Athlogic (the “Company”) complies with the personal information protection provisions of applicable laws governing information and communications service providers, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Personal Information Protection Act, the Protection of Communications Secrets Act, and the Telecommunications Business Act. The Company establishes this Privacy Policy under applicable laws and strives to protect users’ rights and interests.
This policy applies to the websites and mobile application services provided by the Company (the “Service”).
Article 1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes only. If a purpose changes, it will take necessary measures, such as obtaining separate consent, under Article 18 of the Personal Information Protection Act.
- Membership registration and management: identification and authentication, maintaining membership, preventing misuse, notices, and handling complaints.
- Provision of goods or services: workout routine recommendations and analysis, personalized content, paid-service payments and settlement, and delivery of goods such as event prizes.
- Preregistration and marketing: launch notices, development of new services or products, personalized services, events and advertising information and participation opportunities, visit frequency analysis, and service usage statistics.
- Health data analysis: personalized exercise coaching based on physical information and workout records.
- Health app integration: automatic import of sleep and weight data, analysis, and summaries.
- AI coaching and conversational features: personalized routine recommendations, adjustments, exercise explanations, and next-week routines based on workout records, goals, preferences, usage history, chat input, and selected responses.
- AI stability and quality management: analyzing response-generation errors, preventing misuse, security checks, quality improvement, support inquiries, validation of generated results, and operational records.
- AI routine generation and personalized memory: generating routines using performance records, routine progress, likes and dislikes, feedback, and conversations, and referencing them in future recommendations when applied by the user.
Article 2. Information Collected and Collection Methods
The Company collects the minimum personal information needed to provide the Service.
1. Categories of information
| Category | Purpose | Required information | Optional information |
|---|---|---|---|
| Preregistration | Launch and event notices | Mobile phone number | — |
| Registration | Identification and account creation | Email (ID), password, name or nickname | Profile photo |
| Service use | Personalized exercise solutions | Sex, date of birth, height, weight, usual activity level, workout records (performance) | — |
| Paid purchases | Payment and refunds | Payment and purchase history (card details and similar information are processed by the app marketplace) | — |
| Automatic collection | Stability and statistics | Device information (OS, model), IP address, cookies, visit times, usage records, and misuse records | — |
| Optional health integration | Automatic sleep/weight import and analysis | — | Weight, sleep (time asleep/time in bed), measurement time; read-only access through Apple Health/Health Connect APIs after consent |
| AI coaching/chat | AI answers, routine recommendations and adjustments, next-week routines, error analysis, security, and misuse prevention | Chat input, selected response options, AI answers, generated routines, workout summaries, goals, exercise likes/dislikes, performance records, routine progress, feature usage times, request/response status, and technical logs such as errors and usage | Health information such as pain, injuries, conditions, surgery history, physical condition, and exercise restrictions, only when voluntarily entered by the user |
2. Collection methods
- Website preregistration, mobile app registration, written forms, fax, phone, support boards, email, and event entries.
- Automatic collection using tools that collect generated information.
- Information entered or selected directly while using AI coaching.
- AI responses, generated routines, error logs, and operational logs produced when providing AI coaching.
Article 3. Processing and Retention Periods
1. The Company retains and processes information within the period required by law or agreed to at collection.
2. In principle, information is destroyed without delay when an account is deleted or the collection and use purposes are fulfilled. Preregistration phone numbers are destroyed within 3 months after the app launches and notification delivery is completed.
3. Health integration data is retained until account deletion or deletion of the relevant records. Revoking OS permissions immediately stops further collection.
4. Where retention is legally required, the Company retains member information for the following periods:
- Act on Consumer Protection in Electronic Commerce: contracts or withdrawal records, 5 years; payments and supply of goods or services, 5 years; complaints or disputes, 3 years; display and advertising records, 6 months.
- Protection of Communications Secrets Act: website visit records, 3 months.
- Framework Act on National Taxes: books and supporting documents for transactions under tax laws, 5 years.
5. AI coaching/chat retention periods:
- Temporary conversations during AI check-in are processed temporarily while the app runs. Intermediate conversations before routine generation are generally not stored continuously.
- AI routine generation and conversation records, including conversation logs, generation status, and related records, are retained for up to 7 days from creation for status management, error response, and customer support, then deleted or destroyed.
- AI error analysis and quality management logs are retained for up to 7 days from creation for error analysis, security, and quality management, then deleted or destroyed.
- Temporary information used to improve AI response speed and optimize costs may be retained for up to 30 minutes.
- AI-generated routine previews and applied results are retained as needed for review, application, revisiting, and service provision, then destroyed under applicable laws and this policy when the account or related records are deleted.
Article 4. Destruction Procedures and Methods
Personal information is, in principle, destroyed without delay once its processing purpose is fulfilled. Information entered by users is moved to a separate database (or separate file storage for paper), retained for the period specified by internal policies and applicable laws, then destroyed. Information moved to this database is not used for other purposes unless required by law.
- Electronic files are deleted using technical methods that prevent recovery.
- Printed personal information is shredded or incinerated.
Article 5. Disclosure to Third Parties
The Company processes information only within Article 1’s purposes and discloses it to third parties only where Articles 17 and 18 of the Personal Information Protection Act permit, such as user consent or specific legal provisions. The Company currently does not disclose users’ personal information to external third parties.
Outsourcing cloud infrastructure, AI models, storage, analytics, or error handling to provide AI coaching constitutes entrusted processing rather than third-party disclosure. Processors and their tasks are listed in Article 6.
Article 6. Entrusted Processing and International Transfers
The Company entrusts the following processing tasks to operate the Service. Changes to processors or tasks will be disclosed through this policy without delay.
| Processor | Tasks | International transfer |
|---|---|---|
| Google Cloud Platform and Google AI services (including Firebase and Vertex AI/Gemini) | Member and exercise/health data storage, server operations, AI coaching responses, routine recommendations/adjustments and generation, error analysis, security logs, analytics, and service operations | Countries hosting Google data centers, including the United States, or Google Cloud processing regions |
| Google (Analytics) | Usage statistics and analytics | See international transfer details below |
| Mixpanel | Usage statistics and analytics | See international transfer details below |
| Google (Play Store) | In-app payments and payment information management | See international transfer details below |
| Apple (App Store) | In-app payments and payment information management | See international transfer details below |
| RevenueCat | In-app purchase verification and subscription management | See international transfer details below |
| Algolia | Food data search | See international transfer details below |
| Perplexity | Food information search and AI analysis | See international transfer details below |
| Kakao Corp. | Kakao business channels and business messages | See international transfer details below |
International transfer details
The Company uses global cloud servers and AI model processing services. Personal information may therefore be transmitted, stored, or processed abroad.
- Countries: countries hosting processors’ data centers, including the United States, or cloud processing regions.
- Timing and method: transmission over networks as needed during registration, service use, AI coaching, payments, analytics, and error handling.
- Information: member identifiers, email, name or nickname, usage and workout records, workout goals and preferences, health integration data, AI chat input and responses, generated routines, generation execution logs, error/diagnostic logs, device information, IP addresses, visit times, and other information needed to provide the Service.
- Recipients: processors in Article 6, including Google Cloud Platform, Firebase, Vertex AI/Gemini, Google Analytics, Mixpanel, RevenueCat, Algolia, Perplexity, and Kakao Corp.
- Purposes: service provision, storage, server operations, AI coaching and routine generation, payments, subscriptions, analytics, search, customer notices, error analysis, security, and quality improvement.
- Retention and use: the periods specified in this policy or until the processing agreement ends; legally required records are retained for the statutory period.
Article 7. Health Integration Data
- Sleep and weight data is read from Apple Health/Health Connect only with consent, using read-only access.
- This data is used only to import sleep/weight records and provide analysis or summaries.
- Health data is not used for advertising or marketing, sold, rented, or disclosed to third parties.
- Users may change or revoke permissions in OS settings (Apple Health/Health Connect) at any time; revocation stops further collection.
- If used for AI coaching, health integration data is processed only for health-promoting services such as routine recommendations, exercise analysis, recovery reference, and routine adjustments.
- Health integration data is not used for advertising/marketing targeting, sale, rental, or third-party disclosure.
- Revocation in OS or app settings stops collection. Existing analysis, recommendations, or legally required records may remain for the retention periods under this policy.
Article 8. Rights of Users and Legal Representatives
Users may at any time request access, correction of errors, deletion, or suspension of processing. Requests may be made in writing, by email, or by fax, and the Company will act without delay. Users may also use account deletion or profile editing in app settings.
When correction is requested, the relevant information will not be used or disclosed until correction is complete.
Users may request access, correction, deletion, or suspension of processing for AI conversations, AI responses, generation execution records, and other personal information. Consent to AI coaching may be withdrawn, which may restrict some or all AI coaching features. Records needed for error analysis, security, disputes, or legal compliance may be retained for the periods in this policy.
Article 9. Security Measures
- Administrative measures: internal management plans and employee training.
- Technical measures: access authorization management, access control systems, encryption of unique identifying information, and security software.
- Physical measures: access controls for computer rooms and document storage.
- Restricted AI conversation and generation records are protected by authorization and access controls, log management, retention limits, and masking or de-identification where necessary.
Article 10. Cookies and Opting Out
The Company uses cookies to store and retrieve usage information for personalized services. Cookies are small amounts of information sent by a website’s HTTP server to a browser and may be stored on a computer’s hard drive.
- Purpose: optimized information based on visits, usage patterns, popular search terms, and secure connection status.
- Control: users may refuse cookies through browser privacy options (Tools > Internet Options > Privacy).
- Refusing cookies may make personalized services difficult to use.
Article 11. Privacy Officer and Contact
The following officer oversees personal information processing, complaints, and remedies.
- Name: Jiheon Baek
- Position: Representative of Athlogic
- Phone: 010-8306-9110
- Email: support@athlogic.kr
Access requests are received and processed by the Athlogic Customer Support Team, using the same contact details above.
Article 12. Remedies for Privacy Violations
Users may request dispute resolution or consultation from the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency’s privacy reporting center. Other reporting and consultation contacts are:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Reporting Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.cyber.go.kr)
Article 13. Policy Changes
This policy takes effect on June 9, 2026. Changes and their effective dates will be announced through appropriate channels such as service notices, app screens, email, or push notifications.
For changes materially affecting users’ rights, including collection categories, purposes, retention, entrusted processing, or international transfers, the Company will take measures required by applicable laws.