Rivata — Privacy Policy
Effective: September 19, 2026 · Version 1.1 · Provider: WebAppBiz (707kib@gmail.com)
Rivata (formerly "AI Persona" / "AI 비서실") is an AI video chat app with a talking avatar. This policy explains what data the app handles, why, and where it goes. Rivata is available on Android, iOS and as a Windows PC program; all share the same account and the same rules below.
1. Data we process
Account
- Sign-in account (Sign in with Google or Sign in with Apple): user ID, email address and display name. Used to identify you, to link your purchases and characters to your account, and to synchronize your data between your devices.
- Device registration: a device key, the app version, and the time and version of your consent to the Terms of Service (kept as proof of consent only).
- Country and language: the country derived from your IP address and the language the app runs in, used to show prices in your store currency and for service statistics. Not combined with your chat content.
Conversation
- Chat text is sent to an external AI service (Google Gemini) to generate answers. If you register your own API key, the text goes directly from your device to Google under your key. Without a key, a limited trial goes through our server, which forwards the text to Google and counts usage; we do not store your chat content on the server.
- Voice is converted to text on your device (Android: Google speech recognition, iOS: Apple speech recognition, PC: on-device recognition). The audio itself is not sent to our server.
- Spoken answers: to read answers aloud with a neural voice, the answer text is sent to our server, which synthesizes the audio and returns it without storing the text. Offline, the device's built-in voice is used.
- Photos you attach to a question are sent to the AI service to answer that question. The app never captures or sends photos automatically.
- Web search and weather you ask for are looked up on public web services; only the search words are sent.
Memories, persona, settings, alarms (account sync)
- The app remembers things you tell it (name, preferences, events), the persona settings of each character, app settings, your AI key and alarms. These are stored on your device and, when you are signed in, uploaded to our server so your PC and phone stay in sync.
- Your AI key is always stored encrypted. You can turn on encryption for the rest of the synced data in the app (Settings → Sync); then the server stores only ciphertext it cannot read.
- You can view, add and delete memories in the app at any time; deletions are synchronized.
Character creation
- When you order a custom character, the photo, name, gender and relationship settings you submit are sent to our server and kept with the order history (received, generated, delivered times) to produce the character, confirm the order and answer inquiries. You confirm that the photo is of yourself or of a person who consented, and not of a minor.
Purchases
- Payments are handled by Google Play (Android) or the App Store (iOS). We receive the purchase token or transaction and the product ID and verify them with Google or Apple to unlock the purchased character or creation credit. We do not receive your card or bank details.
- Purchases started on the PC program are completed on your phone: the PC shows a link/QR code and, if you allow notifications, sends a push notification to your signed-in phone. Only your account ID and the product are transmitted.
PC program only (optional)
- If you connect your email or calendar in the PC program, the credentials you enter are stored encrypted on that PC only and are used to read and send on your behalf when you ask. They are never sent to our server.
Technical
- Server access logs (IP address, time, request path) for security and abuse prevention.
- Push notification tokens (Firebase Cloud Messaging / Apple Push Notification service) to deliver purchase requests from your PC and service notices to your phone.
- Alarms you set are scheduled on your device.
2. Permissions used
- Microphone — voice input (only while the mic toggle is on).
- Camera / photos — attaching a photo to a question, or submitting a photo for character creation (only when you choose).
- Notifications, exact alarms, full-screen intent — ringing the alarms you set and delivering purchase requests, including when the app is closed.
- Internet — AI answers, character downloads, sync, purchases.
3. Third parties
- Google (Sign-In, Gemini AI, speech recognition, Google Play Billing, Firebase Authentication and Cloud Messaging) — governed by Google's policies.
- Apple (Sign in with Apple, App Store In-App Purchase, speech recognition, Apple Push Notification service) — governed by Apple's policies.
- We do not sell personal data and do not use it for advertising.
4. Retention and deletion
- Synced data is kept while your account is active. Deleting an item in the app deletes it on the server at the next sync.
- Order photos and order history are kept for service and inquiry purposes; character files delivered to you remain on your devices.
- Server access logs are kept for up to 90 days.
- To delete your account and all server data: in the app, Settings → Account → Delete account (immediate). If you no longer have the app, see Delete account or contact 707kib@gmail.com from the signed-in address.
5. Children
The app is not directed to children under 14, and character creation must not use photos of minors.
6. Security
All traffic uses HTTPS. API keys are stored in the device's secure storage and encrypted on the server. Optional end-to-end encryption is available for synced data.
7. Changes and contact
We will post updates to this page. Questions: 707kib@gmail.com
Rivata — 개인정보 처리방침
시행일 2026년 9월 19일 · 버전 1.1 · 제공자: 웹앱비즈(707kib@gmail.com)
Rivata(구 'AI Persona' / 'AI 비서실')는 말하는 아바타와 대화하는 AI 영상 대화 앱입니다. 이 문서는 앱이 어떤 정보를 어떤 목적으로 다루며 어디로 보내는지를 설명합니다. 안드로이드·iOS 앱과 Windows PC 프로그램은 같은 계정과 같은 규칙을 씁니다.
1. 처리하는 정보
계정
- 로그인 계정(구글 로그인 또는 Apple 로그인): 사용자 ID·이메일·표시 이름. 본인 확인, 구매·인물을 계정에 묶기, 기기 간 동기화에 씁니다.
- 기기 등록: 기기 키, 앱 버전, 약관 동의 시각·버전(동의 사실 확인 목적으로만 보관).
- 국가·언어: 접속 IP로 파악한 국가와 앱 표시 언어. 스토어 통화로 가격을 보여 주고 서비스 통계에 씁니다. 대화 내용과 결합하지 않습니다.
대화
- 대화 글은 답변 생성을 위해 외부 AI 서비스(Google Gemini)로 전송됩니다. 본인의 API 키를 등록하면 기기에서 구글로 직접 갑니다. 키가 없으면 제한된 체험 대화가 제공자 서버를 거쳐 구글로 전달되며 서버는 횟수만 셀 뿐 대화 내용을 저장하지 않습니다.
- 음성은 기기 안에서 글자로 바뀝니다(안드로이드: 구글 음성 인식, iOS: Apple 음성 인식, PC: 기기 내 인식). 목소리 자체는 제공자 서버로 보내지 않습니다.
- 답변 읽어 주기: 신경망 목소리로 답변을 읽기 위해 답변 글이 제공자 서버로 전송되고, 서버는 소리로 합성해 돌려주며 글을 저장하지 않습니다. 오프라인이면 기기 내장 목소리를 씁니다.
- 질문에 첨부한 사진은 그 답변을 위해 AI 서비스로 전송됩니다. 앱이 사진을 자동으로 촬영·전송하지 않습니다.
- 웹 검색·날씨 요청은 공개 웹 서비스에서 찾아보며 검색어만 전송됩니다.
기억·페르소나·설정·알람(계정 동기화)
- 대화 중 파악한 정보(이름·취향·일정), 인물별 페르소나, 앱 설정, AI 키, 알람은 기기에 저장되며 로그인 상태에서는 PC와 폰이 같아지도록 제공자 서버에 올라갑니다.
- AI 키는 항상 암호화해 보관합니다. 나머지 동기화 자료도 앱(설정 → 동기화)에서 암호화를 켤 수 있으며, 그러면 서버는 읽을 수 없는 암호문만 보관합니다.
- 기억은 앱에서 언제든 확인·추가·삭제할 수 있고 삭제도 동기화됩니다.
인물 생성
- 맞춤 인물을 요청하면 올린 사진·이름·성별·관계 설정이 서버로 전송되어 생성·주문 확인·문의 응대를 위해 처리 이력(접수·생성·전송 시각)과 함께 보관됩니다. 사진은 본인 또는 동의받은 사람의 것이며 미성년자가 아님을 확인합니다.
결제
- 결제는 Google Play(안드로이드) 또는 App Store(iOS)가 처리합니다. 제공자는 구매 토큰(거래 정보)과 상품 ID만 받아 구글·애플에 확인한 뒤 구매한 인물·생성권을 열어 줍니다. 카드·계좌 정보는 받지 않습니다.
- PC 프로그램에서 시작한 구매는 폰에서 끝냅니다. PC가 링크·QR 코드를 보여 주고, 알림을 허용했다면 로그인된 폰으로 푸시 알림을 보냅니다. 계정 ID와 상품만 전달됩니다.
PC 프로그램에서만(선택)
- PC 프로그램에 메일·캘린더를 연결하면 입력한 인증 정보는 그 PC에만 암호화 저장되며, 요청할 때 읽기·보내기에 씁니다. 제공자 서버로는 보내지 않습니다.
기술 정보
- 보안·악용 방지를 위한 서버 접속 기록(IP·시각·요청 경로).
- PC의 구매 요청과 서비스 공지를 폰으로 전달하기 위한 푸시 토큰(Firebase Cloud Messaging / Apple Push Notification service).
- 설정한 알람은 기기 안에서 예약됩니다.
2. 사용하는 권한
- 마이크 — 음성 입력(마이크를 켠 동안만)
- 카메라·사진 — 질문에 사진 첨부, 인물 생성용 사진 제출(직접 고를 때만)
- 알림·정확한 알람·전체화면 — 설정한 알람을 울리고 구매 요청을 전달하기 위해(앱이 꺼져 있어도)
- 인터넷 — AI 답변, 인물 내려받기, 동기화, 결제
3. 제3자
- 구글(로그인, Gemini AI, 음성 인식, Google Play 결제, Firebase 인증·클라우드 메시징) — 구글의 정책이 적용됩니다.
- 애플(Apple 로그인, App Store 인앱 결제, 음성 인식, Apple 푸시 알림) — 애플의 정책이 적용됩니다.
- 개인정보를 판매하지 않으며 광고에 쓰지 않습니다.
4. 보관과 삭제
- 동기화 자료는 계정이 유지되는 동안 보관됩니다. 앱에서 지우면 다음 동기화 때 서버에서도 지워집니다.
- 주문 사진·이력은 서비스 제공과 문의 응대를 위해 보관되며, 전달된 인물 파일은 이용자 기기에 남습니다.
- 서버 접속 기록은 최대 90일 보관합니다.
- 계정과 서버 자료 전체 삭제는 앱에서 설정 → 계정 → 계정 삭제(즉시). 앱을 이미 지웠으면 계정 삭제 안내를 보시거나 로그인한 주소로 707kib@gmail.com에 요청하시면 처리합니다.
5. 아동
만 14세 미만을 대상으로 하지 않으며, 인물 생성에 미성년자 사진을 쓸 수 없습니다.
6. 보안
모든 통신은 HTTPS를 씁니다. API 키는 기기 보안 저장소에 두고 서버에서도 암호화합니다. 동기화 자료는 선택적으로 종단간 암호화할 수 있습니다.
7. 변경과 문의
변경 사항은 이 페이지에 게시합니다. 문의: 707kib@gmail.com