Effective dates are based on Korea Standard Time (KST).

[Pebbling] Privacy Policy

Our Privacy Promise

Hello, and thank you for trusting Pebbling with your personal reflections. Your privacy and trust are our top priorities.

  • We use your information only to improve your service experience.
  • We never sell or share your personal data for advertising or commercial purposes.
  • All records are encrypted and securely stored. Even Pebbling’s team cannot access the original content of your entries.
  • During data analysis, individuals cannot be identified — all data are pseudonymized or anonymized.
  • We are committed to full transparency about what we collect, how we use it, and with whom we share it.

Article 1 (Purpose of Processing Personal Information)

Pebbling processes personal information for the following purposes:

  1. Account creation and management
  2. Service provision and operation (e.g., saving and viewing records)
  3. Customer support and inquiries
  4. Legal compliance (e.g., tax, consumer protection)
  5. Improving service quality and user experience
  6. Marketing and communications (only with separate user consent; refusal does not affect core service use)
  7. Emergency protection of life, body, or property, when required

Article 2 (Categories of Personal Information Processed)

CategoryData CollectedPurpose of Use
Account Registration[From Apple/Google] Name (or nickname), EmailAccount creation and management
Service Use (User Input)Preferred pronoun (he/she/they), Journal entries (text)Record storage and retrieval
Service Use (Automatically Collected)Pseudonymous ID, device information (OS, app version, model), access logs, error logs, ad identifiers (ADID/IDFA), cookies and similar technologiesService improvement, analytics, and security management
Future Features (Planned)Photos, external links, community posts, AI recommendation dataFor providing new features

Information Not Collected:

  • Passwords: Only social logins are supported; no password storage.
  • Payment details: In-app purchases are processed via App Store or Play Store; no financial data (e.g., card numbers) are stored by Pebbling.

Article 3 (Retention and Destruction of Personal Information)

  • General Rule: Data are deleted immediately upon account deletion. Backup data are securely removed within a regular system cycle.
  • Retention by Law:
    • Contract, withdrawal, and payment records — 5 years
    • Consumer complaints or dispute records — 3 years
    • Advertising and display records — 6 months
    • Tax-related transaction records — 5 years
  • Fraud Prevention: Data may be retained for up to 1 year to prevent illegal registrations or misuse.
  • Destruction Method: Electronic files are permanently deleted beyond recovery; paper documents are shredded or incinerated.

Article 4 (Provision of Personal Information to Third Parties)

Pebbling does not share personal data with third parties unless:

  • Required by law, or
  • The user has provided explicit consent for a specific purpose.

Article 5 (Entrusted Processing and Overseas Transfers)

ProcessorCountryPurpose of ProcessingDataRetention Period
SupabaseKorea (Seoul), U.S.Database hostingAll collected data in Article 2Until account deletion or contract termination
Google FirebaseU.S. and othersError monitoring & analyticsLogs, device info, ad IDAccording to Google policy
Apple App Store / Google PlayVariousIn-app purchase processingPayment metadataAccording to store policy
Meta SDKU.S. and othersMarketing performance measurementAdvertising IDAccording to Meta policy

Article 6 (Reasonably Related Use Beyond Original Purpose)

Pebbling may use or provide personal data for purposes reasonably related to the original intent of collection, considering factors such as user expectations, relationship relevance, and data security.

Article 7 (User and Legal Guardian Rights)

  • Users may request access, correction, deletion, suspension of processing, or withdrawal of consent at any time.
  • Requests can be made via the in-app inquiry form, by email ([email protected]), or in writing.
  • For minors, legal guardians may exercise the same rights on behalf of the user with proper authorization.
  • Some data may be retained if required by law (e.g., tax records).
  • California Residents (CCPA/CPRA): Have rights to access, correct, delete, and opt-out of data sharing.
  • International Users (e.g., GDPR): Have the right to file complaints with their national data protection authorities. In Korea, users may contact the Personal Information Protection Commission (www.pipc.go.kr, ☎118).

Article 8 (Breach Notification)

If any data breach or leakage occurs, Pebbling will promptly notify affected users and relevant authorities as required by law, including details on the breached items, time of occurrence, response measures, and mitigation steps.

Article 9 (Data Security Measures)

  • Administrative: Internal management plan, staff training
  • Technical: Data encryption in storage and transmission, access control minimization, security software installation
  • Physical: Restricted access to servers, controlled data storage areas

Article 10 (Data Protection Officer)

  • Name: Hyunwoo Hwang
  • Title: CEO / Data Protection Officer
  • Email: [email protected]
  • Address: 40 Dongil-ro 186-gil, Nowon-gu, Seoul, Republic of Korea

Article 11 (Changes to This Policy)

This Policy takes effect from the date below.

  • Material changes (e.g., new data categories or third-party sharing): announced 30 days before enforcement.
  • General updates: announced 7 days prior.

📌 Business & Data Controller Information

  • Effective Date: September 19, 2025
  • Company Name: Mongle Labs
  • Address: 40 Dongil-ro 186-gil, Nowon-gu, Seoul, Republic of Korea
  • Data Protection Officer: Hyunwoo Hwang (CEO)
  • Email: [email protected]

[Pebbling] Privacy Policy

Pebbling's Privacy Promise

Hello, this is the Pebbling team.

Thank you for entrusting your precious personal reflections to Pebbling. Your privacy and trust are our top priorities.

  • We use your information only to provide a better service experience. We never use personal information for advertising or third-party sale purposes.
  • All records are encrypted and stored securely. The records you create are stored in encrypted form, and even Pebbling's operations team cannot directly view the original content.
  • Individuals cannot be identified during data analysis. We manage data through pseudonymization and anonymization so that individuals cannot be identified.
  • We disclose everything transparently. This Policy clearly explains what information we collect, how we use it, and with whom we share it.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes.

  1. Membership registration and account management
  2. Service provision and operation, such as storing and viewing records
  3. Handling complaints and responding to customer inquiries
  4. Complying with legal obligations, such as tax and consumer protection laws
  5. Improving service quality and user experience
  6. Marketing and advertising, only when the user has separately consented; refusal of consent does not restrict use of the basic service
  7. Minimum processing necessary to protect life, body, or property in emergency situations

Article 2 (Personal Information Processed)

CategoryCollected ItemsPurpose of Use
Membership Registration[Provided by Apple/Google] Name (or nickname), emailAccount creation and management
Service UsePreferred reference (he/she/that person), written records (text), photosRecord storage and viewing
Service Use (Automatically Collected)Pseudonymous ID, device information (OS, app version, model name), access logs, error logs, cookies and similar technologiesService improvement and analytics, security management
Future Features (Planned)External links, community posts, AI recommendation-related dataProviding new features

Information We Do Not Collect

  • Passwords: Only social login is supported, and passwords are not stored.
  • Payment information: In-app payments are processed through the app stores, and card numbers or other financial information are not stored.

Article 3 (Retention and Destruction of Personal Information)

  1. General rule: Personal information is destroyed without delay when a member withdraws. However, backup data is securely deleted within a regular system cycle for operational reasons.
  2. Retention required by law
    • Records of contracts, withdrawal of offers, and payments: 5 years
    • Records of consumer complaints and dispute handling: 3 years
    • Records of labeling and advertising: 6 months
    • Tax-related transaction books and supporting documents: 5 years
  3. Prevention of misuse: Information may be retained for 1 year when necessary to prevent fraudulent registration or misuse.
  4. Destruction procedure and method: Electronic files are securely deleted so they cannot be restored, and paper documents are shredded or incinerated.

In-app payments are processed through Apple/Google, and the Company does not store card numbers or other sensitive payment information. However, purchase status, such as subscription status, and receipt identifiers may be retained for the legally required period to provide the Service.

Article 4 (Provision of Personal Information to Third Parties)

  1. The Company does not provide personal information to third parties in principle.
  2. However, information may be provided within the minimum necessary scope when there is a legal basis or when the user has separately consented.

Article 5 (Entrusted Processing and Overseas Transfer of Personal Information)

ProcessorCountryEntrusted WorkItemsRetention and Use Period
SupabaseRepublic of Korea (Seoul), United StatesDatabase hostingAll collected items in Article 2Until withdrawal or termination of entrustment
Google FirebaseUnited States and othersError monitoring and analyticsLogs, device information, advertising IDAccording to the processor's policy
Apple App Store / Google PlayVarious countriesIn-app payment processingPayment-related metadataAccording to the store's policy

The processors' servers may be located overseas, and in such cases personal information may be transferred to the relevant countries.

Article 6 (Use Within a Scope Reasonably Related to the Purpose of Collection)

The Company may additionally use or provide personal information within a scope reasonably related to the original purpose of collection, after comprehensively considering relevance, predictability, and whether security measures are in place.

Article 7 (Rights and Obligations of Users and Legal Guardians, and How to Exercise Them)

  1. Users may request access, correction, deletion, suspension of processing, or withdrawal of consent for personal information at any time.
  2. Rights may be exercised through various methods, including in-app inquiries, email ([email protected]), or written requests.
  3. For minors, legal guardians may exercise the same rights, and the representative must submit a power of attorney.
  4. Some rights may be restricted under applicable laws, and information that must be retained under laws such as tax laws cannot be deleted.
  5. California residents (CCPA/CPRA): You have the rights to access, delete, and correct information and to opt out of information sharing.
  6. International rights (including GDPR): You have the right to lodge a complaint with the personal information protection supervisory authority in your country of residence. Korean users may file complaints with the Personal Information Protection Commission (www.pipc.go.kr, 118).

Article 8 (Personal Information Breach Notification)

If the Company becomes aware of a personal information leak or other breach, it will notify data subjects and supervisory authorities without delay in accordance with applicable laws. The notice may include the leaked items, time of occurrence, response measures, and measures to minimize harm.

Article 9 (Measures to Ensure Security of Personal Information)

  • Administrative measures: Establishment of an internal management plan and employee training
  • Technical measures: Encrypted storage and transmission, minimum access privileges, and installation of security programs
  • Physical measures: Access control for server rooms and management of data storage areas

Article 10 (Data Protection Officer)

  • Name: Sein Kim
  • Title: Representative
  • Email: [email protected]

Article 11 (Changes to This Privacy Policy)

  • This Policy applies from the effective date.
  • Material changes: Notice 30 days before enforcement
  • General changes: Notice 7 days before enforcement

Business and Data Protection Officer Information

  • Effective Date: July 15, 2026
  • Business Name: Sein Kim
  • Address: 442, 4F, 1055 Dongil-ro, Nowon-gu, Seoul, Republic of Korea
  • Data Protection Officer: Representative
  • Official Email: [email protected]

[Pebbling] Privacy Policy

Pebbling's Privacy Promise

Hello, this is the Pebbling team at Mongle Labs.

Thank you for entrusting your precious personal reflections to Pebbling. Your privacy and trust are our top priorities.

  • We use your information only to provide a better service experience. We never use personal information for advertising or third-party sale purposes.
  • Records are stored securely in accordance with cloud security standards. Your records are encrypted at the disk level in a secure cloud environment, and our team does not arbitrarily access them except when necessary for service operations or customer support.
  • Your records are not used to train AI models. We may send record text to an external AI service to provide a better experience and personalized feedback, but we do not opt in to providing that data for model training. The AI provider may retain abuse-monitoring logs for up to 30 days.
  • We do not send account identifiers such as your name or email together with record text for AI analysis.
  • We disclose everything transparently. This Policy clearly explains what information we collect, how we use it, and with whom we share it.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes.

  1. Membership registration and account management
  2. Service provision and operation, such as storing and viewing records, AI analysis, and personalized feedback
  3. Handling complaints and responding to customer inquiries
  4. Complying with legal obligations, such as tax and consumer protection laws
  5. Improving service quality and user experience
  6. Marketing and advertising, only when the user has separately consented; refusal of consent does not restrict use of the basic service
  7. Minimum processing necessary to protect life, body, or property in emergency situations

Article 2 (Personal Information Processed)

CategoryCollected ItemsPurpose of Use
Membership Registration[Provided by Apple/Google] Name (or nickname), emailAccount creation and management
Service UsePreferred reference (he/she/that person), written records (text), photos, metadataRecord storage and viewing, analysis of record content through an AI model, and personalized feedback
Service Use (Automatically Collected)Pseudonymous ID, device information (OS, app version, model name), access logs, error logs, cookies and similar technologiesService improvement and analytics, security management

Information We Do Not Collect

  • Passwords: Only social login is supported, and passwords are not stored.
  • Payment information: In-app payments are processed through the app stores, and card numbers or other financial information are not stored.

Article 3 (Retention and Destruction of Personal Information)

  1. General rule: Personal information is destroyed without delay when a member withdraws. However, backup data is securely deleted within a regular system cycle for operational reasons.
  2. Retention required by law
    • Records of contracts, withdrawal of offers, and payments: 5 years
    • Records of consumer complaints and dispute handling: 3 years
    • Records of labeling and advertising: 6 months
    • Tax-related transaction books and supporting documents: 5 years
  3. Prevention of misuse: Information may be retained for 1 year when necessary to prevent fraudulent registration or misuse.
  4. Destruction procedure and method: Electronic files are securely deleted so they cannot be restored, and paper documents are shredded or incinerated.

In-app payments are processed through Apple/Google, and the Company does not store card numbers or other sensitive payment information. However, purchase status, such as subscription status, and receipt identifiers may be retained for the legally required period to provide the Service.

Article 4 (Provision of Personal Information to Third Parties)

  1. The Company does not provide personal information to third parties in principle.
  2. However, information may be provided within the minimum necessary scope when there is a legal basis or when the user has separately consented.

Article 5 (Entrusted Processing and Overseas Transfer of Personal Information)

ProcessorCountryEntrusted WorkItemsRetention and Use Period
OpenAI OpCo, LLCUnited StatesAI analysis and text processing of user recordsWritten records (text)Up to 30 days for abuse-monitoring logs, subject to legal or security exceptions
SupabaseRepublic of Korea (Seoul), United StatesDatabase hostingAll collected items in Article 2Until withdrawal or termination of entrustment
Google FirebaseUnited States and othersError monitoring and analyticsLogs, device information, advertising IDAccording to the processor's policy
Apple App Store / Google PlayVarious countriesIn-app payment processingPayment-related metadataAccording to the store's policy

The processors' servers may be located overseas, and in such cases personal information may be transferred to the relevant countries.

The transfer to OpenAI occurs over an encrypted network when the user requests AI analysis. OpenAI may be contacted at [email protected]. Users may refuse the transfer by not using the AI analysis feature; in that case, record storage and viewing remain available, but AI analysis and personalized feedback are not provided.

Article 6 (Use Within a Scope Reasonably Related to the Purpose of Collection)

The Company may additionally use or provide personal information within a scope reasonably related to the original purpose of collection, after comprehensively considering relevance, predictability, and whether security measures are in place.

Article 7 (Rights and Obligations of Users and Legal Guardians, and How to Exercise Them)

  1. Users may request access, correction, deletion, suspension of processing, or withdrawal of consent for personal information at any time.
  2. Rights may be exercised through various methods, including in-app inquiries, email ([email protected]), or written requests.
  3. For minors, legal guardians may exercise the same rights, and the representative must submit a power of attorney.
  4. Some rights may be restricted under applicable laws, and information that must be retained under laws such as tax laws cannot be deleted.
  5. California residents (CCPA/CPRA): You have the rights to access, delete, and correct information and to opt out of information sharing.
  6. International rights (including GDPR): You have the right to lodge a complaint with the personal information protection supervisory authority in your country of residence. Korean users may file complaints with the Personal Information Protection Commission (www.pipc.go.kr, 118).

Article 8 (Personal Information Breach Notification)

If the Company becomes aware of a personal information leak or other breach, it will notify data subjects and supervisory authorities without delay in accordance with applicable laws. The notice may include the leaked items, time of occurrence, response measures, and measures to minimize harm.

Article 9 (Measures to Ensure Security of Personal Information)

  • Administrative measures: Establishment of an internal management plan, minimizing personnel who handle personal information, and security training
  • Technical measures: AES-256 disk- and backup-level encryption through Supabase infrastructure, SSL/TLS encryption in transit between user devices, servers, and external APIs, and minimum access privileges
  • Physical measures: Data center access controls and management of data storage areas by cloud infrastructure providers

Article 10 (Data Protection Officer)

  • Name: Sein Kim
  • Title: Representative
  • Email: [email protected]

Article 11 (Changes to This Privacy Policy)

  • This Policy applies from the effective date.
  • Material changes: Notice 30 days before enforcement
  • General changes: Notice 7 days before enforcement

Business and Data Protection Officer Information

  • Effective Date: August 3, 2026
  • Business Name: Sein Kim
  • Address: 442, 4F, 1055 Dongil-ro, Nowon-gu, Seoul, Republic of Korea
  • Data Protection Officer: Representative
  • Official Email: [email protected]