Privacy policy

What we collect, what we don't, and who we entrust it to.

Last revised 2026-08-30

한국어: 개인정보처리방침. 한국어본이 법적으로 우선하며, 아래 영문은 이해를 돕기 위한 번역입니다.

1. What we collect

Email addressTo deliver and re-send your licence key, and to answer enquiries. You enter it yourself at purchase.
Payment referenceThe transaction ID, order number, amount, currency, and status issued by the payment provider. We never collect card or bank account numbers — the provider's widget handles them directly and they do not pass through our servers.
Device identifier hashA one-way hash used to count activated machines. The underlying hardware information is not transmitted.
Access logsServer logs such as request time and IP address, kept to prevent abuse and fraudulent use.

There is no sign-up. Licences arrive by email; no account or password is created.

2. What the app sends, and what it does not

The content a product handles never leaves your machine. That covers BicMac's clipboard contents, screenshot images, and window layouts, and Greenday's tasks, schedule, and habit records — all of it is stored only on your Mac.

In Greenday, dated tasks are sent to a calendar service (iCloud or Google) only if you turn that sync on yourself. It is off by default, and the connection goes from your machine straight to that service without passing through our servers.

The app reaches the network in only two other cases.

  • Update checks — asking GitHub for the latest version number.
  • Licence activation and revalidation — sending the licence key and the device identifier hash to our server.

We put no analytics tooling and no advertising SDK in the app. We do not collect usage behaviour.

3. Processors and international transfers

We entrust personal data processing to the businesses below in order to provide the service. Use beyond the entrusted scope is prohibited by contract.

Domestic processors

Toss Payments Inc.Korean payment processing · Republic of Korea (not an international transfer)

International transfers — the table below discloses the items required by article 28-8(2) of the Korean Personal Information Protection Act. Under article 28-8(1)(iii) of the same Act, we transfer the data abroad within the scope needed to perform the contract and to serve users, disclosing the following in place of obtaining separate consent.

Recipient Contact Country Data transferred When and how Purpose Retention
Paddle.com Market Ltd. Privacy contact Ireland Email address, payment method details, amount and currency, billing country Over HTTPS at the time of an international payment Processing international payments and tax filing. Paddle acts as merchant of record 5 years after the transaction ends (Irish and EU accounting and tax retention duties)
Resend, Inc. Privacy contact United States Email address, licence key Over HTTPS when a key is sent or re-sent Delivering the licence key by email 30 days after sending (delivery log retention)
Cloudflare, Inc. Privacy contact United States (headquarters). Storage and processing take place on Cloudflare's global network and no specific country is guaranteed Email address, licence key, device identifier hash, payment records, access IP Stored and transmitted continuously while the service is used Website hosting and running the licence database Same as the retention periods in section 4 (fully removed once the post-deletion backup window has passed)

How to refuse — you may refuse the international transfer of your personal data by writing to the contact in section 8. Because payment and key delivery both depend on that transfer, refusing means you cannot use the paid service. Use of the free version is unaffected.

Web fonts are served from this site itself — merely opening a page does not hand your IP address to an external font CDN such as Google. (The transfer of your access IP to Cloudflare, our hosting provider, is as described in the table above.)

4. Retention and destruction

We destroy data without delay once the purpose of collection is met. Data we hold ourselves is kept as follows.

  • Email address and licence key — licences have no time limit, so we keep these until you ask us to delete them. Deleting them also voids the licence; only the records subject to statutory retention below are kept separately.
  • Device identifier hash — destroyed when the activation is released, or when the slot is reclaimed after 90 days without revalidation.
  • Access logs3 months (Protection of Communications Secrets Act)

The following records are held separately for the periods set by law.

  • Records of contracts and withdrawal of subscription — 5 years (E-Commerce Act)
  • Records of payment and supply of goods — 5 years (E-Commerce Act)
  • Records of consumer complaints and dispute handling — 3 years (E-Commerce Act)

Procedure — personal data whose retention period has ended, or whose purpose has been fulfilled, is classified for destruction under our internal policy and destroyed with the representative's approval. Data that must be kept by law is separated into its own database and is not used for any other purpose.

Method — personal data held as electronic files is deleted from the active database in a way that cannot be recovered. The database keeps automatic point-in-time backups for disaster recovery (currently up to 30 days), so copies remaining in backups disappear once that window passes. During that window backup copies are not used for anything other than disaster recovery. Printed personal data is shredded or incinerated.

5. Your rights

You may request access to, correction of, deletion of, or suspension of processing of your personal data. Write to support@begreen.dev and we will act without delay.

If you have simply lost your licence key, that is not a data request — you can re-send it yourself at pay.begreen.dev/recover.

Requesting deletion also voids the licence. Purchase records remain for the statutory periods in section 4.

6. Security measures

  • All traffic is encrypted with HTTPS.
  • The admin console is reachable only by one designated account through Cloudflare Access, with two-factor authentication required.
  • Every administrative change (voiding a key, manual issuance, releasing a machine) is written to an audit log.
  • Device identifiers are stored only as hashes, never in their original form.

7. Cookies

This website (begreen.dev) uses no cookies and carries no visitor analytics. On the payment site (pay.begreen.dev) the provider's checkout may use cookies necessary to process the payment, governed by that provider's own policy.

8. Data protection officer

Officer신민석
Emailsupport@begreen.dev

To report or seek advice on a privacy violation in Korea, you can contact the Personal Information Infringement Report Centre (118), the Supreme Prosecutors' Office Cyber Investigation Division (1301), or the National Police Agency Cyber Bureau (182).

9. Changes to this policy

When we revise this policy we announce the effective date and the changes on this page at least 7 days beforehand.

Terms · Refunds