Effective date: October 5, 2026
베이비링구얼 (Babylingual), a sole proprietorship, operates in the Republic of Korea. Send privacy inquiries to contact@babylingual.org.
1. Information and purposes
| Category | Information | Purpose |
|---|---|---|
| Voice service | Submitted recordings, voice/generation identifiers, lesson text and generated speech | Generate and deliver English learning speech based on a parent's voice |
| Accounts and authentication | App account identifiers, authentication/session information, request identifiers and status | Authenticate requests, link accounts, prevent duplicate processing and recover operations |
| Service operations | Requested curriculum step/day, download/cleanup requests, results and usage counts | Deliver content, recover failures, enforce allowances and perform cleanup |
| Access and error handling | Connection information such as IP addresses, request paths/times and error information | Limit requests, resolve failures and protect the service |
| Subscriptions | Account identifiers, products, subscription/purchase history and transaction information | Verify purchases, grant access and restore subscriptions |
| Support | Email address and information included in an inquiry | Handle inquiries and privacy-rights requests |
| On-device use | Playback history/statistics and language, reminder and voice-profile settings | Show progress, personalize on-device use and deliver local notifications |
The app's re-recording report includes voice slot, invalidated-day/deleted-clip counts, subscription status and related period information. Complete on-device listening history is distinct from operational requests sent to servers. Requests that include an account identifier are linked to that account.
When Preview device verification is operated, Apple DeviceCheck tokens/results and allowance records are processed.
2. Providers, disclosures and international transfers
For overseas processing and storage necessary to provide the contracted service, transfer information is disclosed in this policy before processing under PIPA Article 28-8(1)(3)(a). This does not cover unrelated third-party purposes or optional advertising. Separate consent is used where required.
| Recipient and contact | Items, purpose and transfer timing | Country / retention |
|---|---|---|
| Cloudflare, Inc. / legal@cloudflare.com | Account/request identifiers, connection metadata, source/output audio and service state; request handling and storage when the app uses the service, via HTTPS/TLS | R2 audio files are stored in the United States. The primary D1 database holding account and service information is located in South Korea. Requests pass through Cloudflare's global network. Retention follows section 3 by data type. |
| Modal Labs, Inc. / security@modal.com | Voice prompts, lesson/text, user/job/object references, generated audio and processing status; speech generation for each requested job, via HTTPS/TLS | Requests are routed through Virginia, United States. Application logs, asynchronous job inputs/outputs and payloads over 2 MiB are stored in the United States. The countries where speech-generation servers execute are not separately restricted. Retention follows section 3. |
| RevenueCat, Inc.; compliance@revenuecat.com | App user ID and purchase/subscription/entitlement information; SDK subscription operations, purchase/restore and server verification, via HTTPS/TLS | Customer data is stored on AWS in the United States. Delete the customer profile with account deletion under the procedure below; segregate only required statutory records. |
| Cloudflare, Inc. Email Routing / legal@cloudflare.com; Google LLC (Gmail) / googlekrsupport@google.com | Sender/contact, message/attachments and delivery information; forwarding and responding when an inquiry is sent | Inquiries pass through Cloudflare Email Routing and are stored in the Gmail mailbox. Cloudflare and Google process information on servers worldwide. Inquiry and statutory-record retention follows section 3. |
Apple processes store transactions under its own relationship with the purchaser; Babylingual does not directly collect payment-card numbers. Voice caches remaining on previously used generation servers are also covered by deletion requests. These disclosures are updated when processors or external integrations change.
If you do not want an international transfer, you can stop before submitting a voice registration or generation request, or request suspension/deletion through the app or contact@babylingual.org. We verify account control and explain the scope and outcome. Refusing transfers necessary for speech generation may prevent new speech generation; refusing transfers necessary for subscription verification may prevent subscription functionality. Deletion cannot reverse a transfer that has already occurred; the transferred information is handled under the retention and deletion rules below.
3. Retention and deletion
| Category | Retention and end condition |
|---|---|
| Registered source recording | While the voice profile is in use; delete on replacement, voice deletion, withdrawal or account deletion. It is needed for later requested synthesis and does not follow the generated-output three-day rule. |
| Unattached Preview upload / Preview | Unattached Preview uploads: at most seven days after upload. Successfully accepted paid/Settings sources follow the registered-source rule. Preview source/output: seven days after latest successful generation, or earlier explicit deletion. Verify the paid copy before deleting a promoted Preview copy; a paid source then follows the registered-source rule. |
| Ordinary generated server speech | Becomes eligible for expiry three days after upload; delete sooner when applicable. Expiry processing is asynchronous, not a guaranteed instant of physical erasure. |
| Device files and state | Until removal, account cleanup or applicable cache eviction. The app retries incomplete local cleanup; inaccessible/offline devices and OS backups are not remotely erased by a server response. |
| Account/authentication/usage | During service use, then delete/revoke at account deletion except the limited cleanup/recovery records below. Quota/bootstrap history uses a 90-day cutoff. |
| Deletion/recovery records | Keep the minimum records needed for deletion, failure handling and reapplying deletions after recovery for 30 days after the related actions finish, then delete them. Account-linkable hashed identifiers are personal information. If processing is delayed, keep only necessary records and explain the reason and next action. |
| Temporary processing / Modal records | Temporary speech-generation files become due for deletion when the job ends. Modal retains function inputs/outputs for up to seven days and app logs for one day. Changes to retention periods are reflected in these disclosures. |
| Cloudflare logs / D1 recovery | Workers Logs are retained for three days and D1 recovery history for seven days. Any additional exports or backups are subject to a separately disclosed retention period. |
| RevenueCat customer profile | While needed for subscription service; include erasure in account deletion. Preserve only separately required statutory records, not the entire profile. |
| Ordinary inquiries | Delete received messages, replies and attachment copies 90 days after resolution, including removal from Trash. Remove unnecessary voice attachments sooner. Actual consumer complaints/disputes follow the statutory rule below. |
| Statutory archive | Required contract/withdrawal and payment/supply records: five years; consumer complaint/dispute records: three years; advertising records: six months. Keep only the necessary records separately; this does not authorize retaining all source recordings. |
| Administrator access audit | Covered administrator access records: at least one year or the longer applicable statutory minimum; separate from ordinary user request logs. |
Request deletion in the app or at contact@babylingual.org. After verifying the request scope and account control, we stop further use of the relevant information and process deletion of service copies and information held by the relevant providers. We explain the completed scope and the reasons and periods for any retained data. Requests are handled without delay within the applicable legal time limits. Failed deletions are retried and reviewed by the responsible operator. If processing is delayed, the remaining scope, reason and next action are explained.
RevenueCat erasure does not cancel an Apple subscription. A provider accepting a deletion request does not by itself confirm immediate erasure of every physical copy. Logs and recovery history follow their respective retention periods. When restoring a backup, we reapply deletion requests so erased information is not put back into use. Statutory records remain separate and access-restricted and are erased when their applicable purpose or retention period ends.
4. Rights and contact
Send requests for access, correction/deletion, suspension of processing or consent withdrawal to contact@babylingual.org. Requests undergo appropriate identity checks and are handled under applicable law, with the outcome or restriction explained.
- Email: contact@babylingual.org
5. Safeguards and intended users
Recording files retained on the device during initial voice registration use iOS file protection and backup exclusion. App authentication tokens are stored in Keychain.
Voice registration is presented on the basis that adults use their own voices. The service does not automatically verify age or speaker identity.
6. Changes
Changes and their effective date will be communicated, with earlier versions available for reference.
↑ Back to top