Privacy Policy

Effective date: 2026-08-14

TEMPO (the “Service”) complies with applicable data protection laws, including Korea’s Personal Information Protection Act (PIPA), and maintains this Privacy Policy to protect users’ personal data. The Service is built on the principles of data minimization and on-device processing first: autocomplete, next-word prediction, and writing-style learning are processed on your device. However, if keyboard learning and conversation history are enabled and you use reply suggestions, the recent sent-reply pairs described below may be transmitted temporarily to refresh a room-specific reply-behavior profile. The Service shows ads on some in-app screens using the Kakao AdFit advertising SDK. Your conversations and typed input are never collected, used, or shared for advertising purposes.

1. Personal data we process and how we collect it

The Service can be used without creating an account, and using the app requires no identifying information such as your name, email, phone number, or contacts. The single exception is your email address, if you choose to sign up for an iOS launch notice on our website (section C below); if you do not sign up, no email is collected. We process the following.

A. Data sent to and processed on our servers

  • AI feature input and conversation context: When you actively trigger reply suggestions, translation, AI chat, or compose, the relevant input and conversation context are processed. If keyboard learning and conversation history are enabled, up to 24 recent context-and-reply pairs that you actually sent may also be transmitted at low frequency and compressed into a room-specific behavior profile containing only fixed categories, not names, topics, or quotations. This refresh runs asynchronously so it does not delay the current suggestion. Sensitive patterns are masked before transmission, and the data is used only for response generation and personalization and is not stored by default.
  • Anonymous usage statistics (always active): Aggregate numeric events containing no input content (e.g., feature usage counts, suggestion acceptance), an anonymous install identifier (installId), and the app version. They do not reveal who typed what.
  • Anonymous analytics and stability diagnostics (Google Firebase, always active): We use Google Firebase (Analytics and Crashlytics) for product improvement and stability analysis. The following is sent to Google: usage events containing no input content, an app-instance identifier, device model, OS version, app version, approximate location (country level), and crash diagnostics. We do not send the advertising identifier (AAID) or ad-personalization signals to Firebase.
  • Advertising performance measurement (Meta, always active): To verify whether our advertising actually leads to installs and subscriptions, we use the Meta (Facebook) SDK. The advertising identifier (AAID), device model, OS version, and app version are sent to Meta along with app install/launch and designated conversion events (keyboard activation, paywall view, checkout started, subscription completed and its amount). Your typed input and conversation context are never included by any path. You can reset the advertising identifier or opt out of ad personalization at any time under Android Settings → Ads.
  • Ad delivery data (free tier): When you open an in-app screen that contains an ad, the Kakao AdFit SDK requests an ad and sends Kakao the device's advertising identifier (AAID), device information (model, OS version, screen size), network connection information, app version, approximate location (country level), and ad impression/click events. Your typed input and conversation context are never included in an ad request. No ad request is made while a Premium subscription is active.
  • Install source information (always active): To understand how you found the app and improve our guidance, we collect once on first launch the install source that Google Play provides (labels contained in the marketing link, such as a campaign name) along with click and install timestamps. It contains no personally identifying information and no input content.
  • AI improvement training data (only with separate consent): Only if you opt in, we collect pseudonymized pairs of accepted reply suggestions, autocomplete/next-word suggestions, spelling auto-corrections, and translations (source and result) to improve quality and our models. In addition to client-side masking, a second server-side de-identification removes emails, phone numbers, and similar. This is off by default.
  • Push notification registration token: To send service announcements, subscription status updates, and (if you consent) promotional messages, we store the registration token issued to your device by Google Firebase Cloud Messaging, along with your notification consent status, app version, language, and time zone. The token does not identify you and becomes invalid when you uninstall the app. Turning notifications off in the app or requesting data deletion removes it from our servers immediately.
  • Consent records: We log the fact of granting/withdrawing consent for training data (install identifier, consent item, status, timestamp) for legal evidence.

B. Data primarily stored on your device

  • Conversation history and accessibility/notification capture text: If you turn on the Accessibility Service or notification access, the Service reads on-screen or notification conversation text to improve reply accuracy. It never reads financial apps (banking, payment, wallet) or password fields. Captured text is masked and stored on your device. If keyboard learning and conversation history are enabled and you use reply suggestions, only the recent sent-reply pairs described in section A may be transmitted temporarily to refresh the behavior profile.
  • Writing-style data: Samples such as your recent sent messages, used to mimic your tone.
  • Word-learning data: Word/phrase frequency (unigrams/bigrams) for autocomplete.
  • Clipboard history: Recent copied items for smart input assistance (up to 20).
Items under (B) are stored on your device only when you enable the related feature (history saving, accessibility, notifications). Except for the minimum reply pairs used for the behavior-profile refresh described in section A, raw history is not sent to servers. It is deleted when you uninstall the app or reset it in-app.

C. Information you provide on our website

  • Email address for the iOS launch notice (only if you sign up): The Service is currently available on Android only. If you enter your email address on our website's waitlist and consent to its collection and use, we store that address along with the referral markers indicating which marketing link brought you and a coarse device category (Android/iOS). The sole purpose is a single iOS launch notice; we do not use it for any other advertising or marketing. Consent is optional, and declining has no effect on your use of the app.

D. Information recorded automatically when you visit our website

  • Visit records (no content): When you open a page on our website we record which page it was, how far you scrolled, a coarse device category (Android/iOS/desktop) and whether it was an in-app browser, and how you arrived (the markers contained in a marketing link, and the site that linked to us). The purpose is aggregate analysis of which pages are actually read so we can improve them.
  • Coarse location (country and first-level region only): Alongside the visit record above, we record where the visit came from only down to the country and its first-level administrative region. The purpose is aggregate analysis of whether our announcements reach the intended regions and whether automated (non-human) traffic is mixed in. This value is derived by our web server from the connection and passed to us; we do not store the IP address itself. We do not collect your city, street address, or GPS location, and we do not use your device's location permission.
Section (D) involves no cookies, no login data, and no identifier that distinguishes one visitor from another. These records therefore yield visit counts only: they cannot identify you or link your visits together, and they contain nothing you typed.

2. Purposes of processing

  • Generating responses for features you request (reply suggestions, translation, chat, compose)
  • Analyzing usability and stability and improving quality (anonymous statistics)
  • Improving AI models and response quality (training data, only with consent)
  • Sending subscription status updates and service announcements (push notifications)
  • Sending promotional messages such as events and offers (only with separate consent; never between 21:00 and 08:00 KST)
  • Sending a single iOS launch notice (only if you signed up for the waitlist)

We do not use personal data for any other purpose. We never use your input or conversations for advertising or marketing, and promotional messages are sent only to users who separately opted in and can be withdrawn at any time in the app settings.

3. Retention and destruction

  • AI feature input: Processed only to generate a response; not stored separately by default.
  • Anonymous usage statistics: Retained for 12 months from collection, then destroyed or de-identified.
  • AI improvement training data: Retained until you withdraw consent or request deletion; destroyed without delay upon such request.
  • Push notification registration token: Retained until you turn notifications off or request data deletion. Once a device reports the token as expired, it is excluded from delivery immediately.
  • On-device data: Kept on your device until you delete it or uninstall the app, at which point it is removed.
  • iOS waitlist email: Destroyed immediately after the launch notice is sent. If no launch occurs, it is destroyed 12 months after collection; if you request deletion earlier, it is destroyed without delay.
  • Website visit records and coarse location: Retained for 12 months from collection, then destroyed. Because they carry no identifier distinguishing one visitor from another, an individual deletion request cannot be matched to specific rows; the records are destroyed in bulk when the retention period elapses.

Destruction procedure: Personal data whose retention period has elapsed or whose purpose has been fulfilled is destroyed without delay; electronic files are permanently erased by irrecoverable means.

4. Provision to third parties

We do not provide users’ personal data to third parties, except where specifically required by law or requested by investigative authorities under legally prescribed procedures.

5. Processing consignment and overseas transfer

To generate AI responses and to show ads, we entrust processing as below, and data may be transferred overseas in the process.

ProcessorEntrusted workTransferred itemsDestination
Google LLC (Google Gemini API)AI response generation (reply, translation, chat, compose)Input/conversation context at feature run (masked), anonymous install identifierUnited States
Google LLC (Firebase Analytics)Anonymous usage statistics and product-improvement analysisUsage events (no content), app-instance identifier, device model, OS version, app version, approximate location (country)United States
Google LLC (Firebase Crashlytics)Crash and stability diagnosticsCrash logs, device state (model, OS, memory, etc.), app version, diagnostic identifierUnited States
Kakao Corp. (Kakao AdFit)Serving in-app ads and measuring impressions/clicksAdvertising identifier (AAID), device information (model, OS version, screen size), network connection information, app version, approximate location (country), ad impression/click eventsRepublic of Korea
Meta Platforms, Inc. (Facebook SDK)Measuring install and conversion performance of our advertising (ad attribution)Advertising identifier (AAID), device information (model, OS version), app version, app install/launch and designated conversion events (keyboard activation, paywall view, checkout started, subscription completed and its amount)United States
When and how: AI features are transmitted over HTTPS when you run a feature; if keyboard learning and conversation history are enabled, the reply-behavior profile may refresh asynchronously after reply-suggestion use. Ads are requested when you open a screen containing an ad, and Firebase analytics/diagnostics and Meta ad-attribution events are transmitted when the corresponding event occurs. Firebase does not collect AAID or ad-personalization signals. Meta receives only AAID and the conversion events listed above; conversations and typed input are never included. Ad requests never include conversations or input, and no ad request is made while Premium is active.

6. Automatically collected identifier (installId)

For cost accounting and anonymous statistics, the Service generates a random install identifier (installId) once on first launch, stores it on the device, and sends it with server requests. It does not identify a specific individual and is not combined with contacts or advertising identifiers. For analytics and diagnostics, an app-instance identifier generated by Google Firebase is also used; it likewise is not combined with advertising identifiers and is reset when you uninstall the app. Uninstalling the app deletes the installId; reinstalling creates a new value. The Service does not use web cookies. To serve ads, Kakao AdFit uses the device's advertising identifier (AAID); Meta uses it to measure advertising performance. It is not combined with the installId or the app-instance identifier. You can reset the advertising identifier or opt out of ad personalization at any time under Android Settings → Ads.

7. Your rights and how to exercise them

You may at any time request access to, correction of, deletion of, or suspension of processing of your personal data.

  • Withdraw consent: Consent for AI improvement training data can be toggled in settings at any time; turning it off stops that collection immediately. Anonymous usage statistics are collected continuously for product analysis and stability diagnostics.
  • Delete training data: Turning off training data provision lets you request deletion of such data collected on the server.
  • Delete on-device data: Conversation history, style, word, and clipboard learning data can be deleted by resetting in-app or uninstalling.
  • Other access/correction/deletion/suspension requests can be submitted to the protection officer below, and we will act without delay.

8. Security measures

  • Encryption in transit (HTTPS)
  • Masking of sensitive data before transmission/storage and pseudonymization/de-identification of training data
  • On-device storage encryption (provided by the operating system)
  • Exclusion of sensitive screens such as financial apps and password fields
  • Minimization of access privileges to personal data

9. Personal data protection officer

The Service designates a protection officer to oversee personal data processing and handle user inquiries and complaints.

  • Protection officer: SeoJean Han / Representative
  • Contact (email): keyboardai.support@gmail.com

10. Remedies for infringement

If you need counseling or dispute mediation regarding personal data infringement, you may contact the following Korean agencies.

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
  • Privacy Infringement Report Center (KISA): 118 / privacy.kisa.or.kr
  • Supreme Prosecutors’ Office Cyber Investigation: 1301
  • National Police Agency Cyber Bureau: 182

11. Children under 14

The Service is intended for users aged 14 and over and does not knowingly collect personal data from children under 14.

12. Changes to this policy

This policy may be revised due to changes in law or the Service; changes and their effective date will be announced on this page.

13. Business information and contact

  • Representative: SeoJean Han
  • Email: keyboardai.support@gmail.com
개인정보처리방침 — TEMPO