PRIVACY

Privacy notice

Data controller

RealEng (real_talk) · Representative: 김유숭 · 경기도 화성시 동탄신리천로 270, 402동 4층 c189호

Information and purposes

On the web, account email, social sign-in identifiers, and the timestamp of your age-14-or-older attestation are used for sign-in and eligibility. The Apps in Toss mini app is offered by Toss only to users aged 19 or older, so a mini app user's eligibility follows from that platform rule rather than from an attestation the user made. In the mini app we store a consent record — the consent type, the version and wording agreed to, the time of agreement and the time our server recorded it, the app version, bundle, platform and runtime environment, and a SHA-256 hash of the anonymous identifier — to keep legally required evidence of consent and to meet Apps in Toss requirements. Across all channels, language and avatar settings, text transcripts, session information, learning reports, and usage time provide learning features and entitlements. Dodo Payments customer and subscription identifiers and subscription status manage web billing access. Apps in Toss order numbers, product codes, granted time, wallet balances, and available purchase or refund status manage mini-app payments and passes.

To keep learning on track, we store per-expression study records alongside lesson-level progress. A per-expression record contains the identifying codes of the lesson and expression studied, how many times it was answered correctly and incorrectly, the most recent study path (quiz, speaking drill, review, or conversation) and its outcome, the review stage and the next scheduled review time, and the first and most recent study times. It is used only to build the mistake note, the review schedule, and the weekly learning report. These records are learning state computed and stored by the service, and are not used to train AI.

If you use the Apps in Toss share reward, we store a grant record containing the share event identifier (a random value generated by the app to prevent duplicate grants when Toss does not supply one), the practice time granted, and the time of the grant. It is used only to prevent a duplicate grant for the same share and to enforce the daily and cumulative grant limits. The service neither receives nor stores personal information about the people you shared with, such as their names or contact details.

Apps in Toss user identifiers

When you sign in with Toss, we receive the app-specific user identifier (userKey) issued by Toss, link it to a service account, and use it to maintain sign-in, manage the wallet and learning history, and process disconnection. The one-time authorization code used during sign-in is used to verify Toss sign-in and issue a session, then is not stored separately. The service does not store a name, phone number, birth date, or address from Toss sign-in.

For guest access, we receive the mini-app-specific anonymous identifier issued by Toss, verify that it is valid, and create an anonymous service account. We do not store the raw anonymous key in the RealEng database; a one-way derived hash and an internal account identifier are used to associate the wallet and learning history with the same guest. Because a guest identifier can distinguish a user when combined with other data, we protect it under this notice.

Visit and marketing measurement

On the website, to measure advertising performance and improve the service, we process a randomly generated first-party visitor identifier, visit time, country-level location, display language, the visited path without its query string, normalized source, channel and campaign, and only the referring site's host name. When the country cannot be determined otherwise, the browser's reported time zone (for example Asia/Seoul) is used solely to infer it and is not stored. The visitor identifier is stored in an HttpOnly first-party cookie. We do not store raw IP addresses, user agents, full referrer URLs, or non-allow-listed URL query values in the marketing analytics database.

Camera and voice

Camera video is shown only as a local self-view on the user's device and is never uploaded, stored, or transmitted to RealEng servers. Audio is sent to the OpenAI API to provide live conversation, speech recognition, and pronunciation coaching, but raw audio is not stored in the RealEng database. Recognized text and AI responses may be retained under the conversation storage rules below.

real_talk is an English conversation learning service. It provides no voice uploading, voice cloning, impersonation, deepfake, facial recognition, biometric analysis, or replication of any real person's likeness or voice. The AI voices and avatars are synthetic characters that do not represent real individuals.

Conversation storage and retention

Recognized text exchanged between the user and AI is stored with the account's conversation session to provide learning history and reports, and is automatically deleted 90 days after creation. Basic session information such as the scenario and duration, and generated learning reports, are retained while the account remains active or as needed to provide the service and resolve disputes, and are deleted sooner if the user deletes the conversation or the account. Raw camera video and raw microphone audio are not retained in the RealEng database.

Overseas transfer to OpenAI (United States)

When providing AI conversations, speech recognition, translation, coaching, and learning reports, we transfer audio, recognized conversation text, target learning phrases, and session context to OpenAI in the United States. The transfer occurs over an encrypted connection when the user uses the relevant feature, for the purpose of generating AI responses, transcripts, translations, coaching, and learning reports.

Under OpenAI's current API data policy, the Realtime API does not retain separate application state to provide the feature, while abuse-monitoring logs that may include some input and output can generally be retained for up to 30 days. Application state for the Responses API used for reports and translations may be retained for 30 days by default. Exceptions may require longer retention to comply with law or protect the services or third parties from harm. OpenAI's policy also states that API data is not used to train its models unless the API customer explicitly opts in.

If you do not want this overseas transfer, do not start the AI conversation, speech recognition, coaching, or report features, or contact seeusoong@realeng.net to request restriction of processing or account deletion. Those AI learning features cannot be provided without the transfer.

Other retention periods

Consent records must stay available to prove that consent was given, so they are not deleted when an account is deleted; the account link is removed and only a form that cannot identify you — the hashed install identifier and the consent wording details — is kept. Website visit and marketing measurement data, including the first-party visitor identifier, is automatically deleted no later than 13 months after collection. Account and sign-in linkage information, entitlement balances, and learning settings are retained while the account remains active. Per-expression study records are automatically deleted 18 months after the last study date, and sooner if the account is deleted. Share reward grant records are retained while the account remains active because they are required to prevent duplicate grants and to enforce the limits, and are deleted together with the account. Payment, refund, and dispute records may be retained separately for the mandatory period required by applicable law and then deleted.

Service providers and payment channels

We use Supabase for authentication and data storage, OpenAI for AI features, Dodo Payments for web billing, tax, and refunds, and Vercel for web hosting. In Apps in Toss, Toss provides mini-app distribution, sign-in, and in-app payment infrastructure, while Google Play or Apple processes platform-specific payments and final refunds. We transmit only the information needed to provide the service over encrypted connections. Information processed directly by payment providers and app marketplaces is also governed by their terms and privacy notices.

Children's privacy

On the web, real_talk is available only to users aged 14 and older, and users must confirm that they are at least 14 before using the service. The Apps in Toss mini app is offered by Toss only to users aged 19 or older, so mini app users are 19 or older without a separate check on our side. On either channel, if we learn that information belongs to a user below the applicable age, we delete the account and related data.

Your rights, account deletion, and contact

Request access, correction, deletion, restriction, or account deletion at seeusoong@realeng.net or 070-7954-3513. Users signed in with Toss can also leave through ‘Disconnect’ in the mini-app profile, while guests can request deletion from customer support. Once account deletion is completed, we delete the profile, wallet, sessions, text transcripts, learning reports, lesson progress, per-expression study records, and share reward grant records linked to the service account, and we unlink the account from the Apps in Toss order ledger and from the consent records. Consent records remain in a form that cannot identify you, so that the fact of consent can still be evidenced. So that a refunded order can never be granted again to another account, the order number, product code, and payment or refund status remain in a form that is no longer linked to an account. Payment and dispute records that must be retained by law are stored separately and deleted when the required period ends; records held directly by Toss, an app marketplace, or a payment provider are handled under that provider's policy. The privacy contact is 김유숭.

Effective August 28, 2026