Griing Talk

Privacy Policy

Published: 2026-07-18 · Effective: 2026-07-18

This policy explains what personal data Griing Talk collects, why, where it is stored, how long we keep it and what you can do about it. The short version: we never record audio or video, we use no advertising or third party tracking, and your account and learning profile are stored on our servers in a database hosted in the Seoul region of Korea. We apply the standards of Korea's Personal Information Protection Act (PIPA) and the EU General Data Protection Regulation (GDPR) to every user, wherever you live.

1. Who we are and what this policy covers

Controller: Foo AI Corp. (representative: JEEHO SONG; business registration number: 284-81-02702; address: 82 Daehak-ro, Yuseong-gu, Daejeon 34183, Republic of Korea), operator of the Griing Talk service.

Contact for all privacy matters: contact@griing.com or 02-581-3001.

This policy covers the Griing Talk website and service. It applies to visitors, to Members, and to people who ask to be notified when live matching opens.

Because the Service is used by people in Korea and in English speaking countries, we comply with PIPA, the Network Act of Korea, and the GDPR.

2. Personal data we collect, and where it is stored

Account data: your email address; your date of birth (entered at sign up and used only to check that you are 18 or over, we keep only your birth year and the fact that the adult check was passed, not the full date); and a display name (derived from your email or set during onboarding). The retained account data is stored on our servers, in a database operated by Supabase and hosted in the Seoul region of Korea.

Sign in provider data: if you sign in with your Google account, we receive from Google your email address and your Google account identifier, which we use to create and authenticate your account. We do not receive your Google password.

Learning profile, entered by you at onboarding: native language, target language, self assessed level (0 to 4), interests, and learning goal. This is also stored on our servers in the same database.

Launch notification list: if you ask to be notified when live matching opens, we store your email address on our server, in a database operated by Supabase. If you are signed in when you make the request, we also attach the learning profile signals we already hold (target language, self assessed level, interests) and your interest signals (whether you would want to meet the same partner again, whether you would be interested in a paid plan), together with the screen the request came from and your interface language. If the database is unavailable at that moment, the record, including your email address, is written to a file on our server as a fallback so that your request is not lost; any log entry we write about the request masks the email address and stores a one way hash of it instead of the address itself.

Automatically collected data: your IP address, browser and device information (user agent), the date and time of the request, and the path requested. These are recorded by our hosting provider and are used for security, abuse prevention and rate limiting.

Product usage events: we record which screens are viewed and which buttons are pressed, using a fixed whitelist of event names, together with the interface language and a timestamp. These records are written to our server log. We do not attach your name or email address to them and we do not build advertising profiles.

What we do not collect: we do not record audio or video, we operate no CCTV, we collect no payment or card data, no resident registration number or other unique identifier, no biometric data, and no special category or sensitive data. We use no third party analytics, no advertising SDK and no tracking pixel.

When live 1:1 video sessions are introduced, the audio and video stream will be transmitted between the two participants and will not be recorded or stored by us. We will store only session metadata such as the start time, the end time and the duration. We will publish the amended policy before that feature goes live.

3. Why we process it (purposes)

To create and maintain your account, to verify that you are 18 or over, and to keep you signed in between visits.

To provide the Service: to remember your learning profile, to prepare a level appropriate match and to run the practice session.

To send you one notification when live matching opens, if you asked for it, and to prepare the first matching rounds using the profile signals you provided.

To keep the Service safe: to prevent abuse, spam and automated attacks, and (once those features exist) to receive and review reports and to block a Member who violates the rules.

To improve the product: to understand which parts of the Service are actually used.

To comply with legal obligations and to establish, exercise or defend legal claims.

4. Legal bases for processing

Account data and learning profile: necessary for the performance of the contract with you (GDPR Article 6(1)(b); PIPA Article 15(1)4).

Adult age check: performance of the contract and our legitimate interest in keeping minors off an adults only video service (GDPR Article 6(1)(b) and 6(1)(f); PIPA Article 15(1)4 and 15(1)6).

Launch notification list and any marketing email: your consent, which you may withdraw at any time (GDPR Article 6(1)(a); PIPA Article 15(1)1; Article 50 of the Network Act of Korea).

Security logs, IP address and rate limiting: our legitimate interest in the security and integrity of the Service (GDPR Article 6(1)(f); PIPA Article 15(1)6).

Product usage events: our legitimate interest in improving the Service, processed with the minimum identifiers necessary (GDPR Article 6(1)(f); PIPA Article 15(1)6). You may object to this processing at any time by writing to contact@griing.com.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and we limit the data to what is necessary.

5. How long we keep it (retention)

Account and learning profile, stored on our servers: kept while your account exists, and destroyed without undue delay when you delete your data or close your account.

Supabase authentication session cookie: kept for the duration of your signed in session as managed by Supabase Auth, and cleared when you sign out or close your account.

Language setting cookie and launch notification flag cookie: 1 year, or immediately when you delete them.

Launch notification list (email address and profile signals): until the launch notification has been sent, or 24 months from collection, or until you ask us to delete it, whichever comes first.

Server access logs and product usage events: up to 30 days (and shorter where our hosting provider's log retention is shorter), after which they are deleted or anonymised.

Reports and blocks (once that feature exists): 3 years from receipt, for the prevention of repeat abuse and the handling of disputes, after which they are destroyed. We will confirm the detailed rule in the amended policy published before that feature goes live.

Because the Service is currently free of charge and involves no transaction, no records subject to the retention duties of the Act on the Consumer Protection in Electronic Commerce arise. If a paid plan is introduced, the statutory retention periods will be set out here in advance.

Where the law requires us to retain a record for longer, we keep it only for the required period and only for that purpose.

6. Disclosure to third parties

We do not sell personal data. We do not share personal data with third parties for their own marketing.

We do not disclose personal data to third parties except where you have given your separate consent, or where a law, a court order or a lawful request by an authority requires it. Where we receive such a request we check its legal basis and scope before responding, and we disclose no more than is required.

7. Processors we entrust with personal data

We entrust part of the processing to the following providers, which act only on our instructions and only for the purposes below. We check that they apply appropriate security measures, and we prohibit further sub processing without our agreement.

Vercel Inc. (United States): hosting of the website and its server functions, and the platform logs that contain IP address, user agent, request time and path. Entrusted for the duration of the service contract.

Supabase Inc. (a United States company; the database is hosted in the Seoul region (ap-northeast-2) of the Republic of Korea): storage of account and profile data and of the launch notification list. The data is stored in Korea, and Supabase Inc. may access it from the United States for operation and support. Entrusted for the duration of the service contract.

Google LLC (United States): authentication when you choose to sign in with your Google account (OAuth). This applies only if you use Google sign in. Entrusted for the duration of the service contract.

LiveKit Inc. (United States): real time transmission of audio and video for live 1:1 sessions. This processing has not started, because live sessions are not yet available. It will begin only when that feature is launched, and the stream is transmitted rather than recorded.

If we change a processor or add a new one, we will update this section and, where required, notify you in advance.

8. International transfers

Account and profile data and the launch notification list are stored by Supabase in the Seoul region of Korea, so they remain within Korea; because Supabase Inc. is a United States company, it may access that data from the United States for operation and support. The data processed by Vercel (platform logs and request data) and by Google (the email address and account identifier exchanged when you sign in with Google) is processed in the United States, outside Korea and outside the EEA.

Items concerned: for Vercel, IP address, user agent, request metadata and any data contained in a request; for Google, the email address and Google account identifier exchanged during sign in; for Supabase (stored in Korea, with possible access from the United States), account and profile data and the launch notification list (email address, profile signals, interest signals); for LiveKit, once launched, the real time audio and video stream and session connection metadata.

Purpose: hosting, database storage and real time video transmission, that is, the operation of the Service itself. Transfers are made continuously over an encrypted network connection as you use the Service, and the data is retained for the periods set out in section 5.

Legal basis under PIPA: the entrusted overseas processing and the access from abroad described above are necessary to perform the contract with you, and they are disclosed in this policy in accordance with Article 28-8(1)3 of PIPA.

Legal basis under the GDPR: for users in the EEA, the storage of account and profile data in Korea is covered by the European Commission's adequacy decision for the Republic of Korea, and transfers to the United States (Vercel, Google, and LiveKit once launched) are made under the European Commission's standard contractual clauses or another Chapter V safeguard offered by the processor.

You may refuse an international transfer. Because these transfers are indispensable to operating the Service, the practical effect of a refusal is that we cannot provide the Service to you; in that case you may close your account and we will delete your data. To refuse, write to contact@griing.com.

9. Your rights and how to exercise them

You have the right to be informed about the processing, to access your data, to have inaccurate data corrected, to have your data deleted, to have processing suspended or restricted, to object to processing based on legitimate interests, to withdraw a consent you have given, and to receive your data in a portable form (GDPR Articles 15 to 22; PIPA Articles 35 to 37).

The fastest way to delete your data is the "Delete my data" button on the home screen. It deletes the Griing Talk cookies on the device you are using and, when you are signed in, also deletes your email address from the launch notification list held on our server.

For any other request, write to contact@griing.com. A legal representative or an authorised agent may act on your behalf.

We answer without undue delay: within 10 days for requests under PIPA and within one month for requests under the GDPR. If a request is refused we tell you why and how to appeal. Exercising a right is free of charge.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

10. Destruction of personal data

When the purpose of the processing has been achieved, the retention period has expired, or you have asked us to delete your data, we destroy it without undue delay and, in any case, within 5 days.

Data held in electronic files is deleted by a technical method that makes it unrecoverable. Any data printed on paper is shredded or incinerated.

Where a law requires us to keep a record beyond that point, we separate it from other data and store it only for the legally required purpose and period.

11. Cookies: what we set and how to refuse them

We use cookies, which are small text files stored by your browser, to run the Service. All of our cookies are first party cookies. We set no advertising cookie, no behavioural profiling cookie and no third party cookie.

Supabase authentication cookies (names begin with sb-): hold the Supabase authentication session that keeps you signed in. Purpose: authentication. Retention: the duration of your signed in session as managed by Supabase Auth, cleared when you sign out or close your account.

lf_notify: records that you have already asked for the launch notification, so the form is not shown to you again. Purpose: convenience. Retention: 1 year.

lf_lang: records your interface language. Purpose: convenience. Retention: 1 year.

Local storage: we also keep small convenience data in your browser's local storage (saved practice questions, demo progress and whether you have accepted the session pledge). These stay on your device, are never sent to our servers, and are cleared when you sign out or use the "Delete my data" button.

How to refuse: you can accept all cookies, be asked before a cookie is stored, or refuse all cookies in your browser settings (typically under Settings, Privacy). You can also delete stored cookies at any time, including with the "Delete my data" button in the Service.

Effect of refusal: the Supabase authentication cookie is strictly necessary to sign in and to use the Service. If you refuse it, you can still read the public pages but you will not be able to sign in.

12. How we protect your data (security measures)

Encryption in transit: the Service is served over HTTPS with HSTS enabled.

Session integrity: sign in is handled by Supabase Auth, which issues the session as a signed token delivered through cookies that are marked SameSite and are sent only over a secure connection in production; row level security on the database restricts each account to its own data.

Browser hardening: a content security policy is applied to page (HTML document) responses and further security headers are applied to responses, and cross site request forgery is blocked by a same origin check on state changing requests.

Abuse prevention: requests to sign in, to submit the notification form, to send events and to delete an account are rate limited.

Minimisation in logs: email addresses in our logs are masked, and where an identifier is needed for deduplication or for handling a deletion request a one way hash is stored instead of the address; the actual email address for a launch notification is held only in the notification store (the database, or a server file used as a fallback when the database is unavailable), because it is needed to send the notification.

Access control: database access keys are held on the server only and are never exposed to the browser, row level security is enabled on the database schema, and access is granted on a least privilege basis.

Software supply chain: dependencies are audited and the code is scanned by static analysis on every change in our continuous integration pipeline.

No security measure is perfect. If a personal data breach occurs, we will notify you and the competent authority within the periods required by law (PIPA and GDPR Articles 33 and 34).

13. Launch notifications and marketing messages

We send an email only if you asked us to notify you when live matching opens. We do not send unsolicited promotional email.

Where a message is promotional in nature, we label it as an advertisement in the subject line, identify the sender, state how to unsubscribe, and do not send it between 21:00 and 08:00 Korean time without your separate prior consent, as required by Article 50 of the Network Act of Korea.

You may unsubscribe at any time, free of charge, by using the unsubscribe link in the message or by writing to contact@griing.com. We stop sending and delete your address from the list.

14. Adults only: no data from anyone under 18

The Service is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not offer any part of the Service to children.

The age check at sign up calculates your full age from the date of birth you enter and refuses the account if you are under 18. Because the check relies on your own declaration, it is not identity verification.

If we learn that we hold data of a person under 18, we suspend the account immediately, delete the account and destroy the personal data without undue delay, and we do not use it for any purpose in the meantime. If you believe a person under 18 is using the Service, write to contact@griing.com.

15. Automated decisions and profiling

Matching works by filtering on the language pair, then on level within a range of plus or minus one, then on overlapping interests. It is an automated process, but it produces a suggested conversation partner only.

We make no automated decision that produces legal effects concerning you or that similarly significantly affects you, and we carry out no profiling for advertising or for scoring you (GDPR Article 22; PIPA Article 37-2).

If we ever introduce such a decision, we will explain the criteria in advance and give you the right to refuse it and to ask for human intervention.

16. Privacy officer and contact

Privacy officer (PIPA Article 31): JEEHO SONG, Representative, contact contact@griing.com or 02-581-3001.

Access requests are received and handled by the Representative at contact@griing.com.

We have assessed that we are not required to designate a data protection officer under GDPR Article 37, because we carry out neither large scale regular and systematic monitoring nor large scale processing of special category data. You may direct any GDPR request to the contact above.

We do not currently offer the Service to individuals in the EEA or the United Kingdom as a target market. If we begin to target those regions, we will designate a representative under GDPR Article 27 where one is required.

17. How to raise a complaint

Please contact us first at contact@griing.com. We would rather fix the problem directly.

In Korea you may also contact: the Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr); the Privacy Infringement Report Centre (118, privacy.kisa.or.kr); the Supreme Prosecutors' Office cybercrime division (1301, www.spo.go.kr); or the National Police Agency cyber bureau (182, ecrm.police.go.kr).

If you are in the EEA or the United Kingdom, you have the right to lodge a complaint with the data protection supervisory authority of the country where you live, where you work, or where the alleged infringement took place (GDPR Article 77).

18. Changes to this policy

If we change this policy we will publish the amended text, the reason for the change and the effective date on the Service at least 7 days before it takes effect.

If the change is unfavourable to you or is otherwise material, for example when live video, real matching or server side accounts are introduced, we will publish it at least 30 days in advance, notify you individually where required, and obtain a fresh consent where the law requires one.

The dates of publication and entry into force of the current version are shown at the top of this page.

Version 1.0, written for the Service as it actually operates today. Any amendment will be announced in advance under section 18. · Terms of Service
Privacy Policy · Griing Talk