Privacy Policy
AdiByte Privacy Policy
Effective date: July 20, 2026
This is a translation provided for convenience; the Korean version prevails.
AdiByte (the "Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act ("PIPA"), in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly. Given the nature of the AI persona chat service, the Company specifically informs users that their conversation content is processed and transmitted to overseas artificial intelligence APIs.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed is not used for purposes other than the following, and where the purpose of use changes, the Company will take necessary measures such as obtaining separate consent under Article 18 of PIPA.
- Membership registration and management
confirming intent to register, identifying and authenticating users via social sign-in, maintaining and managing membership, preventing service misuse, and various notices and communications. - Providing the AI persona chat service
to provide the conversation service, the Company transmits the conversation content entered by the user to an artificial intelligence language model to generate responses, and processes and stores conversation content to maintain the context (memory) of the conversation. - Payment and settlement of paid services
providing paid services such as subscriptions and credits, processing payment and settlement, and handling withdrawals and refunds. - Safety and service improvement
guidance in crisis situations (such as risk of self-harm or harm to others), detection of misuse and abuse, and improvement of service quality and stability.
Article 2 (Items of Personal Information Collected)
The Company collects the following items of personal information.
| When collected | Items collected | Method of collection |
|---|---|---|
| At registration (social sign-in) | email, unique social account identifier, profile information (if provided), nickname | Social sign-in integration (Kakao, Google, etc.) |
| During use (AI conversations) | conversation content entered by the user (prompts), conversation history and memory, personas and categories used | Direct input by the user |
| When using paid services | payment/refund records, subscription status, credit usage history (payment method information such as card numbers is processed by the payment processor Paddle and not stored by the Company) | Payment processor (Paddle) integration |
| During use (automatic collection) | IP address, cookies, service usage records, access logs, device/browser information | Automatic collection |
Article 3 (Processing and Retention Period)
The Company processes and retains personal information within the retention and use period required by law or the period consented to by the data subject at the time of collection.
| Item retained | Retention period | Basis |
|---|---|---|
| Member information | Until membership withdrawal | Consent of the data subject |
| Conversation content and memory | Until membership withdrawal or the user's deletion request | Consent of the data subject |
| Records on contracts or withdrawal of subscription | 5 years | E-Commerce Act |
| Records on payment and supply of goods, etc. | 5 years | E-Commerce Act |
| Records on consumer complaints or dispute handling | 3 years | E-Commerce Act |
| Website visit records (access logs, etc.) | 3 months | Protection of Communications Secrets Act |
Article 4 (Provision to Third Parties)
The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing), and provides personal information to third parties only where it falls under Articles 17 and 18 of PIPA, such as with the consent of the data subject or under special provisions of law.
Article 5 (Entrustment of Processing and Cross-Border Transfer)
To provide the Service smoothly and securely, the Company entrusts the following processing tasks to domestic and overseas providers, and personal information is transferred abroad in the process. Given the nature of the AI persona chat service, the conversation content entered by users is transmitted to overseas artificial intelligence (LLM) API providers to generate responses.
| Recipient (processor) | Country | Items transferred | Purpose and retention |
|---|---|---|---|
| Supabase, Inc. | United States, etc. | member information, conversation content, service usage records | Operation of server infrastructure such as database, authentication, and storage / until termination of the entrustment contract or the end of the retention period |
| OpenRouter, Inc. and the artificial intelligence API providers routed through it (e.g., Anthropic, Google, xAI) | United States, etc. | conversation content entered by the user (prompts) and conversation context | Generation of AI persona responses / for the period necessary to generate responses (see note below) |
| Paddle.com Market Ltd. | United Kingdom, United States, etc. | information necessary for payment, subscription, and refund processing | Payment processing for paid services (Merchant of Record) / until the retention period required by applicable law |
When entering into entrustment contracts, the Company specifies in writing, pursuant to Article 26 of PIPA, matters such as the prohibition of processing personal information beyond the purpose of the entrusted work, technical and administrative protection measures, restrictions on re-entrustment, supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely.
Article 6 (Special Rules on Processing Personal Information for the AI Service)
- Processing of conversation content: conversation content entered by users is processed to generate AI persona responses and to maintain the context (memory) of the conversation, and in this process it is transmitted to overseas artificial intelligence API providers pursuant to Article 5.
- AI model training: the Company does not use users' conversation content for the purpose of training the Company's or any third party's artificial intelligence models. If use for training purposes becomes necessary in the future, the Company will give prior notice and provide a procedure for data subjects to consent or refuse.
- Deletion of conversation content: users may at any time request deletion of their conversation content and memory through features within the Service or through a request to the Chief Privacy Officer, and upon membership withdrawal the relevant conversation content is destroyed except where retention is required by law.
Article 7 (Processing of Personal Information of Children Under 14)
The Company does not permit membership registration by children under 14 and, in principle, does not collect the personal information of children under 14. If it is confirmed that the personal information of a child under 14 has been collected, the Company will destroy such personal information and delete the relevant account without delay.
Where a minor aged 14 or older uses the Service, the consent of a legal representative is required, and the legal representative may request access to, correction, deletion of, or suspension of processing of the child's or minor's personal information.
Article 8 (Rights and Obligations of Data Subjects and How to Exercise Them)
Data subjects may exercise the following privacy-related rights against the Company at any time, including the right to access and delete their own conversation content.
- Request to access personal information (including conversation content)
- Request to correct errors, if any
- Request to delete
- Request to suspend processing
These rights may be exercised against the Company in writing, by email (somewizcorp@gmail.com), and the Company will act on them without delay.
If a data subject requests correction or deletion of errors in personal information, the Company will not use or provide the personal information concerned until the correction or deletion is completed.
These rights may also be exercised through an agent such as the data subject's legal representative or a duly authorized person. In such case, a power of attorney in the form of Attached Form No. 11 of the Notification on Methods of Processing Personal Information must be submitted.
Article 9 (Destruction of Personal Information)
- When personal information becomes unnecessary, such as upon the lapse of the retention period or achievement of the processing purpose, the Company destroys the personal information without delay.
- Where personal information must continue to be preserved under other laws despite the lapse of the consented retention period or the achievement of the processing purpose, the Company moves the personal information to a separate database (DB) or stores it in a different location.
- The procedure and method of destroying personal information are as follows.
- Procedure: the Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Company's Chief Privacy Officer.
- Method: information in electronic file format is destroyed using technical methods that prevent recovery of the records. Personal information printed on paper is shredded or incinerated.
Article 10 (Measures to Ensure the Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information.
- Administrative measures: establishing and implementing an internal management plan, minimizing and training staff who handle personal information
- Technical measures: managing access rights to personal information processing systems, installing access control systems, encrypting unique identifying information and transmission channels, and installing security programs
- Physical measures: access control to computer rooms, data storage rooms, and the like
Article 11 (Chief Privacy Officer)
The Company designates a Chief Privacy Officer as follows to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to personal information processing.
Data subjects may direct all inquiries, complaints, and requests for remedy relating to personal information protection that arise while using the Company's Service to the Chief Privacy Officer. The Company will answer and process such inquiries without delay.
Article 12 (Changes to the Privacy Policy)
This Privacy Policy applies from July 20, 2026. Where content is added, deleted, or modified due to changes in law, policy, or the Service, the Company will give notice through announcements within the Service from at least 7 days before the changes take effect.
- Current Privacy Policy: effective July 20, 2026
Article 13 (Remedies for Infringement of Rights)
To obtain remedies for infringement of personal information, data subjects may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and the like. For other reports of and counseling on personal information infringement, please contact the following agencies.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.cyber.go.kr)
A person whose rights or interests are infringed by a disposition or omission by the head of a public agency in response to a request under Articles 35 (Access), 36 (Correction and Deletion), or 37 (Suspension of Processing) of PIPA may file an administrative appeal as provided by the Administrative Appeals Act.
Last updated: July 20, 2026