Privacy Policy
Last Modified: 2/26/2026
MusePilot AI ("Company") values user privacy and complies with the Personal Information Protection Act and related laws. Through this Privacy Policy, we inform users how their personal information is used and what measures are taken to protect it.
1. Personal Information Collected
We collect the following personal information for Service provision:
Required Items
- Email address
- Password (stored encrypted)
- Name (when optionally provided)
Automatically Collected Items
- IP address
- Cookies
- Access time
- Service usage history
- Device information (browser type, OS, etc.)
2. Purpose of Collection and Use
Collected personal information is used for the following purposes:
- Service Provision: Member identification, service use, AI content generation
- Member Management: Identity verification for membership services, personal identification, prevention of unauthorized use, registration confirmation, record retention for dispute resolution
- Service Improvement: New service development and customized service provision, service based on statistical characteristics and advertising, service validity verification, event and advertising information provision
- Payment Processing: Payment processing for paid services
- Customer Support: Responding to user inquiries, sending notifications
3. Retention Period
We promptly destroy personal information after the collection and use purpose is achieved. However, if preservation is required by relevant laws, we retain member information for the period specified by law as follows:
| Item | Legal Basis | Period |
|---|---|---|
| Records on contracts or withdrawal of offers | E-Commerce Act | 5 years |
| Records on payment and supply of goods | E-Commerce Act | 5 years |
| Records on consumer complaints or dispute resolution | E-Commerce Act | 3 years |
| Website visit records | Communications Privacy Act | 3 months |
4. Third-Party Provision
We do not provide user personal information to external parties in principle. However, exceptions are:
- When users give prior consent
- When required by law or when investigative agencies request through legal procedures
Third-Party Provision for Payment Processing
- Recipient: Stripe, Inc.
- Purpose: Payment processing and subscription management
- Items: Email address, payment information
- Retention: 5 years after payment completion or as required by law
5. Processing Entrustment
We entrust some tasks necessary for Service provision to external companies and regulate necessary matters in entrustment contracts to ensure safe management of personal information:
| Company | Entrusted Task |
|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure provision |
| OpenAI | AI content generation |
| Stripe | Payment processing |
6. User Rights and Exercise
Users may exercise the following rights at any time:
- Request to access personal information: You may request to view personal information held by the Company.
- Request to correct/delete personal information: You may request correction or deletion of incorrect personal information.
- Request to suspend processing: You may request suspension of personal information processing.
- Withdraw consent: You may withdraw consent to collection and use of personal information.
- Account deletion: You may withdraw through the settings menu in the Service or through customer service.
These rights can be exercised through the settings page in the Service or by written request or email to the Privacy Officer, and we will respond without delay.
7. Destruction Procedure and Method
We promptly destroy personal information after the collection and use purpose is achieved.
- Destruction Procedure: Information entered by users for membership registration, etc. is moved to a separate DB after the purpose is achieved, stored for a certain period according to internal policies and information protection reasons under relevant laws, then destroyed.
- Destruction Method: Personal information stored in electronic file format is deleted using technical methods that make records unrecoverable.
8. Security Measures
We take the following measures to ensure personal information security:
- Encryption: Sensitive information such as passwords and access tokens is encrypted for storage and management.
- Anti-hacking measures: We install security programs and regularly update and inspect them to prevent personal information leakage or damage from hacking or computer viruses.
- Access Control: We limit access rights to personal information to minimum necessary personnel.
- Secure Transmission: Personal information is securely transmitted through security protocols such as SSL/TLS.
9. Cookie Usage
We use cookies to store and retrieve usage information to provide personalized services to users.
- Purpose of cookies: Analyze user access frequency and visit times, understand user preferences and interests, maintain service usage history
- How to reject cookies: Users can set options such as allowing or blocking cookies in web browser settings. However, if you refuse to store cookies, you may have difficulty using personalized services.
10. Privacy Officer
We have designated the following Privacy Officer to oversee personal information processing matters and handle complaints and damage relief related to personal information processing:
Privacy Officer
- Department: Privacy Protection Team
- Email: privacy@musepilot-ai.com
Users may contact the Privacy Officer for all inquiries, complaints, and damage relief related to personal information protection that arise while using our Service. We will respond without delay.
11. Remedies for Rights Infringement
Users may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, KISA Personal Information Infringement Report Center, etc. for relief from personal information infringement:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Investigation Division: 1301 (www.spo.go.kr)
- National Police Agency Cyber Bureau: 182 (cyberbureau.police.go.kr)
12. Changes to Privacy Policy
If there are additions, deletions, or modifications to this Privacy Policy due to changes in laws, policies, or security technology, changes will be announced through Service notifications at least 7 days before implementation. However, significant changes affecting user rights will be announced at least 30 days in advance.
This Privacy Policy is effective from 2/26/2026.