Privacy Policy
1. Introduction
Wintoriva Inc. (hereinafter referred to as the "Company") operates the service, EmotiKkok. To protect the freedoms and rights of our users, the Company complies with the Personal Information Protection Act (PIPA) of the Republic of Korea and other relevant laws. Pursuant to Article 30 of the PIPA, we hereby establish and disclose this Privacy Policy to inform users of our procedures and standards for processing personal information and to ensure that any related grievances are handled promptly and efficiently.
2. Purposes of Processing Personal Information
The Company processes personal information for the following purposes in accordance with the Personal Information Protection Act (PIPA). Personal information will not be used for any purpose other than those listed below. In the event that the purpose of processing is changed, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the PIPA.
- User Registration and Account Management Personal information is processed to verify identification and intent to join via social login; confirm agreement to the Terms of Service and verify age eligibility; maintain and manage accounts; prevent fraudulent service use and verify re-registration eligibility under operating policies; process account cancellations and perform data destruction procedures; and deliver various notices and notifications.
- Provision of Service Features and Content Personal information is processed to provide storage and retrieval functions for data entered or configured by the user (including emotion levels, notes, and system-provided nicknames); to implement visualization and editing functions for records; to provide interactive dialogue with AI virtual characters and event content (including customized environments based on the user's selected language and character type); to manage access rights and verify usage restrictions in accordance with service policies; and to display recording activity data and provide localized settings.
- Service Operation and Stability Personal information is processed to manage service usage records based on access logs and IP addresses; detect abnormal usage and security threats; identify and debug system errors; perform data backup and recovery for server operations; and prevent security incidents.
- Customer Support and Report Processing Personal information is processed to verify and respond to user inquiries; process complaints and notify results; perform fact-checking and implement disciplinary measures (such as usage restrictions) in response to reports of inappropriate dialogue within the service; and preserve records for dispute resolution purposes.
- Service Improvement and New Feature Development Personal information may be utilized to optimize the user experience through service usage pattern analysis; enhance existing features and operating policies; develop and test new AI-based services; verify service validity (retention analysis); and evolve AI dialogue styles and optimize service algorithms. Furthermore, the Company may process reported dialogue by deleting or replacing personally identifiable information to create anonymous information that cannot identify a specific individual. Such anonymous data is utilized for research and statistical purposes to improve AI response quality and optimize prompts. All such analyses are conducted strictly within a scope for statistical purposes that does not identify specific individuals.
3. Personal Information We Process
The Company processes personal information in accordance with the Personal Information Protection Act ("PIPA").
(1) Items Processed Without Separate Consent
The Company processes the following personal information without requiring separate consent, based on the performance of a contract for service provision (PIPA Art. 15(1)4) and the legitimate interests of the Company (PIPA Art. 15(1)6). However, for items that may contain sensitive information, such as personal notes directly entered by the User, processing is conducted only after obtaining separate and explicit consent.
- User Registration and Account Management
- Required Items: Identity Provider (Google/Apple), Platform-specific Unique Identifier (UID), Email Address, Internal User ID, Registration/Modification Timestamps, Account Settings (Nickname configured through the system's predefined combinations, Language, Country).
- Legal Basis: PIPA Art. 15(1)4 (Performance of a Contract).
- Service Provision and Usage Record Management
- Items Processed: Emotional states (emotion levels, stress indices), personal notes, service usage records (log creation/modification timestamps, activity history, selected AI characters and items, interaction counts per session, session completion status, service usage timestamps), AI dialogue usage data (temporary conversation context data for response generation and session maintenance).
- Items Collected upon Reporting: Full text of the dialogue session subject to the report (both User and AI utterances), reason for report, identifiable information related to the report, and access logs.
- Legal Basis: PIPA Art. 15(1)4 (Performance of a Contract) and Art. 15(1)6 (Legitimate interests in ensuring service safety and preventing abuse).
- Notices:
- Regarding Sensitive Information: Personal notes voluntarily entered by the User may contain sensitive information as defined under Article 23 of the PIPA (e.g., health status, religion, beliefs). The Company obtains separate explicit consent for such items upon registration or service use. Collected information is processed solely for the purpose of providing storage and retrieval functions for emotional records. The Company does not analyze User-entered content to infer health status, beliefs, or political opinions, nor does it conduct profiling for such purposes.
- Volatility of Dialogue and Exceptional Storage: When using AI virtual character dialogue services, the actual text content of conversations is not stored on our servers or databases. It is processed only as a temporary state (Custom State) for API transmission and is immediately destroyed upon the end of the session. However, if a User reports inappropriate AI utterances, the Company collects the full text of that session and related information for safety management and fact-checking. Such data is stored for a maximum of 90 days before being destroyed (unless longer retention is required by applicable laws). This process is conducted through an explicit verification procedure at the time of reporting.
- Statistical Use of Data: To prevent duplicate use of services and optimize content, the Company processes limited statistical data that cannot identify a specific individual, such as conversation timestamps and progress metrics.
- Data Destruction and Succession: Upon account deletion (withdrawal), User account information and service record data are permanently deleted (Hard Delete) within a specified grace period to prevent fraudulent use and organize the system. However, supplementary records related to AI dialogue may be converted into a state where specific individuals cannot be identified and utilized as statistical material. Data required for preservation by law or internal policy, such as report records, will be destroyed after a separate retention period. Detailed procedures are outlined in Sections 5 and 6. In the event of a merger, division, or transfer of business, personal information may be transferred to ensure service continuity pursuant to Article 27 of the PIPA, with prior notice provided.
- AI Service Operation and Safety Monitoring
- Items Processed: Real-time dialogue text data (not stored on servers; destroyed immediately after analysis).
- Purpose of Use: Real-time monitoring and response to policy violations based on the OpenAI Moderation API to ensure User safety.
- Legal Basis: PIPA Art. 15(1)4 (Performance of a Contract) and Art. 15(1)6 (Legitimate interests in maintaining service safety).
- Notice: If policy violations (self-harm, child sexual abuse, hate speech, threats, violence, illegal acts, etc.) are detected, dialogue may be restricted. Such data is used temporarily for analysis purposes only.
- Customer Support and Consultation
- Required Items: User's email address, inquiry details.
- Optional Items: Device information (model, OS, app version) voluntarily provided by the User for support, and any attachments provided by the User.
- Legal Basis: PIPA Art. 15(1)4 (Performance of a Contract).
- Notice: Users may refuse to provide optional items. While support remains available without them, there may be limitations in in-depth error analysis or technical support.
- Automatically Generated and Collected Information
- Items Processed: IP address, access timestamps, device information (OS, version, model), coarse geographic location (city-level), browser info (User Agent), Locale settings, referral source, behavioral data (dwell time, funnel/drop-off data, click events, navigation paths, session duration, app error logs, update version, content usage history, AI session duration, and usage limit verification records).
- Purpose of Use: Ensuring service stability and security, system error analysis, UI/UX improvement via Google Firebase and Google Analytics, service usage pattern analysis (excluding note content) for business decision-making, and monitoring AI response quality.
- Legal Basis: PIPA Art. 15(1)6 (Legitimate interests) and Art. 15(1)4 (Performance of a Contract - Service optimization and security).
- Notice: The Company utilizes Google Firebase and Google Analytics for statistical analysis. Collected behavioral data is never combined with personally identifiable information and is processed in a fully anonymized state. We utilize this only as aggregated statistical data, not as pseudonymous information.
- Summary of Legal Basis:
- Security and Stability: Legitimate interests of the Company to provide and secure the service (PIPA Art. 15(1)6).
- Service Improvement: Legitimate interests of the Company to analyze anonymized usage patterns for quality enhancement (PIPA Art. 15(1)6). Users may opt-out via device settings as outlined in Section 13.
- Contract Performance: Providing seamless service and managing usage limits requested by the User (PIPA Art. 15(1)4).
- Age Verification: Legitimate interests of the Company to ensure compliance with the policy of serving Users aged 17 and older (PIPA Art. 15(1)6).
(2) Information Obtained from Third Parties
- External Authentication Services: The Company utilizes authentication services from Google and Apple for simplified login. During this process, the Company receives the user's email address and platform-specific unique identifiers (UID/Subject ID). These are persistent values that remain unchanged even if the user’s platform profile information is updated. The Company does not collect or store direct authentication credentials, such as passwords.
(3) Processing of Sensitive and Unique Identifying Information
- The Company does not collect or process unique identification numbers (e.g., Resident Registration Numbers) prescribed by law.
- In principle, the Company does not proactively request or intentionally collect sensitive information (such as thoughts, beliefs, religion, or health status) that may significantly infringe upon a user’s privacy.
- However, in the case of sensitive information (such as psychological states) that may be included in notes directly entered by the user, the Company stores and preserves such information only after obtaining separate and explicit consent. Collected information is processed solely for the purpose of providing storage and retrieval functions to the user, and the Company strictly refrains from any processing activities, such as arbitrary access or profiling to infer personal tendencies.
- Information entered during interactions with AI virtual characters is processed only as volatile data (such as Custom States) and is not stored in the database (DB). Such data is immediately destroyed upon the termination of the dialogue session or page navigation, and the Company cannot recover or access it.
- For the purpose of improving AI response quality and conducting related research, the Company utilizes only anonymized information from which personally identifiable information has been removed. The Company does not directly collect or use sensitive information in its original, user-entered state as training data for AI models.
- The Company applies a high level of technical and administrative security measures required by law to protect stored sensitive information, including AES-256 encrypted storage, minimization of access privileges, and SSL/TLS encrypted transmission.
(4) Provision of Personal Information to Third Parties
- The Company processes the user's personal information only within the scope specified in Section 3 and does not process it beyond this scope or provide it to third parties without the user's prior consent.
- The Company does not currently provide users' personal information to any third parties, including external agencies or companies.
- However, exceptions may be made in cases that fall under Articles 17 and 18 of the PIPA, such as when required by special provisions of the law (e.g., requests from investigative agencies in accordance with procedures and methods prescribed by law for investigative purposes).
4. Protection of Personal Information of Minors
The Company implements the following age-based usage restrictions and protection measures to safeguard the personal information of users.
- Age Restriction (Age 17 and Older): To protect users in accordance with applicable laws and regulations, the Service is available only to individuals aged 17 and older. The Company does not permit registration or use of the Service by individuals under the age of 17.
- No Intentional Collection: The Company verifies user age through an age confirmation pop-up at the time of registration and does not knowingly collect or process personal information from users under the age of 17.
- Immediate Remediation: If the Company becomes aware that personal information of a user below the age limit, such as a child under 14, has been collected, or upon the request of a legal representative, the Company will immediately terminate the associated account and destroy the relevant information without delay in accordance with relevant laws.
- User Responsibility: Users are required to confirm that they are aged 17 or older during the registration process. The Company assumes no liability for any consequences arising from a user's misrepresentation of their age.
5. Retention and Processing Period of Personal Information
- The Company processes and retains personal information within the retention and usage period prescribed by relevant laws or the period notified to the User at the time of collection.
- The specific processing and retention periods for each category are as follows:
- Account Registration and Management: Permanent deletion within 72 hours of account withdrawal request
- Upon requesting withdrawal, the account is immediately deactivated, and re-registration is restricted for up to 72 hours to prevent service abuse and ensure stable system processing.
- In cases where management is required to prevent fraudulent use or verify compliance with operating policies: Internal identification information is stored in an encrypted state for up to 90 days from the date of withdrawal before destruction.
- If an investigation related to a violation of relevant laws is ongoing: Until the conclusion of the relevant investigation.
- Emotional Logs: Permanent deletion within 72 hours of withdrawal request or upon manual deletion by the User
- User-recorded "Emotional Logs" (emotion levels, stress indices, note content, timestamps, activity history—including sensitive information within notes) are subject to a Hard Delete from our database within 72 hours of withdrawal for system efficiency and data organization.
- AI Character Dialogue Logs: De-identification within 72 hours of withdrawal request
- "AI Character Dialogue Logs" (interaction counts, session status, character/item selections, usage info) are converted into a state where specific individuals cannot be identified within 72 hours of withdrawal. These are retained as anonymous data for statistical purposes to improve service quality.
- Reported AI Dialogue Data: Up to 90 days from the date of report (unless longer retention is required by law)
- If a User reports inappropriate AI utterances, the collected dialogue and related information are stored for fact-checking and safety management for the specified period regardless of the User's withdrawal status. However, text data from which personally identifiable information has been removed may be retained indefinitely as anonymous information for research and AI response quality optimization.
- Mandatory Retention Under Relevant Laws:
- Records on consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce).
- Records on contracts, withdrawal of offers, payments, and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce).
- Log data and connection tracking data: 3 months (Protection of Communications Secrets Act).
- Automatically Generated/Collected Information: Subject to relevant laws and external platform policies
- Service usage statistics and analysis logs: Destroyed upon account withdrawal or upon expiration of the retention period set by external platforms (Google Firebase, Google Analytics).
- Platform backup data: Automatically destroyed after a maximum of 30 days in accordance with the backup policy of the service platform (Bubble.io).
6. Procedures and Methods for Destruction of Personal Information
- The Company destroys personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period, achievement of processing purposes, or the User's withdrawal from the service.
- If personal information must be preserved in accordance with other laws, such information shall be stored separately from other personal information. Details can be found in Section 5 (Retention and Processing Period).
- The specific procedure and method for destroying personal information are as follows:
- Destruction Procedure
- Upon Account Deletion: The account is immediately deactivated upon withdrawal request, and re-registration is restricted for up to 72 hours for security. User account info and "Emotional Logs" are permanently removed via Hard Delete from the database within 72 hours. For abuse prevention, minimal identifiers may be stored separately in an encrypted state for the period defined in Section 5.
- Upon Deletion of Individual Records: When a User deletes a specific emotional log, the data (including sensitive info) is immediately removed via Hard Delete and becomes irrecoverable by any technical means.
- AI Character Dialogue Logs: Dialogue text between the User and AI is not stored in the database and is destroyed immediately upon session termination. Logs generated during the process are de-identified within 72 hours of withdrawal, ensuring they no longer identify any specific individual. Such data is maintained as Anonymous Information under the PIPA for statistical analysis.
- Reported Dialogue Records: Dialogue stored exceptionally for fact-checking via the reporting function is destroyed after the period specified in Section 5. The Company may utilize the text data for AI research after fully removing identifiable information to render it anonymous.
- Automatically Collected Information: Information for statistical analysis is processed upon withdrawal to permanently sever links with account identifiers, transforming it into Aggregated Data. External platform logs are purged automatically based on their respective sequential deletion cycles.
- Destruction Method
- Personal information in electronic file format is completely deleted using technical methods (such as Low-Level Formatting) that render the record unreproducible.
- System backup data and access logs on the service platform (Bubble) are automatically and sequentially destroyed by system configurations following the legal retention periods or platform policies specified in Section 5.
- Text data generated during AI dialogue services is processed only as Volatile Data that is not stored in the database. It is physically and automatically purged from both the server and client-side immediately upon the end of a session or closing of the app.
7. Matters Concerning the Transfer of Personal Information
In the event that the Company transfers personal information to another person due to the transfer of all or part of its business, or through a merger or acquisition, the Company shall notify Users of such facts in advance through in-app notices or service screens. The Company ensures the rights of data subjects regarding the transfer of personal information in accordance with the procedures and methods prescribed by the Personal Information Protection Act ("PIPA") and other relevant laws.
8. Entrustment of Personal Information Processing
- To ensure seamless service operations, the Company entrusts personal information processing tasks as follows:
- Processor: Bubble Group, Inc.
- Entrusted Task: Provision of service infrastructure, encrypted storage and management of member information and content data, and system maintenance. (The Company utilizes this platform as a data repository; the Processor does not separately analyze or process the text content of notes entered by Users.)
- Processor: Google LLC (Google Firebase, Google Analytics)
- Entrusted Task: Statistical analysis of service usage records (excluding note content) and service stability monitoring.
- Processor: OpenAI, Inc.
- Entrusted Task: Real-time text processing for providing interactive services with AI virtual characters, generation of responses, and real-time monitoring (Moderation) to ensure compliance with service safety guidelines. (The dialogue content transmitted is processed as volatile data and is not stored in the Company’s database.)
- Notice: The Company complies with OpenAI’s API policies. All dialogue data, including sensitive information within User-entered notes, is technically configured (via API mode) to not be utilized for AI model training purposes. Transmitted data is used solely for temporary processing to generate real-time responses and detect inappropriate content, and it is handled in a volatile state that is not stored in the Company’s database.
- When entering into an entrustment contract, the Company specifies matters concerning the prohibition of processing personal information for purposes other than the performance of entrusted tasks, technical and administrative protective measures, restrictions on sub-entrustment, management and supervision of the Processor, and liability for damages in accordance with Article 26 of the PIPA. The Company supervises the Processor to ensure that personal information is handled safely.
- In accordance with Article 26, Paragraph 6 of the PIPA, the Company obtains consent if a Processor sub-entrusts the personal information processing tasks, and the Company discloses the sub-processors and the nature of sub-entrusted tasks through this Privacy Policy.
- Should there be any changes to the nature of the entrusted tasks or the Processors, the Company will disclose such changes through this Privacy Policy without delay.
- If personal information processing tasks are performed overseas, relevant details are provided separately in "Section 9. International Collection and Transfer of Personal Information."
9. Overseas Collection and Transfer of Personal Information
To provide seamless global services and enhance user convenience, the Company stores and processes personal information in the United States. Users have the right to refuse the international transfer of their personal information through the contact information provided in Section 15. However, as this service is built on global cloud infrastructure (Bubble, AWS) and AI engines (OpenAI), refusing the international transfer will make it impossible to create an account or use the core features of the service (such as record storage and AI dialogue).
(1) Overseas Entrustment and Storage of Personal Information (Service Infrastructure)
- Legal Basis: Article 28-8, Paragraph 1, Subparagraph 3 of the PIPA (Overseas entrustment and storage for the performance of a contract).
- Items Transferred:
- Account Management Data: Identity Provider (Google/Apple), Platform-specific Unique Identifier (UID), Email Address, Internal User ID, Registration/Modification Timestamps, Account Settings (Nickname, Language, Country).
- Service Usage Data: Emotional states (levels, stress indices), personal notes, service usage records (log creation/modification timestamps, activity history, character/item selections, interaction counts, session status, usage timestamps), AI dialogue usage data (temporary context data for response generation and session maintenance).
- Items Collected upon Reporting: Full text of the dialogue session subject to the report (both User and AI utterances), reason for report, identifiable information related to the report, and access logs.
- Destination Country: United States
- Transfer Method & Timing: Transmitted via encrypted communication (HTTPS) in real-time during service use.
- Recipient: Bubble Group, Inc.
- Privacy Policy: https://bubble.io/privacy
- Contact: support@bubble.io
- Purpose of Transfer: Provision of service infrastructure and secure data storage, fact-checking of reported content, and safety management. (Transferred note content is processed solely for storage purposes to provide the service and is not utilized for separate analysis or statistical purposes.)
- Retention Period: Pursuant to Section 5 (Retention and Processing Period), with key details as follows:
- Account Management: Permanent deletion within 72 hours of withdrawal request.
- Abuse Prevention: Internal identification information stored in an encrypted state for up to 90 days from withdrawal.
- Emotional Logs: Permanent deletion within 72 hours of withdrawal request.
- AI Dialogue Logs: De-identified within 72 hours of withdrawal request and retained as anonymous data for statistical purposes.
- Reported Dialogue: Up to 90 days from the date of report (text data with personally identifiable information removed may be retained for research and AI optimization).
- Platform Backup Data: Automatically destroyed after a maximum of 30 days in accordance with the platform’s (Bubble.io) policy.
- Opt-out Method & Procedure: As the service is built on Bubble infrastructure, users wishing to opt-out of international transfer must proceed with "Account Deletion (Withdrawal)" within the service.
(2) Overseas Entrustment of Personal Information (Analytics Tools)
- Legal Basis: Article 15(1)1 and Article 28-8(1)1 of the PIPA (Consent-based transfer).
- Items Transferred: IP address, access timestamps, device information (OS, version, model), coarse geographic location, browser info (User Agent), Locale settings, referral source, behavioral data (dwell time, funnel data, click events, navigation paths, session duration, error logs, update version, content usage history, AI session duration, and usage limit records).
- Destination Country: United States
- Transfer Method & Timing: Automatically transmitted via the integrated SDK during service use.
- Recipient: Google LLC
- Privacy Policy: https://policies.google.com/privacy
- Contact: https://support.google.com/policies
- Purpose of Transfer: Statistical analysis of user behavior and service quality enhancement.
- Retention Period: In accordance with Google’s data retention policy; processed only as aggregated statistical data that does not identify specific individuals.
- Opt-out Method & Procedure: Users may refuse data collection via device settings or in-app settings. Refer to Section 13 for detailed instructions.
(3) Overseas Entrustment of Personal Information (AI Services)
- Legal Basis: Article 28-8, Paragraph 1, Subparagraph 3 of the PIPA (Overseas entrustment for the performance of a contract).
- Items Transferred: User-configured nickname, Locale settings, and user-inputted dialogue text (which may include sensitive information) and AI-generated responses.
- Destination Country: United States
- Transfer Method & Timing: Transmitted in real-time via API communication during interactions with AI characters.
- Recipient: OpenAI, Inc.
- Privacy Policy: https://openai.com/policies/row-privacy-policy
- Contact: privacy@openai.com
- Purpose of Transfer: Provision of AI-powered conversational content, response generation, and real-time safety monitoring (Moderation) to block inappropriate content.
- Retention Period: Immediate destruction upon session termination (Volatile processing). Dialogue text exists only for temporary processing to generate responses and is not stored on the Company’s servers or databases. However, in cases of user reports, dialogue logs may be stored in secure storage for up to 90 days for fact-checking. Furthermore, in accordance with OpenAI’s policies, such data is not utilized for training AI models.
- Opt-out Method & Procedure: Users may stop international transfer by refraining from using AI dialogue features or through "Account Deletion (Withdrawal)."
(4) Storage of Customer Support Emails
- Legal Basis: Article 15(1)4 and Article 28-8(1)3 of the PIPA (Contract performance).
- Items Transferred:
- (Required): User's email address, inquiry details.
- (Optional): Device information (model, OS, app version) and attachments voluntarily provided by the User.
- Destination Country: United States
- Transfer Method & Timing: Transmitted and stored via the internet upon receipt of a customer inquiry.
- Recipient: Google LLC (Google Workspace / Gmail)
- Purpose of Transfer: Processing customer inquiries and maintaining records for dispute resolution.
- Retention Period: 3 years from the date of inquiry (pursuant to relevant laws).
- Opt-out Method & Procedure: Users may refuse transfer by not sending email inquiries; however, this may limit online consultations and technical support.
10. Measures to Ensure the Safety of Personal Information
The Company implements the following security measures to ensure that your personal information is not lost, stolen, leaked, altered, or damaged:
- Administrative Measures
- The Company has appointed a Data Protection Officer (DPO) and established internal management plans for implementation.
- Access to personal information is strictly limited to the minimum number of essential personnel. All administrative access to our systems requires Multi-Factor Authentication (MFA) to ensure rigorous control.
- Technical Measures
- Access Control & Encrypted Storage: We apply Data-Level Security (Privacy Rules) to ensure that user-generated data is accessible only by the account owner. All personal information, including sensitive information contained within notes, is managed using verified encryption algorithms such as AES-256 when stored in the database. Furthermore, strict criteria for granting and revoking access rights to the personal information processing system are established and enforced. Following our design principles, the Company does not build any separate internal management tools (Admin Panels) designed to individually retrieve or analyze the contents of user notes.
- Encryption in Transit: All data communications within the service are secured using SSL/TLS encryption technology to ensure safe data transmission.
- Log Management & Security: Access logs and personal information processing records are maintained for at least one (1) year. When communicating with external services (e.g., OpenAI), all API keys are managed exclusively on the Server-side to prevent unauthorized exposure. We maintain system security through the installation and operation of security software.
- Enhanced AI Service Security: When transmitting data to external AI models (e.g., OpenAI), the Company transmits only the text data, excluding personal identifiers (names, emails, etc.). We ensure secure server-to-server communication (API key security management, etc.) to prevent data leakage during transmission.
- Physical Measures
- Cloud Infrastructure Security: Our services are hosted on professional cloud infrastructure (Amazon Web Services - AWS) that complies with world-class security standards, including ISO 27001 and SOC 2. The infrastructure is monitored 24/7 with advanced intrusion detection and prevention systems.
11. Potential for Disclosure of Sensitive Information and Opt-out Methods
This service is a private, single-user service that does not, by default, disclose to the public any information entered or configured by the user (including emotion records, notes, and nicknames) or the contents of conversations with AI virtual characters.
- Private Storage Structure: Technical access controls (Privacy Rules) are implemented to ensure that data created by the user is accessible only through records matched with their own account. The Company does not provide any features for sharing records among users or disclosing them to the public within the service.
- User Self-Determination: You have full control over your data through the following measures:
- You decide whether to input sensitive content when creating logs.
- You can immediately destroy stored sensitive information at any time using the in-app deletion feature. Upon deletion, the data is subject to a Hard Delete from our database, making it irrecoverable.
- Data Protection Policy: The Company does not utilize the text content of notes written by users for profiling or statistical analysis. We maintain a closed storage structure where exposure to search engines is blocked. However, in the exceptional case of a "Report" initiated directly by the user, the Company may access the relevant dialogue logs solely for the purpose of fact-checking and safety management.
12. Installation, Operation, and Refusal of Automated Personal Information Collection Devices
- The Company operates automated collection devices (SDKs, server logs) that store and retrieve usage information from time to time to provide personalized services and improve the service environment.
- The details regarding the behavioral information automatically collected by the Company are as follows:
- Legal Basis: Article 15(1)4 of the PIPA (Performance of a Contract) and Article 15(1)1 of the PIPA (User Consent).
- Items Collected: IP address, access timestamps, device information (OS type and version, model name), coarse geographic location (city-level), browser information (User Agent), system language and region settings (Locale), referral source, behavioral data (dwell time, funnel/drop-off data, click events, navigation paths, session duration, app error logs, update version, content usage history, AI session duration, and usage limit verification records).
- Method of Collection: Automated generation and collection via SDKs and server logs during app execution and usage.
- Purpose of Collection: Service provision and security response, prevention of abnormal usage, ensuring system stability, and enhancement of service quality and UI/UX through behavior analysis.
- Retention and Usage Period: Pursuant to Section 5 (Retention and Processing Period) of this Policy. However, fully Anonymized Data that cannot identify a specific individual may be retained and utilized for the duration necessary for service quality improvement and business analysis.
- The Company does not process behavioral information collected under this section for the purpose of providing Targeted Advertising that identifies the user, nor does it sell or share such data with third parties for commercial purposes.
- The Company utilizes professional analytics tools (such as Google Analytics including Firebase Analytics) for statistical analysis and quality improvement. Detailed information can be found in Section 9 (Overseas Transfer) and Section 13 (Third-Party Data Collection).
- How to Refuse Automated Collection: Users may control the operation of automated collection devices through mobile device settings or by uninstalling the application. However, refusing the collection of essential logs may result in restrictions on the use of the service.
- Settings: Device [Settings] > [Applications] > [Select App] > [Permissions] to configure settings for each item.
- Inquiries, exercise of opt-out rights, and grievance reports related to behavioral information can be submitted through the designated department listed in this Policy.
- ▶ Privacy Protection Department
- Department: EmotiKkok Team
- Email: cs_en@emotikkok.com
13. Matters Concerning Third-Party Collection of Behavioral Information via Automated Collection Devices
- The Company allows third-party service providers to collect certain behavioral information through analysis tools (SDKs) to analyze service usage statistics and enhance overall quality.
- The details of behavioral information collected by third parties through the Company’s app are as follows:
- Name of Collection Device: Google Firebase / Analytics SDK
- Type of Collection Device: SDK (Mobile App)
- Service Provider: Google LLC
- Data Collected: IP address, access timestamps, device information (OS name and version, model name), coarse geographic location (city-level), browser information (User Agent), system language and region settings (Locale), referral source, behavioral data (dwell time, funnel/drop-off data, click events, navigation paths, session duration, app error logs, update version, content usage history, AI session duration, and usage limit verification records).
- Purpose of Collection: Statistical analysis of app usage and service error monitoring.
- Such behavioral information is processed solely for statistical analysis without identifying any specific individual and is not used for providing targeted advertising.
- Data subjects may restrict the collection of behavioral information by third parties through the following methods. The Service does not request permissions for location, contacts, or microphone, nor does it collect and utilize advertising identifiers (ADID/IDFA) for advertising purposes. To control the collection of basic usage behavior through analytics tools, the following methods are available:
- Severing Data Connection via Account Deletion: Users can delete all service usage records and identifiable data through the "Delete Account" feature within the app. Upon account deletion, the user’s identifiable information is permanently removed (Hard Delete) or fully anonymized within 72 hours in accordance with the procedures in Sections 5 and 6. This process fundamentally severs the link between behavioral information recorded in third-party analytics tools and the actual user account, leaving only statistical data that can no longer identify a specific individual. However, logs linked with internal identification information may be retained for up to 90 days in exceptional cases, such as for preventing service abuse or verifying compliance with operating policies.
- Tracking Restrictions via Device Settings:
- Android: Settings > Privacy > Ads > Delete Advertising ID (or Opt out of Ads Personalization).
- iOS: Settings > Privacy & Security > Tracking > Disable "Allow Apps to Request to Track." Note: These are device-level security settings. Since the Service does not collect advertising identifiers, changing these settings will not impact the use of the service.
- Stopping Automatic Collection via App Uninstallation: As the Service does not utilize separate web browser cookies, simply uninstalling the app will immediately stop all automatic collection and transmission of behavioral information generated during service use.
- Reviewing and Opting Out of Third-Party (Google) Policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout
- Protection of Children’s Behavioral Information: The Company does not collect behavioral information of children under the age of 14 for targeted advertising purposes, nor does it provide targeted advertising to children in accordance with its age restriction policy.
14. Rights and Obligations of Information Subjects and Legal Representatives and How to Exercise Them
- Users may exercise their rights to access, correct, delete, or withdraw their personal information at any time through the following in-app features:
- Inquiry and Configuration: Users can directly view or change their account settings, such as selecting nicknames from system-provided combinations and choosing language or country preferences, in the [Settings > My Info] menu.
- Records Management: Users can directly modify or immediately delete individual emotional logs (including sensitive information within notes) on the calendar or list screens. Data manually deleted by the user is subject to a Hard Delete from the Company’s database and cannot be technically recovered.
- Account Deletion (Withdrawal): Users can immediately terminate their account via the [Settings > Delete Account] feature within the app.
- Data Destruction Policy Upon Withdrawal: Upon a user's request for withdrawal, the Company follows the destruction procedure specified in Section 6 (Procedures and Methods for Destruction), with the key details as follows:
- Upon requesting withdrawal, the account is immediately deactivated, and re-registration is restricted for up to 72 hours to prevent service abuse and ensure system stability. All account information and User-recorded "Emotional Logs" are subject to a Hard Delete from the database within 72 hours of the withdrawal request. Since the data enters the destruction phase immediately upon withdrawal and is technically irrecoverable, requests for account recovery due to a change of heart cannot be accepted.
- Dialogue-related logs generated during interactions with the AI are completely severed from any personally identifiable information within 72 hours of the withdrawal request. This data is converted into Anonymous Information (where the identity of the user is unknown) and may be maintained for service improvement and statistical analysis rather than being destroyed.
- However, in exceptional cases where management is required to prevent service abuse or verify compliance with operating policies, internal identifiers may be stored separately in an encrypted state for the period defined in Section 5. Reported dialogue logs also follow the preservation policies specified in the relevant provisions.
- Guidance on Disconnecting Social Login:
- Relationship between Withdrawal and External Accounts: Withdrawal from this Service only pertains to the permanent destruction of account information and emotional log data held within our systems. It does not delete the User’s actual account on social login platforms (e.g., Google, Apple).
- Disconnection Process: The revocation of access permissions and the disconnection of external authentication services (Google, Apple, etc.) are within the scope of the User’s direct management as the data subject. Therefore, to fully revoke the Service's access to a social platform account after withdrawal, the User must manually proceed with the disconnection via the "Security" or "Connected Apps" settings of each provider (e.g., Google Account Settings or Apple ID Settings).
- Limitation of Company Liability: The Company does not have the authority to manage the User’s external account settings, nor is it obligated to forcibly revoke external platform permissions upon withdrawal. Users are responsible for managing their own security settings in accordance with the policies of each social platform.
- Users may exercise their rights by submitting a request in writing or via email to the Data Protection Officer. The Company will take action without delay after verifying the identity of the requester.
- Limitations on the Exercise of Rights: The Company may restrict or refuse the exercise of a data subject’s rights in any of the following cases:
- Where retention is mandated by law or is necessary to comply with other legal obligations;
- Where the request significantly interferes with the normal operation of the Service (e.g., repetitive or excessive requests);
- Where the request may unfairly infringe upon the life, physical safety, property, or other interests of a third party;
- Where the data has already been manually deleted by the user;
- Where the account withdrawal has been completed and the data destruction process has already been initiated. Upon withdrawal, data enters a stage where technical recovery is impossible. Therefore, requests for recovery, access, or correction cannot be accommodated after withdrawal. Users are advised to decide carefully when requesting withdrawal.
- Where information requested for deletion is subject to an investigation due to a report, or where retention is mandatory under law or internal policies for fraud prevention and service safety management. (In such cases, the data will be destroyed without delay after the retention period expires.)
- Exercise of Rights by Proxy: If a right is exercised through a legal representative or an authorized agent, a written power of attorney must be submitted in accordance with Form 11 of the "Notice on Personal Information Processing Methods."
15. Contact Information of the Privacy Protection Officer and Dedicated Department
- The Company has designated a Privacy Officer and a dedicated department to oversee the processing of personal information and to address inquiries, complaints, and grievances from users regarding their personal data.
- ▶ Privacy Protection Department
- Department Name: EmotiKkok Team
- Email: cs_en@emotikkok.com
- Users may contact the following department for all privacy-related inquiries, including requests for information access, exercise of rights, or dispute resolution. The Company is committed to responding to and resolving all inquiries promptly and in accordance with applicable laws and regulations.
16. Remedies for Infringement of Rights and Interests
Users may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee or the Personal Information Infringement Reporting Center (operated by the Korea Internet & Security Agency) to seek remedies for personal information breaches. For reporting or consultations regarding other personal information infringements, please contact the following South Korean authorities:
- the Personal Information Dispute Mediation Committee: (Toll-free) 1833-6972 (www.kopico.go.kr)
- the Personal Information Infringement Reporting Center: (Toll-free) 118 (privacy.kisa.or.kr)
- the National Police Agency: (Toll-free) 182 (ecrm.police.go.kr)
17. Governing Language
This Privacy Policy may be provided in both Korean and English versions. In the event of any discrepancy, inconsistency, or conflict between the Korean version and the English version regarding the interpretation or content of this Policy, the Korean version shall prevail and take precedence.
18. Amendments to the Privacy Policy
- This Privacy Policy is effective as of April 23, 2026.
- In the event of any changes to this Privacy Policy, the Company will notify Users in advance via in-app banners, pop-up windows, or in-service notices. As the Company does not collect additional contact information (such as phone numbers), these in-app notices shall serve as and substitute for individual notification to Users.
- Notwithstanding the above, for changes that may materially affect User rights or are unfavorable to Users, the Company will provide at least thirty (30) days' prior notice.
- By continuing to access or use our services after those revisions become effective, you agree to be bound by the revised Privacy Policy. If you do not agree to the new terms, you may opt out by terminating your account through the membership withdrawal process within the app.
[Personal Information Controller Info]
- Business Name: Wintoriva Inc.
- Location: Republic of Korea
- Email: cs_en@emotikkok.com
The Company processes personal information in accordance with relevant laws, and inquiries regarding this Privacy Policy can be submitted to the email address above.
To request account deletion via email, please send your request to cs_en@emotikkok.com using the email address registered with your account. If you used Apple’s "Hide My Email" feature, please include the private relay email address shown in the app's settings.