Article 1 (Personal Information Controller)
The personal information controller is Linkive Co., Ltd., and the service is Forcletter. This policy applies to the Forcletter website, mobile app, public link-in-bio pages, community, advertising campaigns, customer support and related features.
Article 2 (Personal Information Processed and Purposes)
The Company processes the following information to the extent necessary to provide the Service. Not providing optional information does not affect use of the basic Service, except for the relevant optional feature.
1. Individual member accounts
a. Data: Kakao or Apple identifier, email, nickname, profile image, name, gender, age group, birth year, mobile number, sign-in and consent times
b. Purposes: identification, sign-in, profiles, notifications, customer support and prevention of misuse
2. Business members and organizations
a. Data: work email, encrypted password, email verification records, organization name, contact person, team, invitation and permission information
b. Purposes: business verification, organizational collaboration, and campaign, payment and permission management
3. Instagram and Facebook connections
a. Data: account and Page identifiers, usernames, names, profile images, follower, following and post counts, posts, Reels, comments, DMs, insights, reach, engagement, demographics, OAuth access tokens and expiration and connection status
b. Purposes: account analysis, reports, comment and DM operations, content management, advertising price predictions and campaign suitability checks
4. Service content
a. Data: AI conversations and results, goals, notes and schedules, link-in-bio pages, blocks, clicks, views and form submissions, community posts, comments, likes and reports, and notification and reminder settings
b. Purposes: requested features, content storage and publication, statistics, handling reports and service improvement
5. Advertising campaigns
a. Data: campaigns and application messages, Instagram profiles and performance, selection, rejection, messages, drafts, posts, reviews, shipping, feedback and settlement status, and names, emails and phone numbers separately disclosed in the campaign
b. Purposes: campaign discovery, applications, selection, contract performance, shipping, publication checks, dispute handling and settlement
6. Shipping
a. Data: recipient, contact details, postal code, primary and detailed address, and consent records
b. Purposes: sponsored product shipping and shipping inquiries
7. Subscriptions and payments
a. Data: subscription plan, period, billing date, coupons and usage, Toss Payments billing key, card issuer and masked card number, and order, payment, failure and refund history
b. Purposes: recurring payments, plan changes, billing and refunds, payment failures and disputes
8. Settlements and taxes
a. Data: account holder, bank and account number, national identification number or business and tax classification, payment amounts, taxes, payment records and consent records
b. Purposes: advertising payments, withholding tax and statutory tax processing, including tax invoices and payment statements
9. App, device and usage records
a. Data: IP address, cookies, browser, device and operating system information, access, click, error and performance logs, advertising attribution data, app push tokens and notification preferences
b. Purposes: maintaining sign-in, security, incident response, usage statistics, service quality improvements and permitted notifications
Article 3 (Collection Methods and Legal Basis)
1. The Company collects information users directly enter on registration, profile, subscription, campaign, shipping, settlement, link-in-bio form and customer support screens.
2. The Company receives authorized information through Kakao, Apple and Meta OAuth, the Instagram Graph API, payment providers and app operating systems.
3. Cookies, logs, clicks, views and error information may be generated automatically during service use.
4. Processing is based on user consent, entering into and performing service agreements, legal obligations, and legitimate service security and fraud prevention needs. Unique identifiers, such as national identification numbers, are processed only for settlement purposes supported by tax or other laws, or separate consent.
Article 4 (Retention and Use Periods)
1. Accounts, profiles, connections and service content: until withdrawal or completion of the processing purpose. On withdrawal, new Instagram data collection and sign-in stop immediately, and information not legally required to be retained is deleted or de-identified without delay.
2. OAuth tokens: use stops upon disconnection, withdrawal or expiration, and tokens are deleted after the minimum period necessary for recovery and security.
3. AI conversations and analysis records: until the user deletes them or withdraws. Records needed for quality, dispute or security checks are limited to the minimum period necessary.
4. Community and public link-in-bio pages: until deletion by the user or account termination. Records needed for others’ rights, reports or disputes may be retained with restricted, nonpublic access.
5. Link-in-bio form submissions: until the period stated in the page operator’s collection purpose and consent notice. Operators must delete submissions once the purpose is fulfilled.
6. Shipping information: until shipping and related disputes are completed. Information with no ongoing campaign or remaining purpose is deleted without delay.
7. Settlement, payment and campaign transaction records: for the statutory period or until disputes are resolved.
8. Fraud prevention and security records: up to one year after withdrawal. Access logs, such as IP addresses, are retained for up to three months where required by law.
Article 5 (Separate Statutory Retention)
The following records may be retained with separate access controls under applicable law.
1. Contracts or withdrawal, payments, and supply of goods or services: five years
2. Consumer complaints or dispute handling: three years
3. Display and advertising records: six months
4. Electronic financial transaction records: the period prescribed by applicable laws
5. Tax records, including withholding, payment statements and tax invoices: the periods prescribed by applicable laws, including the Framework Act on National Taxes, Income Tax Act and Corporate Tax Act
6. Website access records: three months under the Protection of Communications Secrets Act
Article 6 (Disclosure to Third Parties)
The Company does not sell personal information or disclose it to unrelated third parties without consent. Where legally permitted or necessary to perform a user-requested service, information is disclosed within the following scope.
1. Campaign advertisers or their organizations
a. Data: applicants’ Instagram profiles and performance, application messages, names, emails and phone numbers required in advance by the campaign, drafts, posts, messages and performance status
b. Purposes and period: application review, campaign contract performance and dispute handling, until the purpose is fulfilled or the statutory retention period expires
2. Selected influencers and shipping or settlement personnel
a. Data: campaign terms and the minimum contact, shipping and payment information needed for the work
b. Purposes and period: campaign performance, including shipping, content creation and payment, until the purpose is fulfilled or the statutory retention period expires
3. Investigative bodies, courts and tax authorities
a. Disclosure is limited to lawful requests under applicable law.
If recipients, data, purposes or periods differ on a campaign screen, the Company provides separate notice and obtains necessary consent.
Article 7 (Processing Entrusted to Service Providers)
The Company uses contracts and supervision to ensure processors handle personal information safely.
1. Toss Payments: card registration, recurring payments, cancellations, refunds and payment records
2. Amazon Web Services: cloud infrastructure, including file and image storage and email delivery
3. Kakao and Alimtalk delivery providers: social sign-in and transaction, security, campaign and subscription notifications
4. Meta Platforms: connected Instagram and Facebook API features and message processing
5. Google: Google Analytics usage statistics and Gemini API-based AI responses and analysis
6. OpenAI: API-based AI responses and analysis
7. Vercel: web service delivery, deployment and technical log processing
8. Slack Technologies: internal collaboration for customer inquiries and operational notifications
This policy is updated when processor or subprocessor names or providers for the same function change. Changes materially affecting user rights are announced separately.
Article 8 (International Transfers)
In providing the Service, the following information may be transferred through encrypted networks to overseas providers’ systems.
1. Google LLC
a. Countries, timing and method: the United States and other countries where Google operates facilities; HTTPS transmission when AI requests or analytics events occur
b. Data and purposes: AI inputs, account and content statistics, images and responses, usage events and device information; Gemini response generation and Google Analytics
c. Retention: the period under the Company’s contracts and settings and Google’s API and Analytics retention policies
2. OpenAI, L.L.C.
a. Country, timing and method: the United States; HTTPS transmission when AI requests occur
b. Data and purposes: user inputs, account and content information needed for analysis, and generated responses; AI response generation
c. Retention: standard API inputs and outputs may be retained for up to 30 days for purposes such as abuse monitoring, with exceptions for legal obligations
3. Vercel Inc. and Slack Technologies, LLC
a. Countries, timing and method: the United States and other countries where each provider operates facilities; encrypted transmission during web use, customer inquiries and operational processing
b. Data and purposes: web access and error logs, customer inquiry content and internal processing records; web delivery and customer support
c. Retention: the period under the Company’s contracts and settings and each provider’s retention policies
4. Meta Platforms affiliates
a. Countries, timing and method: the United States and other countries where Meta operates facilities; encrypted transmission when connecting accounts, retrieving data or using messaging features
b. Data and purposes: OAuth identifiers and tokens, Instagram and Facebook account, content, comment and DM information; connected features
c. Retention: while the user maintains the connection and for the period under Meta’s policies
Users may refuse consent to AI data transfers, which restricts only AI features. To refuse essential infrastructure transfers, users may request account deletion through customer support.
Article 9 (Personal Information in AI Features)
1. Features: AI Poki conversations, Instagram account and post analysis, weekly report summaries, link-in-bio analysis and features identified as using AI
2. Inputs: user-provided text, images and attachments, connected account profiles and insights, content and comments being analyzed, and service usage context
3. Outputs: AI-generated answers, summaries, recommendations, analyses and user feedback
4. Before the first AI transmission, the Company explains the data and purposes of transfers to Google Gemini and OpenAI and obtains consent. AI requests are also blocked on the server without consent.
5. The Company does not use user inputs or outputs to train its own general-purpose AI models, nor does it opt to provide them separately to AI providers for model-improvement training.
6. AI outputs may be inaccurate. Users should not enter unnecessary sensitive information, such as national identification numbers, bank passwords, full card numbers or health information, or third parties’ nonpublic information.
7. Users may contact support to withdraw AI transfer consent, request access to or deletion of related records, or challenge inappropriate results. Related AI features are restricted after withdrawal.
Article 10 (On-Device Processing and App Permissions)
1. The app may provide push notifications, local reminders, Live Activities and other device features. Notification schedules stored only on the device can be removed through app or operating system settings, or by deleting the app.
2. Permissions are requested through operating system screens when a feature is used and may be revoked at any time in device settings. Denying permission does not prevent use of features that do not require it.
3. Push tokens are used only to send notifications. Their use stops and they are deleted upon sign-out, withdrawal or permission revocation.
Article 11 (Children Under 14)
Forcletter is not directed at children under 14 and does not allow their registration. If the Company learns that information from a child under 14 has been collected, it will verify and delete it without delay.
Article 12 (Cookies and Behavioral Information)
1. The Company uses cookies and local storage to maintain sign-in, provide security and preferences, and compile usage statistics.
2. Google Analytics may process page, click, attribution, browser, device, approximate location, error and performance information. Sensitive payment or settlement input values themselves are not sent as analytics events.
3. Users may delete or block cookies or change advertising personalization settings in their browsers. Blocking essential cookies may prevent features such as sign-in from working.
4. The app may process device identification, performance and error information to the extent permitted by the operating system. It does not collect third-party personalized advertising identifiers without advertising tracking permission.
Article 13 (Destruction of Personal Information)
1. Personal information is destroyed without delay when its retention period ends or its purpose is fulfilled.
2. Information required by law is stored separately or logically isolated, with access restricted to the required purpose.
3. Electronic files are deleted using methods that make recovery difficult, and paper documents are shredded or incinerated.
4. Upon withdrawal, sign-in and new Instagram data collection stop immediately. Direct identifiers, tokens, push information and content not subject to statutory retention are deleted or de-identified. Minimum records needed for ongoing transactions, settlements or disputes may be retained with restrictions until the purpose is fulfilled.
Article 14 (Safeguards)
1. Access to personal information is granted only to the minimum personnel necessary for their work, with access records and permissions managed.
2. Passwords are stored using one-way hashes. Important information, such as OAuth tokens, bank account numbers, national identification numbers and detailed shipping information, is encrypted or masked.
3. HTTPS is used in transit. The Company operates authentication and authorization checks, input validation, unauthorized access prevention, backups and incident response procedures.
4. Processors and personnel are subject to privacy obligations, and policies and processing practices are reviewed regularly.
Article 15 (Data Subject Rights and Requests)
1. Users can edit profiles, opt out of notifications, disconnect Instagram, manage posts and link-in-bio pages, and withdraw in account settings. Users unable to sign in can find account deletion instructions at https://forcreator.co.kr/account-deletion.
2. Requests for access, correction, deletion, suspension of processing, withdrawal of consent or transfer records may be sent to linkive@linkive.co.kr or KakaoTalk channel customer support.
3. After verifying the user or authorized representative, the Company provides the outcome within the statutory period. If there are legal grounds for refusal or restriction, it explains those grounds and how to appeal.
4. Users may also exercise rights directly with campaign advertisers or link-in-bio page operators that independently collect information. The Company provides in-service reporting and inquiry channels.
Article 16 (Privacy Officer and Access Requests)
The privacy officer and contact for access requests are as follows.
1. Name and position: Suhwan Kim, CEO
2. Department: Security and Personal Information Protection
3. Phone: 070-8080-3748
4. Email: linkive@linkive.co.kr
Article 17 (Remedies for Rights Infringement)
Privacy counseling and dispute mediation may be requested from the following Korean organizations.
1. Personal Information Infringement Report Center: 118 without an area code in Korea, privacy.kisa.or.kr
2. Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
3. National Police Agency Cybercrime Reporting System: 182 without an area code in Korea, ecrm.police.go.kr
4. Supreme Prosecutors’ Office: 1301 without an area code in Korea, www.spo.go.kr
Article 18 (Policy Changes)
The Company updates this policy when laws, the Service or processing practices change. Changes materially affecting data subject rights are announced before taking effect or immediately upon revision through service notices and, where possible, individual means. Minor changes, such as processor list updates, may be documented in the change history.
Supplementary provisions
Article 1. This policy first took effect on November 24, 2025.
Article 2. AI data transfer provisions were added on July 24, 2026.
Article 3. This comprehensively revised policy was announced and took effect on July 27, 2026. It reflects actual account, Instagram, AI, link-in-bio, campaign, payment, shipping and settlement processing, and the 2026 Privacy Policy Drafting Guidelines.