Privacy Policy
This translation is provided for reference only. In case of any discrepancy, the Korean original shall prevail.
Effective date: 2025.09.01
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information being processed shall not be used for any purpose other than the following, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with the Personal Information Protection Act (PIPA).
1. Membership Registration and General Purposes
- Identification of Users and Member management
- Customer consultation, handling of inquiries, operation of user protection services, investigation of incidents such as dispute and complaint handling, and preservation of records
- Statistics, risk management, and improvement of customer service quality
- Restriction of use in the event of a breach of contract, prevention of account theft and fraudulent use, and verification of service usage records
- Delivery of notices such as amendments to the terms of service
- Provision and processing of event information and participation opportunities, and provision of advertising information
- Provision of the AI character conversation service and improvement of the conversation algorithms of the AI character conversation service
- Provision of a service supporting the withdrawal of membership cancellation requests
2. Development of New Services, Marketing, and Advertising
- Development and specialization of new services (products)
- Provision of services and placement of advertisements based on demographic characteristics
- Identification of access frequency
- Analysis of service usage performance
- Statistics on Members' use of the Service
- Delivery of advertising information such as events
- Notice of new services and products
3. In principle, the Company uses Members' personal information only within the scope of the purposes of collection and use, and does not disclose it to other persons or other companies/institutions. However, the following cases are exceptions.
- Where separate consent has been obtained from the data subject
- Where there are special provisions in the law or it is unavoidable in order to comply with statutory obligations
- Where the data subject or their legal representative is unable to express their intent, or prior consent cannot be obtained due to an unknown address or similar reasons, and it is clearly recognized as necessary for the urgent interests of the life, body, or property of the data subject or a third party
- Where personal information is provided in a form that does not allow the identification of a specific individual, as necessary for purposes such as compiling statistics or academic research
- Where it is necessary for the investigation of a crime and the filing and maintenance of a prosecution
- Where a Member's information (name, address, mobile phone, telephone number) is used for business-related contact
Article 2 (Processing and Retention Period of Personal Information)
1. The Company processes and retains personal information within the retention and use period of personal information prescribed by law, or within the retention and use period of personal information consented to by the data subject at the time of collecting personal information.
2. The respective processing and retention periods of personal information are as follows.
- Records concerning contracts or withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records concerning payment and the supply of goods, etc.: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records concerning consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
- Books and supporting documents concerning all transactions prescribed by tax law: 5 years (Framework Act on National Taxes)
- Records concerning electronic financial transactions: 5 years (Electronic Financial Transactions Act)
- Login records related to service use: 3 months (Protection of Communications Secrets Act)
3. The Company may retain the relevant personal information as follows in order to prevent fraudulent use of the Service and its recurrence.
1) Prevention of Fraudulent Use
- Items retained: encrypted same-person identification information (a hashed value of the email address)
- Retention period: 6 months from the date of membership withdrawal
2) Prevention of Re-registration by Members Who Violated the Terms of Service
- Items retained: duplicate registration verification information (DI)
- Retention period: 6 months from the date of loss of membership (date of sanction)
Article 3 (Items of Personal Information Processed)
The Company processes the following items of personal information.
1. Membership Registration and General
- Name, mobile phone number, date of birth, gender, identity verification information (CI), email address
- Universally unique identifier (ID), access medium information such as media type, IP address
- Information on messages sent and received (time of transmission, message content, etc.), User feedback information
2. The following items of personal information may be automatically generated and collected in the course of using the Service.
- Mobile phone device information and carrier, IP address, cookies, MAC address, service usage records, visit records, records of improper use
Article 4 (Provision of Personal Information to Third Parties)
The Company does not provide Users' personal information to third parties except where the User has given separate consent or where required by law. Where necessary to connect services with third parties, the Company provides personal information as follows, within the scope necessary for the use of the Service.
Article 5 (Outsourcing of Personal Information Processing)
The Company outsources tasks necessary for the provision of the Service to external companies to process personal information as described below, and manages and supervises the outsourced companies so that they do not violate applicable laws and regulations.
Article 6 (Destruction of Personal Information)
1. Where a Member has applied for membership withdrawal, the Company grants a grace period of 7 days to support the withdrawal of a cancellation request made by mistake. During the grace period, the Member may log in to the Service and withdraw the cancellation request; after the grace period has elapsed, the personal information shall be permanently destroyed in accordance with the procedures below.
2. The Company destroys the relevant personal information without delay when the personal information becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing.
3. Where personal information must continue to be preserved under other laws despite the expiration of the retention period consented to by the data subject or the achievement of the purpose of processing, the relevant personal information shall be transferred to a separate database (DB) or preserved in a different storage location.
4. The procedures and methods for destroying personal information are as follows.
- Destruction procedure
- The Company selects the personal information for which grounds for destruction have arisen, and destroys the personal information with the approval of the Company's Chief Privacy Officer.
- Destruction method
- The Company destroys personal information recorded and stored in electronic file format so that the records cannot be reproduced, and destroys personal information recorded and stored in paper documents by shredding them with a shredder or incinerating them.
Article 7 (Measures to Ensure the Security of Personal Information)
The Company makes the following efforts to protect the valuable personal information of Users.
[Administrative Measures]
- Promptly responding to changes in laws, regulations, and systems of relevant authorities and strengthening the level of management to safely protect personal information
- Establishing policies and guidelines on personal information and conducting regular training on information security and personal information protection so that the Company's executives and employees comply with them
- Limiting the number of personnel handling personal information to a minimum
[Technical Measures]
- Access control for systems processing personal information (assignment of individual accounts, password controls, minimization of privileges, creation and monitoring of access records)
- Encryption of personal information in transmission and storage (one-way encryption applied to passwords)
- Installation of antivirus programs and 24-hour monitoring through intrusion detection and prevention systems to protect personal information from hacking or computer viruses
- Application of appropriate protective measures through continuous research on new hacking and security technologies
[Physical Measures]
- Designating computer rooms and data storage rooms as controlled and protected areas and controlling access to them
Article 8 (Installation, Operation, and Refusal of Devices That Automatically Collect Personal Information)
The Company uses 'cookies' that store and retrieve usage information from time to time in order to provide individualized, customized services to Users.
[What Are Cookies?]
- A cookie is a very small text file sent to the User's browser by the server used to operate the website, and it is stored on the User's computer.
[Purposes of Use]
- Supporting Users in using the website easily and conveniently by maintaining their usage environment
- Providing differentiated information according to individual areas of interest (targeted marketing, exposure of related services based on areas of interest)
- Providing personalized services and information and improving the Service through analysis of Users' visit records and usage patterns
[How to Refuse Cookie Collection]
- Cookies do not store personally identifiable information such as names or telephone numbers, and Users have the right to choose whether to install cookies. Accordingly, Users may set options in their web browser to allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. However, if the User refuses to install cookies, web use may become inconvenient and there may be difficulties in using some services that require login.
[Examples of Option Settings for Cookie Collection]
- For Internet Explorer: [Settings] menu at the top right of the web browser > [Internet Options] > [Privacy] > [Advanced]
- For Chrome: [⋮] menu at the top right of the web browser > [Settings] > [Privacy and security] > [Site settings] > [Cookies and site data]
- For Microsoft Edge: [⋮] menu at the top right of the web browser > [Settings] > [Privacy, search, and services] > [Tracking prevention]
Article 9 (Management of Behavioral Information)
The Company collects and uses behavioral information for use in product and service development, customer analysis, marketing, and other purposes. Behavioral information refers to online user activity information — such as website visit history, app usage history, and search history — that makes it possible to identify and analyze a User's interests, preferences, tastes, and tendencies.
1. Items of Behavioral Information Collected
- Users' visit records within the web service, usage records such as searches and clicks, and advertising identifiers
2. Methods of Collecting Behavioral Information
- Automatic collection and transmission of Users' key actions performed within the app
3. Purposes of Collecting Behavioral Information
- Product and service development and statistics, user analysis, and provision and processing of customized advertising based on User behavioral information
4. Retention and Use Period of Behavioral Information and Subsequent Information Processing Methods
- Behavioral information is retained and used for 3 years from the date of collection. After the retention period has elapsed, it is retained and used solely for statistical purposes after de-identification measures have been applied.
5. How Users May Exercise Control
- Users may refuse such use by adjusting their browser settings, such as refusing the storage of cookies.
- Internet Explorer: Settings menu at the top > Internet Options > Privacy > Advanced > Block cookies
- chrome: Settings menu on the right of the web browser > Privacy and security > Cookies and other site data
Article 10 (Remedies for Infringement of Rights and Interests)
Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Personal Information Infringement Report Center, and other bodies in order to obtain relief from infringement of personal information.
In addition, please contact the following organizations to report or consult on other personal information infringements.
1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code required) (www.kopico.go.kr)
2. Personal Information Infringement Report Center: 118 (no area code required) (privacy.kisa.or.kr)
3. Supreme Prosecutors' Office: 1301 (no area code required) (www.spo.go.kr)
4. Korean National Police Agency: 182 (no area code required) (ecrm.cyber.go.kr)
To guarantee data subjects' right to informational self-determination and to provide consultation on infringements and remedies for damage, Plaitoon will take action without delay if you contact our Chief Privacy Officer in writing, by telephone, or by email.
<Addendum> This Privacy Policy applies from September 1, 2025.