Privacy
Policy
RareLee (hereinafter "the Company" or "RareLee") respects user privacy and complies with applicable privacy laws including the Korean Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other applicable regulations in jurisdictions where RareLee operates.
This Privacy Policy describes what data we collect, how we use it, who we share it with, and your rights.
■ Key Statements at a Glance (for App Store Reviewers and Users)
The following three statements summarize the items most often asked about during App Store review. Each statement is restated in full in its own dedicated section further down in this policy.
(A) Face data is NOT retained. RareLee does not collect, extract, generate, derive, share, or store face data. Face data is never generated in the first place. See "Face Data Policy" below for the full disclosure required by Apple App Store Review Guideline 5.1.1(i).
(B) RareLee does NOT use any third-party AI service. No user data is sent to OpenAI, Google AI, Anthropic, AWS Rekognition, or any other external AI / ML / computer-vision / biometric provider. All automated processing runs on RareLee's own privately-operated internal servers. See "Third-Party AI Service Policy" below.
(C) Photos uploaded for personal style consulting are stored on RareLee's own cloud storage (Amazon S3, Seoul region) and viewed only by RareLee's authorized human consultants for the requested consultation. Photos are deleted after at most 90 days, and immediately on user request. See "Photo Handling" below.
■ Purpose of collection and use of personal information
The Company uses the collected personal information for the following purposes.
o Contract performance and billing for service provision
Content provision, purchase and payment, product delivery or billing, financial transaction authentication and financial services
o Member management
Identification of members, personal identification, prevention of fraudulent use by bad members and prevention of unauthorized use, confirmation of intent to join, age verification, confirmation of consent of legal representative when collecting personal information of children under 14 years of age, complaint handling, notification delivery
o Service development
Service modification and development
o Use for marketing and advertising
Provision of advertising information such as events, frequency of access, or statistics on members' use of services
* However, photos that reveal the user's appearance are never used for marketing or advertising purposes.
■ Personal information items collected and collection methods
A. Personal information items collected
o The company collects the following personal information for membership registration, consultation, and service application.
- When registering as a member: Name, login ID, password, home phone number, mobile phone number, email, and in the case of members under the age of 14, the minimum personal information among the legal representative's information (name of legal representative, date of birth, gender, duplicate registration confirmation information, mobile phone number)
- When applying for a service: Date of birth, gender, payment information, and other content required when applying for consulting (photos showing the member's appearance)
o Service usage records, access logs, cookies, access IP, payment records, and records of improper use may be created and collected during the service use process or business processing.
B. Collection method
- Collection through homepage, written forms, bulletin boards, email, event application, delivery request, phone, fax, and information collection tools
■ Retention and use period of personal information
In principle, after the purpose of collecting and using personal information has been achieved, the relevant information is destroyed without delay. However, exceptions may be made in cases where it is stipulated in relevant laws or consent has been obtained from the user, and when a member withdraws, information is stored for 90 days from the withdrawal date, and until the settlement of the relevant debt-credit relationship arising from the use of the service.
■ Personal information destruction procedures and methods
In principle, the company destroys the relevant information without delay after the purpose of collecting and using personal information has been achieved. The destruction procedures and methods are as follows.
o Destruction procedures
The information entered by the member for membership registration, etc. is transferred to a separate DB (separate file in the case of paper) after the purpose has been achieved and stored for a certain period of time according to the internal policy and other information protection reasons according to relevant laws (see retention and use period) and then destroyed.
Personal information transferred to a separate DB will not be used for any other purpose than that for which it is retained, unless required by law.
o Destruction method
Personal information stored in electronic file format is deleted using a technical method that makes the record unrecoverable, and personal information recorded on paper documents or other recording media is shredded or incinerated, or the relevant portion is masked or perforated.
■ Provision of Personal Information to Third Parties
The Company does not, in principle, provide users' personal information to external parties. However, the following cases are exceptions.
o When users have given prior consent
o When there is a request from an investigative agency in accordance with the procedures and methods stipulated by law or for investigative purposes based on the provisions of the law
o When pseudonymized information is provided for statistical compilation, scientific research, public record preservation, etc.
o When necessary for billing for service provision
■ Consent to collection and use of sensitive information
The Company complies with Article 23 (Restrictions on processing sensitive information) of the Personal Information Protection Act. However, sensitive information may be processed in any of the following cases:
o In cases where the information subject is notified of the matters in Article 15, Paragraph 2 or Article 17, Paragraph 2 of the Personal Information Protection Act and consent is obtained separately from consent for the processing of other personal information
o In cases where laws specifically require or permit the processing of sensitive information
When processing sensitive information, the company will take necessary measures to ensure the security of the sensitive information, such as encryption, so that the sensitive information is not lost, stolen, leaked, forged, altered or damaged.
Respondents regarding service use have the right to refuse consent to the processing and disclosure of the above sensitive information.
■ Face Data Policy (addresses Apple App Store Review Guideline 5.1.1(i))
Explicit summary statement: RareLee does NOT collect, derive, generate, retain, share, or otherwise process face data. Face data is not retained, because face data is never generated in the first place.
Definition: In this policy, "face data" means biometric face data — facial feature points, facial landmarks, biometric templates, face geometry, face embeddings or face vectors, or any other data that can uniquely identify a person from their facial biometrics.
The following six items address each disclosure that Apple App Store Review Guideline 5.1.1(i) requires for any app that uses face data:
(1) Explicit statement that face data is not retained: Face data is NOT retained by RareLee. RareLee does not generate face data, therefore there is nothing to retain.
(2) Reasons for storing face data: Not applicable. RareLee does not store face data for any purpose, ever.
(3) Length of time face data is stored and why: Not applicable. Face data is never stored, not even temporarily. No retention period applies because no face data exists.
(4) Which third parties RareLee shares face data with: NONE. Because RareLee does not generate or possess face data, no face data is or can be shared with any third party.
(5) Reasons for sharing face data with third parties: Not applicable. No face data is shared.
(6) Whether third parties also store face data on RareLee's behalf: Not applicable. No third party receives face data from RareLee. None of RareLee's data processors (see "Entrustment of Personal Information Processing" below) receive or store face data.
Important clarification — what may be misread as face data but is NOT:
- Categorical labels such as "face shape" (e.g., "oval", "round", "long") or "eye shape" (e.g., "almond", "monolid") shown inside RareLee are USER-SELECTED survey responses. The user themselves selects a label from a predefined list inside the app. These categorical labels are NOT extracted from photos, NOT detected by automated face recognition or facial analysis, and are NOT biometric face data.
- Photos voluntarily uploaded by users for personal style consulting are visually reviewed by RareLee's authorized human consultants only, for the sole purpose of providing the styling consultation the user requested. NO automated face detection, face recognition, facial-landmark extraction, biometric template generation, or face-recognition AI processing is applied to these photos at any stage of RareLee's pipeline.
- Local biometric authentication on the user's device (e.g., Face ID, Touch ID, Optic ID) is handled entirely by Apple's LocalAuthentication framework on-device and never leaves the device. RareLee receives only a pass/fail authentication result; RareLee never receives biometric data from such authentication.
■ Third-Party AI Service Policy (addresses Apple App Store Review Guidelines 5.1.1(i) and 5.1.2(i))
Explicit summary statement: RareLee does NOT share, transmit, or send user personal data to any third-party AI service.
Specifically, RareLee does NOT send user photos, user-uploaded images, survey responses, account information, payment information, or any other user-generated content to:
- OpenAI (including ChatGPT, GPT models, DALL-E, Whisper, embeddings APIs)
- Google AI (Gemini, Vertex AI, Cloud Vision API, ML Kit, AutoML)
- Anthropic (Claude APIs)
- AWS AI/ML services (Rekognition, Comprehend, Bedrock, Textract, SageMaker inference)
- Microsoft / Azure AI services (Azure OpenAI, Cognitive Services, Face API)
- Meta AI APIs
- Hugging Face inference endpoints
- Replicate, Stability AI, Cohere, Mistral, Perplexity, or any similar third-party AI inference provider
- Any other external AI, machine-learning, computer-vision, biometric, or generative-AI service
All automated recommendation logic used inside RareLee operates exclusively on RareLee's own privately-operated internal servers. No user data is transmitted to any external AI service for analysis or inference.
Because no third-party AI service receives user data, the third-party AI disclosure and consent requirements introduced by Apple App Store Review Guideline 5.1.2(i) (effective November 2025) do not currently apply to RareLee. If this ever changes in the future, RareLee will, before any user data is shared with a third-party AI service: (a) update this Privacy Policy to identify the specific AI provider by name and to disclose what data is sent and why; and (b) present a separate, in-app explicit consent dialog before any user data is transmitted to that third-party AI service, in compliance with Guideline 5.1.2(i).
■ Photo Handling
Photos voluntarily uploaded by users for personal style consulting are handled as follows:
(1) Storage: Photos are stored in RareLee's cloud storage hosted on Amazon Web Services (Amazon S3) in the Seoul region (ap-northeast-2). AWS acts as RareLee's storage infrastructure provider only — AWS does NOT view, analyze, mine, train models on, or otherwise use the photos for any purpose other than passive storage on RareLee's behalf. AWS's processing of personal data on RareLee's behalf is governed by the AWS Data Processing Addendum and AWS Service Terms, which provide a level of protection at least equivalent to the protections described in this Privacy Policy.
(2) Access: Only RareLee's authorized human consultants can view uploaded photos, and only for delivering the requested style consultation.
(3) No AI face analysis: As stated above, RareLee does NOT run any face-recognition, face-detection, biometric, or third-party AI processing on uploaded photos at any stage.
(4) Retention: Photos are retained for up to 90 days after the consulting result is delivered. The 90-day retention exists for (a) result verification, (b) customer support, and (c) refund and service-issue handling. After 90 days, the photos are permanently deleted using irreversible methods.
(5) Deletion on request: Upon account deletion or a user's explicit deletion request, uploaded photos are deleted immediately, regardless of the 90-day window.
(6) No marketing / no training: Photos are NEVER used for marketing, advertising, sale, or AI model training. RareLee does not train AI models on user photos.
(7) Children's photos: For users under 14, photo upload requires legal-representative consent, and the same handling rules apply.
Users may revoke consent and request photo deletion at any time by contacting contact@rarelee.co.kr.
■ Entrustment of Personal Information Processing
For service operation, RareLee entrusts certain processing tasks to the processors listed below. Each processor is contractually bound to provide a level of personal-data protection equivalent to or stronger than this Privacy Policy, in compliance with Apple App Store Review Guideline 5.1.1(i). None of these processors are AI providers; none of them receive or process face data; none of them use entrusted data for their own AI training, advertising, or marketing.
o Processor: Amazon Web Services, Inc. (AWS) — Seoul region (ap-northeast-2)
Entrusted task: Cloud storage (Amazon S3) for user-uploaded photos and application data. Storage only — no analysis, no AI processing, no advertising use.
Retention: Up to 90 days for photos (see Photo Handling above); for other data, the retention period applicable to that data type under this Privacy Policy.
Data protection: AWS Data Processing Addendum; AWS is ISO/IEC 27001, 27017, 27018, SOC 1/2/3, and PCI-DSS certified.
o Processor: KG Inicis Co., Ltd. and Toss Payments Corp.
Entrusted task: Payment processing, refund processing, and purchase-safety services.
Retention: Period required by applicable financial regulations and the duration of the service-provision contract.
o Processor: CoolSMS (NHN Cloud)
Entrusted task: SMS and KakaoTalk transactional messaging — order notifications, consultation-status updates, and other service messages.
Retention: As required for delivery; transactional logs retained per applicable telecommunications laws.
o Processor: Goodsflow Inc.
Entrusted task: Logistics and delivery information processing for shipped products.
Retention: Period required by applicable commerce and delivery regulations.
o Processor: Apple Inc. and Google LLC (only when the user voluntarily chooses social sign-in)
Entrusted task: Identity-token verification for Sign in with Apple and Sign in with Google. RareLee receives only the minimum identifier (sub) and the email/name the user explicitly permits to share. No biometric data is received from these providers.
Retention: As long as the linked RareLee account exists.
RareLee does NOT entrust user data to any third-party AI service, any advertising network, or any analytics provider that processes user-identifiable personal data beyond what is listed above.
■ User and legal representative rights and methods of exercising them
o Users can view or modify their registered personal information at any time and may also request cancellation of membership.
o Users may refuse to have their personal information collected, and if they do not consent to the collection of personal information, they may be restricted from using some services.
o In the case of children under the age of 14, the legal representative has the right to view, edit, delete, suspend processing, and withdraw consent to the collection and use of the child's personal information.
o To view or edit personal information, click on "Change Personal Information" (or "Edit Member Information") and to cancel membership (withdraw consent), click on "Cancel Membership" and go through the identity verification process to directly view, edit, or withdraw.
o Alternatively, you may contact the Personal Information Protection Officer in writing, by phone, or by email, and we will take action without delay.
o If you request correction of errors in your personal information, we will not use or provide the relevant personal information until the correction is complete. In addition, if incorrect personal information has already been provided to a third party, we will promptly notify the third party of the results of the correction process to ensure that the correction is made. o The company processes personal information that has been terminated or deleted at the request of the user in accordance with the provisions of “Retention and Use Period of Personal Information Collected by the Company” and processes it so that it cannot be viewed or used for any other purpose.
■ Matters regarding the installation, operation, and refusal of automatic personal information collection devices
The company operates “cookies” that store and retrieve your information from time to time. Cookies are very small text files that the server used to operate the website sends to your browser and are stored on your computer hard disk.
The company uses cookies for the following purposes:
o Purpose of use of cookies, etc.
1. Target marketing and provision of personalized services through analysis of access frequency and visit time of members and non-members, identification of users" tastes and areas of interest, tracking of traces, identification of degree of participation in various events and number of visits, etc.
2. You have the option to install cookies. Therefore, you can allow all cookies, confirm each time a cookie is stored, or refuse to store all cookies by setting options in your web browser. o How to reject cookie settings
1. To reject cookie settings, you can select the option of the web browser you use to allow all cookies, confirm each time a cookie is saved, or reject all cookie storage.
2. Example of setting method (for Internet Explorer): Tools at the top of the web browser > Internet Options > Personal Information
3. However, if you reject cookie installation, there may be difficulties in providing services.
■ Measures to ensure the safety of personal information
The company is taking the following measures to prevent the personal information of the information subject from being lost, stolen, leaked, falsified/altered, or damaged.
o Establishment and implementation of an internal management plan for personal information protection, operation of a dedicated organization, regular employee training, etc.
o Access control and access authority restriction measures for personal information processing systems, installation of security programs
o Provision of storage facilities or installation of locking devices and access control for safe storage of personal information
■ Personal information complaint service
The company has designated a personal information protection officer as follows to protect customers' personal information and handle complaints related to personal information.
o Personal information protection officer
Name: Seungah Lee
Email: contact@rarelee.co.kr
o You may report any complaints related to personal information protection that occur while using the company's services to the personal information protection officer or the department in charge.
o The company will promptly and sufficiently respond to users' reports.
o If you need to report or consult about other personal information infringements, please contact the following organizations.
Personal Information Infringement Report Center (privacy.kisa.or.kr / 118 without area code)
Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
Supreme Prosecutors' Office Cyber Investigation Department (spo.go.kr / Area code + 1301)
National Police Agency Cyber Safety Bureau (cyberbureau.police.go.kr / 182 without area code)
-Announcement Date: May 28, 2026
-Enforcement Date: May 28, 2026
-Previous policy effective from: February 21, 2024. Changes in this revision: (a) added "Key Statements at a Glance" summary; (b) restructured the Face Data Policy to explicitly address each disclosure required by Apple App Store Review Guideline 5.1.1(i); (c) added an explicit Third-Party AI Service Policy addressing Apple App Store Review Guideline 5.1.2(i); (d) added a dedicated Photo Handling section; (e) updated the list of data processors to accurately reflect current operations, including Amazon Web Services for cloud storage.