INFIDITY Integrated Privacy Policy

Current revision effective date: 2026-09-28

The policy body below matches the privacy policy published in the app. Earlier correction, announcement, and effective dates retained in the body refer to the document history.

Tangle advertising and tracking clarification: September 2, 2026

This correction updates the advertising identifier and advertising tracking descriptions in Articles 2 and 9 to reflect Tangle's current operation. It does not introduce new collection or use of personal information. All other provisions remain unchanged. The original announcement and effective dates below are retained as part of the document history.

Emotionwave Inc. (the "Company") 'collects, uses and provides personal information on the basis of user consent', and 'actively guarantees users' rights (the right to informational self-determination)'.

INFIDITY refers to the integrated platform built and operated by Emotionwave Inc., and includes Tangle and the other services under the INFIDITY platform (the "INFIDITY Services").

The Company processes personal information lawfully and manages it safely in compliance with the Personal Information Protection Act and related laws and regulations for the protection of users' personal information.

A 'privacy policy' means the guidelines the Company must observe so that users may use the INFIDITY Services with confidence. This Privacy Policy applies commonly to the INFIDITY platform and to all subordinate services, including Tangle. Every user who has registered for one or more of the INFIDITY subordinate services, such as Tangle, is regarded as a member of the INFIDITY platform as well as a member of the individual service and is subject to this Privacy Policy. INFIDITY does not operate a unified account system, so each service operates independently with its own separate account system.

This Privacy Policy applies to INFIDITY's store, website, mobile applications and related services. The Company may update this Privacy Policy periodically and post the new version on INFIDITY's official channels. Where a material change is made, the Company will notify users as required by applicable law, including by posting a notice within the Service before the change takes effect. A user who continues to use the INFIDITY Services after the effective date is subject to the new Privacy Policy.


Scope applicable to Tangle

Tangle currently does not provide identity/adult verification services, microphone recording or voice collection features, or Kakao/Naver login. Accordingly, the provisions below on identity/adult verification purposes, personal information collected for verification, collection of CI/DI and retention of CI, and voice information collection do not apply to Tangle. Tangle supports Google and Apple social login. Confirmation that a registrant is at least 14 years old is separate from identity/adult verification and does not collect CI or DI. This clarification concerns these unused features in Tangle and does not indicate whether other services offer them.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information being processed is not used for any purpose other than the following, and where the purpose of use changes, the Company takes the necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.

  1. Member management: Identifying users, verifying intent to register and the number of registrations, preventing improper use by members subject to use restrictions, verifying the consent of a legal representative and confirming the identity of the legal representative, maintaining and managing membership status, and various notices and communications. A separate account is created and operated for each service.
  2. Customer support: Handling inquiries and complaints arising in the course of using the INFIDITY Services, delivering announcements, and handling grievances.
  3. Provision and advancement of AI services: Providing services such as AI chat, story mode and scene generation (Fan Media), improving the performance of artificial intelligence algorithms, and training next-generation models (machine learning).
  4. Use of pseudonymized information: Pseudonymizing the conversation records exchanged between users and the AI (text, images, etc.) into de-identified form and using them for the purposes of compiling statistics, scientific research and preservation of records in the public interest.
  5. Payment and settlement: Managing purchase and usage records of paid items ('Gyul'), settling charges, processing refunds, and providing identity/adult verification services (not applicable to Tangle).
  6. New service development and marketing: Developing new INFIDITY services, informing users of opportunities to take part in events and promotions, and use for marketing and advertising.
  7. Service improvement: Analyzing service usage records and access frequency, and providing customized services and improving the Service through statistics on service use.
  8. Building a safe usage environment: Building a safe usage environment to protect users' personal information and preventing improper use of the Service.

Article 2 (Items of Personal Information Collected)

The Company collects the minimum personal information necessary to provide the INFIDITY Services. The categories of personal information the Company collects may vary depending on the INFIDITY Services the user uses and the requirements of applicable law.

① Information the user provides directly to the Company

CategoryWhen collectedItems collected
RegistrationAt first sign-up(Required) Social ID (Google, Apple; Kakao/Naver do not apply to Tangle), email, nickname, profile picture / (Optional) gender, date of birth
Service useOngoingConversation information with the AI (including text, images and video), messages and other content the user submits, service usage behavior information (input information and outputs), feedback
Voice information — Not applicable to TangleWhen voice features are usedVoice and sound recorded from the microphone device of a mobile device or PC
Event participationOn participationName, phone number and similar information the user provides in connection with surveys, promotions, prize events, auditions and other events
Adult verification — Not applicable to TangleOn verificationName, date of birth, gender, mobile phone number, carrier, encrypted connecting information (CI), duplicate registration information (DI)
Paid purchasesOn paymentPayment method information, payment amount, payment date and time, purchased product information (the Company's payment service provider collects the user's payment details)

② Information the Company collects automatically

  1. Information on the account and on usage progress within the INFIDITY Services
  2. Text messages exchanged between users within the INFIDITY Services
  3. IP addresses and mobile device identifiers needed to provide the service. Tangle uses FCM tokens to deliver push notifications and does not collect advertising identifiers (ADID/IDFA).
  4. Information about the user's device, such as device name and operating system, browser type and language, internet service provider and mobile carrier
  5. Information the Company collects through cookies and similar technologies
  6. Approximate location information (derived from the IP address)
  7. Information on service use (usage information within the INFIDITY Services, purchase history, interactions the user has with other users within the Service, etc.) and access logs

Article 3 (Processing of Personal Information of Children Under 14)

  1. Where consent is required in order to process the personal information of a child under 14, the Company obtains consent from that child's legal representative.
  2. When obtaining the consent of a legal representative for the processing of the personal information of a child under 14, the Company may request minimum information from the child, such as the legal representative's name and contact details; it has the legal representative indicate whether consent is given on the internet site where the details of the consent are posted, and confirms the fact by notifying the legal representative's email address that the indication of consent has been confirmed.

Article 4 (Processing and Retention Periods of Personal Information)

  1. The Company processes personal information within the retention and use period consented to by the user at registration and when using the Service. Where a user withdraws consent to the collection and use of personal information, that user's personal information is destroyed once the purpose of collection and use has been achieved or the period has ended.
  2. In principle, a user's personal information is retained until the member withdraws from membership. However, where withdrawal is requested, personal information is preserved for 14 days after the withdrawal request in order to guard against unwanted withdrawal caused by identity theft and similar events. In addition, pseudonymized identification information may be retained for one year after withdrawal in order to prevent improper use.
  3. The scope of storage of INFIDITY service usage data follows the operation policy of each service. Furthermore, for services in which user creations arise, the creations and related data are preserved permanently. However, a user may request deletion of their creations and related data.
  4. Among a user's personal information, connecting information (CI) is stored securely for 30 days in a storage area separate from the existing storage area, for the purposes of preventing confusion and improper use of the Service and of identity verification. (Not applicable to Tangle.)
  5. The connecting information (CI) of accounts whose use of the INFIDITY Services has been restricted is encrypted and stored securely for up to 5 years in a storage area separate from the existing storage area, in order to prevent improper use. (Not applicable to Tangle.)

① Retention of personal information under applicable laws

Pursuant to Article 21 of the Personal Information Protection Act, where the retention period of personal information has elapsed or the purpose of processing has been achieved, the Company destroys the personal information without delay. However, where it must be preserved for a certain period under any of the following, it is retained for that period.

  1. Article 6 of the Act on Consumer Protection in Electronic Commerce
    • Records on contracts or withdrawal of subscription: 5 years
    • Records on payment and supply of goods: 5 years
    • Records on consumer complaints or dispute handling: 3 years
  2. Article 85-3 of the Framework Act on National Taxes, Article 160-2 of the Income Tax Act
    • Records on processing prescribed by tax law: 5 years
  3. Article 15-2 of the Protection of Communications Secrets Act
    • Login records: 3 months

Article 5 (Procedure and Method for Destroying Personal Information)

Where personal information becomes unnecessary, such as through the elapse of the retention period or the achievement of the purpose of processing, the Company destroys that personal information without delay.

Where personal information must continue to be preserved under other laws even though the retention period consented to by the data subject has elapsed or the purpose of processing has been achieved, that personal information is moved to a separate database (DB) or preserved in a different storage location.

※ The items of personal information preserved under other laws and the grounds for preservation can be found in "Article 4 (Processing and Retention Periods of Personal Information)".

① Destruction procedure

The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Company's Chief Privacy Officer.

② Destruction method

Personal information recorded and stored in electronic file form is destroyed so that the records cannot be reproduced, and personal information recorded and stored on paper documents is destroyed by shredding or incineration.

Article 6 (Processing of Pseudonymized Information for AI Advancement)

  1. Pursuant to Article 28-2 of the Personal Information Protection Act, the Company may pseudonymize and use users' conversation data.
  2. Pseudonymized information is information from which a specific individual cannot be identified without the use of additional information; the Company stores it separately and manages access rights so that it is processed safely.
  3. Purposes of processing: Analysis of AI model utterances, research into algorithm improvement and performance advancement, compilation of statistics, scientific research, and preservation of records in the public interest.

Article 7 (Entrustment and Overseas Transfer of Personal Information Processing)

For the operation of global infrastructure, the Company entrusts and transfers overseas part of its operations as follows.

Entrustee (country)Entrusted work and purposeItems
AWS (United States)Global server operation and data storageAll personal information collected
Google (United States)Infrastructure management and service usage analyticsDevice information, logs

External AI processing

Tangle sends information needed for AI responses, image generation and conversation memory processing to external AI providers. Chat requests may include the current message, earlier conversation, extracted memories and, if provided, gender context needed to generate a response. Image requests include generation instructions and character reference images. Personal information that you enter in a conversation may also be transmitted.

ProviderPurposeInformation transmitted
OpenAIAI responses, image generation and memory extractionMessages, conversation history, memories and gender context needed for the feature; image instructions and reference images
MiniMaxAI responsesMessages, conversation history, memories and gender context
GoogleEmbeddings for conversation memory retrievalMessages and memory content being processed

External AI requests may be processed through direct connections or through the company AI gateway.

Only information needed for the feature and processing route is sent. Each request is not necessarily sent to every provider; if response generation fails, it may be retried with another disclosed provider. The existing description of Google's infrastructure and service analytics processing remains separate.

External AI data retention

Under OpenAI’s public API policy, API inputs and outputs are not used for model training unless data sharing is explicitly opted into. Abuse-monitoring logs are retained for up to 30 days by default and may be retained longer for legal or safety reasons. Responses API response data may be subject to a default 30-day retention period. Actual retention depends on the API features used and the applicable account and contractual settings. Information sent to an external AI provider is therefore not necessarily deleted immediately after a response.

The Google embedding processing described above supports conversation memory retrieval and is separate from Firebase usage analytics, which is subject to optional consent.

Article 8 (Measures to Secure the Safety of Personal Information)

The Company takes the following measures to secure the safety of personal information.

  1. Administrative measures: Establishment and implementation of an internal management plan, operation of a dedicated organization, minimization of staff who handle personal information, and regular staff training.
  2. Technical measures: Management of access rights to personal information processing systems and similar systems, installation of access control systems, encrypted storage of passwords and unique identifying information and application of security protocols to transmission channels, and installation and updating of security programs to prevent hacking.
  3. Physical measures: Access control for the computer room, document storage room and similar areas.

Article 9 (Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof)

① Opting out of marketing emails and other direct marketing communications

Where permitted by applicable law, the Company may send marketing communications to users on the basis of an existing customer relationship. Users may opt out of receiving promotional communications such as marketing emails from the Company by following the instructions stated in the communication concerned or by changing their settings within the INFIDITY Services. Updated settings may not take effect immediately. Please note that users may continue to receive non-promotional communications from the Company, such as communications regarding updates to the Service, the Company's INFIDITY terms of service or this Privacy Policy, or information relating to transactions such as the user's purchases within the Service.

② Push notifications

The Company may send push notifications to users through the mobile applications of the INFIDITY Services. Users may opt out of receiving this type of communication at any time by changing the settings on their mobile device.

③ Advertising and tracking in the Tangle app

Tangle does not use AdMob or collect advertising identifiers (ADID/IDFA). Tangle does not combine user or device data collected from the app with data collected from third-party apps or websites for targeted advertising or advertising measurement, and does not share that data with data brokers. Processing information for push notifications, internal service analytics and content recommendations, including short-form videos and Explore, is distinct from tracking for advertising purposes.

④ Installation, operation and refusal of cookies

The Company may install and operate cookies in order to provide web-based services. Cookies are used to support fast and convenient use of the website and to provide customized services. A cookie is a very small text file that a website sends to the user's browser when the user accesses that website, and it is stored on the user's PC.

⑤ Purpose of use

Cookies that store and retrieve user information from time to time are used in order to provide personalized and customized services. When a user visits the website, the website server reads the cookies stored on the user's device to maintain the user's preferences and provide customized services. Cookies help users access and conveniently use the website as they have configured it when they visit. For Tangle, processing information to maintain service preferences and improve usability is distinct from combining it with third-party data for advertising tracking; Tangle does not perform the latter.

⑥ Refusing cookie collection

Users have the option of whether to allow cookies to be installed and may allow or refuse cookies through the cookie settings at 'Settings > Privacy > Cookies and other site data' at the top of the web browser. However, if the installation of cookies is refused, it may be difficult to use the web and some services that require login.

Article 10 (Rights and Duties of Data Subjects and Legal Representatives and How to Exercise Them)

A data subject may exercise against the Company at any time rights such as requesting access to, correction of, deletion of, or suspension of the processing of personal information, withdrawing consent, and refusing an automated decision or requesting an explanation of it (the "exercise of rights").

※ A request such as access to the personal information of a child under 14 must be made directly by the legal representative. A data subject who is a minor aged 14 or over may exercise rights concerning their personal information either personally or through a legal representative.

The exercise of rights may be made against the Company in writing, by email, by facsimile (FAX) and similar means pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company takes action on it without delay.

  1. A data subject may at any time view, modify or delete personal information directly under INFIDITY 'My Information > Member Information', or request access through 'Contact us'.
  2. A data subject may withdraw consent to the collection and use of personal information at any time through 'Withdraw membership'.
  3. A data subject may at any time refuse an automated decision and request an explanation through 'My Information > Member Information > Contact us'.
  4. Residents of Europe (GDPR) may exercise the right to be forgotten and the right to data portability, and residents of California (CCPA) may exercise the right to opt out of the sale of personal information.
  5. The exercise of rights may be requested through customer support (privacy@emotionwave.com).

The exercise of rights may be made through an agent such as the data subject's legal representative or a duly authorized person. In that case, a power of attorney in the form of Annex No. 11 of the "Public Notice on Methods of Processing Personal Information" must be submitted.

A data subject's right to request access to and suspension of the processing of personal information may be limited under Article 35(4) and Article 37(2) of the Personal Information Protection Act.

Where other laws expressly specify the personal information as subject to collection, deletion of that personal information may not be requested.

Where the data subject has consented to the fact that an automated decision will be made, or has been informed in advance through a contract or similar means, or where there is an express provision of law, refusal of the automated decision is not recognized and only an explanation and a review may be requested.

In addition, a request to refuse or to obtain an explanation of an automated decision may be denied where there is a justifiable reason, such as where it risks unduly infringing the life, body, property or other interests of another person.

The Company verifies whether the person exercising rights is the data subject or a duly authorized agent. Additional information may be collected in order to handle inquiries and consultations made to customer support.

Service nameAdditional personal information items collected
Contact usCalling phone number

Some services may collect additional personal information with the user's consent in order to provide various specialized features.

Article 11 (Chief Privacy Officer)

The Company designates a Chief Privacy Officer as follows, who takes overall responsibility for work relating to the processing of personal information and handles users' complaints and remedies for damage in connection with the processing of personal information.

Chief Privacy Officer and responsible department

Users may direct to the Chief Privacy Officer and the responsible department any inquiries, complaints, requests for remedies for damage and similar matters relating to the protection of personal information that arise while using the Company's services. The Company will respond to and handle users' inquiries without delay.

Article 12 (Remedies for Infringement of Data Subjects' Rights)

If you have any inquiries, complaints or other comments relating to the protection of personal information, please submit them to the contact details above and we will review them promptly and reply.

In addition, where a report or consultation relating to personal information is needed, assistance may be obtained through the following bodies.

Article 13 (Notice Obligations Before Amendment)

This Privacy Policy may be amended for purposes such as reflecting applicable laws or changes to the INFIDITY Services. Where the Privacy Policy is changed, the changes are announced in advance at least 7 days beforehand.

However, where a material change to users' rights occurs, prior notice is given at least 30 days beforehand.

Article 14 (Changes to the Privacy Policy)

This Privacy Policy may be amended due to applicable laws or changes to the INFIDITY Services. Where the Privacy Policy is changed, the changes are announced in advance by posting a notice on the initial screen of the INFIDITY platform.


Chief Privacy Officer Officer: INFIDITY Operations Team Email: support@infidity.ai Inquiries: support@infidity.ai

Announced: April 8, 2026 Effective: April 15, 2026

Emotionwave Inc.

Coming soon