Privacy Policy
Effective date: 2026-04-19
Maestiq (the "Company") respects your privacy and complies with Korean Personal Information Protection Act, GDPR, and applicable laws. This Privacy Policy explains how we collect, use, and protect your personal information.
1. Information We Collect
Required (at registration): - Email address - Name (if provided via social login) - Authentication provider ID (Clerk User ID)
Automatically collected (during Service use): - IP address, User-Agent, access time - Cookies (session management, locale preference) - Video browse, analysis, and save history - Credit deduction and refund records
Payment information (for subscribers): - Payment method data is collected and stored directly by Paddle. We only receive the transaction ID, amount, and status. We do not store card numbers or other sensitive payment details.
Collection methods: direct input by the user, automatic logging during Service use, and transfer from third parties (Clerk, Paddle).
2. Purpose of Use
We use collected information for:
- Account authentication and management
- Service delivery (feed, analysis, save, notifications)
- Payment processing and subscription management
- Credit balance tracking and refund processing
- Customer support
- Service improvement and new feature development (statistical, anonymized)
- Fraud prevention and Service security
- Legal compliance
3. Retention Periods
We retain personal information only as long as necessary. Some records are kept for legal compliance:
- Registration/deletion records: Deleted immediately upon account deletion (up to 30 days retained if fraud investigation is needed)
- Contract or withdrawal records: 5 years (Korean E-Commerce Law)
- Payment and service provision records: 5 years (Korean E-Commerce Law)
- Consumer complaint or dispute records: 3 years (Korean E-Commerce Law)
- Access logs: 3 months (Korean Communications Privacy Act)
4. Sharing with Third Parties
We do not share personal information with third parties except when:
- You give prior consent
- Required by law or valid law enforcement request
5. Data Processors (Subprocessors)
We entrust the following subprocessors to operate the Service:
| Processor | Purpose | Country | Policy |
|---|---|---|---|
| Clerk, Inc. | Authentication & account management | USA | https://clerk.com/privacy |
| Paddle Commerce Inc. | Payment processing (Merchant of Record) | UK, USA | https://www.paddle.com/legal/privacy |
| Supabase, Inc. | Database & backend | USA (Singapore region) | https://supabase.com/privacy |
| Google LLC | AI analysis (Gemini API) & YouTube data collection | USA, Global | https://policies.google.com/privacy |
| Cloudflare, Inc. | Web infrastructure, CDN, edge computing | USA, Global | https://www.cloudflare.com/privacypolicy |
All processors operate under Data Processing Agreements (DPA) and process personal information only as instructed by the Company.
6. International Data Transfers
We transfer personal information internationally for Service operation:
- Destination countries: USA, UK, Singapore (server locations of Clerk, Paddle, Supabase, Google, Cloudflare)
- Data transferred: All items listed in Section 1
- Transfer timing: Continuously during Service signup and use
- Transfer method: Encrypted network (TLS) API communication
- Legal basis: User consent and GDPR Article 46 Standard Contractual Clauses (SCC)
- Retention: As per Section 3
You have the right to refuse international transfer, but Service use may be restricted as a result.
7. Cookies and Similar Technologies
- Essential cookies: Session management, login persistence (Clerk)
- Preference cookies: Language selection (`NEXT_LOCALE`, `supascoop:locale`)
- Analytics cookies (planned): Service usage patterns (separate consent when introduced)
You may disable cookies in your browser settings, but disabling essential cookies will prevent Service use.
8. Your Rights
You may exercise the following rights (GDPR Articles 16-22 and Korean PIPA Articles 35-37):
- Access: View personal information we hold
- Rectification/Erasure: Correct or delete inaccurate information
- Restriction: Pause processing temporarily
- Portability (GDPR): Receive a copy of your data in structured format
- Withdraw Consent: Revoke consent for collection/use
To exercise these rights, email hi@maestiq.com. We will respond within 10 business days.
9. Automated Decision-Making
We use automated decision-making for:
- Scoop Score calculation: Algorithmic aggregation of view, like, comment, and freshness data (0-100)
- Feed ranking: Country-, category-, and Score-based ranking
You have the right to request an explanation or object to automated decisions. Email hi@maestiq.com to request human review.
10. Children's Privacy
We do not knowingly collect personal information from children under 14. If we discover a child under 14 has registered, we will delete the account and collected data immediately.
11. Data Protection Officer
We have designated a Data Protection Officer (DPO) to oversee privacy matters:
- Name: DongHyun Yoon
- Position: Representative
- Email: hi@maestiq.com
All privacy-related inquiries, complaints, and remedies may be directed to the DPO.
12. Security Measures
We implement the following safeguards:
- Administrative: Internal management policies, regular staff training
- Technical: TLS/AES encryption, access control, intrusion detection, backups
- Physical: Server room access control (via subprocessors)
13. Changes to This Policy
We will notify you of material changes to this Policy at least 7 days (30 days for material changes) in advance via in-Service announcement or email.
Effective date: 2026-04-19