Privacy Policy
Effective date: June 6, 2026 | Last updated: August 28, 2026
This document is a translation provided for reference. In case of any discrepancy with the Korean original, the Korean original prevails, and governing law and jurisdiction follow the provisions of the original.
Table of contents
- Personal information items collected and collection methods
- Purpose of Collection and Use of Personal Information
- Retention and Use Period of Personal Information
- Outsourcing of Personal Information Processing
- Overseas Transfer of Personal Information
- Provision of Personal Information to Third Parties
- Procedure and Method for Destruction of Personal Information
- User Rights and How to Exercise Them
- Personal information of children under 14
- Automatic Personal Information Collection Devices (Cookies, etc.)
- Personal Information Protection Officer
- Changes to the Privacy Policy
FineHour Inc. (the "Company") values users' personal information in connection with operating RightPose AI (the "Service") and complies with the Personal Information Protection Act (Korea) and related laws. This policy describes the personal information the Company collects, uses, retains, and destroys.
1. Personal information collected and collection methods
1-1. Items collected while using the Service
| Category | Items collected | Collection method |
|---|---|---|
| Sign up / Log in | Email address, Firebase UID, OAuth authentication token (With Google sign-in: Google account name and profile image are not stored) | Entered directly by the user, Firebase Authentication |
| Profile survey (optional) | Birth year, gender, occupation, how you heard about the service | Entered directly by the user during app onboarding |
| Subscription payment | Order number, payment method type, payment approval key, email address for upcoming payment notifications (entered by the user) (The Company does not collect raw payment details such as card number or CVC — handled by Toss Payments) | Payment outsourced to Toss Payments; entered directly by the user |
| Service usage records | Anonymous visitor ID (local storage, randomly generated), app download count, per-account most recent login and posture monitoring run dates (by day) | Collected automatically |
| Error diagnostic reports | Error message and stack, app version, screen path where the error occurred, and (if signed in) member identifier (UID) Separately, the on-device log file (~/.rightpose/rightpose.log) is stored only on your device | Sent automatically when an error occurs / generated automatically by the app (locally) |
| Reviews, surveys, and inquiries (optional) | Reviews: nickname, one-line intro (occupation, etc.), star rating, review text Satisfaction survey (NPS): score, comments Inquiries and feedback: inquiry content, attached images, account email | Entered directly by the user |
🔒 Posture analysis images are never sent to or collected on our servers.
Camera footage is processed only on the user's device (locally) and is under no circumstances transmitted to servers or collected by the Company. Images are deleted from memory immediately after analysis, and only when the user, in the app settings, 'Save photos' is turned on, and even then they are stored encrypted (AES-GCM) only on the user's device. Stored photos can be deleted from the app at any time, and in no case are they transmitted to a server.
Personal information of advertisers applying to place ads (contact name, contact details, etc.) is governed by a separate Consent to Collection and Use of Personal Information for Ad Services apply.
1-2. Information we do not collect
- Unique identifiers such as resident registration numbers and passport numbers
- Health/medical information, biometric information — posture assessment records and statistics are stored only on the user's device
- Location data
- Camera footage and posture analysis images (not collected on servers — see notice above)
2. Purpose of collecting and using personal information
| Items collected | Purpose of use |
|---|---|
| Email, Firebase UID | Service operations such as member identification, login and account management, and new sign-up processing |
| Profile survey (birth year, gender, occupation, how you found us) | User statistics analysis and service improvement (e.g., feature improvements by age group) |
| Payment information (keys provided by Toss Payments) | Processing subscription payments, refunds, and issuing receipts |
| Upcoming payment notice email | Sending advance notice emails for upcoming recurring (auto-renewal) payment dates |
| Anonymous visitor ID, per-account usage dates | Service usage statistics and feature improvement |
| Error diagnostic reports | Analyzing causes of service outages/errors and improving quality |
| Reviews (nickname, content, etc.) | Published on the service homepage after review (promotion) — notice and consent given at time of writing |
| Satisfaction survey (NPS) and inquiry details | Measuring service satisfaction, handling inquiries, and sending replies |
3. Retention and use period of personal information
| Item | Retention period | Basis |
|---|---|---|
| Account information (email, UID), profile survey | Until account deletion | User consent |
| Payment history | 5 years from the payment date | Article 6 of the E-Commerce Act (Korea) |
| Records of consumer complaints and dispute handling (including inquiries) | 3 years | Article 6 of the E-Commerce Act (Korea) |
| Error diagnostic reports (server logs) | Automatically deleted 30 days after collection | User consent |
| Reviews | For the duration of publication (deleted immediately upon request) | User consent |
| Anonymous visitor ID | Stored only in browser local storage, not linked to your account | User consent |
4. Outsourcing of personal information processing
The Company outsources the processing of personal information as described below in order to provide the Service.
| Contractor | Outsourced tasks | Retention and use period |
|---|---|---|
| Toss Payments Co., Ltd. | Credit card and easy-pay processing, payment cancellations and refunds | 5 years after payment completion, or until the outsourcing contract ends |
| Google LLC (Firebase / Google Cloud) | Member authentication (Authentication), data storage (Cloud Firestore/Storage), serverless function execution (Cloud Functions), web hosting, error log collection (Cloud Logging), notification emails (Gmail) | For the duration of Service use (error logs: 30 days) |
5. Overseas transfer of personal information
To operate the service infrastructure, the Company stores and processes personal information overseas as described below. Users may refuse the overseas transfer, but in that case use of the Service may be restricted.
| Category | Details |
|---|---|
| Recipient | Google LLC (USA) — Firebase / Google Cloud |
| Items transferred | Account information (email, UID), profile survey, subscription and payment status, usage records, error reports, inquiries and reviews |
| Destination country and date of transfer | Countries where Google data centers are located, including the US / As needed while using the service |
| Method of transfer | Transmission via information and communications networks |
| Retention and use period | Same as the retention period in Article 3 of this Policy |
| How to opt out | Delete your account or request it from the Privacy Officer (Article 10) |
The Korea region (asia-northeast3, Seoul) is used by default, but some processing, such as authentication and logging, may take place on Google's global infrastructure.
6. Provision of personal information to third parties
The Company does not provide personal information to third parties without the User's consent, except in the following cases.
- Where the user has given prior consent
- Where a legal obligation exists, such as a request from an investigative agency under applicable law
7. Procedure and method for destroying personal information
Personal information is destroyed without delay once the retention period has elapsed or the purpose has been fulfilled.
- Electronic files: Permanently deleted in a way that cannot be restored
- Paper documents: Not applicable (the Company does not hold personal information in paper form)
When you delete your account, your account information (including the profile survey) is deleted immediately; only payment information that must be retained by law is kept for the required period and then destroyed. Posture records and photos stored on your device can be deleted by you directly, either by uninstalling the app or using the in-app delete function.
8. Users' rights and how to exercise them
The user may exercise the following rights at any time.
- Request to access personal information
- Request to correct or delete personal information
- Request to suspend processing of personal information
- Account deletion — via the app's My Page or by email request
To exercise your rights, email the Privacy Officer listed below; requests are handled within 10 business days.
9. Personal Information of Children Under 14
The Company does not collect personal information from children under 14, and children under 14 may not sign up. At sign-up, users must confirm that they are 14 or older, and if we learn that personal information of a child under 14 has been collected, we will delete it without delay.
10. Automatic personal information collection devices (cookies, etc.)
The Service website does not use advertising or tracking cookies. To identify visitors, it uses the browser's localStorage stores only an anonymous ID, which is deleted when browser data is cleared. To keep you signed in, Firebase Authentication uses browser storage (localStorage and IndexedDB).
11. Personal Information Protection Officer
| Full name | Ung Ji |
|---|---|
| Title | CEO |
| finehour@fine-hour.com | |
| Contact | 050-6866-9305 |
You may also file complaints or seek remedies regarding personal information processing with the following organizations.
- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 (no area code)
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office, Cyber Investigation Division: www.spo.go.kr / 1301 (no area code)
- Korean National Police Agency Cyber Bureau: ecrm.police.go.kr / 182 (no area code)
12. Changes to this Privacy Policy
This Policy may be revised with prior notice in response to changes in laws or policies. Revisions will be announced via a website notice and in-app notification.
- Revised August 28, 2026 — added the children-under-14 clause and introduced a sign-up consent step (age 14+, terms, and privacy)
- Revised July 10, 2026 — added profile survey, upcoming-payment notification emails, error diagnostic reports, and review/survey/inquiry items; added notice on encrypted on-device storage of posture photos; added overseas transfer clause; clarified outsourcing details
- Enacted and effective June 6, 2026
If you need a previous version of the Privacy Policy,finehour@fine-hour.com.