LEGAL

Privacy Policy

Effective date: June 11, 2026

Last updated: October 6, 2026

aanug ("the Company") complies with the Personal Information Protection Act and related laws to safely process personal information and protect the rights of data subjects in providing the KokoRoom service. Because KokoRoom processes sensitive information related to health and sex life — including menstruation, ovulation, PMS, physical symptoms, sexual activity, contraceptive pill records, and changes in libido — the Company handles this information separately from general personal information, obtains separate consent where required, and manages it securely.

1. Collection and Use of Personal Information

The Company collects and uses the following personal information to provide the Service, identify Users, respond to inquiries, improve the Service, and provide account backup and restoration where selected by the User.

a. Service use and identification

  • Firebase anonymous uid, name/nickname, date of birth, user role (self/partner), app language, first use date, terms agreement status

b. Account backup and restoration

  • When a User connects Google or Apple sign-in: the provider's account identifier, Firebase uid, and the email address and display name supplied by the provider. Apple may supply a private relay email or no email on a subsequent sign-in. KokoRoom does not receive the User's Google or Apple password.
  • When a User chooses account backup: linked account identifiers and the records and settings included in the backup scope described before linking
  • The backup scope may include health- and sexual activity-related records and is explained separately before the account is linked

c. Daily logging and notifications

  • Date, condition phase, emotions, memos, notification settings and times, FCM/APNs token

d. Partner connection

  • Your invite code, partner's code, partner's name, connection date, connection status, request/accept/decline/cancel status, requester and recipient uid and name
  • When using the Bench: messages or selected expressions, poke signals, sender and recipient identifiers, sending times, and delivery/read status needed to exchange them with the connected partner

e. Feedback submission

  • Feedback content, timestamp, anonymous uid-based userHash, OS, device name, app version, build number, language, current phase/weather, first use date

f. Device and technical information

  • Identifiers and access/server processing logs for Firebase Auth, Firestore, Messaging, Cloud Functions, Installations, App Check, and Remote Config; app and OS version, device information, language, network/IP information, and error or verification results needed for security, configuration, notifications, and troubleshooting

g. KokoRoom+ purchases and restoration

  • Store, product and transaction/order identifiers, purchase tokens or signed transaction information, purchase and expiration times, subscription or refund status, and the linked KokoRoom uid are processed to verify purchases, restore access, prevent duplicate claims, and provide the connected partner's benefits.
  • Apple App Store or Google Play handles payment. KokoRoom does not receive payment card numbers or bank account details.

h. Usage analytics

  • Google Analytics for Firebase processes app-instance/device identifiers, device and OS information, app version, language, approximate region derived from network information, and app activity such as launches, screen views, sessions, and feature interactions. The SDK may also collect in-app purchase product, price, and currency information. On Android it may collect the advertising identifier when available under device settings.
  • This information helps us understand onboarding and feature use and improve the Service. Our custom analytics events do not include health records, cycle dates, memo contents, names, dates of birth, email addresses, or KokoRoom account identifiers. Technical identifiers and purchase metadata mean this collection is not described as fully anonymous.
  • We do not use these analytics to target advertisements or sell personal information. Google Signals and Google Ads linking are not enabled. Google may process aggregated and de-identified measurements for benchmarking and modeling, and access analytics data to provide technical support under the configured service settings.
  • Analytics event-level data is configured for 2 months and user-level data for 14 months, with the user period renewed on new activity. Aggregated reports are not subject to these same periods. Device advertising/privacy settings control availability of advertising identifiers.

Retention period

  • In principle, personal information is retained until withdrawal or a request for account and data deletion
  • Records and settings stored through account backup remain on the server even if the account is disconnected from a device, and are retained until they are deleted through the account and data deletion process or another applicable deletion condition occurs
  • Customer inquiry and feedback records, data subject to statutory retention periods, and backups/logs are retained for their respective required periods
  • Account deletion does not automatically erase the separate purchase-verification ledger or the minimal deletion marker used to prevent an old login token from recreating a deleted account. These are retained for purchase ownership, fraud prevention, and deletion safety. No fixed automatic expiry is currently configured for these separate records; contact us to request review or deletion where applicable. Store-held transactions are also subject to Apple's or Google's own retention rules.

2. Processing of Sensitive Information

With separate consent where required, the Company processes the following health- and sex life-related sensitive information to provide the Service:

  • Most recent period start/end dates, average cycle length, period records, detailed menstruation records, predicted cycle phase, next expected period date, ovulation date, cycle day
  • Whether a period is occurring, condition phase, physical symptoms, lifestyle symptoms, PMS records, discharge records, non-menstrual bleeding records, sexual activity records, contraceptive pill records, changes in libido, and health- or sex life-related information that may be included in memos
  • When account backup is selected, sensitive information included in the separately disclosed backup scope may also be processed on the Company's servers for backup and restoration

If a User does not consent to the processing of sensitive information required for a particular feature, use of that feature or certain core Service features may be limited.

3. Third-Party Provision of Personal and Sensitive Information

As a general rule, the Company does not disclose Users' personal information to outside parties. However, when a User consents to a partner connection, today's cycle weather and cycle predictions are provided to the connected partner. Only items the User explicitly enables in the sharing scope may also be provided, including actual period records, analysis results covering up to the most recent six months, and past or current condition, mood, body, lifestyle, self-care, user-added, and memo records. Items not selected for sharing are not provided. Exceptions apply where required by law or where the User has given consent.

4. Outsourcing and Overseas Transfer of Personal Information

The Company uses Google Firebase and Google Cloud (including Authentication, Firestore, Messaging, Cloud Functions, Installations, App Check, Remote Config, and Google Analytics for Firebase) to operate, secure, and analyze the Service, including supported account backup and restoration. Feedback data is delivered via Slack. Apple and Google process sign-in and store purchases when those features are used. As a result, personal information may be stored and processed on servers located outside Korea.

Service providers process information for the functions described above. Partner sharing is initiated by the User and limited to the applicable connection and sharing choices. Transport to our online services is encrypted; account-linked server backups are not represented as anonymous or end-to-end encrypted.

5. Retention and Destruction of Personal Information

The Company destroys personal information without delay once the retention period has passed or the purpose of processing has been achieved, unless retention is required by applicable law.

If a User chooses account backup, linked account identifiers and the records and settings described before linking are processed on the Company's servers for backup and restoration. Disconnecting an account from a device does not delete records already stored on the server. Users may delete those records through the account and data deletion process provided by the Service.

A partner device may store an encrypted temporary copy of shared information only after the server confirms the current connection, recipient, and sharing scope. The copy is used only for that connection and scope. Once the app confirms a disconnection, sharing termination, or scope change, it promptly deletes the prior encryption key and copy. On a cold offline launch, the app does not display the temporary copy before server confirmation.

6. User Rights

Users may request to view, correct, or delete their personal information, or withdraw consent, at any time. Users who use account backup may also delete the linked account and server-stored backup data through the account and data deletion process provided by the Service. Disconnecting an account from a device alone does not constitute a request to delete server-stored backup data.

Request account or data deletion

In KokoRoom, open Settings, select your profile (My Info), and choose Delete Account. Follow the confirmation and account verification steps. This removes the account and its server backup, profile, partner connection, and associated shared records and Bench data. The purchase ledger and security deletion marker described above are exceptions.

You may also email aanug@aanug.com to request deletion of your KokoRoom account or specific data without deleting the account. Specify which option you want and your sign-in provider or account email so we can verify ownership. Do not send passwords, verification codes, payment card details, or health records. We will verify the request and explain any information that must be retained and the applicable reason.

Deleting the app or signing out does not delete the server account. Account deletion does not cancel an App Store or Google Play subscription; manage or cancel subscriptions in the store separately.

7. Personal Information Protection Officer

Representative
YiJu Jang

8. Effective Date

This Privacy Policy takes effect on June 11, 2026.

The October 6, 2026 update clarifies existing account sign-in and backup, KokoRoom+ purchase verification, Bench communication, analytics, and deletion handling for version 1.1.0. It does not introduce additional app permissions or data collection.

Service
KokoRoom
Operator
aanug
Representative
YiJu Jang
Contact
aanug@aanug.com | KokoRoom