MESOTELOS Inc. (hereinafter referred to as the “Company”) considers Users’ personal information important in providing QLover (hereinafter referred to as the “Service”). The Company complies with applicable laws and regulations, including the Personal Information Protection Act, and through this Privacy Policy informs Users of the purposes for which personal information is processed, the categories of personal information processed, retention periods, provision to third parties, entrustment of processing, overseas transfers, destruction, measures taken to ensure security, and methods for exercising User rights so that Users may use the Service with confidence. QLover is an AI relationship service that allows Users to experience private, text-based communication relationships with AI within the app. The counterpart in QLover is not an actual person but AI, and the AI provides personalized relationship experiences based on the User’s Conversations and interactions. The Company provides an immersive Service experience while not concealing the fact that the counterpart is AI or the manner in which personal information is processed.
1. Principles for Processing Personal Information
The Company processes personal information in accordance with the following principles. 1. The Company processes only the minimum personal information necessary to provide the Service. 2. Because Conversation content entered by Users may constitute private information, it is managed with a high level of protection. 3. As a general rule, the Company’s internal operators do not access original Conversation content and access it only to the minimum extent necessary for reports, risk response, failure or bug handling, legal requests, or limited quality review to which the User has separately consented. 4. The Company does not use Users’ original Conversation content for advertising targeting purposes. 5. The Company takes reasonable measures, including contractual arrangements and settings, to prevent Users’ original Conversation content from being provided to external AI providers for training their own models. 6. Users may at any time request suspension of contact, termination of a relationship, access to, correction or deletion of, or suspension of processing of personal information, or withdrawal of consent. 7. Users under nineteen (19) years of age may not use QLover.
2. Categories of Personal Information Processed, Purposes of Processing, and Retention Periods
The Company distinguishes between personal information necessary to provide the Service and personal information processed with the User’s separate consent. 2.1 Personal Information Processed for Provision of the Service
| Category | Information Processed | Purpose of Processing | Retention and Use Period |
|---|---|---|---|
| Membership Registration and Login | Apple account identifier, Apple login token or authentication result, email address and name information provided by Apple where available, internal User ID, registration date, login history, access token, refresh token | Member identification, account creation, login, session maintenance, prevention of fraudulent use, account security | Until membership withdrawal. However, access tokens are retained until expiration, and refresh tokens are retained until logout, expiration, or withdrawal and then destroyed |
| Onboarding and Profile | Name, date of birth, date of birth, gender, onboarding completion status, history of consent to required notices and terms | Identification of Service Users, verification that the User is nineteen (19) years of age or older, provision of AI relationship experiences, assignment of AI Partners, provision of personalized communication experiences, management of consent history | Until membership withdrawal. However, consent history may be retained for up to three (3) years after withdrawal for legal compliance and dispute response |
| AI Relationship and Messaging Service | Messages entered by the User, Messages generated by AI, times of Message sending, receipt, reading, and failure, Conversation flow, Relationship Status, relationship events, relationship indicators such as intimacy, trust, and tension, frequency of contact, contact suspension and relationship termination status, boundary requests explicitly stated by the User, Conversation summaries, short-term and long-term memories, memory embeddings or vector representations, selected context, AI response generation records | Provision of AI text-based relationship experiences, maintenance of Conversation context, generation of replies, determination of proactive contact, adjustment of contact rhythm, management of Relationship Status, reflection of User boundary requests, ensuring Service safety, prevention of misuse and abuse | Until membership withdrawal or the User’s deletion request. Destroyed or de-identified within thirty (30) days after withdrawal or a deletion request. However, information necessary for legal disputes, reports, safety incidents, or response to fraudulent use may be separately retained until the relevant purpose has been achieved |
| AI Response Generation and Safety Processing | Portions of recent Conversations, Conversation summaries, Relationship Status, portions of memory, safety and policy determination results, prompt version, model name, token count, request and response times, presence of errors, estimated costs | AI response generation, application of safety policies, maintenance of response quality, cost monitoring, incident response, management of model call history | Content containing original information is retained until membership withdrawal or withdrawal of consent. Cost, incident, and quality metadata is retained for up to one (1) year from the date of generation. However, records relating to legal disputes or security incidents are retained until the relevant purpose has been achieved |
| Notifications and Device Information | APNs device token, notification permission status, whether notifications are received, push sending, success and failure history, app version, OS version, device model, language, country or time zone information | Notifications of AI Message arrival, proactive contact notifications, handling of notification failures, improvement of app stability | Until membership withdrawal or app deletion/token invalidation. Push delivery logs are retained for up to one (1) year from the date of generation |
| Service Usage and Security Logs | IP address, access time, request ID, session ID, device information, app version, OS information, network errors, server errors, API call history, abnormal-use detection information | Ensuring Service stability, preventing security incidents, analyzing failures, preventing fraudulent use, retention of access records required by law | Access records: three (3) months. Security and incident-response logs: up to one (1) year from the date of generation. However, records relating to incidents or disputes are retained until the relevant purpose has been achieved |
| Customer Support and Inquiries | Email address, inquiry content, attachments, response content, processing history, account identification information | Responding to inquiries, confirming errors, processing User requests, dispute response | Three (3) years after completion of inquiry processing |
| Settings and User Requests | Notification settings, history of consent to and withdrawal of personal information processing, contact suspension requests, relationship termination requests, account deletion requests, history of requests for access to, deletion of, or suspension of processing of personal information | Reflecting User intent, processing exercise of rights, processing contact suspension and relationship termination, fulfillment of legal obligations | Until membership withdrawal. However, request-processing history may be retained for up to three (3) years after completion of processing for dispute response and legal compliance |
2.2 Personal Information Processed with the User’s Separate Consent
| Category | Information Processed | Purpose of Processing | Retention and Use Period |
|---|---|---|---|
| Service Quality Improvement | Portions of de-identified Conversation content, AI responses, User feedback, Relationship Status, memory summaries, model inputs and outputs, error situations, usage patterns, quality evaluation results | Improvement of AI response quality, improvement of safety policies, prompt improvement, improvement of relationship experiences, product quality verification | Until withdrawal of consent or membership withdrawal. However, information that has already been statistically processed or de-identified may be retained in a form that does not identify an individual |
| Limited Conversation Review | Original Conversations or portions of Conversations within the scope consented to by the User, AI responses, Conversation times, Relationship Status, quality-review notes | Initial Service quality verification, reproduction of errors, inspection of AI response safety, improvement of relationship experiences | Until withdrawal of consent or membership withdrawal. Highly sensitive content is masked or excluded from review, and review records are destroyed after being retained for up to one (1) year |
| Marketing and Event Information | Email address, status of consent to receive notifications, event participation information | Service news, events, and benefit information | Until the earlier of withdrawal of consent or membership withdrawal |
3. Restrictions on Users Under 19 and Processing of Children’s Personal Information
QLover is a Service intended for Users who are nineteen (19) years of age or older. The Company does not permit registration or use by Users under nineteen (19) years of age. The Company may restrict Service registration or use by Users identified as being under nineteen (19) years of age through date-of-birth or age-verification information obtained through identity verification, and the information collected shall be destroyed without delay after the purposes of age verification and access restriction have been achieved. The Company does not knowingly collect the personal information of children under fourteen (14) years of age. If the Company confirms that a child under fourteen (14) years of age has used the Service or provided personal information, the Company shall delete such information without delay and restrict use of the Service.
4. Processing of Sensitive Information
The Company does not require Users to enter sensitive information such as ideology or beliefs, trade union or political party membership, political opinions, health information, sexual life, genetic information, or criminal history. However, because QLover is a free-form Conversation Service, Users may voluntarily enter sensitive information during Conversations. In such cases, the Company processes such information only within the following scope: 1. providing AI responses to content entered by the User; 2. protecting User safety and responding to crisis situations; 3. processing deletion, correction, or suspension-of-processing requests made by the User; 4. minimum review for limited reasons such as reports, failures, bugs, or legal requests; and 5. limited quality review only where the User has separately consented. However, highly sensitive Conversations are preferentially masked or excluded from review. Users may avoid entering sensitive information during Conversations and may request deletion of information already entered.
5. Special Notice Regarding Conversation Data and AI Processing
The core feature of QLover is a text-based relationship experience between Users and AI. For this purpose, the Company processes Users’ Messages, AI responses, Relationship Status, memories, contact rhythm, safety signals, and other information. When generating AI responses, the Company does not always transmit the full original Conversation to external AI providers. To the extent possible, the Company selects and processes only the minimum context necessary for response generation, such as recent Conversations, necessary summaries, relevant memories, and Relationship Status. The Company does not use original Conversation content for advertising targeting purposes. The Company also takes reasonable measures, including contracts, settings, and access controls, to prevent Users’ original Conversation content from being provided to external AI providers for training their own models. If original Conversations are accessed for Service quality improvement or operational review, the following principles apply: 1. Access to original Conversations is restricted by default. 2. Limited Conversation review for Service quality verification is conducted only where optional consent has been provided. 3. Even where unavoidable reasons exist, such as reports, risk signals, bugs, failures, or legal requests, access is limited to what is necessary. 4. The reason for access, the person accessing the information, the time of access, and the identifier of the relevant relationship or Conversation are recorded in audit logs. 5. Sensitive content is masked or excluded from review to the extent possible. 6. The original-Conversation review function for initial quality verification is removed or strongly restricted when its necessity decreases.
6. Provision of Personal Information to Third Parties
The Company processes Users’ personal information only within the scope of the purposes specified in this Policy and, as a general rule, does not provide Users’ personal information to third parties. However, personal information may be provided in accordance with applicable laws and regulations in the following circumstances: 1. where the User has consented in advance; 2. where necessary to provide a smooth Service experience; 3. where there is a special provision of law or provision is unavoidable in order to comply with a legal obligation; 4. where an investigative agency, court, supervisory authority, or other authority makes a request through lawful procedures; 5. where necessary to prevent an imminent risk to the life, physical safety, or property of the User or another person; or 6. where information is provided in a form that does not identify a specific individual for statistical compilation, research, Service improvement, or similar purposes. If the Company provides personal information to a third party, the Company shall inform the User in advance of the recipient, purpose of provision, information provided, retention and use period, the right to refuse consent, and any disadvantages resulting from refusal, and shall obtain consent. However, this shall not apply where applicable laws and regulations permit provision without consent.
7. Entrustment of Personal Information Processing
The Company may entrust part of its personal information processing operations to external professional service providers in order to provide the Service reliably. When entering into an entrustment agreement, the Company specifies in the agreement and manages and supervises matters including prohibition of processing personal information for purposes other than performance of the entrusted work, technical and administrative safeguards, restrictions on re-entrustment, access controls, incident notification, and destruction or return upon termination of the agreement so that the processor handles personal information securely.
| Processor | Entrusted Work | Information Processed |
|---|---|---|
| Amazon Web Services Korea LLC or Amazon Web Services, Inc. | Cloud infrastructure, server operation, log storage | Server deployment information, logs, device information, operational data |
| Apple Inc. | Sign in with Apple, provision of APNs push notifications | Apple account identifier, authentication token, email if provided, APNs device token, push delivery information |
| Anthropic PBC, MongoDB Inc., DeepSeek | AI text generation, input interpretation, embedding generation | Portions of Conversations necessary for response generation, Conversation summaries, portions of memory, Relationship Status, prompts, model-call metadata |
| Supabase Inc. | Database and file storage | Member information, Messages, memories, Relationship Status |
| ATON Inc. | Identity verification | Name, gender, date of birth, CI, DI |
| Vercel Inc. | Deployment and hosting of web landing pages | Minimum technical information including web access logs, browser information, and IP addresses |
| Google / Gmail | Receipt and processing of customer inquiries | Email address, inquiry content, response history |
The Company shall disclose changes to the content of entrusted work or processors through this Privacy Policy.
8. Overseas Transfer of Personal Information
For the provision of the Service, the Company may entrust some personal information processing operations to overseas businesses or transfer personal information to servers located overseas. Overseas transfers are made only to the extent necessary for provision of the Service, and the Company establishes contractual safeguards to ensure that processors handle personal information securely. The following is the planned list based on the MVP and will be updated to reflect the contracts, regions, retention periods, and contact information applicable at the actual time of launch.
| Recipient | Country of Transfer | Information Transferred | Purpose of Transfer | Timing and Method of Transfer | Retention and Use Period |
|---|---|---|---|---|---|
| Anthropic PBC, MongoDB Inc., DeepSeek | United States, China, etc. | Portions of Conversations necessary for AI response generation, Conversation summaries, portions of memory, Relationship Status, prompts, model-call metadata | AI response generation, input interpretation, embedding generation | Transmitted through an encrypted network during use of the Service | For the period specified in the processing agreement and settings or until the purpose of Service provision has been achieved |
| Apple Inc. | United States, etc. | Apple login authentication information, APNs device token, push delivery information | Login, authentication, provision of push notifications | Transmitted through an encrypted network during use of the Service | Until the purposes under Apple policies and Service provision have been achieved |
| Supabase Inc. | United States, etc. | Member information, Messages, memories, Relationship Status, photos | Database and file storage | Transmitted through an encrypted network during use of the Service | Until expiration of the retention period |
| Vercel Inc. | United States, etc. | Technical information such as web access logs, browser information, and IP addresses | Landing-page hosting and ensuring stability | Transmitted through an encrypted network when accessing the website | Until expiration of the contractual retention period or log retention period |
Users may refuse overseas transfers. However, if a User refuses overseas transfers essential to the provision of the Service, such as AI response generation, Apple login, push notifications, and error tracking, use of all or part of the Service may be restricted. Requests to refuse an overseas transfer or related inquiries may be made through the contact information of the Personal Information Protection Officer provided in this Policy.
9. Processing of Pseudonymized Information
Where necessary for Service quality analysis, safety improvement, and cost and performance analysis, the Company may pseudonymize personal information or convert it into statistical information for use. “Pseudonymized information” means information processed so that a specific individual cannot be identified without the use or combination of additional information. When processing pseudonymized information, the Company follows the principles below: 1. Pseudonymized information and additional information are stored separately. 2. The number of persons who may access pseudonymized information is minimized. 3. Pseudonymized information is not used for the purpose of re-identifying a specific individual. 4. If information capable of identifying a specific individual is generated in the course of processing pseudonymized information, processing is immediately suspended and such information is recovered and destroyed. 5. Where original Conversation content may be included, the Company obtains the User’s optional consent or masks sensitive information and processes only the minimum amount necessary.
| Purpose of Processing | Information Subject to Pseudonymization | Retention Period |
|---|---|---|
| AI response quality analysis, safety policy improvement, Service usability analysis | Conversation and Message events, AI response results, Relationship Status, memory summaries, error logs, feedback, and cost and quality indicators from which direct identifiers have been removed | Up to three (3) years from the date of pseudonymization or until the purpose has been achieved |
| Cost and Performance Analysis | Model name, token count, request time, whether response succeeded or failed, error type, estimated cost, usage patterns from which direct identifiers have been removed | Up to three (3) years from the date of generation or until the purpose has been achieved |
The Company does not provide pseudonymized information to third parties or combine it with other information to re-identify individuals. Changes to the processing of pseudonymized information shall be disclosed through this Privacy Policy.
10. Procedures and Methods for Destruction of Personal Information
The Company destroys personal information without delay when its retention period expires or the purpose of processing has been achieved. 10.1 Destruction Procedure 1. The Company identifies personal information for which a reason for destruction has arisen, such as expiration of the retention period, membership withdrawal, a deletion request, or withdrawal of consent. 2. Information subject to destruction is separated, excluding information that must be retained under applicable laws and regulations or for dispute response. 3. Electronic files are deleted in a manner that makes recovery or reproduction difficult. 4. Paper documents, if any, are shredded or incinerated. 5. Backup data is destroyed after a certain period according to the backup cycle, and access is restricted until destruction. 10.2 Method of Destruction Electronic personal information is permanently deleted or de-identified using methods that prevent recovery or reproduction. Information remaining in databases, file storage, log storage, or backup storage is sequentially deleted in accordance with the Company’s internal destruction policies. Upon membership withdrawal, Service data such as User Messages, memories, and Relationship Status is, as a general rule, destroyed or de-identified within thirty (30) days. However, information necessary for legal retention obligations, safety incidents, reports, dispute response, or prevention of fraudulent use is separately retained until the relevant purpose has been achieved and then destroyed.
11. Automatic Collection Devices and Processing of Behavioral Information
The Company may automatically collect certain information during use of the app and website for the provision and stability of the Service. 11.1 Information That May Be Automatically Collected in the App Information such as app version, OS version, device model, access time, IP address, request ID, error logs, push token, notification permission status, Service usage history, and Message sending, receipt, and reading status may be collected. This information is used for Service provision, sending notifications, incident response, maintaining security, preventing fraudulent use, and improving quality. 11.2 Information That May Be Automatically Collected on the Web Landing Page When a User accesses the web landing page, IP address, browser information, access time, device information, and server logs may be collected. Based on the MVP, QLover does not operate behavioral-information collection for personalized advertising purposes or third-party advertising tracking tools. If personalized advertising, retargeting, or marketing analytics tools are introduced in the future, the Company shall separately provide information regarding the information collected, purposes, retention periods, and methods of refusal and shall obtain consent where necessary. 11.3 Methods of Refusal Users may restrict cookies, app tracking, notification receipt, and similar functions through device or browser settings. iOS notification refusal: iPhone Settings > Notifications > QLover > Turn off Allow Notifications iOS app tracking restriction: iPhone Settings > Privacy & Security > Tracking > Turn off Allow Apps to Request to Track Cookie restriction: May be restricted through the privacy or cookie settings of the browser being used However, if the collection of essential cookies or essential technical information is restricted, certain functions such as login, session maintenance, security, and notifications may not operate properly.
12. Notice Regarding Automated Processing and AI Decision-Making
Because QLover is an AI-based Service, some processing is performed through automated methods. For example, AI may analyze a User’s Messages and Relationship Status to determine reply content, reply timing, whether proactive contact is possible, Relationship Status, memory candidates, safety signals, and other matters. Such automated processing is intended to provide QLover’s AI relationship experience and is not used for the purpose of making decisions that have significant effects on Users’ legal rights, obligations, credit, employment, insurance, financial transactions, or similar matters. Users may request the following measures in relation to automated processing: 1. request to stop contact; 2. request to end a relationship; 3. request deletion of specific memories or Conversations; 4. request suspension of personal information processing; 5. withdrawal of optional consent; and 6. request for an explanation regarding AI processing methods or personal information processing. After confirming the User’s request, the Company shall process it without delay in accordance with applicable laws and regulations.
13. Rights of Users and Legal Representatives and Methods of Exercise
Users may exercise the following rights against the Company at any time: 1. request access to personal information; 2. request correction of personal information; 3. request deletion of personal information; 4. request suspension of processing of personal information; 5. withdraw consent to personal information processing; 6. request transfer of personal information or provision of a copy; 7. request explanations and measures regarding automated processing; and 8. request account withdrawal and deletion of relationship data. Rights may be exercised through the following methods: In-app path: QLover app > Settings Email: ama@mesotelos.com When the Company receives a request from a User to exercise rights, it shall verify the User’s identity and process the request without delay. However, all or part of a request may be restricted where another law requires retention of the relevant personal information, where there is a risk of infringing the rights or freedoms of another person, or where performance of the agreement to provide the Service would become difficult. In such cases, the Company shall inform the User of the reason for the restriction.
14. Measures to Ensure the Security of Personal Information
The Company implements the following technical, administrative, and physical measures to prevent Users’ personal information from being lost, stolen, leaked, forged, altered, or damaged: 1. Personal information access privileges are granted only to personnel who require them for their work. 2. Operator access to original Conversations is restricted, and when access occurs, the reason, person accessing, date and time, and target information are recorded in audit logs. 3. Original Message text and sensitive personal information are not recorded in ordinary error logs. 4. Secure communication methods, including encryption during transmission, are used. 5. Authentication information such as passwords or authentication tokens is securely stored and managed. 6. Authentication tokens in the iOS app are stored using secure storage such as Keychain. 7. Server access privileges, database access privileges, and operational dashboard access privileges are separately managed. 8. Access records for personal information processing systems are retained and abnormal access is monitored. 9. Sensitive data is masked, separately stored, and subject to access restrictions to the extent possible. 10. Obligations concerning personal information protection, restrictions on re-entrustment, incident notification, and destruction or return are reflected in agreements with external processors. 11. Procedures for responding to failures and data breaches are established, and Users and relevant authorities are notified in accordance with applicable laws and regulations where necessary. 12. Personal information protection training is provided to personnel who handle personal information.
15. Personal Information Protection Officer and Contact Information
The Company designates a Personal Information Protection Officer to oversee personal information processing operations and to handle User complaints and provide remedies for damages relating to personal information processing. Personal Information Protection Officer Name: Hyungoo Jeon Position: Representative Email: ama@mesotelos.com Telephone: 010-8273-9248 Users may contact the above contact point regarding any personal information protection inquiries, complaints, remedies for damages, or requests for access, correction, deletion, or suspension of processing arising from the use of QLover. The Company shall respond to and process User inquiries without delay.
16. Remedies for Infringement of Rights
Users may contact the following institutions for consultation or dispute resolution regarding infringements of personal information: 1. Personal Information Infringement Report Center: 118 without an area code 2. Personal Information Dispute Mediation Committee: 1833-6972 3. Relevant cyber investigation department of the Supreme Prosecutors’ Office 4. Relevant cybercrime reporting department of the National Police Agency
17. Changes to the Privacy Policy
The Company may amend this Privacy Policy if applicable laws and regulations, Service content, personal information processing methods, processors, or details of overseas transfers change. If an amendment materially affects User rights, the Company shall provide notice through appropriate means, such as an in-app notice, website notice, email, or push notification, beginning at least thirty (30) days before the effective date. Other changes shall be announced beginning at least seven (7) days before the effective date. Previous versions of the Privacy Policy shall be retained so that they may be viewed within the Service or on the website.
18. Supplementary Provisions
This Privacy Policy shall apply from September 11, 2026.