KephaLabs (케파랩스)

Privacy Policy

Last updated: 2026-07-10


This Privacy Policy explains what personal data KephaLabs ("we", "us", "our") processes when you use the Zeric Revit add-in, visit kephalabs.com, or subscribe to Zeric Pro, and the rights you have over that data. It applies to our international customers.

1. Who we are (data controller)

The controller responsible for your personal data is:

2. Data we collect and why

2-1. Account & subscription data

When you subscribe to Zeric Pro, we process the email address you use at checkout in order to issue and renew your licence token and to send you service notices. Legal basis: performance of our contract with you.

2-2. Payment data (handled by Polar)

Payments are processed by Polar as Merchant of Record. Polar collects the information needed to take payment — such as your name, payment-method details, billing address, country, and IP address — under Polar's Privacy Policy. We never receive your full card details. From Polar we receive only what we need to manage your subscription (such as your email, country, and subscription status). Legal basis: performance of contract.

2-3. Usage telemetry (opt-in)

Only if you opt in to "send anonymous usage statistics", we collect:

Legal basis: your consent, which you can withdraw at any time (Section 8).

2-4. Capability Gap reports (per-event consent)

Only when you click "Didn't work" / "Helpful" and confirm the transmit-preview dialog, we collect: a separate InstallationId (not cross-correlated with the telemetry ID), your natural-language request and its normalized-intent form, the building-block IDs used / estimated missing capability, Revit version / locale / add-in version, and any optional comment you write. Legal basis: your consent.

2-5. Support communications

If you email us, we process your message and contact details in order to respond. Legal basis: our legitimate interest in providing support.

2-6. Licence anti-abuse (at licence verification)

2-7. Free-plan usage limit (when you use the free plan)

3. What we do not collect

4. Who we share data with (processors)

We do not sell your personal data. We share it only with service providers who process it on our behalf under contract:

Opt-in usage statistics and Capability Gap data are processed on our own servers, not by a third-party analytics provider.

Your AI (LLM) provider (such as Anthropic, OpenAI, Google, or xAI) is called directly from your computer using your own API key under the BYOK model — that traffic does not pass through us, and your relationship with that provider is governed by their own terms and privacy policy.

If you use the optional local-AI mode (Ollama, running on your own computer), your requests and the model's processing take place entirely on your PC: no request or response data leaves your device, and no external AI provider is contacted. Any hardware check (GPU / CPU / memory) used to recommend a suitable local model is performed locally and is not transmitted to or stored by us.

If you use the optional experimental code-generation feature (which turns a request that has no matching built-in feature into code on the fly), your request text may be sent to OpenRouter, Inc. (United States), which routes it to a US-based inference provider to generate the code. We restrict this routing to US-based providers and exclude providers hosted in other countries such as China. Only your request text is transmitted — never your Revit model, files, or element data. You can disable this by enabling Offline mode. Contact: [email protected].

5. International data transfers

Our servers are located in the Republic of Korea, which the European Commission recognizes as providing an adequate level of data protection (adequacy decision, 2021). Where personal data is transferred to or processed by our service providers in other countries, we rely on appropriate safeguards (such as adequacy decisions or standard contractual clauses) as required by applicable law.

6. How long we keep data

7. Your rights

Subject to applicable law (including the GDPR / UK GDPR where it applies to you), you have the right to access, correct, delete, export (data portability), or restrict the processing of your personal data, to object to processing, and to withdraw consent at any time without affecting processing carried out beforehand.

8. Opt-out & withdrawing consent

Open the Zeric [Settings] dialog or first-run wizard and turn off the opt-in — all opt-in usage-statistics and Capability-Gap transmission stops immediately. (Licence anti-abuse processing in §2-6 is not part of the opt-in and continues as part of licence verification.) You can also unsubscribe from non-essential emails at any time.

9. California privacy notice

We do not sell or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). California residents have the right to know, delete, and correct their personal information, and not to be discriminated against for exercising these rights; requests can be made at [email protected].

10. Cookies

Our own website does not set cookies; it stores only your language preference locally in your browser (via localStorage). When you proceed through the Polar checkout, Polar may set cookies necessary to process your payment, under Polar's own policy. We do not use advertising or cross-site tracking cookies.

11. Children

Zeric is not directed to children and is not offered to anyone under the age of 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time; the "Last updated" date above reflects the latest version, and material changes will be notified in-app or by email.

13. Contact

Questions about this policy or your data: [email protected].