Privacy Policy
Last updated: September 26, 2026 (draft)
Mirimi ("the service") is built to collect as little as possible and to let you take it all back. This policy explains what we collect, why, who processes it for us, and when it is deleted. The service is operated from the Republic of Korea and follows the Personal Information Protection Act (PIPA); if you live elsewhere, the rights your local law gives you still apply.
Operator (data controller)
- Legal / trading name: ITERIA (이터리아), represented by Jinwook Choi
- E-mail: support@iterialab.com
- Address: Room 310, College of Business Administration and Economics, 70 Hannam-ro, Daedeok-gu, Daejeon 34430, Republic of Korea
1. What we collect
(1) When you sign up
- E-mail sign-up: your name (nickname), your e-mail address and your password, stored only as an irreversible hash, so we never see the password itself.
- Google sign-in: your Google account identifier and e-mail address, plus the name and profile picture URL that Google passes on, and the name (nickname) you confirm when you finish signing up. The name from Google only pre-fills the name field; we keep only the name you confirm and save.
- Both: the sign-up date, your app language and your device time zone.
- Your name (nickname) is used only to address you in the app and to tell accounts apart. It does not have to be your real name, and you can change it any time in Me → Settings → Name. We do not collect your date of birth or phone number (we only ask you to confirm you are 14 or older when you sign up). Things like your age range or gender are collected only as the optional items in (5) below, and only if you choose them.
(2) What builds up on the server as you use the service
- Study material: the text extracted from the file you chose, its title, page and character counts, its language, and an optional exam date.
- The original file is never uploaded. Text extraction happens on your device.
- Questions: the AI-generated questions, options, answers, explanations and short source excerpts (120 characters or fewer), and the name of the model that produced them.
- Study activity: your answers, whether they were correct, response times, the question format, whether you used a hint, whether you graded yourself, when you answered and when the server received it, the number of the sitting (study session) each answer belonged to, your review schedule and an estimate of your current level.
- Notification settings: whether reminders are on, the times, the days, the daily limit and your quiet hours.
- Question reports: the question you reported and the reason.
- Generation logs: the model name, prompt version, success or failure, token counts, duration and error message. The text of your material is not kept in these logs.
- Plan usage: your plan and how many generations you have used today and this month.
- Entitlements: the Pro periods from a free trial, a paid subscription, the launch promotion and similar offers, and a record of when each period was created or changed (when you became Pro and when it ended, including periods pushed back by rewards).
- Consent records: which document and version you accepted, when, and in which language you read it. We also keep, with the time, each time you give, decline (including simply closing the consent sheet) or withdraw consent to ad data sharing. We keep a decline so that we don't ask you the same question again on another device or after you reinstall the app.
- Rewards (if you use or have used Pro): when rewards applied to you, daily study totals (including whether you completed the quest and how many long-term correct answers you had), the point ledger, settlement results, billing-date deferral records and any signals that need review.
- Usage analytics — app sessions: when you opened and left the app, how long you stayed, how you came in (launch, return, or a notification tap), and how often you visited each screen and for how long (the kind of screen only — never the IDs or contents of your materials or questions).
- Usage analytics — feature events: the event name with a few simple properties (for example: opened from a notification, reached a plan limit, changed a setting, opened the plans screen), the app build number and the time. On the free plan this also records whether an ad slot opened, whether an ad or a note from Mirimi was shown, and the revenue amount and currency of a single ad. The content of the ads is never recorded.
- Usage analytics — device information: operating system and version, device model, app version, device language and region setting, and time zone.
- Usage analytics never contain your e-mail, your material or question text. We do not collect device identifiers, advertising IDs or location (GPS). What Google receives, such as your advertising ID, when ads are shown on the free plan is described separately in sections 4 and 13.
- Turn "Send usage data" off under Me → Settings → Privacy and we stop collecting them and delete what your device was still holding. The ad records above follow this switch too. However, what the Google ads SDK sends directly to Google cannot be turned off with this switch (section 13).
- Daily summaries: a per-user daily summary the server computes from the records above and your study activity (how many times you opened the app, time spent, first and last use, questions answered, study sessions, notification opens, and your plan that day).
(3) Stored on your device
- App language, sound, daily goal and whether you have seen the welcome screen.
- A copy of your notification settings and the scheduled reminders (including the upcoming-payment notice). Reminders are raised by your device; there is no push server, so their contents never reach us.
- Answers that have not been uploaded yet. They are sent when you are back online, then removed from the device.
- The consent boxes you ticked at sign-up. They are written to the server at your first sign-in and then cleared.
- On the free plan: how many practice rounds you have used today, the order of ad slots, the date until which notes from Mirimi are paused, and whether you have already seen one-time notices (trial ended, free plan changes and similar).
- These values stay on your device. However, while "Send usage data" is on, events such as changing a setting, a practice round being counted, a notice being shown or choosing "Don't show for 7 days" are recorded as the feature events described in (2).
(4) Crash reports (only in builds where this is enabled)
- When crash reporting (Sentry) is enabled, an error sends us its type and location, the app version, the device model and the OS version.
- Before anything is sent we strip out e-mail addresses and anything that looks like content: extracted text, question text and similar. We never send screenshots, tap recordings or session replays.
- Builds without the setting send nothing at all.
- Turn "Send crash reports" off under Me → Settings → Privacy and we stop collecting them. (In builds without crash reporting the switch is not shown.)
(5) Optional "About you" information (only what you choose)
- Items: age range, gender, status (high school student, university student, employee and so on), year of study, field, reason for studying, how you found Mirimi, and the region you live in. Every item is optional and we collect only what you pick.
- Purpose: improving the service, statistics by user type and marketing planning. We look at it only as statistics that do not identify you, and never use it to send you personal advertising.
- Retention: until you delete it or your account.
- You may refuse, and refusing has no effect at all on your use of the service. You can change or delete your answers any time under Me → Settings → About you.
(6) When you subscribe (once billing is open)
- Google Play processes the payment. We never receive your card number, bank account or other payment details.
- What we receive: the purchase token (kept on the server only), the order number, the product and plan (monthly or 4-month), the payment status (paid, grace period, on hold, cancellation scheduled, refunded), the subscription period (start, end and next billing date), the price, currency and country, and a record of billing dates pushed back by rewards.
- To confirm which account a purchase belongs to, the app sends Google Play an irreversible hash of your account number when you buy.
- Purpose: confirming your subscription and turning Pro on, handling renewals, cancellations and refunds, applying rewards as billing-date deferrals, upcoming-payment notices, and checking for fraudulent payments.
(7) Free-trial record
- Items: an irreversible hash of the e-mail address you signed up with, and the date you received the trial. The e-mail address itself is not kept in this record. For Gmail addresses, dots and anything after a "+" are ignored before hashing, so variants count as the same address.
- Purpose: to give each person the free trial only once (so that deleting an account and signing up again does not restart the trial). If a record exists, you can still sign up but you will not get another trial.
- Retention: kept for one year even after you delete your account, then deleted (section 3).
2. Why we use it
- To create and keep your account and sign you in.
- To generate practice questions from your material.
- To schedule reviews and remind you on your device.
- To show your progress, accuracy and memory state.
- To apply plan limits, control costs and prevent abuse.
- To provide paid subscriptions: confirming payments, handling renewals, cancellations and refunds, applying reward points as billing-date deferrals, and upcoming-payment notices.
- To calculate and settle rewards for Pro users and check for abuse, and to show free-plan users the points they would have earned today on Pro.
- To show ads on the free plan (ads are served by Google and follow sections 4 and 13).
- To prevent the free trial from being given more than once (section 1 (7)).
- To answer your questions and handle reports.
- To improve the service through aggregate statistics.
- To improve features and design rewards by analysing how the app is used (how often, for how long, which features, how many questions per sitting).
- To plan marketing using statistics that do not identify anyone. We will ask for your separate consent before sending you any advertising.
- To meet our legal obligations.
3. How long we keep it
- As a rule, while your account exists. When you delete your account, we delete it without delay.
- Deleting a single material also deletes its text, its questions and the related study history.
- Account deletion removes your profile, materials and extracted text, questions, study history and review schedule, level estimates, notification settings, question reports, generation logs, plan usage and entitlements, entitlement change records, consent records, daily summaries, your optional "About you" answers, and all reward enrolment, daily totals, ledger, settlement and review records. The payment and subscription records and the free-trial record below (deleted after one year) are the exceptions.
- Raw usage analytics (app sessions and feature events) are deleted after one year. Older trends are kept only as daily totals that belong to no one (sign-ups, active users, time spent and so on).
- Your optional "About you" answers are deleted as soon as you delete them under Me → Settings → About you.
- Deleted accounts are kept only as a monthly count (how many accounts, by bands of account age, plan and number of active days). We do not keep whose account it was or when it was deleted, and use the count only for statistics to improve the service.
- Points lost through account deletion are kept only as a monthly total (how many accounts left how many points). We do not keep whose points they were or when the account was deleted, and use the total only to reconcile our points liability.
- Two exceptions: usage analytics and billing notification records are kept with the user identifier removed, for statistics and reconciliation only (usage analytics still within the one-year limit above). What remains cannot identify you.
- Payment and subscription records (section 1 (6)) are kept even after you delete your account, as required by Korea's E-Commerce Act: records of contracts, withdrawals, payments and supply for 5 years, and records of consumer complaints and disputes for 3 years. After you delete your account we cut the link to it and keep them only for this purpose. Before billing opens there are no such records.
- The free-trial record (section 1 (7)) is kept for one year after account deletion and then deleted.
- Deletion is permanent. Copies inside backups disappear as the backup cycle rolls over.
4. Sharing
We do not sell your data. We share it with third parties only in the following cases.
① Sharing for ads (free plan, only if you choose to consent)
- Recipient: Google LLC (privacy contact: googlekrsupport@google.com)
- Purposes: showing ads, limiting how often the same ad appears, preventing fraudulent clicks and keeping ads secure, measuring ad performance
- Items: advertising ID and app set ID, IP address (and the approximate location estimated from it), device/OS/app information, ad views and clicks together with usage such as app launches and taps, and app and ad SDK performance data
- Retention: as set by Google's own policy. Google says it anonymizes ad server logs by removing part of the IP address after 9 months and cookie information after 18 months. If you withdraw consent, we stop providing it from then on.
- How: not through our servers — the Google ads SDK inside the app sends it to Google directly.
- You may refuse, and you can still use every learning feature of the free plan. You will see occasional notes from Mirimi instead of Google ads, and only unlocking extra practice rounds by watching ads (up to 2 a day) won't be available.
② Where the law requires it (a valid warrant, court order or similar)
Everything else needed to run the service is handled by the processors in section 5.
5. Processors
- Supabase Inc. — database, authentication and server functions. Entrusted: everything stored on the server under section 1 (1), (2), (5), (6) and (7). Kept until you delete your account (the exceptions in section 3 until their periods end).
- Groq LLC — generating questions from your material text. Entrusted: the passage to build questions from, and the generation settings. Kept only for as long as the request takes.
- [Backup AI provider] — a standby provider used for the same purpose only when the main one is unavailable. We will name it here and announce it before it is actually used.
- Google LLC — Google sign-in. Entrusted: the account details needed to verify the sign-in.
- Functional Software, Inc. (Sentry) — crash reporting, in builds where it is enabled. Entrusted: the error data in section 1 (4).
- Google LLC (Google Play) — app distribution, payment and subscription processing and purchase verification (our server checks the subscription with the purchase token, and asks Google Play to push back the billing date when rewards apply). Entrusted: the purchase token and order and subscription details. Kept as set by Google's policy and contract.
Ads on the free plan (Google AdMob) are not listed here as processing on our behalf, because Google also uses the data for its own purposes; they are disclosed as sharing under section 4 ①.
Each processor is bound by contract to protect the data and not to use it for any other purpose. If this list changes, we update this policy and announce it.
6. Transfers outside Korea (PIPA art. 28-8)
All of the processors in section 5, and the sharing for ads in section 4 ①, involve transfers outside the Republic of Korea.
- Supabase Inc. (United States) — Items: everything stored on the server under section 1 (1), (2), (5), (6) and (7). When and how: continuously over encrypted connections (HTTPS) while you use the service. Purpose: database, sign-in and server functions. Retention: until you delete your account (the exceptions in section 3 until their periods end). The servers that hold the data are in the Seoul region, but because the company is US-based and its staff may access the data for operations and support, we disclose this as an overseas transfer.
- Groq LLC (United States) — Items: the passage to build questions from and the generation settings. When and how: over HTTPS each time questions are generated. Purpose: question generation. Retention: for the duration of the request. We use the provider on terms under which your text is not used to train models.
- Google LLC (United States) — Items: the account details needed to verify a Google sign-in. When and how: over HTTPS at sign-in. Purpose: authentication. Retention: per Google's own policy.
- Google LLC (United States) — Google Play purchase verification — Items: purchase token, order number, subscription status and billing-date deferral requests. When and how: over HTTPS when you pay, renew, cancel or get a refund, and when rewards are applied. Purpose: confirming subscriptions and applying rewards. Retention: per Google's own policy.
- Google LLC (United States and other countries) — ads (free plan, only if you separately consent to the transfer abroad) — Countries: the United States and other countries where Google operates servers. Items, purposes and retention: as in section 4 ①. When and how: each time an ad is loaded or shown, the ads SDK in the app sends it over an encrypted connection (TLS), not via our servers. Recipient: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · privacy contact: googlekrsupport@google.com. How to refuse: do not consent, or turn off Me → Settings → Privacy → "Ad data sharing"; you will then see notes from Mirimi instead of Google ads.
- Functional Software, Inc. / Sentry (United States) — Items: the error data in section 1 (4). When and how: over HTTPS when an error occurs. Purpose: diagnosing and fixing faults. Retention: the provider's configured period.
- Privacy contacts of the recipients: Supabase Inc. privacy@supabase.com · Groq LLC privacy@groq.com (P.O. Box 1778, Mountain View, CA 94042, USA) · Google LLC googlekrsupport@google.com (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) · Functional Software, Inc. (Sentry) compliance@sentry.io (45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA)
You can refuse. You may refuse these transfers. However, sign-in, storage and question generation are the core of the service, so refusing means you cannot really use it; you would refuse by not signing up, or by deleting your account. Crash reports, usage data and ad data sharing can be refused on their own: turn off "Send crash reports", "Send usage data" and "Ad data sharing" under Me → Settings → Privacy. If you cannot reach those switches, write to support@iterialab.com instead.
7. Your rights
- You can ask to see, correct, delete or stop the processing of your personal data at any time.
- Things you can do in the app right away: review your study history (Me tab), delete materials and questions, change notification settings, turn off crash reports, usage data and ad data sharing (Me → Settings → Privacy), change or delete your optional answers (Me → Settings → About you), and delete your account (Me → Settings → Delete account).
- You can withdraw your consent to ad data sharing at any time (Me → Settings → Privacy → "Ad data sharing"). You can delete or reset your phone's advertising ID under Settings → Google → Ads (menu names differ slightly between devices). Once deleted, only an all-zero value is passed on.
- For anything else, use Me → Settings → Send feedback or write to support@iterialab.com. We reply within 10 days of receiving the request.
- A legal representative or an authorised agent may act for you; we will verify the authorisation.
- We will never treat you differently for exercising these rights.
8. Children under 14
- You must be at least 14 to sign up. We confirm this at sign-up and keep a record of the confirmation.
- If we find that a user is under 14, we delete the account and its data. If you know of such an account, please tell us at support@iterialab.com.
- We encourage every user under 19 to agree study times with a parent or guardian.
- For every user, including those under 18, ad requests are sent with teen protections and we never request personalized ads.
9. How we protect your data
- Access control: the database uses row-level security, so each account can read and write only its own rows.
- Encryption in transit: all traffic between the app and the server uses HTTPS.
- Passwords: stored only as irreversible hashes.
- Secrets: AI provider keys and similar values live on the server and are never shipped inside the app.
- Purchase tokens: on the server they are kept only in an area the app cannot read; the tables the app reads hold only an irreversible hash.
- Data minimisation: we do not keep original files, and crash reports are scrubbed of anything that looks like content.
- On the device: app data is stored where other apps cannot read it and is excluded from device backups.
10. Automated decisions
- The service automatically decides which question to ask next and when to schedule a review, based on your study history. This is there to help you learn and does not affect your legal rights or obligations.
- Rewards: 4 days before your next payment, right after your first payment, and when your points reach 10,000P, points are applied automatically as a billing-date deferral under the rules (Rewards Rules section 5). If you disagree with the result, write to support@iterialab.com.
- If reward activity shows signs of abuse, the payout is held and a person reviews it. If you disagree with the outcome, write to support@iterialab.com and we will look again.
11. Data protection officer
- Data protection officer: Jinwook Choi (Representative)
- Contact: support@iterialab.com
- Responsible for privacy enquiries, complaints and remedies.
In Korea you may also contact the Korea Internet & Security Agency privacy centre (privacy.kisa.or.kr, 118), the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), or the police cybercrime bureau (ecrm.police.go.kr, 182). If you are in the EU or the UK, you may also complain to your local supervisory authority.
12. Changes to this policy
- When this policy changes we announce the change and its effective date in the app. For changes that matter to you we give 30 days' notice and ask you to accept the new version.
13. Behavioural information: collection, use, sharing and how to refuse
- We do not use behavioural information such as your app usage for personalized ads, and we do not ask any ad company for personalized ads.
- When ads are shown on the free plan, the Google ads SDK (AdMob) inside the app requests an ad from Google, and Google receives the information in section 4 ① (if you chose to consent to ad data sharing).
- Settings we apply to every ad: personalized ads off (non-personalized ads only), teen protections, ad content rating G (all ages), and ads in sensitive categories blocked (gambling, alcohol, dating, weight loss, loans, sexual content, politics, religion and similar). Your study materials, questions and "About you" answers are never put into ad requests.
- When we do not request ads: while you use Pro, a trial or the launch offer; before you accept the Terms and the Privacy Policy; and if you have not consented to ad data sharing. While you use a screen reader (TalkBack) or Switch Access, we do not request full-screen ads after a session (except "Watch an ad for 1 more round", which you choose yourself).
- The ad records in our usage analytics (section 1 (2)) follow the "Send usage data" switch, but what the Google ads SDK sends directly to Google cannot be turned off with that switch. To stop it, use the options below.
- How to refuse or control it: ① in the app, turn off Me → Settings → Privacy → "Ad data sharing" ② on your phone, Settings → Google → Ads → "Delete advertising ID" ③ use Pro ④ where the law requires it (such as in Europe), Me → Settings → "Ad privacy choices"
- How Google handles data: Google Privacy Policy (https://policies.google.com/privacy) and "How Google uses information from sites or apps that use our services" (https://policies.google.com/technologies/partner-sites)
- Contact: the data protection officer in section 11
This document is still a draft. The final wording may change after a lawyer's review before release.