Product privacy
NGST Express It Privacy Policy
This policy explains how NohGang Works Co.,Ltd. handles information in connection with NGST Express It.
Summary
- Provider and controller
- NohGang Works Co.,Ltd. (주식회사 노강웍스)
- Representative
- Noh HoeGang
- Optional cloud processing
- Settings, derived templates and thumbnails, template usage records, connection and file information; sessions excluded
- Company accounts, ads and analytics SDKs
- Not used
- Privacy contact
- urgentman2@nohgangworks.com
- Effective date
- September 24, 2026
1. On-Device Information
The app processes settings, templates, work files and user-selected content on the device. Session data stays local and is excluded from cloud synchronization. Usage counts and last-used times can synchronize to your personal account as described below; they are not sent to a company analytics service. You control exports, sharing destinations and any device-to-device features you use.
2. Optional Google Drive and OneDrive Synchronization
Your choice and purpose. In Normal or Expert mode, you can connect your personal account through Google's or Microsoft's official authorization interface to synchronize settings and user-created derived templates across devices. Google Drive uses the Google Drive API; OneDrive uses the Microsoft Graph API. The app does not receive your account password or require a NohGang Works account. Easy mode does not run synchronization.
Information synchronized. The app uploads and downloads the app-mode selection, Program Options for each mode, user-created derived templates including their text, settings, author and other metadata, file references, and associated thumbnail images. Templates and thumbnails can contain personal information you enter or display. Usage counts and last-used times for bundled templates are synchronized with template IDs and a random per-installation identifier to merge usage history across devices. These records are stored in your cloud account, not sent to a company analytics server.
Where your data is stored. When you connect cloud storage, copies of the synchronization data described above are sent directly from your device to the Google Drive or OneDrive account you connected. When you connect the same account on another device, the app downloads those copies to restore or synchronize settings and templates. The app reads and processes files on your devices for this purpose, but the company does not receive or retain those files or cloud connection credentials on separate company-operated servers. We do not operate a central repository of users' backups. Files you choose to attach to an email inquiry are separate from this automatic synchronization and are handled under Section 3.
Personal information you enter may also be saved. Free-text fields in user-created templates accept many kinds of written content within the app's supported formats and size limits. For example, if you enter a name, phone number, address or private note in a template and save it, cloud synchronization may store that information as part of the template. A thumbnail displaying the content may also show the same information. This is content you choose to create for display, rather than membership information the app requires you to supply. Cloud storage does not automatically redact or remove personal information. You should review what you enter and decide what to save and whether to connect cloud storage. When entering another person's information, you must have the authority required by applicable law.
Connection and synchronization information. The app processes access tokens and any refresh tokens, granted permissions, an account identifier used to check account continuity, file IDs, names, edit times, hashes, deletion markers and storage-capacity information. Account continuity checks prevent silent reconnection to the wrong account. Sessions and current work state, your device's entire photo/video/font collection, and separate content files are excluded. A file reference in a template does not copy its original file to another device; a thumbnail may contain a separate image copy.
Google Drive permissions and location. The drive.file permission covers files created by or made available to the app. New files are saved in the app-created NGST/expressit folder. The drive.appdata permission reads and migrates older hidden app data, and old copies may remain. Google processes the data under your account and its Privacy Policy.
OneDrive permissions and location. After Microsoft account authorization, Files.ReadWrite.AppFolder allows reading and writing files in the app folder, and offline_access allows the authorized connection to be refreshed. This does not grant access to every file in your OneDrive. Files are stored in your OneDrive app folder and count toward that account's storage quota. Microsoft processes the data under its Privacy Statement. Microsoft's app-folder documentation explains the permission boundary.
Retention and protection. Transfers use HTTPS directly between your device and the selected provider, without a company-operated synchronization server. Provider servers may be outside your country. Settings use INI; templates and usage records use JSON, and thumbnail images may be embedded in template files. The app does not add end-to-end encryption. Connection credentials are stored separately in platform-protected device storage and are excluded from synchronized settings and templates. Local reconciliation records and pending downloads may contain synchronization copies. Last-sync time, transferred bytes and storage usage are shown in the app.
Use and sharing. Connected cloud data is used for the synchronization you request and connection/storage management, not for sale, advertising, credit decisions or general-purpose AI model training. Company personnel do not routinely read personal cloud files. Files you voluntarily attach to a support inquiry are handled to resolve that inquiry. If you connect more than one provider, data received from one can pass through the local copy and synchronize to another provider you connected.
NGST Express It's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. New processing purposes, data categories or providers will be disclosed before activation, with consent where required.
3. External Services and Email
The app does not upload work content, identifiers, or usage analytics to a company server. App stores, operating-system features, external apps, and sharing destinations apply their own policies when selected by the user.
If you email us, we use the address, supplied name, message, and attachments to respond. Ordinary inquiries are deleted within 30 days after the final response; consumer complaint or dispute records may be kept for 3 years when required by Korean e-commerce law. See the Website Privacy Policy for Cloudflare email routing.
4. Disclosure, Tracking, and Automated Decisions
We do not sell app personal information, share it for targeted advertising, use analytics or tracking SDKs, or make automated decisions with legal or similarly significant effects. Do Not Track and Global Privacy Control signals do not change app behavior because the app does not perform behavioral tracking.
5. Deletion and Your Rights
You can disconnect each provider in the app. You can also revoke app access through Google Account connections or your Microsoft account app-permissions controls. Disconnecting removes that device’s saved connection credentials; it does not delete local content, existing cloud files or credentials on another device. Changing app mode also does not delete cloud data. Local synchronization records and pending downloads may remain until app data is removed.
To delete cloud copies, disconnect all devices, delete the NGST/expressit files in Google Drive or the files in the OneDrive app folder and empty the provider’s trash where applicable. If you previously used hidden app-data backups, remove those through Google Drive’s app-management controls as well. A connected device or a retained legacy backup can otherwise restore data. Provider backup retention and deletion follow the provider’s policy. To remove local copies, use the app or operating system’s file/app-data controls, including local cloud caches; retain an export first if you need one.
We delete inquiry information when its retention period ends. You may request access, correction, deletion, restriction or other rights available where you live through the contact below. The company cannot directly delete files held only in your device or personal cloud account; those are managed using the controls described above.
6. Children, Security and External Cloud Incidents
The app is not directed to children under 13 or, in Korea, children under 14. If we learn that a child's information was submitted without required authorization, we delete it.
What encryption protects. Communication between the app and the cloud provider uses HTTPS/TLS encryption. This reduces the risk of someone intercepting or altering files while they travel over the internet. Encryption in transit cannot prevent every security incident, and it does not prevent someone who has already gained access to an account or device from opening stored files.
Protection of stored files. The app does not add a separate password known only to you or end-to-end encryption that allows only you to decrypt cloud files. Protection of stored files also depends on the cloud provider's safeguards and your account, device and sharing settings. Someone who can access a file may therefore be able to read the template content or thumbnail inside it. For example, information may be exposed if you enter your account password on a phishing site, your device is infected with malware, you make a backup folder accessible to others, or a security incident occurs at the cloud provider.
Controls available to you. Do not give others your account password or approve their login requests. Use available provider controls such as multi-factor authentication (an additional identity check beyond a password), signed-in device reviews and sharing permissions. You can choose not to connect cloud storage or disconnect it later. Disconnecting does not delete files already stored in the cloud; follow Section 5 if you also want to remove cloud copies. Operation and security of the external cloud service, and its incident response, are governed by the provider's terms and privacy policy and applicable law.
Responsibility when an incident occurs. Exposure of a template containing personal information does not, by itself, establish that a company server was breached or that the company disclosed the information. For example, if someone takes over your cloud account and downloads a template without any security failure attributable to the app or company, the incident must be assessed by examining the cause of the unauthorized access to that account or cloud service. Similarly, when a photograph made with a photo-editing app is stored in a personal cloud account and later exposed through that account, the app used to create the photograph and the cause of the disclosure must be considered separately.
The company is not responsible for an external account or cloud-service incident for which it is not at fault merely because a file was created or synchronized using this app. If a security defect in the app or an act by the company causes an incident, the company's responsibility is assessed on those facts and under applicable law. Responsibility depends on the cause of the incident and each party's fault. This notice does not exclude or limit liability arising from the company's intentional misconduct or negligence, or any liability or user rights that cannot be excluded or limited under applicable law.
We update this policy and provide any required notice or consent request before introducing materially different processing.
7. Privacy Officer and Changes
Privacy Officer: Noh HoeGang
Controller: NohGang Works Co.,Ltd. (주식회사 노강웍스)
Email: urgentman2@nohgangworks.com
We update the effective date and provide notice through this page or the app when required. If the Korean and English versions differ, the Korean version controls without limiting mandatory rights where you live.