← Back to Home

Privacy Policy

Revised: September 29, 2026 · Effective: November 2, 2026 (for members who join after this Privacy Policy was posted, from the time they join)

This is an English translation. The Korean version governs.

For members who joined before this Privacy Policy was posted, the previous Privacy Policy (revised July 15, 2026) applies until November 1, 2026. You can see what has changed in the Addenda.

To protect the freedom and rights of data subjects, Moeyo.ai (a sole proprietorship; the “Operator”) complies with Korea’s Personal Information Protection Act and related laws, processes personal information lawfully, and manages it securely. Accordingly, under Article 30 of the Personal Information Protection Act, the Operator establishes and discloses this Privacy Policy as follows to inform data subjects of the procedures and standards for processing personal information and to handle related complaints promptly and smoothly.

Article 1 (Purposes of Processing Personal Information)

The Operator processes personal information for the following purposes. Personal information being processed is not used for any purpose other than the following, and if a purpose of use changes, the Operator will take the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.

  1. Membership registration and management
    • Confirming the intent to join, and maintaining and managing membership
    • Preventing fraudulent use of the Service, and sending various notices
    • Identity verification, and handling complaints and other requests
  2. Providing the Service
    • Image upload and storage
    • Providing the automatic classification service
    • Image clustering and personal collection management
    • Species information search and recommendations
    • Displaying and saving field record routes
    • Providing paid currency and subscriptions, and processing refunds (where offered)
  3. Improving the accuracy of Service features
    • Automatic classification and organization of photos
    • Duplicate cleanup
    • Accuracy of search and recommendations
    • Photo quality assessment and error detection
    • Improving (training) the classification program so that it recognizes photos more accurately, and checking its performance

    The scope of this processing, what is excluded from it, and how to turn it off are set out in Article 15. The results of this processing are not used for advertising targeted at individual members, and interest-based advertising is provided only with separate consent under Article 17.

  4. Community operation and safety
    • Providing and displaying community features such as posts, comments, and name suggestions
    • Receiving and handling reports, and content moderation (hiding, making private, deleting, etc.)
    • Preventing abuse and misuse, and applying usage limits
  5. Marketing and advertising (optional, with separate consent)
    • Developing new services and providing customized services
    • Providing event and advertising information and opportunities to participate
    • Sending push notifications (service notifications and marketing notifications)
    • Statistics on use of the Service
  6. Moeyo Studio early access updates (for those who apply; non-members may also apply)
    • Sending news about Moeyo Studio early access
    • Reference in preparing early access

Criteria for additional use: The Operator may make additional use of personal information to the extent reasonably related to the purpose for which it was collected, and decides this based on the following criteria: ① whether the use is related to the original purpose of collection; ② whether it is processing the member could anticipate; ③ whether it does not unfairly infringe the member’s interests; ④ whether safety measures such as pseudonymization and encryption have been taken. The processing under Article 15 is based on these criteria.

Article 2 (Processing and Retention Periods of Personal Information)

The Operator processes and retains personal information within the retention and use period set by law, or within the retention and use period to which the data subject consented when the personal information was collected.

  1. Member information
    • Retention period: until membership withdrawal
    • Exception: where retention is required by applicable laws, kept for the period required
  2. Uploaded content (images and metadata)
    • Retention period: until the member requests deletion or withdraws from membership
    • When a member requests deletion, the Operator removes the data without delay from the originals and from the materials used for training. Backup copies and temporary storage (caches) are deleted progressively on a set schedule. Removing only the part that an individual photo contributed to a model that has already been built is not possible with current technology; the deletion is reflected from the time the next model is rebuilt.
  3. Field records
    • Routes: if the member has agreed to the Location Information Terms and chosen to save to their account, until the member deletes them or withdraws from membership. Before consent, routes are stored only on the member’s device
    • Records confirming the use and provision of location information: at least 6 months (Act on the Protection, Use, etc. of Location Information)
    • Field record notes and photos: until the member requests deletion or withdraws from membership
  4. Data processed so that no one can tell who took it
    • Data processed under Article 15 so that individuals cannot be recognized is retained until the purpose of the processing is achieved
  5. Service usage analytics and login/security information
    • App and web usage records: 180 days
    • IP addresses and device (browser) information for login sessions: 30 days on the web, 90 days in the app
  6. Report and moderation records
    • Retention period: 3 years after the report has been handled (for responding to disputes and preventing recurrence)
    • The content of the reported material as it stood at the time of the report (a snapshot) may be kept to handle the report even if the material is deleted
  7. Moeyo Studio early access application information
    • Retention period: until early access updates have been completed or the applicant requests deletion (deletion requests: support@moeyo.ai)
  8. Retention required by law
    • Records on contracts, withdrawal of offers, and the like: 5 years (Act on Consumer Protection in Electronic Commerce)
    • Records on payment and the supply of goods, and the like: 5 years (Act on Consumer Protection in Electronic Commerce)
    • Records on consumer complaints or dispute handling: 3 years (Act on Consumer Protection in Electronic Commerce)
    • Website visit records (logs): 3 months (Protection of Communications Secrets Act)

Article 3 (Categories of Personal Information Processed)

The Operator processes the following personal information:

  1. Required items
    • Email address, name or username, profile photo (optional) — provided from the member’s Google or Apple account
    • For members who sign in with email: email address and password (stored only in a form that cannot be decrypted)
  2. Information collected automatically while the Service is used
    • IP address, cookies, Service usage records
    • Access logs, visit date and time, browser information
    • Device information (OS, screen resolution, etc.)
    • Push notification device token (if the member agrees to receive notifications)
  3. User-uploaded content and metadata
    • Image files
    • EXIF metadata:
      • GPS coordinates (latitude, longitude, altitude)
      • Location information reverse-geocoded from GPS coordinates (place names, administrative area names)
      • Capture time (date and time)
      • Camera model, lens information
      • ISO, shutter speed, aperture, etc.
    • Information entered by users:
      • Classification information (automatic classification + manual entry)
      • Tags, notes, observation records
      • Diaries, photo notes, episode bodies, and names and descriptions of personal subjects (people, pets, etc.) — of these, diaries, notes, episode bodies, and descriptions are encrypted when stored (Article 8)
      • Activity area on the profile (the area the member chose and its representative coordinates)
      • Visibility settings
  4. Community activity information
    • Posts (episodes and questions), comments, comment reactions, and records of name suggestions and agreement (votes)
    • Report records (reporter, reported target, reason, and a snapshot of the reported content at the time of the report)
    • Hidden-comment list (the users a member has hidden — visible only in the member’s own settings)
    • Friend designations and profile bookmark lists
  5. Field record information
    • Routes (latitude, longitude, accuracy, time recorded) — stored on the server only if the member has agreed to the Location Information Terms and chosen to save to their account (“Save to Lifebook” in the app); until then, routes remain only on the member’s device
    • Location information of photos taken during a field record — stored attached to the photo, in the same way as ordinary uploaded photos
    • Field record notes, weather and temperature entered by the member, and step count summaries (if the member chooses)
    • Other members whom the member designates as people who were with them — stored only as the member’s own record
  6. Payment-related information
    • A token that identifies the store account (a random value used in place of an email address or account ID)
    • Purchase, refund, and subscription renewal history (including receipt information sent by the store)
    • ※ Payment method information such as card numbers is processed by the App Store and Google Play, and the Operator does not keep it
  7. Service usage analytics
    • App and web usage records such as screen views and feature use, app installation identifier, language setting (retained for 180 days)
    • Install source information (the referral source when installed from an app store; the domain of the previous page and campaign tags when visiting the web)
    • Age range, gender, and how the member heard about Moeyo, as answered by the member in an optional survey (until account deletion; can be deleted in settings)
    • ※ Advertising identifiers (IDFA/GAID) are currently not collected (Article 17(5))
    • ※ Turning off the app’s “Usage analytics on this device” setting stops the collection of usage analytics sent by the app. Google Analytics on the web can be refused through browser settings or Google’s opt-out tool
  8. Login and security information
    • IP addresses and device (browser) information for login sessions — retained for 30 days on the web and 90 days in the app
    • Records kept when the Operator has checked a member’s records (Article 16)
  9. Moeyo Studio early access application information (for those who apply; not linked to a member account)
    • Required: email address
    • Optional: what the applicant mainly takes photos for (and the order of priority if they pick more than one), their affiliation, how many photos they have to organize, the computer they use (Windows/macOS), and any message they leave
    • Recorded automatically: page language, referral source tag, version of the consent text and time of consent, time of application and update, number of reapplications

Location information: GPS information included in uploaded images is collected automatically. Location information is not public by default, and members choose, for each record, whether to make it public and to what extent. Unless the member directly chooses to make the precise location public, precise GPS coordinates are not sent to other users. For species that need protection, the Operator may adjust the display so that the location is shown only as a wide area or not shown at all. Precise locations (coordinates) are not stored or displayed on posts asking for a name (question posts); to help others work out the name, only the name of a region at the level the member chooses (by default, the state or province) may be displayed.

Article 4 (Provision of Personal Information to Third Parties)

The Operator processes data subjects’ personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the data subject’s consent or under special provisions of law.

The Operator currently does not provide personal information to third parties. However, the following cases are exceptions:

  • When required by law (court warrants, requests from investigative agencies, etc.) — handled according to the principles in Article 16(1)
  • When the data subject has given explicit consent

Article 5 (Consignment of Personal Information Processing and International Transfers)

To provide the Service smoothly, the Operator consigns personal information processing tasks as follows. When concluding a consignment contract, the Operator specifies in the contract or other documents, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information for purposes other than performing the consigned tasks, technical and managerial safeguards, restrictions on re-consignment, management and supervision of the trustee, and responsibilities such as compensation for damages, and supervises whether the trustee processes personal information safely.

Trustee (country)Consigned tasksItems transferredRetention and use period
Cloudflare, Inc. (United States)Cloud storage, image processing, CDN, cache managementImage files, metadataUntil the consignment contract ends
Amazon Web Services, Inc. (United States)Transmission path (CloudFront) between the app/web and the Operator’s servers (API and automatic classification) — no cachingContent of transmitted requests (photos, records, etc.), IP addressNot stored (access logs are subject to that company’s policy)
Google LLC (United States)① Login authentication
② App and web usage statistics analysis (Google Analytics for Firebase, Google Analytics 4 — including the Operator’s own usage records sent from the Operator’s servers)
③ Map display on Android (Google Maps)
④ Push delivery on Android (FCM)
① Email and authentication information
② Usage records, app installation identifier, platform, version
③ Locations to be shown on the map
④ Push content and device tokens
Until the consignment contract ends
Apple Inc. (United States)Login authentication, push delivery on iOS (APNs), map display on iOS (MapKit)Authentication information, push content and device tokens, locations to be shown on the mapUntil the consignment contract ends
Resend, Inc. (United States)Sending email (account deletion notices and announcements)Email address, email contentUntil the consignment contract ends
Open-Meteo (Germany, free API)Automatic weather lookup for field records (where this feature is offered, and only when the member has saved the route to their account)Coordinates coarsened to two decimal places, dateNot stored
OpenFreeMap (web map tiles)Providing web map background tiles — requested directly by the browserThe map area being viewed, IP addressNot stored (subject to that company’s policy)
OpenAI (ChatGPT) · Google LLC (Gemini) · Anthropic PBC (Claude) · Apple Inc. (Apple Intelligence — may be processed on the device) (United States)Processing using AI tools: ① AI features the member requests or turns on (text summaries, explanations of name candidates, photo descriptions and organization, image generation, etc.) ② Handling inquiries and support (inquiries the member sends and records the member asks to have checked) ③ For content made public to everyone (public posts, public questions, etc.): filtering (assisting with spam, harmful content, and report review), analysis (usage trends, checking the accuracy of names, etc.), and automatic organization and descriptions. Records a member has not made public are sent only when the member has requested or consented, as in ① and ②. These tools are used only on terms under which the provider does not use members’ data to train its own modelsThe text and photos needed for that processingMay be kept for the abuse-prevention period set by the provider (subject to that company’s policy)

※ If the consigned tasks or the trustees change, the Operator will disclose this through this Privacy Policy without delay.

International transfer: Members’ personal information is processed and stored in the Republic of Korea (the Operator’s servers) and the United States (the trustees above), and temporary storage to speed up content delivery (CDN cache) may take place on servers in regions close to the member. If the trustees or processing locations change, this Policy will be updated to reflect it. The transfer takes place by transmission over the network when the Service is used. Members may refuse the international transfer, but in that case use of the Service, such as login and image storage, may be restricted. If you wish to refuse, please contact support@moeyo.ai.

Possible future infrastructure changes: Depending on how the Service is operated, the Operator may move its entire infrastructure (cloud storage, databases, etc.) to another cloud provider, and will give advance notice if it does so.

Article 6 (Destruction of Personal Information)

  1. When personal information is no longer needed, for example because the retention period has expired or the purpose of processing has been achieved, the Operator destroys it without delay.
  2. If personal information must continue to be retained under other laws even though the retention period consented to by the data subject has expired or the purpose of processing has been achieved, the Operator moves that personal information to a separate database (DB) or stores it in a different location.
  3. The procedures and methods for destroying personal information are as follows:
    • Destruction procedure: The Operator selects personal information for which a reason for destruction has arisen and destroys it with the approval of the Operator’s Personal Information Protection Officer.
    • Destruction methods:
      • Electronic files: securely deleted so that they cannot be recovered or reproduced
      • Records, printouts, paper documents, etc.: shredded or incinerated
  4. Data processed so that no one can tell who took it:
    • Data processed under Article 15 so that individuals cannot be recognized is not processed for the purpose of recognizing specific individuals, and information that could be used to re-identify it is kept separately.
    • When a member requests deletion, the Operator removes the data without delay from the originals and from the materials used for training, and excludes it from further processing. Backup copies and temporary storage (caches) are deleted progressively on a set schedule. Removing only the part that an individual photo contributed to a model that has already been built is not possible with current technology; the deletion is reflected from the time the next model is rebuilt.

Article 7 (Rights and Obligations of Data Subjects and How to Exercise Them)

  1. Data subjects may exercise the following personal information protection rights against the Operator at any time:
    • Request access to personal information
    • Request correction of errors
    • Request deletion
    • Request suspension of processing
  2. Rights under Paragraph 1 may be exercised against the Operator in writing, by email, or by other means in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Operator will take action without delay.
  3. Rights under Paragraph 1 may be exercised through an agent, such as the data subject’s legal representative or a person the data subject has authorized. In that case, a power of attorney in Form No. 11 annexed to the “Notice on Personal Information Processing Methods (No. 2020-7)” must be submitted.
  4. Members can do the following themselves on the settings page in the Service:
    • View and edit personal information
    • Delete uploaded images
    • Turn off the processing under Article 15 (“How your records are used”)
    • Withdraw consent to saving routes to their account (Location Information Terms)
    • Request membership withdrawal (permanently deleted after a 30-day grace period)
  5. For requests for access to personal information and for suspension of processing, the data subject’s rights may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.

Article 8 (Measures to Ensure the Security of Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Operator takes the following technical, managerial, and physical measures necessary to ensure security:

  1. Managerial measures
    • Establishing and implementing an internal management plan
    • Minimizing and training staff who handle personal information
    • Conducting regular self-audits
  2. Technical measures
    • Passwords are not kept for members who use social login (Google or Apple). Email login passwords are stored only in a form that cannot be decrypted
    • Potentially sensitive information, such as notes, diaries, descriptions, and episode bodies written by members and field record routes, is encrypted when stored
    • Encryption in transit (HTTPS)
    • Secure token-based login system
    • Defenses against major web security vulnerabilities
    • Installation and operation of access control systems
    • Retaining access records and preventing their forgery or alteration; retaining records of the Operator’s checks of members’ records
    • Installing security programs and updating them regularly
  3. Physical measures
    • Data storage using cloud infrastructure
    • Operating backup systems (data redundancy)
    • Using locks for documents, auxiliary storage media, and the like that contain personal information

Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

  1. To provide individually customized services to users, the Operator uses “cookies,” which store usage information and retrieve it from time to time.
  2. Cookies are small pieces of information that the server used to run a website sends to the user’s computer browser, and they may be stored on the hard disk of the user’s PC.
    • Purpose of cookies: keeping you signed in, analyzing Service usage records, providing customized services
    • Installing, operating, and refusing cookies: You can refuse cookie storage through the option settings under Tools → Internet Options → Privacy at the top of your web browser.
    • If you refuse cookie storage: you may have difficulty using customized services.

Article 10 (Personal Information Protection Officer)

The Operator has designated a Personal Information Protection Officer, as shown below, to take overall responsibility for work related to personal information processing and to handle data subjects’ complaints and provide remedies for damage related to personal information processing.

Personal Information Protection Officer

  • Name: Jaeho Lee
  • Position: Representative
  • Contact: support@moeyo.ai · +82-70-8998-2587
  • ※ Your inquiry will be directed to the department in charge of personal information protection.

Data subjects may contact the Personal Information Protection Officer about any inquiries, complaints, requests for remedies, or other matters related to personal information protection that arise while using the Operator’s services. The Operator will respond to and handle data subjects’ inquiries without delay.

Article 11 (Requests for Access to Personal Information)

  1. Data subjects may submit a request for access to personal information under Article 35 of the Personal Information Protection Act to the department below. The Operator will make efforts to process data subjects’ access requests promptly.
  2. Department that receives and processes access requests
    • Email: support@moeyo.ai
  3. In addition to the department in Paragraph 1, data subjects may also request access to personal information through the Ministry of the Interior and Safety’s “Personal Information Protection Comprehensive Support Portal” website (www.privacy.go.kr).

Article 12 (Remedies for Infringement of Rights)

To obtain remedies for infringement of personal information, data subjects may apply for dispute resolution or consultation to bodies such as the Personal Information Dispute Mediation Committee and the Personal Information Infringement Report Center of the Korea Internet & Security Agency. For other reports of, or consultations on, personal information infringement, please contact the organizations below.

  1. Personal Information Infringement Report Center (operated by the Korea Internet & Security Agency)
    • Responsibilities: reports of personal information infringement, requests for consultation
    • Website: privacy.kisa.or.kr
    • Phone: 118 (no area code)
    • Address: Personal Information Infringement Report Center, 3F, 9 Jinheung-gil (301-2 Bitgaram-dong), Naju-si, Jeollanam-do (58324), Republic of Korea
  2. Personal Information Dispute Mediation Committee
    • Responsibilities: applications for personal information dispute mediation, collective dispute mediation (civil resolution)
    • Website: www.kopico.go.kr
    • Phone: 1833-6972 (no area code)
    • Address: 4F, Government Complex Seoul, 209 Sejong-daero, Jongno-gu, Seoul (03171), Republic of Korea
  3. Supreme Prosecutors’ Office Cybercrime Investigation Division
    • Phone: 02-3480-3573
    • Website: www.spo.go.kr
  4. Korean National Police Agency Cyber Bureau
    • Phone: 182 (no area code)
    • Website: cyberbureau.police.go.kr

A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal as provided in the Administrative Appeals Act.

Article 13 (Changes to This Privacy Policy)

  1. This Privacy Policy applies from its effective date. If anything is added, deleted, or corrected in accordance with laws or policy, the changes will be announced through notices starting 7 days before they take effect.
  2. However, if there is a significant change to data subjects’ rights, it will be announced at least 30 days in advance, and data subjects’ consent may be obtained again if necessary.

Article 14 (Rights of International Users)

  1. Rights based on where you live
    • Members may, in accordance with the laws of the region where they live, request access to, correction of, deletion of, or suspension of processing of (a request that it no longer be used) their personal information. The Operator provides the rights in Article 7 equally to all members, regardless of where they live.
    • The Operator does not sell members’ personal information to third parties. However, if the Service is succeeded through a merger, business transfer, or the like, personal information is transferred to the successor in accordance with Article 3-2 of the Terms of Service and applicable laws, and the Operator will give notice of this.
    • Members will not be disadvantaged for exercising these rights.
  2. Residents of Japan (APPI)
    • The Operator processes personal information in accordance with Japan’s Act on the Protection of Personal Information (APPI).
    • Residents of Japan may request access to, correction of, deletion of, or suspension of use of their personal information.
    • The Operator uses data processed under Article 15 so that individuals cannot be recognized only within the Operator, and does not provide it to third parties. Models built from this data and their outputs are governed by Article 15(6).
    • Personal information is processed and stored in the Republic of Korea (the Operator’s servers) and the United States (the trustees in Article 5), and temporary storage for content delivery may take place in regions close to the member. Use of statistical and anonymous information is governed by Article 11(10) of the Terms of Service.
  3. International data transfers
    • The countries, companies, items, and timing of international transfers, and how to refuse them, are as set out in Article 5.
    • The Operator applies the same safeguards set out in this Policy to international transfers.

Article 15 (Automatic Processing of Records and Service Quality Improvement)

  1. Purpose of processing: The Operator processes members’ records to improve the accuracy of Service features, such as automatic classification and organization of photos, duplicate cleanup, the accuracy of search and recommendations, photo quality assessment, and error detection. This includes improving (training) the classification program so that it recognizes photos more accurately, and checking its performance.
  2. What is not processed, and how to turn it off
    • Photos judged to include people
    • Photos that may contain personal information, such as documents and screenshots
    • Text a member has not made public (notes, the bodies of private posts, descriptions of personal subjects, etc.)
    • Records of a member who has turned this processing off in settings

    Members can turn this processing off at any time under “How your records are used” in settings, and turning it off does not limit their use of the Service. Once it is turned off, no new processing takes place, and data already included is excluded from the time the next model is rebuilt. However, records a member has set to public (everyone) and material the member has provided directly after seeing a separate notice, such as photo contributions or public questions, are processed separately from this setting, in accordance with Article 11(4) of the Terms of Service and that notice.

  3. What is done before processing: When the Operator uses members’ records to make automatic classification more accurate, it follows these procedures.
    • It removes information that could reveal who took the photo (account, name, file name, device) and removes the capture information (EXIF) inside the photo file
    • It keeps location only at the level of a broad administrative area, such as a state or province, or removes it, and converts the capture time to the year and week
    • It stores the removed information in a separate store and separates access permissions
    • It does not use data processed in this way for the purpose of recognizing specific individuals
    • It determines whether a person is included by classifying the type of photo and checking for face regions, and in this processing it does not store facial features or compare them with other photos
    • It currently does not use photos mainly of vehicles, buildings, or objects, because they may contain license plates or signs
  4. Records: The Operator keeps records of which data was processed under which rules.
  5. What the Operator does not do: The results of this processing are not used for advertising targeted at individual members. Statistics from which individuals cannot be recognized (e.g., frequently recorded living things and regions) may be used to operate the Service and to provide information and guidance, and interest-based advertising is provided only if the member has separately consented under Article 17. Records a member has not made public are not exposed to other users in the course of this processing, and are not viewed by people except in the cases set out in Article 16(1).
  6. Models and their outputs: Models built or improved through this processing, and their outputs, may be provided outside the Service in accordance with Article 11(11) of the Terms of Service. Even then, the processed data (photos) itself is not provided to third parties, and the Operator makes sure that members’ photos or personal information cannot be recognized or extracted through the models or outputs.

Article 16 (Human Review)

  1. Records not made public: The Operator does not view records that a member has not made public. However, in the following cases the Operator may check them to the minimum extent necessary, and when it does so through the Service’s admin screens, it keeps a record of that fact: ① a report has been received; ② an automated check has flagged possible illegal content; ③ it is required by law; ④ a check is needed because the member has made an inquiry or asked for support; ⑤ it is necessary to diagnose a Service error. Checks under ① and ② are limited to the reported or flagged records and to what is needed to assess them; checks under ④ and ⑤ are limited to the records related to the inquiry or error in question; and the AI tools listed in Article 5 may be used for checks under ④. In case ③, the Operator will verify that proper legal process (such as a warrant or court order) has been followed, provide only the minimum information requested, and, unless prohibited by law, notify the member.
  2. Photos members ask to have reviewed: Photos that a member has provided by requesting a review, for example to confirm a name, may be viewed by the Operator or by review participants designated by the Operator. Review participants might not be officers or employees of the Operator.
  3. Scope of information provided to review participants
    • Provided: information needed for the review, such as the photos within their assigned scope, name candidates, any description the member included, and the region at the state or province level (where provided)
    • Not provided: the member’s name and account information, precise location, detailed capture information, or the member’s other records
  4. Management: Review participants’ permissions are valid only within the taxonomic groups, regional scope, and period set by the Operator. When the Operator views records through the Service’s admin screens, it keeps a record of that fact.
  5. Cancellation: Members may cancel the sharing at any time, and once they do, new assignments and viewing stop.
  6. Checking public photos: The Operator and review participants who have been granted permission may check photos that are public to everyone, or that a member has provided directly for review, only to the minimum extent necessary to confirm species names, life stages, and body parts, to check photo quality, rights, and safety, and to select photos for species information. Review screens do not provide precise location information, other private records, or unnecessary account information, and the scope and expiry of permissions are managed. When the original of a public photo is no longer public, or the member withdraws the photo, its public display in species information also stops. However, the minimum records needed for handling reports, rights disputes, and legal retention obligations may be kept separately for a set period.

Article 17 (Interest-Based Advertising)

This feature is not currently in effect. This article is included in advance so that, when the feature starts, consent can be obtained as described below without revising this Policy again. Until then, no processing takes place under this article.

  1. The Operator may use the following information to provide interest-based advertising only if the member has separately consented:
    • Taxonomic groups the member has set as interests
    • Activity area the member has set
    • Profile information the member has entered
  2. If the Operator obtains separate consent, it may also use information generated while the Service is used, such as screen views and time spent. This consent is obtained separately from the consent in Paragraph 1.
  3. Not consenting does not limit your use of the Service in any way. If you do not consent, ads unrelated to your interests may be shown.
  4. Members may withdraw consent in settings at any time. Information used to select ads is no longer used for that purpose once the member withdraws consent or withdraws from membership.
  5. The Operator currently does not collect advertising identifiers (IDFA/GAID). If collection becomes necessary, the Operator will give separate notice and obtain consent.

Addenda

This Privacy Policy is effective from March 8, 2026.
Revised July 15, 2026 — Added processing items and purposes related to community features (posts, comments, asking for a name) and the retention period for report and moderation records.

Revised September 29, 2026 — Purpose of improving the accuracy of Service features and criteria for additional use (Article 1); added items for field records, payments, usage analytics, login security, and Moeyo Studio early access applications (Articles 1, 2, and 3); organized the exceptions to provision to third parties (Article 4); updated consignment and international transfers (Article 5); clarified how deletion requests are handled and moved the model-related provisions (Article 6 → Article 15); updated encryption measures (Article 8); revised the rights of international users (Article 14); new articles on automatic processing of records (Article 15), human review (Article 16), and interest-based advertising (Article 17).

The Privacy Policy revised on September 29, 2026 takes effect on November 2, 2026. However, for members who newly join after this Policy was posted, and for Moeyo Studio early access applicants, it applies from the time they join or apply. For members who joined before it was posted, the previous Policy applies until November 1, 2026.

Contact Us

If you have any questions about the processing of personal information, please contact us:

Email: support@moeyo.ai
Website: https://moeyo.ai

Privacy Policy