Entory Privacy Policy

choicode (the "Company", "we") operates the AI picture-diary service "Entory" (the "Service"). This Privacy Policy explains what personal information we collect, how we use and protect it, and the rights you have over it.

1. Information We Collect

Category Data How it is collected
Guest (anonymous) use Anonymous session identifier, uploaded photos, diary text Generated automatically / entered by you when using the Service before signing up
Required (sign-up) Email address, social account identifier (Google/Apple), nickname During Google/Apple OAuth authentication
Service use Photos you upload, diary text and comments, album names, style settings you create, app language setting Entered or uploaded by you
AI-generated results AI-transformed images, AI-written letter text Generated automatically when you use AI features
Collected automatically Device information (OS version), service usage records (album sharing, invitations, and visit history; in-app behavioral events), access logs Generated automatically while you use the Service
Paid service Subscription status, payment history identifiers (we do not collect card details — Apple/Google hold them) During in-app purchase
Photo card printing (when the service launches) Recipient name, contact number, shipping address, information required for customs clearance on international shipments (e.g., personal customs codes), payment history identifiers (we do not collect card details — the payment service provider holds them) Entered by you when placing a print order / generated during payment
Consent records Date and time of consent or withdrawal, consent items and version, IP address, device information Recorded automatically when you give or withdraw consent (terms of service, privacy policy, international transfer)
Report records Reported target and reason, detail memo, reporter identifier, date and time Entered by you / recorded automatically when you report content in the app
Block records Identifier of the blocked user, date and time Recorded automatically when you block a user in the app

2. How We Use Information

  1. Identifying members and handling sign-up, account management, and account deletion
  2. Providing the Service — diary creation and storage, AI image transformation, and related features (including anonymous use before sign-up)
  3. Managing paid subscriptions and calculating usage limits (including the free allowance)
  4. Preventing fraudulent use of the Service and handling infringement reports
  5. Producing and shipping printed photo cards (when the printing service launches)
  6. Complying with legal obligations

3. Data Retention

Data Basis Period
Records of contracts, order withdrawal, payment, and supply of goods Korean e-commerce law 5 years
Records of consumer complaints and dispute handling Korean e-commerce law 3 years
Access logs Service security, fraud prevention, and compliance with statutory retention obligations 1 year

4. Service Providers and International Data Transfers

We entrust parts of data processing to the service providers below. Each provider processes data in the listed country; depending on where you live, some of this processing constitutes a transfer of your data outside your country.

Provider Task Data processed Country / location Retention
Google LLC (Vertex AI) AI image transformation Photos, text you enter in AI transformation and style-creation flows United States and other Google Cloud operating countries (see the AI processing section below) Not stored after processing, except that a request flagged as suspected abuse may be retained and reviewed for up to 90 days (see the AI processing section below)
Supabase, Inc. Database, authentication, and image storage hosting Account information, service data, original photos and transformed results Republic of Korea (Seoul, ap-northeast-2) Until account deletion
RevenueCat, Inc. Subscription management Anonymous identifier, subscription status United States Statutory retention period after subscription ends
Resend, Inc. Report-related email delivery Report identifier, report reason and memo, reporter identifier (internal identifier), email addresses of notice recipients (reporter and poster) United States Deleted 30 days after sending
Expo (650 Industries, Inc.) Web page hosting (Terms, this Policy, invite-link landing) and app update delivery Visitor IP address, access logs, invite-link tokens (via URL) United States Deleted after the hosting infrastructure's standard log retention period
Payment service provider (to be determined at photo card launch) Payment for the printing service Payment information Statutory retention period (Korean e-commerce law, 5 years)
Printing and shipping partner (to be determined at photo card launch) Photo card production and delivery Images to be printed; recipient name, contact number, and shipping address Deleted after delivery is complete

International AI processing

To perform AI style transformation, photos you upload and text you enter are processed outside your country:

No biometric processing. We process photos solely to generate a stylized illustration. We do not use photos for facial recognition, identity verification, or to identify, match, or track any individual, and we do not create, receive, or store face geometry, faceprints, biometric templates, or facial embeddings. We do not use any face detection or face recognition service.

Where the law of your country requires consent for this transfer, we ask for it in an in-app consent screen before your first AI transformation, and you may withdraw it at any time in [Settings > International Transfer Consent]. Withdrawing (or declining) consent means the AI transformation feature — the core feature of the Service — cannot be used.

5. No Sale of Personal Information; Disclosure to Third Parties

We do not sell or share your personal information for advertising. We do not disclose it to third parties, except:

  1. to the service providers in Section 4, or where disclosure is required by a lawful request from a competent authority; or
  2. when you request a refund of a paid subscription from an app marketplace and the marketplace operator asks us for information needed to evaluate the request — with your consent, we provide the following.
Recipient Information provided Purpose Retention
Apple Inc. or Google LLC (only the marketplace where the refund was requested) Subscription usage information: account tenure, whether payments or prior refunds exist, and whether and to what extent paid features were used Supporting the review of the refund you requested Per the recipient's privacy policy

6. Your Rights

You may exercise the following rights at any time:

  1. Access and correction: your account information is available in the in-app settings; for corrections, contact the privacy officer below.
  2. Deletion (account deletion): [Settings > Delete Account] in the app — after confirming the deletion scope, all data is permanently deleted from all systems immediately.
  3. Data export: on request to the privacy officer below, we provide your data in a machine-readable format.
  4. Withdrawal of consent: via in-app settings or by contacting the privacy officer below.

You may exercise these rights through an authorized agent. We respond to requests within 10 days of receipt.

7. Deletion Procedure and Method

8. Security

  1. Encryption in transit (TLS) and access control on stored data (Row Level Security)
  2. Minimization and management of access privileges
  3. Retention of access records
  4. Data sent for AI processing is not used for model training and is not stored, except where it is retained for abuse monitoring (see the international AI processing section).

9. Age Requirement

The Service is intended for persons who are 18 years of age or older. We do not knowingly collect personal information from persons under 18. Persons under 18 may not access or use the Service, including as a Guest User. If we learn that a person under 18 has used the Service, we may restrict or terminate access and delete the related personal information, subject to any retention required by applicable law.

10. Privacy Officer and Contact

Privacy officer Eunhye Choi (Representative)
Contact entory@choicode.com

If you are in the Republic of Korea, you may also contact the Personal Information Infringement Report Center (privacy.kisa.or.kr / 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972).

11. Changes to This Policy

When we change this Policy, we will give notice through an in-app announcement or by posting on this page at least 7 days before the change takes effect (30 days for material changes).