Privacy Policy
Effective: August 3, 2026 · Last Updated: August 3, 2026
1. Overview and Controller
ROA (the “Company”) operates TalkDa (the “Service”) and processes personal information in accordance with applicable laws, including Korea’s Personal Information Protection Act.
- Company: ROA
- Representative: Kim Jeong-se
- Business registration number: 142-09-74925
- Mail-order report number: 2025-용인기흥-02392
- Address: 507-1101, 214 Sinbong 1-ro, Suji-gu, Yongin-si, Gyeonggi-do, Republic of Korea
- Email: roameta2014@gmail.com
- Phone: 050-5008-1428
Related: Terms · Refund Policy · Payment
2. Purposes of Processing
- Account management (email/password or Google/Kakao social login, agreement records, deletion)
- Child profile management
- Personality assessment and documents
- Parenting diaries and observation summaries
- AI parenting consultation and summaries
- AI features (response generation and search/context indexes)
- Service credits (Echo, Lumi, Core)
- Payment / paid-feature integration
- Feedback and support
- Operations (analytics, security, language preference)
- Marketing (only if consented)
3. Categories of Personal Information Processed
Depending on the features you use, the Company may process the following personal information. Items for unused features may not be created.
3.1 Sign-up and login
- Email sign-up: username, email, password (stored with one-way encryption)
- Google/Kakao social login: account identifier, verified email, signup path; display name may be used when creating an account
- Agreement records: Terms/Privacy/medical-notice versions and timestamps; marketing consent
3.2 Child profile and related content
- Child name/label, birth date (optional), gender, tendency documents/summaries
- Assessment answers/results, parent subjective answers, AI follow-up Q&A
- Reports, parenting diaries, observation summaries, consultation messages and summaries
3.3 Feedback
- Submitted feedback fields and handling status
3.4 Payments and credits
- Product type, amount/currency, status, provider, transaction/order identifiers, paid/cancelled/refunded times
- Echo/Lumi/Core balances and expiry; Echo event grants
- The Company does not store full card numbers or CVC; payment details are handled on the Paddle checkout page
3.5 Automatically collected data
- Service usage records (event type, time, path), masked IP address, browser/OS and similar connection environment information
- Login session, security cookies to help prevent forged requests, language cookie, temporary social-login state, temporary AI/consultation chat state
3.6 Other data that may be stored
- If general diary or diet features are used: diary content, diet profile, weight/meal records
- Index data used for AI search and context (diary/profile/child-tendency text and related information)
4. Retention Period
- In principle, personal information is retained until account deletion.
- Upon account deletion: deleting the account removes linked database records (profiles, assessments, diaries, consultations, feedback, payment orders, activity events, credit balances). Echo/Lumi/Core balances are forfeited.
- Index data for AI search and context: may remain for a period after original data is deleted due to technical processing.
- Paddle-side records: payment, receipt, tax, and refund records held by Paddle follow Paddle’s policies and applicable law.
- Legal retention: information required by law, or involved in investigations, may be retained for the required period.
- Sessions/cookies: end on expiry/logout/browser deletion; language cookie may last up to about one year.
- Personal information may temporarily remain in system backups.
5. Provision to Third Parties
Except with the user’s consent or as required by law, the Company does not provide personal information to third parties. Matters related to external AI processing, social login, and the payment provider are described in Sections 6 through 8.
6. External AI Processing
The Company uses the OpenAI API to provide AI features such as consultation, tendency documents/reports, and summaries. User-entered content, child-related content, and conversation/summary/tendency text needed for those features may be processed. Cross-border transfer details are set out in Section 7.
7. Cross-Border Transfer
The Company may transfer personal information outside Korea as follows.
7.1 OpenAI
- Recipient: OpenAI
- Data: input needed when using AI consultation, tendency documents, summaries, and similar features
- Purpose: generating AI responses
- Timing/method: transmitted via API when the relevant AI feature is used
- Refusal: you may refuse by not using AI features; those AI features will then be unavailable
- Contact: privacy officer in Section 14
7.2 Paddle
- Recipient: Paddle
- Data: member identifier, product type, information needed for payment linking, and email if available. Card numbers and CVC are not stored or sent by Company servers.
- Purpose: paid product/subscription payment integration and granting service credits based on payment results
- Timing/method: when using the checkout page and through payment-completion notifications
- Policy: Paddle Privacy Policy
- Refusal: you may refuse related transfers by not making payments; paid purchases will then be unavailable
8. Payment Provider (Paddle)
Paddle handles payment, tax processing, receipts, subscriptions, and refunds for paid products. Payment-card details such as card number and CVC are processed directly on the Paddle checkout page. The Company exchanges with Paddle the transaction information needed to confirm payment results and deliver purchased products/credits. Personal information that Paddle collects and processes directly is governed by the Paddle Privacy Policy. Cross-border transfer details are set out in Section 7.
9. Child-Related Information
The Service processes child-related information entered by users (e.g., guardians). Users must enter such information only with appropriate authority.
Age and consent requirements follow applicable law, this Policy, and the Terms of Service.
Access/correction/deletion may be requested via in-product features or the privacy officer in Section 14.
10. Cookies and Sessions
- Sessions/cookies are used for login and security as needed.
- A language cookie may last up to about one year.
- Rejecting cookies may limit login and related features.
11. Your Rights
- You may request access, correction, deletion, or suspension of processing.
- Where available, use in-product account/child/diary/consultation features.
- Account deletion follows Section 4 and the deletion screens.
- Contact the privacy officer in Section 14.
12. Destruction of Personal Information
- Unnecessary personal information is deleted without undue delay.
- Account deletion removes linked records in the Service database.
- Electronic records are deleted in a manner that makes recovery reasonably impracticable.
- Handling and deletion of index data follow Section 4.
13. Security Measures
- One-way encrypted storage of passwords and similar credentials
- Access control by login/authorization and staff/admin separation
- HTTPS and secure cookie settings in production
- IP address masking and minimization for activity logs
- No direct storage of card numbers or CVC on Company servers
14. Personal Information Protection Officer
- Privacy officer: Kim Jeong-se
- Email: roameta2014@gmail.com
- Phone: 050-5008-1428
15. Changes to This Policy
Changes will be posted on this page or via in-service notice. This Policy applies from August 3, 2026.