1. Purposes of processing
We process personal information for social sign-in and account management; YouTube analysis, Shorts creation, editing, download, and project management; transactional notices such as project completion and, with optional consent, event, discount, feature, and template advertising emails; usage measurement, plan limits, and fraud prevention; visit and usage analytics and Service improvement; error handling, security, quality improvement, and customer support.
2. Information we process
Social sign-in: account identifier, email, display name, profile image, provider, and latest sign-in time. Service use: YouTube URL, video ID, title, channel, duration, thumbnail, generated titles and captions, edit settings and output, project status, and usage. Email notices: account email, advertising-email address, project number, delivery content, status and time, and advertising-email consent or refusal status and decision time. Payment: payer name, email, encrypted phone number, product, amount, transaction identifiers, issuer, card type, masked card number, an encrypted ThePayOne card ID or Toss billing key, and a Toss customer identifier. Customer support: reply email, inquiry category and message, submission page, browser and device information, and submission time. Automatically generated data: session cookies, access time, IP address, browser and device information, request and error logs, paid-feature use time, filter settings, result count, linked subscription and order identifiers, Google Analytics cookies and visitor or session identifiers, pages, referrer, approximate region, and usage events.
Easy Cut does not collect or store passwords for Google or other social sign-in providers. Card number, expiry, date of birth or business number, PIN, and CVC are used only in the processor's card-registration or payment request and are not stored in our database or application logs. Processor-issued payment tokens, including a ThePayOne card ID or Toss billing key, and billing contact details are encrypted with AES-256-GCM for recurring payment and payment processing and are not written to application logs.
3. Retention periods
Account profile, login sessions, projects, templates, saved-card identifiers, billing contact details, email-delivery state, and advertising-email consent or refusal records are deleted without delay on account withdrawal unless statutory retention applies. Records of contracts or withdrawal are kept for 5 years; payment and supply of goods or services for 5 years; consumer complaints or disputes for 3 years; and display or advertising for 6 months under Article 6 of Korea's Enforcement Decree of the Electronic Commerce Consumer Protection Act. Google Analytics cookies may remain for up to two years from creation, subject to browser settings and Google policy, while event data follows the configured property-retention period. Source video, extracted audio, and intermediate transcripts exist only during a job; editing clips, completed video, thumbnails, and caption ranges remain for up to 30 days under the plan.
On withdrawal, only the minimum contract, payment, refund, and service-supply evidence legally required is linked to a pseudonymous identifier and kept in a separately access-restricted area. A live dispute, investigation, or litigation may extend retention only to the extent and duration supported by another legal basis.
4. Disclosure to third parties
We do not sell or provide personal information to third parties as a rule, except where required by law or separately consented to by the user.
5. Processing vendors
We use Supabase, Inc. for authentication and a database primarily stored and processed in Seoul; Vercel Inc. for hosting and request or security processing; Amazon Web Services, Inc. and AWS Korea for video processing and private storage in Seoul; Google LLC for sign-in, YouTube metadata, paid Gemini AI, and visit analytics using analytics cookies; OpenAI OpCo, LLC for transcription and fallback text generation; Plus Five Five, Inc. (Resend) for project-completion and consented advertising email delivery; and ThePayOne and Toss Payments Co., Ltd. for payments in Korea. Toss Payments may process the customer identifier, authentication key, billing key, card authentication information, and product, amount, order, and transaction identifiers needed for card registration, billing-key issuance, automatic subscription charges, cancellations, and payment results. Each processor is limited to information needed for its assigned role, and we review contractual security, purpose limitation, subprocessing, incident notice, and deletion obligations.
6. International transfers
Transfers necessary to perform the service contract rely on Article 28-8(1)(3) of Korea's Personal Information Protection Act. Google Analytics uses analytics cookies for visit, returning-visit, and session statistics and Service improvement. Advertising storage, ad user data, ad personalization, and Google Signals are disabled.
Supabase, Inc. (privacy@supabase.com): account, project, usage, and billing-state data may be accessed in the United States for support, security, or incident response when you sign in or use the Service over TLS; primary database storage and processing is in Seoul. Data follows our retention periods and is deleted after the processor's 30-day return period when the contract ends, unless law requires otherwise. You may refuse through support, but account features will be unavailable.
Vercel Inc. (privacy@vercel.com): IP, device, request and error logs, and service data included in requests are transferred over TLS on each web or API request to the United States and countries where Vercel subprocessors operate, for hosting, security, and incident response. Data is kept while providing the Service; processor backups may remain up to 30 days after deletion or termination unless law requires otherwise. Refusal makes the website and API unavailable.
Plus Five Five, Inc. (Resend; privacy@resend.com): recipient email, project number, email subject and body, delivery time and status, and message identifier are transferred over TLS to the United States and subprocessor countries when a project completes or a consented advertising email is sent. The purpose is transactional project-completion and consented event or discount email delivery. Data is retained while services are provided and deleted within 90 days after processor-contract termination unless law requires otherwise. You may refuse through support; completion email will then be unavailable but the web Service remains available, and refusing advertising email does not affect use of the Service.
Google LLC for sign-in and YouTube API: Google account identifier, email, display name, profile image, and public YouTube URL or metadata are transferred over TLS when you sign in or request video verification, to the United States and countries where Google operates data centers. Data remains while needed for the linked account and Service or until permission withdrawal and deletion complete. You may decline Google sign-in or request unlinking, but features requiring sign-in and video verification will be unavailable.
Google LLC paid Gemini API: transcript, video or clip metadata, candidate ranges, and request or response data are transferred over TLS during a job to the United States and countries where Google or its agents operate facilities, to generate highlights, titles, and synthetic comments and prevent abuse. Related logs may be retained up to 55 days. You may refuse by not submitting a job; AI Shorts creation will then be unavailable. Google Cloud privacy contact: https://support.google.com/cloud/contact/dpo.
OpenAI OpCo, LLC (privacy@openai.com): audio chunks, transcript, video or clip metadata, and generation requests or responses are transferred over TLS during a job, primarily to the United States and to subprocessor locations including Korea, Japan, and Singapore, for transcription, fallback highlight, title and synthetic-comment generation, and abuse prevention. The audio transcription endpoint has no default customer-content retention; text-generation safety logs may be retained up to 30 days, except where law or severe-abuse prevention requires longer. You may refuse by not submitting a job; AI Shorts creation will then be unavailable.
Google Analytics visit analytics: analytics cookies and visitor or session identifiers, timestamp, browser and device information, page, referrer, approximate region, and an IP address that may be processed in transit are sent over TLS to the United States and Google data-center countries for visit, returning-visit, and session analytics and Service improvement. Analytics cookies may remain for up to two years and event data follows the configured property-retention period. Advertising features remain disabled. You can delete or block analytics cookies or restrict transmission with browser tracking-prevention or content-blocking features without affecting ordinary Service use.
7. AI processing
Every job's audio is chunked and transcribed through the OpenAI API. Transcript and video or clip metadata may be sent to the paid Gemini API to create highlights, titles, and synthetic comment copy; if paid processing has not been confirmed or Gemini fails, the OpenAI API performs text generation.
We do not separately share user content for provider model training or use it to train our own model. Our runtime does not send user content to the unpaid Gemini API, and OpenAI API inputs and outputs are not used for model training by default. Providers may retain limited safety logs for the periods in Section 6.
The Service does not perform speaker biometric identification or facial recognition, and AI does not make a fully automated decision with legal or similarly significant effect. Synthetic comments are not real user comments. Review accuracy, legality, and rights before publishing.
8. Destruction
Personal information is destroyed without delay when its purpose or retention period ends. On withdrawal, account, content, and saved-payment-method data not subject to statutory retention is deleted immediately. Separately retained statutory records are marked for destruction after their record-specific expiry date once no active legal hold remains. Electronic files are deleted in a manner designed to prevent recovery; video output is removed through application cleanup and storage lifecycle policies.
9. Cookies
Easy Cut uses essential session cookies for sign-in and project ownership and Google Analytics cookies for visit, returning-visit, and session statistics and Service improvement. Advertising storage, ad user data, ad personalization, and Google Signals are disabled. Blocking essential cookies may prevent sign-in or project features; blocking analytics cookies does not affect ordinary Service use.
10. Your rights
You may request access, correction, deletion, suspension, consent withdrawal, or refusal of an international transfer. We respond through customer support after identity verification under applicable law. Refusing necessary processing may limit the relevant feature. You can delete or block Google Analytics cookies in browser settings or restrict transmission through tracking-prevention or content-blocking features without affecting ordinary Service use.
11. Security measures
We apply encryption in transit, restricted access, server-only secret management, private storage and signed URLs, protected session cookies, access logging, paid and no-training AI processing checks, vendor safeguards, and regular deletion policies.
12. Children under 14
Easy Cut is not directed to children under 14 and does not intentionally collect their personal information without a legal guardian's consent.
13. Privacy contact
Controller: Artiroom · Representative and privacy officer: Kim Dong-min · Phone: +82-10-4836-2874 (weekdays 14:00–19:00 KST) · Email: easycut@easycut.co.kr · Address: 40, Seongsan-ro 8-gil, Mapo-gu, Seoul, Republic of Korea
Privacy inquiries and rights requests may be submitted through the contact above. Korea Internet & Security Agency privacy report center: 118; Personal Information Dispute Mediation Committee: 1833-6972.
14. Changes to this policy
We revise this policy when laws, processors, AI training or retention terms, transfer countries, or data practices change. Material changes are announced before taking effect.
Additional notice: YouTube channel connection and uploading
YouTube connection and uploading are being prepared in a limited test environment and are not yet generally available. This notice applies to test participants who choose to use the feature.
Easy Cut uses YouTube API Services. Channel authorization is optional and separate from signing in to Easy Cut. It is used to display the user's connected channel, upload a completed video selected by the user, and check the upload result.
We process the channel ID and name, granted permissions, and authorization tokens. When the user requests an upload, we send the selected video, title, description, visibility, made-for-kids classification, and realistic altered or synthetic content disclosure to Google. We retrieve the video ID, actual visibility, and processing status, including the status of private uploads.
Authorization tokens are encrypted on the server and access is restricted by account. Tokens are not provided to browsers or source-video ingestion workers. We do not sell the Google API integration data or use it for advertising targeting or training general-purpose AI models. Easy Cut's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We periodically check channel information and authorization. Connections unused or not successfully validated for 29 days are deleted. Upload details are deleted 29 days after creation; only minimal internal user, output and connection identifiers and output versions remain to prevent duplicate uploads. Those records are also deleted on disconnection or account withdrawal. Incomplete authorization requests expire after 10 minutes and are removed within approximately 70 minutes while the cleanup process operates normally.
The channel-connection screen offers disconnection and data deletion. It removes all YouTube connections, authorization tokens, upload records and pending authorization requests for that Easy Cut account and requests Google authorization revocation. If revocation cannot be confirmed, we display a link for manual revocation. Users may also revoke access in their Google account or request deletion at easycut@easycut.co.kr. Disconnecting does not delete videos already uploaded to YouTube or the original project output.
Data is sent to Google LLC over encrypted TLS connections during authorization, user-requested uploads and authorization checks. Google may process data in the United States and countries where Google operates data centers. Videos and related data retained by Google follow Google's Privacy Policy and the user's YouTube management settings. Users may decline channel authorization to avoid these transfers and continue using features that do not require YouTube connection or uploading.