Allcast
Home
PRIVACY POLICY

Privacy Policy

Denise complies with the Personal Information Protection Act and other applicable laws. Published: July 20, 2026 · Last updated: July 21, 2026 · Version v1.1

This Privacy Policy explains how the personal data of users of Allcast’s automated video-distribution service (the “Service”) is collected, used, stored, and destroyed. The Company publishes this policy at the bottom of its website so that users can review it at any time.

1. Personal data we collect

The Company collects the minimum personal data necessary to provide the Service, as follows.

CategoryItems collectedMethod
Sign-upEmail address, password (or social-login identifier), nicknameEntered by the user
Platform connectionAuthentication tokens of connected accounts (Meta, TikTok, Google/YouTube, etc.), channel/account identifiers, channel name and profile imageOAuth authentication after user consent
Content processingVideos to be distributed and their metadata (title, description, thumbnail, posting status, etc.)Retrieved via the connected account’s API
Payment (if applicable)Payment method information, payment historyCollected via a payment gateway (PG)
Automatically generatedService usage records, access logs, IP address, cookies, device/browser informationGenerated automatically while using the Service

2. Purposes of collection and use

  • Member identification and verification, and provision of membership-based services
  • Automatically adapting and distributing videos uploaded by the user to the platforms the user selected
  • Performing core features such as uploading posts and checking their status through each connected platform’s API
  • Responding to inquiries, delivering notices, and providing service-related guidance
  • Service improvement, usage-statistics analysis, prevention of misuse, and security
  • Fee settlement and payment (when using paid features)

3. Retention and use period

In principle, the Company destroys personal data without delay once the purpose of collection and use has been achieved. However, where retention is required by law, data is kept for the periods below.

  • Member information: destroyed immediately upon account withdrawal. Account records, connected-account tokens, uploaded videos and thumbnails are all deleted at the moment of withdrawal, and no separate retention period applies.
  • Records on contracts or withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
  • Records on payment and supply of goods: 5 years (same Act)
  • Records on consumer complaints or dispute handling: 3 years (same Act)
  • Access logs and other communication-fact confirmation data: 3 months (Protection of Communications Secrets Act)

The statutory retention periods above apply to transaction records that arise once paid features are in use. Authentication tokens of connected accounts are destroyed immediately when the user disconnects the account or withdraws their membership.

4. Provision to third parties

The Company does not use users’ personal data beyond the scope stated in this policy, nor provide it to third parties, except in the following cases.

  • Where the user has given prior consent
  • Where required by law, or where an investigative agency requests it under procedures prescribed by law

Posting content to the platforms the user selected for distribution (Instagram, Facebook, Threads, TikTok, etc.) is carried out at the user’s explicit instruction, and data is transmitted to those platforms only within the distribution scope the user has set.

5. Outsourcing of data processing

To provide the Service smoothly, the Company may outsource personal-data processing as follows, and reflects matters for safe management in the relevant contracts as required by law.

ProcessorOutsourced work
Vercel Inc.Web application hosting and delivery
Supabase Inc.Database, authentication and account data storage
Cloudflare, Inc. (R2)Storage of videos and thumbnails uploaded by users
Denise (support@allcast.net)Handling inquiries and sending service notices

6. Third-party platform connections

With the user’s consent, the Service connects to the APIs of external platforms such as Meta (Instagram, Facebook, Threads), TikTok, and Google (YouTube). YouTube is covered in more detail in Section 7 below.

  • The Company complies with each platform’s policies and developer terms (e.g., Meta Platform Terms, TikTok Developer Terms).
  • Data obtained through these connections is used solely to provide the automated distribution the user requested; it is never sold for advertising or transferred to unrelated third parties.
  • Users can revoke access at any time through each platform’s security settings or the “Disconnect” menu in the Service.

7. YouTube API Services

The Service uses YouTube API Services to publish videos to YouTube at the user’s request. By connecting a YouTube channel, the user also agrees to be bound by the YouTube Terms of Service. Google’s handling of personal data is governed by the Google Privacy Policy.

The Google user data the Service accesses through YouTube API Services, and how each item is handled, is as follows.

DataWhy it is neededHow it is storedWhen it is deleted
OAuth access and refresh tokensTo publish videos to the channel the user selectedEncrypted (AES) and separated by customer identifierImmediately upon disconnecting the channel or withdrawing membership
Channel name and channel identifierTo show the user which channel a video will be published to, so that publication to the wrong channel is preventedStored in the databaseImmediately upon disconnecting the channel or withdrawing membership
Publication result (video URL, status)To show the user whether publication succeeded and to allow failed attempts to be retriedStored in the databaseUpon withdrawal of membership

The Service requests only the two permissions below, which are the minimum required to provide the feature.

  • youtube.upload — publishing videos to the connected channel. This is the core function of the Service and cannot be replaced by a narrower permission.
  • youtube.readonly — reading the channel name so that the user can confirm the destination channel before publishing.

Data obtained through YouTube API Services is used solely to provide the publication the user requested. It is never sold, used for advertising, or transferred to unrelated third parties, and it is not used to train machine-learning or artificial-intelligence models. The Service does not store copies of YouTube content beyond what is described in the table above.

Revoking access. Users may revoke the Service’s access to their YouTube account at any time, in either of the following ways.

  • Select “Disconnect” for YouTube on the Settings screen of the Service. The stored tokens are deleted immediately.
  • Remove Allcast from the Google security settings page at myaccount.google.com/permissions.

8. Rights of users and legal representatives

Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal data, and may withdraw consent to collection and use by withdrawing their membership. Rights can be exercised through in-service settings or by contacting the Privacy Officer in writing or by email; the Company will act without delay.

9. Destruction procedure and method

  • Procedure: personal data whose purpose has been achieved is stored for a set period under internal policy and applicable law, then destroyed.
  • Method: electronic files are permanently deleted in a way that prevents recovery, and printouts are shredded or incinerated.

10. Security measures

  • Administrative: establishing and implementing an internal management plan, minimizing access rights, and regular training
  • Technical: access control, encrypted storage of tokens and passwords, encryption in transit (SSL/TLS), and retention of access logs
  • Physical: access control for data-processing systems

11. Use of cookies

The Company may use cookies to provide personalized services. Users may refuse cookie storage through their browser settings, in which case some services may be limited.

12. Privacy Officer and contact

For inquiries, complaints, or remedies regarding personal-data processing, please contact us below.

Privacy OfficerJeong Hyunjae (Representative)
ContactEmail support@allcast.net
Address1102, 11F, 102-dong, 70-1 Dongnip-ro, Nam-gu, Gwangju, Republic of Korea

If you need to report or consult on a privacy infringement, you may also contact the Personal Information Dispute Mediation Committee (+82-1833-6972) or the Privacy Infringement Report Center (118), among others.

13. Duty to notify of changes

If this Privacy Policy is added to, deleted, or amended, we will announce it via in-service notices at least 7 days before the effective date (30 days before for material changes).

Back to home