Legal & data
Privacy Policy
Last updated: October 1, 2025
JourneyLab (the “Company”) values your privacy and complies with the Korean Personal Information Protection Act and related laws. This policy explains how personal data is collected, used, stored and destroyed in MemoTalk (ChatDo).
1. Personal data we collect
- At sign-up (required): email address, password
- While using the Service: the tasks and notes you write, images you upload
- Collected automatically: device information (OS version, model), IP address, access time, usage records, error logs
- For paid purchases: payment date, amount and a payment identifier from PayPal. The Company does not store card numbers.
2. Purposes of use
- Identifying members, managing accounts and maintaining sessions
- Storing notes and tasks and synchronising them across devices
- Providing image text recognition (OCR)
- Processing credit purchases, refunds and transaction records
- Responding to enquiries and sending service notices
- Improving the Service, diagnosing errors and preventing abuse
3. Retention periods
Personal data is destroyed without delay once its purpose is achieved or the account is closed, except where law requires retention:
- Records on contracts and withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records on payment and supply of goods: 5 years (same Act)
- Records on consumer complaints and dispute handling: 3 years (same Act)
- Service access logs and IP records: 3 months (Protection of Communications Secrets Act)
4. Provision to third parties
As a rule the Company does not provide personal data to third parties.
Exceptions apply only where the user has given prior consent or where an investigative authority makes a lawful request under statutory procedure.
5. Processors
The Company entrusts limited processing to the following providers, with contractual safeguards for secure handling:
- Supabase — database, authentication and storage infrastructure (until account closure or termination of the contract)
- Email delivery provider — verification and notification emails
- PayPal — payment and refund processing for credits
6. Overseas transfer
Because of the infrastructure used by our processors, personal data may be stored and processed on servers outside Korea. The Company applies the safeguards required by applicable law.
7. Your rights
You may at any time request access to, correction or deletion of your personal data, suspension of processing, or withdrawal of consent (account closure).
Use the settings screen in the app or write to info@memotalk.kr; we act without delay after verifying the request.
For children under 14, a legal representative may exercise these rights.
8. Destruction of personal data
- Data whose retention period has expired or whose purpose is achieved is destroyed without delay.
- Electronic files are erased by technical means that prevent recovery.
- Printed materials are shredded or incinerated.
9. Security measures
- Encryption of credentials at rest and encryption in transit (HTTPS/TLS)
- Minimising and managing access rights to personal data
- Retention and tamper-protection of access logs
- Technical safeguards against hacking and other intrusions
10. Data protection officer
In Korea you may also contact the Personal Information Dispute Mediation Committee (1833-6972), the Privacy Infringement Report Centre (118), or the cyber investigation units of the Supreme Prosecutors' Office (1301) and the National Police Agency (182).
- Officer: JourneyLab Data Protection Officer
- Email: info@memotalk.kr
- Address: 2F #137, 128 Teheran-ro, Gangnam-gu, Seoul, Republic of Korea
11. Changes to this policy
Any change to this policy will be announced in advance through in-service notices or this page.
This policy is effective from October 1, 2025.
This document mirrors the official version published with the MemoTalk app. The Korean version prevails in case of any discrepancy.