Nina AI
Privacy Policy
Effective: June 23, 2026 | Last updated: July 6, 2026
Hyeon Tae Kim (the "Operator") establishes and discloses this Privacy Policy to protect users' personal information in connection with the mobile application Nina (the "App") and related services (the "Service"), in compliance with applicable laws including the Personal Information Protection Act of Korea.
1. Personal Information Collected and Collection Methods
The Operator may collect the following personal information to provide the Service.
| Category | Items collected | Collection method |
|---|---|---|
| Sign-up / login | Service user ID, social provider identifier, email (if provided; when using Apple “Hide My Email,” a relay proxy email may be stored), name (entered in the App), profile photo URL (Kakao, only with separate consent), login provider (Kakao/Google/Apple) | Received from Kakao, Google, or Apple when using social login. Kakao nicknames, gender, and date of birth are not collected. Kakao profile photos are collected only after separate consent in profile settings. |
| Profile / onboarding | Name, gender, date of birth, height/weight, activity level, goal type (lose/maintain/gain), target weight (final goal and cycle-stage goal), weekly pace (kg/week), estimated duration (weeks), onboarding type (fast/standard/minimal), profile photo or in-app preset icon | Entered, selected, or uploaded by the user in the App |
| Meal logs | Food name, calories and macronutrients (carbs, protein, fat), per-serving basis and serving count, meal type and log time, public nutrition database reference ID (when searching or logging) | Entered by the user or generated through AI analysis, food search, or saved food selection |
| Food photos | Analysis image (not stored on servers), thumbnail image for meal log display | Captured or selected after camera or photo library permission |
| Saved foods | Food name, nutrition information, image (if any), public nutrition database reference ID | Saved by the user from meal logs or related flows |
| Health goals | Target calories, carb/protein/fat targets (g) and macronutrient ratio (%), calorie rollover enabled and cap | Entered or configured by the user in the App |
| Notifications (optional) | Device notification permission status | User response to permission request (push delivery is not currently provided) |
| Service usage | Access timestamps, IP address, device info (OS, app version, etc.), auth tokens, error and crash logs, usage analytics | Generated automatically during use of the Service |
| Local device storage | Auth session, on-device cache of server-synced data (profile, health goals, meal logs, etc.), recent food search terms, notification settings | Stored on the device by the App (relevant items cleared on logout or account deletion) |
The Operator does not knowingly collect personal information from children under 14. If such collection is identified, the information will be deleted without delay.
2. Purposes of Collection and Use
- User identification, authentication, and service provision
- Meal logging, saved foods, nutrition analysis, and calorie/macro goal management
- Food search and nutrition lookup based on public nutrition databases
- Extracting nutrition information through AI analysis of food photos
- Storing and syncing profile, onboarding, and personalized settings across devices
- Service improvement, error and crash handling, security, and abuse prevention
- Usage analytics and statistics (screen views, feature usage, etc.)
- Handling user inquiries and complaints
- Compliance with legal obligations
3. Retention and Use Period
Personal information is retained until the purpose of collection and use is fulfilled. Where required by law, information may be retained for the period prescribed by applicable regulations.
- Member information, profile, health goals, meal logs, saved foods, and uploaded photos: Until account deletion (deleted without delay after deletion)
- Error and crash logs: Per processor retention policy
- Usage analytics: Per processor retention policy (identifiers reset on logout or account deletion)
- Legal retention: As required by applicable laws, including consumer protection regulations
4. Provision to Third Parties
The Operator does not provide users' personal information to third parties in principle, except in the following cases:
- When the user has given prior consent
- When required by law or by lawful request from investigative authorities
5. Processing Entrustment and Cross-Border Transfer
The Operator may entrust processing or use services of overseas providers as follows to operate the Service.
| Processor | Entrusted tasks | Retention period |
|---|---|---|
| Supabase, Inc. | Authentication, database and file storage, serverless function execution | Until contract termination or account deletion |
| AI analysis service providers | AI nutrition analysis of food photos | Until the analysis request is completed (cross-border transfer possible; configured to disallow long-term retention and model training) |
| Kakao Corp. | Kakao social login authentication | Until authentication is completed |
| Google LLC | Google social login authentication | Until authentication is completed |
| Apple Inc. | Apple social login authentication | Until authentication is completed |
| PostHog, Inc. | App usage analytics and product statistics | Until the analytics purpose is fulfilled or upon account deletion/request |
| Functional Software, Inc. (Sentry) | App error and crash collection, performance monitoring | Per processor retention policy |
Processors' servers may be located outside the Republic of Korea, and users' personal information may be transferred abroad. The Operator complies with protection measures required by applicable law.
6. Destruction Procedures and Methods
Personal information is destroyed without delay when the retention period expires or the purpose is achieved.
- Electronic files: Permanently deleted in a manner that prevents recovery
- Paper records: Shredded or incinerated
- Upon account deletion: Account information, profile, health goals, meal logs, saved foods, uploaded photos, and related data are deleted and local device cache is cleared (except where legal retention is required)
7. User Rights and How to Exercise Them
Users may exercise the following rights at any time:
- Request access, correction, deletion, or suspension of processing of personal information
- Withdraw consent to collection, use, or provision of personal information
- Request account deletion
These rights may be exercised through in-app settings or the contact information below. The Operator will take action without delay in accordance with applicable law.
8. Security Measures
The Operator implements the following measures to protect personal information:
- Access control and least-privilege principles
- Access controls so users can access only their own data
- Encryption in transit and authenticated API access
- Secure server-side storage of sensitive information
- Secure on-device storage of authentication information
- Minimal collection of sensitive information for error and analytics services
- Minimizing personnel with access to personal information
9. Device Permissions and Local Storage
The App may use the permissions and storage below. Users may deny permissions in device settings.
- Camera and photos: Food capture/selection and profile photo upload (denial may limit these features)
- Notifications: Local scheduled reminders at breakfast, lunch, dinner, and snack times (optional; scheduled on device)
- On-device storage: Login session, server data cache, recent search terms, notification settings, etc. (relevant items cleared on logout or account deletion)
10. Privacy Officer
The Operator designates the following privacy officer to oversee personal information processing and handle user complaints and remedies.
- Name: Hyeon Tae Kim
- Title: Operator
- Email: contact@kodoko.ai
11. Remedies for Infringement
For reports or consultation regarding personal information infringement, users may contact:
- Personal Information Dispute Mediation Committee (Korea): 1833-6972 — www.kopico.go.kr
- Korea Internet & Security Agency (KISA) Privacy Center: 118 — privacy.kisa.or.kr
12. Changes to This Policy
If this Policy changes, notice will be provided in the App or on this page. If changes materially affect user rights, notice will be given at least 7 days before the effective date (30 days in advance if unfavorable to users).
The Korean version of this Privacy Policy is the authoritative version for users in Korea. This English translation is provided for convenience.