1. Who we are
AIVERA operates the oorio brand and Services. For privacy questions or rights requests, use the website contact form or email tampeter@naver.com.
2. Scope
This Policy covers the oorio Universe website and oorio products that link to it. A product may present a supplementary privacy notice describing data unique to that product. The supplementary notice forms part of this Policy.
3. Information we may collect
Depending on the Service and features you choose, we may collect: account and contact information; inquiry-form content; profile and preference information; assessment answers and results; conversation content you submit; game activity and progress; subscription and transaction status received from an app store or payment provider; device, app, language, log, diagnostic, crash, security, and approximate network information; consent records; and communications with support. We do not receive full payment-card numbers from Apple or Google.
4. Sensitive information
Some self-reflection, assessment, or conversation features may involve information that could be sensitive, including information about wellbeing or health. We process such information only when necessary for a feature you choose, with an appropriate legal basis and additional safeguards. Do not submit information you do not want processed. Product-specific notices will explain any sensitive-data processing in greater detail.
5. How we collect information
We collect information directly from you, automatically from your device or browser, from app stores and service providers, and from integrations you intentionally connect. The website stores your language preference locally in your browser. The contact form is processed through our hosting/form provider.
6. Purposes of processing
We use information to provide and personalize Services; calculate results and progress; maintain accounts and subscriptions; respond to inquiries; protect safety and security; prevent fraud and abuse; diagnose errors; improve usability and reliability; comply with law; enforce terms; and, with consent where required, send service or marketing communications.
7. Legal bases
Where the GDPR or similar law applies, we rely on performance of a contract, consent, compliance with legal obligations, protection of vital interests where appropriate, and legitimate interests such as securing, operating, and improving Services. You may withdraw consent at any time, without affecting prior lawful processing.
8. Sharing and processors
We may share information with vendors that provide hosting, form processing, cloud infrastructure, analytics, crash reporting, customer support, authentication, payments, app distribution, communications, and AI processing. We may also disclose information to comply with law, protect rights and safety, complete a corporate transaction, or at your direction. Vendors may process information only for defined purposes under contractual or legal obligations. We do not sell personal information for money.
9. International transfers
Information may be processed in countries other than where you live. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, contractual protections, or consent. Product-specific notices may identify important providers and processing locations.
10. Retention
We retain information only as long as reasonably necessary for the purposes described, including account operation, legal obligations, dispute resolution, security, backup cycles, and fraud prevention. Retention periods vary by data type and product. We delete or de-identify information when it is no longer needed, unless law requires retention.
11. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information. No system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your device and credentials.
12. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about sharing. You may also complain to a competent privacy authority. We may verify identity and may retain information where legally permitted or required.
13. Account and data deletion
Where a Service uses accounts, it will provide an in-app deletion method or a clearly accessible deletion-request route as required by applicable platform rules. You may also contact us. Deleting an account may not immediately remove information retained for legal, security, fraud-prevention, or backup purposes.
14. Children
Services intended for general audiences are not directed to children below the minimum age permitted without parental consent. Child-focused products will use age-appropriate design, parental consent where required, data minimization, and product-specific disclosures. We do not knowingly collect children’s personal information contrary to applicable law.
15. Cookies, local storage, and similar technologies
The website may use essential cookies or local storage for language, security, and core functionality. If we add non-essential analytics or advertising technologies, we will provide appropriate notice and consent controls where required. We do not currently use the website contact form for behavioral advertising.
16. Automated processing
Some Services may generate assessments, recommendations, difficulty adjustments, or conversational responses using automated systems. Unless a product expressly states otherwise, these outputs do not produce legal or similarly significant effects without human involvement.
17. Platform disclosures
Our Apple App Privacy and Google Play Data safety declarations are intended to reflect actual product behavior. Because products evolve, the current store disclosure and any in-product notice should be read together with this Policy. We update disclosures when data practices change.
18. Changes to this Policy
We may update this Policy to reflect changes in products, technology, law, or providers. We will post the revised Policy and effective date and provide additional notice where required.
19. Contact and complaints
Contact: tampeter@naver.com or the website contact form. Operator: AIVERA. You may also contact the privacy or data-protection authority in your jurisdiction.
