← Chaeon Studio

DearMI

Privacy Policy

Last updated: June 15, 2026 · Effective: June 22, 2026

At a glance DearMI helps users manage psychiatry and counseling appointments. Health information you enter is treated as sensitive data, encrypted with AES-256-GCM at the column level, and is never shared with third parties except for prescription OCR processing (image) and drug-information lookups (drug name only). Your data is permanently deleted within 30 days of account deletion.

Article 1 (Purpose)

Chaeon Studio (the "Company") establishes this Privacy Policy (the "Policy") to protect the personal information of users (the "Users") of the DearMI service (the "Services"), to comply with the Personal Information Protection Act of Korea, the Act on Promotion of Information and Communications Network Utilization and Information Protection (the "Network Act"), and other applicable laws, and to promptly address User concerns regarding the protection of personal information.

Article 2 (Principles of Processing)

In accordance with applicable laws and this Policy, the Company may collect Users' personal information. Collected personal information may only be provided to third parties with the User's consent, except where lawfully compelled by statute.

Article 3 (Disclosure of this Policy)

① The Company discloses this Policy through the in-app "My Page > Terms & Policies" menu and via the Company's website so Users can review it at any time.

② The Company uses appropriate font sizes and colors to make the Policy easy to read.

Article 4 (Amendments)

① This Policy may be amended in response to changes in applicable laws or the Company's service policies.

② The Company will give notice of amendments by one or more of the following methods: a. In-app announcements or dedicated screens b. Notification by email or push notification

③ Notice will be given at least 7 days before the effective date. For material changes affecting User rights, at least 30 days in advance.

Article 5 (Personal Information We Collect)

The Company collects the following categories of personal information.

① Account registration and identification (required) - Email address, name, and unique identifier (sub) received from the social login provider (Google / Apple) - Apple Private Relay address when the User chooses to hide their email

② Information you enter while using the Services (required, includes sensitive health data) - Appointments: hospital name, scheduled date, notes - Counseling records: free-text content, tags, mood scores you write - Prescription images and OCR results (hospital name, prescribed date, drug name, dosage/strength, dose per intake, directions, number of days) - Medication schedules and intake history - Mood check-ins and daily notes - Pre-appointment prep notes

③ Payment and subscription information (when purchasing paid plans) - iOS: App Store IAP receipt and originalTransactionId - Android: Google Play purchase token, or Toss Payments transaction key - The Company does not directly store card numbers, CVCs, or other primary payment credentials.

④ Automatically collected information (required) - Device push notification token (Expo Push Token) - App version, OS, language setting, time zone - Service usage logs (API call timestamps, error logs) and IP address

Article 6 (Methods of Collection)

The Company collects personal information by the following methods.

① Automatically received from the OAuth provider (Google / Apple) at sign-up ② Directly entered by the User in app screens ③ Uploaded by the User via camera or photo library (e.g., prescription images) ④ Generated and collected automatically during service use (push registration, app launches, etc.)

Article 7 (Purposes of Use)

The Company uses collected personal information only for the following purposes.

① User identification and prevention of fraudulent registration ② Provision of core service features (appointment records, medication management, etc.) ③ Prescription image OCR analysis (Google Gemini API — the uploaded prescription image is transmitted for text recognition) ④ Drug information lookup (Korea: Ministry of Food and Drug Safety "Drug Product Approval Information" public API / United States: U.S. FDA OpenFDA Drug Label API and U.S. NLM RxNorm drug-name normalization API — only the drug name is transmitted) ⑤ Push notifications for appointments, medication, and check-ins (Expo Push Service) ⑥ Paid subscription payment processing and receipt verification ⑦ User support and dispute resolution ⑧ Statistical analysis for service improvement (only in non-identifiable form) ⑨ Response to violations of applicable laws or these Terms

Article 8 (Delegation of Processing)

For smooth service delivery, the Company delegates the processing of personal information as follows. Upon termination of the delegation contract or upon account deletion, the relevant information is destroyed without delay or recovered from the processor.

Article 9 (Transfer of Personal Information Overseas)

The Company transfers personal information overseas to the U.S.-based processors listed in Article 8.

Items transferred: The minimum items from Article 5 necessary to perform the relevant delegated work Country / time / method: United States / at the time of service use / over an encrypted network (TLS 1.2+) Recipients: Amazon Web Services Inc., Google LLC, Expo (650 Industries Inc.), Apple Inc., U.S. National Library of Medicine (NLM), U.S. Food and Drug Administration (FDA) Purpose and retention period: Until the purposes described in Article 7 are achieved, or until account deletion

By agreeing to this Policy at sign-up, the User consents to the overseas transfer described above. The User has the right to refuse, but refusal will prevent use of the core features of the Services.

Article 10 (Retention and Use Period)

① The Company retains personal information until the purposes of collection and use are achieved or until the User deletes their account.

② Upon account deletion, personal information is immediately soft-deleted and is permanently destroyed from databases and S3 storage within 30 days (cannot be recovered).

③ However, records of abusive use may be retained for up to one year after account deletion to prevent fraudulent re-registration.

Article 11 (Retention Required by Law)

The Company retains personal information as required by the following Korean statutes.

① Act on the Consumer Protection in Electronic Commerce, Etc. - Records on contracts or withdrawal of subscriptions: 5 years - Records on payment and supply of goods/services: 5 years - Records on consumer complaints or dispute resolution: 3 years - Records on display and advertising: 6 months ② Protection of Communications Secrets Act: Website log records — 3 months ③ Electronic Financial Transactions Act: Records on electronic financial transactions — 5 years

Article 12 (Destruction Procedure and Method)

① Personal information whose retention period has expired or whose processing purpose has been achieved is destroyed without delay.

② Information stored in electronic file form is permanently deleted using methods that prevent recovery; paper documents are destroyed by shredding or incineration.

Article 13 (User Rights)

Users and their legal representatives may at any time exercise the following rights.

① Right to access and correct — directly available within the app ② Right to deletion — processed immediately via "Delete Account" in My Page ③ Right to restrict processing — request via chaeon.studio@gmail.com ④ Right to data portability — Premium Plan users can export their own data as PDF

Article 14 (Children Under 14)

The Company does not collect personal information from children under 14 and permits account registration only for users aged 14 or older. Any account identified as belonging to a child under 14 is deleted immediately.

Article 15 (Security Safeguards)

The Company implements the following technical and administrative safeguards to ensure the security of personal information.

① Technical safeguards - Sensitive data such as counseling records is encrypted at the database column level using AES-256-GCM - Password-less authentication via OAuth (social login only) - JWT-based authentication; refresh tokens are stored as SHA-256 hashes and rotated on each use - All communication uses HTTPS (TLS 1.2 or above) - Images stored in S3 use SSE-S3 server-side encryption and are accessible only via Presigned URLs (15-minute expiry) - Intrusion prevention systems and regular security audits

② Administrative safeguards - Minimization of personnel handling personal information and strict access control - Regular audits of delegated processors - Privacy and security training for staff

Article 16 (Automatic Collection Devices)

The Services are provided through a mobile application and do not use web cookies. Device push tokens are collected to deliver push notifications and can be disabled at any time via OS settings or in-app notification settings.

Article 17 (Response to Data Breach)

Upon becoming aware of any loss, theft, or leakage of personal information, the Company will, without delay, notify affected Users of the following and report the incident to the Personal Information Protection Commission or the Korea Internet & Security Agency as required by the Personal Information Protection Act.

① Items of personal information affected ② Time and circumstances of the leakage ③ Actions the User can take ④ The Company's response measures ⑤ Contact for further consultation

Article 18 (Personal Information Protection Officer)

The Company designates the following Personal Information Protection Officer to oversee all matters relating to personal information processing and to handle related complaints.

Personal Information Protection Officer - Organization: Chaeon Studio - Email: chaeon.studio@gmail.com

Article 19 (Remedies for Infringement of Rights)

Data subjects may apply for dispute resolution or consultation with the following bodies for relief from personal information infringement.

Addendum

This Policy was established on May 22, 2026, and the amended version takes effect on June 22, 2026.