Privacy Policy

Effective Date: August 13, 2026

Kim Hyunsuk, operating under the brand name Hypersoso (“Operator,” “we,” “us,” or “our”), operates kkirok (the “Service”), a service that allows users to record food photos and, where they choose, share them with members of their Groups.

We respect your privacy and seek to process personal information in accordance with applicable privacy and data protection laws, including the laws of the Republic of Korea and, where applicable, the laws of the countries or regions in which our Users are located.

This Privacy Policy explains what personal information we process, why and how we process it, where it may be stored or transferred, how long it may be retained, and what rights and choices may be available to you.


1. Scope of This Privacy Policy

This Privacy Policy applies to the kkirok mobile application, related websites, and other services directly provided by us in connection with kkirok.

The Service may be distributed internationally through platforms such as Google Play.

Where privacy, consumer protection, child protection, or other mandatory laws of a country or region apply to a User, we will seek to comply with those laws to the extent they apply to the Service and our processing activities.


2. Personal Information We Process

The personal information processed through kkirok may vary depending on:

2.1 Account and Authentication Information

When you create an account or sign in using your Google account, we may process information through Google OAuth 2.0, Firebase Authentication, or other authentication mechanisms supported by the Service.

This may include:

We do not directly collect or store the password for your Google account.

Your Google account is independently managed by Google. Deleting your kkirok account does not delete your Google account.


2.2 Age and Age-Assurance Information

We may process age-related information where reasonably necessary to provide age-appropriate features, advertising, or privacy protections and to comply with applicable law.

This may include:

Where reasonably practicable, we seek to retain only the minimum age-related information required for the relevant purpose rather than retaining an exact date of birth for longer than necessary.

Information collected specifically for age assurance will not ordinarily be used for unrelated advertising personalization.


2.3 Food Photos and Food Records

When you create or upload a Food Photo, we may process:

A Food Photo may unintentionally contain personal information such as:

kkirok does not use Food Photos for the purpose of facial recognition, biometric identification, or identity verification.


2.4 Group Information

When you create or join a Group, we may process:


2.5 Emoji Reaction Information

When you react to a Food Photo with an emoji, we may process:


2.6 Reporting and Safety Information

When you report a Food Photo, other Content, or another matter supported by the Service, we may process:

We use reporting information for moderation, User safety, prevention of abuse, and legal compliance.

We do not voluntarily disclose a reporting User's identity to the reported User unless disclosure is reasonably necessary to comply with applicable law, legal process, or dispute-resolution obligations.


2.7 Support and Inquiry Information

If you contact us, we may process:


2.8 Information Automatically Processed

Depending on the SDKs and features active on your device, the following information may be automatically generated or processed through services such as Firebase, Google Analytics for Firebase, Firebase Crashlytics, and the Google Mobile Ads SDK:

The exact information processed may vary depending on SDK version, device configuration, operating system, age, region, consent status, and your privacy or advertising settings.


3. Guest Use and Local RoomDB Data

Some kkirok features may be used without creating an account or signing in.

Food Photos and related Food Records created while signed out are generally stored locally on your device using RoomDB or application-specific storage.

Unless you use an account-based upload or transfer feature, this locally stored Food Record information is not stored on our servers as account data.

Food Photos stored solely in Guest mode are not shared through server-based Group features.

However, third-party SDKs included in the app, including Firebase Crashlytics, Google Analytics for Firebase, or the Google Mobile Ads SDK, may still process limited app or device information for analytics, diagnostics, security, or advertising purposes where permitted.

For minors, Users whose age has not been established, or Users subject to specific legal protections, such processing may be restricted.

Local RoomDB information may be deleted or lost if you:

We cannot remotely access, restore, or delete data that exists only in RoomDB or other local storage on your device.


4. Device Permissions and Photo Access

kkirok may request access to device features such as:

where necessary to allow you to capture or select Food Photos.

Such permissions are used for the functionality for which they are requested.

The Service is not intended to automatically upload photos from your device that you have not selected for upload or sharing.

You may manage application permissions through Android system settings.

If you deny a permission, features that depend on that permission may not function.


5. How and Why We Process Personal Information

We process personal information only where reasonably necessary for legitimate Service purposes and where an appropriate legal basis exists under applicable law.

5.1 Providing the Service

We process information to:

Where the GDPR, UK GDPR, or similar laws apply, some of this processing may be necessary to enter into or perform our contract with you.


5.2 Safety, Security, and Abuse Prevention

We may process information to:

Where applicable law requires a legal basis, this processing may rely on our legitimate interests in protecting Users, securing the Service, and preventing misuse, or on applicable legal obligations.


5.3 Crash and Error Analysis

We may use Firebase Crashlytics or similar tools to identify crashes, technical errors, and reliability issues.

Where applicable law requires consent for such processing, we will seek consent before enabling processing that requires it.


5.4 Analytics and Service Improvement

We may use Google Analytics for Firebase or similar tools to understand:

Where applicable law requires prior consent for analytics, analytics processing will be subject to that consent.


5.5 Advertising

We may use Google AdMob to:

Where consent is legally required for personalized advertising, tracking, or related processing, such processing will occur only after obtaining the required consent.


5.6 Compliance with Legal Obligations

We may process information where reasonably necessary to:


6. Storage and Sharing of Food Photos

Food Photos are generally treated as your personal meal records unless you expressly choose to share them with a Group.

A Food Photo that you do not share will not be displayed to other Group members through Group functionality.

If you choose to share a Food Photo with a Group, the photo and information reasonably necessary to provide the sharing feature may be visible to members of that Group.

Group members may also be able to leave Emoji Reactions where the Service supports that functionality.

kkirok is not designed to make Group-shared Food Photos publicly available to the general internet.

Before sharing a photo, you should check whether it contains information such as:

If you stop sharing or delete a Food Photo, we will stop or restrict further display of the photo through the Service according to the applicable functionality.

We cannot guarantee deletion of copies that another User or third party has independently and lawfully saved or shared outside the Service.


7. Potentially Sensitive Information in Photos

We do not require Users to include sensitive personal information in Food Photos.

kkirok is not intended to infer or analyze:

from Food Photos.

However, Users may unintentionally upload images containing such information.

If a Food Photo containing sensitive information is shared with a Group, other members of that Group may be able to see that information.

Users should avoid sharing photos containing sensitive or private information that they do not wish other Group members to see.

Where applicable law requires separate consent or another specific legal basis for processing sensitive personal information, we may restrict the relevant processing or take other measures necessary to comply with applicable law.


8. Disclosures and Sharing of Personal Information

We do not operate kkirok for the purpose of selling Users' personal information for monetary consideration.

Personal information may be disclosed in the circumstances described below.

8.1 User-Directed Group Sharing

If you choose to share Content with a Group, Group members may receive or view information such as:


8.2 With Your Direction or Consent

We may disclose information where you expressly request or lawfully consent to the disclosure.


8.3 Legal Requirements and Protection of Rights

We may disclose personal information where reasonably necessary and legally permitted to:


9. Service Providers and Third-Party Services

We use third-party providers to operate and maintain kkirok.

These providers may process personal information only to the extent relevant to the services they provide.

9.1 Google LLC and Related Google Services

We may use the following Google services.

Firebase Authentication / Google Sign-In

Used for:

Google Analytics for Firebase

Used for:

Firebase Crashlytics

Used for:

Google AdMob / Google Mobile Ads SDK

Used for:


9.2 Supabase

We use Supabase for database and backend functionality associated with account-based Service features.

Information stored or processed through Supabase may include:

The primary kkirok PostgreSQL database is configured to use the Seoul, Republic of Korea region.


9.3 Cloudflare

We use Cloudflare R2 Object Storage to store and provide Food Photos uploaded by signed-in Users.

Information processed through Cloudflare R2 may include:

kkirok may use an Asia-Pacific (“APAC”) location preference or equivalent data-placement configuration for Cloudflare R2.

Such a configuration is intended to prefer processing or storage in the Asia-Pacific region and should not be interpreted as a guarantee that data will be stored exclusively in one specific country.


10. International Transfers of Personal Information

kkirok relies on global infrastructure.

As a result, some personal information may be transferred to, accessed from, or processed in countries other than:

We take measures required by applicable law for international transfers of personal information.

10.1 Google

Recipient

Google LLC and relevant affiliates or service providers.

Information that may be transferred

Purposes

Countries or regions

The United States and other countries or regions in which Google or its service providers maintain relevant infrastructure.

Timing and method

Information may be transferred through encrypted network communications when Google functionality or related SDKs are used.

Retention

Information may be processed according to the applicable Google service, our configuration, and Google's relevant retention practices.


10.2 Cloudflare

Recipient

Cloudflare, Inc. and relevant service providers.

Information that may be transferred

Purposes

Countries or regions

Asia-Pacific regions and other locations where processing is reasonably necessary for Cloudflare to provide its services.

Timing and method

Information may be transferred through encrypted network communications when photos are uploaded, stored, or requested.

Retention

Generally until the Food Photo is deleted, the associated account is deleted, or the processing purpose otherwise ends, subject to limited backup, security, and deletion-processing periods.


10.3 Supabase

Our primary database is located in the Seoul region.

However, information may potentially be accessed or processed from other locations in connection with Supabase's global service operations, security, administration, technical support, or relevant subprocessors.

Where such processing constitutes an international transfer under applicable law, we will seek to apply appropriate transfer safeguards.


For Users in the Republic of Korea, international transfers will be handled using a lawful basis permitted under applicable Korean privacy law, including any notice or consent required by law.

For Users in the European Economic Area, transfers to the Republic of Korea may, where applicable, rely on an applicable adequacy decision or another lawful transfer mechanism.

For Users in the United Kingdom, transfers to the Republic of Korea may rely on applicable UK adequacy regulations or another lawful transfer mechanism.

Where information is subsequently transferred from Korea to another country, we will seek to apply contractual, technical, or organizational safeguards required by applicable law.


11. Analytics and Diagnostics

Google Analytics for Firebase

We may use Google Analytics for Firebase to understand how the Service is used and to improve kkirok.

Information processed may include:

Where legally required, analytics processing will occur only after the relevant consent is obtained.

We seek to configure analytics retention in accordance with data-minimization principles and the operational needs of the Service.


Firebase Crashlytics

We use Firebase Crashlytics to diagnose crashes and improve stability.

Crashlytics may process information such as:

Information processed by Crashlytics may be retained in accordance with the applicable Google service settings and retention practices.


12. Advertising and Age-Appropriate Advertising

We may use Google AdMob to display advertisements.

Advertising-related processing may include:

We restrict advertising-related processing based on:

Users Under 18

As a general Service policy, we do not provide personalized advertising or remarketing to Users identified as under 18 years of age.

Where child or teen protection laws or platform policies apply, we may use age-appropriate settings provided by the Google Mobile Ads SDK or otherwise restrict advertising processing.

If applicable law or platform rules prohibit the use or transmission of advertising identifiers for children or Users whose age cannot be established, we will seek to configure the Service accordingly.


Adult Users

Personalized advertising may be available to adult Users only where permitted by applicable law and consistent with applicable consent and privacy settings.

If a User does not permit personalized advertising, the Service may display:


13. Profiling and Automated Decision-Making

kkirok itself does not currently use solely automated processing to make decisions that are intended to produce legal effects or similarly significant effects concerning Users.

Advertising providers may perform advertising-related profiling for adult Users where permitted by law and the User's choices.

As a general Service policy, we do not provide personalized advertising to Users identified as under 18 years of age.

We do not use Food Photos for the purpose of inferring sensitive characteristics for advertising, including:


14. Retention of Personal Information

We retain personal information only for as long as reasonably necessary for the relevant purpose or as required or permitted by applicable law.

Account and Profile Information

Retained until Account Deletion, subject to any lawful retention requirements.


Food Photos and Food Records

Generally retained until:


Group Information

Retained while necessary to provide Group functionality.

Information that is no longer necessary following Group deletion, leaving a Group, removal from a Group, or Account Deletion will be scheduled for deletion where appropriate.


Emoji Reactions

Retained until:


Reporting and Safety Information

Retained for as long as reasonably necessary to:

Such information may be retained for a limited additional period where reasonably necessary for security, fraud prevention, dispute handling, or legal compliance.


Support Information

Generally retained until the inquiry has been resolved and the information is no longer reasonably necessary.

Information may be retained longer where necessary for dispute resolution or legal compliance.


Guest Food Records

Food Records stored solely in RoomDB or other local storage are not subject to a server-side retention period controlled by us.


Analytics and Diagnostic Information

Information processed through Google Analytics for Firebase, Firebase Crashlytics, or similar services may be retained according to our configured retention settings and the applicable provider's retention practices.

We seek to avoid retaining analytics or diagnostic personal information longer than reasonably necessary.


Advertising Information

Advertising information may be processed according to:


15. Deletion of Personal Information and Accounts

When personal information is no longer required for its processing purpose or the applicable retention period has expired, we will delete or otherwise dispose of it in accordance with applicable law.

Account Deletion

You may request deletion of your kkirok account through:

Following Account Deletion, we will initiate deletion of information no longer required, which may include:

Deletion may occur sequentially across systems including:

Some deleted information may remain temporarily within technical backup or recovery systems.

Such backup information will not ordinarily be used for active Service purposes while awaiting deletion.

Electronic information will be deleted using methods reasonably designed to make recovery or reconstruction impracticable, subject to technical and legal requirements.

Data stored solely in RoomDB or other local device storage cannot be remotely deleted by us.

You may remove such information using:


16. Children and Teen Users

Minimum Age

The general minimum age for kkirok is 13 years old.

Individuals under 13 may not use the Service.

However, if the law of a User's country or region requires:

that local requirement applies.


Republic of Korea

Where consent is legally required to process the personal information of a User under the applicable Korean age threshold, we will seek to obtain consent from the User's legal representative and verify that the consent was provided by the appropriate representative as required by applicable law.

Where the Service does not provide the technical process necessary to satisfy such a requirement, access to affected functionality may be restricted until the legal requirement can be met.


European Economic Area

The age at which a child may independently consent to certain online personal information processing may vary by EEA member state.

Where:

we may require valid parental or guardian authorization or decline to provide the processing that requires such consent.


United Kingdom

For Users in the United Kingdom, we seek to comply with applicable UK GDPR requirements and other applicable standards relating to children and online services.

Where appropriate, we may apply age-appropriate:


Advertising and Social Features for Minors

As a general policy, Users identified as under 18 are not provided personalized advertising.

Where required by applicable law or platform policy, we may introduce additional age assurance, parental involvement, or other safeguards before enabling certain social, Group-sharing, or advertising functionality.

If we learn that we have processed personal information belonging to a User under 13 without appropriate legal authorization, we may restrict access and take reasonable steps to delete the relevant information.

Questions relating to children's or teenagers' privacy may be submitted to:

cs@hypersoso.app


17. Your Privacy Rights

Depending on your jurisdiction, you may have rights concerning your personal information.

Requests may be submitted through available in-app functionality or to:

cs@hypersoso.app

We may request information reasonably necessary to verify your identity or a representative's authority before acting on certain requests.


17.1 Users in the Republic of Korea

Subject to applicable Korean law, Users may have rights including:

A legal representative or authorized agent may exercise rights where permitted by law.


17.2 EEA and UK Users

Where the GDPR or UK GDPR applies, you may have rights including:

Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.


17.3 United States Users

Where a U.S. state privacy law applies to us or to a particular processing activity, you may have rights provided by that law, which may include:

We do not operate kkirok for the purpose of selling personal information for monetary consideration.

However, some U.S. privacy laws may define certain transfers of identifiers or activity information for personalized advertising as “sharing,” “targeted advertising,” or a similar regulated activity.

Where such laws apply, we will provide the choices required by applicable law.

As a general policy, Users identified as under 18 are not provided personalized advertising.


18. Privacy Choices and Withdrawal of Consent

Where supported by the Service and applicable law, you may be able to manage choices relating to:

Declining optional processing will not ordinarily prevent you from using unrelated core Service functionality.

However, if processing is technically or legally necessary to provide a specific feature, refusing that processing may prevent use of that feature.


19. Security Measures

We use technical and organizational measures appropriate to the nature and scale of the Service to help protect personal information against:

Measures may include:

We periodically review our security measures and may improve them as the Service evolves.

However, no method of electronic transmission or storage can be guaranteed to be completely secure.


20. Personal Data Breaches and Security Incidents

If we identify a breach, unauthorized access, or other security incident involving personal information, we will take measures required by applicable law.

Such measures may include:

If you believe your account or personal information has been compromised, contact:

cs@hypersoso.app


21. Privacy Contact and Person Responsible for Privacy

The following contact is responsible for privacy-related inquiries and requests.

Data Controller / Privacy Contact

Personal Information Access and Rights Requests

Requests concerning access, correction, deletion, restriction, withdrawal of consent, Account Deletion, or other privacy rights may be submitted through the contact information above.


22. EEA and UK Representatives

The Operator is established in the Republic of Korea.

Depending on the manner in which kkirok is offered in the European Economic Area or United Kingdom, the scale and nature of processing, and applicable law, we may be required to appoint a representative in the EEA or United Kingdom.

If such a legal obligation applies, we will appoint the required representative and publish the representative's name and contact information in this Privacy Policy or another appropriate privacy notice.


23. Complaints and Regulatory Authorities

You may contact us regarding any privacy concern at:

cs@hypersoso.app

Users in the Republic of Korea may also seek assistance from competent privacy authorities or dispute-resolution bodies, including the relevant Korean personal information protection authorities.

Users outside the Republic of Korea may have the right to submit a complaint to a competent data protection or privacy regulator in their country or region.

Nothing in this Privacy Policy limits a statutory right to contact a competent supervisory authority.


24. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes involving:

When we update this Privacy Policy, we will publish the updated version and its effective date through the Service, our privacy-policy webpage, or another reasonably accessible method.

If a change materially affects Users' privacy rights or obligations, we will provide additional notice where required by applicable law.

Where previous versions exist, we may make them available so Users can review the history of material changes.


Supplementary Provision

This Privacy Policy is effective as of August 13, 2026.

Previous versions