< Privacy Policy v1.0 >
Effective date: 2026-07-30
1. General Provisions and Purpose
vivome (“the Company” or “vivome”) values your personal data and complies with the Personal Information Protection Act (PIPA) of the Republic of Korea and other applicable laws while providing the vivome service (“the Service”).
2. Personal Data We Collect
1) Account information — The Service is anonymous by default. On first launch, we do not ask for your name, contact, gender, or age; a randomly generated anonymous account identifier is issued automatically. We link an email address to your account only if you choose to, for purposes such as backup or cross-device sync. If you enter a nickname, it is stored on your own device.
2) Records you enter or upload — When using core features, records you enter or upload yourself: intake, habits, symptoms, physical and mental condition, sleep, menstrual cycle, thoughts, people around you, daily events, photos, and voice. Health-related information among these may constitute sensitive data under PIPA and is processed only with your separate consent.
3) Automatically generated data — Access logs, service usage records, app error (diagnostic) logs, device and OS information, and IP address may be generated automatically during use, and the website uses cookies to maintain your login session.
4) On-device-only data — Information that on-device AI processes solely within your device and does not transmit to the Company's servers (e.g., intermediate results of on-device analysis, audio for on-device speech recognition) is not separately collected or stored by the Company.
5) External health app integration — Only if you grant permission through your device's operating-system settings, the Service reads items you allow, such as sleep duration, heart rate variability, resting heart rate, and blood oxygen saturation, from external health apps such as Apple Health and saves them into your calendar health records. The Service does not currently offer a feature to export or save vivome records to an external health app. You may withdraw this permission at any time in your device settings.
3. Purposes of Processing
The Company processes personal data to create and identify accounts and manage usage status, store records and sync them across devices, display the calendar and insights, provide wellness analysis (e.g., energy maps) and content recommendations, respond to inquiries, deliver notices, diagnose errors, and improve service quality.
Health-related records are used only to the extent needed to provide the personalized record-keeping and analysis you request, and are never used for ad targeting or sold to third parties.
4. Processing of Sensitive Data
The Company may process sensitive data you enter yourself, such as health, symptoms, physical and mental condition, sleep, menstrual cycle, photos, and voice.
Under Article 23 of PIPA, sensitive data is collected and used only through a separate consent process distinct from general personal-data consent and the terms of service. The separate consent screen informs you of the items, purposes, and retention period of the sensitive data processed.
You may decline consent to process sensitive data, in which case some features such as health-record-based insights may be limited.
The Company processes sensitive data only to the minimum extent necessary to provide the Service, restricts access rights, and applies encryption and access controls during transmission and storage.
5. Anonymous Community Aggregation (Planned Feature)
The Company does not currently offer a community insights feature and does not collect or use your records for community aggregation purposes.
The Company may in the future add a community insights feature showing anonymized cases of other users in similar contexts as statistics. In that case, because such records may constitute health-related sensitive data, they would be collected and used only after explicit, separate opt-in consent (default OFF) distinct from general personal-data consent and the terms, under Article 23 of PIPA, and the Company will disclose the separate consent process and method in advance.
6. Retention and Use Period
As a rule, the Company destroys personal data without delay when its processing purpose is achieved or upon account withdrawal. Retention and use periods by data type are as follows.
• Account information and user records (raw entries, event/statistics data, vault backups): until account withdrawal is processed (destroyed without delay upon withdrawal)
• Temporary cache of advanced photo-analysis results: kept for up to 1 hour to improve response speed and prevent duplicate requests, then automatically deleted
• AI usage metadata (request time, feature, model, token count, cost, etc.; excludes record content): retained for billing verification and abuse prevention, and destroyed once the purpose is achieved
• Automatically collected data such as access logs: for the period set by applicable law
• Backups: deleted in turn within the backup rotation cycle
Information that must be retained under applicable laws (e.g., the Act on Consumer Protection in Electronic Commerce, the Protection of Communications Secrets Act) is stored separately for the legally required period and then destroyed.
7. Provision to Third Parties
As a rule, the Company does not provide your personal data to third parties.
However, we may provide it to the extent necessary where you have consented in advance, where required by law, or where lawfully requested by investigative or other authorities under due process.
8. Delegation of Processing
To provide a stable service and implement core features, the Company delegates part of its personal-data processing to the processors below, and supervises them to handle personal data safely under applicable law.
• Supabase Inc. — cloud infrastructure (database, authentication, file storage) operation and backup (on Amazon Web Services)
• OpenAI, L.L.C. — only when you consent to “Cloud AI use” and run an advanced feature: analysis, optical character recognition (OCR), speech recognition (STT), and wellness-insight generation (AI responses, dream/emotion analysis) of the relevant input (text, image, voice)
• Upstash, Inc. — temporary caching of advanced photo-analysis results (Redis, up to 1 hour) to improve response speed
• Resend (Plus Five Five, Inc.) — sending inquiry replies and service notice emails
Records you enter (diary, photos, voice) may be transmitted to the above processors, to the minimum extent needed for analysis, only when you use the advanced AI analysis features, and the Company does not use them for advertising or external sale. Separately, end-to-end (zero-knowledge) vault backup data you set up is encrypted on your device, so neither the Company nor its processors can view its contents.
9. Cross-Border Transfer of Personal Data
The Company transfers personal data overseas (for processing/storage) as follows. All transfers use encrypted network (TLS) transmission, and the timing of each transfer is when the relevant feature's use, storage, backup, or sending is required.
• Recipient: Supabase Inc. / Country: United States (entity), Singapore (data storage region) / Items: account identifier, user records, backups / Purpose: data storage, authentication, backup / Retention: until account withdrawal
• Recipient: OpenAI, L.L.C. / Country: United States / Items: input you transmit after consent (text, image, voice) / Purpose: advanced AI analysis, OCR, speech recognition, insight generation / Retention: the Company does not store the original on its servers after processing; OpenAI's retention/use follows OpenAI's policy and API agreement
• Recipient: Upstash, Inc. / Country: United States / Items: advanced photo-analysis results and request identifiers / Purpose: temporary cache for faster responses / Retention: up to 1 hour
• Recipient: Resend (Plus Five Five, Inc.) / Country: United States / Items: email address / Purpose: sending inquiry replies and notice emails / Retention: until the sending purpose is achieved
You may refuse cross-border transfer, in which case the relevant features (e.g., cloud AI analysis, email replies) may be limited. To refuse, turn off “Cloud AI use” in the app settings or contact support@vivome.io.
10. AI Processing and Automatically Generated Content
The Service's automatic tag classification (NLP) and basic photo analysis run within your device. Advanced analysis such as optical character recognition (OCR), speech recognition (STT), detailed photo analysis, and AI responses (dream/emotion analysis, etc.) transmit the necessary input to OpenAI in the United States, encrypted (TLS), only when you consent to “Cloud AI use” (default opt-out/OFF) and run the relevant feature. No external transmission occurs before consent.
Speech recognition, depending on your settings, either (i) is processed only within your device (on-device — voice is not transmitted externally), or (ii) transmits the voice to OpenAI if you choose and consent to cloud speech recognition. The most sensitive photos, such as bowel movements or body parts, are designed to be analyzed only within your device and are not transmitted externally.
The Company does not separately store on its servers the original content transmitted for advanced analysis. However, photo-analysis results are temporarily cached for up to 1 hour to improve response speed and prevent duplicate requests, and usage metadata such as request time, feature, and token count (excluding record content) is retained as logs for billing and abuse prevention.
AI-generated tags, responses, and analysis results are automatically generated content not individually reviewed by a human. They are not medical devices or medical acts and are reference information that does not provide diagnosis or treatment; medical judgments regarding symptoms, medication, treatment, or diet changes must be discussed with a qualified professional such as a physician.
11. Rights of Data Subjects and How to Exercise Them
You may at any time request access to, correction of, deletion of, suspension of processing of, or withdrawal of consent regarding your personal data. For children under 14, a legal representative may exercise these rights.
You may exercise your rights via the app settings or support@vivome.io, and the Company will act within the period set by applicable law. Some requests may be limited where retention is required by law or where another user's rights may be infringed.
12. Procedure and Method of Destruction
The Company destroys personal data without delay once grounds for destruction arise. Electronic files are deleted by secure means that make recovery or reproduction difficult, and printouts are shredded or incinerated.
Destruction timing by data type follows the “Retention and Use Period” section of this policy. Information that must be retained by law is moved to separate storage, kept for the legally required period, and then destroyed.
13. Measures to Ensure Security
The Company implements reasonable technical and administrative measures to protect personal and sensitive data, including transport-layer encryption (TLS), protection of stored data, least-privilege access, access-log retention, security updates, and internal access controls.
Your original entries are stored end-to-end (zero-knowledge) encrypted on your device, so neither the Company nor its processors can decrypt or view their contents. Data separately synced for app–web integration is also end-to-end encrypted.
However, the structured data stored to reconstruct records into a calendar and statistics (event codes, attribute values (facets), free-text notes, references) and the titles of THOUGHT records are not currently end-to-end encrypted; they are protected by Row Level Security and storage-medium encryption. Authorized Company operators may access this data when necessary, such as for incident response. Expanding end-to-end encryption to structured data is on our roadmap.
Photos and diaries in Pro Vault backups are stored end-to-end encrypted on your device, and the decryption key exists only on your device, so neither the Company nor its processors can decrypt them.
Original audio files intended for on-device speech recognition are kept only in your device's internal storage and are not transmitted externally; at this stage, no separate encryption is applied to device storage, and such encryption is on our roadmap.
15. Children Under 14
The Service is not directed to children under 14, and the Company does not collect the personal data of children under 14.
If it is confirmed that a child under 14's personal data was collected without a legal representative's consent, the Company deletes it without delay.
16. Privacy Officer and Contact
Privacy Officer: Yuji Lim (CEO) / Email: support@vivome.io
17. Duty to Notify / Changes
When the Company changes this policy, it will announce the changes and effective date in advance via the Service or website. For material changes (collection items, purposes, third-party provision, delegation, cross-border transfer, etc.), notice is given at least 7 days in advance (30 days for changes unfavorable to users), and where separate consent is required, it is obtained under applicable law.
Addendum: This policy takes effect on 2026-07-30 (added the external health app integration item). Previous versions are available in the previous-version list at the bottom of this page.