Foruki Privacy Policy
This translation is provided for convenience. The Korean version prevails.
Effective October 8, 2026 · Version foruki-2026-10-08.1
What changed in this revision: we renamed the service from Doci to Foruki. The operator and how personal information is processed have not changed.
What changed in this revision: we added the sections “Usage analytics” and “Request limits”. We added the first-AI-use record to “Retention and deletion of AI records”, how usage analytics records are viewed to “Operator access”, the existing cookie that usage analytics uses to “Browser storage and share links”, the usage analytics records deleted when you leave to “Retention and deletion requests”, and requests to see, delete or stop usage analytics records to “Contact and your rights”. We still put no ads or third-party analytics tools on document screens.
This update adds consent for external apps to write comments and the app name kept on them, what external apps may read within the same rights (comments, versions, tallies, settlements, tasks, attachment names), and document copies. Foruki’s own AI processing is unchanged.
This update adds external app suggestions and document creation, separate consent and revocation for each permission, and retention of suggestions and the creating app’s name. Foruki’s own AI processing is unchanged.
What's changed: optional waitlist consent, pending confirmation, withdrawal and retention; beta recruitment groups, invitation sources and discount eligibility; and weekly notices. Email delivery is still being set up.
Beta waitlist requests
We limit requests using hashes of email and IP addresses to prevent abuse. We do not store the original IP address and keep these hash records for at most two days. Deleting a request also deletes its email-hash rate-limit record. A hash is not the same as anonymous information.
We store your email, language, sign-up source, consent time and notice version to send beta invitations. We keep them for one year or until you withdraw. We won't send advertising emails. You can use Foruki without agreeing.
Email delivery is being set up, so requests remain unconfirmed. Once a provider is ready, we plan to verify addresses before sending invitations. Pending confirmation is not verification. Operators cannot mark requests verified or send mail yet.
Use your removal link to delete the request and consent record immediately. Without the link, contact us for identity verification and deletion. We keep only a random request ID and deletion time for 30 days to reapply deletion after a backup restore. Backups expire within 30 days.
If the purpose, collected information, retention period or message audience changes, we issue a new waitlist notice version and obtain fresh consent before using existing requests for the new purpose. Typo fixes do not change the consent version.
Beta participation and change notices
When you accept an invitation, we record your recruitment group, invitation source, participation time and discount eligibility on your account. We don't store the raw code. Closing your account deletes participation records. Usage analytics stores only fixed group and source values, without codes or emails, and follows the existing opt-out, regional exclusion and retention rules.
Discount eligibility is a record for explaining terms when payments open; it isn't a payment or paid entitlement. Weekly notices are readable in the app and sent to active members' inboxes and devices when published. There is no automated external posting or email delivery.
External app connections and permissions
An external app you choose to connect can read your documents, shared documents and tasks within the scopes you approve. Shared documents may include other participants’ content; make sure you have the right to share it. Foruki sends the requested content to your connected app without AI processing. The app’s privacy information governs its subsequent processing, retention and international transfers. Disconnecting does not automatically delete copies the app has already received.
We store the connected app’s name and identifier, consented permissions, connection time and last use, plus the type, outcome and time of requests. Activity records are deleted after 90 days and contain no document content, search queries or sharing links. Revoking a permission immediately blocks token use for that scope. Disconnecting the app entirely deletes the connection record after 90 days. Closing your account deletes its connections, tokens and activity records. Space owners can disable external app connections for the space.
You consent to suggestions and document creation separately from reading. Suggestions, the app name, the person who submitted them, timestamps and review outcomes are stored with the document. An editor applies or rejects suggestions. New documents are created immediately and retain the app name. Suggestions and provenance are removed when the document is deleted. Revoking a permission blocks future requests; it does not delete existing suggestions or documents. Disabling external apps for a space blocks reading, suggestions and creation. For assignee suggestions, the connected app receives names of people assignable in the document and document-scoped references. We do not send account identifiers. Foruki does not forward these requests to another external AI.
Writing comments is yet another separate consent. Comments and text-change suggestions written by a connected app are posted in your name right away, and the unverified app name stays on them. An app with read permission can also read, within the same rights, the comments you can see, saved versions, poll and survey tallies, settlement calculations, tasks, and the names and sizes of attached files. File contents and share links are never sent. Copying a document creates a new document in your library only when the original’s owner allows copies.
Teams and document collections
We use team names, descriptions, membership, invitations, permissions, and document and collection associations to provide collaboration. Teammates can see each other’s nicknames and team permissions. Leaving or being removed ends team-granted document access. Account deletion removes your team membership and invitation records. Moving a personal collection into a team preserves existing sharing links; newly added team documents are not exposed through those external links.
NAVER sign-up defaults
When you first sign up with NAVER, we prefill your nickname with the nickname you consent to share. Change it if it is already taken or does not meet Foruki’s nickname rules. After sign-up, we import your consented NAVER profile photo into Foruki storage as your default photo, remove photo metadata and resize it. If import fails, we use a profile icon. Existing members’ nicknames and photos are not overwritten. You can change them or remove your photo in My settings. After sign-up, we delete the temporary nickname and external photo URL; your stored profile photo is deleted when you withdraw.
Finding friends and email
To help people find friends, we store the email your social sign-in provider shares with your consent and update it when you sign in. For Google and Kakao, we use only verified email addresses. If no email is provided, people can find you by nickname instead. We do not show your email in search results or to other members. You can turn off email lookup under My settings → Friends. We do not merge accounts by email; if another account already has the same address, we do not register it again. Your account email is deleted when you withdraw.
Account information and consent
We use the unique account identifier from your social sign-in provider, your nickname, and the version and time of your consent to authenticate members and provide the service. Your display settings (text size, start page and so on) are kept with your account, and the profile photo you upload yourself in My settings (optional) is kept in Foruki’s file storage. Profile photos uploaded earlier stay with your account information as a small square image until they are moved to the file storage. Profile photos are saved again as an image no larger than 1024 px on the long side and a small square image, with photo details such as the location removed, and are currently shown only in your own menu and settings screen. We do not collect your date of birth, and we do not automatically copy your real name, profile photo or email from other services into your public nickname. If you do not consent to the collection and use of the information needed to sign up, you cannot become a member.
Kakao sign-in is available only when the feature is enabled. If you use it, a sign-in request is sent to Kakao, and Foruki stores your Kakao member number and sign-in records for authentication. We do not receive your Kakao name or profile picture, and do not show your member number or external sign-in tokens to other participants. External sign-in tokens are stored encrypted. When you withdraw, we delete the account’s sign-in connections and records and request that Kakao unlink Foruki. If unlinking fails, we keep the tokens and retry for up to seven days. Your Kakao account itself is not deleted.
Documents and participation records
We store document titles, body text, formatting, tables and attached information, edit history, sharing permissions, comments and responses to keep documents and let people work on them together. A member’s library and My templates are linked to their account. Participants’ names and edit details may be shown depending on each document’s access permissions, and members who deleted their account are shown without a name as ‘Deleted user’. Do not write sensitive personal information or passwords in documents.
We link the time a member last viewed a document and its version at that time to their account and the document, so we can show what changed since their last visit. Owners can compare against that history; other participants see only content they can currently access.
My tasks gathers titles, statuses, due dates and other details of unfinished items assigned to you from documents you can currently open, and shows them to you. We do not save this combined list separately on the server.
We store the document and expense split identifiers you choose to add to your account. We never infer participation from names. Only expense splits you can currently access are shown. Removing an entry, deleting your account or permanently deleting the document removes this record.
Comment suggestions, reactions and mentions
When you quote a sentence or suggest a change, we store the comment, its author and creation time, the original text and its position, a short surrounding passage used to find it again, and the proposed replacement. We also store whether the suggestion was applied or declined, who handled it and when. People who can view the document can see its comments and suggestions. The quoted original text is shown only while it can still be found in the current body, and is no longer shown after a suggestion is applied. The surrounding passage used to locate it is not shown. Owners and people with editing access can apply or decline suggestions.
For reactions, we store who reacted to which comment, the reaction type and the time. People who can view the document see only counts by type and their own choices. Even the owner cannot see a list of people who reacted. Reactions do not send notifications. Removing your reaction deletes its record.
When a member mentions someone with @ in a comment, we store that person's account reference with the comment and show their display name to people who can view the document. We notify the mentioned member. New change suggestions notify the owner and members with editing access who can still view the document; applying or declining a suggestion notifies the member who proposed it. We do not notify you of your own actions, or send notifications to people who muted the document or lost access.
Deleting a comment clears its quoted text, surrounding passage, proposed text, mention references and reactions. Hiding a comment keeps this information but stops showing it. When you delete your account, we delete your reactions, comments and suggestions. Comments and suggestions with replies from others leave an empty placeholder. We also remove references to your account from mentions in other comments. Changes already applied to someone else's document body and names typed into text are not automatically removed. Permanently deleting a document deletes its comments, suggestions, reactions and mention records.
Group space
When a member creates a group space, we store its name, owner, document list and each document’s sharing permissions, information needed to verify and redisplay the space link, and the members who joined and when they joined. People invited through the space link can see the space name, titles, last-modified times and sharing permissions of available documents, and the number of members. Each document opens with its own permissions. Only the space creator can see members’ nicknames and join times.
When a member leaves or is removed, we delete their space membership record. Deleting a space removes its name, links, document list and membership records, while the documents remain. Space-specific links are also turned off for documents the space creator still owns that are not in the trash. Permanently deleting a document removes it from the space list too.
Notifications
To show notifications to members, we store the recipient, notification type, related document and item, person who caused the notification, creation time and read time. Only the recipient can see a notification. We do not copy document content into notification records; we check current content and access permissions each time they are viewed. If you can no longer access a document, its notifications are no longer shown.
When a shared document changes, we tell the members who can access it in one line per document. To do this, we store, for each document, the position and time of the last change we notified and the number of changes not yet notified; for changes that leave no edit history (adding a document to a team, locking, restoring from the Trash and similar), we store who made them, what kind they were and when, for 90 days. A notification holds who edited (up to 3 people), how many people, and the number of new comments and responses. When you can no longer access a document, we tell you only that, without the document's title.
We link the notification level you chose for each document (All changes, Only what's for me or Off) and the time it was set to your account. We may create reminders as task due dates or poll and survey deadlines approach or pass. You can turn reminders off in My settings. Your reminder preference is stored with your account.
Once a day, we remove notifications older than 90 days and older read notifications beyond the latest 100 document-change notices and 500 other notices per member. We store document, task and deadline identifiers to prevent duplicate reminders. Task deadline records are removed when the document is permanently deleted; other reminder records are cleared after 60 days.
So that changes to the same document do not reach your devices too often, we store, for each member and document, when a device notification was last sent and when a bundled one is due, and delete this a day after nothing is left to send. To notify you once each time storage use passes 80%, 95% and 100%, we store the level passed and the time, and delete it the next time a file is stored while use is more than 10 percentage points below that level. To tell you when a long AI task finishes after you closed its window, we store when the task was last watched and delete it with the task record.
To tell you about a sign-in on a new device, we store, for each browser or app you sign in on, a device identifier, the browser and operating system family (for example, Chrome · macOS) and when it was first and last seen, linked to your account. We do not store IP addresses or locations. We delete the record of a device not seen for 400 days, and delete all of them when you delete your account.
We store a notification time zone, such as Asia/Seoul, in your account settings. We first detect it from your signed-in browser, and you can change it in your settings. It defines today in My tasks, quiet hours for device notifications and daily notification groups. Reminders are added to your inbox at night too; only device delivery is deferred according to each recipient’s time zone and settings.
We store your quiet hours, document change scope and device notification settings by type in your account. For a device notification that is held, we store the time it will be sent with the notification.
To bundle device notifications about document changes into one an hour after 20 in a day, we store the times device notifications were sent for each member and delete them after two days. They are also deleted when you delete your account.
Document webhooks and phone notifications
Content in device notifications is on by default. When enabled, document, space and item titles, participant display names and situation messages already visible in your inbox are sent through push services such as Apple, Google and Mozilla. Web notifications are encrypted in transit; app notifications use Google FCM and, on iPhone, APNs. We do not send document body text, full comments or share-link secrets. Turn off ‘Show content in device notifications’ in My settings to receive only a generic new-notification message. Android follows the device’s hide-sensitive-content lock-screen setting. Manage notifications already displayed on your device.
Document webhooks are currently disabled in production. Only when this feature is enabled can the owner send document change notifications to an external service they choose. Sent data includes document, table, item, poll and form titles, statuses, change types, times and counts, the document identifier and a document address without a share link secret. We do not send the document body, comment text or a participant list, but personal information such as names typed into titles or statuses may be included. People who can view notifications in the external service may also see this information.
When a webhook is configured, we encrypt and store the receiving service's address. We also store its domain and last four characters for the settings screen, notification types, enabled state, who configured it and when, and delivery results. Delivery records are kept for 30 days and then deleted. Deleting the webhook or permanently deleting the document deletes its settings and delivery records. Changing the owner disables delivery and deletes the receiving address. Notifications already sent to an external service are not erased when you delete the document or your Foruki account; they follow the receiving service's retention and deletion rules.
Members can subscribe after turning on device notifications in My settings and allowing notifications on the device. We store the device's push receiving address (endpoint), encryption keys, subscription time and delivery status, linked to the login session, device and account. Notifications are encrypted and sent through browser push services such as Apple, Google and Mozilla. We send contextual inbox messages or generic messages according to your content-display setting. Unsubscribing or signing out deletes the corresponding subscription information; deleting your account deletes it for all devices. Manage notifications already displayed on your device in its notification settings.
Guest display names
Guests can optionally enter a name for each document so people can recognize them in comments and named polls. We store up to 40 characters in the document and show it as “Name · Visitor number” to people who can view that document. Only the owner can see names and individual choices in named polls. You can change or clear the name while you can access the document from the same guest device. If you clear device data or your 30-day device session expires and is replaced, you may no longer be able to change or clear the previous name yourself. In that case, contact Foruki.
We keep the last saved name and the time it was saved in this device’s browser storage to prefill the name in your next document. Saving an empty name also clears the name remembered on this device. Clearing browser data does not clear names stored in documents.
Attendance surveys and date polls
Attendance surveys store names, notes and numeric answers you enter in the questions, your selected answers, and submission and update times to collect attendance responses. Answers are linked to member or guest participation records to prevent duplicate submissions and let you find your own answers again. You can view your own answers; only the document owner can view other people’s individual answers and submission times. Account names and device information are not automatically shown with survey answers. If the owner enables result sharing before publishing, participants can see aggregates such as counts per choice and numeric totals according to the result visibility settings. Names, notes and date answers are not shared. With few responses, someone may infer an individual answer from the aggregates.
Date polls store your selected date choices and submission and update times, linked to your participation record, to collect available dates. For named polls, only the owner can see display names and individual choices. For anonymous polls, even the owner cannot see individual choices. You can view your own choices. Other participants can only see aggregates according to the result visibility set by the owner.
For time and rating questions, we store the time you enter and the rating you choose (1–5) with your other survey answers. Only you and the document owner can see individual answers. Surveys with result sharing enabled show counts for each rating and the average according to their visibility settings. Time answers are not shared with other participants. First-come surveys show capacity and remaining places regardless of result visibility settings, and polls with capacity limits show counts for each choice. These numbers may allow people to infer how many people responded or an individual’s choice.
Settlement names and amounts
Settlements store the person and group names you enter, group members, expense amounts and dates, payers and people excluded from a split as document content to split costs and calculate who pays or receives how much. People who can view the document can see this information and the calculated shares. An author label linked to an account becomes “Former user” after withdrawal, but names and amounts entered directly in another person’s settlement document are not automatically deleted. They can be edited or deleted according to the document’s editing permissions.
When you select Sent, we save the sender and recipient (people or groups), amount and date as a row in the expense split table. This is a participant’s record, not an actual transfer or confirmation from a bank. People who can view the document can see it, and editing permissions determine who can cancel or edit it. Canceling a record hides the row, which can be restored from hidden items. History keeps the content from when you save the document. Like other expense split content, it follows the document’s history, retention and deletion rules. Records and names and amounts entered in someone else’s document are not automatically deleted when you delete your account.
Table calculations, links and CSV
Formulas, row links to other tables in the same document, and rollup settings are stored as document content. Calculation and rollup results are computed from table values as needed, rather than saved as separate cell values. Timelines and charts also render or calculate table values you can already view on your device.
CSV import reads the file on your device. When you create the table, it sends cell content and column settings to the server to save in the document. The CSV file itself is not uploaded or retained, but imported personal information such as names and contact details follows the same document permissions, history, retention and deletion rules as table content entered by hand.
CSV downloads create a file on your device. It may include names and values shown in the table, as well as creator and editor names you have permission to view. Deleting a document or your account does not delete downloaded files, so please manage them on the device where they were saved.
Table rules, repeating items and unsettled expense reminders
When the owner enables an automatic table rule, we store its condition, action, target column, enabled state, creator and creation time. Completing an item can fill the chosen date cell with today's date; completing or adding an item can notify the owner or assignee. The owner and people with editing access can see rule settings, and anyone who can view the document can see changed values. Repeat settings are stored with the item. When a completed item's deadline passes and the next round arrives, the system reopens its status, moves its deadline and records the previous round's date. These values follow the document's history, retention and deletion rules.
Unsettled expense reminders check whether transfers remain in an expense split table and notify only the document's member owner. The notification includes no settlement amounts or participant names. We store a record identifying the calculation result to avoid repeating reminders for the same state. These reminders follow the same notification, retention and deletion settings as other reminders. You can turn off reminders in your account settings or mute the document.
Table of contents and content from other documents
The table of contents is built from headings in the current document. Adding content from another document stores only references to the source document and text location. The source is read using each viewer's current permissions and displayed as read-only. Being able to view the document containing the reference does not let you see the source without permission. No copy of the source content is stored in the containing document's body, search index, AI index or history. Duplicating that document does not create a copy of the source content either. If the source is deleted or you lose access, it is no longer shown.
Attached files and photos
Files and photos that members upload to documents are treated as document content. Files are kept on a file storage device (NAS) that the Foruki operator manages directly, together with each file’s name, size, type, uploader and upload time. When photos (JPEG, PNG, WebP, GIF) are uploaded, we remove metadata such as the location and camera details and create separate small images for previews. If a photo cannot be read, for example because the file is damaged, it may be kept as a download-only file without its metadata removed. We do not remove metadata inside other files, such as author details in PDFs or office documents, so check them before uploading. Only people who can view the document (the owner and people with edit, comment or view permission) can preview and download its files; poll and survey response links cannot see them. Each file can be up to 20 MB, one document can hold up to 100 MB of files in total, and executable files are not accepted.
Drive
Only the member who uploaded a Drive file can see and download it. A file linked to a document, however, can also be seen and downloaded in its current version by anyone who can see that document, and new versions and names reach every document the file is linked to right away. Drive files are kept on the same file storage device (NAS) as document attachments, together with the file name, size, type, upload time, favorite mark, trash state, the folder names and locations, and whether a file is linked to documents and when and why a link was removed. When a new version is uploaded, the files of previous versions are kept too, up to the latest 10 per file, and deleted versions and folders are removed the same way as permanently deleted files. Even when a Drive file is permanently deleted, the same file attached to a document stays as an attachment of that document. Photo metadata is handled the same way as for attachments.
When a Drive file is uploaded, gets a new version, is renamed, when a folder is created or moved, when a file is linked to a document or a link is removed, and when items are moved to the trash, restored or permanently deleted, and at whose request, is recorded with ID numbers only, without the file name or content, kept for 1 year and then deleted. After a file is permanently deleted or its owner deletes their account, these records keep only the ID numbers and “Deleted user” until the retention period ends.
AI assistant
The AI assistant is optional. AI processing happens when a member makes a request in the AI assistant panel, or when a scheduled feature they turned on themselves (such as the weekly progress summary) runs. The request, any selected text, and the document content the feature needs, limited to what the requester can currently see (body text, tables, comments, poll and survey results, decisions, text from attached text files and so on), are then sent to an AI model. In a shared document this can include content written by other participants and names that appear in the document. When an AI feature needs attached photos or PDFs, the Foruki server reads their text itself (macOS built-in text recognition) and sends that text and, if needed, the photo itself to the AI model. Guests can only use public template recommendations. The document search index, however, is built for every document whether or not the AI assistant is used (see below).
AI processing goes through OpenRouter, an AI service in the United States, and is carried out by the AI model providers OpenRouter connects to. OpenRouter picks one of the providers that offer the model and sends the request there, and Foruki does not separately restrict whether providers retain data or use it for training. Depending on the provider, request and response content may therefore be kept for a period of time or used to improve the provider's own services (including model training). If the provider handling a request fails, the request is retried only with the same provider and is not passed on to another provider. No account identifier is attached to requests. Foruki does not use AI requests or document content to train AI. Original requests are not shown in general administration screens; authorized staff investigating errors may review private diagnostic records under the retention rules below. AI results are first shown to the requester as a preview and only go into the document when they apply them.
For requests that need up-to-date information (creating a document, adding content and so on), the AI builds a short search query based on your request and the document's content, and a meta-search program Foruki runs on its own server (SearXNG) sends that query to external search engines, including ones outside Korea. Search queries may include what is written in your request or the document (including personal information such as names and contact details), so please do not put anything in your request that you would not want sent to external search engines. Search engines receive the request from Foruki's server, so your account and device information are not passed on. For each request Foruki's server opens and reads at most 3 highly relevant web pages, and their text is deleted once processing ends. Results that use web material list the sources used (title, link and search date). Web search cannot be turned off separately.
For template recommendations, the topic you enter (guests included) and the titles and summaries of public templates, and for search by meaning, related documents and asking your documents, the search words, are sent to OpenRouter's embedding feature (the bge-m3 model), which turns them into lists of numbers that represent meaning. For this document search, Foruki sends the title and the text excerpts visible with view access of every document that is not in the trash (member and guest documents) to OpenRouter's embedding feature and indexes them each time a document is created or changed, whether or not anyone uses the AI assistant. Search results only show documents the searching member can currently open.
Guest display names may also be included in comments or edit information read by AI. Names of participants linked as assignees are included in the document search index and sent to OpenRouter’s embedding service.
Retention and deletion of AI records
Requests, document content and tool results used in an AI task are kept only while the task is being processed, and a ready result can only be opened or applied for 30 minutes if it is an answer, or 15 minutes if it is a proposal that changes a document. When a task is applied, cancelled, fails or expires, its request and result content are deleted, and the task record without content (feature, status, times and identifiers of applied results) is deleted after 30 days. Results you apply become document content and follow the document retention rules, and the information needed to undo an AI change is kept for 30 days. In the conversation beside the document, your requests (up to 1,000 characters) and the answers (up to 1,600 characters) are visible only on the device and account that started the conversation, and are deleted 30 days after they were sent. You can also delete a conversation yourself. Weekly progress summary previews that were not applied are deleted after 7 days. The search index of every document (titles, text excerpts and lists of numbers) is kept in Foruki's database, rebuilt when a document changes, and deleted when the document is moved to the trash or deleted forever. Text extracted from text files for AI to read is deleted together with the file. Usage statistics keep only the feature, status, time taken, character counts, token counts, cost and whether a search succeeded, with no request content, and they can no longer be linked to anyone once the task record is deleted or the member leaves. Separately, the time you first used AI and the feature you used are kept in the usage analytics records with a pseudonymous identifier for 13 months, and are deleted when you leave. When you leave Foruki, your AI conversations, task records and undo information are deleted too. These records may also remain in database backups for disaster recovery for up to 30 days. To investigate errors and prevent recurrence, we keep separate diagnostic records of AI processing issues, excluding provider outages. These may include the original request and input settings, document and block identifiers, part of the failed model output, the failure stage and code, timestamps, and software version. Authentication tokens, cookies, and secrets in edit or recovery links are redacted. Records are stored in access-restricted server files for no more than 30 days and may be removed earlier when storage limits are reached. They are used only to investigate and fix issues and may be accessed only by authorized personnel. After account deletion, these records are deleted within this separate retention period; deletion requests can be submitted through Foruki support. When daily AI allowances apply, we store the account's successful-result and draft counts, time zone, reset time and each job's counting status for that period. Counts contain no request content, reset when the next usage period begins, and are deleted when you close your account.
Outsourcing and transfer abroad for AI processing
To provide the AI assistant, Foruki entrusts the processing of content that may contain personal information to businesses outside Korea as follows.
- Names included in transferred data: assignee names in the document search index and guest display names in comments or edit information needed for an AI request may also be included.
- Recipients: OpenRouter, Inc. (169 Madison Ave #2404, New York, NY 10016, USA · privacy contact privacy@openrouter.ai) and one AI model provider that OpenRouter picks for each request. Currently the providers are Reka, Wafer, DekaLLM, Ionstream, DeepInfra, Phala, Mancer, Parasail, Chutes, AkashML, CoreWeave, Novita, Alibaba, Cloudflare and Venice for the chat model (Qwen3.8 27B), and Parasail and DeepInfra for embeddings (bge-m3). The list can change and can be checked on OpenRouter's provider page for each model.
- Destination country: United States (OpenRouter processes data in Google Cloud regions in the US). Most model providers are also US companies, but some have their headquarters in another country (for example Alibaba in China), some do not state where they process data, and some are decentralized providers that process data on servers spread across several countries.
- When and how: sent over an encrypted connection (HTTPS) each time an AI feature is requested or a scheduled feature you turned on runs, and each time the document index is built or updated.
- Items transferred: AI requests and selected text, the document content a feature needs (which may contain personal information such as text written by other participants and names in the document), text read from attached photos and PDFs and, where needed, the photos, template recommendation topics, and, for the search index, the titles and text excerpts of every document plus search words. Account identifiers are not sent.
- Purpose: producing AI assistant results, template recommendations, search by meaning and finding related documents
- Retention period: under its data processing agreement, OpenRouter deletes request and response content right after the response is generated, and keeps only usage records without content (token counts, processing time and so on) for as long as its business and legal obligations require. How long model providers keep data and how they may use it (including for training) follows each provider's own policy, and Foruki does not separately restrict this. Each provider's policy can be checked on OpenRouter's provider page for each model.
- How to refuse and what happens if you do: if you do not use the AI assistant, nothing is sent because of AI requests. You then cannot use the AI features, but all document features keep working. In a shared document your writing may be included when another participant uses AI, so do not share the document if you do not want that. Sending for the search index happens for every document whether or not AI is used, and there is currently no way to refuse only this. If you do not want it, delete the document (moving it to the trash also deletes its stored index right away) or let us know through the Foruki contact form.
- External search engines: for web searches, search queries built from your request and the document's content are sent to external search and news engines (DuckDuckGo, Naver, Google News, Bing News, Wikipedia, Wikinews). Search queries may include personal information.
Operator access
To run the service (usage statistics, handling inquiries and reports, and checking for problems), one designated operator can view the member list (nickname, sign-up date, last sign-in time, sign-in method, language setting and number of documents) and the document list (title, how it was created, status, creation and edit times, the number of participants, comments and share links, and the number and size of files). The operator does not see document contents, file names or contents, or share link secrets, and each operator view is logged. Daily statistics are kept only as totals that cannot identify individuals, and usage analytics records are never viewed person by person, except when handling your own request to see or delete them (see “Usage analytics”).
Usage analytics
To improve the service and produce usage statistics, Foruki’s own servers record a few steps of how Foruki is used: signing up, making a first document (including whether it started blank, from a template, as a copy or with AI), creating a share (link, response link, invitation, team or group space), first opening a share link, using Foruki on a given day (once a day, on days you open a Foruki screen or a document, or do something in a document), first using a task table and first using AI (your first request to AI).
These records arise from requests Foruki already processes to provide the service to members and guests, and they are kept only with account or device identifiers transformed with a separate secret key. We therefore use them additionally, within the scope reasonably related to the original purpose of collection, under Article 15(3) of Korea’s Personal Information Protection Act. The criteria Foruki applied under Article 14-2 of its Enforcement Decree: the use is related to the original purpose of providing the service to members and guests, it can be expected from how the service works, it causes no disadvantage to you, identifiers are stored transformed with a separate secret key, and it holds no document content.
These records hold only the step and its time (to the minute), the interface language, whether you are a member or a guest, whether the account or device was already using Foruki before these records began, how a document was made (blank, template, copy or AI), how something was shared (link, response link, invitation, team or group space) and whether a link was made again, the first AI feature you used, and a pseudonymous identifier that differs for each person (your account or device identifier transformed with a secret key). They do not say which document, link, invitation or team was involved. Usage analytics records never hold document titles or contents, link secrets, names or email addresses, IP addresses, browser information or location. We use no third-party analytics tools and create no new cookies or browser storage, and we also use the device identifier in the existing cookie, or in the app’s sign-in information, used for sign-in and device checks, and your interface language setting, for usage analytics. If you connect from the European Economic Area (EEA), the United Kingdom or Switzerland, or your browser or app sends Global Privacy Control (GPC, a do-not-track signal), we do not record usage analytics.
When you sign in, the records made on that device until you signed in are connected to the account that signed in at that time. If you bring a document a guest made into your account with its recovery key, that guest’s records are connected to your account too. The designated operator has no person-by-person view: they see only totals by starting week and the state of the records by day. While there are few users, however, a week’s total may describe the records of only one or two people. The number of people who opened a share link is also seen only as a total and is never shown to the document owner.
Records of the days you used Foruki and of first opening a share link are deleted after 90 days, and other records after 13 months. For weekly totals older than 13 months, we keep only overall totals of 5 people or more. When you leave, we delete your records together with the records made before sign-in that are connected to your account, and the weekly totals you were counted in are recalculated for as long as the underlying records are kept. Older weekly totals remain only as numbers of people, and starting-week totals of fewer than 5 people among them are hidden. They may remain in disaster-recovery database backups for up to 30 days, and if we restore from such a backup they are deleted again. Records from devices that never signed in are not linked to a member account, so we cannot confirm through the contact form that they are yours; they are deleted when their period ends. Guests can stop the recording by turning on Global Privacy Control (GPC) in their browser. While you use the app without signing in, there is not yet a setting that stops the recording. Members can ask through the Foruki contact form to see, delete or stop (no further recording of) their usage analytics records.
Email verification status
When a sign-in provider supplies email verification status, we store that status and the time checked for each provider. You can also sign up with a provider that supplies no verification status. These records are deleted when you close your account.
Request limits
To prevent repeated sign-ups and guest starts, we turn IP addresses and the existing device cookie into pseudonymous hashes for rate limits. Sign-ups allow 30 per IP and 5 per device per day. Guest sessions allow 60 per IP per hour and 20 per device per day. We do not store raw IP addresses in these records, use the hashes for analytics, or collect browser fingerprints. Hashes are deleted after two days.
Browser storage and share links
We keep your sign-in session, device identification information, recent document access records and unsaved drafts in cookies and browser storage. Link secrets are stored on the server as hashes. If you clear your browser data, you may lose guest access records or unsaved input. Photos and files you viewed in documents may remain in your browser cache (permission is checked again each time they are opened). On a device that several people use, clear the browser data when you are done. We do not put ads or third-party analytics tools on document screens. Usage analytics (see “Usage analytics”) are recorded by Foruki’s own servers. For this we create no new cookies or browser storage, and we also use the device identifier in the existing cookie, or in the app’s sign-in information, used for sign-in and device checks, and your interface language setting, for usage analytics.
Display choices such as table views and collapsed headings are remembered in this device’s browser storage so you can reopen the same view. You can clear them with “Reset remembered views” or by clearing browser data.
“Show title in link previews” is off by default. If the owner enables it for a link, anyone with that link and link preview services such as KakaoTalk can see the document title (or the question title and deadline for a poll or form link). The body and participant names are not shown. Turning it off, revoking the link or reissuing it stops Foruki from showing the title, but previews already created by a messenger may remain on that service.
This device also remembers date columns chosen for timelines, and chart category and value columns, chart shape and summary choices. These display preferences are not stored separately on the server or shared with others. You can clear them by resetting remembered views or deleting browser data.
Sending shares and calendar files
When an owner selects “Copy with title” or “Send”, the device builds a sharing message with the document or question title, the poll or survey deadline if present, and the address including the link’s secret. The message goes through the chosen clipboard or device share sheet and is not separately stored on Foruki’s server. Recipients and the selected app can see the title and link sent. Deleting the document in Foruki does not delete messages already copied or sent; their retention and deletion are managed by recipients and the app.
“Send via KakaoTalk” is available only when KakaoTalk sharing is enabled. When the owner selects it, the browser loads Kakao’s sharing script, and Kakao receives the IP address, browser information, and the title, message text and link, including its secret, to be sent. Kakao’s sharing script may store information in this device’s browser. Recipients can see the message sent. Retention and deletion of information held by Kakao and on your device follow the service’s policies and browser settings. Deleting a Foruki document or withdrawing does not delete messages already sent.
ICS files downloaded to add an event to a calendar are created on your device and are not separately stored on Foruki’s server. They contain the document title, information field name, and date and time, but no share link, participant list or document body. Personal information entered directly in the title or field name may be included. People who receive the file or have access to the calendar you import it into can see its content. Calendar settings may sync it to an external service. Deleting a document or withdrawing does not delete downloaded files or calendar events, so manage them on your device and in your calendar.
Retention and deletion requests
Account information is kept while we provide the member service and is deleted as soon as you delete your account. You can delete your account right away under Account in My settings by typing a confirmation phrase, and you are signed out on every device. Deleting your account deletes your sign-in connection, nickname, settings and consent records, your profile photo, your library organization, My templates and saved bundles, the documents you own (including shared documents and documents in the Trash), your comments and poll & survey responses in other people’s documents, the inquiries you sent from your account, and your usage analytics records. If other people replied to one of your comments, only an emptied ‘deleted comment’ placeholder remains. The body text, tables, records and files you added to other people’s documents are part of those documents, so they stay, and the author is shown without a name as ‘Deleted user’. Guest documents left on a device where you never signed in are not part of your account, so they stay. Anything that takes longer is finished within a few minutes. When you change or delete your profile photo, it stops being shown right away and is erased from file storage within 24 hours. Documents moved to the Trash can be restored within 30 days, but not after permanent deletion. Documents made without signing in are moved to the Trash if nobody opens them for 90 days and permanently deleted 30 days later. When you sign in on a device, the documents made on that device without signing in are moved to your account library and kept as member documents from then on. Files in a document in the Trash are kept until the restore deadline but cannot be opened, and they are erased from file storage within 24 hours of permanent deletion. Files uploaded to a document but never used are deleted after 24 hours, and files removed from a document are kept for 30 days for undo and history restore and then deleted. If a document made by copying still uses the same file, that file is deleted only after it is removed from that document too. When you delete your account, files you uploaded but never used in a document are deleted, and the files of the documents and profile photo deleted with your account are erased from file storage within 24 hours. Database backup copies kept for recovery from failures are deleted 30 days after they are made, and if we ever restore from a backup before then, the account deletion and permanent deletion records are applied again before the restored data is used. If we start keeping backups of file storage, we will add how long backup copies are kept to this policy. External sign-in tokens are stored encrypted and revoked when the account is deleted; a failed revocation is retried for up to 7 days. Your Google or Naver account itself is not deleted. Team-created documents are an exception. If another active teammate remains when you delete your account, their ownership passes to the team administrator or a successor, and the documents, attachments and team collections stay with the team. The administrator can also reassign team document ownership. Personal documents brought into a team follow their original ownership and deletion rules. If no eligible teammate remains, they are deleted as shown in the account deletion confirmation.
Guest display names, attendance survey and date poll responses, and settlement content are kept with the document and deleted when it is permanently deleted. Documents moved to the trash can be restored for 30 days. Guest-owned documents that nobody opens for 90 days move to the trash and are permanently deleted 30 days later. This 90-day rule does not separately apply to guest names and responses in someone else’s document. When a member withdraws, we delete their own documents and their comments, poll responses and survey answers in other people’s documents. Comments with replies from others remain only as empty placeholders. Deleted information may remain in disaster recovery database backups for up to 30 days from the backup’s creation. Team-created documents are an exception. If another active teammate remains when you delete your account, their ownership passes to the team administrator or a successor, and the documents, attachments and team collections stay with the team. The administrator can also reassign team document ownership. Personal documents brought into a team follow their original ownership and deletion rules. If no eligible teammate remains, they are deleted as shown in the account deletion confirmation.
Permanently deleting a document also deletes its notifications, per-document notification settings, reminder deduplication records and last-view records. Deleting your account deletes your received notifications and notification settings, last-view records, spaces you created and their links, document lists and membership records, and your membership records in other spaces. In notifications retained for other people, your activity is attributed to a deleted user. Team-created documents are an exception. If another active teammate remains when you delete your account, their ownership passes to the team administrator or a successor, and the documents, attachments and team collections stay with the team. The administrator can also reassign team document ownership. Personal documents brought into a team follow their original ownership and deletion rules. If no eligible teammate remains, they are deleted as shown in the account deletion confirmation.
Files in the Drive trash are removed from the file storage after 30 days, and permanently deleted Drive files within 24 hours. When you delete your account, all files in your Drive (the trash included) are deleted.
Contact and your rights
You can delete your account (and your information) yourself in My settings. Please send requests to access or correct your personal information, requests to see, delete or stop (no further recording of) your usage analytics records, and other account requests through the Foruki contact form. The content of your inquiry and, if you are signed in, your account identifier are kept for 90 days to handle the inquiry, and inquiries sent from your account are deleted when you delete your account. Do not send passwords, verification codes or resident registration numbers.