Learn Languages with Retriever — Privacy Policy

apochopo Inc. ("we", "the Company") publishes this Privacy Policy under Article 30 of Korea's Personal Information Protection Act (PIPA) to explain how we handle personal data in Learn Languages with Retriever (the "Service"). The Korean version of this page is the authoritative text; this English version is provided for your convenience.

1. Purposes of processing

We process personal data only for the purposes below. If a purpose changes we obtain separate consent as required by PIPA Article 18.

PurposeData usedLegal basis (GDPR Art. 6)
Account creation, identification and keeping you signed inEmail address, password (hash), name (optional), account id, session tokenPerformance of a contract
Syncing your learning record across devicesProgress data (XP, completed lessons, streak, hearts, review schedule)Performance of a contract
Personalising content from your taste picksOnboarding taste selections, native-language setting, answer about your level in the language you are learningPerformance of a contract
Sending essential service email (password reset)Email addressPerformance of a contract
Running the friend-referral programme and settling rewardsReferring account id, invitee's email address, hashed sign-up IPLegitimate interests (fraud prevention), consent for the invite email
Learning reminders and, where you opted in, promotional notificationsPush token, device time zone and language, app version, notification settings and consent timestampPerformance of a contract; consent for promotional messages
Improving quality and diagnosing errorsDe-identified event records (session id, event name and non-identifying properties, platform, app version)Legitimate interests
Processing in-app purchases and payment disputesProduct id, transaction id, store platformPerformance of a contract; legal obligation
Reviewing reports about AI answersThe reported sentence and a short surrounding excerptLegitimate interests (service safety)
Identifying Apps in Toss mini-app users and managing daily usageToss anonymous key (a hash issued by the Toss app — the server only verifies it and never stores the raw value); a usage-counting identifier derived from it with our secret keyLegitimate interests (abuse prevention)
Speech recognition for speaking practice in the Apps in Toss mini-appThe audio recorded in a speaking round; the language code of the language being learnedPerformance of a contract

2. Data we collect

TypeItemCollected when
RequiredEmail address, password (stored only as an irreversible bcrypt hash; the plaintext is never kept)Sign-up
OptionalNameSign-up and profile editing
Required (generated)Account id, sign-up timestamp, session token and session epochSign-up and sign-in

Generated automatically while you use the Service:

  • Learning record — XP, completed lessons, streak, taste picks, hearts, review schedule
  • Usage analytics — session id, event name and non-identifying properties, platform (iOS/Android/web), app version. No email, name or free text is ever placed in an event.
  • Notification data — push token, device time zone and language, app version (only if you enable notifications)
  • In-app purchase records — product id, transaction id, store platform
  • Referral records — the referring account and the invitee's email address
  • A hash of the IP address used at sign-up — the raw address is never stored anywhere; only an HMAC of it is kept, solely to detect self-referrals and bulk sign-ups made for referral rewards
  • AI report records — only if you use the report button: the reported sentence and a short surrounding excerpt
  • Error and crash records — technical details captured when the app or site fails, so we can find the cause: error name and message, the list of code locations involved, screen path, platform, app version and session id. Strings that look like email addresses and long tokens are masked automatically before storage. Deleted automatically 90 days after collection.
  • Server logs — access records written automatically by our hosting provider (request path, response code, timestamp, IP address)

If you use the Apps in Toss mini-app, no account is created, so none of the email, password or name items in the table above are collected. Instead the following are processed (details in section 10-2).

  • Toss anonymous key — a per-user hash the Toss app issues to the mini-app. It accompanies read-aloud and speaking requests to our server; the server only asks Toss whether it is valid and never stores the raw value. To count daily usage we keep only a value re-hashed with our secret key (irreversible), together with a per-day count
  • Speaking-round recordings — the mini-app has no on-device speech recognition, so the audio you speak is received by our server and forwarded to the speech-recognition processor in section 5 to be turned into text. Neither we nor the processor stores the audio; it is discarded as soon as it has been recognised
  • Progress and settings — kept only in the mini-app storage inside the Toss app, never on our servers

We do not collect special-category/sensitive data or government identifiers, and we do not collect advertising identifiers (ADID/IDFA) or location data. In the iOS/Android apps and on the web, microphone audio in speaking practice is processed on your device only (see section 10) and is never collected; the exception for the Apps in Toss mini-app is in section 10-2.

3. Retention periods

We process and retain personal data within the retention period required by law or agreed with you when the data was collected.

DataRetentionBasis
Account and learning recordUntil you delete your account — deleted from the database immediately on deletionConsent / contract (purpose fulfilled)
Referral record (invitee's email address)30 days from the day the invite was sentConsent; reward settlement
Hashed sign-up IPUntil account deletion (removed with the account row)Legitimate interests (fraud prevention)
Push token and notification settingsUntil you turn notifications off or delete your accountConsent
Marketing consent and withdrawal timestampsUntil account deletionNetwork Act Art. 50 (proof of consent)
De-identified usage analytics24 months from collectionLegitimate interests
Error and crash records90 daysLegitimate interests (service reliability)
Server access logs3 monthsProtection of Communications Secrets Act Art. 15-2
Usage counts derived from the Toss anonymous key (Apps in Toss mini-app)24 months from collection — kept only as per-day counts; the raw key is never stored and the derived value cannot be produced or reversed without our secret keyLegitimate interests (abuse prevention, usage management)
Speaking-round recordings (Apps in Toss mini-app)Not stored — discarded as soon as recognisedPerformance of a contract
Contract and withdrawal-of-subscription records5 years (if you made a paid purchase)Korean E-Commerce Act
Payment and supply-of-goods records5 years (if you made a paid purchase)Korean E-Commerce Act
Consumer complaint and dispute records3 yearsKorean E-Commerce Act

We do not automatically archive or delete dormant accounts. You may delete your account at any time (section 8).

4. Disclosure to third parties

We do not sell or share your personal information, including for cross-context behavioural advertising as those terms are used in the CCPA/CPRA, and we have not done so in the preceding twelve months. We disclose personal data to third parties only with your separate consent or where the law specifically requires it (PIPA Arts. 17 and 18). Where we are compelled by a lawful request from an authority, we notify the affected user unless legally prohibited from doing so. Processing carried out on our behalf by service providers is listed in section 5.

5. Processors

To run the Service we entrust the following processing to the providers below.

ProcessorTaskData entrustedRetention
Supabase, Inc.Database hosting for accounts and learning recordsAll account data and learning records in section 2Until account deletion or end of contract
Vercel Inc.Web and API hosting and deliveryData contained in requests; access logs (IP, path, response code, timestamp)Until end of contract (access logs 3 months)
OpenAI, L.L.C.Generating AI tutor and Daily Talk replies, generating pronunciation tips, text-to-speech synthesis, speech recognition (STT) for speaking practice in the Apps in Toss mini-appText you type or say (the on-device transcript of your speech); conversation settings (level in the language you are learning, native language, chosen partner and scenario); sentences to be read aloud. In the Apps in Toss mini-app: the audio recorded in a speaking roundDiscarded immediately after processing (stored by neither party)
Google LLC (Gemini)Generating AI replies and pronunciation tips (alternate provider); speech synthesis (fallback path)Same items as the OpenAI row aboveDiscarded immediately after processing
Groq, Inc.Generating AI replies and pronunciation tips (alternate provider)Text you type or say; conversation settingsDiscarded immediately after processing
650 Industries, Inc. (Expo Push)Delivering push notificationsDevice push token, notification contentUntil notifications are disabled or the account is deleted
Resend, Inc.Sending essential service email and referral invitationsEmail address, message bodyThe provider's log-retention period after sending
RevenueCat, Inc.Validating in-app purchase receiptsPurchase history, app user idFor the duration of payment-dispute handling
Apple Inc. · Google LLCIn-app payment processing and receipts; push delivery (APNs/FCM)Store account identifier, transaction data, push tokenPer each company's policy

Each processing agreement records, as PIPA Article 26 requires, the prohibition on processing beyond the entrusted purpose, technical and administrative safeguards, restrictions on sub-processing, supervision of the processor, and liability. We publish any change of processor on this page.

Confirmation that our AI processors provide equal protection — we send data to the AI processors above (OpenAI, Google, Groq) only after confirming that they provide protection equal to or greater than our own. Specifically, we confirm and contractually require that they (i) do not use the data for model training, (ii) do not use it for any purpose beyond generating the requested reply, (iii) apply technical and administrative safeguards including transport encryption (TLS) and access control, and (iv) restrict sub-processing and notify us of any incident. These commitments come from each provider's business (API) terms and data-processing addendum, and we re-verify them periodically.

Verifying the Toss anonymous key — the anonymous key used by the Apps in Toss mini-app is issued by the operator of the Toss app (Viva Republica Inc.), and our server asks Toss's partner API whether a key is valid. This is a platform function Toss provides for its mini-apps, not processing we entrust to Toss; the handling of personal data inside the Toss app is governed by Toss's own privacy policy.

6. International transfers

Most of the processors in section 5 are incorporated and operate servers outside Korea, so personal data is transferred abroad to the extent needed to run the Service (PIPA Art. 28-8). There are two legal grounds: processing and storage entrusted for the performance of the Service (database and server hosting, read-aloud synthesis, speech recognition in the Apps in Toss mini-app, notification and email delivery) rests on Art. 28-8(1)(iii) and is disclosed through this policy, while transfers for the AI tutor, Daily Talk and pronunciation coaching rest on Art. 28-8(1)(i) and require your separate in-app consent (section 10). For transfers from the EEA/UK we rely on the European Commission's Standard Contractual Clauses included in each provider's data processing agreement.

RecipientCountryWhen and howDataPurposeRetention
Supabase, Inc. (privacy@supabase.io)United States (data is stored in the Seoul region `ap-northeast-2`; remote administrative access may occur from the US)Continuously, over HTTPS/TLS, whenever you sign in or sync progressAccount data and learning recordsDatabase hostingUntil account deletion
Vercel Inc. (privacy@vercel.com)United StatesContinuously, over HTTPS/TLS, whenever you use the ServiceData in requests, access logsWeb and API hostingUntil end of contract (logs 3 months)
Google LLCUnited StatesAlternate/fallback provider — same trigger and method as the OpenAI row below. In the Apps in Toss mini-app used only as the fallback path for read-aloud; recorded audio is never sentSame items as the OpenAI row below (excluding recorded audio)AI replies and speech synthesisDiscarded immediately
Groq, Inc. (privacy@groq.com)United StatesAlternate provider — same trigger and methodText you type or say; level in the language you are learning, native language, chosen partner and scenarioAI repliesDiscarded immediately
OpenAI, L.L.C. (privacy@openai.com)United StatesAfter you consent to AI sharing inside the app, over HTTPS/TLS at the moment you use AI conversation, pronunciation coaching or read-aloud. In the Apps in Toss mini-app: a study sentence is sent when read-aloud plays, and the recorded audio is sent when you grant microphone permission and start a speaking round, by the same methodText you type or say (the on-device transcript of your speech); level in the language you are learning, native language, chosen partner and scenario; sentences to be read. In the Apps in Toss mini-app: the audio recorded in a speaking roundAI replies, speech synthesis, speech recognition (Apps in Toss mini-app)Discarded immediately
650 Industries, Inc. (privacy@expo.dev)United StatesOver HTTPS/TLS, when a notification is sentPush token, notification contentPush deliveryUntil notifications off / account deleted
Resend, Inc. (privacy@resend.com)United StatesOver HTTPS/TLS, when an email is sentEmail address, message bodyService and invitation emailThe provider's log-retention period
RevenueCat, Inc. (support@revenuecat.com)United StatesOver HTTPS/TLS, at the moment of purchasePurchase history, app user idReceipt validationPayment-dispute handling period
Apple Inc. · Google LLCUnited StatesOver each platform's encrypted channel, at purchase or notification deliveryStore account identifier, transaction data, push tokenPayment processing and push deliveryPer each company's policy

How to refuse a transfer — storing your account and learning record (rows 1–2) is essential to the Service, so refusing it means you cannot register or sync progress. Every other transfer can be refused by turning the feature off: Settings > Sound to disable AI voice, simply not using the AI tutor, and Settings > Notifications to disable notifications. Refusing these does not restrict the rest of the learning features.

Refusing in the Apps in Toss mini-app — the mini-app has no AI conversation feature, so nothing you write is transmitted. The transfer of speaking-round audio does not happen if you decline microphone permission; only that round is skipped and the rest of the lesson continues. Read-aloud in the mini-app uses server AI voice only (there is no built-in device voice), so the transfer of app-authored study sentences cannot be refused other than by not using the mini-app — those sentences contain none of your personal data. Account and learning-record storage (rows 1–2) does not occur in the mini-app. This notice is also available as a separate page.

7. Destruction of personal data

We destroy personal data without delay once the retention period expires or the purpose is fulfilled.

  • Procedure — when you delete your account, the account row and every learning record, referral record and purchase record attached to it are removed together by database cascade. Data we must keep by law is moved to separate storage and destroyed at the end of the statutory period.
  • Method — electronic files are erased permanently in a way that makes recovery impossible; any printed material is shredded or incinerated.
  • Backups — deleted data may persist in operational backups for up to 30 days and disappears when the backup expires. During that window backups are used for recovery only.

8. Your rights and how to exercise them

You may at any time request access to, correction of, deletion of, or suspension of the processing of your personal data, and you may object to processing based on legitimate interests and request data portability. We respond without delay and in any case within 10 days of receiving your request. EEA/UK users may also lodge a complaint with their supervisory authority; California residents may exercise the CCPA rights of access, deletion, correction and opt-out (we do not sell or share personal information) and will not be discriminated against for doing so.

What you want to doHow
Check or edit your account detailsSettings > Account
View your learning recordProfile screen (record and calendar)
Change your passwordSign-in screen > Forgot your password > reset via the emailed link
Change or withdraw notification consentSettings > Notifications
Delete your account and personal dataSettings > Account > Delete account, or the account deletion page
Any other access, correction, deletion or objection requestEmail contact@apochopo.com from the address you registered with

You may act through a legal representative or an authorised agent, in which case we require evidence of the authorisation. We verify that a person making a request is the data subject or a legitimate representative.

9. Cookies and other automatic collection

MechanismWhat it doesHow to refuse
Essential session cookie (httpOnly, SameSite=Lax, Secure)Keeps you signed in on the webYou can block cookies in your browser, but sign-in will not persist and the Service becomes unusable
Session token (app)Keeps you signed in; stored only in the iOS Keychain / Android KeystoreSign out in Settings > Account
localStorageHolds pre-sign-in progress and display settings on your deviceClear site data in your browser
Usage analytics eventsDe-identified counts of screen views and feature useCan be disabled globally by configuration; events never contain identifying data
Mini-app storage (Apps in Toss Storage)Holds progress and settings inside the Toss app when you use the Apps in Toss mini-app; never sent to our serversDeleted together with the mini-app when you remove it from the Toss app

We use no advertising or tracking cookies, no advertising identifiers (ADID/IDFA), and we do not collect or share behavioural data for targeted advertising. No third-party advertising or analytics SDK is bundled in the app.

10. Speech features and the AI tutor

In speaking practice in the iOS/Android apps and on the web, microphone audio is processed entirely on your device. Your device's own speech recognition converts it to text, which is compared with the answer; the recorded audio is never transmitted or stored. Microphone permission is requested only the first time you start this exercise, and declining simply skips those questions with no penalty. The Apps in Toss mini-app, which has no on-device speech recognition, is governed by section 10-2.

Consent before any AI sharing — the AI tutor (Talk), Daily Talk and pronunciation coaching can only answer by forwarding your text to the AI providers listed in section 5. Before any sentence is sent, the app shows a separate in-app consent screen stating (i) what data is sent, (ii) who it is sent to, and (iii) what is not sent, and asks for your permission. If you decline, only those three features are locked — lessons, review and listening practice keep working — and the server blocks the AI requests, so nothing is transmitted. You can withdraw consent at any time in Settings > AI conversation, and the same block applies immediately.

  • What is sent — the text you type, the text your device transcribes from your speech, and the settings the conversation needs (level in the language you are learning, native language, the partner and scenario you chose).
  • What is NOT sent — account identifiers such as your email address and name, and your learning history, are never sent to an AI provider. In the iOS/Android apps and on the web, microphone audio itself never leaves your device (speech recognition runs on-device only).
  • Who receives it and why — the AI processors in sections 5 and 6 (primary provider: OpenAI, L.L.C., United States), solely to generate the reply or tip, and discarded immediately after processing.

Conversations are kept on your device only, are not part of progress sync, and our servers do not store them. If you report an inappropriate answer, only the reported sentence and a short surrounding excerpt are stored for review.

Read-aloud uses server AI voice by default. What it sends is an app-authored study sentence or the AI reply just generated — never text you wrote yourself. Turning off 'AI voice (online)' in Settings > Sound switches to your device's built-in voice, after which no sentence leaves the device.

Generative AI notice and labelling — we use generative AI to (i) write lesson questions, options, explanations and context notes, (ii) generate replies in the AI tutor, Today's Talk and pronunciation coaching, and (iii) synthesize read-aloud voices. Under Article 31 of the Korean Framework Act on Artificial Intelligence we give you this notice in the app the first time you use the Service (and keep it permanently available in Settings), and we label the output in the way that fits it: output generated on the spot (AI tutor, Today's Talk, calls, pronunciation tips) carries an "AI-generated" label on the screen where it appears, while content we prepared in advance (lesson questions and read-aloud speech) is disclosed through that prior notice and the permanent notice in Settings — the Enforcement Decree allows this label to take any form a person or a machine can read, including in-UI display and an initial notice. This is not the same thing as the prior consent above — consent is about whether your sentences may be sent out; the label is about what you receive. Labelling therefore applies even if you decline consent.

We never provide your personal data or conversations to any AI provider for model training. We also make no automated decisions producing legal or similarly significant effects — difficulty and review scheduling are learning conveniences and do not affect your rights or obligations.

10-2. The Apps in Toss mini-app

The Learn Languages with Retriever mini-app offered inside the Toss app through "Apps in Toss" (the "mini-app") differs from the iOS/Android apps and the web in the ways below. For mini-app users this section prevails over the other sections of this policy.

  • There is no account. The mini-app has no sign-up or sign-in; you are identified solely by the Toss anonymous key the Toss app issues to the mini-app. We collect no account data such as an email address or name, and the key is not linked to any apochopo account. Our server verifies the key that accompanies a read-aloud or speaking request with Toss, then counts daily usage under a value re-hashed with our secret key; the raw key is never stored.
  • Your learning record stays on the device. Progress and settings are kept only in the mini-app storage inside the Toss app and are never sent to or synced with our servers. Removing the mini-app from the Toss app deletes them, and we cannot restore them.
  • Speaking practice audio goes through our server. The mini-app has no on-device speech recognition, so the audio recorded in a speaking round is received by our server and forwarded to the speech-recognition processor in sections 5 and 6 (OpenAI, L.L.C., United States) to be turned into text. Neither we nor the processor stores the audio; it is discarded as soon as it has been recognised, and the resulting text is used only to check your answer and is not stored. Microphone permission is requested the first time you start a speaking round; declining skips only that round, with no penalty.
  • Read-aloud uses server AI voice only. The mini-app has no built-in device voice, so the switch to device voice described in section 10 does not apply. What is sent is only an app-authored study sentence, never text you wrote.
  • The AI tutor, Daily Talk and pronunciation coaching are not offered in the mini-app. There is therefore no prior AI-sharing consent step in the mini-app, and nothing you type is ever sent to an AI provider.
  • No push notifications, email or in-app purchases. The mini-app is free, and we collect no push token, email address or purchase record from it. The error and crash records described in section 2 are collected in the mini-app on the same terms (identifying strings masked, deleted after 90 days). Friend invitations only create a link to share; the link carries a short code derived from the anonymous key, never the key itself.
  • Toss Login is not used. If we later adopt Toss Login (which would provide Toss account data such as your name), we will amend this policy in advance under section 16, describe the data collected and the deletion steps on unlinking or withdrawal, and ask for your separate consent in the app.
  • Your rights — since our servers hold no personal data that could identify a mini-app user, access, correction and deletion are exercised by removing the mini-app from the Toss app. For anything else, write to contact@apochopo.com.
  • The handling of personal data by the Apps in Toss platform and the Toss app itself (including issuing the anonymous key) is governed by the Toss operator's privacy policy.

11. Marketing messages

Promotional notifications (milestone congratulations, weekly summaries, widget tips) are sent only if you turn them on in Settings > Notifications, and we record the time you consented, as Article 50 of Korea's Network Act requires. You can withdraw consent at any time on the same screen, and no promotional notification is sent between 21:00 and 08:00. Learning reminders (streak, review, goal and return-visit prompts) are part of providing the Service and do not require separate consent.

12. Children under 14

The Service is available only to users aged 14 or over, and we do not collect personal data from children under 14. You confirm you are 14 or older when you sign up. If we learn that an account belongs to a child under 14, we verify and delete the account and its personal data without delay. Guardians may write to contact@apochopo.com and we will act immediately.

13. Security measures

The measures below are actually in place, not aspirational.

  • Administrative — the number of people who handle personal data is kept to a minimum, access is limited to what the work requires, and this policy plus our internal baseline (`docs/SECURITY.md`) are updated whenever collected data or processors change.
  • Access control — every database table has Row Level Security enabled deny-by-default; only the server reads and writes, through a dedicated connection. No database key is shipped in the app or browser bundle, and all access goes through our own API.
  • Passwords — stored only as irreversible bcrypt hashes, so not even an operator can read them.
  • Session protection — session tokens are signature-verified and checked against a per-account epoch, so a password reset, a sign-out-everywhere, or account deletion invalidates every existing token at once. On mobile, tokens live only in the iOS Keychain / Android Keystore.
  • Encryption in transit — all traffic between the apps and our servers uses HTTPS/TLS only.
  • Data minimisation — analytics events carry no identifying data, and the sign-up IP is kept only as a hash.
  • Abuse protection — sign-up, sign-in and other authentication endpoints are rate-limited.

If we become aware of a breach we notify affected users of the data, timing and remedial steps without delay, report it to the supervisory authority as the law requires, and immediately invalidate affected sessions.

14. Data protection officer and contact

We have appointed the privacy officer below to take overall responsibility for personal data handling and to deal with complaints and remedies. You may direct any privacy-related enquiry arising from your use of the Service to this contact, and we will answer and act on it without delay.

  • Privacy officer: 윤민정
  • Contact: contact@apochopo.com
  • Controller: apochopo Inc. (주식회사 아포초포)
  • Representative: 윤민정
  • Business registration number: 178-86-04021
  • Address: 서울특별시 강남구 개포로 264, 107동 902호 (개포동, 개포래미안포레스트)

15. Remedies

In Korea you may seek help from the bodies below. Users elsewhere may also contact their local supervisory authority.

16. Changes to this policy

This policy applies from its effective date. We announce additions, deletions or corrections in the Service or on this page at least 7 days before they take effect, and at least 30 days before for changes that materially affect your rights.

VersionEffectiveChange
v14 July 2026First version
v228 August 2026Full alignment with PIPA Art. 30 disclosure items — purpose/item/retention tables, processor and international-transfer tables (recipient, country, timing, method, data, retention), destruction procedure, rights and how to exercise them, automatic-collection mechanisms and how to refuse them, security measures, under-14 handling, remedies and a revision history. English version added
v34 September 2026Added prior in-app consent for AI sharing (section 10) — consent screen before any transmission, explicit lists of what is and is not sent, withdrawal in Settings and server-side blocking. Corrected the AI processor tables to the actual configuration (primary provider OpenAI) and added pronunciation coaching. Added confirmation that AI processors provide equal protection (section 5)
v46 September 2026Added the generative-AI notice and output labelling (section 10, Korean AI Framework Act Article 31) — where AI is used, when and where the prior notice is given, and how output is labelled depending on what it is (on-screen label for real-time output; prior notice plus the permanent notice in Settings for pre-written content). Stated that this is separate from consent to AI transmission
v512 September 2026Added the Apps in Toss mini-app section (10-2) — identification by Toss anonymous key only (raw key never stored; a derived value for usage counting), learning record kept only in mini-app storage, speaking audio recognised via our server (OpenAI) and discarded immediately, read-aloud by server AI voice only, no AI conversation features and no Toss Login. Added mini-app items to sections 1, 2, 3, 5, 6 and 9. Stated the legal grounds for international transfers (PIPA Art. 28-8(1)(i) and (iii)) and published the transfer notice as a separate page
v619 September 2026Service name changed (apochopo daily → Learn Languages with Retriever) and the description of what you learn corrected (English → the language you are learning). The personal data we process, purposes, retention, processors and international transfers are unchanged

Effective date: 19 September 2026
Last revised: 19 September 2026 (announced 12 September 2026)

← Back