Privacy Policy
Effective Date: May 2, 2026 Last Updated: August 21, 2026
Translation Notice: This English version is provided for reference only. The Korean-language version is the legally binding original. In the event of any discrepancy between this translation and the Korean version, the Korean version shall prevail.
SUBTWO ("Company," "we," "us," or "our") values the privacy of users of Bagle ("Service") and complies with the Personal Information Protection Act ("PIPA"), the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other applicable laws of the Republic of Korea.
1. Categories of Personal Information We Collect and Collection Methods
1.1 Required Information
| Item | Purpose | Collection Method |
|---|---|---|
| Email address | Account creation, login, customer support | Provided by the social login provider |
| OAuth identifier | Apple / Google / Kakao social login | Automatically collected during OAuth authentication |
1.2 Optional Information
| Item | Purpose | Collection Method |
|---|---|---|
| Nickname (display name) | Profile display, customer support | Entered by user |
| UI language | Multilingual UI rendering | Auto-detected from device, or set by user |
| Face photo (avatar) | AI virtual try-on image generation, personal color diagnosis | Uploaded by user |
| Pet photo | Inclusion of pet in AI virtual try-on | Uploaded by user |
| Clothing photos | AI clothing tagging, outfit recommendation, virtual try-on | Uploaded by user |
| Gender, date of birth, height | Personalized outfit recommendation | Entered by user |
| Location (latitude/longitude or city name) | Weather-based outfit recommendation | Collected from device GPS when location permission is granted, or selected by user |
| Personal color diagnosis result | Color-based outfit recommendation | Stored AI diagnosis result |
| Style preferences | Personalized outfit recommendation | Auto-derived from feedback on recommendation results |
| Style persona (free-form text, up to 100 characters) | Personalized outfit recommendation and virtual try-on | Entered by user (Atelier plan only) |
| Usage settings (avatar / pet / personal color enabled status) | Feature display control | Set by user |
You may decline consent to the collection of optional items and still register and use the basic Service. However, features directly related to those items (virtual try-on, outfit recommendation, personal color diagnosis, etc.) may be unavailable.
1.3 Automatically Collected Information
| Item | Purpose |
|---|---|
| Device information (OS version, device model) | Service optimization, error handling |
| IP address | Abuse prevention (rate limiting), access-log retention, error handling |
| App usage logs (screen views, feature usage) | Service improvement, usage analytics |
| Error/diagnostic logs (crash reports, stack traces, preceding-action breadcrumbs) | Error/crash detection and service stabilization |
| Subscription information (tier, renewal status, expiry) | Tier-based feature delivery, billing management |
| Bagle balance and transaction history | In-app credit usage management, accounting |
| Payment records (Bagle purchases / subscription billing) | Transaction recordkeeping, refund handling |
2. Purposes of Use
We use the personal information collected only for the following purposes.
- Service delivery: Member management, AI outfit recommendation, virtual try-on, wardrobe management, style-persona-based personalization (Atelier plan)
- AI image processing: AI tagging of uploaded clothing photos (Anthropic Claude API), virtual try-on image generation (Google Gemini API)
- Payment processing: Purchase and use of Bagle in-app credit, subscription management
- Customer support: Responding to inquiries, handling complaints
- Service improvement: Usage statistics analysis (Firebase Analytics), error/crash detection and service stabilization (Sentry)
- Legal compliance: Retention of transaction records under Article 6 of the Korean Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree
3. Notice Regarding AI Data Processing
3.1 AI Services in Use
The Service uses the following AI services to deliver its core features.
| AI Service | Provider | Data Processed | Purpose |
|---|---|---|---|
| Claude API | Anthropic, PBC | Clothing photos, face photos, style data, style persona text (Atelier) | Clothing tagging, personal color diagnosis, outfit recommendation |
| Gemini API | Google LLC | Clothing photos, avatar photos, style persona text (Atelier) | Virtual try-on image generation |
3.2 AI Processing Considerations
- Uploaded images are transmitted to Anthropic and Google servers for AI processing (see Section 4 on processing entrustment and Section 6 on cross-border transfer).
- For personal color diagnosis, the face photo is transmitted to Anthropic servers. The photo is resized to 512×512 before transmission and is deleted from the AI server immediately after diagnosis.
- Background removal is performed on-device using the iOS Vision framework; images are not transmitted to any external server.
- AI providers' handling of data is governed by the entrustment contract concluded with the Company and by each provider's privacy policy.
- AI-generated outfit recommendations and try-on images are for reference only, and actual results may differ from what is depicted.
- The Company operates the Service in accordance with the Anthropic Commercial Terms of Service and the Google Cloud / Gemini API Terms of Service (which provide that API input data is not used to train models). If those policies change, the Company will update this Policy.
4. Entrustment of Personal Information Processing
Pursuant to Article 26 of the Korean Personal Information Protection Act, the Company entrusts the processing of personal information for the delivery of the Service as follows.
| Trustee | Entrusted Work | Items Processed | Retention / Use Period |
|---|---|---|---|
| Anthropic, PBC | Image and text processing for AI clothing tagging, personal color diagnosis, and outfit recommendation | Clothing photos, face photo (resized to 512×512), style data, style persona text (Atelier) | Deleted immediately after processing (per Anthropic API terms) |
| Google LLC (Gemini API) | AI virtual try-on image generation | Clothing photos, avatar photos, style persona text (Atelier) | Deleted immediately after processing (per Google API terms) |
| Google LLC (Firebase) | App analytics, app integrity verification (App Check) | Device information, usage logs | Until termination of the entrustment contract, or until member withdrawal |
| Functional Software, Inc. (d/b/a Sentry) | Error/crash monitoring and service stabilization | Error/diagnostic logs (stack traces, preceding-action breadcrumbs), device information | Up to 90 days (per Sentry's retention policy) |
| OpenWeather Ltd. | Weather data lookup | Location data (latitude/longitude or city name) | One-time lookup; not separately stored |
| Supabase Pte. Ltd. | Member authentication and database operations | Email address, OAuth identifier, profile information, wardrobe / outfit / try-on data | Upon member withdrawal (per the retention periods in Section 7) |
| Cloudflare, Inc. | Image storage and CDN delivery | Clothing photos, face photo (avatar), pet photo, virtual try-on images | Deleted upon member withdrawal |
| Render Services, Inc. | API server hosting | Personal information transmitted in the course of using the Service, server application logs (IP address, account identifier, request path) | Limited to the time of processing (logs are subject to Render's log retention policy) |
| RevenueCat, Inc. | In-app purchase and subscription status management | Account identifier (UUID), purchase and transaction records | Until termination of the entrustment contract, or until member withdrawal |
| 650 Industries, Inc. (Expo) | App update delivery and push notification relay | Push token, notification content, device information | Limited to the time of transmission; not separately stored |
| Apple Inc. | Push notification delivery (APNs), Apple login authentication, app integrity verification (App Attest) | Push token, notification content, OAuth identifier and authentication token, device integrity verification data | Limited to the time of transmission or authentication |
| Kakao Corp. (주식회사 카카오) | Kakao social login authentication | OAuth identifier, email address | Limited to the time of authentication (processed within Korea) |
The Company confirms that each trustee's API terms of service (Anthropic Commercial Terms of Service, Google Cloud Terms of Service, etc.) reflect the matters required under each item of Article 26(1) of the Korean Personal Information Protection Act (prohibition of processing for purposes other than those specified, security safeguards, restriction on sub-entrustment, allocation of liability for incidents, etc.), and the Company establishes the entrustment relationship by consenting to those terms. If those terms change, the Company will update this Policy.
5. Provision of Personal Information to Third Parties
The Company in principle does not provide users' personal information to any third party.
The following are exceptions.
- Where the user has given prior consent
- Where required by law, or in response to requests pursuant to investigative or judicial proceedings
Apple Inc. (App Store IAP payments) acts as the Company's payment-system provider and directly processes payment information in accordance with Apple's own policies; the Company receives only confirmation of payment and a transaction identifier from Apple. Apple's handling of personal information is governed by Apple's privacy policy.
6. Cross-Border Transfer of Personal Information
Pursuant to Article 28-8 of the Korean Personal Information Protection Act, the Company transfers personal information abroad as follows.
| Item | Details |
|---|---|
| Items transferred | Clothing photos, face photo (resized to 512×512), avatar photo, pet photo, style data, style persona text (Atelier plan), email address, OAuth identifier and authentication token, profile information, wardrobe / outfit / try-on data, location data (latitude/longitude or city name), account identifier (UUID), purchase and transaction records, push token, device information, usage logs, error/diagnostic logs (stack traces, breadcrumbs) |
| Destination country | United States, Singapore, United Kingdom |
| Timing and method of transfer | Transferred immediately at the time the user uses the relevant feature (sign-up, use of AI features, image storage, payment, notification delivery, etc.), via encrypted communication (TLS 1.2 or above) |
| Recipient (entity name / contact) | Anthropic, PBC (privacy@anthropic.com) / Google LLC (Gemini API: support-deletion@google.com; Firebase: firebase-support@google.com) / Functional Software, Inc. d/b/a Sentry (compliance@sentry.io) / Supabase Pte. Ltd. (privacy@supabase.io) / Cloudflare, Inc. (privacyquestions@cloudflare.com) / Render Services, Inc. (support@render.com) / RevenueCat, Inc. (privacy@revenuecat.com) / 650 Industries, Inc. (Expo) (secure@expo.dev) / Apple Inc. (privacy@apple.com) / OpenWeather Ltd. (info@openweathermap.org) |
| Recipient's purpose of use | AI clothing tagging, outfit recommendation, virtual try-on image generation, personal color diagnosis, member authentication and database operations, image storage and CDN delivery, API server hosting, in-app purchase and subscription status management, app update delivery and push notification relay, push notification delivery (APNs) and Apple login authentication, app analytics and app integrity verification, error/crash monitoring and service stabilization, weather data lookup |
| Recipient's retention / use period | Deleted immediately after API processing (per each provider's API terms) / for Supabase, Cloudflare, RevenueCat, and Firebase, until termination of the entrustment contract or member withdrawal / for Expo, Apple, and OpenWeather, limited to the time of transmission or authentication / for Render, limited to the time of processing (logs are subject to Render's log retention policy) / for Sentry, up to 90 days (per Sentry's retention policy) |
| Method, procedure, and effect of refusing transfer | Consent to cross-border transfer is a mandatory item required to provide the service's core features; if you do not consent, sign-up is not available. After sign-up, you may stop the cross-border transfer by withdrawing your membership. |
Pursuant to Article 28-8(3) of the Korean Personal Information Protection Act and Article 29-10 of its Enforcement Decree, the Company contractually requires recipients to apply protective measures equivalent to those required by Korean personal information protection law.
7. Retention and Use Period
| Item | Retention Period | Basis |
|---|---|---|
| Account information | Permanently deleted 14 days after withdrawal (restorable within 14 days) | User request + confirmation period to prevent accidental withdrawal and protect the user's held Bagle |
| Wardrobe / outfit / try-on data | Permanently deleted 14 days after withdrawal (restorable within 14 days) | User request + confirmation period to prevent accidental withdrawal and protect the user's held Bagle |
| Bagle transaction records | 5 years after withdrawal (anonymized) | Korean Electronic Commerce Act Art. 6 and Enforcement Decree Art. 6 (payment records, 5 years) |
| Subscription billing records | 5 years after withdrawal (anonymized) | Korean Electronic Commerce Act Art. 6 and Enforcement Decree Art. 6 (contract / withdrawal requests, 5 years) |
| Payment provider (RevenueCat) inbound event payloads (as received) | 5 years after withdrawal | Korean Electronic Commerce Act Art. 6 and Enforcement Decree Art. 6 (payment records, 5 years) |
| Free-credit grant history (email address) | For as long as the duplicate-grant prevention purpose remains | PIPA Art. 15(1)(6) (legitimate interests) — preventing duplicate free-credit grants when the same email address signs up again |
| Audit records (payment, abuse and withdrawal history) | For as long as the abuse-prevention and service-analytics purposes remain | PIPA Art. 15(1)(6) (legitimate interests) — responding to payment errors and refund abuse, and producing service statistics |
| Consumer complaint / dispute resolution records | 3 years | Korean Electronic Commerce Act Art. 6 and Enforcement Decree Art. 6 |
| Login records | 3 months | Internal security policy (compliant with PIPA Art. 29 safeguard obligations) |
Personal information retained pursuant to applicable law is stored and managed separately from other personal information in accordance with Article 21(3) of the Korean Personal Information Protection Act.
8. Procedure and Method of Destruction
- Timing: Upon achievement of the retention purpose or upon member withdrawal (after expiry of the applicable retention period where another statute imposes a retention obligation).
- Method: Pursuant to Article 16 of the Enforcement Decree of the Korean Personal Information Protection Act, information in electronic file form is permanently deleted by means that prevent recovery, and image files held on storage media are permanently deleted from Cloudflare R2 storage.
- Upon member withdrawal: All sessions are signed out immediately upon withdrawal, and a 14-day grace period is observed to prevent accidental withdrawal and to protect the user's held Bagle, during which the user may sign back in with the same account to undo the withdrawal. After the 14-day grace period elapses, the Company permanently deletes all data including the account, profile, wardrobe, outfits, try-on images, and Bagle balance. Transaction records subject to retention obligations under the Korean Electronic Commerce Act or other applicable laws are anonymized and stored separately for 5 years.
9. User Rights and How to Exercise Them
9.1 Common Rights
You may exercise the following rights.
- Right of access: Request access to your collected personal information
- Right to rectification: Request correction of inaccurate information
- Right to erasure: Request deletion of personal information (member withdrawal)
- Right to suspend processing: Request suspension of the processing of your personal information
How to exercise: From in-app Settings > Member Withdrawal, or by writing to support@baglestyle.com.
9.2 Korean Users
Pursuant to Articles 35 through 37 of the Korean Personal Information Protection Act, you may request access, rectification, deletion, and suspension of processing of your personal information; the Company will act within 10 days as provided in the Enforcement Decree of the same Act. Where the Company denies a request, or only partially accepts it, the Company will notify the reason and the method of objection in writing (by email or the like).
Requests through a legal representative are also permitted; in such cases, documents proving the legal representative's status must be submitted.
9.3 Users in Japan, the United States, and Other Overseas Jurisdictions
At the time of entry into each overseas market, the rights guaranteed by the applicable local law (e.g., Japan's Act on the Protection of Personal Information (APPI); California's CCPA/CPRA) will be added as a separate addendum. As of the Effective Date of this Policy, the rights described in Sections 9.1 and 9.2 above under the Korean Personal Information Protection Act apply.
10. Safeguards for the Protection of Personal Information
Pursuant to Article 29 of the Korean Personal Information Protection Act and Article 30 of its Enforcement Decree, the Company implements the following technical, administrative, and physical safeguards.
- Formulation and implementation of an internal management plan for the safe handling of personal information
- Access control and restriction of access privileges to personal information (Supabase Row Level Security)
- Encryption for the safe storage and transmission of personal information (TLS 1.2 or above in transit)
- Retention and tamper-prevention of access logs for response to personal information incidents (Supabase database audit logs)
- Installation and updating of security software for personal information
- Physical safeguards for the secure storage of personal information (leveraging the data-center security controls of cloud infrastructure providers (Supabase, Cloudflare, Render, Google Cloud, Apple, Sentry))
11. Children's Personal Information
The Service is not intended for persons under 18, and persons under 18 may not register as members. Bagle relies on third-party generative-AI services (including Google Gemini and Anthropic Claude) to provide core features such as outfit recommendations and virtual try-on, and those services' terms restrict use to individuals aged 18 and over; the Company therefore blocks sign-up for those under 18. This threshold also satisfies Article 22-2 of the Korean Personal Information Protection Act, which requires legal-guardian consent for processing the personal information of children under 14.
If we become aware that a person under 18 has registered, the Company will delete the relevant information immediately. In particular, for a child under 14, the Company will, pursuant to Article 22-2 of the Korean Personal Information Protection Act and related laws, delete the relevant information immediately and, where possible, notify the legal guardian of the fact.
12. Changes to this Privacy Policy
When the Company changes this Policy, it will, pursuant to Article 30(2) of the Korean Personal Information Protection Act and Article 31 of its Enforcement Decree, post the revised Policy on the Service screen or the website (baglestyle.com/privacy) from at least 7 days before the effective date and will keep the revised content continuously available on this Policy page. For material changes that may disadvantage users (such as the addition of new categories of collection, expansion of third-party provision, or addition of cross-border transfers), the Company will post them by the same means from at least 30 days before the effective date, and will obtain consent again where required.
13. Personal Information Protection Officer
Pursuant to Article 31 of the Korean Personal Information Protection Act and Article 32 of its Enforcement Decree, the Company designates its Personal Information Protection Officer as follows.
- Name: Heejun Han
- Title: Representative
- Affiliation: SUBTWO
- Email: support@baglestyle.com
Users may contact the officer above with any inquiry, complaint, or request for redress arising in connection with their use of the Service.
14. Contact
For inquiries, complaints, or requests for redress regarding personal information, please contact us.
- Email: support@baglestyle.com
- Korea — Personal Information Dispute Mediation Committee: www.kopico.go.kr (1833-6972)
- Korea — Internet & Security Agency Privacy Infringement Report Center: privacy.kisa.or.kr (118)
- Korea — Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr (1301)
- Korea — Korean National Police Agency Cyber Bureau: ecrm.cyber.go.kr (182)