Skip to content
Cairn · PairTraceTerms of Service한국어Contact

Cairn Privacy Policy

Prototype · Published 9 September 2026 · Document version 2026-09-09

The Korean version of this policy is authoritative and the English version is a translation; if the two differ, the Korean version governs. Cairn is a prototype under development. Features may change, and before personal data is used for a new purpose or passed somewhere new, the Operator will explain the change and obtain any consent required.

1. Operator and scope

KangRim Lee, a sole operator, runs Cairn under the name PairTrace and is responsible for personal data protection. Send enquiries and requests to access, correct, delete, suspend processing, or close an account to kangrim@pairtrace.com.

This policy applies to Cairn accounts and workspaces, the work records kept with a connected AI, and the Google sign-in and Gmail connection features. Enquiries from the website go to kangrim@pairtrace.com. Where a separate enterprise pilot agreement has been signed, the processing conditions in that agreement apply as well.

2. What is processed and why

Items processed, by feature
FeatureItems processedPurpose
Account and sign-inEmail address; account and workspace identifiers and names; sign-up time. For password sign-up, a verification hash and salt rather than the password itself. For Google sign-in, the Google account identifier and email address.Sign-up and sign-in; distinguishing accounts and workspaces
Authentication and consentSession identifiers and verification values; issue, expiry, and revocation times; records of AI connections and access permissions. For new sign-ups, the terms version, the time consent was recorded, the sign-up method, and records confirming the privacy policy was reviewed and that the user is 14 or over.Keeping you signed in, access control, checking consent records
Work criteria and historyGoal, completion criteria, and permitted-action proposals from the user and the connected AI; responses, approvals, changes, results, supporting evidence, and the associated times; team and shared material the user registers.Agreeing work criteria, reviewing history, reuse and sharing the user chooses
Gmail search and previewGoogle access and refresh tokens; account and permission information; search queries; message identifiers, subjects, senders, and dates from search results; a text preview of the selected message.Showing the search you requested and the message you selected
Gmail work provenanceWork, Google account, message, and thread identifiers; subject, sender, date, and the time recorded.Linking imported mail to work candidates and distinguishing duplicate imports
Security and operationsPartially masked IP addresses; access and error records such as request path, method, response status, and time.Access control, checking errors and misuse, managing service availability

Material needed to provide the account and work service is processed on applicable legal bases such as performance of the user agreement, and processing that requires separate consent is explained with its purpose and items set out separately. Confirming that you have read this policy is not by itself blanket consent to all processing of personal data.

3. Google sign-in and Gmail reading

Google sign-in uses openid and email. After separate consent, Gmail uses the gmail.readonly permission to provide the search you request and a preview of one message you select. That permission is the scope Google grants for reading a mailbox; it is not access limited to the single message you select.

Cairn does not send, modify, or delete mail, download attachments, or synchronise automatically. It does not put message bodies into work criteria or pass them to a connected AI automatically. Criteria you type yourself when creating a work candidate from Gmail are provided to the connected AI, so please check what you are passing on if you copy content out of a message.

4. AI and team sharing, and limits on use of Google data

A connected AI can read the work criteria, responses, and history it is permitted to see, and can leave proposals. Material you publish to a team or to a criteria library is visible to those recipients. No separate feature for reading original Gmail messages is provided to an AI connection. Information an AI service receives is also subject to the terms and privacy conditions of the provider you selected.

Google data, and anything derived from it, is used only to the extent needed to provide and improve features that are clearly visible to you. It is not used for advertising, sale, data brokerage, credit scoring or lending decisions, or to create, train, or improve any machine learning or AI model.

The Operator and anyone working on its behalf do not routinely read users' mail. Even where reading is permitted — with your explicit consent for specific material, for a necessary security investigation, or to comply with the law — it is limited to the minimum needed for that purpose. Selecting your own mail for preview is not treated as consent for the Operator to read it.

Google data is transferred only where Google's policies permit: to provide or improve an explicit service feature with user consent, to take necessary security measures or comply with the law, or in a merger or acquisition for which explicit prior consent was obtained. The Operator complies with the Limited Use requirements of the Google API Services User Data Policy and the Google Workspace user data policy.

5. Retention, deletion, and disconnecting

  • Account, work criteria, and history: kept while you use the service. Material whose purpose has been fulfilled, or that is covered by a lawful account-closure or deletion request, is destroyed under the procedure below.
  • Sign-in sessions: valid for 8 hours from issue. Expiry or sign-out ends the authentication; it does not mean stored records are deleted immediately. Remaining session records are kept for the life of the account and are included when the account is deleted.
  • Gmail tokens and provenance: kept to operate the connection; tokens, previews, and provenance records are stored encrypted. When you complete “Disconnect Gmail” in Cairn, tokens, previews, and provenance material in active storage are cleared. A record of the disconnected state may remain to prevent reconnection conflicts.
  • Previews: available for 10 minutes after creation. Expired files are cleared during a later preview request or creation, or while disconnecting from Cairn. The passing of 10 minutes does not delete the file and its backups simultaneously.
  • Revoking permission at Google: you can revoke access from the connection settings of your Google account. Cairn learns of the revocation from a subsequent access or refresh failure; files already stored are not automatically deleted at that moment. To clear stored material, disconnect within Cairn or ask by email.
  • Work already created: disconnecting Gmail leaves work criteria and history in place. Deletion of that material can be requested separately.
  • Consent and authentication request records: sign-up consent records and remaining authentication-request and disconnection-state records are kept for the life of the account and are included when the account is deleted. Expired or consumed Google requests may be cleared when a later request is created. The actual retention ceiling for security and operational logs, and the full set of storage locations, will be settled before publication.
  • Backups: deleted material may remain in recovery backups for up to 30 days. During that period it is not used for ordinary service, and a deletion request is reapplied on restore. Where the law requires separate retention, the basis, items, and period are set out separately.

Requests to access, correct, delete, or suspend processing are handled without delay once identity is confirmed using the minimum information necessary, and the outcome — or the reason for a delay or restriction — is notified within the period set by applicable law, including the 10-day notification duty where it applies. Operationally, a ceiling of 30 days applies to full account closure and clearing of material, but that period is not used as a reason to delay a statutory duty or a destruction that can be carried out immediately. Electronic material is destroyed by a procedure that prevents recovery or reconstruction. For material already lawfully shared with others, or received by a separate AI service, you also need to check the procedures of whoever holds it.

6. Processing entrusted to others and processing abroad

Operational records confirm that Cairn servers use Oracle Cloud's Chuncheon region in the Republic of Korea. Google provides sign-in and mail access, and the AI provider you connect receives the work material you select. The website is served by Vercel, and enquiries go to kangrim@pairtrace.com.

7. Safeguards and minimum age

The service applies HTTPS, per-account access checks, storage of password verification values, and encrypted storage of Gmail tokens, previews, and provenance. It uses the authentication cookies the service needs; if you refuse them, you may not stay signed in. No analytics or advertising scripts are placed on this policy page.

The prototype is for people aged 14 and over. If the Operator learns that a user is under 14, it will stop the use and take the necessary steps, including deleting material. The Operator does not represent that it provides a legal-guardian consent mechanism.

8. Changes and effective date

Changes and their effective dates are announced on this page. Where important matters change — the purposes for which personal data is used, the items processed, or who receives it — notice is given before the change takes effect, and separate consent is obtained where necessary. The possibility that prototype features may change does not widen the scope of consent already given.

Sole operator KangRim Lee · PairTrace · kangrim@pairtrace.com
Cairn Terms of Service · Home