Contentrip

Contentrip AI

Privacy Policy

In effect from September 2, 2026

This is a translation of the Korean original. If the two differ, the Korean text prevails. For questions, contact dev@impactstation.kr.

Impact Station Co., Ltd. (the "Company") treats your personal data with care and complies with the Personal Information Protection Act of Korea and other applicable laws. This policy describes what personal data we process, for what purpose, how long we keep it, and how we destroy it.

ControllerDetail
Company nameImpact Station Co., Ltd.
RepresentativeSong Sanghoon
Business registration number683-86-00599
Address901, 23 Gukhoe-daero 66-gil, Yeongdeungpo-gu, Seoul, Republic of Korea

This policy is published at all times at https://contentrip.com/en/privacy.


Article 1 Categories of personal data we process

We process only the minimum personal data needed to provide the service.

1-1. Collected automatically when you sign up or sign in

Values that the provider passes to the Company when you sign in with a social account.

ItemDetail
Email addressAccount identification
NameDefault for your initial display name
Profile pictureWe copy the image the provider gives us into our own storage — we do not store the original URL
Email verification timeValue provided by the provider
Social account identifier · authentication tokenNeeded to keep you signed in
Sign-in methodWhere your data goes
GoogleUnited States — explained in Article 6
AppleUnited States — explained in Article 6
KakaoRepublic of Korea — it does not leave the country
Email and passwordIt does not go anywhere

1-2. Entered by you

You can use the service without entering these. They appear on your public profile.

GroupItems
ProfileDisplay name · profile picture · bio · handle (generated automatically at sign-up)
Creator profileCountry and city of activity · specialties · tools used · languages · roles · whether you accept bank transfers (for display) · collaboration terms (available hours · time zone · team size · external links)
Posts and commentsBody text · attached images
CommissionsCommission message (255 characters) · reference links · budget · preferred region
ReportsReason for the report · detailed description

1-3. Generated while you use the service

ItemDetail
Playback recordsPlayback start, progress and end events; resume position
View recordsProfile views
Recommendation impression recordsWhich recommendations were shown and clicked
Relationship recordsFollows · blocks · favourites · likes
NotificationsNotification title, body and sender

Activity recorded while signed out is not personal data. Records from browsing without signing in contain no value that points to a person — they remain only as aggregate data with no way to identify anyone.

1-4. What we do not collect today

The items below are not collected because no screen exists for them. We will amend this policy before opening any such feature.

  • ·Resident registration numbers, passport numbers and other unique identifiers — there is no place to store them
  • ·Bank account numbers, payee details and other payment information — there is no place to store them
  • ·Sensitive data such as beliefs, health or sex life — there is no place to store them
  • ·Date of birth · age — there is no place to store them
  • ·IP addresses · browser information — not stored in the Company's database
  • ·Company details (company name, business registration number, contact person) — a field exists but there is no input screen
  • ·App push tokens · search queries · electronic signature records — fields exist but nothing is recorded
  • ·Payment information — payments are not connected

Article 2 Purposes of processing

PurposeData processed
Identifying members · keeping you signed inEmail · social account identifier · authentication token
Showing public profilesDisplay name · profile picture · handle · bio · creator profile
Ranking content · composing the home screenPlayback and view records (aggregated)
Resuming playbackPlayback position
Showing recommendations and measuring their performanceRecommendation impression and click records
Social features such as follow and blockRelationship records
Sending notificationsNotification recipients and content
Receiving and handling reportsReason · details · outcome
Receiving and brokering commissionsCommission content · budget · region
Audit trail of operator actionsWho acted, on what, why, and with what result
Meeting legal obligations (transaction and tax records)Orders · payments · tax invoices · settlement records

Article 3 Processing and retention periods

3-1. Principle

Member data is kept for as long as membership continues and destroyed under the procedure in Article 7 after you request withdrawal.

3-2. Kept longer because the law requires it

Transaction and tax records are retained rather than destroyed, as required by law. These records are stored and managed separately from other personal data.

RecordsOrder · payment · refund records
Legal basisE-Commerce Act — payment and supply of goods
Retention5 years
RecordsWithdrawal of offer · contract records
Legal basisE-Commerce Act — withdrawal of offer and contracts
Retention5 years
RecordsConsumer complaints · dispute handling records
Legal basisE-Commerce Act — complaints and disputes
Retention3 years
RecordsLabelling and advertising records
Legal basisE-Commerce Act — labelling and advertising
Retention6 months
RecordsTax invoices · transaction evidence (counterparty name, business registration number, email)
Legal basisFramework Act on National Taxes — transaction evidence
Retention5 years (7 years for cross-border transactions)
RecordsSettlement records · contracts · project records
Legal basisBoth bases above apply — they are transaction evidence and contract records at once
Retention5 years

We retain records as if we were an intermediary in mail-order sales. The proviso to Decree The E-Commerce Decree limits an intermediary's retention scope to "records processed through its own information processing system", but the Company retains the whole table above rather than that narrower scope — retaining more broadly satisfies the statutory duty under either reading. The retention periods are the same either way.

3-3. Retention of service usage records

Records left behind as you use the service are made impossible to attribute to a person once the periods below pass. The records remain as statistics, but the values linking them to you are erased.

RecordViewing, view and recommendation impression records
Period90 days
What happens thenThe identifiers (member number, session number) are erased. How often a work was shown remains as statistics
RecordSignage device status records
Period30 days
What happens thenErased
RecordPlayback logs (settlement evidence)
Period400 days after settlement is paid
What happens thenErased. Not erased before payment — the basis for settlement would disappear
RecordDiscarded playback records
Period365 days
What happens thenErased

Deleting your account is handled regardless of the periods above. After withdrawal we destroy data following a 30-day grace period, and the identifiers in usage records are erased at the same time (Article 7).

These periods are kept by code that runs every hour, not by a promise on paper. Writing a period into a policy with no procedure to erase makes the policy itself a promise that is not kept — so this article was written after the deletion and anonymisation procedures existed.

Article 4 Provision to third parties

The Company does not provide your personal data to third parties. We do entrust processing to the extent needed to operate the service; that is described in Articles 5 and 6.


Article 5 Entrustment of processing

ProcessorAmazon Web Services, Inc.
Entrusted workDatabase · web server execution · file storage
Where processedDomestic (Seoul)
ProcessorAmazon Web Services, Inc.
Entrusted workImage delivery (CDN)
Where processedOverseas — United States and others
ProcessorGoogle LLC
Entrusted workSocial sign-in authentication · profile image hosting
Where processedOverseas — United States
ProcessorApple Inc.
Entrusted workSocial sign-in authentication
Where processedOverseas — United States
ProcessorKakao Corp.
Entrusted workSocial sign-in authentication
Where processedDomestic
ProcessorMux, Inc.
Entrusted workVideo encoding · streaming
Where processedOverseas — United States
ProcessorGitHub, Inc.
Entrusted workExecution environment for scheduled batch jobs
Where processedOverseas — United States

The database, web servers and file storage are processed domestically (Seoul). Only the rows marked "Overseas" above leave the country; details are in Article 6.


Article 6 Transfers of personal data overseas

6-0. Basis for the transfer, and why we do not seek separate consent

To provide the service the Company entrusts the processing and storage of personal data to overseas providers. This is entrustment and storage necessary to perform the contract with you, and because the matters below are disclosed in this policy, we do not seek separate consent.


For each recipient we set out the five points below.

6-1. Google LLC — social sign-in authentication · profile image hosting

There are two paths for this transfer.

ItemDetail
What is transferred(a) Sign-in — your IP address and browser information at the moment you are taken to the Google sign-in screen (collected by Google directly)
(b) Profile pictures do not travel by this path — we copy the picture into our own storage at sign-up, so a viewer's IP address never reaches Google
Country · when · howUnited States and others (countries where Google operates) / at the moment of a sign-in attempt / HTTPS request
Recipient · contactGoogle LLC — googlekrsupport@google.com (the contact given in Google's Korean privacy policy)
Purpose · retentionSign-in authentication · profile image delivery / Google does not publish a single retention period — it varies by data type and user setting. For as long as the Company offers Google as a sign-in method
How to refuseYou can sign up with a different method — using Kakao (domestic) or email and password sends nothing to Google

6-2. Apple Inc. — social sign-in authentication

ItemDetail
What is transferredYour IP address and device information at the moment you are taken to the Apple sign-in screen (collected by Apple directly)
Country · when · howUnited States — Apple states that it stores personal data gathered worldwide with Apple Inc. in the United States / at the moment of a sign-in attempt / HTTPS request
Recipient · contactApple Inc. — https://www.apple.com/legal/privacy/contact/ (the privacy contact Apple provides)
Purpose · retentionSign-in authentication / Apple likewise does not publish a single retention period. For as long as the Company offers Apple sign-in
How to refuseSigning up with another method (Kakao, email) sends nothing to Apple

During sign-in the Company does not send these providers any identifier that points to you. The only value carried in a sign-in request is a temporary value confirming that the request started on our screen; it contains no member number, email address or anything similar.

Apple's private email relay runs in the opposite direction. Apple gives the Company an anonymous address; it is not personal data the Company sends to Apple. That anonymous address is stored by the Company, so it appears among the items collected in Article 1.

6-3. Mux, Inc. — video encoding · streaming

ItemDetail
What is transferredThe original video uploaded by a creator, and the viewer's IP address and playback request information when a video is played
The Company does not send user identifiers to Mux
Country · when · howUnited States / at upload · at playback / the browser uploads to and requests playback from Mux directly
Recipient · contactMux, Inc. (88 Stevenson Street, San Francisco, CA 94105, USA) — privacy@mux.com
Purpose · retentionVideo encoding and stream delivery / Mux likewise does not publish a single retention period. Original videos are kept until the Company deletes the asset; viewer IP addresses follow Mux's own policy
How to refuseIf you do not play videos, your IP address is not passed on. Watching videos is however the core of the service, so this makes it hard to use in practice. A creator who does not upload a video transfers no original

6-4. Amazon Web Services, Inc. — image delivery (CDN)

ItemDetail
What is transferredProfile pictures · content thumbnails · images attached to posts (public files only)
Country · when · howCDN servers in a country near you / on the first request for a file / temporarily cached after HTTPS delivery
Recipient · contactAmazon Web Services, Inc. — https://aws.amazon.com/contact-us/
Purpose · retentionFaster delivery. Deleted when the cache expires; the original stays in Korea
How to refuseTo refuse this transfer you may withdraw your membership, which destroys the files. Note that if you refuse, profile pictures and thumbnails will not be visible

Storage is domestic. Originals are in the Seoul region; what goes abroad is a copy for delivery.

Files that require sign-in do not travel by this path — original videos and settlement statements open only through signed URLs and do not pass through the CDN.

Whether to upload a potentially sensitive image such as a photograph of your face is your choice. We point out that profile pictures appear on public screens and therefore take this path.

6-5. GitHub, Inc. — running scheduled batch jobs

ItemDetail
What is transferredPersonal data within the scope the batch handles (accounts due for destruction, records due for aggregation). GitHub does not store it
Country · when · howUnited States (GitHub-hosted runners) / hourly aggregation batch · daily destruction batch at 03:00 Korea time / the runner connects to the database directly
Recipient · contactGitHub, Inc. (88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA) — dpo@github.com
Purpose · retentionProviding an execution environment for scheduled batches / results are not stored. Execution logs are retained by GitHub for 90 days by default (configurable)
How to refuseSee 6-6 below

6-6. How to refuse an overseas transfer, and its effect (common)

If you do not want these transfers you may stop them by withdrawing your membership. The withdrawal procedure is in Article 7.

  • ·You cannot refuse individual processors. The providers above are infrastructure the service runs on; remove any one and the service does not work.
  • ·If you refuse, you cannot use the service. Sign-up, sign-in, video playback and profile display all run on that infrastructure.
  • ·Some transfers can be partly avoided by not using the feature, as noted for Mux and the CDN above (uploading your own profile picture, not playing videos).

Article 7 Procedure and method of destruction

7-1. Procedure

  1. 1.You request withdrawal (account deletion).
  2. 2.A 30-day grace period applies. You may cancel the request during this time.
  3. 3.Once the grace period ends, a destruction job that runs daily at 03:00 Korea time processes it.

When destruction is deferred — if any of the following applies we wait until it is resolved. Once resolved, it continues automatically without a new request. The withdrawal screen tells you which reason caused the deferral.

ReasonHow it resolves
A project is in progressResolves automatically when the project ends
Settlement money is unpaidResolves automatically when settlement completes
A report or dispute is being handledResolves automatically when handling completes
You have an active subscriptionYou must cancel it yourself
A refund deduction balance remainsPlease contact support

7-2. Method — this is destruction of identifying data followed by anonymisation, not "deletion"

When you withdraw, we erase the values that point to a person and make the author unidentifiable in records that remain, such as posts and comments. What is erased and what remains:

TargetAccount
ErasedName · email · email verification time · profile picture
RetainedInternal identifier only
TargetProfile
ErasedHandle · display name · profile picture · bio
RetainedSign-up time · role · withdrawal status and the reason recorded
TargetCompany details
ErasedContact person's name · contact details · business registration number
RetainedCompany name · country · industry
TargetPlayback and view records
ErasedWho did it · who was viewed
RetainedThe action itself (for aggregation)
TargetSearch query records
ErasedWho searched
RetainedThe query
TargetRecommendation impression records
ErasedWho saw it
RetainedThe impression record

Posts, comments and reviews you wrote are not deleted and remain. Following the author leads only to the emptied profile described above.

7-3. Records of destruction

Destruction is carried out by a method that cannot be reversed, and matters concerning destruction are recorded and managed. Afterwards the Data Protection Officer verifies the result.

7-4. Retained under the law

The transaction and tax records described in Article 3 are not destroyed but stored separately.


Article 8 Rights of data subjects and legal representatives, and how to exercise them

You may exercise the following rights at any time.

RightDetail
AccessConfirm the personal data the Company processes about you
Correction · deletionAsk us to correct or delete inaccurate content
Suspension of processingAsk us to stop processing your personal data
Withdrawal of consentWithdraw consent for data processed on the basis of consent
  • ·You can edit profile information yourself on the profile edit screen.
  • ·For anything else, please write to dev@impactstation.kr.
  • ·We handle requests within 10 days and tell you the outcome.
  • ·If we refuse a request or cannot act on it, we tell you the reason without delay.
  • ·You may also make requests through a legal representative or an authorised agent.

Article 9 Automatic collection devices (cookies)

The Company uses the following cookies.

Cookieauthjs.session-token
PurposeKeeping you signed in
Lifetime30 days
If you refuseYou cannot stay signed in
CookieNEXT_LOCALE
PurposeRemembering your chosen display language
LifetimeCleared when you close the browser (session cookie)
If you refuseYour language choice is not remembered next visit

How to refuse — you can refuse cookie storage or delete stored cookies in your browser settings. Note that if you refuse the sign-in cookie you cannot use features that require signing in.

The Company does not use third-party cookies for advertising or analytics.


Article 10 Measures to secure personal data

The Company takes the following measures.

MeasureDetail
Access control at the database levelRow-level security policies apply to the main tables holding member data, so the database itself ensures only your own data is returned
Separation of connection privilegesThe account the service uses and the account for administrative work are separated, so the service account cannot bypass security policies
Tamper protection for consent recordsConsent and withdrawal records are append-only; the service account cannot modify or delete them
Audit trail of operator actionsOperator actions record who, what, why and with what result, and are neither modified nor deleted
Protection of sign-in dataThe sign-in cookie is set so browser scripts cannot read it
Access control for videoVideo playback URLs open only with a signed token valid for six hours
Encryption in transitAll external transmission uses encrypted connections (HTTPS, encrypted database connections)
Internal management planWe maintain and operate an internal management plan for handling personal data safely
Access log retentionWhat operators did with personal data is recorded and not erased. Service access logs are kept for one year
Encryption at restThe database and file storage are encrypted at rest. Passwords are never stored in plain text and are kept only in an irreversible form
Malware protection · physical access controlServers run in the cloud provider's data centres and the runtime is replaced with a fresh image on every deployment. We operate no server room of our own

We do not process unique identifiers (such as resident registration numbers) or sensitive data. There is no place to store them, so no separate encryption obligation arises for them.

The specifics of these measures are recorded in our internal management plan. We can demonstrate them from that document if a supervisory authority asks.

Article 11 Items that do not apply

Items the law requires "only where applicable". They do not apply.

11-1. Possibility of sensitive data being made public and how to opt out

The Company does not process sensitive data. There is no place to store it.

11-2. Processing of pseudonymised data

The Company does not process pseudonymised data.

11-3. Criteria for additional use or provision

The Company does not use or provide data beyond the purposes for which it was collected.

11-4. Country names where personal data of Korean data subjects is collected directly from abroad

The Company has no flow that collects directly from abroad.


Article 12 Personal data of children under 14

The Company does not process the personal data of children under the age of 14. This is the same wherever you live.

  • ·After sign-up, before you first use the service, we confirm that you are 14 or older; until you do, you cannot use the service.
  • ·We record only the fact and time of that confirmation. We neither ask for nor store your date of birth or age — the principle of not holding unnecessary data (Article 1) applies here too.

Different countries set different ages, and 14 satisfies all of them together.

BasisPersonal Information Protection Act of Korea
Age set by that law14
Relation to our threshold (14)The same
BasisCOPPA (United States)
Age set by that law13
Relation to our threshold (14)Stricter
BasisUK GDPR
Age set by that law13
Relation to our threshold (14)Stricter
BasisGDPR Article 8 (European Economic Area)
Age set by that law13–16, as set by each member state
Relation to our threshold (14)See the explanation below

On GDPR Article 8 — that provision sets an age for processing where consent is the legal basis (it points explicitly to Article 6(1)(a)). The Company processes data to provide the service on the basis of performance of a contract (see the table in Article 15-2), so the age requirement in that provision does not apply directly. We therefore do not vary the age by member state on screen and keep a single threshold of 14.

If we learn that a user is under 14 we destroy that account's personal data without delay. The child or their legal representative may tell us through the contact point in Article 13.

This confirmation is self-declared and does not go through an identity verification agency. The law does not specify a verification method, so we use this approach for now; if stronger verification becomes necessary we will change it and amend this article at the same time.

Article 13 Data Protection Officer and contact

13-1. Data Protection Officer

ItemValue
NameSong Sanghoon
PositionRepresentative [Representative]
Department— (no separate department)
Contactdev@impactstation.kr

13-2. Department receiving and handling access requests

There is no separate department; the Data Protection Officer (Representative Song Sanghoon) receives and handles requests directly. The contact point is dev@impactstation.kr.

13-3. Domestic representative

Not applicable. The Company is a Korean corporation (Impact Station Co., Ltd.) — the duty to appoint a domestic representative applies to businesses with no address or place of business in Korea.


Article 14 Remedies for infringement of rights

If you need help with a personal data infringement, you may contact the following bodies.

BodyPersonal Information Dispute Mediation Committee
What it doesDispute mediation · collective mediation
Contact1833-6972 (kopico.go.kr)
BodyPrivacy Infringement Report Centre
What it doesReporting an infringement
Contact118 (privacy.kisa.or.kr)
BodySupreme Prosecutors' Office
What it doesRequesting an investigation
Contact1301 (spo.go.kr)
BodyKorean National Police Agency
What it doesRequesting an investigation
Contact182 (ecrm.police.go.kr)

You may also file an administrative appeal under the Administrative Appeals Act if you object to a controller's disposition.


Article 15 Changes to this policy

If this policy changes we will tell you through service notices from seven days before it takes effect. For important changes we will tell you from 30 days before.

You can compare what changed, before and after, in the revision history.

Revision history

Effective date1 September 2026
ChangeInitial enactment
Before · after—
Effective date2 September 2026
ChangeArticle 12, timing of age confirmation
Before · afterBefore: "At sign-up we confirm that you are 14 or older; without that confirmation the sign-up does not proceed." After: "After sign-up, before you first use the service, we confirm that you are 14 or older; until you do, you cannot use the service."

Article 15-2 Provisions for users outside Korea

The service can be used in many countries. Depending on where you live, the personal data law of that country also applies, and this article sets out what changes then.

The storage location is the same wherever you live — the Republic of Korea (Seoul). From the moment your personal data reaches the Company it is processed as described in Articles 5 and 6.

15-2-1. If you are in the European Economic Area (EEA) or the United Kingdom

The Company offers the service to residents of the EEA and the United Kingdom, so the GDPR (and UK GDPR) applies. The Company is the controller under those laws.

Legal bases for processing — the basis depends on what data is processed and why.

What we processLegal basis
Providing the service: account creation, sign-in, video playback, profile displayPerformance of a contract
Maintaining security, handling abuse and reports, aggregation to improve the serviceLegitimate interests — we have balanced these against your rights
Retaining transaction and tax recordsLegal obligation

Rights you can exercise — send requests to dev@impactstation.kr. We handle them and tell you the outcome within one month.

RightDetail
AccessReceive a copy of the personal data we process about you
RectificationAsk us to correct inaccurate content
ErasureAsk us to delete it (the "right to be forgotten")
Restriction of processingAsk us to pause processing
PortabilityReceive your data in a machine-readable format and move it elsewhere
ObjectionObject to processing based on legitimate interests
Withdrawal of consentWithdraw consent at any time. Processing before withdrawal remains valid
  • ·You may lodge a complaint with a supervisory authority. In the EEA this is the authority of your member state; in the United Kingdom it is the Information Commissioner's Office (ICO, ico.org.uk).
  • ·We do not carry out processing that produces legal effects concerning you based solely on automated decision-making.

Transfers to the Republic of Korea — the European Commission adopted an adequacy decision for the Republic of Korea in December 2021. Transferring personal data from the EEA to Korea therefore requires no additional safeguard such as standard contractual clauses. The United Kingdom likewise recognises the Republic of Korea as providing adequate protection.

Contact — GDPR enquiries and requests to exercise rights are received at dev@impactstation.kr. The Data Protection Officer is named in Article 13.

15-2-2. If you are in the United States

  • ·We do not knowingly collect the personal data of children under 13 (COPPA). If we learn of it we destroy the data without delay.
  • ·The Company does not sell personal data and does not share it for targeted advertising. We use no third-party cookies for advertising or analytics (Article 9).
  • ·Whether state laws such as California's apply depends on the size of the business. If a point comes where they apply, we will amend this article and tell you before it takes effect.

15-2-3. If you are in another country

If the law of your country of residence grants broader rights than this policy, those rights prevail. The rights in Article 8 can be exercised from anywhere through the same contact point (dev@impactstation.kr).


Article 16 Effective date

This Privacy Policy takes effect on 1 September 2026.