morewhere › privacy
morewhere — Privacy
Languages: English (en)日本語 (ja)한국어 (ko)
This page carries the privacy document in every language the source publishes. Each language block below is reproduced word for word from morewhere’s own generated legal packet, with the effective date and status the source records for it.
morewhere United States Privacy Notice
This notice at collection explains the personal-information categories, purposes, training boundaries, retention criteria, and state privacy rights associated with morewhere. morewhere is operated by PROJECT82 LLC, an active entity. Its business address of record is 30 N Gould St, STE R, Sheridan, WY 82801, USA.
Who is responsible for the data
morewhere is operated by PROJECT82 LLC, an active entity. Its business address of record is 30 N Gould St, STE R, Sheridan, WY 82801, USA. The identified operator determines why and how covered personal information is processed for this service, subject to the draft and release limitations stated here. This is a release-blocked draft with no approved effective date. Before publication, the operator record must complete final legal review, a DMCA designated agent and working legal/DMCA mailbox must be confirmed, vendor facts must be reconciled to live configuration and contracts, and United States counsel must approve the state-law, arbitration, consumer, and sales disclosures.
Notice at collection: categories collected
morewhere provides persona and desire profiles, world policy, and character or world AI chat. Profiles, world policy, character or world chat, account, and safety records support the requested experience. If paid features are offered, the checkout screen identifies the applicable entitlement and its conditions before purchase. Entry begins at age 15, while training eligibility begins at age 19. Users ages 15–18 remain in protected mode and their data is excluded from training. Depending on use, categories may include account and contact details; age or birth-date data; device, log, and cookie data; conversation or call content; recordings and derived transcripts; character, memory, and preference data; safety reports; purchase and transaction records excluding full payment credentials handled by a store or payment provider; and support communications. A category not verified in the product data flow is not added to this notice by assumption.
Sources of personal information
We receive information directly from you, from your interactions with AI and safety features, from the device or browser you use, from app stores or payment services, and from service providers acting for the operator. We do not treat an unverified vendor inventory as a final public recipient list.
Purposes and authority for use
We use information to create an account, provide requested AI responses and continuity, classify age, personalize features, process purchases, detect abuse, investigate reports, secure systems, provide support, comply with law, establish or defend claims, and, for eligible adult data after valid notice, evaluate and improve models. Applicable consent, contract, legal-obligation, and legitimate-purpose requirements are honored by jurisdiction.
Service processing is separate from training
Operational processing may continue after a training opt-out when needed to generate replies, store conversations or requested memory, perform age and content-safety checks, handle reports, prevent fraud, secure accounts, complete payments, provide support, or meet legal duties. Training, fine-tuning, evaluation-dataset addition, and long-term pseudonymized retention for those purposes stop prospectively as described in the AI Data Use Notice.
Human review and labeling
Only a limited number of authorized personnel may review the minimum context needed for improvement quality evaluation or labeling. Improvement labeling views must never expose account or direct contact details. Operational support or safety review is a distinct limited-purpose process and does not make those details available for improvement labeling. Access, viewing, export, and deletion events are logged, and an external labeler may not be used until confidentiality, security, access, and deletion obligations are contractually verified.
Service providers and disclosures
Service providers may support hosting, AI inference, security, customer support, analytics, communications, or payments only under appropriate instructions and safeguards. The provider names, locations, purposes, transfer details, and retention terms are not yet verified against live configuration and contracts; this notice remains blocked until that roster is complete. We may also disclose information when lawfully required or necessary to protect rights and safety.
Cross-border processing
The operator is a United States company, so personal information from users outside the United States is processed abroad as the ordinary course rather than as an exception. The transfer is carried out as necessary to perform the service agreement with you, and is disclosed here rather than made subject to a separate consent. Transferred data is deleted without delay when an account is closed, except records a statute requires be kept, which are held separately for that statutory period and then deleted.
Information may also be processed by service providers outside the state or country where a user lives. Before this notice becomes effective, the operator will verify each destination, recipient role, purpose, transfer mechanism, safeguard, and retention term. This draft does not substitute an assumed country or vendor for that required transfer record.
Retention criteria
Retention criteria include the time needed to provide an active account or requested feature, the sensitivity and volume of the data, safety and fraud needs, legal recordkeeping, dispute limitation periods, a valid preservation request, and the time required for secure deletion from backups. Training copies follow the additional eligibility, opt-out, and separability rules in the AI Data Use Notice rather than an unlimited retention period.
Security safeguards
We use administrative, technical, and organizational measures proportionate to the data and risk, such as access restriction, logging, separation of operational and training stores, masking, and protected transmission where appropriate. No system is perfectly secure, so this notice does not promise absolute prevention of loss or unauthorized access.
State privacy rights and choices
Depending on residence and applicable law, you may request access, correction, deletion, or portability; opt out of certain sale, share, or targeted advertising activity; limit certain sensitive-data use; and receive equal service without unlawful retaliation. You may appeal a denied request and may use an authorized agent where permitted. This draft does not authorize the monetary sale of training data. A factual classification of any SDK disclosure as a sale, share, or targeted advertising event requires completion of the vendor audit before release.
Children, teens, and unknown ages
Entry begins at age 15, while training eligibility begins at age 19. Users ages 15–18 remain in protected mode and their data is excluded from training. All minor and unknown-age events are ineligible for model training, evaluation datasets, and labeling for improvement. If age information changes or indicates a minor, pending training material is removed or blocked under the AI Data Use Notice.
AI outputs and automated processing
Automated systems generate content, personalize continuity, classify safety risk, and help detect abuse. They may make mistakes and are not represented as human judgment. Where applicable law grants review or opt-out rights for a decision producing legal or similarly significant effects, the operator will provide the required process rather than relying on this general description.
How to make a privacy request
A verified privacy and legal request channel will be displayed before this notice becomes effective. The final mailbox has not yet been confirmed, so this draft does not invent contact details. Requests may require proportionate identity verification, and an authorized agent may need to show authority.
Changes to this notice
We will date and describe material changes and provide prominent advance notice when required. New training terms apply only after the required versioned notice and never backdate authority. Earlier versions remain in revision history, and mandatory rights continue despite a policy change.
morewhere プライバシーポリシー
morewhereに適用する個人情報の取扱いの日本語ドラフトです。対象サービス、PROJECT82 LLCとの関係、日本法上の保護および未確認事項に伴う公開停止条件を一つの文書内で説明します。
個人情報取扱事業者
morewhereの運営主体はPROJECT82 LLCです。事業所住所は「30 N Gould St, STE R, Sheridan, WY 82801, USA」です。この管轄における登録番号は確定した正本がないため記載しません。日本向け販売業者表示の最終確認は別途必要です。 PROJECT82 LLCは、公開版で個人情報取扱事業者としての役割、共同利用または委託との区別、および日本向け連絡方法を明確にします。運営主体表示の確認が終わる前に本ドラフトを施行せず、未検証の代表者または連絡先を確定事実として記載しません。
取り扱う情報の種類
morewhereはペルソナ・欲求プロファイル、ワールドポリシー、キャラクターまたはワールドのAIチャットを提供します。 利用開始は15歳以上とし、15~18歳には保護された利用条件を適用します。成人データのAI学習対象は19歳以上に限ります。 取り扱い得る情報には、アカウント情報、年齢区分、利用者が入力または送信した会話・音声・生成物、端末と利用記録、購入・決済状態、問い合わせ、評価、再生成、編集および通報結果が含まれます。実際の項目は利用機能に応じて限定し、不要な要配慮個人情報の入力を求めません。
情報の取得元
情報は、利用者が直接提供する場合、morewhereの機能利用から生成される場合、アプリストアまたは決済事業者から取引状態を受ける場合、および不正利用・安全調査に必要な範囲で適法に取得する場合があります。第三者から取得する項目と取得元は検証したうえで公開し、未確認の供給者やデータ経路を推測して列挙しません。
利用目的と取扱根拠
個人情報保護法(APPI)に基づく利用目的は、サービス提供、本人認証、年齢保護、利用者が選んだパーソナライズ、安全性確保、不正防止、決済、問い合わせ対応、法的義務、品質評価および適格な成人データによるAI改善です。新たな目的が合理的関連性を超える場合は、事前の目立つ通知と、法令上必要な同意その他の適切な根拠を整えます。
サービス処理とAI学習の区別
回答生成、会話保存、利用者が求めたメモリー、年齢・安全確認、通報調査、セキュリティ、決済、サポートおよび法的義務の処理は、サービス運営のために行います。これとは区別して、適格な成人の新規データは目立つ事前通知を根拠にAI評価・微調整・学習へ既定利用し、利用者は退会せず将来分を拒否できます。
人による確認とラベリング
品質、安全性、通報およびデータラベリングのため、権限を付与された従業員または秘密保持・安全管理・削除義務を契約した確認済み受託者が、必要最小限の文脈へアクセスする場合があります。画面には実利用者のアカウントや連絡先を表示せず、アクセス、閲覧、書出しおよび削除の記録を残します。
委託先
ホスティング、AI処理、分析、決済、配信、サポートまたはラベリングの委託先は、契約、処理目的、所在国、安全管理措置、再委託および削除条件を確認してから利用・公開します。現在の候補事業者に未検証事項があるため、名称や役割を確定した一覧として本稿に掲載せず、検証済みの委託先表が完成するまでリリースを停止します。
外国への移転
本サービスの運営主体は米国法人であるため、日本の利用者の個人情報は例外としてではなく原則として国外へ移転して取り扱われます。この移転は利用者との利用契約の履行に必要な範囲で行い、別途の同意を求めるのではなく本通知による明示をもって実施します。 移転を受けた情報は退会時に遅滞なく消去し、法令が保存を求める記録のみ当該法定期間に限り分別して保管したうえで消去します。
委託先または第三者へ個人データを移転する場合も、個人情報保護法(APPI)に従い、移転先の国・地域、受領者、目的、項目、方法、保有条件および継続的な保護措置を確認し、必要な情報提供や同意を行います。委託先の相手方と保障措置は未検証であり、完全な公開表と法律顧問の承認が整うまで施行しません。
保有期間と削除基準
情報は、アカウントと機能の提供、安全調査、購入記録、権利請求、紛争対応および法的保存義務に必要な期間を、情報の性質、利用目的、危険性および法定期間に照らして決めます。目的が終了し保存義務や権利保全の必要がなければ削除または不可逆化し、検証されていない一律の年数を約束せず、公開前に項目別基準を確認します。
安全管理措置
当社は、アクセス権限の最小化、認証、保存領域の分離、通信および保存時の保護、監査記録、脆弱性対応、委託先管理ならびに事故対応をリスクに応じて実施します。完全な安全を保証することはできませんが、漏えい等が生じた場合は影響を評価し、個人情報保護委員会への報告や本人通知など適用法上必要な措置を行います。
本人の権利
利用者は、個人情報保護法(APPI)その他適用法に従い、利用目的の通知、保有個人データの開示等請求、訂正・追加・削除、利用停止・消去および第三者提供停止を求めることができます。法定の例外を適用する場合は理由を説明し、拒否または限定の見直しを求められる経路を公開版に設けます。
未成年者の情報
利用開始は15歳以上とし、15~18歳には保護された利用条件を適用します。成人データのAI学習対象は19歳以上に限ります。 未成年者または年齢不明の利用者の会話をAI学習、モデル評価またはデータラベリングへ使用しません。年齢に応じた保護、保護者への案内、購入制限および安全モードを適用し、年齢確認に用いる情報を別の目的へ無制限に転用しません。
自動処理と人による見直し
AIは応答生成、推奨、安全分類、年齢区分の補助、不正検知およびコンテンツ審査に用いられる場合があります。自動処理が利用停止その他の重要な影響に関係するときは、秘密情報や安全性を害しない範囲で主な理由を示し、適用法が求める場合または合理的に可能な場合に人による再確認と異議申立ての機会を設けます。
請求・問い合わせ窓口
開示等請求、AI学習拒否、苦情および安全上の連絡に用いる正式な窓口は、運営主体と受信能力を検証して公開版へ記載します。未確認の担当者名、メールアドレスまたは電話番号を作成せず、窓口が実際に請求を受領・追跡できることを確認するまで本ポリシーを施行しません。緊急事態には本窓口ではなく地域の公的緊急サービスを利用してください。
ポリシーの変更
利用目的、AI学習、情報の種類、共有先または利用者の権利に重要な変更がある場合、変更内容と適用時期を分かりやすく事前通知し、法令上必要な選択または同意を得ます。新しいAI学習目的を過去のデータへ無通知で遡及適用せず、当時の通知または有効な既存同意より前に発生した事象を学習対象にしません。
morewhere 개인정보처리방침
morewhere의 개인정보 수집, 이용, 제공, 보유 및 권리 행사 기준을 설명하는 공개본입니다.
개인정보처리자
morewhere의 개인정보처리자는 운영주체인 PROJECT82 LLC입니다. 다만 운영주체의 설립 또는 지역 공개사항이 검증되지 않은 경우에는 해당 사실을 확정하여 표시하지 않고 공개를 차단합니다. 개인정보 보호책임자와 법적 연락수단 역시 검증된 정본에 등록된 뒤 공개본에 반영됩니다.
처리 항목과 공개표
개인정보 보호법에 따른 개인정보 처리 공개표는 다음 기준으로 구성됩니다.
| 처리 항목 | 수집 출처 | 이용 목적 | 보유 기준 |
|---|---|---|---|
| 계정·연령·기기 정보 | 이용자 및 기기 | 가입, 연령 보호, 보안 | 계정 유지와 법적 의무에 필요한 기간 |
| 프로필, 월드 정책, 캐릭터·월드 채팅 및 계정·안전 기록 | 이용자와 서비스 이용 | 페르소나·욕구 프로필, 월드 정책 및 캐릭터·월드 AI 채팅, 기억, 신고 처리, 성인 데이터의 적격 AI 개선 | 목적 달성, 거부, 삭제 또는 분쟁 보존 기준까지 |
| 결제·거래 기록 | 앱스토어 또는 결제 처리자 | 유료 기능이 제공되는 경우 결제 화면에 표시되는 이용권, 정산, 환불, 사기 방지 | 전자상거래 및 세무 의무에 필요한 기간 |
수집 출처
정보는 이용자가 입력하거나 업로드한 내용, morewhere 이용 중 생성된 기술·대화 기록, 앱스토어 또는 결제 처리자가 전달한 거래 상태, 안전 신고와 고객지원 상호작용에서 수집됩니다. 연락처 업로드나 제3자 데이터처럼 별도 기능이 확인되지 않은 항목은 수집한다고 가정하지 않으며, 새 출처는 실제 구현과 법적 근거를 확인한 뒤 고지합니다.
이용 목적과 법적 근거
정보는 계약상 서비스 제공, 계정과 페르소나·욕구 프로필, 월드 정책 및 캐릭터·월드 AI 채팅 운영, 안전·보안, 고객지원, 결제, 법적 의무, 정당한 이익 또는 필요한 동의를 근거로 처리합니다. 대한민국에서 동의가 필요한 민감정보·고유식별정보·선택적 마케팅은 다른 목적과 분리하고, 성인 AI 개선은 가입·첫 대화 전의 눈에 띄는 기본 사용 고지 및 이후 거부권을 전제로 운영합니다.
서비스 처리와 AI 학습의 구분
실시간 답변 생성, 이용자가 요청한 기억, 연령·안전 점검, 신고·보안 대응, 결제, 고객지원 및 법적 의무 처리는 AI 학습 거부 후에도 서비스 제공을 위해 계속될 수 있습니다. 반면 거부 효력 이후의 신규 데이터는 학습 큐, 평가, 미세조정, 장기 가명 학습 데이터에 추가하지 않으며 두 목적의 권한과 저장소를 구분합니다.
사람의 검토와 라벨링
품질 평가, 안전 조사 또는 데이터 라벨링을 위해 권한을 부여받은 임직원이나 비밀유지·보안·삭제 의무가 계약된 수탁자가 최소한의 문맥을 검토할 수 있습니다. 실제 계정과 연락처는 라벨링 화면에서 분리하고 접근·조회·내보내기·삭제 기록을 남기며, 검증되지 않은 외부 라벨링 업체에는 데이터를 제공하지 않습니다.
처리위탁과 제공
호스팅, AI 처리, 결제, 광고, 오류 진단 등 실제 사용이 증명된 수탁자만 아래에 표시합니다. 계약과 콘솔에서 아직 확정하지 못한 값은 추정하지 않고 "확인 필요"라고 표시하며, 그 값이 하나라도 남아 있으면 공개 승인을 받을 수 없습니다.
| 수탁자 | 위탁 업무 | 처리 국가 | 보유 기준 |
|---|---|---|---|
| Supabase | 인증·데이터베이스·스토리지·서버 함수 | 확인 필요 | 확인 필요 |
| Sentry | 오류·장애 진단 | 확인 필요 | 확인 필요 |
| RevenueCat | 인앱결제 검증·구독 권한 | 확인 필요 | 확인 필요 |
| PostHog | 제품 분석·세션 리플레이(전체 텍스트 마스킹) | 미국 | 확인 필요 |
| Expo | 푸시 알림 릴레이 | 확인 필요 | 확인 필요 |
수탁자가 추가·변경되면 이 표를 갱신해 사전 고지합니다. 이용자의 개인정보를 마케팅 목적으로 제3자에게 판매하거나 공유하지 않습니다.
국외이전
서비스의 운영주체는 미국 법인이므로, 대한민국 이용자의 개인정보는 예외적으로가 아니라 기본적으로 국외로 이전되어 처리됩니다. 이 이전은 이용자와 체결한 서비스 이용계약의 이행에 필요한 범위에서 이루어지며, 개인정보 보호법 제28조의8 제1항 제3호에 따라 이 방침의 고지로써 수행합니다(별도 동의를 받지 않습니다). 이전받은 정보는 회원 탈퇴 시 지체 없이 파기하며, 전자상거래법 등 법령이 보존을 요구하는 기록만 해당 법정 기간 동안 분리 보관한 뒤 파기합니다.
국외이전 공개표는 현재 다음과 같이 공개 차단 상태입니다.
| 수령자·국가 | 처리 항목 | 이용 목적 | 이전 시기·방법 | 보유기간 | 검증 상태 |
|---|---|---|---|---|---|
| 공개값 미검증 | 공개값 미검증 | 공개값 미검증 | 공개값 미검증 | 공개값 미검증 | 미검증·공개 차단 |
공급자 계약과 실제 데이터 흐름을 대조하여 각 값을 검증하고 필요한 동의 또는 고지를 완료하기 전에는 수령자나 국가를 추정하지 않으며, 국외이전 조항과 전체 공개를 차단합니다. 다만 이전 국가 또는 보유기간이 확인되지 않았다는 이유로 수탁자의 존재까지 감추지는 않습니다 — 해당 수탁자는 Supabase, Sentry, RevenueCat, PostHog, Expo이며, 위 위탁 공개표에 처리 업무와 함께 이미 기재되어 있습니다.
보유 및 파기
개인정보는 계정과 기능 제공, 거래 정산, 안전 사건 조사, 분쟁 대응 및 법적 보존의 목적을 달성하는 데 필요한 기간만 보유합니다. 목적이 끝나고 보존 근거가 없으면 안전한 방식으로 삭제하거나 익명화하며, 백업은 제한된 주기에 따라 격리 삭제합니다. AI 학습용 가명정보에는 별도의 짧고 검토 가능한 보유 기준을 적용합니다.
안전성 확보조치
접근권한 최소화, 인증과 권한 검토, 전송·저장 보호, 비밀 관리, 취약점 대응, 로그와 이상 징후 감시, 백업 분리 및 사고 대응 절차를 위험에 비례하여 적용합니다. 가명정보와 재식별에 필요한 추가정보는 별도 권한으로 분리하고, 이용자에게 중대한 위험이 있는 침해가 발생하면 적용 법률의 절차와 기한에 따라 통지합니다.
정보주체의 권리
이용자는 적용 법률에 따라 개인정보의 열람, 정정, 삭제, 처리정지, 동의 철회, 이의제기 및 가능한 경우 이동을 요청할 수 있습니다. AI 학습 거부는 계정 삭제와 분리하여 제공하고, 법률상 제한 사유가 있으면 그 범위와 이유를 설명합니다. 개인정보침해신고센터와 개인정보분쟁조정위원회 등 법정 구제절차도 이용할 수 있습니다.
아동·청소년 정보
15세부터 가입할 수 있고 15~18세는 보호 모드를 사용하며, AI 학습에는 19세 이상 성인의 데이터만 사용합니다. 모든 미성년자의 대화와 생성 콘텐츠는 AI 학습·평가·라벨링 대상에서 제외합니다. 필요한 경우 법정대리인 동의, 보호자 경로, 제한 모드 또는 연령 확인을 적용하고, 최소 연령 미만 이용을 알게 되면 계정 제한과 삭제 등 법률상 요구되는 조치를 취합니다.
자동화된 처리
추천, 안전 분류, 연령 위험 신호, 부정이용 탐지 및 AI 응답에는 자동화된 처리가 사용될 수 있습니다. 법적 효과 또는 이에 준하는 중대한 영향을 주는 완전 자동 결정이 실제 도입되는 경우에는 그 의미와 예상 결과, 사람이 검토하는 방법 및 적용 법률상 이의제기권을 별도로 고지하고 검증합니다.
개인정보 보호책임자와 구제
개인정보 보호책임자는 다음과 같습니다.
| 구분 | 내용 |
|---|---|
| 성명 | 전진원 |
| 직책 | 대표(Founder) |
| 연락처 | jin@project82.kr |
개인정보 열람·정정·삭제·처리정지 등 권리 행사와 문의는 위 연락처로 접수할 수 있습니다. 이용자는 개인정보침해신고센터(118), 개인정보분쟁조정위원회(1833-6972) 및 관할 감독기관의 구제 절차도 이용할 권리가 있습니다.
방침 변경
수집 항목, 목적, AI 학습 범위, 수탁자, 국외이전, 보유기간 또는 이용자 권리에 중대한 변경이 있으면 적용 법률이 요구하는 시점과 방식으로 미리 고지합니다. 새 목적에 동의가 필요하면 별도 동의를 받고, 이전 버전과 변경 요약을 보존하여 이용자가 어떤 조건이 언제 적용되었는지 확인할 수 있게 합니다.