Privacy Policy
AirOut Inc. (“we”) publishes this policy under Article 30 of the Korean Personal Information Protection Act (PIPA). It applies to the QMIX application and related services.
Language generation, speech recognition and speech synthesis all run on servers we operate ourselves — your conversations are not sent to any third-party AI provider.
1. Why we process personal data
- Providing the service — creating, storing and resuming conversations; syncing across devices
- Identifying and authenticating you — Sign in with Apple, keeping you signed in
- Conversation ownership — deciding and recording whether a conversation created before sign-in may be moved to your account
- Operating and improving the service — handling errors, checking response performance, preventing abuse
2. What we collect
a. If you create an account
| Item | Detail | Required |
|---|---|---|
| Apple account identifier | The per-app identifier (sub) Apple issues. On its own it does not
reveal your real name or contact details. |
Yes |
| Email address | Only if you choose Share My Email on the Sign in with Apple sheet. If you choose Hide My Email, we receive Apple’s relay address (privaterelay.appleid.com). We do not send marketing email to either. | No |
| Session value | A SHA-256 hash of your sign-in token plus its expiry. The token itself is stored only on your device, never on our servers. | Yes |
We do not collect your name. Our Sign in with Apple request is configured not to ask for it.
b. Created while you use the service
| Item | Detail |
|---|---|
| Conversation content | What you type and what QMIX replies. Your first message is also used as the conversation title. |
| Attached images | Only images you deliberately send from the camera or your photos. |
| Voice | Audio captured while the microphone is on is processed solely to transcribe it. The audio itself is not stored. The resulting text is stored as conversation content. |
| Usage records | Model name, token count, response latency and timestamps — used for performance checks and error handling. |
| Conversation metadata | Conversation id, title, owner, created and updated times. |
c. If you use QMIX without signing in
You can talk without an account. Your messages are stored on the server temporarily, but when you quit and reopen the app that conversation is deleted from the server and a new one begins. No Apple identifier or email is collected.
d. Automatically collected data
We use no cookies, no advertising identifiers and no web analytics tools. Our web server does record access logs — IP address, request time and request path — used only for security incident response and fault analysis.
e. What we never collect
Name, date of birth, gender, phone number, postal address, payment details, location, contact lists, your photo library at large, health data, or any category treated as sensitive information (PIPA Art. 23) or a unique identifier (PIPA Art. 24).
3. How long we keep it
| Data | Retention | Basis |
|---|---|---|
| Account data (identifier, email) | Until you delete your account | Your consent |
| Conversations and attached images | Until you delete them or delete your account | Your consent |
| Signed-out conversations | Deleted when the app is reopened | Service design |
| Session value | Deleted on expiry or sign-out | Service provision |
| Ownership transfer records | 1 year | Dispute handling |
| Web server access logs | 90 days | Security |
When you delete your account, the conversations and images linked to it are deleted at the same time by database cascade, and are not recoverable.
4. Sharing with third parties
We process personal data only for the purposes in section 1 and share it with third parties only where PIPA Articles 17 and 18 allow. We currently share no personal data with any third party.
5. Processing on our behalf and transfers abroad
Language generation, speech recognition and speech synthesis all run on servers we operate ourselves. Conversation content is not handed to an outside provider in that process.
One exception: when your question requires a web search, the search query leaves the country as follows.
| Recipient | Country | Data transferred | When and how | Purpose | Retention |
|---|---|---|---|---|---|
| Exa Labs, Inc. | United States | The search query derived from your question | Over the network, at the moment a search is needed | Returning web search results | Per that provider’s policy |
The query does not include your account identifier, your email, or the full text of your conversation. Conversations that need no search trigger no such transfer.
Sign in with Apple is carried out through Apple Inc.’s systems. In that flow we download Apple’s public verification keys to check your sign-in assertion; we do not send any personal data we hold to Apple.
6. Deletion
- Process — data whose retention period has passed or whose purpose is met is destroyed without delay. Account deletion is immediate; we keep no grace copy.
- Method — records are removed from the database; stored files such as attached images are deleted irrecoverably.
7. Your rights and how to exercise them
You may ask us at any time to access, correct, delete or suspend processing of your personal data.
- In the app — Settings → Account → Delete account. Your account and conversations are removed immediately.
- Per conversation — delete individual conversations from the list.
- Anything else — write to the address below; we respond within 10 days.
A legal representative or an authorised agent may act on your behalf, on presentation of a power of attorney in the form prescribed by the Korean notification on personal data handling.
8. Cookies and automated collection
We do not use cookies or any other automated collection device, and we run no behavioural advertising.
9. Security measures
- Encryption in transit — all traffic between the app and our servers uses TLS.
- One-way storage of credentials — sign-in tokens are stored only as SHA-256 hashes.
- Access control — the database exposes no external port and is reachable only from the internal network; administrative access is granted narrowly.
- Ownership checks — every read, write or delete on a conversation verifies that the requester owns it.
- Replay protection — sign-in assertions are matched against a one-time nonce, and a used assertion is refused for a period afterwards.
10. Contact
| Operator | AirOut Inc. |
| Privacy officer | Head of Service Operations |
| [email protected] |
You may also contact the Korean Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the Privacy Infringement Report Centre (privacy.kisa.or.kr, 118).
11. Changes to this policy
This policy applies from its effective date. Where law, policy or the service changes, we will post the revision on this page at least 7 days before it takes effect — at least 30 days in advance where the change materially affects your rights.