stock EAGLE by Milestone

개인정보처리방침

마일스톤 파이낸셜 그룹(이하 “회사”)은 stock EAGLE(이하 “서비스”) 이용자의 개인정보를 「개인정보 보호법」에 따라 아래와 같이 처리합니다. Google 로그인 정보의 접근·이용·저장·공유·삭제는 제9항, 개인정보 권리 행사와 삭제 요청 방법은 제10항에서 확인할 수 있습니다.

English version of this policy ↓

서비스명 stock EAGLE (stock-eagle.co.kr)
운영자 마일스톤 파이낸셜 그룹
사업자등록번호 540-87-02389
주소 서울특별시 성동구 왕십리로 137, 116동 21층 4호
시행일 2026년 9월 8일

1. 수집하는 개인정보 항목과 수집 방법

stock EAGLE은 이용자가 직접 입력한 국내 주식 보유 내역을 바탕으로 종가(EOD) 기준 평가금액·손익, 리스크와 테마 노출을 확인하는 서비스입니다. 증권사 계좌를 연결하거나 주문을 실행하지 않습니다. 회사는 아래 정보를 회원 인증과 서비스 제공에 사용하며, 주민등록번호나 증권사 계좌 비밀번호를 수집하지 않습니다.

구분·수집 시점처리하는 항목용도
이메일 회원가입이메일 주소, 비밀번호계정 생성과 로그인. 비밀번호는 해시로 변환하여 보관
간편로그인제공자명, 제공자의 회원 식별값, 이메일 주소, 이름 또는 닉네임. Google 이메일 인증 여부는 계정 연결 판단 시 일시 처리카카오·Google·네이버를 통한 회원 식별, 계정 생성·연결과 표시 이름 설정. 제공자가 전달하는 항목에 한함
계정 생성·승인·로그인 과정서비스 회원 번호, 가입 시각, 권한, 승인 상태, 승인 담당자와 시각, 간편로그인 연결·최근 로그인 시각, 비밀번호 변경 시각, 로그인 유효성 확인 정보회원별 접근 권한과 승인 이력 관리, 로그인 및 보안 관리
포트폴리오·관심종목 입력포트폴리오 이름, 보유 종목·수량·매입단가, 관심종목, 등록 시각회원별 보유 내역 저장, 종가 기준 평가·분석 및 관심종목 조회
인증 시도접속 IP 주소, 인증 종류, 입력한 이메일 주소 또는 로그인 식별값, 시도 시점반복적인 가입·로그인·비밀번호 재설정 등의 요청 제한
비밀번호 재설정 요청이메일 주소, 회원 번호, 재설정 토큰의 해시, 생성·만료·사용 시각, 재설정 안내 내용에 관한 운영 기록요청 확인, 재설정 링크의 유효성 확인과 재사용 방지

비밀번호 원문은 회원 데이터베이스에 저장하지 않습니다. 무작위 솔트를 적용한 PBKDF2-SHA256(반복 600,000회) 해시로 보관합니다. 간편로그인으로 새로 만든 계정에는 서비스 비밀번호가 설정되어 있지 않으며, Google 등 제공자의 비밀번호도 전달받지 않습니다.

2. 개인정보의 처리 목적

가입 승인 여부는 서비스의 로그인·승인 대기 화면에서 확인합니다. 회사는 개인정보를 광고성 정보 전송이나 마케팅에 이용하지 않습니다.

3. 보유 및 이용 기간

정보보유 기간과 삭제 기준
회원·간편로그인 연결 정보회원 관계 유지 및 인증에 필요한 동안 보유합니다. 탈퇴·삭제 요청은 제10항의 이메일로 접수하며, 본인 확인 후 불필요해진 정보를 지체 없이 파기합니다.
포트폴리오·관심종목이용자가 해당 내역을 삭제하거나 회원 탈퇴를 요청할 때까지 보유합니다. 탈퇴 요청의 삭제 대상에 함께 포함됩니다.
Google 이메일 인증 여부·접근 토큰해당 로그인 요청 처리 중에만 사용하며 회원 데이터베이스나 이용자의 브라우저 저장소에 보관하지 않습니다. 상세 내용은 제9항을 참고하십시오.
인증 시도 제한 기록서버 메모리에서 최근 15분의 시도를 판단합니다. 같은 식별값의 다음 요청, 일부 인증 성공 또는 오래된 항목 정리 시 제거되며, 서버 프로세스 종료 시 사라집니다. 15분은 차단 판단 구간으로, 모든 IP·식별값이 15분 후 일괄 삭제된다는 뜻은 아닙니다.
비밀번호 재설정 정보링크의 유효기간은 30분이며 사용 후 다시 사용할 수 없습니다. 유효기간 만료만으로 기록이 삭제되지는 않습니다. 다시 요청하면 이전의 미사용 토큰 기록을 삭제하며, 남은 회원별 기록은 탈퇴·삭제 요청의 대상에 포함됩니다.
데이터베이스 백업장애 복구를 위해 일별 백업은 7일, 주별 백업은 4주 보관하도록 순환 정리합니다. 운영 데이터에서 삭제된 정보도 기존 백업에는 해당 백업의 보관 기간이 끝날 때까지 남을 수 있습니다.

비밀번호 재설정 안내의 이메일 주소와 내용은 현재 서버 운영 기록에 남습니다. 안내에는 재설정 링크가 포함되므로, 계정 관련 삭제 요청 시 이 기록에 대해서도 함께 요청할 수 있습니다. 법령에 따른 별도의 보존 의무가 있는 경우에는 해당 근거와 기간에 따라 보관하며 다른 목적으로 사용하지 않습니다.

4. 개인정보의 제3자 제공

회사는 이용자의 개인정보를 판매하거나 독립적인 제3자의 목적으로 제공하지 않습니다. 광고·마케팅 사업자에게도 제공하지 않습니다. 법령에 근거가 있거나 적법한 절차에 따른 요구가 있는 경우에는 그 범위에서 처리합니다. 서비스 운영을 위한 처리위탁은 제5항과 같이 별도로 안내합니다.

5. 개인정보 처리의 위탁

수탁자위탁 업무·처리 범위
Amazon Web Services, Inc.일본 도쿄 리전의 서버·데이터베이스·백업 운영 및 보관. 회원·간편로그인 연결 정보, 입력한 포트폴리오·관심종목과 서비스 운영에 필요한 인증·재설정 기록 처리

현재 서비스는 AWS SES를 통한 이메일 발송을 사용하지 않습니다. 비밀번호 재설정 안내는 서버 운영 기록으로 남으며 이용자의 이메일로 자동 발송되지 않습니다. 가입 승인 시에도 자동 안내 메일을 발송하지 않습니다. 이메일 발송 위탁을 시작하는 경우 실제 수탁 업무와 처리 정보를 이 방침에 반영합니다.

회사는 위탁 업무의 목적과 범위 내에서 개인정보가 처리되도록 관리하며, 개인정보 문의는 제13항의 보호책임자가 접수합니다.

6. 개인정보의 국외 이전

서비스의 서버, 데이터베이스와 백업은 일본에 위치합니다. 회원가입·로그인 및 서비스 이용 과정에서 정보가 일본의 서버로 전송되어 처리·보관됩니다.

구분내용
이전받는 자·연락 창구Amazon Web Services, Inc. (AWS), AWS 개인정보 문의 안내. 서비스 회원 정보의 권리 행사는 아래 회사 연락처로 접수
국가·보관 위치일본, AWS 아시아 태평양 도쿄 리전(ap-northeast-1)
이전 목적서비스 제공에 필요한 서버 처리, 회원·입력 정보 보관 및 장애 복구용 백업
이전 항목제1항의 서비스 수집·생성 정보와 제9항의 Google 로그인 처리 정보. 이용자 브라우저의 저장소 전체를 이전하는 것은 아닙니다.
시점·방법가입·로그인·정보 입력·조회 등 서비스 이용 시 HTTPS 등 암호화된 통신을 통해 전송하고 서버에서 처리·보관
보유·이용 기간제3항의 정보별 기간과 삭제 기준 적용. 로그인 중 일시 처리하는 정보와 회원 정보·백업의 보유 기간은 서로 다릅니다.
문의·거부 방법vostage99@gmail.com으로 국외 이전 관련 문의, 처리 정지 또는 탈퇴·삭제 요청 접수

국외 이전을 원하지 않는 이용자는 서비스 이용을 중단하고 위 연락처로 처리 정지·삭제를 요청할 수 있습니다. 서비스가 일본 서버에서 회원 인증과 데이터 저장을 수행하므로 이 처리를 거부하면 회원 서비스를 제공하기 어렵습니다.

7. 쿠키 및 브라우저 저장소

이름·종류목적보관·삭제
oauth_state
HttpOnly 쿠키
간편로그인 요청과 응답의 일치 확인 및 요청 위조(CSRF) 방지최대 10분. 로그인 완료 시 삭제하며, 로그인 취소 시에는 만료까지 남을 수 있음. 브라우저에서도 삭제 가능
stock_ai_token
브라우저 로컬 저장소
stock EAGLE이 발급한 서비스 로그인 토큰 보관. Google 접근 토큰이 아님로그아웃, 앱이 인증 만료를 확인한 때 또는 이용자가 브라우저 저장 데이터를 지울 때 삭제. 토큰의 유효기간 만료와 저장소에서의 삭제는 별개
auth_notice
브라우저 세션 저장소
로그인 만료 안내 문구의 일시 보관로그인 화면에서 안내를 읽어 오거나 브라우저의 해당 탭 세션이 종료될 때 삭제

서비스가 사용하는 쿠키는 위 oauth_state 하나이며, 광고·행태정보 수집 목적의 쿠키나 제3자 분석·광고 도구를 사용하지 않습니다. 브라우저 설정에서 쿠키와 사이트 저장 데이터를 삭제하거나 차단할 수 있으나 간편로그인 또는 로그인 상태 유지가 제한될 수 있습니다.

8. 간편로그인으로 수집하는 정보

이용자가 카카오·Google·네이버 계정으로 가입하거나 로그인하는 경우, 회사는 허용된 권한 범위에서 제공자가 전달한 식별값·이메일·이름 또는 닉네임을 처리합니다. 회사는 제공자의 비밀번호를 전달받지 않습니다.

제공자명과 회원 식별값을 기준으로 이미 연결된 계정을 찾습니다. 기존 연결이 있으면 로그인 시각과 제공자 이메일을 갱신합니다. 제공자 쪽에서 이메일을 바꾸어도 동일 식별값의 연결을 찾으며, 이 변경이 서비스의 회원 이메일·이름 변경으로 자동 반영되는 것은 아닙니다.

각 제공자의 계정 설정에서 서비스 연결을 해제할 수 있습니다. 연결 해제와 stock EAGLE에 이미 저장한 정보의 삭제는 별개이므로, 회원 정보 삭제는 제10항에 따라 요청해 주십시오.

9. Google 사용자 데이터의 처리

stock EAGLE은 Google 로그인을 회원 인증 수단으로 사용합니다. Google에서 받은 기본 계정 정보로 서비스 계정을 만들거나 기존 계정에 연결하며, 이용자가 직접 입력한 주식 보유 내역을 Google 계정에서 가져오지 않습니다.

요청하는 권한 범위와 항목

범위사용하는 항목목적·저장 여부
openidGoogle 계정 고유 식별자(sub)동일 이용자 식별과 계정 연결. 데이터베이스에 저장
email이메일 주소, 이메일 인증 여부(email_verified)계정 생성·연결 판단. 이메일은 저장하고 인증 여부는 해당 로그인 처리에만 사용
profile이름(표시 이름, name)계정 생성 시 표시 이름 및 간편로그인 연결 정보로 저장. 제공되지 않으면 이름 없이 처리

요청 범위는 openid, email, profile 세 가지입니다. Gmail 메일 내용, Google Drive 파일, Calendar 일정, Contacts 연락처에 접근하거나 해당 권한을 요청하지 않습니다. 기본 프로필 응답에 사진 URL·언어 등 추가 필드가 포함될 수 있으나, 서비스는 이 추가 필드를 사용하거나 데이터베이스에 저장하지 않습니다.

접근 (Access)

이용자가 Google 로그인을 진행할 때마다 서버가 Google의 인증 코드를 접근 토큰으로 교환하고 사용자 정보 API를 조회합니다. 최초 가입 시에만 조회하는 것은 아닙니다. 조회는 해당 로그인 절차에서 이루어지며, 로그인 후 백그라운드에서 Google 계정을 계속 조회하지 않습니다. Google 비밀번호를 받지 않고, 오프라인 접근 권한이나 리프레시 토큰을 요청하지 않습니다.

이용 (Use)

Google 사용자 데이터를 광고, 광고 목적의 프로파일링, 데이터 판매 또는 인공지능·머신러닝 모델 학습에 사용하지 않습니다.

저장과 보호 (Storage and protection)

Google 식별자·이메일·이름은 서비스 회원 정보 및 간편로그인 연결 정보로 저장합니다. 연결 정보에는 제공자명, 서비스 회원 번호, 연결 생성 시각과 최근 로그인 시각도 포함됩니다. 보관 위치는 일본 도쿄의 AWS 서버·데이터베이스이며, 계정 유지·삭제와 백업 보유 기간은 제3항을 따릅니다.

Google 접근 토큰은 해당 서버 로그인 요청에서 사용자 정보를 조회하는 데만 사용합니다. Google 접근 토큰·ID 토큰·리프레시 토큰과 이메일 인증 여부를 회원 데이터베이스나 브라우저 저장소에 저장하지 않습니다. 브라우저에 저장하는 토큰은 stock EAGLE이 별도로 발급한 서비스 로그인 토큰입니다. 전송 구간 암호화와 계정별 권한 확인 등 보호 조치는 제12항과 같습니다.

공유와 이전 (Sharing and transfer)

Google 사용자 데이터를 판매하거나 제3자의 독립적인 목적으로 제공하지 않습니다. 제5항의 AWS가 서비스 운영·보관·백업 업무를 처리하며, 제6항과 같이 일본에서 보관합니다. 법령에 따른 적법한 요구가 있는 경우를 제외하고 다른 외부 사업자의 광고·분석 목적으로 전달하지 않습니다. 회사 담당자는 회원 승인, 이용자가 요청한 지원·권리 행사 처리, 보안 또는 법적 의무 수행에 필요한 범위에서만 접근합니다.

삭제 요청과 Google 연결 해제 (Deletion and revocation)

저장된 Google 연결 정보와 회원 정보의 열람·정정·삭제 또는 탈퇴는 vostage99@gmail.com으로 요청할 수 있습니다. 요청 계정의 이메일과 원하는 처리 내용을 알려주시면 본인 확인 후 처리합니다. 비밀번호나 인증 코드는 보내지 마십시오. 회원 탈퇴 요청은 Google 연결 정보, 회원 정보, 포트폴리오·관심종목 및 관련 회원별 기록을 대상으로 하며, 백업의 순환 삭제는 제3항을 따릅니다.

Google 계정의 연결 관리에서 stock EAGLE의 접근 권한을 해제할 수도 있습니다. Google 연결을 해제해도 stock EAGLE 데이터베이스의 기존 정보가 자동 삭제되거나 이미 발급된 서비스 로그인 토큰이 즉시 무효화되지는 않습니다. 서비스 이용 종료와 저장 정보 삭제를 원하면 stock EAGLE에서 로그아웃하고 위 연락처로 탈퇴·삭제를 요청해 주십시오.

Google API 서비스 사용자 데이터 정책 준수

stock EAGLE이 Google API로부터 받은 정보를 이용하고 다른 앱으로 전송하는 행위는, 제한적 사용(Limited Use) 요건을 포함한 Google API 서비스 사용자 데이터 정책을 준수합니다.

Google User Data (English summary)

App and purpose: stock EAGLE, operated by Milestone Financial Group, uses Google sign-in to authenticate members of its end-of-day stock portfolio service.

Scopes and data: We request only openid, email, and profile. We use the Google account identifier, email address, email verification status, and display name. Additional profile fields, such as a picture URL or locale, may be returned but are not used or saved to our database. We do not access Gmail messages, Drive files, Calendar events, or Contacts.

Access and use: During each Google sign-in, our server exchanges the authorization code and retrieves user information to create or link the account. Verified email is required when first linking to an existing account with the same email. Authorized staff use the member email, name, and approval status to manage service access. We do not receive Google passwords, request offline access or refresh tokens, or fetch Google data in the background after sign-in.

Storage and protection: The identifier, email, and name are stored with the account link and its creation and last sign-in times on AWS in Tokyo, Japan. Email verification status and Google tokens are not stored in the member database or browser storage. The browser stores a separate stock EAGLE session token. HTTPS and role-based access controls protect access to the service.

Sharing: AWS processes data for hosting and backups as described in Sections 5 and 6. We do not sell Google data, disclose it for independent third-party purposes, or use it for advertising, advertising profiles, or AI/ML training. Legally required disclosures are limited to their lawful scope. AWS SES email delivery is not currently enabled.

Retention and deletion: Account data is retained while needed for the membership. Request access, correction, account closure, or deletion at vostage99@gmail.com, identifying the account and your request without sending passwords or authentication codes. We verify the requester and delete data no longer needed. Account deletion includes the Google link and member portfolio/watchlist data. Daily database backups rotate after 7 days and weekly backups after 4 weeks; deleted live data may remain in those backups until rotation.

Revocation: You may revoke access in Google account connections. Revocation does not automatically delete data already stored by stock EAGLE or immediately invalidate an existing stock EAGLE session. Sign out and contact us separately to request account and data deletion.

stock EAGLE's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. 정보주체의 권리와 행사 방법

이용자는 개인정보의 열람·정정·삭제·처리 정지를 요구할 수 있습니다. 법정대리인이나 위임을 받은 자를 통해서도 요청할 수 있습니다.

Google에서 서비스 연결을 해제하는 방법과 서비스에 남은 정보를 삭제하는 방법은 제9항에 안내되어 있습니다. 회원 식별·인증에 필요한 정보의 처리 정지나 삭제를 요청하면 해당 계정의 서비스 이용이 제한될 수 있습니다.

11. 개인정보의 파기

회사는 보유 기간이 끝나거나 처리 목적이 달성된 개인정보를 지체 없이 파기합니다. 탈퇴·삭제 요청은 보호책임자가 본인 확인 및 삭제 대상 확인을 거쳐 처리합니다. 운영 데이터와 백업은 구분하여 처리하며, 백업은 제3항의 보관 기간에 따른 순환 정리 대상입니다. 법령상 보존 의무로 즉시 삭제할 수 없는 정보가 있다면 해당 사유와 기간을 요청자에게 안내합니다.

12. 안전성 확보 조치

13. 개인정보 보호책임자

개인정보 처리에 관한 문의, 불만 처리, 피해 구제는 아래로 연락해 주십시오. 회사는 지체 없이 답변하겠습니다.

개인정보 보호책임자 윤성현 / 정보보호 총괄
연락처 vostage99@gmail.com

14. 권익침해 구제 방법

개인정보 침해로 인한 신고나 상담이 필요하시면 아래 기관에 문의하실 수 있습니다.

15. 처리방침의 변경

이 방침을 변경하는 경우 시행일 최소 7일 전부터 이 페이지와 서비스 화면을 통해 알립니다. 다만 이용자의 권리에 중대한 영향을 미치는 변경은 30일 전에 알립니다. Google 사용자 데이터의 이용 목적이나 처리 범위를 변경할 때에는 변경 내용을 알리고 필요한 동의를 받은 후 적용합니다.


Privacy Policy (English)

This is the complete English version of the Korean policy above. Milestone Financial Group (“the Company”) processes the personal data of stock EAGLE (“the Service”) users as described below, in accordance with the Personal Information Protection Act of the Republic of Korea. Where the two versions differ, the Korean text governs.

Service stock EAGLE (stock-eagle.co.kr)
Operator Milestone Financial Group
Business registration number 540-87-02389
Address 21F-4, Bldg 116, 137 Wangsimni-ro, Seongdong-gu, Seoul, Republic of Korea
Effective date 8 September 2026

1. Personal data we collect and how we collect it

stock EAGLE lets a user record the Korean-listed stocks they hold and see end-of-day (EOD) valuation, profit and loss, risk and theme exposure calculated from those entries. The Service does not connect to brokerage accounts and does not place orders. We use the data below to authenticate members and provide the Service. We do not collect resident registration numbers or brokerage account passwords.

When collectedData processedPurpose
Email sign-upEmail address, passwordAccount creation and sign-in. The password is stored only as a hash.
Social sign-inProvider name, provider member identifier, email address, name or nickname. For Google, the email verification status is processed transiently when deciding account linking.Identifying the member via Kakao, Google or Naver, creating or linking the account, and setting a display name. Limited to what the provider supplies.
Account creation, approval and sign-inService member number, sign-up time, role, approval status, approver and approval time, social link and last sign-in time, password change time, session validity informationManaging per-member access rights and approval history, sign-in and security.
Portfolio and watchlist entryPortfolio name, holdings with quantity and average cost, watchlist items, entry timeStoring each member's holdings and providing EOD valuation, analysis and watchlist lookups.
Authentication attemptsIP address, authentication type, submitted email address or login identifier, time of attemptRate-limiting repeated sign-up, sign-in and password-reset requests.
Password reset requestsEmail address, member number, hash of the reset token, creation, expiry and use times, and operational records of the reset noticeConfirming the request, validating the reset link and preventing reuse.

We do not store password plaintext in the member database. Passwords are stored as PBKDF2-SHA256 hashes with a random salt and 600,000 iterations. Accounts created through social sign-in have no Service password, and we never receive the password held by Google or any other provider.

2. Purposes of processing

Approval status is shown on the Service's sign-in and pending-approval screens. We do not use personal data for advertising or marketing messages.

3. Retention periods

DataRetention and deletion
Member and social link dataRetained while needed to maintain and authenticate the membership. Closure and deletion requests are received at the address in Section 10; after verifying the requester we delete data that is no longer needed without undue delay.
Portfolio and watchlistRetained until the user deletes the entries or requests account closure. Included in the scope of a closure request.
Google email verification status and access tokenUsed only while that sign-in request is being processed. Not stored in the member database or in the user's browser storage. See Section 9.
Authentication rate-limit recordsHeld in server memory and evaluated over the most recent 15 minutes. Removed on the next request for the same identifier, on certain successful authentications, or when stale entries are cleared, and lost when the server process stops. The 15 minutes is the blocking window, not a guarantee that every IP or identifier is purged after 15 minutes.
Password reset dataThe link is valid for 30 minutes and cannot be reused once used. Expiry alone does not delete the record. A new request deletes the previous unused token record; remaining per-member records fall within the scope of a closure or deletion request.
Database backupsFor disaster recovery, daily backups rotate after 7 days and weekly backups after 4 weeks. Data deleted from live systems may remain in an existing backup until that backup's retention period ends.

The recipient address and content of a password reset notice currently remain in server operational records, and that notice contains the reset link, so a deletion request for an account may also cover those records. Where a law requires separate retention, we keep the data on that legal basis for the required period and use it for no other purpose.

4. Provision to third parties

We do not sell personal data and do not provide it for the independent purposes of any third party, including advertising and marketing companies. Where there is a legal basis or a lawful request, we process data within that scope. Processing entrusted to service providers is described separately in Section 5.

5. Entrusted processing

ProcessorScope of entrusted work
Amazon Web Services, Inc.Operating and storing servers, databases and backups in the Tokyo region of Japan, covering member and social link data, the portfolios and watchlists users enter, and the authentication and reset records needed to run the Service.

The Service does not currently send email through AWS SES. Password reset notices remain in server operational records and are not automatically delivered to the user's mailbox, and no automated notice is sent on approval. If we begin entrusting email delivery, we will update this policy to reflect the actual work and data involved. We manage entrusted processing so that data is handled only within the stated purpose and scope; privacy enquiries are received by the officer named in Section 13.

6. Transfer of personal data abroad

The Service's servers, databases and backups are located in Japan. When you sign up, sign in or use the Service, data is transmitted to and processed and stored on servers in Japan.

ItemDetails
Recipient and contactAmazon Web Services, Inc. (AWS). Requests concerning Service member data are received at the Company address below.
Country and locationJapan — AWS Asia Pacific (Tokyo) region, ap-northeast-1.
PurposeServer processing required to provide the Service, storage of member and entered data, and backups for disaster recovery.
Data transferredThe data collected and generated as described in Section 1 and the Google sign-in data described in Section 9. The entire contents of the user's browser storage are not transferred.
Timing and methodTransmitted over encrypted connections such as HTTPS when signing up, signing in, entering or viewing data, then processed and stored on the server.
RetentionPer-item periods and deletion criteria in Section 3 apply. Data processed transiently during sign-in and stored member data and backups have different retention periods.
Enquiries and objectionContact vostage99@gmail.com to ask about the transfer or to request suspension of processing, account closure or deletion.

A user who does not want their data transferred abroad may stop using the Service and request suspension or deletion at the address above. Because the Service performs member authentication and data storage on servers in Japan, we cannot provide the member service if this processing is refused.

7. Cookies and browser storage

Name and typePurposeRetention and deletion
oauth_state
HttpOnly cookie
Matching a social sign-in request to its response and preventing request forgery (CSRF).Up to 10 minutes. Deleted when sign-in completes; if sign-in is cancelled it may remain until expiry. Can also be cleared in the browser.
stock_ai_token
Browser local storage
Holding the session token issued by stock EAGLE. This is not a Google access token.Removed on sign-out, when the app detects an expired session, or when the user clears site data. Token expiry and removal from storage are separate events.
auth_notice
Browser session storage
Temporarily holding a session-expiry message.Removed once the sign-in screen reads the message, or when that browser tab's session ends.

oauth_state is the only cookie the Service sets. We do not use advertising or behavioural cookies and do not embed third-party analytics or advertising tools. You may block or clear cookies and site data in your browser, though social sign-in or staying signed in may then not work.

8. Data collected through social sign-in

When a user signs up or signs in with a Kakao, Google or Naver account, we process the identifier, email address and name or nickname supplied by that provider within the permissions granted. We never receive the password held by the provider.

We look up an existing link using the provider name and member identifier. If a link exists, we update the sign-in time and the provider email. If the user changes their email at the provider, we still match the same identifier; that change is not automatically applied to the Service member email or name.

You can disconnect the Service in each provider's account settings. Disconnecting is separate from deleting data already stored by stock EAGLE — to delete member data, make a request under Section 10.

9. Google user data

stock EAGLE uses Google sign-in as a means of member authentication. We use the basic account information received from Google to create a Service account or link an existing one. The stock holdings shown in the Service are entered by the user and are never retrieved from a Google account.

Scopes requested and data used

ScopeData usedPurpose and storage
openidGoogle account identifier (sub)Identifying the same user and linking the account. Stored in the database.
emailEmail address, email verification status (email_verified)Creating the account and deciding whether to link it. The email is stored; the verification status is used only while that sign-in is processed.
profileDisplay name (name)Stored as the display name and as part of the social link record. If not supplied, the account is created without a name.

We request only openid, email and profile. We do not access, and do not request access to, Gmail messages, Google Drive files, Calendar events or Contacts. The basic profile response may include additional fields such as a picture URL or locale; the Service neither uses nor stores those fields.

Access

Each time a user signs in with Google, our server exchanges the authorization code for an access token and calls the user-info API. This is not limited to the first sign-up. The call happens during that sign-in only; we do not query the Google account in the background afterwards. We do not receive Google passwords and do not request offline access or refresh tokens.

Use

We do not use Google user data for advertising, advertising profiles, data sales, or artificial intelligence or machine learning model training.

Storage and protection

The Google identifier, email and name are stored as member data and as a social link record, which also holds the provider name, Service member number, link creation time and last sign-in time. They are stored on AWS servers and databases in Tokyo, Japan; retention on account closure and in backups follows Section 3. A Google access token is used only to retrieve user information during that server-side sign-in request. We do not store Google access tokens, ID tokens, refresh tokens or the email verification status in the member database or in browser storage. The token stored in the browser is a separate stock EAGLE session token. Protection measures such as transport encryption and per-account authorization are described in Section 12.

Sharing and transfer

We do not sell Google user data or provide it for the independent purposes of a third party. AWS performs hosting, storage and backup work as described in Section 5, in Japan as described in Section 6. Except for lawful legal requests, we do not pass this data to other external companies for advertising or analytics. Company staff access it only as needed for member approval, handling a support or data-subject request from the user, security, or legal obligations.

Deletion and revocation

To access, correct or delete stored Google link data and member data, or to close your account, email vostage99@gmail.com with the account email and the action you want. We verify the requester before acting. Please do not send passwords or authentication codes. An account closure request covers the Google link record, member data, portfolio and watchlist entries and related per-member records; backup rotation follows Section 3.

You may also revoke stock EAGLE's access in your Google account connections. Revoking access does not automatically delete data already held in the stock EAGLE database and does not immediately invalidate a Service session token that has already been issued. To stop using the Service and delete stored data, sign out of stock EAGLE and send a closure request to the address above.

Compliance with the Google API Services User Data Policy

stock EAGLE's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Your rights and how to exercise them

You may request access to, correction of, deletion of, or suspension of the processing of your personal data. A legal representative or an authorised agent may also make the request.

How to disconnect the Service at Google and how to delete data held by the Service are described in Section 9. If you request suspension or deletion of data required to identify and authenticate a member, use of that account may be restricted.

11. Destruction of personal data

We destroy personal data without undue delay once the retention period ends or the purpose is achieved. Closure and deletion requests are handled by the privacy officer after verifying the requester and the scope of deletion. Live data and backups are handled separately; backups are subject to the rotation periods in Section 3. If a legal retention obligation prevents immediate deletion, we tell the requester the basis and the period.

12. Security measures

13. Privacy officer

Please direct enquiries, complaints and remedy requests about the processing of personal data to the contact below. We will respond without undue delay.

Privacy officer Yoon Seonghyeon / Head of Information Security
Contact vostage99@gmail.com

14. Remedies for infringement

If you need to report or consult about a privacy infringement, you may contact the Korean authorities below.

15. Changes to this policy

If we change this policy we will give notice on this page and in the Service at least 7 days before the effective date, and at least 30 days before for changes that materially affect user rights. If we change the purpose or scope of processing of Google user data, we will give notice and obtain any required consent before applying the change.