Privacy Policy

Sign in

Note: JOLIMITALK is operated from the Republic of Korea. This English page is an informational summary : the Korean original is the legally binding text per the Korean Personal Information Protection Act §30 and IT Network Act §27-2. For the full legal version, switch to Korean below.

View Korean original (legally binding)

Last updated: 2026-08-31 · Locale: en-US · Governing law: Republic of Korea (Personal Information Protection Act §30, IT Network Act §27-2, Telecom Business Act §22-5).

1. Purpose of Processing

JOLIMITALK processes personal data to provide a 1:1 messaging service with Jolimi (a virtual character):

  • Account registration, sign-in, authentication
  • Conversation, image generation, and other service features
  • Marron top-up, deduction, and payment (beta: self-service)
  • Cost alerts, notices, and operational communication
  • Usage analytics and service improvement
  • Illegal content moderation and security incident response

2. Data Collected

  • Required: email, password (stored in a form that cannot be reversed), first/last name (Korean and English)
  • Optional: title
  • Auto-generated: registration timestamp, sign-in / access logs, IP address, IP-based country code, session identifier
  • During use: messages you send, attached images, generated images, session summaries, marron transactions

3. Retention

  • Account: anonymized immediately on deletion (email, name, password invalidated). The profile as it stood before anonymization is kept separately for 1 year and disclosed only where investigative authorities or the law require it (Korean Communications Privacy Act §15-2, Telecom Business Act §83).
  • Conversations, messages, images and direct messages: retained for 1 year per Korean Communications Privacy Act §15-2 (communication facts data, max 12 months) and §15-3 (operator cooperation duty). Deleting content removes it from your view; it remains within the scope kept for administration and lawful cooperation.
  • Direct message threads: kept for 1 year even after both people delete them, for the same administrative and lawful purposes.
  • Sign-in attempt records: cleared after 2 days.
  • Sign-in session records: kept while the device stays registered, and removed when you disconnect the device or sign out. You can review and disconnect your devices at any time.
  • Administrator action records: retained for 1 year for security and lawful cooperation.

4. Operator Content Review

Under Korean Telecom Business Act §22-5 (illegal recording prevention duty) and IT Network Act §44-7 (illegal information distribution blocking), as a value-added telecom operator the service has the right to review user content.

Operator (admin) content review is performed only for:

  • Illegal recordings, deepfakes, content harmful to minors
  • Prompt injection and security attack response
  • Marron, payment, or service abuse investigation
  • Cooperation with investigative authorities and lawful requests under Korean Communications Privacy Act §15-2 (communication facts data retention) and §15-3 (operator cooperation duty)
  • Admin review of DM rooms closed when both parties deleted (Communications Privacy Act §15-2)

Every operator review action is recorded (timestamp, target user, session, message count). You may request your own review history at any time.

5. Third-Party Processors

  • Anthropic Inc. (US): message text exchange for AI replies.
  • OpenAI (US): image safety screening and image generation.
  • Google LLC (US): image and sticker generation.
  • ForwardMX (UK): operational mail dispatch (SMTP).
  • Google LLC (US) / Open-Meteo: reverse geocoding, maps and weather lookup, plus real-time search (Gemini + Google Search grounding). With your consent, an approximate location (district level; precise coordinates are not stored) is used for weather and nearby suggestions, deleted on opt-out or after 30 days of inactivity.

Outsourcing is limited to the minimum data needed for service delivery and moderation (messages, attachments, user identification metadata). Each processor's own retention policy applies. See their terms.

6. AI-Generated Content Marking

All images generated by JOLIMITALK embed the following EXIF / metadata:

  • Software: JOLIMITALK
  • ImageDescription: AI generation marker + model name
  • XMP-AI:Generator: model ID + generation timestamp

Some metadata may be lost when the image is captured, re-encoded, or uploaded to certain social platforms.

7. Your Rights

Under Korean PIPA §35–37, you may exercise the following rights:

  • Access your personal data (request by email)
  • Correction or deletion (request by email)
  • Suspension of processing (request to deactivate)
  • Withdrawal of consent (account deletion: email, name, and password anonymized immediately)
  • Data portability (JSON export, sent by admin)

Note: under Communications Privacy Act §15-2, the archived profile, messages, images, direct messages and access records remain in the admin scope even after they are masked in the user's own view. Exercise of rights (access, correction, deletion) may be limited where investigative cooperation or security audit takes precedence.

8. Security Measures

  • Passwords are stored as a one-way hash; linked-service tokens are stored encrypted.
  • Sign-in sessions expire on their own and can be ended from any device you have registered.
  • All traffic is encrypted in transit.
  • Attached images pass an automated safety screen before they are delivered.
  • Administrative access is kept to a minimum and administrator actions are recorded in an audit log.
  • We run monitoring and alerting for security incidents, and back up data regularly.
  • Sender IP recorded for DM messages and user-role messages (Communications Privacy Act §15-2 communication facts data retention)

9. Contact

Privacy officer: operator (Heino) · joliverse@joliverse.net

This policy is updated when laws or service policies change. Significant changes are announced at least 7 days in advance.

Back to sign in