This is an unofficial reference translation provided for convenience. The legally binding version is the Korean original. If the two versions differ in any way, the Korean version prevails.
UUP Privacy Policy
Unofficial reference translation. This document is a reference translation provided for convenience. The legally binding version is the Korean original at https://uup.kr/privacy. If the two versions differ in any way, the Korean version prevails.- Version: v1.13 (YouTube optional first-comment disclosure 2026-09-07 · security measures & Google user data disclosures effective 2026-08-27 · Recipe AI reference image (v1.11) effective 2026-08-20 · regional analytics/advertising cookies (v1.9) effective 2026-08-24 · TikTok automation (v1.8) effective 2026-08-27 — see the supplementary provisions below)
- Effective date: 2026-07-20 (initial)
- Business operator: Onetop (원탑) (Business Registration No. 461-09-00872) · Representative: Choi Hanul · Address: 201-1, 2F, 9-19 Bonghwa-ro, Gimpo-si, Gyeonggi-do, Republic of Korea · Contact: help@uup.kr
- Registered URL (permanent):
https://uup.kr/privacy
Onetop (원탑) (the "Company") complies with the Personal Information Protection Act and other applicable laws, and through this Privacy Policy explains for what purposes and in what manner users' personal information is collected, used and stored, and what rights users may exercise.
1. Items of personal information collected, legal basis, purpose and retention period
| Item collected | Legal basis | Purpose of processing | Retention period |
|---|---|---|---|
| Phone number (including records of SMS verification code sending and verification) | Performance of a contract (sign-up and identity verification) | Sign-up, identity verification, management of service use per account | Destroyed on member withdrawal (however, the trial_history in Section 2 below is retained separately on a separate basis) |
| Email address (the value provided in the Kakao/Google OAuth profile) | Performance of a contract | Delivery of Paddle payment receipts and invoices, and important service notices (outages, policy changes, etc.) | Destroyed on member withdrawal |
OAuth identifier (Kakao member number, Google sub) | Performance of a contract | Account identification and login processing | Destroyed on member withdrawal |
| Payment-related information (plan, subscription status, Paddle transaction identifiers and other read-model data the Company retains) — the Company does not directly collect the underlying payment instrument data such as card numbers; Paddle processes it | Performance of a contract, legal obligation | Management of subscription and payment status, retention of records required under tax invoicing rules and the Act on Consumer Protection in Electronic Commerce | 5 years for contract and payment records (Act on Consumer Protection in Electronic Commerce) |
| Service usage event logs (page visits, clicks, automation sending logs, etc.) | Performance of a contract, legitimate interests (service improvement and prevention of abuse) | Providing analytics, service quality management, abuse detection | Raw records retained for 13 months and then rolled up into aggregate tables (minimising personal identification); raw webhook logs 30 days |
| External analytics and advertising conversion data (pages visited, completion of sign-up, trial and payment, transaction identifier, payment amount and currency, browser and device data, IP address and advertising identifiers) | Optional consent for visitors in the European Economic Area (EEA), the United Kingdom and Switzerland; legitimate interests (measuring advertising performance) for visitors in other regions, including the Republic of Korea | Measuring visits, sign-up, trial and purchase conversions; advertising performance analysis | According to the applicable Google and Meta retention settings; no new collection after consent is withdrawn |
| Whether the user has consented to receive marketing information, and the history of that consent | Separate consent | Determining whether to send marketing notifications | Destroyed on withdrawal of consent or member withdrawal (however, the consent and withdrawal history may be retained separately for the period prescribed by applicable law in order to respond to disputes) |
| Report submission information (reporter's contact details, reason for the report, target URL) | Legitimate interests | Handling of platform content reports (F-4.2.20) | For the period determined by applicable law and internal policy after handling is complete |
| Chat content and access information (IP address, browser and device information, the screen address on which the chat was started and the referral path, and an email address where the user has entered one) — only for support chat used without logging in | Legitimate interests (responding to inquiries and preventing abuse) | Responding to inquiries, identifying the same inquirer, managing support quality and blocking abuse | Destroyed 90 days after the last message (where the user has taken over that conversation into their own account, destroyed on member withdrawal) |
| Legal name, contact details, address and other identity information required for settlement — only for users who have applied for and been approved into the Partner Program (each a "Partner") | Performance of a contract (revenue-sharing agreement) | Payment and settlement of partner earnings | Destroyed after termination of the partner agreement and completion of settlement (items subject to statutory retention under Section 4 follow that period) |
| Resident registration number — only for Partners who are individuals (recipients of business income) | Legal obligation — performance of the withholding tax and payment statement filing obligations under the Income Tax Act. Processed only where there is a specific statutory basis pursuant to Article 24-2 of the Personal Information Protection Act, and not collected on the basis of the user's consent alone | Withholding tax on business income and tax filing (preparation and submission of withholding tax receipts and payment statements) | Destroyed without delay once the retention period for withholding-related records under Section 4 (5 years) has elapsed |
| Bank account information (bank name, account number, account holder) — Partners only | Performance of a contract | Transfer of partner earnings | Destroyed after termination of the partner agreement and completion of settlement (items subject to statutory retention under Section 4 follow that period) |
| Copies of identity verification documents (individuals: copy of ID and bankbook / businesses: business registration certificate and copy of bankbook) — Partners only. Copies of ID documents are submitted with the latter digits of the resident registration number masked, and the Company does not retain unmasked copies | Performance of a contract and legal obligation | Verifying that the holder of the transfer account and the person subject to withholding are the same | Destroyed without delay once verification is complete (the copies themselves are not retained; the fact of verification and the withholding evidence remain as items retained under Section 4) |
| Business registration number, trade name, representative's name — only for Partners who are businesses (issuers of tax invoices) | Performance of a contract and legal obligation | Payment of partner earnings, receipt of tax invoices and tax filing | Destroyed after termination of the partner agreement and completion of settlement (items subject to statutory retention under Section 4 follow that period) |
| The body of scheduled posts (caption, or title, description and tags), first-comment text, images and videos (video files and technical metadata such as length, resolution and format), the scheduled time, and the publishing result (post and comment identifiers, link, publishing time and, where it failed, the reason) — only where the social scheduled publishing feature is used | Performance of a contract | Publishing posts to the user's own social accounts at the time the user specifies, and showing the user the publishing result and the cause of any failure | Destroyed on member withdrawal (the user may delete them directly on the Service screens at any time, before or after publishing) |
TikTok Business Account open_id, profile and connection token; comment identifiers and text; message event identifiers and message text required for an automated response; member-configured keywords and reply content; and delivery results — only where the member directly connects and uses TikTok Business comment and messaging automation | Performance of a contract; the user's express connection consent | Reading and matching comments on the member's own videos to post replies, and automatically responding in a messaging conversation initiated by the other TikTok user | Token and profile destroyed on disconnect; raw webhook events after 30 days; delivery logs after 13 months; all other information on deletion of the automation or member withdrawal |
| Google Gemini API key (issued and registered directly by the user) — only where the user uses the Recipe AI assistant | Performance of a contract; the user's express registration | Authenticating Google API calls when the user requests recipe-text polishing or cover-image generation (charges are billed to the user's own Google account) | Stored encrypted (sealed); destroyed without delay when the user deletes it, and upon account deletion |
| Information relating to the partner attribution cookie (referral link identifier, click time) — only where the visit came through a partner's advertising link | Legitimate interests (recognising partner referrals and preventing fraudulent referrals) and performance of a contract | Recognising partner referrals and calculating commissions | The cookie is deleted 120 days after it is stored, or immediately upon completion of sign-up. Referral attribution records are destroyed after settlement with the relevant Partner is complete and the period during which the Partner may dispute the figures (90 days) has ended. Records disputed within that period are retained until the handling of that dispute is complete and then destroyed (items subject to statutory retention under Section 4 follow that period) |
- In the retention periods for partner-related items in the table above, "completion of settlement" means the time at which the unpaid balance is paid in full, or the time at which the user waives that balance in accordance with the procedure set out in the Partner Terms (Section 8).
2. Retention of trial_history after withdrawal
In order to prevent abuse of the "one free trial per phone number" policy (such as re-registering in order to repeat a trial), the Company does not store phone numbers directly but manages a trial history (trial_history) converted into a one-way hash (HMAC-based phone_lookup_hmac).
- Legal basis: legitimate interests (preventing abuse of the Service) and a measure incidental to performance of the contract.
- Scope retained: only the hash value, from which the phone number cannot be restored, together with the time the trial was granted and its status; it is not retained in combination with other personal information such as name or email address.
- Retention period: retained separately for one year after member withdrawal and then destroyed.
- Users may make inquiries about the retention of this item through this Privacy Policy and
/support.
2-2. Separate processing of partner settlement information
The Company collects the partner-related items in Section 1 (legal name, contact details and address, resident registration number, business registration number, trade name and representative's name, bank account information, and copies of identity verification documents) only from users who have applied for and been approved into the Partner Program. Because these items are more sensitive than the information the Company collects from ordinary members, they are processed separately as follows.
- Time and scope of collection: collection is divided into two points. The tax type (individual or business) is selected when applying to participate as a Partner, and the legal name, resident registration number, business registration number, bank account information and copies of identity verification documents are collected at the time of the first payout request. In either case collection is limited to the minimum necessary for paying earnings and withholding tax, and nothing is collected from users who have not applied to become a Partner.
- Resident registration number: processed only for the purpose of performing the statutory withholding obligation and not used for any other purpose, and not collected on the basis of the user's consent alone (see the legal basis in Section 1). It is encrypted when stored and is masked by default when displayed on screen.
- Copies of identity verification documents: not stored in a publicly accessible repository but in a private repository; access is limited to settlement staff and an access record (audit log) is left each time they are viewed. Once the verification purpose is achieved the copies are destroyed without delay (Section 1).
- Bank account information: stored encrypted and not used for any purpose other than transferring earnings.
- A Partner may withdraw from participation in the Partner Program, in which case the Company destroys the above information without delay except for items requiring statutory retention (Section 4). However, if an unpaid balance remains at the time of withdrawal, the minimum items necessary for paying it are retained separately until payment is complete or the user waives that balance, and are then destroyed (the items and the basis follow Section 8). Withdrawal from the Partner Program is separate from member withdrawal and does not affect membership status.
3. Entrustment and overseas transfer of personal information
In order to provide the Service, the Company entrusts work or transfers personal information overseas as set out below. The Company does not label all of the recipients below collectively as "entrusted parties"; it distinguishes and discloses their status as personal information controller, entrusted processor or independent controller according to the form of the agreement.
| Recipient | Country | Status | Items transferred/processed | Purpose | Basis |
|---|---|---|---|---|---|
| Aligo (SMS provider) | Republic of Korea | Domestic entrusted processor | Phone number, content of the verification message | Sending SMS verification codes at sign-up | Entrustment agreement |
Railway (Singapore, asia-southeast1) | Singapore | Entrusted processor for server and database hosting | All items necessary for operating the Service (application server, PostgreSQL, Redis) | Operating the Service infrastructure | Entrustment agreement; consent to overseas transfer or a statutory exception |
Google Cloud Storage (Seoul, asia-northeast3) | Republic of Korea | Domestic backup-storage processor | Encrypted database and cryptographic-key backups, plus pre-R2 file originals retained through 2026-09-10 for rollback | Disaster recovery and migration rollback | Entrustment agreement |
| Cloudflare, Inc. (R2, APAC placement) | United States, Asia-Pacific and other locations | Overseas storage and CDN processor | Uploaded images, videos and attachments, and copies of partner identity-verification documents | File storage, CDN delivery and private document storage | Entrustment agreement, overseas-transfer consent or a statutory exception |
| Paddle.com Market Limited and its affiliates | United Kingdom and others | Independent Controller — Paddle and UUP are in a data-sharing relationship between separate controllers under the Master Services Agreement / Data Sharing Addendum, not a joint entrustment relationship | Name, address, email address, purchase history and other items necessary for payment | Payment processing, tax calculation, issuance of invoices and receipts, subscription management | Performance of a contract |
| Meta (Instagram, Threads, Facebook) | United States and others | Independent controller | Instagram and Threads account and Facebook Page connection tokens, comment/DM events, and the body (caption), first comment, images and videos of posts the user has requested to publish | Providing the Auto DM feature, and publishing posts the user has scheduled to the user's own account (Page) | Performance of a contract; the user's express connection consent |
| Google (OAuth, YouTube, Gemini API) | United States and others | Independent controller | Profile information for login (email address, etc.), YouTube channel connection tokens and channel identification information (channel name, etc.), and the video files, titles, descriptions and tags the user has requested to publish, optional first-comment text entered by the user, the target video identifier and comment publishing results (including the comment identifier), and — where the user uses the Recipe AI assistant — the content of requests authenticated with the user's own Gemini API key (recipe name, introduction, ingredients, cooking sentences and the tone/photo hints the user wrote) and any photo the user designates as a reference for image generation (a photo the user uploaded, or the finished-dish photo of the original recipe post the user specified by URL for import) | Social login, and uploading videos the user has scheduled to the user's own YouTube channel and posting the optional first comment written by the user on that video, and recipe-text polishing and cover-image generation at the user’s request (reflecting the mood and composition of the reference photo the user designated) | Performance of a contract; the user's express connection consent |
| Meta Platforms, Inc. (Meta Pixel) | United States and others | Independent controller | Pages visited, sign-up, trial and purchase conversions, transaction identifier, amount and currency, IP address, browser and device data, and advertising identifiers | Advertising performance and conversion measurement | The user's optional consent in the EEA, the United Kingdom and Switzerland; legitimate interests in other regions |
| Google LLC (Google Analytics 4) | United States and others | Independent controller | Pages visited, sign-up, trial and purchase conversions, transaction identifier, amount and currency, IP address, browser and device data, and analytics identifiers | Service usage and conversion analytics | The user's optional consent in the EEA, the United Kingdom and Switzerland; legitimate interests in other regions |
| Cloudflare, Inc. (Zaraz) | United States and others | Entrusted analytics-tag processor | Consent state and the external analytics and advertising conversion data above | Consent management and delivery of Meta Pixel and Google Analytics tags | Entrustment agreement; the user's optional consent in the EEA, the United Kingdom and Switzerland; legitimate interests in other regions |
| TikTok Pte. Ltd. | Singapore and others | Independent controller | TikTok account and TikTok Business Account connection tokens and account identifiers (open_id, nickname, etc.); videos, images and text requested for publishing; comment and message events; member-configured keywords and replies; and delivery results | Posting content the user has scheduled to the user's own TikTok account or sending it to the TikTok app's drafts; replying to comments on the member's own videos; and automatically responding in a messaging conversation initiated by the other TikTok user | Performance of a contract; the user's express connection consent |
| Kakao (OAuth) | Republic of Korea | Independent controller | Profile information for login (member number, email address, etc.) | Social login | Performance of a contract |
- Social account connection tokens (Instagram, Threads, Facebook, YouTube, TikTok) are stored encrypted and are destroyed without delay when the user disconnects the account. Google user data obtained through the YouTube connection is not used for any purpose other than those stated in the table above (uploading to the user's own channel, posting the optional first comment written by the user, and displaying information about the connected channel), and is not sold to third parties or used for advertising purposes. Specific security measures for tokens and other sensitive data are described in Section 8-2.
- Users may refuse overseas transfer, but in that case use of all or part of the Service (payment, infrastructure operation, etc.) may be restricted. Inquiries about overseas transfer are received through
/support. - The Company does not entrust or transfer personal information to any recipient other than those listed in the table above. If a new entrustment or overseas transfer becomes necessary, the Company gives notice of it in advance and reflects it in this table before beginning.
4. Statutory retention periods
Under applicable law, the following items are retained separately for the periods below regardless of a user's deletion request or member withdrawal.
| Item retained | Retention period | Governing law |
|---|---|---|
| Records relating to the transmission of marketing information | 6 months | Network Act |
| Records relating to contracts or withdrawal of subscription | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records relating to payment and the supply of goods and services | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records relating to consumer complaints or dispute handling | 3 years | Act on Consumer Protection in Electronic Commerce |
| Withholding-related records (withholding tax receipts, payment statements, etc.) — only for payment of partner earnings | 5 years | Framework Act on National Taxes (Article 85-3, retention of books and records) |
5. Data subjects' rights and how to exercise them
Users may exercise the following rights in relation to their personal information.
- The right to request access to, correction of, deletion of, and suspension of processing of personal information
- The right to request data portability (data export)
- Posts already published through social scheduled publishing are posted to the user's own social accounts, so a deletion request made to the Company applies only to the records the Company retains. Posts published on the relevant social service must be deleted by the user on that service directly.
How to exercise: requests are received through the account settings screen and the /support page, subject to identity verification (login and recent re-authentication). The Company notifies the outcome within the period prescribed by applicable law and keeps a record of the handling history as evidence.
6. Cookies and similar technologies
- The Company uses a session cookie (
__Host-uup_session) to maintain the login session; this is a cookie essential to use of the Service and is used without separate consent. - In support chat used without logging in, the Company uses an identifying cookie for finding that conversation again (
__Host-uup_chat, valid for 90 days). This cookie exists to continue the support conversation and is not used for advertising, behavioural data collection or tracking of service use; it is stored only when the user starts a chat. - Where a visit comes through a Partner's advertising link (
https://uup.kr/p/{code}), an identifying cookie for recognising the partner referral (__Host-uup_ref) is stored. - Validity: 120 days; it is deleted immediately at the point sign-up is completed and the referral is recognised. The period during which a partner referral is actually recognised is 90 days, and the remaining 30 days is a margin allowing for boundary error in determining the point of recognition. That determination is made by the Company's servers by comparing the access time recorded in the cookie, independently of the cookie's validity period, so once the recognition period has passed, a referral is not recognised even if the cookie remains.
- Purpose: limited to performance of the revenue-sharing agreement with the Partner (recognising referrals and calculating commissions). This cookie is not used for advertising or behavioural data collection, is not provided to third parties or shared with advertising businesses, and is not used in producing the service usage statistics described below.
- Storage condition: it is stored only where the visit came through a Partner's advertising link, and is not stored for users who visit by any other route.
- Not used for click aggregation: among the referral figures provided to Partners, click counts (including de-duplication at the visitor level) are likewise produced without using this cookie, using the cookieless anonymous aggregation method described below. This cookie is read only to identify the referring Partner at the point sign-up is completed.
- The service usage statistics for visits and clicks shown to users (including partner referral figures) continue to use cookieless anonymous aggregation without cookies that track individuals. Separately, Cloudflare Zaraz may let Google Analytics 4 and Meta Pixel process visit and sign-up, trial and purchase conversion data. For visitors in the European Economic Area (EEA), the United Kingdom and Switzerland, analytics and advertising cookies are off by default and operate only after the user selects the relevant category in the consent banner (no response is treated as a refusal). For visitors in other regions, including the Republic of Korea, the same cookies may be used without a separate banner consent, on the basis of legitimate interests in measuring advertising performance. The visitor's region is determined from the connecting IP address.
- Any visitor may refuse or withdraw consent at any time from “Analytics and ad cookies” in the site footer; withdrawal does not retrospectively cancel processing that occurred before withdrawal. Refusal or withdrawal does not affect sign-up, payment or other service terms. To apply the regional rule and keep a later withdrawal, the Company uses a visitor-country cookie (
uup_geo, 30 days) and a consent-policy revision cookie (uup_consent_rev); these cookies are not used as advertising identifiers. - Users may refuse the storage of cookies through their browser settings, but in that case there may be constraints on some uses of the Service, such as logging in. Refusing the partner referral identifying cookie may mean that a partner referral is not recognised, but it has no effect on the service the user receives or on their payment terms.
7. Personal information of children under 14
The Company does not permit members under the age of 14 to sign up. By agreeing to the Terms at sign-up, users affirm that they are aged 14 or older; if a user is found — whether at sign-up or afterwards — to be under the age of 14, the Company halts the sign-up or restricts use and destroys without delay any personal information already collected.
8. Destruction of personal information
On member withdrawal, the Company destroys without delay all personal information other than the statutory retention items in Section 4 above and the trial_history in Section 2. Partner settlement information (Section 2-2) is destroyed, except for items requiring statutory retention, after the partner agreement has terminated and settlement of all unpaid balances is complete. In this paragraph, "settlement is complete" means the time at which that balance has been paid in full, or the time at which the user has waived that balance in accordance with the procedure set out in the Partner Terms; in both cases the basis for the separate retention below ends at that point.
Even where a user withdraws from membership, for as long as an unpaid balance remains, the minimum items necessary for paying it are retained separately until payment is complete or the balance is waived, and are then destroyed; other partner settlement information is destroyed without delay on withdrawal. The items retained separately are limited to the following.
- Legal name and bank account information (including the account holder) — necessary for the transfer.
- Information necessary for withholding — necessary in order to perform the statutory withholding obligation at the time of payment.
The Company does not separately retain contact details (email address or mobile phone number) for this purpose. This means that no retention beyond the scope necessary for payment takes place; other items are destroyed together at the time of withdrawal.
The point of destruction of partner referral attribution records follows the table in Section 1 rather than this Section (they are retained until the period for disputing figures ends). Destruction follows the procedures set out in the Company's personal information handling policy and applicable law; the point of physical deletion from databases, backups and storage may not exactly coincide with the time of the request due to the nature of the systems involved (for example, the asynchronous lifecycle of cloud storage).
8-2. Technical and organizational security measures
The Company implements the following measures to protect users' personal information and social-connection data (including Google user data).
- Encryption in transit — All service traffic is encrypted with HTTPS (TLS), and HSTS (max-age one year, including subdomains) is applied to block unencrypted connections.
- Encryption of sensitive data at rest
- Social account connection tokens (OAuth access and refresh tokens for Instagram, Threads, Facebook, YouTube and TikTok) are encrypted (sealed) at the application level with AES-256-GCM before being stored in the database. The system is designed so that storing a token fails outright if the encryption facility is not configured — no code path stores a token in plaintext.
- Phone numbers are stored encrypted with AES-256-GCM; lookups and duplicate checks use an irreversible HMAC-SHA256 one-way hash (Section 2).
- Resident registration numbers and bank account information are stored encrypted and masked on screen (Section 2-2).
- External API keys the user registers directly (Gemini API key) are stored encrypted (Section 1).
- Encryption key management — Encryption keys are managed separately from application data, and key backups are protected with asymmetric encryption (sealed with a public key only; the private key is kept offline separately), so that a compromise of the server environment does not also expose the backup keys.
- Backup protection — Database backups are kept in separate storage with at-rest encryption (Google Cloud Storage, Section 3), and their integrity is verified after upload.
- Access control — Access to personal information is limited to the minimum number of personnel. Administrative functions are granted only to designated operator accounts, separated by role, and administrative actions are recorded in an audit log including the actor, IP address and time. Access control for partners' identity-document copies follows Section 2-2.
- Session protection — Login session cookies are protected with the HttpOnly and Secure attributes and expire after 14 days of inactivity (30 days maximum). Irreversible actions such as account deletion additionally require recent re-authentication.
- Intrusion prevention and anomaly detection — All external traffic passes through a security proxy with a web application firewall (WAF). Rate limits are applied to key functions to block brute-force and bulk requests, and features where the server fetches content from external URLs are validated to block access to internal networks (SSRF prevention). Errors and anomalies in external integrations are collected in real time and reported to the operations alert channel.
- Data minimization — When connecting external services, the Company requests only the minimum scopes needed to provide the feature. The YouTube connection requests scopes needed to identify the connected channel and upload videos at the user's request; when connecting or reconnecting an account with first-comment support, it also requests permission to post comments. Independently of granting that permission, writing a first comment is optional and a comment is posted only when the user enters its text.
- Destruction of connection data — When the user disconnects a social connection, the Company destroys the stored access and refresh tokens without delay (Section 3). Independently of this, the user can revoke the Company's access at any time from their Google account security settings (
https://myaccount.google.com/permissions). - Breach response — Upon becoming aware of a personal-data breach, the Company notifies affected users and reports to the competent authorities without delay, as required by applicable law.
Notice regarding Google user data (YouTube API Services · Limited Use)
- The Company's YouTube features use YouTube API Services. By connecting a YouTube channel, the user also agrees to be bound by the YouTube Terms of Service (
https://www.youtube.com/t/terms); Google's handling of personal information is governed by the Google Privacy Policy (https://policies.google.com/privacy). - UUP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (`https://developers.google.com/terms/api-services-user-data-policy`), including the Limited Use requirements. The Company does not use Google user data for purposes other than those stated in the table in Section 3, does not sell it to third parties, and does not use it for advertising purposes.
9. Personal information protection officer and contact
- Personal information protection officer: Choi Hanul (Representative)
- Contact: help@uup.kr /
https://uup.kr/support/ the account settings screen
10. Changes to this notice
This Privacy Policy may be amended in line with changes in law, policy or the Service. When it is amended, the Company gives prior notice of the effective date and the changes and retains the versions before and after the amendment.
Supplementary provisions
The amended version of this Privacy Policy (Section 7 — reflecting the method of affirming that the user is aged 14 or older, consistent with Terms v1.1) takes effect on 2026-07-21.
The amended version of this Privacy Policy (v1.2 — adding to Section 1 the chat content and access information collected in support chat used without logging in, and stating in Section 6 the identifying cookie used to continue that conversation) takes effect on 2026-07-28. It adds items collected in connection with the launch of a new feature (support chat used without logging in); it is not a change disadvantageous to existing users, and the above information is collected only where the user starts a chat themselves.
The amended version of this Privacy Policy (v1.4 — adding to Section 1 the body (caption), first-comment text, images, scheduled time and publishing result of scheduled posts in connection with the launch of the social scheduled publishing feature; adding Threads to the recipient in the Meta row of Section 3, adding the body, first comment and images of posts requested for publishing to the items transferred, and stating the publishing of posts the user has scheduled as a purpose; and stating in Section 5 the scope of deletion requests in relation to posts already published) takes effect on 2026-08-05. It adds items collected in connection with the launch of a new feature (social scheduled publishing); it is not a change disadvantageous to existing users, and the above information is collected only from members who use the scheduled publishing feature themselves. For members who do not use this feature there is no change to the items collected, the purposes of use or the retention periods. Posts are always published only to the user's own account, connected and authorised by the user themselves, and the Company publishes the content the user has written without altering it.
The amended version of this Privacy Policy (v1.5 — adding videos (video files and technical metadata such as length, resolution and format) and titles, descriptions and tags to the scheduled publishing item in Section 1 in connection with the expansion of the channels covered by social scheduled publishing; adding Facebook (Pages) to the recipient in the Meta row of Section 3, stating YouTube channel connection tokens and channel identification information and the uploading of videos requested for publishing in the Google row, and adding a new TikTok row; and stating in Section 3 that social account connection tokens are stored encrypted and destroyed on disconnection) takes effect on 2026-08-06. It adds items collected in connection with the launch of new channels (Facebook Pages, YouTube, TikTok); it is not a change disadvantageous to existing users, and the above information is collected only from members who connect the relevant channel themselves and use scheduled publishing. For members who do not use this feature there is no change to the items collected, the purposes of use or the retention periods. Posts are always published only to the user's own account (Page or channel), connected and authorised by the user themselves, and the Company publishes the content the user has written without altering it.
The amended version of this Privacy Policy (v1.3 — adding to Section 1 Partners' identity information for settlement, resident registration number, business registration number (including trade name and representative's name), bank account information and copies of identity verification documents, together with information relating to the partner referral identifying cookie, in connection with the launch of the Partner Program; adding the separate processing standards for those items as a new Section 2-2; stating the statutory retention of withholding-related records in Section 4; stating the partner referral identifying cookie in Section 6; and stating in Section 8 the separate retention and point of destruction where an unpaid balance remains) takes effect on 2026-07-29. It adds items collected in connection with the launch of a new feature (the Partner Program); it is not a change disadvantageous to existing users, and the above information is collected only from users who apply for and are approved into the Partner Program themselves. For users who do not apply as Partners there is no change to the items collected, the purposes of use or the retention periods. However, because the partner referral identifying cookie is stored for users who visit through a Partner's advertising link, its name, purpose, validity period and recognition period are also stated in Section 6.
The amended version of this Privacy Policy (v1.6 — adding external analytics and advertising conversion data to Section 1, the processing by Meta Pixel, Google Analytics 4 and Cloudflare Zaraz to Section 3, and the optional-consent and withdrawal method to Section 6) takes effect on 2026-08-17. Before that date the tags are blocked by consent management; from the effective date they operate only where the user has opted in to the analytics or advertising category. Refusal or withdrawal does not affect the terms of using the Service.
The amended version of this Privacy Policy (v1.7 — changing the primary file-storage processor in Section 3 to Cloudflare R2 and clarifying that Google Cloud Storage retains only encrypted backups and pre-migration originals through 2026-09-10 for rollback) takes effect on 2026-08-19. The R2 buckets are placed in Asia-Pacific (APAC), but processing locations may vary under Cloudflare's default jurisdiction policy, so the processing is disclosed as an overseas transfer.
The amended version of this Privacy Policy (v1.8 — adding to Sections 1 and 3 the account information, comment and message events, configured keywords and replies, purposes, and retention periods required for TikTok Business Account comment and messaging automation) takes effect on 2026-08-27. The feature is provided only after both TikTok's application and security review approval and this Policy's effective date, and the information above is collected only from members who directly connect a TikTok Business Account and use the feature. The Company replies only to comments on the member's own videos and automatically responds only in a conversation where the other TikTok user sent the first message; it does not initiate unsolicited advertising messages.
The amended version of this Privacy Policy (v1.9 — splitting the legal basis for analytics and advertising cookies in Sections 1, 3 and 6 by region) takes effect on 2026-08-24. Visitors in the European Economic Area (EEA), the United Kingdom and Switzerland still need optional consent before analytics and advertising cookies operate. Visitors in other regions, including the Republic of Korea, may have the same cookies used without a separate banner consent, and a refusal given on the v1.6 banner is no longer kept after this amendment. Any visitor may refuse or withdraw again from the site footer. Because this is a change unfavourable to users, it takes effect after a seven-day advance notice period from the date of publication.
The amended version of this Privacy Policy (v1.10 — adding to Section 1 the collection, encrypted storage and destruction of the Google Gemini API key the user registers directly for the Recipe AI assistant, and specifying in the Google row of Section 3 the recipe content transmitted when the user requests text polishing or cover-image generation (recipe name, introduction, ingredients, cooking sentences and the tone/photo hints the user wrote) and its purpose) takes effect on 2026-08-20, its date of publication (immediate effect for a non-detrimental addition for a new feature — the same standard as v1.2 and v1.4). It applies only to members who turn the feature on in their page settings and register an API key; for members who do not use it, there is no change to the items collected, purposes or retention periods. Generation charges are billed to the user's own Google account and the Company does not pay them on the user's behalf. Recipe import only means the Company's server fetching a public post URL the user specifies; no personal data of the user is transmitted to that site in the process.
The amended version of this Privacy Policy (v1.11 — adding to the Google row of Section 3 the fact that a photo the user designates as a reference for Recipe AI image generation is transmitted together with the text, and its purpose) takes effect on 2026-08-20, its date of publication (immediate effect for a non-detrimental addition for a new feature — the same standard as v1.2, v1.4 and v1.10). Previously the Policy disclosed that only the text of a recipe was transmitted; where the user designates a reference photo for image generation, that image file is transmitted as well. Only two kinds of photo are transmitted — (i) a photo the user uploaded to the service, or (ii) the finished-dish photo of the original recipe post the user specified by URL for import — and the Company does not transmit any photo the user has not designated. The reference photo is passed only at the moment of the generation request and the Company does not separately store that image file (a photo the user uploaded remains stored as the user's own asset and is destroyed when the user deletes it). Designating a reference photo is optional; if none is designated, only text is transmitted as before. For members who do not use this feature, there is no change to the items collected, purposes or retention periods.
⚠ Note to users: if you designate a photo taken by someone else (such as the photo in an imported original post) as a reference, that photo is transmitted to Google and the generated result may reflect its composition and mood. You are responsible for having the right to use that photo and for your use of the generated output; the Company merely passes on the target you designate and does not verify rights in it.
The amended version of this Privacy Policy (v1.12 — adding a new Section 8-2 on technical and organizational security measures (encryption in transit and at rest, application-level AES-256-GCM encryption of social connection tokens, separate encryption-key management, access control and audit logging, intrusion prevention, data minimization, token destruction on disconnection, and breach response), together with disclosures that the service uses YouTube API Services and adheres to the Google API Services User Data Policy including the Limited Use requirements, links to the YouTube Terms of Service and the Google Privacy Policy, and guidance that users can revoke the Company's access directly in their Google security settings) takes effect on 2026-08-27, its date of publication. This amendment documents protective measures already in operation and adds guidance on users' means of exercising their rights; it changes no items collected, purposes of use or retention periods and is not disadvantageous to users (immediate effect for a non-detrimental change — the same standard as v1.2 and v1.4).
This amendment (v1.13 — specifying the data sent to Google, purposes and additional permission for the optional YouTube first comment) takes effect on 2026-09-07. It applies only to users who choose this feature; general availability begins after the required Google verification. Retention and deletion of first-comment text and publishing results follow the scheduled-publishing row in Section 1 and Section 5. This feature does not include retrieving viewer comments or replying to them.