HeyHi

HeyHi Privacy Policy

Effective Date: September 22, 2026

1. General Provisions

Carpe Inc. (the “Company”) complies with applicable laws, including the Personal Information Protection Act, in connection with HeyHi (the “Service”), and establishes and discloses this Privacy Policy in order to process users' personal information lawfully and securely.

2. Purposes of Processing Personal Information

The Company processes personal information for the following purposes.

3. Items Processed

3.1 Membership Registration and Login

CategoryItems Processed
Kakao loginAccount identifier, email (where the user has consented to its provision)
Google loginAccount identifier, email
Apple loginAccount identifier, email (including relay email provided by Apple), authentication token for unlinking upon membership withdrawal
Age verificationWhether the user is aged 14 or older (user confirmation)
Profile (optional)Nickname, handle, profile photo, bio

3.2 Use of the Service

3.3 Automatically Collected Information

3.4 Payments

Payment method information such as card numbers is processed directly by the app marketplaces (Google Play, App Store), and the Company does not collect such information.

3.5 Customer Support

Email, nickname, account identification information, content of inquiries and reports, attachments, and handling records

3.6 Marketing

Where separate consent has been given, information necessary for actual transmission, such as push token, nickname, and consent status

4. Retention Periods

InformationRetention Period
Member informationUntil membership withdrawal
AI chat and Story dataUntil deleted by the user or until membership withdrawal
AI request processing recordsChat content is deleted after 7 days (immediately upon membership withdrawal), and only usage statistics such as the number of requests and processing volume are retained
Notification settings and push tokensUntil membership withdrawal or achievement of the purpose
Customer inquiries3 years after handling is completed
Consent to receive advertising informationUntil consent is withdrawn or membership is withdrawn

Even after membership withdrawal, information remaining in backups kept for failure recovery is sequentially deleted within a maximum of 7 days.

In accordance with applicable laws, the following information is retained separately for the periods indicated.

Governing LawItemPeriod
Act on the Consumer Protection in Electronic CommerceRecords on contracts or withdrawal of subscriptions, etc.5 years
Act on the Consumer Protection in Electronic CommerceRecords on payment and supply of goods, etc.5 years
Act on the Consumer Protection in Electronic CommerceRecords on consumer complaints or dispute resolution3 years
Act on the Consumer Protection in Electronic CommerceRecords on labeling and advertising6 months
Protection of Communications Secrets ActLogin records3 months

5. Children Under the Age of 14

HeyHi does not permit children under the age of 14 to register as members. Where it is confirmed that a child under the age of 14 is using the Service, the account and personal information will be processed in accordance with applicable laws.

6. Conversations Containing Sensitive Information

The Company does not, as a rule, request the entry of sensitive information; however, users may voluntarily enter sensitive information in the course of free-form AI chat. Users are advised not to enter unnecessary sensitive information or other people's personal information.

7. Provision to Third Parties

The Company does not, as a rule, provide personal information to third parties. However, exceptions apply in cases such as the user's consent, requirements under laws, lawful investigative requests, or emergencies permitted by laws.

8. Outsourcing of Personal Information Processing

The Company outsources personal information processing tasks as follows for the smooth provision of the Service.

OutsourceeOutsourced Task
Amazon Web Services, Inc.Server infrastructure operation and data storage (Asia Pacific (Seoul) Region)
Vercel Inc.AI model connection (AI Gateway)
AI model providers such as OpenAI, L.L.C. and DeepSeekAI response generation
Kakao Corp., Google LLC, Apple Inc.Social login authentication
Google LLC (Google Play), Apple Inc. (App Store)In-app payments and purchase verification
Google LLC (Firebase Cloud Messaging), Apple Inc. (Apple Push Notification service)Sending push notifications
Google LLC (AdMob)Providing ads and verifying ad rewards

9. Cross-Border Transfer of Personal Information

The Company transfers personal information overseas (through outsourcing of processing and storage) as follows for the provision of the Service.

RecipientCountryItemsPurposeTime and Method of TransferRetention Period
Vercel Inc.United StatesChat input, conversation context, Character and Persona settingsRelaying AI response generation requestsTransmitted over an encrypted network during AI chatUntil request processing is completed (subject to the relevant provider's retention policy)
AI model providers (OpenAI, L.L.C., etc.)United States and other countries where model providers are locatedChat input, conversation context, Character and Persona settingsAI response generationEncrypted transmission via AI Gateway during AI chatUntil request processing is completed (subject to the relevant provider's retention policy)
Google LLCUnited StatesPush token, advertising identifier, device information, purchase receipt informationSending push notifications, providing ads, payment verificationEncrypted transmission during use of the ServiceUntil termination of the outsourcing contract or achievement of the purpose
Apple Inc.United StatesPush token, purchase receipt information, login linkage informationSending push notifications, payment verification, unlinking loginEncrypted transmission during use of the ServiceUntil termination of the outsourcing contract or achievement of the purpose

Users may refuse the cross-border transfer of personal information. However, since AI chat, payments, notifications, and the like cannot be provided without cross-border transfer, users who refuse the transfer will be unable to use those services, and may stop the transfer by withdrawing membership.

10. Chat Data for AI Improvement and Training

The Company processes the content of users' AI chats to the extent necessary for providing chat, maintaining context, ensuring Service safety, and responding to errors, and does not use it for the purpose of training general-purpose AI models.

11. Destruction

Personal information is destroyed without delay when the retention period expires or the purpose is achieved. Electronic files are deleted using technical methods that make recovery difficult, and information required to be retained by laws is stored separately.

12. User Rights

Users may exercise rights such as access, correction, deletion, suspension of processing, withdrawal of consent, and membership withdrawal in accordance with applicable laws.

13. Security Measures

The Company implements reasonable protective measures such as access rights management, encryption of data in transit and at rest, protection of access records, operation of security systems, establishment of an internal management plan, and employee training.

14. Automatic Collection Devices

The Company may use similar technologies, such as on-device storage, to keep users logged in and for convenience of use. Users may reset their advertising identifier or limit ad tracking in their device settings, and in regions where ad privacy settings are provided, users may change their consent in the settings within the Service.

15. Push Notifications and Marketing

The Company distinguishes between functional notifications and advertising marketing notifications, and sends advertising information only with the user's separate consent. Consent to marketing and nighttime marketing can be withdrawn at any time.

16. Pseudonymized Information

The Company does not currently process pseudonymized information. If the Company begins processing pseudonymized information, it will disclose the purpose, items, retention period, and safety measures in this Policy.

17. Chief Privacy Officer

The Company has designated a Chief Privacy Officer as follows to oversee tasks related to personal information processing and to handle related complaints and remedies for damages.

18. Remedies for Infringement of Rights

Users may apply to the following organizations for dispute resolution, consultation, or the like in order to obtain remedies for infringement of personal information.

19. Changes and Effective Date

If the contents of this Policy change, the Company will provide notice through announcements within the Service starting 7 days before the effective date (30 days before for changes that materially affect user rights). This Policy takes effect on September 22, 2026.