Privacy Notice
This notice explains how My Korean Boyfriends handles information when eligible users aged 13 and older use our fictional, AI-assisted interactive story service.
1. Who we are
이의석, an individual developer, operates My Korean Boyfriends and is the controller or business responsible for the personal information described here, except where a provider acts as an independent controller under its own notice.
Privacy contact: euisuk97@gmail.com. We have not appointed a separate data protection officer or representative. Requests sent to this address are handled by the operator.
2. Scope and age
This notice applies to the mobile app, support channels, and pages on my-korean-boyfriends.vercel.app. You must be at least 13 and obtain parent or guardian authorization where local law requires it. If local law does not permit your use even with that authorization, you may not use the service. The service is not directed to children under 13, and we do not knowingly collect their personal information. If we learn that an ineligible child provided information, we will take reasonable steps to delete it. Contact us if you believe this has happened.
3. Information we handle
| Category | Examples | Source |
|---|---|---|
| Account and eligibility | Apple or Google sign-in identifier, email or relay email if supplied, name or profile image returned by Google, account ID, minimum-age and required-authorization confirmation, broad age band (13–15, 16–17, or 18+), locale, and settings. You select an age range before your first conversation; we do not ask for, send, or store your date of birth. The app requests email—but not full name—from Apple. | You and the sign-in provider. |
| Story and chat content | Selected fictional persona, suggested replies, messages you type, story state, safety reports, and AI-generated output. | You, our editorial content, and the AI service. |
| Reward, experiment, and referral activity | Scene/turn events, verified-ad and promotional-credit balances, temporary ad-availability assistance requests and non-sensitive error categories, conversion milestone and experiment assignment, offer exposure, referral code, shared-link creation, attributed install/sign-up status, referral qualification, credit use, limits, and fraud-prevention decisions. | The app, our systems, Google AdMob, and AppsFlyer when enabled. |
| Optional product analytics | A random app-installation identifier, screen names and time spent, locale, platform, onboarding steps, persona identifier, and ad or generation status. After sign-in, events may also include the internal account UUID and story-session UUID and are therefore linkable to your account until deletion. Chat text, email, advertising ID, and access tokens are excluded. | The app, only after you opt in. |
| Device and diagnostics | Device/OS/app version, IP address, provider-inferred approximate region, logs, and network/service status. The app does not currently integrate a separate crash-reporting SDK. | Your device and service providers. |
| Advertising data | Ad request and impression data, reward-completion events, consent choices, and advertising or device identifiers where permitted by settings and law. For AdMob server-side verification (SSV), the app sends your authenticated internal account UUID as the SSV user ID and the current story-session UUID as SSV custom data; it does not put chat text in those fields. | Your device, our systems, and Google AdMob. |
| Support, tester interest, and safety | Your email address, message, attachments, content reports, and our response history when you choose to email us. Public tester-interest intake is currently paused, so the website does not collect country, device, or tester-interest details. | You, your email provider, Google email services, and in-app reports when enabled. |
Do not put passwords, financial account details, government identifiers, health records, exact location, or other sensitive information into story chat or support requests. We have not configured a separate third-party crash-reporting, customer-support, or product-analytics SDK. The mobile configuration includes AppsFlyer for install attribution and referral deep links, but referral attribution remains disabled until its deferred-link and reward verification is completed. Consented product events are written directly to our Supabase backend when optional analytics is enabled.
4. Why we use information
- To create and secure your account, confirm eligibility, store account and story records, and provide the service you request.
- To send the limited conversation context needed to generate and return a story continuation.
- To show a rewarded ad only when you choose it, verify completion, grant a story credit, and prevent duplicate or fraudulent rewards.
- To offer friend referrals to consenting users aged 13 and older, create referral links, match referred installs, determine reward eligibility, apply reward limits, and record reward use. Referral access does not depend on advertising history or A/B experiment allocation.
- To ask for an App Store or Google Play review through the operating system's native prompt. We do not receive your rating or review through that prompt, and promotional credit is not conditioned on leaving a review.
- To maintain, debug, measure, localize, secure, and improve the app.
- To enforce safety rules, investigate reports, respond to support requests, and comply with law.
Optional product analytics is unavailable and remains off for users in the 13–15 and 16–17 bands. For adult users, it is off until they choose it in Settings. Existing adult users may retain an earlier optional analytics choice. Turning it off stops future analytics collection and removes the app's local analytics identifier, but does not by itself delete events already stored on the server. Delete your account to remove identified events and pre-sign-in events whose installation identifier later became linked to your account, or email a privacy request. Events from an installation identifier that was never linked to an account cannot be located through an account request. This choice is separate from the consent controls used by the advertising SDK.
Where a legal basis is required, we rely on performance of our agreement for account and story features; consent for sending story content to an AI provider, optional analytics, and any advertising or device access that requires consent; legal obligations for valid requests and compliance records; and legitimate interests in service security, fraud prevention, reliability, and non-personalized measurement where those interests are not overridden by your rights. You may withdraw consent for future processing at any time. Mandatory rights under laws such as the GDPR, UK GDPR, Brazil's LGPD, applicable U.S. state privacy laws, and local consumer or privacy laws remain available where they apply.
5. Providers and disclosures
| Recipient | Purpose and data | Required launch detail |
|---|---|---|
| Supabase | Provides authentication, database, server functions, and operational logs and processes account, story, reward, analytics, report, and diagnostic records on our behalf. | Our operational project is hosted in the Singapore region. Exposed tables have row-level security enabled, and privileged operations run only on the server. Backup and provider-plan retention remain subject to the selected service plan and are described in the retention section below. |
| OpenAI API | Generates story continuations using gpt-5.6-luna. It receives persona, scenario and safety instructions; locale; stored story summary and state; up to the latest 20 messages needed for continuity; and a one-way pseudonymous safety identifier derived from the internal account UUID and a server secret for abuse prevention. It does not receive the sign-in email, name, profile image, or raw account UUID. | Requests are made server-side using an operational API project. We do not opt in to use submitted API content to train models. API content and abuse-monitoring records are handled under the OpenAI account's applicable API data controls. Sign-in accepts the account terms but does not authorize AI processing. The service requests separate, explicit permission immediately before your first conversation, before story content is sent to the AI provider. You may decline and keep browsing. |
| Google AdMob | Delivers and measures rewarded ads and confirms reward events where advertising is available. For SSV, Google receives our internal account UUID in the user_id field and the current story-session UUID in custom_data so our server can associate a signed reward callback with the correct account and story. These identifiers are linkable to records in our service even though they are not your email or chat text. Google may also process IP address, device/ad identifiers, consent signals, and ad interactions. | Our production Android and iOS apps and their rewarded-ad units are registered with AdMob. The app requests non-personalized rewarded ads and presents Google's regional consent choices where required. Age-band controls, ad formats, mediation, regional messages, and partner settings may affect availability. |
| AppsFlyer | For users aged 13 and older who separately opt in, when referral attribution is activated, routes shared OneLink URLs to the appropriate store or app and measures direct or deferred app opens. It may process an AppsFlyer/device identifier, IP address, device and app information, install/open timestamps, campaign and link parameters, approximate location inferred from network data, and an opaque referral code. We do not place your email, chat text, or raw internal account UUID in the shared referral parameter. | AppsFlyer account and OneLink configuration are registered, but referral attribution remains disabled until deferred-link and reward verification is completed. All age bands, including 13–15 and 16–17, may opt in separately. Existing accounts are not opted in automatically. AppsFlyer advertising identifier collection is disabled for referral matching. You can withdraw referral consent in Settings; this stops future SDK activity and clears unclaimed local referral data, without revoking rewards already earned. Before activation, we will verify the contracted entity, plan, retention, processing locations, data-processing terms, and platform privacy disclosures. Deferred attribution can fail; the service does not offer manual referral-code entry or screenshot-based attribution. |
| Apple and Google sign-in | Authenticate you and provide an account identifier plus account details you authorize them to share. | Sign in with Apple is the default on iOS and requests email only; Google Sign-In is the default on Android and supplies an identity token and authorized profile details. Apple private-relay email is supported. |
| Vercel Inc. | Hosts these public pages and may process request metadata such as IP address, user agent, timestamps, and security logs. | This site does not install client-side analytics, advertising scripts, or a form backend. Support, safety, privacy, and deletion links open your email application; public tester intake is paused. |
| Google email services | Receives support, safety, privacy, and deletion emails sent to our published Gmail address, including the information you choose to include. | Do not email passwords, tokens, government IDs, payment information, or full private conversations. |
We may also disclose information when reasonably necessary to comply with law, protect users and the service, investigate abuse, or complete a merger, financing, acquisition, or asset transfer with appropriate notice and safeguards. Provider processing remains subject to each provider's applicable contract, data-processing terms, and service settings.
6. Rewarded ads and choices
After the included replies, you may choose a rewarded ad for three new AI-generated scenes for that character, usable for one hour. Additional characters unlock separately through a verified rewarded ad. These benefits have no cash value, and clicking an advertiser's link is not required. Ad availability varies. Open Settings → Privacy & support → Advertising privacy choices to revisit Google's regional consent form when available. You can also use your device privacy settings and Google's advertising controls. The app requests non-personalized ads and applies the age-band controls described above; we will reassess platform permission and disclosure requirements if the production configuration changes.
When a signed-in user requests a rewarded ad, the production app configures AdMob SSV with the internal account UUID as user_id and the active story-session UUID as custom_data, prefixed with character: for a character unlock. Google includes those values in the signed callback to our server, which uses them to validate account/session ownership and prevent duplicate rewards.
During a temporary ad-availability assistance period, we may grant limited story access when an ad cannot load. Our server records the account and session identifiers, assistance purpose, non-sensitive failure category, request identifier, time and entitlement needed to apply usage limits and prevent duplicate grants. This assistance is recorded separately from verified ad completions and is not reported as a watched ad. It does not authorize advertising or AI processing that you have not consented to.
Users aged 13 and older may separately consent to installation matching for qualifying friend referrals. Refusing this optional consent does not block story use. We store the referral-consent timestamp with your account; a missing timestamp means consent has not been granted or has been withdrawn. Qualifying referrals grant limited promotional story credits. A conversion-milestone credit is granted independently of any store rating or review. We do not request, collect, or verify a screenshot of a store review.
7. International transfers
Supabase stores our operational project data in Singapore. Vercel and Google email services may process public-site request metadata or emails in the United States and other countries where they and their subprocessors operate. OpenAI, Google AdMob, and, when activated, AppsFlyer may process the data described above internationally under their applicable service terms and settings. Before a public Korean launch, we will publish the required Korean-language overseas-transfer details and obtain separate consent where applicable.
Where required, transfers rely on the selected provider's data-processing agreement, approved contractual clauses, adequacy decisions, consent, or another lawful mechanism. Prepared controls minimize fields, use encrypted transport, restrict administrative access, and avoid sending email, name, or full account records to an AI model. Contact us for information about safeguards relevant to your request.
8. Retention and deletion
The current public website installs no client-side analytics or advertising scripts and uses no cookies or browser storage. Vercel automatically records edge-request and operational data needed to host and secure the pages. The site has no form backend, account database, or AI connection; public tester-interest intake is paused. Google email services receive only information you deliberately send by email. The app-data rows below describe the operational mobile service and its deletion design.
| Data | Retention rule or launch condition |
|---|---|
| Account, profile, story, chat, reward, experiment, referral, and in-app report records | Retained until the user deletes the account unless a shorter promotion limit applies or limited security evidence must be preserved as permitted by law. The hard-delete function removes the authentication user and linked profile, stories, messages, generation jobs, credits, experiment assignments, referral records, in-app reports, and identified analytics together. Individual-story deletion and automatic inactivity deletion are not currently offered. |
| Optional product analytics | Collection is off until the user opts in. Turning it off stops new events and deletes the local identifier. Account deletion removes identified events plus all pre- and post-sign-in events and rate-limit rows for installation identifiers previously linked to that account. An installation identifier that was never linked to an account cannot be found through an account request; production analytics will remain disabled until a maximum retention period and cleanup job for such unlinked records are configured and published here. |
| Security, server, hosting, and diagnostic logs | Controlled by the selected provider plan and security needs. The normal retention window follows the applicable provider setting; we will publish a fixed public schedule before a public release. A record under active security investigation or legal preservation may be kept longer where permitted. |
| Support, privacy, deletion, and safety email | Before live service opens, the operator will establish and publish category-specific retention and a documented deletion schedule. Public tester-interest intake is paused until that work and the applicable localized transfer notice are complete. Do not send information that is not necessary for your request. |
| Backups | No production database backup plan has been selected. Before live data is accepted, this row will state the actual managed backup rotation. Deleted data in a backup will not be returned to ordinary use and will be re-deleted if a disaster-recovery restore occurs. |
Deleting your account removes associated live records under the prepared hard-delete design. Where contractually available, we request deletion from processors; provider-held security, abuse-monitoring, advertising, hosting, or email records may instead expire under the provider's settings and policy. See Delete your account for in-app and web-request steps.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive a portable copy, opt out of certain targeted advertising or sales/sharing, and appeal a denied request. You may also complain to your local regulator. We may verify your identity and may deny or limit a request where law permits.
Submit a request to euisuk97@gmail.com. Add Privacy request to the subject and state your country and requested action. Do not send a password, sign-in token, or unnecessary identity document. An authorized agent should include permission signed by the account holder; we may verify both the authorization and the account using proportionate information. If we deny a request, reply with Privacy appeal in the subject within 30 days. We respond within the period required by applicable law, ordinarily within 30 days after verification.
10. Security
The mobile service uses encrypted HTTPS transport, Supabase row-level access controls, server-only privileged keys, short-lived authentication tokens, encrypted storage for model-provider credentials, signed AdMob reward callbacks, request limits, and administrator routes that require a second authentication factor. No administrator will be granted production access before multi-factor authentication is enrolled and tested. No storage or transmission method is completely secure. Report a suspected account or data incident to euisuk97@gmail.com.
11. Changes and contact
We may update this notice when the app, providers, or law changes. We will post the revised date and provide additional notice when required. Privacy questions and requests can be sent to euisuk97@gmail.com. A separate postal privacy address is not currently published; where applicable law requires another contact channel, we will provide it in the relevant store listing or in response to a verified request.