TenClips

Privacy Policy

Effective Date: June 18, 2026

Neta (hereinafter the "Company") complies with applicable laws including the Republic of Korea's Personal Information Protection Act, the EU's General Data Protection Regulation (GDPR), and the U.S. California Consumer Privacy Act (CCPA), and processes users' personal information securely. The personal information processed by the Company is limited to the minimum necessary to provide the Service.

Article 1 (Categories of Personal Information Collected)

Mandatory Collection Items

• Email address (account creation and identity verification)

• Password (stored only as a non-reversible one-way hash, and encrypted with HTTPS/TLS during transmission)

• Nickname

• Adult-status confirmation information (record of the self-certification check that the user is 18 years of age or older (19 or older in the Republic of Korea) — date of birth is not collected)

• Location information (clip recording location metadata — included when the user uploads)

• Recording time (clip metadata)

• Device information (OS, device model, app version)

Optional Collection Items

• Profile picture

Article 2 (Purposes of Collection and Use of Personal Information)

• Provision of the Service, member management, and identity verification

• Operation of clip upload, storage, and sharing services

• Provision of location-based services (displaying the region name where a clip was recorded)

• AI automatic tag and memo generation (analysis of certain frame images extracted from clips — see Article 9 for details)

• Statistical analysis and improvement of Service usage

• Prevention of fraudulent use and security operations

• Fulfillment of legal obligations

Article 3 (Retention and Use Period of Personal Information)

As a general principle, a user's personal information is destroyed immediately upon withdrawal from the Service; however, in the following cases it is retained for the period prescribed by law.

• Log records: 3 months (Protection of Communications Secrets Act)

• Minimum information to prevent fraudulent use: 1 year

• Payment and transaction records (when using payment features): the period prescribed by applicable laws (such as the Act on Consumer Protection in Electronic Commerce)

Article 4 (Procedures and Methods for Destruction of Personal Information)

When personal information becomes unnecessary due to the expiration of the retention period, achievement of the processing purpose, withdrawal from the Service, or similar reasons, the Company destroys such personal information without delay.

• Destruction procedure: The Company selects the personal information for which a cause for destruction has arisen and destroys it upon confirmation by the Chief Privacy Officer.

• Destruction method: Information in electronic file form is permanently deleted using a method that makes recovery or reproduction impossible, and information printed on paper is shredded or incinerated.

• Information that must be preserved under the law is stored separately from other personal information, and once the preservation period has passed, it is destroyed in the manner described above.

Article 5 (Processing of Location Information)

Neta processes location information in accordance with the Act on the Protection and Use of Location Information.

• Location information (GPS coordinates) included in a clip is made public or kept private according to the user's settings.

• Location information is not provided to third parties without the user's explicit consent.

• Users may refuse the collection of location information at any time through the app settings or device settings. However, location-related features will be restricted.

• The Company does not perform real-time location tracking and collects only the metadata included when a clip is uploaded.

Article 6 (Provision of Personal Information to Third Parties)

The Company does not provide personal information to third parties without the prior consent of the user. However, the following cases are exceptions.

• Where the user has set a clip to "Public," thereby making the location information and recording time public

• Where there is a lawful request from an investigative agency under the law

• Where it is urgently necessary to protect the life or body of the user

Article 7 (Entrustment of Personal Information Processing)

The Company entrusts the processing of personal information for the operation of the Service as follows.

• Cloud video and image storage: Cloudflare (R2 object storage)

• Authentication, database, serverless functions, push notifications: Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging)

• AI content analysis: Anthropic (analyzing frame images extracted from clips to generate automatic tags and memos — see Article 9 for details)

• Payment processing: payment service providers (to be separately announced upon introduction of payment features)

The entrusted companies process personal information only within the scope of the entrusted work, and do not use it for any separate purpose or provide it to third parties.

Article 8 (Overseas Transfer)

The Company may transfer personal information overseas (to the United States) for the operation of the Service.

• Recipient and country of transfer: Cloudflare, Inc. / Google LLC / Anthropic, PBC (United States)

• Items transferred: account information, clip data (videos and extracted frame images), location information

• Purpose of transfer: data storage and processing, authentication and notifications, AI automatic tag and memo generation

• Timing and method of transfer: transmitted in encrypted form (HTTPS/TLS) over the information and communications network (the internet) at the time of Service use and upload

• Protective measures: application of each provider's privacy policy and Standard Contractual Clauses (SCC)

For users in the EU/EEA, appropriate safeguards under Article 46 of the GDPR apply.

Article 9 (Processing of Personal Information Related to Generative Artificial Intelligence (AI) Services)

The Company transmits certain frame images extracted from clips uploaded by users to a generative AI service (Anthropic, United States) to generate automatic tags and memos for the clips. This falls under Article 7 (Entrustment of Processing) and Article 8 (Overseas Transfer).

• Intended scope of use: Extracted frame images are processed solely for the purpose of generating automatic tags and memos for the relevant clip.

• Memos are automatically generated only when the user leaves them blank without entering them directly, and the user may modify or delete tags and memos at any time on the clip edit screen.

• This Service does not have any conversational (prompt) feature in which the user freely enters text, and the Company does not collect the contents of users' conversations.

• Transmitted frame images are not used to train Anthropic's AI models (based on Anthropic's commercial API terms), and are deleted from Anthropic's servers within a maximum of 30 days after analysis processing.

Article 10 (Personal Information of Children Under 14)

The Company's Service is available for sign-up and use only by those aged 18 or older (19 or older in the Republic of Korea), and the Company does not collect or process the personal information of children under the age of 14.

Article 11 (Users' Rights)

Users in the Republic of Korea (Personal Information Protection Act)

• Right to request access to, correction of, and deletion of personal information

• Right to request suspension of processing

• Right to withdraw consent

Users in the EU/EEA (Additional GDPR Rights)

• Right to Restriction

• Right to Portability

• Right to Object

• Right to refuse automated decision-making

• Right to lodge a complaint with a supervisory authority (DPA)

Users in California, United States (CCPA)

• Right to opt out of the sale of personal information (the Company does not sell personal information)

• Right to request disclosure of the categories of personal information collected and the purposes thereof

Rights may be exercised by sending a request to the Chief Privacy Officer's email below (privacy@tenclips.net), and requests are processed within 30 days of receipt.

Article 12 (Security of Personal Information)

The Company implements the following security measures to process users' personal information securely.

• Passwords are stored as non-reversible one-way hashes, and the original passwords are not retained.

• HTTPS/TLS encryption is applied during data transmission.

• Minimization of server access privileges and logging of access records

• Minimization of personnel handling personal information and provision of security training

• Periodic inspection of security vulnerabilities

Article 13 (Cookies and Tracking Technologies)

The Service may use cookies and similar tracking technologies for convenience of app use and statistical analysis. Users may restrict tracking through their device settings, but some Service features may be limited.

Article 14 (Matters Not Applicable to Processing)

The Company does not engage in the following types of personal information processing, and if it processes them in the future, it will amend this Policy and provide prior notice.

• Additional use or provision without the consent of the data subject

• Processing of pseudonymized information

• Automated decisions that produce legal effects on, or similarly significantly affect, the data subject (automatic clip tag and memo generation does not fall under this)

• Operation and management of fixed or mobile visual data processing devices (such as CCTV)

• The Company is not subject to the designation of a domestic representative

Article 15 (Chief Privacy Officer)

The Company designates a Chief Privacy Officer who oversees matters relating to the processing of personal information.

• In charge: Personal Information Processing Officer

• Title: Chief Privacy Officer (CPO)

• Email: privacy@tenclips.net

• Processing hours: weekdays 09:00 – 18:00 (excluding holidays)

Article 16 (Remedies for Infringement of Rights)

Users in the Republic of Korea may inquire about remedies and consultation for damages caused by infringement of personal information with the following agencies.

• Personal Information Dispute Mediation Committee: (no area code) 1833-6972 / www.kopico.go.kr

• Privacy Infringement Report Center, KISA: (no area code) 118 / privacy.kisa.or.kr

• Supreme Prosecutors' Office Cyber Investigation Division: (no area code) 1301 / www.spo.go.kr

• National Police Agency Cyber Bureau: (no area code) 182 / ecrm.police.go.kr

Article 17 (Changes to the Policy)

If this Policy is changed, notice will be provided through the app's announcements 7 days before the effective date. Material changes will be separately announced by email or in-app notification 30 days in advance.

Notice Date: June 18, 2026

Effective Date: June 18, 2026

Neta Operations Team