SeaInStar Inc. (hereinafter the "Company") attaches great importance to the protection of the personal information of members (hereinafter "Members") who use CINSTAR (hereinafter the "Service"), the service provided by the Company. The Company makes every effort to ensure that personal information provided online to the Company by Members in the course of using the Service is protected, and complies with the personal information protection provisions of laws and regulations relating to personal information, including the Personal Information Protection Act.

The Company sets out this Privacy Policy below to inform Members of the purposes and manner in which the personal information they have provided to the Company is used, and what measures are taken to protect personal information. This Privacy Policy may be amended in accordance with changes in laws, regulations, and public notices, or in accordance with the Company's terms and internal policies. In the event of any such amendment, the Company will post the changes on the Service screen or notify Members.


Business Information


Article 1 (Purposes of Processing Personal Information)

  1. As a matter of principle, the Company collects only the minimum amount of information so that Members can retain control over their own information. The Company collects only the essential information necessary to provide the basic Service, and where separate personal information is required to provide additional services, it obtains separate consent at the time of collection. The Company will not refuse to provide the Service on the ground that a Member has not provided personal information beyond the minimum personal information.
  2. The Company processes personal information for the following purposes. The personal information being processed will not be used for any purpose other than the following purposes, and where the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
    1. Membership registration and management
      Confirmation of intent to register, maintain, or withdraw membership; identification and authentication of the individual in connection with the provision of membership-based services; maintenance and management of membership status; prevention of fraudulent use of the Service; performance of statutory obligations; management of re-registration; investigation of violations of laws and regulations and the terms of service; receipt and handling of reports of and blocking of content and users; various notices and notifications; and handling of grievances such as the receipt of complaints.
    2. Provision of the Service
      Provision of audition- and casting-related services; posting, storage, and transmission of audition videos and free-form content uploaded by Members (hereinafter "Digital IP"); recording and management of content as Digital IP; support for casting review and progress; provision of customized services; and payment and settlement.
    3. Use for marketing and advertising (optional)
      Development of new services and provision of customized services; provision of events and promotional information and opportunities to participate; statistical analysis of Service use; identification of access frequency; and the like.
  3. Separation of consent items: The Company obtains consent items separately at the time of membership registration. Confirmation of being at least 14 years of age, agreement to the Terms of Service, consent to the collection and use of personal information, and consent to the content license (the use within the Service of content such as videos uploaded by the Member) are [mandatory] items for the provision of the Service, while consent to receive marketing and promotional information (email/push) and consent to receive event and benefit notifications are [optional] items. Members may register and use the basic functions of the Service even if they do not consent to the optional items. Members may change (withdraw) their optional consent at any time after registration in the in-app settings. The specific scope of the content license is governed by Article 14 of the Terms of Service and the Digital IP Registration Consent.

Article 2 (Items of Personal Information Collected and Processed)

  1. The Company collects and processes the following items of personal information for the purposes set out in Article 1.
    Processing purposeProcessing items
    Service membership registration and managementMandatory: email address, nickname · Optional: profile photo, country of residence
    Social login (Google)Mandatory: Google account identifier (unique key), email
    Social login (Apple)Mandatory: Apple account identifier (unique key), email (including private relay email)
    Social login (Kakao)Mandatory: Kakao profile information (nickname/profile photo), Kakao account (email)
    Digital IP registration (audition videos / free-form content)Mandatory: uploaded files (videos, images, documents, etc.), content title, content description · Optional (audition): applied role, profile information
    Use and provision of the Service (optional)mobile phone number
    Advertising identifier (advertising SDK)ADID/IDFA (advertising identifier) — for iOS, only where consent is given under App Tracking Transparency (ATT)
  2. The following information may be automatically generated and collected in the course of using the Service.
    • IP address, cookies, ADID/IDFA (advertising identifier), device information (OS, device model, app version, etc.), Service usage records, access logs, payment records
    • When using the report/block features within the Service: the reason for, subject of, and date and time of the report; the subject of and date and time of the block; and other records necessary for handling reports and blocks.

Non-logged-in (guest) use: The Company provides a guest mode in which some content may be browsed without membership registration or login. When using the Service as a guest, the Company does not collect membership registration information (email, nickname, etc.) and processes only within the scope of the automatically generated information of this paragraph (access logs, device information, etc.). To use features that require login—such as sending a Cheer, commenting, applying for an audition, or uploading content—a Member must agree to this Policy and the Terms of Service at the time of membership registration.

  1. Advertising identifiers and advertising SDKs: The Company may use advertising SDKs (e.g., Google AdMob) to display advertisements within the Service (including reward-based advertisements such as "watch an ad" in missions), measure performance, and provide customized advertising, and in this process may collect and use advertising identifiers (Android ADID, iOS IDFA). For iOS, the Company collects and uses IDFA only where a Member has permitted tracking in accordance with the App Tracking Transparency (ATT) consent process. Members may refuse or reset the collection of advertising identifiers by the method set out in Article 10.
  2. The Company collects personal information by the following methods.
    1. Information entered by Members when registering for membership or using the Service through the mobile application, web pages, etc.
    2. Information entered by Members for customer center inquiries, consultations, etc.
    3. Collection of generated information through automatic collection devices and advertising SDKs.
  3. The Company may optionally request Members to enter personal information for purposes such as statistical analysis or the provision of prizes during in-Service surveys and events, and will not send promotional information unless the Member has expressly given prior consent to receive promotional information.

Article 3 (Storage, Processing, and Retention Period of Personal Information)

  1. Unless otherwise provided by law or separately agreed with the Member, or in other special circumstances, the Company retains a Member's personal information while the Member uses the Service or until the purposes set out above are achieved, and uses it for purposes such as providing the Service.
  2. As a matter of principle, a Member's personal information is destroyed without delay once the purpose of collection and use is achieved or when there is a withdrawal request from the Member or a request for destruction.
    • Content recorded as Digital IP: A record of the registration of content consists of the content hash value, the time of registration, and an anonymous identifier, and does not include personally identifying information (the original video, real name, email, etc.). Upon a Member's deletion request, the original content and personally identifying information are destroyed except where there is a statutory retention obligation, and only the registration record, from which an individual cannot be identified, is preserved. Details are governed by the Digital IP Registration Consent terms.
  3. However, the Company may retain, for six months from the date of termination of the use agreement, the relevant Member's email address, nickname, mobile phone number (where collected), and records of fraudulent use (Service usage records, access logs, cookies, access IP information) in order to prevent confusion in the Service, cooperate with investigative agencies, prevent the recurrence of fraudulent use and re-registration, and resolve disputes.
  4. Where it is necessary to preserve information in accordance with relevant laws and regulations, the Company retains Member information for the following periods, and such information is used only for the purpose of preservation.
    Basis for preservationItems preservedRetention period
    Act on Consumer Protection in Electronic Commerce, etc.Records on contracts or withdrawal of subscription, etc.5 years
    Act on Consumer Protection in Electronic Commerce, etc.Records on payment and the supply of goods, etc.5 years
    Act on Consumer Protection in Electronic Commerce, etc.Records on labeling and advertising6 months
    Act on Consumer Protection in Electronic Commerce, etc.Records on consumer complaints or dispute handling3 years
    Protection of Communications Secrets ActWebsite visit log records3 months

    In v1, the Company processes payments for paid services solely through the in-app purchase (IAP) of the App Store and Google Play, and does not directly operate an external payment gateway (PG). Accordingly, payment information such as payment methods and card numbers is processed by each store and is not retained by the Company, and the identity-verification record preservation items under the Act on Reporting and Using Specified Financial Transaction Information do not apply. The Company retains only the transaction identification information (order number, etc.) necessary for payment confirmation and refund processing, in accordance with the Electronic Commerce Act standards in the table above.


Article 4 (Provision of Personal Information to Third Parties)

  1. The Company uses a Member's personal information within the scope notified in Article 1, and does not use it beyond that scope or provide it to third parties without the Member's prior consent. However, the following cases are excepted.
    1. Where prior consent has been obtained from the Member
    2. Where required under the provisions of relevant laws and regulations (including where investigative agencies and supervisory authorities request the provision of personal information for investigation or inquiry purposes in accordance with the procedures and methods prescribed by relevant laws and regulations)
    3. In the case of a transfer of business, etc.
  2. Where the Company provides a Member's personal information to a third party, the Company informs the Member of and obtains consent to the following matters.
    • The recipient of the personal information
    • The recipient's purpose of use of the personal information
    • The items of personal information provided
    • The recipient's retention and use period of the personal information
  3. Provision of information in connection with casting: Audition videos and profile information uploaded by a Member who applies for an audition may be provided to and viewed by the Company and the production company and casting personnel of the relevant work (hereinafter "Production Company, etc.") for the purpose of casting review and progress for that work. The Company notifies the following matters for each work on the audition application screen, and a Member is deemed to consent to such provision and viewing upon applying for an audition — Recipient: the Production Company, etc. of the relevant work (as indicated in the work announcement) / Purpose of use: casting review and progress / Items provided: audition video, application profile / Retention period: until the completion of the relevant casting process. The detailed scope is governed by the Digital IP Registration Consent terms and the guidance on the audition application screen.
  4. A Member may refuse to consent to the provision of personal information to third parties and may withdraw consent to third-party provision at any time. Even if consent is refused, the Member may use the membership registration service, but the use of related services based on third-party provision (e.g., applying for an audition) may be restricted.

Article 5 (Entrustment of Personal Information Processing)

  1. For the smooth provision of the Service, the Company entrusts the processing of personal information as follows, and in accordance with relevant laws and regulations, stipulates the matters necessary to ensure that personal information is managed safely when entering into entrustment agreements. The information shared is limited to the minimum information necessary to achieve the relevant purpose.
    TrusteeEntrusted work
    Google LLC (Firebase)Member authentication, sending push notifications
    Google LLC (Google Cloud Platform)Storage and hosting of content and data (cloud infrastructure — data storage: the domestic Seoul (asia-northeast3) region)
    Google LLC (Google AdMob and other advertising SDKs)Advertisement display, performance measurement, and provision of customized advertising (processing of advertising identifiers)

    The v1 Service does not engage a separate trustee for identity verification or SMS messaging (it uses only social login and app push). When such work is introduced, it will be disclosed through this Policy in accordance with paragraph 4.

    Because payments for paid services are processed solely through the in-app purchase (IAP) of the App Store and Google Play, there is no entrustment of payment information to a separate payment gateway (PG). The processing, settlement, and refund of payment methods are subject to the policies of each store operator (Apple, Google).

  2. Overseas transfer of personal information: For the provision of the Service, the Company entrusts (transfers overseas) the processing of personal information to overseas personal information processors as follows.
    Recipient of transferCountry to which transferredDate/time and method of transferItems transferredRetention period
    Google LLC (Firebase authentication / push notifications)The United States and other countries where Google data centers are locatedTransmission over the network at the time of Service useAuthentication information such as account identifiers and email, and push tokensUntil the termination of the entrustment agreement or until the Member withdraws

    Uploaded content files and Service data (Google Cloud Platform storage and databases) are stored in the domestic Seoul (asia-northeast3) regionand do not constitute an overseas transfer. Firebase authentication and push notifications are notified as subject to overseas transfer because their region cannot be fixed due to the nature of Google's global infrastructure.

  3. When entering into an entrustment agreement, the Company specifies in documents such as the contract, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information for purposes other than the performance of the entrusted work, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of the trustee, liability such as damages, and the like, and supervises whether the trustee processes personal information safely.
  4. If the content of the entrusted work or the trustee changes, the Company will disclose this through this Privacy Policy without delay.

Article 6 (Rights and Obligations of Members and the Method of Exercising Them)

  1. Members may exercise their rights against the Company at any time, such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information.
  2. Members may view and edit their personal information at any time in the in-app Settings > Account Information.
  3. Members may at any time request the withdrawal of consent to the provision of personal information or withdrawal of membership (account deletion), and may apply directly in the in-app Settings > Withdraw Membership. When a Member withdraws consent or withdraws membership, the Company will, except where there is a retention obligation under Article 3, without delay destroy the collected personal information so that it cannot be recovered or reproduced. However, upon withdrawal of consent or deletion, the use of some or all of the related services may be restricted.
  4. Where a Member requests the correction or deletion of personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.
  5. A Member may exercise the rights under this Article through a legal representative or a duly authorized person.
  6. Requests for access to and suspension of the processing of personal information may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act, and requests for correction or deletion may be restricted where the personal information is specified as a subject of collection in other laws or regulations.
  7. Where a request is made pursuant to the rights of a data subject, the Company verifies whether the person making the request is the data subject themselves or a legitimate representative.

Article 7 (Personal Information of Children Under 14 Years of Age)

The Company does not provide the Service to children under 14 years of age and does not collect the personal information of children under 14 years of age. At the time of membership registration, the Company confirms that the Member is at least 14 years of age, and where it is confirmed that the Member is under 14 years of age, membership registration is not permitted.


Article 8 (Procedures and Methods for Destruction of Personal Information)

  1. Information entered by a Member is stored for the retention period under internal policy and relevant laws and regulations (see Article 3) after the purpose is achieved, and is then destroyed. Personal information transferred to a separate database is not used for any other purpose unless required by law.
  2. The Company destroys personal information by the following methods.
    1. Personal information printed on paper: shredded with a shredder or incinerated
    2. Personal information stored in electronic file form: deleted using a technical method that prevents the records from being reproduced
  3. The Company does not operate a separate policy of segregated storage or destruction (dormancy) for long-term inactive Members; a Member's personal information is retained until the Member withdraws membership or the retention period set out in Article 3 elapses. If a dormancy policy is introduced in the future, it will be disclosed through this Policy.

Article 9 (Technical and Managerial Protection Measures for Personal Information)

The Company takes the following measures to ensure security so that Members' personal information is not lost, stolen, leaked, altered, or damaged.

  1. Establishment and operation of a personal information protection organization, such as the designation of a personal information protection officer; establishment and implementation of an internal personal information management plan; and an annual inspection.
  2. Establishment and implementation of standards for granting, changing, and revoking access rights to the personal information processing system; operation of an access control system; minimization of personnel handling processing; and regular security training.
  3. Encrypted storage and transmission of personal information (password encryption, SSL/TLS encryption of transmission sections, etc.).
  4. Retention of access records and prevention of forgery and alteration.
  5. Installation and updating of anti-virus programs to respond to computer viruses.
  6. Installation and operation of access control devices to guard against external intrusion.

Article 10 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

  1. The Company may use cookies for Member-customized services. Cookies are used to understand the manner of Service use and to provide optimized information, and Members may refuse the storage of cookies through their web browser settings. However, if the storage of cookies is refused, there may be difficulty in using some services.
  2. The Company may collect the advertising identifiers (ADID/IDFA) of mobile app users, and Members may refuse such collection as follows.
    • Android: Settings > Google > Ads > deselect ad personalization (or delete the advertising ID)
    • iOS: Settings > Privacy & Security > Tracking > turn off Allow Apps to Request to Track

Article 11 (Personal Information Protection Officer and Responsible Department)

The Company designates a personal information protection officer as set out below to take overall responsibility for matters concerning the processing of personal information and to handle data subjects' complaints and provide remedies for damage.

Members may direct inquiries to the above officer and responsible department regarding personal information protection in connection with their use of the Service, including inquiries, complaint handling, and remedies for damage, and the Company will respond and handle them without delay.


Article 12 (Remedies for Infringement of Rights and Interests)

To obtain relief for the infringement of personal information, Members may apply for dispute resolution or consultation, etc., to the following organizations.

  1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
  2. Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
  3. Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) (www.spo.go.kr)
  4. Cyber Investigation Bureau, National Police Agency: 182 (no area code) (ecrm.cyber.go.kr)

Article 13 (Exclusion from Application of the Privacy Policy)

The Company may provide links to other companies' websites or materials through the Service. In such cases, the Company has no control over the external sites and materials, and this Privacy Policy does not apply to their collection of personal information. When moving to another site, please check the privacy policy of that site.


Article 14 (Changes to the Privacy Policy)

Where there is any addition, deletion, or change to the content of this Privacy Policy, the Company will give notice through "Announcements" at least 7 days before the amendment. However, where there is a material change to Members' rights, such as the collection and use of personal information or provision to third parties, notice will be given at least 30 days in advance.


Addendum