PicoPet Privacy Policy

Version 1.1 · Last updated: August 16, 2026

This English version is provided for convenience. In the event of any discrepancy between this translation and the original Korean version, the Korean version prevails.

pilstech (Representative: Kim Hong-pil; hereinafter the "Operator") operates the mobile application "PicoPet" (hereinafter the "Service") in compliance with applicable laws, including the Personal Information Protection Act, and establishes and discloses this Privacy Policy as follows in order to protect users' personal data.

1. Items of Personal Data Collected and Methods of Collection

The Operator collects the following personal data. The Service does not use a separate sign-up form and relies solely on social account login (Kakao, Google, Apple).

CategoryItems collectedMethod of collection
User identification
(Required)
Social login provider (Kakao/Google/Apple), unique social account identifier, nickname (automatically generated at sign-up, changeable in the app) At social login
User information
(Optional)
Email address (only where the user has consented to its provision through the social account) At social login
Breed recommendation Preference analysis responses (selected tags), recommendation results (list of breeds), and the user-uploaded face photo (an image whose background has already been removed on the user's device) When using the breed recommendation feature
User-generated content Feed posts (photos, text, breed information), comments, like records, decorated photos, diaries (title, content, photos, mood tags), saved breeds, item unlock history, and the block relationships and reports created by the user When using the relevant feature
Automatically collected items Last login date and time and IP address, and the authentication token used to keep the user signed in Automatically collected at login

The processing of face photos uploaded by users is set out separately in Section 2 (Processing of Face Data). Background removal and breed recommendation analysis are performed on the user's device, and the Operator does not separately extract or store biometric facial features.

2. Processing of Face Data

The breed recommendation feature of the Service uses the user's face photo. The Operator handles the Face Data processed in this feature as follows.

2.1 Face Data processed

  1. The Face Data processed by the Operator consists solely of the face image file that the user has taken or selected and uploaded, together with the address (URL) string of that image stored in the database.
  2. The Operator does not create or store any biometric identifier capable of uniquely identifying a user from their face. Specifically, the Operator does not create, derive, or store any of the following:

2.2 Purposes of processing

  1. Background removal and breed recommendation analysis are performed on the user's device; the server performs no facial recognition and no breed recommendation computation. The face image is transmitted to the server only after processing on the device has been completed.
  2. The server stores the face image solely for the following purposes:
  3. Face photos are not used for facial recognition, identity verification, biometric authentication, determining whether two images are of the same person, advertising, marketing, or user tracking.

2.3 Where face images are stored

  1. Face image files are stored on the PicoPet servers that the Operator builds and manages directly.
  2. The database stores only the address (URL) string of the image, not the image file itself.
  3. Face images are not stored in any external cloud storage (for example, Amazon S3, Google Cloud Storage, or Firebase Storage), and are not transmitted to any external artificial intelligence (AI) API.

2.4 Provision to third parties

  1. The Operator does not sell face images or face-related data, and does not provide or transmit them to advertising networks, analytics services, crash-reporting services, or external artificial intelligence services.
  2. Communication with the social login providers listed in Section 8 is limited to login authentication; Face Data is not included in that communication.

2.5 Retention period

  1. A face image is retained until the user (i) deletes the relevant recommendation result, (ii) resets their recommendation history, or (iii) deletes their account. It is not deleted automatically merely because a period of time has elapsed.
  2. Uploaded files that were not properly linked to a recommendation record or other content during Service processing are automatically deleted after the minimum period necessary.

2.6 How to delete

  1. Users may delete an uploaded face photo through any of the following in the app:
  2. Upon such deletion, the Operator deletes both the database record and the actual image file stored on the server (including any resized images generated from that file).
  3. However, where the user continues to use the same image in another feature (for example, a shared feed post), the image file is retained until that use ends.

3. Purposes of Processing Personal Data

  1. User management, such as user identification and maintaining login status
  2. Storing breed recommendation results and restoring them when the app is reinstalled (for Face Data, see Section 2)
  3. Providing core Service features such as photo decoration, feed, and diary
  4. Preventing misuse and ensuring the stability of the Service
  5. Protecting users, including responding to inquiries
  6. Operating and maintaining the Service and investigating violations of the Terms of Service
  7. Detecting misuse, ensuring account security, and handling reports about posts

4. Retention and Use Period of Personal Data

  1. The user's personal data is retained and used until the account is deleted, and is deleted promptly upon account deletion in accordance with the procedure in Section 5 below. However, the report records referred to in paragraph 2 of that Section are retained for one year from the date of account deletion and are then deleted.
  2. The retention period for face photos is set out separately in Section 2.5.
  3. However, where retention is required under applicable laws, the data is kept for the period prescribed by such laws. (For example, Service access records are kept for 3 months under the Protection of Communications Secrets Act. If paid or payment features are introduced in the future, transaction and payment records may be kept under the Act on the Consumer Protection in Electronic Commerce.)

5. Procedure and Method of Deleting Personal Data

  1. When the user uses "Delete Account" in the app, the Operator deletes the following data without delay. Deletion is carried out both in the database of the Service's operating servers and in the image files linked to those records:
  2. Notwithstanding paragraph 1, reports submitted about posts and comments are retained for one year from the date of account deletion in order to address repeated infringement of rights, protect users, and handle disputes, and are deleted thereafter. Reports whose retention period has expired are deleted by the Operator on a regular basis without any separate request. Such records contain the internal identification numbers of the reporting user and the reported target, the reason for the report, and the date and time of the report; they do not contain any image file, including face photos.
  3. For a user who signed in with an Apple account, the Operator also requests revocation of the login token issued by Apple upon account deletion.
  4. Data in electronic file form is removed without delay from the database and file storage of the Service's operating servers by means of deletion commands, and deleted data can no longer be accessed through the Service.

6. Provision of Personal Data to Third Parties

The Operator does not provide users' personal data to third parties, except where the user has separately consented or where required under the provisions of applicable laws. The provision of Face Data to third parties is set out separately in Section 2.4.

7. Consignment of Personal Data Processing

The Operator does not consign the operation of its Service servers to any external hosting company; the Operator builds and operates the servers directly. All data, including photos uploaded by users (face photos included), is stored only on servers managed directly by the Operator and is not transmitted to external analytics services or artificial intelligence APIs. The Operator does not store users' photos in external cloud storage and does not transmit them to external services for advertising, analytics, or crash-reporting purposes. For the third-party services used to process login, please refer to Section 8.

8. Notice Regarding Social Login and Third-Party SDKs

For login purposes, the Service includes the following third-party SDKs in the app, and communication with each provider's servers occurs during the login process. That communication is limited to the information required for login authentication and does not include photos uploaded by users or any Face Data. Matters concerning each provider's processing of personal data are governed by that provider's own privacy policy.

9. Your Rights and How to Exercise Them

  1. Users may exercise the following rights at any time:
  2. When a user deletes content such as a post, diary entry, or decorated photo, or replaces its image with a different one, the image file linked to that content is deleted together with the database record. However, where the same image is still in use in the user's other content, it is retained until that use ends.
  3. Requests for access, correction, deletion, or suspension of processing that are difficult to handle through the above methods may be made by email to the Privacy Officer in Section 11 below, and the Operator will take action without delay.
  4. Users must be at least 14 years of age to use the Service, and the Operator does not collect the personal data of children under the age of 14.

10. Measures to Ensure the Security of Personal Data

  1. Encryption of data in transit (HTTPS)
  2. Access control based on authentication tokens — the Service APIs require user authentication and verify that the requester is the owner of the data when handling requests to view, modify, or delete their own data, such as recommendation records, posts, and diaries
  3. Image files uploaded by users are accessible only through addresses generated from unguessable random identifiers (UUIDs), and those addresses are provided only through the user's own app screens
  4. Minimization of access privileges for servers and administrator accounts, and retention of access logs
  5. Applying security updates to the operating system and server software
  6. Restricting network access through firewalls and similar measures
  7. Restricting access to files and backups containing personal data

11. Privacy Officer

Users may direct all inquiries, complaints, and requests for remedy regarding the protection of personal data arising during use of the Service to the contact above.

12. Complaints and Remedies

If you need to report or seek advice regarding an infringement of personal data, you may contact the following organizations (all are Korean authorities).

13. Changes to This Privacy Policy

If the contents of this Policy are added to, deleted, or modified, notice will be given via an in-app announcement or this page from 7 days prior to the effective date. However, for any change that is unfavorable or material to users, notice will be given from 30 days prior to the effective date.

Addendum

This Privacy Policy takes effect on August 16, 2026. It replaces the previous Privacy Policy (Version 1.0, effective July 18, 2026) as of that date.

The Korean version of this Privacy Policy is the official version and shall prevail in the event of any inconsistency between the translated versions.