Privacy Policy

**SniffSniff Privacy Policy**

Effective Date: July 8, 2026

Neural Arcade Inc. (hereinafter the "Company") values the personal information of users (hereinafter "Users") of the SniffSniff service (hereinafter the "Service") and complies with the Personal Information Protection Act and other relevant laws and regulations. This Privacy Policy explains the items of personal information collected by the Company, the purposes of collection, the retention period, and the methods of processing.

**Article 1 (Items of Personal Information Collected and Methods of Collection)**

All services operated by the Company use a common Neural Arcade account, and the personal information collected (account information, AI characters, profile data, QnA inputs, etc.) may be used in common across all services provided by the Company.

**1. Items Collected**

The Company collects the following personal information to provide the Service.

[At Sign-Up]

Email sign-up: name, date of birth, email address

Google-linked sign-up: name, date of birth, Google account email

Apple-linked sign-up: name, date of birth, Apple-provided email (actual email or, at the User's choice, a relay email)

※ Date of birth is collected for age verification and for applying service usage restrictions.

[During Service Use]

Profile photo, pet photo, self-introduction

Additional profile information (lifestyle patterns, interests, values, hobbies, and other information the User optionally enters)

Location information (collected only when the User has granted location access permission; GPS coordinates (latitude/longitude) are not stored on the server but are converted into and stored as city name and country code)

Chat content (AI auto-chat and direct chat)

Device information (operating system, app version, device information, advertising identifier (ADID/IDFA))

[Automatically Collected]

Access logs, service usage records

App install/launch and in-app event records, and acquisition source information (ad click information, referrer, IP address)

App error and abnormal termination (crash) logs and performance diagnostic information (time of error, error message, stack trace, app version, device/OS information, IP address, internal user identifier)

[When Using Paid Services]

Payment information is processed through the Apple App Store and Google Play Store; the Company does not directly collect payment information. The Company processes only the purchase receipts and subscription status information issued by the stores in order to verify subscription status.

**2. Methods of Collection**

Sign-up and profile setup within the app

Social login (Google, Apple) integration

Automatic generation and collection during the course of Service use

Automatic collection via in-app SDKs (attribution, error monitoring, analytics, etc.)

**Article 2 (Purposes of Collection and Use of Personal Information)**

The Company uses the collected personal information for the following purposes.

Membership registration and management: identity verification, account management, prevention of fraudulent use

Service provision: location-based discovery and encounter of nearby Users, AI character auto-chat, chat report generation, and other service provision

AI service operation and enhancement: AI character generation and auto-chat functionality, keyword extraction, report generation

Customer support: handling of inquiries and complaints, CS response

Service improvement and development: improving service quality, developing new features

Ensuring service stability: analyzing the causes of app errors and abnormal terminations, performance monitoring, and incident response

Advertising and marketing: provision of personalized advertising (upon User consent, based on service usage records and advertising identifiers), measurement of advertising performance and attribution (acquisition source) analysis

Legal compliance: fulfillment of obligations under relevant laws

Service safety management and prevention of fraudulent use

※ The Company does not guarantee the accuracy, completeness, or appropriateness of AI-generated content, and Users must use AI-generated results at their own discretion and responsibility.

※ The Company may apply technical and administrative measures to prevent inappropriate or harmful AI-generated content.

**Article 3 (Retention and Use Period of Personal Information)**

**1. Principle**

The Company retains the User's personal information during the period of Service use, and after withdrawal, retains it for the periods set out below before destroying it without delay.

**2. Retention Under Internal Policy**

Profile information, AI characters, chat records: retained for 1 year from the date of withdrawal, then destroyed (for dispute resolution and investigation of illegal use)

Records of reports, sanctions, and operations for service safety management: retained for 1 year from the date of withdrawal, then destroyed

Chat message bodies are stored on an external messaging service and may automatically expire after 6 months (180 days). The Company separately retains only channel metadata (start/end times, etc.).

App error and crash logs: retained for up to 90 days and then automatically deleted, in accordance with the error monitoring service's policy

**3. Mandatory Retention Under Relevant Laws**

Records of contracts or withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)

Records of payment and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)

Records of consumer complaints or dispute handling: 3 years (Act on Consumer Protection in Electronic Commerce)

Access logs: 3 months (Protection of Communications Secrets Act)

**Article 4 (Provision of Personal Information to Third Parties)**

The Company does not, in principle, provide Users' personal information to third parties. However, exceptions apply in the following cases.

When the User has given prior consent

When investigative agencies, etc., request it in accordance with the provisions of the law

**Article 5 (Entrustment of Personal Information Processing)**

The Company entrusts the processing of personal information as follows for smooth provision of the Service.

Entrusted Party | Entrusted Work

OpenAI, Google LLC (Google Gemini) | AI service provision (AI character generation, auto-chat, etc.)

Sendbird, Inc. | Chat service (transmission and storage of chat messages)

Google LLC (Google AdMob) | Advertising service (if advertising networks such as Meta, AppLovin, Unity Ads, etc., are added in the future, they will be applied after prior notice)

Google LLC (Firebase Auth, Firebase Cloud Messaging) | Service operation (user authentication and push notifications)

Google LLC (Google Analytics, BigQuery) | Service analytics (analysis of service usage data)

AB180 Inc. (Airbridge) | Advertising performance measurement and attribution analysis (analysis of app installs, in-app events, and acquisition sources)

Functional Software, Inc. (Sentry) | App error and performance monitoring (collection and analysis of crash and error logs)

Apple Inc., Google LLC | Payment processing (in-app payment processing and verification of purchase receipts and subscription status)

※ Each entrusted party does not use personal information beyond the purpose of performing the entrusted work, and immediately destroys personal information upon termination of the entrustment contract.

**Article 6 (Overseas Transfer of Personal Information)**

In the course of providing the Service, the Company may entrust part of its personal information processing work to overseas operators. These operators take safeguards equivalent to the Korean Personal Information Protection Act through contracts.

Users may direct inquiries regarding overseas transfer of personal information to customer support (cs@neuralarcade.ai). However, in the case of overseas transfers essential to providing the Service, withdrawing consent may restrict Service use or require membership withdrawal.

**OpenAI (USA)** · https://help.openai.com

Items transferred: profile photos, pet photos, images and prompts for AI avatar generation, profile information, chat content

Purpose of transfer: AI character generation, auto-chat, report creation

Time of transfer: real-time transmission when using AI services

Retention period: in accordance with OpenAI's security and abuse-prevention policies

**Google LLC (USA)** · https://support.google.com/policies/answer/9581826

Items transferred: email, device information, advertising identifier, service usage records, app event data

Purpose of transfer: Google login authentication, push notifications, in-app advertising, analysis of service usage data (Google Analytics, BigQuery)

Time of transfer: real-time transmission upon service sign-up and app launch

Retention period: in accordance with each Google service policy

**Sendbird, Inc. (USA)** · privacy@sendbird.com

Items transferred: chat message bodies, channel metadata

Purpose of transfer: in-app chat message transmission and server storage

Time of transfer: real-time transmission when using chat

Retention period: channel metadata: until withdrawal / message bodies: up to 6 months (180 days)

**Functional Software, Inc. (Sentry) (USA)** · compliance@sentry.io

Items transferred: app error and abnormal termination logs, error screen and stack trace, app version, device/OS information, IP address, internal user identifier

Purpose of transfer: app error and performance monitoring, root-cause analysis of incidents

Time of transfer: real-time transmission when an error or event occurs

Retention period: in accordance with Sentry's policy (up to 90 days for event data)

**Apple Inc. (USA)** · https://www.apple.com/legal/privacy/contact/

Items transferred: name, Apple email, purchase receipts

Purpose of transfer: Apple login authentication, in-app payment verification and processing

Time of transfer: real-time transmission upon Apple sign-up and payment

Retention period: in accordance with Apple's policy

※ AB180 Inc. (Airbridge) is a domestic (Korean) operator that processes personal information within the Republic of Korea, and therefore does not constitute an overseas transfer. However, in the course of attribution measurement, advertising identifiers and event information may be delivered to the advertising media partner (ad network) whose advertisement the User clicked, in order to confirm advertising performance; where such a media partner is an overseas operator, the items above shall apply.

**Article 7 (Processing of Location Information)**

The Company collects Users' location information (GPS) to provide location-based services.

Location information is collected only when the User has granted location access permission on their device.

Collected GPS coordinates are not stored on the server; only information converted into city name and country code form is stored.

Collected location information is used solely to provide location-based services such as the nearby-User discovery feature, and a User's precise location coordinates are not directly disclosed to other Users.

Users may refuse the collection of location information at any time through device settings, in which case the use of location-based services may be restricted.

The Company may adjust the precision of location information or limit the scope of certain features to protect Users.

The Company complies with the Act on the Protection, Use, etc. of Location Information and other relevant laws.

**Article 8 (Facial and Biometric Information; Profile Photos)**

(1) The Company processes profile photos and pet photos uploaded by Users for the purpose of providing the Service, such as AI avatar generation. In this process, the Company does not perform any biometric data processing, including facial recognition, extraction of face geometry, or generation of biometric identifiers. Uploaded images are not stored or analyzed as separate facial data.

(2) A User's profile photo is not disclosed during the AI auto-chat stage; it is disclosed to the other User only when that other User directly enters a chat message to start a conversation.

(3) The collection, use, entrustment, overseas transfer, and retention of uploaded images are governed by Articles 1, 5, 6, and 3.

**Article 9 (Measures to Ensure the Security of Personal Information)**

The Company implements the following technical and administrative protective measures to ensure the security of personal information.

Management of access rights to personal information and granting of minimum necessary privileges

Encryption of personal information

Retention of access records and prevention of forgery/alteration

Installation of security programs and periodic inspection

Application of filtering and masking measures so that personal information is not included when error logs are collected

The Company continuously improves its technical and administrative measures for the protection of personal information.

**Article 10 (Destruction of Personal Information)**

The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved.

Personal information in electronic file form is permanently deleted using a method that makes recovery and reproduction impossible.

Personal information printed on paper is destroyed by shredding or incineration.

**Article 11 (Users' Rights and How to Exercise Them)**

As data subjects, Users may exercise the following rights: the right to request access to personal information, the right to request correction of errors, the right to request deletion, and the right to request suspension of processing. The above rights may be requested through customer support (cs@neuralarcade.ai) in writing, by email, etc., and the Company will take action within the period prescribed by relevant laws. However, processing may be restricted under relevant laws.

**Article 12 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)**

The Company may use automatic collection devices such as cookies and advertising identifiers (ADID, IDFA) for service provision and analysis, advertising performance measurement, and for providing personalized advertising. Advertising identifiers (ADID, IDFA) may be used for the purpose of providing personalized advertising, analyzing advertising performance, and measuring attribution (acquisition source), and on iOS devices, they are collected only when the User has given prior consent in accordance with the App Tracking Transparency (ATT) policy. Users may refuse automatic collection through device settings. However, refusal may restrict the use of some features of the Service.

**Article 13 (Transmission of Advertising Information)**

The Company transmits advertising information only when it has obtained the User's prior consent. Users may refuse to receive advertising information at any time, and refusal does not affect Service use.

**Article 14 (Personal Information Protection Officer)**

The Company designates a Personal Information Protection Officer as set out below to protect Users' personal information and handle complaints related to personal information.

Name: Suji Lee

Position: Chief Executive Officer

Contact: cs@neuralarcade.ai

**Article 15 (Remedies for Infringement of Rights)**

Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972

Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 (no area code)

Supreme Prosecutors' Office: www.spo.go.kr / 1301

National Police Agency: ecrm.police.go.kr / 182

**Article 16 (Additional Provisions by Country)**

[Users Residing in the Republic of Korea] Use may be restricted for those under 14 years of age, or those who fall under the age requiring consent in the User's country.

[Users Residing in the United States] U.S. federal law and the laws of each state apply, and Users residing in California hold additional privacy rights under the CCPA. Under COPPA, use may be restricted for those under 13 years of age, or those who fall under the age requiring consent in the User's country.

[Users Residing in Japan] Japanese laws and regulations, including the Act on the Protection of Personal Information (個人情報の保護に関する法律), apply to Users residing in Japan. In accordance with Japanese laws, regulations, and guidelines, the consent of a legal guardian may be required when collecting a child's personal information, and use may be restricted in such cases. Under the Act on the Protection of Personal Information, Users may request access to, correction of, deletion of, or suspension of use of their personal information through customer support (cs@neuralarcade.ai).

**Article 17 (Protection of Children's Personal Information)**

The Company strives to protect children's personal information in accordance with relevant laws.

This Service restricts membership registration by children under 14 years of age. The Company verifies age based on the date of birth entered at sign-up, and registration is restricted if the User is found to be under 14.

If it is confirmed that a User signed up with a false date of birth, use may be restricted, and any damages arising therefrom shall be borne by the relevant User or their legal guardian.

Where necessary, the Company may require a legal guardian's consent procedure, and if relevant information has been collected in violation of the law, the Company will take necessary measures.

**Article 18 (Changes to the Privacy Policy)**

This Privacy Policy may be revised in accordance with changes in laws and policies or changes to the Service. In the event of revision, notice will be given through in-app announcements 7 days before the effective date (30 days before for material changes).

This Privacy Policy takes effect on July 8, 2026.

Back to home