한국어

Reply Privacy Policy

Operator: Darak Studio Co., Ltd. · Contact: hello@darak.studio · Effective date: 2026-10-03

Draft pending legal review. Every item marked “to be confirmed” (retention periods, cross-border transfer details and so on) will be settled before this policy is published as final. If this translation differs from the Korean version, the Korean version applies. Which version prevails for users outside Korea: to be confirmed

Darak Studio Co., Ltd. (“we”) runs the Reply app and its server. This policy explains what personal information Reply processes and how. It lists what the current app and server actually process.

You sign in to Reply with Apple (iPhone) or Google (Android). The minimum sign-up age is 19 in every country. Outside Korea, you enter your date of birth to confirm you are 19 or older. In Korea, you also complete identity verification through PortOne to confirm you are 19 or older and link that identity to your social sign-in account. Items marked “Korea” apply only to users of the Korean service. Sign-up is not available in the United Kingdom, Brazil, or the US states of Mississippi and Tennessee.

1. Information we process

CategoryItemsPurposeVisible to other users
Sign-up and log-in with Apple or GoogleAn identifier made from your Apple or Google account ID (stored only as a hash with a separate secret key), sign-in method (Apple or Google), date of birth entered outside Korea (used only for the age check; only the birth year is stored), for Sign in with Apple an Apple token stored encrypted (see below)Confirming you are 19 or older outside Korea, linking social sign-in accounts to your Reply account, log-in, stopping deleted or restricted accounts from signing up againOnly an age range derived from the birth year (e.g. “30–34”)
Identity verification
(Korea)
Birth year, an identifier derived from the CI value (or DI when CI is absent), hashed with a separate secret key, verification time. Earlier PortOne accounts may retain an existing phone number and CI or DI hashConfirming you are 19 or older, one account per person, log-in, stopping deleted or restricted identities from signing up againAn age range derived from the birth year, and a verification badge
Collected at sign-upGender (male, female or not specified), country (the country of your App Store or Google Play account, or your device’s region setting if that is unavailable) and region from earlier Korean sign-ups, accepted terms version and timeApplying the “letters I receive” setting (gender) and, from app 1.2, readers chosen by gender for a letter sent by rocket or Santa Claus; choosing the sign-up method that applies in your country; checking that sign-up is available in your region; recording consent to the terms. The sign-up country or region is not shown to other usersNothing
Pen-name cardPen name, one-line intro, interests, region (a Korean province/city or a country, optional), “letters I receive” setting (gender and, from app 1.2, age group), time of consent to safety screening, time of the last pen-name changeSigning your letters, replies and conversations; ordering the letters shown on the shore (shared interests and language, and from app 1.2 whether the free ocean current carried a letter to the country on your card); “Read by country” (letters are chosen by the region on the writer’s card); from app 1.2, the shore your letters set out from on the ocean current and the countries a helicopter can take them toPen name, intro, interests, region, age range, verification badge (Korean identity verification only), team badge, month joined
Read by country (app 1.1 or later)The country you chose, start and end time, the bottle usedShowing only that country’s letters for 24 hours; bottle recordsNothing
Ocean currents and vehicles (app 1.2 or later)For each letter: how it was sent (the current, or a helicopter, mail ship, seaplane, submarine, rocket or Santa Claus), the country whose shore it reached first (for Santa Claus, every country it was left at, and the chosen countries left out for too few readers), the country it set out from (the country on your card when you sent it), its story route (by current, on a 1° map grid; by vehicle, a line between fixed map points set for the two countries), the real-world days by current statistics (current only), the time of day and weather when it set out (for example “night, rain”) at the representative place of a time zone that the public IANA time zone list gives for that country (see “Time zone”), and the extra bottles usedDelivering the letter to that shore at the time shown before sending; showing the forecast, route, postmark and launch conditions; bottle records; comparing how ocean currents affect replies with the previous way of sending (some accounts, chosen by their Reply account number, send letters the previous way). A Santa Claus letter is shown only to readers whose card shows one of the countries it was left at. Stored with the letter and kept or deleted with itThe shore the letter reached and how it was sent (for Santa Claus, every country it was left at; never the countries left out, which only the writer sees). While your card still shows the country the letter set out from, readers also see that country, the full route, the days at sea and the time of day and weather when it set out. If you remove or change the country on your card, readers see “A bottle from the open sea” and only the last part of the route, also for letters you sent earlier
Choosing readers (app 1.2 or later)For a letter sent by a vehicle that offers it: the age group and gender of readers you chose, if any. For your account: when you last opened the shore (updated at most once an hour)Showing such a letter only to readers of the chosen country who fit the choice and whose settings accept the sender (and the sender’s theirs); counting readers who opened the shore in the last 7 days, so that a choice too few people fit is refused before any bottle is used, and, for Santa Claus, per chosen country (with or without a choice) to leave out a country where too few fit. The age group comes from your birth yearNothing. Readers are not told what the sender chose, and nobody sees a count of readers or when you opened the shore
Time zone (app 1.2 or later)Your device’s time-zone setting (for example “Europe/Lisbon”), sent with the request that draws the beach scene (also before you sign in) and with each letter you send by current or by a vehiclePicking a fixed representative place for that time zone (from the public IANA time zone list) to show the time of day and weather on the beach, and to record a letter’s launch conditions. It is used only while handling that request; our server does not store it or write it to its logsNothing directly. For each time zone, the public IANA time zone list (zone.tab) gives the one country each entry belongs to and one representative place. A letter’s launch conditions come from the representative place of your time zone if that time zone belongs to the country on your card, and otherwise from the time zone the list marks as covering most of that country; the representative place is always inside the country on your card. In a country with several time zones, readers may see the conditions for your part of the country
What you writeLetters (text, topic, language), replies, messages, letters you removed from your shore (a record so the letter is not shown to you again; it does not delete the letter), whether you continued or passed on a replyProviding the service, safety screening, handling reportsA letter is readable by several users on the shore for up to 72 hours; a reply is visible to the letter’s author; a message is visible to the conversation partner
Reports, blocks, restrictionsReport reason and details, a copy of the reported content at the time of the report (pen name and text), outcome and notes, block list, restriction timeHandling reports, preventing repeat abuse, handling disputesNothing. The public trust dashboard shows only totals such as reports resolved in the last 30 days
Bottle purchases, ad rewardsStore transaction ID, product, purchase and refund status, an account token used to confirm purchases, ad reward records, bottle ledgerConfirming and crediting purchases, handling refunds, preventing double creditNothing
Rewarded ads
(only if you use them)
Your ad consent choices (kept on your device by Google’s consent tool); the data the Google Mobile Ads SDK collects (section 3)Showing the ad you ask for, confirming the reward, respecting your consent choicesNothing
Inviting friends (app 1.2 or later)Your invite code (8 characters, made without reference to your pen name or account); whose invite code you entered, and when; when the invite succeeded and whether the inviter was given bottlesGiving invite rewards; applying the inviter’s reward limits (per 30 days and in total); preventing abuse (entering your own code, two people entering each other’s codes, or entering a second code). To check whether an invite has succeeded, we also look at information we already process: when the friend signed up, whether they have posted a letter, when they last opened the shore, and whether the account is restricted or deleted. To adjust the invite conditions and limits, we look at statistics in totals only (the share of invites that succeed, and how long invited accounts keep using Reply and how often they are reported). The bottles given are recorded in the bottle ledgerNothing. The inviter sees only how many friends signed up with their code and how many invites succeeded, never the friends’ pen names, accounts or sign-up times. The friend is not shown the inviter’s pen name either. Only the people you give your invite code to know it
Access and security recordsIP address (stored as a hash with a secret key, to rate-limit sign-up and identity verification requests), log-in tokenAbuse prevention, securityNothing
Sign-up region checkConnecting IP address (looked up only to determine the region; not stored for this purpose)Checking that sign-up is available in your region (new sign-ups are blocked in the United Kingdom, Brazil, and the US states of Mississippi and Tennessee). Region is determined using DB-IP data: “IP geolocation by DB-IP” (https://db-ip.com, CC BY 4.0)Nothing
Age range signal (app 1.2, iOS 26 or later and Android)The age range Apple or Google shares (used only for the sign-up decision; not stored)Checking sign-up age. If the shared age range is under 19, sign-up is refusedNothing
Sign-up refusal recordA hash made from your Apple or Google account ID, and the date you can sign up againIf you tried to sign up with a date of birth or age range that is under the minimum age, to stop the same account from trying again until the date you can sign up. It is deleted after that date passesNothing

2. AI safety screening and automatic restrictions

3. Rewarded ads and consent

4. Service providers and international transfers

RecipientWhat they doInformation sharedLocation
RailwayHosting for the API server and databaseAll information the service storesServer location (region) to be confirmed
Apple (Sign in with Apple)Checking your sign-in; issuing and, when you delete your account, revoking the Apple tokenThe sign-in token and one-time code Apple gives the app; the stored Apple token when you delete your accountTo be confirmed
Google (Google sign-in)Checking your sign-inThe sign-in token Google gives the app is checked with Google’s public keys; our server sends Google no user data for thisTo be confirmed
DeepSeekAI safety screeningThe text being checked (letters, replies, messages, pen name and intro)Sent over an encrypted connection (HTTPS) each time you write. Destination country, recipient’s legal name and contact, and retention period to be confirmed
Apple (App Store)iOS in-app purchase payment, transaction checks, refund noticesTransaction details, the purchase account tokenTo be confirmed
Google (Analytics, Firebase)App usage statistics (from app 1.2)Event names (sign-up or sign-in, letter sent, reply written, reply accepted), the app-instance ID, and usage data such as device and app version and approximate regionTo be confirmed
Google (Google Play)Android in-app purchase payment, transaction checks, refund noticesTransaction details, the purchase account tokenTo be confirmed
Google (AdMob and its consent tool)Rewarded ads and ad consent (section 3)The data the ad SDK collects (section 3); the Reply account number and reward session number used to confirm a rewardTo be confirmed
PortOne and its contracted identity verification provider provider name to be confirmed (Korea only)Identity verificationPortOne’s contracted provider processes the information you enter or confirm on the verification screen. Reply checks the name, date of birth and CI (or DI when CI is absent) in the result and retains only the birth year, CI/DI hash and verification timeTo be confirmed
Operations alert tool, if configured service to be confirmedNew-report alertsReport number and reason code only; no user-written textTo be confirmed

5. Retention and deletion

When you delete your account in the app (Account → Delete account), we immediately:

Deleting your account without the app: if you can no longer open the app, email hello@darak.studio with the subject “Delete my Reply account” and your pen name. Because we do not store your email address, we may ask you to confirm that the account is yours before we delete it as described here. Confirmation method and response time to be confirmed

After deletion, we keep:

Sign-up, sign-in and verification request records are deleted automatically (hourly) 24 hours after they expire, and sign-up refusal records after the date you can sign up again. These are the retention periods we apply now. Whether a legal retention duty applies to these records, and the retention period for all other items: to be confirmed. For all other items, automatic deletion when a retention period ends is not yet in place. When a retention period ends, the data is erased so it cannot be restored.

6. Your rights

7. Security measures

8. Privacy officer and contact

Privacy officer: Darak Studio Co., Ltd. person to be confirmed
Contact: hello@darak.studio

Representative in the EU and the UK: to be confirmed
Agencies for privacy complaints and counselling: to be confirmed

9. Changes to this policy

We will announce changes in the app and on this page before they take effect. Effective date: 2026-10-03

Terms of Service · Child Safety Policy