Back

Privacy Policy

Bloom Vocal (hereinafter "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (PIPA) of Korea to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

1. Purpose of Processing Personal Information

The Company processes personal information for the following purposes:

  1. Membership registration and management: Member identification, verification of intent to register, identity verification, prevention of fraudulent use
  2. AI voice coaching service: Voice recording analysis, AI coaching feedback generation, training curriculum provision, progress tracking
  3. AI onboarding and personalization: Identification of user level and goals, baseline voice assessment, personalized training plan creation
  4. Voice health management: Real-time symptom checks, risk assessment, health record management
  5. Service improvement: Usage statistics analysis, service quality enhancement

2. Items of Personal Information Processed

CategoryItems CollectedCollection Method
Registration (required)Email, name, profile imageGoogle OAuth social login
Onboarding profile (required)Age range, experience level, gender (optional), voice classification, training goalsDirect input via AI conversation
Voice data (required)Voice recording files (MP3, M4A, WAV, WebM, OGG, FLAC)User upload
AI analysis resultsCoaching feedback, rubric scores, timestamped notesAutomatically generated by AI
Training recordsExercise logs, session records, progress metrics, milestonesAutomatically collected during service use
Voice health informationSymptom records, risk assessment resultsUser input and automatic assessment
Automatically collectedCookies, access logs, IP address, browser typeAutomatically collected during service use

3. Processing and Retention Period

The Company processes and retains personal information within the period prescribed by law or agreed upon with the data subject at the time of collection.

CategoryRetention PeriodBasis
Member account informationUntil membership withdrawalService agreement
Voice recording filesDeleted immediately after AI analysis (not stored on server)Data minimization principle
AI analysis results / training recordsUntil membership withdrawalService provision
Voice health recordsUntil membership withdrawalService provision
Access logs3 monthsProtection of Communications Secrets Act
E-commerce transaction records5 yearsAct on Consumer Protection in Electronic Commerce

4. Provision of Personal Information to Third Parties

In principle, the Company does not provide personal information to third parties. However, personal information may be provided in the following cases:

RecipientPurposeItems ProvidedRetention Period
Google LLCMember authentication (OAuth)Email, name, profile imageUntil withdrawal or disconnection

5. Entrustment of Personal Information Processing

The Company entrusts personal information processing as follows for service provision:

TrusteeEntrusted Tasks
OpenAI, Inc.AI analysis of voice recordings and coaching feedback generation (GPT-audio API)

The Company ensures that the trustee does not process personal information beyond the purpose of the entrusted tasks, and stipulates matters concerning personal information security management in the entrustment contract.

6. Cross-Border Transfer of Personal Information

The Company transfers personal information overseas as follows for service provision:

RecipientCountryItems TransferredPurposeRetention Period
OpenAI, Inc.United StatesVoice recording filesAI voice analysis and coaching feedbackDeleted immediately after API processing
Google LLCUnited StatesEmail, name, profile imageMember authentication (OAuth)Until disconnection

The Company takes protective measures in accordance with PIPA for cross-border transfers. Data subjects may refuse consent to cross-border transfers; however, refusal may limit the use of AI coaching services.

7. Destruction Procedures and Methods

  1. Destruction procedures: Personal information is destroyed without delay after the retention period expires or the processing purpose is achieved. If retention is required by law, the data is moved to a separate database and destroyed after the required period.
  2. Destruction methods: Electronic files are permanently deleted using methods that prevent recovery. Personal information printed on paper is shredded or incinerated.

8. Processing of Sensitive Information

The Company processes the following sensitive information:

Sensitive InformationPurposeLegal Basis
Voice recordings (may constitute biometric data)AI voice analysis and coaching feedbackSeparate consent from data subject
Voice health information (health-related data)Voice health management and risk assessmentSeparate consent from data subject

Separate consent is obtained for processing sensitive information, and data subjects may refuse such consent. However, refusal may limit the use of AI coaching analysis and voice health management services.

9. Automated Decision-Making

The Company uses AI to perform the following automated decisions:

Automated DecisionCriteria and Procedures
AI voice analysis and coaching feedbackThe OpenAI GPT-audio model analyzes voice recordings and generates feedback on breathing, pitch, tone, rhythm, and expression.
Training level assessment and curriculum recommendationBased on voice assessment results and profile information from onboarding, the system determines beginner, intermediate, or advanced level and recommends a personalized curriculum.
Voice health risk assessmentBased on symptom information entered by the user, the system automatically evaluates risk level (none, low, medium, high, critical).

Data subjects may exercise the following rights regarding automated decisions:

  • Right to refuse automated decisions
  • Right to request an explanation of automated decisions
  • Right to request human intervention (review by a person) for automated decisions

To exercise these rights, please contact the Chief Privacy Officer listed below.

10. Rights and Obligations of Data Subjects

Data subjects may exercise the following personal information protection rights at any time:

  1. Request to access personal information
  2. Request to correct or delete personal information
  3. Request to suspend processing of personal information
  4. Request to withdraw consent
  5. Request to refuse automated decisions and request explanations

Rights may be exercised through the settings menu within the Service or via email. The Company shall take action without delay. When a data subject requests correction or deletion, the Company shall not use or provide the relevant personal information until the correction or deletion is completed.

For children under 14, legal representatives may request access, correction, deletion, or suspension of processing of the child's personal information.

11. Measures to Ensure Security of Personal Information

The Company takes the following measures to ensure the security of personal information:

  • Administrative measures: Establishment and implementation of internal management plans, minimization of personnel handling personal information, and training
  • Technical measures: Encryption (TLS for transmission, database encryption for storage), access control management, installation of security software
  • Physical measures: Access control for server rooms and data storage facilities

12. Cookies and Automatic Collection Devices

The Company uses cookies to store and retrieve user information.

  • Purpose of cookies: Maintaining login status, remembering language settings, analyzing service usage statistics
  • How to refuse cookies: Users can allow or block cookies through their web browser settings.
    • Chrome: Settings → Privacy and security → Cookies and other site data
    • Safari: Preferences → Privacy → Cookies and website data
    • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Note: Blocking cookies may restrict some services including login.

13. Chief Privacy Officer

The Company has designated the following Chief Privacy Officer to oversee personal information processing and handle data subject complaints and remedies:

Privacy Department

  • Department: Privacy Department
  • Email: doublejstudio21@gmail.com

Data subjects may contact the Chief Privacy Officer regarding any inquiries, complaints, or remedies related to personal information protection.

14. Remedies for Privacy Violations

Data subjects may apply for dispute resolution or consultation with the following organizations for remedies against privacy violations:

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office Cyber Investigation Division: 1301 (www.spo.go.kr)
  • National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)

15. Changes to this Privacy Policy

This Privacy Policy may be amended in accordance with changes in laws and policies. Any amendments shall be announced through the Service notice board, and the amended policy shall take effect from the date of announcement.

16. Effective Date

This Privacy Policy is effective as of March 1, 2026.