Identity
Configured Google or Kakao sign-in is started through the CORELINK account service. Authentication providers handle their own credentials. PDI receives only the minimum account claims required to open the member workspace.
Platform hosting
PDI application records use the Site's managed Cloudflare Worker and D1 environment. Public pages expose only approved fields. Exact residential addresses, private contacts and identity records are not returned by public marketplace endpoints.
Managed authentication
Where Supabase is used for account-session support, the configured project is operated in the Tokyo region. Tokens are validated server-side and provider secrets are never returned to the browser.
AI translation
Support messages are sent to the configured AI translation processor only when a language conversion is needed. Korean-to-Korean messages are not sent for translation. Automatic translation is labelled, encrypted in storage and subject to staff review. A separate checkbox is required before the first translated conversation.
Suppliers and professionals
Customer details are disclosed to a supplier or licensed professional only when needed for an accepted service step. PDI records the purpose, case and responsible party. Public candidate sources are not treated as authorized customer-data recipients.
Analytics boundary
PDI's internal performance events use a random session value rotated into a one-day hash. The event record does not store an IP address, email, account id, user agent, full referrer URL, searched address or chat text. Campaign fields are limited to short marketing labels.
