Yoonseul Privacy Policy
Initial Publication Date: January 10, 2026
Last Updated: February 9, 2026 (v1.2)
Last Updated: June 27, 2026 (v1.3)
Chapter 1. General Provisions
Iroum Co., Ltd. (the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act and other applicable laws of the Republic of Korea, in order to protect the personal information of users and to handle related grievances promptly and effectively.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information processed shall not be used for any purpose other than those listed below. If the purpose of use is changed, the Company shall take necessary measures, such as obtaining separate consent.
- <strong>Membership Registration and Management:</strong> Verification of intent to register, identification and authentication of users, maintenance and management of membership status, and prevention of unauthorized use of the Service.
- <strong>Provision of the Service:</strong> Creation and management of Memorial Spaces, uploading of photographs, videos, and text, guestbook entries, offering floral tributes, and sharing of Spaces.
- <strong>Payment and Settlement:</strong> Processing of payments arising from the use of Premium Subscription services (in-app purchases).
- <strong>Push Notifications:</strong> Delivery of Service-related notifications, including guestbook notifications and floral tribute notifications.
- <strong>Customer Support:</strong> Receipt of and response to user inquiries, and delivery of announcements.
- <strong>Marketing (Optional):</strong> Provision of personalized services, events, and promotional information.
- <strong>AI Conversation and Content Generation Services</strong>: Providing AI-powered conversation features (e.g., "Chat with Yoonseul"), generating conversation summaries and personalized responses, and creating AI-generated content (e.g., daily tea messages, AI Letters)
Article 2 (Consent to the Collection of Personal Information)
The Company provides a procedure through which users may select an "Agree" button regarding the contents of this Privacy Policy or the Terms of Service. When a user selects the "Agree" button, the user shall be deemed to have consented to the collection of personal information.
Article 3 (Items of Personal Information Processed and Methods of Collection)
1. Required Items
- <strong>At Membership Registration:</strong> Social login identifier (Kakao / Google / Apple ID), nickname, email address.
- <strong>For Mobile Phone Verification:</strong> Mobile phone number.
2. Optional Items
- Consent to receive marketing communications
- B2B partner invitation code information
3. Information Automatically Generated and Collected During Use of the Service
- Device information (operating system version, device identifier)
- Service usage records, access logs, and access IP address
- Push notification token (FCM Token)
- When using AI conversation features: conversation content, emotional records entered by the user (e.g., heart temperature, emotion words), and summaries and conversational memory information generated from the conversation
4. Information Not Collected (On-Device Processing)
The following information is processed solely on the user's device for identity verification purposes and is neither transmitted to nor stored on the Company's servers:
- Death verification documents, including death certificates and post-mortem examination certificates.
- Such documents are processed via OCR on the user's device and immediately discarded thereafter. No copy of such documents is stored on the Company's servers under any circumstances.
5. Methods of Collection of Personal Information
- Membership registration through the mobile application
- Linking with social login services (Kakao, Google, Apple)
- Automatic collection during use of the Service
- Inquiries submitted through customer support
Article 4 (Protection of Children's Personal Information)
- The Company restricts membership registration by children under the age of fourteen (14) and does not collect personal information from such children.
- If the Company becomes aware that personal information of a child under the age of fourteen (14) has been collected, the Company shall promptly destroy such information and restrict the use of the Service for the relevant account.
Article 5 (Period of Processing and Retention of Personal Information)
- The Company processes and retains personal information within the retention and use period prescribed by applicable laws or within the period to which the user consented at the time of collection.
- <strong>Standard Retention Period:</strong> Until withdrawal of membership. However, in the case of Memorial Spaces, the information is retained until the Owner or administrator of the Space requests its deletion.
- <strong>Retention Pursuant to Applicable Laws</strong>
- Records concerning contracts or withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records concerning payment and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records concerning consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
- Records concerning access logs: 3 months (Protection of Communications Secrets Act)
- AI Conversation History and Generated Memory Data: Users may delete their conversation history and memory data at any time, immediately, through the features provided within the app upon account deletion.
Article 6 (Destruction of Personal Information)
- When personal information becomes unnecessary, including due to the expiration of the retention period or the achievement of the purpose of processing, the Company shall destroy such personal information without delay.
- If personal information must continue to be retained under applicable laws despite the expiration of the retention period consented to by the user or the achievement of the purpose of processing, such personal information shall be transferred to a separate database or stored in a separate location.
- <strong>Methods of Destruction</strong>
- Electronic files: Permanent deletion using technical methods that prevent restoration.
- Paper documents: Destruction by shredding or incineration.
Article 7 (Provision of Personal Information to Third Parties)
- The Company uses personal information only within the scope notified under Article 1 and, in principle, does not use such information beyond that scope or provide it externally without the prior consent of the user.
- The following cases shall constitute exceptions:
- Where the user has provided prior consent;
- Where required by applicable laws, or where requested by investigative authorities in accordance with the procedures and methods prescribed by law for investigative purposes.
- When providing personal information to a third party, the Company shall notify the user of the recipient, the items provided, the purpose of provision, and the retention and use period, and shall obtain the user's consent. The same procedure shall apply in the event of any change to or termination of the third-party provision relationship.
Article 8 (Entrustment of Personal Information Processing)
- For the smooth processing of the Service, the Company entrusts the processing of personal information as follows:
-
Google LLC (Firebase): Push notification delivery and user authentication.
-
Amazon Web Services: Storage and delivery of content (S3, CloudFront).
-
RevenueCat: Subscription payment management.
- When entering into entrustment agreements, the Company specifies in writing matters concerning the prohibition of processing personal information for purposes other than the entrusted work, technical and administrative protective measures, restrictions on re-entrustment, supervision of the entrusted party, and liability for damages, in accordance with Article 26 of the Personal Information Protection Act, and supervises whether the entrusted parties process personal information safely.
- In the event of any change to the entrusted work or the entrusted party, such change shall be disclosed without delay through this Privacy Policy.
- Google Cloud (Vertex AI): Text processing for AI conversations and AI content generation (conversation content entered by users is not used to train AI models)
Article 9 (Rights and Obligations of Users and Methods of Exercising Them)
- Users may exercise the following rights regarding personal information protection vis-à-vis the Company at any time:
- Right to request access to personal information;
- Right to request correction in the event of errors;
- Right to request deletion;
- Right to request suspension of processing.
- The exercise of such rights may be made through <strong>My Page > Settings</strong> within the application or by email (support@yoonseulapp.co.kr). The Company shall take action without delay upon such request.
- If a user requests correction or deletion of personal information due to errors, the Company shall not use or provide the relevant personal information until such correction or deletion is completed.
- Users are obligated to keep their personal information accurate and up to date. The user shall be responsible for any issues arising from the entry of inaccurate information.
- Users shall not infringe upon the personal information of others, including through misappropriation. The user shall be solely responsible for all consequences arising from any such violation.
Article 10 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure that users' personal information is not lost, stolen, leaked, altered, or damaged.
1. Technical Measures
- Encrypted data transmission (SSL/TLS)
- Encrypted storage of passwords
- Access privilege management and access control
- Prevention of hacking and computer viruses through the use of anti-virus software and similar tools
- Control of unauthorized external access through intrusion prevention systems
- <strong>On-Device OCR Processing:</strong> Death verification documents (including death certificates and post-mortem examination certificates) are processed only on the user's device and are not transmitted to the Company's servers.
2. Administrative Measures
- Establishment and implementation of internal management plans
- Minimization of personnel handling personal information and provision of regular training
- Separate access privilege management and periodic password updates for employees who process personal information
3. Physical Measures
- Access control over cloud servers (Firebase – United States / Asia, AWS – Seoul Region)
The Company shall not be responsible for any issues arising from the leakage of personal information caused by the user's own negligence or by issues on the Internet.
Article 11 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
- The Company uses "cookies" that store and periodically retrieve usage information in order to provide users with individualized and customized services.
- Cookies are used to analyze users' access frequency, duration of use, and similar information, and are utilized to improve the Service.
- Users may, through web browser settings, allow the storage of cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. However, if the storage of cookies is refused, the use of certain services may be limited.
Article 12 (Chief Privacy Officer)
The Company designates the following Chief Privacy Officer to be responsible for matters concerning the processing of personal information and to handle user complaints and remedies in connection with personal information processing:
- <strong>Name:</strong> Hyuna Ha
- <strong>Position:</strong> Chief Executive Officer
- <strong>Contact:</strong> support@yoonseulapp.co.kr
Users may direct any inquiries, complaints, or requests for remedies relating to personal information protection arising from the use of the Service to the Chief Privacy Officer, and the Company shall respond to such inquiries promptly and in good faith.
Article 13 (Remedies for Infringement of Rights)
In order to obtain remedies for personal information infringement, users may apply for dispute resolution or consultation to the following institutions:
- <strong>Personal Information Dispute Mediation Committee:</strong> 1833-6972 (www.kopico.go.kr)
- <strong>Personal Information Infringement Report Center:</strong> 118 (no area code required) (privacy.kisa.or.kr)
- <strong>Supreme Prosecutors' Office, Cyber Investigation Division:</strong> 1301 (www.spo.go.kr)
- <strong>National Police Agency, Cyber Bureau:</strong> 182 (no area code required) (cyberbureau.police.go.kr)
Article 14 (Changes to the Privacy Policy)
This Privacy Policy shall apply from its effective date. In the event of any addition, deletion, or revision of its contents pursuant to applicable laws or the Company's policies, such changes shall be announced through in-application notices at least seven (7) days prior to the effective date of such changes.
Supplementary Provisions
This Privacy Policy shall take effect on February 9, 2026.