Reply Privacy Policy
Draft pending legal review. Every item marked “to be confirmed” (retention periods, cross-border transfer details and so on) will be settled before this policy is published as final. If this translation differs from the Korean version, the Korean version applies. Which version prevails for users outside Korea: to be confirmed
Darak Studio Co., Ltd. (“we”) runs the Reply app and its server. This policy explains what personal information Reply processes and how. It lists what the current app and server actually process.
You sign in to Reply with Apple (iPhone) or Google (Android). The minimum sign-up age is 19 in every country. Outside Korea, you enter your date of birth to confirm you are 19 or older. In Korea, you also complete identity verification through PortOne to confirm you are 19 or older and link that identity to your social sign-in account. Items marked “Korea” apply only to users of the Korean service. Sign-up is not available in the United Kingdom, Brazil, or the US states of Mississippi and Tennessee.
1. Information we process
| Category | Items | Purpose | Visible to other users |
|---|---|---|---|
| Sign-up and log-in with Apple or Google | An identifier made from your Apple or Google account ID (stored only as a hash with a separate secret key), sign-in method (Apple or Google), date of birth entered outside Korea (used only for the age check; only the birth year is stored), for Sign in with Apple an Apple token stored encrypted (see below) | Confirming you are 19 or older outside Korea, linking social sign-in accounts to your Reply account, log-in, stopping deleted or restricted accounts from signing up again | Only an age range derived from the birth year (e.g. “30–34”) |
| Identity verification (Korea) | Birth year, an identifier derived from the CI value (or DI when CI is absent), hashed with a separate secret key, verification time. Earlier PortOne accounts may retain an existing phone number and CI or DI hash | Confirming you are 19 or older, one account per person, log-in, stopping deleted or restricted identities from signing up again | An age range derived from the birth year, and a verification badge |
| Collected at sign-up | Gender (male, female or not specified), country (the country of your App Store or Google Play account, or your device’s region setting if that is unavailable) and region from earlier Korean sign-ups, accepted terms version and time | Applying the “letters I receive” setting (gender) and, from app 1.2, readers chosen by gender for a letter sent by rocket or Santa Claus; choosing the sign-up method that applies in your country; checking that sign-up is available in your region; recording consent to the terms. The sign-up country or region is not shown to other users | Nothing |
| Pen-name card | Pen name, one-line intro, interests, region (a Korean province/city or a country, optional), “letters I receive” setting (gender and, from app 1.2, age group), time of consent to safety screening, time of the last pen-name change | Signing your letters, replies and conversations; ordering the letters shown on the shore (shared interests and language, and from app 1.2 whether the free ocean current carried a letter to the country on your card); “Read by country” (letters are chosen by the region on the writer’s card); from app 1.2, the shore your letters set out from on the ocean current and the countries a helicopter can take them to | Pen name, intro, interests, region, age range, verification badge (Korean identity verification only), team badge, month joined |
| Read by country (app 1.1 or later) | The country you chose, start and end time, the bottle used | Showing only that country’s letters for 24 hours; bottle records | Nothing |
| Ocean currents and vehicles (app 1.2 or later) | For each letter: how it was sent (the current, or a helicopter, mail ship, seaplane, submarine, rocket or Santa Claus), the country whose shore it reached first (for Santa Claus, every country it was left at, and the chosen countries left out for too few readers), the country it set out from (the country on your card when you sent it), its story route (by current, on a 1° map grid; by vehicle, a line between fixed map points set for the two countries), the real-world days by current statistics (current only), the time of day and weather when it set out (for example “night, rain”) at the representative place of a time zone that the public IANA time zone list gives for that country (see “Time zone”), and the extra bottles used | Delivering the letter to that shore at the time shown before sending; showing the forecast, route, postmark and launch conditions; bottle records; comparing how ocean currents affect replies with the previous way of sending (some accounts, chosen by their Reply account number, send letters the previous way). A Santa Claus letter is shown only to readers whose card shows one of the countries it was left at. Stored with the letter and kept or deleted with it | The shore the letter reached and how it was sent (for Santa Claus, every country it was left at; never the countries left out, which only the writer sees). While your card still shows the country the letter set out from, readers also see that country, the full route, the days at sea and the time of day and weather when it set out. If you remove or change the country on your card, readers see “A bottle from the open sea” and only the last part of the route, also for letters you sent earlier |
| Choosing readers (app 1.2 or later) | For a letter sent by a vehicle that offers it: the age group and gender of readers you chose, if any. For your account: when you last opened the shore (updated at most once an hour) | Showing such a letter only to readers of the chosen country who fit the choice and whose settings accept the sender (and the sender’s theirs); counting readers who opened the shore in the last 7 days, so that a choice too few people fit is refused before any bottle is used, and, for Santa Claus, per chosen country (with or without a choice) to leave out a country where too few fit. The age group comes from your birth year | Nothing. Readers are not told what the sender chose, and nobody sees a count of readers or when you opened the shore |
| Time zone (app 1.2 or later) | Your device’s time-zone setting (for example “Europe/Lisbon”), sent with the request that draws the beach scene (also before you sign in) and with each letter you send by current or by a vehicle | Picking a fixed representative place for that time zone (from the public IANA time zone list) to show the time of day and weather on the beach, and to record a letter’s launch conditions. It is used only while handling that request; our server does not store it or write it to its logs | Nothing directly. For each time zone, the public IANA time zone list (zone.tab) gives the one country each entry belongs to and one representative place. A letter’s launch conditions come from the representative place of your time zone if that time zone belongs to the country on your card, and otherwise from the time zone the list marks as covering most of that country; the representative place is always inside the country on your card. In a country with several time zones, readers may see the conditions for your part of the country |
| What you write | Letters (text, topic, language), replies, messages, letters you removed from your shore (a record so the letter is not shown to you again; it does not delete the letter), whether you continued or passed on a reply | Providing the service, safety screening, handling reports | A letter is readable by several users on the shore for up to 72 hours; a reply is visible to the letter’s author; a message is visible to the conversation partner |
| Reports, blocks, restrictions | Report reason and details, a copy of the reported content at the time of the report (pen name and text), outcome and notes, block list, restriction time | Handling reports, preventing repeat abuse, handling disputes | Nothing. The public trust dashboard shows only totals such as reports resolved in the last 30 days |
| Bottle purchases, ad rewards | Store transaction ID, product, purchase and refund status, an account token used to confirm purchases, ad reward records, bottle ledger | Confirming and crediting purchases, handling refunds, preventing double credit | Nothing |
| Rewarded ads (only if you use them) | Your ad consent choices (kept on your device by Google’s consent tool); the data the Google Mobile Ads SDK collects (section 3) | Showing the ad you ask for, confirming the reward, respecting your consent choices | Nothing |
| Inviting friends (app 1.2 or later) | Your invite code (8 characters, made without reference to your pen name or account); whose invite code you entered, and when; when the invite succeeded and whether the inviter was given bottles | Giving invite rewards; applying the inviter’s reward limits (per 30 days and in total); preventing abuse (entering your own code, two people entering each other’s codes, or entering a second code). To check whether an invite has succeeded, we also look at information we already process: when the friend signed up, whether they have posted a letter, when they last opened the shore, and whether the account is restricted or deleted. To adjust the invite conditions and limits, we look at statistics in totals only (the share of invites that succeed, and how long invited accounts keep using Reply and how often they are reported). The bottles given are recorded in the bottle ledger | Nothing. The inviter sees only how many friends signed up with their code and how many invites succeeded, never the friends’ pen names, accounts or sign-up times. The friend is not shown the inviter’s pen name either. Only the people you give your invite code to know it |
| Access and security records | IP address (stored as a hash with a secret key, to rate-limit sign-up and identity verification requests), log-in token | Abuse prevention, security | Nothing |
| Sign-up region check | Connecting IP address (looked up only to determine the region; not stored for this purpose) | Checking that sign-up is available in your region (new sign-ups are blocked in the United Kingdom, Brazil, and the US states of Mississippi and Tennessee). Region is determined using DB-IP data: “IP geolocation by DB-IP” (https://db-ip.com, CC BY 4.0) | Nothing |
| Age range signal (app 1.2, iOS 26 or later and Android) | The age range Apple or Google shares (used only for the sign-up decision; not stored) | Checking sign-up age. If the shared age range is under 19, sign-up is refused | Nothing |
| Sign-up refusal record | A hash made from your Apple or Google account ID, and the date you can sign up again | If you tried to sign up with a date of birth or age range that is under the minimum age, to stop the same account from trying again until the date you can sign up. It is deleted after that date passes | Nothing |
- We never store the email address or name of your Apple or Google account. The sign-in token that Apple or Google issues may contain your email address; our server reads only the account ID from it.
- Your date of birth is used only to check your age at sign-up. We keep only the birth year, which also gives the age range on your card and, from app 1.2, your age group for “letters I receive” settings and readers chosen by vehicle. In Korea, your name and full date of birth are used only to check the verification result and are not stored. We do not receive a phone number from the PortOne verification result.
- If you sign in with Apple, we exchange a one-time code from Apple for an Apple token and store it encrypted (AES-256-GCM). We use it for one purpose only: to revoke Reply’s access to your Apple ID when you delete your account. If you do not finish sign-up, we delete the token 24 hours after the sign-in request expires and, if no account exists for that Apple ID, ask Apple to revoke Reply’s access at that time, for the same purpose.
- Your gender, phone number, real name and date of birth are never shown to other users.
- An account that signed up in Japan, or whose pen-name card region is Japan, cannot choose the gender of the letters it receives, and the received-letter gender setting it makes is not applied. Choosing the recipient gender for a paid vehicle (rocket or Santa Claus) is also unavailable if the sender is a Japanese account or Japan is among the destination countries.
- At sign-up we use your connecting IP address to determine whether sign-up is available in your region, but we do not store the IP address for this purpose (the hashed IP kept for rate-limiting is unchanged). The region data is “IP geolocation by DB-IP” (https://db-ip.com, CC BY 4.0).
- An age range that Apple or Google shares on iPhone (iOS 26 or later) or Android is used only for the sign-up decision and is not stored. If the shared age range is under 19, sign-up is refused, with the same re-sign-up lock as an under-age date of birth.
- A recalled message disappears from the other person’s screen, but its original text stays on the server as evidence for reports.
- The log-in token is kept in your device’s secure storage. Some security events, such as App Review sign-in attempts, are written to server logs together with the IP address.
- We never receive card numbers or other payment details. Apple or Google processes the payment.
- Reply does not collect photos, videos, files, voice, device location (GPS) or your contacts. From app version 1.2, Google Analytics (Firebase) records that a sign-up or sign-in, a letter sent, a reply written or a reply accepted happened (the event name only), together with the app-instance ID and usage data Firebase collects automatically, such as device and app version and approximate region, to produce usage statistics. Your pen name, anything you write, your birth date, gender and Reply account number are not sent. There is no crash-reporting tool. The Google Mobile Ads SDK collects its own usage and diagnostic data (section 3).
- Reply does not send push notifications at present. If we add them, we will update this policy first.
- Ocean currents and beach scenes (app 1.2 or later) work at country and time-zone level only. They use the country on your pen-name card and your device’s time-zone setting. They do not use GPS, a location permission, your IP address or your sign-up country. The countries a helicopter can reach are looked up from the country on your card in a fixed table of sea regions on our server; nothing else about you is used or stored for this.
- Weather comes from MET Norway (the Norwegian Meteorological Institute). Our server asks MET Norway for the forecast at the fixed representative places of the world’s time zones, on its own hourly schedule, whether or not anyone is using the app. It sends only those fixed coordinates and an identifying header with our contact email. No information about you, your device or your IP address is sent, and the app never contacts MET Norway directly.
- Data sources: ocean routes are derived from the NOAA Global Drifter Program (CC BY 4.0; not endorsed by or affiliated with NOAA), weather from MET Norway (CC BY 4.0), time zones from the IANA tz database (public domain) and coastlines from Natural Earth (public domain). These sources contain no information about users. The full credits are in the app under Account → Data sources.
2. AI safety screening and automatic restrictions
- Letters, replies, messages, and your pen name and intro (when changed) are checked in two steps before they are stored or delivered: first a pattern check for contact details, links and messenger IDs, then an AI model provided by DeepSeek.
- Only the text being checked and the screening instructions are sent to DeepSeek. Your account ID, sign-in details, phone number and the rest of your pen-name card are not sent with it.
- Content judged inappropriate is not sent, and neither is content that cannot be checked at that moment.
- When you first create your pen-name card, we ask for your consent to send text to this third-party AI screening service, which may be in another country (section 4). Without it you cannot create a pen-name card, so you cannot use letters, replies or conversations. There is no in-app button to withdraw consent; delete your account or email us. Withdrawal handling to be confirmed
- If three or more different users report an account within 7 days, or two or more different users report it for child safety or threats, the account is restricted automatically until we review it. If you disagree, email us and a person on our team will review it.
3. Rewarded ads and consent
- Ads appear only when you choose “Watch for one bottle” on the screen where you get more bottles. No ads appear while you read, reply or chat. The ads are provided by Google AdMob, only in app builds with ads turned on.
- When you are signed in, the app first asks Google’s consent tool (User Messaging Platform) whether consent is needed where you are, and shows Google’s consent form if it is. The ad SDK starts only after you first choose “Watch for one bottle” and the consent tool allows ads. Where the tool offers it, an “Ad privacy settings” button on the screen where you get more bottles lets you change your choices at any time. Regions and choices covered by our consent message (e.g. EEA, UK, Switzerland, US states): to be confirmed when the message is set up in AdMob
- On iPhone and iPad, the first time you choose “Watch for one bottle”, Reply shows Apple’s tracking permission prompt (App Tracking Transparency) once, before the ad SDK starts. It is not shown when you open the app. If you allow it, the Google Mobile Ads SDK receives your device’s advertising identifier (IDFA) and may link it with information collected in other companies’ apps and websites to show more relevant ads and to measure ads. If you don’t allow it, everything works the same, including the bottle reward, and ad requests are sent without the advertising identifier. You can change your choice at any time in Settings → Privacy & Security → Tracking.
- According to Google’s disclosures for Android and iOS, the Google Mobile Ads SDK may collect your IP address (which may be used to estimate the general location of the device), interactions such as app launches, taps and video views, information about the ads you have seen, performance and diagnostic information, and device identifiers (on Android the advertising ID and app set ID; on iOS a device identifier such as the advertising identifier), for advertising, analytics and fraud prevention. Google processes this data under its own policies.
- To confirm a reward, Google sends our server your Reply account number and a one-time reward session number. We do not give Google your pen name, what you write, your date of birth or your gender.
- Whether the ads you see are personalised depends on your consent choices, your tracking choice (iPhone and iPad) and your device’s ad settings. Details to be confirmed
4. Service providers and international transfers
| Recipient | What they do | Information shared | Location |
|---|---|---|---|
| Railway | Hosting for the API server and database | All information the service stores | Server location (region) to be confirmed |
| Apple (Sign in with Apple) | Checking your sign-in; issuing and, when you delete your account, revoking the Apple token | The sign-in token and one-time code Apple gives the app; the stored Apple token when you delete your account | To be confirmed |
| Google (Google sign-in) | Checking your sign-in | The sign-in token Google gives the app is checked with Google’s public keys; our server sends Google no user data for this | To be confirmed |
| DeepSeek | AI safety screening | The text being checked (letters, replies, messages, pen name and intro) | Sent over an encrypted connection (HTTPS) each time you write. Destination country, recipient’s legal name and contact, and retention period to be confirmed |
| Apple (App Store) | iOS in-app purchase payment, transaction checks, refund notices | Transaction details, the purchase account token | To be confirmed |
| Google (Analytics, Firebase) | App usage statistics (from app 1.2) | Event names (sign-up or sign-in, letter sent, reply written, reply accepted), the app-instance ID, and usage data such as device and app version and approximate region | To be confirmed |
| Google (Google Play) | Android in-app purchase payment, transaction checks, refund notices | Transaction details, the purchase account token | To be confirmed |
| Google (AdMob and its consent tool) | Rewarded ads and ad consent (section 3) | The data the ad SDK collects (section 3); the Reply account number and reward session number used to confirm a reward | To be confirmed |
| PortOne and its contracted identity verification provider provider name to be confirmed (Korea only) | Identity verification | PortOne’s contracted provider processes the information you enter or confirm on the verification screen. Reply checks the name, date of birth and CI (or DI when CI is absent) in the result and retains only the birth year, CI/DI hash and verification time | To be confirmed |
| Operations alert tool, if configured service to be confirmed | New-report alerts | Report number and reason code only; no user-written text | To be confirmed |
- We share personal information with these providers only for the purposes above, and we require them to protect it at a level at least equal to this policy. Contracts and data processing terms with each provider: to be confirmed
- Apple and Google also process information under their own privacy policies when you sign in, pay or view ads.
- Reply is used in many countries, and the operator and the providers above process data in countries other than yours, so your information is transferred abroad. The operator’s country, the server region and DeepSeek’s destination country: to be confirmed.
- For users in the European Economic Area, the United Kingdom and Switzerland, the safeguard we rely on for each transfer (such as an adequacy decision or standard contractual clauses): to be confirmed. You can ask us for a copy of these safeguards by email.
5. Retention and deletion
When you delete your account in the app (Account → Delete account), we immediately:
- stop you from logging in;
- if you signed in with Apple, ask Apple to revoke Reply’s access to your Apple ID and erase the stored Apple token (if Apple cannot be reached, we still erase the token);
- erase any phone number retained from earlier Korean verification, sign-up country or region, gender, “letters I receive” setting, pen name, intro, interests and region;
- take your letters off the shore (including letters still at sea) and close your pending replies.
Deleting your account without the app: if you can no longer open the app, email hello@darak.studio with the subject “Delete my Reply account” and your pen name. Because we do not store your email address, we may ask you to confirm that the account is yours before we delete it as described here. Confirmation method and response time to be confirmed
After deletion, we keep:
- hashed account identifiers and account links (made from your Apple or Google account ID, plus your CI/DI if you completed Korean identity verification), sign-in method, birth year and consent records (terms and safety screening), to stop the same account from signing up again (a deleted Apple or Google account, or a deleted identity, cannot register again);
- letters, replies and messages that other people received, as part of their conversation history (you are shown to them as someone who has left);
- report, block and restriction records, purchase, refund and bottle ledger records, and invite records (app 1.2 or later);
- PortOne identity verification results (birth year, CI/DI hash and verification time); the sign-up and verification request records that contain a hashed IP address and the PortOne identity verification identifier are deleted 24 hours after they expire;
- the sign-up refusal record (a hash made from your Apple or Google account ID and the date you can sign up again), kept until that date and then deleted;
- records of discontinued earlier features (such as paid replies), if any exist.
Sign-up, sign-in and verification request records are deleted automatically (hourly) 24 hours after they expire, and sign-up refusal records after the date you can sign up again. These are the retention periods we apply now. Whether a legal retention duty applies to these records, and the retention period for all other items: to be confirmed. For all other items, automatic deletion when a retention period ends is not yet in place. When a retention period ends, the data is erased so it cannot be restored.
6. Your rights
- In the app: view and edit your pen-name card, block and unblock, change ad consent choices (where offered), delete your account (Account → Delete account).
- By email (hello@darak.studio), wherever you live: ask for access to or a copy of your information, correction, deletion, restriction of processing or objection to it, a copy in a portable format, or withdrawal of consent. We may need to confirm that the request comes from the account holder. Response time to be confirmed.
- European Economic Area, United Kingdom, Switzerland. The legal bases we rely on are to be confirmed by legal review: performing our contract with you (account, letters, replies, messages, purchases); our legitimate interest in keeping the service safe (safety screening, handling reports, preventing abuse, security) together with the consent you give for AI screening; your consent for ad-related processing, which you can withdraw at any time; and legal obligations. You may complain to the data protection authority where you live or work. Our representative in the EU and the UK: to be confirmed.
- United States. Depending on your state, you may have the right to know, access, correct and delete your personal information and to opt out of its “sale” or “sharing” for targeted advertising. We do not sell personal information for money, and we will not treat you differently for using these rights. Whether the ad SDK’s processing counts as a “sale” or “sharing” under a given state law, and how to opt out: to be confirmed.
- Adults only. You must be 19 or older to sign up for Reply in every country (outside Korea, by the date of birth entered at sign-up; in Korea, confirmed by identity verification). Accounts that already exist keep working. We do not knowingly collect personal information from younger people. If we learn that an account belongs to someone who was under the sign-up age when the account was created, we restrict it and delete it. Procedure to be confirmed
7. Security measures
- Traffic between the app and the server is encrypted (HTTPS).
- Apple and Google account IDs, CI/DI values and IP addresses are stored only as hashes made with a separate secret key; names are not stored.
- The Apple token is stored encrypted (AES-256-GCM) with a key derived from a separate secret, and it is never written to logs or sent to the app.
- Server secrets are never built into the app.
- Operator functions require a separate long secret token.
- Other administrative and physical measures: to be confirmed
8. Privacy officer and contact
Privacy officer: Darak Studio Co., Ltd. person to be confirmed
Contact: hello@darak.studio
Representative in the EU and the UK: to be confirmed
Agencies for privacy complaints and counselling: to be confirmed
9. Changes to this policy
We will announce changes in the app and on this page before they take effect. Effective date: 2026-10-03