MyFit Privacy Policy

This document is a translation of the Korean original. In the event of any discrepancy between this translation and the Korean original, the Korean original shall prevail.

Vibeline (Business Registration No.: 895-01-03886; the "Company") complies with applicable laws, including the Personal Information Protection Act of the Republic of Korea ("PIPA"), the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. of the Republic of Korea (the "Network Act"), and the Act on the Consumer Protection in Electronic Commerce, Etc. of the Republic of Korea (the "E-Commerce Act"), and establishes and discloses this Privacy Policy as follows in order to protect users' personal information and respect their rights and interests.

This Policy applies to the mobile application myfit (the "Service") operated by the Company. myfit is a virtual fitting service that uses artificial intelligence (AI) to show users how clothing would look on them, based on a photo of themselves that the user uploads.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information is not used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent.

  1. Providing the AI virtual fitting service: Generating and providing virtual fitting result images by using AI to combine the photo uploaded by the user with the clothing the user has selected
  2. Member management: Sign-up and user identification/authentication, management of anonymous or SSO (Google, Apple, Kakao) accounts, blocking sign-up by children under 14 years of age, and preventing fraudulent use
  3. Payment and settlement: Processing in-app purchases of paid services such as credits and subscriptions, handling refunds and withdrawal of offers, and retaining transaction records
  4. Service operation and improvement: Improving quality through analysis of service usage records, monitoring errors and fraudulent use, and responding to customer inquiries
  5. Operating the referral (invitation) program: Granting and managing referral rewards through invitation codes
  6. Sending notifications: Providing service-related information via push notifications (where the user has consented)

Article 2 (Personal Information Items Processed)

The Company processes the following items of personal information.

1. Information the user directly enters or provides

CategoryItems collectedNotes
Uploaded photo of the userPhotos of the user uploaded as input for synthesis (may include the face and body)Used only as input for virtual fitting. Originals are not stored on the server (see Article 5)
Uploaded clothing photosPhotos of clothing uploaded by the user as input for synthesisUsed as input for virtual fitting and for handling customer inquiries. Retained for up to 90 days (see Article 5)
Account informationAnonymous identifier (ID) or SSO identifier (Google, Apple, Kakao), email addressIdentifier and email received from the relevant provider upon SSO sign-up
Date of birthDate of birthTo block sign-up by children under 14 years of age (age verification)
Payment informationIn-app purchase history (such as the product, the date and time of payment, and the transaction identifier)Payments themselves are processed through the app store's in-app purchase system, and the Company does not directly collect or store payment method details such as card numbers
Referral informationInvitation codeFor granting referral rewards

2. Information automatically generated or collected in the course of using the Service

CategoryItems collected
Device informationDevice model, OS version, device identifier, app version, language and country settings
Push tokenToken for sending push notifications (FCM/APNs)
Service usage recordsAccess date and time, feature usage history, fitting attempt records, error logs
Generated outputAI virtual fitting result images

Article 3 (Processing and Retention Periods of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by law or the retention and use period consented to by the user.

ItemRetention period
Uploaded photo of the userNot stored (processed in memory and discarded immediately)
Uploaded clothing photosRetained for up to 90 days to handle customer inquiries (such as synthesis errors and moderation decisions), then deleted automatically. If the user deletes the relevant fitting record, it is removed from the Service immediately, and the retained copy is also permanently deleted within the above period. Upon account deletion, permanently deleted after the deletion grace period (30 days)
AI virtual fitting result imagesRetained for up to 90 days after generation, then deleted automatically. If the user deletes them, they are immediately removed from the Service; retained copies are kept solely to prevent fraudulent use and respond to customer inquiries, and are permanently deleted within the above retention period (up to 90 days). Upon account deletion, permanently deleted after the deletion grace period (30 days)
Community posts (images and text)If the user deletes them, they are immediately removed from the Service, and retained copies are kept for up to 90 days from the date of deletion to handle reports and disputes, then permanently deleted. Upon account deletion, permanently deleted after the deletion grace period (30 days)
Account information (identifiers, email, date of birth)Until 30 days (grace period) have elapsed after account deletion
Device information, push tokens, service usage recordsUntil 30 days (grace period) have elapsed after account deletion (or the applicable period where a separate statutory retention obligation exists)
Payment and transaction recordsFor the period prescribed by applicable laws

Retention under applicable laws

In accordance with the E-Commerce Act and other applicable laws, the following information is retained for the periods specified below.

Article 4 (Provision of Personal Information to Third Parties)

The Company processes users' personal information only within the scope specified in Article 1 and does not provide personal information to third parties without the user's prior consent. The following cases are exceptions.

  1. Where the user has given prior consent
  2. Where there is a special provision in the law, or where an investigative agency makes a request for investigative purposes in accordance with the procedures and methods prescribed by law

Article 5 (Special Notice on Photo Processing)

Given the nature of a virtual fitting service, the Company separately provides the following notice regarding photo processing.

  1. User photos are not stored: The original photo of the user (the person) uploaded by the user is processed only temporarily in memory for synthesis, and is not stored anywhere, including the Company's servers and databases, and is discarded immediately after processing.

  2. Retention of clothing photos: Clothing photos uploaded by the user are retained for up to 90 days to facilitate the handling of customer inquiries, such as synthesis errors and moderation decisions, and are deleted automatically once that period has elapsed. If the user deletes the relevant fitting record, it is removed from the Service immediately, and the retained copy is also permanently deleted within the above period. Upon account deletion, it is permanently deleted after the deletion grace period (30 days).

  3. Retention of result images: AI virtual fitting result images are retained on the server for up to 90 days for the user's convenience in viewing and reuse, and are deleted automatically once the retention period has elapsed. If the user deletes them, they are immediately removed (no longer displayed) from the Service; retained copies are kept solely to prevent fraudulent use and respond to customer inquiries, and are permanently deleted within the above retention period (up to 90 days). Upon account deletion, they are permanently deleted after the deletion grace period (30 days).

  4. Exporting to the device photo library: Users may export result images to their own device photo library. Users are responsible for managing images saved on their devices.

  5. No processing of biometric information: The Company processes photos that include faces, but does not technically process them for the purpose of identifying or authenticating a specific individual (such as extracting facial feature points or creating biometric templates). Photos are used solely for the purpose of clothing synthesis (virtual fitting), and the Company therefore does not process them as biometric identification information (biometric data) under PIPA.

Article 6 (Outsourcing of Personal Information Processing and Cross-Border Transfers)

To provide the Service smoothly, the Company outsources personal information processing tasks as follows, and because some processors are located overseas, personal information is transferred abroad. When entering into outsourcing agreements, the Company stipulates the matters necessary to ensure that personal information is managed securely.

ProcessorCountry of transferItems transferredPurpose of outsourcing/transferRetention and use period
OpenAI, L.L.C.United StatesUploaded photos, synthesis request informationAI virtual fitting image synthesisUntil the purpose of processing is fulfilled (original photos are discarded immediately after synthesis)
Supabase, Inc.United StatesAccount information, result images, service usage records, and similar dataOperation of service infrastructure (authentication, database, servers)Until account deletion or termination of the outsourcing agreement
RevenueCat, Inc.United StatesPayment and transaction identifiers, device identifiersIn-app purchase and subscription management and settlementUntil account deletion or termination of the outsourcing agreement
Expo (Expo, Inc.) / Google (FCM, Android) / Apple (APNs, iOS)United StatesPush tokens, device informationDelivery of push notificationsUntil account deletion or termination of the outsourcing agreement
PostHog, Inc. (if used)United StatesService usage records, device informationService usage analysis and quality improvementUntil account deletion or termination of the outsourcing agreement

Article 7 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)

Users may exercise the following rights at any time.

  1. Request access to their personal information
  2. Request correction where there are errors
  3. Request deletion
  4. Request suspension of processing
  5. Withdraw consent and delete the account

These rights may be exercised through the in-app settings screen (e.g., My Page > Account/Privacy Management), or by contacting the Chief Privacy Officer or the responsible department in writing or by email (admin@vibeline.co.kr), and the Company will act without delay. If a user requests correction or deletion of personal information, the Company will not use or provide that personal information until the correction or deletion is completed. These rights may also be exercised through a legal representative or an authorized agent, in which case a power of attorney must be submitted.

If a request to exercise these rights may be restricted or refused under applicable laws, the Company will notify the user of the reason without delay.

Article 8 (Destruction of Personal Information)

  1. When personal information becomes unnecessary, such as upon expiration of the retention period or fulfillment of the purpose of processing, the Company destroys the personal information without delay.
  2. Information in electronic file form is permanently deleted using methods that make recovery or restoration impossible, and paper documents are shredded or incinerated.
  3. AI virtual fitting result images and uploaded clothing photos are automatically destroyed once up to 90 days have elapsed after generation (upload). Items deleted directly by the user are removed from the Service immediately; retained copies are kept solely to prevent fraudulent use and respond to customer inquiries, and are permanently destroyed within the above retention period (up to 90 days). Retained copies of community posts deleted directly by the user are permanently destroyed within up to 90 days from the date of deletion. Upon account deletion, they are permanently destroyed after the deletion grace period (30 days). Uploaded photos of the user are discarded immediately after synthesis, so no separate destruction procedure is required.

Article 8-2 (Account Deletion and Grace Period)

When a user requests account deletion, the Company immediately deactivates the account to suspend use of the Service and applies a 30-day grace period. During the grace period, the user may log in again to cancel (restore) the deletion. Once the grace period (30 days) has elapsed, the account, personal information, result images, community posts, and other data are permanently deleted (comments written by the user may be preserved with the author anonymized and displayed as a "deleted user"). However, payment and transaction records and other information subject to statutory retention obligations are retained for the applicable period.

Article 9 (Personal Information of Children Under 14)

The Company does not allow children under 14 years of age to sign up for or use the Service. The Company verifies age via date of birth at sign-up and blocks sign-up if the person is confirmed to be under 14 years of age. The Company does not operate a separate legal-representative consent procedure. If it is confirmed that personal information of a child under 14 years of age has been collected, the Company will destroy that information without delay.

Article 10 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information.

  1. Administrative measures: Establishing and implementing an internal management plan, minimizing the number of personnel handling personal information, and managing access privileges
  2. Technical measures: Managing access rights to personal information processing systems, encrypting data in transit, and implementing access controls and intrusion prevention
  3. Physical measures: Controlling access to data

In particular, by processing the uploaded original photo of the user (the person) only in memory without storing it on the server and discarding it immediately, the Company structurally minimizes the risk of exposure of potentially sensitive photo information.

Article 11 (Chief Privacy Officer)

The Company has designated the following Chief Privacy Officer (CPO) to take overall responsibility for personal information processing and to handle users' inquiries, complaints, and requests for remedies related to the processing of personal information.

Users may direct any inquiries, complaints, or requests for remedies concerning personal information protection arising in the course of using the Service to the officer above, and the Company will respond and take action without delay.

Article 12 (Remedies for Infringement of Rights and Interests)

Users may apply to the following organizations for dispute resolution or counseling in order to obtain relief from infringement of their personal information.

Article 13 (Changes to This Privacy Policy)

This Privacy Policy may be changed in accordance with changes in laws, policies, or the Service, and any changes will be announced through in-app notices or similar means. Where material changes are made, they will be announced at least 7 days before the effective date (or at least 30 days in advance in the case of changes unfavorable to users).