This Privacy Policy has been established by Digiwill Co., Ltd. (hereinafter "Digiwill"), the operator of ClassI — Next-Generation Classroom Management Solution (hereinafter "ClassI"), to comply with the Personal Information Protection Act (PIPA), the Framework Act on Education, the Elementary and Secondary Education Act, and other applicable laws and regulations.
ClassI enables teachers to remotely monitor and control student devices during classroom instruction. This Policy describes how personal information is collected, used, stored, and shared throughout that process.
This Privacy Policy covers the following software and services provided by Digiwill (collectively, "Services"):
In accordance with the principle of minimal processing, Digiwill collects only the data strictly necessary to provide each software feature:
- Data Collected
- Device name · IP address · Current screen status · List of active websites / apps / programs · Network connection status
- Collection Trigger
- Automated real-time collection via software agent — active during class hours only
- Data Collected
- Device control logs: timestamp of control action · type of action (lock / unlock / app restriction / screen switch) · target device identifier
- Collection Trigger
- Logged automatically each time the teacher explicitly issues a control command
- Data Collected
- Full AI conversation text (student questions + AI responses) · Timestamp of conversation · Student identifier (student ID or anonymised ID)
- Collection Trigger
- Automatically recorded whenever the student uses the in-app AI feature
- Data Collected
- Real-time screen data from the student's device (live streaming frames only)
- Collection Trigger
- Transmitted in real time when the teacher explicitly issues a broadcast command
- Data Collected
- Email address of the teacher and registered student accounts (collected via Google account authentication)
- Purpose
- Account creation · User identity verification · Delivery of personalized educational features · Essential service communications (e.g., class invitations, deletion confirmations)
- Collection Trigger
- Collected at initial authentication (Google OAuth) when the teacher or student first signs in to the extension or app
- Applies To
- Classi AI 선생님 (Teacher Extension) · Classi AI 학생 (Student Extension) · Classi AI Android App
- Data Collected
- Anonymised interaction data: features accessed · frequency of use · session duration · error/crash events
- Purpose
- Diagnosing technical issues · Understanding user behaviour to improve extension functionality · Product improvement decisions
- Collection Trigger
- Automatically collected during active use of the extension or app
- Applies To
- Classi AI 선생님 (Teacher Extension) · Classi AI 학생 (Student Extension) · Classi AI Android App
The following data is collected specifically from teachers when logging in and operating the ClassI AI Teacher application. This is separate from student data collection.
- Account Data
- Teacher account credentials (hashed password, registered email address / username used for authentication)
- Session & Access Logs
- Teacher IP address · Login / logout timestamps · Session duration · Device type, browser and OS information
- Action Logs
- Records of all teacher-initiated control commands: feature used, target device identifier, timestamp — retained for audit and accountability purposes
- AI Usage Logs (ClassI AI)
- Prompts entered by the teacher into ClassI AI · AI-generated responses · Timestamps — used to monitor appropriate use and improve educational quality
- Collection Trigger
- Automatically recorded upon login and during active use of the ClassI AI Teacher application
- Automated real-time collection via software agent (client program installed on student devices)
- Automatic logging each time the teacher explicitly executes a control command
- Submission of written or electronic consent forms by students and guardians
The following browser permissions are requested by each ClassI extension. All permissions are strictly necessary for the described classroom features and are not used for any other purpose.
| Permission | Why It Is Required | Data Accessed |
|---|---|---|
tabs | Required to monitor which browser tabs are open on student devices and block/close inappropriate tabs during class | Tab URLs and titles on student devices (during active class sessions only) |
activeTab | Required to interact with the currently active tab to apply screen controls and URL restrictions | URL of the currently active tab |
storage | Required to locally store session state, teacher preferences, and class configuration | Local configuration data — not transmitted externally |
identity | Required to authenticate the teacher via Google account and load Google Classroom class/student data | Teacher's Google account email and Google Classroom course list |
scripting | Required to inject screen lock, URL block, and notification scripts into student browser windows | No data read — scripts are executed only to apply controls |
webRequest / declarativeNetRequest | Required to enforce URL allow/block lists during exam mode | Requested URLs (compared against teacher-configured lists; content is not read) |
notifications | Required to send push notifications (messages, alerts) to student devices | Notification content composed by the teacher |
Host permissions (digiwill.ai, server endpoints) | Required to communicate with ClassI servers for real-time monitoring, control commands, and AI features | Encrypted command/response payloads between teacher client and ClassI server |
| Permission | Why It Is Required | Data Accessed |
|---|---|---|
tabs | Required to send the current tab list to the teacher dashboard and to receive tab open/close commands from the teacher | Tab URLs and titles — transmitted to teacher's dashboard during class sessions only |
storage | Required to store local session state, current class code, and student preferences | Local session data — not transmitted externally |
identity | Required to identify the student via their Google account to match them to the correct class | Student Google account email, used to join the class roster |
scripting | Required to apply teacher-sent controls: screen lock, forced URL navigation, notification display | No data read — scripts execute control actions only |
webRequest / declarativeNetRequest | Required to enforce URL restrictions and exam-mode allow/block lists set by the teacher | Requested URLs compared against teacher-configured lists; page content is not read |
desktopCapture / tabCapture | Required to capture and transmit the student's screen to the teacher's monitoring dashboard (real-time streaming; not recorded) | Screen pixel data — streamed in real time, never stored |
Host permissions (digiwill.ai, server endpoints) | Required to maintain the real-time connection to ClassI server for receiving teacher commands | Encrypted command/response payloads |
Digiwill uses collected personal information only within the purposes listed below. Use beyond these purposes is strictly prohibited.
| Feature | Purpose of Use | Legal Basis (PIPA) |
|---|---|---|
| Real-Time Monitoring | Monitor class engagement; block inappropriate content; maintain learning environment | Art. 15(1)(6) — Legitimate Interest |
| Screen Control | Lock/unlock devices; restrict apps; support orderly instruction | Art. 15(1)(6) — Legitimate Interest |
| AI Conversation Data | Assess AI usage patterns; prevent inappropriate content; improve educational quality | Art. 15(1)(1) — Explicit Consent |
| Screen Broadcast | Support presentations, collaborative tasks, and teacher demonstrations | Art. 15(1)(6) — Legitimate Interest |
This section describes the complete lifecycle of personal information from the point of collection through to permanent destruction. Digiwill retains data only for the minimum period necessary to fulfil the stated purpose, and destroys it without delay once that purpose is achieved.
Data is collected automatically via the ClassI / ClassI AI software agent or through explicit teacher commands — only during active class sessions, only to the extent required for each feature.
Data is processed solely within the purposes listed in Article 3. No data is used for advertising, profiling, or any purpose unrelated to in-class educational activities. AI conversation data is anonymised where student identification is not required.
Stored data is encrypted at rest and in transit. Access is granted on a strict least-privilege basis per account. Intrusion detection, firewall protection, and access-log retention (minimum 6 months) are applied at all times.
Once the retention period ends or the collection purpose is achieved, data is transferred to an isolated database, held only as long as legally required, and then permanently destroyed using the methods below. Isolated data is never used for secondary purposes.
| Data Category | Where Stored | Access Controls | Retention Period | Destruction Method |
|---|---|---|---|---|
| Real-Time Monitoring Data | Teacher's screen only (RAM / display buffer) |
Visible to assigned teacher only | Not stored | Discarded immediately after display — never written to disk |
| Screen Control Logs | Internal server (encrypted at rest) |
Teacher & system admin only | 30 days | Automatic permanent deletion via scheduled job |
| AI Conversation Content (ClassI AI) |
Encrypted cloud storage (if applicable) |
Teacher & designated admin; anonymised where possible | ≤ 3 months after class ends | Irrecoverable deletion or full anonymisation |
| Screen Broadcast Data | Not stored (live stream only) |
N/A | Not stored | N/A — stream is never captured or saved |
| Consent Forms & Records | Secure internal archive | Privacy Officer & designated admin only | 2 years post-enrollment | Physical shredding or certified electronic deletion |
Pursuant to Article 29 of the Personal Information Protection Act, Digiwill implements the following technical, administrative, and physical safeguards to prevent loss, theft, leakage, alteration, or damage of personal information.
- All communication between student device agents and teacher servers uses encrypted dedicated channels (TLS)
- Access privileges follow the principle of least privilege, assigned per teacher / administrator account
- Intrusion detection systems (IDS) and firewalls are operated; regular vulnerability assessments are performed
- Access logs are retained for at least 6 months with tamper-prevention controls applied
- The number of personnel who handle personal information is kept to the minimum necessary
- Mandatory periodic personal information protection training is provided to all handlers
- Internal management plans are established and reviewed/updated annually
- All handlers sign confidentiality agreements; access rights are revoked immediately upon role change or resignation
- A Chief Privacy Officer (CPO) is designated to regularly supervise processing activities
- Servers and storage devices are maintained in access-controlled, locked facilities
- External physical access to devices is prohibited; entry/exit records are maintained
This section discloses how data processed by the ClassI AI feature is handled, including whether and how it is transmitted to external AI service providers.
| Provider | Role | Data Transmitted | Data Retention by Provider | Safeguard |
|---|---|---|---|---|
| OpenAI, L.L.C. San Francisco, CA, USA |
LLM API — generates AI responses within ClassI AI | Conversation prompt text only (no student name, ID, or device info is included in the API call) | Per OpenAI API data usage policy — input/output data is not used to train models via the API; subject to OpenAI's retention terms | API-only; no model training on user data |
| Google LLC Mountain View, CA, USA |
LLM API (Google Gemini) — supplements AI response generation within ClassI AI | Conversation prompt text only (no student name, ID, or device info is included in the API call) | Per Google Cloud / Gemini API data usage policy — API data is not used to train models by default; subject to Google's retention terms | API-only; no model training on user data |
- Student names, student IDs, or any directly identifying information
- Device names or IP addresses
- Screen content, control logs, or broadcast data
- Consent forms or any records outside the AI conversation context
AI conversation prompt data is processed by OpenAI and Google on servers located primarily in the United States. This constitutes a cross-border transfer of personal information. Digiwill ensures that such transfers are governed by appropriate contractual protections (Data Processing Agreements) consistent with applicable data protection law, including PIPA Article 28-8.
| Transfer Destination | Legal Basis | Protective Mechanism |
|---|---|---|
| United States (OpenAI) | Art. 28-8 PIPA — contractual transfer | Data Processing Agreement (DPA) with OpenAI |
| United States (Google LLC) | Art. 28-8 PIPA — contractual transfer | Data Processing Agreement (DPA) with Google |
Digiwill has designated the following Chief Privacy Officer to protect user data and handle related complaints:
- Organisation
- Digiwill Co., Ltd.
- Phone
- 031-213-9280
- brick@digiwill.co.kr
- Response Time
- Within 10 business days of receipt
For personal information infringement reports or further enquiries, you may also contact:
Personal information is shared with third parties only in the following limited circumstances:
| Circumstance | Details | Safeguard |
|---|---|---|
| User / Guardian Consent | Data shared only when explicit prior consent has been obtained from the user or their legal guardian | Consent required before any disclosure |
| Legal / Investigative Request | Disclosure required by law or requested by investigative authorities following legally prescribed procedures | Only via lawful process |
| Statistical / Research Use | Provided only in fully anonymised, de-identified form for statistical compilation, academic research, or market research — no individual can be identified | Anonymised / de-identified only |
| Aggregated Demographic Data — Business Partners | Generic aggregated demographic statistics (e.g., aggregate feature usage rates, regional adoption) that are not linked to any individual user may be shared with trusted business partners and affiliates for product improvement purposes. No email address, name, student ID, or other personal identifier is included in this data. | Aggregated & non-identifying only |
For software operation, maintenance, and AI functionality, Digiwill entrusts personal information processing to the following named entities. All agreements contain explicit data protection obligations compliant with PIPA, and each sub-processor is supervised to ensure safe processing.
| Sub-Processor (Legal Name) | Country | Tasks Entrusted | Data Accessed | Retention |
|---|---|---|---|---|
| Digiwill Co., Ltd. In-house development team |
Republic of Korea | Software development, system operation, bug fixes, feature improvements, internal maintenance | All system data — access strictly limited by role | Duration of employment / contract |
| Amazon Web Services, Inc. (AWS) aws.amazon.com |
Republic of Korea (ap-northeast-2 region) |
Cloud infrastructure — encrypted hosting of application servers, databases, and AI conversation data storage | Encrypted server and database contents; AWS has no access to plaintext data | Duration of service agreement |
| OpenAI, L.L.C. openai.com |
United States | LLM API — generates AI responses for ClassI AI feature (see Article 6) | AI conversation prompt text only — no student IDs, names, or device info included in API calls | Per OpenAI API data policy; data not used for model training |
| Google LLC cloud.google.com |
United States | LLM API (Google Gemini) — supplements AI response generation for ClassI AI feature (see Article 6) | AI conversation prompt text only — no student IDs, names, or device info included in API calls | Per Google Cloud API data policy; data not used for model training |
Students and guardians (legal representatives) may exercise the following rights at any time:
- Access — Request confirmation of what personal information is being processed
- Correction / Deletion — Request correction of inaccurate data or deletion of unnecessary data
- Processing Suspension — Request suspension of specific data processing activities
- Withdrawal of Consent — Withdraw consent for collection and use at any time without penalty
Rights may be exercised by contacting the Chief Privacy Officer (Article 7) in writing, by phone, or by email. Requests will be processed and responded to within 10 business days.
When a teacher or school administrator requests account deletion, or when a student's enrollment ends, the following data erasure procedure applies:
| Step | Action | Timeframe |
|---|---|---|
| 1. Request submission | Submit a deletion request to brick@digiwill.co.kr or via the in-app account settings | Immediately upon request |
| 2. Identity verification | Digiwill verifies the requester's identity to prevent unauthorised deletion | Within 2 business days |
| 3. Active data deletion | All personal data associated with the account (AI conversations, control logs, session data) is permanently deleted from active databases | Within 7 business days of verification |
| 4. Backup purge | Residual data in encrypted backup systems is overwritten in the next scheduled backup cycle | Within 30 days |
| 5. Confirmation | A deletion confirmation notice is sent to the requester's registered email address | Upon completion |
Digiwill will provide advance notice of any amendments to this Privacy Policy at least 7 days before they take effect, via in-app announcements or school newsletters. For material changes, at least 30 days' advance notice will be given.
| Current Version | v1.0 |
| Effective Date | June 16, 2026 |
| Last Modified | June 15, 2026 |


