FLIK Legal Document
Privacy Policy
Effective date: August 30, 2026
Article 1 (General Provisions)
FlikWorld (the ‘Company’) regards the personal information of users of the FLIK service (the ‘Service’) as important and complies with the Personal Information Protection Act and other applicable laws. This Privacy Policy explains what personal information the Company processes and for what purposes, how it protects that information, and what rights users may exercise.
Article 2 (Purposes of Processing Personal Information)
The Company processes personal information to the extent necessary for the following purposes.
① Member registration, identification of the individual, age verification, email and mobile phone authentication, and account management
② Login, password reset, session management, prevention of improper use, and service security
③ Provision of community functions such as profiles, posts, comments, follows, likes, saves, sharing, and reports
④ Storage, posting, and transmission of image and video uploads, AI tools and workflows, and prompt content
⑤ Ordering, payment, supply, confirmation of purchase history, cancellation, and refund of Prompt Products
⑥ Seller registration, identity verification, verification of business information, connection of settlement accounts, calculation of sales proceeds, and payment thereof
⑦ Customer inquiries, reports of rights infringement, dispute handling, and performance of legal obligations
⑧ Analysis of service usage, quality improvement, error response, preparation of statistics, and development of new functions
⑨ Display of advertisements, measurement of advertising performance, interest-based advertising, and prevention of fraudulent ad clicks
⑩ Where the user has separately consented, notification of service news, events, and promotions
Article 3 (Categories of Personal Information Processed)
The Company may process the following personal information in the course of providing the Service.
① Member registration and account management
1. Mandatory items: email address or mobile phone number, one-way encrypted value of the password, date of birth, whether the user agreed to the Terms of Service and this Privacy Policy, and the time of such agreement
2. Optional items: whether the user consented to receive marketing information, and the time of such consent
3. Generated information: member number, registration route, whether email and mobile phone authentication was completed, account status, registration date, and time of most recent login
② Profile and community activity
1. Username, display name, introduction, profile image, external profile links, and profile visibility
2. Post title, description, images, videos, and tags; AI tools and models used; prompts, negative prompts, and workflows
3. Comments, reviews, reasons and details of reports, likes, saves, bookmarks, follows, and sharing records
③ Service use and security information
1. IP address or IP hash, cookies and advertising identifiers, browser, operating system, device type, User-Agent, language, access date and time, visited and referring pages, and request paths
2. Service usage records; search, view, click, and advertising responses; video watch time, completion rate, and re-watch status; and records of viewing Prompt Products
3. Random device identifiers generated by the browser, login session and token identifiers, login successes and failures, and security events
④ Payment and purchase
1. Purchaser and seller member numbers, order number, payment number, product name, amount, currency, payment method type, payment, cancellation, and refund status, and the time of processing
2. Transaction and approval numbers of the payment gateway, and payment responses, webhooks, and audit records with personal information removed
3. The Company does not directly store complete payment method information such as card numbers, expiry dates, or CVCs that are processed directly on an external payment window
⑤ Seller registration, identity verification, and settlement
1. Seller country or region; classification as an individual, sole proprietor, or corporation; legal name; date of birth; contact details; address; postal code; and country of tax residence
2. Trade name, business registration number, bank name, bank identification information, account number, account holder, and settlement currency
3. Identity verification provider, session, status, time, and result code; mobile phone authentication status; PayPal seller account identification information; and settlement eligibility status
4. Type, version, and time of consent to the seller terms, the payout policy, third-party provision, and similar matters
5. Sales, refunds, fees, settlement balances, settlement requests, and payment records
⑥ Customer support and exercise of rights
The inquirer's email address and telephone number, the content of the inquiry or report, attachments, the outcome of processing, and consultation records
⑦ The Company does not directly collect or store resident registration numbers, images of passports or identification cards, or payment passwords. External identity verification and settlement providers may process such information on their own screens.
Article 4 (Legal Bases for Processing)
① The Company processes the personal information necessary to conclude and perform contracts with users, such as member registration, account and content functions, purchase, payment and refunds, and seller registration and settlement.
② Where the user's separate consent is required, the Company informs the user of the items collected, the purposes, the retention period, and the effect of refusing consent, and obtains consent. A user who does not consent to optional items may still use essential services, although the relevant optional functions may be restricted.
③ The Company may process personal information to perform legal obligations such as retention of electronic commerce records, tax and accounting, lawful requests from investigative agencies, and responses to disputes.
④ The Company may process the personal information necessary, to the extent permitted by law, for service security, prevention of improper use, incident response, and protection of the rights of the Company and users.
Article 5 (Processing and Retention Periods)
① The Company destroys personal information without delay once the purpose of processing has been achieved or the member has withdrawn from the Service. However, where there is a retention obligation under applicable law, a need for dispute handling, or a separately notified retention period, the information is retained for that period, stored separately or with restricted access.
② The principal retention periods are as follows.
1. Member account and profile information: until withdrawal of membership or deletion of the relevant information
2. Email and SMS authentication codes: up to 10 minutes after issuance. Minimal records for prevention of improper use and incident response may be retained for the retention period of separate security records
3. Login sessions: up to 90 days after issuance or last renewal
4. Records of video viewing, product views, prompt viewing, and clicks on the Company's own advertisements and sponsorships: 90 days from the date of collection
5. Access, authentication, and security event records: 3 years from the date of collection
6. History of consent to the terms, personal information, and marketing: 3 years after withdrawal of membership or withdrawal of consent
7. Records concerning contracts or withdrawal of subscription: 5 years
8. Records concerning payment and the supply of goods or digital content: 5 years
9. Records concerning consumer complaints, reports, or dispute handling: 3 years
10. Records concerning labeling and advertising: 6 months
11. Records of sales, refunds, fees, and settlement: 5 years after completion of the transaction
12. Seller identity verification and settlement-related information: 5 years after termination of seller status or withdrawal of membership. However, where applicable law provides a shorter or longer period, that period applies
③ Posts made public by a user may be retained after withdrawal of membership in anonymized form so that the author cannot be identified. A member may delete deletable posts before withdrawing. Content connected to a transaction, report, or dispute may be retained until the relevant procedure is completed.
Article 6 (Provision of Personal Information to Third Parties)
① The Company processes personal information within the scope of the purposes of processing and does not provide it to third parties except where the user has separately consented or where permitted by law.
② Personal information may be provided as follows for the purposes of product purchase, payment, identity verification, and settlement. The specific recipients, items, purposes, and retention periods are notified again on the relevant transaction screen and in the separate consent form.
1. PortOne and connected payment and identity verification providers: order number, payment number, product name, amount, currency, payment status, and information necessary for identity verification / payment, cancellation and refunds, prevention of fraudulent payment, and identity verification of domestic sellers / for the period prescribed by applicable law and the policies of the relevant provider
2. PayPal and its affiliates: seller tracking identifier, PayPal seller account identification information, and onboarding, payment-receipt, and settlement status / verification of overseas sellers and connection of settlement accounts / for the period prescribed by applicable law and PayPal's policies
3. Google LLC: cookies and advertising identifiers, IP address, device and browser information, and service usage and click events / provision, personalization, and performance measurement of advertising through Google AdSense / until deletion or objection by the user or for the period prescribed by Google's policies
4. Investigative agencies, courts, supervisory authorities, and the like: information within the scope of a lawful request / performance of legal obligations, criminal investigation, and dispute resolution / for the period prescribed by applicable law
③ Where the Company intermediates between third-party sellers and purchasers in the future, it will separately notify the seller information and the provision of personal information necessary for the transaction before purchase and obtain the required consent.
Article 7 (Entrustment of Personal Information Processing)
The Company may entrust the work necessary to provide the Service to the following providers and manages and supervises matters necessary for the protection of personal information through entrustment agreements and similar means.
① Amazon Web Services: operation of API servers and database, cache, and service data infrastructure / Seoul region, Republic of Korea / until termination of the entrustment agreement or achievement of the purpose
② Vercel Inc.: front-end deployment, CDN, web request processing, and failure logs / until termination of the entrustment agreement or achievement of the purpose
③ Cloudflare, Inc.: storage and delivery of profile and post images and videos, CDN, and upload processing / until deletion of the files or termination of the entrustment agreement
④ Brevo SAS: email authentication for member registration, password reset, and similar purposes, and future email notices to consenting members / until achievement of the sending purpose or termination of the entrustment agreement
⑤ Twilio Inc. and connected telecommunications carriers: sending of authentication SMS messages to members and sellers, confirmation of delivery status, and prevention of fraudulent sending / until completion of authentication and expiry of the statutory and provider retention periods
⑥ Korea PortOne Co., Ltd. and connected payment and identity verification providers: provision of the payment window, payment verification, cancellation and refunds, webhook processing, and identity verification of domestic sellers / until expiry of the statutory retention period for electronic commerce or termination of the entrustment agreement
⑦ PayPal and its affiliates: onboarding of overseas sellers, confirmation of seller status, and connection of settlement accounts / until the end of the seller relationship and expiry of the statutory retention period
⑧ Google LLC: analysis of service usage and preparation of statistics through Google Analytics / until deletion or objection by the user or for the period prescribed by Google's policies. The provision, personalization, and performance measurement of advertising through Google AdSense is processed by Google for its own purposes and therefore constitutes provision to a third party and transfer abroad rather than entrustment; it is addressed in Articles 6, 8, and 11.
⑨ Kakao Corp.: search of postal codes and addresses for domestic sellers / until completion of the address search. Access records may be processed in accordance with Kakao's policies.
Article 8 (Transfer of Personal Information Abroad)
① The Company may transfer personal information abroad in the course of using global cloud, email, SMS, payment and settlement, analytics, and advertising services. Transfers occur from time to time as the Service is used, by transmission or access over an information and communications network or by storage on overseas servers.
② The principal transfers abroad are as follows.
1. Vercel Inc. / the United States and the countries in which Vercel's sub-processors are located / IP address, request URL, device and browser, access and error logs, and information transmitted to the front end / deployment, delivery, security, and failure response for the web service / for the period prescribed by the provider's policies after use of the Service and termination of the agreement / privacy@vercel.com
2. Cloudflare, Inc. / the United States and the countries in which Cloudflare operates its global infrastructure / identifiers of uploaded images, videos, and files, IP address, and delivery logs / storage, delivery, and security of content / for the period prescribed by the provider's policies after deletion of the files or termination of the agreement / privacyquestions@cloudflare.com
3. Brevo SAS / the European Union, including France, Germany, and Belgium / email address, authentication code, content sent, and delivery, receipt, and bounce results / sending of authentication and notification emails / for the period prescribed by the provider's policies after achievement of the sending purpose or termination of the agreement / Brevo privacy contact point
4. Twilio Inc. and connected telecommunications carriers / the countries in which Twilio and the carriers process data, including the United States / mobile phone number, authentication messages and codes, sending and receiving information, time and status of delivery, IP address, and communications metadata / SMS authentication, delivery, security, and prevention of improper use / until achievement of the authentication purpose or expiry of the retention period under Twilio and telecommunications laws / privacy@twilio.com
5. PayPal and its affiliates / the United States, Singapore, and the countries in which PayPal provides its services / seller tracking ID, PayPal seller account identification information, and onboarding, payment-receipt, and settlement status / verification of overseas sellers and connection of settlement accounts / until the end of the seller relationship and expiry of the statutory and PayPal policy retention periods / PayPal privacy contact point
6. Google LLC / the United States and the countries in which Google processes data / cookies and advertising identifiers, IP address, device and browser, pages visited, and usage, click, advertising, and purchase events / usage analysis, provision of advertising, personalization, and performance measurement / until deletion or objection by the user or for the period prescribed by Google's policies / Google privacy contact point
③ A user may refuse certain transfers abroad by not using optional functions or by changing cookie and advertising settings. However, a user who refuses a transfer abroad that is essential to performance of the contract, such as email and SMS authentication or settlement for overseas sellers, cannot use the relevant function.
④ The Company implements the protective measures required by applicable law, including agreements with providers receiving transfers abroad, access controls, encrypted transmission, and support for the exercise of rights. The sub-processors and processing countries of external providers may change in accordance with their policies and service structures, and material changes will be reflected in this Policy.
Article 9 (Destruction of Personal Information)
① The Company destroys without delay personal information for which the retention period has expired or the purpose of processing has been achieved. Information that must be retained under applicable law is stored separately from other information or with restricted access rights for the relevant period and then destroyed.
② Electronic files are deleted by a secure method that makes recovery or reproduction difficult, and paper documents are shredded or incinerated.
③ Information contained in backups is deleted sequentially in accordance with the backup operation cycle, and its use for purposes other than recovery is restricted until deletion.
④ Upon withdrawal of membership, the Company deletes or anonymizes email addresses, telephone numbers, and profile identification information and deletes personal activity information such as follows, likes, and saves. Member identifiers may be removed from sharing and viewing records, and comments are switched to a deleted state.
Article 10 (Sensitive Information and Disclosure of User Content)
① The Company does not, in principle, collect sensitive information as a mandatory item. However, if a user voluntarily includes sensitive content such as health, political opinions, religion, or sex life in posts, profiles, comments, or prompts, such content may be disclosed to other users or on the internet according to the visibility the user has set.
② A user should confirm the visibility setting before posting and should not post sensitive information or the personal information of others. After posting, the user may use the deletion, private-setting, or edit functions provided, or request deletion from the Company.
③ The Company may restrict the display of, or delete, publicly disclosed information where there is a risk of a violation of law or an infringement of rights.
Article 11 (Cookies, Automatic Collection Devices, and Interest-Based Advertising)
① The Company and external providers may use cookies, local storage, session storage, pixels, SDKs, and similar technologies for login persistence, security, preference settings, usage analysis, and the provision of advertising.
② The principal stored and automatically collected information used by the Company includes HttpOnly cookies for authentication, theme settings, device identifiers generated by the browser, and values that prevent duplicate transmission of purchase and refund events.
③ Google Analytics may collect pages visited, device and browser information, referral paths, and service usage events. The Company restricts the transmission of email addresses, telephone numbers, passwords, authentication codes, full prompt text, and full comment text to analytics events.
④ Advertising providers such as Google AdSense may use a user's activity, cookies, and advertising identifiers to provide interest-based or personalized advertising and to measure advertising performance.
⑤ A user may refuse or delete the storage of cookies in the browser settings and may limit ad personalization and analytics through tools such as Google Ads Settings and the Google Analytics Opt-out Browser Add-on. If essential cookies are blocked, some functions such as login may not operate normally.
⑥ The Company takes reasonable measures to provide users in countries and regions where prior consent is required under applicable law with the means to make choices regarding cookies and personalized advertising.
Article 12 (Rights of Data Subjects and Legal Representatives)
① A user may request access to, correction or deletion of, or suspension of the processing of his or her personal information, withdraw consent, and withdraw from membership. Depending on the laws of the applicable country or region, additional rights such as data portability, an explanation of automated decisions, or objection to processing for advertising purposes may be recognized.
② A user may make a request using the profile and settings functions of the Service or at support@flik-world.com. The Company processes the request in accordance with the periods and procedures prescribed by applicable law after verifying that the requester is the data subject or a duly authorized representative.
③ A legal representative may exercise the rights of a minor in accordance with applicable law. The Company does not permit member registration by persons under 14 years of age, and where an account is found not to meet the age requirement, the Company may take necessary measures such as restricting use or deleting the account.
④ A request may be restricted in whole or in part where there is a retention obligation under applicable law or a risk of infringing the rights and freedoms of others, and the Company will inform the user of the reason.
⑤ Inquiries, withdrawals of consent, and objections concerning the processing of personal information and transfers abroad may be submitted to the personal information protection department. If a user refuses essential processing or transfer, provision of the related service becomes difficult and the account or certain functions may be restricted.
Article 13 (Measures to Ensure Safety of Personal Information)
The Company implements the following technical, administrative, and physical measures to protect personal information.
① One-way encrypted storage of passwords and encrypted storage of key personal information of sellers
② Encryption of transmission channels, HttpOnly and Secure settings for authentication cookies, and verification of the origin of access
③ Minimization of access rights, additional authentication before access to sensitive information, and logging of administrator activity
④ Recording of login, authentication, and security events, restriction of abnormal requests, and destruction of sessions
⑤ Access control for databases, caches, and file storage, and separate management of secret keys
⑥ Restrictions on uploaded files, prevention of malicious requests, and operation of procedures for responding to failures and security incidents
⑦ Management and supervision of entrusted providers and training of personnel who handle personal information
Article 14 (Personal Information Protection Department)
The Company operates the following department for the processing of personal information and the handling of related grievances.
① Department: FlikWorld Personal Information Protection
② Telephone: +82-70-7954-6548
③ Email: support@flik-world.com
④ Address: 2F, Unit 232A, 106 Jangdae-ro, Yuseong-gu, Daejeon, Republic of Korea (Jangdae-dong)
Article 15 (Remedies for Infringement of Rights)
A user may contact the following organizations for consultation on or resolution of disputes concerning infringement of personal information.
① Personal Information Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
② Personal Information Dispute Mediation Committee: 1833-6972 / kopico.go.kr
③ Supreme Prosecutors' Office: 1301 (no area code) / spo.go.kr
④ National Police Agency: 182 (no area code) / ecrm.police.go.kr
Article 16 (Additional Information for Global Users)
① The Company provides the Service to global users, and depending on a user's place of residence, local laws such as the General Data Protection Regulation of the European Union (GDPR), the UK GDPR, and the privacy laws of individual states of the United States may apply in addition to the Personal Information Protection Act of the Republic of Korea.
② To the extent such laws apply, the Company takes reasonable measures to ensure lawful bases for processing, safeguards for transfers abroad, and the rights to withdraw consent, to access, delete, and port personal information, and to object to personalized advertising.
③ If a user uses the Service from outside the Republic of Korea, personal information may be transferred to and processed by the Company in the Republic of Korea and on servers located in the Seoul region.
④ Where legal obligations or user rights differ by region, the Company may provide separate region-specific notices or consent screens.
Article 17 (Amendment of This Privacy Policy)
① The Company may amend this Policy in response to changes in applicable law, the Service, or the manner in which personal information is processed.
② Where there is a material change, the Company gives notice from thirty days before the effective date by a reasonable method such as a service announcement or email, and gives notice of any other change in principle from seven days before the effective date.
③ Previous versions of this Privacy Policy are retained so that users may review them.
Addendum
① This Privacy Policy takes effect on August 30, 2026.
② This Privacy Policy is prepared in Korean and translated into English. Where the Korean and English versions differ in content, the Korean version prevails, provided that where applicable law requires an interpretation more favorable to the user, that interpretation applies.