Privacy Policy

Version 2026-07-18 Effective 2026-07-18 Labuchat Inc.

This English text is a translation provided for the user's convenience. In the event of any conflict or discrepancy between this translation and the original Korean version, the Korean version shall prevail and be legally binding.

Labuchat Inc. (hereinafter the "Company") complies with applicable laws, including the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter the "Network Act") and the Personal Information Protection Act, and establishes and discloses the following Privacy Policy in order to protect members' personal information and to handle related grievances promptly and smoothly.

Article 1 (Purposes of Collection and Use of Personal Information)

The Company processes personal information for the following purposes. The personal information being processed shall not be used for any purpose other than the following, and where the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent.

  1. Membership registration and management: Processed for purposes such as confirming intent to register as a member, identifying and authenticating individuals in connection with the provision of membership services, restricting registration of minors under the age of 19 (adult verification), maintaining and managing membership status, preventing misuse, providing various notices and notifications, and handling grievances.
  2. Provision of services and payment of fees: Processed for purposes such as providing the 1:1 voice communication service, purchasing and paying for paid services, and settling Partner (Creator) revenue and filing tax returns.
  3. Creating a safe communication environment: Call contents are recorded and retained for the purposes of preventing unlawful acts such as sexual harassment, abusive language, and fraud within the Service and acts in violation of the terms of service, sanctioning malicious users, and verifying facts and securing evidentiary materials in the event of a dispute between members. Such voice information is not used for biometric identification purposes such as identity verification.
  4. Development of new services and use of data: Processed for purposes such as AI training for the development of new services (features), statistical analysis, production of promotional content (short-form, etc.) through de-identification (modulation) processing of voice data, the construction of training data for the development of artificial intelligence and humanoid technologies, and the provision of event information and participation opportunities.
  5. Analysis of Service use and usability improvement: Processed for purposes such as analyzing web/app screen usage patterns, diagnosing service errors, and improving user experience (UX) through session replay (screen playback) and heatmap analysis.

Article 2 (Items of Personal Information Collected)

The Company collects the minimum personal information necessary to provide the Service.

  1. Upon membership registration and use of the Service (mandatory)
    • ID (email), password, nickname, gender, date of birth
    • Mobile phone number, device information (Device ID, model name, OS), access logs, cookies, access IP information
    • Adult-verification information (CI/DI), telecommunications carrier information
  2. Upon paid payment
    • Card issuer name, card number (partial), approval number, mobile payment approval information, and other information provided by the payment gateway
  3. Upon Partner settlement (unique identifying information)
    • Items collected: real name, resident registration number (or alien registration number), bank name, account number, account holder name
    • Basis for collection: Collected in order to perform withholding obligations under applicable tax laws, including Article 145 of the Income Tax Act, and destroyed immediately after the relevant purpose is achieved or encrypted and stored separately for the retention period prescribed by law.
  4. Information collected in the course of using the Service
    • Voice conversation contents (recording files), chat records, contents of received reports, suspension and sanction records, and Point accrual and use history
  5. Information automatically collected through analytics tools
    • Screen touch, scroll, and click interaction data; session replay recordings (screen playback records, with sensitive elements such as input fields automatically masked); session identifiers; and acquisition campaign information

Article 3 (Processing and Retention Period of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by law or the period consented to by the data subject at the time of collection. The retention periods of major personal information are as follows.

  1. Member information: Until withdrawal of membership (provided that where a creditor-debtor relationship, such as settlement, remains, until the settlement is completed)
  2. Records of misuse (prevention of re-registration): Identifying information (CI/DI, device information) of members permanently suspended for sexual harassment, abusive language, and the like shall be stored separately for 5 years after withdrawal
  3. Retention required by law:
    • Records on payment and supply of goods: 5 years (the Act on Consumer Protection in Electronic Commerce)
    • Records on consumer complaints or dispute handling: 3 years (the Act on Consumer Protection in Electronic Commerce)
    • Records on the collection/processing and use of credit information: 3 years (the Credit Information Use and Protection Act)
    • Records of website visits (log-ins): 3 months (the Protection of Communications Secrets Act)
    • Records related to tax filing, such as withholding (including resident registration numbers): 5 years (the Framework Act on National Taxes)

Article 4 (Provision of Personal Information to Third Parties)

As a matter of principle, the Company does not provide users' personal information to external parties. However, the following cases shall constitute exceptions.

  1. Where users have given prior consent
  2. Partner settlement: Where withholding details must be reported to the National Tax Service in accordance with applicable laws, including the Income Tax Act
  3. Where there is a request from an investigative agency in accordance with the procedures and methods prescribed by law, pursuant to the provisions of law or for investigative purposes

Article 5 (Outsourcing of Personal Information Processing)

The Company outsources the processing of personal information as follows in order to provide the Service smoothly.

Article 6 (Processing of Pseudonymized Information and Special Provisions)

For purposes such as compiling statistics, scientific research (including industrial research), and preserving records in the public interest, the Company may pseudonymize the collected personal information so that a specific individual cannot be identified, and may use it or provide it to third parties. This may be carried out without the data subject's separate consent on the basis of the "Three Data Acts" (the amended Personal Information Protection Act).

  1. Purposes of processing: Analysis of service-usage patterns, technology development to advance AI and humanoid algorithms, and production of de-identified marketing content
  2. Items subject to pseudonymization: Voice conversation contents, gender, age range, and service-usage records (excluding identifying information such as name and phone number)
  3. Safety measures: Implementation of technical and managerial protective measures, such as storing pseudonymized information separately from additional information (identifying keys) and obtaining a pledge not to re-identify when providing information to third parties

Article 7 (Rights of Users and Legal Representatives)

  1. A user may, at any time, view or modify their personal information, and may request to withdraw consent to its collection and use (withdrawal of membership).
  2. However, information that must be retained by law pursuant to Article 3 (settlement records, records of misuse, etc.) may be retained for a certain period even after withdrawal.

Article 8 (Destruction of Personal Information)

  1. The Company shall destroy the relevant personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose.
  2. Method of destruction: Electronic files are deleted using technical methods that render them unrecoverable and unreproducible, and paper documents are shredded or incinerated.

Article 9 (Measures to Ensure the Safety of Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, managerial, and physical measures necessary to ensure safety.

  1. Managerial measures: Establishment and implementation of an internal management plan, and regular employee training
  2. Technical measures: Access-rights management for the personal information processing system, encryption of unique identifying information, and installation of security programs
  3. Physical measures: Access control of the server room and similar areas

Article 10 (Personal Information Protection Officer)

The Company designates a Personal Information Protection Officer as set forth below, who takes overall responsibility for matters concerning the processing of personal information and handles users' complaints and remedies for damage.

Users may direct any inquiries, complaints, requests for remedy of damage, and other matters relating to the protection of personal information arising while using the Company's Service to the Personal Information Protection Officer and the responsible department.

Article 11 (Collection and Use of Mobile Phone Numbers for Surveys and Usability Studies)

The Company collects and uses mobile phone numbers as follows for surveys and usability studies to improve service quality, and this item is optional.

1. Items of personal information collected

2. Purposes of collection and use of personal information

3. Retention and use period of personal information

4. Outsourcing of personal information processing

The Company outsources the processing of personal information as follows for the dispatch of verification codes and notification messages.

OutsourceeOutsourced workRetention and use period
NAVER Cloud Corp.Mobile phone number verification and dispatch of notification messages (SMS / AlimTalk)Until termination of the outsourcing agreement or withdrawal of membership

5. Rights of the data subject and refusal of consent

Article 12 (Use of Cookies and Session-Replay Analytics Tools)

The Company operates cookie-based analytics tools and session-replay (screen playback) tools as follows in order to analyze Service usage and improve usability.

  1. Web Service: On the web, the Company uses Microsoft Clarity as a session-replay and heatmap analytics tool, which is loaded only where the user has consented to the "analytics" category in the cookie consent settings. For analytics purposes, a session identifier (track_sid), acquisition campaign information, and a user-role tag (e.g., guest/host) are collected together.
  2. Mobile App (version 1.2.11 and later): In the app, the Company collects app-screen usage sessions in replay form via the Microsoft Clarity Mobile SDK. Screen elements that may contain sensitive information, such as input fields, are automatically obscured under the SDK's default settings (strict masking).
  3. Purposes of collection and use: Diagnosing service errors and improving usability and service quality through analysis of screen usage patterns
  4. Outsourcing and cross-border transfer: Related information processing is outsourced to Microsoft Corporation, the operator of the above analytics tool, and may be transferred abroad in the course of such processing. See Article 5 for further details on outsourcing.
  5. Withdrawal of consent: On the web, users may withdraw their consent to analytics at any time through the cookie settings; once withdrawn, Microsoft Clarity will no longer load from that session onward.

Addendum

This Policy shall take effect on July 18, 2026.

Amendment history: July 18, 2026 — Added disclosure regarding the Microsoft Clarity session-replay analytics tool (web/app) (previous version effective June 18, 2026)