Privacy Policy
Effective August 15, 2026 · Policy version 2026-08-15
1. Data controller
- Business: Round
- Representative: Heejae Byun
- Korean business registration number: 426-53-01094
- E-commerce registration: 2026-Yongin Giheung-01168
- Address: Building 118, Unit 403, 11 Jungbu-daero 55beon-gil, Giheung-gu, Yongin-si, Gyeonggi-do 16952, Republic of Korea
- Privacy contact: representative / admin@team-round.com
2. Service for adults
Only people aged 18 or older may use Yeoun as a guest, create an account, or make a payment. We do not intentionally collect personal data from anyone under 18 and currently offer no parental-consent flow. When an age violation is verified, access is blocked and personal data is deleted except where retention is legally required.
3. Separate guest and account agreements
| Stage | Required review and consent | If declined |
|---|---|---|
| Guest start | Guest Terms, guest session and use-data processing, AI processing and overseas transfer, and 18-or-older confirmation | No guest session is issued |
| Account sign-up | Account Terms, processing of account data such as email or Google identifiers, AI processing and overseas transfer, and 18-or-older confirmation | No account is created |
| Existing member after a policy revision | A changed required item where renewed consent is legally required | The affected feature or AI conversation may be restricted |
Guest consent never replaces account sign-up consent. If a guest converts to an account, both agreement histories remain source-attributed under that account and are deleted with the account. Service notifications are separate from marketing notifications such as new-story or event notices. Marketing notifications are optional, do not affect access to the service, and can be withdrawn at any time in Account.
4. Personal data processed
| Category | Data | Purpose | Retention |
|---|---|---|---|
| Required agreement history | User/guest ID, acceptance or withdrawal type, versions and hashes of Terms, policies, AI notice and provider manifest, locale, surface, timestamp, and idempotency ID | Proof of contract and consent, renewed consent after revisions | Deleted with the account or guest record. If a separate case or transaction record has a statutory retention duty, only that record is separated for the applicable period |
| Guest | Random guest ID, access and refresh sessions and expiry; connection IP or a one-way hash of the session-owner identifier may be processed temporarily for rate limiting | Authentication, progress, duplicate and abuse prevention | Until record deletion or the operational period after session/contract end; IP/owner-hash rate-limit data until its window ends |
| Email account | Email, one-way hashed and salted password, display name, authentication method | Sign-up, sign-in, recovery, security | Until account deletion |
| Google account | Immutable Google identifier (sub), verified email, display name, authentication method | Google account sign-up, sign-in, and linking | Until unlinking or account deletion |
| Story and conversation | User dialogue and actions, AI responses, choices, story progress, worldline, character participation | AI response, story execution, recovery, support | Original conversation text: 30 days; progress until deletion |
| Relationships and memories | Qualitative stage and axes, evidence events, approved memories, summaries, character knowledge, mutual decisions | Relationship continuity across works and relationship rooms | Until the item, relationship, or account/guest record is deleted |
| Purchase and subscription | Product ID, Google Play order and transaction IDs, purchase/subscription time and status, verification, cancellation, and refund result; no full payment-card number | Verification, credit/subscription grant, restoration, refunds, fraud response | Applicable statutory e-commerce period |
| Service analytics | Pseudonymous ID, app launch, catalogue impression, detail view, session start, first response, completion, relationship connection, latency, model, fallback, cost | Quality, conversion, incident, and cost analysis | Until purpose completion or account/record deletion; no conversation text in analytics events |
| Error diagnosis | App/server version, device and OS type, error code and stack, request route; configured to remove conversation text, tokens, email, and receipt data before transfer | Incident detection and recovery | Sentry project retention setting |
| App notifications | Notification device ID, Expo push token, OS, locale and time zone, service/marketing preferences and consent timestamps, delivery/error outcome | Service notices such as purchase/review updates, optional new-story/event notices, quiet hours and duplicate prevention | Until device unregistration or account deletion; notification preferences and opt-in/withdrawal events are also deleted with the account |
| Creator | Account, application/review records, works, drafts, uploaded assets, rights confirmation, settlement agreement, revenue and payout-request information | Studio, review, publication, rights, settlement | Contractual and statutory period; raw payout credentials are not collected without an approved payout provider |
| Rights complaints and responses | Claimant, agent, and creator name or organisation, contact, case ID, affected work or asset, claim, response, appeal, and submitted evidence | Complaint intake, party verification, temporary action, response, appeal, dispute handling, and audit | Separated after case closure and deleted after the applicable legal or dispute period; unnecessary identity or financial data is not requested |
The service is not designed to request government ID numbers, full card numbers, raw account passwords, or verification codes in conversation. If a user voluntarily enters such data in ordinary chat, it may be processed for response generation and included in the 30-day conversation-retention window; do not enter it.
5. Legal basis and withdrawal
We process personal data as necessary to enter into and perform the service contract, on explicit consent, to comply with law, and to secure the service and prevent abuse. Declining required consent prevents guest-session or account creation. Later withdrawal of AI processing and overseas-transfer consent blocks new AI conversations but does not automatically delete the account or existing conversation, relationship, or memory records. Use the separate deletion controls to delete them.
Service and marketing notifications have separate controls. Marketing is off by default and is sent only after an optional opt-in. Withdrawal blocks queued marketing notifications immediately. Operating-system notification permission remains under the user's device settings.
6. Processors
| Processor | Service | Data and period |
|---|---|---|
| Google Cloud / Google LLC | Server, database, Secret Manager, Google authentication, and Play purchase verification | Account, progress, and purchase data needed to operate the service, until contract end or deletion request except statutory records |
| Vercel Inc. | Public website and policy pages | Technical web-access data for the period set by Vercel policy and our configuration |
7. Overseas transfer and external services
When generating an AI response, your input, the necessary conversation, story and relationship context, request metadata, and generated output are encrypted in transit to OpenAI. The current customer AI provider is fixed to OpenAI and does not automatically fail over to another external AI provider.
| Recipient and contact | Country | Purpose and data | Timing and method | Retention and improvement use |
|---|---|---|---|---|
| OpenAI, L.L.C. privacy@openai.com | United States | AI response and safety/abuse prevention; input, necessary context, metadata, output | Encrypted transfer for every customer AI conversation, including free, subscription, and credit-funded turns | Not used for model training by default under the standard API policy; safety logs may be retained up to 30 days. Yeoun applies store: false where supported. |
| Google LLC Privacy contact | United States and disclosed global processing countries | Google authentication, Google Cloud service operation, and Play verification; identity, service, or transaction data needed for the feature | Encrypted transfer when the feature is requested or the service operates | Authentication, cloud, and purchase data follow Google policy, our configuration, and statutory periods. Google is not used as a customer AI-conversation provider. |
| Functional Software, Inc. (Sentry) privacy@sentry.io | Germany region and United States | App/server error diagnosis: error code, stack, device, OS, version, and request route | Encrypted transfer when an error occurs | Our Sentry project retention setting. The integration is configured to remove conversation text, tokens, email, and receipt data before transfer. |
| 650 Industries, Inc. (Expo) and Google LLC (Firebase Cloud Messaging) | United States and provider-disclosed processing countries | App notification delivery: Expo push token, device/OS/locale, notification title/body, allow-listed app route, delivery outcome | Encrypted transfer when a device registers or a notification is sent | Provider policy and our configuration. Notifications do not contain dialogue, memories, birth data, or payment receipts. |
See AI processing and overseas data transfer for provider policy links and the effect of refusal. Without consent, guest onboarding or account sign-up cannot finish; after withdrawal, new AI conversations are unavailable.
8. Retention and deletion
- Original dialogue, actions, and AI responses: replaced with a deletion marker and destroyed 30 days after creation, or promptly after an earlier user deletion request
- Progress, worldline, relationships, promoted memories, and knowledge: stored separately until the user deletes the item, relationship, record, or account
- Contract, cancellation, payment, and supply records: five years under Korean e-commerce law
- Consumer complaint and dispute records: three years under Korean e-commerce law
- Rights complaint, response, and appeal records: the applicable statutory period or the period reasonably needed for the rights dispute after case closure
- Advertising and display records: six months under Korean e-commerce law
- Access records, where Korean communications-secrecy or another law applies: the applicable statutory period
Electronic files are deleted in a manner intended to prevent recovery. Statutory records are separated and not used for unrelated purposes. Deletion targets remaining in backups expire through the defined backup rotation and are not restored as active service data.
9. Your rights
You may request access, portability, correction, deletion, restriction, or withdrawal of consent for your personal data and agreement history. Use the account and memory controls, the account deletion page, or admin@team-round.com. A request may be limited where required by law or to protect another person’s rights, and we will explain the reason.
10. Automated decisions
Yeoun automatically interprets input, in-story events, and relationship evidence for story progress and a character’s mutual decision. This may affect branches and relationship features but does not make consequential real-world decisions about legal rights, credit, or employment. Users can review, correct, or exclude memories, reset a relationship, and contact support about suspected errors.
11. Security safeguards
- No storage of raw passwords; one-way hashing and salting
- HTTPS in transit and production-secret management through Secret Manager
- Separate access and refresh tokens, session rotation, and owner-scoped access control
- Encrypted purchase tokens, hashed identifiers, and server verification
- Analytics without conversation text and privacy scrubbing before error reporting
- Account export/deletion, memory controls, and AI-consent withdrawal
12. Cookies and similar technology
The mobile app stores authentication tokens in the operating system’s secure storage. Studio may use HttpOnly, Secure, SameSite cookies needed to maintain a web sign-in. The public policy site does not use personalised-advertising cookies.
13. Changes and remedies
We announce the effective date and material changes in the service or on this page. A change requiring new consent is accepted explicitly before it takes effect. Korean users may also seek counselling or dispute mediation through the Personal Information Infringement Report Center (118), Personal Information Dispute Mediation Committee, or other competent authority; overseas users may contact their applicable privacy authority.