Logo

Privacy Policy

Effective Date: April 30, 2026


OnomaAI Inc. ("Company") values the personal information of insertoon users and complies with applicable laws, including the Personal Information Protection Act. This Privacy Policy explains how the Company collects, uses, stores, and protects personal information.

1. Categories of Personal Information Collected

The Company may collect the following personal information while providing the service.

1) Sign-up and account use

  • Required: email address, login identifier, name or nickname, password or social login identifier
  • Optional: profile image, company name, contact information, and other information voluntarily entered by the user

2) Payment and subscription use

  • Payer identification details, payment history, order number, product name, payment amount, payment time, and payment status
  • Billing key alias for recurring payments, payment method type, masked payment method information, and payment provider information
  • Account details or additional verification information for refunds and dispute handling

3) Information collected automatically during service use

  • Access date and time, IP address, cookies, browser information, device information, operating system information, and log records
  • Projects, workspaces, uploaded files, generation history, editing history, usage records, and error logs

4) Customer inquiries and support

  • Inquirer name, email address, phone number, inquiry details, and attached materials

2. Purposes of Processing Personal Information

The Company processes collected personal information for the following purposes:

  1. User identification, confirmation of intent to sign up, account management, and identity verification
  2. Service operation, project storage and sync, and content generation and editing features
  3. Paid product payments, subscription management, coin charging, refunds, and settlement
  4. Service stability, abuse prevention, security response, and incident analysis
  5. Customer support, complaint handling, and notice delivery
  6. Event, promotion, and service improvement notices. Marketing messages that require consent will be sent only after obtaining such consent where required by law.

3. Retention and Use Period

The Company deletes personal information without delay once the collection and use purpose has been fulfilled. However, in the following cases, the Company may retain certain information for a limited period to comply with law or protect legitimate interests.

1) Internal retention standards

  • Records for dispute response and abuse prevention after account deletion: up to 30 days
  • Records related to refunds, complaints, and usage restrictions: up to 3 years
  • Security incident and access log analysis materials: up to 12 months

2) Retention required by law

  • Records regarding contracts or withdrawal of offers: 5 years
  • Records regarding payments and supply of goods or services: 5 years
  • Records regarding consumer complaints or dispute resolution: 3 years
  • Records regarding 표시·advertising matters: 6 months
  • Communication confirmation data such as login logs: the period required by applicable law

4. Provision to Third Parties

As a rule, the Company does not provide users' personal information to outside parties. Exceptions may apply in the following cases:

  1. When the user has provided prior consent
  2. When required by law or to comply with legal obligations
  3. When provision to payment providers or related institutions is necessary within the minimum scope required for payment, refund, or settlement

5. Outsourcing of Personal Information Processing

The Company may outsource certain tasks to specialized external providers for smooth service operation.

CategoryTrustee or CategoryOutsourced Task
Cloud infrastructureAmazon Web Services and similar providersServer operation, file storage, backup, and security
Payment processingPortOne, KakaoPay, Toss Payments, and similar providersOne-time payment, recurring payment, payment verification, and refund handling
Customer support and communicationEmail, collaboration, and notification service providersInquiry handling and notice delivery

The Company enters into contracts with outsourced providers and supervises them to ensure personal information is processed safely.

6. User Rights and How to Exercise Them

Users may exercise the following rights at any time regarding their personal information:

  1. Request access to personal information
  2. Request correction or deletion of personal information
  3. Request suspension of processing
  4. Withdraw membership or consent

Users may exercise these rights through service functions or the contact point below, and the Company will respond without undue delay in accordance with applicable law.

7. Destruction Procedures and Methods

  1. The Company deletes personal information without delay when the retention period expires or the processing purpose is achieved.
  2. Electronic files are deleted using technical measures that prevent restoration or reproduction.
  3. Paper documents are destroyed by shredding or incineration.

8. Measures to Ensure Security

The Company implements the following measures to protect personal information:

  1. Minimization and management of access rights
  2. Retention of access logs and prevention of tampering
  3. Encryption at rest or in transit where appropriate
  4. Security programs, vulnerability reviews, and access control systems
  5. Employee privacy and security training

9. Use of Cookies

The Company may use cookies for login persistence, usage environment analysis, and service improvement. Users may reject cookie storage through browser settings, but some service functions may become unavailable.

10. Children's Personal Information

As a rule, the Company does not knowingly collect personal information from children when legal guardian consent is required by law. If necessary, a separate guardian consent process will be established.

11. Chief Privacy Officer and Contact

The Company has designated the following department and contact information to protect personal information and handle related complaints.

[Chief Privacy Officer]

  • Department: Management Support Team
  • Name: Kim Jeong-a
  • Email: contact@onomaai.com
  • Organization: OnomaAI Inc.
  • Phone: 070-4130-0221
  • Address: Room 201, Building D, Huigyeong Foundation, 39 Maeheon-ro 8-gil, Seocho-gu, Seoul (Yangjae-dong)

Users may contact this point of contact regarding all privacy-related inquiries, complaints, and damage relief arising while using the service.

12. Remedies for Rights Infringement

If you need to report or consult about a personal information infringement, you may contact the following organizations:

  • Personal Information Infringement Report Center (www.cyberprivacy.or.kr, phone: 02-1336)
  • Privacy Mark Certification Committee (www.eprivacy.or.kr, phone: 02-580-0533)
  • Supreme Prosecutors' Office Cybercrime Investigation Division (cybercid@spo.go.kr / 02-3480-3571)
  • Korean National Police Agency Cyber Terror Response Center (www.ctrc.go.kr / 02-392-0330)

13. Notice of Changes

If this Privacy Policy is added to, deleted from, or modified, the Company will provide notice through the service or related notice pages at least 7 days before the revision takes effect.

Supplementary Provision

This Privacy Policy takes effect on April 30, 2026.