Moji Privacy Policy
Effective date: 3 September 2026
w3company co.,ltd. ("the Company") protects users' personal data in accordance with the Personal Information Protection Act of the Republic of Korea and other applicable law. This Policy explains how the Company collects, uses, stores and destroys personal data in the Moji service ("the Service").
Article 1 (Personal data we collect and how)
| Category | When collected | Items | Required |
|---|---|---|---|
| Registration | On sign-up | Mobile number, date of birth, gender, country | Required |
| Profile | On profile creation | Name or nickname, profile photograph, self-introduction | Required |
| Additional profile | On profile creation | Interests, languages spoken, languages being learned, occupation, education | Optional |
| Messages and attachments | On sending a message | Text, photographs, voice messages, attachments, recipient identifier | Required |
| Call records | On using calls | Call time, duration, connection information (call content is not collected) | Required |
| Payment | On purchasing a Paid Service | Payment method type, authorisation number, purchase history | Required |
| Enquiries | On contacting us or reporting | Content of the enquiry, contact details, outcome | Required |
| Survey responses | On taking part | Responses | Optional |
Collection methods: direct entry by the user; automatic generation during use (Article 2); and receipt from partners or payment providers.
Where a user mistakenly enters a national identification number, passport number or driving licence number, the Company deletes it irrecoverably as soon as it becomes aware and informs the user. The Company does not collect unique identification numbers.
Article 2 (Data collected automatically)
| Item | Detail |
|---|---|
| Access logs | Access time, IP address, usage records, time spent |
| Device information | Device model, operating system and version, app version, language setting, device time zone |
| Advertising identifier | ADID (Android), IDFA (iOS) - only where the user has consented |
| Error logs | Crash reports, diagnostics · device sensor readings = during face verification the Company may read accelerometer and gyroscope values to confirm that a real person is holding the device, used only for that check and not retained |
| Approximate location | Country and city inferred from IP address |
Article 3 (Sensitive data)
- The Company processes the following sensitive data only with the user's separate consent. Declining does not restrict use of the basic Service.
When collected Purpose Item Basis On Face Verification Identity and liveness confirmation Live-captured face image PIPA Article 23 On profile creation (optional) Interest-based recommendation Religion, belief PIPA Article 23 - The Company does not collect political opinions, trade union membership, health data, genetic data or criminal records.
- Sensitive data is not used for advertising or marketing and is not sold to any third party.
- Consent may be withdrawn at any time; the data is then destroyed without delay.
Article 4 (Purposes of processing)
Registration and identity confirmation; performing the service agreement; displaying profiles and providing recommendations and matching; messaging, calls, translation and map-based discovery; detecting and blocking fraudulent accounts, spam, impersonated profiles and unlawful or harmful content; payment, settlement and refunds; handling enquiries, reports and disputes; improving the Service and developing new features; displaying advertising (Article 8); and complying with legal obligations.
Article 5 (AI features and automated decisions)
- The Company uses automated analysis for:
Feature What is assessed Effect on the user Recommendations Profile, interests and usage patterns determine display order Which members you see changes Translation The language of a message is converted None Safety checks Whether content indicates fraud, spam, impersonation, or unlawful or harmful material Warning, content removal, repeat Face Verification, feature restriction, account suspension - A permanent account suspension is never confirmed on the basis of an automated determination alone; a member of staff carries out the final review.
- Under Article 37-2 of the Personal Information Protection Act, users have the right to (a) an explanation of the criteria and procedure of an automated decision and (b) request human re-review.
- Requests may be made in settings or to [email protected]. The Company responds within 10 days, with reasons, as required by Articles 35 and 36 of the Personal Information Protection Act and Articles 41 and 43 of its Enforcement Decree.
- Safety checks do not involve a person reading individual conversations. Where a report is received or a detection occurs, staff may review material to the minimum extent needed to decide.
- A detailed explanation of the criteria used in automated decisions is published in this Policy and in the in-service guidance. This Policy sets out the rights and the channels for exercising them.
- Messages are not end-to-end encrypted, in order to allow the safety functions above. Data is protected by TLS 1.2+ in transit and AES-256 at rest.
Article 6 (Face data - biometric data)
The Company operates Face Verification to prevent fraudulent accounts and profile impersonation. Face data is sensitive data under Article 23 of the Personal Information Protection Act and is handled as follows.
(1) What we collect - a live-captured image or video of the user's face. The Company does not currently retain facial geometry data; what it retains is the face image. Should the Company come to retain facial geometry data, it will state that fact and the retention period in this Policy in advance and obtain the user's separate consent before doing so. The Company protects that image to the standard applied to sensitive data for biometric data and obtains separate consent.
(2) When - when the user seeks a verification badge; when an impersonation report is received; when the primary profile photograph is changed; or when a safety check indicates further verification is needed.
(3) Purpose - (a) identity confirmation, by comparing the live capture with the registered profile photograph; and (b) liveness confirmation, to detect a stolen or synthetic image. Face data is also used to prevent fraud, impersonation and re-registration, to respond to user reports and disputes, and to improve the accuracy of safety functions. Where the Company wishes to use it for any other purpose, it obtains the user's separate consent. The Company does not sell face data to any third party.
(4) Consent - before collecting face data the Company informs the user of the items collected, the purpose, the retention period and the method of destruction. The Company does not derive or store a feature value from the face image, so the image is not biometric identification data under Article 18(3) of the Enforcement Decree of the Personal Information Protection Act. The basis for processing is Article 15(1)(4) of that Act (performance of a contract), and the notice is given within the personal data consent at sign-up. The Company nonetheless protects face images to the standard applied to biometric data. Declining does not restrict use of the basic Service.
(5) Processor and transfer
| Processor | Task | Country |
|---|---|---|
| Amazon Web Services, Inc. (Amazon Rekognition) | Face comparison and liveness computation | United States |
The Company discloses face data to no third party other than the above and does not sell, lease or trade it.
(6) Retention and destruction
| Data | Retention |
|---|---|
| Live-captured image or video | Retained until the member withdraws from the Service or withdraws consent to Face Verification, and destroyed without delay at that point · destroyed without delay on a member request · where retention is necessary to prevent fraud, impersonation or re-registration, to respond to a dispute, or to comply with a request for cooperation from an investigating authority, in no case is it retained longer than 3 years after the member's last interaction with the Service, regardless of where the member lives |
| Facial geometry data | Not retained. Where a feature value is generated during the comparison it is discarded immediately · should the Company come to retain it, that fact and the retention period are stated in this Policy in advance and separate consent is obtained first |
| Irreversibly transformed identifier of an account restricted for fraud or impersonation (no face image, no verification document) | Up to 15 years, depending on the seriousness of the harm · used only to prevent re-registration and protect users |
| Verification outcome and audit record | 1 year • contains no face image and no facial geometry data |
| Members resident in Illinois, Texas and Washington | Article 18(2)(b) takes precedence |
The Company deletes face data irrecoverably once these periods expire, including where the user has terminated their account.
The table above applies equally to face data collected before this Policy takes effect. Face data collected before the effective date is also destroyed without delay on a member request.
(7) Security - TLS 1.2+ in transit, AES-256 at rest, access limited to verification staff, and access logging retained and monitored.
(8) Your rights and re-consent - a user may decline Face Verification and may withdraw consent at any time, in which case stored face data is destroyed without delay. Users who completed Face Verification before this Policy takes effect will be asked to consent again on the effective date. If a user does not consent within 30 days of that request, the Company destroys that user's face data and withdraws the verification badge. Where one of the second to fourth grounds in (2) exists, use of the Service may be restricted until that ground is resolved.
(9) Illinois, Texas and Washington residents - Article 18(2)(b) takes precedence.
Article 7 (Location data)
- With the user's consent, the Company collects location data for map-based discovery, nearby-member recommendations and the prevention of misuse.
- The conditions and procedures for using location-based features are governed by Article 11-2 of the Moji Terms of Service. The matters the Location Information Act requires this Policy to contain are as follows: purpose of processing personal location data - map-based discovery, nearby-member recommendations and the prevention of misuse; retention of personal location data - (1) values used for map-based discovery and nearby-member recommendations are retained until the user stops using location-based features or withdraws consent, and are destroyed without delay at that point; (2) values used to prevent misuse are retained while the account remains active, and are destroyed without delay when the user deletes the account or withdraws consent to the use of location data; (3) where otherwise necessary to provide location-based features, the data may be retained for the minimum period necessary to achieve the purpose of use; (4) notwithstanding the foregoing, where there is a legitimate ground for retention under other statutes or under the Location Information Act, that ground applies; basis for retaining confirmation data on the use and provision of location data - Article 16(2) of the Location Information Act; retention period for confirmation data - retained for six months or longer, and where necessary to respond to a user report or dispute, to confirm fraudulent use, or to a request for assistance from an investigative authority, retained until that ground ceases to apply; destruction procedure and method - destroyed without delay by an unrecoverable method once the retention period expires or the purpose is achieved, with electronic files deleted by technical means; provision to third parties - the Company does not provide personal location data to third parties without the user's consent, and where it comes to do so it will inform the user in advance and obtain separate consent; notification on provision to third parties - the recipient, date and time and purpose are notified to the user on each occasion, immediately; rights of a guardian of a child aged 8 or under - the Service is available only to those aged 18 or over, so the Company holds no personal location data processed with a guardian's consent, and where such a user is identified the account is stopped and the data destroyed without delay; protective measures for location data - under Article 16 of the Location Information Act and its Enforcement Decree the Company designates a location data manager and location data handlers and limits their access rights, and implements administrative and technical safeguards under its internal Location Data Handling Policy; location data manager - WungSeok Choi, Representative Director, [email protected]; transfer abroad - location data is included in the transfers abroad set out in Article 12 (United States).
- Consent may be withdrawn at any time, and location permission may be switched off in the device settings.
- The Company does not use personal location data for purposes other than those the user has designated, and records and retains confirmation data on the use and provision of location data as required by Article 16(2) of the Location Information Act.
Article 8 (Advertising and personalised advertising)
- The Company displays advertising in the Service and works with advertising providers to do so.
- Data is provided for personalised advertising only where the user has consented in the consent management screen. The items provided are the advertising identifier, IP address, device information, country- and city-level approximate location, and in-app interaction records.Sharing of the full IP address - the Company currently has Google AdMob's "full IP address sharing" setting enabled, so the unmasked full IP address is passed on each ad request to Google and to buyers Google intermediates. It is not passed in the following cases: (i) the user has not consented to personalised advertising, in which case limited ads are served instead; (ii) the request originates in the EEA, the UK or Switzerland, where the full IP address is passed only on connected-TV inventory and the Company operates no connected-TV inventory; (iii) the request is flagged as non-personalised, limited or subject to restricted data processing; or (iv) the ad unit belongs to a mediation partner's bidding. A user may stop it by withdrawing consent in the app's privacy settings. If the Company disables this setting, the passing of the full IP address stops immediately. Because that narrows the personal data the Company discloses, the Company will delete this passage at the next revision of this Policy.
- The Company does not provide names, mobile numbers, message content, call content, face data or sensitive data for advertising purposes.
- The set of advertising providers changes from time to time. The Company therefore does not fix individual provider names in this Policy and instead points to the public lists maintained jointly by the industry; their addresses are given in Article 12, and the in-app consent management screen reads from the same lists.
- Users may withdraw consent to personalised advertising at any time in settings. Advertising will still be shown but will not be tailored using the user's data.
Article 9 (Disclosure to third parties)
- The Company does not disclose personal data to third parties, except: with the user's prior consent; where required by law or to comply with a legal obligation; where an investigative authority so requires under a statutory procedure; where necessary to avert an imminent risk to the life, body or property of the user or a third party; or under Article 10.
- Other members see the user's public profile: profile photograph, name or nickname, age, verification badges, self-introduction and optional items.
Article 10 (Sharing of fraudulent-account signals)
- To prevent fraud, the Company may share information about accounts restricted for fraud or impersonation with other services operated by the Company (SeriUs, Pixys and others) and with partners with whom the Company cooperates for safety purposes.
- The items shared are limited to: (a) an irreversibly transformed account identifier; (b) the category of the restriction (for example fraud, impersonation, spam); and (c) the time of the restriction.
- The Company does not share names, mobile numbers, email addresses, original profile photographs, message or call content, face data or sensitive data.
- The basis is Article 15(1)(6) of the Personal Information Protection Act (legitimate interest). The Company acts only where the interest in user safety manifestly outweighs the rights of the data subject.
- A user may object at [email protected]. Where the objection is justified, the Company excludes that information from sharing.
Article 11 (Processors)
| Processor | Task |
|---|---|
| Amazon Web Services, Inc. | Server operation and data storage; face comparison |
| Google LLC (Firebase) | Authentication, push notification, error collection |
| Google LLC (AdMob) | Advertising delivery |
| Apple Inc. · Google LLC | In-app payment processing |
The Company sets out data protection requirements in each processing agreement and supervises compliance.
Article 12 (International transfers)
| Recipient | Country | Items | Purpose | Timing and method | Retention |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. | United States | Profile, messages, usage records, face data | Server operation, face comparison | Network transmission when the Service is used | 30 days after termination (face data: see Article 6) |
| Google LLC | United States | Registration data, device information, error logs | Authentication, push notification, error collection | Network transmission when the Service is used | 30 days after termination |
| Google LLC (AdMob) | United States | Advertising identifier, IP address, device information | Advertising delivery and bid mediation | Network transmission on each ad request | Until consent is withdrawn |
| Advertising providers (those participating in Google AdMob bidding and mediation) | United States, Europe, China, Singapore and others, according to each provider's own location | Advertising identifier, IP address, device information | Ad delivery and performance measurement | Network transmission on each ad request | Until consent is withdrawn |
Contact details and data protection officers for each recipient are set out in their own privacy policies. A user may refuse an international transfer, in which case all or part of the Service may become unavailable. Transfers from the European Economic Area to the Republic of Korea rely on the European Commission's adequacy decision; transfers to other countries use Standard Contractual Clauses.
🔴 The set of advertising providers changes from time to time. The Company therefore does not fix individual provider names in this Policy and instead points to the public lists maintained jointly by the industry.
- Google ad technology providers - https://support.google.com/admob/answer/9012903 (maintained by Google, always current)
- Google GDPR ad partners - https://support.google.com/admob/answer/10113004
- Providers not registered on the IAB TCF Global Vendor List - https://storage.googleapis.com/tcfac/additional-consent-providers.csv
The in-app consent management screen reads from these same lists, so this Policy, the public lists and the consent screen cannot diverge. When adding a new advertising provider the Company updates the partner settings in the AdMob console first and only then sends ad requests to it.
Article 13 (Retention and destruction)
| Item | Retention | Basis |
|---|---|---|
| Account and profile | 30 days after termination | Recovery from accidental deletion; preventing evasion of enforcement |
| Messages and attachments | 30 days after termination | As above |
| Face data | Until withdrawal from the Service or withdrawal of consent (until the account is deleted, for accounts restricted for fraud or impersonation) | Article 6 |
| Verification outcome and audit record (no images) | 1 year | Handling disputes |
| Identifiers of accounts restricted for fraud or impersonation | 3 years | Preventing re-registration; user safety |
| Records of contracts and withdrawal | 5 years | E-Commerce Act |
| Records of payment and supply | 5 years | E-Commerce Act |
| Records of complaints and dispute handling | 3 years | E-Commerce Act |
| Login records | 3 months | Protection of Communications Secrets Act |
Data is destroyed without delay once the period expires: electronic files irrecoverably, paper records by shredding or incineration. Where a user does not use the Service for one year, the Company gives notice of dormancy and destroys the personal data 30 days later. Anonymised statistics may be kept without time limit.
Article 14 (Security measures)
Internal management plan and regular staff training; encryption in transit (TLS 1.2+); encryption at rest for face data, verification documents and passwords (AES-256); role-based access control and an access control system; mandatory two-factor authentication for administrator accounts; retention and review of access logs; and physical access control.
Article 15 (Your rights and how to exercise them)
- Users and their legal representatives may at any time request access; request correction of errors; request deletion; request suspension of processing; withdraw consent; request an explanation of or refuse an automated decision (Article 5); and request transmission of their data.
- Requests may be made in the app settings or to [email protected]. An account may be deleted directly in the app; on the web, by request to [email protected].
- The Company acts within 10 days of receipt and informs the user of the outcome.
- The Company does not disadvantage users for exercising these rights.
Article 16 (Users under 18)
- The Service is for those aged 18 and over, and the Company does not knowingly collect personal data from anyone under 18.
- On confirming that an account belongs to a person under 18, the Company immediately stops the account and destroys the personal data collected, retaining only the minimum identifier needed to prevent re-registration.
- Suspected accounts may be reported in-app or to [email protected].
Article 17 (Data protection officer and remedies)
Data protection officer - WungSeok Choi, Chief Executive Officer, [email protected]
EU representative (GDPR Article 27) - FGND Core GmbH, Hauptstrasse 151, 10827 Berlin, Germany · [email protected]
Remedies (Republic of Korea) - Korea Internet & Security Agency privacy centre (privacy.kisa.or.kr · 118); Personal Information Dispute Mediation Committee (www.kopico.go.kr · 1833-6972); Supreme Prosecutors' Office cybercrime division (www.spo.go.kr · 1301); National Police Agency cyber bureau (ecrm.cyber.go.kr · 182).
Article 18 (Region-specific provisions)
1. European Union, European Economic Area, United Kingdom and Switzerland
a. Legal bases - performance of a contract (GDPR Article 6(1)(b)), consent (Article 6(1)(a)), compliance with a legal obligation (Article 6(1)(c)) and legitimate interests (Article 6(1)(f)). Face data and other special category data are processed on the basis of explicit consent (GDPR Article 9(2)(a)).
b. Legitimate interests pursued - maintaining and improving the Service; preventing fraud and abuse; and analysing usage statistics.
c. Users have the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and may lodge a complaint with a supervisory authority.
d. AI training - the Company pseudonymises usage records and uses them under Article 20 of the Moji Terms of Service, on the basis of legitimate interests (Article 6(1)(f) GDPR). A user may object at any time under Article 21 GDPR, and the Company will exclude that user's data from training.
e. Digital Services Act - reporting channels, statements of reasons, appeals and out-of-court dispute settlement are set out in Articles 23 to 26 and Article 37 of the Moji Terms of Service.
2. United States
a. All states
i. The Company honours the rights provided under the privacy laws of California, Virginia, Colorado, Connecticut, Utah, Texas and other states: the right to know, to delete, to correct, to opt out of processing for targeted advertising, and not to be discriminated against for exercising those rights.
ii. Personalised advertising, "sale" and "sharing" - the Company does not sell personal information for monetary consideration. It does provide advertising identifiers, IP addresses and device information to advertising providers for personalised advertising, and this constitutes "sharing" for cross-context behavioral advertising under California law. Users may opt out at any time in the app's privacy settings, and where a user accesses the Service on the web the Company honours Global Privacy Control signals. Opting out does not remove advertising; it stops advertising being tailored using the user's data.
iii. Sensitive personal information - use is limited to providing the Service and safety purposes, and users may request that its use be limited. The Company does not provide sensitive data - including religion, gender preference and ethnicity or cultural background - for advertising purposes, and does not sell it under any circumstances.
iv. Maryland residents - in accordance with the Maryland Online Data Privacy Act, the Company does not sell sensitive data and limits the processing of sensitive data to what is strictly necessary to provide the service the user has requested.
v. Minors - the Company does not serve personalised advertising to, and does not sell or share the personal data of, any user it knows or should know is under 18. The Service is restricted to those aged 18 and over; on confirming an account below that age the Company stops the account under Article 16 and removes it from advertising audiences.
vi. Full IP address and location - an unmasked full IP address can narrow a user's location considerably. The Company treats it as capable of amounting to "precise geolocation" and applies the following safeguards: (a) the full IP address is not passed for users who have not consented to personalised advertising; (b) where a user requests a limit on the use and disclosure of sensitive personal information, or opts out of personalised advertising, the Company records that user's personalised-advertising consent as withdrawn, from which point (a) applies - the same method is applied to users in every state, including California and Maryland; and (c) the Company does not sell the full IP address for monetary or other valuable consideration.
b. Illinois, Texas and Washington residents - face data
i. Before collecting face data, the Company informs the user in writing (including by electronic means) of the fact of collection, the purpose and the retention period, and obtains a written release or equivalent consent.
ii. The Company does not sell, lease, trade or otherwise profit from face data.
iii. Retention and destruction schedule - face data is permanently deleted on the earlier of the fulfilment of the initial purpose of collection and three years after the member's last interaction with the Company, matching the standard set by the Illinois Biometric Information Privacy Act. Where a member withdraws from the Service or withdraws consent, destruction occurs sooner.
iv. Washington residents may also consult the separate consumer health data notice.
3. Vietnam
Processing purposes and items are notified and consent obtained in accordance with the Personal Data Protection Law (Luật số 91/2025/QH15, in force 1 January 2026). Where the Company's monthly user numbers in Vietnam exceed the applicable threshold, the Company will meet local storage requirements to the extent the law requires, in accordance with Nghị định 147/2024.
4. Japan
Under the Act on the Protection of Personal Information, where personal data is provided to a third party in a foreign country the Company provides information on that country's name and its data protection regime. The countries concerned are listed in the table in Article 12.
Article 19 (Changes to this Policy)
- This Policy applies from its effective date.
- Where the Policy is changed, the Company posts the content, the reason and the effective date in the Service from 7 days before the effective date. Notice is also given individually by in-app message. The Company may not hold a user's email address and therefore does not give notice by email.
- Where a change requires consent, the Company obtains that consent before processing personal data under the changed Policy.
Business information
- Company: w3company co.,ltd. · Representative: WungSeok Choi
- Address: Room 404, Annex, 21 Baekbeom-ro 31-gil, Mapo-gu, Seoul 04147, Republic of Korea
- Business registration number: 325-87-02892 · E-commerce registration: 2024-Seoul Mapo-2171
- Email: [email protected]
주식회사 더블유쓰리컴퍼니 | 대표 최웅석 | 사업자등록번호 325-87-02892
통신판매업신고 제2024-서울마포-2171호 | 개인정보 보호책임자 최웅석
서울특별시 마포구 백범로31길 21, 별관 404호 (우)04147
이메일 [email protected]
