Privacy Policy
Operator (Data Controller): AK Interactive Co., Ltd.
Service: Baseline
Effective Date: June 15, 2026
Version: v1.0
Baseline continuously observes your health to detect changes from your personal baseline and show you your daily health state. This Policy explains how your personal information is collected, used, and protected, in accordance with Article 30 of the Personal Information Protection Act ("PIPA") of the Republic of Korea.
This English text is a translation provided for convenience. In the event of any conflict with the Korean version, the Korean version prevails.
At a Glance
- •Baseline uses the health data it collects only to show you your health state.
- •We do not sell your health data, and we do not use it for advertising.
- •Your account and health data are stored on servers located in Korea (Seoul).
- •For AI-generated health interpretation, some data is transmitted to AI providers in the United States in encrypted form, and is not used to train their models.
- •You can delete your data directly in the app, and request access or an export at any time.
- •The Service is available only to users aged 19 and over.
1. General
AK Interactive Co., Ltd. (the "Company") values your personal information and complies with PIPA and related laws. The Company operates Baseline (the "Service") and, through this Privacy Policy (this "Policy"), explains the purposes and methods by which your personal information is processed and the measures taken to protect it.
In this Policy, "user" means a data subject who registers for and uses the Service. The Company makes this Policy continuously available within the Service or on its website and will give advance notice of any material changes.
A health-management tool. Baseline is a health-management aid that detects and displays changes relative to your personal baseline. It is not a substitute for medical care (diagnosis or treatment) or a medical device. If you have health concerns, please consult a qualified medical professional.
2. Personal Information We Process and How We Collect It
The Company collects only the minimum personal information necessary to provide the Service.
| Category | Items collected | Required / Optional |
|---|---|---|
| Account & authentication | From social login (Apple, Kakao, Google): the account identifier, email address, name or nickname, and profile information | Required |
| Profile & body metrics | Year of birth, sex, height, weight, time zone/language, profile image, notification settings | Some required, some optional |
| Self-reported health information (sensitive) | Health conditions, symptoms, and medications you enter | Optional |
| Wearable / vitals / sleep / activity metrics (partly sensitive) | Heart rate, heart rate variability, and similar vital-sign metrics; sleep metrics (duration, efficiency, stages, etc.); activity metrics (steps, calories, exercise time, etc.) | Optional (with permission) |
| Health checkup / lab results (sensitive) | Uploaded checkup documents (image/PDF) and values extracted from them — general checkup items such as body measurements, blood pressure, blood and urine tests, plus sensitive items including Hepatitis B/C markers and depression/cognitive screening scores, and physician opinion | Optional (on upload) |
| Journal / check-ins (sensitive) | Condition score, stress score, presence of symptoms, free-text memo | Optional |
| Menstrual / cycle information (sensitive) | Period start date, flow level, cycle phase/day, whether cycle tracking is enabled | Optional |
| AI conversation content (sensitive) | Chat messages between you and the AI, conversation titles and metadata (including in-app chat and the KakaoTalk channel) | Optional (when used) |
| Derived scores & baselines | Health scores, states, and analysis/inference results computed from collected data | Auto-generated |
| Processing data for analysis/search (sensitive) | Processing data generated and stored to provide search/analysis features, and the corresponding source text | Auto-generated |
| Device / connection / logs | Device identifier, platform/app version, sync events, access/refresh tokens for connected services, access logs/IP address, push notification token | Required |
| Usage analytics | Screen/feature usage events, user identifier (does not include health values) | Required |
How we collect
- • Directly from you when you register, set up your profile, enter journal entries, or upload checkup documents
- • From the provider when you sign up or sign in via social login (Apple, Kakao, Google)
- • From Apple Health (HealthKit) and connected wearables (Oura, etc.) with your consent, when you grant permission and connect them
- • From AI conversations via in-app chat or the KakaoTalk channel
- • Automatically during use of the Service (score/baseline computation, logs/device information, usage analytics, etc.)
Wearable and health platforms import data only when you connect your own account (for example, Oura data is retrieved from overseas servers and stored on servers in Korea), and you can disconnect at any time. Currently connected: Apple Health, Oura. Coming soon: Samsung Health, WHOOP.
3. Purposes of Processing
The Company uses collected personal information only for the following purposes; if a purpose changes, it will take necessary measures such as obtaining separate consent under Article 18 of PIPA.
- Providing the health-monitoring service — establishing your personal baseline, detecting deviations from it, analyzing health patterns, and providing the state signal (Green/Yellow/Red)
- AI-based health interpretation and chat — generating Korean-language health interpretations and suggestions, AI chat responses, and extracting data from checkup documents, based on collected metrics/checkups/records
- Search and analysis features — retrieving and connecting relevant context to provide search and analysis features
- Notifications — sending push notifications about health-state changes and the Service
- Member management and customer support — identity verification, registration/withdrawal, inquiries, and notices
- Service operation, improvement, and stability — error monitoring/diagnostics (Sentry), product usage analytics (PostHog), fraud prevention, and quality improvement
4. Processing of Sensitive Information (Health Information)
By its nature, Baseline processes a range of sensitive information (Article 23 of PIPA), specifically:
- • Wearable vitals and sleep data
- • Health checkup/lab results (including Hepatitis B/C markers and depression/cognitive screening scores)
- • Self-reported conditions, symptoms, and medications
- • Journal/check-ins (condition, stress, symptoms, memo)
- • Reproductive-health information such as menstrual/cycle data
- • Uploaded checkup documents and images
- • AI conversation content and the analysis/search data generated from it
- • Health-state inferences derived from the above
The Company processes such sensitive information according to the following principles:
- • The Company obtains separate consent, distinct from other personal-information processing, before processing sensitive information, and informs you of any disadvantage (such as feature limitations) of withholding consent.
- • Sensitive information is used only for the health-management purposes specified in Section 3, and is not used or provided for advertising/marketing, identity-based data mining, sale to data brokers, or any other purpose.
- • Sensitive information is protected with additional safeguards (encryption in transit and at rest, access controls, etc.; see Section 11).
- • You may withdraw your consent to the processing of sensitive information at any time, and upon withdrawal the Company will destroy the relevant information without delay (except where retention is required by law).
Your control. Connecting or uploading health data is entirely your choice, and you can change or revoke permissions and connections at any time in your device settings or within the Service.
5. Retention and Use Period
The Company destroys personal information without delay once the purpose of processing is achieved or the retention period expires.
| Category | Retention period | Basis |
|---|---|---|
| Account/profile information | Until withdrawal of membership (destroyed without delay upon withdrawal) | User consent |
| Health-related data (sensitive) — checkups, journal, conversations, embeddings, etc. | Until withdrawal of membership or withdrawal of the relevant consent (destroyed without delay thereafter). No separate automatic expiry (TTL) is set | User consent |
| Access logs (logs of the personal-information processing system) | At least 1 year (at least 2 years where large volumes of sensitive information are processed) | Standards for Securing the Safety of Personal Information |
Upon withdrawal of membership (account deletion), the Company cascade-deletes the user's personal information, including uploaded checkup images. Where retention is required by applicable law, such information is stored separately from other personal information and is not used for any purpose other than retention.
6. Provision to Third Parties
The Company does not provide your personal information to third parties beyond the scope stated in this Policy, except:
- • where you have given prior consent; or
- • where there is a special provision of law, or an investigative agency requests it through lawful procedures.
The Company does not routinely provide personal information to third parties. Matters where processing is entrusted to external providers to operate the Service are addressed separately in Section 7 (Entrustment) and Section 8 (Overseas Transfer).
7. Entrustment of Personal-Information Processing
To provide the Service smoothly, the Company entrusts personal-information processing as follows. In entrustment agreements, the Company specifies in writing, under Article 26 of PIPA, matters such as the prohibition of processing beyond the purpose, safety measures, restrictions on re-entrustment, management/supervision, and liability for damages, and it supervises the entrustees.
| Entrustee | Entrusted work | Notes |
|---|---|---|
| Amazon Web Services | Cloud infrastructure and data storage | Storage region: Republic of Korea (Seoul) |
| Supabase, Inc. | Database, backend infrastructure, and storage operation | Server/data location: Republic of Korea (Seoul) |
If the content of the entrusted work or the entrustee changes, the Company will disclose it without delay through this Policy. Matters relating to the transfer of personal information to overseas providers are addressed separately in Section 8.
8. Overseas Transfer of Personal Information
To provide the Service — including generating AI-based health interpretations and analyzing checkup documents — the Company transfers personal information overseas (for processing/storage) as set out below. The Company discloses the following in this Policy under Article 28-8 of PIPA, and where sensitive information is involved, obtains separate consent to the overseas transfer from the user.
| Recipient | Country | Items transferred | Timing / method | Purpose | Retention / use period |
|---|---|---|---|---|---|
| Anthropic, PBC (privacy@anthropic.com) | USA | Health/sleep/activity metrics, checkup values, self-reported health information, journal entries, and chat messages needed for interpretation | Encrypted (TLS) transmission via API when the feature is used | AI health interpretation and chat responses | Not used for model training. Deleted within ~30 days |
| Google LLC (data-access-requests@google.com) | USA | The full uploaded checkup document/image (which may contain name, resident registration number, etc.) | Encrypted (TLS) transmission via API when a document is uploaded | Data extraction from checkup documents | Not used for model training (on the paid tier) |
| OpenAI, L.L.C. (privacy@openai.com) | USA | Text of chat messages, checkup-document excerpts, and lab values | Encrypted (TLS) transmission via API when such data is generated | Providing search/analysis features | Not used for model training. Deleted after ~30 days |
| Sentry (Functional Software, Inc. — compliance@sentry.io) | USA | Email/IP/device/error information (session-replay text and images are masked by default) | When an error occurs or during app use | Error monitoring and app stability | ~90 days (varies by plan) |
| PostHog (PostHog, Inc. — privacy@posthog.com) | USA | Screen/feature usage events, user identifier (no health values) | During app use | Product usage analytics | Per PostHog's retention policy/settings |
Refusing the overseas transfer. You may refuse the overseas transfer of your personal information. However, features that involve overseas processing — such as AI health interpretation and automatic analysis of checkup documents — may be limited if you refuse. You can make this request at privacy@baselineop.com.
If you use social login, Apple (USA) and Google (USA) may process authentication information such as your email and name during authentication, while Kakao login is processed domestically.
Recipients process the transferred information only within the purposes above and do not use it for any other purpose such as model training. The Company secures protections equivalent to the level required by PIPA through data processing agreements (DPAs) and similar measures with the recipients.
9. Destruction Procedure and Method
Procedure. Personal information whose retention period has expired or whose purpose has been achieved is destroyed through procedures under internal policy. Where retention is required by law, it is destroyed after the retention period ends.
Method
- • Electronic files: permanently deleted by means that prevent recovery or reproduction
- • Paper and other printouts: shredded or incinerated
Upon withdrawal of membership (account deletion), uploaded checkup images stored in storage are deleted first, after which all personal data linked to the account is cascade-deleted. Upon withdrawal of consent to sensitive-information processing, the relevant data is likewise destroyed without delay by the methods above.
10. Rights of Data Subjects and How to Exercise Them
You (and your legal representative) may exercise the following rights at any time:
- • Request to access your personal information
- • Request to correct or delete errors, etc.
- • Request to suspend processing
- • Withdraw consent (including consent to sensitive information and overseas transfer) and withdraw membership
You may exercise these rights within the Service settings or by contacting the Privacy Officer (Section 16) in writing, by email, etc., and the Company will act without delay under Article 41 of the PIPA Enforcement Decree and related provisions. If exercised through a representative, a power of attorney must be submitted. Requests for access, correction, etc., may be restricted under applicable law.
11. Measures to Secure Safety
The Company takes the following measures to secure the safety of personal information:
- • Encryption in transit: TLS encryption for all data communications
- • Encryption at rest: encrypted storage of key sensitive information; checkup documents and the like are stored encrypted (server-side encryption / key management, SSE-KMS)
- • Access control: minimization and differentiated assignment of access rights to the personal-information processing system, and control of external access
- • Access-log retention and review: retention of system access logs and prevention of forgery/alteration
- • Internal management: establishment and implementation of an internal management plan and training of personnel who handle personal information
12. Automatic Collection Tools and How to Refuse
The Service may automatically collect device information, access logs, push notification tokens, and the like to identify users and operate the Service. You can refuse or change permissions such as notifications through your device or OS settings.
To improve service quality and ensure stability, the Company uses the following tools:
- • Product usage analytics (PostHog): collects screen/feature usage events and a user identifier. It does not include health values.
- • Error monitoring (Sentry): collects email/IP/device/error information for diagnostics. Where the session-replay feature is used, screen text and images are transmitted masked by default.
These tools are operated by providers located in the United States; related overseas-transfer matters are governed by Section 8.
13. Apple Health (HealthKit) and Wearable Data
For data the iOS app accesses through Apple Health (HealthKit), the Company complies with Apple's policies and the App Store Review Guidelines.
- • Health data collected from HealthKit and connected wearables is used only for your health management.
- • Such data is not used for advertising/marketing or sold to third parties, and is not used for purposes unrelated to its original purpose, such as data mining.
- • Health information collected via HealthKit is not stored in iCloud.
- • You can review and change Baseline's data-access permissions at any time in iOS under Settings > Privacy & Security > Health or in the Health app.
14. No Advertising or Behavioral Profiling
Baseline does not display targeted advertising within the Service, and does not perform behavioral analysis based on sensitive information such as health data, nor use advertising identifiers for tracking users across other companies' apps and websites (cross-app tracking).
15. Age Restriction
Because the Service handles sensitive health information, only users aged 19 and over may register and use it. The Company does not target minors, including children under 14, and does not collect personal information from those age groups.
16. Privacy Officer and Access Requests
The Company has designated a Privacy Officer to oversee personal-information processing and handle user inquiries and complaints.
| Item | Details |
|---|---|
| Privacy Officer | Mingi Cho (Director) |
| Contact (email) | privacy@baselineop.com |
You may direct privacy-related inquiries, complaints, and remedy requests to the contact above, and the Company will respond and act without delay.
17. Remedies for Infringement
To obtain relief for personal-information infringement, you may apply for dispute resolution or consultation with the following bodies:
- • Personal Information Dispute Mediation Committee — 1833-6972 / kopico.go.kr
- • Privacy Infringement Report Center (Korea Internet & Security Agency) — 118 (no area code) / privacy.kisa.or.kr
- • Supreme Prosecutors' Office Cyber Investigation — 1301 / National Police Agency Cyber Bureau — 182
(These are Korean authorities. Users outside Korea may also contact their local data-protection authority.)
18. Changes to This Policy
This Policy applies from its effective date. If the content is added to, deleted, or modified due to changes in law or the Service, the Company will give notice within the Service or on its website at least 7 days before the change takes effect (at least 30 days for material changes that are disadvantageous to users). The Company also keeps the previous version of the Policy available for users to review.
- • Date of notice: June 15, 2026
- • Effective date: June 15, 2026
This Privacy Policy applies to the Baseline service operated by AK Interactive Co., Ltd.
Contact: privacy@baselineop.com
