Mayu

Privacy Policy

Announced 2026-09-08 · Effective 2026-09-15 (previous effective date 2026-09-02)

Reference translation: This English text is a courtesy translation provided for reference only. The Korean version is the official, legally binding text, and the Korean version prevails if the two differ. View the Korean original.
At a glance: No provision to third parties / destroyed without delay when you delete your account / health information stored encrypted / contact privacy@habitushealth.app

1. General

Habitus Health Corporation (the “Company”) establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act of Korea to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This policy applies to the mobile application “Mayu” and the website (mayu.ai.kr) provided by the Company. Where processing differs between the app and the website, the relevant article states each separately.

2. Personal Information We Process

Category Items
Member information (required) Email (or social account identifier), nickname, date of birth, sex, device information (model, OS, app version, push token)
Sensitive information (health; separate consent) Height, weight, BMI, goal weight and weight records; meal records, photos, and analysis results; exercise records; type, dose, and administration records of medications; menstrual cycle (optional); fasting records; medical conditions entered by the user; appetite, condition, and adverse-reaction records (when entered); menstrual cycle sharing settings (the items selected for sharing, the identifier of the member the cycle is shared with, the time zone of the sharing member, anniversary dates, and the time sharing started)
Location information (optional consent) GPS location (while recording exercise) · approximate location (to show weather)
Marketing (optional consent) Nickname, app push token
Paid subscription (optional) Subscription status (whether subscribed, product, period) and payment history metadata (payment time, product name, amount, app market order identifier). Payment-method information (card numbers and similar) is processed by the app market operator and is not collected or stored by the Company
Community (optional use) Group chat messages and attached photos, cheering posts (destroyed when a member deletes their account, and together with the room when a group room is removed)
Automatically collected Access time, access IP, app usage records (including error logs)

When a member uses the menstrual cycle sharing feature, only the items the member selects are displayed to one other member whom the member designates with an invitation code, and they remain displayed until the member turns sharing off. The Company does not create a copy for that display on the other member’s device or account, and the sharing settings are destroyed without delay when sharing is turned off or the member deletes their account.

3. Purposes of Processing

① Member management, including sign-up, identification, and sign-in (including sending a one-time email verification code at sign-up) ② storing and displaying records such as meals, exercise, weight, and medication, and providing statistics ③ operating friend and group community features ④ responding to customer inquiries and delivering announcements ⑤ preventing fraudulent use and securing service stability ⑥ de-identified statistical analysis for service improvement

4. Retention Period

Personal information is destroyed without delay when a member deletes their account, except that information is retained for the periods required by law, including the Protection of Communications Secrets Act (access records, 3 months) and the Act on the Consumer Protection in Electronic Commerce (where applicable: contract and payment records, 5 years; dispute handling, 3 years; display and advertising, 6 months).

5. Provision to Third Parties

① The Company does not provide personal information collected in the app to third parties. ② However, on the website (mayu.ai.kr), for visitors who have consented to the advertising purpose, behavioral information is transmitted to Meta Platforms, Inc. through the Meta pixel as described in Sections 11 and 12. This constitutes provision to a third party under Article 17 of the Personal Information Protection Act and a cross-border transfer under Article 28-8 of the same Act; the transfer details are disclosed in Section 7. ③ If any other provision becomes necessary in the future, the Company will disclose the recipient, purpose, items, and retention period, obtain separate consent under Article 17 of the Personal Information Protection Act, and publish the details in this policy. ④ Sharing activity in friend and group features is the data subject’s own choice to display information to other members within a scope the data subject selects, and does not constitute provision to third parties. ⑤ Display in the menstrual cycle sharing feature is likewise the data subject’s own choice of the items to share and of the member to share them with, displayed to one other member, and does not constitute provision to third parties. The feature operates only after separate consent is obtained on that screen, and the display stops when the data subject turns sharing off.

6. Outsourcing of Processing

The Company outsources personal-information processing as follows under Article 26 of the Personal Information Protection Act. Outsourcing contracts stipulate compliance with privacy laws, restrictions on re-outsourcing, and security measures, and the Company supervises each processor.

Processor Outsourced work
Amazon Web Services, Inc. (Seoul region, Korea) Cloud server operation and data storage, and email delivery (transactional email such as sign-up verification codes) — stored in Korea, so this is not a cross-border transfer
Google LLC (Firebase) Sending app push notifications
Anthropic, PBC (Claude API) AI analysis of meal photos and generation of AI coach (Mayu coach) answers — the information provided is used only for analysis and is not used for model training (DPA)
Open-Meteo (weather forecast API · governed by Swiss law) Weather lookup on the home screen. Only coordinates rounded to about 1 km are sent; account identifiers, names, and records are not sent (the operator discloses that the access IP and the coordinates may remain in its server logs)

7. Cross-border Transfer

To provide meal analysis and the AI coach through a US-based AI provider (Anthropic), the Company transfers personal information (including sensitive health information) abroad as set out below, with the member’s separate consent under Article 28-8, Paragraph 1, Item 1 of the Personal Information Protection Act (see the “Consent to Cross-border Transfer of Personal Information” for the consent language). AWS, which stores the data, uses the Seoul region in Korea, so storage does not constitute a cross-border transfer. Data subjects may refuse or withdraw consent, in which case sign-up and use of AI meal analysis and the AI coach may be limited.

Item Details
Recipient Anthropic, PBC (Claude API) — note: AWS uses the Seoul region in Korea and is not a cross-border transfer
Country United States
Time and method Transmitted over telecommunications networks when AI features are used
Items transferred Meal photos submitted for AI analysis, AI coach conversation input (may include health records)
Purpose AI meal analysis and generation of AI coach answers
Retention and use period Until the purpose of the outsourced work is achieved (destroyed without delay upon account deletion or withdrawal of consent)

The Company also transfers personal information abroad as set out below for visit analysis and personalized advertising on its website (mayu.ai.kr). Transfers occur only for visitors who have consented to the relevant purpose, and no information is sent before consent because the script is not loaded. Refusing or withdrawing consent does not restrict use of the website.

Item Advertising purpose Analytics purpose
Recipient Meta Platforms, Inc.
(Contact) 1 Meta Way, Menlo Park, CA 94025, USA · help.meta.com/support/privacy
Google LLC
(Contact) googlekrsupport@google.com
Country United States United States
Time and method Transmitted over telecommunications networks through the Meta pixel while a consenting visitor uses the website Transmitted over telecommunications networks through Google Analytics 4 while a consenting visitor uses the website
Items transferred Page view records, app store button click records, cookie identifiers (_fbp, _fbc) Referral paths and page usage records, cookie identifiers (_ga series)
Purpose Displaying personalized advertising and measuring advertising performance Analyzing how the website is used
Retention and use period Cookies for up to 3 months; deleted immediately upon withdrawal of consent Cookies for up to 24 months; deleted immediately upon withdrawal of consent
How to refuse, and the effect Leaving the relevant option unselected or choosing “Decline all” in the cookie banner prevents the transfer. Consent may be withdrawn at any time through “Cookie settings” in the Cookie Policy, and refusing or withdrawing does not restrict use of the website.

8. Destruction of Personal Information

① Personal information is destroyed without delay when the retention period expires or the purpose of processing is achieved. ② Electronic files are deleted in a way that makes recovery impossible, and paper documents are shredded or incinerated.

9. Rights of Data Subjects and Legal Representatives

① Data subjects may at any time request access to, correction or deletion of, or suspension of processing of their personal information under Articles 35 through 37 of the Personal Information Protection Act. ② Rights may be exercised through in-service features, in writing, or by email (privacy@habitushealth.app), and the Company notifies the result of its measures within 10 days of receiving the request. ③ The Company accepts only adults (19 or older under Korean law) as members and does not process personal information of children under 14 (see Article 22-2 of the Act).

10. Security Measures

Under Article 29 of the Personal Information Protection Act and the Standards for Measures to Secure the Safety of Personal Information, the Company establishes and implements an internal management plan, manages tiered access permissions, operates access controls (intrusion blocking and detection), encrypts personal information (passwords and sensitive health information encrypted in storage and in transit), retains access records and prevents their forgery or alteration, prevents malicious programs, and controls physical access.

11. Automatic Collection Tools

① The app does not use web browser cookies. The app may use tools that collect device information and error logs to secure service stability, and the items collected do not exceed the automatically collected items listed in Section 2. ② The website (mayu.ai.kr) uses cookies to analyze visits and measure advertising performance. The tools used, the types of cookies, and their retention periods are disclosed in a table in the Cookie Policy. ③ Analytics cookies and advertising cookies each require separate consent, and the relevant script is not loaded before consent is given. ④ Visitors may select individual purposes or decline all of them in the notice banner shown on their first visit, and may change their choice at any time through “Cookie settings” in the Cookie Policy. Declining all of them does not restrict use of the website. ⑤ Visitors may also refuse or delete stored cookies in their web browser settings.

12. Behavioral Information

① The Company collects and uses behavioral information on its website (mayu.ai.kr) for personalized advertising as set out below. The app does not collect behavioral information for personalized advertising.

Item Details
Behavioral information collected Website page view records, app store button click records, cookie identifiers (_fbp, _fbc)
Collection method Collected and transmitted automatically through the Meta pixel (Meta Platforms, Inc.) while a visitor uses the website
Purpose Displaying personalized advertising and measuring advertising performance
Retention and use period Cookies for up to 3 months; deleted immediately upon withdrawal of consent

② Advertising cookies require consent separately from analytics cookies, and the pixel script is not loaded before consent is given, so no information is sent to Meta.

③ Data subjects may refuse collection by leaving “Advertising cookies” unselected or choosing “Decline all” in the notice banner, and may withdraw consent at any time through “Cookie settings” in the Cookie Policy. Stored cookies (_fbp, _fbc) are deleted immediately upon withdrawal, and refusing or withdrawing consent does not restrict use of the Service.

④ The information above is transferred to Meta Platforms, Inc. in the United States. This constitutes provision to a third party under Article 17 of the Personal Information Protection Act and a cross-border transfer under Article 28-8 of the same Act, and the transfer is disclosed in Section 7.

⑤ The Company does not use sensitive information, such as health records entered in the app, for personalized advertising, and does not combine it with information collected through the pixel.

13. Pseudonymized Information

The Company does not currently process pseudonymized information. If information is pseudonymized in the future for statistical, scientific research, or public-interest archiving purposes under Article 28-2 of the Personal Information Protection Act, the details will be disclosed in this policy.

14. Privacy Officer

The Company designates and operates a privacy officer under Article 31 of the Personal Information Protection Act. Responsible department: Privacy & Security Team · Contact: privacy@habitushealth.app · +82-70-8018-8640

15. Remedies for Infringement

You may report to or consult the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the Cybercrime Investigation Division of the Supreme Prosecutors’ Office (1301), or the National Police Agency Cyber Investigation Bureau (182, ecrm.police.go.kr). These are Korean authorities.

16. Changes to This Policy

If this policy is added to, deleted from, or amended, notice is given through in-service announcements from 7 days before the effective date (30 days for material changes to data subjects’ rights).

Home · Terms of Service · Privacy Policy · Cookie Policy · 한국어 원문

© 2026 Habitus Health Corporation. All rights reserved.