Privacy Policy
Effective October 2, 2026 · Version 1.4
This is an English translation of the Korean original. If the two differ, the Korean version prevails.
mellow (the “Service”) treats its users’ personal information with care and complies with the Personal Information Protection Act (개인정보 보호법) and other applicable laws. This policy explains what information the Service receives, why, and how it handles it, and what users can ask of the Service in return.
1. Personal information we collect
| Category | Items | When collected |
|---|---|---|
| Account | Email address, display name, profile image URL, password converted into an irreversible hash (for email sign-up), time of email verification, social login provider and the provider’s member identifier | When signing up with email or with a Kakao, Google or Apple account |
| Email verification | Recipient email address, verification code and delivery result. The server stores a temporary record in which the address, verification code and connecting IP are converted into secret-key-based hashes, along with request and failure counts | When requesting or confirming an email sign-up verification code |
| Learning settings | App language (used for the screens, translations and report explanations), native language, target language, level, interests | During onboarding and when settings are changed |
| Optional profile | Age range, gender, country or region — date of birth, exact age and precise location are not collected. Country or region is suggested from the device settings, and ‘None’ can be chosen | When chosen by the user during onboarding or in profile editing |
| Calls | Voice spoken during calls, conversation text and translation and grammar-correction results, the friend, situation and mode of the call, start and end times and call length | During a call |
| Learning records | Call reports, review items, conversation summaries the friend remembers | Generated automatically after a call ends |
| AI response reports | Member and call identifiers, the reported AI response, the report reason and any description the user enters, time of receipt and review, and the outcome | When reporting an AI response in the app |
| Notifications | Push notification token (device identifier) | When notifications are allowed |
| Subscription | Subscription status and validity period, store purchase identifier | When a subscription is started, renewed or canceled |
| Consent records | Time of consent to AI processing and the notice version consented to, sign-up date and time | When consent is given |
| AI usage records | Operational information such as member and call identifiers, AI provider and model, feature used, number of tokens provided, request identifier, processing time, and success or failure status | When AI features are used |
The Service does not receive payment method information directly. Card numbers and other payment details are handled by the Apple App Store and Google Play; the Service is told only whether a subscription is valid.
Voice during calls is processed in real time and is not recorded in the Service’s storage. What is stored is the text transcribed from the voice.
All features can be used without entering an age range, gender, or country or region. They can be changed or deleted at any time in profile editing, and changes take effect from the next call. AI usage records do not separately copy and store voice or the original text of conversations or prompts.
2. Purposes of use
- Member identification and login — to verify the user through email or a social account and to carry the same learning records across device changes
- Running calls — to understand what the user says and continue the conversation
- Learning feedback — to produce grammar corrections, call reports and review items
- Conversation personalization — to help with examples suited to the chosen age range and with natural language expressions according to gender. Learning ability, interests or personality are not inferred from age range or gender.
- App language and country or region — to provide the screens, translations and learning report explanations in the chosen language, and to use country or region as a reference for running and improving the Service by region
- Scheduled call notifications — to call at the agreed time
- Subscription management — to determine whether paid features are available
- Handling AI response reports — to review responses reported by users and reduce inappropriate responses
- Service operation — to respond to outages, prevent abuse, and check per-user AI usage and processing quality
3. Retention and use period
Email verification codes are valid for 10 minutes and can be used only once. Temporary records kept for verification and request limiting are deleted periodically 24 hours after they expire. The time of verification is kept until the account is deleted. The email delivery provider keeps sending logs and email data for 30 days.
Personal information is destroyed without delay when a member withdraws. Call records, reports, review items, friend memories, the optional profile, AI usage records and AI response reports linked to the account are deleted together with the account.
However, where applicable laws require retention, information is kept for the required period. For example, under the Act on the Consumer Protection in Electronic Commerce (전자상거래 등에서의 소비자보호에 관한 법률), records of contracts or withdrawal of subscription are kept for 5 years, and records of consumer complaints or dispute resolution for 3 years.
4. Entrustment of processing and transfer abroad
For calls and operations, the Service entrusts the processing of personal information to the companies below, some of which process it outside Korea.
| Processor | Entrusted task | Items transferred | Country, timing and method of transfer |
|---|---|---|---|
| OpenAI, L.L.C. | Speech recognition, conversation generation, speech synthesis, generation of call reports and review items | Voice during calls, conversation text, summaries of earlier calls and what the AI friend remembers, review expressions, display name (so the friend can address the user by name), explanation language (the app language), and age range and gender chosen by the user. Email address and country or region are not sent, but information the user says in the conversation may be included in the conversation content. | United States · during calls and right after a call ends · encrypted network transmission |
| Resend (Plus Five Five, Inc.) | Sending sign-up verification emails and handling delivery status | Recipient email address, email content including the verification code, delivery result | United States and Japan (sending regions) · when a verification code is requested · encrypted network transmission |
| RevenueCat, Inc. | Checking subscription status and validating receipts | Member identifier, store purchase identifier, subscription status | United States · when a subscription is started, renewed or canceled · encrypted network transmission |
| Google LLC | Delivering Android push notifications (Firebase Cloud Messaging) | Push notification token, notification content | United States · when a notification is sent · encrypted network transmission |
| Apple Inc. | Delivering iOS push notifications | Push notification token, notification content | United States · when a notification is sent · encrypted network transmission |
| Expo, Inc. | Relaying push notifications | Push notification token, notification content | United States · when a notification is sent · encrypted network transmission |
| Railway Corp. | Server and database hosting | All items stored under Section 1 of this policy | United States · while the Service is used · encrypted network transmission |
5. Provision to third parties
The Service does not provide users’ personal information to third parties. However, where an investigative agency makes a request through due legal process under applicable law, the Service complies.
6. Users’ rights
Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information. They can edit it directly or delete their account in the app’s settings, or make a request to the contact below. Requests are handled within 10 days of receipt.
The Service does not collect personal information of children under the age of 14.
7. Destruction procedure and method
Personal information whose retention period has passed or whose processing purpose has been achieved is destroyed without delay. Electronic files are permanently deleted in a way that cannot be recovered, and printed records are shredded or incinerated.
8. Security measures
- All transmission is encrypted with TLS.
- Passwords are stored in a form that cannot be decrypted, and access rights are limited to the minimum number of people needed for operations.
- Server access logs are kept, and the database sits inside a private network so that it cannot be accessed directly from outside.
9. Privacy officer
Name: Seongeun Cho
Contact: mellow@nullge.com
10. Remedies for infringement
For advice or to report an infringement of personal information, users may contact the following agencies.
- Personal Information Dispute Mediation Committee — 1833-6972 (kopico.go.kr)
- Personal Information Infringement Report Center (KISA) — 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office Cyber Investigation Division — 1301 (spo.go.kr)
- Korean National Police Agency Cyber Bureau — 182 (ecrm.police.go.kr)
11. Changes to this policy
When this policy changes, notice is given on this page and in the app at least 7 days before the effective date. Changes unfavorable to users are announced 30 days in advance, and consent is obtained again if the purposes of use of personal information or the processors change.