AdiByte

Privacy Policy

AdiByte Privacy Policy

Effective date: July 20, 2026

This is a translation provided for convenience; the Korean version prevails.

AdiByte (the "Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act ("PIPA"), in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly. Given the nature of the AI persona chat service, the Company specifically informs users that their conversation content is processed and transmitted to overseas artificial intelligence APIs.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information being processed is not used for purposes other than the following, and where the purpose of use changes, the Company will take necessary measures such as obtaining separate consent under Article 18 of PIPA.

  1. Membership registration and management
    confirming intent to register, identifying and authenticating users via social sign-in, maintaining and managing membership, preventing service misuse, and various notices and communications.
  2. Providing the AI persona chat service
    to provide the conversation service, the Company transmits the conversation content entered by the user to an artificial intelligence language model to generate responses, and processes and stores conversation content to maintain the context (memory) of the conversation.
  3. Payment and settlement of paid services
    providing paid services such as subscriptions and credits, processing payment and settlement, and handling withdrawals and refunds.
  4. Safety and service improvement
    guidance in crisis situations (such as risk of self-harm or harm to others), detection of misuse and abuse, and improvement of service quality and stability.

Article 2 (Items of Personal Information Collected)

The Company collects the following items of personal information.

When collectedItems collectedMethod of collection
At registration (social sign-in)email, unique social account identifier, profile information (if provided), nicknameSocial sign-in integration (Kakao, Google, etc.)
During use (AI conversations)conversation content entered by the user (prompts), conversation history and memory, personas and categories usedDirect input by the user
When using paid servicespayment/refund records, subscription status, credit usage history (payment method information such as card numbers is processed by the payment processor Paddle and not stored by the Company)Payment processor (Paddle) integration
During use (automatic collection)IP address, cookies, service usage records, access logs, device/browser informationAutomatic collection
Note on processing conversation contentConversation content entered by users may include sensitive information voluntarily entered by the user (such as health/psychological status or personal and family matters). The Company processes this only to the minimum extent necessary to provide the Service, and users are asked to exercise caution when entering sensitive information.

Article 3 (Processing and Retention Period)

The Company processes and retains personal information within the retention and use period required by law or the period consented to by the data subject at the time of collection.

Item retainedRetention periodBasis
Member informationUntil membership withdrawalConsent of the data subject
Conversation content and memoryUntil membership withdrawal or the user's deletion requestConsent of the data subject
Records on contracts or withdrawal of subscription5 yearsE-Commerce Act
Records on payment and supply of goods, etc.5 yearsE-Commerce Act
Records on consumer complaints or dispute handling3 yearsE-Commerce Act
Website visit records (access logs, etc.)3 monthsProtection of Communications Secrets Act

Article 4 (Provision to Third Parties)

The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing), and provides personal information to third parties only where it falls under Articles 17 and 18 of PIPA, such as with the consent of the data subject or under special provisions of law.

Current status of provision to third partiesThe Company does not currently provide users' personal information to third parties for purposes such as promotion or solicitation of goods or services. Entrustment of processing and cross-border transfers necessary to provide the Service are described in Article 5.

Article 5 (Entrustment of Processing and Cross-Border Transfer)

To provide the Service smoothly and securely, the Company entrusts the following processing tasks to domestic and overseas providers, and personal information is transferred abroad in the process. Given the nature of the AI persona chat service, the conversation content entered by users is transmitted to overseas artificial intelligence (LLM) API providers to generate responses.

Recipient (processor)CountryItems transferredPurpose and retention
Supabase, Inc.United States, etc.member information, conversation content, service usage recordsOperation of server infrastructure such as database, authentication, and storage / until termination of the entrustment contract or the end of the retention period
OpenRouter, Inc. and the artificial intelligence API providers routed through it (e.g., Anthropic, Google, xAI)United States, etc.conversation content entered by the user (prompts) and conversation contextGeneration of AI persona responses / for the period necessary to generate responses (see note below)
Paddle.com Market Ltd.United Kingdom, United States, etc.information necessary for payment, subscription, and refund processingPayment processing for paid services (Merchant of Record) / until the retention period required by applicable law
Notice on cross-border transfer (Article 28-8 of PIPA)Data subjects may refuse the above cross-border transfers; however, if you refuse, you may be unable to use all or part of the Service, including generation of conversation responses. Each processor's handling of personal information is governed by that provider's own privacy policy, and the Company manages, through contracts and other means, the recipients' safe protection and processing of personal information. Details such as the recipients' contact information can be confirmed through the Chief Privacy Officer.

When entering into entrustment contracts, the Company specifies in writing, pursuant to Article 26 of PIPA, matters such as the prohibition of processing personal information beyond the purpose of the entrusted work, technical and administrative protection measures, restrictions on re-entrustment, supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely.

Article 6 (Special Rules on Processing Personal Information for the AI Service)

  1. Processing of conversation content: conversation content entered by users is processed to generate AI persona responses and to maintain the context (memory) of the conversation, and in this process it is transmitted to overseas artificial intelligence API providers pursuant to Article 5.
  2. AI model training: the Company does not use users' conversation content for the purpose of training the Company's or any third party's artificial intelligence models. If use for training purposes becomes necessary in the future, the Company will give prior notice and provide a procedure for data subjects to consent or refuse.
  3. Deletion of conversation content: users may at any time request deletion of their conversation content and memory through features within the Service or through a request to the Chief Privacy Officer, and upon membership withdrawal the relevant conversation content is destroyed except where retention is required by law.

Article 7 (Processing of Personal Information of Children Under 14)

The Company does not permit membership registration by children under 14 and, in principle, does not collect the personal information of children under 14. If it is confirmed that the personal information of a child under 14 has been collected, the Company will destroy such personal information and delete the relevant account without delay.

Where a minor aged 14 or older uses the Service, the consent of a legal representative is required, and the legal representative may request access to, correction, deletion of, or suspension of processing of the child's or minor's personal information.

Article 8 (Rights and Obligations of Data Subjects and How to Exercise Them)

Data subjects may exercise the following privacy-related rights against the Company at any time, including the right to access and delete their own conversation content.

  1. Request to access personal information (including conversation content)
  2. Request to correct errors, if any
  3. Request to delete
  4. Request to suspend processing

These rights may be exercised against the Company in writing, by email (somewizcorp@gmail.com), and the Company will act on them without delay.

If a data subject requests correction or deletion of errors in personal information, the Company will not use or provide the personal information concerned until the correction or deletion is completed.

These rights may also be exercised through an agent such as the data subject's legal representative or a duly authorized person. In such case, a power of attorney in the form of Attached Form No. 11 of the Notification on Methods of Processing Personal Information must be submitted.

Article 9 (Destruction of Personal Information)

  1. When personal information becomes unnecessary, such as upon the lapse of the retention period or achievement of the processing purpose, the Company destroys the personal information without delay.
  2. Where personal information must continue to be preserved under other laws despite the lapse of the consented retention period or the achievement of the processing purpose, the Company moves the personal information to a separate database (DB) or stores it in a different location.
  3. The procedure and method of destroying personal information are as follows.
    • Procedure: the Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Company's Chief Privacy Officer.
    • Method: information in electronic file format is destroyed using technical methods that prevent recovery of the records. Personal information printed on paper is shredded or incinerated.

Article 10 (Measures to Ensure the Safety of Personal Information)

The Company takes the following measures to ensure the safety of personal information.

  1. Administrative measures: establishing and implementing an internal management plan, minimizing and training staff who handle personal information
  2. Technical measures: managing access rights to personal information processing systems, installing access control systems, encrypting unique identifying information and transmission channels, and installing security programs
  3. Physical measures: access control to computer rooms, data storage rooms, and the like

Article 11 (Chief Privacy Officer)

The Company designates a Chief Privacy Officer as follows to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to personal information processing.

Chief Privacy OfficerIn charge: AdiByte Operator Email: somewizcorp@gmail.com

Data subjects may direct all inquiries, complaints, and requests for remedy relating to personal information protection that arise while using the Company's Service to the Chief Privacy Officer. The Company will answer and process such inquiries without delay.

Article 12 (Changes to the Privacy Policy)

This Privacy Policy applies from July 20, 2026. Where content is added, deleted, or modified due to changes in law, policy, or the Service, the Company will give notice through announcements within the Service from at least 7 days before the changes take effect.

  • Current Privacy Policy: effective July 20, 2026

Article 13 (Remedies for Infringement of Rights)

To obtain remedies for infringement of personal information, data subjects may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and the like. For other reports of and counseling on personal information infringement, please contact the following agencies.

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • National Police Agency: 182 (ecrm.cyber.go.kr)

A person whose rights or interests are infringed by a disposition or omission by the head of a public agency in response to a request under Articles 35 (Access), 36 (Correction and Deletion), or 37 (Suspension of Processing) of PIPA may file an administrative appeal as provided by the Administrative Appeals Act.

Last updated: July 20, 2026

Privacy Policy โ€” AdiByte