Skip to content
Architect V

Privacy Policy

Blackhole Inc. (the 'Company') establishes and discloses this Privacy Policy under Article 30 of the Korean Personal Information Protection Act in order to protect the personal data of data subjects and handle related complaints.

Published Effective

1. Personal data we process

CategoryItemsHow it is collected
Account (signed in)Google account identifier, email address, profile name (optional), internal account identifierWhen the user chooses to sign in with Google
Account (guest)Device identifier, app instance identifierGenerated when the app is first launched
Service usageIP address, access time, usage records, OS and device information, app versionCollected automatically while the Service is used
NotificationsPush notification tokenWhen the user allows notifications
PaymentsApp market transaction identifier, product name, payment time, payment statusReceived from the app market when a payment completes
Install sourceInstall referrer string (content code, target app identifier)Received from the app market on installation
User inputConversation content, images attached by the user, in-service settingsWhen the user enters it
EnquiriesEmail address, message, attachmentsWhen the user contacts us

The Company does not collect or store card numbers, bank account numbers, or other payment credentials. Payments are handled by the app market operator.

2. Purposes of processing

  • Identifying members, creating and managing accounts, linking family accounts
  • Providing the Service, its content, and user-specific features
  • Confirming payments for paid goods, managing purchase history, handling refunds
  • Preventing abuse, blocking abnormal access, keeping the Service stable
  • Delivering notices, handling enquiries and complaints, responding to disputes
  • Analysing usage statistics and improving quality

3. Retention and use periods

Personal data is destroyed without delay once the purpose of collection and use is achieved, except where the law requires retention for a set period.

CategoryRetention periodBasis
Account information and usage recordsUntil the account is deletedConsent / performance of contract
Records on contracts or withdrawal of subscription5 yearsAct on Consumer Protection in Electronic Commerce
Records on payment and supply of goods5 yearsAct on Consumer Protection in Electronic Commerce
Records on consumer complaints or dispute handling3 yearsAct on Consumer Protection in Electronic Commerce
Records on labelling and advertising6 monthsAct on Consumer Protection in Electronic Commerce
Access (sign-in) logs3 monthsProtection of Communications Secrets Act

4. Provision to third parties

The Company processes personal data only within the purposes stated in this policy and does not provide it to third parties except where Articles 17 and 18 of the Personal Information Protection Act apply, such as separate consent from the data subject or a specific provision of law.

Where an investigative authority makes a request following the procedures and methods prescribed by law, the Company cooperates within the scope the law allows.

5. Processing entrusted to others

The Company entrusts the following processing in order to run the Service.

ProcessorEntrusted work
Google LLCAccount authentication (Firebase Authentication), push notification delivery, usage analytics
Google Cloud Platform (Google LLC)Server, database, and file storage operation; generative AI responses (Vertex AI)
OpenAI, L.L.C.In-service image generation
Vercel Inc.Hosting of the company website
Google Play (Google LLC)App distribution and in-app payment processing

Under Article 26 of the Personal Information Protection Act, entrustment contracts specify the prohibition of processing beyond the purpose, technical and administrative safeguards, limits on sub-processing, supervision of the processor, and liability for damages; the Company supervises compliance.

Changes to entrusted work or processors are disclosed through this policy.

6. Transfer of personal data abroad

The Company transfers personal data abroad as follows, under Article 28-8 of the Personal Information Protection Act.

RecipientCountryItemsTime and methodPurposeRetention
Google LLCUnited States and other countries hosting Google data centresAccount identifier, email, device and access information, push token, usage recordsTransmitted over the network as the Service is usedAuthentication, notifications, infrastructure, usage analyticsUntil the entrustment ends or the retention period expires
Google LLC (Vertex AI)United States and other Google Cloud regionsConversation content and other request data entered by the userTransmitted over the network when the feature is usedGenerating AI responsesDestroyed without delay after the request is processed; not used to train models
OpenAI, L.L.C.United StatesImage generation request dataTransmitted over the network when the feature is usedImage generationDestroyed without delay after the request is processed
Vercel Inc.United StatesWebsite IP address, access logsTransmitted when the website is accessedWebsite hosting and securityUntil the entrustment ends

A user may refuse the transfer of personal data abroad. Where the transfer is essential to providing the Service, refusing it may limit use of that service. Refusals can be sent to the privacy officer listed below.

7. Destruction of personal data

Personal data is destroyed without delay once it is no longer needed — within 5 days after the retention period ends, or within 5 days after the purpose is achieved.

  • Electronic files are deleted by a technical method that prevents recovery.
  • Printed records are shredded or incinerated.
  • Data that must be retained by law is stored separately from other personal data and destroyed when the period ends.

8. Rights of data subjects and how to exercise them

A data subject may at any time request access to, correction of, deletion of, or suspension of the processing of their personal data. Accounts can also be deleted directly in the app settings.

Requests may be made by email or in writing. The Company acts within 10 days of receipt and reports the outcome. A request made through a legal representative or an agent requires a letter of authority.

Deletion may be restricted where another statute specifies the personal data as subject to collection.

9. Children under 14

The Service is not directed at children under 14 and does not accept sign-ups from them. If the Company learns that personal data of a child under 14 has been collected, it destroys that data without delay.

10. Automatic collection devices and how to refuse them

The company website does not store cookies on the visitor's device and does not use advertising or tracking scripts.

The apps collect an app instance identifier and event records for usage analysis. Users can reset or limit the advertising identifier in their device settings and can opt out of analytics collection in the app settings.

11. Security measures

  • Access to personal data is granted to the minimum number of people needed, and permissions are reviewed regularly.
  • Personal data is encrypted in transit (TLS), and credentials and other sensitive values are encrypted at rest.
  • Access logs of personal data systems are retained and protected against tampering.
  • Personal data systems run in an environment with controlled access from the public internet.

12. Privacy officer

The Company designates a privacy officer who is responsible for personal data processing and for handling complaints and remedies from data subjects.

Contact details appear in the business information at the foot of this page.

13. Remedies for infringement

Data subjects may apply to the following bodies for dispute resolution or advice regarding a personal data infringement.

BodyPhoneWebsite
Personal Information Dispute Mediation Committee+82 1833-6972www.kopico.go.kr
Korea Internet & Security Agency, privacy report centre+82 118privacy.kisa.or.kr
Supreme Prosecutors' Office, cybercrime+82 1301www.spo.go.kr
National Police Agency, cybercrime+82 182ecrm.police.go.kr

A person dissatisfied with the Company's action under Articles 35, 36, or 37 of the Personal Information Protection Act may request an administrative appeal under the Administrative Appeals Act.

14. Changes to this policy

This policy applies from the effective date shown below. Where content is added, removed, or corrected because of changes in law, policy, or security technology, the change is announced at least 7 days before it takes effect.

Business information

Legal name
Blackhole Inc.
Representative
Bada Kim
Brand
Architect V
Business registration no.
493-88-01704
Corporate registration no.
110111-7755329
Address
B1, 7-4 Eonnam 11-gil, Seocho-gu, Seoul 06776, Republic of Korea
Phone
010-7726-5508
Email
contact@arch-v.co.kr
Privacy officer
Bada Kim (privacy@arch-v.co.kr)
Hosting provider
Vercel Inc.

These documents are written under the laws of the Republic of Korea. This English text is provided for convenience; if it conflicts with the Korean text, the Korean text prevails. Amendments are announced 7 days before they take effect, or 30 days before when they are unfavourable to users.