I'm Miri (the "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (PIPA) to protect the personal information of data subjects and to promptly and smoothly handle any related grievances.
1. Purpose of Collecting and Using Personal Information
The Company processes personal information for the purposes below. The personal information processed is not used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of PIPA.
1-1. Member Registration and Management
- Verifying intent to register
- Identity verification and authentication for member services
- Maintaining and managing membership
- Preventing fraudulent use of the service
- Various notices and communications
1-2. Fortune (Saju) Analysis Service
- Calculating and analyzing Saju (Four Pillars)
- Providing personalized fortune information
- AI-based conversational consultation service
- Providing AI-based real-time voice consultation and managing consultation quality (ages 18 and over)
- Providing lucky elements (colors, numbers, directions, times)
- Providing compatibility analysis and relationship advice involving acquaintances registered by the user
1-3. Service Improvement and Development
- Developing new services and providing customized services
- Service usage statistics and analysis
- Improving service quality
2. Personal Information Collected
The Company collects the following personal information to provide its services.
2-1. Required Information
- At registration: social login identifier (Apple ID or Google account), email address, name — when using Apple Sign-in / Google Sign-in
- For Saju analysis: date of birth (solar/lunar), time of birth, place of birth
- During service use: AI conversation history, Saju analysis results, service usage records
- When using voice consultation (ages 18 and over): real-time voice data, input/output transcription text of the user and the AI, information the user provides directly during the conversation, call date/time and session identifiers, AI responses and quality-evaluation results
※ The original voice audio is not permanently stored in the Company's databases; it is processed in real time to generate AI responses and then destroyed. Only the text transcripts of the conversation are retained for a limited period for consultation quality management and then automatically deleted. Depending on feature settings and processor policies, conversation state/cache may be temporarily retained (up to 24 hours). - When using acquaintance compatibility (optional): information about an acquaintance entered directly by the user — name or nickname, date of birth, time of birth (optional), place of birth (optional), gender (optional), relationship, blood type (optional)
※ Acquaintance information is used solely for compatibility analysis within the user's own account and is not disclosed to the acquaintance or to other users. When entering another person's personal information, the user is responsible for complying with applicable laws, including obtaining that data subject's consent; if the data subject requests deletion, the Company will delete the information without delay (via the in-app deletion feature or an email inquiry). Acquaintance information is destroyed when the user withdraws membership. - When you contact support: your email address, the subject and body of your inquiry, attachments, and send/receive timestamps
※ This covers both the in-app support chat and inquiries sent directly to the Company's support email address (cristina@miri.im). An inquiry may contain information you provide yourself, such as a payment order or receipt number. The Company uses it solely to handle and answer your inquiry, diagnose faults, and improve the service. Non-members may also contact us by email; in that case the Company processes the above only as needed to reply and deletes it once the period in Section 3-3-4 has passed. - Marketing communications (optional): whether you have consented to receive marketing communications
2-2. Automatically Collected Information
- Device information (OS version, device model)
- Service usage records
- Access logs
- App error logs (Firebase Crashlytics)
- Cookies and access IP information
2-3. Collection Methods
- Collected during registration and service use through the mobile app
- Collected via Apple Sign-in / Google Sign-in
- Automatically generated and collected during service use
- Collected when you send an inquiry through the in-app support chat or to the Company's support email address
3. Processing and Retention Period
The Company processes and retains personal information within the retention/use period required by law or the retention/use period consented to by the data subject at the time of collection.
3-1. Member Information
- Retention period: Until membership withdrawal
- Withdrawal processing: After a withdrawal request, personal information is destroyed following a 24-hour grace period. During the grace period, account access is blocked; after 24 hours, deletion proceeds automatically and completes within 48 hours of the request at the latest.
- Statutory retention exception: Records subject to statutory retention under Section 3-3 below (payment/contract records, etc.) are not deleted but instead de-identified (identifiers replaced with encrypted hashes) and retained only for the applicable statutory period, and are not used for any other purpose.
- Exception: Where an investigation or inquiry due to a violation of applicable laws is underway, until such investigation or inquiry concludes.
3-2. Service Usage Records
- Retention period: Automatically deleted after the 24-hour grace period following membership withdrawal (completed within 48 hours of the request at the latest)
- Exception: Where retention is required by law, retained for the period specified by that law
3-3-2. Voice Consultation Records
- Voice consultation text transcripts: Retained for 7 days from creation, then deleted without delay (users may also request access or deletion before then)
- Voice consultation quality-evaluation results: Retained as aggregate statistics that cannot identify individuals
- Voice consultation consent records (including consent-wording version, per-item consent results, and time of withdrawal): Until membership withdrawal
3-3-4. Customer Inquiry Records
- Retention period: destroyed without delay once 3 years have passed from the date the inquiry was resolved (records on consumer complaints or dispute resolution under the Act on Consumer Protection in Electronic Commerce — see 3-3 below).
- Inquiries from members: the inquiry content and reply history are destroyed together with the account upon withdrawal. Records subject to the statutory retention above are kept only for the statutory period after the de-identification described in 3-1.
- Email inquiries from non-members: destroyed once the statutory period above has passed, and destroyed without delay upon the data subject's deletion request before then (except where a statutory retention obligation applies).
3-3. Statutory Retention
- Records on contracts or withdrawal of subscription: 5 years (E-Commerce Act (Korea))
- Records on payment and the supply of goods, etc.: 5 years (E-Commerce Act (Korea))
- Records on consumer complaints or dispute handling: 3 years (E-Commerce Act (Korea))
- Records on labeling/advertising: 6 months (E-Commerce Act (Korea))
- Website visit records: 3 months (Protection of Communications Secrets Act)
4. Provision of Personal Information to Third Parties
In principle, the Company processes users' personal information only within the scope specified in Article 1 (Purpose of Collecting and Using Personal Information) and does not process it beyond the original scope or provide it to third parties without the user's prior consent.
However, the following are exceptions.
4-1. Essential Provision for Service Delivery
The Company provides personal information to third parties as follows:
| Recipient | Purpose | Information Provided | Retention and Use Period |
|---|---|---|---|
| Google (Gemini API) | AI conversation generation, real-time voice conversation generation and transcription, consultation quality evaluation | Conversation history, Saju analysis results, and—for voice consultation—the user's voice (real-time streaming) and conversation transcripts | Deleted without delay after processing (temporary session state/cache up to 24 hours) |
| OpenAI, L.L.C. | AI conversation generation — backup processing only when the primary provider (Google) fails or exceeds its limits | Conversation history, Saju analysis results | Processed with the no-response-storage option applied; under OpenAI API policy, retained for up to 30 days for abuse monitoring and then deleted (not used to train AI models) |
| Google (Firebase) | Data storage and management | Member information, Saju information, conversation history, voice transcripts | Until membership withdrawal (voice transcripts: 7 days from creation) |
| Google Sign-in authentication | Google account identifier, email, name | Deleted immediately after authentication | |
| Apple | Apple Sign-in authentication | Apple ID, email, name | Deleted immediately after authentication |
| Apple | Supporting App Store refund request review | Purchase transaction information, service usage/consumption information (usage period, usage volume, etc.) | Per Apple's refund review policy |
4-2. Provision Required by Law
- Where there are special provisions in law or it is unavoidable in order to comply with legal obligations
- Where it is unavoidable for a public institution to perform its statutory duties
5. Consignment of Personal Information Processing
For the smooth handling of personal information, the Company consigns personal information processing tasks as follows:
| Consignee | Consigned Task | Consignment Period |
|---|---|---|
| Google LLC (Firebase) | Cloud server operation and data storage | Until membership withdrawal or termination of the consignment contract |
| Google (Gemini API) | AI conversation generation service, real-time voice conversation processing and transcription, consultation quality evaluation | Each time the service is used |
| OpenAI, L.L.C. | Backup AI conversation generation processing (when the primary provider fails or exceeds its limits) | Each time the service is used |
When entering into consignment contracts, in accordance with Article 26 of PIPA, the Company specifies in the contract or other documents such matters as the prohibition of processing personal information beyond the purpose of the consigned work, technical and managerial safeguards, restrictions on re-consignment, supervision of the consignee, and liability including damages, and supervises whether the consignee processes personal information safely.
5-2. International Transfer of Personal Information
To the extent necessary to perform the AI conversation/voice consultation service contract concluded with the user, and pursuant to Article 28-8(1)(iii) of PIPA, the Company consigns the processing of and stores personal information overseas as follows.
| Recipient (Contact) | Country | Date/Time and Method of Transfer | Items Transferred | Purpose of Use | Retention/Use Period |
|---|---|---|---|---|---|
| Google LLC (Privacy inquiries: googlekrsupport@google.com · Google Korea LLC, 152 Teheran-ro, Gangnam-gu, Seoul (Gangnam Finance Center), ☎ +82-2-531-9000 · HQ: 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA) | USA | Real-time encrypted transmission over the network during consultation | Real-time voice, input/output transcripts, conversation content, Saju analysis results | Real-time AI conversation/voice conversation generation and transcription | Deleted without delay after processing (temporary session state/cache up to 24 hours) |
| Google LLC (Firebase, same as above) | USA | Stored continuously during service use | Member information, Saju information, conversation/transcript records | Cloud data storage and management | Until membership withdrawal or the end of the retention period (voice transcripts: 7 days) |
| Google LLC (Gemini API, same as above) | USA | Transmitted at quality evaluation after the consultation ends | Voice conversation transcripts | Consultation quality management | Deleted after processing is complete |
| OpenAI, L.L.C. (Privacy inquiries: https://privacy.openai.com) | USA | Real-time encrypted transmission over the network when the primary provider fails or exceeds its limits | Conversation content, Saju analysis results | AI conversation generation (backup processing) | No-response-storage option applied; under OpenAI API policy, retained for up to 30 days for abuse monitoring and then deleted |
Method, procedure, and effect of refusing the transfer: The international transfers above are essential to providing the AI conversation/voice consultation features. For voice consultation, you can review and refuse the transfer during the separate consent process presented at first use; if you do not consent, you cannot use AI voice consultation, but there is no restriction on using other services. If you do not consent to the transfer related to text-based AI conversation, you cannot use the AI conversation feature.
If the notice above changes, the Company will inform you in advance (Article 28-8(3)), and when transferring personal information overseas, the Company implements the protective measures set out in Articles 17 through 19 and Chapter V of PIPA and its Enforcement Decree (paragraph 4).
6. Rights of Data Subjects and How to Exercise Them
Data subjects may exercise the following personal information protection rights against the Company at any time:
6-1. Rights
- Right to request access to personal information
- Right to request correction of errors
- Right to request deletion
- Right to request suspension of processing
6-2. How to Exercise Rights
Email: cristina@miri.im
Membership withdrawal: In-app Settings → Account → Withdraw Membership
6-3. Limitations on Exercising Rights
The exercise of data subjects' rights may be restricted in the following cases:
- Where there are special provisions in law or it is unavoidable in order to comply with legal obligations
- Where there is a risk of harming another person's life or body, or of unfairly infringing another person's property or other interests
For users in the European Economic Area (EEA), you also have the right to data portability and the right to lodge a complaint with your local data protection authority.
7. Destruction of Personal Information
When personal information becomes unnecessary due to the expiration of the retention period, achievement of the processing purpose, etc., the Company destroys it without delay.
7-1. Destruction Procedure
- Information entered by the user is, after the purpose is achieved, moved to a separate database (or separate documents in the case of paper) and stored for a certain period in accordance with internal policies and other applicable laws, or destroyed immediately.
- Such personal information is not used for any other purpose except as required by law.
7-2. Destruction Method
- Electronic files: Completely deleted using technical methods that prevent the records from being reproduced
- Paper documents: Shredded or incinerated
8. Measures to Ensure the Security of Personal Information
In accordance with Article 29 of PIPA, the Company takes the following technical, managerial, and physical measures necessary to ensure security:
8-1. Managerial Measures
- Establishing and implementing an internal management plan
- Regular employee training
- Minimizing and training staff who handle personal information
8-2. Technical Measures
- Encryption of personal information
- Technical countermeasures against hacking and similar threats
- Installation of access control systems
- Retention of access logs and prevention of forgery or tampering
8-3. Physical Measures
- Access control for computer rooms, data storage rooms, and similar facilities
9. Installation, Operation, and Refusal of Automatic Collection Devices
The Company may automatically collect the following information to improve services and provide customized services:
9-1. Information Collected
- App usage patterns
- Device information (OS version, device model)
- Service usage statistics
9-2. How to Refuse
Users can refuse the collection of information through their device settings:
- iOS: Settings → Privacy → Tracking → turn off "Allow Apps to Request to Track"
10. Personal Information Protection Officer
The Company designates a Personal Information Protection Officer, as set out below, to take overall responsibility for personal information processing and to handle data subjects' complaints and provide remedies for damages related to personal information processing:
Email: cristina@miri.im
Data subjects may direct any inquiries, complaints, or requests for damage relief related to personal information protection arising from their use of the Company's services to the Personal Information Protection Officer. The Company will respond to and handle data subjects' inquiries without delay.
11. Requesting Access to Personal Information
Under Article 35 of PIPA, data subjects may request access to their personal information from the department below. The Company will endeavor to process such access requests promptly:
Email: cristina@miri.im
12. Remedies for Rights Infringement
Data subjects may contact the following organizations for damage relief, consultation, and similar matters regarding personal information infringement:
12-1. Personal Information Infringement Report Center (operated by KISA)
- Responsibilities: Reporting personal information infringement, requesting consultation
- Website: privacy.kisa.or.kr
- Phone: 118 (no area code)
- Address: (58324) 3F, 9 Jinheung-gil, Naju-si, Jeollanam-do, Republic of Korea
12-2. Personal Information Dispute Mediation Committee
- Responsibilities: Applications for personal information dispute mediation and collective dispute mediation (civil resolution)
- Website: www.kopico.go.kr
- Phone: 1833-6972 (no area code)
- Address: (03171) 4F, Government Complex Seoul, 209 Sejong-daero, Jongno-gu, Seoul
12-3. Supreme Prosecutors' Office Cybercrime Investigation Division
- Phone: 02-3480-3573
- Website: www.spo.go.kr
12-4. National Police Agency Cyber Bureau
- Phone: 182 (no area code)
- Website: cyberbureau.police.go.kr
12-5. For users outside Korea
Please contact your local data protection authority or email us at cristina@miri.im.
13. Changes to This Privacy Policy
This Privacy Policy is effective from July 25, 2026. If there are additions, deletions, or corrections due to changes in law or policy, the Company will provide notice by posting an announcement on this Privacy Policy page at least 7 days before the changes take effect.