This is a reference translation of the Korean-language original, prepared to comply with South Korea's Personal Information Protection Act (PIPA). If this translation and the Korean original conflict, the Korean original governs.
Mozzamile ("Company") treats your personal information as important and complies with the Personal Information Protection Act and other applicable laws of the Republic of Korea. This Privacy Policy is a unified, company-wide policy that applies across all services operated by the Company (MozzaRun, MozzaDok, FamLoop, and others; "Services") and the Company's shared authentication system ("Platform Account"). Each Service also maintains its own service-specific Terms of Service; any data processing specific to a single Service is described in the per-service appendix in Article 2.
This Policy is a disclosure/notice document about personal data processing, not a document through which the Company obtains consent. Consent for the collection and use of personal information at Platform Account signup is obtained through the unified Account Terms of Service (via the mandatory consent checkbox on the signup screen); the legal basis, purpose, items, retention period, and the right to refuse consent are set out there. This Policy exists to disclose the Company's personal data practices in full, including that same information, for transparency.
Article 1 (Purposes of Processing)
The Company processes personal information for the following purposes:
- Platform Account creation, identity verification, sign-in, and fraud prevention
- Providing the Services and each Service's core functionality (see appendix)
- Handling inquiries and complaints
- Stable operation, error response, and improvement of the Services
- Compliance with obligations under applicable law
Article 2 (Items Collected and Retention Period)
2-1. Platform Account (shared sign-in across all Services)
The Company handles sign-in for multiple Services through one shared Platform Account. The items below vary by signup route (social login or email signup); the legal basis and detailed items are set out in the unified Account Terms of Service.
| Category | Items collected | Retention and use period |
|---|---|---|
| Common | Social login provider and the provider's user identifier (Apple, Google), or email address; for email signup, an encrypted (hashed) password | Until account deletion |
| Optional | Name or username (collected only for certain signup routes) | Until account deletion |
| Authentication / security | Encrypted authentication tokens, authorization codes, authentication state records, signup/password-reset attempt records (email, expiry time), device credential (custodial accounts only) | Until the issuance purpose is fulfilled, or as required by applicable law |
| Consent record | Account Terms of Service consent history (time of consent, document URL, document version, the Service through which signup occurred) | Retained after account deletion for the period required by applicable law, to respond to disputes |
2-2. Per-service appendix
The table below describes, on a per-service basis, the personal information each Service collects on its own, separate from the Platform Account data above. The Company updates this appendix whenever a Service's purposes or items change.
| Service | Items collected | Purpose | Retention and use period |
|---|---|---|---|
| MozzaRun | Location data (GPS route during a running session), Apple HealthKit workout data (heart rate, calories), device information, app usage logs, crash/performance data | Recording route, distance and pace; ensuring service stability and pattern-based improvement (HealthKit data is not used for advertising or marketing) | MozzaRun can be used without signing in, so it is not linked to a Platform Account — location and HealthKit data are stored only on the user's own device (iCloud) after a session ends and are not accessed by the Company. Device information, app usage logs, and crash/performance data are collected via the outsourced processing described in Article 4 (Firebase) and retained until the outsourcing purpose is fulfilled or as required by applicable law, then destroyed |
| MozzaDok | No personal information is collected — subscription renewal dates and similar settings are stored only on the user's own device (iCloud) and are not accessed by the Company | N/A | N/A |
| FamLoop | Name/nickname, avatar, date of birth (optional), family member relationships and invite code, emotion logs/tags/sharing settings, parent-child messages, AI translation results, device information, usage logs, push token | Family emotion logging and sharing, AI translation, payment/subscription processing, notifications, service improvement, and detecting crisis indicators and reporting to the relevant authorities to protect user safety (see Article 3) | Until account deletion, except: contract/withdrawal records (5 years), payment records (5 years), complaint-handling records (3 years), and advertising display/receipt history (6 months), each retained separately as required by applicable law |
* Where FamLoop processes the personal information of a child under 14 (e.g. emotion logs), the child's account is linked only through an invite code issued by a legal guardian; the child's emotion logs and messages are not disclosed to or sold to third parties, and are not used to train any AI model. The detailed scope of processing and the guardian's access/deletion rights are set out in FamLoop's own Terms of Service and privacy appendix.
* Where FamLoop detects an urgent risk indicator in a family member's emotion logs or messages — such as an indication of self-harm, suicide, or child abuse — the Company may provide the minimum information necessary to the relevant authorities (e.g. law enforcement, a child protection agency) to fulfill its statutory reporting obligations and to protect user safety, in accordance with applicable law (e.g. the Act on the Prevention of Suicide, the Act on Special Cases Concerning the Punishment of Child Abuse Crimes). This constitutes an exceptional disclosure under Article 3 (Disclosure to Third Parties).
2-3. Visitors to this website (mozzamile.com)
The following information may be generated automatically in the ordinary course of operating this website, without any sign-up or analytics tooling.
| Items collected | Purpose | Retention and use period |
|---|---|---|
| Access logs (IP address, browser/device information, access time) | Stable service operation, response to fraudulent use | Up to 3 months from collection |
| Language-preference cookie (NEXT_LOCALE) | Functional cookie to remember the selected language (Korean/English/Japanese) | Up to 1 year after being set, or until deleted from the browser |
| Information the user voluntarily includes in an email (name, email address, inquiry content, etc.) | Responding to inquiries | 1 year after the inquiry is resolved |
Inquiries are sent directly from the user's own email client to devteam@mozzamile.com; the website itself does not store inquiry content on any server.
Article 3 (Disclosure to Third Parties)
The Company processes personal information only within the purposes stated in Article 1, and does not disclose it to third parties without the user's prior consent, except:
- Where the user has separately given prior consent
- Where required by law, or where requested by an investigative agency for investigative purposes following the procedures set out in applicable law
- Where, during use of FamLoop, an urgent risk indicator (e.g. self-harm, suicide, or child abuse) is detected and disclosure is necessary to fulfill a statutory reporting obligation or to protect user safety (see the 2-2 per-service appendix in Article 2 for details)
Article 4 (Outsourcing of Personal Data Processing)
The Company outsources the following personal-data-processing work to outside vendors in order to operate the Services. In each case, in accordance with Article 26 of the PIPA, it specifies in the outsourcing agreement matters such as a prohibition on processing personal information for any purpose other than the outsourced work, technical and managerial safeguards, restrictions on re-outsourcing, the Company's management and supervision of the processor, and liability for damages, and supervises the processor's handling of personal information.
| Processor | Outsourced work | Related Service(s) |
|---|---|---|
| Google LLC | App/service usage analytics (Firebase Analytics), push notification delivery (Firebase Cloud Messaging), error/performance monitoring (Crashlytics) | MozzaRun, FamLoop |
| Google LLC (Gemini) | AI-based emotion analysis, translation, and summarization | FamLoop |
| Apple Inc. / Google LLC | In-app (subscription) payment processing | FamLoop |
The items transferred to the processors above, whether that transfer crosses a national border, and the related safeguards are described in detail in Article 5 (Overseas Transfer of Personal Information). The Company's own service infrastructure (servers), as of 2026-09-18, continues to run directly on self-hosted (on-premises) servers; the outsourcing above is limited to specific functions such as authentication integration, usage analytics, and AI processing. If the outsourcing arrangements change in the future, this Article will be updated without delay to name the fact of outsourcing, the processor, and the outsourced work.
Article 5 (Overseas Transfer of Personal Information)
The Company transfers personal information overseas as set out below in order to provide the Services. Such transfers are limited to what is necessary to perform the Platform Account creation contract or to provide the Services, within the scope permitted by applicable law, and the Company takes measures — including through agreements with the recipients — to ensure that personal information transferred overseas is managed securely.
| Recipient | Recipient country | Items transferred | Timing and method of transfer | Purpose of use and retention period | Safeguards |
|---|---|---|---|---|---|
| Apple Inc. / Google LLC (social login providers) | United States | Provider-side user identifier, authentication token | TLS-encrypted transmission on each login/authentication | Identity verification and sign-in (necessary to perform the account-creation contract) — until Platform Account deletion or social login disconnection | Each provider's own privacy policy and account security practices |
| Google LLC (Firebase Analytics, Cloud Messaging, Crashlytics) | United States | Device information, app usage logs, crash/performance data, push token (MozzaRun, FamLoop) | Real-time TLS-encrypted transmission during service use | Stable service operation, error response, usage-pattern analysis/improvement, notification delivery — until the outsourcing purpose is fulfilled or as required by applicable law | Standard Contractual Clauses (SCCs) and Google Cloud/Firebase data processing terms |
| Google LLC (Gemini) | United States | Emotion logs and message text (limited to AI analysis/translation/summarization, FamLoop) | TLS-encrypted transmission on each AI-processing request | Providing AI-based emotion analysis, translation, and summarization — retained until the outsourcing purpose is fulfilled or as required by applicable law | Standard Contractual Clauses (SCCs) and Google Cloud data processing terms |
Under Article 28-8 of the PIPA, users have the right to refuse the overseas transfers above; to exercise that right, contact the Privacy Officer designated in Article 9. Note that the items related to the social login providers (Apple, Google) are necessary for account creation and authentication, so refusing them may limit the ability to sign up or sign in through that social login method.
Article 6 (Rights and Obligations of Data Subjects)
As a data subject, the user may exercise the following rights against the Company at any time:
- Requesting access to personal information
- Requesting correction where there is an error
- Requesting deletion
- Requesting suspension of processing
These rights may be exercised in writing, by phone, or by email (see the Privacy Officer's contact in Article 9), and the Company will act on such requests without delay. Rights may also be exercised through a legal representative or an authorized agent, in which case a power of attorney in the form prescribed by the Enforcement Rule of the PIPA must be submitted.
Article 7 (Destruction Procedure and Method)
The Company destroys personal information without delay once the retention period has elapsed, the processing purpose has been achieved, or the information otherwise becomes unnecessary.
- Procedure: personal information subject to destruction is identified under the Company's internal policy and destroyed with the Privacy Officer's approval.
- Method: information stored electronically is permanently deleted using methods that prevent recovery; paper records are destroyed by shredding or incineration.
Article 8 (Measures to Secure Personal Information)
The Company takes the following measures to secure personal information:
- Storing passwords using one-way hashing (bcrypt)
- Encrypting sensitive data such as authentication tokens at rest
- Limiting access to personal information to the minimum necessary personnel
- Technical countermeasures and up-to-date security software against hacking and similar threats
- Access control over systems that process personal information
- Establishing and operating an internal management plan
Article 9 (Privacy Officer)
The Company designates a Privacy Officer responsible for personal data processing overall and for handling complaints and remedying harm related to personal data processing, as follows:
| Role | Detail |
|---|---|
| Contact | Mozzamile development team (acting as Privacy Officer) |
| devteam@mozzamile.com |
Users may direct any privacy-related inquiry, complaint, or request for remedy arising from use of the Company's services to the contact above, and the Company will respond and act without delay.
Article 10 (Remedies for Rights Infringement)
Data subjects may seek dispute resolution or consultation from the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Privacy Infringement Report Center, and other bodies listed below:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.police.go.kr)
Article 11 (Changes to this Policy)
Where this Policy is added to, removed, or amended due to changes in law, policy, or security technology, the Company will announce the change on this website at least 7 days before it takes effect (or at least 30 days before, for material changes).
| Version | Effective date | Summary of change |
|---|---|---|
| 2026-09-11 | 2026-09-11 | Initial publication — unified company-wide policy introduced alongside Platform Account consolidation |
| 2026-09-18 | 2026-09-18 | Added an overseas-transfer article (Article 5); updated the outsourcing article (Article 4) to name the actual processors; specified MozzaRun's retention period and no-advertising-use of health data (Article 2); specified FamLoop's child-data protections and its basis for disclosing crisis indicators to the relevant authorities (Articles 2 and 3); reflected that MozzaRun requires no sign-in and stores location data locally on-device (iCloud) (Article 2); updated FamLoop's AI processor to Google LLC (Gemini) (Articles 4 and 5) |
