Cosmify

Privacy Policy

YOLDCOMPANY · Cosmify (우꾸)

Effective Date: January 1, 2026

This Privacy Policy is provided in both Korean and English. In the event of any discrepancy in interpretation, the Korean text shall prevail.

YOLDCOMPANY ("Company") values your privacy and is committed to protecting your personal data. This policy complies with applicable data protection laws, including the Korean Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR) where applicable, and the California Consumer Privacy Act (CCPA) where applicable.

Article 1 (Data Collected and Methods)
The Company collects the following information to provide the Service:

[Social Login]
- Email address, nickname, and profile image — collected via Google or Kakao OAuth within the scope permitted by each provider.

[Service Use]
- User-created Universes (canvas_data), gallery visibility settings, and like history.

[Payments]
- Order numbers and payment method type. Detailed card information is processed directly by Toss Payments (South Korea) or Stripe (global) and is not stored by the Company.
- Purchase history: Pass purchases (Basic/Master) and AI Credit purchases.

[Automatically Collected]
- IP address, browser type and version, access timestamps, and service usage logs.

Article 2 (Purpose of Collection and Use)
① Providing and operating the Service (editor, gallery, AI image generation)
② User identification and authentication
③ Payment and purchase history management, and customer support
④ Service improvement, error analysis, and usage statistics
⑤ Delivery of notices and enforcement of Terms of Service

Article 3 (Retention Period)
Personal data is deleted immediately after its collection purpose has been fulfilled. The following categories are retained for the periods specified below in accordance with applicable law:

| Category | Retention Period | Legal Basis |
|----------|----------------|-------------|
| Contract and withdrawal records | 5 years | Korean E-Commerce Act |
| Payment and delivery records | 5 years | Korean E-Commerce Act |
| Consumer complaint and dispute records | 3 years | Korean E-Commerce Act |
| Access logs | 3 months | Korean Communications Secret Protection Act |

Article 4 (Third-Party Disclosure)
① The Company does not disclose personal data to third parties as a general principle.
② Exceptions apply in the following circumstances:
  - The User has provided prior consent.
  - Disclosure is required by a lawful request from a law enforcement authority.
  - Minimum necessary shipping information is shared with the goods shop for order fulfillment (domestic Korea only, after obtaining User consent).

Article 5 (Data Processing Subcontractors)
The Company engages the following subcontractors to operate the Service. Each subcontractor processes only the minimum information necessary for its designated purpose.

| Subcontractor | Delegated Purpose |
|--------------|------------------|
| Supabase Inc. | Database storage and user authentication |
| Vercel Inc. | Server infrastructure and service hosting |
| Toss Payments Co., Ltd. | Domestic (Korea) payment processing and settlement |
| Stripe, Inc. | Global payment processing |
| OpenAI, L.L.C. | AI image generation processing |

Article 6 (User Rights)
① Users may request access to, correction of, or deletion of their personal data held by the Company at any time.
② To submit a request, email official@yoldcompany.com. Please include your account email and the nature of your request.
③ Requests will be processed within 10 business days of receipt.
④ Upon account deletion, personal data is immediately destroyed, except for data required to be retained by law, which is stored separately before destruction.
⑤ EU/EEA residents may additionally exercise their rights under GDPR, including the right to data portability and the right to lodge a complaint with a supervisory authority.
⑥ California residents may exercise their rights under the CCPA, including the right to know, the right to delete, and the right to opt out of the sale of personal information (the Company does not sell personal information).

Article 7 (Cookie Use)
① The Company uses cookies for login session maintenance, language preferences, and basic analytics.
② Users may disable cookies in their browser settings. Disabling cookies may limit the functionality of certain features (e.g., staying logged in).

Article 8 (Data Destruction)
① Electronic files: permanently deleted using technically unrecoverable methods.
② Physical records (if any): shredded or incinerated.

Article 9 (Data Protection Officer and Contact)
For inquiries, complaints, or requests related to personal data processing, please contact:

- Name: Dongkwon Kim (CEO / Data Protection Officer)
- Email: official@yoldcompany.com

For additional assistance with privacy-related matters in Korea:
- Korea Internet & Security Agency (KISA): privacy.kisa.or.kr / Tel. 118
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / Tel. 1833-6972