Skip to content
U Utilook
Tools Categories About
English 한국어
Tools Categories About
English 한국어

Privacy Policy

Effective date: August 6, 2026 Last updated: September 4, 2026

Utilook (the “Service”) values the privacy of its users and complies with applicable laws, including the Personal Information Protection Act of Korea. This Privacy Policy explains what information may be processed while using the Service, the purposes of such processing, retention periods, and users’ rights.

Article 1. Basic Principles of Processing

  1. The Service currently does not offer account registration and does not directly require personal information such as your name, resident registration number, phone number, or address in order to use the Service.
  2. The Service processes only the minimum information necessary to provide its features and operate reliably.
  3. Data you enter or upload into a tool may be processed either in your browser or on the Service’s servers, depending on the nature of the tool.
  4. Tools that require server transmission or temporary storage separately explain, on the relevant tool page, how the data is processed, whether it is stored, and the criteria for deletion.
  5. The Service does not use your data beyond the disclosed purposes and the scope permitted by applicable law.

Article 2. Categories of Personal Information That May Be Processed

1. Information you provide directly

If you contact us by email, the following information may be processed:

  • The sender’s email address
  • A name or nickname you provide
  • The subject and content of your inquiry
  • Files you attach
  • Screen or environment information you provide to help identify an issue

You should not send resident registration numbers, financial information, health information, passwords, authentication tokens, or third parties’ personal information that is not necessary for your inquiry.

2. Information that may be generated automatically while using the Service

  • IP address
  • Access date and time
  • Requested URL
  • Browser and operating system information
  • Device type and screen environment
  • Referral path
  • Cookies or similar identifiers
  • Error records
  • Security and access logs
  • Usage statistics such as tool run counts

Some of this information may be processed by Cloudflare, Google Cloud, or advertising/analytics services that may be adopted in the future.

3. Information not directly collected at this time

The Service currently does not directly collect the following as member information:

  • Account IDs and passwords
  • Unique identifiers such as resident registration numbers
  • Payment and credit card information
  • Precise location data
  • Mobile phone contacts
  • Kakao account profiles

The KakaoTalk share feature uses the Kakao JavaScript SDK solely to run the sharing function; the Service does not provide Kakao login or Kakao profile lookup.

Article 3. Purposes of Processing

The Service may use the processed information for the following purposes:

  1. Providing the website and web tools
  2. Reviewing and responding to inquiries, bug reports, and tool suggestions
  3. Analyzing and recovering from service failures
  4. Preventing misuse, automated attacks, and security threats
  5. Analyzing usage status and non-identifiable statistics
  6. Improving service performance and usability
  7. Where advertising applies, delivering ads and measuring their performance
  8. Complying with applicable law and responding to disputes

If the purpose of processing materially changes, we will amend this Policy and follow the necessary procedures in accordance with applicable law.

Article 4. Handling of Tool Input Data and Uploaded Files

  1. Each tool’s data processing may be either browser-based or server-based, depending on the feature.
  2. Data processed only in the browser is not transmitted to the Service’s servers.
  3. Tools that require server processing allow you to review the following on the relevant page:
    • Data sent to the server
    • Purpose of processing
    • Whether it is stored
    • Deletion criteria for temporary files or results
  4. The Service does not include tool inputs, uploaded file names, processing results, session identifiers, or temporary tokens in the default share URL.
  5. Before entering sensitive, confidential, authentication, medical, or financial information, or non-public information of third parties, you should check how the relevant tool processes data.
  6. The Service does not retain your files or input data beyond what is necessary to use the tool.

Article 5. Retention and Use Period

  1. The Service retains personal information only for as long as necessary to achieve the purpose of processing.
  2. Email inquiries and attachments are retained for the period necessary to handle the inquiry and any follow-up, and are then deleted.
  3. Access, error, and security logs are retained for periods set per system in order to respond to incidents, maintain security, and prevent misuse.
  4. Where there is a statutory obligation to retain data, it may be stored separately for the period prescribed by law.
  5. Statistics that are anonymized or aggregated so that individuals cannot be identified may be retained for service improvement.

Article 6. Destruction of Personal Information

  1. When the purpose of processing is achieved or the retention period ends, the information is destroyed without undue delay.
  2. Electronic files are deleted in a manner that makes recovery difficult.
  3. Information that must be retained under applicable law is stored separately from other information and destroyed after the retention period ends.
  4. Information stored in an external provider’s systems may be handled according to that provider’s deletion and retention policies.

Article 7. Provision to Third Parties

  1. As a rule, the Service does not sell or arbitrarily provide your personal information to third parties.
  2. It may be provided within the scope permitted by applicable law in the following cases:
    • Where you have consented in advance
    • Where there is a legal basis
    • Where a relevant authority makes a request through lawful procedures
    • Where urgently necessary to protect life or safety
  3. Where advertising, analytics, or security providers process information to operate their own services, that provider’s privacy policy may also apply.

Article 8. External Services and Processing Activities

In the course of operation, the Service may use the following external services:

  • Cloudflare: DNS, CDN, security, attack mitigation, and email routing
  • Google Cloud: application hosting and server operation
  • Neon: storage and management of Service usage statistics using a PostgreSQL database
  • Kakao: KakaoTalk share feature
  • Have I Been Pwned Pwned Passwords: range lookup using the first 5 characters of a SHA-1 hash for password breach checks
  • Resend: delivery of tool suggestion and problem report emails
  • Google: ad delivery and measurement if the AdSense advertising service is activated

Information that may be processed can include IP address, request information, browser information, security logs, cookies, and advertising identifiers.

Article 9. Overseas Processing or Transfer

In the course of using the global infrastructure of external services such as Cloudflare, Google, Kakao, Have I Been Pwned, and Resend, some information may be processed outside the Republic of Korea.

Where an overseas transfer applies, the Service will confirm and disclose the following in accordance with applicable law:

  • The categories of personal information transferred
  • The destination country
  • The timing and method of transfer
  • The recipient
  • The purpose of transfer
  • The retention and use period
  • How to refuse the transfer and the effects of refusal

Article 10. Cookies and Similar Technologies

  1. The Service uses the following first-party cookies to compile usage statistics and distinguish visit sessions:
    • utilook_visit_date: used to determine whether the same browser has already been counted as a unique visitor for the current day.
    • utilook_session: used to distinguish visit sessions and retained for approximately 30 minutes from the user’s most recent activity.
  2. These cookies do not store personal information directly entered by users, such as names, email addresses, or passwords.
  3. The Service may use these cookies to compile statistics such as daily unique visitors, visit counts, and Service usage.
  4. The Service and external providers may additionally use cookies or similar technologies for the following purposes:
    • Keeping basic preferences
    • Security and prevention of misuse
    • Usage statistics analysis
    • Ad delivery and frequency management where advertising is enabled
    • Ad performance measurement where advertising is enabled
  5. You can delete or block cookies through your browser settings.
  6. If cookies are blocked or deleted, a visit may be counted as a new visit and some features or settings may not be maintained properly.

Article 11. Google AdSense and Advertising Cookies

  1. Third-party advertising services such as Google AdSense may be applied to the Service in the future.
  2. When advertising is activated, third-party ad providers, including Google, may use cookies to serve ads based on your visits to this or other sites.
  3. Through Google’s advertising cookies, Google and its partners may serve ads based on your visit history to sites.
  4. You can manage personalized advertising and cookie use through Google’s Ads Settings and your browser settings.
  5. Where advertising is not yet activated, we do not use expressions that could imply that ads are currently being served.
  6. When an advertising service is actually applied, we will review this Policy together with consent-management features.

Article 12. Consent Management for Overseas Users

Where cookie-based advertising or analytics features are provided in the European Economic Area, the United Kingdom, Switzerland, or similar regions, the Service will provide the notices and consent-management features required under applicable law and Google’s policies.

When AdSense is applied, we will configure a certified CMP or an appropriate consent-management feature as required by Google.

Under applicable law, you may have rights such as access to, correction of, deletion of, restriction of, and objection to the processing of your personal information, as well as withdrawal of consent.

Posting this Privacy Policy alone does not replace a cookie consent process.

Article 13. Security Measures

Taking into account the nature and level of risk of the personal information processed, the Service applies the following protective measures:

  1. Encrypted communication via HTTPS
  2. Minimizing administrator access privileges
  3. Separate management of environment variables and credentials
  4. Use of security services and access restrictions
  5. Security updates for the application and servers
  6. Restricting access to logs and inquiry information
  7. Deleting information that is no longer needed
  8. Checking that secrets are not included in public repositories
  9. Response and recovery in the event of a security incident

This article should not be interpreted as guaranteeing absolute security or the prevention of all incidents.

Article 14. Your Rights and How to Exercise Them

Under applicable law, you may request the following regarding your personal information:

  • Access
  • Correction
  • Deletion
  • Suspension of processing
  • Withdrawal of consent
  • Deletion of inquiry emails

Request email: [email protected]

The Service may request identity verification to the minimum extent necessary to handle your request. A request may be limited where it would infringe a third party’s rights or where there is a statutory retention obligation.

Article 15. Children’s Personal Information

The Service currently does not offer account registration or personal-information collection services aimed at children under the age of 14.

If it is confirmed that a child under the age of 14 provided personal information during an inquiry, the child or their legal representative may request deletion of that information.

Article 16. Privacy Inquiries

  • Service name: Utilook
  • Privacy inquiries: [email protected]

We do not arbitrarily state the real name of a privacy officer or business registration details that have not been confirmed.

If disclosure of officer information becomes necessary due to the business form or legal requirements, this Policy will be updated.

Article 17. Changes to This Privacy Policy

  1. This Policy may be amended in response to changes in law, service features, data processing methods, or external services.
  2. Changes that materially affect users’ rights will be announced through the site before they take effect.
  3. When changes occur, we manage them so that the previous version and its effective date can be identified.

Contact: [email protected]

U Utilook

Free web tools, ready in your browser.

About Privacy Policy Terms of Service Contact Sitemap
© 2026 Utilook. All rights reserved.

Share