Privacy Policy

Effective date: 2026-06-09

1. Purpose of Processing Personal Information

Able Co., Ltd. (hereinafter "Company") processes personal information for the following purposes and does not use it for any other purpose. Prior consent is obtained if the purpose changes.

A. Member identification and authentication
  - Identity verification via phone number
  - Prevention of fraudulent use and unauthorized access

B. Service provision
  - Sending/receiving messages, friend matching, push notifications
  - Display of profile information

C. Payment and settlement
  - Paid subscription billing, refunds, receipt issuance
  - Fraudulent transaction detection

D. Customer support and dispute resolution
  - Handling inquiries, investigating Terms of Service violations

2. Personal Information Collected and Collection Method

A. Collected at sign-up (required)
  - Phone number (E.164 format)
  - Hashed phone number (SHA-256, used for friend matching)
  - User ID (auto-assigned by Supabase)
  - PIN hash (PBKDF2-SHA256, stored on device — never transmitted)

B. Collected during service use
  - Profile: display name, profile photo (optional)
  - Chat message content, attached images
  - Friend relationships and conversation participation
  - Push notification tokens (Web Push, APNs, FCM)
  - Device info (OS, app version), IP address (for security logs)

C. Collected during payment
  - Payment identifier (Apple/Google transaction ID, RevenueCat app_user_id, product ID)
  - Subscription history (start/end timestamps, renewal/cancellation/refund events)
  - ※ Sensitive payment data such as card numbers, Apple ID credentials, and Google payment info are never collected by the Company. Apple App Store / Google Play handle them within their own payment systems.

D. Collection methods
  - Direct entry by members (registration, profile setup)
  - Automatic collection during service use (access logs, messages)
  - Subscription state changes received from Apple/Google via RevenueCat webhooks

3. Retention and Use Period of Personal Information

A. Member info: until membership withdrawal
B. Message data: even after the sender withdraws, retained in anonymized form for as long as the conversation room exists, to protect the rights of other participants
C. Payment records: 5 years (Korean E-Commerce Act)
D. Display/advertising records: 6 months (Korean E-Commerce Act)
E. Access logs: 3 months (Korean Protection of Communications Secrets Act)
F. Dormant accounts: separated after 1+ years of inactivity, destroyed after 4 years

4. Provision to Third Parties

As a rule, the Company does not provide users' personal information to third parties. Exceptions:
  - When the user has given prior consent
  - When required by law or upon lawful request from investigative authorities (e.g., warrant)

5. Entrustment of Personal Information Processing

The Company entrusts personal information processing as follows for smooth service operation:

┌────────────────────────────────────────────────────────────┐
│ Processor (Purpose)                       │ Entrusted Items │
├────────────────────────────────────────────────────────────┤
│ Supabase Inc. (DB/Auth/Storage)           │ All items       │
│ RevenueCat, Inc. (subscription verification) │ Payment IDs  │
│ Apple Inc. / Google LLC (in-app payment)  │ Payment processing │
│ Solapi (SMS delivery)                     │ Phone number    │
│ Apple Inc. (APNs push)                    │ Push token      │
│ Google LLC (FCM push)                     │ Push token      │
│ Vercel Inc. (web hosting)                 │ Access logs     │
└────────────────────────────────────────────────────────────┘

Entrustment contracts specify obligations under Article 26 of the Korean Personal Information Protection Act, including prohibition of personal information processing beyond the entrusted purpose, security measures, restrictions on re-entrustment, and liability for damages.

6. International Transfer of Personal Information

The Company transfers personal information internationally as follows for service operation:

A. Supabase (destination: India — Mumbai region)
  - Items transferred: member identifiers, profiles, messages, payment metadata
  - Transfer timing and method: real-time network transmission during service use
  - Retention period: same as Article 3 of this Policy

B. Apple Inc. (destination: United States) — APNs push notifications
  - Items transferred: push tokens, notification metadata
  - Retention period: until the member unsubscribes from push or withdraws

C. Google LLC (destination: United States) — FCM push notifications
  - Items transferred: push tokens, notification metadata
  - Retention period: until the member unsubscribes from push or withdraws

Users may decline international transfer by withdrawing membership, in which case service use will be restricted.

7. Procedure and Method for Destroying Personal Information

A. Procedure: Information past its retention period is moved to a separate database, kept for a certain period, and then destroyed.
B. Method:
  - Electronic files: permanently deleted in an unrecoverable manner
  - Paper documents: shredded or incinerated

8. Rights of Data Subjects and How to Exercise Them

Users may exercise the following rights at any time:
  - Request to view personal information
  - Request to correct errors
  - Request for deletion
  - Request to halt processing

How to exercise: through the Settings menu in the Service or by emailing companyable@naver.com. The Company will respond within 10 days of receiving the request.

9. Security Measures for Personal Information

The Company takes the following technical, administrative, and physical measures:

A. Technical measures
  - TLS 1.2 or higher encryption for transmission (HTTPS, HSTS preload)
  - PIN stored as PBKDF2-SHA256 hash (100,000 iterations)
  - Phone numbers stored as SHA-256 hash for friend matching (original never exposed)
  - Messages accessible only to conversation participants via Postgres Row-Level Security
  - Payment information processed only via App Store / Google Play in-app purchase (no direct card data collection)
  - Content immediately masked when the app moves to background

B. Administrative measures
  - Minimized number of staff handling personal information; access controls
  - Regular security audits and vulnerability assessments

C. Physical measures
  - Cloud data center access controls and 24/7 monitoring (according to processor policies)

10. Personal Information Protection Officer

The Company designates the following Personal Information Protection Officer:

  - Name: Jeehyun Kim
  - Email: companyable@naver.com

For reports or consultations on personal information infringement, you may contact:
  - Korea Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
  - Supreme Prosecutors' Office Cyber Investigation (spo.go.kr / +82-2-3480-3573)
  - Korean National Police Cyber Bureau (ecrm.police.go.kr / 182)

11. EU Users (GDPR) Rights

Users residing in the European Union (EU) to whom the GDPR applies may exercise the following rights regarding their personal data processed by the Company:

  - Right of access
  - Right to rectification
  - Right to erasure ("right to be forgotten")
  - Right to restriction of processing
  - Right to data portability
  - Right to object
  - Right to withdraw consent

How to exercise: Send a request along with information sufficient to verify your identity to companyable@naver.com. In principle, the Company will respond within one month in accordance with Article 12 of the GDPR. If you believe the Company's response is insufficient, you have the right to lodge a complaint with your local data protection supervisory authority.

Legal bases (GDPR Article 6): Processing is based on (a) the data subject's consent, (b) performance of a contract, and (c) the Company's legitimate interests.

Data Protection Officer (DPO): Jeehyun Kim / companyable@naver.com

12. Changes to This Privacy Policy

Any additions, deletions, or modifications to this Policy will be announced at least 7 days before the effective date (30 days for material changes).

  - Effective date: 2026-06-09