Notice. This is a reference translation provided for convenience. The Korean original is legally binding and prevails in case of any discrepancy. View the Korean original: /legal/privacy

Privacy Policy

Effective date: August 5, 2026

Notice of upcoming amendment (announced August 24, 2026): effective October 1, 2026, Section 3 (Retention and Use Period) will include a new item retaining generation request records (prompts and failure reasons) for 30 days from account deletion. See Section 3 and the Addendum for details.

1. Categories of Personal Information Collected and Methods of Collection

The Company collects the following personal information in order to provide the Service:

  • Mandatory items: social login account information (email address, nickname, profile image), date of birth (age eligibility verification), service usage records, payment records
  • Automatically collected items: access IP address and the country of access estimated from it, device information (browser type, OS), service usage records, date and time of access, visit/usage statistics and cookie-based analytics identifiers collected via a web analytics tool (Google Analytics), and sign-up acquisition information (identifiers of the advertising/search source of the visit, referrer page address, and first landing page)
  • Methods of collection: automatically collected upon social login (Kakao, Google); automatically generated in the course of using the Service; entered directly during the sign-up consent process (date of birth)

2. Purposes of Collection and Use of Personal Information

  • Membership registration and management: identity verification, verification and management of eligibility (including age) to use the Service
  • Provision of the Service: AI image generation, gallery management, credit management
  • Payment processing: processing of credit purchase payments and refunds
  • Improvement of the Service: analysis of usage statistics, enhancement of service quality
  • Customer support: responding to inquiries, resolution of disputes
  • Prevention of abuse: detection of multiple accounts, prevention of duplicate attendance check-ins

Your personal information is processed only within the scope of the purposes set out above, and is not used for AI model training.

3. Retention and Use Period of Personal Information

Personal information is retained until the User withdraws from membership, and is destroyed without delay after withdrawal. However, information that must be retained under applicable laws, and information that is kept for a set period under internal policy and then destroyed, is retained as follows:

  • Records on contracts or withdrawal of subscription: 5 years (Act on the Consumer Protection in Electronic Commerce, etc. — Korean E-Commerce Act)
  • Records on payment and supply of goods, etc.: 5 years (Korean E-Commerce Act)
  • Records on labeling and advertising: 6 months (Korean E-Commerce Act)
  • Records on consumer complaints or dispute handling: 3 years (Korean E-Commerce Act)
  • Communication confirmation data: 12 months (Protection of Communications Secrets Act)
  • Abuse-prevention records (internal policy): a one-way hash of social account identifiers is retained for 1 year after account deletion to prevent duplicate receipt of one-time benefits upon re-registration, and device identification information (browser fingerprint) is retained until the purpose of collection is achieved to prevent duplicate welcome-credit grants. These are stored only as hashes/fingerprints from which the original information cannot be reconstructed.
  • Generation request records (internal policy): the Company securely retains the prompt of an image/video generation request (as entered by the User or as finally composed by the Service) and the failure reason for 30 days from account deletion to identify abuse and to investigate generation errors and disputes, after which they are removed from our systems. Generated content such as images and videos is not retained and is destroyed immediately upon account deletion. (Applies to account deletions on or after October 1, 2026.)

4. Provision of Personal Information to Third Parties

As a general rule, the Company does not provide Users' personal information to third parties. The following cases are exceptions:

  • Where the User has given prior consent
  • Where required by the provisions of applicable laws, or where an investigative agency so requests for investigative purposes in accordance with the procedures and methods prescribed by law

5. Entrustment of Personal Information Processing and Cross-Border Transfer

The Company entrusts the processing of personal information as set out below in order to provide the Service, and part of such information is transferred overseas:

Entrusted partyEntrusted workCountry of location
Supabase Inc.Database, authenticationUnited States (Seoul region)
Polar Software, Inc.Payment processing and settlement agency services (Merchant of Record), refund processingUnited States
Dodo Payments Inc.Payment processing and settlement agency services (Merchant of Record), refund processingUnited States
Vercel Inc.Web service hostingUnited States
Google LLCSocial login (OAuth); AI prompt assembly, reference-image analysis, and caption generation (Google Gemini); web analytics (Google Analytics)United States
Cloudflare, Inc.Media storage and CDNUnited States
WaveSpeedAI PTE. LTD.Intermediation of AI image and video generation APIs (transmission of prompts and reference images)Singapore
Beijing Kuaishou Technology Co., Ltd.AI video generationChina
Alibaba Cloud Computing Co., Ltd.AI video generationChina
ByteDance Ltd.AI image generationChina
X.AI Corp.AI image generationUnited States
BFL GmbHAI image generationGermany
OpenAI, L.L.C.AI image generationUnited States
Beijing Zhipu Huazhang Technology Co., Ltd.AI image generationChina

Prompts and reference images are transmitted to the AI image and video generation providers, and are destroyed immediately upon completion of generation. Personal information transferred overseas is used solely for the purpose of providing the Service, and is managed securely in accordance with the privacy policies of the relevant providers.

For payment processing, personal information is transferred overseas as set out below (Article 28-8 of the Personal Information Protection Act).

  • Transferee: Dodo Payments Inc. (current payment processor), Polar Software, Inc. (processing existing subscriptions)
  • Items transferred: email address, order/user identifiers, purchased product information
  • Country of transfer: United States
  • Time and method of transfer: transmitted over HTTPS at the time the User requests payment
  • Purpose of use: payment processing, settlement, and refund processing
  • Retention and use period: until termination of the entrustment contract (or, where a statutory retention obligation applies, for that period)
  • How to refuse and the effect of refusal: if you do not proceed with payment, no personal information is transferred; in that case, you cannot purchase paid credits.

6. Destruction of Personal Information

Where personal information becomes unnecessary, such as upon expiry of the retention period or achievement of the purpose of processing, the Company destroys such personal information without delay.

  • Person responsible for destruction: the Personal Information Protection Officer
  • Time of destruction: upon expiry of the retention period or upon withdrawal from membership
  • Method of destruction: electronic files are deleted by a method that renders them irrecoverable, and paper documents are shredded or incinerated.

7. Users' Rights and How to Exercise Them

Users may exercise the following rights at any time:

  • Request access to their personal information
  • Request correction where there are errors, etc.
  • Request deletion
  • Request suspension of processing

The above rights may be exercised by email (contact@eclabs.kr) or in writing, and the Company will take the necessary measures within 10 days from the date of the request.

8. Notice on the Use of Cookies and Device Identification Information

  • Session cookies: used to maintain the login session.
  • Analytics cookies: cookies set by Google Analytics (such as _ga) are used to analyze visit and usage statistics. They are not essential to the Service, and their collection may be refused via the method below.
  • Acquisition analytics cookie: to analyze, in statistical form, which advertisement, search, or external page a visit came from, acquisition source information is stored in a first-party cookie (lilit_attr, retained for 30 days) on the first visit, and is kept once as part of the sign-up record upon registration. It is not provided to third parties, is not stored when the analytics opt-out below is enabled, and is destroyed upon account deletion.
  • Device identification information: a browser-based device identifier (hash value) is collected for the purpose of preventing abuse, such as preventing duplicate attendance check-ins. Only a hash value, which cannot directly identify an individual, is stored, and it is not provided to third parties.

Users may refuse the storage of cookies through their browser settings; however, in such case there may be limitations on the use of the Service. Collection of analytics cookies may be refused (opt-out) at any time via the ‘Analytics data collection’ setting on the My Page, with no impact on the use of the Service.

9. Personal Information Protection Officer

  • Name: Yunsung Choi
  • Position: Chief Executive Officer
  • Email: contact@eclabs.kr

10. Remedies for Infringement of Rights

If you need to report or seek consultation regarding an infringement of personal information, you may contact the following organizations:

  • Personal Information Infringement Report Center (KISA) — privacy.kisa.or.kr / 118 (toll-free within Korea; not dialable from overseas)
  • Personal Information Dispute Mediation Committee — www.kopico.go.kr / 1833-6972 (toll-free within Korea; not dialable from overseas)
  • Supreme Prosecutors' Office, Cybercrime Investigation Division — spo.go.kr / 1301 (toll-free within Korea; not dialable from overseas)
  • National Police Agency, Cyber Investigation Bureau — ecrm.police.go.kr / 182 (toll-free within Korea; not dialable from overseas)

11. Data Processing in AI Services

  • Prompts and reference images entered by the User are transmitted to external AI service providers for the purpose of AI generation processing.
  • Generated content is stored on a CDN (Cloudflare R2) and may be deleted by the User at any time.
  • Neither the Company nor the AI service providers use Users' data for AI model training.

12. Measures to Ensure Safety

The Company takes the following measures to ensure the safety of personal information:

  • Access control: management of access rights to personal information processing systems
  • Retention of access logs: retention of access logs of personal information processing systems for at least one year
  • Encryption: passwords and payment information are encrypted in storage and in transmission
  • Security measures: technical countermeasures against hacking, viruses, etc.

13. Notification of Personal Information Breach Incidents

Where a leakage of personal information is confirmed, the Company will notify the affected Users within 72 hours of the items leaked, the time of the leakage, the measures Users may take in response, the measures taken by the Company, and contact information for consultation. At the same time, the Company will report the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency.

14. Processing of Pseudonymized Information

The Company does not currently process pseudonymized information.

15. Notice of Changes to the Privacy Policy

Where this Policy is amended, the Company will give notice of the changes through announcements within the Service at least 7 days prior to the effective date of the amendment. Where the amendment is unfavorable to Users, notice will be given at least 30 days in advance.

Addenda

This Privacy Policy takes effect on July 30, 2026. The latest amendment takes effect on August 5, 2026.

Amendment history: August 5, 2026 — added web analytics (Google Analytics) to the entrusted tasks of Google LLC in the Section 5 table, and reflected analytics cookies and the opt-out method in the Section 1 automatically-collected items and the Section 8 cookie notice.

Amendment history: August 6, 2026 — added an entrusted party to the Section 5 table (Armitage Labs OÜ, content moderation).

Amendment history: August 10, 2026 — clarified the entrusted tasks of Google LLC in the Section 5 table to reflect actual processing (AI prompt assembly, reference-image analysis, and caption generation); notice given on August 3, 2026.

Amendment history: August 10, 2026 — removed Armitage Labs OÜ (content moderation) from the Section 5 table (the entrustment ended and the pre-screening of prompt text and request identifiers, together with the related cross-border transfer, ceased; applied immediately as a change not unfavorable to Users).

Amendment history: August 11, 2026 — added an entrusted party to the Section 5 table (Dodo Payments Inc., payment processing and settlement agency services) and added a notice of overseas transfer for payment. As providing a payment method is essential to performing the service agreement and the personal-information items transferred are the same in scope as those for the existing payment entrustment (Polar Software, Inc.), the change takes effect the same day. The existing entrustment to Polar Software, Inc. remains until the processing of in-progress subscriptions ends.

Amendment history: August 24, 2026 — specified the acquisition analytics cookie (lilit_attr) and the retention of sign-up acquisition information in the Section 1 automatically-collected items and the Section 8 cookie notice (a clarification of processing already within the existing ‘service usage records / usage-statistics analysis’ category — applied immediately as a change not unfavorable to Users; refusal follows the existing analytics-cookie opt-out setting).

Amendment history: September 11, 2026 — specified the country of access (a country code estimated from the access IP address already collected) in the Section 1 automatically-collected items (a clarification of processing already within the existing ‘access IP address / service usage records / usage-statistics analysis’ category — applied immediately as a change not unfavorable to Users; used only for statistics and operations, never to decide eligibility or pricing).

Amendment history: announced August 24, 2026 — added a ‘generation request records (internal policy)’ item to the Section 3 retention periods (retention of prompts and failure reasons for 30 days from account deletion). As a change that may be unfavorable to Users, it is announced 30 days in advance pursuant to Section 15 and takes effect on October 1, 2026. It does not apply to accounts deleted before the effective date.

隐私政策 | LILIT