1. Scope and operator
This policy applies to the ENORI iOS app, this website, customer support, and related services. The data controller and service operator is BBDynoLab, located in Seoul, Republic of Korea. Send privacy, rights, and legal requests to della.kimko@gmail.com. In-app support reaches the same operator.
2. Information we collect
Account and authentication
- Sign in with Apple identifier, login status, and security tokens
- Name or private relay email provided by Apple when you choose to share it
- Device installation identifier, notification token, app language, and time zone
Profile and introduction preferences
- Nickname, date of birth, gender, nationality, and country, region, and city of residence
- Job category, lifestyle preferences, relationship goals, distance and relocation preferences, interests, personality descriptions, languages and levels
- Introduction, first question, and preferred gender, age, countries, regions, languages, and relationship direction
ENORI does not collect profile photos. Your search preferences are not shown to people you are introduced to.
Service activity
- Daily introductions, skips and requests, acceptances and declines, matches, and chat messages
- YEON balance and ledger, App Store product and transaction identifiers, purchase and refund status
- Choices such as pausing introductions, blocking, and requesting account deletion
Safety, age verification, and support
- Age-verification image, submission country and time, review status, and outcome
- Document type, version, language, and acceptance or withdrawal time for the adult notice, Terms, Privacy Policy, Community Rules, and sensitive profile processing
- Feature-specific acknowledgements, including profile truthfulness and the age-document processing notice
- Report category and details, block choice, and the range of recent messages you elect to include
- Moderation reason, appeal statement, review status, and outcome
- Support category, reply email, inquiry details, and handling status
Technical information
- Request time, error and security logs, IP address, and information needed for network delivery
- Minimal first-party events used to maintain service quality and prevent abuse
3. How we use information
- Create and authenticate accounts, publish profiles, and provide mutually compatible introductions
- Provide requests, matches, chat, on-device translation, and notifications
- Process YEON purchases, use, restoration, receipts, and refunds
- Verify age, protect contact sharing, review content, and respond to reports and blocks
- Handle support, resolve incidents, and improve service security and reliability
- Meet legal obligations and address disputes, fraud, and abuse
Translation privacy: Supported chat translation is processed on your device. The translated result is not sent to or stored on ENORI servers. Original messages are stored to provide the conversation.
4. Legal bases and consent
Depending on applicable law, ENORI processes information to perform the service contract, provide requested features, pursue legitimate safety and security interests, comply with legal duties, and based on consent where required. The adult notice and contractual documents are presented separately. Matching and publishing profile attributes such as nationality, gender, and relationship goals requires a separate consent. Withdrawing it stops profile publication and introductions, while support, rights requests, and account deletion remain available.
5. Sharing and service providers
ENORI does not sell personal information as advertising data. The following providers may process information only as needed to deliver the service:
- Apple: Sign in with Apple, App Store in-app purchases, server notifications, and push notifications
- Cloudflare: API execution, database, private age-verification file storage, security, and delivery
- Legal and safety recipients: when required by law or needed to protect life and safety, address rights violations, or prevent fraud
International processing and transfers
- Cloudflare, Inc.: processes account, profile, chat, report, support, purchase-status, and technical information for API execution, D1 database, private R2 storage, delivery, and security. Production D1 and R2 use APAC as their primary location; transit, security, and support may involve the United States and other countries where Cloudflare operates. Transfers occur over encrypted networks during service use and data is retained for the periods below or until the service-provider agreement ends.
- Apple Inc. and affiliates: process Sign in with Apple identifiers, app-account tokens, purchase/refund identifiers, and notification tokens for authentication, payments, refunds, and push delivery in the user’s App Store region and countries where Apple operates. Transfers occur over encrypted networks when those services are used, and Apple retains data under its legal obligations and service policies.
- Google LLC: if you email the public contact, Gmail may process the email address and message in the United States and other countries where Google operates. Transfer occurs over an encrypted network when the message is sent and retention follows inquiry handling and mailbox settings.
ENORI does not sell or share personal information for advertising. Where law requires separate transfer consent, signup will repeat the recipient, country, purpose, and effect of refusal. Refusing a necessary transfer may prevent authentication, storage, purchases, notifications, or email support, but in-app rights requests and account deletion remain available.
6. Retention and deletion
- Account, profile, preferences, chats, and support inquiries: kept while the account is active and deleted with the account. Blocks and service settings follow the same schedule.
- Age-verification images: may wait for review for up to seven days and are deleted within 24 hours after approval or rejection. Undecided materials expire and are deleted after seven days. The adult-status result, reason, and review time remain until account deletion.
- Consent and acknowledgement records: document type, version, language, acceptance or withdrawal time, and feature acknowledgements remain as a change history until account deletion.
- Pseudonymized safety evidence: report details and up to 50 recent messages you elect to include are separated from account information and kept for up to 180 days after closure. A documented legal hold may extend retention only until the recorded end of a dispute or lawful request.
- Moderation and appeal records: kept while the account is active or for the longer applicable safety-evidence period; directly identifying records are deleted with the account.
- Minimal purchase records: after account deletion, transaction identifiers are hashed and separated from the account, kept for five years from the transaction for commerce, tax, refund, and dispute duties, then deleted.
- Security and administrator audit records: kept for up to one year. Audit records tied to a legal hold follow the safety-evidence rule above.
At the end of retention, electronic records are deleted so they are not reasonably recoverable and reasonable steps propagate deletion to processors.
7. Your choices and rights
Subject to applicable law, you may request access, correction, deletion, restriction or objection, withdrawal of consent, and portability of your personal information.
- Profile and preferences: edit them under Me in the app
- Withdraw sensitive-profile consent in Privacy settings (profile publication and introductions stop)
- Pause or resume introductions and manage notifications in Settings
- Review and remove blocked users in Safety settings
- Appeal moderation through the in-app appeal or support route
- Delete account: Me → Account → Delete Account
- Other requests: submit an in-app support ticket
We may need additional verification to protect your account. If a legal exception applies, we will explain the reason and available appeal process.
8. Security
We have implemented encryption in transit, limited access, environment-specific secret keys, encrypted notification tokens, role-based access, dual approval for material policy changes, and audit records, and will enable operator multi-factor authentication before launch. No method is completely secure. If a breach occurs, we will notify users and authorities as required by applicable law.
9. Adults only
ENORI is only for people aged 18 and over. If we learn that information from a minor has been collected, we restrict the account and delete the information as required. Sign in with Apple verifies account control; it does not replace adult verification.
10. Service territories
Initial ENORI registration and matching are for residents of the Republic of Korea and Japan. ENORI will not be offered in other App Store territories until the applicable privacy, online-safety, adult-connection-service, and local-representative requirements are completed.
11. Changes and contact
We will announce material changes in the app or on this site before they take effect and request new consent where purposes or mandatory document versions change. Submit requests in Me → Privacy, Terms & Support or email della.kimko@gmail.com.