Privacy Policy

Neosapience, Inc. (hereinafter "the Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of Korea, in order to inform data subjects of the procedures and standards under which their personal information is processed, and to handle grievances related to the Neona AI service promptly and smoothly.

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes and does not use it for any purpose other than those stated below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act (PIPA) of Korea.

  1. Membership Registration and Management

Personal information is processed for the purposes of confirming the intent to register as a member, identifying users in connection with the provision of membership-based services, restricting registration by children under 14 years of age, providing simplified (social) login, maintaining and managing membership status, and delivering various notices and notifications.

  1. Service Provision

Personal information is processed for the purposes of providing AI character conversations and voice/video content services, managing usage records, processing payments and settlement, informing users of new features and service updates, and providing events/promotions.

  1. Service Analysis and Improvement

Personal information is processed for the purposes of analyzing service usage, performing demographic analysis, and improving the service.

  1. Complaint Handling

Personal information is processed for the purposes of verifying the identity of the complainant, confirming the details of the complaint, making contact and giving notice for fact-finding, and communicating the results of the handling.

2. Personal Information Items Processed and Retention Periods

The Company collects and uses personal information of data subjects on the following legal bases.

  1. Personal information items processed without the consent of the data subject

The following personal information items are processed without the consent of the data subject.

Legal BasisCategoryPurpose of ProcessingItems ProcessedRetention Period
Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract)Membership registration (social login)Membership registration and management[Required] UID, email address (Google account or Apple account)Until membership withdrawal
Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract)Contact Us (complaint handling)Handling of member inquiries and support(Required) UID, email address3 years (Article 6 of the Act on Consumer Protection in Electronic Commerce)
Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract)Payment processing and settlement for credit purchasesService provision[Web payments] (credit/debit card) card number (16 digits), (KakaoPay/Toss Pay/PAYCO) payment completion information; [App payments] in-app payment completion information5 years (Article 6 of the Act on Consumer Protection in Electronic Commerce)
  1. Personal information items processed with the consent of the data subject

The following personal information items are processed with the consent of the data subject.

Legal BasisCategoryPurpose of ProcessingItems ProcessedRetention Period
Article 15(1)(1) of the Personal Information Protection Act (PIPA) of Korea (consent of the data subject)Events/promotionsService provision(Required) Email addressUntil membership withdrawal or withdrawal of consent
  1. Retention periods required by statute

Even after membership withdrawal or loss of membership status, the Company retains personal information for the statutory retention periods required by applicable laws in the following cases.

Legal BasisCategoryRetention Period
Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement DecreeRecords on display and advertising6 months
Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement DecreeRecords on contracts or withdrawal of offers5 years
Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement DecreeRecords on payment and the supply of goods, etc.5 years
Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement DecreeRecords on consumer complaints or dispute resolution3 years
Article 85-3 of the Framework Act on National TaxesBooks and supporting documents relating to all transactions prescribed by tax law5 years
Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement DecreeWebsite visit records (log records, access IP addresses, etc.)3 months
  1. Notice regarding facial images and biometric information

The Company provides features that generate AI-based content using images uploaded by users (e.g., photos containing faces). Accordingly, the Company makes the following clear disclosures.

3. Processing of Personal Information of Children Under 14

① The Company restricts membership registration for customers under 14 years of age, for whom the consent of a legal representative would be required.

4. Rights and Obligations of Users and Legal Representatives, and How to Exercise Them

① Users and their legal representatives may at any time request the Company to allow access to, transmit, correct, or delete their personal information, to suspend its processing, or to withdraw consent (hereinafter "exercise of rights").

② Rights may be exercised against the Company in writing or by telephone, email, fax, the internet, or similar means, and the Company will take action without delay.

③ Rights may also be exercised through an agent, such as the user's legal representative or an authorized delegate. In such cases, a power of attorney in the attached form must be submitted.

④ A user's right to request access to or suspension of processing of personal information may be restricted.

⑤ Deletion of personal information may not be requested where that personal information is specified as subject to collection under other laws.

⑥ The Company verifies whether the person exercising rights is the data subject or a legitimate agent.

⑦ Users may exercise their rights through the department below. The Company will respond within 10 days from the date it receives a request to exercise rights.

▶ Department for Receiving and Handling Requests to Exercise Personal Information Rights

5. Outsourcing of Personal Information Processing

① For the smooth handling of personal information tasks, the Company outsources personal information processing as follows.

Outsourcee (Processor)Outsourced Task
OpenRouter, Inc.AI conversation generation and content translation (LLM)
LangfuseLLM logging and observability
Typecast (Neosapience)Speech synthesis (TTS)
PixAICharacter image generation
HedraVideo generation
LiveKit, Inc.Real-time voice/video chat
Amazon Web Services, Inc.Cloud infrastructure and media (S3) storage
MongoDBData storage
Google LLC (Firebase)Authentication, push notifications (FCM), and social login
Mixpanel, Inc.Service usage behavior analysis
Functional Software, Inc. (Sentry)Error monitoring
Toss Payments Co., Ltd.Card payment gateway (web; KRW, Korea)
Apple Inc.iOS in-app purchases and subscription management
Google LLC (Google Play)Android in-app purchases and subscription management
AppsFlyer Ltd.Install attribution and deep linking
AB180 Inc. (Airbridge)Attribution and deep linking
Slack Technologies (Salesforce)Internal operational notifications

② When concluding outsourcing contracts, the Company specifies in the contract or other documents matters concerning the prohibition of processing personal information for purposes other than performing the outsourced task, technical and administrative protection measures, restrictions on sub-outsourcing, management and supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely.

③ Where a processor sub-outsources the Company's personal information processing tasks, it obtains the Company's consent, and the sub-processor and the details of the sub-outsourced tasks are disclosed through this Privacy Policy.

④ If the details of the outsourced tasks or the processor changes, the Company will disclose this without delay through this Privacy Policy.

⑤ Cases where personal information processing is outsourced overseas are described in "8. Overseas Collection and Transfer of Personal Information."

6. Destruction of Personal Information

In principle, the Company destroys personal information without delay once the purpose of its processing has been achieved. The procedures, timing, and methods of destruction are as follows.

① The Company destroys personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period, achievement of the purpose of processing, discontinuation of the relevant service, or closure of the business.

② Where personal information must continue to be preserved under other laws despite the expiration of the retention period consented to by the user or the achievement of the purpose of processing, the personal information is moved to a separate database (DB) or preserved in a different storage location.

※ The items of personal information preserved under other laws, the legal basis for preservation, and the preservation periods can be found in "2. Personal Information Items Processed and Retention Periods."

③ The procedures and methods for destroying personal information are as follows.

a. Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen, and destroys the personal information with the approval of the Company's Personal Information Protection Officer.

b. Destruction method: The Company destroys personal information recorded and stored in electronic file format so that the records cannot be reproduced, and destroys personal information recorded and stored on paper documents by shredding or incineration.

7. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

① The Company collects and uses cookies, IP addresses, and access device information in order to provide personalized services.

a. A cookie is a very small text file sent by a web server to the user's browser and stored on the user's computer hard drive. When the user visits the website again, the server reads the contents of the cookie stored on the user's PC to maintain the service settings configured by the user.

b. An IP address is online address information assigned by an internet network provider to devices, such as PCs, that connect to the internet.

c. Access device information is information that can be identified through the software used to operate the device.

② The Company uses cookies for the purpose of analyzing site visits and usage patterns, purchased items, items of interest, and the like, in order to provide differentiated information tailored to the user's tastes and interests.

③ Users have a choice regarding cookies. By configuring options in the web browser, users may allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. However, refusing the storage of cookies may cause difficulties in using some services.

a. How to block cookie collection in web browsers

Web BrowserHow to Block Cookie Collection
ChromeSettings > Privacy and security > Delete browsing data
EdgeSettings > Cookies and site permissions > Manage and delete cookies and site data
SafariSettings > Privacy > Cookies and website data

b. How to block cookie collection in mobile browsers

Web BrowserHow to Block Cookie Collection
ChromeSettings > Privacy and security > Delete browsing data
EdgeSettings > Advanced > Block all cookies
SafariSettings > Browsing history > Clear browsing history

8. Overseas Collection and Transfer of Personal Information

The Company transfers personal information collected from service users overseas as described below; if you refuse the overseas transfer, use of the service is not possible.

Legal basis: Article 28-8(1)(3)(a) of the Personal Information Protection Act (PIPA) of Korea (overseas transfer of personal information)

Personal Information Items TransferredDestination CountryTiming and Method of TransferRecipientPurpose of UseRetention and Use Period
Chat conversation content (entire messages)United StatesTransferred on an ongoing basis over an encrypted network during service useOpenRouter, Inc.AI conversation generationUntil membership withdrawal or withdrawal of consent
Chat messages, traces, session IDsGermany (EU)Transferred on an ongoing basis over an encrypted network during service useLangfuseLLM logging and observabilityUntil membership withdrawal or withdrawal of consent
Image generation promptsJapanTransferred on an ongoing basis over an encrypted network during service usePixAICharacter image generationUntil membership withdrawal or withdrawal of consent
AI-generated output (image and voice data)United StatesTransferred on an ongoing basis over an encrypted network during service useHedraVideo generationUntil membership withdrawal or withdrawal of consent
Voice/video streamsUnited StatesTransferred on an ongoing basis over an encrypted network during service useLiveKit, Inc.Real-time voice/video chatUntil membership withdrawal or withdrawal of consent
All personal information collected during service use, generated mediaUnited StatesTransferred on an ongoing basis over an encrypted network during service useAmazon Web Services, Inc.Data storage and cloud infrastructureUntil membership withdrawal or withdrawal of consent
All member information, conversations, payment records, etc.United StatesTransferred on an ongoing basis over an encrypted network during service useMongoDBData storageUntil membership withdrawal or withdrawal of consent
Email, social identifiers, device identifiers, push tokensUnited StatesTransferred on an ongoing basis over an encrypted network during service useGoogle LLC (Firebase)Authentication, push notifications, statisticsUntil membership withdrawal or withdrawal of consent
User ID, access logs, usage events, sessionsUnited StatesTransferred on an ongoing basis over an encrypted network during service useMixpanel, Inc.Usage behavior analysisUntil membership withdrawal or withdrawal of consent
IP address, device/OS, logs, (depending on settings) user identification informationUnited StatesTransferred on an ongoing basis over an encrypted network during service useFunctional Software, Inc. (Sentry)Error monitoringUntil membership withdrawal or withdrawal of consent
Apple ID, purchase history, device identifiersUnited StatesTransferred on an ongoing basis over an encrypted network during service useApple Inc.iOS in-app purchases and subscriptionsUntil membership withdrawal or withdrawal of consent
Google account, purchase history, device identifiersUnited StatesTransferred on an ongoing basis over an encrypted network during service useGoogle LLC (Google Play)Android in-app purchases and subscriptionsUntil membership withdrawal or withdrawal of consent
Advertising identifiers, app eventsIsrael/United StatesTransferred on an ongoing basis over an encrypted network during service useAppsFlyer Ltd.Install attributionUntil membership withdrawal or withdrawal of consent

9. Personal Information Protection Officer and Grievance Handling Department

① The Company designates a Personal Information Protection Officer as follows, who bears overall responsibility for personal information processing and for handling user complaints and providing remedies related to personal information processing.

▶ Personal Information Protection Officer

▶ Personal Information Protection Department

② Users may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from the use of the Company's services (or business) to the Personal Information Protection Officer and the department in charge. The Company will respond to and handle user inquiries without delay.

10. Remedies for Infringement of Users' Rights and Interests

Users who wish to obtain relief from personal information infringement, such as dispute resolution or consultation, may file reports or seek consultation with the following agencies.

  1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
  2. Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
  3. Korean National Police Agency: 182 (no area code) (ecrm.police.go.kr)
  4. Supreme Prosecutors' Office Cyber Crime Investigation Unit: 1301 (no area code) (www.spo.go.kr)

11. Measures to Ensure the Security of Personal Information

The Company takes the following measures to ensure the security of personal information.

  1. Administrative Measures: Establishment and implementation of an internal management plan, regular employee training, operation of a dedicated organization
  2. Technical Measures: Management of access rights to personal information processing systems, installation of access control systems and other related protective measures, network isolation measures, encryption of personal information, storage and inspection of access records, installation, operation, and updating of security programs, and inspection and remediation of vulnerabilities in personal information processing systems
  3. Physical Measures: Access control to computer rooms, data storage rooms, and similar facilities; storage of important documents in secure locations with locking devices; safety measures against disasters and calamities

12. Changes to the Privacy Policy

If there are additions, deletions, or modifications to this Privacy Policy, prior notice will be given through "Announcements" at least 7 days before the revision.

However, where there are significant changes to user rights, such as changes to the items of personal information collected or the purposes of use, notice will be given at least 30 days in advance, and user consent may be obtained again if necessary.

This Privacy Policy takes effect from July 17, 2026. Previous versions of the Privacy Policy can be viewed below.

[Entity Collecting and Using Personal Information]