1. Overview
Olbit (Orvyt) (the “Operator”) complies with applicable privacy law, including the Personal Information Protection Act of the Republic of Korea, and processes personal information only as necessary to provide the service. This policy applies to the Orvyt web service and related features provided directly by the Operator.
When a user chooses an external platform or AI feature, that provider's terms and privacy policy may also apply. Orvyt does not request sensitive information or government-issued unique identifiers as part of ordinary registration.
Orvyt is intended for users aged 14 or older and asks users to confirm that they meet this age requirement during registration. Orvyt does not knowingly collect personal information from children under 14.
2. Purposes and Categories of Personal Information
The data processed depends on the features selected by the user. Not every category is collected from every user.
| Purpose | Data processed | Default retention |
|---|---|---|
| Registration, login, and account management | User identifier, email, name, profile image, login-provider information, session and authentication information | Until membership withdrawal or account deletion, except that a hash of the email address is kept for 3 days after withdrawal to restrict immediate re-registration |
| Music and video project production | Artist and project information, titles, lyrics, prompts, audio, image, video and text files, editing and rendering settings, and output | Until deleted by the user or the account is deleted |
| AI generation, transformation, and rendering | Input content and options required for the requested feature, job identifiers, status, output, and error records | For the period required to provide and recover the job, or until the project is deleted |
| External-account connection and content publication | Platform account and channel identifiers, display name and profile, OAuth tokens and granted scopes, publication metadata, and processing results | Connected YouTube API Data is revalidated or refreshed within 30 days. OAuth tokens and stored data are deleted immediately on disconnection or account deletion |
| Payments, subscriptions, refunds, and transaction management | Plan, order, payment and subscription identifiers, amount, currency, payment status and time, refund and cancellation records | For transaction-record retention periods required by applicable law |
| Customer support and dispute handling | User identifier, email, inquiry and response content, and handling records | For the period needed after resolution or as required by applicable law |
| Optional product analytics | Analytics consent status, anonymous and session identifiers, and page and feature usage events | Collected only with consent and retained for no more than 14 months |
| Essential reliability, security, and error response | IP address, request metadata, and error, security and audit records, excluding secrets and raw user input | Orvyt security events are retained for no more than 30 days; external error records follow the shortest configured provider retention period |
3. Retention
The Operator deletes personal information without undue delay when its purpose has been fulfilled or the user requests deletion. Information that must be retained by law is separated from service data and used only for the legally required purpose.
- Contract or withdrawal records and payment and service-delivery records: 5 years
- Consumer complaint or dispute-resolution records: 3 years
- Display and advertising records: 6 months
- Records necessary for a legal dispute or security incident: until that procedure ends
- Re-registration restriction after withdrawal: the email address of a deleted account is kept for 3 days only as an irreversible hash, never in its original form, and is deleted after 3 days
4. External Services and Processing Providers
The Operator may use the following providers only as necessary to deliver the service. Data for an optional feature is not sent to that feature's provider unless the user selects it.
| Provider | Processing function |
|---|---|
| Supabase | User authentication, databases, and account-data processing |
| Vercel, Google Cloud, and Cloudflare | Web hosting, job processing, file storage, and transfer |
| Vercel Web Analytics | Visit counts measured without cookies or identifiers |
| OpenAI, Google Gemini, xAI, ElevenLabs, and Suno | AI generation or transformation requested by the user |
| Toss Payments and other payment providers | Payment-method registration, recurring payments, cancellation, refunds, and transaction verification |
| Google, YouTube, Meta, TikTok, and DistroKid | Account connections and content publication selected by the user |
| Google Analytics and Microsoft Clarity | Product analytics only when the user has consented |
| Sentry | Essential error collection and security or incident response; performance tracing is not collected |
| Slack and GitHub | Operational notifications, customer-support handling, development, and deployment collaboration |
Processing countries and storage locations may vary with each provider's infrastructure. Where account connection, external transmission, or optional consent is required, Orvyt separately explains the transferred data and effect in the relevant feature.
5. How Orvyt Uses, Processes, and Shares Google and YouTube User Data
Data Orvyt accesses and stores
Orvyt uses YouTube API Services. When a user connects a Google account, Orvyt may access and store the user's Google email address and basic profile information; YouTube channel ID, title, and profile image; accessible playlist and published-video metadata; OAuth access and refresh tokens; and the scopes granted by the user.
How Orvyt uses the data
Orvyt uses this data only to display the connected channel; retrieve, select, and create playlists; upload videos and custom thumbnails; apply user-selected metadata and visibility; schedule publication; and display upload and playlist-update results. Orvyt performs these actions only after the user expressly initiates and confirms them.
Internal processing and access
Google and YouTube user data is processed by Orvyt's access-controlled application and backend systems. Access is limited to authorized Orvyt personnel who require it to operate, secure, troubleshoot, or support the requested integration. Orvyt does not use this data for unrelated internal purposes.
External processing and sharing
Supabase processes authentication records, access-controlled OAuth tokens, and channel-connection data on Orvyt's behalf. Google Cloud processes the backend requests needed to prepare and authorize user-requested YouTube API operations. When a user confirms an upload, the browser transfers the selected video file directly to YouTube through a resumable upload session. Orvyt also transmits the title, description, tags, visibility, thumbnail, audience and disclosure settings, and selected playlist action to YouTube. These providers may process the data only to deliver, secure, and recover the service under Orvyt's instructions and their applicable terms.
No sale or unrelated sharing
Orvyt does not sell Google or YouTube user data and does not share it with advertising providers, other users, OpenAI or other AI providers, Google Analytics, Microsoft Clarity, Sentry, Slack, or GitHub. Orvyt does not use it for advertising targeting, credit assessment, or general-purpose AI model training. Orvyt may disclose the minimum information legally required to a competent authority where necessary to comply with law or protect users and the service.
Retention, revocation, and deletion
- While a channel remains connected, Orvyt retrieves current YouTube API Data when the feature is used. A daily maintenance process also revalidates channel and playlist data through the YouTube API before 30 days have elapsed since the previous validation.
- Users can disconnect a YouTube channel from the Orvyt channel-connection settings.
- Users can also revoke Orvyt's access through Google Account third-party connections.
- When a user disconnects YouTube in Orvyt, Orvyt programmatically revokes the Google OAuth token and immediately deletes stored tokens, channel and playlist references, and YouTube video identifiers. The same stored data is deleted immediately when periodic validation detects that access was revoked through Google.
- Content already published to YouTube is not automatically deleted and must be managed by the user in YouTube Studio.
Use of Google user data is also governed by the Google Privacy Policy, and YouTube features are governed by the YouTube Terms of Service. Orvyt's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
6. Cookies and Product Analytics
Orvyt may use essential cookies or browser storage to maintain login, provide security, and recover work steps. Only when a user consents to analytics does Orvyt use anonymous and session identifiers and page and feature events to improve the service. Those events are automatically deleted within 14 months.
Orvyt counts total visits with Vercel Web Analytics as needed to operate the service. That measurement uses no cookies or browser storage and stores no identifier that could identify a person or track return visits.
Users may change analytics consent at any time in Orvyt's privacy and cookie settings. Declining optional analytics does not prevent login or use of core production features. Users may also delete or restrict cookies through their browser.
Sentry error collection is an essential reliability and security function separate from optional analytics. Orvyt filters error data to prevent raw user input, secrets, and authentication tokens from being transmitted and does not collect performance tracing data.
7. Deletion
Electronic information scheduled for deletion is deleted in a manner designed to make recovery impracticable. Information stored by an external service is handled through that provider's deletion process. Backup data is deleted according to a separate recovery lifecycle and is not reintroduced into ordinary service processing.
Account deletion removes general account and project data, stored files, OAuth tokens, and active sessions. Payment and refund records that must be retained by law are separated from the user account, stripped of direct identifiers, and used only for the statutory purpose. The email hash kept to restrict re-registration is deleted 3 days after withdrawal.
Users should download required projects and output before deleting their account. Content published to or provided directly to an external platform may need to be deleted separately on that platform.
8. User Rights and Requests
Users may request access to, correction or deletion of, restriction of processing of, or withdrawal of consent for their personal information, and may request account deletion. Requests can be submitted through service settings, customer support after login, or the contact information below. Orvyt may request the minimum additional information necessary to verify identity.
A request may be limited where retention is required by law or fulfilling it would infringe another person's rights. Orvyt will explain the reason for a limitation. Orvyt does not provide the service to children under 14.
9. Security Measures
The Operator applies technical and organizational measures appropriate to the personal information processed, including access restrictions, per-user data-access controls, encryption in transit, server-side handling of OAuth tokens and secrets, limited-lifetime signed URLs, sensitive-log filtering, and administrator audit records.
10. Contact and Policy Changes
Privacy questions and rights requests may be submitted through customer support after login or by email at developer@orvyt.kr.
- Privacy officer: ManSub Han, Representative
- Business: Olbit (Orvyt)
- Business registration number: 497-49-01196
- Telephone: 070-8064-2363
If this policy changes materially, Orvyt will provide notice in the service before the change takes effect and will update the effective date and change history on this page.