Privacy Policy

    AYou Privacy Policy

    Last updated: 2026-08-29

    Back to home

    TORYMAKER ("we," "us," or "our") processes personal data to provide the AYou mobile app, website, and related services. The official document is published on ayoulog.com.

    1. Scope

    This Policy applies to:

    • The AYou mobile app and ayoulog.com website
    • AI lifestyle content such as AYou/Fren conversations, tarot, past-life generation, link AI digests, AI Beauty product search when made available, and sharing
    • With AYou message numbers, friend-link sending, new messages, and the message inbox
    • 9×9 online ranked Baduk matches between signed-in members, with random matching based on an AYou internal rating
    • The 2G2G standalone pocket-messaging app and its device inbox
    • Device-first records such as photos, emotions, memos, tasks, D-day items, links, rest, and daily well-being records
    • Related account, API, billing, analytics, push-notification, health-app integration, and support features

    Features marked as under development or hidden from the production release are not part of the current release scope.

    1.1 Scope of the 2G2G Standalone App

    • 2G2G is a separate store app that uses the same Supabase account and AYou message number. An account-deletion request made from either app may therefore apply to the shared account and data linked to that account.
    • 2G2G processes the account identifier required for OAuth sign-in and an email address when the sign-in provider supplies one. For messaging, it processes the in-service public number, message body, and sending, receipt, reporting, and blocking status. The public number is an in-service public alias, not a carrier telephone number.
    • Received messages are stored in a separate device inbox inside AYou with a maximum of 99 messages. AYou does not provide its own message backup or cross-device sync; whether the operating system (OS) includes them in a backup or device transfer depends on the user's device settings. The With-message retention, reporting, and blocking periods in Section 9 apply to the service data.
    • 2G2G does not access contacts, the device's real phone number, SMS or call history, camera, photo library, health data, or advertising identifier. It has no Star Wallet, in-app purchase, advertising, AI-generation, or health-integration surface.
    • Apple App Privacy and Google Play Data safety for 2G2G are completed per app using only the sign-in, public-number, and messaging functions above. We update this policy and those store declarations together when a feature or SDK changes.

    2. Personal Data We Process

    2.1 Information you provide

    • Account identifiers: email, OAuth login identifiers, and limited profile information provided by social login providers
    • Profile data: nickname, name, birth date, gender, optional birth time, birth place, and similar profile inputs. In the mobile app, these inputs are stored locally on the device by default and may be sent to our API and an enabled AI provider only as needed for the requested AI feature.
    • Local profiles and device data entered before sign-in remain on the device by default and may not automatically merge when you sign in to an existing account or connect a new account.
    • AI inputs: questions, text, selected or cropped photos that may include facial features, card selections, character context, conversation context, and generation context used for AYou/Fren conversations, personalized friend creation, custom Fren roleplay, tarot, past-life generation, and follow-up replies. For an emotion essay, this can include up to 80 selected emotion records with a short note, emoji, valence, recorded time, and category. Section 3 explains the separate handling of photo and face data and the specific text-AI notice, recipient, data, storage, and retention practices.
    • Link AI digest inputs: a web link address that you explicitly ask AI to digest, together with the public title, description, and readable body retrieved from that public webpage. This information is sent to the AYou API and to the actual Google Gemini API or OpenAI API recipient named before the request, to process that request. AYou does not currently collect YouTube video, audio, or caption content as a Link AI digest input or send that content to an AI provider.
    • AI Beauty product-search inputs: when you explicitly request a product search, the product name, optional brand, size/version and purchase or sales country, device language, and the first public product URL you entered in the product materials or added from a search-result draft. This information is sent to the AYou API and OpenAI API for GPT-5.6 Luna public-web search. The request does not include skin-condition notes, subjective usage experience, or the product note stored locally on your device.
    • Voice input: AYou does not store raw microphone audio on its servers. The operating system's speech-recognition service converts speech to text, and the transcript is handled under the same rules as text you type.
    • Local record data: photos, emotions, memos, links, tasks, D-day items, folders, tags, favorites, hydration, movement, and other records you enter
    • Health-app integration data: when you grant permission, selected steps, hydration, workout, and activity information from HealthKit or Health Connect, plus supported State of Mind information on iOS. Availability depends on the device and OS.
    • Support information: inquiry contents, email address, and information you provide for troubleshooting
    • With message information: the AYou message number you create and message bodies sent through a shared link or directly from the app. Bodies of received messages are stored on the recipient's device; only messages a device has not yet collected and messages a user has reported remain on our servers. For a message a device has collected, only the sender identifier — never the body — is kept for 30 days so that blocking and reporting remain possible, and is then deleted. An AYou message number is a public in-service alias, not a carrier telephone number, and a body is limited to one SMS segment without image, video, or audio attachments.

    2.2 Information generated or processed during use

    • Usage data: login history, feature usage, generation requests, saved/shared result activity, and usage-limit information
    • Online ranked Baduk operations: queue, match, ready-state, and timestamp information linked to the signed-in account identifier; black/white seat; 9×9 events (play, pass, and resignation); dead-stone proposal/confirmation for scoring; finish reason/result; server-calculated remaining game time; and the AYou internal rating, rating deviation, and completed-match count. The internal rating is only for matching and service experience; it is not an official kyu/dan or external rating. We do not disclose a real name, email address, account identifier, or free-form nickname to an opponent; the opponent is displayed only with a generic label.
    • Online ranked Baduk availability: before sign-in, we may display aggregate counts of participants, members matching, and members playing. This public availability signal never includes an individual account, queue, match, or rating.
    • Device and app data: OS, app version, language, country/time zone, network status, browser information, errors, and diagnostics
    • Billing and entitlement data: purchased products, star grants/consumption, subscription state, restore state, RevenueCat identifiers, a non-reversible identifier derived from the signed installation before optional sign-in, and app store transaction metadata. Before optional account connection, the RevenueCat customer identifier is anonymous and is not an email address, name, or OAuth profile.
    • Push notification data: FCM/APNs tokens, notification preference state, notification delivery/open events, and append-only With nighttime-consent events. A grant event records server time, consent-contract version, displayed locale, and the SHA-256 hash of the exact rendered consent body. A withdrawal event is server-timestamped and copies or references the version, locale, and body hash of the grant being withdrawn; it does not represent a hash of separate withdrawal wording.
    • Security data: logs needed to detect abuse, abnormal access, and authorization status, plus the SHA-256 hash and expiry time of a short-lived seat ticket used to verify access to an online ranked Baduk seat. The raw ticket is not stored in a URL, local storage, or the database; it remains only in the game screen's memory.
    • Link AI operational metadata: request identifiers, feature, AI provider and model, token usage, cost, processing status, and elapsed time, excluding the link address, public source content, and AI digest result. This metadata may be processed separately as needed for star billing, security, and error handling.
    • AI Beauty search operational metadata: feature, AI provider and model, token usage, estimated search-tool cost, processing status, and elapsed time, excluding the product name, optional URL, and search-result content. This metadata may be processed separately for usage limits, security, cost monitoring, and error handling.
    • Reporting and feedback data: reports, ratings, feedback, and handling status related to AI outputs or service content. A With message report may include the selected reason, a snapshot of the body at the time of the report, and minimum delivery metadata.
    • With message metadata: whether the sender was a signed-in AYou member or a public web-link visitor, acceptance and delivery times, handset-inbox waiting and expiry times, read/deleted/reported/blocked status, the accepted Terms version, the applied content-policy version, and a request identifier used to prevent duplicate delivery. We do not store a public web sender's name, email, real telephone number, raw IP address, or User-Agent in a message record.
    • With abuse-prevention information: to enforce short-window sending and receiving limits, we may process non-reversible HMAC bucket keys with counts and expiry times, and an inbox-scoped HMAC identifier used to block the same sender within one inbox. For public web sending, we may use a server-issued, signed, random HttpOnly cookie for up to one year, but the raw cookie is not stored in message or block records.
    • Advertising data: when you choose a rewarded ad in the Star Wallet, Google Mobile Ads and User Messaging Platform may process advertising identifiers, IP-based approximate location, device and app information, ad request/impression/interaction and reward-confirmation data, and consent status. The exact processing depends on your region and choices.

    2.3 Generated output data

    • AYou outputs: conversation replies, tarot interpretations, past-life text and generated images, follow-up conversations, and sharing metadata. Tarot and the current mobile personal past-life results and their follow-up chats are retained only as local device data; Section 3 describes the different storage treatment for With and for the legacy account-linked personal-image and relationship-past-life routes retained for compatibility.
    • Online ranked Baduk game records: 9×9 events, scoring proposals/confirmations, status and time, finish reason/result, and internal-rating settlement information. Section 9 explains the account linkage, deletion, and retention basis for de-identified game records.
    • Link AI digest outputs: a headline, summary, key points, sections, action items, tags, and similar structured results. These results are stored with the corresponding link in the local database on your device.
    • AI Beauty product-search outputs: a candidate product match, source-linked general ingredient roles and product-description candidates, conflicts and unknowns, and public source links. The full result is not saved automatically. Only sources and AI notes you select are retained in the local database on your device after you explicitly save them from the product editor.
    • Local processing outputs: record classification, link metadata, and in-app statistics

    3. Face Data and Photo Handling

    3.1 What we mean by face data

    • In this Policy, face data means the pixels in a photo you select or crop that may show a face, and a portrait or other visual output generated from that photo. It does not mean Face ID, TrueDepth, ARKit face maps, face geometry, facial landmarks, biometric templates or embeddings, or a face-recognition identifier.
    • AYou does not create or keep a biometric template, perform face recognition, verify identity, build a face-recognition database, or use photo or face data for advertising targeting, sale, eligibility decisions, or training an AYou model.

    3.2 Current mobile photo features, recipients, and AYou storage

    FeatureWhat is sent and to whomAYou storage and deletion
    Selfie Studio (profile and freeform image modes)The selected or cropped photo, which may include a face, and the generation choices you provide are sent through the AYou API to the OpenAI API to create the requested image.AYou does not write the original photo or generated result to an AYou database or Supabase Storage. The result is saved in the app's local documents storage until you delete it or remove the app.
    Current mobile personal past-life generationIf you choose a photo, it, the selected world, and one class card are used for the requested result. The photo is sent through the AYou API to the OpenAI API for the portrait; the text portion may use the AI provider enabled for that request.AYou does not write the original photo, personal result body, or generated portrait to an AYou database or Supabase Storage. Text results are stored in local SQLite and the portrait in local app documents until you delete the record or remove the app.
    Sticker StudioThe image you select, which may include a face, and the requested sticker choices are sent through the AYou API to the OpenAI API to create the requested sticker.AYou does not write the original image or generated sticker to an AYou database or Supabase Storage. The result remains in local app storage until you delete it or remove the app.
    With together roomsA selected photo that may include a face and the room's generation choices are sent through the AYou API to the OpenAI API to create a derived portrait. When a host requests the initial completed group/family image or a quality regeneration, the participant portraits already stored in the With room are sent to OpenAI again for that requested group image.Derived portraits and completed images are stored in the private Supabase generated-images bucket for the room. They remain there until the host deletes the room. The host, room participants, and a person using a valid invitation or share link may receive a time-limited signed URL for the relevant stored output.
    • The submitted current mobile binary does not call the compatibility endpoints described in this paragraph. The legacy account-linked personal-image route (/api/past-life/[id]/image) can send an optional photo to OpenAI, does not persist that input photo, and stores the generated portrait in private Supabase generated-images storage with its account-linked past_lives result and generation-job metadata. Its image prompt is cleared after successful completion. The separate legacy account-linked relationship route (/api/past-life-relationship) can send a shared photo and generation inputs to Google Gemini API and stores its generated narrative, images, and storage paths in past_life_relationships and private generated-images storage. These legacy records and files remain until account deletion or a verified privacy-deletion request, subject to legal retention requirements; the current app does not provide a separate feature-level delete control for them. They are not covered by the current personal past-life no-server-storage statement above.

    3.3 Separate permission before each user-requested photo transfer

    • Before each user-initiated current mobile generation request that sends a selected or cropped photo, or participant portraits stored in a With room, the app shows a separate just-in-time notice. It identifies that the image may contain face data, the OpenAI recipient, the requested generation purpose, and the applicable result storage. For a With final image or quality regeneration, the host also confirms authority to send the portraits of the people shown.
    • Tapping the affirmative control permits the requested generation and any limited delivery retry needed to complete that same request. Closing or cancelling the notice before the request starts means AYou does not begin that transfer to OpenAI. A new user-initiated generation or regeneration requires a new notice. Declining a transfer does not require account deletion and does not prevent use of features that do not need that image.
    • You may withdraw permission for a future transfer by declining the next notice. Withdrawal cannot recall information already sent to a processor for a completed request. You can delete a one-person local result in its originating feature; for a With result, the host can delete the room. You may also contact us using Section 17 for a privacy request.

    3.4 Retention by OpenAI and other processors

    • AYou handles the one-person original photos in the table only while fulfilling the request and does not intentionally persist them in an AYou database or Supabase Storage.
    • AYou has not verified that an OpenAI Zero Data Retention organization setting applies to this processing. Unless and until that setting is verified and applicable, OpenAI's standard API data controls may retain API inputs, outputs, and related abuse-monitoring logs for up to 30 days. A longer or different retention may apply where required for legal, safety, security, or abuse-prevention reasons under the provider's applicable terms and policies.
    • The legacy relationship route is not called by the submitted current binary. For a request made by a compatible legacy client, Google Gemini API processing and retention depend on the Google service tier, account configuration, and terms that actually apply to that request. Google does not publish one universal maximum retention period for every such configuration, so AYou does not represent a fixed Google retention period or an unverified Zero Data Retention setting. This is separate from the account-linked AYou storage described in Section 3.2.
    • The provider retention described in this subsection is separate from local result storage and the private With output storage described above. We do not control a processor's legally required retention, but we disclose it so you can decide whether to send a photo.

    3.5 Text AI: notice, recipients, data, storage, and retention

    • Before the current app sends text or local result context that may be personal data to a third-party AI service, it shows a separate just-in-time notice. This applies to AYou/Fren chat, personalized friend creation, Fren custom-world requests, initial Tarot and Saju readings, Today Tarot and Today Saju, result follow-ups, emotion essays, and Link AI digests. The notice identifies the actual recipient, the data category, the purpose, local storage, and deletion scope. Cancelling means AYou does not start that request or its text transfer.
    • This confirmation is scoped to the named third-party provider and the notice version for the active app-screen session. The first transfer in a new screen session, a changed actual recipient, or a changed notice version needs a new confirmation. It is not a consent boundary for every model option: changing between public models from the same already-disclosed provider does not create a redundant prompt. The current client includes the provider and notice-version token with the request; if a current client supplies an incomplete, stale, or recipient-mismatched token, the server rejects it before an external AI call or server wallet hold.
    • Current AYou/Fren chat models are OpenAI models. To create a reply, AYou sends the message you choose to send, recent turns in that room, and a continuation summary when one exists, to the OpenAI API. Other local AYou records are not automatically added. To create or regenerate a personalized friend, AYou sends the request and, when you edit/regenerate it, the name and edited personality, tone, situation, and greeting to the OpenAI API. To create a Fren custom world, AYou sends the scene request, selected draft, and character identifier to the OpenAI API.
    • Initial Tarot names the selected provider and model and sends the concern you enter, selected cards and card/deck context, question metadata, and an optional selected advisor. It does not automatically add profile or birth information. Initial Saju on the web sends the selected provider and model, your question, an optional selected advisor, and only a browser-generated minimum Saju consultation profile. That profile contains one five-element balance focus or a general focus; it does not contain birth date, birth time, gender, birth country, time zone, pillars, day master, element counts, ten gods, relations, or major/annual luck cycles. The full chart is calculated and displayed only in the browser and may remain in a local consultation record. Initial Saju and Today Saju in the mobile app may send a derived chart, local date, selected focus area, and an optional advisor after naming the selected provider and model, but remove raw birth-profile fields. If you write birth information or other personal data directly in a free-form question, that content may be transmitted as part of the question. For these selected-model routes, the server verifies the provider in the current confirmation against the selected model option and uses that selected provider/model for the request.
    • Today Tarot uses a data-free recipient preflight before the notice, so the notice names the live OpenAI or Google Gemini recipient. It sends only the three selected cards, deck context, locale/tier/date request values, and the provider/version confirmation; it does not send a concern, profile, or advisor. The server resolves the live provider again, validates the confirmation, and uses that same provider for the AI call rather than switching recipients after the notice.
    • For a Link AI digest, the app sends the selected link URL, request identifier, locale, tier, date request values, and the provider/version confirmation to AYou; AYou retrieves the public title, description, and readable webpage body and sends that source material to the OpenAI or Google Gemini recipient named by a data-free preflight. The server resolves, validates, and pins that provider before a wallet hold and before the AI call. YouTube video, audio, and caption content is not used for an AI digest.
    • For an emotion essay, AYou sends no more than 80 selected text-bearing emotion records. Each sent record can include only its short note, emoji, valence, recorded time, and category; other local emotion records are not sent. A data-free preflight names the live OpenAI or Google Gemini recipient, and the server resolves, validates, and pins that provider before a wallet hold and before the AI call. The selected records remain local. The generated essay remains in the active screen's memory unless you separately choose a device share/save action; AYou does not keep the request text or essay as server history.
    • For a result follow-up, AYou sends the new question, the current result summary or derived result context, recent follow-up turns, and a continuation summary when one exists. A web Saju follow-up uses only the minimum Saju consultation profile described above and does not resend the full chart. Where a public consultation model is pinned to the result, the notice names that model's provider and model. For the released runtime route, the notice names OpenAI and the server rejects the request before any external transfer if the live recipient is not OpenAI. A web result follow-up can be started only by a signed-in user and uses the same OpenAI notice and pre-transfer validation.
    • AYou keeps AYou/Fren chat messages, their continuation summaries, personalized friend profiles, custom-world drafts, Tarot/Saju results and follow-ups, and Link digest results on the device according to the relevant feature. It does not retain their full text as AYou server chat history. Limited request, provider/model, token, cost, timing, billing, security, and quality metadata that excludes the full text may be processed for delivery, billing, abuse prevention, reliability, and error handling.
    • AYou sends OpenAI text requests through the Responses API with application-state storage disabled (store: false). We have not verified that OpenAI Zero Data Retention or Modified Abuse Monitoring applies. Under OpenAI's standard API data controls, abuse-monitoring logs may contain API content and may be retained for up to 30 days, subject to legal, safety, security, or abuse-prevention exceptions. Google Gemini processing and retention for a route that names Google Gemini depend on the Google service tier, account configuration, and terms that actually apply; AYou does not represent an unverified fixed Google retention period.

    4. Purposes of Processing

    We process personal data to:

    • Authenticate accounts, maintain sessions, and identify users
    • Provide account-specific features such as hosting/managing together rooms, publishing shared posts, account-based records, and backups
    • Provide AYou AI results, history, follow-up replies, and share links
    • Match signed-in members for online ranked Baduk, manage 9×9 game state, rules, and time, and process results and AYou internal ratings
    • Display online ranked Baduk availability only as aggregate counts that do not identify a person
    • Process a selected or cropped photo that may include face data only after the separate permission described in Section 3, to create the image feature you requested
    • Provide local record storage, link collection and AI digests, source-linked product searches you request, and task and D-day management
    • Provide the health-app read/write integration and integration-status display that you choose to enable
    • Process stars, subscriptions, payments, refunds, and restore purchases
    • Receive AI output reports/feedback, improve safety, and respond to policy violations
    • Maintain reliability, diagnose errors, secure the Service, prevent abuse, and enforce policies
    • Provide customer support, notices, legal compliance, and dispute handling
    • Deliver With messages and display the inbox; process read, delete, report, and sender-block actions; pause or rotate links; filter high-confidence harmful content before delivery; prevent duplicate or spam delivery; and review reports
    • Improve user experience, analyze feature quality, and produce service statistics
    • Provide optional rewarded ads, manage advertising privacy choices, prevent abuse, and confirm reward delivery

    5. Legal Bases

    Processing may rely on one or more of the following bases:

    • Performance of a service contract
    • User consent
    • Our legitimate interests, including security, quality improvement, abuse prevention, and service reliability
    • Compliance with legal obligations
    • Protection of vital interests where necessary

    For users in the EEA, the With bases are assigned by purpose rather than combined into one blanket basis:

    • Performance of the service contract: accepting and delivering a With message, managing the delivery queue, displaying the recipient's inbox, and carrying out inbox read and delete actions
    • Consent: optional remote With message-arrival alerts and, separately, optional nighttime alerts. Operating-system notification permission is an additional device control and is not a substitute for either consent.
    • Our legitimate interests: protecting accounts and the Service through security logging, access control, duplicate and abuse prevention, rate limits, high-confidence harmful-content filtering, sender blocking, and report review, balanced against users' rights and reasonable expectations

    EEA legal bases for online ranked Baduk are also separated by purpose:

    • Performance of a service contract: matching signed-in members, running a game, and recording the result and internal rating
    • Legitimate interests: server-authoritative time and rule verification, prevention of unauthorized access, automation, and abuse, and reliability, error, and dispute response

    Another applicable basis, including compliance with a legal obligation, may apply where required by law.

    6. Processors, Vendors, and International Processing

    To provide the Service, the following third-party services may process personal data, and data may be processed outside your country.

    CategoryProviderPurposeData that may be processed
    Auth/DB/storageSupabaseaccount authentication, database storage, session handling, star/purchase entitlements, account-based feature storage, online ranked Baduk, and private With output storageaccount identifiers, entitlement data, star ledger entries, online ranked Baduk queue, match, seat, ready-state, and timestamp information; internal rating, rating deviation, and completed-match count; game events, scoring, result, and time; a short-lived seat ticket hash and expiry; With message numbers, bodies of messages not yet delivered, delivery/block status, limited-period report evidence, private With derived portraits and completed images, and service data you ask to save to an account; tarot and current mobile personal past-life result bodies, generated portraits, and their follow-up chats are excluded
    Hosting/APIVercelweb hosting, API execution, logsrequest/response data, diagnostics
    AI text — current AYou/Fren conversation, personalized friend creation, and Fren custom worldOpenAI APIreplying in AYou/Fren chat; creating a requested friend profile or custom Fren worldthe scoped message/recent turns/continuation summary; or the friend/world request and only the edited fields described in Section 3.5
    AI text — initial Tarot, web initial Saju, and mobile-app initial/Today Sajuthe selected public model's OpenAI API or Google Gemini API recipientinterpreting the requested consultationTarot concern, selected cards/deck context, question metadata, and optional advisor. Web initial Saju sends only the question, optional advisor, and one minimum five-element balance focus or a general focus; it does not send original birth information or the full chart. Mobile-app initial/Today Saju may send the question or local date/focus area, a locally calculated derived Saju chart, and an optional advisor, but raw Saju birth-profile fields are removed before the AI request as described in Section 3.5. The exact selected provider/model is shown before sending.
    AI text — Today Tarot, Link AI digest, and emotion essayOpenAI API or Google Gemini API resolved in a data-free recipient preflightinterpreting three selected tarot cards; digesting a public webpage; or writing an emotion essayToday Tarot: three selected cards and deck context, with no concern/profile/advisor. Link digest: selected URL plus the public title, description, and readable body fetched by AYou. Emotion essay: no more than 80 selected records' short note, emoji, valence, recorded time, and category. The exact recipient is shown before sending and is revalidated/pinned for the request as described in Section 3.5.
    AI text — result follow-upOpenAI API, Google Gemini API, or the provider named for a pinned public consultation modelanswering a new question about the current resultnew question, current result context, recent follow-up turns, continuation summary when present, and any selected cards/advisor needed for that result. A web Saju follow-up uses only the minimum balance consultation profile rather than the full chart; the exact recipient is stated before sending as described in Section 3.5.
    Other AI text generationGoogle Gemini API, OpenAI API, Anthropic Claude APIa separately scoped AI feature that identifies its actual provider before processingonly the inputs described in that feature's notice and needed for the request
    AI image generation and face-data photo processingOpenAI APIcurrent mobile Selfie Studio, personal past-life portrait, Sticker Studio, and With portrait or group/family-image generationselected or cropped photo pixels that may include a face, stored With participant portraits, generation choices, and the minimum visual context needed for the requested image; the retention in Section 3.4 may apply
    Legacy account-linked personal past-life imageOpenAI API and Supabasethe compatibility /api/past-life/[id]/image route, which is not called by the submitted current binaryoptional selected photo, account-linked narrative/draft and generation metadata, and the generated portrait/storage path, as described in Section 3.2
    Legacy account-linked relationship past-lifeGoogle Gemini API and Supabasethe compatibility /api/past-life-relationship route, which is not called by the submitted current binaryselected shared photo, narrative inputs, generated narrative, generated images, and related account record/storage paths, as described in Section 3.2
    AI Beauty product searchOpenAI APIchecking a product you request through GPT-5.6 Luna public-web search and returning source-linked editable candidatesproduct name; optional brand, size/version and purchase or sales country; device language; and the first public product URL you entered in the product materials or added from a search-result draft. Local skin-condition notes, subjective usage experience, and product notes are excluded
    YouTube link metadataYouTube/Googleretrieving the public title, channel, and thumbnail when you save a linkthe YouTube link or video identifier you save and standard network/request information; video, audio, and caption content are excluded
    Analytics/PushGoogle Firebase (Analytics, Cloud Messaging)usage analytics, push notifications, diagnosticsdevice/app-instance identifiers, event logs, push tokens
    Ads/consentGoogle Mobile Ads, User Messaging Platformoptional rewarded ads, regional consent and advertising privacy choices, completed-ad and reward-delivery confirmationadvertising identifiers, IP-based approximate location, device/app information, ad request/impression/interaction and reward-confirmation data, consent status
    Billing/entitlementsRevenueCatsubscription and purchase entitlement checks, restore purchases, and—when the separately configured Firebase measurement integration is enabled—sending purchase lifecycle events to Google Firebase Analyticsan anonymous app user identifier before optional account connection, an account app user identifier after connection, Firebase app-instance identifier used only for that measurement link, purchase status, transaction metadata, and purchase-event value/currency
    Payment processingApple App Store, Google Playin-app billing, refunds, subscription cancellationspayment and transaction data
    OAuth loginGoogle, Apple, Facebook, Kakao, and similar providerssocial login authenticationOAuth identifiers, limited account profile fields
    • Information sent to the Google Gemini API, OpenAI API, or Anthropic Claude API is used to process the requested AI generation. We do not separately use those inputs to train an AYou model. Each provider's processing and retention follow the provider agreement, data-control settings, and retention policy applicable to us; the additional, specific disclosure for OpenAI photo processing is in Section 3.4.
    • For OpenAI API processing, AYou's use of the Services constitutes acceptance of the OpenAI Services Agreement. Section 5.3 incorporates the OpenAI Data Processing Addendum when OpenAI processes personal data. Under that DPA, OpenAI processes customer data on the customer's documented instructions, subject to legal exceptions, and commits to the confidentiality and reasonable and appropriate security measures stated in the DPA. AYou relies on those current contractual safeguards for this limited transfer, reviews the applicable processor terms and settings when the processing changes, and does not represent an independently verified guarantee beyond those terms. These contractual safeguards do not mean that Zero Data Retention or Modified Abuse Monitoring is enabled; OpenAI photo-data retention is disclosed separately in Section 3.4. Google Gemini processing is governed by the Google API and Gemini terms, service tier, and account configuration actually applicable to the request; without verified applicable DPA/settings evidence, AYou does not represent a fixed Google retention period or an independently verified equivalent-protection level. Other processors are governed by the agreements and data controls that actually apply to them.
    • A web link address, public title, description, and readable webpage body sent for a link AI digest are used by the AYou API while handling the request and are sent to the Google Gemini API or OpenAI API actually enabled for it. We do not retain the link address, public source content, or digest result long-term in an AYou AI result database or server storage, and this link AI digest request does not automatically add them to the public link pool. The AI provider's processing and retention follow the provider agreement, settings, and policy described above. Metadata that excludes the source content may be processed separately for billing, security, and error handling. For YouTube links, AYou only makes the metadata request needed to confirm the public title, channel, and thumbnail and does not create a new AI digest from video, audio, or caption content.
    • Product-identification information and an optional public URL sent for AI Beauty search are used by the AYou API while handling the request and are sent to OpenAI API for public-web search. We do not retain those product inputs or the search-result content long-term in an AYou AI result database or server storage, and we do not publish them automatically. An editable selection is stored on your device only if you choose it and then explicitly save the product. Feature, provider, model, token, estimated-cost, processing-status, and elapsed-time metadata that excludes the source content may be processed separately for usage limits, security, cost monitoring, and error handling. OpenAI's processing and retention follow the provider agreement, settings, and policy described above.

    We do not sell personal data for unrelated purposes without a legal basis or your consent.

    7. App Store / Google Play Privacy Notices

    • We report the app's actual data practices in Apple App Privacy and Google Play Data safety.
    • The declarations are based on actual SDK and server behavior, including account data, profiles, user content, generated outputs, usage data, billing/entitlement data, diagnostics, and security data where applicable.
    • In a build that offers online ranked Baduk, App Privacy and Data safety reflect the actual collection, account linkage, and purposes of game records, internal ratings, and security/operational data linked to a signed-in account. Offering only aggregate public availability counts does not replace that disclosure duty.
    • If app features, SDKs, advertising/analytics/billing, or AI model calls change, we update the app store privacy declarations and this Policy together.
    • Under Google Play policy, the privacy policy remains accessible both in the app and from the store listing.
    • The current release includes optional repeatable rewarded ads using Google Mobile Ads and User Messaging Platform. Android advertising ID or iOS IDFA and related advertising data may be processed for ad delivery, frequency management, reward verification, and measurement depending on region and your choices. For signed-out users, the ad-star balance and duplicate prevention are associated with a token and hash derived from the device install ID; no anonymous Supabase account is created.
    • Buying a Star pack or AYou Pro, restoring an eligible Pro subscription, and using paid content do not require AYou account registration. Before optional sign-in, we use the RevenueCat anonymous identifier and a non-reversible hash derived from the signed installation for the guest purchase ledger, entitlement, duplicate prevention, and server-side Star usage. If you later choose to sign in for supported cross-device use, the eligible reward/paid balance and Pro connection are linked to that account once; first-install trial Stars are excluded.
    • If Firebase purchase measurement is enabled in RevenueCat, the app sends its Firebase app-instance identifier to RevenueCat so RevenueCat can send the relevant purchase lifecycle event, value, and currency to Google Firebase Analytics. This is measurement for purchase and subscription performance; it does not change entitlement, wallet, or payment processing.

    8. Local Data and Backups

    8.1 AYou Web Tool Data

    • The tarot and saju web tools on ayoulog.com use browser site data such as localStorage and, where needed, sessionStorage. This data may include a guest-session identifier, the AI-text-transfer consent marker, consultation progress, a browser-local profile containing original saju birth information when you choose to remember it, and the consultation records described below. This data is readable only in the same browser on the same site; it is not synchronized to an AYou account, the mobile app, or server records even when you sign in.
    • To prevent service abuse and uncontrolled AI-request cost, each web consultation request temporarily uses a protected server rate-limit bucket containing only the consultation action, billing tier, time window, request count, and secret-key HMAC values derived from the guest-session identifier and network address. That bucket never stores the raw IP address, guest token, question, reading result, or birth information, and is not a consultation record or profile.
    • When web analytics is enabled, to measure web-consultation entry and completion rates as aggregate statistics, we may send Google Firebase Analytics minimum events such as the consultation feature, display locale, and whether an initial consultation request started or received a successful response. These analytics events do not include the question, selected cards, original birth information, full chart, advisor, model, full result text, result identifier, guest-session identifier, or network address.
    • For tarot, your question, selected cards, selected deck, advisor name and identifier, and full result text may be saved as a completed-consultation record in that browser's localStorage. Questions and replies exchanged through the Continue asking feature below a result remain only in the current tab's memory and are not added to long-term records.
    • For saju, if you choose to remember birth information, original birth information such as birth date, selected birth time, gender, birth country, and time zone remains only in that browser's local profile. We do not transmit that original birth information or the browser-calculated full chart (such as pillars, element counts, ten gods, and major/annual luck cycles) outside the browser. A web consultation sends only the question, advisor information, and one minimum focus for reading five-element balance or a general focus to the AYou API and the AI provider actually enabled for the request. If you directly write original birth information in a free-form question, that content may be transmitted as part of the question. A saju record may retain the full derived chart and full result text, but does not include original birth information.
    • Immediately before starting AI generation or a follow-up question, the screen identifies the actual AI provider and the purpose of the transfer and asks for your consent. If you close or decline that notice, we do not start the transfer. The consent marker is tied to the provider and notice version, so a new consent is required if the actual provider or notice version changes.
    • AYou does not retain full web-tarot or web-saju result text, consultation records, or follow-up-chat text in a result database or server storage, and does not create public result URLs that read them. Information needed for generation is transmitted transiently through the AYou API to the AI provider actually enabled for the request. That provider's processing and retention are governed by Section 3.5.
    • AYou profile inputs such as name, birth date, gender, optional birth time, and birth place are stored locally on your device by default. We do not automatically sync these inputs to the Supabase profile table.
    • General AI content and local profile inputs can be used without signing in. Account connection is optional and may be used for hosting/managing together rooms, publishing shared posts, account-based records, and backups.
    • Online ranked Baduk is a server game linked to a signed-in account, separate from device-local life records. Its game records are not automatically combined with local records or AI memory.
    • When you sign in to an existing account, pre-sign-in local device data may not automatically merge with server account data.
    • AYou photos, emotions, memos, tasks, D-day items, links, rest, and daily well-being records operate on a local-first basis and are stored in a local device database (SQLite).
    • AYou/Fren chat messages and continuation summaries, personalized friend profiles, custom-world drafts, and result follow-up conversations are local device data. They are not synchronized as server chat history. Deleting the relevant chat, result, or local record removes the linked local text according to that feature's control.
    • Emotion Diary records are local device data. When you choose an emotion essay, no more than the selected 80 text-bearing records are sent for that one request; the returned essay remains in active screen memory unless you separately save or share it on your device, and is not stored as AYou server history.
    • Tarot and current mobile personal past-life results and their follow-up chats are stored only in the local SQLite database on that device. They are not stored as Supabase account results and are not synchronized across devices. Generated current mobile personal past-life images are stored in the app's documents storage on that device.
    • The photo and face-data rules for Selfie Studio, current mobile personal past-life generation, Sticker Studio, With, and the legacy account-linked personal-image and relationship-past-life routes are described in Section 3. In particular, the private server storage for With and legacy generated outputs is different from the local-only handling of current one-person results.
    • For tarot, the concern, selected cards, advisor, and conversation context are sent transiently to the AYou API and enabled AI provider. For current mobile personal past-life generation, the selected world, one class card, and an optional photo are sent transiently. We do not retain that flow's personal result bodies, generated images, or follow-up chat bodies in a result database or server storage. Billing, security, error-handling records, and quality metrics that exclude the full content may be processed separately.
    • When you explicitly request an AI digest for a web link, the web link address, public title, description, and readable webpage body are sent to the AYou API and the Google Gemini API or OpenAI API actually enabled for link digests. The digest result is saved with the corresponding link in the local database on your device. AYou currently checks only public metadata for YouTube links and does not use video, audio, or caption content for AI digests.
    • We do not retain the link address, public source content, or digest result long-term in an AYou AI result database or server storage, and we do not publish them automatically. Request, feature, provider, model, token, cost, processing-status, and elapsed-time metadata that excludes the source content may be processed separately for billing, security, and error handling.
    • AI Beauty product records, source materials, and subjective usage experiences remain separate in the local database on that device. Product search sends only product-identification information and an optional public URL; it does not automatically combine locally stored skin-condition notes, subjective usage experience, or product notes. Selecting materials from a search creates an editable draft only and does not write it to the local database until you explicitly save the product.
    • Deleting a tarot or personal past-life result from the records also deletes its linked follow-up chat and the generated past-life image from that device.
    • We do not provide multi-device realtime sync by default. The current production release does not provide a single-file export of all local app records.
    • Save and share options provided by individual features, such as saving to the photo library or using the system share sheet, run only when you choose them. These actions and any future backup feature do not automatically upload local records to an account server without your confirmation.
    • Backup data is not automatically combined with AYou chat memory, AI search, AI training, or model improvement. Data separately submitted to an AI feature may be processed to provide that feature.
    • Deleting a file saved or shared through an individual feature does not necessarily delete local AYou data on your current device.
    • Data may be lost if the device is lost, the app is deleted, the OS is reset, or local storage is damaged. Where available, use the photo-library save or system-share option offered by a feature to keep a separate copy of important results.

    9. Retention and Deletion

    9.1 Retention and Deletion of AYou Web Tool Data

    • Web tarot and saju consultation records remain in that browser's localStorage, up to 80 records for each feature. When a new record would exceed that limit, the oldest record for the same feature is removed from browser storage. You can delete an individual record through the delete control in the corresponding tarot or saju history list.
    • A server rate-limit bucket stops being used when its 10-minute or one-day window ends and is progressively removed from expired buckets during subsequent rate-limit processing. We use it only for abuse prevention and service security.
    • A tarot or saju result-specific address reads only the local record in that browser; it is not a public link. The result cannot be restored in another browser or on another device. Deleting your account does not automatically delete web-tool data in that browser.
    • Continue asking chat remains only in the current tab's memory and disappears when you close or refresh the tab. Turning off the option to remember saju birth information stops future inputs from being newly saved to the browser profile, but you must clear browser site data to remove original birth information already stored there.
    • You can remove web-tool local records, original saju birth information, guest-session identifiers, and consent markers by clearing ayoulog.com site data in your browser settings, including local and session storage. This data can also disappear without notice when a private-browsing session ends, the browser clears storage, or its storage policies require it. Because the web tools do not provide server synchronization or backup, deleted or lost data cannot be restored.
    • Deleting a record or browser site data does not undo processing of information already transmitted to an AI provider for a request. That provider's retention and deletion practices are governed by Section 3.5.
    • Personal data is deleted when the processing purpose is fulfilled or when the applicable legal retention period expires.
    • Account information and service records are retained while the account remains active and are logically deleted without undue delay after account deletion is requested.
    • When account deletion is completed, the online ranked Baduk profile, current queue, and match-player association for that account (including seat-ticket hash and expiry) are deleted with it. Events, scoring, status, time, and result of a completed game may remain as a de-identified game record after participant account identifiers and seat credentials have been removed. We may retain that record until its service-operation, security, error, or dispute-response purpose ends or a legal retention period ends; we do not promise a fixed automatic deletion date for this feature.
    • Cloud backup data that you do not delete may be retained while your account remains active to provide backup/restore. It is deleted when you delete the backup or request account deletion, although system backup copies may remain for an additional period according to operational cycles and retention policies.
    • Information needed for billing, settlement, refunds, abuse response, disputes, or legal obligations may be retained as required by law.
    • For Selfie Studio, the current mobile personal past-life flow, and Sticker Studio, AYou does not write the original photo or generated result to an AYou database or Supabase Storage. The result remains on your device until you delete it or remove the app. OpenAI may retain API data for up to 30 days under the standard API controls described in Section 3.4, subject to applicable legal, safety, security, or abuse-prevention exceptions.
    • AYou/Fren chat messages and continuation summaries, personalized friend profiles, custom-world drafts, and result follow-up chats remain on the device until you delete the related local chat, result, or record, or remove the app. AYou does not retain their full text as server chat history. The separate third-party text-AI retention disclosure is in Section 3.5.
    • Emotion Diary records remain on the device until you delete them or remove the app. A generated emotion essay is not automatically saved as an AYou local record or server history; it is removed when the active screen is discarded unless you separately create a device share/save output. The processor-retention disclosure for its selected text is in Section 3.5.
    • With derived portraits and completed group/family images remain in private Supabase generated-images storage until the host deletes the room. We do not promise an automatic deletion date for a completed room.
    • The legacy account-linked personal-image and relationship-past-life routes may retain their account-linked result records, generated images, and storage paths in Supabase until account deletion or a verified privacy-deletion request, subject to legal retention requirements. The current app does not expose a separate feature-level delete control for these compatibility records.
    • Personal past-life results in the current mobile flow remain only on the device until you delete them from the records or remove the app.
    • Deleting a tarot result from the records deletes the local result and its linked follow-up chat from that device. Account deletion is not required to delete local tarot records.
    • When you permanently delete a link from Trash, the linked AI digest is also deleted from the local database on that device. If you only move the link to Trash, the digest remains until you permanently delete the link.
    • When you delete an AI Beauty product record, the public sources, saved AI-search selection, and subjective usage experiences linked to that product are deleted from the local database on the same device. There is no separately retained AI Beauty result body on our server to delete.
    • Locally deleted data may be affected by device storage and backup state, and local deletion does not automatically mean deletion of an existing cloud backup copy.
    • With message bodies are stored on the recipient's device. Our servers keep only messages a device has not yet collected, for up to 30 days from receipt, and erase the body and the sender mailbox link as soon as the device confirms it stored them. The device inbox holds 99 messages; while it is full, new messages are not sent to the device and wait on the server instead. When the recipient frees a slot, the longest-waiting message is delivered first. A message a device has not collected within 30 days has its body, sender link, and sender identifiers erased, is not delivered, and cannot be recovered. Read and delete actions on a stored message happen only on that device and are not reflected on the server. AYou does not provide its own message backup or cross-device sync. Whether messages stored on the device remain after deleting the app or changing devices depends on the operating system (OS) backup and device-transfer settings. Our servers may retain a request-identifier tombstone that prevents a delayed retry from delivering the same message twice, together with the minimum sender-block identifiers and accepted terms version needed to build report evidence if you later report the message. Those identifiers are kept for 30 days after the device collects the message and are then erased; the message can no longer be blocked or reported afterwards. That information does not include the message body. When an account is deleted we delete the remaining server-side message data, and a public number may be retained only as an inactive number marker so that old links never resolve to someone else.
    • If you report a With message, a snapshot of that message body is uploaded from your device at the moment you report it, and we may retain the report reason, that snapshot, an inbox-scoped sender HMAC, and minimum delivery metadata separately from the ordinary inbox for up to 90 days from the report. This evidence may remain for that period even if the original message or account is deleted first, and is deleted after the period unless a legal obligation or dispute requires otherwise.
    • With abuse-prevention buckets expire after their configured sending-limit windows and are removed through operational cleanup. An inbox-scoped sender-block identifier may remain until you unblock that sender or delete the recipient account.
    • Each separate With nighttime-alert grant and withdrawal is retained as an immutable, append-only event while the account remains active. A grant retains the exact rendered consent-body evidence described above; a withdrawal is server-timestamped and retains a reference copy of that grant evidence rather than a separate withdrawal-text hash. Turning the nighttime setting off clears its current active consent version and grant time but does not overwrite its event history. Account deletion cascade-deletes these consent events with the account.
    • A device token that the server deactivates remains unavailable for delivery and becomes eligible for deletion 30 days after invalidation; the protected cleanup removes it after that point. Account deletion removes the account's device tokens earlier.

    10. Your Rights

    Subject to applicable law, you may exercise the following rights:

    • Request access, correction, or deletion of personal data
    • Request restriction or suspension of processing
    • Withdraw consent where processing is based on consent
    • Submit privacy inquiries, objections, or complaints
    • Request account deletion

    To request account deletion, use in-app account settings, follow the guidance at https://ayoulog.com/delete-account, or contact torymakerapp@gmail.com. We will process requests according to applicable law and identity verification requirements.

    Account deletion also applies to the account-linked profile, queue, and participant information for online ranked Baduk. Section 9 governs a completed game record after account identifiers have been removed.

    For face-data photo processing, you can decline the next just-in-time consent notice to stop a future user-requested transfer. To remove an already-created result, delete the local result in its originating feature, ask the With host to delete the room when applicable, or contact us using Section 17 for a request relating to legacy account-linked personal or relationship data.

    11. Advertising, Tracking, and Choices

    • Google Mobile Ads provides rewarded ads only when a signed-in or guest user chooses them from the Star Wallet. The feature currently operates in Korea, the United States, and Japan. After a short wait following each credited ad, users may claim again within the daily claim limit shown in the app.
    • Depending on region and your choices, Google may process Android advertising ID or iOS IDFA, IP-based approximate location, device and app information, ad interaction data, and consent status for ad delivery, frequency management, reward confirmation, and measurement. Health-app data and AYou local records are not used for ad targeting.
    • Before you open a rewarded ad, the app refreshes regional consent information and provides an advertising privacy choices screen when required. On iOS, it requests App Tracking Transparency authorization where applicable. You can use the core Service without watching ads and can reopen advertising privacy choices from the Star Wallet.
    • Stars are granted after the ad provider confirms that the ad was completed. We update supported countries, reward ranges, consent flows, App Privacy, Data safety, and Ads declaration together with actual app behavior.

    12. Health-App Integration

    • Health-app integration is off by default and works only after you connect a feature and grant operating-system permission.
    • AYou local records remain the source of truth; HealthKit or Health Connect is an optional mirror. Turning off integration does not delete AYou local records.
    • Health data is not used for ad targeting, credit, insurance, employment decisions, medical diagnosis, or AI model training.
    • Unless you separately enter health-related content into an AI feature, data read from the health app is not sent to a generative AI provider.

    13. Notifications and Device Calendar

    • Record reminders for routines, schedules, D-day items, and focus sessions are scheduled as local notifications on your device. Reminder titles and record contents are not sent to a push server, and a scheduling failure does not prevent the underlying record from being saved on the device.
    • A With message-arrival alert is an optional service notification that tells you a friend sent an AYou in-app message. It is not carrier SMS/MMS or an advertising or marketing alert, and it is managed separately from CRM notification consent.
    • With message alerts are off by default. The general message-alert preference applies at the account level. We register a device signed in to that account as a delivery target only after you enable the preference and grant the operating-system notification permission on that device.
    • Without current nighttime consent, the server sends only a generic data-only, TTL-zero arrival signal to every active device that supports the current With push contract. The device's local clock when it actually receives the signal is authoritative: the app may show a local notification only from 8:00 AM inclusive until before 9:00 PM. The cached IANA time zone and registration time are telemetry and are never a server-side delivery or visibility gate. If the operating system does not run the data handler in the background or after a force quit, the alert fails closed and is not shown; the message remains available in the inbox. With current nighttime consent, the server may send the same generic wording as an operating-system-visible notification, including during local nighttime.
    • A With push contains only generic new-message wording. It never includes the message body, sender number, friend link, or sender identifier. The device's notification-preview, Focus, Do Not Disturb, and channel settings may apply separately.
    • Android TTL zero and APNs expiration zero reduce stale provider delivery on a best-effort basis; they do not mathematically guarantee that delay is impossible. For the no-nighttime-consent path, the device's receipt-time local-clock check remains the visibility control. A delivery or handler failure does not remove the underlying inbox message.
    • For remote notifications, we may process the FCM/APNs token, app language, IANA time zone and its registration time, per-device operating-system notification availability, and the account's preference state. For each nighttime-alert grant, we record an immutable event containing server time, consent-contract version, displayed locale, and the SHA-256 hash of the exact rendered consent body. A withdrawal event records its own server time and copies or references the withdrawn grant's version, locale, and consent-body hash; it is not a hash of separate withdrawal wording.
    • You can independently turn off account-level With, nighttime, and CRM alerts in the app, or revoke notification permission for a particular device in its operating-system settings. Withdrawing nighttime consent stops future nighttime push processing, clears its current active consent version and grant time, and records a withdrawal event; turning off general With alerts also turns off nighttime alerts and records that withdrawal if nighttime consent was active. Withdrawal does not delete delivered messages, disable the inbox, or affect the lawfulness of processing carried out before withdrawal. If all remote alerts are disabled in the app or device permission is unavailable, we disable server delivery for that device.
    • When you sign out, we deactivate that device token as a delivery target for the account and request invalidation of the device's FCM token. A registered token may be refreshed or invalidated after an account switch, device change, token refresh, app removal, or delivery failure. An inactive server token becomes eligible for deletion 30 days after invalidation and is removed by protected cleanup; account deletion removes the account's tokens earlier.
    • Device-calendar connection shows events from calendars you permit in the AYou Schedule screen on a read-only basis. AYou does not create, edit, or delete device events and does not send event contents to AYou servers, advertising providers, or AI providers.

    14. Children and Minors

    • The Service is not directed to children and is not submitted to app stores as a children-directed service.
    • Because we do not operate a separate parental/guardian consent system, we apply the following minimum ages. When a date of birth is entered, users below the minimum age are restricted from using the Service.
    • Korea: 14 or older (under the Personal Information Protection Act, processing personal data of children under 14 requires legal guardian consent)
    • United States: 13 or older (COPPA)
    • EU/EEA and the UK: 16 or older (a conservative baseline for varying digital-consent ages)
    • Other regions: 14 or older by default
    • If we become aware that we have processed personal data of a user below the applicable minimum age, we delete that information without undue delay.
    • Guardians may request review or deletion of their child's personal data through the contact in Section 17.

    15. Security Measures

    We apply reasonable technical and organizational safeguards, including:

    • HTTPS transport encryption
    • Role separation and least-privilege access controls
    • Authentication and session security management
    • Error and security log monitoring
    • Data minimization
    • Review of necessary safeguards when using third-party processors

    16. Changes to This Policy

    • This Policy may be updated due to changes in law, service features, third-party processors, or operations.
    • Material changes will be announced through the app or website before they take effect.
    • The last updated date is shown at the top of this document.

    17. Contact and Business Information