본문으로 건너뛰기

대한민국 · Other countries

BagelChat Privacy Policy

1. About This Policy

This Privacy Policy describes how Konrev, INC., the operator of the BagelChat AI character chat service (the "Service"), collects, uses, discloses, and protects personal information. It applies to all users of the Service worldwide, with additional region-specific rights set out in Section 9 ("Your Rights"), which contains dedicated subsections for the EEA, UK, California, Nevada, Korea, and Brazil.

If you do not agree with this Policy, do not use the Service.

2. Information We Collect

2.1 Information You Provide

CategoryExamplesPurpose
Account informationSocial-login unique identifier, email address, profile name, date of birthIdentify you and provide the Service
Identity verification (Korea Members only — where applicable)Name, date of birth, gender, DI, mobile number — via NICE Information ServiceVerify your identity and age in Korea
Age assurance (Self-Declaration) — non-Korean MembersSelf-declaration consent record: timestamp, IP and device information at consent, date of birth registered at the time, calculated age, country of access, and history of date-of-birth correctionsVerify eligibility for Age-restricted Contet, prevent abuse of age controls, handle disputes. See also Operating Policy Chapter 3 (Age Assurance).
Conversation contentMessages, characters, images, audio, video you submit; AI responses; reactionsProvide the AI conversation feature
Payment data — web paymentsTransaction identifier (order/authorization number), payment timestamp, and payment amount for one-time Cream purchases. Raw card data is handled directly by our payment processor and is not retained by Konrev.Operate one-time Cream purchases
Payment data — in-app purchases (Apple, Google)Transaction identifier and Subscription status received from Apple App Store or Google Play. Konrev does not collect or retain your card information for IAP transactions; that data is handled by Apple or Google directly.Operate Subscription via in-app purchase, manage Subscription state
Customer supportEmail address, inquiry contentsRespond to your requests

2.2 Information Collected Automatically

We and our service providers use cookies, SDKs, and similar technologies to collect:

  • IP address, device identifiers (ADID / IDFA), browser, operating system
  • Service usage records (sessions, page views, click events, time spent)
  • Crash and error logs
  • General location inferred from IP address
  • Application information (version, etc.) where you use the mobile app

2.3 Information from Third Parties

If you sign in through a third-party social platform (e.g., Google, Apple, Meta), we receive the basic profile information that platform shares according to your permissions. We may also receive information about you from other users (e.g., referrals or interactions involving you).

3. How We Use Information

We use personal information to:

  • create, administer, and secure your account;
  • provide the Service and personalize your experience;
  • process payments and manage Cream balances, Including the Subscription Service;
  • communicate with you about features, updates, and policy changes;
  • provide customer support;
  • analyze, maintain, and improve the Service. Konrev may use your Conversation Content (Input and Output) to research, develop, and train (including re-training and fine-tuning) Konrev's own AI models. For Members in the EEA, the UK, or Switzerland, such use is based on your explicit consent — and, where the Content reveals special-category data (such as data concerning sex life or sexual orientation), on Art. 9(2)(a) explicit consent — which you may withdraw at any time; for other Members, the applicable legal basis and any opt-out are described in Section 12. Konrev may also use pseudonymized data derived from Conversation Content for recommendation systems, statistical research, and service-quality improvement. This own-model training is distinct from external generative AI providers, which do not train their own models on your Content (see Sections 5 and 6). See Section 12 (AI Training and Pseudonymized Analytics Policy) for details;
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • comply with legal obligations and enforce our Terms; and
  • create aggregated or de-identified data for legitimate business purposes.

Where GDPR or a similar regime applies, we process your personal information under one or more of the following legal bases:

PurposeLegal basis
Providing the Service, processing payments, account managementPerformance of a contract (Art. 6(1)(b))
Marketing emails, optional analyticsConsent (Art. 6(1)(a)) — withdrawable at any time
Pseudonymized analytics, recommendation systems, statistical research, service-quality improvementLegitimate interests (Art. 6(1)(f)) and, in respect of pseudonymization, GDPR Recitals 26 and 28 (functional equivalent of Korea's PIPA Article 28-2 pseudonymization regime)
Training Konrev's own AI models on Conversation ContentExplicit consent (Art. 6(1)(a); and Art. 9(2)(a) where the Content reveals special-category data) — withdrawable at any time. EEA/UK/Swiss Members are not subject to own-model training without such consent.
Fraud prevention, security, business analyticsLegitimate interests (Art. 6(1)(f))
Tax, accounting, compliance with legal requestsLegal obligation (Art. 6(1)(c))
Sensitive data (where applicable)Explicit consent (Art. 9(2)(a))

You can withdraw consent at any time without affecting the lawfulness of prior processing. Withdrawing consent to own-model training stops further such use; data already lawfully incorporated into a trained model that cannot technically be separated or recalled is addressed in Section 12. See Section 12 (AI Training and Pseudonymized Analytics Policy) for full details on how Konrev handles your Conversation Content with respect to AI training and analytics.

5. How We Share Information

We do not sell personal information for monetary consideration. We share information only as described below:

Recipient categoryPurposeExamples
Service providers (processors)Operate the Service on our instructionsAWS, Cloudflare, Google Cloud — hosting; Toss Payments — (i) web payment processing including foreign credit-card payments for one-time Cream purchases, (ii) fraud prevention ; NICE Information Service — identity verification (Korea only); Zendesk — customer support; Sentry (Functional Software, Inc.) — error monitoring
App marketplaces (for IAP only)Process Subscription via in-app purchaseApple Inc. (Apple App Store), Google LLC (Google Play) — these parties handle their own card-data collection and storage under their own policies
AI model providersGenerate AI responses under enterprise-grade or equivalent contracts ensuring the data is not used to train such providers' own AI modelsOpenAI, Anthropic, X.AI, Google Cloud (AI Platform)
Analytics and marketing partnersMeasurement, attribution, advertisingGoogle Analytics, Amplitude, OneSignal, TikTok, Meta, X Corp.
Legal / safetyComply with law, protect rights and safety, address fraud, respond to subpoenasLaw enforcement, courts, regulators
Business transfersM&A, financing, asset saleSuccessor entity (subject to this Policy)
With your consentAs you direct

6. International Data Transfers

The Service is global. Personal information we collect may be transferred to, stored in, and processed in countries outside your country of residence, including the Republic of Korea, the United States, and Japan, which may have data-protection laws different from those of your jurisdiction.

CountryRecipientData transferredPurpose
Republic of KoreaKonrev, INC. (operator)All personal informationService operation, customer support
Republic of KoreaToss Payments Co., Ltd.Payment data: transaction identifiers, foreign credit-card data for one-time Cream purchasesPayment processing, fraud prevention
Republic of KoreaNICE Information Service Co., Ltd.Identity-verification informationIdentity and age verification (Korea Members only)
USA, JapanAmazon Web Services, Inc.All personal informationCloud infrastructure, storage
USACloudflare, Inc.All personal informationCDN, security
USAGoogle Cloud Korea LLCAll personal information, messages, metadataCloud infrastructure, AI
USAOpenAI, L.L.C. ([email protected])Messages and metadataAI response generation under enterprise-grade contract: no provider-side model training
USAAnthropic, PBC ([email protected])Messages and metadataAI response generation under enterprise-grade contract: no provider-side model training
USAX.AI Corp. ([email protected])Messages and metadataAI response generation under enterprise-grade contract: no provider-side model training
USAAmplitude, Inc.Usage records, cookies, advertising identifiersAnalytics, service improvement
USAGoogle, LLCUsage records, cookies, advertising identifiersAnalytics, advertising
USAOneSignal, Inc.Usage records, advertising identifiersPush notifications
USAZendesk, Inc.Email, user name, inquiry contentsCustomer support
USAFunctional Software, Inc. (Sentry)Usage records, device info, IP addressError monitoring
USAApple Inc. (for iOS in-app purchases)IAP Subscription transaction dataApp marketplace payment processing
USAGoogle LLC (for Android in-app purchases)IAP Subscription transaction dataApp marketplace payment processing

Safeguards. For transfers from the EEA, UK, Switzerland, or other restricted jurisdictions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), the EU-U.S. Data Privacy Framework (where the recipient is certified), or other lawful mechanisms. A copy of the applicable safeguard is available on request at [email protected].

Where transfers are necessary to perform the contract with you (i.e., to provide the Service), we rely on that necessity as a permitted basis under GDPR Art. 49(1)(b). You may contact us at [email protected] to discuss alternatives where available.

7. Data Retention

We retain personal information for as long as necessary to provide the Service and for the periods set out below, unless a longer retention is required or permitted by law.

DataRetention
Account informationUntil account closure (longer if required by law or for unresolved disputes/claims)
Records used to prevent fraud or abuse90 days after account closure
Identity-verification records (Korea Members)1 year (where applicable)
Age-assurance consent records and date-of-birth correction history (non-Korean Members)Until account closure (longer where required for unresolved disputes or legal purposes)
Contracts, withdrawal requests5 years (Korea e-commerce law — where applicable)
Payment and supply records (Including the Subscription Service)5 years
Consumer complaint or dispute records3 years
Website / app access logs3 months
Behavioral data (cookies, advertising identifiers)Up to 24 months from collection
IAP Subscription payment dataKonrev does not retain payment-method data for IAP; retention is governed by Apple App Store or Google Play
Pseudonymized data used for recommendation systems and analyticUp to 5 years from pseudonymization, or until the analytics purpose is achieved, whichever is earlier
Conversation Content used for own-model trainingRetained for training use until you withdraw consent or opt out; thereafter no new training use. Data already incorporated into a trained model is governed by §12.1.

After expiration, we delete or irreversibly anonymize the data.

8. Security

We implement administrative, technical, and physical safeguards designed to protect personal information from loss, misuse, and unauthorized access, including:

  • internal management plans, training, and access controls;
  • encryption in transit and at rest where appropriate;
  • intrusion-detection and monitoring;
  • physical access controls (CCTV, restricted entry, locked storage).

No method of transmission or storage is 100% secure. We cannot guarantee absolute security and ask that you safeguard your credentials.

Breach Notification. In the event of a personal data breach affecting your information, we will notify the relevant supervisory authorities and affected users as required by applicable law (including GDPR Arts. 33-34, CCPA, and Korea's PIPA).

Payment-Card Data. Raw card data is handled directly by our payment processor and is not retained by Konrev. For Subscription purchased through in-app purchase, all payment-card data is handled directly by Apple App Store or Google Play; Konrev does not collect or retain such data.

9. Your Rights

9.1 Universal Rights

Regardless of where you live, you may:

  • access the personal information we hold about you;
  • correct inaccurate or incomplete information;
  • delete your account and associated data (subject to legal-retention exceptions);
  • delete a specific conversation by deleting the chat room containing it (the Service provides chat-room-level deletion; individual message deletion is not available);
  • object to or withdraw consent for marketing communications.

Submit requests to [email protected]. We will verify your identity before responding and reply within the timeframes required by applicable law.

9.2 EEA / UK Residents (GDPR / UK GDPR)

You have the right to:

  • access, rectification, erasure ("right to be forgotten"), restriction, and portability;
  • object to processing based on legitimate interests, including profiling;
  • object at any time, on an absolute basis, to processing for direct marketing (Art. 21(2));
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22), and to obtain an explanation of and contest such decisions;
  • withdraw consent at any time;
  • lodge a complaint with your local supervisory authority (a list is available at https://edpb.europa.eu/about-edpb/board/members_en) or, in the UK, with the Information Commissioner's Office (https://ico.org.uk/).

9.3 California Residents (CCPA / CPRA)

You have the right to know, access, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing" of personal information (as those terms are defined under the CCPA/CPRA).

Categories collected in the past 12 months: identifiers; Protected Classifications; commercial information; internet/electronic-network activity; geolocation; audio/visual content in messages; inferences. Sensitive personal information may include account credentials and any sensitive information voluntarily disclosed in messages. We obtain the categories of information described above directly from you, as well as from other sources, such as advertising partners, internet service providers, data analytics providers, operating systems and platforms, social media platforms, and where the information is publicly available.

"Sale" / "Sharing". We do not sell personal information for money. We may "share" online identifiers and usage data with advertising partners (e.g., Meta, TikTok, Google, X Corp.) for cross-context behavioral advertising. To opt out, email [email protected] with the subject line "Do Not Share My Personal Information." We do not knowingly sell or share personal information of minors under 16.

You also have the right to be free from discrimination for exercising these rights.

9.4 Nevada Residents

Nevada Revised Statutes Chapter 603A gives you the right to opt out of the future "sale" of certain covered information. Although we do not currently sell such information, you may submit a request by emailing [email protected] with the subject line "Nevada Do Not Sell Request."

9.5 Korea Residents (PIPA)

You may also exercise your rights under Korea's Personal Information Protection Act, including the right to access, correct, delete, suspend processing, and withdraw consent. You may submit complaints to:

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr (within Korea)
  • Korea Internet & Security Agency Privacy Center: 118 / privacy.kisa.or.kr (within Korea)

9.6 Brazil Residents (LGPD)

You may request confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about sharing, withdrawal of consent, and review of automated decisions. Contact [email protected].

9.7 Authorized Agents

You may use an authorized agent to submit requests on your behalf. We may require written authorization and verification of your identity.

10. Children's Privacy

The Service is not directed to children under 14 (or under 16 in the EEA, UK, Switzerland, and where required by local law). We do not knowingly collect personal information from children below the applicable minimum age. To the extent the U.S. Children's Online Privacy Protection Act ("COPPA") applies, we do not knowingly collect personal information from children under 13; if we learn that we have, we will close the account and delete the information as required by COPPA.

If you are a parent or guardian and believe your child has provided personal information to us, contact [email protected].

11. Cookies, Analytics, and Targeted Advertising

We use cookies and similar technologies for: (a) operating the Service ("strictly necessary"); (b) analytics and product improvement; and (c) advertising and measurement. Where required by law (e.g., EEA/UK), we request your consent through a cookie banner before placing non-essential cookies.

Analytics & Advertising Partners: Google (Google Analytics, Google Ads), Amplitude, OneSignal, TikTok (Pixel), Meta (Pixel), X Corp. (Pixel).

How to manage:

12. AI Training and Pseudonymized Analytics Policy

This Section sets forth how Konrev uses Conversation Content for AI training and analytics, in alignment with the Korean Personal Information Protection Commission's "Personal Information Processing Policy Drafting Guidelines (April 2026 edition)" — particularly the newly introduced Generative AI Service Appendix — and, for GDPR-style regimes, the legal bases in Section 4.

12.1 Training of Konrev's Own AI Models

Konrev may use your Conversation Content (Input and Output), and data derived therefrom, to research, develop, and train (including re-training and fine-tuning) Konrev's own AI models.

  • EEA, UK, and Switzerland: Konrev relies on your explicit consent (Art. 6(1)(a); and Art. 9(2)(a) where the Content reveals special-category data, such as data concerning sex life or sexual orientation). You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Other regions (including Korea): the legal basis and your right to opt out of own-model training are described in Section 1 and Section 10 and the applicable regional terms; you may exercise the opt-out at any time by contacting [email protected].

When you withdraw consent or opt out, Konrev stops further use of your Content for own-model training. With respect to data already lawfully incorporated into a trained model that cannot technically be separated or recalled, Konrev ceases new training use and applies technical and organizational safeguards to minimize re-identification risk.

This own-model training is distinct from, and must not be confused with, the external-provider no-training commitment in Section 12.3.

12.2 Pseudonymized Analytics for Service-Quality Improvement

Konrev may use your Conversation Content, after pseudonymization (as that term is functionally defined under GDPR Recitals 26 & 28 and Korea's PIPA Article 28-2), for the following purposes:

  • recommendation systems for characters, content, and features;
  • statistical research and analytics;
  • service-quality improvement, INCluding evaluation of safety and content policies;
  • detection and prevention of fraud, abuse, and misuse.

The legal basis for this processing in the EEA/UK is legitimate interests (Art. 6(1)(f)). We apply technical and organizational measures — including separation of pseudonymized data from re-identification keys, access controls, and retention limits set out in Section 7 — to reduce risk to your rights.

12.3 Processing by External Generative AI Providers

To generate AI responses, your Conversation Content (in particular, your prompts) is transmitted to external generative AI providers — currently OpenAI, Anthropic, X.AI, and Google Cloud AI — listed in Section 6. Konrev maintains enterprise-grade or equivalent contracts with such providers ensuring:

  • the data is not used by such providers to train their own AI models;
  • the data is processed under appropriate confidentiality and security obligations.

The recipients, transfer mechanisms, and safeguards applicable to such international transfers are described in Section 6.

12.4 Automated Decision-Making

We do not use personal information for legally significant automated decisions about you (e.g., credit, employment, insurance) without human review. Where the GDPR, UK GDPR, or comparable regime applies, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (GDPR Article 22), the right to obtain an explanation of such decisions, and the right to contest them. Contact [email protected] to exercise this right.

12.5 Generative AI Disclosure

In accordance with Article 50 of the EU AI Act and similar transparency obligations, we provide a separate Generative AI disclosure in Terms of Service Section 2, informing you that you interact with an AI system and not a human.

The Service may link to third-party websites, apps, or services we do not operate. Their privacy practices are governed by their own policies. We are not responsible for third-party data handling.

14. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice through the Service or by email at least 30 days before the change takes effect (or such longer period as required by law). For non-material changes (e.g., clarifications, typo fixes), at least 7 days' notice will be provided.

Prior versions of this Policy are accessible through the Service's policy archive page, together with their respective effective periods.

Continued use of the Service after the effective date constitutes acceptance.

15. Contact

Konrev, INC.

Privacy Contact: [email protected]

Customer Support: [email protected]

Data Protection Officer: Lee Kyung-chan, CTO

Addendum

This Privacy Policy shall take effect on June 25, 2026, and shall be read and applied in conjunction with any supplemental terms applicable to your country of residence.

With respect to any matters arising on or after the effective date, this Privacy Policy shall also apply to all service agreements and transactions entered into with the Operator prior to this Policy taking effect.