Privacy Policy

Hanplanet / Privacy Policy
Sign Up Login

Privacy Policy

Effective Date: 2026-06-19

Hanplanet ("Service") values user privacy and user files. This Privacy Policy explains how Hanplanet, HanDrive, account authentication, GitHub integration, Google integration, Google Drive integration, search, translation, chat, and related features collect, use, store, and protect information.

1. Information We Collect

We may collect or store the following information as needed to provide the Service:

  • Account data: username, password hash, name, email address, profile image, language preference, theme preference, search engine preference, consent timestamps
  • Authentication data: login session cookies, security tokens, email verification codes, two-factor authentication state, IP address, User-Agent, request logs
  • HanDrive data: files and folders users upload, create, edit, delete, move, or share; file names, paths, MIME types, sizes, modification times, permissions, share links, public write settings, folder icons, sync exclusions
  • Git/Forgejo data: repository names, branch names, commit messages, commit IDs, collaborator permissions, repository access tokens
  • GitHub integration data: GitHub user ID, login, display name, email, avatar URL, OAuth access token, refresh token, token expiration, scopes, selected repositories, branch/commit/file metadata, and repository cache
  • Google integration data: Google user ID, email, display name, avatar URL, OAuth access token, refresh token, token expiration, scopes, Google Drive display setting, and Google Picker selected item list
  • Google Drive data: when the user enables Google Drive display and selects files or folders with Google Picker, Drive file/folder IDs, names, MIME types, sizes, modification times, parent folders, file content, and results of download/upload/create/update/delete/move actions for selected files/folders and items inside selected folders
  • Usage data: page visits, button clicks, API calls, error logs, game records, root quick links, public portfolio content, and support inquiries
  • AI/translation input: text users submit to the chatbot or translation feature and the generated response

2. How We Collect Information

Information may be collected when users:

  • Sign up, log in, update account settings, or edit profiles
  • Authenticate or link accounts through GitHub or Google OAuth
  • Upload, edit, download, delete, share, sync, or convert HanDrive files to Git repositories
  • Enable Google Drive display, select files or folders with Google Picker, and view, upload, edit, move, or delete selected items or items inside selected folders
  • Select GitHub repositories and view, edit, add, delete, commit, or manage branches for repository files
  • Use search, translation, chatbot, game, portfolio, or inquiry features
  • Interact with the Service in ways that generate security, error, or abuse-prevention logs

3. How We Use Information

We use collected information to:

  • Create accounts, authenticate logins, maintain sessions, and protect accounts
  • Provide HanDrive upload, organization, preview, edit, download, delete, sharing, and sync features
  • Display and manage Google Drive files/folders selected with Google Picker, and items inside selected folders, only when authorized by the user
  • Display and manage selected GitHub repositories in HanDrive only when selected by the user
  • Provide Git/Forgejo repository creation, branch/commit management, and collaborator permissions
  • Provide requested search, translation, chatbot, game, and portfolio features
  • Respond to inquiries, analyze errors, audit security, prevent abuse, and maintain service stability
  • Comply with laws and enforce the Terms of Service

4. Google API Data

The Service uses Google OAuth, the Google Drive API, and Google Picker. Google profile and email information are used for login, sign-up, and account linking. Google Drive item lists are stored only when the user enables the Google Drive display option in the account modal and selects files or folders with Google Picker. The Service displays only those selected files/folders, and items inside selected folders, inside HanDrive. The Service does not arbitrarily sync or display the user's entire Google Drive. Within the selected scope, read, upload, create, update, rename, move, and delete actions are performed only in response to user actions.

When Google Drive display is disabled, the server blocks Google Drive-related HanDrive API access. When a Google account is unlinked, locally stored Google connection data, tokens, and Google Picker selected item lists are deleted. Users may also revoke app access in their Google account security settings.

The Service does not use Google user data for advertising, sale, user tracking, or training general AI/ML models. The Service's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. GitHub Data

The Service uses GitHub OAuth for login, sign-up, and account linking, and to load repositories that the user is authorized to access. Only repositories selected by the user are displayed in the HanDrive root. Within selected repositories, the Service performs file read, edit, add, delete, commit, and branch create/delete actions only in response to user actions.

GitHub connection data and tokens are stored to provide GitHub features. When a GitHub account is unlinked, locally stored GitHub connection data, tokens, and selected repository information are deleted. Users may also revoke app access in GitHub settings.

6. Files, External Storage, and Cache

HanDrive files are stored in the configured service storage location. Depending on operational settings, SSD or HDD storage may be used. GitHub repository cache follows the configured storage location policy and is used to display repository files and improve Git operation speed.

Google Drive files remain in Google Drive by default. For files/folders selected with Google Picker, and items inside selected folders, the Service may transmit or temporarily process file metadata and file content only as needed to fulfill user-requested actions. If a user drags and drops a Google Drive file into HanDrive, a copy of that file may be stored in HanDrive storage.

Files shared through public links may be accessible to anyone with the link. Public-write Markdown files may be edited by authorized external users, so users should avoid sharing sensitive information publicly.

7. Third Parties and Service Providers

We do not sell personal information. Information may be processed by the following services only as needed:

  • Google: Google login, Google account linking, and display/management of Google Picker selected files/folders
  • GitHub: GitHub login, GitHub account linking, repository listing, and repository file/branch/commit actions
  • Forgejo/Gitea: HanDrive-based Git repositories, authentication, clone/push, and collaborator management
  • Email providers: sign-up, verification, notifications, and support
  • CDN, tunnel, web server, hosting, and security infrastructure: service delivery, security, performance, and logs
  • External search engines selected by the user: search queries submitted from the root search feature
  • Local AI server: text submitted by the user to chatbot or translation features

Information may also be disclosed when required by law, valid legal request, user consent, service security, or rights protection.

8. Cookies and Sessions

The Service may use cookies and browser storage to keep users logged in, identify sessions, perform security checks, and store preferences. Users may block or delete cookies in browser settings, but login and some features may not work correctly.

9. Retention and Deletion

We keep information only as long as needed for the purposes described in this policy.

  • Account data: until account deletion
  • OAuth connection data and tokens: until unlinking, account deletion, or token invalidation
  • HanDrive files and sharing settings: until deleted by the user or account deletion
  • Git/GitHub repository cache: until repository deselection, unlinking, account deletion, or operational cleanup
  • Access and error logs: as needed for security, troubleshooting, and abuse prevention
  • Support inquiries: as needed for support and dispute handling

When retention is no longer necessary, information is deleted or de-identified. Backup or log copies may be removed according to regular retention cycles.

10. User Rights

Users may request or perform:

  • Access, correction, or deletion of personal information
  • Deletion of HanDrive files and removal of sharing links
  • GitHub or Google account unlinking
  • Disabling Google Drive display and removing Google Picker selected items
  • Account deletion
  • Privacy inquiries or objections

Users may also revoke OAuth app access directly in Google or GitHub account security settings.

11. Security Measures

The Service applies security measures such as:

  • Password hash storage
  • Restricted access to sessions and tokens
  • User-specific HanDrive path and permission checks
  • Server-side blocking of Google Drive APIs when Google Drive display is disabled and permission checks based on Google Picker selected items
  • GitHub repository selection and permission checks
  • Security and error log monitoring
  • Least-privilege operational access

12. Contact

Operator: Hanbyeol Lim
Email: [email protected]

13. Changes

This Privacy Policy may be updated to reflect changes in laws, external API policies, or Service features. Material changes will be announced on this page or within the Service.

Privacy Policy / Terms of Service