Chatple Global
Privacy Policy
Last updated: September 1, 2026
Article 1 (Overview, Scope)
- METACRAFT CO., LTD. (the ‘Company,’ ‘we,’ ‘us,’ or ‘our’) operates the Chatple Global website, AI character chat, content, and related features (collectively, the ‘Service’). We process personal information lawfully and securely under the Personal Information Protection Act of Korea (‘PIPA’) and other applicable laws, as described in this Privacy Policy.
- This Policy applies to Service visitors, Members, Creators, support requesters, and other individuals who interact with the Service. Information independently processed by an external website or platform is governed by that provider's own policy.
Article 2 (Personal Information and Legal Bases)
- Contract performance and Service delivery (PIPA Article 15(1)(4)): Where account registration, login, or similar account features are provided, we may process the minimum account-identification information and Service settings supplied by the user or login provider. However, signup data collected by Chatple Korea, such as name, mobile telephone number, date of birth, and gender, is not separately stored in the Chatple Global database.
- AI chat and content features (PIPA Article 15(1)(4)): We may process prompts, chat content and history, character and scenario settings, uploaded images, audio, and files, generated output, content reports, and safety-review information.
- Support, rights requests, and reports (PIPA Article 15(1)(4) and legal obligations): We may process, to the extent necessary, an email address or account identifier, inquiry or report content, attachments, identity-verification results, and resolution records.
- Automatically generated Service data (contract performance or legitimate interests under PIPA Article 15(1)(6)): We may process, to the minimum extent necessary, IP address, device, browser, operating-system and language information, access time, usage, click, search and error logs, session identifiers, cookies, and fraud or security signals. Where legitimate interests are relied upon, we balance our interests against user rights and apply appropriate safeguards.
- Consent-based information (PIPA Article 15(1)(1)): When required, we separately disclose and obtain consent for optional marketing contact details, optional analytics or advertising technologies, sensitive information for a separate feature, or information beyond what is necessary, including the items, purpose, retention period, and effect of refusal. Refusing optional consent does not prevent use of the core Service, though the optional feature may be unavailable.
- Information from third parties: We may receive the minimum account identifiers, public profile information, or security signals necessary for a user-selected feature from login providers, fraud-prevention providers, or partners.
Article 3 (Purposes of Processing)
- We process personal information to register and manage accounts, enable login, provide AI chat, character, image and community features, maintain user settings, and generate requested output.
- We process personal information to receive, verify, and resolve support inquiries, reports, privacy-rights requests, complaints, and disputes, and to communicate the outcome.
- We process necessary information to detect and address account compromise, fraud, spam, security incidents and prohibited content, ensure system reliability, enforce our terms, and protect users and the Service.
- We may process minimal information to analyze Service use, troubleshoot errors, improve quality, and develop features. We do not currently use raw chats to train general-purpose AI models.
- Where a user separately consents, we may send event, benefit, new-feature, or promotional messages and measure advertising performance.
Article 4 (AI Chats, Sensitive Information, and Training Use)
- AI chats may contain private thoughts and sensitive content relating to sexual preferences or sex life, health, beliefs, or similar matters. We do not require users to submit real-world sensitive information to use core chat features. Users should not unnecessarily submit their own or another person's real name, contact details, unique identifiers, confidential information, or sensitive information.
- Chat input may be processed by us and AI providers to generate the requested response and review safety or errors. Direct account identifiers are separated or removed before transmission. Any temporary processing or retention by an external AI provider, and its duration, is governed by our applicable contract and API settings and that provider's data-retention policy. We limit processing to what is necessary to provide the Service, and internal access is restricted to personnel with a business need.
- We do not currently use raw chats to train general-purpose AI models or process chat messages as a separate pseudonymized dataset for analytics or model improvement. If we introduce such processing, we will establish the legal basis and safeguards required by PIPA and update this Policy.
- If a separate feature intentionally processes or provides sensitive information to a third party, we obtain consent separately from other consent under PIPA Article 23. Users may report or challenge inappropriate output or data use at support@chatple.live.
Article 5 (Retention and Destruction)
- Account, profile, and Service settings are retained until account deletion and, where necessary to prevent restoration errors or misprocessing, destroyed within up to seven days afterward. Account identifiers, IP addresses, and enforcement records necessary to prevent abuse may be retained for up to one year from collection under legitimate interests and data-minimization principles.
- Chat input, attachments, generated output, and safety-review information are generally retained for six months from collection for Service delivery, disputes, and safety response. If a user deletes a chat earlier, we delete it within a reasonable period except where legal retention or security needs apply.
- Support, complaint, and dispute records are retained for up to three years after resolution. Analytics and behavioral information is retained for up to one year from collection or the shorter period configured in the applicable tool. A shorter operational setting controls where applicable.
- We destroy personal information without undue delay when its retention period expires or its purpose is fulfilled. Electronic files are deleted in a manner designed to prevent restoration, and paper records are shredded or incinerated. Information retained by law is logically separated and restricted from use for other purposes.
Article 6 (Provision to Third Parties)
- We process personal information within the disclosed purposes and do not provide it to a third party without separate consent or another legal basis. Before a third-party provision, we disclose the recipient, purpose, data, retention period, and effect of refusing consent.
- We may provide only necessary information within the scope permitted by law in response to a lawful request from an investigative authority, court, or regulator, or where there is a legal basis to urgently protect the life, body, or property of a user or third party.
- An AI, cloud, or analytics provider acting only on our instructions is managed as a processor. If a provider uses information for its own purposes or independently retains it, we separately assess third-party provision and provide any required disclosure or consent.
Article 7 (Processing by Service Providers)
- We may outsource the following categories of work to service providers: cloud hosting and backup; AI model inference and response generation; login; support and message delivery; analytics and error monitoring; and security and fraud prevention.
- We use Amazon Web Services for cloud services and ByteDance/Volcengine, Google, OpenRouter, Anthropic, and OpenAI for AI models or infrastructure. Optional analytics and advertising may use Google, Meta, and other domestic or international advertising platforms, advertising networks, or advertising-measurement providers. Specific providers may vary depending on advertising activities.
- Our processing agreements address purpose limitation, security, confidentiality, subcontracting restrictions, incident notice, return or destruction, oversight, and responsibility. We supervise processors' secure handling and disclose changes to processors or outsourced work through this Policy.
Article 8 (Overseas Transfers)
- Because Chatple Global uses overseas cloud and AI providers, personal information may be stored, accessed, or processed outside Korea. Under PIPA Article 28-8, we establish a lawful basis, such as overseas processing or storage necessary to perform the contract or separate consent, and apply required safeguards.
- Amazon Web Services, Inc. (United States, privacy@amazon.com): At Service use, minimum account-identification information, usage records, chats and attachments, and IP and device information are transferred through encrypted networks such as TLS for hosting, storage, and backup. We use the same provider environment as Chatple Korea, and the information is destroyed under our retention periods and contractual deletion schedule.
- ByteDance Ltd. (Volcengine) (Singapore, privacy@bytedance.com), Google LLC (United States, data-protection-office@google.com), OpenRouter, Inc. (United States, privacy@openrouter.ai), Anthropic PBC (United States, privacy@anthropic.com), and OpenAI OpCo, LLC (United States, privacy@openai.com): When an AI feature is used, chat input, attachments, character settings, and technical information needed for generation are transferred via HTTPS for model inference, response generation, and safety processing. Direct account identifiers are excluded. Each provider's retention and use period is governed by our applicable contract and API settings and that provider's data-retention policy.
- Google LLC, Meta Platforms, Inc., and other domestic or international advertising platforms, advertising networks, or advertising-measurement providers: If a user allows optional Analytics or Marketing technologies and we actually deploy those tools, cookies, browser or device identifiers, IP address, and visit, click, or conversion events may be transferred through encrypted networks for usage analytics, online advertising operations, and advertising-performance measurement. Specific providers may vary depending on advertising activities; retention and refusal methods are described in Articles 5 and 9.
- Refusing an overseas transfer necessary to perform the contract may prevent the relevant AI or account feature from being provided. Optional transfers for analytics or advertising may be refused through the Service's Cookie Settings, and related cookies may also be blocked through browser controls. We update and announce this Policy when a new provider materially changes the processing purpose, transferred data, country, retention, or other important conditions.
Article 9 (Cookies and Behavioral Information)
- We classify storage technologies by purpose. ‘Necessary’ supports requested Service functions such as login sessions, security, language settings, and storage of cookie choices. ‘Analytics’ covers usage, error, and performance analysis, while ‘Marketing’ covers online advertising operations and advertising-performance measurement.
- On a first visit, users may choose ‘Accept all,’ ‘Continue with necessary only,’ or ‘Settings.’ Necessary is always active, while Analytics and Marketing are off by default until the user provides consent. The settings interface permits category-level choices, and the actual tools, data, and retention periods are disclosed in this Policy or a linked cookie list.
- Cookie choices are stored only in that browser's cookie or localStorage and are not linked to a login account or retained in our server database. A separate choice is therefore required in another browser or device, and the banner may reappear after browser data is cleared or when private-browsing mode is used.
- Behavioral information may include visited pages, searches, clicks, feature use, ad impressions and clicks, cookies, advertising identifiers, click IDs, IP, device and browser information, and conversion events, collected through web tags, pixels, SDKs, or server-to-server transmission. Such information may be processed through Google LLC, Meta Platforms, Inc., and other domestic or international advertising platforms, advertising networks, or advertising-measurement providers. Specific providers may vary depending on advertising activities. We do not use raw chats or sensitive chat information concerning sexual preferences, health, or similar matters for advertising or advertising-performance measurement.
- Advertising pixels and server-to-server (‘S2S’) conversion transmission are used only where needed for actual advertising operations. If a user has not allowed Marketing in that browser, we do not run advertising pixels or send advertising-purpose S2S conversion events arising from that browser. This does not mean every tool uses an identical technical value or architecture; it means the same category choice governs the same advertising purpose. Before sending account, email, telephone, or other information to an ad provider for matching, we establish the required legal basis and separate disclosure.
- Users may change or withdraw choices for the same browser at any time through ‘Cookie Settings’ in the Service footer or another persistent location. They may also delete or block cookies in the browser or manage mobile advertising identifiers and tracking permissions. A change applies to that browser, and blocking Necessary storage technologies may prevent login or other features from working.
Article 10 (Promotional Communications)
- Under Article 50 of Korea's Network Act and other applicable laws, we send promotional information by email, text, push, or web notification only after obtaining prior consent. Operational notices concerning transactions, security, or policy changes are distinguished from promotional messages.
- Users may withdraw promotional-message consent at any time through the unsubscribe control in a message, account settings, or support@chatple.live. We stop promotional messages after withdrawal and notify the user of consent, refusal, or withdrawal processing as and when required by law.
Article 11 (Security and Data Incidents)
- We apply administrative, technical, and physical measures proportionate to processing scale and risk, including internal plans, training and least-privilege access, access control and log review, encryption in transit and at rest, one-way password hashing, vulnerability and malware response, backups, and physical access controls.
- Access logs of personnel and others to personal-information systems are retained and reviewed for the period required by Korea's Security Measures Standards. These logs differ from ordinary user web-visit records, and cookie choices are stored only in the relevant browser as described in Article 9.
- If a personal-data incident occurs, we take steps to mitigate harm and notify affected users and report to the Personal Information Protection Commission or another authority when and within the time required by PIPA.
Article 12 (User Rights and How to Exercise Them)
- Users may request access or transmission, correction or deletion, suspension of processing, and withdrawal of consent. A request may be limited where another law requires retention or another statutory restriction applies, in which case we explain the reason.
- Requests may be made through account settings, in-Service deletion tools, or support@chatple.live. We may verify the requester or a lawful representative and respond within the statutory period.
- If we make a solely automated decision that materially affects a user's rights or obligations, the user may reject it or request an explanation and human review to the extent provided by PIPA Article 37-2. Ordinary AI response generation is not, by itself, treated as a consequential automated decision.
- Automated tools may assist with fraud detection, content review, or account enforcement. We provide a reasonable appeal and human re-review mechanism for significant actions such as account suspension or restriction of Service access.
Article 13 (Age Restrictions and Children's Data)
- The Service is generally intended for users aged 18 or older, and users must confirm that they are at least 18 when using the Service.
- We do not knowingly collect personal information from children under 14. If we learn that such information was collected without lawful guardian consent, we restrict the account and take necessary steps, including prompt deletion.
Article 14 (Public Areas)
- Information included in public characters, profiles, comments, posts, or Creator content may be visible to other users. Users should review the audience before posting real-world personal information or another person's information in a public area.
Article 15 (Privacy Contact and Remedies)
- Controller: METACRAFT CO., LTD. / Department responsible for privacy matters and related complaints: Customer Support / Contact: support@chatple.live
- Users may seek advice, report an infringement, or request dispute mediation through the KISA Privacy Infringement Report Center (privacy.kisa.or.kr, 118 in Korea), Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), Personal Information Protection Commission (pipc.go.kr), or Supreme Prosecutors' Office cybercrime channel (spo.go.kr, 1301 in Korea).
Article 16 (Changes and Effective Date)
- We may revise this Policy when laws, the Service, technology, processors, or processing practices change. Material changes are announced through the Service, email, or another appropriate method before they take effect, and we obtain renewed consent where legally required. Urgent security or legal changes may be announced immediately or afterward where appropriate.
- Prior versions will be maintained for access through the Service's policy archive. Effective date: September 1, 2026 (draft; to be confirmed after legal review).