EN

COSY Privacy Policy

GlowUpRizz Inc. (hereinafter the "Company") complies with relevant laws including the Personal Information Protection Act ("PIPA") and the Act on Promotion of Information and Communications Network Utilization and Information Protection (the "Network Act"). Through this Privacy Policy, the Company informs you what information it collects, how it uses the collected information, with whom it shares it, and how data subjects may exercise their rights.

This Privacy Policy applies to the COSY website (aicosy.co.kr) and the mobile application (hereinafter the "Service").


Article 1 (Items of Personal Information Collected and Methods of Collection)

1. Items Collected at Registration

Category Items Collection Method Required/Optional
Identity verification information Real name, mobile phone number, gender, date of birth, domestic/foreign national status, Connecting Information (CI) Provided by an identity verification agency (PortOne, Danal, etc.) Required
Account information Email address, password (stored with bcrypt one-way encryption) Entered directly by the Member Required (partially exempt for social login)
Social login information (when using Kakao or Apple) Social account unique identifier, email, nickname, profile image, real name, mobile phone number, gender, date of birth (within the scope provided by each platform) Kakao OAuth, Apple OAuth API Required (when that registration path is selected)
Profile information Activity name (nickname), bio (up to 200 characters), profile image Entered directly by the Member Required
Channel information YouTube/Instagram/TikTok channel URL, number of subscribers/followers, channel start date Entered directly by the Member or via external channel OAuth integration At least 1 channel required
Business information (Business Members) Business registration number, business registration certificate image Entered and uploaded directly by the Member Required for Business Members
Business profile information (Business Members) Target age range, target gender, recent advertising rates, references (URL or attachments) Entered directly by the Member Required for Business Members

2. Items Collected at Settlement/Withdrawal Application

Items Collection Method Basis for Retention
Financial account in the Member's own name (account holder, bank, account number) Entered directly by the Member and authenticity-verified through the USEB (USEB Inc.) account verification widget For settlement payment purposes
Resident registration number (individual Members) or business registration number (Business Members) USEB ID OCR or direct entry by the Member Income Tax Act Article 145-2, Enforcement Decree Article 216 (submission of payment statements)
Copy of ID (for OCR processing) Captured once during the settlement registration procedure; the original image is destroyed immediately after OCR processing, and only the encrypted OCR result is stored Identity verification obligation

3. Items Collected Automatically During Service Use

Items Time of Collection Storage Location
IP address, User-Agent, access time, access path Automatically collected when accessing the Service Server access logs
Cookies (token, admin-token — JWT authentication cookies) Issued upon login, stored in the browser Client side + server verification
Device OS, app version, push token (Subscription ID) Collected by the OneSignal SDK when the mobile app is launched OneSignal servers + Company servers
Service usage records (page views, clicks, search terms, advertising response history, etc.) During Service use Google Analytics, Google Tag Manager, Company server analytics logs
External channel statistical data (number of subscribers, views, watch time, number of likes, number of comments, video metadata, etc.) When a Member integrates or re-syncs an external channel Company servers

4. Mobile App Permissions

The Company's mobile app requests access permissions on the device for the following functions. Members may change permissions at any time in their device settings.

Permission Purpose of Use Required/Optional
Camera Taking profile photos, photographing ID/business registration certificate Optional
Photos/media library Uploading profile photos, business registration certificate, reference materials Optional
Notifications Push notifications for collaboration matching, settlement, announcements, etc. Optional

Other than the above permissions, the Company does not collect location, contacts, microphone, call logs, or similar data.

5. Personal Information of Children Under 14

The Service may only be used by persons aged 14 or older, and the Company automatically blocks registration by persons under 14 based on the date of birth obtained during identity verification.

6. Collection of Sensitive Information

As a general rule, the Company does not collect sensitive information concerning ideology/beliefs, joining or withdrawing from a labor union or political party, political views, health/sex life, race/ethnicity, and the like.


Article 2 (Purposes of Collection and Use of Personal Information)

Purpose Category Detailed Uses Personal Information Processed
Member identification/management Identity verification, prevention of duplicate registration, confirmation of intent to register, blocking registration by persons under 14, prevention of improper use, maintenance/management of membership, confirmation of the Member's intent, delivery of notices Name, mobile phone number, date of birth, gender, CI, email, password
Service provision Creator/influencer matching, advertising matching between Advertisers and Members, member-to-member Campaign (collaboration) proposal/matching, provision of channel analytics and statistics, content/product recommendation Nickname, profile, channel information, channel statistics
Settlement/tax Payment of advertising/campaign revenue, withdrawal processing, withholding tax, submission of payment statements Account number, account holder, resident registration number or business registration number, ID OCR result
Customer support Responding to inquiries, dispute resolution, delivery of announcements Email, mobile phone number, nickname
Transmission of advertising information (for consenting recipients only) Notices of new campaigns, events, promotions, recommended content alerts Email, mobile phone number, app push token
Statistics/analytics/service improvement Service usage statistics, access frequency analysis, development of new features, detection of security threats Automatically collected items (IP, UA, usage records, etc.), channel statistics

Article 3 (Retention and Use Period of Personal Information)

When a Member terminates the service agreement or the purpose of collection and use has been achieved, the Company destroys the retained personal information without delay. However, the following information is retained for the periods specified under relevant laws.

1. Retention Under the Company's Internal Policy

Items Retention Period Reason
Records of improper use (part of the identity verification information of expelled Members) 1 year from the date the improper use is confirmed Prevention of improper re-registration/re-use
Connecting Information (CI) 1 year after Member withdrawal, or until the purpose of preventing short-term re-registration is achieved Prevention of duplicate registration by the same person

2. Retention Under Relevant Laws

Items Retention Period Governing Law
Records on contracts or withdrawal of subscription, etc. 5 years Act on the Consumer Protection in Electronic Commerce
Records on payment and supply of goods, etc. 5 years Act on the Consumer Protection in Electronic Commerce
Records on consumer complaints or dispute handling 3 years Act on the Consumer Protection in Electronic Commerce
Records on labeling/advertising 6 months Act on the Consumer Protection in Electronic Commerce
Records on payment of business income/other income (including account number, resident registration number or business registration number) 5 years from January 1 of the year following the tax year in which the payment date falls Income Tax Act Article 145-2, Enforcement Decree Article 216
Records on electronic financial transactions 5 years Electronic Financial Transactions Act
Service visit records (login IP, access time, etc.) 3 months Protection of Communications Secrets Act

Article 4 (Provision of Personal Information to Third Parties)

Except where the data subject has consented or where there is a special provision under other laws, the Company does not provide a Member's personal information to third parties. The Company may provide information with consent in the following cases.

1. Information Provided to Advertisers (when a Member applies for or is matched to an advertising campaign)

Recipient Purpose of Provision Items Provided Retention/Use Period
The Advertiser who requested the advertising (individually notified when the Member applies/is matched) Conducting the advertising campaign, evaluating advertising performance, issuing settlement statements Nickname, profile image, bio, channel URL, channel statistics, target age/gender information, information provided directly by the Member during the campaign 3 years after the end of the Advertiser's campaign, or a period in accordance with the Advertiser's own retention policy

2. Information Disclosed to a Counterparty Member upon Member-to-Member Campaign (Collaboration) Matching

Recipient Purpose of Provision Items Provided
Campaign counterparty Member (when a Member has proposed/accepted a campaign) Conducting member-to-member collaboration, coordinating schedule/roles/settlement Nickname, profile image, bio, channel URL, channel statistics, information provided directly by the Member during the campaign

When applying for, proposing, or accepting a campaign, the Member goes through a separate consent procedure regarding the above provision.

2. Provision Under Laws

The Company may provide a Member's personal information to investigative agencies, tax authorities, the Financial Supervisory Service, and the like, in accordance with relevant laws, in the following cases:


Article 5 (Entrustment of Personal Information Processing)

For the smooth provision of the Service, the Company entrusts the processing of personal information as follows. When entering into an entrustment agreement, the Company specifies in writing (e.g., in the contract) matters concerning responsibility—including the prohibition on processing personal information beyond the purpose of the entrusted work, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of the trustee, and indemnification—pursuant to Article 26 of PIPA.

1. Identity Verification/Payment/Settlement

Trustee Entrusted Work Items Processed
Danal Co., Ltd. Mobile phone identity verification Name, mobile phone number, carrier, date of birth, gender, domestic/foreign national status, CI
USEB Inc. (USEB) Account authenticity verification, ID OCR, KYC Account holder name, account number, financial institution information, ID image

2. Notifications/Email/Push Delivery

| --- | --- | --- |

KR