say one thing
Privacy Policy
Effective date: August 20, 2026
say one thing Team (the “Operator”) complies with applicable privacy laws and publishes this Privacy Policy to explain how we collect, use, retain, and protect personal information in the say one thing service.
1. Purposes, Information Collected, and Retention
We process personal information only to the extent necessary for the purposes below.
Account Registration and Sign-In
- Purpose:
- User identification, Google or Apple sign-in, account administration, and prevention of unauthorized use
- Information:
- Email address, sign-in provider, provider user identifier, internal user ID, and generated nickname and icon
- Retention:
- Until the account is deleted
Guest Use
- Purpose:
- Temporary account creation, service delivery, and user differentiation
- Information:
- Internal user ID, generated nickname and icon, and guest status
- Retention:
- Until the account or guest account is deleted
Voice Conversation Service
- Purpose:
- Matching users, recording, sending, and playing voice messages, and managing conversation status
- Information:
- Voice files, recording duration, sender and recipient, sent time, room information, and message status
- Retention:
- Until the conversation room or account is deleted
Notifications and Service Operations
- Purpose:
- Push notifications, maintaining sign-in status, security, troubleshooting, and service improvement
- Information:
- Push token, device platform, IP address, user agent, encrypted session identifier, access and activity timestamps, and service usage records
- Retention:
- Push tokens until account deletion; session information until sign-out or account deletion; access, security, and error logs for up to 90 days from creation
Information that must be retained by law is stored separately for the legally required period and then destroyed.
2. Collection Methods and Legal Bases
- We receive information authorized by the user during Google or Apple sign-in.
- We collect information directly when the user creates an account, records or sends voice messages, or configures notifications.
- IP address, user agent, session data, and usage records may be generated automatically while the service is used.
- Information necessary to provide the service is processed to enter into and perform our agreement with the user. Where consent is required, we process information based on the user's consent.
3. Sharing Personal Information
We do not ordinarily disclose personal information to third parties. To provide voice conversations, a user's nickname, icon, voice messages, and sent times are shared with the matched conversation partner. This information is retained until the conversation room or relevant account is deleted. Exceptions may apply where disclosure is required by law or separately authorized by the user.
4. International Processing of Personal Information
We use the following overseas service providers for sign-in and push notifications. These transfers are necessary to provide the contracted service and are made under Article 28-8(1)(3) of the Korean Personal Information Protection Act.
Google LLC
- Contact:
- Google Privacy Policy
- Destination:
- The United States and other countries where Google operates data processing facilities
- Information transferred:
- Google sign-in token, user identifier, email address, Android push token, and notification content
- Purpose:
- Google sign-in authentication and notifications through Firebase Cloud Messaging
- Timing and method:
- Transferred over an encrypted network when signing in or sending a notification
- Retention:
- Until the processing purpose is fulfilled or for the period specified by Google's policies
Apple Inc.
- Contact:
- Contact Apple about Privacy
- Destination:
- The United States and other countries where Apple operates data processing facilities
- Information transferred:
- Apple sign-in token, user identifier, email address, iOS push token, and notification content
- Purpose:
- Apple sign-in authentication and notifications through Apple Push Notification service
- Timing and method:
- Transferred over an encrypted network when signing in or sending a notification
- Retention:
- Until the processing purpose is fulfilled or for the period specified by Apple's policies
Users who do not want an international transfer may stop using Google or Apple sign-in or disable push notifications. Refusing a sign-in transfer prevents use of that sign-in method, and refusing the push-notification transfer prevents receipt of notifications.
5. Destruction of Personal Information
We destroy personal information without undue delay when its retention period expires or its processing purpose is fulfilled. Electronic files are deleted using methods that prevent recovery. Any paper records are shredded or incinerated. Information required by law is separated from other information and destroyed when the applicable retention period ends.
6. User and Legal Representative Rights
Users may request access to, correction or deletion of, suspension of processing of, or withdrawal of consent for their personal information. Users can delete an account in the app, use our Account and Data Deletion page, or contact us at the address below. We will verify the requester and respond within the period required by law. If we process personal information of a child under 14, we obtain consent from the child's legal representative, who may exercise the same rights.
7. Cookies and Similar Technologies
We use encrypted session cookies to keep users signed in. These cookies are not used for personalized advertising or user tracking. Users may reject or delete cookies through browser settings, but features that require sign-in may then be unavailable.
8. Security Measures
- Encryption in transit using HTTPS and encryption of session cookies
- Least-privilege access and access controls for personal information
- Secure storage of passwords and other authentication information
- Security reviews, access-log management, and filtering of personal information from request logs
9. Privacy Contact and Remedies
Privacy contact: say one thing Team
Email: privacy@vtalks.net
For advice or reports concerning a privacy violation, users may contact the following Korean authorities.
- KISA Privacy Infringement Report Center: 118 (without area code)
- Personal Information Dispute Mediation Committee: 1833-6972
- Supreme Prosecutors' Office: 1301 (without area code)
- Korean National Police Cyber Crime Reporting System: 182 (without area code)
10. Changes to This Policy
If this Policy changes, we will provide notice in the service or on this page before the changes take effect.
Published and effective: August 20, 2026