Privacy Policy
Last updated: June 15, 2026 Effective date: June 15, 2026 Version: 1.1
1. Overview
pikle ("Company") values your privacy and complies with applicable laws, including Korea's Personal Information Protection Act (PIPA). This Privacy Policy explains how the Company collects, uses, shares, and protects personal information in connection with the pikle service ("Service").
2. Personal Information We Collect
2.1 Information collected at sign-up
| Category | Items | Required |
|---|---|---|
| Required | Email address or phone number (depending on sign-up method), nickname, username | Required |
| Social login | Social account unique identifier, email (if you consent to share) | Required |
| Optional | Profile photo, date of birth, gender, interests, expertise, hobbies | Optional |
When signing up or verifying with a phone number, it is used to send a one-time verification code (OTP) for identity confirmation.
2.2 Information collected automatically during use
| Category | Items | Purpose |
|---|---|---|
| Device info | Device type, OS version, app version, unique device identifier | Service optimization |
| Usage info | Service usage records, access time, access IP | Service analysis/improvement |
| Vote data | Vote participation records, choices | Service provision |
| Push token | Device token for sending push notifications | Notification delivery |
| Advertising ID | iOS IDFA, Android AAID | Personalized ads, ad performance measurement |
About advertising identifiers
The Company may collect OS-provided advertising identifiers (iOS IDFA / Android AAID) to deliver personalized ads through ad SDKs such as Google AdMob.
- Purpose: personalized ads, ad impression/click measurement, ad fraud prevention
- iOS (App Tracking Transparency): A prompt asking whether to allow tracking appears on first launch; if declined, the IDFA is not collected. You can change this later in iOS Settings → Privacy & Security → Tracking.
- Android: You can reset or disable the advertising ID in Android Settings → Privacy → Ads.
- Declining the advertising identifier does not prevent you from using the Service; ads simply become non-personalized (general) ads.
2.3 Payment & subscription information
When you use the paid membership (PIKLE Pro), the following information is processed. Actual payment is made through Apple App Store / Google Play in-app purchases, and the Company does not directly collect or store payment instrument details such as card numbers.
- Purchase history, subscription status and expiration date, store transaction identifier
2.4 Identity verification information (expert verification only, optional)
Only for users who apply for expert verification, the following information is collected and processed to verify identity. Verification is handled through a dedicated identity-verification provider (Veriff).
- ID document image, face image/video (selfie)
- This is provided only by users who apply for expert verification; it is not collected if you do not apply.
2.5 Additional information that may be collected
- When contacting support: inquiry content, contact details
- When participating in events: shipping address, contact details (if applicable)
3. How We Collect Personal Information
The Company collects personal information through the following methods:
- Sign-up: in-app sign-up process (email or phone number)
- Social login: linking Apple or Google accounts
- Service use: automatic collection during app use
- Identity verification: collection via the identity-verification provider (Veriff) when applying for expert verification
- Customer inquiries: email, in-app contact
4. Purposes of Use
4.1 Service provision
- Member management and identity confirmation
- Expert verification (identity confirmation)
- Payment and subscription management
- Core services such as pickle, 4·8·16, and feed
- Vote tallying and statistics
- Personalized content recommendations
- Push notification delivery
4.2 Service improvement
- Usage statistics analysis
- New service development and improvement of existing services
- AI/algorithm-based service quality improvement
4.3 Safe operation
- Prevention of and sanctions against misuse
- Record retention for dispute resolution
- Legal compliance
4.4 Marketing and advertising (with consent)
- Event and promotion announcements
- Personalized advertising
5. Use of AI and Data Processing
5.1 Purposes of AI use
The Company uses artificial intelligence (AI) and algorithmic technologies to improve service quality:
| Purpose | Processed data | Description |
|---|---|---|
| Content recommendation | Vote records, interests, usage patterns | Personalized feed (Gemini AI feed rule generation) |
| Content embedding | Content text/images | Vector-similarity recommendation (Gemini Embedding) |
| Content labeling | Images, text | Automatic categorization and detection of inappropriate content |
| Statistical analysis | Anonymized vote data | Generating vote-result statistics |
| Abuse detection | Usage patterns, images | Detecting spam/malicious content |
5.2 Algorithm-based data processing
Algorithm-based processing is performed within the scope necessary to operate the Service, such as content recommendation and feed ranking.
5.3 Automated decision-making
- Automated decision-making applies to content recommendation, feed ranking, etc.
- You may object to automated decisions.
6. Retention and Destruction
6.1 Retention periods
| Category | Retention period | Basis |
|---|---|---|
| Member information | Until account deletion | Service provision |
| Individual vote records | 90 days (aggregates retained anonymized) | Service, statistics |
| Content view records | 90 days | Service improvement |
| Content impression records | 30 days | Feed optimization |
| Notification records | 90 days | Service provision |
| Search records | 90 days | Service improvement |
| Profile visit records | 90 days | Service provision |
| Chat messages (text) | While the account is active | Service provision |
| Chat media (photos/videos) | 14 days | Storage management |
| Feed personalization rules | 7 days | Service improvement |
| Misuse records | 5 years | Recurrence prevention |
6.2 Retention required by law
| Category | Retention period | Legal basis |
|---|---|---|
| Access logs (login IP, time, device) | 6 months | Protection of Communications Secrets Act |
| Personal data processing logs (view/edit/delete) | 3 years | PIPA |
| Contract / withdrawal records | 5 years | Act on Consumer Protection in E-Commerce |
| Consumer complaint/dispute records | 3 years | Act on Consumer Protection in E-Commerce |
6.3 Destruction method
- Electronic files: permanently deleted by irrecoverable means
- Paper documents: shredded or incinerated
7. Provision to Third Parties
In principle, the Company does not provide personal information to third parties without your consent. Exceptions:
- When you have consented in advance
- When required by law
- Outsourcing to external vendors essential for the Service (see Section 8)
8. Outsourcing of Personal Information Processing
The Company outsources personal information processing as follows:
| Processor | Outsourced task | Server location | Retention |
|---|---|---|---|
| Supabase (AWS) | Database hosting, authentication | Seoul (ap-northeast-2) | Until end of contract |
| Google Cloud (Gemini) | AI content analysis, embedding, feed rule generation | USA | Processed per Google policy (not used for model training) |
| Cloudflare Images | Image storage, CDN, optimization | Global | Until end of contract |
| Cloudflare Stream | Video storage, transcoding, streaming | Global | Until end of contract |
| Veriff (Veriff OÜ) | Identity verification for expert verification (ID/face) | EU (Estonia) | Destroyed after verification per Veriff policy |
| RevenueCat | Subscription/payment status management | USA | During subscription management |
| Google (Firebase) | Push notification delivery, phone number verification (OTP) | USA | Until end of contract |
| Sentry | Error/crash diagnostics | USA | Until diagnostic purpose is fulfilled |
| OpenAI | Content moderation | USA | Processed per OpenAI policy (not used for model training) |
| Google AdMob | Personalized ads and performance measurement | USA | Per Google policy |
8.5 Cross-Border Transfer of Personal Information
Personal information may be transferred overseas to provide the Service:
| Recipient | Country | Items transferred | Purpose | Time & method | Retention |
|---|---|---|---|---|---|
| PIKLE, Inc. (Delaware, USA) | USA (Delaware) | Member info, posts, activity records, etc. | Service operation and provision | At sign-up, via TLS encryption | Until account deletion |
| Google Cloud (Gemini AI) | USA | Content text (anonymized) | AI analysis, embedding | At request, via TLS encryption | Per Google policy |
| Cloudflare Images | Global CDN | Image files | Storage and CDN distribution | At upload, via TLS encryption | Until original deleted |
| Cloudflare Stream | Global CDN | Video files | Storage, transcoding, streaming | At upload, via TLS encryption | Until original deleted |
| Veriff (Veriff OÜ) | EU (Estonia) | ID document image, face image/video | Expert verification (identity) | At application, via TLS encryption | Destroyed after verification |
| RevenueCat, Inc. | USA | User identifier, purchase/subscription history | Subscription/payment management | At payment, via TLS encryption | During subscription management |
| Google (Firebase) | USA | Push token, phone number | Notification delivery, phone verification | When applicable, via TLS encryption | Until end of contract |
| Sentry (Functional Software, Inc.) | USA | Error logs, device/app info | Error/crash diagnostics | On error, via TLS encryption | Until diagnostic purpose fulfilled |
| OpenAI, L.L.C. | USA | Content under review (text/image) | Inappropriate content review | At request, via TLS encryption | Per OpenAI policy |
| Google AdMob | USA | Advertising ID (IDFA/AAID) | Personalized ads | On ad impression | Per Google policy |
pikle is operated by PIKLE, Inc. (Delaware, USA). All member data is stored on infrastructure under PIKLE, Inc.'s control (Supabase Seoul region) and is then processed by PIKLE, Inc. (USA) to provide the Service. You are deemed to consent to this cross-border transfer upon sign-up.
9. Your Rights
You may exercise the following rights:
9.1 Rights
- Right to access: request access to collected personal information
- Right to rectification: request correction of inaccurate information
- Right to erasure: request deletion of personal information
- Right to restrict processing: request suspension of processing
- Right to withdraw consent: withdraw consent to processing
- Right to data portability: request transfer of your data
9.2 How to exercise
- In-app Settings > Privacy management
- Email: contact@pikleapp.com
- Customer support inquiry
9.3 Processing timeline
Within 10 days of receipt (up to 30 days for complex cases)
10. Security Measures
10.1 Technical measures
- Encryption of personal information (SSL/TLS in transit, encryption at rest)
- Access permission management and access control
- Installation and update of security programs
- Technical safeguards against hacking
10.2 Administrative measures
- Minimizing staff who handle personal information
- Regular security training
- Access-log management for processing systems
11. Children's Personal Information
- The Company does not collect personal information from children under 14.
- Users under 14 cannot sign up.
- If we learn that information from a child under 14 has been collected, we delete it immediately.
12. Cookies and Tracking Technologies
12.1 Purposes
- Maintaining login state
- Providing usage convenience
- Usage-statistics analysis
12.2 How to opt out
- You can change cookie/tracking permission in device settings
- Some features may be limited if declined
13. Privacy Officer
| Field | Information |
|---|---|
| Name | Cheolgon Lee |
| Title | Privacy Officer |
| contact@pikleapp.com |
14. Remedies for Infringement
For remedies regarding personal information infringement, you may contact:
- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office Cybercrime Division: spo.go.kr / 1301
- National Police Agency Cyber Bureau: cyberbureau.police.go.kr / 182
15. Changes to This Policy
- This Policy may be revised in line with laws, policies, or service changes.
- Material changes are announced 7 days before they take effect, via in-app notice or email.
- Change history is recorded at the bottom of this document.
Change History
Version 1.1 — 2026-06-15
- Added phone number, identity verification (ID/face), payment/subscription, and push token to collected items
- Added Veriff (identity), RevenueCat (payment), Google Firebase (push/phone verification), Sentry (error diagnostics), OpenAI (moderation), and Google AdMob (ads) to processors and cross-border transfers
- Corrected social login to the actually provided scope (Apple, Google)
- Corrected vote-record retention to actual operation (individual 90 days, aggregates anonymized)
- Tidied AI data-processing wording (5.2); softened Gemini/OpenAI processing claims
Version 1.0 — 2026-04-26 (initial release)
- Initial release