AI PIXELL Privacy Policy
Effective date · June 29, 2026
Distinction by Processing Environment (Important).
- SaaS/Cloud Services (such as PIXELL Detailer): content uploaded by the user (video and images) is processed by the Company and on cloud infrastructure.
- AI PIXELL Desktop Client: User Content (video and images) is processed locally within the user’s device and is not uploaded to or collected by the Company or any external party. The information that the Desktop Client transmits to the Company is limited to license verification and activation information, telemetry, error reports, and the like.
Article 1 (Items of Personal Information Collected)
The Company collects various types of personal information, with the user’s consent, when the user interacts with the Service. The principal items collected are as follows:
Personal Identification Information. This includes name, email address, telephone number, postal address, payment information, and the like. This information is provided directly by the user during account registration, service subscription, and payment.
Usage Data. This is information generated in the course of the user’s use of the Service and includes IP address, browser type, operating system, device information, access time, pages visited, and the like. This data is used to understand how users use the Service and to improve the user experience.
Content Data — SaaS/Cloud Services Only. This includes images, videos, and other content that the user uploads, processes, and stores through SaaS/cloud services. The Company processes such content within the scope necessary to provide the service requested by the user. ※ The AI PIXELL Desktop Client processes User Content locally only and does not upload it to or collect it for the Company. This item applies only to SaaS/cloud services (such as PIXELL Detailer).
License and Device Data — Desktop Client. For installation, activation, license verification, and device binding of the AI PIXELL Desktop Client, the Company collects the following: license key, client ID (user identifier), hardware identification information (HWID), and activation time.
Telemetry — Desktop Client. To improve service compatibility, quality, and stability, the Company collects operating system and hardware specifications (GPU, etc.), app version, and usage metrics (number of processing tasks, feature-specific calls, etc.).
Error Reports and Diagnostic Logs.
- (Automatic) When an app error occurs, crash logs, stack traces, and error context may be collected automatically.
- (Manual Submission) The Company may request the user to submit log files in order to identify the cause of errors and to improve and resolve them. Logs submitted by the user are intended to include system and technical error information that is not sensitive information (for example, error messages, processing environment, and operation records), and the Company uses the submitted logs solely for the purposes of error diagnosis, improvement, and resolution.
Communication Data. This includes email, chat messages, customer support tickets, and other records of correspondence with users. This data is used to respond to inquiries and to improve the quality of customer support.
Cookies and Tracking Technologies. The Company uses cookies, web beacons, and similar tracking technologies to collect information about the user’s browsing behavior. Cookies are used to customize the user environment, save preferences, and analyze site traffic. The user can manage whether to allow cookies through its browser settings.
Personal Information of Users Under the Age of 14. When the Company collects personal information of a user under the age of 14, it collects and processes, as mandatory items at the time of membership registration, the name, email, and password for the purposes of verifying the consent of the legal representative, subsequently confirming the identity of the legal representative, and confirming an intent to withdraw membership. In addition, in the course of obtaining the legal representative’s consent to membership registration, the Company collects the legal representative’s name and email address.
Article 2 (Purposes of Use of Personal Information)
The Company uses the personal information it collects for the following purposes:
Service Provision and Improvement. The Company uses personal information to provide the services requested by the user. This includes transaction processing, account management, and enhancement of service features. For example, in SaaS/cloud services, Content Data uploaded by the user is used to process the requested files and to enhance their quality.
License Verification and Prevention of Abuse — Desktop Client. The Company uses license and device information (HWID, etc.) for license verification, activation, and device binding; checking concurrent-use limits; preventing duplicate provision of free trials; and detecting and preventing abuse, such as the misuse of the refund policy.
Error Diagnosis and Service Improvement. The Company uses telemetry and error reports and diagnostic logs (including those automatically and manually submitted) for the diagnosis and resolution of app errors and for improving compatibility, quality, and stability. Logs submitted manually are used solely for the purposes of diagnosing, resolving, and improving the relevant error.
Communication with Users. The Company uses contact information to deliver important notices such as account notifications, service-related announcements, and security alerts. In addition, where the user has consented, the Company may send promotional information such as newsletters, special discounts, and announcements of new services.
Provision of a Personalized Experience. The Company uses Usage Data and cookie information to personalize the user’s environment, facilitate navigation of the platform, and help the user easily find preferred content.
Security and Legal Compliance. The Company uses personal information to strengthen the security of the Service, perform fraud detection and prevention, and confirm compliance with legal and regulatory requirements. This includes monitoring of suspicious activity and audit procedures to verify policy compliance.
Service Analysis and Improvement. The Company uses aggregated or anonymized data to analyze service usage patterns, measure the effectiveness of marketing activities, and improve overall service performance.
Article 3 (Entrustment of Personal Information Processing)
The Company does not sell, rent, or exchange the user’s personal information to third parties. However, in the following cases, the Company may entrust to, or provide to, a third party the processing of the user’s personal information after notifying the purposes and items of collection and use, the retention period, and the like, and obtaining the user’s consent:
Sharing with Service Providers. The Company may share the user’s information with trusted third-party suppliers that support the operation and provision of the Service. Examples include payment agents, cloud storage providers, and customer support platforms. The Company ensures that such service providers comply with strict data protection standards.
Provision for Legal Reasons. The Company may disclose personal information where there is a legal requirement, where it must respond to a subpoena or court order, or where it deems it necessary to protect the Company’s rights, investigate policy violations, or ensure the safety of others.
Provision in Corporate Transactions. Where the Company is involved in a merger, acquisition, or sale of assets, the user’s personal information may be transferred as part of such transaction. In such case, the Company will notify the user in advance and take the measures necessary to ensure that the personal information continues to be protected.
Where the User Consents. Where the user’s express consent has been obtained, the Company may share personal information with third parties. This may include the provision of information for marketing and promotional purposes.
※ The entrustment related to content processing below (video analysis, quality enhancement, upscaling, etc.) applies to SaaS/cloud services in which the user uploads content. Because the Desktop Client processes content locally, content is not provided to entrustees; license, telemetry, and error information transmitted from the desktop to the Company may be processed by the Company and infrastructure and analytics providers.
The current entrustees for the processing of the user’s personal information and the details of their tasks are as follows:
| Entrustee | Details of Entrusted Tasks |
|---|---|
| Google LLC | User behavior analysis |
| Amazon Web Services, Inc. | Personal information processing system, file management system, video analysis, video quality enhancement, video upscaling, video processing (SaaS/cloud) |
| Toss Payments Co., Ltd. | Domestic payment agency (Korea only) |
Article 4 (Measures to Protect Personal Information)
The Company regards the security of the user’s personal information as very important and implements various security measures to protect it. The principal measures are as follows:
- Encryption: sensitive data, such as payment information, is protected using encryption technology during transmission.
- Access Controls: access rights to personal information are granted, at a minimum, only to personnel who require them to perform their duties, and access is restricted to authorized personnel only.
- Regular Security Audits: the Company regularly performs security checks and assessments to identify and address vulnerabilities in its systems.
- Incident Response: the Company has procedures in place to respond immediately if a security breach occurs, and in the event of a breach, it promptly takes measures to minimize the impact on personal information.
The Company does its best to protect the user’s personal information; however, please be advised that no security system can be perfect.
Article 5 (Retention and Use Period of Personal Information)
The Company retains and destroys personal information for a certain period in order to provide the Service, fulfill the user’s requests, comply with legal obligations, resolve disputes, and perform the contract. The retention period varies for each type of personal information collected, depending on the purpose of processing and applicable law. However, where there is a retention obligation under applicable law, the Company retains the personal information for the period specified in such law and destroys it without delay once that period has elapsed.
- Account Data: retained while the account is maintained. If the user terminates the account, it is deleted and destroyed immediately, except where retention is required under applicable law or for a legitimate business purpose (such as dispute resolution or compliance with legal obligations).
- Content Data (SaaS/Cloud): personal information contained in Content Data uploaded by the user is retained for 10 days and then destroyed.
- License and Device Data (Desktop): retained for the period during which the license is valid (for a perpetual license, the duration of the license) or while the account is maintained, and destroyed upon license termination or account termination, except where required under applicable law or for a legitimate business purpose (such as prevention of abuse).
- Telemetry and Error Reports/Diagnostic Logs: retained for the period necessary to achieve the purpose of collection (improvement of quality and stability; error diagnosis and resolution) and then destroyed. Manually submitted logs are destroyed without delay once the diagnosis and resolution of the relevant error is complete.
- Communication Data: records of the user’s inquiries and customer support, such as emails and chat logs, are retained while the account is maintained. Upon account termination, they are deleted and destroyed immediately, except where required under applicable law or for a legitimate business purpose.
Personal Information Required to Be Retained by Law. Notwithstanding the destruction policy above, the Company retains the following items in accordance with statutory retention obligations and destroys them upon expiration:
| Statute | Records Subject to Retention | Retention Period |
|---|---|---|
| Act on the Consumer Protection in Electronic Commerce | Records on contracts or withdrawal of subscription | 5 years |
| Act on the Consumer Protection in Electronic Commerce | Records on payment and the supply of goods, etc. | 5 years |
| Act on the Consumer Protection in Electronic Commerce | Records on consumer complaints or dispute handling | 3 years |
| Framework Act on Electronic Documents and Transactions | Records on the distribution of electronic documents through a certified electronic address | 10 years |
| Framework Act on National Taxes | Books and supporting documents on all transactions prescribed by tax law | 5 years |
| Protection of Communications Secrets Act | Login records | 3 months |
Article 6 (Rights and Choices of Users)
The user has the following rights with respect to the personal information held by the Company:
- Right of Access and Rectification: the user may access its own personal information and request rectification where it is inaccurate or incomplete.
- Right to Erasure: the user may request the deletion of its own personal information. However, exceptions apply where retention is necessary to comply with legal obligations or for a legitimate business purpose.
- Right to Restriction of and Objection to Processing: the user has the right to request restriction of, or to object to, certain processing activities. For example, the user may opt out of processing for direct marketing purposes.
- Right to Data Portability: the user may request to receive its own personal information in a structured, machine-readable format and to have it transmitted to another personal information controller.
- Right to Withdraw Consent: where the Company processes personal information on the basis of consent, the user may withdraw its consent at any time. However, this does not affect the lawfulness of processing prior to withdrawal.
How to Exercise Rights. The user may exercise the above rights by contacting pixell@4by4inc.com. The Company responds promptly to the user’s request in accordance with applicable law.
Article 7 (Cross-Border Transfer of Personal Information)
The Company’s head office is located in the Republic of Korea, and the user’s personal information may be transferred to and processed in the Republic of Korea and other countries in which the Company’s service providers operate. By using the Service, the user is deemed to consent to the transfer and processing of personal information outside its country of residence (including countries whose level of data protection may not be the same as that of the country of residence). Even where personal information is transferred abroad, the Company establishes appropriate protective measures in accordance with applicable data protection laws to ensure that the user’s personal information is safely protected.
※ The cross-border transfer related to content below applies to the use of SaaS/cloud features in which the user uploads and processes content. Because the Desktop Client processes content locally, no cross-border transfer of content occurs; license, telemetry, and analytics information may be transferred to the operators below (such as Google).
| Recipient | Officer / Contact | Country | Date & Method of Transfer | Items Transferred | Purpose of Use | Retention Period |
|---|---|---|---|---|---|---|
| Google LLC | CPO, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA | USA | Remote network transmission at the time of service use | Google account basic profile (email, name), internal user identifier, content information such as video, audio, and images generated in the course of service use | User behavior analysis, service provision, member authentication, Google OAuth login, YouTube API integration posting | Until membership withdrawal or disconnection of integration |
| YouTube API Services (Google LLC) | CPO, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA | USA | Remote API transmission at the time of using the YouTube posting feature | Video files, posting-related information such as video title/description, internal identifier | Provision of the YouTube video posting feature requested by the user | Until the member requests disconnection of integration |
| Amazon Web Services, Inc. | CISO Chris Betz, 410 Terry Avenue North, Seattle, WA 98109, USA | USA | Transmission of video/audio to AWS servers for inference processing at the time of service use | Email address, internal user identifier, uploaded video/image/audio, generated results | AI analysis/generation, provision of image/video quality-enhancement services, infrastructure operation | Until membership withdrawal or achievement of the purpose |
| Vast.ai, Inc. (GPU Cloud Provider) | Privacy Team, 548 Market St PMB 75932, San Francisco, CA 94104, USA | USA | Transmission to a remote GPU server at the time of service use or upon server scaling | Internal user identifier, uploaded video/image/audio, content data required for model inference | AI model inference (video upscaling/conversion, etc.), enhancement of service quality, GPU use for infrastructure scaling | Until membership withdrawal or achievement of the purpose |
Article 8 (Changes to the Privacy Policy)
The Company may revise this Privacy Policy from time to time in accordance with business practices, technological developments, legal requirements, and other needs. When the Privacy Policy is changed, the Company updates the “Effective Date” at the top of this Policy and, where required by law, notifies users by an appropriate method. Users are encouraged to review this Policy periodically. If a user continues to use the Service after the changed Policy takes effect, the user is deemed to have agreed to the changed Policy.
Article 9 (Personal Information Protection Officer and Contact)
If a user has any inquiry, opinion, or complaint regarding this Privacy Policy or the Company’s personal information processing practices, the user may contact the Company at the following:
- Personal Information Protection Officer — Name: Seo Heehwan
- Email: pixell@4by4inc.com
- Address: 12th–14th Floors, 479 Gangnam-daero, Seocho-gu, Seoul, Republic of Korea
Article 10 (Remedies for Infringement of Rights)
A data subject may apply to the following organizations for dispute resolution, consultation, and the like in order to obtain relief from infringement of personal information.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.kopico.go.kr
- Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (no area code) / privacy.kisa.or.kr
- Cyber Investigation Division, Supreme Prosecutors’ Office: 1301 (no area code) / www.spo.go.kr
- National Office of Investigation Cyber Bureau, Korean National Police Agency: 182 (no area code) / ecrm.police.go.kr
4BY4 Co., Ltd. Address: 12th–14th Floors, 479 Gangnam-daero, Seocho-gu, Seoul, Republic of Korea Inquiries: pixell@4by4inc.com