← Back to HomePrivacy Policy
Last Updated: July 15, 2026
⚠️ This document is currently in beta testing phase and some content may change when the service is officially launched.
Moeyo.ai (sole proprietorship, hereinafter referred to as "the Operator") complies with Korea's Personal Information Protection Act (PIPA) and related laws to legally process personal information and manage it securely for the protection of data subjects' freedom and rights. In accordance with Article 30 of the Personal Information Protection Act, the Operator establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards for personal information processing and to promptly and smoothly handle related complaints.
Article 1 (Purpose of Processing Personal Information)
The Operator processes personal information for the following purposes. The personal information being processed is not used for purposes other than those specified below, and if the purpose of use changes, necessary measures will be taken, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
- Membership Registration and Management
- Confirmation of membership registration intent, maintenance and management of membership qualifications
- Prevention of fraudulent use of services, various notifications
- Identity verification, handling of complaints and civil affairs
- Service Provision
- Upload and storage of biological observation images
- AI-based automatic species classification service
- Image clustering and personal collection management
- Species information search and recommendations
- AI Model Training and Service Improvement
- AI model training using uploaded images and metadata
- Species classification accuracy improvement
- New feature development and service quality improvement
- User behavior pattern analysis and personalized service provision
- Community Operation and Safety
- Providing and displaying community features such as posts, comments, and name suggestions
- Receiving and handling reports, and content moderation (hiding, unpublishing, deletion, etc.)
- Preventing abuse and misuse, and applying usage limits
- Marketing and Advertising (Optional, with separate consent)
- Development of new services and provision of customized services
- Provision of events and advertising information and participation opportunities
- Push notification delivery (service and marketing notifications)
- Statistics on service usage
Article 2 (Processing and Retention Period of Personal Information)
The Operator processes and retains personal information within the retention and use period stipulated by law or the retention and use period for which consent was obtained from data subjects when collecting personal information.
- Member Information
- Retention period: Until membership withdrawal
- Exception: Retained for the relevant period when retention is required by related laws
- Uploaded Content (Images, Metadata)
- Retention period: Until deletion is requested by the member or until membership withdrawal
- However, data already used for AI training is integrated into the model and cannot be individually deleted
- After membership withdrawal, data may be anonymized and retained for service improvement
- Report and Moderation Records
- Retention period: 3 years after report handling is completed (for dispute response and abuse prevention)
- A snapshot of the reported content as of the time of the report may be retained for handling purposes even if the content is later deleted
- Retention by Law
- Records related to contracts or withdrawal of offers: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records related to payment and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records related to consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
- Website visit records (log records): 3 months (Protection of Communications Secrets Act)
Article 3 (Categories of Personal Information Processed)
The Operator processes the following categories of personal information:
- Required Collection Items
- Email address (provided by Google OAuth2)
- Name or username (provided by Google OAuth2)
- Profile photo (provided by Google OAuth2, if selected)
- Information Automatically Collected During Service Use
- IP address, cookies, service usage records
- Access logs, visit date and time, browser information
- Device information (OS, screen resolution, etc.)
- Push notification device tokens (when notification consent is given)
- User-Uploaded Content and Metadata
- Image files
- EXIF Metadata:
- GPS coordinates (latitude, longitude, altitude)
- Reverse geocoded location information based on GPS coordinates (place names, administrative regions)
- Capture time (date and time)
- Camera model, lens information
- ISO, shutter speed, aperture values, etc.
- Information entered by users:
- Species classification information (AI automatic + manual entry)
- Tags, notes, observation records
- Privacy settings
- Community Activity Information
- Posts (episodes and questions), comments, comment reactions, and name suggestion/agreement (vote) records
- Report records (reporter, reported target, reason, and a snapshot of the reported content at the time of the report)
- Hidden-comment user list (users a member has hidden — visible only in the member's own settings)
- Friend designations and profile bookmark lists
⚠️ Important: GPS information included in uploaded images is automatically collected and will only be displayed to other users when the member selects "Make GPS information public" in settings. The default setting is private. Exact GPS coordinates are never sent to other users under any circumstances, and no location information (coordinates or place names) is stored or displayed on question ("ask for a name") posts.
Article 4 (Provision of Personal Information to Third Parties)
The Operator processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only in cases specified in Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or special provisions of law.
The Operator currently does not provide personal information to third parties.However, the following cases are exceptions:
- When required by law (court warrants, requests from investigative agencies, etc.)
- When there is explicit consent from the data subject
- Google Lens Integration: When a Member voluntarily chooses to use the Google Lens feature within the service, the relevant image is transmitted to Google. This occurs only by the Member's explicit choice, and the transmitted image is processed in accordance with Google's Privacy Policy.
Article 5 (Consignment of Personal Information Processing)
The Operator consigns personal information processing tasks as follows to provide smooth services. When concluding consignment contracts, the Operator specifies matters in documents such as contracts in accordance with Article 26 of the Personal Information Protection Act, including prohibition of processing personal information other than for the purpose of performing consigned tasks, technical and managerial protection measures, restrictions on re-consignment, management and supervision of trustees, and matters related to responsibilities such as damage compensation, and supervises whether trustees process personal information safely.
| Trustee | Consigned Tasks | Transfer Items | Transfer Method | Retention and Use Period |
|---|
| Cloudflare, Inc. | - Cloud storage and image processing - CDN services - Data storage location: United States | Image files, metadata | Network transmission during service use | Until termination of consignment contract |
| Google LLC | - Authentication service - Email sending service - Data storage location: United States | Email address, authentication information | Network transmission during service use | Until termination of consignment contract |
※ If the content of consigned tasks or trustees change, we will disclose this through this Privacy Policy without delay.
※ Members may refuse the international transfer of personal information; however, this may restrict the use of the Service (OAuth login, image storage, etc.). To refuse, please contact support@moeyo.ai.
Possibility of Future Infrastructure Changes: The Operator may migrate the entire infrastructure (cloud storage, databases, etc.) to other cloud providers depending on service operation conditions, and will notify in advance through announcements in such cases.
Article 6 (Destruction of Personal Information)
- The Operator destroys personal information without delay when it becomes unnecessary, such as when the retention period expires or the processing purpose is achieved.
- If personal information must be retained according to other laws despite the expiration of the retention period consented to by the data subject or achievement of the processing purpose, the Operator moves the personal information to a separate database (DB) or stores it in a different location.
- The procedures and methods for destroying personal information are as follows:
- Destruction Procedures: The Operator selects personal information for which reasons for destruction have occurred, and destroys personal information with approval from the Operator's Personal Information Protection Officer.
- Destruction Methods:
- Electronic file formats: Securely deleted so that it cannot be recovered or reproduced
- Records, printouts, documents, etc.: Shredded with a shredder or incinerated
- Special Cases Related to AI Training Data:
- Images and metadata used for AI model training undergo de-identification processing before being integrated into model weights, making it extremely difficult with current technology to remove individual data from the model.
- When membership is withdrawn or deletion is requested, original images and metadata will be destroyed immediately, but data already used for training may remain inside the model after anonymization.
- This is in accordance with the content utilization policy for service improvement consented to at the time of registration.
- The Operator may release trained AI models or their derivatives for research, education, open-source, or other purposes. The Operator takes reasonable technical measures to prevent extraction of individual data subjects' original data from published models.
Article 7 (Rights and Obligations of Data Subjects and Methods of Exercise)
- Data subjects may exercise the following personal information protection-related rights against the Operator at any time:
- Request for access to personal information
- Request for correction if there are errors
- Request for deletion
- Request for suspension of processing
- The exercise of rights under Paragraph 1 can be made to the Operator in writing, by email, etc. in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and the Operator will take action without delay.
- The exercise of rights under Paragraph 1 may be made through a legal representative of the data subject or an authorized agent. In this case, a power of attorney in accordance with Form No. 11 of the "Notice on Personal Information Processing Methods (No. 2020-7)" must be submitted.
- Members can directly perform the following tasks in the service settings page:
- View and modify personal information
- Delete uploaded images
- Set GPS information disclosure preferences
- Change copyright license
- Request membership withdrawal (permanently deleted after 30-day grace period)
- Requests for access to personal information and suspension of processing may be restricted by the rights of data subjects pursuant to Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
Article 8 (Security Measures for Personal Information)
The Operator takes the following technical, managerial, and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act:
- Managerial Measures
- Establishment and implementation of internal management plans
- Minimization and education of personal information handling staff
- Implementation of regular internal audits
- Technical Measures
- Personal information encryption: Passwords are encrypted and stored (using Google OAuth2)
- Installation of security programs to prevent personal information leakage and damage by hacking or computer viruses
- Transmission encryption through HTTPS protocol
- Secure token-based authentication system
- Defense systems against major web security vulnerabilities
- Installation and operation of access control systems
- Retention of access records and prevention of forgery and alteration
- Physical Measures
- Data storage using cloud infrastructure
- Operation of backup systems (data redundancy)
- Use of locking devices for documents and auxiliary storage media containing personal information
Article 9 (Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)
- The Operator uses 'cookies' that store usage information and retrieve it from time to time to provide individual customized services to users.
- Cookies are small pieces of information sent by the server used to operate the website to the user's computer browser and may be stored on the user's PC hard disk.
- Purpose of using cookies: Maintaining login status, analyzing service usage records, providing customized services
- Installation, operation, and rejection of cookies: You can reject cookie storage by setting options in Tools → Internet Options → Privacy menu at the top of your web browser.
- If you reject cookie storage: You may experience difficulties in using customized services.
Article 10 (Personal Information Protection Officer)
The Operator designates a Personal Information Protection Officer as follows to take overall responsibility for personal information processing tasks and to handle complaints and remedy damages of data subjects related to personal information processing.
Personal Information Protection Officer
- Name: Jaeho Lee
- Position: Representative
- Contact: support@moeyo.ai
- ※ Connected to the Personal Information Protection Department.
Data subjects may contact the Personal Information Protection Officer regarding all personal information protection-related inquiries, complaint handling, damage remedies, etc. that arise while using the Operator's services. The Operator will respond to and handle data subjects' inquiries without delay.
Article 11 (Request for Access to Personal Information)
- Data subjects may request access to personal information pursuant to Article 35 of the Personal Information Protection Act to the department below. The Operator will endeavor to process data subjects' requests for access to personal information promptly.
- Department for Receiving and Processing Personal Information Access Requests
- In addition to the department for receiving and processing access requests in Paragraph 1, data subjects may also request access to personal information through the Ministry of the Interior and Safety's 'Personal Information Protection Comprehensive Support Portal' website (www.privacy.go.kr).
Article 12 (Remedies for Rights Infringement)
Data subjects may apply for dispute resolution or consultation to receive remedies for personal information infringement. The following organizations are available for users in the Republic of Korea. Users in other regions may contact us at support@moeyo.ai for assistance with privacy-related inquiries.
- Personal Information Infringement Report Center (Operated by Korea Internet & Security Agency)
- Jurisdiction: Reporting personal information infringement, consultation requests
- Website: privacy.kisa.or.kr
- Phone: 118 (without area code)
- Address: 3F Personal Information Infringement Report Center, 9 Jinheung-gil, Naju-si, Jeollanam-do (58324), Republic of Korea
- Personal Information Dispute Mediation Committee
- Jurisdiction: Application for personal information dispute mediation, collective dispute mediation (civil resolution)
- Website: www.kopico.go.kr
- Phone: 1833-6972 (without area code)
- Address: 4F Government Complex Seoul, 209 Sejong-daero, Jongno-gu, Seoul (03171), Republic of Korea
- Supreme Prosecutors' Office Cybercrime Investigation Division
- Phone: 02-3480-3573
- Website: www.spo.go.kr
- National Police Agency Cyber Bureau
- Phone: 182 (without area code)
- Website: cyberbureau.police.go.kr
Any person whose rights or interests have been infringed by a disposition or inaction taken by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act may request an administrative appeal in accordance with the provisions of the Administrative Appeals Act.
Article 13 (Changes to Privacy Policy)
- This Privacy Policy shall be applied from the effective date, and if there are additions, deletions, or corrections according to laws and policies, they will be announced through the notice section at least 7 days before the implementation of the changes.
- However, if there are significant changes to the rights of data subjects, they will be announced at least 30 days in advance, and consent from data subjects may be obtained again if necessary.
Article 14 (Rights of International Users)
- California Residents (CCPA)
- The Operator does not sell members' personal information to third parties.
- California residents may request information about the categories of personal information collected, the purposes of use, and whether it has been provided to third parties.
- California residents may request deletion of their personal information, and the Operator will respond within a reasonable period.
- The Operator will not discriminate against members who exercise these rights.
- Japanese Residents (APPI)
- The Operator processes personal information in accordance with Japan's Act on the Protection of Personal Information (APPI).
- Personal information may be processed and stored in the Republic of Korea and the United States (where cloud infrastructure is located).
- Japanese residents may request access to, correction of, deletion of, or suspension of use of their personal information.
- International Data Transfers
- Members' personal information may be stored and processed on cloud infrastructure located in the United States for the purpose of providing the Service.
- The Operator may process and store data on servers located in South Korea, Japan, the United States, and other countries for service provision. Server locations may change based on operational needs.
- The Operator applies the same protective measures specified in this Policy when transferring data internationally.
Addendum
This Privacy Policy shall be effective from March 8, 2026.
Amended July 15, 2026 — added processing categories/purposes for community features (posts, comments, asking for a name) and the retention period for report and moderation records.
Contact
If you have any questions regarding personal information processing, please contact us:
Email: support@moeyo.ai
Website: https://moeyo.ai