Privacy Policy

Effective Date: October 1, 2025 · Version: 1.0

Gloryou Co. (“the Company”) collects, uses, and provides personal information based on user consent in relation to the use of the NEUME service (“the Service”). The Company guarantees the rights of users and complies with domestic laws, privacy protection regulations, and guidelines for personal information processors. This Privacy Policy provides details on how personal information is handled.

1. Collection of Personal Information

NEUME operates as a service that includes membership features, collecting the minimum amount of personal information necessary during account verification or while using the Service.

Personal Information Collected by Service Category

Account Verification (Email / SMS / LINE / Meta / Apple)

  • Required: Email address (for email verification), mobile number (for SMS verification)
  • Optional: LINE ID (where applicable)
  • Required for SNS SSO: Meta/Apple user identifier — used only to send one-time codes/verification links and link accounts

Partnership / Hospital Inquiry

  • Required: Company name, contact person, phone number, email

Hospital Contract (Hospital Member)

  • Required: Contact person, hospital name, representative name, business registration number, international patient attraction number, phone number, email, address, representative number

Identity Verification (PASS)

  • Required: Mobile number, date of birth, gender

When Using Content Services

  • Treatment / side-effect reviews (sensitive data)
  • Required: Treatment details, post-treatment photos; Optional: Pre-treatment photos

Request for Content Takedown (Identity Verification Documents)

  • Individual: Required name, phone, email, copy of ID (partially masked), power of attorney
  • Organization: Required name, phone, email, copy of ID (partially masked), business registration certificate, power of attorney

Location-Based Services

  • Location information

2. Purpose of Use

  • Identification and verification of members, confirmation of registration intent, and age verification
  • Account verification via Email, SMS, LINE, Meta, and Apple (sending one-time codes/verification links and linking accounts)
  • Handling inquiries and complaints, and delivering notices
  • Payment processing for paid services
  • Prevention of fraudulent use (e.g., account theft)
  • Marketing and advertising (with user consent) and personalized content delivery
  • Development of new services and quality enhancement
  • Statistical analysis and operational record management

3. Provision and Outsourcing of Personal Information

Provision to Third Parties

Personal information is not provided to any third party without separate consent from the user or unless required by law. Specifically, mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Outsourcing of Personal Information Processing

To provide and operate the Service efficiently, certain tasks may be outsourced to external partners. The Company supervises and manages the entrusted companies to ensure compliance with privacy protection obligations.

Entrusted companies and purposes:

  • Amazon Web Services — System hosting and management
  • Google — Verification of SNS login and account information
  • Facebook (Meta) — Verification of SNS login and account information
  • Apple — Verification of SNS login and account information
  • LINE Corporation — Customer support/communication for overseas users; SNS login/account verification
  • WhatsApp LLC — Customer support and communication for overseas users
  • Tencent (WeChat) — Customer support and communication for overseas users
  • Kakao (KakaoTalk) — Customer support and communication for domestic users
  • Instagram (Meta Platforms) — Promotion, customer engagement, and marketing communication via SNS
  • TikTok Pte. Ltd. — Promotion, customer engagement, and marketing communication via SNS

If a user refuses overseas data transfer, certain overseas communication services may be unavailable.

Per Article 26 of the Personal Information Protection Act, contracts with entrusted parties specify and enforce security, re-entrustment restrictions, and technical/managerial safeguards.

4. Retention and Destruction of Personal Information

Personal information is destroyed without delay once the purpose of collection and use has been fulfilled.

  • Electronic files: Permanently deleted using non-recoverable methods
  • Documents: Shredded or incinerated

Retention Periods by Internal Policy

  • Membership withdrawal: Retained for 30 days, then destroyed
  • Hospital listing application data: Retained for 3 years after consultation, then destroyed
  • Hospital contract data: Retained for 3 years after contract termination, then destroyed
  • Consultation application data: Retained for 3 years after completion, then destroyed
  • Records of fraudulent use: Retained for 3 years, then destroyed

Retention under Relevant Laws

  • Contract or withdrawal records — Act on the Consumer Protection in Electronic Commerce — 5 years
  • Payment and supply records — 5 years
  • Customer complaints or dispute handling — 3 years
  • Records on display/advertising — 6 months
  • Accounting and tax documents — 5 years
  • Electronic financial transaction records — Electronic Financial Transactions Act — 5 years
  • Service access logs — Protection of Communications Secrets Act — 3 months

5. User Rights and Exercise Methods

  • Edit via “Edit Profile” or “Modify Member Information” menu
  • If incorrect data is corrected, its use and provision will be suspended until completion
  • Deleted data will not be used for any other purpose in accordance with this Policy
  • Upon membership withdrawal, the user’s personal data will be deleted immediately

6. Use of Cookies

  • What are cookies? Small text files stored on the user’s device via a web browser when visiting a website
  • Purpose: To maintain user environment settings and provide customized services
  • How to refuse cookies: In your browser, e.g., Settings → Privacy → Cookies and Site Data (refusal may limit certain functions)

7. Collection and Use of Behavioral Information

  • Information collected: Visit records, activity logs, search history within the Service
  • Collection method: Automatically via cookies and tracking tools
  • Purpose of use: Service improvement and personalized advertising/content
  • Retention period: Up to 1 year, then destroyed or irreversibly anonymized

User control:

  • Android: Settings → Google → Delete Advertising ID
  • iOS: Settings → Privacy → Disable App Tracking

Contact: CS Email: neume0808@gmail.com

8. Safeguards for Personal Information

  • Encryption: Passwords and key data stored using encryption
  • Protection from hacking: Firewalls, antivirus programs, and regular backups
  • Access control: Limited access and role-based authorization for personnel handling data
  • Training: Regular privacy-protection training sessions
  • Accountability: Dedicated privacy officers and monitoring systems established

9. Processing of Location Information

The Company protects users’ personal location information in accordance with applicable laws.

  • Location data is used for search results, content recommendations, and personalized advertising.
  • Records of use or provision of location information are retained for 6 months, then deleted.
  • For children under 8 years old, processing requires written guardian consent and proof of guardianship.

Location Information Manager

  • Name: Minju Hong
  • Title: CEO
  • Email: neume0808@gmail.com

10. Personal Information Protection Officer

  • Department: Gloryou Co.
  • Chief Privacy Officer: Minju Hong
  • Privacy Manager: Minju Hong
  • Email: neume0808@gmail.com

Additional Contact Points:

  • Personal Information Infringement Report Center — privacy.kisa.or.kr / 118
  • Supreme Prosecutors’ Office Cyber Crime Division — www.spo.go.kr/ 1301
  • National Police Agency Cyber Bureau — ecrm.police.go.kr / 182

11. Notification of Policy Changes

Any changes to this Policy will be announced at least 7 days in advance (30 days for major changes) via the website or email notice.

Unless objections are raised, continued use of the Service will be deemed consent to the revised terms.

Separate consent will be obtained for any additional data collection or third-party sharing.

12. Effective Date and Revision History

  • Date of Notice: October 1, 2025
  • Effective Date: October 1, 2025
  • Version: 1.0

Currently Effective Privacy Policy

Effective Date: October 1, 2025 · Version: 1.0

隱私權政策 | Neume