Privacy Policy Archive
Privacy Policy (July 16, 2026)
Effective date: 2026-07-16.
1. Controller and Scope
- This policy applies to the Myven website, landing pages, signup and authentication, dashboards, public profiles, bio links, Instagram comments and direct messages (DM) automation, sponsorship proposals, public reports, policy enforcement and appeals, customer support, service emails, product analytics, and security operations.
- Myven primarily complies with the Personal Information Protection Act of Korea and also considers other applicable privacy, consumer, e-commerce, communications, and platform rules depending on user location, payment use, or external service connections.
- Myven processes personal information only as needed to provide the service, manage accounts, operate public profiles and Instagram integrations, protect security, provide support, send service notices, improve the product, and comply with law. If a user refuses required processing or required processors, Myven may be unable to provide core features such as signup, login, public profiles, and Instagram integrations.
- Company and responsible-person information, including the controller, privacy officer, privacy request handler, address, phone, and email, is available on the Company page.
2. Purposes, Data, Retention, and Basis
- The table below summarizes the purposes, data, retention periods, and legal basis for Myven’s personal information processing.
Table: Current Myven processing inventory
| Purpose | Data | Retention | Basis / Nature |
|---|---|---|---|
| Signup, email verification, login, account management | Email, username, encrypted password, account status, email verification and password reset records, authentication provider, signup/update/deletion records | Until account deletion. One-time verification records are retained only while operationally needed after verification or expiration. Direct identifiers are deleted or anonymized when account deletion is processed. | Contract performance, security, abuse prevention |
| Google login, Google signup, existing-account linking | Myven processes the stable Google account identifier (sub), email address, Google’s email-verification state, and optional name. For Google signup, Myven stores the account identifier, email, and email-verification state; it normalizes the name only as needed to initialize the Myven display name. Returning login resolves the account by the stable identifier and does not silently change the Myven account or profile from the Google email or name. Existing-account linking stores only the account identifier and email-verification state as linked-identity information; it does not separately store or overwrite the Google email, name, hosted domain, or profile picture for that linked identity. In every flow, the raw Google-issued ID token is processed transiently for verification and is not stored. Hosted-domain information may be used transiently to determine signup eligibility but is not stored; the profile picture is neither used nor stored. Myven does not request, use, or store Google API access tokens or refresh tokens and does not use Google API authorization in this sign-in flow. | The Google account identifier and email-verification state are retained until account deletion. Email and the initial display name used for signup follow the Myven account and profile retention periods. Raw tokens and other non-stored items are not retained. | Signup, authentication, login, and user-requested existing-account linking |
| Beta signup and legacy waitlist operational history | Signup sequence, beta group, historical coupon and benefit eligibility values, invitation and notice email records for legacy waitlisted users, referral signup information | Until account deletion for legacy waitlist operations and verification of historical processing. After deletion, data is deleted or anonymized except where legal retention applies. | Service provision, operational history, signup requested by the user |
| Referral links and attribution | Referral code, referrer and referred-user relationship, referral status, creation and end records | Until account deletion. If the referrer deletes the account, the direct identifying relationship may be anonymized or disconnected. | Service feature provision, benefit administration, abuse prevention |
| Public profiles, bio links, redirects, dashboard editing | Public username, display name, profile image, public visibility, search-engine visibility setting, social links and sponsored links | Until the user deletes the item or account. Public output is hidden and direct identifiers are deleted or anonymized on account deletion. | Contract performance and user-directed publication |
| Profile images and sponsorship attachments | File management information, upload confirmation information, public URL, security scan state, expiration and attachment state | While connected to a profile or proposal. Unattached temporary files are subject to deletion after expiration. | Service feature provision, malicious file and abuse prevention |
| Instagram account connection, comments, and direct messages (DM) automation | Instagram account identifier, username, profile image, connection status, permissions, integration token, comment and DM events, automation settings, delivery results | While the Instagram connection remains active. Tokens are revoked or disabled on disconnect or deletion, while legal, security, and dispute records may be retained where needed. | User-requested Instagram automation, Meta and Instagram policy compliance, security |
| Sponsorship proposals and transactional features | Company, contact name, phone, email, budget, media channels, usage rights, deliverables, AI-generated-content permission, approval criteria, progress status, attachment information | While needed for proposal handling, disputes, and abuse prevention. Deletion requests are handled by deletion or anonymization except where legal retention or dispute handling applies. | Proposal handling, pre-contract steps, abuse prevention |
| Public reports, policy investigations, enforcement, and appeals | Report category and description, masked values and hashes of target identifiers and URLs, hashes and domain of optional reporter contact details, hashes of IP address and User-Agent, request identifier, evidence summary, enforcement, appeal, and review records | Retained for five years from report intake, then evidence and free text are anonymized unless a legal hold applies. The minimum target and state identifiers needed for an enforcement action that remains effective are retained until that enforcement ends; ended historical records are disconnected from targets and actors when the five-year period expires. | Service and user protection, abuse prevention, disputes, legal and platform-policy compliance |
| Public performance analytics and dashboard statistics | Visit, click, link movement, redirect records, visit date, page and link classification information, de-identified information for duplicate-visit detection, suspected abuse information | Retained as needed for service statistics and abuse prevention. Raw access information that directly identifies an individual is not stored. | Essential product analytics, performance improvement, abuse prevention |
| Security, incident response, and service reliability | Error type, request path, processing status, processing time, service environment information, and similar operational records | Retained as needed for security, incident response, and service reliability. Unnecessary direct identifiers are managed so they are not included in operational records. | Security, incident response, service reliability |
| Customer support, important notices, transactional emails | Email address provided by the requester, support content, handling records, send/receive/delivery status | Retained after support completion for the period needed for disputes, security, and legal compliance. | User request handling, service notices, legal compliance |
| Paid services, sponsorship contracts, revenue settlement, digital goods | Myven processes buyer name, date of birth, billing country, contact number, payment currency, default language, payment email, payment phone number, membership product, amount, currency, coupons and discounts, payment, billing, refund, PG receipt or sales slip, dispute records, PortOne and payment gateway transaction identifiers, billing key identifiers, payment status, and processing history. Myven does not directly store sensitive payment information such as full card numbers or CVC. | On account deletion, direct identifiers are anonymized or separated from the identity layer. However, transaction records that must be retained under e-commerce, tax, accounting, consumer dispute, or similar laws are retained separately under a jurisdiction-specific retention policy, then irreversibly anonymized or deleted after the retention period expires and any legal hold is released. | Contract performance, legal obligations, settlement and dispute handling |
3. Minors and Legal Representatives
- The basic Myven service is provided to Users who are at least 14 years old. Myven does not allow children under 14 to sign up for or use the Service and does not intentionally collect personal information from children under 14.
- Members who are at least 14 but under 19 are classified as minor members, and Myven restricts transactional features designated by the Company, including paid services, advertising or sponsorship contracts, revenue settlement, and digital product sales.
- Paid services, settlement, advertising or sponsorship, and similar transactional features are provided only to Users who are at least 19 years old and have completed the identity or age verification required by the Company. Myven may process the minimum verification data necessary for this purpose, such as the verification provider result, verification time, and verification status.
- If a member under 19, or a User who has not completed identity or age verification, bypasses restrictions and uses paid services or transactional features, Myven may suspend those features and take steps required for contract cancellation, refunds, settlement holds, or similar measures according to applicable law, the Terms, or a separate refund policy.
- Myven may require age verification, identity verification, or additional checks at signup or before feature use to protect minors, maintain transaction stability, and comply with law.
4. Deletion and Destruction
- When account deletion is requested, Myven disables the account, prevents login, and deletes or anonymizes direct identifiers such as email, username, name, and authentication provider identifiers.
- Public profile output, social links, sponsored links, and other public information are hidden, deleted, or anonymized. Legal retention records, dispute records, security audit records, and statistical analytics may be retained, separated, or anonymized where immediate deletion would undermine legal obligations or service integrity.
- Payment, refund, PG receipt or sales slip, and dispute records are managed across identity, transaction, evidence, and policy layers. After account deletion, user-facing access is blocked and only the minimum needed identifiers are tokenized or anonymized.
- After jurisdiction-specific legal retention periods, disputes, security needs, and legal holds end, retained transaction records are irreversibly anonymized or deleted.
- Electronic files are deleted or anonymized in a way that makes recovery difficult. Paper records, if any, are shredded or destroyed by an equivalent method.
5. Sharing
- Myven does not sell personal information. Myven does not disclose personal information to third parties except where required by law, requested or consented to by the user, or necessary to provide the service.
- If a user connects Instagram, Myven communicates with Meta and Instagram services to perform the requested automation and may exchange account identifiers, permissions, message and comment events, and delivery requests with Meta Platforms, Inc. and its affiliates.
- For sponsorship proposals, proposal details such as company, contact information, budget, deliverables, and usage rights are provided to the owner of the relevant public profile for review.
- In Google Sign-In, Google directly handles account selection, authentication, and connection information and supplies Myven with an authentication ID token after the user authorizes use of the Google account. Myven does not send Myven-held account or profile data to Google in this authentication flow.
6. Processors
- Myven may outsource the following processing to external providers to provide the service. Refusing a required processor may prevent Myven from providing the relevant feature or the service. Optional processors will be separately disclosed or consented to where required when introduced.
Table: Key processors
| Processor | Role | Type |
|---|---|---|
| Amazon Web Services, Inc. and affiliates | Service hosting, data storage, file storage, email delivery, security and incident response | Required: refusal prevents service provision |
| Cloudflare, Inc. | Cloudflare Turnstile security verification, bot detection, and public report abuse prevention (processing signals such as IP address, TLS fingerprint, User-Agent, sitekey, and origin) | Required when using the public report feature: refusal prevents non-member report submission |
| Meta Platforms, Inc. and Instagram services | Instagram account authentication, permission checks, comments and direct messages (DM) related functions requested by the user | Required when using related features: refusal prevents Instagram integration |
| PostHog, Inc. | Not currently used. If introduced, it may process usage records for product analytics, quality improvement, and feature usability analysis. | Optional |
| Google Analytics (Google LLC) | Not currently used. If introduced, it may process usage records for web and product analytics, conversion measurement, and quality improvement. | Optional |
| Email and customer support providers | Email delivery, inquiry receipt, customer support handling | Required: refusal prevents account verification, security notices, important notices, and support |
| Korea PortOne Co., Ltd. | Payment integration service provision, billing key issuance, payment authorization, billing, refunds, receipts, and dispute processing support | Required: refusal prevents paid services and transactional features |
7. Cross-Border Transfers and Direct Processing by Overseas Providers
- Myven is hosted in Korea. If Myven uses a service provided outside Korea or a product operated by an overseas provider, Myven will disclose the recipient, country, transferred data, purpose, and retention period in this policy or in the service UI.
- The direct Google Sign-In processing described below is distinct from a transfer of personal information held by Myven to Google. Google directly processes account selection, authentication, and connection information in the user’s browser and then supplies Myven with a user-authorized authentication ID token. This processing is also separate from Google Analytics, which is not currently used.
Table: Cloudflare Turnstile cross-border transfer
| Recipient and contact | Country | Data | Timing and method | Purpose | Retention | Refusal and effect |
|---|---|---|---|---|---|---|
| Cloudflare, Inc. (privacy contact: dpo@cloudflare.com) | United States and countries where Cloudflare operates its global network | IP address, TLS fingerprint, User-Agent, sitekey and associated origin, and similar security signals | Transmitted over encrypted network connections when the public report page loads security verification or a report is submitted | Distinguishing people from bots, blocking bot traffic, and improving Turnstile detection | A validation token is valid for up to five minutes after issue. Other signals are processed for the period needed under Cloudflare’s privacy policy and service terms, then deleted or anonymized. | A person may refuse by not using the report page or not completing the security check, but anonymous public report submission will be unavailable. Other rights requests may be sent through the support contact on Company. |
Table: Google Sign-In direct overseas processing and direct collection
| Overseas provider and policy | Processing countries | Data Google may directly process | Timing and method | Purpose | Retention | Refusal and effect |
|---|---|---|---|---|---|---|
| Google LLC (Google Privacy Policy) | United States and countries where Google services operate under the Google Privacy Policy | Account and authentication information such as the stable account identifier, email, email-verification state, and optional name, plus IP address, browser, device, network, origin, and security information that Google may directly process | Loading a login or signup page initializes the Google Sign-In component before the Google button is clicked and may communicate with Google resources over encrypted network connections. Existing-account linking from account settings starts only after the user explicitly selects the link action and reauthenticates with the Myven password. If Google authentication on login or signup discovers an existing Myven account, Myven confirms that account’s password before completing the link. | Rendering the Google Sign-In button and account chooser, account selection, authentication, security, and supplying Myven with the user-authorized authentication ID token | Myven does not invent a fixed period; processing follows the Google Privacy Policy and Google data-retention guidance. | Blocking Google resources in the browser or network prevents Google Sign-In, but Myven email signup and email login remain available. Merely choosing the email method after the page loads does not cancel Google communication already initiated on page load. |
Table: Other services that may involve cross-border processing
| Service | Processing | Type |
|---|---|---|
| Meta Platforms, Inc. and Instagram | Instagram account identifiers, permissions, comments, and direct messages (DM) may be processed outside Korea while providing Instagram integration features. | Required when using related features: refusal prevents Instagram integration |
| PostHog, Inc. | Not currently used. If introduced, product analytics and quality-improvement information may be processed outside Korea, and Myven will provide the required notice before introduction. | Optional |
| Google Analytics (Google LLC) | Not currently used. If introduced, web and product analytics information may be processed outside Korea, and Myven will provide the required notice before introduction. | Optional |
8. Cookies, Tracking, and Behavioral Data
- Myven may use cookies or similar technologies for language preferences, login sessions, security protection, public performance analytics, and abuse prevention.
- PostHog and Google Analytics are not currently used. If introduced, Myven will update this policy or the service UI with the collected data, retention period, opt-out or restriction method, and advertising personalization status.
Table: Tracking technologies
| Type | Data | Purpose | Restriction method |
|---|---|---|---|
| Essential cookies | Language preference information, login session information, security protection information | Language state, login session, security protection | Browser blocking is possible, but blocking essential cookies may break login, dashboard, and security features. |
| Myven first-party performance analytics | Visit, click, link movement, redirect records, page and link classification information, de-identified duplicate-visit information, suspected abuse information | Creator dashboard statistics, performance improvement, abuse prevention | Essential product analytics and security processing. Refusal may limit public profile and dashboard features. |
| PostHog if introduced | Product usage events, page movement, clicks, session replay, errors, feature usage, and other configured items | Product analytics, feature improvement, incident analysis | Browser blocking, service settings, or support request paths may be available. |
| Google Analytics if introduced | Page and event records, device and browser information, referrer, campaign, approximate location. Myven does not send direct identifiers such as email, phone, real name, or precise location. | Web analytics, conversion measurement, quality improvement | Browser cookie restrictions, Google Analytics opt-out tools, service settings, or support request paths may be available. |
9. Generative AI
- Myven currently does not process personal information in generative AI services. User-entered personal information, Instagram messages, sponsorship proposals, attachments, and dashboard data are not provided to external generative AI models or large language model (LLM) training.
- If an AI feature later processes personal information, Myven will update this policy and the service UI before launch to disclose purposes, inputs and outputs, training use, processors, cross-border transfers, opt-out rights, and deletion, correction, and suspension methods.
10. Automated Decisions
- Myven currently does not make fully automated decisions that materially affect user rights or obligations, such as credit scoring, hiring, price discrimination, or contract refusal.
- Myven automatically sends every new beta signup an activation email immediately regardless of environment or signup sequence. The user may use the account after opening the activation link and verifying ownership of the email address. Signup sequence and historical coupon or benefit eligibility values are retained for legacy waitlist operations and verification of historical processing; they are not used to determine benefit eligibility for new signups or restrict activation-email delivery. Users may request an explanation or correction through the customer support contact details on the Company page.
11. Security Measures
- Myven limits access to personal information through access controls and permission checks.
- Myven applies safeguards such as encrypted transmission, secret management, and file type and size limits.
- Myven manages service operation records and analytics records so unnecessary direct identifiers are not included.
- Public performance analytics is handled in a way that makes direct identification difficult.
- If a security incident occurs, Myven will notify, report, mitigate harm, and prevent recurrence as required by applicable law.
12. Rights Requests
- Users and legal representatives may exercise rights available under applicable law, including access, transfer, correction, deletion, suspension of processing, consent withdrawal, and requests to refuse or explain automated decisions.
- Requests can be sent through the customer support contact details on the Company page. Myven verifies the requester or authorized representative and responds within the period required by law.
- Some requests may be limited, anonymized, or handled through separated retention where legal retention, security, abuse prevention, dispute handling, transactions, settlement, tax records, or third-party rights require it.
13. Privacy Contact and Remedies
- Privacy inquiries, rights requests, complaints, and remedy requests may be sent through the customer support contact details on the Company page.
- The privacy officer, privacy request handler, and contact details are available on the Company page.
- For privacy infringement consultation or reporting in Korea, users may contact the KISA Privacy Infringement Report Center at privacy.kisa.or.kr or 118, the Personal Information Dispute Mediation Committee at kopico.go.kr, or the Personal Information Protection Commission portal at privacy.go.kr. Criminal or investigation matters may be directed to the relevant law-enforcement agency.
14. Changes and Previous Version
- This update ends the early-benefit program for new signups and clarifies that signup sequence and historical coupon or benefit eligibility values are retained only for legacy waitlist operations and historical processing records. It also corrects and clarifies disclosure of the already-active Google login, Google signup, existing-account linking, and Google’s direct overseas processing and collection. It does not add a new required purpose for existing member account data or alter existing consent records, so Myven does not require blanket re-consent from existing members. It does not introduce a new Google API authorization purpose, and Myven does not request, use, or store Google API access tokens or refresh tokens in this sign-in flow. Myven will request consent when a future feature legally requires separate consent.
- The immediately preceding policy is available in the July 15, 2026 archive.