This document is a translation of the Korean original. In the event of any discrepancy between this translation and the Korean original, the Korean original shall prevail.
Vibeline (Business Registration No.: 895-01-03886; the "Company") complies with applicable laws, including the Personal Information Protection Act of the Republic of Korea ("PIPA"), the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. of the Republic of Korea (the "Network Act"), and the Act on the Consumer Protection in Electronic Commerce, Etc. of the Republic of Korea (the "E-Commerce Act"), and establishes and discloses this Privacy Policy as follows in order to protect users' personal information and respect their rights and interests.
This Policy applies to the mobile application myfit (the "Service") operated by the Company. myfit is a virtual fitting service that uses artificial intelligence (AI) to show users how clothing would look on them, based on a photo of themselves that the user uploads.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information is not used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent.
- Providing the AI virtual fitting service: Generating and providing virtual fitting result images by using AI to combine the photo uploaded by the user with the clothing the user has selected
- Member management: Sign-up and user identification/authentication, management of anonymous or SSO (Google, Apple, Kakao) accounts, blocking sign-up by children under 14 years of age, and preventing fraudulent use
- Payment and settlement: Processing in-app purchases of paid services such as credits and subscriptions, handling refunds and withdrawal of offers, and retaining transaction records
- Service operation and improvement: Analyzing service usage records, diagnosing synthesis errors and quality issues through short-term (up to 7 days) retention of processed person-photo inputs created for AI delivery, monitoring fraudulent use, and responding to customer inquiries
- Operating the referral (invitation) program: Granting and managing referral rewards through invitation codes
- Sending notifications: Providing service-related information via push notifications (where the user has consented)
- Serving advertisements and measuring their performance: Displaying advertisements in the Service, providing interest-based (personalized) advertising, preventing ad fraud such as invalid clicks, and attributing and measuring the performance of advertising the Company runs on other channels (see Article 6-2)
Article 2 (Personal Information Items Processed)
The Company processes the following items of personal information.
1. Information the user directly enters or provides
| Category | Items collected | Notes |
|---|---|---|
| Device original and EXIF of the user's photo | The original camera/library file selected by the user, pixels outside the selected crop, and EXIF metadata (such as capture location, time, and device information) | Used only on the device to create the fitting image; not sent to or stored on the server (see Article 5) |
| Processed person-photo input for AI delivery | The photo of the user that the app creates and uses for delivery to the AI model after cropping, resizing, and compressing the selected area (may include the face and body) | Transfer to OpenAI is required to generate a fitting. To diagnose synthesis errors and improve quality, the Company retains a copy identical to the transmitted input in private storage for up to 7 days (including where transmission or synthesis fails), after which it is automatically deleted without undue delay; it is deleted immediately if the user deletes the relevant fitting record (see Article 5) |
| Uploaded clothing photos | Photos of clothing uploaded by the user as input for synthesis | Used as input for virtual fitting and for handling customer inquiries. Retained for up to 90 days (see Article 5) |
| Account information | Anonymous identifier (ID) or SSO identifier (Google, Apple, Kakao), email address | Identifier and email received from the relevant provider upon SSO sign-up |
| Date of birth | Date of birth | To block sign-up by children under 14 years of age (age verification) |
| Payment information | In-app purchase history (such as the product, the date and time of payment, and the transaction identifier) | Payments themselves are processed through the app store's in-app purchase system, and the Company does not directly collect or store payment method details such as card numbers |
| Referral information | Invitation code | For granting referral rewards |
2. Information automatically generated or collected in the course of using the Service
| Category | Items collected |
|---|---|
| Device information | Device model, OS version, device identifier, app version, language and country settings |
| Push token | Token for sending push notifications (FCM/APNs) |
| Service usage records | Access date and time, feature usage history, fitting attempt records, error logs |
| Generated output | AI virtual fitting result images |
| Advertising identifier | The iOS Advertising Identifier (IDFA) and the Android Advertising ID (AAID). Collected and transmitted by the advertising SDK (Google AdMob) when an ad is requested, and by the measurement SDK (Meta SDK) when attributing an app install. The Company does not store it in its own database (see Article 6-2) |
| Advertising usage records | Ad impressions, clicks, and view-completion records, together with the device information and IP address (which may be used to estimate approximate location such as country) that the advertising SDK collects when requesting an ad |
| Advertising measurement records | App install and launch, completed sign-up, and completed in-app purchase or subscription, together with the amount and currency. Collected and transmitted by the measurement SDK (Meta SDK) so the Company can tell whether a user installed the app after seeing its advertising and improve ad efficiency. These records do not include directly identifying information such as name or email (see Article 6-2) |
Article 3 (Processing and Retention Periods of Personal Information)
The Company processes and retains personal information within the retention and use period prescribed by law or the retention and use period consented to by the user.
| Item | Retention period |
|---|---|
| Original device file, pixels outside the crop, and EXIF of the user's photo | Not stored (a fitting input is created on the device and these source data are not sent to the server) |
| Processed person-photo input for AI delivery | Transfer to and processing by OpenAI are required to provide fitting. Retained privately for up to 7 days to diagnose synthesis errors and improve quality, then automatically deleted without undue delay. Deleted immediately if the user deletes the relevant fitting record |
| Uploaded clothing photos | Retained for up to 90 days to handle customer inquiries (such as synthesis errors and moderation decisions), then deleted automatically. If the user deletes the relevant fitting record, it is removed from the Service immediately, and the retained copy is also permanently deleted within the above period. Upon account deletion, permanently deleted after the deletion grace period (30 days) |
| AI virtual fitting result images | Retained for up to 90 days after generation, then deleted automatically. If the user deletes them, they are immediately removed from the Service; retained copies are kept solely to prevent fraudulent use and respond to customer inquiries, and are permanently deleted within the above retention period (up to 90 days). Upon account deletion, permanently deleted after the deletion grace period (30 days) |
| Community posts (images and text) | If the user deletes them, they are immediately removed from the Service, and retained copies are kept for up to 90 days from the date of deletion to handle reports and disputes, then permanently deleted. Upon account deletion, permanently deleted after the deletion grace period (30 days) |
| Account information (identifiers, email, date of birth) | Until 30 days (grace period) have elapsed after account deletion |
| Device information, push tokens, service usage records | Until 30 days (grace period) have elapsed after account deletion (or the applicable period where a separate statutory retention obligation exists) |
| Advertising identifier and advertising usage records | The Company does not store the advertising identifier in its own database; the retention and use period of information transmitted to Google via the advertising SDK is governed by Google's privacy policy and data retention policies. However, records of rewarded-ad view completion and its server-side verification (which do not include the advertising identifier) are retained for the same period as the service usage records above, in order to grant credits and prevent fraudulent use |
| Advertising measurement records | The Company does not separately store these records in its own database; the retention and use period of information transmitted to Meta via the measurement SDK is governed by Meta's data policy and retention policies |
| Payment and transaction records | For the period prescribed by applicable laws |
Retention under applicable laws
In accordance with the E-Commerce Act and other applicable laws, the following information is retained for the periods specified below.
- Records concerning contracts or withdrawal of offers: 5 years (E-Commerce Act)
- Records concerning payment and the supply of goods or services: 5 years (E-Commerce Act)
- Records concerning consumer complaints or dispute resolution: 3 years (E-Commerce Act)
- Records concerning labeling and advertising: 6 months (E-Commerce Act)
- Service visit (access) records: 3 months (Protection of Communications Secrets Act of the Republic of Korea)
Article 4 (Provision of Personal Information to Third Parties)
The Company processes users' personal information only within the scope specified in Article 1 and does not provide personal information to third parties without the user's prior consent. The following cases are exceptions.
- Where the user has given prior consent
- Where there is a special provision in the law, or where an investigative agency makes a request for investigative purposes in accordance with the procedures and methods prescribed by law
Article 5 (Special Notice on Photo Processing)
Given the nature of a virtual fitting service, the Company separately provides the following notice regarding photo processing.
-
Device originals and EXIF are neither transmitted nor stored: The original camera/library file, pixels outside the selected crop, and EXIF metadata (such as capture location, time, and device information) of the user's photo never leave the device and are not stored on the Company's servers. The app creates a separate cropped, resized, and compressed image on the device, and only that processed image is used for fitting.
-
OpenAI transfer and processing required for fitting: To generate a virtual fitting, the processed person-photo input, a clothing photo or preset, and synthesis-request information must be transmitted through the Company's server to and processed by OpenAI in the United States. This transfer and processing are required to provide fitting and occur only when the user requests a fitting. Unless the user requests a fitting, the processed person-photo input never leaves the device.
-
Short-term retention for diagnostics: To reproduce and diagnose synthesis errors and quality issues, the Company keeps a copy of the processed person-photo input identical to the one sent to OpenAI in private storage for up to 7 days, after which it is automatically deleted without undue delay. The copy may be retained during this period even if delivery to OpenAI or image generation fails. If the user deletes the relevant fitting record, the diagnostic copy is deleted immediately with it. Access is limited to operational purposes necessary for error diagnosis. The Company does not use these copies for advertising, user identification or authentication, or AI model training, and does not opt in to OpenAI API data sharing for training. OpenAI's separate processing and default abuse-monitoring logs are governed by Article 6.
-
Retention of clothing photos: Clothing photos uploaded by the user are retained for up to 90 days to facilitate the handling of customer inquiries, such as synthesis errors and moderation decisions, and are deleted automatically once that period has elapsed. If the user deletes the relevant fitting record, it is removed from the Service immediately, and the retained copy is also permanently deleted within the above period. Upon account deletion, it is permanently deleted after the deletion grace period (30 days).
-
Retention of result images: AI virtual fitting result images are retained on the server for up to 90 days for the user's convenience in viewing and reuse, and are deleted automatically once the retention period has elapsed. If the user deletes them, they are immediately removed (no longer displayed) from the Service; retained copies are kept solely to prevent fraudulent use and respond to customer inquiries, and are permanently deleted within the above retention period (up to 90 days). Upon account deletion, they are permanently deleted after the deletion grace period (30 days).
-
Exporting to the device photo library: Users may export result images to their own device photo library. Users are responsible for managing images saved on their devices.
-
No processing of biometric information: The Company processes photos that include faces, but does not technically process them for the purpose of identifying or authenticating a specific individual (such as extracting facial feature points or creating biometric templates). Photos are used only for clothing synthesis and diagnosis of errors and quality issues in that synthesis, and the Company therefore does not process them as biometric identification information (biometric data) under PIPA.
Article 6 (Outsourcing of Personal Information Processing and Cross-Border Transfers)
To provide the Service smoothly, the Company outsources personal information processing tasks as follows, and because some processors are located overseas, personal information is transferred abroad. When entering into outsourcing agreements, the Company stipulates the matters necessary to ensure that personal information is managed securely.
| Processor | Country of transfer | Items transferred | Purpose of outsourcing/transfer | Retention and use period |
|---|---|---|---|---|
| OpenAI, L.L.C. | United States | Processed person-photo input for AI delivery, clothing photo or preset, and synthesis request information | Processing required to generate AI virtual fitting images and safety monitoring | By default, up to 30 days in API abuse-monitoring logs (except where longer retention is required by law or reasonably necessary to protect the service or third parties). Not used to train API models, and the Company does not opt in to data sharing for training |
| Supabase, Inc. | United States | Account information, service usage records, fitting request records, private-file object keys, and similar data | Operation of service infrastructure (authentication, database, servers) and access control for private files | For each item's stated retention period, or until account deletion or termination of the outsourcing agreement |
| Cloudflare, Inc. | United States (processor location) and Asia-Pacific region (R2 APAC Location Hint; no guarantee of a specific country) | Processed person-photo inputs (diagnostic copies), uploaded clothing photos, and AI result images | Storage and transfer of diagnostic copies and other private images | Person-photo diagnostic copies: up to 7 days (automatically deleted without undue delay when the period expires; deleted immediately when the fitting record is deleted); uploaded clothing photos and result images: up to 90 days or as otherwise specified by each item's deletion policy |
| RevenueCat, Inc. | United States | Payment and transaction identifiers, device identifiers | In-app purchase and subscription management and settlement | Until account deletion or termination of the outsourcing agreement |
| Expo (Expo, Inc.) / Google (FCM, Android) / Apple (APNs, iOS) | United States | Push tokens, device information | Delivery of push notifications | Until account deletion or termination of the outsourcing agreement |
| PostHog, Inc. (if used) | United States | Service usage records, device information | Service usage analysis and quality improvement | Until account deletion or termination of the outsourcing agreement |
| Google LLC (Google AdMob) | United States | Advertising identifier (IDFA / Android Advertising ID), device information, IP address, and advertising usage records such as impressions, clicks, and view completions | Serving advertisements in the Service and measuring their performance, providing interest-based (personalized) advertising, and preventing ad fraud | As governed by Google's privacy policy and data retention policies |
| Meta Platforms, Inc. (Meta SDK) | United States | Advertising identifier (IDFA / Android Advertising ID), device information, IP address, and advertising measurement records such as app install, launch, completed sign-up, and completed purchase | Attribution and performance measurement of advertising the Company runs, and optimization of ad targeting | As governed by Meta's data policy and retention policies |
The Cloudflare R2 APAC setting is a best-effort Location Hint for performance optimization, not a jurisdictional restriction guaranteeing storage in a particular country. (Cloudflare R2 data location)
OpenAI's processing and default abuse-monitoring logs are separate from the Company's 7-day diagnostic retention. OpenAI's default abuse-monitoring retention of up to 30 days may apply (except where longer retention is required by law or reasonably necessary to protect the service or third parties). OpenAI API data is not used to train models unless the Company explicitly opts in to data sharing, and the Company does not opt in. (OpenAI API data controls)
- Legal notice on cross-border transfers: The table above contains the matters required to be disclosed for cross-border transfers under Article 28-8 of PIPA (recipient, country of transfer, items transferred, purpose of transfer, and period of use). Users may notify the Company that they refuse a cross-border transfer. However, the OpenAI transfer required for fitting and the Cloudflare storage used for diagnostics and retention are transfers necessary to provide the Service, so refusing them may restrict use of virtual fitting and related features.
- Refusing the advertising-related transfer does not restrict use of the Service: Users may refuse the transfer of the advertising identifier to Google and Meta for personalized advertising and advertising measurement at any time using the methods in Article 6-2. Even if they refuse, they can continue to use every MyFit feature; they will simply see ads that are not tailored to their interests.
- Any changes to the outsourcing or transfer details, or any addition or change of processors, will be disclosed through this Policy.
Article 6-2 (Online Personalized Advertising and Behavioral Information)
The Company displays advertisements in the Service to support its operation, and measures the performance of the advertising it runs on other channels. There are two types of in-app ads: a banner ad at the bottom of certain screens and rewarded ads that the user explicitly chooses to watch (to earn credits, and to start a fitting as a free member). Advertisements are served through Google AdMob, operated by Google LLC. Advertising performance is measured through the Meta SDK, provided by Meta Platforms, Inc., which the Company uses to tell whether a user installed the app after seeing its advertising. The Company may provide personalized (interest-based) advertising, and provides the following notice in that regard.
| Item | Ad serving (Google AdMob) | Performance measurement (Meta SDK) |
|---|---|---|
| Behavioral information collected | Advertising identifier (iOS Advertising Identifier (IDFA), Android Advertising ID), device information, IP address, and advertising usage records such as impressions, clicks, and view completions | Advertising identifier (IDFA / Android Advertising ID), device information, IP address, and app install, launch, completed sign-up, and completed purchase together with the amount and currency |
| Method of collection | Automatically collected by the advertising SDK embedded in the app and transmitted to Google when the user views a screen containing an ad or watches a rewarded ad | Automatically collected by the measurement SDK embedded in the app and transmitted to Meta when the user launches the app or one of the events above occurs |
| Purposes of collection and use | Serving ads and measuring their performance, providing interest-based advertising, and preventing ad fraud such as invalid clicks | Attribution and performance measurement of advertising the Company runs, and optimization of ad targeting |
| Retention and use period | The Company does not store the advertising identifier in its own database; the retention and use period of the transmitted information is governed by Google's privacy policy and data retention policies | The Company does not separately store these records in its own database; the retention and use period of the transmitted information is governed by Meta's data policy and retention policies |
- How to consent to or refuse personalized advertising and advertising measurement (The choices below apply to both ad serving and performance measurement. If you refuse, the advertising identifier is no longer sent to Meta either.)
- iOS: Before the app first displays an advertisement, it asks for permission through the iOS App Tracking Transparency prompt, and provides personalized advertising and advertising-identifier-based measurement only if the user allows it. The choice can be changed at any time under Settings > Privacy & Security > Tracking on the device.
- Android: The device's advertising settings apply. Users may refuse personalized advertising and advertising-identifier-based measurement by selecting "Delete advertising ID" or opting out of ad personalization under Settings > Google > Ads.
- European Economic Area (EEA), the United Kingdom, and similar regions: Where the relevant laws apply, the app presents a separate consent form through Google's User Messaging Platform (UMP), and users may make their choice there.
- Refusing does not restrict use of the Service. Even if a user refuses personalized advertising, every MyFit feature remains available; the user will simply see ads that are not tailored to their interests.
- Records of rewarded ads: To provide features tied to rewarded ads, such as earning credits and starting a fitting, the Company retains the fact that an ad was watched to completion and the result of its server-side verification (these do not include the advertising identifier) as service usage records. The retention period follows Article 3.
- Children: The Company does not allow children under 14 years of age to sign up for or use the Service (Article 9), and the Service is not primarily directed to children.
- Information on how Google processes data for advertising purposes is available in the Google Privacy Policy and How Google uses information from sites or apps that use our services. Information on how Meta processes data is available in the Meta Privacy Policy and the Meta Business Tools Terms.
Article 7 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
Users may exercise the following rights at any time.
- Request access to their personal information
- Request correction where there are errors
- Request deletion
- Request suspension of processing
- Withdraw consent and delete the account
These rights may be exercised through the in-app settings screen (e.g., My Page > Account/Privacy Management), or by contacting the Chief Privacy Officer or the responsible department in writing or by email (admin@vibeline.co.kr), and the Company will act without delay. If a user requests correction or deletion of personal information, the Company will not use or provide that personal information until the correction or deletion is completed. These rights may also be exercised through a legal representative or an authorized agent, in which case a power of attorney must be submitted.
If a request to exercise these rights may be restricted or refused under applicable laws, the Company will notify the user of the reason without delay.
As to the processed person-photo input retained for diagnostics, users may at any time have the retained copy destroyed immediately by deleting the relevant fitting record.
Article 8 (Destruction of Personal Information)
- When personal information becomes unnecessary, such as upon expiration of the retention period or fulfillment of the purpose of processing, the Company destroys the personal information without delay.
- Information in electronic file form is permanently deleted using methods that make recovery or restoration impossible, and paper documents are shredded or incinerated.
- Diagnostic copies of processed person-photo inputs are retained for up to 7 days and automatically destroyed without undue delay when that period expires. They are destroyed immediately if the user deletes the relevant fitting record. Original device files, pixels outside the crop, and EXIF are not stored on the server and therefore require no separate server-side destruction procedure. AI virtual fitting result images and uploaded clothing photos are automatically destroyed once up to 90 days have elapsed after generation (upload). Items deleted directly by the user are removed from the Service immediately; retained copies are kept solely to prevent fraudulent use and respond to customer inquiries, and are permanently destroyed within the above retention period (up to 90 days). Retained copies of community posts deleted directly by the user are permanently destroyed within up to 90 days from the date of deletion. Upon account deletion, they are permanently destroyed after the deletion grace period (30 days).
Article 8-2 (Account Deletion and Grace Period)
When a user requests account deletion, the Company immediately deactivates the account to suspend use of the Service and applies a 30-day grace period. During the grace period, the user may log in again to cancel (restore) the deletion. Once the grace period (30 days) has elapsed, the account, personal information, result images, community posts, and other data are permanently deleted (comments written by the user may be preserved with the author anonymized and displayed as a "deleted user"). However, payment and transaction records and other information subject to statutory retention obligations are retained for the applicable period.
Article 9 (Personal Information of Children Under 14)
The Company does not allow children under 14 years of age to sign up for or use the Service. The Company verifies age via date of birth at sign-up and blocks sign-up if the person is confirmed to be under 14 years of age. The Company does not operate a separate legal-representative consent procedure. If it is confirmed that personal information of a child under 14 years of age has been collected, the Company will destroy that information without delay.
Article 10 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information.
- Administrative measures: Establishing and implementing an internal management plan, minimizing the number of personnel handling personal information, and managing access privileges
- Technical measures: Managing access rights to personal information processing systems, encrypting data in transit, and implementing access controls and intrusion prevention
- Physical measures: Controlling access to data
In particular, the Company does not transmit off-device or store original device files, pixels outside the selected crop, or EXIF; keeps the processed person-photo input privately for up to 7 days for diagnostic purposes only; and restricts access to error and quality diagnosis, thereby minimizing the risk of exposure of potentially sensitive photo information.
Article 11 (Chief Privacy Officer)
The Company has designated the following Chief Privacy Officer (CPO) to take overall responsibility for personal information processing and to handle users' inquiries, complaints, and requests for remedies related to the processing of personal information.
- Chief Privacy Officer: Younghwan Kim (CEO)
- Contact (email): admin@vibeline.co.kr
Users may direct any inquiries, complaints, or requests for remedies concerning personal information protection arising in the course of using the Service to the officer above, and the Company will respond and take action without delay.
Article 12 (Remedies for Infringement of Rights and Interests)
Users may apply to the following organizations for dispute resolution or counseling in order to obtain relief from infringement of their personal information.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.kopico.go.kr
- Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (no area code) / privacy.kisa.or.kr
- Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) / www.spo.go.kr
- Cyber Investigation Bureau, Korean National Police Agency: 182 (no area code) / ecrm.police.go.kr
Article 13 (Changes to This Privacy Policy)
This Privacy Policy may be changed in accordance with changes in laws, policies, or the Service, and any changes will be announced through in-app notices or similar means. Where material changes are made, they will be announced at least 7 days before the effective date (or at least 30 days in advance in the case of changes unfavorable to users).
- Date of announcement: June 26, 2026
- Effective date: June 26, 2026
- Amendment announced and effective: August 5, 2026
- Amendment announced and effective: August 11, 2026
- Amendment announced and effective: August 12, 2026 (new disclosure of personalized advertising and behavioral information — Article 1(7), Article 2, Article 3, Article 6, and Article 6-2)
- This amendment announced and effective: August 18, 2026 (addition of Meta Platforms, Inc. as a processor for advertising performance measurement, and related disclosures — Article 1(7), Article 2, Article 3, Article 6, and Article 6-2). The processing takes effect in practice from the app version released on or after this amendment, and if you refuse using the methods in Article 6-2 the advertising identifier is not transmitted to Meta. Refusing does not restrict use of any MyFit feature.