Privacy Policy

Exodus Ent, Ltd.(hereinafter referred to as the "Company") recognizes the protection of users' personal information as a matter of paramount importance with respect to the "KamiOshi" mobile application service (hereinafter referred to as the "Service"). The Company complies with relevant laws and regulations regarding personal information protection, protects the rights and interests of users, and establishes this Privacy Policy (hereinafter referred to as the "Policy") in order to smoothly handle users' complaints and consultations regarding personal information.
When modifying the Privacy Policy, the Company will notify users through in-app announcements or the official website.
○ This Policy shall come into effect on May 26, 2026.

Article 1 (Purpose of Processing Personal Information)

The Company processes (uses) collected personal information for the following purposes. Processed personal information will not be used for purposes other than the following, and prior consent will be sought from users if the purpose of use changes.
(1)Member Registration and Management:
Confirmation of intent to register as a member, personal identification and authentication for providing membership services, maintenance and management of member qualifications, personal identification due to the implementation of a restrictive personal identification system, prevention of unauthorized use of services, confirmation of whether a statutory agent consents when collecting personal information of children under 14 years old, various notices and notifications, handling of complaints, and retention of records for dispute mediation.
(2)Customer Support and Complaint Resolution:
Identification of applicants, verification of complaints and consultations, contacting and notifying for fact-finding investigations, and notification of processing results.
(3)Provision of Goods or Services: 
Provision of the Service, provision of content, provision of customized (personalized) services, personal authentication, and age verification.
(4)Utilization for Marketing and Advertisements:
Development of new services (products) and provision of customized services, provision of events and promotional information and opportunities to participate, provision of services and posting of advertisements based on demographic characteristics, verification of service effectiveness, identification of access frequency, or statistical analysis regarding members' use of the Service.

Article 2 (Items of Personal Information to be Processed)

1 The Company collects the following minimum personal information as mandatory or optional items for member registration, smooth customer consultation, and provision of various services:
(1)Apple Easy Member Registration
Mandatory items: Profile information (email address, name)
Optional items: Email address
(2)Google Easy Member Registration
Mandatory items: Profile information (email address, name, profile picture)
(3)LINE Easy Member Registration
Mandatory items: Profile information (nickname, profile picture, status message), internal identifier
2 In the course of using the service or processing business operations, the following information may be automatically generated or additionally collected:
(1)IP address, device information (device identifiers, etc.), access logs, date and time of visit, payment and purchase information, service utilization records, bad use records, advertising identifiers (ADID/IDFA).

Article 3 (Processing and Retention Period of Personal Information)

1 The Company processes and retains personal information within the period of retention and use of personal information based on laws and regulations, or within the period of retention and use of personal information agreed upon by the User at the time of collecting personal information. In principle, the Company destroys the applicable personal information without delay once the purpose of processing personal information has been achieved.
2 However, information retained for a certain period in accordance with internal policies or applicable laws and regulations is as follows:
(1)Information related to member registration and management
Purpose of retention: User management, prevention of unauthorized use, and response to complaints
Retention period: 3 years from the date of consent to collection and use
Basis: Consent of the data subject and standards for record management regarding collection/processing and use of credit information.

Article 4 (Matters Concerning the Provision of Personal Information to Third Parties)

1 The Company provides personal information to third parties only when it falls under applicable laws and regulations, such as when prior consent of the User is obtained or there are special provisions in laws.
2 Except for the cases mentioned above, the Company does not provide users' personal information to third parties.

Article 5 (Entrustment of Personal Information Processing)

1 In principle, the Company does not entrust the processing of personal information to external companies without the User's consent.
2 If entrustment of business becomes necessary in the future, the Company will specify matters concerning responsibilities such as prohibition of personal information processing for purposes other than performing entrusted business, technical and administrative protection measures, restrictions on re-entrustment, management and supervision of the trustee, and liability for damages in documents such as contracts in accordance with relevant laws and regulations, and will thoroughly supervise whether the trustee processes personal information safely.
3 If the details of the entrusted business or the trustee change, it will be disclosed through this Policy without delay.

Article 6 (Rights and Obligations of Data Subjects and Methods of Exercise)

1 Users may exercise the following rights at any time as personal data subjects:
(1)Request to view personal information
(2)Request correction if there are errors, etc.
(3)Request deletion
(4)Request suspension of processing
2 The exercise of rights under Paragraph 1 can be made through the customer support window designated by the Company (in-app inquiry or email: kamioshi@myloveidol.com), and the Company will take appropriate measures against this without delay.
3 If a User requests correction or deletion of errors, etc., in personal information, the Company will not use or provide the applicable personal information until the correction or deletion is completed.
4 The exercise of rights under Paragraph 1 can be made through agents such as the statutory agent of the User or a person who has been delegated. In this case, documents proving the power of agency, such as a power of attorney, must be submitted.

Article 7 (Destruction of Personal Information)

1 In principle, the Company destroys personal information without delay when the purpose of processing personal information has been achieved. The procedures, time limits, and methods for destruction are as follows:
(1)Destruction Procedures: 
 Information entered by the User is transferred to a separate database (a separate storage file in the case of paper) after the purpose is achieved, and is destroyed after being stored for a certain period or immediately in accordance with internal policies and other relevant laws and regulations. At this time, personal information transferred to the database will not be used for other purposes unless required by law.
(2)Destruction Time Limit: 
The User's personal information will be destroyed within 5 days from the end date of the retention period if the retention period has expired, or within 5 days from the date when processing is recognized as unnecessary when the personal information becomes unnecessary due to the achievement of the processing purpose, abolition of the service, or termination of business.
(3)Destruction Method: 
Information in the form of electronic files is destroyed using technical methods (such as low-level formatting) that cannot reproduce records. Personal information printed on paper is destroyed by shredding with a shredder or through incineration.

Article 8 (Measures to Ensure Safety of Personal Information)

1 The Company takes technical, administrative, and physical measures necessary to ensure safety in accordance with relevant laws and regulations as follows:
(1) Minimization and Education of Employees Handling Personal Information: The Company designates employees who handle personal information and limits them to the minimum necessary to strictly manage personal information.
(2)Implementation of Regular Self-Audits: Self-audits are conducted regularly (once a quarter) to ensure stability related to personal information handling.
(3)Formulation and Implementation of Internal Management Plans: Internal management plans are formulated and implemented in accordance with company regulations for the safe processing of personal information.
(4)Encryption of Personal Information: Important personal information, such as the User's password, is encrypted, stored, and managed so that only the User knows it. In addition, separate security functions such as encrypting file transfer data are used for important data.
(5)Technical Countermeasures Against Hacking, etc.: The Company installs security programs, conducts periodic updates and inspections, and installs systems in areas where external access is controlled to technically and physically monitor and block personal information leakage and damage caused by hacking or computer viruses.
(6)Restriction of Access to Personal Information: Necessary measures are taken for access control to personal information through granting, changing, and canceling access rights to the database system that processes personal information, and unauthorized access from the outside is controlled using an intrusion prevention system.
(7)Retention of Access Records and Prevention of Falsification/Alteration: Records of connection to the personal information processing system are retained and managed for at least 6 months, and security functions are used to prevent access records from being falsified, altered, stolen, or lost.
(8)Matters Concerning Installation, Operation, and Refusal of Automatic Personal Information Collection Devices: In principle, the Company does not use cookies for behavioral tracking purposes that infringe upon users' privacy. If cookies are used in web browsers, users can refuse cookie collection by adjusting their settings.

Article 9 (Personal Information Protection Officer and Department)

1 The Company takes overall responsibility for business concerning personal information processing, and designates a Personal Information Protection Officer as follows for handling users' complaints and damage relief related to personal information processing:
▶ Personal Information Protection Officer
Name: Seongho Han
Position: Chief Executive Officer (CEO)
Contact: 02-6959-5225, kamioshi@myloveidol.com
※ Connected to the personal information protection department.
▶ Personal Information Protection Department
Department Name: Security Team
Person in Charge: Booyoung Park
Contact: 02-6959-5225, kamioshi@myloveidol.com
2 Users may inquire with the Personal Information Protection Officer and the department in charge regarding any and all inquiries, complaint handling, and damage relief related to personal information protection arising from using the Company's services. The Company will answer and process users' inquiries without delay.
3 Users may also officially request to view personal information through the "Personal Information Protection Comprehensive Support Portal" website of the Ministry of the Interior and Safety (http://www.privacy.go.kr ) in accordance with relevant laws and regulations.

Article 10 (Agencies for Complaint Handling and Consultation regarding Personal Information)

1 The following organizations are public agencies separate from the Company. If you are not satisfied with the results of the Company's independent personal information complaint handling and damage relief, or if you need more detailed assistance, please contact them:
(1)Personal Information Infringement Report Center (Operated by KISA)
Website: privacy.kisa.or.kr
Phone: 118 (without area code)
(2)Personal Information Dispute Mediation Committee (Operated by KISA)
Website: privacy.kisa.or.kr
Phone: 118 (without area code)
(3)Cyber Crime Investigation Unit, Supreme Prosecutors' Office: 02-3480-3573 (http://www.spo.go.kr )
(4)Cyber Crime Investigation Unit, National Police Agency: 1566-0112 (www.netan.go.kr)

Article 11 (Amendment of Privacy Policy)

1 This Privacy Policy applies from the effective date. If there are additions, deletions, or corrections of modifications in accordance with laws and regulations and policies, it will be notified through announcements within the app or the official website from 7 days prior to the enforcement of the modifications.