bubi Privacy Policy

Effective: June 10, 2026
This English version is provided for convenience. The Korean version of this Privacy Policy is the legally binding text; in case of any conflict, the Korean version shall prevail.

bubi ("Service") complies with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other applicable laws of the Republic of Korea, and has adopted this Privacy Policy to protect Members' personal data.

1. Personal Data We Collect

2. Purposes of Collection and Use

  1. Member identification and account management
  2. Provision of AI chat and voice call services (including LLM and voice AI API calls)
  3. Character creation and portrait generation services
  4. Maintaining conversation context, session summarization, long-term memory retrieval, and relationship scoring
  5. Subscription and credit state management and payment/refund processing
  6. Notification delivery (chat, marketing, and night notifications per Member settings)
  7. Fraud detection and prevention, and service quality improvement
  8. Responding to user inquiries and delivering announcements
  9. Compliance with legal obligations

3. Retention Period

Upon account termination, account identifiers are deleted or de-identified without undue delay. However, chat/call records, payment and credit records, dispute records, access logs, and similar data may be retained to the extent necessary for legal retention duties, dispute handling, and fraud prevention, and then deleted or de-identified after the periods below:

4. Disclosure to Third Parties

We do not disclose personal data to third parties, except with the Member's prior consent or where required by law.

5. Processors (Subcontractors)

We entrust the following parties with personal data processing tasks for service operation:

ProcessorTaskProcessing LocationData ProcessedRetention
Supabase, Inc.Database, auth, and storage hostingUnited States / Singapore and other selected regionsAccount data, profiles, chat/call records, credit/payment metadata, generated images, usage logsService period and the retention periods in Section 3
RevenueCat, Inc.Subscription and credit payment state management and webhooksUnited StatesApp user identifier, subscription/product IDs, transaction IDs, subscription statusSubscription/payment management period and statutory retention periods
OpenRouter, Inc. and model/image providers selected through OpenRouterLLM routing, AI response/summary/embedding generation, portrait image generationUnited States and other provider processing locationsChat/call inputs, character settings, image generation prompts, context needed for response generationUntil the processing purpose is achieved or as retained under the provider's policy
OpenAI, L.L.C. / Anthropic PBC and other LLM providersLLM inference, summarization, embeddings, and other AI featuresUnited States and other provider processing locationsChat inputs, text to summarize, and context needed for response generationUntil the processing purpose is achieved or as retained under the provider's policy
ElevenLabs, Inc.Conversational voice AI (speech recognition, synthesis, call processing)United States and other locationsVoice call input/transcripts, character voice settings, call metadataUntil call processing purpose is achieved or as retained under the provider's policy
Apple Inc. / Google LLCIn-app purchase processingUnited States and other locationsPayment account, transaction ID, payment status, and store payment informationStore policy and statutory retention periods
Google LLC (Google Analytics for Firebase)Usage statistics and behavioral analyticsUnited StatesApp instance identifier, user identifier (user_id), screen/event usage logs, subscription tier (free/paid), country/languageRetained under Google's policy (default up to 14 months)

6. Cross-Border Transfer

Under Section 5, personal data may be transferred to the countries where processors or service providers are located. Transfers occur electronically over TLS-encrypted network channels when the Service is used; transferred data, purposes, and retention periods follow the table in Section 5 and Section 3. Members have the right to refuse cross-border transfers under Article 28-8 of the Personal Information Protection Act; refusal may limit access to AI chat, voice calls, account management, subscription/credit processing, or other parts of the Service.

7. Your Rights

  1. Members may request at any time to access, correct, delete, or suspend processing of their personal data.
  2. Use the in-app "Delete Account" function or email the contact below to submit requests.
  3. We will respond within 10 days of receipt, subject to exceptions permitted by law.

8. Deletion Procedure

9. Security Measures

10. Cookies, Device Identifiers, and Microphone

The mobile app does not use cookies and does not collect advertising identifiers (IDFA/GAID). However, app-internal identifiers, device information, and access logs may be generated for service quality improvement and fraud prevention. Voice call features require microphone access permission, which can be managed in device OS settings.

11. Children's Privacy

We do not knowingly collect personal data from children under 13. Any such account, if discovered, will be deleted immediately.

12. Data Protection Officer

Please direct privacy-related inquiries, complaints, and remedy requests to the contact above.

13. Remedies for Rights Infringement

For infringement reports or consultation, Members may contact:


14. Revision History