Calibre Signal Privacy Policy
opus89 (the "Operator") protects the personal information of users of the mobile application "Calibre Signal" (the "Service") in accordance with applicable law, including the Personal Information Protection Act of the Republic of Korea, and maintains this policy as follows.
1. Personal Information Collected and Collection Methods
A. At sign-up (social login)
| Category | Items |
|---|---|
| Google login | Email address, name and profile photo (to the extent provided by the account), social account identifier |
| Apple login (when supported) | Email address (or private relay address), name, account identifier |
B. Generated or collected during use of the Service
| Category | Items |
|---|---|
| Information created by users | AI conversations, bookmarks, keyword alert settings, calendar reminders, report reactions |
| Usage records | Credit grant/deduction history, promotion and referral code usage records, login timestamps, app launch records (for daily usage aggregation) |
| Notifications (if allowed) | Push notification token |
Guests who are not signed in are automatically assigned an anonymous session identifier for browsing content. It is not linked to identity information such as an email address.
C. Items not collected
The Operator does not collect advertising identifiers (IDFA/AAID), location data, contacts, photos, or other on-device materials, and does not use third-party advertising or analytics SDKs.
2. Purposes of Processing
- Member identification, login persistence, and service provision (syncing bookmarks, alerts, reminders)
- Generating AI analysis and answers (processing questions and conversations entered by users)
- Settling credit grants/deductions and preventing abuse (multiple accounts, code misuse, etc.)
- Sending push notifications (where the user has allowed them)
- Producing service usage statistics (in aggregate form, such as daily user counts) and improving the Service
- Complying with legal obligations and responding to disputes
3. Retention and Use Periods
Principle: personal information is destroyed without delay upon membership withdrawal. As exceptions, the following are retained for the periods below.
| Item | Period | Basis |
|---|---|---|
| App launch records | Automatically destroyed after 180 days | Internal policy (once the statistical purpose is fulfilled) |
| AI conversations | Automatically destroyed 180 days after last use | Internal policy (cleanup of long-unused conversations) |
| Abuse-response records | 1 year | Internal policy (preventing recurrence) |
| Service access records (login records) | 3 months | Protection of Communications Secrets Act (Korea) |
| Records on contracts, withdrawal of offers, payment, and supply of goods | 5 years | E-Commerce Consumer Protection Act (Korea) |
| Records on consumer complaints and dispute resolution | 3 years | E-Commerce Consumer Protection Act (Korea) |
4. Outsourcing and Cross-Border Transfer
The Operator entrusts the processing of personal information to the companies below in order to provide the Service; where a contractor is an overseas entity, personal information may be transferred to and processed outside Korea. Users consent to this at sign-up; consent may be refused, but in that case use of the Service is restricted.
| Contractor (Country) | Entrusted work | Items transferred | Retention |
|---|---|---|---|
| Supabase, Inc. (US) | Database and authentication infrastructure (data servers: AWS Seoul region, Republic of Korea) | All items in Section 1 | Until the outsourcing contract ends |
| OpenAI, L.L.C. (US) | Generating AI answers and news analysis | Questions and conversations entered by users | Upon completion of processing |
| Perplexity AI, Inc. (US) | Generating deep-research answers | Questions entered by users | Upon completion of processing |
| Google LLC (US) | Social login authentication, data backup storage | Account identification data / encrypted backups | Until the outsourcing contract ends |
| Apple Inc. (US) (when supported) | Social login authentication | Account identification data | Until the outsourcing contract ends |
| 650 Industries, Inc. (Expo) (US) | Push notification delivery | Push tokens | Upon completion of processing |
| RevenueCat, Inc. (US) (upon paid launch) | In-app purchase validation and subscription state management | Store payment identification data | Until the outsourcing contract ends |
- The AI processing contractors (OpenAI, Perplexity) state that data sent via their APIs is not used for model training.
- The Operator does not sell or provide personal information to third parties, except where there is a lawful request based on applicable law.
5. Destruction and Separate Storage
- Personal information whose retention period has expired or whose processing purpose has been achieved (e.g., membership withdrawal) is destroyed without delay.
- Records that must be preserved by law under the exceptions in Section 3 are not destroyed but are stored separately from other personal information, access for purposes other than preservation is blocked, and they are destroyed without delay once the preservation period ends.
- Electronic files are deleted using methods that make recovery impossible.
- Personal information contained in backup media is destroyed progressively according to the backup retention cycle and is removed from backups within a maximum of 180 days from the point of destruction. Backup data is not used for any purpose other than recovery.
6. User Rights
- Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information.
- Membership withdrawal (consent revocation) can be done via the in-app account menu or the contact below; upon withdrawal, personal information is destroyed except for the exceptions in Section 3.
- Rights may be exercised by email (Section 9), and the Operator will act without delay.
7. Security Measures
- Encryption in transit: all communications are encrypted with TLS.
- Access control: the database is controlled with row-level security (RLS) so that users can access only their own data.
- On-device protection: login session data is stored encrypted in the device's secure storage (Keychain/Keystore).
- Minimized administrator access: the Operator's access to user data is limited to the minimum necessary for customer support and security response, and viewing private conversations leaves an audit record.
- Minimal collection: only the minimum information necessary to provide the Service is collected.
8. Children Under 14
The Operator does not collect personal information of children under the age of 14. Age (14 or older) is confirmed during sign-up, and any account identified as belonging to a child under 14 is destroyed without delay.
9. Privacy Officer
- Affiliation: opus89 (Representative)
- Name: to be finalized and announced before the effective date
- Email: [email protected]
Reports and consultations regarding privacy infringement may also be directed to the Korea Personal Information Infringement Report Center (privacy.kisa.or.kr, dial 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).
10. Changes to This Policy
If this policy is added to, deleted from, or modified, notice will be given via the Service or the website at least 7 days before the change takes effect (30 days for material changes).
Addendum — This policy takes effect on the official effective date (to be announced).
← CALIBRE SIGNAL Home