← English legal information

Privacy Policy

Effective August 15, 2026 · Policy version 2026-08-15

Yeoun retains original conversation text for 30 days and does not use it to train Company models or for personalised advertising. Input and context for every customer AI conversation, including free, subscription, and credit-funded turns, are transferred overseas to OpenAI and are not automatically forwarded to another external AI provider during an outage.

1. Data controller

2. Service for adults

Only people aged 18 or older may use Yeoun as a guest, create an account, or make a payment. We do not intentionally collect personal data from anyone under 18 and currently offer no parental-consent flow. When an age violation is verified, access is blocked and personal data is deleted except where retention is legally required.

3. Separate guest and account agreements

StageRequired review and consentIf declined
Guest startGuest Terms, guest session and use-data processing, AI processing and overseas transfer, and 18-or-older confirmationNo guest session is issued
Account sign-upAccount Terms, processing of account data such as email or Google identifiers, AI processing and overseas transfer, and 18-or-older confirmationNo account is created
Existing member after a policy revisionA changed required item where renewed consent is legally requiredThe affected feature or AI conversation may be restricted

Guest consent never replaces account sign-up consent. If a guest converts to an account, both agreement histories remain source-attributed under that account and are deleted with the account. Service notifications are separate from marketing notifications such as new-story or event notices. Marketing notifications are optional, do not affect access to the service, and can be withdrawn at any time in Account.

4. Personal data processed

CategoryDataPurposeRetention
Required agreement historyUser/guest ID, acceptance or withdrawal type, versions and hashes of Terms, policies, AI notice and provider manifest, locale, surface, timestamp, and idempotency IDProof of contract and consent, renewed consent after revisionsDeleted with the account or guest record. If a separate case or transaction record has a statutory retention duty, only that record is separated for the applicable period
GuestRandom guest ID, access and refresh sessions and expiry; connection IP or a one-way hash of the session-owner identifier may be processed temporarily for rate limitingAuthentication, progress, duplicate and abuse preventionUntil record deletion or the operational period after session/contract end; IP/owner-hash rate-limit data until its window ends
Email accountEmail, one-way hashed and salted password, display name, authentication methodSign-up, sign-in, recovery, securityUntil account deletion
Google accountImmutable Google identifier (sub), verified email, display name, authentication methodGoogle account sign-up, sign-in, and linkingUntil unlinking or account deletion
Story and conversationUser dialogue and actions, AI responses, choices, story progress, worldline, character participationAI response, story execution, recovery, supportOriginal conversation text: 30 days; progress until deletion
Relationships and memoriesQualitative stage and axes, evidence events, approved memories, summaries, character knowledge, mutual decisionsRelationship continuity across works and relationship roomsUntil the item, relationship, or account/guest record is deleted
Purchase and subscriptionProduct ID, Google Play order and transaction IDs, purchase/subscription time and status, verification, cancellation, and refund result; no full payment-card numberVerification, credit/subscription grant, restoration, refunds, fraud responseApplicable statutory e-commerce period
Service analyticsPseudonymous ID, app launch, catalogue impression, detail view, session start, first response, completion, relationship connection, latency, model, fallback, costQuality, conversion, incident, and cost analysisUntil purpose completion or account/record deletion; no conversation text in analytics events
Error diagnosisApp/server version, device and OS type, error code and stack, request route; configured to remove conversation text, tokens, email, and receipt data before transferIncident detection and recoverySentry project retention setting
App notificationsNotification device ID, Expo push token, OS, locale and time zone, service/marketing preferences and consent timestamps, delivery/error outcomeService notices such as purchase/review updates, optional new-story/event notices, quiet hours and duplicate preventionUntil device unregistration or account deletion; notification preferences and opt-in/withdrawal events are also deleted with the account
CreatorAccount, application/review records, works, drafts, uploaded assets, rights confirmation, settlement agreement, revenue and payout-request informationStudio, review, publication, rights, settlementContractual and statutory period; raw payout credentials are not collected without an approved payout provider
Rights complaints and responsesClaimant, agent, and creator name or organisation, contact, case ID, affected work or asset, claim, response, appeal, and submitted evidenceComplaint intake, party verification, temporary action, response, appeal, dispute handling, and auditSeparated after case closure and deleted after the applicable legal or dispute period; unnecessary identity or financial data is not requested

The service is not designed to request government ID numbers, full card numbers, raw account passwords, or verification codes in conversation. If a user voluntarily enters such data in ordinary chat, it may be processed for response generation and included in the 30-day conversation-retention window; do not enter it.

5. Legal basis and withdrawal

We process personal data as necessary to enter into and perform the service contract, on explicit consent, to comply with law, and to secure the service and prevent abuse. Declining required consent prevents guest-session or account creation. Later withdrawal of AI processing and overseas-transfer consent blocks new AI conversations but does not automatically delete the account or existing conversation, relationship, or memory records. Use the separate deletion controls to delete them.

Service and marketing notifications have separate controls. Marketing is off by default and is sent only after an optional opt-in. Withdrawal blocks queued marketing notifications immediately. Operating-system notification permission remains under the user's device settings.

6. Processors

ProcessorServiceData and period
Google Cloud / Google LLCServer, database, Secret Manager, Google authentication, and Play purchase verificationAccount, progress, and purchase data needed to operate the service, until contract end or deletion request except statutory records
Vercel Inc.Public website and policy pagesTechnical web-access data for the period set by Vercel policy and our configuration

7. Overseas transfer and external services

When generating an AI response, your input, the necessary conversation, story and relationship context, request metadata, and generated output are encrypted in transit to OpenAI. The current customer AI provider is fixed to OpenAI and does not automatically fail over to another external AI provider.

Recipient and contactCountryPurpose and dataTiming and methodRetention and improvement use
OpenAI, L.L.C.
privacy@openai.com
United StatesAI response and safety/abuse prevention; input, necessary context, metadata, outputEncrypted transfer for every customer AI conversation, including free, subscription, and credit-funded turnsNot used for model training by default under the standard API policy; safety logs may be retained up to 30 days. Yeoun applies store: false where supported.
Google LLC
Privacy contact
United States and disclosed global processing countriesGoogle authentication, Google Cloud service operation, and Play verification; identity, service, or transaction data needed for the featureEncrypted transfer when the feature is requested or the service operatesAuthentication, cloud, and purchase data follow Google policy, our configuration, and statutory periods. Google is not used as a customer AI-conversation provider.
Functional Software, Inc. (Sentry)
privacy@sentry.io
Germany region and United StatesApp/server error diagnosis: error code, stack, device, OS, version, and request routeEncrypted transfer when an error occursOur Sentry project retention setting. The integration is configured to remove conversation text, tokens, email, and receipt data before transfer.
650 Industries, Inc. (Expo) and Google LLC (Firebase Cloud Messaging)United States and provider-disclosed processing countriesApp notification delivery: Expo push token, device/OS/locale, notification title/body, allow-listed app route, delivery outcomeEncrypted transfer when a device registers or a notification is sentProvider policy and our configuration. Notifications do not contain dialogue, memories, birth data, or payment receipts.

See AI processing and overseas data transfer for provider policy links and the effect of refusal. Without consent, guest onboarding or account sign-up cannot finish; after withdrawal, new AI conversations are unavailable.

8. Retention and deletion

Electronic files are deleted in a manner intended to prevent recovery. Statutory records are separated and not used for unrelated purposes. Deletion targets remaining in backups expire through the defined backup rotation and are not restored as active service data.

9. Your rights

You may request access, portability, correction, deletion, restriction, or withdrawal of consent for your personal data and agreement history. Use the account and memory controls, the account deletion page, or admin@team-round.com. A request may be limited where required by law or to protect another person’s rights, and we will explain the reason.

10. Automated decisions

Yeoun automatically interprets input, in-story events, and relationship evidence for story progress and a character’s mutual decision. This may affect branches and relationship features but does not make consequential real-world decisions about legal rights, credit, or employment. Users can review, correct, or exclude memories, reset a relationship, and contact support about suspected errors.

11. Security safeguards

12. Cookies and similar technology

The mobile app stores authentication tokens in the operating system’s secure storage. Studio may use HttpOnly, Secure, SameSite cookies needed to maintain a web sign-in. The public policy site does not use personalised-advertising cookies.

13. Changes and remedies

We announce the effective date and material changes in the service or on this page. A change requiring new consent is accepted explicitly before it takes effect. Korean users may also seek counselling or dispute mediation through the Personal Information Infringement Report Center (118), Personal Information Dispute Mediation Committee, or other competent authority; overseas users may contact their applicable privacy authority.