Privacy Policy
MyangStella (the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act (PIPA) of Korea to protect users' personal information and promptly address related concerns.
1. Personal Information Collected
The Company collects the following personal information to provide the Service.
a. Free Service (Star Profile Card)
- Required: Date of birth, place of birth
- Optional: Time of birth
※ Free service data is not stored on our servers. It is computed in real-time and immediately discarded.
b. Paid Service (Astrology Reports)
- Required: Name, date of birth, place of birth, email address
- Optional: Time of birth, phone number, forecast start date (Transit reports)
c. Synastry (Compatibility) Report — Additional Data
- Required: Your name or nickname and partner's name or nickname (for report display), partner's date of birth, place of birth
- Optional: Partner's time of birth
※ Names/nicknames collected for the compatibility report are used solely to refer to each person within the report. You may use a nickname or alias instead of your real name.
d. Customer Inquiries
- Required: Name, email address, inquiry message
- Optional: Order number
e. Automatically Collected Information
- IP address, browser type and version (User-Agent string), HTTP request method, response status code, access date/time, pages visited (may be automatically collected by Cloudflare and server infrastructure)
2. Purpose of Use
- Calculating astrology charts and generating reports
- Automatic report generation using AI (via external AI services)
- Payment processing and identity verification
- Sending report access links (magic links) via email
- Processing refunds and handling customer inquiries
- Service quality improvement and statistical analysis (after de-identification)
3. Retention Period
Personal information is destroyed without delay after its purpose has been fulfilled. Specific retention periods are as follows:
a. Service Operation
| Category | Retention Period |
|---|---|
| Free service data (birth info) | Not stored (discarded immediately after real-time computation) |
| Paid report content (AI-generated report, chart analysis data) | 45 days from report creation |
| Order record PII (name, email, phone, birth info) | 5 years per the Act on Consumer Protection in E-Commerce (Article 6), then anonymised and destroyed |
| Email address (for magic link delivery) | Delivery records deleted after report access period (45 days) expires. However, email included in order records is retained per applicable laws (see Section 3b). |
b. Retention Required by Law
The following information is retained separately as required by applicable laws:
| Category | Legal Basis | Period |
|---|---|---|
| Records of contracts or withdrawal | Act on Consumer Protection in E-Commerce | 5 years |
| Records of payment and supply of goods | Act on Consumer Protection in E-Commerce | 5 years |
| Records of consumer complaints or disputes | Act on Consumer Protection in E-Commerce | 3 years |
| Records of advertisements | Act on Consumer Protection in E-Commerce | 6 months |
| Electronic financial transaction records over 10,000 KRW | Electronic Financial Transactions Act (retained by payment gateway) | 5 years |
| Service access logs (IP, access date/time) | PIPA Article 29 and Safety Measures Standards | 1 year |
4. Outsourcing of Personal Information Processing
The Company outsources the following personal information processing tasks for seamless service delivery.
| Service Provider | Outsourced Tasks | Retention |
|---|---|---|
| Korea PortOne Inc. | Payment integration | Duration of payment service |
| KG Inicis Co., Ltd. | Domestic electronic payment processing | Duration of payment service |
| Twilio (SendGrid) | Report access link email delivery | Until email delivery is complete |
| Cloudflare, Inc. | Web hosting and CDN services (frontend) | Duration of service |
| Railway Corp. | Backend server and database hosting | Duration of service |
| OpenAI, LLC | AI report generation (API processing) | Until API processing complete |
| Anthropic, PBC | AI report generation backup (API processing) | Until API processing complete |
In accordance with Article 26 of PIPA, outsourcing contracts specify restrictions on processing beyond the outsourced purpose and requirements for security measures.
OpenAI and Anthropic process personal information as data processors on behalf of the Company for report generation. Only birth data (excluding real names) and chart analysis data are transmitted. For synastry (compatibility) reports, the nicknames/aliases entered by the user may also be transmitted for in-report personalization. Transmitted data is deleted in accordance with each provider's protective measures (see Section 6).
5. Third-Party Disclosure
The Company uses personal information within the scope stated in "2. Purpose of Use" and does not provide it to third parties without prior consent, except in the following cases:
| Recipient | Purpose | Data Provided | Retention |
|---|---|---|---|
| PayPal Pte. Ltd. | International payment processing | Email address, payment amount | Per PayPal's own policy |
※ PayPal acts as an independent data controller for payment information and processes data according to its own Privacy Policy. Users may exercise their data subject rights (access, correction, deletion) directly with PayPal.
The Company may disclose personal information when required by law or in response to lawful requests from law enforcement authorities.
6. Overseas Transfer of Personal Information
In accordance with Article 28-8 of PIPA, the Company transfers users' personal information overseas for report generation and payment processing. Such transfers are made pursuant to Article 28-8(1)(iii) (outsourcing necessary for the conclusion and performance of a contract).
| Recipient | Contact | Country | Purpose | Data Transferred | Transfer Method |
|---|---|---|---|---|---|
| OpenAI, LLC | privacy@openai.com | United States | AI report generation (outsourced) | Birth data (excluding real name; nicknames may be included for synastry), chart analysis data | Encrypted transmission via API at time of report generation |
| Anthropic, PBC | privacy@anthropic.com | United States | AI report generation backup (outsourced) | Birth data (excluding real name; nicknames may be included for synastry), chart analysis data | Encrypted transmission via API at time of report generation |
| PayPal Pte. Ltd. | dpo@paypal.com | Singapore / United States | International payment processing (third-party disclosure) | Email, payment amount | Encrypted transmission via SDK at time of payment |
| Cloudflare, Inc. | privacyquestions@cloudflare.com | United States / Global | Web hosting and CDN (outsourced) | IP address, access information | Automatic transmission upon service access |
| Railway Corp. | privacy@railway.com | United States | Backend server and database hosting (outsourced) | Birth data, email, report data | Encrypted transmission at time of order creation |
| Twilio Inc. (SendGrid) | privacy@twilio.com | United States | Email delivery (outsourced) | Email address, magic link URL | Encrypted transmission via API upon report completion |
Data is transmitted via encrypted communication (TLS/SSL). The following protective measures are applied by each provider:
- OpenAI: API request data is not used for model training. Storage is disabled (store=false) so data is not retained after processing.
- Anthropic: Under its Commercial API Usage Policy, API input/output data is not used for model training and is deleted within 30 days.
- PayPal: Maintains PCI DSS Level 1 certification and applies data protection per international standards.
- Cloudflare: Holds SOC 2 Type II and ISO 27001 certifications, complying with global security standards.
- Railway: Encrypts data at rest and in transit based on SOC 2 Type II certification.
- Twilio (SendGrid): Holds SOC 2 Type II and ISO 27001 certifications. Recipient data is managed per Twilio's own retention policy after email delivery.
Opting out of overseas transfer: Users may refuse the overseas transfer of their personal information. If you refuse, AI report generation will not be possible and access to paid services will be restricted. Opt-out requests may be submitted to support@myangbytelabs.com.
7. Destruction Procedure and Method
- Procedure: Personal information is destroyed without delay when the retention period expires or the purpose of use has been fulfilled.
- Method:
- Electronic files: Permanently deleted using irrecoverable methods (complete deletion from databases)
- Other records: Shredded or incinerated
8. User Rights and How to Exercise Them
Users may exercise the following rights regarding their personal information at any time:
- Right to access personal information
- Right to correct or delete personal information
- Right to request suspension of processing
- Right to data portability (under PIPA Article 35-2, you may request transfer of your personal information to yourself or a third party, within the scope designated by the Personal Information Protection Commission)
How to exercise: Send a request to support@myangbytelabs.com with verification information (name, email, order number). Requests will be processed within 10 days and you will be notified of the result.
Once identity is verified, requests are processed promptly. However, information required to be retained by law will be destroyed after the mandatory retention period.
Rights Regarding Automated Decisions (Article 37-2 of PIPA)
Paid reports are automatically generated using AI (artificial intelligence). The personal information used in automated decisions and the processing procedure are as follows:
- Personal information used: Date of birth, time of birth (optional), place of birth — this data is used to calculate an astrology chart via astronomical ephemeris (Swiss Ephemeris), and the chart analysis data is then sent to AI for report generation. Identifying information such as name and email is not sent to AI.
- Processing procedure: Birth data input → chart calculation (server) → chart analysis data sent to AI API → AI report generation → rule-based validation (1st) + AI validation (2nd) → upon passing validation, report is stored and magic link sent
Users have the right to request an explanation of automated decisions, to object to automated decisions, and to request human intervention. Such requests may be submitted to support@myangbytelabs.com.
Withdrawing Consent
You may withdraw your consent for specific processing activities at any time by contacting support@myangbytelabs.com. Consent may be withdrawn separately for:
- Collection and use of personal information
- Third-party disclosure (PayPal payment processing)
Please note that withdrawing consent for collection/use may make it impossible to provide the paid Service. Overseas transfer of personal information is based on outsourcing necessary for contract performance (PIPA Article 28-8(1)(iii)) and does not require separate consent. If you wish to refuse overseas transfer, please refer to the opt-out procedure in Section 6.
9. Security Measures
The Company implements the following measures in accordance with Article 29 of PIPA and Article 30 of the PIPA Enforcement Decree to ensure the safety of personal information:
- Administrative measures: A Privacy Officer has been designated. Personnel handling personal information are kept to a minimum, and regular privacy protection training is conducted.
- Technical measures: Personal information is transmitted via encrypted communication (TLS/SSL). Databases are protected with infrastructure-level encryption at rest, and key authentication data (such as magic link tokens) is additionally encrypted at the application level. Access permissions are managed and regular security vulnerability assessments are conducted.
- No payment data storage: Payment information (card numbers, CVV, etc.) is never stored on Company servers. Payment data is processed directly by the payment gateway (PG).
10. Children's Privacy
The Company does not collect personal information from children under the age of 13 (under U.S. COPPA) or under 14 (under Korean PIPA). If we become aware that a user is under 13 (or under 14 for Korean residents), any collected information will be promptly destroyed. If you believe that personal information of a child under 13 or 14 has been collected, please contact support@myangbytelabs.com and we will take immediate action.
11. Cookies and Automatic Data Collection
The Company uses the following cookies. Cookies are small data files stored in the user's browser and do not contain personally identifiable information.
- Language preference cookie: Saves the user's language selection (Korean/English).
- Technical cookies: Our web hosting provider (Cloudflare) may automatically set cookies for security and performance purposes (e.g., __cfruid, __cf_bm). These cookies are essential for service delivery and do not collect personal information.
- Social sharing cookies: The Kakao JavaScript SDK is loaded for the KakaoTalk sharing feature. Kakao may set its own cookies when the sharing function is used. Such cookies are governed by Kakao's Privacy Policy.
- Browser Local Storage: To facilitate recent order history review and report re-access, we store order identifiers (internal order ID, order confirmation code) and order summary information (product type, order date) in the browser's Local Storage. This data is not transmitted to our servers and can be deleted at any time through browser settings or developer tools. Items older than 30 days are automatically removed.
- Browser Session Storage: During the checkout process, form data entered by the user (name, birth information, email, etc.) is temporarily stored in the browser's Session Storage. This data is automatically deleted when the tab or browser is closed and is not transmitted to our servers.
- How to refuse: Users can disable cookies through browser settings. However, disabling cookies may cause language settings to reset on each visit or limit certain service functionality.
The Company does not sell or share personal information for cross-context behavioral advertising. As no opt-out processing is applicable, DNT and GPC signals do not trigger any additional action.
12. Privacy Officer
| Name | Seoyun Yang |
| Title | Representative / Privacy Officer |
| support@myangbytelabs.com | |
| Phone | 070-8095-2868 |
13. Data Breach Notification
In accordance with Article 34 of PIPA, if a personal information breach occurs, the Company will notify affected users within 72 hours. For breaches affecting 1,000 or more individuals, the Company will also report to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours. Notification will include:
- Categories of personal information breached
- Timing and circumstances of the breach
- Actions users can take
- Company's response measures and remediation procedures
- Contact information for the responsible department
For users in the United States, the Company will notify affected individuals within the timeframe required by applicable state law (e.g., 30 days in California and New York).
14. Agencies for Personal Information Infringement Relief
If you need to report or consult about personal information infringement, you may contact the following organizations:
- Personal Information Infringement Report Center (KISA): Phone 118 / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: Phone 1833-6972 / www.kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation Division: Phone 1301 / www.spo.go.kr
- National Police Agency Cyber Bureau: Phone 182 / ecrm.police.go.kr
15. Regional Disclosures
European Union / United Kingdom
This Service is not directed at or intended for, and does not offer goods or services to, individuals in the European Union, European Economic Area, or United Kingdom within the meaning of GDPR Article 3(2). Order placement from EU/EEA/UK IP addresses is blocked; however, general browsing of the website is not restricted. The Company does not designate an EU/UK representative under GDPR Article 27.
California (CCPA/CPRA)
The Company does not sell, rent, or share personal information for cross-context behavioral advertising as defined by the California Consumer Privacy Act (CCPA). California residents may contact support@myangbytelabs.com to exercise their rights under the CCPA, including the right to know, the right to correct, the right to delete, the right to opt-out of the sale of personal information, and the right to non-discrimination for exercising these rights. The Company will not discriminate against you for exercising any of your CCPA rights. The Company will respond to verifiable consumer requests within 45 days of receipt.
16. Changes to This Privacy Policy
This Privacy Policy may be updated due to changes in laws, policies, or services. Changes will be announced within the Service at least 10 days before the effective date.
17. Language
This Privacy Policy is provided in Korean and English. In the event of any discrepancy or conflict between the Korean and English versions, the Korean version shall prevail.
Announced: April 2, 2026
Effective: April 9, 2026