개인정보처리방침

bake · 버전 2.0 · 2026년 9월 8일 시행

훈연스튜디오(이하 “회사”)는 bake 서비스 제공을 위해 필요한 최소한의 정보를 처리합니다.

1. 수집하는 정보

기기 내 편집 데이터와 백업

앱 안의 편집 프로젝트와 프로젝트에 저장한 영상·사진·녹음 등 미디어는 기기에 로컬로 저장되며 회사 서버나 클라우드에 자동으로 동기화 또는 백업되지 않습니다. 앱을 삭제하면 앱 안의 프로젝트와 미디어도 함께 삭제되어 복구할 수 없습니다. 중요한 영상은 앱을 삭제하기 전에 사진 앱이나 파일 앱으로 내보내야 합니다. 사진 앱이나 파일 앱으로 이미 내보낸 사본은 앱을 삭제해도 유지됩니다.

AI 기능을 선택하면 해당 요청에 필요한 데이터와 사용자가 명시적으로 선택한 참고자료 또는 영상의 필요한 부분만 아래 외부 처리자에게 전송됩니다. 자동 컷편집과 자동 자막은 선택한 영상 파일 전체가 아니라 분석용 저용량 음성과 시간 매핑만 전송합니다. 계정 없이 로컬 영상 편집 기능을 이용할 수 있습니다.

2. 이용 목적

3. 저장 및 보유

Instagram 분석 보고서와 최소 공개 프로필 요약은 계정 삭제 또는 사용자의 삭제 요청 시까지 보관됩니다. 분석에 사용한 대표 썸네일 원본은 AI 요청 처리 중에만 일시적으로 내려받고 별도로 저장하지 않습니다. 이전 앱 버전에서 생성된 Instagram 연결 정보와 액세스 토큰은 새 공개 아이디 분석에 전혀 사용하지 않으며 계정 삭제 또는 사용자의 삭제 요청 시 삭제됩니다. 공개 상품 식별자·상품명·대표 이미지 URL·출처와 공개 참고자료의 구조화된 분석 결과는 중복 수집을 줄이기 위해 사용자 계정과 연결하지 않고 최대 14일 캐시될 수 있습니다. 원본 대표 이미지와 상품 상세 화면은 별도로 복제·보관하지 않습니다. 자동 컷편집·자동 자막 분석용 음성은 요청 처리 중에만 비공개로 임시 보관하고 성공·실패·취소 후 즉시 삭제를 시도합니다. 일시적인 삭제 실패는 삭제 대기로 기록해 자동 정리 작업이 재시도합니다. 전사·컷 경계·자막 결과와 과금 기록은 결과 복구와 분쟁 대응을 위해 계정 삭제 또는 삭제 요청 시까지 보관될 수 있습니다. AI 전송 동의 기록은 기기와 서버에 계정별로 저장되며 회원 탈퇴, 앱 데이터 삭제 또는 동의 철회 처리 시 삭제됩니다. 법령상 보존 의무가 있는 결제 기록은 해당 기간 동안 분리 보관할 수 있습니다. 외부 제공자의 처리는 각 제공자의 계약과 데이터 처리 정책에 따릅니다.

알림함 기록은 회원 탈퇴 시까지 보관하며 알림 받기를 꺼도 앱 내 알림함에는 유지됩니다. 앱 내 알림 받기를 끄거나 로그아웃하면 현재 기기의 Expo 푸시 토큰 등록을 해제하고, 회원 탈퇴 시 계정에 연결된 토큰을 삭제합니다. 앱을 먼저 삭제해 해제 요청이 전달되지 않은 경우에는 푸시 제공자가 토큰이 유효하지 않다고 응답할 때 해당 토큰을 비활성화하며, 비활성 토큰은 회원 탈퇴 또는 삭제 요청 시 삭제합니다. 기기 내 편집 프로젝트와 미디어는 자동 백업되지 않으며 앱 삭제 후 회사가 복구할 수 없습니다.

4. 외부 처리자

각 제공자의 보유·삭제는 해당 상업용 서비스 계약, 데이터 처리 조건 및 개인정보처리방침에 따릅니다. 회사는 외부 처리자가 본 방침과 관련 법령에서 요구하는 것과 동등한 수준의 보호 조치를 제공하는지 계약·처리 조건 및 공개 보안 문서를 통해 확인하고, 서비스 제공에 필요한 범위에서만 처리하도록 요구합니다.

Expo 푸시 토큰, 기기 플랫폼과 알림 내용은 사용자가 선택한 서비스 알림 제공에만 사용하며 광고, 사용자 추적 또는 광고 프로파일링에 사용하지 않습니다.

5. 사용자의 선택과 권리

공개 Instagram 계정 분석과 AI 기능은 선택 사항입니다. 계정 분석에는 Instagram 로그인·Meta 연결·액세스 토큰을 사용하지 않습니다. 온보딩의 공개 계정·참고자료·AI 기획·AI 음성 동의는 기기 내 개인 영상 음성을 포함하지 않습니다. 자동 컷편집·자동 자막을 처음 실행할 때 별도의 화면에서 OpenAI로 전송되는 데이터·목적·삭제 시점을 확인하고 동의를 받습니다. 동의하지 않으면 음성 추출·업로드·AI 요청과 크레딧 차감이 시작되지 않으며 로컬 영상 편집은 계속 사용할 수 있습니다. 향후 전송을 원하지 않으면 선택형 AI 기능을 더 이상 실행하지 않을 수 있습니다. 기기와 서버에 저장된 동의 기록은 프로필 → 계정 → 회원 탈퇴, 앱 데이터 삭제 또는 동의 철회 처리로 삭제할 수 있고, 동의 철회·처리 정지는 hunyeon.studio@gmail.com으로 요청할 수 있습니다. 프로필 → 알림 설정에서 알림 받기를 끌 수 있습니다. 이 경우 현재 기기의 푸시 토큰 등록과 예약된 로컬 알림은 해제되지만 앱 내 알림함 기록은 회원 탈퇴 전까지 유지됩니다. 프로필의 계정 설정에서 계정을 영구 삭제할 수 있습니다. 자세한 절차는 데이터 삭제 안내를 확인하세요.

6. 보안 및 문의

전송 구간 암호화, 사용자별 접근 제어 및 인증 토큰으로 정보를 보호합니다. 개인정보 문의: hunyeon.studio@gmail.com

Privacy Policy

bake · Version 2.0 · Effective September 8, 2026

Hunyeon Studio processes only the information needed to provide bake.

Information we process

Optional Apple or Google sign-in details; subscription, credit and Apple transaction records; and, when you run Instagram account analysis, the public username you enter, public name, bio, website, profile-photo URL and account metrics. Account analysis processes up to 40 recent public posts’ IDs, captions, hashtags, media types, permalinks, timestamps, likes, comments, views and representative thumbnails. When you save a shopping link or use it for AI video planning, we process the public Coupang/Naver product URL, public product identity, product name, representative-image URL and page metadata. AI video planning may process the topic, revision request, selected identity/style settings, saved Instagram-analysis key message and key audience when Content is enabled, text and Coupang page metadata, public Naver Store product-detail images, and public-video audio and frames from references you select. AI voice generation processes only the selected cut caption and voice type. Auto Cut and Auto Captions process low-bitrate audio, analysis ranges, cut identifiers, duration and time mapping from the on-device video the user selects. When you allow system notifications and turn on notifications in the app, we store the Expo push token and device platform (iOS/Android). We also store account notification-inbox records, including notification kind, title, body, related-screen data, creation time and read time.

On-device editing data and backups

In-app editing projects and project media, including videos, photos and recordings, are stored locally on the device. bake does not automatically sync or back up this local data to Company servers or cloud storage. Deleting the app deletes the projects and media stored inside bake, and they cannot be recovered. Export important videos to Photos or Files before deleting the app. Copies already exported to Photos or Files remain after the app is deleted.

Processors and purpose

Supabase provides authentication, database, private temporary audio storage and serverless functions and stores account-linked consent, job, billing, Expo push-token/platform and notification-inbox records plus public-product snapshots kept separate from user accounts. Anthropic processes video-planning inputs, Coupang page text and metadata, selected public Naver Store product-detail screens, the saved Instagram-analysis key message and key audience when selected, and public Instagram profile/account/post text, public metrics and representative thumbnails to create AI results. OpenAI processes audio, frames and captions when you select a public Instagram video reference, and low-bitrate analysis audio and time mapping from an on-device video only when you run Auto Cut or Auto Captions. Bright Data collects the public profile, recent posts and representative thumbnails for the Instagram username you enter; public post/video information when you select a public Instagram reference; public Coupang product-page text and metadata; or public Naver Store product-page text and detail images when you select a shopping reference. ElevenLabs processes a selected cut caption and voice type only when you choose AI voice generation. 650 Industries, Inc. (Expo) processes the Expo push token, notification title/body and related-screen data for the period needed to relay a notification to Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM). Apple and Google provide optional sign-in/payment and system-push delivery; Cloudflare provides proxying and security. Push identifiers, device platform and notification content are used only for service notifications, not for advertising, user tracking or advertising profiles.

Retention and equivalent protection

Analysis reports and a minimized public-profile summary remain until account deletion or a user deletion request. Original Instagram thumbnails are downloaded only temporarily for the AI request and are not stored separately. Instagram connection data or access tokens created by an earlier app version are never used by the new public-username analysis and are deleted upon account deletion or a user deletion request. Public product identity, product name, representative-image URL, provenance and structured public-reference analysis results may be cached for up to 14 days without a link to a user account. Original representative images and product-detail screenshots are not copied or retained separately. Auto Cut and Auto Captions analysis audio is privately retained only during request processing; deletion is attempted after success, failure or cancellation, and transient failures are retried by automated cleanup. Generated transcript, cut-boundary and caption results and billing records may remain until account deletion or a deletion request for result recovery and dispute handling. Notification-inbox records remain until account deletion, including while push is turned off. The current-device Expo push token is unregistered when you turn off in-app notifications or sign out, account-linked tokens are deleted upon account deletion, and the token is disabled when the push provider reports it as invalid. Provider-side retention and deletion follow each provider’s commercial contract and data-processing policies. We review contractual/data-processing terms and public security materials to confirm protection equivalent to this Policy and applicable law, and require processing to be limited to service delivery.

Your choices

Public Instagram account analysis and AI features are optional. Account analysis does not use Instagram login, a Meta connection or an access token. Onboarding consent for public-account, reference, AI-planning and AI-voice features does not include audio from a private on-device video. Before the first Auto Cut or Auto Captions request, a separate disclosure identifies the data sent to OpenAI, its purpose and deletion timing. Declining blocks audio extraction, upload, the AI request and credit charge, not local editing. You can prevent future transfers by not using the optional AI features. Delete consent records by deleting your bake account in Profile → Account, deleting app data, or requesting withdrawal. To withdraw consent or request suspension of processing, email hunyeon.studio@gmail.com. Turn off push in Profile → Notification Settings; this unregisters the current-device push token and cancels scheduled local notifications while notification-inbox records remain until account deletion. You may permanently delete your account in Profile → Account. See our data deletion instructions.