Privacy Policy

Effective date: September 27, 2026 Last updated: September 27, 2026

This Privacy Policy explains how CALEAVO (“Avocards”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use the Avocards mobile applications, websites, and related services (together, the “Service”).

You can also read our Terms and Conditions and Account and Data Deletion instructions.

1. Who is responsible for your information

CALEAVO is the operator and data controller responsible for Avocards.

  • Operator: CALEAVO
  • Address: 8th floor, Number F870, 191 Dongbaekjungang-ro, Giheung-gu, Yongin, Gyeonggi 17006, Republic of Korea
  • Privacy contact: info@caleavo.com
  • Telephone: +82 10-2683-5235

For privacy questions or requests, email us with the subject “Privacy request”. We may need to verify your identity before acting on a request.

2. Information we process

The information we process depends on the features you use.

Category Examples Why we use it
Account and authentication User ID, email address, display name, profile photo, sign-in provider and authentication tokens Create and secure your account, sign you in, provide support and prevent abuse
Learning and profile activity Cards added or created, answers, mistakes, views, mastery, lessons, streak, XP, coins, hints, achievements, categories, preferences and favourite artists Provide learning features, sync progress, personalise the Service and calculate rewards
Purchases and entitlements Product, subscription status, transaction or receipt identifiers and entitlement history Process and restore Premium access and virtual-item purchases; Apple or Google processes your payment details
User content Custom-card words, meanings, definitions, examples, images, reports and category information Save, sync, display and, when you explicitly choose a public option, publish content
AI requests and outputs Sentences submitted for grammar analysis, words selected for dialogs, custom-card prompts, recognised scan text, generated explanations, translations and audio Provide the AI feature you requested and prevent misuse
Notifications Push token, notification preferences, delivery status, inbox entries and action links Deliver requested service and learning notifications and preserve recent notification history
Device and usage information Device and app version, operating system, IP address, language, screen and feature interactions, approximate region, user or device identifiers and advertising identifiers where permitted Operate, secure, measure and improve the Service, attribute installs and show advertising in the free version
Diagnostics Crash reports, performance traces, request logs and error details Diagnose failures, protect the Service and improve reliability
Communications Support emails and information you include in them Answer requests and resolve problems

Please do not submit confidential, medical, financial, identity-document or other sensitive personal information in cards, scans, AI prompts, reports or support messages.

3. AI features

Avocards uses third-party artificial-intelligence services, currently OpenAI, through our backend. We send only the content needed to fulfil the request. We do not intentionally include your email address or profile details in an AI prompt.

Grammar analysis

When you request grammar analysis, the Korean sentence, your selected language and the instructions needed to format the explanation are sent for processing. The generated analysis may be stored with an asynchronous job long enough to return it to you and make the related notification available.

Dialog generation

When you generate a dialog, selected vocabulary, language information and generation instructions are sent for processing. The output can contain a dialog, translations and learning annotations.

AI-generated custom cards

When you generate a custom card, the word, optional meaning, selected language and generation instructions are sent for processing. A saved AI-generated card may be translated into supported languages, have pronunciation audio generated, and become publicly searchable after you choose to save it as public and it passes applicable safety checks. Do not publish content you do not have the right to share.

Manually entered custom cards are private by default. We use them to provide storage and synchronisation and do not make them publicly searchable unless the product clearly offers and you choose a public publishing action.

Scan import

Camera or gallery images are analysed on the device to recognise text. Avocards sends the recognised text, rather than the source image, to the backend to find matching cards and resolve import conflicts. If a future scan flow uploads an image for AI analysis, we will disclose that before upload and update this Policy.

AI choices and limitations

AI features are optional. Using Generate or Analyse requests that Avocards send the described content to OpenAI for that feature. If you do not want content sent to OpenAI, do not use that feature; the rest of the Service remains available subject to its normal requirements.

We request that AI API responses are not stored for product training. The provider may temporarily retain request data for security and abuse monitoring under its enterprise/API terms. AI output can be incorrect, incomplete or inappropriate and must not be treated as professional advice. You can report problematic output in the app or by contacting us.

Depending on your location and the processing involved, we rely on:

  • performance of our agreement to provide accounts, learning, synchronisation, requested AI features and purchases;
  • legitimate interests in securing, supporting, measuring and improving the Service, where those interests are not overridden by your rights;
  • consent for optional notifications, device permissions, tracking, advertising personalisation, third-party AI sharing or other processing where consent is required; and
  • legal obligations relating to transactions, accounting, fraud prevention, disputes and lawful requests.

You may withdraw consent through the relevant device setting, in-app control or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal.

5. When information is public

Your account and learning progress are not public by default. A card or category becomes public only when the Service presents a publishing action and you choose it. Public content may be searchable and copied into other users’ collections. Removing your original content will not automatically remove an independent copy already saved by another user, but we may remove or anonymise public source records where required.

Never publish personal information about yourself or another person. We may review, restrict or remove public content that is unlawful, abusive, unsafe, infringing or inconsistent with our Terms.

6. Service providers and international transfers

We use service providers to operate Avocards. They process information only for the described purpose and under their applicable agreements and privacy terms.

Provider or category Purpose Typical information Processing locations
Microsoft Azure API hosting, databases, storage, monitoring and content delivery Account, learning, user content, service logs and generated results Configured Azure regions, which may be outside your country
Google Firebase and Google services Authentication, messaging, analytics, crash/performance reporting, configuration and Android advertising Account identifiers, push tokens, usage, advertising/device identifiers and diagnostics Global infrastructure, including the United States
Apple Apple sign-in, App Store purchases, push delivery and platform services Account or device token and purchase information Apple processing locations
OpenAI Grammar analysis, dialog and card generation, translation or related AI processing Content submitted to an AI feature and generated output United States and other documented service locations
RevenueCat Subscription and entitlement management App user ID, product, entitlement and transaction information United States and documented subprocessors
OneSignal Push and in-app notification delivery App user ID, email where configured, push token, device and notification tags United States and documented subprocessors
AppsFlyer Install attribution and campaign measurement App user ID, device/advertising identifiers, install and campaign events United States, EEA and documented subprocessors
Amplitude Product analytics App user ID, device and feature-interaction data United States and documented subprocessors
Meta/Facebook Facebook sign-in and configured app measurement Login identity and app/device events United States and documented subprocessors
Apple App Store and Google Play Billing, refunds and subscription management Store account and transaction information Store processing locations

These transfers may be protected by an adequacy decision, contractual safeguards, provider certification where legally recognised, or consent or another statutory transfer basis where applicable. Contact us to request information about the safeguard relevant to you. Provider configurations and locations may change; we review this table when the processing changes.

We may also disclose information when reasonably necessary to comply with law, protect users or the public, investigate abuse, enforce our Terms, or complete a corporate reorganisation with appropriate safeguards.

We do not sell personal information for money. Some analytics, attribution or advertising activities may be considered “sharing”, “targeted advertising” or “cross-context behavioural advertising” under certain laws. Where applicable, we provide the required consent or opt-out controls.

7. Cookies, analytics and advertising

Our websites use necessary storage required for security and basic operation. We do not load optional website analytics, advertising pixels or session replay before the consent required by applicable law. If we add optional website tracking, we will identify it in a consent control and allow you to reject or withdraw it as easily as you accept it.

The apps use analytics, attribution, crash-reporting and advertising SDKs described above and may access device or advertising identifiers. On iOS, tracking that falls within Apple’s App Tracking Transparency rules requires authorisation. You can limit applicable permissions in your device settings and use available in-app privacy controls.

8. Device permissions

Avocards may request access to notifications, camera, photo library, microphone or speech recognition only when a related feature needs it. Denying a permission prevents that feature from using the protected device capability but does not normally prevent unrelated features. You can revoke permissions in your device settings.

9. Retention

We retain information only as long as needed for the purposes above or as legally required.

  • Account and synchronised learning data are kept while your account is active and are scheduled for deletion when your account is deleted, subject to the exceptions below.
  • Notification inbox entries, asynchronous AI job results and unsaved AI-generated-card drafts expire after approximately 90 days.
  • Private custom cards are kept while your account is active or until you delete them. Public content may need to be removed, anonymised or retained in limited form to protect other users’ saved collections and the integrity of the public catalogue.
  • Purchase and transaction evidence may be retained for the period required by tax, accounting, consumer and fraud-prevention law. Apple, Google and RevenueCat keep their own transaction records under their policies.
  • Security, diagnostic and support records are kept for the shortest period reasonably needed for reliability, security, dispute handling and legal compliance, according to the relevant system or provider configuration.
  • Encrypted backups may persist for a limited rotation period before being overwritten.

We delete, anonymise or securely isolate information when its retention period ends, unless preservation is required for a legal claim, security investigation or other legal obligation.

10. Account and data deletion

You can initiate deletion inside the app through Settings > Remove personal data. You can also use our Account and Data Deletion page or email info@caleavo.com.

Deletion removes or anonymises the account and associated personal data under our control, subject to legal retention and the public-content limitations explained above. It does not automatically cancel an Apple App Store or Google Play subscription; cancel recurring billing in the store before deleting your account. We may retain a minimal record of the request to demonstrate compliance.

11. Your rights

Subject to applicable law, you may ask us to:

  • confirm whether we process your information and provide access or a copy;
  • correct inaccurate or incomplete information;
  • delete information;
  • restrict or object to processing;
  • provide portable information you supplied;
  • withdraw consent; or
  • explain and challenge a decision based solely on automated processing where the law gives that right.

You may also complain to the Korean Personal Information Protection Commission or your local data-protection authority. EEA and UK residents may complain to the authority where they live or work. We will not discriminate against you for exercising a privacy right.

12. Security

We use administrative, technical and organisational safeguards designed to protect personal information, including encrypted network transport, authenticated access and restricted production access. No service can guarantee absolute security. Contact us immediately if you believe your account or information has been compromised.

13. Children

Avocards is a general-audience learning service and is not directed to children under 13. A person under 13, or under a higher minimum digital-consent age in their country, must not create an account or provide personal information without verifiable permission from a parent or legal guardian. If you are below the age of legal majority where you live, your parent or guardian must review the Terms with you.

If you believe a child provided personal information without the required permission, contact us and we will investigate and delete it where required.

14. Changes

We may update this Policy when the Service or law changes. We will change the date above and provide an in-app, website or email notice before a material change takes effect where required. Earlier versions may be requested from the privacy contact.

15. Contact

For privacy requests or questions:

CALEAVO 8th floor, Number F870 191 Dongbaekjungang-ro, Giheung-gu Yongin, Gyeonggi 17006, Republic of Korea info@caleavo.com +82 10-2683-5235