Holoceive Inc. (the "Company") treats users’ personal data with care and complies with the Personal Information Protection Act and other applicable laws of the Republic of Korea. This Privacy Policy explains how personal data is handled in NUIRUMI (the "Service").
NUIRUMI does not transmit photos or videos taken with the camera to the Company’s servers. Captures are stored only on the user’s device, and plush recognition and part tracking are processed on the device.
Article 1 (Personal Data Collected and How It Is Collected)
1. Collected for registration and account management (required)
Social sign-in identifier (X, Apple, Google)
Email address. When signing in with an X account no email is provided, so none is collected.
Nickname. If the user does not enter one, the Company assigns a value.
2. Generated automatically while the Service is used
Device and app information, access IP address, access time, service usage records, error logs
3. Stored in the Service by the user
Pattern data and pattern thumbnail images the user saved
Pattern view records, received-pattern records, report records
4. Not collected by the Company
Photos and videos taken with the camera
Legal name, date of birth, gender, phone number, address
Payment information. The Service has no paid purchases.
Location data, contacts, advertising identifiers
Collection methods: the social sign-in process, automatic generation during app use, and direct entry by the user.
Article 2 (Purposes of Collection and Use)
Providing and operating the Service: maintaining accounts, providing pattern saving and sharing
Member management: identifying members, preventing misuse, handling enquiries
Maintaining a healthy environment: receiving and processing reports
Improving the Service: responding to errors, analysing usage statistics
Article 3 (Retention and Use Period)
Account information is retained until the member requests account deletion.
On a deletion request, the nickname is deleted immediately, and the pattern data and thumbnails the user saved are destroyed immediately.
For pattern codes, only the code value and its ownership record remain in a disabled state, so that the same code cannot be reissued to another user.
If the user signs in again with the same social account after deletion, the account is reactivated.
Records that must be preserved under applicable law are kept for the period that law prescribes and then destroyed.
Article 4 (Destruction Procedure and Method)
Procedure: personal data whose purpose of collection and use has been achieved is retained for a set period under internal policy and applicable law, then destroyed.
Method: information in electronic file form is deleted by technical means that make recovery impossible.
Article 5 (Provision to Third Parties)
The Company does not provide users’ personal data to third parties, except with the user’s prior consent or upon a lawful request from an investigative authority under applicable law.
Article 6 (Entrustment of Processing)
For smooth operation of the Service, the Company entrusts processing as follows.
Amazon Web Services, Inc. — server operation and data storage
Google LLC — delivery of app remote configuration values (Firebase Remote Config)
Article 7 (Transfer of Personal Data Abroad)
The Company stores personal data on servers located outside the Republic of Korea while providing the Service.
Items transferred: account information, nickname, pattern data, service usage records
Destination country: Japan (Amazon Web Services Asia Pacific Tokyo region)
Recipient: Amazon Web Services, Inc.
Timing and method: transmitted over the network when the Service is used
Retention: for the period set out in Article 3
A user may refuse the transfer of personal data abroad, in which case member features may be unavailable.
Article 8 (User Rights and How to Exercise Them)
A user may view or correct their personal data at any time and may request account deletion.
Changing the nickname, setting creator crediting, and deleting the account can be done directly from the settings screen in the app.
Other requests may be sent to the privacy officer’s email in Article 11, and the Company will act without delay.
Article 9 (Protection of Children Under 14)
The Company does not collect personal data from children under 14 without the consent of a legal guardian. If such collection is discovered, the data is destroyed without delay. Camera features that do not require signing in can be used without any collection of personal data.
Article 10 (Technical and Administrative Safeguards)
All communication with the server is encrypted with HTTPS.
Sign-in tokens are kept in the device’s secure storage.
Access to personal data is limited to the minimum number of personnel.
The plush recognition model runs on the device, so captured footage does not leave it.
Article 11 (Privacy Officer)
Name: JOO YOUNGJIN
Position: Representative
Email: jin@holoceive.com
Article 12 (Changes to This Policy)
If this Privacy Policy is added to, deleted from or amended, notice will be given within the Service at least 7 days before the effective date.
Addendum
This Privacy Policy takes effect on 8 September 2026.