๐Ÿ›’ ๋ ˆ์‹œํ”ผ ์ƒ์„ธ ํŽ˜์ด์ง€ ์—…๋ฐ์ดํŠธ โ€” ์ปฌ๋ฆฌ ์ถ”๊ฐ€ & ์‡ผํ•‘ UI ๊ฐœ์„ ย 
Show more
Sign In

Hemogry Privacy Policy (Global)

H
Hemogry
์นดํ…Œ๊ณ ๋ฆฌ
  1. Notice
Hemogry Privacy Policy (Global)
Effective date: September 7, 2026
VIVIVAVA Inc. ("we", "us", "our") operates the Hemogry service (the "Service").
This Policy explains what personal information we collect, why we process it, who we share it with, how long we keep it, and what you can ask us to do about it.
We collect only what a given purpose needs, and we do not use personal information beyond the purposes set out here unless the law allows it or you have agreed to it.
This Policy applies globally. Where the law where you live gives you rights beyond those set out here, we honour those rights as that law requires.
This Policy is published on our website and is available inside the Service.
1. Who we are
Controller: VIVIVAVA Inc. (Hemogry)
Email: official@vivivava.co.kr
Registered address: #303, 107 Gwanggyo-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea
If the law requires it, we may appoint a representative in the EU or the UK and publish their contact details on our website.
2. What we collect
Section 2.1 is information you give us, 2.2 is information collected automatically while you use the Service, and 2.3 is information we generate when we process your requests.
2.1 Information you give us
(a) Account
- Required: email address, name or display name, the account identifier your social login provider issues
- Optional: the address of the profile image your social login provider hosts
(b) What you enter or send while using the Service
- Links to content you save, and the details that come with them (title, description, channel name, the creator's display name, account name and profile image address, and comments publicly attached to the content)
- Search terms you enter
- What you type in a conversation used to edit a recipe, and what the Service replies
- Content you choose to paste in
- Images you upload, including photos attached to a conversation and photos of dishes you cooked
- Posts, reviews and ratings you write
(c) Support, reports and partnership enquiries
- Optional: contact details you give us, the content of your enquiry, your device and app version, screenshots and logs you attach
- For partnership or advertising enquiries: company name, contact person's name, email address, phone number
(d) Payment
- The purchase receipt issued by the app store (purchase identifier, the store the purchase was made in, amount, purchase date). We do not collect card or bank account details ourselves.
(e) Receipt reward participation (only where the feature is offered and you choose to take part)
- Required: mobile phone number, the receipt images you submit, and the purchase details visible in them
You can decline to provide required items, in which case you may not be able to register or to use the part of the Service that needs them. Declining optional items does not restrict your use of the Service.
2.2 Information collected automatically
- Device information (operating system, browser, device model) and a device identifier
- IP address, cookies and session identifiers, access times, records of how you use the Service
- Records of how you interact with Service screens
- Error and crash records
- The device token used to send you notifications
- Language and region settings, notification settings
2.3 Information we generate
- Content hashes
- The output and scores of automated analysis and classification (for example cooking relevance, harmful content)
- Values that express features of content and conversations in numeric form
- Processing results and status values
- Risk signals used to prevent abuse (large volumes of requests in a short period, repeated requests from the same device or address, requests that look automated) and the records used to match those signals
- Account identifiers created while the Service is used, including temporary identifiers created under a guest access method
2.4 How we collect it
Through what you enter on Service screens, through the social login we offer (in which case the provider passes us the items in 2.1(a)), automatically while you use the Service, and through the channels you use to contact us.
2.5 Sensitive information and national identifiers
We do not ask for or collect sensitive or special category information as defined by the laws that apply, and we do not collect resident registration numbers or equivalent national identifiers. This does not cover information you choose to enter yourself in a post, a review, an enquiry or a conversation with the Service. Where you do enter such information, we process it only as far as we need to in order to handle that post or enquiry.
2.6 Information you enter yourself
Where you enter personal information yourself into a post, a review, an enquiry or a conversation with the Service, that information is there because you chose to put it there. Where the Service offers an area that is visible to other users, what you enter there can be seen by them according to its visibility setting, can be reached by search engines and other outside services, and may not be fully retrievable by us once others have shared it onward, so we suggest you do not enter anything you would rather not make public.
If you send us personal information we did not ask for, we use it only as far as we need to in order to deal with your request or enquiry, and we may delete anything that is not needed.
You should submit only content that you have the right to use in the Service.
3. Why we process it
- To register and identify you, manage your account, and prevent fraudulent sign-ups
- To provide and operate the Service, carry out the processing you request, and deliver the result
- To moderate content, detect and prevent abuse, and restrict accounts that repeatedly break the rules
- To improve the quality and security of the Service, to find and fix errors, and to check and improve the accuracy of automated processing
- To take payment, reconcile it, and manage your purchase history
- To answer your enquiries and reports and tell you the outcome
- To send you operational notices and notices the law requires
- To send marketing messages where you have agreed to receive them
- To analyse usage statistically, using information processed so that individuals can no longer be identified, and improve the Service on that basis
- To handle disputes and meet our legal obligations
4. Legal bases (for users in the EEA and the UK)
We process personal information on these bases:
- Performance of a contract, to provide the Service you asked for
- Legal obligation, for example accounting and tax
- Legitimate interests, including keeping the Service secure, detecting and preventing abuse, improving quality and reliability, and handling disputes, where those interests are not overridden by your rights
- Consent, where consent is required, for example for marketing
You can withdraw consent at any time. Withdrawing it does not affect the lawfulness of processing carried out before you withdrew it, and where we process personal information on a basis other than consent, such as performing our contract with you or meeting a legal obligation, that processing continues on that basis.
We may further use or provide personal information within a scope reasonably related to the purpose for which it was originally collected. In deciding whether we can, we consider whether the further use is related to that original purpose, whether it was foreseeable given the circumstances of collection and our processing practices, whether it would unfairly harm your interests, and whether we have applied safeguards such as pseudonymisation or encryption.
5. Cookies, analytics and similar technologies
We use cookies, software development kits and similar technologies to keep you signed in, to keep the Service secure, and to understand how the Service is used.
Through these we collect device information, IP address, access times, records of how you use the Service, and records of how you interact with Service screens. Records of screen interaction may include what you enter on a screen or what is displayed on it.
You can refuse or delete cookies in your browser or operating system settings. Some features will not work if you do.
The Service may include content or features provided by other companies. Where it does, those companies may collect information directly from your device, and their own privacy terms apply to that collection. Where you use a social login, the provider's own privacy terms apply to your account with them and to the information they hold. The same is true of any external site or service you reach through a link in the Service.
6. Sharing and disclosure
Where applicable state law treats our sharing of personal information as a sale or share, you may ask us to stop it, and we handle such requests through the contact channel in section 14.
As a general rule we do not provide personal information to third parties, except in the cases below.
(a) Service providers who process personal information on our instructions
- Supabase Inc.: database operation and account authentication
- NAVER Cloud Corp.: operation of our service servers
- Vercel Inc.: web hosting and execution
- Amazon Web Services, Inc.: file storage and delivery
- 650 Industries, Inc.: relaying push notifications
- Mixpanel, Inc.: usage analytics
- Functional Software, Inc.: error and performance monitoring
- Slack Technologies, LLC: internal operational alerts
- Google LLC: web analytics, notification token issuance, social login, content analysis, recipe generation and editing and nutrition analysis using artificial intelligence models, operating our survey forms, and keeping records of participation in receipt-verification rewards
- NAVER Corp.: web analytics
- Cloudflare, Inc.: domain name service
- Apple Inc. and Google LLC: processing purchases made through their app stores
- Clerk, Inc.: authentication and management of creator accounts
- Meta Platforms, Inc.: authentication of creator accounts and connection of Instagram profiles
- Tally BV: operating the partnership and advertising enquiry form
We put terms in place with these providers as the law requires, whether in a contract or under each provider's standard data processing terms, and we publish changes to this list in this Policy.
(b) Law enforcement or government authorities, where the law requires it or where they make a lawful request
(c) A party involved in a merger, demerger, or a transfer of all or part of our business, where that party takes on the obligations in this Policy
(d) Anyone you ask us to share with, when you deliberately connect the Service to something external
Providing information in a statistical or other form from which individuals can no longer be identified is not a disclosure of personal information.
7. International transfers
We transfer personal information outside Korea in order to run the Service. The details are as follows.
The basis for these transfers is Article 28-8(1)3(a) of the Personal Information Protection Act. Processing or storage abroad is necessary to enter into and perform our contract with you, and we disclose the matters listed in Article 28-8(2) of that Act in this Policy, as set out below.
- Recipient: Mixpanel, Inc. / Country: United States / Items: account identifier, email address, name or display name, IP address, device information, usage records, screen interaction records / When and how: sent over the internet while you use the Service / Recipient's purpose: usage analytics / Recipient's retention period: usage records are kept for 5 years (2 years if our plan changes) and screen interaction records for 30 days, and data is deleted within 30 days of the end of our contract with the recipient. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: compliance@mixpanel.com
- Recipient: 650 Industries, Inc. / Country: United States / Items: notification device token, notification title and body / When and how: sent over the internet when a notification is sent / Recipient's purpose: relaying push notifications / Recipient's retention period: until the purpose of the transfer has been met or our contract with the recipient ends. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: https://expo.dev/contact (privacy enquiry form)
- Recipient: Functional Software, Inc. / Country: United States / Items: account identifier, device, operating system and app version, error records / When and how: sent over the internet when an error occurs / Recipient's purpose: error and performance monitoring / Recipient's retention period: up to 90 days. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: compliance@sentry.io
- Recipient: Slack Technologies, LLC / Country: United States / Items: the email address and content of an enquiry, the company name, contact name and phone number in a partnership enquiry, and the account identifier, IP address and device information where abuse is detected / When and how: sent over the internet when the relevant event occurs / Recipient's purpose: internal operational alerts / Recipient's retention period: until the purpose of the transfer has been met or our contract with the recipient ends. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: privacy@slack.com
- Recipient: Google LLC / Country: United States / Items: cookie identifier, IP address, device information, usage records, account identifier / When and how: sent over the internet while you use the Service / Recipient's purpose: web analytics, notification token issuance, social login / Recipient's retention period: web analytics data is kept for 14 months, and other data until the purpose of the transfer has been met or our contract with the recipient ends. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: googlekrsupport@google.com
- Recipient: Google LLC / Country: United States / Items: if you take part in a survey, your email address and the answers you give; if you take part in receipt-verification rewards, a pseudonymised member identifier, a partially masked phone number, and the record of your participation and payout / When and how: sent over the internet when you take part in a survey or in receipt-verification rewards / Recipient's purpose: operating our survey forms, and keeping records of participation in receipt-verification rewards / Recipient's retention period: until we delete those records. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: googlekrsupport@google.com
- Recipient: Google LLC / Country: United States / Items: what you enter in a conversation with an artificial intelligence feature and the photos you attach, the content you save and the details that come with it (including the creator's display name, account name and profile image, comments publicly attached to the content, and the video and image files of the saved content themselves), and recipe information / When and how: sent over the internet when you use the feature / Recipient's purpose: content analysis, recipe generation and editing and nutrition analysis using artificial intelligence models / Recipient's retention period: the recipient retains the prompts you enter and the responses for 55 days to detect and prevent prohibited use, and then deletes them. On the paid tier the recipient does not use the prompts or responses to improve its products or to train its models. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: googlekrsupport@google.com
- Recipient: Supabase Inc. / Country: the United States and any other country where the recipient or its sub-processors maintain facilities / Items: account identifier, email address, name or display name, the content you save, usage records and other information held in the database / When and how: stored over the internet while you use the Service, and accessible to the recipient from outside Korea for the operation and support of the Service / Recipient's purpose: database operation and account authentication / Recipient's retention period: until 30 days after our contract with the recipient ends, at which point the recipient deletes all copies. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: privacy@supabase.com
- Recipient: Amazon Web Services, Inc. / Country: the United States and any other country where the recipient has an affiliate that provides customer-initiated support / Items: the images and other files you upload / When and how: stored over the internet when you upload a file, and accessible to the recipient from outside Korea where we ask the recipient for support / Recipient's purpose: file storage and delivery / Recipient's retention period: until our contract with the recipient ends, and we retrieve or delete the files and close the account within 90 days of that date. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: aws-korea-privacy@amazon.com
- Recipient: Vercel Inc. / Country: the United States and any other country where the recipient or its subprocessors maintain data processing operations / Items: access records, IP address, device information and the information carried in web service requests / When and how: sent over the internet while you use the web service, and accessible to the recipient from outside Korea for the operation and support of the Service / Recipient's purpose: web hosting and execution / Recipient's retention period: until our contract with the recipient ends or expires, after which the recipient deletes the data within a commercially reasonable time. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: privacy@vercel.com
- Recipient: Clerk, Inc. / Country: United States / Items: a creator's account identifier, email address, name or display name, authentication and sign-in records, and the access token issued when a creator connects an external service account / When and how: sent over the internet when a creator signs up for or signs in to Creator Studio / Recipient's purpose: authentication and management of creator accounts / Recipient's retention period: the recipient deletes all copies within 90 days of the termination or expiry of our contract with the recipient, and will return a copy or make it available for download if we ask by the termination date. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: privacy@clerk.dev
- Recipient: Meta Platforms, Inc. / Country: the United States and any other country where the recipient maintains infrastructure or data centres / Items: the authorisation code and access token issued when a creator consents to connecting an Instagram account, and the connection information carried in that request / When and how: sent over the internet when a creator connects an Instagram account or when the connected account's details are retrieved / Recipient's purpose: authentication of creator accounts and connection of Instagram profiles / Recipient's retention period: the recipient does not state a fixed period and says it keeps information for as long as it is needed to provide its products or to comply with the law. Where deletion is requested, deletion can take up to 90 days, and removal from backup and disaster recovery systems can take up to a further 90 days / Recipient's contact: korealocalagent@support.facebook.com (Meta Communication Agent Ltd., the recipient's designated domestic representative in Korea, tel. 02-732-2947) or https://help.meta.com/support/privacy
- Recipient: Tally BV / Country: Belgium, the United States, and any other country where the recipient or its sub-processors maintain facilities / Items: the company name, contact name, email address, phone number, products and ingredients of interest, and consent to the collection and use of personal information given by a person who submits a partnership or advertising enquiry / When and how: sent over the internet when the enquiry form is submitted / Recipient's purpose: operating the partnership and advertising enquiry form and storing the enquiries received / Recipient's retention period: until we delete the enquiry, and anything we delete is also removed from the recipient's backups within 90 days. If our contract with the recipient ends, the recipient deletes or returns the enquiries at our choice. Some data may remain for a limited period under the recipient's own backup practices / Recipient's contact: hello@tally.so
The country above is the country where the recipient is incorporated. Where a recipient physically stores or processes the information may not be identifiable.
For Supabase Inc., Amazon Web Services, Inc. and Vercel Inc., the information is stored in Korea (Seoul), and the transfer takes the form of the recipient being able to access it from outside Korea for the operation and support of the Service.
You can object to your personal information being transferred abroad. Tell us using the contact in section 14 and we will explain how. Where a transfer is necessary to provide the Service, objecting means you will no longer be able to use all or part of it.
We apply the safeguards that the law and the contractual relationship actually applicable to a transfer require. This Policy does not represent that one particular contractual instrument or transfer mechanism is used in every case.
8. How long we keep it
We delete personal information without delay once the purpose it was collected for has been met, unless another law requires us to keep it or one of the periods below applies.
Periods we set ourselves:
- Records used to detect and prevent abuse, including the identifiers used to make that assessment and the history of any restrictions applied: kept until the purpose of preventing abuse has been met, which includes preventing abuse where an account is deleted and a new one is created. We use these records only for that purpose.
- Content moderation records: kept for as long as we need them to handle disputes and to prevent repeat breaches, then deleted or processed so that individuals can no longer be identified
- Conversation records used to edit recipes: kept until the purposes of providing and improving the Service have been met, then deleted or processed so that individuals can no longer be identified
- Search terms and recently viewed items: kept until you delete them or your account is deleted
- Temporary account identifiers created under a guest access method: kept until the purposes of operating the Service and preventing abuse have been met
- Records needed to resolve a dispute or to establish, exercise or defend a legal claim, where a dispute has arisen or is reasonably anticipated: kept until the dispute is concluded and the related claims can no longer be brought. We use these records only for that purpose.
Periods set by Korean law:
- Act on Consumer Protection in Electronic Commerce: records of contracts and withdrawal of subscription, 5 years; records of payment and supply, 5 years; records of consumer complaints and dispute handling, 3 years; records of labelling and advertising, 6 months
- Protection of Communications Secrets Act: service access logs, 3 months
9. How we delete it
Once the purpose has been met or the retention period has passed, we identify what is to be deleted and delete it without delay.
Personal information held as electronic files is deleted using methods that include processing it so that individuals can no longer be identified. Personal information on paper is shredded or incinerated. We decide the specific method, taking account of the type of information and the form in which it is stored.
Personal information can remain for a period in backups, caches, logs and the systems of the providers who process it for us. How long it remains and when it is deleted can vary with the policies and the actual operating practices of whoever runs each system, and with any retention period the law requires, and we do not identify or guarantee the deletion date of any individual system. During that period we do not use that information beyond what recovery and the running of that system require.
Some information remains after an account is deleted:
- Records kept to prevent repeat abuse. We use these only for that purpose.
- Records the law requires us to keep, for the period the law sets
- Usage records and information we generated, held with the link to the account removed. This can include the contents of conversations you had with the Service.
- Access logs kept to operate the Service and respond to incidents
Information already passed to a third party is handled under that company's own policy.
10. How we protect it
We encrypt personal information in transit.
We encrypt the object storage that holds files such as the images you upload at rest.
We grant and manage the permissions that allow access to personal information.
We create and keep access logs for systems that handle personal information.
We run monitoring to catch errors and unusual activity.
We define and manage who handles personal information.
No measure removes all risk. We decide what specific measures to apply and to what level, taking account of changes in technology, the nature of the Service and the degree of risk. We may withhold the detail of our security arrangements where publishing that detail would itself create risk.
11. Your rights
You can ask us to give you access to your personal information, correct it, delete it, stop processing it, or withdraw a consent you gave, as the law that applies to you provides. The legal representative of a child under 14 can make the same requests on the child's behalf.
If you are in the EEA or the UK, you also have the right to restrict or object to processing, the right to data portability, and the right to complain to your supervisory authority.
If you are in the United States, including California, you have the right to know what we collect, to access, correct, delete and port it, to opt out of any "sale" or "sharing" of personal information, and to limit the use of sensitive information. Where applicable state law treats our sharing of personal information as a sale or share, you may ask us to stop it, and we handle such requests through the contact channel in section 14.
You can also ask us to explain a decision made by automated processing, as the law that applies to you provides. Section 13 explains how we handle that.
For other regions we comply with local privacy law and honour the rights it gives you.
To exercise any of these rights, contact us using section 14. How to make a request, the steps involved, and what we need in order to verify you are set out in the guidance we give inside the Service or in our reply to you. If you contact us through another route, we may tell you how to submit the request, and the time we have to respond runs from the point it is submitted that way. So that we can confirm who you are, please write from the email address registered to your account or follow the verification steps we ask for. If someone is acting for you, send us something that shows they are authorised. Please keep your account and the credentials used to sign in secure, and do not let anyone else use them.
We respond within the time the applicable law allows. Where there is a proper reason to do so, we may extend that time as far as the law permits, and we will tell you why and for how long.
We may refuse a request in whole or in part where another law requires us to hold the information, where granting it would risk harm to another person's life or body, or would unfairly harm another person's property or other interests, where we cannot confirm that you are the person the information relates to or someone properly authorised to act for them, where stopping the processing would make it impracticable to perform our contract with you and you have not made clear that you wish to end it, or where the law otherwise allows. If we refuse, we tell you why.
Withdrawing consent or asking us to stop processing may mean you can no longer use all or part of the Service that relies on that information.
12. Children
The Service is not intended for children under 14. A higher minimum age may apply where the law where you live requires it.
We do not knowingly collect personal information from children under 14. If we confirm that we hold personal information from a child under 14, we delete it without delay. You can tell us about this using the contact in section 14.
13. Automated processing
Hemogry uses automated processing, including profiling, to turn the content you submit into a result, to identify content that is harmful or falls outside the purpose of the Service, and to identify use that appears abusive. This processing applies to everyone who uses the Service.
The criteria and procedure are as follows. Features found in the content and in usage records are compared against criteria we set in advance, and the processing then follows that comparison. The information this produces is described in section 2.3.
You can ask us to explain the outcome of automated processing, and you can send us your views and ask us to consider whether we can take them into account in that processing. Send your request to the contact in section 14. We consider what steps are needed in accordance with the law that applies. Where processing that screens content does not produce a result, the effect is limited to that content, your account stays usable, and you can submit the same link again. There is no additional cost when you do.
We may change the criteria and the way automated processing works in order to provide and improve the Service. As a result, the outcome for the same content or the same activity may change over time.
The results of automated processing can be inaccurate or incomplete. Anything we do in one case does not create an obligation to do the same in another case.
14. How to contact us
Email: support@vivivava.co.kr
Personal information protection officer: Personal Information Protection Team
Team receiving and handling access requests and other rights requests: Personal Information Protection Team
Anyone whose personal information we process, whether or not they use the Service, can use this contact for privacy questions, complaints and remedies. We respond within the time the applicable law allows.
15. Changes to this Policy
We may update this Policy.
Where we do, we tell you the effective date and the substance of the change at least 7 days beforehand, by notice inside the Service or another appropriate means. Where the law requires a longer notice period or individual notice, we follow what the law sets.
Changes that do not adversely affect your rights, such as correcting an error, clarifying wording, or updating the name or contact details of a service provider, may take effect without advance notice. We make those changes known by publishing the updated Policy.
Earlier versions of this Policy are kept by the Company.
16. Device permissions in the mobile app
The mobile app asks for permission to reach information stored on your device and to use device features.
No permission is required in order to use the Service.
The optional permissions we ask for depend on the features of the app and on the features you use. The main ones and why we ask for them are set out below. The full list of permissions the app requests is shown on the listing the app store provides for the app and in your device's operating system settings.
- Camera and photos, so that you can take or choose a photo and add it to the Service
- Notifications, so that we can tell you when processing you requested is finished and send you Service notices
You can use the core features of the Service without granting these. Only the features that need a given permission will be unavailable. You can change permissions at any time in your device's operating system settings.
Regional Addendum
EEA and UK
We rely on performance of a contract, legal obligation, legitimate interests, or consent. Korea, where we process personal information, has been recognised by the European Commission as providing an adequate level of protection. You can exercise your rights by contacting us, or you can contact your local supervisory authority.
Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee reflecting the administrative cost of dealing with it, or decline to act on it, to the extent the applicable law allows. If we do, we will tell you why and how you can complain.
California (CCPA/CPRA)
The categories we collect include identifiers, internet or other electronic network activity, the output of the automated analysis and classification we run on the content you submit, and limited technical information. Where applicable state law treats our sharing of personal information as a sale or share, you may ask us to stop it, and we handle such requests through the contact channel in section 14.
End of Policy.
Hemogry
Subscribe to 'Hemogry'
Subscribe to my site to be the first to receive notifications and emails about the latest updates, including new posts.
Join Slashpage and subscribe to 'Hemogry'!
Subscribe
๐Ÿ‘