Privacy Policy

ToldU ("we", "us", "our") operates the ToldU mobile application (the "App"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have. It is written to meet the requirements of the U.S. California Consumer Privacy Act (CCPA/CPRA) and the Republic of Korea Personal Information Protection Act (PIPA / 개인정보 보호법).

Effective date: 06/26/2026 Data controller: DevIt, 11762 Hartford Way, Mukilteo WA 98275, USA Privacy contact: privacy@toldu.ink Privacy Officer (개인정보 보호책임자): Kipack Jeong — privacy@toldu.ink

Read this first. ToldU is an app for resolving interpersonal conflicts. When you create a case, you describe a real conflict in your own words and we send that text to a third-party AI service to generate a fault analysis. Conflict descriptions and answers can reveal sensitive details about you and other people. Anything you choose to publish becomes publicly visible. Please do not include real names, contact details, or other identifying information about people who have not consented. See "Sensitive information and content about others" below.


1. Information we collect

a. Information you provide

Data When Notes
Email address Sign-up / sign-in (email, Apple, or Google) Apple may relay a private "hide my email" address.
Password Email sign-up Stored hashed by our auth provider; we never see it in plaintext.
Profile details Onboarding / profile Username, avatar image (optional), gender (optional), relationship context (couple, friends, family, coworkers, group, other).
Case content Creating a case The free-text conflict description you write, your answers to AI follow-up questions, and the relationship type.
Posts, votes, comments Using the feed Content you publish, who you voted for on a case, comments and comment likes.
Reports & blocks Moderation Content you report and users you block.
Support messages Contacting us Anything you send to support@toldu.ink.

b. Information collected automatically

Data Purpose
Device & app info (OS version, app version, device model, language) Operate the App, debug crashes.
Push notification token (Expo) Send notifications you've enabled.
Usage & log data (actions taken, timestamps, IP address) Security, abuse prevention, reliability.
Approximate crash/error diagnostics Fix bugs and improve stability.

We do not sell your personal information, and we do not use third-party advertising trackers. We do not knowingly collect precise GPS location.

c. Information from sign-in providers

If you sign in with Apple or Google, we receive a verified identity token and your email (and, with Apple, optionally your name) so we can create your account. We do not receive your social account password.


2. Sensitive information and content about others

Case descriptions and follow-up answers are free text and may contain sensitive personal information — about your relationships, family, health, sexual matters, or beliefs — about you and about other people you describe.

  • We process this content only to generate the AI fault analysis and to operate the features you use (e.g. publishing a post you choose to publish).
  • Under PIPA, sensitive information (민감정보) requires your separate, explicit consent; you provide this in-app before submitting a case. You can withdraw consent by deleting the case or your account.
  • Content about other people: You are responsible for the content you submit. Do not include real names, photos, contact details, or other information that identifies a non-consenting third party. We provide labels (e.g. "A" / "B") so cases can be described without identifying anyone. We may remove content that exposes others.

3. How we use your information

We use personal information to:

  • create and secure your account and authenticate you;
  • generate the AI fault analysis, follow-up questions, and intervention steps for your case;
  • publish posts, record votes, and display community results when you choose to post;
  • power comments, likes, reporting, and blocking;
  • send notifications you've enabled and respond to support requests;
  • detect, prevent, and act on abuse, spam, fraud, and policy violations;
  • comply with legal obligations and enforce our Terms.

Legal bases (where required, e.g. PIPA/GDPR-style frameworks): performance of our contract with you (providing the App); your consent (sensitive case content, push notifications, marketing); and our legitimate interests / legal obligations (security, abuse prevention, compliance).


4. Who we share it with (processors & sub-processors)

We share data only with service providers who process it on our behalf under contract, and only as needed to run the App. Key sub-processors:

Provider Role Data involved
Supabase Database, authentication, realtime, storage Account, profile, case content, posts, votes, comments.
Microsoft Azure (Azure Container Apps + Azure AI Foundry) Backend hosting and AI processing of case content Case description + follow-up answers sent to generate the verdict; server log/diagnostic data.
Apple / Google Sign-in, app distribution, in-app purchases (if enabled) Authentication tokens; purchase/billing handled by the store.
Expo Push notification delivery Push token, notification payloads.
Zapier Workflow automation — routes in-app feedback and content reports to our support inbox Feedback messages and moderation reports (reason, content identifiers, optional details) plus basic device/app diagnostics.

About AI processing: when you create a case, your description and answers are sent to Azure AI Foundry to produce the analysis. Confirm and disclose the provider's data- retention terms here — i.e. whether prompts are retained and whether they are used to train models. ToldU configures the service for no model training on your content; state your final configuration before publishing.

We may also disclose information when required by law, to enforce our Terms, to protect the rights or safety of users or the public, or in connection with a merger or acquisition (with notice where required).


5. International data transfers

We are based in Washington, USA, and use providers that may process data in the United States and other countries. If you are in Korea, your personal information — including case content — is transferred to and processed in the United States and other countries where our providers operate. We obtain your consent to this cross-border transfer in-app as required by PIPA, and we identify the recipient countries, the data transferred, and the purpose at the point of collection.


6. Data retention

We keep personal information only as long as needed for the purposes above:

  • Account data — until you delete your account.
  • Published posts/comments/votes — until you delete them or your account; note that deleting your account removes your content from public view, but aggregate vote tallies already counted may persist in anonymized form.
  • Case content not published — retained while your account is active; deleted when you delete the case or account.
  • Logs/diagnostics — a limited period for security and debugging, then deleted or anonymized.
  • We may retain limited records longer where required by law (e.g. tax, dispute records).

7. Your rights

Depending on where you live, you have the right to:

  • access the personal information we hold about you;
  • correct inaccurate information;
  • delete your information ("right to erasure" / 삭제 요구권);
  • object to or restrict certain processing, and withdraw consent at any time;
  • port your data to another service;
  • not be discriminated against for exercising your rights (CCPA).

In-app account deletion: You can delete your account and associated data from within the App (Settings → Delete account). This also satisfies Apple's and Google's account- deletion requirements.

To exercise other rights, contact privacy@toldu.ink. We will respond within the time required by applicable law (e.g. 45 days under CCPA; PIPA timelines for Korean users). You also have the right to lodge a complaint with your data protection authority — in Korea, the Personal Information Protection Commission (개인정보보호위원회) / KISA (privacy.kr); in California, the California Privacy Protection Agency.

We do not sell or "share" (for cross-context behavioral advertising) your personal information as those terms are defined under the CCPA.


8. Children's privacy

The App is intended for users aged 13 and older. We do not knowingly collect personal information from children below the applicable age of digital consent. If you believe a child has provided us information, contact privacy@toldu.ink and we will delete it. (If you set 13 below 18 in any region, additional children's-privacy obligations apply — confirm with counsel.)


9. Security

We protect your information with industry-standard measures: encryption in transit (HTTPS/TLS), encryption at rest at our providers, row-level security so users can only access their own private data, hashed passwords, and least-privilege access to production systems. No system is perfectly secure; we cannot guarantee absolute security, but we will notify you and the relevant authorities of a breach where the law requires.


10. Changes to this policy

We may update this Privacy Policy. When we make material changes we will update the effective date and notify you in-app or by email where appropriate. Continued use of the App after changes take effect means you accept the updated policy.


11. Contact us

Questions or requests about privacy:

  • Email: privacy@toldu.ink
  • Privacy Officer (개인정보 보호책임자): Kipack Jeong
  • Mail: DevIt, 11762 Hartford Way, Mukilteo WA 98275, USA

This document is a template generated from ToldU's actual data practices and is not legal advice. Have it reviewed by qualified US and Korean counsel before publishing.