Privacy Policy
Blackhole Inc. (the 'Company') establishes and discloses this Privacy Policy under Article 30 of the Korean Personal Information Protection Act in order to protect the personal data of data subjects and handle related complaints.
Published Effective
1. Personal data we process
| Category | Items | How it is collected |
|---|---|---|
| Account (signed in) | Google account identifier, email address, profile name (optional), internal account identifier | When the user chooses to sign in with Google |
| Account (guest) | Device identifier, app instance identifier | Generated when the app is first launched |
| Service usage | IP address, access time, usage records, OS and device information, app version | Collected automatically while the Service is used |
| Notifications | Push notification token | When the user allows notifications |
| Payments | App market transaction identifier, product name, payment time, payment status | Received from the app market when a payment completes |
| Install source | Install referrer string (content code, target app identifier) | Received from the app market on installation |
| User input | Conversation content, images attached by the user, in-service settings | When the user enters it |
| Enquiries | Email address, message, attachments | When the user contacts us |
The Company does not collect or store card numbers, bank account numbers, or other payment credentials. Payments are handled by the app market operator.
2. Purposes of processing
- Identifying members, creating and managing accounts, linking family accounts
- Providing the Service, its content, and user-specific features
- Confirming payments for paid goods, managing purchase history, handling refunds
- Preventing abuse, blocking abnormal access, keeping the Service stable
- Delivering notices, handling enquiries and complaints, responding to disputes
- Analysing usage statistics and improving quality
3. Retention and use periods
Personal data is destroyed without delay once the purpose of collection and use is achieved, except where the law requires retention for a set period.
| Category | Retention period | Basis |
|---|---|---|
| Account information and usage records | Until the account is deleted | Consent / performance of contract |
| Records on contracts or withdrawal of subscription | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on payment and supply of goods | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on consumer complaints or dispute handling | 3 years | Act on Consumer Protection in Electronic Commerce |
| Records on labelling and advertising | 6 months | Act on Consumer Protection in Electronic Commerce |
| Access (sign-in) logs | 3 months | Protection of Communications Secrets Act |
4. Provision to third parties
The Company processes personal data only within the purposes stated in this policy and does not provide it to third parties except where Articles 17 and 18 of the Personal Information Protection Act apply, such as separate consent from the data subject or a specific provision of law.
Where an investigative authority makes a request following the procedures and methods prescribed by law, the Company cooperates within the scope the law allows.
5. Processing entrusted to others
The Company entrusts the following processing in order to run the Service.
| Processor | Entrusted work |
|---|---|
| Google LLC | Account authentication (Firebase Authentication), push notification delivery, usage analytics |
| Google Cloud Platform (Google LLC) | Server, database, and file storage operation; generative AI responses (Vertex AI) |
| OpenAI, L.L.C. | In-service image generation |
| Vercel Inc. | Hosting of the company website |
| Google Play (Google LLC) | App distribution and in-app payment processing |
Under Article 26 of the Personal Information Protection Act, entrustment contracts specify the prohibition of processing beyond the purpose, technical and administrative safeguards, limits on sub-processing, supervision of the processor, and liability for damages; the Company supervises compliance.
Changes to entrusted work or processors are disclosed through this policy.
6. Transfer of personal data abroad
The Company transfers personal data abroad as follows, under Article 28-8 of the Personal Information Protection Act.
| Recipient | Country | Items | Time and method | Purpose | Retention |
|---|---|---|---|---|---|
| Google LLC | United States and other countries hosting Google data centres | Account identifier, email, device and access information, push token, usage records | Transmitted over the network as the Service is used | Authentication, notifications, infrastructure, usage analytics | Until the entrustment ends or the retention period expires |
| Google LLC (Vertex AI) | United States and other Google Cloud regions | Conversation content and other request data entered by the user | Transmitted over the network when the feature is used | Generating AI responses | Destroyed without delay after the request is processed; not used to train models |
| OpenAI, L.L.C. | United States | Image generation request data | Transmitted over the network when the feature is used | Image generation | Destroyed without delay after the request is processed |
| Vercel Inc. | United States | Website IP address, access logs | Transmitted when the website is accessed | Website hosting and security | Until the entrustment ends |
A user may refuse the transfer of personal data abroad. Where the transfer is essential to providing the Service, refusing it may limit use of that service. Refusals can be sent to the privacy officer listed below.
7. Destruction of personal data
Personal data is destroyed without delay once it is no longer needed — within 5 days after the retention period ends, or within 5 days after the purpose is achieved.
- Electronic files are deleted by a technical method that prevents recovery.
- Printed records are shredded or incinerated.
- Data that must be retained by law is stored separately from other personal data and destroyed when the period ends.
8. Rights of data subjects and how to exercise them
A data subject may at any time request access to, correction of, deletion of, or suspension of the processing of their personal data. Accounts can also be deleted directly in the app settings.
Requests may be made by email or in writing. The Company acts within 10 days of receipt and reports the outcome. A request made through a legal representative or an agent requires a letter of authority.
Deletion may be restricted where another statute specifies the personal data as subject to collection.
9. Children under 14
The Service is not directed at children under 14 and does not accept sign-ups from them. If the Company learns that personal data of a child under 14 has been collected, it destroys that data without delay.
10. Automatic collection devices and how to refuse them
The company website does not store cookies on the visitor's device and does not use advertising or tracking scripts.
The apps collect an app instance identifier and event records for usage analysis. Users can reset or limit the advertising identifier in their device settings and can opt out of analytics collection in the app settings.
11. Security measures
- Access to personal data is granted to the minimum number of people needed, and permissions are reviewed regularly.
- Personal data is encrypted in transit (TLS), and credentials and other sensitive values are encrypted at rest.
- Access logs of personal data systems are retained and protected against tampering.
- Personal data systems run in an environment with controlled access from the public internet.
12. Privacy officer
The Company designates a privacy officer who is responsible for personal data processing and for handling complaints and remedies from data subjects.
Contact details appear in the business information at the foot of this page.
13. Remedies for infringement
Data subjects may apply to the following bodies for dispute resolution or advice regarding a personal data infringement.
| Body | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | +82 1833-6972 | www.kopico.go.kr |
| Korea Internet & Security Agency, privacy report centre | +82 118 | privacy.kisa.or.kr |
| Supreme Prosecutors' Office, cybercrime | +82 1301 | www.spo.go.kr |
| National Police Agency, cybercrime | +82 182 | ecrm.police.go.kr |
A person dissatisfied with the Company's action under Articles 35, 36, or 37 of the Personal Information Protection Act may request an administrative appeal under the Administrative Appeals Act.
14. Changes to this policy
This policy applies from the effective date shown below. Where content is added, removed, or corrected because of changes in law, policy, or security technology, the change is announced at least 7 days before it takes effect.
Business information
- Legal name
- Blackhole Inc.
- Representative
- Bada Kim
- Brand
- Architect V
- Business registration no.
- 493-88-01704
- Corporate registration no.
- 110111-7755329
- Address
- B1, 7-4 Eonnam 11-gil, Seocho-gu, Seoul 06776, Republic of Korea
- Phone
- 010-7726-5508
- contact@arch-v.co.kr
- Privacy officer
- Bada Kim (privacy@arch-v.co.kr)
- Hosting provider
- Vercel Inc.
These documents are written under the laws of the Republic of Korea. This English text is provided for convenience; if it conflicts with the Korean text, the Korean text prevails. Amendments are announced 7 days before they take effect, or 30 days before when they are unfavourable to users.