| Signup, email verification, login, account management | Email, username, encrypted password, account status, email verification and password reset records, authentication provider, signup/update/deletion records | Until account deletion. One-time verification records are retained only while operationally needed after verification or expiration. Direct identifiers are deleted or anonymized when account deletion is processed. | Contract performance, security, abuse prevention |
| Google login, Google signup, existing-account linking | Myven processes the stable Google account identifier (sub), email address, Google's email-verification state, and optional name. For Google signup, Myven stores the account identifier, email, and email-verification state; it normalizes the name only as needed to initialize the Myven display name. Returning login resolves the account by the stable identifier and does not silently change the Myven account or profile from the Google email or name. Existing-account linking stores only the account identifier and email-verification state as linked-identity information; it does not separately store or overwrite the Google email, name, hosted domain, or profile picture for that linked identity. In every flow, the raw Google-issued ID token is processed transiently for verification and is not stored. Hosted-domain information may be used transiently to determine signup eligibility but is not stored; the profile picture is neither used nor stored. Myven does not request, use, or store Google API access tokens or refresh tokens and does not use Google API authorization in this sign-in flow. | The Google account identifier and email-verification state are retained until account deletion. Email and the initial display name used for signup follow the Myven account and profile retention periods. Raw tokens and other non-stored items are not retained. | Signup, authentication, login, and user-requested existing-account linking |
| Beta signup and legacy waitlist operational history | Signup sequence, beta group, historical coupon and benefit eligibility values, invitation and notice email records for legacy waitlisted users, referral signup information | Until account deletion for legacy waitlist operations and verification of historical processing. After deletion, data is deleted or anonymized except where legal retention applies. | Service provision, operational history, signup requested by the user |
| Referral links and attribution | Referral code, referrer and referred-user relationship, referral status, creation and end records | Until account deletion. If the referrer deletes the account, the direct identifying relationship may be anonymized or disconnected. | Service feature provision, benefit administration, abuse prevention |
| Public profiles, bio links, redirects, dashboard editing | Public username, display name, profile image, public visibility, search-engine visibility setting, social links and sponsored links | Until the user deletes the item or account. Public output is hidden and direct identifiers are deleted or anonymized on account deletion. | Contract performance and user-directed publication |
| Profile images and sponsorship attachments | File management information, upload confirmation information, public URL, security scan state, expiration, and attachment state. For sponsorship attachments, Myven also processes the upload account when signed in and a secret-key-based upload-source fingerprint. Myven does not retain the raw IP address as attribution data. The full fingerprint is processed only on the server, and the access-restricted operator investigation view displays only a shortened fingerprint. | Ordinary attachments are retained while connected to a profile or proposal, and unattached temporary files are deleted after expiration. For an unattached temporary file found to be malicious, Myven deletes the quarantined object after the temporary upload expires and retains the upload account, source fingerprint, and detection and deletion timestamps needed for investigation for 180 days from detection before deleting the incident row. A linked infected attachment remains quarantined with its object and infected state for the proposal retention period; 180 days after detection, Myven anonymizes the upload account and source fingerprint. | Service feature provision, malicious-file and abuse investigation, service and user protection |
| Instagram account connection, comments, and direct messages (DM) automation | Instagram account identifier, username, profile image, connection status, permissions, integration token, comment and DM events, automation settings, delivery results | While the Instagram connection remains active. Tokens are revoked or disabled on disconnect or deletion, while legal, security, and dispute records may be retained where needed. | User-requested Instagram automation, Meta and Instagram policy compliance, security |
| Sponsorship proposals and transactional features | Company, contact name, phone, email, budget, media channels, usage rights, deliverables, AI-generated-content permission, approval criteria, progress status, attachment information | While needed for proposal handling, disputes, and abuse prevention. Deletion requests are handled by deletion or anonymization except where legal retention or dispute handling applies. | Proposal handling, pre-contract steps, abuse prevention |
| Public reports, policy investigations, enforcement, and appeals | Report category and description, masked values and hashes of target identifiers and URLs, hashes and domain of optional reporter contact details, hashes of IP address and User-Agent, request identifier, evidence summary, enforcement, appeal, and review records | Retained for five years from report intake, then evidence and free text are anonymized unless a legal hold applies. The minimum target and state identifiers needed for an enforcement action that remains effective are retained until that enforcement ends; ended historical records are disconnected from targets and actors when the five-year period expires. | Service and user protection, abuse prevention, disputes, legal and platform-policy compliance |
| Public performance analytics and dashboard statistics | Visit, click, link movement, redirect records, visit date, page and link classification information, de-identified information for duplicate-visit detection, suspected abuse information | Retained as needed for service statistics and abuse prevention. Raw access information that directly identifies an individual is not stored. | Essential product analytics, performance improvement, abuse prevention |
| Security, incident response, and service reliability | Error type, request path, processing status, processing time, service environment information, and similar operational records | Retained as needed for security, incident response, and service reliability. Unnecessary direct identifiers are managed so they are not included in operational records. | Security, incident response, service reliability |
| Customer support, important notices, transactional emails | Email address provided by the requester, support content, handling records, send/receive/delivery status | Retained after support completion for the period needed for disputes, security, and legal compliance. | User request handling, service notices, legal compliance |
| Paid services, sponsorship contracts, revenue settlement, digital goods | Purchaser identifier, name, date of birth, billing country, email, phone number, order and payment information and identifiers, membership product, amount, currency, coupons and discounts, billing, refund, PG receipt or sales slip, dispute records, PortOne and PG transaction identifiers, billing key identifiers, payment status, and processing history. Myven does not receive or store card numbers, expiration dates, or CVC values; those details are processed directly in the PortOne or PG payment screen. | Six months for display and advertising records; five years for contract or withdrawal records; five years for payment and supply records; three years for consumer complaint or dispute records; five years for electronic financial transactions over KRW 10,000; and one year for transactions of KRW 10,000 or less. Where periods overlap, records are separated for the longer period and then deleted or irreversibly anonymized after expiry and release of any legal hold. | Contract performance, legal obligations, settlement and dispute handling |