KEYBUST PRIVACY
This policy explains how KeyBust processes information in connection with its services and integrations.
To provide online-comment records and AI analysis, KeyBust processes the following information. Phone numbers, advertising identifiers, and separately tracked behavioral analytics are not included in the categories described in this policy.
The application database is not implemented to separately collect or store IP addresses, device identifiers, user agents, or advertising identifiers. Vercel may process technical operational information such as request, error, and runtime logs while hosting the service. KeyBust server logs may contain processing identifiers, counts, and error messages, but are not designed to intentionally record comment text.
AI analysis and repeat-account classifications are reference information about risky expressions or activity patterns. They are not used to determine a person’s identity, criminal conduct, or legal status.
Information may be transmitted to and processed by the following external services where necessary to provide the service. Each provider’s policy governs its processing location and detailed retention standards.
| Service | Information processed or transferred | Purpose |
|---|---|---|
| Supabase | Authentication identifiers, email, authentication sessions, protection settings, cases, evidence, comments, analysis, and connection data | Authentication and database operations |
| Google OAuth | OAuth authentication information for sign-in or YouTube connection | Google sign-in and YouTube authorization connection |
| YouTube Data API / YouTube API | Content identifiers for analysis URLs, public content, channel and comment information, and channel or live information accessed with authorization tokens when connected | Content and comment collection and live connection |
| OpenAI API | Original comment text, normalized comment text, and rule-based rationale | AI risk, classification, and rationale generation |
| CHZZK API / OAuth | OAuth authentication information, channel identifiers and names, and live or chat information when connected | CHZZK live connection and chat collection |
| Vercel | Web request, error, and runtime operational information | Web hosting, deployment, and operations |
OpenAI API requests are not implemented to send a comment author name, author ID, analysis URL, and KeyBust member ID together. YouTube and CHZZK connections are used only when you choose to connect them.
Member and Evidence Vault data are retained as needed to provide the service and manage your records. When you delete a case or evidence item, associated evidence, sources, comments, and related data are designed to be deleted together.
Some automatically created URL-analysis cases with no risky comments, saved evidence, or PDF exports, and which you have not chosen to keep or reopen, may be automatically deleted after 24 hours. When you delete your account, KeyBust keeps no separate account-linked retention record for legal, billing, or security purposes, and account-linked data are deleted as part of the deletion process. Payment records at Google Play and backup or security logs of external providers such as Supabase and Vercel may be subject to those providers’ legal and operational retention policies.
PDFs are generated on the server when requested and are not implemented to be stored as separate files in the KeyBust database. A PDF export request record and selected evidence identifiers may be recorded.
When an account is deleted, original uploaded files are first deleted from private storage and the Supabase Auth user is permanently deleted. Personal vault data, YouTube and CHZZK OAuth connections and encrypted refresh tokens, live monitors and sessions, and personal protection settings associated with that user identifier are then deleted. Certain shared review and classification data may be retained after the user identifier is set to NULL so that it can no longer be associated with your account, for service-quality improvement. This applies to profanity-variant dictionary submissions and reviews, human review results for other records, and classification corrections and review information. Our Account and data deletion guide is publicly available.
KeyBust does not sell personal information or disclose it to third parties for advertising or marketing. Transfers to the external services listed in Section 3 occur only as necessary for authentication, data storage, AI analysis, platform connections you select, and hosting.
KeyBust uses Supabase for authentication and database services, Vercel for hosting and operations, and the OpenAI API for AI analysis. Google, YouTube, and CHZZK are connected through sign-in or channel connections you choose. The legal classification of each relationship, relevant agreements, and details of international transfers will be reflected in this policy after confirmation against actual operational settings and contracts.
You may request access, correction, deletion, or suspension of processing of your personal information. You can change protection settings directly in the settings screen and delete individual cases in the Evidence Vault. You may delete your account after final confirmation in the account-deletion area of your protection settings. When deletion is complete, your sign-in session ends and you are returned to the main screen. The publicly accessible Account and data deletion guide explains the deletion process and scope. For privacy requests, contact support@keybust.kr.
For privacy inquiries or requests for access, correction, or deletion, contact us at:
This policy may be updated due to changes in service features, external integrations, retention periods, or applicable laws. For material changes, we will provide notice of the effective date and the changes through the service or this page.
KeyBust uses YouTube API Services to provide its services.
Through YouTube API Services, KeyBust may process YouTube data necessary to provide its services, including public comments and live chat messages associated with YouTube content selected or connected by the user.
Information processed through YouTube API Services may also be subject to Google's Privacy Policy.
Google Privacy Policy: https://policies.google.com/privacy
This Privacy Policy is effective as of August 8, 2026.