Short AI

利用規約プライバシーポリシーお問い合わせとサポート
会社名
Impact Station Inc. (임팩트스테이션 주식회사)
代表者
Song Sanghoon
事業者登録番号
683-86-00599
住所
901, Sanjeong Bldg., 23 Gukhoe-daero 66-gil, Yeongdeungpo-gu, Seoul 07237, Republic of Korea

プライバシーポリシー

2026年10月1日施行

この画面は韓国語正本の翻訳版です。解釈に相違がある場合は韓国語版が優先されます。ご不明な点は dev@impactstation.kr までご連絡ください。

Chapter 1 General Provisions

Article 1 (Purpose)

① The purpose of this Policy is to set out for what purposes Impact Station Co., Ltd. (the "Company") processes Users' personal information in the Short AI service it provides (the "Service"), how long it retains that information, and how it destroys it.

② The Company complies with the Personal Information Protection Act and other applicable laws and keeps this Policy posted within the Service at all times.

③ The personal information controller under this Policy is the Company (Representative: Song Sanghoon; Business Registration Number: 683-86-00599).

Article 2 (Definitions)

① Terms used in this Policy have the meanings given in Article 2 of the Terms of Service.

② "Creator" means a Member who is active in the Creator role under the Creator Member Terms, and "Client" means a Member who has commissioned content production from a Creator through business matching.

Article 3 (Relationship to Other Rules)

① Matters not provided for in this Policy are governed by the Terms of Service and applicable laws.

② Inquiries about this Policy, requests to exercise data subject rights, and objections are received through the contact channel set out in Article 25 of the Terms of Service. Processing deadlines and procedures not separately provided for in this Policy follow that Article.

③ Changes to this Policy follow Article 19, and notice to Members follows Article 33 of the Terms of Service.

Chapter 2 Processing of Personal Information

Article 4 (Personal Information Processed)

① The Company processes only the minimum personal information necessary to provide the Service.

② The items processed during sign-up and sign-in are as follows. You may sign up either by registering an email address and password directly or by signing in with a social account. Depending on the method chosen, either item 1 or item 2 is processed. Item 3 lists the items entered directly by the User. Of those items, nickname and date of birth, together with the name within the scope set out in item 3, must be entered in order to use the Service, while phone number and gender may be left blank and the Service may still be used. However, Members who sign in with a social account are not asked for the items in item 3. In that case the display name is the name passed under item 2, or, where no name is passed, the handle generated automatically at sign-up (paragraph ④, item 1); and whether the Member is at least 14 years old is established by the confirmation recorded on the consent screen.

  1. 1.When signing up with an email address and password (entered directly by the User): email address (account identification and sign-in), password (the original is not stored; it is kept only in an irreversible form. See Article 13), email verification time (the time the sign-up confirmation email was opened)
  2. 2.When signing in with a social account (passed to the Company by the relevant provider): email address (account identification), name (default for the initial display name), profile picture (a copy of the image provided by the provider is kept in the Company's storage; the original URL is not stored), email verification time (the value passed by the provider), social account identifier and authentication token (values needed to keep you signed in)
  3. 3.Items entered directly by the User regardless of sign-up method: name (used for identity verification and Service-related contact; not shown to other Users. Collected only from Members who sign up on or after September 11, 2026; it is not requested from Members who signed up before that date or from Members who sign in with an Apple account. Where sign-in is by social account, the name received under item 2 is also used for this item), nickname (display name; shown on the public profile), phone number (used for identity verification, account recovery, and Service-related contact; not shown to other Users), gender (used only for aggregate statistics from which no individual can be identified; not shown to other Users), date of birth (used to confirm that the User is at least 14 years old and to restrict viewing by content rating; not shown to other Users). Users registered as Creators are not asked again for phone number, gender, or date of birth under this paragraph; the information received during the Creator registration process is used instead

③ When you sign in with a Google or Apple account, personal information is transferred to the United States (Article 9). When you sign in with a Kakao account or sign up with an email address and password, personal information is not transferred abroad. However, usage statistics (paragraph ⑤, item 6) and playback quality records (paragraph ⑤, item 7) are transferred to the United States regardless of the sign-in method, under Article 9, paragraph ⑨ and Article 9, paragraph ⑤ respectively, and, if you have allowed notifications in the app, the app push token and notification content (paragraph ⑤, item 5) are transferred to the United States regardless of the sign-in method, under Article 9, paragraph ⑩.

④ The items entered directly by the User while using the Service are as follows. The profile items in items 1 and 2 are optional; the Service can be used without entering them, and they are shown on the public profile.

  1. 1.Profile: profile picture, bio, handle (generated automatically at sign-up)
  2. 2.Creator profile: country and city of activity, specialties, tools used, languages used, roles, whether bank transfers are accepted (for display), collaboration terms (available hours, time zone, team size, external links)
  3. 3.Posts and comments: body text, attached images
  4. 4.Commissions: commission message (255 characters), reference links, budget, preferred region
  5. 5.Reports: reason for the report, detailed description

⑤ The items generated while using the Service are as follows.

  1. 1.Playback records: playback start, progress, and end events, and the resume position
  2. 2.View records: profile views
  3. 3.Recommendation impression records: which recommendations were shown and selected
  4. 4.Relationship records: follows, blocks, favorites, likes
  5. 5.Notifications: notification title, body, and sender, and, if you have allowed notifications in the app, the app push token of that device
  6. 6.Usage statistics: which screens were opened and which buttons were pressed (page views; playback start, progress, and completion; favorites; likes; follows; shares; whether a search was run). These are aggregated with a third-party analytics tool (Google Analytics). Values that identify the User, such as the Member number or email address, and search terms are not sent; visitors are distinguished only by a random cookie identifier stored in the browser (Article 9, paragraph ⑨ and Article 12)
  7. 7.Playback quality records: how much of a video was played and where it stopped; playback failures, stalling (rebuffering), and picture quality; and the device, browser, screen size, and connection conditions at that time. These are aggregated with a third-party analytics tool (Mux Data). Values that identify the User, such as the Member number or email address, are not sent, and no cookie is used. Records are kept only per video and per single playback, and are not linked to that person's other playbacks (Article 9, paragraph ⑤)

⑥ Activity records made while not signed in contain no value that identifies the User and remain only as aggregate data from which no individual can be identified. These records are not personal information.

⑦ The items processed only in connection with paid use and settlement are as follows. They are processed only when you pay for a pass or receive settlement payments, and are not processed if you do not use those features.

  1. 1.Payment: payment identifier, type of payment method, payment amount, payment time. Information about the payment method itself, such as card numbers and bank account numbers, is processed by the payment agency and is not received by the Company
  2. 2.Settlement account: account holder name, bank, account number. Required to pay settlement amounts
  3. 3.Unique identification information: resident registration number or foreigner registration number. Used only for withholding tax and filing of payment statements as required by the Income Tax Act and the Corporate Tax Act; stored encrypted and masked on screen (Article 13)
  4. 4.Business information: trade name, business registration number, representative's name, place of business address. Collected only from business-registered Creators who issue tax invoices
  5. 5.Client information: the Client's contact person name, contact details, company name, business registration number. Required to conclude and perform production contracts

⑧ Unique identification information is used only for the purpose prescribed by law (withholding tax) and is destroyed once that purpose has ended and the retention period in Article 6 has elapsed. This item is stored encrypted and separately from other information.

⑨ The Company does not collect the following information. If a feature requiring it is introduced, this Policy will be changed first.

  1. 1.Unique identification information not listed in paragraph ⑦, such as passport numbers and driver's license numbers (there is no storage field for it)
  2. 2.Sensitive information such as ideology, beliefs, health, and sex life (there is no storage field for it)
  3. 3.IP addresses and browser information (not stored in the Company's database. Information that the overseas providers in Article 9 receive directly on their own systems is described in that Article)
  4. 4.Search terms and electronic signature records (storage fields exist but are not recorded)

⑩ The following items are processed only for Members who have chosen to consent to receiving marketing communications. Not consenting does not restrict sign-up or use of the Service.

  1. 1.Consent records: whether consent was given, refused, or withdrawn, and the date and time
  2. 2.Items used for sending: email address, nickname, app push token (if you have allowed notifications in the app)

Article 5 (Purposes of Processing Personal Information)

The Company processes the items listed in each of the following for the following purposes.

  1. 1.Member identification and keeping you signed in: email address, social account identifier, authentication token
  2. 2.Public profile display: display name, profile picture, handle, bio, Creator profile
  3. 3.Content ranking and home screen composition: playback and view records (aggregated)
  4. 4.Resume playback: playback position
  5. 5.Recommendation display and performance measurement: recommendation impression and click records
  6. 6.Social features such as following and blocking: relationship records
  7. 7.Sending notifications: notification recipient and content
  8. 8.Receiving and handling reports: reason for the report, details, outcome
  9. 9.Receiving and brokering commissions: commission details, budget, region
  10. 10.Audit records of operator actions: who acted, the target, the reason, the result
  11. 11.Payment and refund of paid passes: payment identifier, payment amount, payment time, pass records
  12. 12.Creator settlement and withholding tax: account holder name, bank, account number, unique identification information, business information, playback logs
  13. 13.Conclusion and performance of production contracts (business matching): commission details, Client contact person information, Creator profile and portfolio
  14. 14.Compliance with legal obligations (transaction and tax records): order, payment, tax invoice, and settlement records
  15. 15.Identity verification, account recovery, and Service-related contact: name (Members who signed up on or after September 11, 2026), phone number
  16. 16.Age verification and viewing restrictions by rating: date of birth
  17. 17.Aggregate statistics (only in a form from which no individual can be identified): gender
  18. 18.Analysis of usage statistics (which screens are used most and where Users leave): usage statistics (Article 4, paragraph ⑤, item 6)
  19. 19.Analysis of playback quality (in which works playback fails or stalls): playback quality records (Article 4, paragraph ⑤, item 7)
  20. 20.Sending marketing communications (informing only Members who have given optional consent about new works, events, and offers by email and app push notification): email address, nickname, app push token, consent records (Article 4, paragraph ⑩)

Article 6 (Processing and Retention Period of Personal Information)

① Member information is retained while membership continues and is destroyed after a withdrawal request in accordance with the procedure in Article 10.

② Transaction and tax records are retained without destruction for the following periods as required by applicable laws, and are stored and managed separately from other personal information.

  1. 1.Order, payment, and refund records: 5 years, as records of payment and supply of goods under the Act on the Consumer Protection in Electronic Commerce
  2. 2.Withdrawal of subscription and contract records: 5 years, as records of withdrawal of subscription and contracts under the Act on the Consumer Protection in Electronic Commerce
  3. 3.User complaint and dispute resolution records: 3 years, as records of consumer complaints and dispute resolution under the Act on the Consumer Protection in Electronic Commerce
  4. 4.Labeling and advertising records: 6 months, as records of labeling and advertising under the Act on the Consumer Protection in Electronic Commerce
  5. 5.Tax invoices and transaction evidence (including the counterparty's name, business registration number, and email address): 5 years (7 years for offshore transactions), as transaction evidence under the Framework Act on National Taxes
  6. 6.Settlement records, contracts, and project records: 5 years, as contract records under the Act on the Consumer Protection in Electronic Commerce and as transaction evidence under the Framework Act on National Taxes
  7. 7.Unique identification information and payment details related to withholding tax: 5 years, as the basis for withholding tax and filing of payment statements under the Income Tax Act and the Corporate Tax Act

③ Because the Company sells passes directly and is a party to production contracts, it retains all of the records in paragraph ②. Under an interpretation that treats the Company as an intermediary, the scope of retention would be narrower, but because the Company retains the wider scope, it satisfies the statutory retention obligation under either interpretation. The retention periods are those in paragraph ② under either interpretation.

④ For records left in the course of using the Service, once the following periods have elapsed, the values linking the record to the User are deleted or the record itself is deleted. Records may remain as statistics, but it becomes impossible to tell who left them.

  1. 1.Viewing, view, and recommendation impression records: after 90 days, the User identifiers (Member number and session number) are deleted. Impression counts per work remain as statistics
  2. 2.Signage device status records: deleted after 30 days
  3. 3.Playback logs (basis for settlement): deleted 400 days after the settlement payment is completed. They are not deleted before payment because they are the basis for settlement
  4. 4.Discarded playback records: deleted after 365 days

⑤ When an account is deleted, these records are processed together regardless of the periods in paragraph ④. They are destroyed after the 30-day grace period following withdrawal, and the User identifiers in the usage records are deleted at the same time (Article 10).

⑥ The periods in paragraph ④ are actually applied by a deletion job that runs every hour.

⑦ The items in Article 4, paragraph ⑩, item 2 are used for sending marketing communications until you withdraw consent to receive marketing communications or withdraw your membership. The consent records in item 1 of the same paragraph are evidence of consent and withdrawal, and are kept until they are destroyed under Article 10 after withdrawal of membership.

Chapter 3 Provision, Outsourcing, and Cross-Border Transfer of Personal Information

Article 7 (Provision of Personal Information to Third Parties)

① The Company provides personal information to third parties only in the following cases and not otherwise. Processing outsourcing required for operating the Service is not provision to a third party and is governed by Articles 8 and 9.

  1. 1.To a Member who has commissioned production through business matching (the Client), the Company provides the Creator's activity name, profile picture, specialties, tools used, portfolio, and grade, and after the project has started, the contact details needed to perform the contract. The time of provision is when the Creator accepts the commission and the project starts; before then, the Creator's contact details are not provided to the Client. The purpose is the conclusion and performance of the production contract, and the retention period is the period set out in Article 6 after the transaction ends
  2. 2.To the Creator, the Company provides the Client's contact person name, contact details, and company name. The time of provision is when the Creator accepts the commission and the project starts (Article 20 of the Terms of Service); before then, the Client's identity is not provided to the Creator. The purpose is the performance of the production contract, and the retention period is the period set out in Article 6 after the transaction ends
  3. 3.To the National Tax Service, the Company provides the payee's name, unique identification information, and payment amount when filing withholding tax returns and payment statements. The purpose is compliance with legal obligations, and the retention period is the period prescribed by law

② The provision under items 1 and 2 of paragraph ① is based on the performance of a contract, and the provision under item 3 is based on a legal obligation. Accordingly, the Company does not obtain separate consent and gives notice by stating it in this Policy.

Article 8 (Outsourcing of Personal Information Processing)

① To provide the Service, the Company outsources (entrusts) the processing of personal information as follows.

  1. 1.To Amazon Web Services, Inc.: database, web server operation, and file storage, processed domestically (Seoul)
  2. 2.To Amazon Web Services, Inc.: image delivery (CDN), processed abroad (United States and other countries)
  3. 3.To Google LLC: social sign-in authentication and profile image hosting, processed abroad (United States)
  4. 4.To Apple Inc.: social sign-in authentication, processed abroad (United States)
  5. 5.To Kakao Corp.: social sign-in authentication, processed domestically
  6. 6.To Mux, Inc.: video encoding, streaming, and playback quality analysis, processed abroad (United States)
  7. 7.To Toss Payments Co., Ltd.: pass payment processing and refund processing, processed domestically
  8. 8.To GitHub, Inc.: execution environment for scheduled batch jobs, processed abroad (United States)
  9. 9.To Google LLC: usage statistics analysis (Google Analytics), processed abroad (United States)
  10. 10.To Google LLC: delivery of app push notifications sent to Android devices (Firebase Cloud Messaging), processed abroad (United States)
  11. 11.To Apple Inc.: delivery of app push notifications sent to iOS devices (Apple Push Notification service), processed abroad (United States)

② The database, web servers, and file storage are processed domestically (Seoul). Only the items marked "abroad" in paragraph ① are processed abroad, and the details are set out in Article 9.

Article 9 (Cross-Border Transfer of Personal Information)

① To provide the Service, the Company entrusts the processing and storage of personal information to overseas providers. This is processing outsourcing and storage necessary for the performance of the contract concluded with the User, and because the matters required by law are disclosed in this Policy, separate consent is not obtained.

② The transfer to Google LLC (social sign-in authentication and profile image hosting) is as follows.

  1. 1.Items transferred: the connecting IP address and browser information at the time the User is redirected to the Google sign-in screen (collected directly by Google). Because a copy of the profile picture is kept in the Company's storage at sign-up, it is not transferred through this route, and the IP address of a person viewing the profile is not transferred to Google either
  2. 2.Destination country, timing, and method: to the United States and other countries where Google operates, transferred by HTTPS request at the time of a sign-in attempt
  3. 3.Purpose of use and retention period: used for sign-in authentication and provision of profile images. Google does not publish a single retention period; it varies by data type and user settings. The transfer continues for as long as the Company offers Google as a sign-in method
  4. 4.How to refuse: if you sign up with another sign-in method, such as Kakao (domestic) or email and password, no information is transferred to Google

③ The transfer to Apple Inc. (social sign-in authentication) is as follows.

  1. 1.Items transferred: the connecting IP address and device information at the time the User is redirected to the Apple sign-in screen (collected directly by Apple)
  2. 2.Destination country, timing, and method: to the United States, transferred by HTTPS request at the time of a sign-in attempt. Apple states that personal information collected worldwide is stored by Apple Inc. in the United States
  3. 3.Purpose of use and retention period: used for sign-in authentication. Apple does not publish a single retention period. The transfer continues for as long as the Company offers Apple sign-in
  4. 4.How to refuse: if you sign up with another sign-in method, such as Kakao or email and password, no information is transferred to Apple

④ During the sign-in process, the Company does not send any value identifying the User to the providers in paragraphs ② and ③. The only value carried in the sign-in request is a temporary value confirming that the request originated from the Company's screen; the Member number, email address, and similar values are not included.

⑤ The transfer to Mux, Inc. (video encoding, streaming, and playback quality analysis) is as follows.

  1. 1.Items transferred: original video files uploaded by Creators; the viewer's IP address and playback request information at the time a video is played; and playback quality records (Article 4, paragraph ⑤, item 7 — the identifier of the video played, the amount played and the point at which it stopped, playback failures and stalling, device, browser, screen size, time of access, and approximate region at city level). The Company does not send User identifiers to Mux and does not use cookies for playback quality records
  2. 2.Destination country, timing, and method: to the United States, at the time of upload and at the time of video playback, by the browser uploading directly to Mux and requesting playback directly from Mux
  3. 3.Purpose of use and retention period: used for video encoding and streaming delivery, and for the analysis of playback quality. Playback quality analysis is used only to find and fix where playback fails or stalls, and is not used for advertising. Mux does not publish a single retention period. Original video files are retained until the Company deletes the asset, and viewer IP addresses and playback quality records follow Mux's policy
  4. 4.How to refuse: if you do not play videos, your viewer IP address is not transferred. However, because video viewing is the core of the Service, use is effectively difficult. Creators who do not upload videos have no original files transferred

⑥ The transfer to Amazon Web Services, Inc. (image delivery, CDN) is as follows.

  1. 1.Items transferred: profile pictures, content thumbnails, and images attached to posts (public files only)
  2. 2.Destination country, timing, and method: to a CDN server in a country near the User, by transmitting the file over HTTPS when it is first requested and then keeping it temporarily (caching)
  3. 3.Purpose of use and retention period: used to improve delivery speed. Deleted when the cache expires; the original remains domestically
  4. 4.How to refuse: files can be destroyed by withdrawing membership. However, if you refuse, profile pictures and thumbnails will not be displayed

⑦ The storage location for paragraph ⑥ is domestic. Originals are in the Seoul region, and what is transferred abroad is a copy for delivery. Files that require sign-in to view (original videos and settlement statements) are opened only through signed URLs and do not pass through the CDN. Because profile pictures are displayed on public screens and pass through this route, the User decides whether to upload potentially sensitive images, such as a photo of their face, to their profile.

⑧ The transfer to GitHub, Inc. (execution of scheduled batch jobs) is as follows.

  1. 1.Items transferred: personal information within the scope processed by the batch jobs (information subject to account destruction and records subject to aggregation). GitHub does not store this information
  2. 2.Destination country, timing, and method: to the United States (GitHub-hosted runners), by the runner connecting directly to the database during the hourly aggregation batch and the daily destruction batch at 03:00 (Korea Standard Time)
  3. 3.Purpose of use and retention period: used to provide an execution environment for scheduled batch jobs. Execution results are not stored; execution logs are retained by GitHub for 90 days by default (adjustable by settings)
  4. 4.How to refuse: in accordance with paragraph ⑪

⑨ The transfer to Google LLC (usage statistics analysis, Google Analytics) is as follows. What is transferred is only a random cookie identifier not linked to any account and the usage records attached to it, and any User, whether a Member or not signed in, may refuse this transfer alone by the method in item 4.

  1. 1.Items transferred: a random cookie identifier stored in the browser (Article 12, paragraph ①, item 4), the URL and title of the screen opened, the type of button pressed (playback start, progress, and completion; favorites; likes; follows; shares; whether a search was run), device, browser, and screen size, time of access, and approximate location at the city level. Values that identify the User, such as the Member number, email address, or name, and search terms are not sent. The connecting IP address is used by Google only to estimate the location and is not stored
  2. 2.Destination country, timing, and method: to the United States and other countries where Google operates, by the browser sending an HTTPS request directly to Google each time a screen is opened or a button is pressed
  3. 3.Purpose of use and retention period: used to analyze Service usage statistics, such as which screens are used most and where Users leave. Not used for advertising or personalized advertising, and advertising personalization signals are turned off. User-level records are retained in Google Analytics for 14 months and then deleted automatically; after that, only aggregate statistics from which no individual can be identified remain
  4. 4.How to refuse: if you refuse or delete the cookies in Article 12, paragraph ①, items 4 and 5 in your browser, or install the Google Analytics opt-out browser add-on provided by Google, no information is transferred. Refusing does not restrict your use of the Service

⑩ The transfer to app push notification delivery providers is as follows. Notifications to Android devices are sent through Google LLC (Firebase Cloud Messaging) and notifications to iOS devices through Apple Inc. (Apple Push Notification service); a notification for a given device is transferred only to the one provider that corresponds to that device's operating system. This applies only if you have allowed notifications in the app, and nothing is transferred when you use the Service in a web browser.

  1. 1.Items transferred: the app push token of that device (Article 4, paragraph ⑤, item 5) and the title and body of the notification. Values that identify the User, such as the Member number, email address, or name, are not sent. Because the device connects directly to the provider when the app obtains a token, the provider directly collects that device's connecting IP address and device information
  2. 2.Destination country, timing, and method: to the United States and other countries where the provider operates, by the device making a request directly to the provider when a token is obtained after notifications are allowed in the app, and by the Company's server sending an HTTPS request to the provider each time a notification is generated
  3. 3.Purpose of use and retention period: used to deliver Service notifications (Article 5, item 7) and, only for Members who have given optional consent, marketing communications (Article 5, item 20) to the device. Notification content is kept temporarily for delivery to the device; if it cannot be delivered immediately because the device is not connected, Firebase Cloud Messaging keeps it for up to 4 weeks and Apple Push Notification service for the period set by Apple, and then delivers or discards it. Google and Apple do not publish a single retention period for delivery records
  4. 4.How to refuse and its effect: if you do not allow notifications in the app, no token is issued or registered and nothing is transferred. If you turn off app notifications in the device settings after allowing them, notifications are not displayed on the device, but notification delivery requests may continue to be transferred to the provider until you sign out on that device. Signing out revokes that device's token and stops the transfer. Withdrawing consent to receive marketing communications in the settings screen stops only app push notifications for marketing communications; Service notifications continue to be delivered by app push. In either case your use of the Service is not restricted, and notifications can be viewed in the notification list within the Service

⑪ The method, procedure, and effect of refusing cross-border transfer are as follows. Users who do not want the transfer may stop it by withdrawing membership, and the withdrawal procedure follows Article 10.

  1. 1.Individual trustees cannot be selected and refused separately. The providers in paragraphs ② through ⑧ are infrastructure required for the Service to operate, and if any one of them is excluded, the Service does not function
  2. 2.If you refuse, you cannot use the Service. This is because sign-up, sign-in, video playback, and profile display all run on the above infrastructure
  3. 3.The transfers in paragraphs ⑤ and ⑥ can be partially avoided by not using the relevant features (uploading a profile picture directly, not playing videos)
  4. 4.The transfer in paragraph ⑨ (Google Analytics) is a statistics tool rather than infrastructure required for the Service to operate, so unlike items 1 and 2, it can be refused on its own; the method and effect follow paragraph ⑨, item 4
  5. 5.The transfer in paragraph ⑩ (app push notification delivery) takes place only if you have allowed notifications in the app, so unlike items 1 and 2, it can be refused on its own; the method and effect follow paragraph ⑩, item 4

Chapter 4 Destruction of Personal Information and Rights of Data Subjects

Article 10 (Procedure and Method of Destroying Personal Information)

① The destruction procedure is as follows.

  1. 1.The User requests withdrawal (account deletion)
  2. 2.A 30-day grace period applies. The request can be cancelled during this period
  3. 3.Once the grace period ends, the destruction job that runs daily at 03:00 (Korea Standard Time) processes it

② If any of the following grounds exists, destruction is deferred until that ground is resolved. Once the ground is resolved, destruction proceeds automatically without a new request, and the reason for the deferral is shown on the request screen.

  1. 1.A project is in progress: resolved automatically when the project ends
  2. 2.Unpaid settlement amounts exist: resolved automatically when settlement is completed
  3. 3.A report or dispute is being handled: resolved automatically when handling is completed
  4. 4.An active subscription exists: resolved only when the User cancels it themselves
  5. 5.A refund deduction balance remains: you must contact the channel set out in Article 25 of the Terms of Service

③ Personal information linked to the account is deleted, and identifying information is erased from records that must retain references for transactions and settlement. Linked sign-in accounts are processed to the same extent. What is deleted and what remains for each target is as follows.

  1. 1.Account: name, email address, email verification time, and profile picture are deleted; only the internal identifier remains
  2. 2.Profile: handle and previous URLs, display name, legal name, phone number, gender, date of birth, age verification time, profile picture, and bio are deleted; the sign-up time, role, withdrawal status indicator, and the record of its reason remain
  3. 3.Company information: contact person name, contact person details, and business registration number are deleted; company name, country, and industry remain
  4. 4.Settlement information: account number, account holder name, and unique identification information are deleted after the retention period in Article 6 has elapsed; payment amounts and dates are tax evidence and are stored separately
  5. 5.Playback and view records: who performed the action and whose profile was viewed are deleted; the action itself remains for aggregation
  6. 6.Search term records: who searched is deleted; the search terms remain
  7. 7.Recommendation impression records: who saw them is deleted; the impression records remain

④ The body text and ratings of posts, comments, and reviews you wrote, and the works, photos, and videos you uploaded, including originals and thumbnails, are deleted. Publication and playback of your works are stopped, and only the empty records needed to maintain references to transaction records are kept. Passwords, sign-in sessions, and social sign-in link information are also deleted.

⑤ Destruction is carried out in a way that cannot be reversed, and matters relating to destruction are recorded and managed. If cleanup at external storage or the video provider fails, it is retried, and the deletion is marked complete only after external cleanup has finished. You can check the receipt, processing status, and final result on the account deletion guide screen of the device from which the request was made (Article 12, paragraph ①, item 6). After destruction, the Chief Privacy Officer verifies the result.

⑥ The transaction and tax records in Article 6, paragraph ② are not destroyed and are stored separately.

⑦ For accounts signed in with Apple, the Company requests that the Apple link be revoked using the stored authentication token. Even where a previous version did not store the token needed for revocation, account deletion proceeds, and the account deletion guide screen provides instructions for revoking the link directly in your Apple account settings.

Article 11 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)

① Users may exercise the following rights at any time.

  1. 1.Access: you may check the personal information about you that the Company processes
  2. 2.Correction and deletion: you may request that inaccurate information be corrected or deleted
  3. 3.Suspension of processing: you may request that processing of your personal information be stopped
  4. 4.Withdrawal of consent: you may withdraw consent for personal information processed on the basis of consent

② Profile information can be edited directly on the profile edit screen.

③ Other requests are received through the contact channel set out in Article 25 of the Terms of Service. The Company processes the request and notifies you of the result within 10 days of receiving it.

④ If the Company refuses a request or is unable to act on it, it notifies you of the reason without delay.

⑤ Users may also make requests through a legal representative or an authorized person.

⑥ Consent to receive marketing communications is handled as follows.

  1. 1.You may withdraw consent or consent again at any time on the Settings screen, and the change takes effect immediately
  2. 2.When consent, refusal, or withdrawal is processed, the date of processing and the result are shown on that screen as notice
  3. 3.Every 2 years from the date of consent, the Company checks whether you wish to keep receiving marketing communications
  4. 4.Marketing communications are not sent by app push notification between 9 PM and 8 AM the following day

Article 12 (Devices That Automatically Collect Personal Information)

① The Company uses the following cookies.

  1. 1.authjs.session-token: a cookie for keeping you signed in, with a lifetime of 30 days. If refused, you cannot stay signed in
  2. 2.NEXT_LOCALE: a cookie for remembering your chosen display language; it disappears when the browser is closed (session cookie). If refused, your language choice is not remembered on your next visit
  3. 3.csid: a random identifier for counting playback starts from the same browser as one while not signed in, with a lifetime of 1 year. It is not linked to any account and cannot identify who you are (Article 4, paragraph ⑥), and refusing it does not restrict your use of the Service
  4. 4._ga: a random identifier for distinguishing visitors (Google Analytics), with a lifetime of 2 years. It is not linked to any account, and refusing it only excludes you from usage statistics without restricting your use of the Service
  5. 5.Cookies named _ga_ followed by a measurement ID: session state for the same visitor (Google Analytics), with a lifetime of 2 years. The effect of refusing is the same as in item 4
  6. 6.contentrip.deletion-receipt: a tamper-proof receipt for checking the processing result on the same device after a withdrawal request, with a lifetime of 180 days. It carries no sign-in authority. If refused or deleted, you cannot check the status by receipt on that device. It does not affect the processing of account deletion

② Users may refuse cookie storage or delete stored cookies in their browser settings. However, if the sign-in cookie is refused, features that require sign-in cannot be used.

③ The Company uses Google Analytics cookies (paragraph ①, items 4 and 5) for the purpose of analyzing usage statistics. Third-party cookies for advertising purposes are not used. The method and effect of refusing analytics cookies follow Article 9, paragraph ⑨, item 4.

Chapter 5 Security Measures and the Chief Privacy Officer

Article 13 (Measures to Ensure the Security of Personal Information)

① The Company implements the following measures.

  1. 1.Database-level access control: row-level security policies are applied to the main tables holding Members' personal information, so that the database itself blocks access to anything other than the signed-in User's own data
  2. 2.Separation of access privileges: the account used by the Service is separated from the account used for administrative work, so the security policies cannot be bypassed with the Service account
  3. 3.Tamper-proof consent records: consent and withdrawal records are append-only and cannot be modified or deleted by the Service account
  4. 4.Audit records of operator actions: operator actions are recorded with who acted, what was done, why, and what the result was, and cannot be modified or deleted
  5. 5.Protection of sign-in information: the sign-in cookie is configured so that browser scripts cannot read it
  6. 6.Video access control: video playback URLs open only with a signed token valid for 6 hours
  7. 7.Encryption in transit: all external transmissions use encrypted connections (HTTPS and encrypted database connections)
  8. 8.Protection of unique identification information: resident registration numbers and foreigner registration numbers received for settlement are encrypted as required by law and stored separately from other information. Access is restricted to settlement staff, the values are masked on screen, and who accessed them and when is recorded
  9. 9.No storage of payment information: information about the payment method itself, such as card numbers and bank account numbers, is processed by the payment agency. The Company's systems have no storage field for it
  10. 10.Internal management plan: an internal management plan for handling personal information securely is established and implemented
  11. 11.Retention of access records: what operators do with personal information is recorded and not erased. Service access records are retained for 1 year
  12. 12.Encryption of stored data: the database and file storage are encrypted at rest. Passwords are not stored in their original form and are kept only in an irreversible form
  13. 13.Malware prevention and physical access control: servers are operated in the cloud provider's data centers, and the execution environment is replaced with a new image on every deployment. The Company does not operate its own server room

② The Company does not process sensitive information and has no storage field for it.

③ Unique identification information is received only from Creators who receive settlement payments, for the statutory purpose of withholding tax, and the encryption and access controls required by law are applied as set out in paragraph ①, item 8.

④ The specific details of the measures in paragraph ① are set out in the internal management plan.

Article 14 (Items Not Applicable)

The following items, which the law requires to be stated only where applicable, do not apply to the Company.

  1. 1.Possibility of disclosure of sensitive information and how to opt out: the Company does not process sensitive information
  2. 2.Processing of pseudonymized information: the Company does not process pseudonymized information
  3. 3.Criteria for additional use and provision: the Company does not use or provide information beyond the purpose for which it was collected
  4. 4.Countries in which personal information of domestic Users is collected directly from abroad: there is no flow of direct collection from abroad

Article 15 (Personal Information of Children Under 14)

① The Company does not process the personal information of children under 14 years of age. This applies regardless of the User's country of residence.

② On first use after sign-up, the User confirms that they are at least 14 years old, and this is verified again by the date of birth entered next (Article 4, paragraph ②, item 3). The Service cannot be used before this confirmation, and a date of birth indicating that the User is under 14 is not stored and sign-up does not proceed.

③ The fact and time of confirmation, and the date of birth, are recorded. The date of birth is not used for any purpose other than age verification and viewing restrictions by content rating.

④ Although the age prescribed by law differs by country, 14 years satisfies all of the following standards.

  1. 1.The Personal Information Protection Act of the Republic of Korea sets the age at 14, the same as the Company's standard
  2. 2.COPPA in the United States and the UK GDPR set the age at 13, so the Company's standard is stricter
  3. 3.Article 8 of the GDPR (European Economic Area) sets the age between 13 and 16 as determined by each member state, and paragraph ⑤ applies

⑤ Article 8 of the GDPR sets the age that applies when consent is used as the legal basis for processing (it expressly refers to Article 6(1)(a) of the same regulation). Because the Company processes personal information for providing the Service on the basis of the performance of a contract (Article 18, paragraph ④), the age requirement in that provision does not apply as such. Accordingly, the Company does not distinguish between the different ages of member states on screen and applies the single standard of 14 years.

⑥ If the Company learns that a User is under 14, it destroys that account's personal information without delay. The child or their legal representative may notify the Company through the contact channel set out in Article 25 of the Terms of Service.

⑦ The confirmation in paragraph ② is a self-declaration that does not go through an identity verification agency. Because the law does not specify a verification method, this method is used for now; if stronger verification becomes necessary, the method will be changed and this Article changed accordingly.

Article 16 (Chief Privacy Officer)

① The Chief Privacy Officer is the Representative, Song Sanghoon, and no separate department is established for personal information protection.

② Requests for access to personal information are received and handled directly by the Chief Privacy Officer without a separate department. The contact channel follows Article 25 of the Terms of Service.

③ Because the Company is a domestic corporation, it is not obligated to designate a domestic representative. The obligation to designate a domestic representative applies to businesses that have no address or place of business in the Republic of Korea.

Article 17 (Remedies for Infringement of Rights)

① Users who need help regarding infringement of personal information may contact the following organizations.

  1. 1.Personal Information Dispute Mediation Committee: applications for dispute mediation and collective dispute mediation
  2. 2.Personal Information Infringement Report Center: reporting infringements
  3. 3.Supreme Prosecutors' Office: requests for investigation
  4. 4.Korean National Police Agency: requests for investigation

② Users who object to a disposition by the personal information controller may file an administrative appeal under the Administrative Appeals Act.

Chapter 6 Supplementary Provisions

Article 18 (Matters Applicable to Overseas Users)

① The Service is available in multiple countries. Depending on the User's country of residence, that country's personal information laws also apply, and this Article sets out what differs in that case.

② The storage location is the Republic of Korea (Seoul) regardless of the country of residence. From the moment the User's personal information reaches the Company, it is processed in accordance with Articles 8 and 9.

③ Because the Company provides the Service to residents of the European Economic Area (EEA) and the United Kingdom, the GDPR (and the UK GDPR) applies, and the Company is the controller within the meaning of those laws.

④ The legal bases for processing the personal information of EEA and UK residents are as follows.

  1. 1.Providing the Service, including account creation, sign-in, video playback, and profile display, is based on the performance of a contract
  2. 2.Maintaining security, handling misuse and reports, and aggregation for Service improvement are based on legitimate interests, and the balance against Users' rights has been assessed
  3. 3.Retention of transaction and tax records is based on legal obligations

⑤ EEA and UK residents may exercise the following rights. Requests to exercise rights are received through the contact channel set out in Article 25 of the Terms of Service, and the Company processes them and notifies you of the result within 1 month.

  1. 1.Access: you may receive a copy of the personal information about you that the Company processes
  2. 2.Rectification: you may request that inaccurate information be corrected
  3. 3.Erasure: you may request deletion (the "right to be forgotten")
  4. 4.Restriction of processing: you may request that processing be suspended
  5. 5.Portability: you may receive your information in a machine-readable format and transfer it elsewhere
  6. 6.Objection: you may object to processing based on legitimate interests
  7. 7.Withdrawal of consent: you may withdraw consent at any time for processing based on consent. Processing carried out before withdrawal remains valid

⑥ The following also apply to EEA and UK residents.

  1. 1.You may lodge a complaint with a supervisory authority. For the EEA, this is the supervisory authority of your member state of residence; for the UK, it is the Information Commissioner's Office (ICO)
  2. 2.The Company does not carry out processing that produces legal effects on Users based solely on automated decision-making
  3. 3.The European Commission adopted an adequacy decision for the Republic of Korea in December 2021. Accordingly, no additional safeguards such as standard contractual clauses are required to transfer personal information from the EEA to the Republic of Korea. The UK also recognizes the Republic of Korea as an adequate country

⑦ The following apply to residents of the United States.

  1. 1.The Company does not knowingly collect the personal information of children under 13 (COPPA), and destroys it without delay if it becomes aware of such collection
  2. 2.The Company does not sell personal information and does not share it for targeted advertising. It does not use third-party cookies for advertising purposes, and the usage statistics analytics cookies are described in Article 12
  3. 3.Whether certain state laws, such as those of California, apply depends on the scale of the business. When they become applicable, this Article will be changed and notice given before they take effect

⑧ Where the laws of the country of residence grant Users residing in other countries broader rights than this Policy, those rights prevail. The rights in Article 11 may be exercised through the contact channel set out in Article 25 of the Terms of Service regardless of the country of residence.

Article 19 (Changes to the Privacy Policy)

① When this Policy is changed, notice is given by posting the changed Policy within the Service. For changes that affect Users' rights, such as an increase in the items processed or the purposes of processing, Users are asked to consent to the changed Policy again before continuing to use the Service, and that consent screen also serves as the notice of the change.

② The changes can be reviewed in the revision history, with the text before and after the change shown side by side.

③ The revision history is as follows.

  1. 1.Effective September 1, 2026: initial enactment. There is no before-and-after comparison
  2. 2.Effective September 8, 2026: Article 4, paragraph ②, item 3 and Article 5, items 15 through 17 were newly added so that nickname, phone number, gender, and date of birth are collected at sign-up; the item in Article 4, paragraph ⑨ stating that date of birth is not collected was deleted; and Article 15, paragraphs ② and ③ were changed accordingly. Members who signed up before the change are asked for the same items after consenting to the changed Policy. The method of giving notice of changes in Article 19, paragraph ① was changed from a prior notice period to posting and renewed consent. On the same effective date, Article 12, paragraph ①, item 3 (the anonymous playback counting cookie) was added
  3. 3.Effective September 11, 2026: Article 4, paragraph ②, item 3 and Article 5, item 15 were changed so that name is collected from Members who sign up on or after the effective date. Name is not collected from Members who signed up before the change, and because the items and purposes of processing for those Members do not change, renewed consent is not obtained and notice is given by posting
  4. 4.Effective September 12, 2026: Article 4, paragraph ⑤, item 6; Article 5, item 18; Article 8, paragraph ①, item 9; Article 9, paragraph ⑨; and Article 12, paragraph ①, items 4 and 5 were newly added so that Service usage statistics are aggregated with a third-party analytics tool (Google Analytics); Article 12, paragraph ③ was changed from "third-party cookies for advertising or analytics purposes are not used" to "Google Analytics cookies are used for the purpose of analyzing usage statistics, and third-party cookies for advertising purposes are not used"; and Article 4, paragraph ③; Article 4, paragraph ⑨, item 3; Article 9, paragraph ⑧, item 4; Article 9, paragraph ⑩; and Article 18, paragraph ⑦, item 2 were changed accordingly. Because usage statistics are aggregated only by a random cookie identifier not linked to any account, the items and purposes of processing for individual Members do not change, so renewed consent is not obtained and notice is given by posting
  1. 1.Effective September 14, 2026: the scope of destruction in Article 10, paragraphs ③ through ⑤ was clarified to include legal name, phone number, gender, and date of birth, as well as posts, comments, reviews, and uploaded files you created; and revocation of the Apple link and guidance for existing accounts were added to Article 10, paragraph ⑦. The receipt cookie for checking withdrawal results was specified in Article 12, paragraph ①, item 6. Because this change reduces the scope of retention and provides a means of confirming withdrawal processing, existing consent continues to be recognized and notice is given by posting
  2. 2.Effective September 21, 2026: Article 4, paragraph ⑤, item 7 and Article 5, item 19 were newly added so that video playback quality is aggregated with a third-party analytics tool (Mux Data); playback quality analysis was added to the entrusted purpose and the transferred items for Mux in Article 8, paragraph ①, item 6 and Article 9, paragraph ⑤; and Article 4, paragraph ③ was changed accordingly. Article 12 does not change, because no cookie is used for playback quality records. Because playback quality records are kept only per single playback, without values identifying the User and without cookies, the items and purposes of processing for individual Members do not change, so renewed consent is not obtained and notice is given by posting
  3. 3.Effective September 30, 2026: Article 4, paragraph ⑩; Article 5, item 20; Article 6, paragraph ⑦; and Article 11, paragraph ⑥ were newly added so that marketing communications are sent by email and app push notification to Members who have given optional consent; and Article 4, paragraph ⑤, item 5 and Article 4, paragraph ⑨, item 4 were changed to reflect that app push tokens are recorded. Article 8, paragraph ①, items 10 and 11 and Article 9, paragraph ⑩ were newly added to reflect that app push notifications are sent through Google LLC (Firebase Cloud Messaging) to Android devices and through Apple Inc. (Apple Push Notification service) to iOS devices; the former Article 9, paragraph ⑩ was moved to paragraph ⑪ and item 5 was added to it; and Article 4, paragraph ③ and Article 9, paragraph ⑧, item 4 were changed accordingly. Because receiving marketing communications is optional and the relevant items are processed only for Members who consent, the items and purposes of processing for Members who do not consent do not change, so renewed consent is not obtained and notice is given by posting
  1. 1.Effective September 30, 2026: Article 4, paragraph ② was changed to reflect that the Service may be used without entering a phone number or gender, and item 3 of the same paragraph was changed to reflect that a name is not requested from Members who sign in with an Apple account. Because this revision adds no item or purpose of processing and merely states accurately the scope already in effect, renewed consent is not obtained and notice is given by posting
  1. 1.Effective September 30, 2026: Article 4, paragraph ② was changed so that Members who sign in with an Apple account are not asked for the items in item 3 of that paragraph. In that case the display name is the name passed by that provider or the handle generated automatically at sign-up, and whether the Member is at least 14 years old is established by the confirmation recorded on the consent screen. Because this revision reduces the items processed, renewed consent is not obtained and notice is given by posting
  1. 1.Effective October 1, 2026: the exception in Article 4, paragraph ②, previously limited to Apple accounts, was extended to all social accounts. Members who sign in with a social account are not asked for the items in item 3 of that paragraph; the display name and the confirmation of being at least 14 years old are as set out in item 8. Because this revision reduces the items processed, renewed consent is not obtained and notice is given by posting
  2. 2.Effective October 1, 2026: the name of the Service was changed from Contentrip to Short AI (Article 1, paragraph ①). The personal information controller, the items and purposes of processing, and the retention periods do not change, so renewed consent is not obtained and notice is given by posting

Addendum

① This Policy takes effect on October 1, 2026.

利用規約プライバシーポリシーお問い合わせとサポート
会社名
Impact Station Inc. (임팩트스테이션 주식회사)
代表者
Song Sanghoon
事業者登録番号
683-86-00599
住所
901, Sanjeong Bldg., 23 Gukhoe-daero 66-gil, Yeongdeungpo-gu, Seoul 07237, Republic of Korea