Privacy Policy
This English version is a reference translation provided for convenience. The Korean original prevails, and the service is governed by the laws of the Republic of Korea. (이 문서는 한국어 원문을 기준으로 하며, 대한민국 법을 따릅니다.)
The Operator of Starpl (hereinafter "the Operator") establishes this Privacy Policy to protect members' personal information in accordance with the Personal Information Protection Act (PIPA) and other applicable laws, and to inform members of related matters. Starpl's basic stance is simple — we collect only what is necessary, we do not use your information for advertising or tracking, and the Operator does not access posts you set to "only me".
1. Personal Information Collected and Collection Methods
| Category | Items | Collection method |
|---|---|---|
| Registration (required) | Email address, password (for email sign-up — stored only as a one-way hash), starname, nickname | Sign-up form |
| Registration (optional) | Birth month and day (when choosing a star by birth constellation — year is not collected), time zone, display language | Sign-up form / settings |
| Social login | Provider (such as Kakao or Google) and information needed for social sign-in, such as the provider's member ID | From the provider upon social login |
| Automatically collected | Session cookie (to maintain login), server access logs (IP address, request logs), sign-in device info (browser, device type, access country — to show your signed-in devices; deleted when the session ends) | Automatically generated during service use |
| Generated through use | Posts (posts, comments, guestbook entries, etc.), images attached to posts and profile photos (re-encoded before storage, which strips EXIF metadata such as GPS location. If a feature to keep it is offered in the future, the metadata is stored as is when a member chooses to keep it; profile photos also go through AI screening before being applied), star friend relationships and friend tags, interest subscriptions, empathy, profile avatar (style and seed), notifications, push notification subscriptions (only when you turn them on for a device — the device-specific delivery address your browser created, its encryption keys, and the device language), report and inquiry history, moderation history, automated first-pass screening records for what others can see | Member's service use |
- To prevent duplicate registrations, we also store a normalized version of your email address (removing dots and aliases).
- Visit counts on star pages are counted by day only using an anonymous hash that cannot identify an individual. Who visited is not stored.
2. Purposes of Processing
- Member management: account creation, login, email verification, etc.
- Account security: reviewing your signed-in devices and remotely signing out unfamiliar sessions
- Service provision: posts, star map, star friends, notifications, etc.
- Safe operation: report handling, rights-infringement takedown notification (Article 44-2 of the Network Act), moderation, etc.
- Automated first-pass screening of what others can see — a supplementary tool to filter illegal or harmful content before human review. Posts set to "only me" are not subject to screening, and screening is performed entirely within the Operator's own (local) systems (§8).
- Prevention of duplicate registrations and misuse (including blocking automated (bot) sign-ups with Cloudflare Turnstile at registration)
- Handling inquiries
We do not use collected personal information for any purpose beyond the above, and we do not use it for advertising or behavioral tracking.
3. Retention Period
| Item | Retention period |
|---|---|
| Member information | Until withdrawal. Withdrawal can be requested directly from Account Settings. After a 30-day grace period, the account and associated records (posts, comments, guestbook entries, friend relationships, notifications, stardust) are permanently deleted. During the grace period, you may log back in to cancel the withdrawal. The withdrawn starname is reserved and cannot be reused; after deletion, you may sign up again with the same email address. |
| Post revision history (pre-edit versions) | When you edit a post, the version from just before the edit is kept alongside it (title, body, visibility, tags, mood, folder, date, and the list of photos attached at that time). It exists so you can look back at earlier versions, and only the author can see it. It is retained for as long as the post itself — deleting a post folds its revision history away with it, and on withdrawal it is permanently deleted after the 30-day grace period described under "Member information" above. Photo files follow their own deletion schedule, so a photo removed from a post may remain in the older versions by name only. |
| Unverified email registration information | May be deleted after 7 days from registration. |
| Notifications | Read notifications are automatically deleted after 90 days. |
| Reports, moderation, audit logs, inquiries, and automated first-pass screening records | Retained even after withdrawal for dispute resolution and legal obligations; the standard retention period is 3 years, taking into account related disputes and legal requirements. Records are deleted without delay once the retention basis no longer applies. Records of automated first-pass screening of what others can see (classifications and reasoning) are also retained as part of the same operational records; screening is performed within the Operator's own (local) systems. |
| Server access logs | IP addresses and request logs generated during server access are not permanently stored in the application database. If retention is legally required, they are retained for that period; otherwise, for the minimum period necessary for operations and security (up to 3 months). |
4. Disclosure to Third Parties
The Operator does not provide members' personal information to third parties. Exceptions apply when a lawful request is received from an investigation agency or other authority pursuant to applicable law.
5. Outsourcing and Cross-Border Transfer
The following external infrastructure is used for service operations, and some information passes through systems of businesses located outside Korea in the process. Transferred information is encrypted in transit (HTTPS for the web, SMTP TLS for email), and cross-border transfer is disclosed through the table below (recipient, purpose, information passed) in accordance with Article 28-8 of the Personal Information Protection Act. Transfer occurs at the time of service use and whenever it is needed in the course of operating the Service, by transmission over an information and communications network.
| Recipient | Purpose | Information passed |
|---|---|---|
| Cloudflare, Inc. (USA) | Traffic relay and security (CDN, tunnel) | Communication data during access |
| Cloudflare, Inc. (USA) | Blocking automated (bot) sign-ups at registration (Turnstile) | IP address and browser environment signals at the time of a sign-up attempt — used by Cloudflare to determine whether the request is human; the Operator receives only the verification result (pass/fail) |
| Cloudflare, Inc. (USA) | Backup file storage (R2 storage) | Encrypted database backup files — encrypted with a public key that only the Operator can unlock before storage; Cloudflare cannot read the contents |
| Zoho Corporation Pte. Ltd. (Singapore; data stored in a United States data center) | Email delivery (verification and notification emails) | Email address, email body |
| Cloudflare, Inc. (USA) | Receiving and forwarding inquiry email (Email Routing) | The sender's email address and the subject and body of the message |
| Google LLC (USA) | Email delivery and mailbox storage | Email address, email body |
| DiceBear (api.dicebear.com · USA) | Profile avatar image generation | Avatar seed (starname + number) — once the Operator's server has retrieved and stored it, it is not sent again |
| NASA SkyView (skyview.gsfc.nasa.gov · USA) | Retrieving the sky photograph (survey image) shown on the star certificate | The star's coordinates (right ascension and declination) — nothing that identifies a person is sent, and once the Operator's server has retrieved and stored the image for a star, it is not sent again |
| Browser vendors' push services (Google, Mozilla, Apple and others · USA) | Delivering push notifications — only when you have turned them on yourself on a device | The device-specific delivery address your browser created (the subscription endpoint) and the encrypted notification body — only that device can open the body, so the delivering service cannot read its contents |
- Contact details for each recipient's data protection point of contact are published by that business in its own privacy policy.
- Each recipient retains the information only for as long as the purpose above requires, and destroys or returns it once that purpose ends.
- If you do not want these transfers, you may stop using the Service by closing your account. The transfers above are necessary to provide the Service, so individual items cannot be refused separately while you continue to use it.
6. Rights of Data Subjects
- Access and export: You may view your records at any time and export them as a file using the export my records feature in star management.
- Correction: Records and profile information can be edited directly.
- Deletion: Records can be deleted directly, and account deletion (withdrawal) can be requested from Account Settings.
- Restriction of processing / withdrawal of consent: Submit a request via the inquiry form, and we will process it without delay in accordance with applicable law.
7. Deletion
Personal information that has exceeded its retention period or whose processing purpose has been achieved is deleted without delay. Electronic files are deleted in a manner that prevents recovery. Upon withdrawal, all data is deleted in batch after a 30-day grace period; records required to be retained for legal or dispute purposes — such as reports, moderation, audit logs, and inquiries — are excluded from deletion (see §3 table). Comments and guestbook entries left on other members' stars are deleted together; where replies exist, only the space may remain with the content removed. Pre-edit versions of posts (revision history) are deleted along with the posts.
8. Security Measures
- Passwords are stored only as one-way hashes; the original text is not retained.
- All communications are encrypted in transit (HTTPS for the web, SMTP TLS for email).
- Posts set to "only me" are not accessed by the Operator or the automated screening. However, once a report is filed, its target may be subject to the Operator's review and to automated classification regardless of its visibility (a post visible to star friends, a private guestbook entry, and so on), to the extent needed to handle that report — posts set to "only me" cannot be reported, so they remain outside this as well. All moderation actions are recorded in audit logs.
- Automated first-pass screening of what others can see — Anything a member leaves on the Service that others can see may undergo automated classification to filter illegal or harmful content before human review. Content previously kept private also becomes subject to screening from the moment its visibility is widened so that others can see it; if it is later made private again, the screening records left in the meantime are retained under the criteria in §3. This screening is performed entirely within the Operator's own (local) systems, and records are not sent to any external party for screening purposes. Content classified as an apparent violation may be temporarily hidden until a human review is completed (the author can still see it), and the final decision on hiding, removal, or restoration is made by a human. Automated classification may be imperfect and is used only as a supplementary tool.
- AI assistance and private posts — Separately from the automated first-pass screening above, the Service's AI does not read a member's private ("only me") posts on its own. The Service offers assistive features that help the member themselves — such as spelling suggestions and tag suggestions. Such a feature may read the member's private posts only if the member turns it on and explicitly consents (off by default; it can be turned off at any time), and the content is processed only for that feature within the Operator's own (local) systems and is not sent to any external party.
- The administration panel is protected by separate access controls.
9. Cookies
The service uses only a session cookie for maintaining login and a language cookie (starpl_lang, kept for 1 year) that remembers your display language. Advertising, analytics, and tracking cookies are not used. You may disable cookies in your browser settings, but this will prevent you from using features that require login.
10. Children Under 14
The service is intended for users 14 or older, and we do not collect personal information from children under 14. At registration, you are required to self-confirm that you are 14 or older (by checking a box). If the laws of your country of residence require a higher minimum age, those requirements apply (see Terms of Service, Article 4). Since we collect only the month and day of your birthday — not the year — the service does not hold any information that would allow us to determine a member's age.
11. Privacy Officer
Privacy Officer: the Starpl Operator (as a sole-operator service, the Operator serves as the Privacy Officer pursuant to Article 31(2) of the Personal Information Protection Act (PIPA)) · Contact: Inquiry (login required) or email [email protected]
For reports and consultations regarding privacy infringement, you may also contact the Korea Internet & Security Agency (KISA) privacy report center (privacy.kisa.or.kr, 118).
12. Notice of Changes
If this policy changes, notice will be given within the service at least 7 days before the effective date. For significant changes — such as to the items collected or processing purposes — notice will be given at least 30 days in advance, with a separate system notice.