MyangStella

Privacy Policy

MyangStella (the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act (PIPA) of Korea to protect users' personal information and promptly address related concerns.

1. Personal Information Collected

The Company collects the following personal information to provide the Service.

a. Free Service (Star Profile Card)

  • Required: Date of birth, place of birth
  • Optional: Time of birth

※ Free service data is not stored on our servers. It is computed in real-time and immediately discarded.

b. Paid Service (Astrology Reports)

  • Required: Name, date of birth, place of birth, email address
  • Optional: Time of birth, phone number, forecast start date (Transit reports)

c. Synastry (Compatibility) Report — Additional Data

  • Required: Your name or nickname and partner's name or nickname (for report display), partner's date of birth, place of birth
  • Optional: Partner's time of birth

※ Names/nicknames collected for the compatibility report are used solely to refer to each person within the report. You may use a nickname or alias instead of your real name.

d. Customer Inquiries

  • Required: Name, email address, inquiry message
  • Optional: Order number

e. Automatically Collected Information

  • IP address, browser type and version (User-Agent string), HTTP request method, response status code, access date/time, pages visited (may be automatically collected by Cloudflare and server infrastructure)

2. Purpose of Use

  • Calculating astrology charts and generating reports
  • Automatic report generation using AI (via external AI services)
  • Payment processing and identity verification
  • Sending report access links (magic links) via email
  • Processing refunds and handling customer inquiries
  • Service quality improvement and statistical analysis (after de-identification)

3. Retention Period

Personal information is destroyed without delay after its purpose has been fulfilled. Specific retention periods are as follows:

a. Service Operation

CategoryRetention Period
Free service data (birth info)Not stored (discarded immediately after real-time computation)
Paid report content (AI-generated report, chart analysis data)45 days from report creation
Order record PII (name, email, phone, birth info)5 years per the Act on Consumer Protection in E-Commerce (Article 6), then anonymised and destroyed
Email address (for magic link delivery)Delivery records deleted after report access period (45 days) expires. However, email included in order records is retained per applicable laws (see Section 3b).

b. Retention Required by Law

The following information is retained separately as required by applicable laws:

CategoryLegal BasisPeriod
Records of contracts or withdrawalAct on Consumer Protection in E-Commerce5 years
Records of payment and supply of goodsAct on Consumer Protection in E-Commerce5 years
Records of consumer complaints or disputesAct on Consumer Protection in E-Commerce3 years
Records of advertisementsAct on Consumer Protection in E-Commerce6 months
Electronic financial transaction records over 10,000 KRWElectronic Financial Transactions Act (retained by payment gateway)5 years
Service access logs (IP, access date/time)PIPA Article 29 and Safety Measures Standards1 year

4. Outsourcing of Personal Information Processing

The Company outsources the following personal information processing tasks for seamless service delivery.

Service ProviderOutsourced TasksRetention
Korea PortOne Inc.Payment integrationDuration of payment service
KG Inicis Co., Ltd.Domestic electronic payment processingDuration of payment service
Twilio (SendGrid)Report access link email deliveryUntil email delivery is complete
Cloudflare, Inc.Web hosting and CDN services (frontend)Duration of service
Railway Corp.Backend server and database hostingDuration of service
OpenAI, LLCAI report generation (API processing)Until API processing complete
Anthropic, PBCAI report generation backup (API processing)Until API processing complete

In accordance with Article 26 of PIPA, outsourcing contracts specify restrictions on processing beyond the outsourced purpose and requirements for security measures.

OpenAI and Anthropic process personal information as data processors on behalf of the Company for report generation. Only birth data (excluding real names) and chart analysis data are transmitted. For synastry (compatibility) reports, the nicknames/aliases entered by the user may also be transmitted for in-report personalization. Transmitted data is deleted in accordance with each provider's protective measures (see Section 6).

5. Third-Party Disclosure

The Company uses personal information within the scope stated in "2. Purpose of Use" and does not provide it to third parties without prior consent, except in the following cases:

RecipientPurposeData ProvidedRetention
PayPal Pte. Ltd.International payment processingEmail address, payment amountPer PayPal's own policy

※ PayPal acts as an independent data controller for payment information and processes data according to its own Privacy Policy. Users may exercise their data subject rights (access, correction, deletion) directly with PayPal.

The Company may disclose personal information when required by law or in response to lawful requests from law enforcement authorities.

6. Overseas Transfer of Personal Information

In accordance with Article 28-8 of PIPA, the Company transfers users' personal information overseas for report generation and payment processing. Such transfers are made pursuant to Article 28-8(1)(iii) (outsourcing necessary for the conclusion and performance of a contract).

RecipientContactCountryPurposeData TransferredTransfer Method
OpenAI, LLCprivacy@openai.comUnited StatesAI report generation (outsourced)Birth data (excluding real name; nicknames may be included for synastry), chart analysis dataEncrypted transmission via API at time of report generation
Anthropic, PBCprivacy@anthropic.comUnited StatesAI report generation backup (outsourced)Birth data (excluding real name; nicknames may be included for synastry), chart analysis dataEncrypted transmission via API at time of report generation
PayPal Pte. Ltd.dpo@paypal.comSingapore / United StatesInternational payment processing (third-party disclosure)Email, payment amountEncrypted transmission via SDK at time of payment
Cloudflare, Inc.privacyquestions@cloudflare.comUnited States / GlobalWeb hosting and CDN (outsourced)IP address, access informationAutomatic transmission upon service access
Railway Corp.privacy@railway.comUnited StatesBackend server and database hosting (outsourced)Birth data, email, report dataEncrypted transmission at time of order creation
Twilio Inc. (SendGrid)privacy@twilio.comUnited StatesEmail delivery (outsourced)Email address, magic link URLEncrypted transmission via API upon report completion

Data is transmitted via encrypted communication (TLS/SSL). The following protective measures are applied by each provider:

  • OpenAI: API request data is not used for model training. Storage is disabled (store=false) so data is not retained after processing.
  • Anthropic: Under its Commercial API Usage Policy, API input/output data is not used for model training and is deleted within 30 days.
  • PayPal: Maintains PCI DSS Level 1 certification and applies data protection per international standards.
  • Cloudflare: Holds SOC 2 Type II and ISO 27001 certifications, complying with global security standards.
  • Railway: Encrypts data at rest and in transit based on SOC 2 Type II certification.
  • Twilio (SendGrid): Holds SOC 2 Type II and ISO 27001 certifications. Recipient data is managed per Twilio's own retention policy after email delivery.

Opting out of overseas transfer: Users may refuse the overseas transfer of their personal information. If you refuse, AI report generation will not be possible and access to paid services will be restricted. Opt-out requests may be submitted to support@myangbytelabs.com.

7. Destruction Procedure and Method

  1. Procedure: Personal information is destroyed without delay when the retention period expires or the purpose of use has been fulfilled.
  2. Method:
    • Electronic files: Permanently deleted using irrecoverable methods (complete deletion from databases)
    • Other records: Shredded or incinerated

8. User Rights and How to Exercise Them

Users may exercise the following rights regarding their personal information at any time:

  • Right to access personal information
  • Right to correct or delete personal information
  • Right to request suspension of processing
  • Right to data portability (under PIPA Article 35-2, you may request transfer of your personal information to yourself or a third party, within the scope designated by the Personal Information Protection Commission)

How to exercise: Send a request to support@myangbytelabs.com with verification information (name, email, order number). Requests will be processed within 10 days and you will be notified of the result.

Once identity is verified, requests are processed promptly. However, information required to be retained by law will be destroyed after the mandatory retention period.

Rights Regarding Automated Decisions (Article 37-2 of PIPA)

Paid reports are automatically generated using AI (artificial intelligence). The personal information used in automated decisions and the processing procedure are as follows:

  • Personal information used: Date of birth, time of birth (optional), place of birth — this data is used to calculate an astrology chart via astronomical ephemeris (Swiss Ephemeris), and the chart analysis data is then sent to AI for report generation. Identifying information such as name and email is not sent to AI.
  • Processing procedure: Birth data input → chart calculation (server) → chart analysis data sent to AI API → AI report generation → rule-based validation (1st) + AI validation (2nd) → upon passing validation, report is stored and magic link sent

Users have the right to request an explanation of automated decisions, to object to automated decisions, and to request human intervention. Such requests may be submitted to support@myangbytelabs.com.

Withdrawing Consent

You may withdraw your consent for specific processing activities at any time by contacting support@myangbytelabs.com. Consent may be withdrawn separately for:

  • Collection and use of personal information
  • Third-party disclosure (PayPal payment processing)

Please note that withdrawing consent for collection/use may make it impossible to provide the paid Service. Overseas transfer of personal information is based on outsourcing necessary for contract performance (PIPA Article 28-8(1)(iii)) and does not require separate consent. If you wish to refuse overseas transfer, please refer to the opt-out procedure in Section 6.

9. Security Measures

The Company implements the following measures in accordance with Article 29 of PIPA and Article 30 of the PIPA Enforcement Decree to ensure the safety of personal information:

  • Administrative measures: A Privacy Officer has been designated. Personnel handling personal information are kept to a minimum, and regular privacy protection training is conducted.
  • Technical measures: Personal information is transmitted via encrypted communication (TLS/SSL). Databases are protected with infrastructure-level encryption at rest, and key authentication data (such as magic link tokens) is additionally encrypted at the application level. Access permissions are managed and regular security vulnerability assessments are conducted.
  • No payment data storage: Payment information (card numbers, CVV, etc.) is never stored on Company servers. Payment data is processed directly by the payment gateway (PG).

10. Children's Privacy

The Company does not collect personal information from children under the age of 13 (under U.S. COPPA) or under 14 (under Korean PIPA). If we become aware that a user is under 13 (or under 14 for Korean residents), any collected information will be promptly destroyed. If you believe that personal information of a child under 13 or 14 has been collected, please contact support@myangbytelabs.com and we will take immediate action.

11. Cookies and Automatic Data Collection

The Company uses the following cookies. Cookies are small data files stored in the user's browser and do not contain personally identifiable information.

  • Language preference cookie: Saves the user's language selection (Korean/English).
  • Technical cookies: Our web hosting provider (Cloudflare) may automatically set cookies for security and performance purposes (e.g., __cfruid, __cf_bm). These cookies are essential for service delivery and do not collect personal information.
  • Social sharing cookies: The Kakao JavaScript SDK is loaded for the KakaoTalk sharing feature. Kakao may set its own cookies when the sharing function is used. Such cookies are governed by Kakao's Privacy Policy.
  • Browser Local Storage: To facilitate recent order history review and report re-access, we store order identifiers (internal order ID, order confirmation code) and order summary information (product type, order date) in the browser's Local Storage. This data is not transmitted to our servers and can be deleted at any time through browser settings or developer tools. Items older than 30 days are automatically removed.
  • Browser Session Storage: During the checkout process, form data entered by the user (name, birth information, email, etc.) is temporarily stored in the browser's Session Storage. This data is automatically deleted when the tab or browser is closed and is not transmitted to our servers.
  • How to refuse: Users can disable cookies through browser settings. However, disabling cookies may cause language settings to reset on each visit or limit certain service functionality.

The Company does not sell or share personal information for cross-context behavioral advertising. As no opt-out processing is applicable, DNT and GPC signals do not trigger any additional action.

12. Privacy Officer

NameSeoyun Yang
TitleRepresentative / Privacy Officer
Emailsupport@myangbytelabs.com
Phone070-8095-2868

13. Data Breach Notification

In accordance with Article 34 of PIPA, if a personal information breach occurs, the Company will notify affected users within 72 hours. For breaches affecting 1,000 or more individuals, the Company will also report to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours. Notification will include:

  • Categories of personal information breached
  • Timing and circumstances of the breach
  • Actions users can take
  • Company's response measures and remediation procedures
  • Contact information for the responsible department

For users in the United States, the Company will notify affected individuals within the timeframe required by applicable state law (e.g., 30 days in California and New York).

14. Agencies for Personal Information Infringement Relief

If you need to report or consult about personal information infringement, you may contact the following organizations:

  • Personal Information Infringement Report Center (KISA): Phone 118 / privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee: Phone 1833-6972 / www.kopico.go.kr
  • Supreme Prosecutors' Office Cyber Investigation Division: Phone 1301 / www.spo.go.kr
  • National Police Agency Cyber Bureau: Phone 182 / ecrm.police.go.kr

15. Regional Disclosures

European Union / United Kingdom

This Service is not directed at or intended for, and does not offer goods or services to, individuals in the European Union, European Economic Area, or United Kingdom within the meaning of GDPR Article 3(2). Order placement from EU/EEA/UK IP addresses is blocked; however, general browsing of the website is not restricted. The Company does not designate an EU/UK representative under GDPR Article 27.

California (CCPA/CPRA)

The Company does not sell, rent, or share personal information for cross-context behavioral advertising as defined by the California Consumer Privacy Act (CCPA). California residents may contact support@myangbytelabs.com to exercise their rights under the CCPA, including the right to know, the right to correct, the right to delete, the right to opt-out of the sale of personal information, and the right to non-discrimination for exercising these rights. The Company will not discriminate against you for exercising any of your CCPA rights. The Company will respond to verifiable consumer requests within 45 days of receipt.

16. Changes to This Privacy Policy

This Privacy Policy may be updated due to changes in laws, policies, or services. Changes will be announced within the Service at least 10 days before the effective date.

17. Language

This Privacy Policy is provided in Korean and English. In the event of any discrepancy or conflict between the Korean and English versions, the Korean version shall prevail.

Announced: April 2, 2026
Effective: April 9, 2026