SLODAY · SLODAY LABS

Privacy Policy

This Policy explains how SLODAY processes personal information and the rights available to users.

Operator
Sloday Labs
Announcement date
August 14, 2026
Effective date
August 14, 2026

1. General provisions

Sloday Labs (the “Company”) operates SLODAY, an emotion-logging and social-connection service (the “Service”), and complies with the Personal Information Protection Act and other applicable laws.

This Privacy Policy explains what personal information the Company processes, why it processes that information, and the rights users may exercise in relation to it.

Personal information processor information
CategoryDetails
Business nameSloday Labs
RepresentativeSungjin Cho
Business registration number3870404158
Address193-9 Gyeomjae-ro, Jungnang-gu, Seoul
Telephone+821029594647
Email[email protected]

2. Items, purpose and retention period of personal information processed

The Company processes the information listed below to the extent necessary to provide the Service. Some information may remain for a limited period after the user deletes it or deletes the account because of statutory retention requirements, records already sent to other users, security or dispute-resolution needs, or limited backup and cache cycles.

Personal Information Processing Details
CategoryCategories of Personal InformationPurpose of processingRetention period
Registration and AuthenticationAuthentication provider identification value, email address, authentication/session informationAccount registration, login, account identification, security, and prevention of misuseUntil account deletion. Information subject to a statutory retention requirement is retained for the legally required period, and information needed for security or dispute resolution is retained only as long as necessary for those purposes.
ProfileUsername, display name, profile photo, bio, date of birth, gender, interests, country/language settingsProvision of profiles, relationship/search functions, provision of age/language based services, and confirmation of whether new members are 16 years of age or older.Until account deletion or the user deletes the relevant information
Emotion RecordsEmotion classification/phrase/memo, recording time, disclosure status, selected story and desire information along with emotionProvide emotion records, timelines, statistics, retrospectives, archives, map Reels, and feeds based on each Vibe’s visibility settingUntil you delete your record or account
Media/contextual informationPhotos, videos, audio, place name/address, location/weather, selected music informationAdd context to emotion records; display and transform media; and provide location, weather, and music featuresUntil the user deletes the content or account. Cache and backups may be deleted sequentially according to technical processing cycles.
Confirmation data on use and provision of location informationType of change to the use or disclosure status of location information, related emotion-record identifier, purpose of use, scope of recipients, and processing time (raw precise coordinates are not stored in the confirmation records)Confirmation of location information use and provision details, support for exercising user rights, and compliance with relevant laws and regulations6 months from record date
Social/CommunicationPublic content, relationship status, first greeting status, emoji reaction, likes, text/voice comments and transcripts, replies, messages, read/delivered status, bookmarks, reason for reporting/direct input content, and blocking historyConnecting between members, chatting and Vibe interaction, handling reports and ensuring service safetyUntil the relevant content or account is deleted. Messages and interaction records sent to other users may remain for as long as necessary to maintain the other party's records, respond to disputes, and ensure service security.
Quiz/Card GameQuiz questions/choices/correct answers created by users, answers/correct answers/response times selected by other users, card game sessions/participation status/questions/answers/progress records, and profile preferred answersProvide quizzes and card games, support relationship building and staged content access, allow users to resume sessions, prevent duplicate participation, summarize profiles, and personalize the Service.Until you delete your quiz, game or account. Profile preferred answers remain active until the user deletes their account.
Today’s VibeSelection mode, date of birth, birth time/time unknown, place of birth, blood type, constellation, MBTI, reference date, creation result and creation provider/prompt versionGenerate entertainment content based on Four Pillars astrology, zodiac signs, or blood type; provide and cache results; and improve quality.Until you delete your settings and creation results or delete your account.
Slo Activity RecordsAccumulated/used balance, applicable rules and versions, accumulated/used/cancelled history, related activity/content identifier, duplicate processing prevention identifier, profile viewing target and expiration timeProvide Slo balances and transaction history, prevent duplicate transactions, enable profile viewing and First Greetings, prevent misuse, and resolve disputesUntil account deletion. Records subject to statutory retention requirements or needed to resolve disputes or investigate misuse are retained for the legally required or otherwise necessary period.
Friend Referrals and Misuse PreventionReferral code, recommender/referred person identification value, referral attribution/activation/review/reward/exclusion status and time, reward ledger identification value, one-way hash of device identification value/IP address/authentication provider identification value, risk signal and reason for exclusionReferral attribution and reward provision, application of monthly and account-specific limits, detection of fraudulent participation such as self-referral, repeated registrations on the same device, multiple accounts, prevention of duplicate benefits, and response to disputesGeneral referral records are retained for the period necessary to operate the referral program and address disputes or misuse. A one-way hash of the authentication-provider identifier and whether a benefit was received may be retained while the referral program operates to prevent duplicate benefits.
Optional VerificationVoice recordings, voice transcripts and match scores, verification status and time, the URL of pre-existing reference media used for face verification, the related Vibe identifier, and face-verification status and timeProvides voice/face authentication and related trust functionsUntil the related media or Vibe is deleted or the account is deleted. Deletion and propagation to backups and caches may take additional time
Device, Notification, and Operational RecordsPush token, Live Activity update/launch token and delivery history, device/platform/app version, time of last activity, battery status, random value for device identification, IP address, approximate latitude/longitude/city/region/country/time zone estimated from IP, connection/error/security logsProvision of notifications and Live Activity, session and failure management, provision of surrounding search reference points when location permissions are not available, security, prevention of unauthorized use and analysis of service useUntil the relevant purpose is fulfilled or the account is deleted. Security and access logs are retained for the period required by applicable law or the Company’s internal security policies.
Product improvement analysisA random installation identifier, member identifier, session identifier, event type and time, platform, app version and build, operating-system version, language, feature entry point, and limited usage attributes such as result counts and distance bands; and a one-way HMAC key used to correlate activity involving the same card or counterpart (the original content and the counterpart’s identifier are not stored in analytics properties)Analysis of service usage status and registration/Vibe/discovery/connection conversion, improvement of functions, verification of failures and collection qualityFor individual original events, 13 months from the time of collection. Statistics collected daily are stored for the duration of service operation so as not to be linked to users.
Website Usage and Performance AnalyticsVisited-page path, referral source, country or region of access, browser, operating system, device type, page-load data, and performance metrics such as Core Web VitalsIdentify website usage status, improve content, and improve errors and performanceFor the period specified by Cloudflare Web Analytics’ retention policy and its agreement with the Company

3. Required/optional information and age criteria

  1. Information required for emotion logging, such as emotion categories or phrases, is used to provide the Service’s core features. Users may choose not to enter sensitive details, including medical or health information, in free-text fields.
  2. Location, photos and videos, microphone access, music-library access, notifications, and face or voice verification are optional. Users who decline them may still use basic emotion-recording and account features; only features that require the relevant permission or information may be unavailable.
  3. Precise location is processed in accordance with applicable location-information law and the separate Location-Based Service Terms. Granting operating-system location permission does not constitute agreement to those Terms.
  4. If the Company separately processes sensitive information—such as biometric information technically generated from a person’s physical, physiological, or behavioral characteristics for the purpose of uniquely identifying that person, or health information—it will obtain separate consent as required by applicable law.
  5. After July 14, 2026, new members must be 16 years of age or older regardless of country or region, and the Company will confirm this based on the date of birth entered by the user.
  6. Existing accounts created before July 14, 2026 will be subject to the previous registration age criteria, regardless of date of birth.
  7. If it is confirmed that a new member is under the age of 16, the account and related personal information created during the registration process are, in principle, immediately deleted. If deletion temporarily fails, access to the service is blocked and only the minimum information necessary for deletion retry and security/error response is retained until deletion is complete.

4. Method of collecting personal information

  1. Directly from information the user enters or selects during registration, profile creation, emotion logging, posting, commenting, chatting, inquiries, or reports
  2. When the user grants camera, photo-library, microphone, location, notification, or music permissions and uses the corresponding feature
  3. When the user chooses to connect an external account or service, such as Sign in with Apple
  4. Automatically when device, access, error, and security information is generated during use of the Service
  5. Automatically from limited usage events generated while viewing, creating, exporting, or navigating major in-app features when Product Improvement Analytics is enabled
  6. Automatically when Slo earning, spending, or reversal records are generated through Service activities such as avatar registration, AI summaries, verification, Vibes, reactions, comments, First Greetings, or profile viewing
  7. When referral-attribution, reward, and fraud-prevention information is generated while entering a referral code, opening a referral link, or creating a first Vibe
  8. When the user enters or selects information, or results are generated automatically, while using Today’s Vibe, user-created quizzes, or card games
  9. When the Service obtains an IP-based approximate location provided by Cloudflare as the user uses Nearby while device location is unavailable
  10. Automatically through the Cloudflare Web Analytics script when website usage and performance information is generated and collected during a website visit

5. Provision of personal information to third parties and disclosure to other users

The Company processes personal information only for the purposes stated in this Privacy Policy and does not sell or provide it to third parties without the user’s separate consent or another legal basis.

  1. When a user makes content public or sends a message to another Member, the user’s profile, public emotion records, photos, videos, comments, messages, and privacy-protected Public Location may be shown to other users according to the user’s settings and Relationship Stage.
  2. The Actual Location is stored for the user’s own records and is not displayed directly to other users. As a rule, public maps use a privacy-protected Public Location offset from the Actual Location.
  3. Even if another user obtains profile-viewing access using Slo, the Actual Location is not disclosed. Only the profile information and Public Content permitted by the applicable Relationship Stage and visibility settings are shown to that user.
  4. Information may be provided to the extent necessary when requested by an investigative agency or court in accordance with legal procedures, or when provision is permitted by law to respond to imminent danger to life or body.

6. Entrustment of personal information processing work

To provide the Service, the Company uses the infrastructure or APIs of the external service providers listed below. The Company uses contracts, management, and oversight measures to help ensure that personal information is processed securely.

Personal information processing outsourcing status
ProcessorProcessing services
Supabase Pte. Ltd.Member authentication, database storage and operation
Cloudflare, Inc.Website/API operation, web usage/performance analysis, network security, file storage, AI inference, and content transmission
OpenAI, L.L.C.AI processing such as selective voice transcription, text summarization, translation, and analysis
Apple Inc.Linkage with Apple functions selected by the user, such as Apple login, push notifications, maps, weather, and music
Google LLCSearch for places selected by users and provide location information
Spotify ABLink to Spotify account selected by user and provide music information

7. Overseas transfer of personal information

In the course of providing the Service, personal information may be transferred abroad or processed in the systems of overseas service providers as described below. Transfers occur over encrypted networks when the user uses the relevant feature or a Service API is called.

Current status of overseas transfer of personal information
Recipient and contact informationDestination countryTransferred data and purposeRetention and use period
Supabase Pte. Ltd. [email protected]South Korea (Seoul Region)Authentication, storage, and operation of service data such as account identification information, profile, emotional records, location, relationship, and messagesUntil use of the service or termination of the outsourcing agreement. Afterwards, the deletion cycle is applied according to the contract and laws.
Cloudflare, Inc. [email protected]United States and Cloudflare’s global processing locationsService transmission, storage, analysis, security, and AI processing of website usage/performance information, access/security information, API requests, upload media, and AI input data.Until use of the Service ends or the outsourcing agreement terminates. Logs and caches are retained for the period specified by Cloudflare’s policy and the applicable agreement.
OpenAI, L.L.C. [email protected]United StatesTranscription, summary, translation, and analysis of optional voice files, transcripts, and emotion/profile-related textsFor the period specified in the API provider’s agreement and data retention policy. Results stored separately by the Company are retained until the relevant feature is discontinued or the user deletes them.
Apple Inc. apple.com/legal/privacy/contactUnited States and Apple’s global processing locationsProvides authentication and selection functions for login identification information, push token, location, search term, and music linkage informationPeriod according to Apple's privacy policy for each service and user account settings
Google LLC policies.google.com/privacyUnited States and Google’s global processing locationsProvides location search function for location or search reference point or place search termFor the period specified by Google’s service policies and its agreement with the Company
Spotify AB spotify.com/legal/privacy-policySweden and Spotify’s global processing locationsAccount linking of linked tokens and music-related information and provision of music functionsUntil the account connection is removed, or for the period specified in Spotify’s policy
  1. Users can refuse overseas transfers required for the function by not using the optional function or disconnecting the account/service. However, if you refuse member authentication and core infrastructure processing, it may be difficult to sign up for or use the service.
  2. If you do not use a function that requires external AI processing, you may refuse to transmit the input information to the AI provider, and in that case, related functions such as voice transcription/authentication, AI summarization/translation, etc. may be restricted.

8. Processing of personal location information

  1. When a user grants location permission and uses a location feature, the Company may process the Actual Location at the time of recording, the privacy-protected Public Location, place and address information, the distance between those locations, and the weather at that time.
  2. As a rule, the Actual Location is used for the user’s records and location-based features, while other users are shown a privacy-protected Public Location that has been randomly offset from the Actual Location.
  3. The Company does not provide a feature that continuously tracks a user’s movements in real time or in the background.
  4. Users may deny or revoke location permission in their device settings. Location, weather, map, and nearby-discovery features will then be unavailable, but basic features that do not require location will remain available.
  5. The separate Location-Based Service Terms provide details about records confirming the use and provision of Personal Location Information, retention periods, user rights, and the Person in Charge of Location Information Management.

9. Automated processing and AI features

  1. The Company may generate summaries, translations, feedback, or daily content based on emotion records, profiles, card-game responses, and similar inputs.
  2. When using Today's Vibe, depending on the mode selected, settings and profile information provided by the user, such as date of birth, time of birth, place of birth, constellation, blood type, MBTI, gender, and age range, may be processed to generate entertainment results.
  3. When you request AI feedback on vibe timelines, distributions, trends, etc., relevant sentiment records and selected time period information may be processed to generate results.
  4. If you utilize the voice authentication, voice message, or voice comment features, your voice files may be processed by OpenAI or Cloudflare Workers AI for transcription and content comparison.
  5. The results generated by AI are reference information within the service and do not replace medical diagnosis, treatment, counseling, or expert judgment.
  6. If the Company intends to use user content separately to train a general-purpose AI model operated by the Company or an external provider, it will clearly inform users in advance and obtain any consent required by applicable law.
  7. Face verification compares a reference photo with live camera frames on the user’s device. The live frames and facial-comparison feature values are neither transmitted to nor stored on the server; only the reference-media URL and verification status are stored on the server.

9-1. TrueDepth API and Face Data Processing

SLODAY uses Apple’s TrueDepth camera and ARKit only when a user voluntarily starts the face-verification feature. Face verification is not required to use the Service’s basic features.

  1. Data processed: The app temporarily processes a reference photo previously uploaded by the user, live RGB image frames from the front-facing camera, face-tracking status and orientation, eye-blink values, face regions and landmarks detected with Vision, a facial feature vector generated on the device, and a similarity score against the reference photo. SLODAY does not collect or store raw TrueDepth depth maps.
  2. Purpose: This data is used solely to determine whether the person in the reference photo is the user in front of the camera and, using an eye blink, to confirm that a live person is present.
  3. On-device processing: Live camera frames, face-tracking information, face regions and landmarks, eye-blink values, facial feature vectors, and similarity scores are processed only on the user’s device. This information is not transmitted to the Company’s servers or stored persistently and is deleted from memory when the face-verification screen is closed.
  4. Server-stored data: After successful verification, the only face-verification feature record stored in the Supabase database consists of the member identifier, related Vibe identifier, URL of reference media previously uploaded by the user, and verification time. Live face images, face templates, facial feature vectors, and similarity scores are not stored on the server. If a first-verification reward is granted, a separate Slo reward and transaction record that contains no face data is generated and processed under the ‘Slo Activity Records’ terms of this Policy.
  5. Sharing and third-party disclosure: Live face data processed through the TrueDepth API and facial feature data generated on the device are not disclosed, sold, rented, or shared with third parties. The limited verification-completion record may be stored and processed by Supabase Pte. Ltd., the Company’s database infrastructure processor, acting on the Company’s instructions.
  6. Prohibited uses: Face data and verification-completion records are not used for advertising, user tracking, marketing, third-party identification, or training facial-recognition or general-purpose AI models of the Company or any third party.
  7. Retention and deletion: Face data temporarily processed on the device is deleted when the verification screen is closed. The server-side verification-completion record is deleted when the related media or Vibe is deleted or when the user deletes their account. Copies in limited backups and caches may be deleted progressively according to each system’s technical deletion cycle.
  8. User choice and rights: Users may choose not to use face verification and may revoke camera permission at any time in device settings. Users may exercise their privacy rights, including deletion of face-verification records, by selecting ‘Delete Face Verification Records’ on the face-verification screen in the app, deleting the related media, Vibe, or account, or contacting [email protected].

10. Destruction of personal information and account deletion

  1. Users can request account deletion through the app's account settings.
  2. After processing a deletion request, the Company deletes or restricts access to the account and related personal information that is no longer needed to provide the Service.
  3. Electronic files will be deleted to make recovery difficult, and if any printouts are present, they will be destroyed by appropriate methods such as shredding or incineration.
  4. Information subject to statutory retention requirements, records needed to address fraud, security incidents, or disputes, and messages or interaction records already sent to other users may be segregated or retained on a limited basis for as long as necessary for the relevant purpose.
  5. To prevent duplicate benefits and repeat registrations from friend referrals, the one-way hash of the authentication provider identification value, whether benefits have been received, and the necessary referral processing records may be retained for a limited time during the operation period of the referral program even after account deletion.
  6. Copies remaining in backups, caches, content delivery networks, or external processing systems may be deleted gradually according to each system’s technical deletion cycle. Accordingly, the Company does not represent or guarantee that every copy will be deleted from every system immediately after account deletion.

11. Rights and exercise methods of users and legal representatives

  1. Users may request to view, correct, or delete their personal information, suspend processing, withdraw consent, and delete their account.
  2. You can turn off ‘Product Improvement Analysis’ at any time in the app’s privacy settings. When turned off, pending optional analysis events are deleted and future optional collections are stopped.
  3. Operational records needed to provide and secure the Service or settle transactions—including whether Slo transactions, reports, security operations, and feature requests succeeded or failed—may be processed under applicable law and this Policy regardless of the Product Improvement Analytics setting.
  4. Deleting an account deletes the original analytics events with member identifiers and the original events with random install identifiers associated with that account. Values that have already been aggregated into de-identified daily statistics and cannot be linked to a specific user may be retained.
  5. Profiles and content can be edited or deleted directly from the app, and other requests can be submitted to [email protected].
  6. The Company may verify the requester’s identity and may limit all or part of a request on grounds permitted by applicable law, in which case it will explain the reason.
  7. A legal representative or a legally authorized person may exercise rights on behalf of the user in accordance with relevant laws and regulations.
  8. Location, camera, microphone, photo, music, and notification permissions can be revoked at any time in the device settings, and external account linking can be canceled in the relevant service or app settings.

12. Personal information protection officer

The Company designates a Chief Privacy Officer to oversee the processing of personal information and handle user inquiries and complaints.

Personal information protection officer information
CategoryDetails
NameSungjin Cho
TitleRepresentative
Telephone+821029594647
Email[email protected]
  1. General privacy inquiries: [email protected]
  2. If you need to report or consult about a personal information infringement, you can contact related organizations such as the Personal Information Infringement Reporting Center (118, no area code), the Personal Information Dispute Mediation Committee (1833-6972), or the National Police Agency (182, no area code).

13. Measures to ensure the safety of personal information

  1. Access control using encryption of transmission section and authentication token
  2. Restrict access rights for each user, including database row-level access policies
  3. Separation of real and public locations and limited self-centered access to real locations
  4. Minimize management rights, check access records and security events
  5. Security updates and vulnerability response for services and storage

14. Website usage analysis

The Company uses Cloudflare Web Analytics to understand the usage status of the website and its performance in actual usage environments.

  1. Analysis information is used to statistically understand landing pages, funnels, access environments, and page performance, and to improve the homepage.
  2. The Company does not use website analysis information to directly identify users or provide customized advertisements, and does not combine it with service usage information such as account information and emotional records of the SLODAY app.

15. Changes to Privacy Policy

  1. The Company may revise this Privacy Policy when applicable law, the Service, or its personal-information processing arrangements change.
  2. Important changes will be notified through the app or website before implementation, and changes that require separate consent under relevant laws will go through the necessary procedures.
  3. Changed on July 14, 2026: Criteria for independent public settings for each vibe, exposure of archives and releases of public expired vibes, and suspension of exposure of public locations when converted to private were clarified.
  4. Changed on July 14, 2026: Slo Balance, ledger, profile viewing rights, Vibe emoji, voice comment, bookmark, report reason, and AI Vibe feedback processing details were added.
  5. Changed July 14, 2026: Added collection items for Product Improvement Analytics, 13-month original retention period, in-app opt-out, and de-identified daily statistics retention criteria.
  6. Changed on July 14, 2026: Added friend referral/fraud use prevention, Today's Vibe, quiz/card game, Live Activity, and IP-based approximate location processing.
  7. Changes dated July 14, 2026: added a worldwide minimum age of 16 for new Members, date-of-birth eligibility checks, and deletion rules for newly created underage accounts.
  8. August 14, 2026 update: Clarified the categories and purposes of face data temporarily processed through the TrueDepth API, on-device processing, the limited server-side record, third-party sharing, retention and deletion, and user rights.
  9. Announcement date: August 14, 2026
  10. Effective date: August 14, 2026