AI character roleplay chat
AI 캐릭터와 함께하는 1:1 역할극 채팅
해빗도그(이하 "회사")는 「개인정보 보호법」 제30조에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다. 본 처리방침은 회사가 운영하는 모바일 애플리케이션 "CORA"(이하 "서비스") 이용에 적용됩니다.
CORA는 사용자가 직접 만든 캐릭터 또는 다른 사용자가 공유한 캐릭터와 대규모 언어 모델(LLM) 기반의 1:1 채팅 역할극을 즐길 수 있는 모바일 애플리케이션입니다. 본 서비스는 회원가입과 인증을 통해 제공되며, 사용자가 입력한 역할극 대사 텍스트는 응답 생성을 위해 외부 AI API 서비스를 통해 처리됩니다(자세한 내용은 제6-1조 참조).
회사는 다음과 같은 개인정보를 처리하고 있습니다.
| 구분 | 항목 |
|---|---|
| 회원가입 시 (필수) | 소셜 로그인 식별자(Google/Apple/Kakao), 이메일 주소(소셜 로그인 제공자가 제공하는 경우), 성명(Apple Sign-In 최초 1회 한정, 사용자 동의 시) |
| 프로필 (필수/선택) | 닉네임(필수), 프로필 이미지(선택, 사용자가 동의하거나 직접 설정한 경우) |
| 서비스 이용 시 생성 | 사용자가 만든 스토리/캐릭터 정보(제목, 설명, 캐릭터 이름·성격·외형·배경설정), 채팅 메시지 전문, AI 생성 이미지 및 생성 파라미터, 신고·차단 기록(신고 대상 캐릭터 ID, 신고 사유, 신고 일시, 차단 대상 사용자/캐릭터 ID), 자동 콘텐츠 검수(moderation) 결과 로그 |
| 알림 서비스 (선택) | 푸시 알림 토큰, 디바이스 OS 종류 |
| 광고 식별자 (선택, 동의 시) | iOS 광고 식별자(IDFA), Android 광고 ID(AAID) |
| 자동 수집 정보 | IP 주소, 기기 모델, 운영체제 버전, 앱 버전, 접속 일시, 서비스 이용 기록, 오류·크래시 로그, 화면 녹화(Session Replay, 운영 환경 한정) |
| 이용 통계 | 일일 메시지 발송 횟수, 광고 시청 횟수 |
중요 안내: 사용자가 채팅 화면에서 입력하는 메시지는 가상 캐릭터와의 역할극 대사로 간주되며, 응답 생성을 위해 외부 AI API 서비스로 전송됩니다. 함께 전송되는 정보는 대사 텍스트, 캐릭터 설정, 그리고 AI가 사용자를 적절히 호칭하기 위한 회원의 닉네임(프로필 표시 이름)에 한정됩니다. 이메일, 사용자 ID(UUID), IP 주소, 디바이스 식별자 등 닉네임 외의 식별 정보는 전송되지 않습니다. 사용자가 채팅 입력란에 본인의 실명, 주민등록번호, 금융정보, 위치정보 등 식별 가능한 개인정보를 직접 입력하는 경우 해당 텍스트가 외부 처리 과정에 포함될 수 있으므로, 이러한 입력은 자제하여 주시기 바랍니다.
회원이 앱 내 회원 탈퇴 기능을 이용하면 회사는 다음과 같이 정보를 처리합니다.
회원 탈퇴는 즉시 처리되며 복구되지 않습니다. 탈퇴 후 동일한 소셜 계정으로 다시 회원가입할 수 있으나, 이 경우 신규 회원으로 처리되어 이전 회원이 보유하던 활동 기록·사용 한도·즐겨찾기 등은 복원되지 않습니다. 회사는 약관 위반 등의 사유가 있는 경우 재가입을 제한할 수 있습니다.
회사는 정보주체의 별도 동의, 법률의 특별한 규정 등 「개인정보 보호법」 제17조에 해당하는 경우 외에는 개인정보를 제3자에게 제공하지 않습니다. 다만 사용자가 자신이 만든 캐릭터를 공개로 설정한 경우, 해당 캐릭터의 닉네임 및 캐릭터 설정 정보는 다른 사용자에게 노출됩니다.
회사는 서비스 제공을 위해 아래와 같이 개인정보 처리 업무를 위탁하고 있습니다. 회사는 위탁계약 체결 시 「개인정보 보호법」 제26조에 따라 개인정보가 안전하게 처리될 수 있도록 필요한 사항을 규정하고, 수탁자가 이를 준수하는지 감독합니다. 위탁 업무 또는 수탁자가 변경되는 경우 본 처리방침을 통해 공개합니다.
| 수탁업체 유형 | 위탁 업무 / 처리 항목 |
|---|---|
| 클라우드 인프라(인증·데이터베이스·파일 저장소) 제공사 | 회원 인증, 회원 정보 및 사용자가 생성한 콘텐츠의 저장·관리(이메일, 닉네임, 프로필 이미지, 캐릭터 설정, 채팅 메시지, 생성 이미지) |
| 플랫폼 인증·푸시 알림 제공사 | 소셜 로그인 인증 처리, 푸시 알림(APNs/FCM) 발송 — 푸시 토큰 및 인증 식별자 처리 |
| 모바일 광고 네트워크 제공사 | 앱 내 광고 노출 및 광고 식별자(IDFA/AAID) 처리 (사용자가 추적에 동의한 경우에 한함) |
| 오류·품질 모니터링 제공사 | 앱 오류·크래시 로그, Session Replay, IP 주소 등의 수집·분석 (운영 환경 한정) |
| Alibaba Cloud (Singapore) Private Limited | Qwen 모델을 통한 채팅 응답 생성 및 장기 대화 기억 요약 — 닉네임, 역할극 대사와 최근 대화 내역, 스토리·캐릭터 설정 및 기존 대화 요약 처리 |
회사는 채팅 응답 생성, 페르소나 검색, 캐릭터 이미지 생성을 위해 외부 AI API 서비스를 이용합니다. 회사가 외부 AI API 서비스로 전송하는 데이터의 범위는 다음과 같습니다.
외부 AI API 서비스는 위와 같이 닉네임을 포함한 텍스트를 전달받지만, 회사 내부에서 회원을 고유하게 식별하는 키(이메일·UUID 등)는 함께 전송되지 않으므로, 외부 AI API 서비스가 단독으로 어느 회원이 입력한 텍스트인지 특정하기는 어렵습니다. 단, 회원이 채팅 입력란에 본인의 실명, 주민등록번호, 금융정보, 위치정보 등 직접적인 식별 정보를 기재하는 경우 해당 텍스트가 외부 AI 처리 과정에 포함될 수 있으므로, 본 처리방침 제2조의 안내에 따라 그러한 입력을 자제하여 주시기 바랍니다.
Qwen 기반 채팅 응답 및 장기 대화 기억 요약은 Alibaba Cloud (Singapore) Private Limited의 Alibaba Cloud Model Studio를 통해 처리됩니다. Alibaba Cloud는 고객 데이터를 별도 동의 없이 모델 개발·개선에 사용하지 않는다고 고지하고 있습니다. 그 밖의 외부 AI API 수탁자와 처리 범위는 본 처리방침 제6조 및 제7조에 따릅니다.
회사는 안정적인 서비스 제공과 회원과의 서비스 이용계약 이행을 위해 일부 처리 업무를 해외에 본사 또는 인프라를 둔 수탁사에게 위탁하고 있으며, 이에 따라 회원의 개인정보가 국외로 이전될 수 있습니다. Qwen 모델 호출은 「개인정보 보호법」 제28조의8 제1항 제3호 가목에 따라 아래 사항을 개인정보 처리방침에 공개하고 처리위탁합니다.
| 이전받는 자 / 연락처 | 이전 항목 | 이전 국가 | 이전 시점·방법 | 이용 목적·보유 기간 |
|---|---|---|---|---|
| Alibaba Cloud (Singapore) Private Limited DPO_Intl@alibabacloud.com |
닉네임, 역할극 대사와 최근 대화 내역, 스토리·캐릭터 설정, 기존 장기 대화 기억 요약 | 싱가포르(요청 및 정적 데이터 저장), 중국 본토를 제외한 국제 추론 노드(추론 중 일시 처리) | AI 채팅 응답 또는 장기 대화 기억 요약 생성 시 암호화된 네트워크를 통한 전송 | 채팅 응답·대화 기억 요약 생성. 서비스 계약 기간 동안 처리하며 계약 종료 시 삭제 또는 반환(법령상 보존 예외) |
Qwen 국외 이전 거부: 이용자는 dev@habitdog.app으로 국외 이전 거부를 요청할 수 있습니다. Qwen 모델 처리는 AI 채팅 제공에 필요하므로 거부 시 해당 채팅 기능의 이용이 제한될 수 있으며, 회원 탈퇴를 통해 전체 서비스 이용을 중단할 수 있습니다.
| 이전 항목 | 이전 국가 | 이전 시점·방법 |
|---|---|---|
| 이메일, 닉네임, 프로필 이미지, 캐릭터 설정, 채팅 메시지, 생성 이미지 | 미국 등 서비스 인프라 운영 국가 | 서비스 이용 시 실시간 네트워크 전송 |
| 광고 식별자(IDFA/AAID) | 미국 등 | 광고 노출 시 실시간 네트워크 전송 (사용자 동의 시) |
| 오류·크래시 로그, Session Replay, IP 주소 | 미국 등 | 오류 발생·세션 녹화 시 실시간 네트워크 전송 (운영 환경 한정) |
| 푸시 토큰, 소셜 로그인 인증 식별자 | 미국 등 | 알림 등록·로그인 시 실시간 네트워크 전송 |
본 처리방침 제6-1조에 따른 외부 AI API 서비스 호출에는 회원의 핵심 식별 정보(이메일·사용자 ID·IP·디바이스 식별자 등)가 함께 전송되지 않습니다. 다만 닉네임과 사용자가 직접 입력한 텍스트는 위와 같이 국외에서 처리될 수 있으므로, 채팅에 실명·주민등록번호·금융정보·정확한 위치 등 식별 가능한 개인정보를 입력하지 마시기 바랍니다.
정보주체는 회사에 대해 언제든지 다음 권리를 행사할 수 있습니다.
위 권리 행사는 앱 내 기능을 이용하시거나, 서면·이메일(dev@habitdog.app)을 통해 요청하실 수 있으며, 회사는 이에 대해 지체 없이 조치하겠습니다.
회사는 서비스 이용 과정에서 다음과 같은 자동 수집 장치를 운영합니다.
위 자동 수집은 OS 설정 또는 앱을 삭제함으로써 거부할 수 있습니다.
회사는 본 서비스의 특성상 만 14세 미만 아동의 회원가입을 허용하지 않습니다. 만약 만 14세 미만 아동이 가입한 사실이 확인되는 경우, 회사는 해당 계정 및 관련 정보를 지체 없이 삭제합니다. 보호자가 자녀의 가입 사실을 발견한 경우 dev@habitdog.app 으로 연락 주시기 바랍니다.
회사는 개인정보 처리에 관한 업무를 총괄하여 책임지고, 개인정보 처리와 관련한 정보주체의 불만 처리 및 피해 구제 등을 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.
정보주체는 개인정보 보호와 관련한 모든 문의·불만·피해 구제를 개인정보 보호책임자에게 문의하실 수 있으며, 회사는 정보주체의 문의에 대해 지체 없이 답변 및 처리해드립니다.
정보주체는 개인정보 침해로 인한 구제를 받기 위해 아래 기관에 분쟁 해결이나 상담 등을 신청할 수 있습니다.
본 개인정보 처리방침은 시행일로부터 적용되며, 법령 및 방침에 따른 변경 내용의 추가, 삭제 및 정정이 있는 경우에는 변경 사항의 시행 7일 전부터 본 페이지에 공지합니다. 다만 사용자의 권리에 중요한 변경이 있는 경우에는 최소 30일 전에 공지합니다.
본 개인정보 처리방침은 2026년 8월 26일(KST)부터 시행됩니다. (직전 시행일: 2026년 5월 31일)
← CORA 문서로HabitDog ("Company", "we", "us") establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea ("PIPA") to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This Privacy Policy applies to the mobile application "CORA" ("Service") operated by the Company.
CORA is a mobile application that allows users to engage in 1:1 roleplay chat conversations with characters they have created or characters shared by other users, powered by Large Language Models (LLMs). The Service is provided through user registration and authentication, and the roleplay dialogue text entered by users is processed through external AI API services to generate responses (see Section 6-1 for details).
We process the following personal information.
| Category | Items |
|---|---|
| Sign-up (required) | Social login identifier (Google/Apple/Kakao), email address (when provided by the social login provider), full name (only on first Apple Sign-In, with user consent) |
| Profile (required/optional) | Display name (required), profile image (optional, when the user consents or sets it directly) |
| Generated during use | User-created stories/characters (title, description, character name, personality, appearance, background), full chat message content, AI-generated images and generation parameters, reporting and blocking records (reported character ID, report reason, timestamp, blocked user/character ID), and automated content moderation result logs |
| Notifications (optional) | Push notification token, device OS type |
| Advertising identifier (with consent) | iOS Identifier for Advertisers (IDFA), Android Advertising ID (AAID) |
| Automatically collected | IP address, device model, OS version, app version, access timestamps, service usage history, error/crash logs, screen recording (Session Replay, production only) |
| Usage statistics | Daily message count, ad view count |
Important Notice: Chat messages you enter are treated as roleplay dialogue with a fictional character and are transmitted to external AI API services to generate responses. The data sent alongside is limited to the dialogue text, the character's settings, and the user's display name (so the AI can address you appropriately). Identifiers other than the display name — such as email, internal user ID (UUID), IP address, and device identifiers — are NOT transmitted. However, if you directly type identifiable personal information (your real name, government ID, financial info, location, etc.) into the chat input, that text may be included in external processing — please refrain from entering such information.
When a Member uses the in-app account deletion feature, we process the Member's information as follows.
Account deletion is processed immediately and cannot be reversed. After deletion, the Member may sign up again using the same social account, but they will be treated as a new member and previous activity records, usage limits, favorites, and similar will not be restored. We may restrict re-registration where there is a violation of the Terms of Service or other legitimate grounds.
We do not provide personal information to third parties except where the data subject has given separate consent or where there are special provisions under the law as set out in Article 17 of PIPA. However, when a user sets a character they created to public, the user's display name and character settings will be visible to other users.
We outsource the following personal information processing tasks to deliver the Service. When entering into outsourcing contracts, we set out matters necessary to ensure the safe processing of personal information in accordance with Article 26 of PIPA, and we supervise the trustees' compliance. Changes to outsourced tasks or trustees will be disclosed through this Privacy Policy.
| Trustee Category | Outsourced Tasks / Items |
|---|---|
| Cloud infrastructure providers (authentication, database, file storage) | Member authentication and storage/management of member information and user-generated content (email, display name, profile image, character settings, chat messages, generated images) |
| Platform authentication and push notification providers | Social login authentication, push notification (APNs/FCM) delivery — push tokens and authentication identifiers |
| Mobile advertising network providers | In-app ad serving and processing of advertising identifiers (IDFA/AAID), only when the user has consented to tracking |
| Error and quality monitoring providers | Collection and analysis of app error/crash logs, Session Replay, and IP address (production only) |
| Alibaba Cloud (Singapore) Private Limited | Chat response generation and long-term conversation memory summarization using Qwen models — processing of display name, roleplay dialogue and recent chat history, story/character settings, and existing conversation summaries |
We use external AI API services for chat response generation, persona search, and character image generation. The data we send to these external AI API services is limited as follows.
External AI API services receive text that includes the display name as described above, but the keys that uniquely identify a member within our systems (email, UUID, etc.) are not transmitted. Accordingly, an external AI API service cannot, on its own, determine which specific member entered a given text. However, if a member directly enters identifiable personal information (real name, government ID, financial info, location, etc.) into the chat input, that text may be included in the external AI processing; please refrain from such entries as guided in Section 2.
Qwen-based chat responses and long-term conversation memory summaries are processed through Alibaba Cloud Model Studio provided by Alibaba Cloud (Singapore) Private Limited. Alibaba Cloud states that it does not use customer data to develop or improve models without separate consent. Other external AI API trustees and processing scopes are governed by Sections 6 and 7 of this Privacy Policy.
To deliver a stable Service and perform our service agreement with members, we outsource certain processing tasks to trustees that operate or are headquartered overseas, and members' personal information may therefore be transferred internationally. Qwen model calls are outsourced on the basis of Article 28-8(1)(3)(a) of PIPA with the following matters disclosed in this Privacy Policy.
| Recipient / Contact | Items Transferred | Destination | Time / Method | Purpose / Retention |
|---|---|---|---|---|
| Alibaba Cloud (Singapore) Private Limited DPO_Intl@alibabacloud.com |
Display name, roleplay dialogue and recent chat history, story/character settings, and existing long-term conversation memory summaries | Singapore (request and static-data storage); international inference nodes excluding mainland China (transient inference processing) | Encrypted network transfer when generating an AI chat response or long-term conversation memory summary | Chat response and memory-summary generation. Processed for the service agreement term and deleted or returned upon termination, except where retention is required by law |
Refusing the Qwen transfer: You may request refusal of this international transfer by emailing dev@habitdog.app. Because Qwen processing is necessary to provide AI chat, refusal may restrict use of that chat feature. You may stop using the Service entirely by deleting your account.
| Items Transferred | Recipient Countries | Time / Method |
|---|---|---|
| Email, display name, profile image, character settings, chat messages, generated images | United States and other countries where the service infrastructure is operated | Real-time network transmission during service use |
| Advertising identifiers (IDFA/AAID) | United States and others | Real-time network transmission during ad serving (only with user consent) |
| Error/crash logs, Session Replay, IP address | United States and others | Real-time network transmission upon errors or session recording (production only) |
| Push tokens, social login authentication identifiers | United States and others | Real-time network transmission upon notification registration or login |
Calls to external AI API services under Section 6-1 do not include the Company's core member identifiers (email, internal user ID, IP, device identifiers, etc.). However, the display name and text entered directly by the user may be processed overseas as described above. Do not enter identifiable personal information such as your real name, government ID, financial information, or precise location in chat.
You may exercise the following rights at any time.
You may exercise these rights through in-app features, or by sending a request via email (dev@habitdog.app), and we will act on your request without delay.
We operate the following automatic collection mechanisms during service use.
You can refuse the above automatic collection through OS settings or by uninstalling the app.
Due to the nature of the Service, we do not allow registration by children under the age of 14. If we become aware that a child under 14 has registered, we will delete the account and related information without delay. If a guardian discovers that their child has registered, please contact dev@habitdog.app.
We designate the following Personal Information Protection Officer to take overall responsibility for personal information processing and to handle complaints and remedies of data subjects related to personal information processing.
Data subjects may apply for dispute resolution or counseling to the following organizations to obtain remedies for personal information infringement.
This Privacy Policy applies from the effective date below. If there are any additions, deletions, or corrections to the contents due to changes in laws or policy, the changes will be announced on this page at least 7 days before they take effect. For changes that materially affect users' rights, the announcement will be made at least 30 days in advance.
This Privacy Policy is effective as of 2026-08-26 (KST). (Previous effective date: 2026-05-31)
← Back to CORA documents