Moyeo policies

Effective 2026-09-29

Privacy Policy

Explains what information the Moyeo website and in-app features operated by Redband process, why, and how it is managed.

This English version is provided for convenience only. If there is any discrepancy between the English and Korean versions, the Korean version prevails.

1. Information We Process and Why

ContextItemsPurpose and legal basisRetention
Email sign-up and sign-inEmail, one-way hash of the password, display name, email verification statusAccount creation, authentication and management; performance of contractUntil deletion upon account deletion
Google and Kakao sign-inAccount identifier for each provider, email, display name, profile image URL, link historyProviding the chosen sign-in method and linking accounts; performance of contractUntil deletion upon unlinking or account deletion
Account settingsProfile image you upload yourself, language and time zone settingsDisplaying your profile and personalized display; performance of contractUntil changed or deleted, or until account deletion
Terms acceptanceVersion of the terms accepted and policies acknowledged, time of acceptance, your self-declaration that you are 18 or olderConfirming sign-up conditions and managing the application of the termsUntil deletion upon account deletion
WorkspaceName, member identifiers and roles, invitation emails, channel access permissions and activity historyCollaboration and permission management; performance of contractAccording to workspace use and deletion and the account deletion procedure
Content creation and schedulingBody text, images and videos, per-channel settings, scheduled time and time zone, publishing resultsSaving, previewing, scheduled publishing and progress notifications; performance of contractUntil you delete it or the workspace is deleted. When a channel is disconnected, that channel's schedules and publishing results (platform post identifiers and links) are deleted while body text, photos and videos remain. Photo and video originals follow the retention periods in Section 2
Social channel connectionChannel identifier, name, handle, bio and profile image, granted permissions, access and refresh tokensVerifying the selected channel and maintaining authenticationUntil the channel is disconnected or a related deletion request is processed
Viewing comments, mentions and performancePost/video identifier, description and preview, comment and mention text, author display information and attachments, reply and handling status, views, reactions, followers, and age range, gender and region aggregates provided by the platformHandling comments and mentions on connected channels and displaying performanceFor the period needed while the connection is maintained. Cleaned up upon disconnection or deletion request. Platform-specific storage limits apply
Comment auto-reply settingsAuto-reply name, keywords, reply and Send DM text, selected post scope, times turned on and off and the member who did soRunning the auto-replies you turn on; performance of contractUntil deleted, or until the channel is disconnected or the workspace is deleted
Comment auto-reply historyIdentifiers of comments and mentions containing keywords, identifiers of sent replies and DMs, handling results and reasons for skippingDisplaying execution results and preventing duplicate sendingFollows the comment history period. Mention records are kept for 30 days or less
DM auto-reply settingsAuto-reply name, keywords, reply text, times turned on and off and the member who did soRunning the DM auto-replies you turn on; performance of contractUntil deleted, or until the channel is disconnected or the workspace is deleted
DM auto-reply historyMessage identifier, sender, text and sent time of received DMs (kept encrypted only until processed, deleted within 24 hours at the latest), matched keyword, non-reversible digests of the sender and message, handling results and reasons for skippingChecking keywords, displaying execution results and preventing duplicate sendingDM text and sender identifier are deleted immediately after checking (within 24 hours at the latest); records are kept for 30 days
Paid subscription and paymentPlan and number of channels used, billing period, amount and currency, invoices and payment status, last four digits of the card, payment method identifier issued by the payment processor (billing key)Performance of the paid subscription contract, payment and refund processing, retention of transaction recordsAfter the subscription ends, according to the statutory retention periods below. The billing key is destroyed when the payment method is removed
NotificationsIdentifier of the user receiving the notification, notification type and target post or workspace, read time, notification settingsInforming you of the results of tasks you requested; performance of contractIn-app notifications are deleted automatically when the history period expires. Notification email sending records are deleted 30 days after sending
Notification email sendingRecipient email address and body (stored encrypted), template type and language, sending status and error code, unsubscribe, bounce and spam complaint resultsDelivering notification emails, identifying causes of failure and preventing resendingDeleted 30 days after sending
Browser push notification subscriptionPush subscription information issued by the browser (endpoint and encryption keys, stored encrypted), service domain of the subscription endpoint, browser and operating system type, registration time and last delivery timeDelivering notifications to devices you have turned on yourselfDeleted immediately when you turn it off on the device or delete your account. Subscriptions expired or revoked by the browser are discarded as soon as a delivery failure is confirmed, and the record of that fact is deleted after 30 days
Authentication, security and incident responseAccess time, request path and IP, browser and operating system information, session and device identifiers, security digests of partial IP/user agent, security activity recordsKeeping you signed in, device management, new-device sign-in notices, blocking misuse and incident responseDuring account deletion, authentication information and device display information are removed. Security activity records are managed with information that directly links users, sessions and access environments reduced, and records of event type, time, handling result and pseudonymous identifiers may remain. Server access and error logs are rotated within limited storage capacity, oldest first.
Service usage analytics (optional)Browser analytics identifier, categorized page type, sign-up button location, allowed referral campaign, browser and device categoryImproving visits, referrals and feature use; enabled by default; collection can be limited through browser controls or Google’s opt-out toolYou can limit collection through browser controls or Google’s opt-out tool. Analytics cookies can be deleted in your browser. You can request deletion of records already transmitted via the support email.
Technical errors and operational alertsError classification, code location and release version; account identifier, masked email, name and browser and operating system category of the signed-up account; paying workspace, invoice identifier, plan and amount. Emails notifying the operator of inquiries and plan requests contain the sender's email address and display name as-is so the operator can reply. Incident alert emails contain no personal informationIdentifying causes of incidents and confirming sign-up, payment and inquiry operations. Where configured, Sentry, an access-restricted Discord channel, and the operator mailbox (Google Workspace) are usedEncrypted bodies for Discord delivery are deleted when delivery ends, and undelivered bodies are kept for up to 24 hours. The ledger row recording delivery is kept for 30 days thereafter and then deleted. Errors and alerts delivered to external services and the operator mailbox are managed separately according to each service's retention and deletion settings.
InquiriesIdentifier and workspace of the user making the inquiry, inquiry type (account, payment, plan, channel connection, publishing, scheduling, error report, feature suggestion, other), inquiry text (at least 10 and up to 2000 characters), the screen from which the inquiry was sent, browser information, service release version and request identifier, time receivedReviewing and answering inquiries; performance of contract or action upon requestDeleted 3 years after the date received. Records of consumer complaints and disputes follow the statutory period below
Account deletion and cancellation survey (optional)The reasons you select and follow-up answers (the service you are moving to, features you needed, difficulties you had), whether you would use Moyeo again, free-text comments (stored encrypted), and your plan and billing cycle at the time of cancellationUnderstanding why users delete their accounts or cancel subscriptions in order to improve the service. Submitting the survey is voluntary and optional3 years after submission, free-text comments and the link to the respondent are deleted to anonymize the response, and only anonymous reason statistics are kept. On account deletion, the link to the respondent is removed immediately
Plan requestsIdentifiers of the requesting workspace and requester, requested plan and billing cycle, number of channels to be used, accompanying note (up to 500 characters), request status and processing timeReceiving and processing usage requests before payment is enabled; performance of contractWhile the workspace is maintained after the request is processed. Where it constitutes a transaction record, the statutory period below applies
Receiving promotional emails (optional)Email address registered to the accountSending promotional emails such as introductions to Moyeo's features and services and events and promotions; separate optional consent (Article 15(1)(i) of the Personal Information Protection Act)From the time of consent until consent is withdrawn or the account is deleted
Email subscription settings and change historyUser identifier, whether email is allowed or refused, notice version, time and channel of changeManaging subscription settings you request, confirming choice history and applying opt-outsKept while the account is maintained and deleted in the deletion procedure upon account deletion. Change history after withdrawal is not used for sending advertisements

Social channel information is received within the scope you allowed on the official authorization screen. If photos or posts contain other people's personal information, please make sure you have the right to post or share it. Moyeo does not receive your Instagram, Threads or YouTube account passwords. Features that do not depend on an optional profile photo or social channel connection can be used without them.

When sending an inquiry, you do not re-enter your email address. The email address and display name used for replies are not stored in the inquiry record; they are read from your signed-in account information and included only in the notification email sent to the operator. The screen and browser information sent with the inquiry text are used to re-check the same issue and are kept for only 3 years, even after the inquiry has been answered.

The reason survey shown when you delete your account or cancel a subscription is optional and is used to improve the service; your account deletion or cancellation proceeds even if you do not submit it. Free-text comments are stored encrypted, and 3 years after submission we delete the free-text comments and the link to the respondent, keeping only anonymous reason statistics. When you delete your account, we immediately remove the link between your responses and your account.

Moyeo does not collect personal information of children under 14. At sign-up we receive your self-declaration that you are 18 or older, and if we learn that a child under 14 has signed up, we delete the account and information after verification.

Use of personal information for marketing purposes and receipt of promotional emails are optional, and you can use the service without consenting. You can withdraw at any time in account settings. We currently do not send promotional emails, but we provide the ability to choose and change whether to receive them. For details, see the Marketing and Promotional Email Notice.

2. Retention Period and Destruction

Personal information is destroyed without delay once the purpose of processing has been fulfilled. Deleting an account deletes the linked posts, media, comments, statistics, AI suggestions and authentication data, and disconnecting a channel deletes that channel's scheduling and publishing records, comments, statistics, AI suggestions and authentication data, in sequence, so the time of receipt and completion may differ. Posts written in Moyeo remain after a channel is disconnected, and their photos and videos remain in the library and follow the file retention rules below. However, to enforce the plan's channel limit, the record showing which channels a workspace first connected (workspace identifier, provider and channel identifier, time of first connection) remains even after the channel is disconnected, for as long as the workspace is maintained.

Photos and videos you upload are kept while they are attached to a post or used by a schedule, workspace or profile. Files not used anywhere are deleted after 7 days, and files that failed inspection are deleted after 1 day. After publishing ends, the original of a file is kept for the retention period of the workspace's plan (Free 30 days, Pro 90 days, Team 180 days) from the day its last publishing ended, and then deleted. After the original is deleted, the preview is kept for as long as the publishing record remains. When a channel is disconnected, we release the usage marks from that channel's schedules and publishing, and these rules apply from then on. Deleting an original does not delete posts already published to Instagram, Threads or YouTube.

Records Retained Under Law

When records constituting electronic commerce arise, they are kept for the following periods and managed separately from general service use purposes (Article 6 of the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce).

  • Records of labeling and advertising: 6 months
  • Records of contracts or withdrawal of subscription: 5 years
  • Records of payment and supply of goods, etc.: 5 years
  • Records of consumer complaints or dispute resolution: 3 years

Retention is limited to the records needed to verify the relevant transaction or dispute. Not every activity record of every member is kept for the same period.

Destruction Procedure and Method

  • Time of destruction: Information is destroyed when the retention period ends or the purpose of processing has been achieved, or when you request deletion and verification is complete.
  • Destruction procedure: After identifying the information to be destroyed, it is destroyed with the confirmation of the Chief Privacy Officer, and the result is recorded.
  • Electronic files: Deleted from databases and storage, or identifying information is removed, so that it cannot be recovered or reproduced. Items stored encrypted are deleted together with their ciphertext.
  • Printed materials: If paper documents or similar are produced, they are shredded or incinerated.
  • Backups: Information remaining in disaster recovery backups disappears as the backups rotate once the retention period below has passed.

Database backups for disaster recovery are kept for 7 days and then deleted automatically, and are never used for any purpose other than recovery.

3. Provision to Third Parties

Redband does not provide personal information to third parties without your consent or a legal basis. When you request tasks such as posting, replying or deleting, or turn on auto-reply, we provide content and identifiers to the relevant platform as described below to carry out that request. This is provision to a third party at your request, and since all recipients below are overseas businesses, their country, retention period and how to refuse are also disclosed in the cross-border provision table in §5. Processing and deletion after provision are governed by each platform's policies.

RecipientPurpose of provisionItems providedRetention and use period
Meta Platforms, Inc. (Instagram, Threads)Publishing posts you request, writing and deleting replies, comment, mention and DM auto-replies, viewing performancePost text and media, target account and post identifiers, reply text, DM text sent by comment auto-replies, reply text of DM auto-replies and the recipient identifier, reply text to mentions, settings values needed for the requestAccording to the platform's policies
Google LLC (YouTube)Shorts uploads you request, viewing and replying to comments, viewing performanceVideo file and upload settings such as title, description and visibility, target channel and video identifiers, reply textAccording to the platform's policies

If you do not want this provision, you can choose not to request the task or disconnect the channel. Once disconnected, posting and comment tasks for that channel are not provided. Redband does not sell user data and does not provide data from connected channels for third-party ad targeting.

3-2. Information Processed on Your Behalf

For comments, replies and mentions on channels you have connected and their authors' display names and account identifiers, replies and DMs sent by comment auto-reply and their results, and received DMs checked and replies sent by DM auto-reply (hereinafter "commenter information"), you are the personal information controller and Redband processes it as entrusted by you. This relationship follows Article 5-4 of the Terms of Service.

The information processed on your behalf and its purposes and retention are as follows.

  • Comment and reply text on connected channels and the author's display name and account identifier: used for viewing comments, replying, comment auto-replies and displaying performance. Follows the comment history period and is deleted when the channel is disconnected.
  • DM text, sender identifier and sent time of DMs received on channels with DM auto-reply turned on: used only for DM auto-reply, which sends the reply you saved once to a DM containing a keyword. Kept encrypted only until processed and deleted immediately after processing, upon disconnection, permission revocation, workspace deletion or a Meta data deletion request, and within 24 hours at the latest; records are kept for 30 days without the text.
  • Identifier, text, author display name and handle of posts in which others mentioned the channel: used only while mention auto-reply is on, to collect and show mentions and post replies. Mention records are kept for no more than 30 days.
  • Reply text of DM auto-replies and the recipient identifier, and reply text to mentions: provided to Meta to send the auto-replies you turned on (§3 Provision to Third Parties).

Redband uses commenter information only for features you request, such as viewing comments, replying, auto-replies and displaying performance, and does not use it for other purposes or provide it to third parties. We do not further entrust processing to anyone other than the processors disclosed in this policy, and the security measures in this policy apply equally to commenter information. When you disconnect a channel or delete a workspace, it is deleted according to the retention criteria in this policy.

4. Processing Entrustment

The companies to which Moyeo entrusts the processing of personal information to provide the service are as follows. Through entrustment contracts, Redband sets the purpose and scope of processing, restrictions on re-entrustment, security measures and destruction obligations, and supervises compliance.

ProcessorEntrusted workInformation processedRetention and use period
Amazon Web Services, Inc.Operating servers and databases in the Seoul region, sending authentication, invitation and notification emails, sending inquiry, request and incident alert emails to the operatorPersonal information stored in the service, emails and messages needed for sendingUntil the entrustment contract ends
Cloudflare, Inc.Running, delivering and protecting access to the website, storing and delivering images and videosAccess requests and IP, data needed to process requests, uploaded media and public imagesUntil the entrustment contract ends
Toss Payments Co., Ltd.Payment authentication, approval and cancellation, and billing key managementPayment method identification information, transaction informationUntil the entrustment contract ends
Google LLC — Google Workspace (Gmail)Receiving and storing customer inquiry emails, receiving and storing operational alert emails (inquiries, plan requests, incidents)Inquirer's email and display name, inquiry text and attachments, plan request details, incident alert bodyUntil the entrustment contract ends
Google LLC — Google AnalyticsService usage analytics in browsers with analytics enabledAnalytics identifier, page type, sign-up button clicks, allowed referral information and device category. Email, post content and arbitrary URL queries are not sentAccording to Google Analytics retention settings and deletion requests
Google LLC — Gemini APIGenerating AI drafts, text polishing, post topics and reply suggestions you requestRequest and body text, target comment, original post, channel information and language, time zone, scheduled time, and other items listed in the AI writing and reply suggestions notice belowLimited abuse monitoring period (according to Google's paid service terms)
Functional Software, Inc. (Sentry)Identifying technical errors in the browser, web server, API and job processingAllowed error classification, code location and release version. Account information, request and response bodies, authentication information and screen recordings are not sentUntil the entrustment contract ends
Discord Inc.Confirming sign-ups and payments in an access-restricted operational channelAccount identifier, masked email, name and device category, workspace and invoice identifiers, plan and amount. Passwords, sessions, card numbers and raw IP are not sentUntil the entrustment contract ends

When we add or change a processor, we revise this policy and publish it before the effective date, and make the changes viewable in the revision history. If you do not agree to the change, you can delete your account or stop using the relevant feature.

Google and Kakao are authentication providers that provide the information needed for the sign-in you choose, and Meta and Google/YouTube are external platforms that perform the functions of connected channels.

AI Writing and Reply Suggestions

Before you use AI for the first time, we show a data processing notice and keep the notice version you acknowledged and the time as an acknowledgment record separate from acceptance of the sign-up terms. Acknowledging the notice does not cause posts to be created or published automatically, and you can use the service without using AI features.

When you request an AI draft, text polishing or post topic recommendation, or press the reply suggestion button to generate a new suggestion, the Moyeo server sends the information needed for generation to Google's Gemini API. Depending on the task, this may include the request and body text you entered, the target comment, the original post, recent messages in the same conversation, recent text written on that channel, the post's engagement metrics, and channel information and language, time zone and scheduled time.

Context is limited to the necessary scope of channels you can access in the current workspace, and writing history from other workspaces is not mixed in. Merely viewing a page or reusing a saved suggestion does not send a new generation request. Generated text is an editable suggestion and is not sent to social channels until you execute publishing or sending a reply.

The commenter's display name is not sent as a separate item, and the sign-in account, workspace, generation job, comment identifiers and internal lookup values are not included in generation requests. However, personal information you enter or that is contained in reference text is not automatically removed, so please do not enter sensitive personal information or secrets.

Moyeo uses the Gemini API under paid terms with a linked billing account. Under paid terms, Google does not use the inputs Moyeo sends or the outputs it returns to improve its products or train models, and retains them for a limited period only to prevent abuse. Google's data processing is governed by the Gemini API Terms of Service, and Moyeo's internal retention period for generated results differs from Google's processing and retention terms.

Moyeo stores AI-generated suggestions encrypted and deletes AI drafts, text polishing and reply suggestions 24 hours after creation, and post topic recommendations after 7 days. Each suggestion is recorded together with the channels used to create it, and when a channel is disconnected, only AI suggestions created using that channel's data are deleted. Suggestions that used only other channels in the same workspace and suggestions created without channel data remain until the retention period above. When a workspace is deleted, all AI suggestions stored in that workspace are deleted.

Moyeo does not use AI to automatically make decisions that have legal effects or similarly significant effects on you. AI only creates suggestions that you review, edit and use.

5. Cross-Border Transfer

Servers and databases are operated in the Amazon Web Services Seoul region and are therefore not transferred overseas. Toss Payments and Kakao are domestic businesses, so they do not constitute cross-border transfer. Processing that goes overseas is disclosed in the two categories below according to its nature.

Processing Entrustment and Storage for Performance of Contract

In accordance with Article 28-8(1)(iii) of the Personal Information Protection Act, we disclose the following regarding processing entrustment and storage necessary for concluding and performing contracts.

Recipient and contactDestination countryBasisTime and method of transferItems transferredPurpose of transferRetention and use periodHow to refuse and effect
Cloudflare, Inc. / dpo@cloudflare.comCountries where Cloudflare's global edge is located, including the United StatesArticle 28-8(1)(iii)Transmitted over encrypted communication when you access the service, use features or upload filesIP and request information needed to process web requests, uploaded images and videos and public imagesProviding the website, storing and delivering media, access protectionFor the period needed to provide the service and as processed upon Moyeo's deletion requestYou can refuse via support@moyeo.io. If you refuse, we cannot provide the web service and media features
Google LLC (Google Workspace, Google Analytics) / 1600 Amphitheatre Parkway, Mountain View, CA 94043, USACountries where Google's data centers are located, including the United StatesArticle 28-8(1)(iii)Transmitted over encrypted communication when inquiry, plan request and incident alert emails are received, and when events are sent with analytics enabledEmail and display name of inquirers and requesters, inquiry text and attachments, plan request details, analytics events and device categoryProcessing inquiries and plan requests, usage analytics in browsers with analytics enabledAccording to each service's retention settings and Moyeo's deletion requestsAnalytics can be limited through browser controls or Google’s opt-out tool, and for inquiries you can use another channel. Refusing does not restrict your use of the service
Functional Software, Inc. (Sentry) / compliance@sentry.ioUnited StatesArticle 28-8(1)(iii)Transmitted over encrypted communication when an error occurs while the service is runningError classification, code location, release versionIdentifying causes of incidents and maintaining service stabilityAccording to the Sentry project's retention settingsYou can request refusal via support@moyeo.io. Refusing does not restrict your use of the service
Discord Inc. / privacy@discord.comUnited StatesArticle 28-8(1)(iii)Transmitted to an access-restricted operational channel when a sign-up or payment event occursAccount identifier, masked email and name, device category, workspace and invoice identifiers, plan and amountInternal alerts for the operator to confirm sign-ups and paymentsAccording to the operational channel's retention settingsYou can request refusal via support@moyeo.io. Refusing does not restrict your use of the service

Overseas Processing When You Request AI Features

Recipient and contactDestination countryBasisTime and method of transferItems transferredPurpose of transferRetention and use criteriaHow to refuse and effect
Google LLC (Gemini API) / 1600 Amphitheatre Parkway, Mountain View, CA 94043, USACountries where Google or its processing agents operate facilitiesArticle 28-8(1)(iii)Transmitted over encrypted communication when you request AI generationRequest and body text you entered, post and comment context needed for generation, channel information, language, time zone and other items in the AI notice aboveGenerating writing and reply suggestions you requestPaid service terms apply, so data is not used for product improvement and is only retained on a limited basis for abuse detectionYou can choose not to request AI generation. Other features can be used without using AI

Moyeo calls the Gemini API from a project with a linked billing account, so the data processing terms for paid services apply. Under these terms, Google does not use inputs and outputs for product improvement and retains them only for a limited period for purposes such as abuse detection. For details, see the Gemini API Terms of Service and the Google Data Processing Addendum.

Cross-Border Provision at Your Request

The transfers below are cross-border provision made to carry out your request when you choose a sign-in method, connect a channel and request posting, replies or performance viewing, or turn on auto-reply. They are of the same nature as the provision to third parties in §3 above, and the recipient, country, items and purpose are explained on the sign-in screen and channel connection screen; they take place only within the scope you consented to on each platform's official consent screen.

Recipient and contactDestination countryBasisTime and method of provisionItems providedPurpose of provisionRetention and use periodHow to refuse and effect
Meta Platforms, Inc. / 1 Meta Way, Menlo Park, CA 94025, USACountries where Meta's data centers are located, including the United StatesArticle 28-8(1)(i)Transmitted over encrypted communication when you connect a channel and request posting, replies, auto-replies or performance viewingChannel identifier and granted permissions, post content and media, reply text, DM text sent by comment auto-replies, reply text of DM auto-replies and the recipient identifier, reply text to mentionsProviding Instagram and Threads channel integration features (posting, replies, comment, mention and DM auto-replies, performance viewing)According to the platform's policies and your deletion requestsYou can choose not to connect a channel or disconnect it. If you refuse, you cannot use the posting and comment features for that channel
Google LLC (YouTube, Google Sign-In) / 1600 Amphitheatre Parkway, Mountain View, CA 94043, USACountries where Google's data centers are located, including the United StatesArticle 28-8(1)(i)Transmitted over encrypted communication when you request sign-in, channel connection, uploads, replies or performance viewingSign-in account identifier and email, channel and video identifiers and granted permissions, uploaded videos and settings, reply textProviding Google Sign-In and YouTube channel integration featuresAccording to the platform's policies and your deletion requestsYou can use another sign-in method or disconnect the channel. If you refuse, you cannot use that sign-in or the YouTube features

The scope of Cloudflare's processing can be found in the South Korea Privacy Addendum and the Customer Data Processing Addendum, and the scope of Google Workspace's processing in the Data Processing Amendment and the Subprocessors and processing locations notice. The list of processing locations in each notice does not indicate the actual country where a specific file is stored.

6. Use of External Platform Data

What Moyeo receives from the external platforms you connect, with which permissions, for what purpose, and when it is deleted can be found for each platform in the Platform Data Use Notice.

  • Instagram · Threads: Permissions requested and data received, handling of Meta's app deauthorization and data deletion request callbacks
  • YouTube: Moyeo uses YouTube API Services. Data by permission, refresh method by data type, and deletion timing
  • Google Sign-In · Limited Use disclosure: Sign-in information transferred to Google LLC in the United States and compliance with the Google API Services User Data Policy
  • Kakao Login: Consent items and unlinking
  • Data deletion by platform: How to disconnect and revoke permissions

7. Google and YouTube Data

Moyeo uses YouTube API Services. We view and store the profile, video information, comments and performance data of connected channels within the scope of granted permissions, and use them for Shorts uploads you specify and for viewing comments and performance on connected channels. YouTube integration features are subject to the YouTube Terms of Service, and Google's processing of personal information is also subject to the Google Privacy Policy (https://policies.google.com/privacy).

Moyeo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This information is processed to provide and improve user-facing features, and is not used for sale, ad targeting or credit assessment. Only the necessary personnel access it, and only in permitted cases such as supporting a user's specific request, security investigations or legal requirements. We do not combine data received from YouTube with personal information from other sources without your separate request or consent.

Data received through the YouTube API is refreshed differently by type. Performance metrics are refreshed once a day for each connected channel, and comments are refreshed by re-fetching recent activity about every 3 hours and re-fetching the entire history period once a day. Channel information such as channel name, handle, profile image and description is received and stored when you connect or re-authorize the channel, and refreshed by re-fetching about every 3 days. When a comment deleted on YouTube is confirmed as deleted during a run that re-fetches the entire history period, its text is deleted immediately and its record within one day. Comments that have not been re-fetched for 30 days are deleted. Video information is re-fetched starting 27 days after it was last checked, and deleted videos or videos that could not be checked for 30 days are deleted together with related performance data. Performance metrics received from YouTube Analytics are kept up to the plan's history period while access has been verified within the last 30 days and the connection and analytics permissions remain in place. If these conditions are not met, performance metrics older than 30 days are deleted. When you disconnect a channel, delete a workspace or delete your account, we delete the related data and authentication tokens stored by Moyeo and request revocation of the authentication tokens through Google's revocation endpoint.

If you disconnect a channel, delete your account, or request deletion in the Moyeo app, we delete the YouTube data stored by Moyeo within 7 days; if you revoke Moyeo's access in your Google Account security settings, we delete it within 30 days. The same deadlines apply to data of channels that can no longer be fetched because token refresh failed.

You can revoke Moyeo's access in Manage third-party apps with account access in your Google Account. Unlinking Google sign-in in Moyeo deletes the link record kept by Moyeo, but you must revoke the app permission remaining in your Google Account yourself on the screen above. You can request deletion of information stored by Moyeo by disconnecting the channel or via support@moyeo.io. Deleting information stored by Moyeo does not delete videos posted on YouTube.

8. Kakao Login Data

When you use Kakao Login, we receive only the items you allowed on Kakao's consent screen. Kakao's consent item names and the items Moyeo stores are as follows.

Kakao consent itemItem stored by MoyeoPurpose of use
Kakao Account (Email)Email addressAccount identification and sign-in, sending service notices
NicknameDisplay nameInitial value of the name shown on screen
Profile ImageProfile image URLInitial value of the profile image shown on screen

You can unlink Kakao Login in account settings, and when you delete your account, Redband requests unlinking from Kakao to disconnect it from Moyeo. For detailed procedures, see the Data Deletion Instructions.

9. Cookies and Browser Storage

Moyeo uses cookies and browser storage to keep you signed in, verify devices securely and remember display settings. The items used are as follows.

NameTypePurposeRetention period
__Host-moyeo-sessionCookieMaintaining the sign-in sessionUntil the session expires. 7 days after last use, up to 30 days after issuance
__Host-moyeo-deviceCookieVerifying trusted devices and detecting abnormal sign-insWhile the device registration is maintained
moyeo-themeCookieRemembering the light or dark mode choiceUp to 1 year
sidebar_stateCookieRemembering whether the sidebar is expandedUp to 7 days
moyeo-filtersCookieRemembering filters chosen on each screenUp to 30 days
Cookies starting with moyeo_analyticsCookieDistinguishing visits in Google Analytics when analytics is enabledAccording to Google Analytics settings. Can be deleted in your browser
moyeo.analytics-consent.v1Local storageRespecting a previously saved analytics refusalUntil you delete it or clear browser storage
Items starting with moyeo.post-autosave:, moyeo.local-draft:Local storageTemporarily saving posts and replies in progress on this deviceNot loaded after 24 hours, and deleted when you sign out
Items starting with moyeo.notifications., moyeo.inbox., moyeo.ai.Local storageRemembering this device's push notification subscription display and dismissed noticesUntil you delete it or clear browser storage

You can delete or block cookies in your browser settings, but required features such as sign-in may not work. Visit analytics is collected by default. You can limit collection by deleting or blocking analytics cookies in your browser or using the Google Analytics Opt-out Browser Add-on. Add-on support varies by browser. If a previous refusal saved in Moyeo remains in this browser, analytics does not start. Clearing browser storage also removes that choice. Analytics is separate from marketing email consent, and limiting analytics does not restrict other service features. Session storage may be used to maintain temporary screen flows.

Moyeo does not collect or use behavioral information for personalized advertising. Analytics tools are used with advertising identifier linkage and ad personalization signals turned off, and the values collected are not shared with advertising businesses.

10. Notifications

Service notification emails that inform you of the status of tasks you requested, such as publishing results, are notices for performance of contract and are separate from consent to receive advertising information. You can adjust how you receive each type in notification settings, and notifications essential to using the service, such as payment, security and account status, cannot be turned off in the app.

When you sign in on a device we have not seen before, we send a new-device sign-in notice to your account email to protect your account. The notice states only the sign-in time and the browser and operating system names, and does not include your IP address or the raw device information sent by your browser. We use the authentication and security information in Section 1 to tell devices apart and collect no additional information for this notice.

Sending records and encrypted bodies of notification emails are deleted 30 days after sending, so that we can check them when you ask about an email you received. In-app notifications disappear automatically when the history period expires, and the history period may vary by plan.

Browser push notifications are used only when you turn them on yourself for each device. When turned on, we receive the subscription information issued by the browser (delivery endpoint and encryption keys) and store it encrypted with a versioned key; we do not store the full delivery endpoint, keeping only the domain that shows which service it is sent to. Push bodies contain only the notification's title and summary and information on the screen to navigate to, and do not contain account identifying information or link URLs.

Push notifications can be turned off per device in the device list in notification settings, and turning them off deletes the subscription information immediately. If you revoke notification permission in the browser, the subscription is discarded as soon as it is confirmed invalid on the next delivery attempt. When you delete your account, subscriptions for all registered devices are deleted.

11. Rights of Data Subjects and How to Exercise Them

You can manage display information and linked accounts and delete your account in account settings. Please send requests for access, correction, deletion or suspension of processing of personal information, and withdrawal of consent, to matthew@moyeo.io or support@moyeo.io. If you are signed in, you can also send the same request through the inquiry window opened by "Contact us" in the account menu at the bottom of the workspace sidebar or the floating question mark button on the screen. These requests are received by customer support (support@moyeo.io), and the Chief Privacy Officer confirms the result. We aim to respond within 2 business days. Requests through an agent are also possible, and we verify your identity or the agent's authority to the extent necessary. Requests are processed without delay, and for requests restricted by law, we explain the reason.

We do not accept sign-ups from anyone under 18 and do not collect personal information of children under 14. If we become aware of such a case, we take the necessary verification and deletion measures.

For consultation on privacy infringement, you can contact the Personal Information Infringement Report Center at 118 (privacy.kisa.or.kr); for dispute mediation, the Personal Information Dispute Mediation Committee at 1833-6972 (kopico.go.kr); and to report crimes related to personal information, the Korean National Police Agency Cyber Investigation Bureau at 182.

Automated Decisions

Comment auto-reply is a feature that executes the keyword and text rules you set exactly as they are, and Redband does not use it to make decisions in a fully automated manner that significantly affect the rights or obligations of you or commenters. Likewise, AI suggestion features only create outputs that go outside only after a person reviews and executes them.

12. Security Measures

In accordance with Article 29 of the Personal Information Protection Act and related notices, Redband takes the following measures.

  • Internal management plan: We establish and implement an internal management plan for the safe processing of personal information and review it regularly.
  • Access rights management: We limit personnel who can access personal information to the minimum number needed for their work, and keep records of granting, changing and revoking permissions.
  • Access log management: We keep access logs of personal information processing systems, retain them for at least the period prescribed by law, and review them regularly.
  • Encryption: Passwords are stored as non-reversible one-way hashes, and sensitive values such as channel access tokens, payment method identifiers, notification bodies and push subscription information are stored with AES-GCM encryption using versioned keys. IP and browser information in security records are kept as digests instead of the originals.
  • Protection in transit: All communication between your browser and the server, and between the server and external services, is encrypted with TLS.
  • Access control: We apply workspace- and channel-level permission checks, session and device management, blocking of abnormal access and request rate limiting.
  • Physical measures: Servers and storage are operated in Amazon Web Services and Cloudflare data centers, and physical safeguards such as entry control are carried out by those businesses under the entrustment contracts.
  • Responsibility and breach notification: Final responsibility for personal information protection lies with the representative. If we become aware that personal information has been or may have been lost, stolen or leaked (hereinafter a "breach"), we notify data subjects within 72 hours from that time and report to the authorities prescribed by law.

13. Chief Privacy Officer

We have designated a Chief Privacy Officer as follows to oversee personal information processing and handle users' inquiries and complaints.

ItemDetails
Name김용민
Title대표
Emailmatthew@moyeo.io
Phone010-5877-8951

For general customer support, please contact support@moyeo.io.

14. Changes to This Policy

When we change this policy, we publish the effective date and the changes, also by account email, 7 days before the effective date for general changes and 30 days before the effective date for changes that are unfavorable to users or material, and make previous versions viewable in the revision history. Changes that require separate consent under applicable law are applied after obtaining your consent.

15. Business Information

ItemDetails
Business name레드밴드
Representative김용민
Business registration number309-08-95749
Mail-order business registration number2026-서울강동-0281
Address서울특별시 강동구 상암로 11, 113동 2002호 (암사동, 선사현대아파트), 05240
Phone010-5877-8951
Customer support emailsupport@moyeo.io
Representative emailmatthew@moyeo.io
Hosting providerAmazon Web Services, Inc., Cloudflare, Inc.

Revision history

Effective dateChanges
2026-09-29 (current version)Clarified how posts, photos, videos and publishing records are handled when a channel is disconnected, and aligned terms with the app (posts, publishing, history period, Send DM)
2026-09-28Added per-plan retention of photo and video originals and new-device sign-in notices, and changed the retention of notification email sending records to 30 days
2026-09-26Clarified default analytics, collection controls and transmitted information
2026-09-23Initial version