Mayu

Privacy Policy

Reference translation: This English text is a courtesy translation provided for reference only. The Korean version is the official, legally binding text, and the Korean version prevails if the two differ. View the Korean original.
At a glance: No provision to third parties / destroyed without delay when you delete your account / health information stored encrypted / contact privacy@habitushealth.app

1. General

Habitus Health Corporation (the “Company”) establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act of Korea to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This policy applies to the mobile application “Mayu” and related services provided by the Company.

2. Personal Information We Process

Category Items
Member information (required) Email (or social account identifier), nickname, date of birth, sex, device information (model, OS, app version, push token)
Sensitive information (health; separate consent) Height, weight, BMI, goal weight and weight records; meal records, photos, and analysis results; exercise records; type, dose, and administration records of medications; menstrual cycle (optional); fasting records; medical conditions entered by the user; appetite, condition, and adverse-reaction records (when entered)
Location information (optional consent) GPS location (only while recording exercise)
Marketing (optional consent) Nickname, app push token
Paid subscription (optional) Subscription status (whether subscribed, product, period) and payment history metadata (payment time, product name, amount, app market order identifier). Payment-method information (card numbers and similar) is processed by the app market operator and is not collected or stored by the Company
Community (optional use) Group chat messages and attached photos, cheering posts (destroyed when the room resets each week)
Automatically collected Access time, access IP, app usage records (including error logs)

3. Purposes of Processing

① Member management, including sign-up, identification, and sign-in ② storing and displaying records such as meals, exercise, weight, and medication, and providing statistics ③ operating friend and group community features ④ responding to customer inquiries and delivering announcements ⑤ preventing fraudulent use and securing service stability ⑥ de-identified statistical analysis for service improvement

4. Retention Period

Personal information is destroyed without delay when a member deletes their account, except that information is retained for the periods required by law, including the Protection of Communications Secrets Act (access records, 3 months) and the Act on the Consumer Protection in Electronic Commerce (where applicable: contract and payment records, 5 years; dispute handling, 3 years; display and advertising, 6 months).

5. Provision to Third Parties

The Company does not provide personal information to third parties. If provision becomes necessary in the future, the Company will disclose the recipient, purpose, items, and retention period, obtain separate consent under Article 17 of the Personal Information Protection Act, and publish the details in this policy. Sharing activity in friend and group features is the data subject’s own choice to display information to other members within a scope the data subject selects, and does not constitute provision to third parties.

6. Outsourcing of Processing

The Company outsources personal-information processing as follows under Article 26 of the Personal Information Protection Act. Outsourcing contracts stipulate compliance with privacy laws, restrictions on re-outsourcing, and security measures, and the Company supervises each processor.

Processor Outsourced work
Amazon Web Services, Inc. (Seoul region, Korea) Cloud server operation and data storage — stored in Korea, so this is not a cross-border transfer
Google LLC (Firebase) Sending app push notifications
Anthropic, PBC (Claude API) AI analysis of meal photos and generation of AI coach (Mayu coach) answers — the information provided is used only for analysis and is not used for model training (DPA)

7. Cross-border Transfer

To provide meal analysis and the AI coach through a US-based AI provider (Anthropic), the Company transfers personal information (including sensitive health information) abroad as set out below, with the member’s separate consent under Article 28-8, Paragraph 1, Item 1 of the Personal Information Protection Act (see the “Consent to Cross-border Transfer of Personal Information” for the consent language). AWS, which stores the data, uses the Seoul region in Korea, so storage does not constitute a cross-border transfer. Data subjects may refuse or withdraw consent, in which case use of AI meal analysis and the AI coach may be limited.

Item Details
Recipient Anthropic, PBC (Claude API) — note: AWS uses the Seoul region in Korea and is not a cross-border transfer
Country United States
Time and method Transmitted over telecommunications networks when AI features are used
Items transferred Meal photos submitted for AI analysis, AI coach conversation input (may include health records)
Purpose AI meal analysis and generation of AI coach answers
Retention and use period Until the purpose of the outsourced work is achieved (destroyed without delay upon account deletion or withdrawal of consent)

8. Destruction of Personal Information

① Personal information is destroyed without delay when the retention period expires or the purpose of processing is achieved. ② Electronic files are deleted in a way that makes recovery impossible, and paper documents are shredded or incinerated.

9. Rights of Data Subjects and Legal Representatives

① Data subjects may at any time request access to, correction or deletion of, or suspension of processing of their personal information under Articles 35 through 37 of the Personal Information Protection Act. ② Rights may be exercised through in-service features, in writing, or by email (privacy@habitushealth.app), and the Company notifies the result of its measures within 10 days of receiving the request. ③ The Company accepts only adults (19 or older under Korean law) as members and does not process personal information of children under 14 (see Article 22-2 of the Act).

10. Security Measures

Under Article 29 of the Personal Information Protection Act and the Standards for Measures to Secure the Safety of Personal Information, the Company establishes and implements an internal management plan, manages tiered access permissions, operates access controls (intrusion blocking and detection), encrypts personal information (passwords and sensitive health information encrypted in storage and in transit), retains access records and prevents their forgery or alteration, prevents malicious programs, and controls physical access.

11. Automatic Collection Tools

The Service is provided as a mobile app and does not use web browser cookies. The app may use tools that collect device information and error logs to secure service stability, and the items collected do not exceed the automatically collected items listed in Section 2.

12. Behavioral Information

The Company does not collect or use online behavioral information for personalized advertising.

13. Pseudonymized Information

The Company does not currently process pseudonymized information. If information is pseudonymized in the future for statistical, scientific research, or public-interest archiving purposes under Article 28-2 of the Personal Information Protection Act, the details will be disclosed in this policy.

14. Privacy Officer

The Company designates and operates a privacy officer under Article 31 of the Personal Information Protection Act. Responsible department: Privacy & Security Team · Contact: privacy@habitushealth.app

15. Remedies for Infringement

You may report to or consult the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the Cybercrime Investigation Division of the Supreme Prosecutors’ Office (1301), or the National Police Agency Cyber Investigation Bureau (182, ecrm.police.go.kr). These are Korean authorities.

16. Changes to This Policy

If this policy is added to, deleted from, or amended, notice is given through in-service announcements from 7 days before the effective date (30 days for material changes to data subjects’ rights).

Home · Terms of Service · Privacy Policy · 한국어 원문

© 2026 Habitus Health Corporation. All rights reserved.