Loading…
Loading…
Privacy
Foo AI Corp. (the “Company”) establishes and discloses the following privacy policy under Article 30 of the Personal Information Protection Act (PIPA) in order to protect the personal information of data subjects and to handle related grievances promptly.
Griing is an AI English learning service for adults aged 18 and over. The AI coach is generative artificial intelligence and is not a person. The Company does not accept sign-up by children under 14, and actively blocks use by anyone under 18.
| Purpose | Details |
|---|---|
| Sign-up, member management, identity verification | Confirming adults aged 18 and over, blocking children under 14, preventing fraudulent use, account recovery |
| Providing the AI English learning service | Conversation, correction, accumulation and review of expression assets, weekly reports, processing of voice replies |
| Payment and subscription management | Paid subscription payment, auto-renewal, refunds, retention of transaction records |
| Sending notifications | Learning briefings (functional), transaction and policy notices (system), promotional information (with consent) |
| Safety and crisis response | Safe responses and referral to specialized institutions when expressions of self-harm or suicide are detected |
| Service improvement | Error analysis, quality evaluation (use of conversation logs for model improvement requires separate consent and is subject to opt-out) |
| Meeting legal obligations | Retention of records required by law, such as the Electronic Commerce Act and the Information and Communications Network Act |
| Category | Items | Collection method |
|---|---|---|
| Required (member) | Mobile identity verification information (name, date of birth, gender, domestic or foreign national status, DI (duplicate join verification information); CI is not retained), email or social login identifier | Identity verification agency integration |
| Required (service) | English conversation text, correction results, expression assets, List of Facts (name, occupation, goals, interests, 5 to 10 items), learning history and review, self-assessed level | Generated during use |
| Optional | Voice replies (only the transcript is stored, original audio 0 days), voice corpus (with opt-in consent) | User input |
| Automatically generated | (App) device identifier, push token, access IP and logs, app usage events (conversation content is not included, only hashed identifiers) (Web) referral cookie (griing_ref), anonymous analytics identifier (griing_aid), page usage events | Automatically collected |
| Payment | Subscription status, payment method token (original card details are not retained, the payment gateway handles them), transaction history | At the time of payment |
Policy of not storing original voice audio: a voice reply is deleted immediately after speech-to-text (STT) conversion and is not stored on the server. If audio temporarily remains because the conversion pipeline failed, it is automatically destroyed within 24 hours at most.
Automatic collection devices on the web (cookies and local storage): the marketing web attributes the inbound source using the first-party cookie griing_ref (an opaque value that holds an invitation or referral code, retained for 30 days). Only where the built-in analytics feature is active, the anonymous identifier griing_aid (a random value stored in the browser that persists until the user deletes it) and usage events such as page views and clicks are processed with a first-party analytics tool, and the overseas transfer to that tool follows Section 7. These values do not identify an individual and are not used for cross-site tracking for advertising purposes. A user may delete or block cookies and local storage in the browser settings at any time to refuse collection, and refusing does not restrict use of the Service.
| Item | Retention period | Basis |
|---|---|---|
| Conversations, corrections, expression assets, List of Facts, learning progress, level, scores | While the membership is active. After deletion is requested, erased from the operational database within 72 hours (accounts under a legal hold excepted). Backups and restore copies expire on their own once the backup retention window (23 days or less) passes | PIPA §21 |
| Original voice audio | 0 days (deleted immediately after transcription) / 24 hours for residue in the pipeline | Operating policy |
| Voice corpus (opt-in) | Until consent is withdrawn. Destroyed within 30 days after withdrawal | Consent form |
| Identity verification records (time, method, DI) | 6 months after withdrawal | Dispute preparedness |
| Payment and contract records | 5 years | Electronic Commerce Act §6 |
| Records of consumer complaints and dispute handling | 3 years | Electronic Commerce Act §6 |
| Crisis, safety, and minor-signal event records (pseudonymized) | Kept for up to 3 years, then converted into de-identified statistics with the original text destroyed (records on hold for a dispute or lawsuit are excepted until it ends) | Safety and litigation preparedness |
| Permission and access audit logs (pseudonymized, append-only) | Kept for 3 to 5 years, then destroyed | Security and dispute preparedness |
| Access logs (IP and similar) | 3 months | Enforcement Decree of the Protection of Communications Secrets Act |
| Training data for model improvement (reflecting opt-out) | Until the purpose is achieved, after pseudonymization | PIPC guidance |
Method of destruction: electronic files are deleted in an unrecoverable manner, and printed materials are shredded or incinerated. The bulk erasure from the operational database within 72 hours of withdrawal runs as an automated batch, and a pseudonymized audit record of each run is kept. Backups and restore copies are not deleted separately; they expire once the backup retention window passes. Accounts under a legal hold (a dispute, an investigation, or a tax obligation) are held back from destruction until that obligation ends.
The Company does not provide the personal information of data subjects to third parties. The following cases are exceptions.
| Entrusted party | Entrusted work |
|---|---|
| Supabase Inc. | Database, authentication, storage (storage location: Seoul region) |
| Railway / infrastructure hosting | Application server operation |
| Identity verification agency (one of PortOne identity, NICE, PASS, and so on) | Mobile identity verification and age verification |
| PortOne (domestic payments) · Paddle.com Market Ltd. (overseas payments) | Payment and subscription processing |
| Expo / FCM and APNs | Sending push notifications |
The Company transfers personal information overseas as follows, for AI processing, infrastructure, payment, and similar purposes.
| Recipient | Country | Items transferred | Purpose of use | Retention period |
|---|---|---|---|---|
| Google LLC (Gemini) | United States | English conversation text, List of Facts | AI correction and response generation | Immediately upon processing (not stored) |
| OpenAI, L.L.C. | United States | Voice transcript text, conversation text (moderation) | STT, content safety checks | Same as above |
| Anthropic, PBC | United States | Conversation text | AI response generation (fallback) | Same as above |
| Supabase Inc. | United States entity (data is stored in the Seoul region) | All items, including member, conversation, and payment data | Data processing and storage | The retention period table in Section 4 |
| Paddle.com Market Ltd. | United Kingdom | Payment and subscription information (email, transaction history) | Overseas payment processing and tax (Merchant of Record) | 5 years (by law) |
| Expo (Expo Push) | United States | Push token | Push delivery | The validity period of the token |
| PostHog, Inc. | United States | Event name, non-PII event properties (screen, step, error code and the like), analytics identifier (web: a random value stored in the browser; app: the member identifier), inbound referral code, and access IP. Conversation text, learning text and voice are not transferred | Analysis of service usage and feature reach, error detection | Per the retention setting of the PostHog project |
A data subject may exercise the following rights at any time.
| Right | How to exercise it | Handling deadline |
|---|---|---|
| Request for access and correction | App settings or email | Within 10 days |
| Deletion (withdrawal) | Withdrawal within two taps in the app settings | Service access is blocked as soon as the request is received, the operational database is erased within 72 hours (accounts under a legal hold excepted), and backups expire once the retention window passes |
| Individual correction or deletion of a List of Facts entry | The memory management screen in the app | Immediately |
| Request to suspend processing | Customer center | Without delay |
| Opt-out of use for model improvement | Toggle in the app settings | Immediately (excluded from the next training batch) |
The Company does not accept membership sign-up by children under 14. If age verification at the sign-up stage confirms that an applicant is under 14, the Company immediately stops the sign-up and destroys the collected information without delay.
Access privilege management, access control, retention of access records (an append-only audit log), encryption, protection against malicious code, and physical access control. Sensitive data such as crisis event logs is stored separately, access is limited to two people, and access records are kept.
| Chief Privacy Officer | JEEHO SONG (contact@griing.com) |
|---|---|
| Grievance handling and inquiries | contact@griing.com · +82-2-581-3001 |
Other reports and counseling on infringement of personal information: Personal Information Dispute Mediation Committee (1833-6972), Privacy Infringement Report Center (118), Supreme Prosecutors’ Office (1301), National Police Agency (182).
A change to this policy is announced from 7 days before it takes effect. However, a change unfavorable to data subjects (an expansion of the items collected, the purposes of use, provision to third parties, or overseas transfer, and so on) is announced from 30 days in advance, and consent is obtained again where necessary.