← Back to NariYume

Privacy Policy

Last updated: August 19, 2026 · Effective August 19, 2026

This Privacy Policy explains how Koro Interactive Pte. Ltd. (UEN 202525340Z), a private company limited by shares incorporated in Singapore (“Koro Interactive”, “we”, “our”, or “us”), collects, uses, and discloses personal data in connection with the NariYume mobile application for iOS and the NariYume web app at nariyume.com/app (together, the “App”).

We comply with the Singapore Personal Data Protection Act 2012 (“PDPA”). Where applicable, we also observe the EU General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”) for users in those jurisdictions.

1. Summary

2. Personal data we collect

2.1 Account information

When you sign in with Sign in with Apple or Google, we receive a stable user identifier (your Firebase UID). We store it alongside your chosen display name, the birth date you enter during setup (used for the age gate and a local birthday reminder; only the month/day and a coarse age range are ever sent to AI processors, see §4), and, if your Apple/Google account shares it, your email address. We also use a per-device identifier to manage which devices are signed in to your account. We do not receive your Apple or Google password.

2.2 Conversation content

Your messages, the AI’s replies, and metadata about your character’s mood and affection state are saved so the App can give you a continuous experience across launches and devices. This content is stored in Google Firebase (Firestore) under a document keyed to your Firebase UID, and locally on your device via Apple’s SwiftData framework.

2.3 Microphone and speech data

When you use voice mode, audio is captured by your device’s microphone and transcribed using Apple’s Speech Recognition framework — on-device whenever your device and language support it, otherwise via Apple’s speech servers under Apple’s privacy terms. The transcribed text is then sent to our AI inference proxy (see §4) to generate a reply. Raw audio is never sent to our servers or to any AI model provider, and we do not store audio recordings.

2.4 Usage and diagnostics

Firebase Analytics is enabled to help us understand aggregate feature usage and stability. We have configured the SDK so that no data is collected for cross-app or cross-site tracking. We do not use your data to build advertising profiles.

2.5 Purchase information

If you subscribe to NariYume Premium, Apple handles payment and shares a transaction identifier with us so we can grant your entitlement. We do not receive your payment card details.

2.6 Optional device data

The App can read from several optional sources on your device to make your character feel more aware of your day. Each of these is off by default, requires the relevant iOS permission, and is used only for the feature described below. You can turn any of them on or off at any time in iOS Settings or from within the App, and we do not store the underlying records on our servers.

3. Purposes of use

We collect and use personal data for the following purposes:

By using the App you consent, to the extent required under the PDPA, to the collection, use, and disclosure of your personal data for these purposes.

4. AI inference — third-party processors

AI responses are generated by third-party large-language models. The App does not contact any model provider directly: requests go to an inference proxy we operate at proxy.nariyume.com (hosted on Cloudflare Workers, and optionally passed through Cloudflare AI Gateway for cost and latency analytics with request logging disabled), which forwards them to OpenRouter. OpenRouter routes each request to a model-hosting provider. The model families we currently use are DeepSeek (conversation, games, memory) and Google Gemini (photo understanding and as an emergency fallback). We do not use any provider outside this chain.

You are asked to agree to this before any of it happens. On first use the App shows a “Before we start” screen naming these processors and the data below, and you proceed by tapping “I agree — let’s start”; nothing is sent until you do, and the App’s network layer refuses to send AI requests until you have. Because AI processing is what the App is, this is a one-time agreement rather than a switch: you can review what you agreed to, and when, under Settings → Privacy & Permissions → AI processing.

Depending on the feature you use, a request may include: the text of your messages and the recent conversation context; a photo you have explicitly attached (downscaled before sending); the first name you chose in the App; your birthday day (month and day only, no year) and a coarse age range; things your character has learned about you in conversation (memories) and notes you have saved; and, only if you have separately enabled them in Settings, a one-line summary of your current weather and the title and timing of your next calendar event. A random per-install identifier accompanies requests for rate limiting and cost measurement; it is not derived from your account.

We do not send your email address, account or sign-in identifiers, your full birth date or exact age, raw location coordinates, your calendar as a whole, photos you have not attached, or any voice audio to these processors.

Our proxy instructs OpenRouter, on every request, to route only to providers whose policy is not to store or train on request data (OpenRouter’s data_collection: deny setting); this setting is enforced on our server and cannot be changed by the App. Providers may still process the request transiently to generate the reply.

5. Content safety and reports

Every AI-generated message in the App exposes a Report action. When you tap Report, we record the message identifier, a truncated copy of the reported text, your Firebase UID (if signed in), and a timestamp in a separate Firestore collection used solely for human moderation review.

6. Disclosure of personal data

We do not sell personal data. We disclose personal data only to:

7. International data transfers

Your personal data is stored on Google Cloud infrastructure, which may process data in the United States, the European Union, or other countries. Where we transfer personal data out of Singapore, the EU, or the United Kingdom, we rely on contractual protections (including Standard Contractual Clauses where applicable) and on the security guarantees of our underlying providers.

8. Retention

9. Children

The App is intended for users aged 13 and older, or the minimum digital-consent age applicable in your jurisdiction, whichever is higher. We do not knowingly collect personal data from children below that age. If we learn that we have, we will delete it promptly.

10. Your rights

Depending on where you live, you have the following rights:

To exercise any of these rights, email our Data Protection Officer at [email protected]. We will respond within 30 days.

11. Security

We use Apple’s Keychain for on-device credential storage, Firebase’s managed security model for cloud data, and TLS for every network request. No system is perfectly secure; we encourage you to use a strong Apple ID / Google account password and enable two-factor authentication.

If we become aware of a personal-data breach that is likely to result in significant harm to you, we will notify you in accordance with applicable law (including the PDPA’s data breach notification obligation).

12. Data Protection Officer

We have designated a Data Protection Officer responsible for overseeing compliance with this Policy and applicable data protection laws. You may contact the DPO at [email protected].

13. YouTube and social media API services

We operate brand and character social-media accounts and an automated publishing service (the “NariYume Content Engine”) that post NariYume marketing content — text, images, and videos of our fictional characters — to our own accounts on third-party platforms, including YouTube. This automated video publishing uses YouTube API Services.

By viewing or interacting with our YouTube channel and content delivered through the YouTube API, you also agree to be bound by the YouTube Terms of Service. Google’s handling of any data collected through these API Services is described in the Google Privacy Policy.

The NariYume Content Engine authenticates only to our own brand accounts in order to publish our own content, using the minimum API scope required to upload videos to our channel. It does not access, request, collect, or store the personal data, Google account data, or YouTube data of any App user or member of the public. You can revoke this application’s access to our Google account at any time via the Google security settings page.

14. Changes to this Policy

We may update this Policy from time to time. When we do, we will post the new version here and update the date above. If the change is material, we will notify you inside the App.

15. Contact

Privacy and data requests: [email protected]
General support: [email protected]
Data Controller: Koro Interactive Pte. Ltd. (UEN 202525340Z), Singapore.

← Back to NariYume