"Neona" is a conversational AI agent platform that allows users to select agents with various personas and engage in voice conversations. Neona is a personalized, interactive media service that lets you have voice conversations with AI characters represented through animation. Free credits are provided by default, and credits are deducted based on your use of the service, such as conversations and generation. You may purchase additional credits to continue conversations.
By using Neona, you are deemed to have agreed to these Terms. If you do not agree to these Terms, please do not use the service. Matters concerning the collection and use of personal information are set forth separately in the Privacy Policy, which you should read before using the service.
Company Information: The Neona service is provided by our team (hereinafter "the Company," "we," or "us"). We may revise or update these Terms from time to time during the operation of the service. If there are material changes to the Terms, we will notify you in advance through in-app notices, email, or similar means. The most current Terms will always be posted in the app or on the website, and you can verify the most recent revision date via the "Last Updated" date at the top of the Terms. If you continue to use the service after the revised Terms take effect, you will be deemed to have agreed to the changes. If you do not agree to the revised Terms, please discontinue use of the service, and you may request account deletion if necessary.
To use the main features of Neona, you may need to create a user account. In connection with account registration and management, you agree to and must comply with the following:
The Company reserves the right to take action such as restricting, suspending, or deleting accounts that violate these Terms or applicable laws, when deemed necessary. For details, please refer to the "Termination of Service" section.
You must not engage in any of the following while using the service.
If a user violates any of the above, the Company may take measures such as making the content private or deleting it, restricting content creation, restricting use of the service, or suspending or terminating the account. In the case of sexual content involving children or adolescents, the Company will take the highest level of measures immediately and without prior notice, and may report the matter to investigative authorities in accordance with applicable law.
The detailed criteria for determining whether conduct falls under any of the above, and the stages of the measures taken, are set forth in a separate operational policy.
Neona values users' personal information, and matters concerning the processing of personal information are governed by the Privacy Policy. These Terms provide a brief overview of personal information handling; for details, please refer to the separate Privacy Policy document.
Credits are entitlements within the service and are divided into the following two types.
When credits are used, free credits are used before paid credits, and among free credits, those closest to expiration are used first. This order is intended to minimize losses to users from lapsed credits.
If the Company changes the expiration terms in a manner unfavorable to users, it will give advance notice, and credits granted before the change remain subject to the terms in effect before the change.
If there are changes to service content, the Company will notify users at least 7 days before the changes take effect through in-service notices, email, app push notifications, and similar means. In the case of service termination, users will be notified at least 30 days in advance through notices, individual notifications, and pop-up windows upon service access. Upon service termination, unused credits may be used until the termination date, and for unused credits above a certain amount, cash refunds or conversion options to other services may be provided. After service termination, personal information will be destroyed immediately after the mandatory retention period required by law has passed, and the destruction method and schedule will be announced. Where necessary, information may be anonymized and used solely for statistical purposes.
For disputes related to these Terms, the Company may cooperate with laws and judicial authorities to protect its rights. The governing law for these Terms is the laws of the Republic of Korea, and related laws (Electronic Commerce Act, Information and Communications Network Act, Copyright Act, etc.) shall be observed.
For inquiries regarding the Terms of Service, please contact us at the following:
These Terms of Service take effect from October 1, 2026. Previous versions of the Terms of Service can be viewed below.
Neosapience, Inc. (hereinafter "the Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of Korea, in order to inform data subjects of the procedures and standards under which their personal information is processed, and to handle grievances related to the Neona AI service promptly and smoothly.
The Company processes personal information for the following purposes and does not use it for any purpose other than those stated below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act (PIPA) of Korea.
Personal information is processed for the purposes of confirming the intent to register as a member, identifying users in connection with the provision of membership-based services, restricting registration by children under 14 years of age, providing simplified (social) login, verifying age and preventing duplicate account registration through identity verification, maintaining and managing membership status, and delivering various notices and notifications.
Personal information is processed for the purposes of providing AI character conversations and voice/video content services, managing usage records, processing payments and settlement, informing users of new features and service updates, and providing events/promotions.
Personal information is processed for the purposes of analyzing service usage, performing demographic analysis, analyzing the quality of AI responses, and improving the service. Pseudonymized information under Section 12 is used for the analysis of AI response quality.
Personal information is processed for the purposes of verifying the identity of the complainant, confirming the details of the complaint, making contact and giving notice for fact-finding, and communicating the results of the handling.
The Company collects and uses personal information of data subjects on the following legal bases.
The following personal information items are processed without the consent of the data subject.
| Legal Basis | Category | Purpose of Processing | Items Processed | Retention Period |
|---|---|---|---|---|
| Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract) | Membership registration (social login) | Membership registration and management | [Required] UID, email address (Google account, Apple account, Kakao account, or LINE account) | Until membership withdrawal |
| Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract) | Service use | Provision of the AI character conversation service | (Required) chat conversation content, service usage history | Until membership withdrawal (information pseudonymized under Section 12 is retained for the period set out in that Section) |
| Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract) | Contact Us (complaint handling) | Handling of member inquiries and support | (Required) UID, email address | 3 years (Article 6 of the Act on Consumer Protection in Electronic Commerce) |
| Article 15(1)(4) of the Personal Information Protection Act (PIPA) of Korea (execution and performance of a contract) | Payment processing and settlement for credit purchases | Service provision | [Web payments] (credit/debit card) payment method information (card number masked by the payment provider, card issuer name, and the like), (KakaoPay/Toss Pay/PAYCO) payment completion information; [App payments] in-app payment completion information | 5 years (Article 6 of the Act on Consumer Protection in Electronic Commerce) |
| Article 23-3 of the Act on Promotion of Information and Communications Network Utilization and Information Protection of Korea (identity verification through an identity verification agency) | Identity verification | Age verification and prevention of duplicate account registration | (Required) duplicate registration information (DI), date of birth, gender, and domestic/foreign national status | Until membership withdrawal; provided that the duplicate registration information (DI) is retained for one year after withdrawal |
The following personal information items are processed with the consent of the data subject.
| Legal Basis | Category | Purpose of Processing | Items Processed | Retention Period |
|---|---|---|---|---|
| Article 15(1)(1) of the Personal Information Protection Act (PIPA) of Korea (consent of the data subject) | Events/promotions | Service provision | (Required) Email address | Until membership withdrawal or withdrawal of consent |
Even after membership withdrawal or loss of membership status, the Company retains personal information for the statutory retention periods required by applicable laws in the following cases.
| Legal Basis | Category | Retention Period |
|---|---|---|
| Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree | Records on display and advertising | 6 months |
| Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree | Records on contracts or withdrawal of offers | 5 years |
| Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree | Records on payment and the supply of goods, etc. | 5 years |
| Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree | Records on consumer complaints or dispute resolution | 3 years |
| Article 85-3 of the Framework Act on National Taxes | Books and supporting documents relating to all transactions prescribed by tax law | 5 years |
| Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree | Website visit records (log records, access IP addresses, etc.) | 3 months |
The Company provides features that generate AI-based content using images uploaded by users (e.g., photos containing faces). Accordingly, the Company makes the following clear disclosures.
To provide features and content that require age verification, and to prevent one person from creating multiple accounts, the Company offers mobile identity verification through an identity verification agency (NICE Information Service Co., Ltd.).
① The Company restricts membership registration for customers under 14 years of age, for whom the consent of a legal representative would be required.
① Users and their legal representatives may at any time request the Company to allow access to, transmit, correct, or delete their personal information, to suspend its processing, or to withdraw consent (hereinafter "exercise of rights").
② Rights may be exercised against the Company in writing or by telephone, email, fax, the internet, or similar means, and the Company will take action without delay.
③ Rights may also be exercised through an agent, such as the user's legal representative or an authorized delegate. In such cases, a power of attorney in the attached form must be submitted.
④ A user's right to request access to or suspension of processing of personal information may be restricted.
⑤ Deletion of personal information may not be requested where that personal information is specified as subject to collection under other laws.
⑥ The Company verifies whether the person exercising rights is the data subject or a legitimate agent.
⑦ Users may exercise their rights through the department below. The Company will respond within 10 days from the date it receives a request to exercise rights.
▶ Department for Receiving and Handling Requests to Exercise Personal Information Rights
① For the smooth handling of personal information tasks, the Company outsources personal information processing as follows.
| Outsourcee (Processor) | Outsourced Task |
|---|---|
| OpenRouter, Inc. | AI conversation generation and content translation (LLM) |
| Langfuse | LLM logging and observability |
| Typecast (Neosapience) | Speech synthesis (TTS) |
| PixAI | Character image generation |
| Hedra | Video generation |
| LiveKit, Inc. | Real-time voice/video chat |
| Amazon Web Services, Inc. | Cloud infrastructure and media (S3) storage |
| MongoDB | Data storage |
| Google LLC (Firebase) | Authentication, push notifications (FCM), and social login |
| Mixpanel, Inc. | Service usage behavior analysis |
| Functional Software, Inc. (Sentry) | Error monitoring |
| Toss Payments Co., Ltd. | Card payment gateway (web; KRW, Korea) |
| Apple Inc. | iOS in-app purchases and subscription management |
| Google LLC (Google Play) | Android in-app purchases and subscription management |
| AppsFlyer Ltd. | Install attribution and deep linking |
| AB180 Inc. (Airbridge) | Attribution and deep linking |
| Slack Technologies (Salesforce) | Internal operational notifications |
| NICE Information Service Co., Ltd. | Mobile identity verification (age verification and prevention of duplicate account registration) |
② When concluding outsourcing contracts, the Company specifies in the contract or other documents matters concerning the prohibition of processing personal information for purposes other than performing the outsourced task, technical and administrative protection measures, restrictions on sub-outsourcing, management and supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely.
③ Where a processor sub-outsources the Company's personal information processing tasks, it obtains the Company's consent, and the sub-processor and the details of the sub-outsourced tasks are disclosed through this Privacy Policy.
④ If the details of the outsourced tasks or the processor changes, the Company will disclose this without delay through this Privacy Policy.
⑤ Cases where personal information processing is outsourced overseas are described in "8. Overseas Collection and Transfer of Personal Information."
In principle, the Company destroys personal information without delay once the purpose of its processing has been achieved. The procedures, timing, and methods of destruction are as follows.
① The Company destroys personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period, achievement of the purpose of processing, discontinuation of the relevant service, or closure of the business. Of the identity verification information, the date of birth, gender, and domestic/foreign national status are destroyed without delay upon membership withdrawal, and the hash value of the duplicate registration information (DI) is destroyed after the period set out in Section 2 has elapsed.
② Where personal information must continue to be preserved under other laws despite the expiration of the retention period consented to by the user or the achievement of the purpose of processing, the personal information is moved to a separate database (DB) or preserved in a different storage location.
※ The items of personal information preserved under other laws, the legal basis for preservation, and the preservation periods can be found in "2. Personal Information Items Processed and Retention Periods."
③ The procedures and methods for destroying personal information are as follows.
a. Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen, and destroys the personal information with the approval of the Company's Personal Information Protection Officer.
b. Destruction method: The Company destroys personal information recorded and stored in electronic file format so that the records cannot be reproduced, and destroys personal information recorded and stored on paper documents by shredding or incineration.
④ Upon membership withdrawal, chat conversation content is destroyed without delay. However, information pseudonymized under Section 12 (Processing of Pseudonymized Information) is retained for the period set out in that Section and is destroyed without delay once that period has elapsed.
① The Company collects and uses cookies, IP addresses, and access device information in order to provide personalized services.
a. A cookie is a very small text file sent by a web server to the user's browser and stored on the user's computer hard drive. When the user visits the website again, the server reads the contents of the cookie stored on the user's PC to maintain the service settings configured by the user.
b. An IP address is online address information assigned by an internet network provider to devices, such as PCs, that connect to the internet.
c. Access device information is information that can be identified through the software used to operate the device.
② The Company uses cookies for the purpose of analyzing site visits and usage patterns, purchased items, items of interest, and the like, in order to provide differentiated information tailored to the user's tastes and interests.
③ Users have a choice regarding cookies. By configuring options in the web browser, users may allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. However, refusing the storage of cookies may cause difficulties in using some services.
a. How to block cookie collection in web browsers
| Web Browser | How to Block Cookie Collection |
|---|---|
| Chrome | Settings > Privacy and security > Delete browsing data |
| Edge | Settings > Cookies and site permissions > Manage and delete cookies and site data |
| Safari | Settings > Privacy > Cookies and website data |
b. How to block cookie collection in mobile browsers
| Web Browser | How to Block Cookie Collection |
|---|---|
| Chrome | Settings > Privacy and security > Delete browsing data |
| Edge | Settings > Advanced > Block all cookies |
| Safari | Settings > Browsing history > Clear browsing history |
The Company transfers personal information collected from service users overseas as described below; if you refuse the overseas transfer, use of the service is not possible.
Legal basis: Article 28-8(1)(3)(a) of the Personal Information Protection Act (PIPA) of Korea (overseas transfer of personal information)
| Personal Information Items Transferred | Destination Country | Timing and Method of Transfer | Recipient | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|
| Chat conversation content (entire messages) | United States | Transferred on an ongoing basis over an encrypted network during service use | OpenRouter, Inc. | AI conversation generation | Until membership withdrawal or withdrawal of consent |
| Chat messages, traces, session IDs | Germany (EU) | Transferred on an ongoing basis over an encrypted network during service use | Langfuse | LLM logging and observability | Until membership withdrawal or withdrawal of consent |
| Image generation prompts | Japan | Transferred on an ongoing basis over an encrypted network during service use | PixAI | Character image generation | Until membership withdrawal or withdrawal of consent |
| AI-generated output (image and voice data) | United States | Transferred on an ongoing basis over an encrypted network during service use | Hedra | Video generation | Until membership withdrawal or withdrawal of consent |
| Voice/video streams | United States | Transferred on an ongoing basis over an encrypted network during service use | LiveKit, Inc. | Real-time voice/video chat | Until membership withdrawal or withdrawal of consent |
| All personal information collected during service use, generated media | United States | Transferred on an ongoing basis over an encrypted network during service use | Amazon Web Services, Inc. | Data storage and cloud infrastructure | Until membership withdrawal or withdrawal of consent |
| All member information, conversations, payment records, etc. | United States | Transferred on an ongoing basis over an encrypted network during service use | MongoDB | Data storage | Until membership withdrawal or withdrawal of consent (information preserved under applicable law and information pseudonymized under Section 12 are retained for their respective periods) |
| Email, social identifiers, device identifiers, push tokens | United States | Transferred on an ongoing basis over an encrypted network during service use | Google LLC (Firebase) | Authentication, push notifications, statistics | Until membership withdrawal or withdrawal of consent |
| User ID, access logs, usage events, sessions | United States | Transferred on an ongoing basis over an encrypted network during service use | Mixpanel, Inc. | Usage behavior analysis | Until membership withdrawal or withdrawal of consent |
| IP address, device/OS, logs, (depending on settings) user identification information | United States | Transferred on an ongoing basis over an encrypted network during service use | Functional Software, Inc. (Sentry) | Error monitoring | Until membership withdrawal or withdrawal of consent |
| Apple ID, purchase history, device identifiers | United States | Transferred on an ongoing basis over an encrypted network during service use | Apple Inc. | iOS in-app purchases and subscriptions | Until membership withdrawal or withdrawal of consent |
| Google account, purchase history, device identifiers | United States | Transferred on an ongoing basis over an encrypted network during service use | Google LLC (Google Play) | Android in-app purchases and subscriptions | Until membership withdrawal or withdrawal of consent |
| Advertising identifiers, app events | Israel/United States | Transferred on an ongoing basis over an encrypted network during service use | AppsFlyer Ltd. | Install attribution | Until membership withdrawal or withdrawal of consent |
① The Company designates a Personal Information Protection Officer as follows, who bears overall responsibility for personal information processing and for handling user complaints and providing remedies related to personal information processing.
▶ Personal Information Protection Officer
▶ Personal Information Protection Department
② Users may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from the use of the Company's services (or business) to the Personal Information Protection Officer and the department in charge. The Company will respond to and handle user inquiries without delay.
Users who wish to obtain relief from personal information infringement, such as dispute resolution or consultation, may file reports or seek consultation with the following agencies.
The Company takes the following measures to ensure the security of personal information.
① Pursuant to Article 28-2 of the Personal Information Protection Act of Korea, the Company may process pseudonymized information without the consent of the data subject for the purposes of compiling statistics and scientific research.
② Purposes of processing: Analysis of AI response quality and advancement of conversation models, and compilation of statistics on service usage behavior.
③ Items processed: Chat conversation content and service usage history. Information that can identify a user is replaced with a separate value, and the additional information used for that replacement is stored separately.
④ Retention period: Five years from the date of pseudonymization. If the purpose of processing is achieved earlier, the information is destroyed without delay.
⑤ Measures to ensure security
a. Pseudonymized information and the additional information are stored separately, and access rights to each are granted differently.
b. The Company does not process pseudonymized information for the purpose of identifying a specific individual. If information that can identify a specific individual is generated in the course of processing, the Company immediately ceases processing and retrieves and destroys such information.
c. Pseudonymized information is not provided to third parties.
⑥ This Section takes effect on October 8, 2026. The "Service use" item in the table under Section 2(1) and Section 6(4) take effect on the same date.
If there are additions, deletions, or modifications to this Privacy Policy, prior notice will be given through "Announcements" at least 7 days before the revision.
However, where there are significant changes to user rights, such as changes to the items of personal information collected or the purposes of use, notice will be given at least 30 days in advance, and user consent may be obtained again if necessary.
This Privacy Policy takes effect from October 1, 2026. However, the "Service use" item in the table under Section 2(1), Section 6(4), and Section 12 (Processing of Pseudonymized Information) take effect on October 8, 2026. Previous versions of the Privacy Policy can be viewed below.
[Entity Collecting and Using Personal Information]