Privacy Policy

Effective date: 2026-04-19

Maestiq (the "Company") respects your privacy and complies with Korean Personal Information Protection Act, GDPR, and applicable laws. This Privacy Policy explains how we collect, use, and protect your personal information.

1. Information We Collect

Required (at registration): - Email address - Name (if provided via social login) - Authentication provider ID (Clerk User ID)

Automatically collected (during Service use): - IP address, User-Agent, access time - Cookies (session management, locale preference) - Video browse, analysis, and save history - Credit deduction and refund records

Payment information (for subscribers): - Payment method data is collected and stored directly by Paddle. We only receive the transaction ID, amount, and status. We do not store card numbers or other sensitive payment details.

Collection methods: direct input by the user, automatic logging during Service use, and transfer from third parties (Clerk, Paddle).

2. Purpose of Use

We use collected information for:

  • Account authentication and management
  • Service delivery (feed, analysis, save, notifications)
  • Payment processing and subscription management
  • Credit balance tracking and refund processing
  • Customer support
  • Service improvement and new feature development (statistical, anonymized)
  • Fraud prevention and Service security
  • Legal compliance

3. Retention Periods

We retain personal information only as long as necessary. Some records are kept for legal compliance:

  • Registration/deletion records: Deleted immediately upon account deletion (up to 30 days retained if fraud investigation is needed)
  • Contract or withdrawal records: 5 years (Korean E-Commerce Law)
  • Payment and service provision records: 5 years (Korean E-Commerce Law)
  • Consumer complaint or dispute records: 3 years (Korean E-Commerce Law)
  • Access logs: 3 months (Korean Communications Privacy Act)

4. Sharing with Third Parties

We do not share personal information with third parties except when:

  • You give prior consent
  • Required by law or valid law enforcement request

5. Data Processors (Subprocessors)

We entrust the following subprocessors to operate the Service:

ProcessorPurposeCountryPolicy
Clerk, Inc.Authentication & account managementUSAhttps://clerk.com/privacy
Paddle Commerce Inc.Payment processing (Merchant of Record)UK, USAhttps://www.paddle.com/legal/privacy
Supabase, Inc.Database & backendUSA (Singapore region)https://supabase.com/privacy
Google LLCAI analysis (Gemini API) & YouTube data collectionUSA, Globalhttps://policies.google.com/privacy
Cloudflare, Inc.Web infrastructure, CDN, edge computingUSA, Globalhttps://www.cloudflare.com/privacypolicy

All processors operate under Data Processing Agreements (DPA) and process personal information only as instructed by the Company.

6. International Data Transfers

We transfer personal information internationally for Service operation:

  • Destination countries: USA, UK, Singapore (server locations of Clerk, Paddle, Supabase, Google, Cloudflare)
  • Data transferred: All items listed in Section 1
  • Transfer timing: Continuously during Service signup and use
  • Transfer method: Encrypted network (TLS) API communication
  • Legal basis: User consent and GDPR Article 46 Standard Contractual Clauses (SCC)
  • Retention: As per Section 3

You have the right to refuse international transfer, but Service use may be restricted as a result.

7. Cookies and Similar Technologies

  • Essential cookies: Session management, login persistence (Clerk)
  • Preference cookies: Language selection (`NEXT_LOCALE`, `supascoop:locale`)
  • Analytics cookies (planned): Service usage patterns (separate consent when introduced)

You may disable cookies in your browser settings, but disabling essential cookies will prevent Service use.

8. Your Rights

You may exercise the following rights (GDPR Articles 16-22 and Korean PIPA Articles 35-37):

  • Access: View personal information we hold
  • Rectification/Erasure: Correct or delete inaccurate information
  • Restriction: Pause processing temporarily
  • Portability (GDPR): Receive a copy of your data in structured format
  • Withdraw Consent: Revoke consent for collection/use

To exercise these rights, email hi@maestiq.com. We will respond within 10 business days.

9. Automated Decision-Making

We use automated decision-making for:

  • Scoop Score calculation: Algorithmic aggregation of view, like, comment, and freshness data (0-100)
  • Feed ranking: Country-, category-, and Score-based ranking

You have the right to request an explanation or object to automated decisions. Email hi@maestiq.com to request human review.

10. Children's Privacy

We do not knowingly collect personal information from children under 14. If we discover a child under 14 has registered, we will delete the account and collected data immediately.

11. Data Protection Officer

We have designated a Data Protection Officer (DPO) to oversee privacy matters:

  • Name: DongHyun Yoon
  • Position: Representative
  • Email: hi@maestiq.com

All privacy-related inquiries, complaints, and remedies may be directed to the DPO.

12. Security Measures

We implement the following safeguards:

  • Administrative: Internal management policies, regular staff training
  • Technical: TLS/AES encryption, access control, intrusion detection, backups
  • Physical: Server room access control (via subprocessors)

13. Changes to This Policy

We will notify you of material changes to this Policy at least 7 days (30 days for material changes) in advance via in-Service announcement or email.

Effective date: 2026-04-19