Privacy Policy
Last Updated: August 20, 2026 | Effective Date: September 4, 2026
1. Scope and Age Notice
This Privacy Policy applies to the "CUDDLES" mobile app for parents/guardians.
This app does not use the microphone function, and its screens are not designed for children to directly enter or provide personal information.
However, service data such as a child's voice and conversations may be generated, transmitted, and stored on our servers through a plush toy (device) linked to the guardian's account. In such cases, the processing, storage, and deletion of that data are subject to the choice and control of the guardian (legal representative), for example via in-app deletion features.
This app does not target children under the age of 14 (in the Republic of Korea) or under the age of 13 (in the United States) as direct service users, and where required by local laws, we comply with guardian consent and notice procedures.
2. Personal Information We Collect
(1) Account Registration / Account Management
Email address, password (hashed), nickname
(1-1) When Using Social Sign-In
If you sign in with a Google, Apple, or Naver account, we receive the following from that provider:
- Required: email address, the provider's unique identifier for you
- Optional: name or nickname, profile picture
We never receive your password and cannot see it. The email address is used to identify your
account and to link your orders.
If you choose “Hide My Email” with Apple, we receive a relay address
(@privaterelay.appleid.com) instead. Because that differs from the email you used at checkout,
past orders will not link automatically — you can link them yourself from My Account.
(2) Automatically Collected Information (Service Operation)
Device information (OS / model / app version), access IP, access date and time, app usage event logs, push tokens, advertising identifiers (AAID / IDFA)
(3) Children's Conversation Data (via Device Linking)
- Source: Plush toy (device) → linked to guardian's account
- Content: Voice recordings (audio data) and transcripts (text) of a child's conversations
- Processing: Collected voice (audio) data is stored encrypted in transit and at rest, and the
original is automatically deleted after 90 days. Where you have agreed, a separate
research copy is kept to improve speech recognition quality; in that copy account identifiers are
replaced with an irreversible speaker code and transcripts mask your child's nickname and the doll's
name. The audio itself, however, is kept as recorded — see
Section 3A for details and how to turn it off.
- Management: The guardian can optionally delete this data immediately from within the app
We do not currently collect any additional items beyond the above. Any future changes will be announced in advance and will be subject to required consents.
3. Purposes of Use
- Member identification and account management, service provision, maintenance, and improvement
- Customer support and error analysis (including ensuring stability and preventing misuse)
- Providing personalization and history based on children's conversation data (e.g., maintaining previous conversation context)
- (With optional consent) Notices, events, and marketing communications
- In-app advertising (AdMob) delivery and performance measurement (depending on personalized / non-personalized ad settings)
3A. Use for Research (Voice and Conversation Data)
To build a service that understands children better and responds more naturally, we pseudonymize or anonymize collected voice and conversation data and use it to improve our speech recognition and conversational models. This may include academic research.
We apply the following safeguards:
- Identifiers separated: Research copies replace account identifiers with an
irreversible speaker code, and transcripts mask your child's nickname and the
doll's name.
The audio itself, however, is kept as recorded. A voice can identify a person on its own, and a recording may contain your child saying their name. Altering the voice would make it useless for recognition research, so we describe this as severing the link, not anonymization. - No re-identification: We do not attempt to re-identify any individual from processed data, and we do not combine it with other information for that purpose.
- Source data stays private: Original audio recordings and raw transcripts are never provided or published externally. Access is limited to research and engineering personnel, and access is logged.
- Results may be published: Outputs of that research — statistics, performance metrics, analyses, papers, and technical reports — may be published in a form from which no individual can be identified or inferred. The underlying data itself is not published.
- Deletion stops research use: When a guardian deletes conversations, the research copies are deleted too, and research use of that data stops. We keep the link between a research copy and its original precisely so that a deletion request reaches the copy. On deletion, access is blocked immediately and temporary copies kept for recovery are fully deleted within 7 days. Only results already published (statistics, papers) cannot be recalled.
If you prefer that your data not be used for research, turn off “Voice research use” in your doll's settings in the app. No new research copies will be made, and copies already made are deleted when you delete those conversations. You may also email support@cuddles-anc.com. Doing so does not limit your use of the service in any way.
4. Retention and Destruction
- Account information: Destroyed without delay upon membership withdrawal
- Access logs / event logs: Retained for the minimum period required by applicable laws, and destroyed within a maximum of 3 years in accordance with our internal policy
- Children's voice (original): Automatically deleted 90 days after storage. If a guardian deletes it sooner, access is blocked immediately and it is fully deleted within 7 days. Encrypted in transit and at rest.
- Children's voice (research copy): Created only where you have agreed under Section 3A, and stored with account identifiers replaced by a speaker code. No fixed retention limit, but deleted when you turn research use off or delete those conversations.
- Children's conversation transcripts: Retained until the guardian requests deletion. In the app you can delete a single conversation, a date range, or everything.
- Transaction / payment records (in-app purchases): Retained for up to 5 years in accordance with applicable laws such as e-commerce regulations
- Destruction method: Electronic files are destroyed using technical methods that prevent recovery or reproduction; paper documents are destroyed by shredding, incineration, or similar physical methods
5. Provision to Third Parties (AdMob / Google Ads)
In principle, the Company does not provide users' personal information to third parties. However, the following third-party disclosures may occur for the purpose of serving in-app advertisements.
- Third party: Google LLC (AdMob / Google Ads)
- Purpose: In-app ad delivery and performance measurement (personalized / non-personalized advertising)
- Items provided: Advertising identifier (AAID / IDFA), device and app information, approximate IP / region, ad impression and click events, etc.
- Retention / Use period: In accordance with the third party's policies
※ You can change your consent to receive personalized ads at any time under App Settings > Privacy / Advertising.
6. Entrusted Processing (Processors)
To improve service quality, we entrust personal information processing tasks as follows.
| Processor | Google LLC (Google Cloud / Firebase) |
|---|---|
| Country | United States |
| Entrusted Task | Infrastructure provision and data storage / processing (hosting, database, authentication, etc.) |
7. Overseas Storage (Cross-Border Transfer)
To operate the service, we use Google Cloud Platform (including Firebase) infrastructure, and user information may be stored and processed on servers located in the United States.
- Recipient: Google LLC (GCP / Firebase)
- Country of transfer: United States
- Items transferred: Account information, service logs, children's conversation data (when linked), etc.
- Timing / Method of transfer: Real-time network transfer during service use
8. Payment (In-App Purchase) Notice
Paid purchases are processed through app store payment systems such as the Apple App Store and Google Play. The Company does not store sensitive payment information such as card numbers.
9. User Rights and How to Exercise Them
Users may request access to, correction of, deletion of, or suspension of processing of their personal information.
- Children's conversation data can be deleted immediately by the guardian from within the app, choosing a single conversation, a date range, or everything. Deleting also clears the audio, transcript, research copy, and the doll's memory summary, which is then rebuilt from the conversations that remain.
- When deletion may be refused: Material under a legal preservation obligation — such as a law enforcement request or preservation order — cannot be deleted. If you attempt deletion in that case, we tell you on screen that it was refused and why. We do not quietly retain it.
- Deletion records: We erase the content but keep the fact of it — when, what scope, and how many items were deleted. No content is included.
- Account deletion can be performed directly from within the app.
- For any other requests, please contact support@cuddles-anc.com.
10. Security Measures
Transport encryption (TLS), one-way hashing of passwords, minimization of access privileges, access log management, and compliance with GCP / Firebase security policies.
11. Data Protection Officer and Contact
- Data Protection Officer: Hyunbae Jeon (CEO, Cuddles ANC Inc.)
- Email: support@cuddles-anc.com
- Phone: +82 32-721-4434
12. Notice and Amendments
If there are any additions, deletions, or modifications to this Policy, we will notify users via an in-app announcement starting at least 7 days before the effective date. For material changes to user rights, we will provide notice at least 30 days in advance.