Mintdesk Gateway

Privacy Policy

민타 ("the Company") publishes this policy under the Korean Personal Information Protection Act. We collect the minimum needed to run the service, and the remote screen, input, files, and clipboard are technically unreadable to us.

Last updated: 13 September 2026Effective: 13 September 2026

This is a translation provided for convenience. The Korean version at mintdesk.minta.kr/legal/privacy.html is the binding text; if the two differ, the Korean version prevails.

Article 1 (Purposes of processing)

The Company processes personal data for the purposes below. If a purpose changes, consent is obtained beforehand.

  • creating and authenticating accounts (email code sign-in);
  • identifying registered Macs and relaying gateway connections;
  • applying plans, processing payments and refunds, issuing tax invoices;
  • preventing abuse and brute-force attacks and keeping the service stable;
  • showing you your connection history so you can detect account misuse yourself;
  • service announcements and answering enquiries.

Article 2 (What we collect and how)

Categories collected
CategoryDataHow
Account Email address, plan, sign-up date Entered by you
Authentication Hash of the sign-in code, IP and time of the code request, hash of the web session token, browser user agent Generated during sign-in
Device Device name you choose, hash of the device token, app version, last seen time When a Mac is registered
Connection history Session start and end time, client IP address, device name, bytes transferred, end reason Generated on each gateway connection
Usage Monthly total of transferred bytes per account Aggregated from connection history
Payment Order number, amount, payment time, payment status Via the payment provider
Enquiries Email address and whatever the message contains Sent by you

The Company neither collects nor stores card or bank account numbers; the payment provider handles that data.

The gateway credential password is a random value generated by the Company, and the database keeps only the hash required for remote desktop authentication (the NT hash). Device tokens, web session tokens, and sign-in codes are stored only as SHA-256 hashes.

The Company does not knowingly collect personal data from children under 14.

Article 3 (What we cannot see)

The gateway relays encrypted traffic between the connecting device and your Mac. Encryption for the remote desktop traffic (TLS and Network Level Authentication) terminates at both ends, so the Company is technically unable to read:

the content of the remote screen, keyboard and mouse input, clipboard contents, files transferred remotely, or your Mac's login password.

What the Company can observe is limited to who (account), under which device name, from which IP address, when, and how many bytes were exchanged.

Article 4 (Retention periods)

Retention
DataRetention
Account data (email, plan)Until the account is deleted; destroyed immediately on request
Device data (name, token hash, app version)Destroyed immediately when the device is unregistered or the account deleted
Connection history (sessions)90 days; the IP address is deleted after 30 days
Server operation logs30 days
Sign-in codes, web sessionsDestroyed on expiry (codes 10 minutes, sessions 30 days)
Monthly usage totalsDestroyed immediately when the account is deleted
Payment and refund recordsUnder the Act on Consumer Protection in Electronic Commerce: contract and withdrawal records 5 years, payment records 5 years, consumer complaint and dispute records 3 years

Deleting your account immediately deletes your devices and connection history. Payment records that must be kept by law are stored separately from other data for the statutory period and are not used for any other purpose.

Article 5 (Processors)

Processors and tasks
ProcessorTaskLocation
Toss Payments Co., Ltd. Payment and refund processing, payment method authentication Republic of Korea
Resend, Inc. (USA) Sending sign-in codes and service emails Resend, Inc. (USA) infrastructure
Vultr Holdings Corporation Server and database hosting Seoul region, Republic of Korea

The gateway servers and database are located in the Seoul region of the Republic of Korea. Error reporting and log analysis run on infrastructure the Company operates itself and are not sent to an external SaaS. Error reports are configured not to include personally identifying information.

Processing contracts set out in writing the obligation to follow the Company's instructions, restrictions on sub-processing, security measures, and liability for damages, and the Company supervises how processors handle the data. Changes of processor or task are published in this policy.

Article 6 (Disclosure to third parties)

The Company does not disclose personal data to third parties, except where:

  • you have consented in advance; or
  • a law specifically requires it, or an investigative authority lawfully requests it following the procedure and form prescribed by law.

The Company refuses requests that do not follow lawful procedure, and informs the affected user that a request was made to the extent the law permits.

Article 7 (Your rights and how to use them)

You may at any time request access to, correction of, deletion of, or suspension of processing of your personal data. You can do the following yourself in the dashboard:

  • view connection history (time, IP, device, bytes for recent sessions);
  • rename or unregister a device;
  • reissue the gateway credential;
  • delete the account, which immediately deletes devices and connection history.

Other requests go to [email protected]; the Company acts without delay and in any case within 10 days, and informs you of the result. You may act through a legal representative or an authorised agent.

A request may be restricted where the data must be kept by law, or where granting it would unfairly harm the life, body, or property of another person; the reason is given.

Article 8 (Destruction of data)

Personal data is destroyed without delay once its retention period ends or its purpose is achieved.

  • Electronic files are deleted from the database in a manner that prevents recovery. IP addresses in connection history are removed automatically after 30 days, and the session records themselves after 90 days.
  • Backups are stored encrypted and expire automatically at the end of their retention cycle (up to roughly 125 days). Backup files cannot be decrypted without a private key held by the Company.
  • Any printed material is shredded or incinerated.

Article 9 (Security measures)

  • Sign-in without stored passwords — web sign-in uses emailed codes; no user-chosen password is kept.
  • Hashed storage — device tokens, web session tokens, and sign-in codes are stored only as SHA-256 hashes. For the gateway credential, only the hash of a Company-generated random value is stored.
  • Encryption in transit — all connections use TLS with certificates from a trusted certificate authority.
  • Access control — the database is not exposed externally and is reachable only from inside the server; administrative access is restricted to an SSH tunnel. Public ports are kept to a minimum.
  • No secrets in logs — passwords, hashes, device tokens, and remote desktop payloads never appear in logs or error reports.
  • Intrusion response — failed authentication and abnormal traffic are detected and blocked automatically, and users are emailed when an account is locked.
  • Backup protection — database backups are encrypted inside the server before leaving it, and the decryption key is stored on no server.

Article 10 (Cookies)

The Company uses a single strictly necessary cookie (mdk_session) to keep you signed in to the web dashboard. It is set HttpOnly, Secure, and SameSite=Lax, and expires after at most 30 days.

No advertising, behavioural, or third-party analytics cookies or tracking scripts are used. You may refuse cookies in your browser settings, but then dashboard sign-in will not persist.

Article 11 (Privacy officer)

Privacy officer
[[REPRESENTATIVE]]
Email
[email protected]
Phone
[[PHONE]]
Address
[[ADDRESS]]

You may bring any privacy question, complaint, or request for remedy arising from use of the Service to the privacy officer, and the Company will answer without delay.

Article 12 (Remedies)

For remedies against privacy infringement you may apply to:

If a Company action or omission regarding a request under Articles 35 (access), 36 (correction and deletion), or 37 (suspension of processing) of the Personal Information Protection Act infringes your rights or interests, you may file an administrative appeal.

Article 13 (Changes to this policy)

When this policy changes, the Company publishes the effective date and the changes on the website at least seven days in advance. Changes with a significant effect on users are also sent by email.

Addendum

This policy takes effect on 13 September 2026.