대한민국 · Other countries
BagelChat Privacy Policy
1. About This Policy
This Privacy Policy describes how Konrev, INC., the operator of the BagelChat AI character chat service (the "Service"), collects, uses, discloses, and protects personal information. It applies to all users of the Service worldwide, with additional region-specific rights set out in Section 9 ("Your Rights"), which contains dedicated subsections for the EEA, UK, California, Nevada, Korea, and Brazil.
If you do not agree with this Policy, do not use the Service.
2. Information We Collect
2.1 Information You Provide
| Category | Examples | Purpose |
|---|---|---|
| Account information | Social-login unique identifier, email address, profile name, date of birth | Identify you and provide the Service |
| Identity verification (Korea Members only — where applicable) | Name, date of birth, gender, DI, mobile number — via NICE Information Service | Verify your identity and age in Korea |
| Age assurance (Self-Declaration) — non-Korean Members | Self-declaration consent record: timestamp, IP and device information at consent, date of birth registered at the time, calculated age, country of access, and history of date-of-birth corrections | Verify eligibility for Age-restricted Contet, prevent abuse of age controls, handle disputes. See also Operating Policy Chapter 3 (Age Assurance). |
| Conversation content | Messages, characters, images, audio, video you submit; AI responses; reactions | Provide the AI conversation feature |
| Payment data — web payments | Transaction identifier (order/authorization number), payment timestamp, and payment amount for one-time Cream purchases. Raw card data is handled directly by our payment processor and is not retained by Konrev. | Operate one-time Cream purchases |
| Payment data — in-app purchases (Apple, Google) | Transaction identifier and Subscription status received from Apple App Store or Google Play. Konrev does not collect or retain your card information for IAP transactions; that data is handled by Apple or Google directly. | Operate Subscription via in-app purchase, manage Subscription state |
| Customer support | Email address, inquiry contents | Respond to your requests |
2.2 Information Collected Automatically
We and our service providers use cookies, SDKs, and similar technologies to collect:
- IP address, device identifiers (ADID / IDFA), browser, operating system
- Service usage records (sessions, page views, click events, time spent)
- Crash and error logs
- General location inferred from IP address
- Application information (version, etc.) where you use the mobile app
2.3 Information from Third Parties
If you sign in through a third-party social platform (e.g., Google, Apple, Meta), we receive the basic profile information that platform shares according to your permissions. We may also receive information about you from other users (e.g., referrals or interactions involving you).
3. How We Use Information
We use personal information to:
- create, administer, and secure your account;
- provide the Service and personalize your experience;
- process payments and manage Cream balances, Including the Subscription Service;
- communicate with you about features, updates, and policy changes;
- provide customer support;
- analyze, maintain, and improve the Service. Konrev may use your Conversation Content (Input and Output) to research, develop, and train (including re-training and fine-tuning) Konrev's own AI models. For Members in the EEA, the UK, or Switzerland, such use is based on your explicit consent — and, where the Content reveals special-category data (such as data concerning sex life or sexual orientation), on Art. 9(2)(a) explicit consent — which you may withdraw at any time; for other Members, the applicable legal basis and any opt-out are described in Section 12. Konrev may also use pseudonymized data derived from Conversation Content for recommendation systems, statistical research, and service-quality improvement. This own-model training is distinct from external generative AI providers, which do not train their own models on your Content (see Sections 5 and 6). See Section 12 (AI Training and Pseudonymized Analytics Policy) for details;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations and enforce our Terms; and
- create aggregated or de-identified data for legitimate business purposes.
4. Legal Bases for Processing (EEA, UK, and other GDPR-style regimes)
Where GDPR or a similar regime applies, we process your personal information under one or more of the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service, processing payments, account management | Performance of a contract (Art. 6(1)(b)) |
| Marketing emails, optional analytics | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Pseudonymized analytics, recommendation systems, statistical research, service-quality improvement | Legitimate interests (Art. 6(1)(f)) and, in respect of pseudonymization, GDPR Recitals 26 and 28 (functional equivalent of Korea's PIPA Article 28-2 pseudonymization regime) |
| Training Konrev's own AI models on Conversation Content | Explicit consent (Art. 6(1)(a); and Art. 9(2)(a) where the Content reveals special-category data) — withdrawable at any time. EEA/UK/Swiss Members are not subject to own-model training without such consent. |
| Fraud prevention, security, business analytics | Legitimate interests (Art. 6(1)(f)) |
| Tax, accounting, compliance with legal requests | Legal obligation (Art. 6(1)(c)) |
| Sensitive data (where applicable) | Explicit consent (Art. 9(2)(a)) |
You can withdraw consent at any time without affecting the lawfulness of prior processing. Withdrawing consent to own-model training stops further such use; data already lawfully incorporated into a trained model that cannot technically be separated or recalled is addressed in Section 12. See Section 12 (AI Training and Pseudonymized Analytics Policy) for full details on how Konrev handles your Conversation Content with respect to AI training and analytics.
5. How We Share Information
We do not sell personal information for monetary consideration. We share information only as described below:
| Recipient category | Purpose | Examples |
|---|---|---|
| Service providers (processors) | Operate the Service on our instructions | AWS, Cloudflare, Google Cloud — hosting; Toss Payments — (i) web payment processing including foreign credit-card payments for one-time Cream purchases, (ii) fraud prevention ; NICE Information Service — identity verification (Korea only); Zendesk — customer support; Sentry (Functional Software, Inc.) — error monitoring |
| App marketplaces (for IAP only) | Process Subscription via in-app purchase | Apple Inc. (Apple App Store), Google LLC (Google Play) — these parties handle their own card-data collection and storage under their own policies |
| AI model providers | Generate AI responses under enterprise-grade or equivalent contracts ensuring the data is not used to train such providers' own AI models | OpenAI, Anthropic, X.AI, Google Cloud (AI Platform) |
| Analytics and marketing partners | Measurement, attribution, advertising | Google Analytics, Amplitude, OneSignal, TikTok, Meta, X Corp. |
| Legal / safety | Comply with law, protect rights and safety, address fraud, respond to subpoenas | Law enforcement, courts, regulators |
| Business transfers | M&A, financing, asset sale | Successor entity (subject to this Policy) |
| With your consent | As you direct | — |
6. International Data Transfers
The Service is global. Personal information we collect may be transferred to, stored in, and processed in countries outside your country of residence, including the Republic of Korea, the United States, and Japan, which may have data-protection laws different from those of your jurisdiction.
| Country | Recipient | Data transferred | Purpose |
|---|---|---|---|
| Republic of Korea | Konrev, INC. (operator) | All personal information | Service operation, customer support |
| Republic of Korea | Toss Payments Co., Ltd. | Payment data: transaction identifiers, foreign credit-card data for one-time Cream purchases | Payment processing, fraud prevention |
| Republic of Korea | NICE Information Service Co., Ltd. | Identity-verification information | Identity and age verification (Korea Members only) |
| USA, Japan | Amazon Web Services, Inc. | All personal information | Cloud infrastructure, storage |
| USA | Cloudflare, Inc. | All personal information | CDN, security |
| USA | Google Cloud Korea LLC | All personal information, messages, metadata | Cloud infrastructure, AI |
| USA | OpenAI, L.L.C. ([email protected]) | Messages and metadata | AI response generation under enterprise-grade contract: no provider-side model training |
| USA | Anthropic, PBC ([email protected]) | Messages and metadata | AI response generation under enterprise-grade contract: no provider-side model training |
| USA | X.AI Corp. ([email protected]) | Messages and metadata | AI response generation under enterprise-grade contract: no provider-side model training |
| USA | Amplitude, Inc. | Usage records, cookies, advertising identifiers | Analytics, service improvement |
| USA | Google, LLC | Usage records, cookies, advertising identifiers | Analytics, advertising |
| USA | OneSignal, Inc. | Usage records, advertising identifiers | Push notifications |
| USA | Zendesk, Inc. | Email, user name, inquiry contents | Customer support |
| USA | Functional Software, Inc. (Sentry) | Usage records, device info, IP address | Error monitoring |
| USA | Apple Inc. (for iOS in-app purchases) | IAP Subscription transaction data | App marketplace payment processing |
| USA | Google LLC (for Android in-app purchases) | IAP Subscription transaction data | App marketplace payment processing |
Safeguards. For transfers from the EEA, UK, Switzerland, or other restricted jurisdictions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), the EU-U.S. Data Privacy Framework (where the recipient is certified), or other lawful mechanisms. A copy of the applicable safeguard is available on request at [email protected].
Where transfers are necessary to perform the contract with you (i.e., to provide the Service), we rely on that necessity as a permitted basis under GDPR Art. 49(1)(b). You may contact us at [email protected] to discuss alternatives where available.
7. Data Retention
We retain personal information for as long as necessary to provide the Service and for the periods set out below, unless a longer retention is required or permitted by law.
| Data | Retention |
|---|---|
| Account information | Until account closure (longer if required by law or for unresolved disputes/claims) |
| Records used to prevent fraud or abuse | 90 days after account closure |
| Identity-verification records (Korea Members) | 1 year (where applicable) |
| Age-assurance consent records and date-of-birth correction history (non-Korean Members) | Until account closure (longer where required for unresolved disputes or legal purposes) |
| Contracts, withdrawal requests | 5 years (Korea e-commerce law — where applicable) |
| Payment and supply records (Including the Subscription Service) | 5 years |
| Consumer complaint or dispute records | 3 years |
| Website / app access logs | 3 months |
| Behavioral data (cookies, advertising identifiers) | Up to 24 months from collection |
| IAP Subscription payment data | Konrev does not retain payment-method data for IAP; retention is governed by Apple App Store or Google Play |
| Pseudonymized data used for recommendation systems and analytic | Up to 5 years from pseudonymization, or until the analytics purpose is achieved, whichever is earlier |
| Conversation Content used for own-model training | Retained for training use until you withdraw consent or opt out; thereafter no new training use. Data already incorporated into a trained model is governed by §12.1. |
After expiration, we delete or irreversibly anonymize the data.
8. Security
We implement administrative, technical, and physical safeguards designed to protect personal information from loss, misuse, and unauthorized access, including:
- internal management plans, training, and access controls;
- encryption in transit and at rest where appropriate;
- intrusion-detection and monitoring;
- physical access controls (CCTV, restricted entry, locked storage).
No method of transmission or storage is 100% secure. We cannot guarantee absolute security and ask that you safeguard your credentials.
Breach Notification. In the event of a personal data breach affecting your information, we will notify the relevant supervisory authorities and affected users as required by applicable law (including GDPR Arts. 33-34, CCPA, and Korea's PIPA).
Payment-Card Data. Raw card data is handled directly by our payment processor and is not retained by Konrev. For Subscription purchased through in-app purchase, all payment-card data is handled directly by Apple App Store or Google Play; Konrev does not collect or retain such data.
9. Your Rights
9.1 Universal Rights
Regardless of where you live, you may:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- delete your account and associated data (subject to legal-retention exceptions);
- delete a specific conversation by deleting the chat room containing it (the Service provides chat-room-level deletion; individual message deletion is not available);
- object to or withdraw consent for marketing communications.
Submit requests to [email protected]. We will verify your identity before responding and reply within the timeframes required by applicable law.
9.2 EEA / UK Residents (GDPR / UK GDPR)
You have the right to:
- access, rectification, erasure ("right to be forgotten"), restriction, and portability;
- object to processing based on legitimate interests, including profiling;
- object at any time, on an absolute basis, to processing for direct marketing (Art. 21(2));
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22), and to obtain an explanation of and contest such decisions;
- withdraw consent at any time;
- lodge a complaint with your local supervisory authority (a list is available at https://edpb.europa.eu/about-edpb/board/members_en) or, in the UK, with the Information Commissioner's Office (https://ico.org.uk/).
9.3 California Residents (CCPA / CPRA)
You have the right to know, access, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing" of personal information (as those terms are defined under the CCPA/CPRA).
Categories collected in the past 12 months: identifiers; Protected Classifications; commercial information; internet/electronic-network activity; geolocation; audio/visual content in messages; inferences. Sensitive personal information may include account credentials and any sensitive information voluntarily disclosed in messages. We obtain the categories of information described above directly from you, as well as from other sources, such as advertising partners, internet service providers, data analytics providers, operating systems and platforms, social media platforms, and where the information is publicly available.
"Sale" / "Sharing". We do not sell personal information for money. We may "share" online identifiers and usage data with advertising partners (e.g., Meta, TikTok, Google, X Corp.) for cross-context behavioral advertising. To opt out, email [email protected] with the subject line "Do Not Share My Personal Information." We do not knowingly sell or share personal information of minors under 16.
You also have the right to be free from discrimination for exercising these rights.
9.4 Nevada Residents
Nevada Revised Statutes Chapter 603A gives you the right to opt out of the future "sale" of certain covered information. Although we do not currently sell such information, you may submit a request by emailing [email protected] with the subject line "Nevada Do Not Sell Request."
9.5 Korea Residents (PIPA)
You may also exercise your rights under Korea's Personal Information Protection Act, including the right to access, correct, delete, suspend processing, and withdraw consent. You may submit complaints to:
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr (within Korea)
- Korea Internet & Security Agency Privacy Center: 118 / privacy.kisa.or.kr (within Korea)
9.6 Brazil Residents (LGPD)
You may request confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about sharing, withdrawal of consent, and review of automated decisions. Contact [email protected].
9.7 Authorized Agents
You may use an authorized agent to submit requests on your behalf. We may require written authorization and verification of your identity.
10. Children's Privacy
The Service is not directed to children under 14 (or under 16 in the EEA, UK, Switzerland, and where required by local law). We do not knowingly collect personal information from children below the applicable minimum age. To the extent the U.S. Children's Online Privacy Protection Act ("COPPA") applies, we do not knowingly collect personal information from children under 13; if we learn that we have, we will close the account and delete the information as required by COPPA.
If you are a parent or guardian and believe your child has provided personal information to us, contact [email protected].
11. Cookies, Analytics, and Targeted Advertising
We use cookies and similar technologies for: (a) operating the Service ("strictly necessary"); (b) analytics and product improvement; and (c) advertising and measurement. Where required by law (e.g., EEA/UK), we request your consent through a cookie banner before placing non-essential cookies.
Analytics & Advertising Partners: Google (Google Analytics, Google Ads), Amplitude, OneSignal, TikTok (Pixel), Meta (Pixel), X Corp. (Pixel).
How to manage:
- Browser cookies: Settings of your browser (Chrome, Safari, Edge, Firefox).
- Mobile advertising ID:
- Android: Settings > Google > Ads > Delete advertising ID
- iOS 14.5+: Settings > Privacy > Tracking > toggle off "Allow Apps to Request to Track"
- Industry opt-outs: NAI (https://optout.networkadvertising.org), DAA (https://optout.aboutads.info), EDAA (https://www.youronlinechoices.eu).
- Google Analytics opt-out: https://tools.google.com/dlpage/gaoptout.
12. AI Training and Pseudonymized Analytics Policy
This Section sets forth how Konrev uses Conversation Content for AI training and analytics, in alignment with the Korean Personal Information Protection Commission's "Personal Information Processing Policy Drafting Guidelines (April 2026 edition)" — particularly the newly introduced Generative AI Service Appendix — and, for GDPR-style regimes, the legal bases in Section 4.
12.1 Training of Konrev's Own AI Models
Konrev may use your Conversation Content (Input and Output), and data derived therefrom, to research, develop, and train (including re-training and fine-tuning) Konrev's own AI models.
- EEA, UK, and Switzerland: Konrev relies on your explicit consent (Art. 6(1)(a); and Art. 9(2)(a) where the Content reveals special-category data, such as data concerning sex life or sexual orientation). You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Other regions (including Korea): the legal basis and your right to opt out of own-model training are described in Section 1 and Section 10 and the applicable regional terms; you may exercise the opt-out at any time by contacting [email protected].
When you withdraw consent or opt out, Konrev stops further use of your Content for own-model training. With respect to data already lawfully incorporated into a trained model that cannot technically be separated or recalled, Konrev ceases new training use and applies technical and organizational safeguards to minimize re-identification risk.
This own-model training is distinct from, and must not be confused with, the external-provider no-training commitment in Section 12.3.
12.2 Pseudonymized Analytics for Service-Quality Improvement
Konrev may use your Conversation Content, after pseudonymization (as that term is functionally defined under GDPR Recitals 26 & 28 and Korea's PIPA Article 28-2), for the following purposes:
- recommendation systems for characters, content, and features;
- statistical research and analytics;
- service-quality improvement, INCluding evaluation of safety and content policies;
- detection and prevention of fraud, abuse, and misuse.
The legal basis for this processing in the EEA/UK is legitimate interests (Art. 6(1)(f)). We apply technical and organizational measures — including separation of pseudonymized data from re-identification keys, access controls, and retention limits set out in Section 7 — to reduce risk to your rights.
12.3 Processing by External Generative AI Providers
To generate AI responses, your Conversation Content (in particular, your prompts) is transmitted to external generative AI providers — currently OpenAI, Anthropic, X.AI, and Google Cloud AI — listed in Section 6. Konrev maintains enterprise-grade or equivalent contracts with such providers ensuring:
- the data is not used by such providers to train their own AI models;
- the data is processed under appropriate confidentiality and security obligations.
The recipients, transfer mechanisms, and safeguards applicable to such international transfers are described in Section 6.
12.4 Automated Decision-Making
We do not use personal information for legally significant automated decisions about you (e.g., credit, employment, insurance) without human review. Where the GDPR, UK GDPR, or comparable regime applies, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (GDPR Article 22), the right to obtain an explanation of such decisions, and the right to contest them. Contact [email protected] to exercise this right.
12.5 Generative AI Disclosure
In accordance with Article 50 of the EU AI Act and similar transparency obligations, we provide a separate Generative AI disclosure in Terms of Service Section 2, informing you that you interact with an AI system and not a human.
13. Third-Party Links
The Service may link to third-party websites, apps, or services we do not operate. Their privacy practices are governed by their own policies. We are not responsible for third-party data handling.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide notice through the Service or by email at least 30 days before the change takes effect (or such longer period as required by law). For non-material changes (e.g., clarifications, typo fixes), at least 7 days' notice will be provided.
Prior versions of this Policy are accessible through the Service's policy archive page, together with their respective effective periods.
Continued use of the Service after the effective date constitutes acceptance.
15. Contact
Konrev, INC.
Privacy Contact: [email protected]
Customer Support: [email protected]
Data Protection Officer: Lee Kyung-chan, CTO
Addendum
This Privacy Policy shall take effect on June 25, 2026, and shall be read and applied in conjunction with any supplemental terms applicable to your country of residence.
With respect to any matters arising on or after the effective date, this Privacy Policy shall also apply to all service agreements and transactions entered into with the Operator prior to this Policy taking effect.