1. Purposes of processing personal information
The Operator processes personal information only to the extent necessary for the following purposes:
- Account registration with a Google account; sign-in with a Google account or a handle/email and password; identity verification; and account recovery
- Managing profiles and friend relationships, finding friends, and processing friend requests
- Publishing photos selected by users, providing friend feeds, and enabling likes on individual objects
- Service security, prevention of misuse, incident response, and handling inquiries
2. Personal information processed, collection methods, and retention periods
A. Information stored only on your device
| Information | Purpose | Retention period |
|---|---|---|
| Photos captured or directly selected by the user, object-recognition results and cropped images, object labels, captions, capture time, and theme | Providing photo-journal features such as CAM, FIELD, and REPORT | Until the user deletes an individual item, uses Delete All Data in the app, or uninstalls the app |
| Local copies of profile and friend information, and app settings | Offline use and preservation of preferences | Until the user uses Delete All Data in the app or uninstalls the app |
Object recognition and mask generation are performed on the device. seesun does not perform facial recognition or biometric analysis intended to identify a person. Photos and analysis results that the user does not save (publish) are not sent to the server.
B. Information processed on the server when sign-in or sharing features are used
| Category | Information processed | How it is collected | Retention period |
|---|---|---|---|
| Account information | Email address; for Google sign-in, the display name and email address associated with the Google account; account password (stored one-way encrypted by the authentication service); internal user identifier; and authentication session information | Collected when the user signs up or signs in with Google, sets a password during sign-up or in Settings, or signs in with a handle/email and password | Until membership withdrawal or completion of an account-deletion request |
| Profile information | Display name and username (@handle) | Entered directly by the user or prefilled from Google account information and confirmed by the user | Until membership withdrawal or completion of an account-deletion request |
| Post and social information | Photos published by the user and cropped object images, object labels, captions, themes, capture times, records of friend requests, acceptances and removals, and likes on individual objects | Collected when the user actively uses publishing, friend, or like features | Until the user deletes the relevant post, relationship, or like, or withdraws membership |
| Automatically generated information | Service access logs, including IP address, access time, request records, and device or app network-environment information | Generated automatically when connecting to the server | For the period necessary for security and incident response, then deleted after the log-retention period under the service provider’s applicable plan and policy |
You may decline to provide the information above; however, seesun is an account-based service, so use of the app will be limited in that case.
The server-side information above is necessary to provide the account and friend-sharing services selected by the user. It is processed under Article 15(1)(4) of the Personal Information Protection Act for the conclusion and performance of a contract. The Operator does not collect personal information for marketing or personalized advertising.
3. App permissions
| Permission | Required? | Purpose |
|---|---|---|
| Camera | Optional | Taking photos in the app. If denied, you may still use the system photo picker and other features. |
| Internet | Required when using sharing features | Sign-in, friend relationships, post uploads, and friend-feed synchronization |
Gallery import uses the Android system photo picker. The app does not request access to your entire photo library and can access only the photos you directly select. The app does not request location, contacts, or microphone permissions.
4. Disclosure of personal information to third parties
As a rule, the Operator does not sell or disclose users’ personal information to third parties. However, when a user publishes a photo, the following information is shared with accepted friends:
| Recipient | Purpose | Information disclosed | Retention and use period |
|---|---|---|---|
| seesun friends whom the user has accepted or who have accepted the user | Providing the friend feed and interaction features | Display name, @handle, published photos, object images and labels, captions, themes, capture times, and object-specific like information | Until the friend relationship or relevant post or like is deleted |
Personal information may be disclosed in accordance with applicable law where a law contains a specific provision or where a law-enforcement or other authority submits a request through lawful procedures. If you publish a photo containing another person, you must take care not to infringe that person’s rights, including by obtaining any required consent.
5. Outsourcing of personal-information processing
The Operator entrusts the following operations to service providers for the smooth provision of the service:
| Service provider | Entrusted operations |
|---|---|
| Supabase Pte. Ltd. | Member authentication, database services, file storage, real-time synchronization, security logs, and server-infrastructure operation |
| Google LLC | Account selection and sign-in authentication when the user chooses Google sign-in |
Through processing agreements and service configuration, the Operator manages the providers to ensure compliance with applicable legal requirements, including restrictions on processing outside the stated purpose, technical and administrative safeguards, management of subprocessors, and deletion of personal information.
6. Overseas transfer of personal information
When the service is used, personal information is transferred to overseas cloud services as described below. If you do not want an overseas transfer, you may stop using the service: sign out or use Delete All Data in Settings, and request account deletion through the contact information below.
| Recipient | Country / location | Information transferred | Purpose | Timing and method | Retention period |
|---|---|---|---|---|---|
| Supabase Pte. Ltd. privacy@supabase.com | Japan (Tokyo AWS region) | Account, profile, post and social information, and access logs described in Section 2.B | Member authentication, database and file storage, synchronization, and security operations | Transferred through encrypted internet communications (HTTPS) when signing in, publishing, or synchronizing | Until the end of the applicable retention period for each item. After deletion, backup and log copies are automatically deleted when the retention period under the service policy expires. |
| Google LLC Google Privacy Policy | United States and other countries where Google provides services | Google sign-in request information, a one-time nonce, and authentication tokens | Google account sign-in authentication | Transferred through encrypted communications when the user chooses Google sign-in | Until the authentication purpose is fulfilled or for the retention period under Google’s policy |
The legal basis for overseas transfers is Article 28-8(1)(3) of the Personal Information Protection Act. This Privacy Policy discloses the processing delegation and storage necessary to conclude and perform the contract with the user.
7. Procedures and methods for destroying personal information
- Personal information is destroyed without delay when its retention period expires or its processing purpose is fulfilled.
- Electronic files are deleted so they cannot be recovered or reproduced. If paper documents are retained, they are shredded or incinerated.
- On-device information can be destroyed by deleting individual items, using Delete All Data in Settings, or uninstalling the app.
- Server posts can be deleted individually. Profiles, posts, friend relationships, and similar data can be destroyed by using Delete All Data or requesting account deletion.
- Copies remaining in backups or security logs are isolated, are not used except for recovery and security purposes, and are automatically deleted when the service provider’s retention period expires.
8. Rights of users and legal representatives, and how to exercise them
You may request access to, correction or deletion of, suspension of processing of, or withdrawal of consent regarding your personal information. In Settings, you may edit your profile, individually delete posts, likes, and friend relationships, or use Delete All Data. If a request cannot be completed directly in the app, send it to the contact address below from the email address used to register. After verifying your identity, the Operator will handle the request within the period prescribed by applicable law. Unless special circumstances apply, account and related-data deletion requests will be completed within seven days after the request is confirmed.
The in-app “Delete All Data” feature currently deletes device data and service data such as the server-side profile, posts, and friend relationships. To completely delete account-identification information remaining with the authentication service, request account deletion at the email address below.
9. Personal information of children under 14
seesun is not directed to children under 14 and does not knowingly collect personal information from children under 14 without consent from a legal representative. If the Operator learns that such information has been collected, it will verify and delete the information without delay.
10. Security measures for personal information
- Encryption of server communications (HTTPS) and blocking of plaintext communications
- Encryption of authentication sessions and key local settings using the device’s secure storage
- One-way hashing of account passwords (by the authentication service)
- Per-user access controls and least-privilege access for server data and files
- Exclusion of device data from operating-system backups and device-transfer processes
- No advertising, user-tracking, or analytics SDKs
11. Privacy officer and contact information
Send inquiries concerning personal-information processing, the exercise of rights, complaints, or remedies for harm to the contact below.
Privacy officer: nouvelle vague intelligence
Email: yoon7k3@gmail.com
For advice or reporting concerning other personal-information infringements, you may contact the following Korean authorities:
- Personal Information Infringement Report Center: 118 (no area code) · privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 · www.kopico.go.kr
- Korean National Police Cybercrime Reporting System: 182 (no area code) · ecrm.police.go.kr
12. Changes to this Privacy Policy
This Privacy Policy takes effect on July 31, 2026. If applicable law, the service, or the handling of personal information changes, the Operator will provide notice through the app or a public webpage before the change takes effect. Changes that materially affect users’ rights will be announced separately in an easy-to-understand manner.
Nouvelle Vague Intelligence