. Resources provisioned in a User's own cloud account under Customer-Cloud deployment are not deleted by the Company automatically (see Section 11 of the Terms of Use).

Where personal information must continue to be preserved under other laws even though the retention period consented to by the data subject has expired or the purpose of processing has been achieved, the Company moves that personal information to a separate database (DB) or stores it in a separate location.


4. Disclosure to Third Parties

  1. The Company processes personal information only within the scope of the purposes stated in this Policy and does not disclose personal information to third parties except (a) where the User has given prior consent, (b) where disclosure is required by applicable law, court order, or lawful request from a competent authority, or (c) in connection with a corporate transaction (merger, acquisition, asset transfer), subject to prior notice to affected Users where required by law.
  2. As those terms are defined by the California Consumer Privacy Act (CCPA/CPRA), the Company does not "sell" or "share" personal information for cross-context behavioral advertising.

5. Outsourcing of Processing (Consignment under PIPA Article 26)

The Company outsources ("consigns") certain processing activities. In accordance with PIPA Article 26, the current consignees and consigned tasks are:

ConsigneeConsigned Task
Amazon Web Services, Inc.Cloud infrastructure, storage, compute, and log hosting (primarily the Seoul region)
GitHub, Inc.Source-code repository mirroring and Output delivery (optional GitHub delivery option)
OpenAI, L.L.C. / Google LLC / Anthropic, PBC / other third-party AI providers (as used)AI processing of user-submitted requirements, configurations, and interview conversations to provide the Service's AI features — including requirements interviews, specification authoring, and backend source-code and test generation — and automated analysis / illegality detection
BackendX US, Inc. (wholly-owned U.S. subsidiary of the Company)Collection of Subscription payments and billing execution on the Company's behalf, solely as the Company's payment-processing agent (holder of the Stripe account; the charging entity shown on card statements)
Stripe, Inc. (additional payment service providers may be added as disclosed)Payment processing, billing, chargeback handling

The current list of consignees is maintained on the Service and updated when changes occur. The Company requires each consignee to implement appropriate technical and organizational safeguards, restricts processing to the consigned purpose, prohibits sub-consignment without approval, and supervises compliance in accordance with PIPA Article 26.


6. Cross-Border Transfer of Personal Information

  1. The Company may consign the processing of, or store, Users' personal information with consignees located outside the Republic of Korea for the purpose of providing the Service. Platform data processed by the Company is primarily stored in the AWS Asia Pacific (Seoul) region (ap-northeast-2). Personal information may be transferred to and processed in countries outside the Republic of Korea (principally the United States) where the consignees listed in Section 5 operate — for example, when third-party AI providers, payment processors, or source-code hosts process data in their respective regions.
  2. Users may refuse cross-border transfer; however, refusal may make some or all Service features unavailable.
  3. In accordance with PIPA Article 28-8(2), the Company provides the following information on cross-border transfers.
Legal BasisConsigned TaskItems TransferredDestination CountryTime and Method of TransferRecipientPurpose of UseRetention Period
PIPA Art. 28-8(1)(iii) (overseas consignment or storage necessary for the performance of a contract)Cloud infrastructure, storage, compute, and log hostingAccount information; project and Service usage records; Requirements, configuration data, and interview conversations; generated Outputs; source code and configuration files; logs and information necessary for Service operationRepublic of Korea, United States, and other AWS regions as configuredTransmission and storage over encrypted networks upon Service use, project creation or storage, deployment, or log generationAmazon Web Services, Inc.Cloud infrastructure, storage, compute, and log hosting for Service provisionFor the duration of Service use and the relevant retention periods in Section 1
PIPA Art. 28-8(1)(iii) (overseas consignment or storage necessary for the performance of a contract)Source-code repository mirroring and Output deliveryGitHub account information; repository collaboration and integration information; generated source code and configuration files; commit and repository metadataUnited StatesTransmission over encrypted networks when the User selects the optional GitHub repository option and connects a repository or mirrors OutputsGitHub, Inc.Optional GitHub repository mirroring, collaborator invitations, and Output deliveryUntil GitHub integration is revoked or the project or account is deleted
PIPA Art. 28-8(1)(iii) (overseas consignment or storage necessary for the performance of a contract)AI-powered requirements interviews, specification authoring, backend code and test generation, and automated illegality detectionThe minimum information among User-submitted Requirements, configuration data, text inputs, and interview conversations necessary for AI processing and automated analysisUnited States, or the country in which the AI API is actually processedTransmission via encrypted API calls when AI features are used or automated analysis is performedOpenAI, L.L.C. / Google LLC / Anthropic, PBC / other third-party AI providers (as used)Provision of AI-powered Service features, requirements analysis, specification authoring, code and test generation, and support for automated illegality and abuse detectionThe period determined by the Company's contract with each AI provider and the actual API and data-retention settings
PIPA Art. 28-8(1)(iii) (overseas consignment or storage necessary for the performance of a contract)Collection of Subscription payments and billing supportAccount identifiers; subscription and plan information; payment, billing, and refund information and transaction identifiersUnited StatesTransmission over encrypted networks upon payment, billing, automatic renewal, refund, or payment-dispute handlingBackendX US, Inc.Collection of Subscription payments and billing support on the Company's behalf5 years from the date of transaction, or the retention period required by applicable law
PIPA Art. 28-8(1)(iii) (overseas consignment or storage necessary for the performance of a contract)Payment processing, billing, and dispute handlingPayer identifiers; payment-instrument tokens; transaction, payment, billing, refund, and dispute-handling information. The Company does not store full payment-card numbersUnited States, or the country in which payment is actually processedTransmission over encrypted payment networks upon payment, billing, automatic renewal, refund, or payment-dispute handlingStripe, Inc. (additional payment service providers may be added as disclosed)Payment processing, billing, refunds, and payment-dispute handlingThe period determined by Stripe's contractual and statutory retention periods and the Company's transaction-record retention period
  1. Transfer mechanism (GDPR / UK GDPR): where personal data of data subjects in the European Economic Area or the United Kingdom is transferred to a country without an adequacy decision, the Company relies on the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures (encryption in transit and at rest, access controls, minimization) as documented in a transfer impact assessment available on request.
  2. Transfer mechanism (PIPA): the Company provides the disclosures required by PIPA Article 28-8 and, where legally required, obtains separate consent.

7. Rights of Users (PIPA, GDPR, UK GDPR, CCPA/CPRA)

Subject to applicable law, Users have the following rights:

  • Access — obtain confirmation of, and a copy of, personal information processed about them.
  • Rectification / correction — request correction of inaccurate or incomplete data.
  • Erasure / deletion ("right to be forgotten") — request deletion subject to legal retention obligations.
  • Restriction of processing — request that processing be limited in certain circumstances.
  • Objection — object to processing based on legitimate interests, including profiling and direct marketing.
  • Data portability — receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Withdrawal of consent — where processing is based on consent, withdraw consent at any time without affecting prior lawfulness.
  • Right not to be subject to automated decision-making (GDPR Art. 22) — the Company's automated illegality-detection outputs are supporting indicators only; any decision that produces legal or similarly significant effects for the User (such as suspension or termination) will include human review, and the User may contest the decision by contacting the Company.
  • Lodge a complaint — data subjects in the EEA/UK may lodge a complaint with their local supervisory authority; Korean data subjects may contact the Personal Information Protection Commission (privacy.go.kr) or the Korea Internet & Security Agency (privacy.kisa.or.kr); California residents may contact the California Privacy Protection Agency or Attorney General.
  • California-specific rights (CCPA/CPRA): right to know categories/specific pieces of PI collected, sources, purposes, and third parties; right to delete; right to correct; right to opt out of sale/sharing (the Company does not sell or share); right to limit use of sensitive PI; right to non-discrimination for exercising these rights. Authorized-agent requests are accepted with verification.

Requests may be submitted to privacy@backendx.ai or team@email.backendx.ai. The Company will verify the requestor's identity and respond within the statutory timeframe (30 days under GDPR, extendable by 60 days; 45 days under CCPA, extendable by 45 days; 10 days for initial response under PIPA).


8. Security Measures

The Company implements technical and organizational measures to protect personal information, proportionate to the nature, scope, context, and purposes of processing and the risks to individuals.

Current measures include:

  • Access control and authentication — role-based access with least-privilege defaults; multi-factor authentication on administrative accounts.
  • Encryption in transit — TLS 1.2 or higher on all external interfaces and on connections to third-party processors (cloud providers, AI providers, payment processors, source-code hosts).
  • Encryption at rest — storage-level encryption on databases and backups; additional application-level (column-level) encryption using an envelope pattern with key-management-service (KMS) keys for higher-sensitivity stores, including user-submitted Requirements and interview conversations. Decrypt operations on higher-sensitivity stores are logged.
  • Per-project tenant isolation (Managed Hosting) — each deployed project runs in its own isolated container network and uses a dedicated database and database role on shared database infrastructure, with per-project database credentials derived through a KMS-backed mechanism rather than stored; error-event captures from deployed services are encrypted with a per-project key before leaving the service, and decryption is confined to the platform paths that serve the project's own operations dashboard and the reactive inspections described in Section 10 of the Terms of Use.
  • Secret scrubbing before external AI processing — where user-submitted content is sent to third-party AI providers for automated analysis (see Section 2), the Company applies deterministic redaction to remove obvious secrets (such as cloud access keys, bearer tokens, and payment-instrument patterns) before transmission. Third-party AI providers are engaged under contracts that prohibit use of transmitted content to train external models, subject to provider constraints.
  • Logging and monitoring — access and activity logs retained per Section 1, with anomaly alerting for privileged access and decryption events.
  • Incident response — documented procedures for detection, containment, investigation, and notification, aligned with the data-breach notification requirements in Section 13.
  • Vendor due diligence — the Company enters into Data Processing Agreements (or PIPA-equivalent consignment agreements) with consignees listed in Section 5 and periodically reviews their security posture.

9. Legal Bases for Processing (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, the Company processes personal data on the following legal bases:

Processing ActivityLegal Basis
Account creation, authentication, Service provision, payment processing, customer supportPerformance of a contract (GDPR or UK GDPR Art. 6(1)(b))
Eligibility-age verification at registration (age-of-majority attestation record)Performance of a contract (GDPR or UK GDPR Art. 6(1)(b)); compliance with legal obligations (Art. 6(1)(c)) — capacity and child-consent rules
Security, fraud/abuse prevention, automated illegality detection, service-quality improvement, internal analyticsLegitimate interests (GDPR or UK GDPR Art. 6(1)(f)) — balanced against data-subject rights
Retention of payment records, complaint records, access logsCompliance with legal obligations (GDPR or UK GDPR Art. 6(1)(c)) — Korean commercial and communications laws
Marketing and advertising communications (Section 1.B)Consent (GDPR or UK GDPR Art. 6(1)(a)), withdrawable at any time

Users must not submit special-category personal data (GDPR Art. 9; PIPA Art. 23) in Requirements or interview conversations. Where such data is nonetheless submitted, the Company will process it only under a lawful basis permitting such processing (such as explicit consent under Art. 9(2)(a) or an applicable Art. 9(2) / PIPA Art. 23 exception) or will delete it upon identification. The Company does not knowingly process special-category data for purposes beyond operating the Service and complying with legal obligations.


10. Chief Privacy Officer (PIPA Article 31)

In accordance with PIPA Article 31, the Company designates a Chief Privacy Officer (개인정보보호책임자) responsible for overall management of personal information and handling of User requests and complaints.

  • Chief Privacy Officer: DK Moon, Representative Director, BackendX Inc. (주식회사 백엔드엑스)
  • Email: privacy@backendx.ai
  • Postal address: 43, Changeop-ro, Eopmoo-dong, 4F 9-ho, Sujeong-gu, Seongnam-si, Gyeonggi-do, 13449, Republic of Korea

Users may contact the CPO for any privacy-related inquiry, request, or complaint. The CPO will respond within the statutory timeframe and will endeavor to resolve issues promptly.


11. EU / UK Representative (GDPR Art. 27 / UK GDPR)

To the extent GDPR Article 27 requires the Company to designate a representative in the European Union, or UK GDPR requires a UK representative, or both, the Company will designate such representative(s) and publish their contact details in this Policy once appointed. Until a representative is formally designated, EEA/UK data subjects may contact the Chief Privacy Officer at privacy@backendx.ai to exercise their rights; the Company will not use the absence of a designated representative to deny or delay rights requests.


12. Children's Privacy

Registration for the Service requires the User to have reached the age of majority under the law of the User's nationality (and in any case to be at least 18 years of age — e.g., 19 for nationals of the Republic of Korea); the User confirms this at registration, and the confirmation is recorded with the document version and timestamp. Accordingly, the Service is not directed to children under 13 (under the U.S. Children's Online Privacy Protection Act, "COPPA"), under 14 (under PIPA), or under 16 (under GDPR, subject to EU member-state variation). The Company does not accept registrations from minors under any circumstances — including with the consent of a legal guardian — and does not knowingly collect or process personal data of children below those ages. Because the Company does not process children's personal information at all, it operates no guardian-consent mechanism (such as the consent procedure contemplated by PIPA Article 22-2 for controllers that do process under-14 data). If the Company learns that a minor has registered or that a child's personal information has been collected, it will delete the account and the associated personal information. If you believe a child has provided personal information, please contact privacy@backendx.ai for prompt deletion.


13. Data-Breach Notification

In the event of a personal-data breach, the Company will notify affected Users and the relevant supervisory authorities in accordance with applicable law, including PIPA Article 34 (notification within 72 hours of awareness of breaches affecting 1,000 or more data subjects), GDPR Article 33/34 (supervisory-authority notification within 72 hours; data-subject notification where high risk is likely), and applicable U.S. state breach-notification statutes.

For End-User Personal Data processed under the DPA, notifying affected end-users and competent authorities is the responsibility of the User as controller. The Company notifies the User without undue delay (and in any case within 24 hours of awareness) and assists the User's notification obligations as set out in the DPA, and notifies end-users directly only where necessary to comply with a direct legal duty or where the User is unresponsive.


14. Contact

For privacy-related inquiries, rights requests, or complaints, please contact:


15. Cookies and Similar Technologies

The Company distinguishes between the in-product Service (app.backendx.ai or equivalent) and the marketing website (backendx.ai). Cookies fall into the categories below; for every category other than strictly necessary cookies (analytics and advertising), the User may grant or withdraw consent per category through the cookie banner or the cookie-preferences control.

  1. Strictly necessary cookies. The in-product Service and the marketing website use strictly necessary cookies and similar technologies for authentication, session management, security, and service operation. These are essential to providing the Service and do not require consent under applicable law.
  2. Analytics (GA4). The Service — the marketing website and the in-product Service alike — uses Google Analytics 4 ("GA4") for traffic measurement, signup-funnel analysis, and product improvement. GA4 sets cookies (including _ga, _ga_<id>) that are classified as non-essential analytics cookies. Regardless of the User's location, no analytics cookies are set until the User consents to the analytics category through the cookie banner (Google Consent Mode defaults to denied). The Google tag may load before consent; in that case it neither sets nor reads cookies and transmits to Google only cookieless signals that reflect the consent state (such as page-visit timestamp, browser type, referrer, consent status, and whether an ad was clicked), which Google uses solely for statistical modeling of traffic and conversions. The User may withdraw consent at any time through the cookie-preferences control. GA4 data is transferred to Google LLC in the United States under Google's standard contractual clauses and within its Consent Mode framework.
  3. Advertising (conversion measurement). The Service uses the conversion-tracking features of the advertising platforms below to measure the conversion performance of advertising traffic and to attribute conversions to ad clicks. The Company uses cookies and data in this category solely to measure advertising effectiveness; it does not use them for personalized advertising to the User (remarketing or behavior-based advertising) and does not permit the advertising platforms to do so (the ad_personalization signal of Google Consent Mode is always set to denied, and no custom audiences are built from Meta Pixel data). No advertising cookies are set until the User consents to the advertising category in the cookie banner, the User may withdraw consent at any time by turning off the advertising toggle in the cookie-preferences control, and after withdrawal those cookies are no longer set or transmitted.
    • Google Ads (Google LLC, United States). Where the User has consented to the advertising category, cookies that store the Google ad-click identifier (including _gcl_aw and _gcl_au, retained for approximately 90 days) are set, and conversion events such as pre-registration and signup are sent to Google Ads. Data is transferred to Google LLC in the United States on the same basis as GA4.
    • Naver Search Ads conversion tracking (Naver Corporation, Republic of Korea). Where the User has consented to the advertising category, the Naver Search Ads conversion-tracking script is loaded, cookies and identifiers for conversion tracking are set, and conversion events are sent to Naver's advertising system. This processing takes place within the Republic of Korea and does not constitute a cross-border transfer.
    • Meta Pixel (Meta Platforms, Inc., United States). Where the User has consented to the advertising category, the Meta Pixel is loaded, cookies that store a browser identifier and the ad-click identifier (_fbp and _fbc, retained for approximately 90 days) are set, and conversion events such as pre-registration and signup are sent to Meta's advertising system. The Company uses this data solely for conversion measurement and does not build audiences for retargeting or other custom-audience advertising. Data is transferred to Meta Platforms, Inc. in the United States, and the Company relies on Meta's data-processing terms and standard contractual clauses.
  4. Next.js framework. The Service is built using the Next.js framework. Next.js does not set tracking cookies by default; any Next.js-generated cookies used by the Service are strictly necessary and scoped to session management and security.
  5. Do Not Track and Global Privacy Control. The Service honors browser-level Global Privacy Control ("GPC") signals where technically feasible, treating them as declined consent for the analytics and advertising categories. Where a GPC signal is received, the analytics and advertising tags are not loaded.
  6. Non-browser clients (MCP server). The MCP server that the Company distributes as an npm package (@backendx/mcp) is a client that lets AI agents use the Service from the User's local environment. It runs without a browser, sets no cookies, and the cookie banner described above does not apply to it. Instead, the following communications take place, as also disclosed in the license document bundled with the package. Retention periods are as stated in the table in Section 1.A.
    • Version check. Each time it starts, the MCP server sends its own package version to the Company's server to confirm that the version is supported. Tools may not operate if the version is no longer supported or the check cannot be completed.
    • Usage analytics. The MCP server sends the name of each tool invoked, whether the invocation succeeded or failed and any error code, the package version, and a client ID and session ID randomly generated per process to Google LLC in the United States via the Google Analytics 4 Measurement Protocol. It does not send prompts, Requirements, generated code, authentication tokens, environment-variable values, tool arguments or results, or account identifiers such as email addresses. Usage analytics are enabled by default; the User may stop them at any time by setting the environment variable DO_NOT_TRACK=1 or BACKENDX_TELEMETRY_DISABLED=1, and doing so does not affect the MCP server's functionality.

16. Changes to This Policy

This Privacy Policy may be amended due to changes in laws or Service operations. Any changes will be announced through the Service or by other reasonable means. Material changes will be notified in advance to the extent required by applicable law, and the "Last Updated" date at the top of this Policy will reflect the most recent revision.