Korea Privacy Addendum

Effective Date: 1 June 2026

Last Updated: 1 June 2026

This Korea Privacy Addendum supplements the Fraw Privacy Policy and applies to users located in the Republic of Korea. This Addendum explains additional information about how Untitled Labs Limited (“Fraw,” “we,” “us,” or “our”) collects, uses, discloses, outsources, transfers, retains, destroys, and protects personal information in connection with the Fraw mobile application, website, software, official functions, extensions, creator tools, and related services.

This Addendum should be read together with the Fraw Privacy Policy. If there is any conflict between this Addendum and the Fraw Privacy Policy, this Addendum will apply to users located in the Republic of Korea to the extent required by applicable Korean privacy laws.

1. Personal Information We Collect and Use

We collect and use personal information only to the extent reasonably necessary to provide, operate, secure, support, improve, and legally administer the Service. The categories of personal information we may collect and use are described below.

CategoryExamplesPurpose of Use
Account informationName, username, display name, profile information, email address, phone number where applicable, login credentials, authentication information, account identifiersAccount creation, login, authentication, account management, user support, service notices, security, fraud prevention, and enforcement of our Terms
Third-party login informationInformation received from Apple ID, Google login, or other supported authentication providersAccount signup, login, authentication, account linking, security, and fraud prevention
Device, technical, diagnostic, and usage informationDevice type, operating system, app version, browser type, language settings, IP address, approximate location derived from IP, general region, device or app identifiers, crash logs, diagnostic data, usage events, timestamps, and performance dataService operation, debugging, analytics, reliability, security, abuse prevention, fraud prevention, feature improvement, and legal compliance
Transaction, subscription, top-up, and purchase informationApp store transaction records, subscription status, renewal status, purchase records, top-up records, refunds, chargebacks, and billing-related recordsSubscription management, purchase verification, credit management, billing support, refund handling, chargeback management, accounting, audit, fraud prevention, and legal compliance
User content and generated contentText prompts, uploaded images, generated images, image transformations, extension configurations, creator publication data, moderation records, and related inputs or outputsProviding image-generation features, generating requested outputs, operating official functions, supporting extensions, moderation, safety review, fraud prevention, user support, and enforcement of our Terms
Face Data and face-containing contentPhotographs, images, or visual content containing a human face that you voluntarily upload, capture, select, or otherwise submit, together with non-identifying image characteristics such as face position, orientation, framing, alignment, image composition, or similar non-identifying information used only to generate the requested image transformationProviding user-requested image-processing features, transmitting images to third-party AI image-generation or image-processing providers where necessary, returning generated results, saving content to your account gallery if you choose to keep it, content safety, abuse prevention, legal compliance, and enforcement of our Terms
Extension-related informationExtension names, descriptions, prompts, configurations, reference images, thumbnails, before-and-after images, generated examples, publication status, archive status, and usage recordsCreating, editing, saving, archiving, publishing, unpublishing, moderating, operating, and administering extensions and related creator features
Creator-program and withdrawal-related informationCreator account status, creator-program records, withdrawal eligibility, withdrawal requests, payout preferences where applicable, payout status, payout amount, payout provider identifier, transaction reference, fraud-prevention signals, and related creator-program communicationsAdministering creator rewards or Diamonds, processing and tracking withdrawal requests, preventing misuse, maintaining accurate records, resolving disputes, accounting, audit, legal compliance, and enforcing our Terms and creator policies
Referral, rewards, and fraud-prevention informationInvitations, referral attribution, signup events, conversion events, account relationships, device signals, payment signals, suspected abuse or manipulation recordsOperating referral or reward programs, determining eligibility, preventing abuse, investigating manipulation, enforcing program rules, and protecting platform integrity
Support, inquiry, complaint, and communication informationSupport requests, feedback, reports, complaints, correspondence, and related recordsResponding to inquiries, providing support, investigating issues, resolving disputes, enforcing our Terms, protecting users and the Service, and maintaining business records
Legal, security, and compliance recordsSecurity logs, abuse-prevention records, moderation records, legal requests, dispute records, enforcement records, and audit recordsSecurity, fraud prevention, abuse prevention, legal compliance, regulatory compliance, dispute resolution, enforcement of our Terms, and protection of legal rights

2. Face Data and Biometric-Related Clarification

Fraw allows users to upload, capture, edit, transform, rebuild, blend, or otherwise process images that may contain a human face. We process Face Data only to provide the image-processing features requested by the user and for related safety, security, abuse-prevention, service-reliability, legal-compliance, and enforcement purposes.

Fraw does not use Face Data to identify you as a real-world person, verify your identity, authenticate your account, create a biometric identification profile, perform facial recognition, perform identity matching, or determine sensitive attributes.

Fraw does not create or store biometric templates, faceprints, face-geometry scans, or other biometric identifiers. Fraw does not use Face Data for advertising, marketing, cross-context behavioral advertising, interest-based advertising, resale, independent profiling, or unrelated model training.

Where Face Data is transmitted to third-party AI image-generation or image-processing providers, it is transmitted only where necessary to generate the requested output, perform related safety or abuse-prevention checks, maintain service reliability, or support the requested feature, subject to the provider terms, service configuration, contractual safeguards, platform terms, data- processing agreements, or equivalent safeguards described in the Fraw Privacy Policy.

3. Creator Payout and Withdrawal Records

For the global version of the Service, Fraw does not directly collect government identification documents, tax identification numbers, tax forms, or other formal identity-verification or tax records from users as part of the standard account signup, login, creator participation, or withdrawal flow.

Account signup and login may be supported through third-party authentication providers, such as Apple ID or Google login.

Creator payouts may be processed through third-party payout providers, such as PayPal, where available. When you use a third-party payout provider, you may be required to provide payout account information, identity information, tax information, or other compliance-related information directly to that provider. That provider’s collection, use, retention, disclosure, and protection of such information are governed by its own terms, privacy policy, and legal obligations.

Fraw may receive or retain limited information from or about the payout process, such as your Fraw account identifier, creator account status, withdrawal eligibility, withdrawal requests, payout status, payout amount, transaction reference, payout provider identifier, fraud-prevention signals, and related creator-program records.

4. Retention and Destruction of Personal Information

We retain personal information only for as long as reasonably necessary for the purposes described in the Fraw Privacy Policy and this Addendum, unless a longer retention period is required or permitted by applicable law.

The following table describes our general retention practices for users located in Korea.

CategoryRetention Period
Account informationRetained while your account is active. After account deletion, account information is deleted or de-identified from active systems within a reasonable period, unless retention is required or permitted for legal, security, fraud-prevention, dispute-resolution, tax, accounting, audit, enforcement, creator-program, payout, or backup purposes.
Temporary processing imagesImages uploaded for AI processing that are not saved to your account gallery, associated with a saved extension, or otherwise retained as part of an account feature are deleted from active systems within 48 hours after generation is complete, unless a longer period is necessary for security, abuse prevention, legal compliance, dispute resolution, technical troubleshooting, enforcement of our Terms, or protection of legal rights.
Saved gallery images and generated contentRetained while your account is active, or until you delete them through available in-app controls, subject to legal, security, fraud-prevention, dispute-resolution, enforcement, creator-program, payout, accounting, audit, and backup-retention requirements.
Original input imagesRetained only where saved to your account, gallery, extension, project, history, or other account feature at your request or as part of a feature you use. Such images are retained while needed to provide the relevant feature, or until you delete the relevant image, gallery item, project, account content, or account, subject to the exceptions described in the Fraw Privacy Policy.
Face Data and face-containing contentRetained as described in the Fraw Privacy Policy, including Section 3.6 (Retention of Face-Containing Images).
Draft, temporary, or unsaved extension assetsRetained while the draft, temporary, or unsaved extension remains available in your account or in the relevant creation flow. Draft, temporary, or unsaved extensions may be deleted individually through available controls where such controls are provided.
Saved private extension assetsRetained while the private extension remains active, archived, visible in your account, or otherwise available through the Service. Archiving a private extension does not delete the extension or its associated assets. Individual deletion may not be available for saved private extensions.
Published or public extension assetsRetained while the extension remains published, active, archived, visible in your account, previously used by a user, or otherwise available through the Service. Individual deletion may not be available for saved published or public extensions.
Archived extension assetsRetained where needed to support account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement of our Terms, and backup-retention purposes.
Creator-program, withdrawal, payout-status, transaction, fraud-prevention, accounting, audit, and compliance recordsRetained for the period required or permitted for creator-program administration, withdrawal processing, payout tracking, accounting, audit, fraud-prevention, legal, and compliance obligations, even after you delete your account, archive an extension, unpublish an extension, or stop participating in creator features.
Support, complaint, moderation, security, and abuse-prevention recordsRetained for the period reasonably necessary to respond to requests, investigate reports, moderate content, resolve disputes, enforce our Terms, comply with law, protect rights and safety, and maintain appropriate business records.
BackupsDeleted information may remain in encrypted backups for a limited period until those backups are overwritten or deleted according to our backup retention schedule. Backup copies are not used for active processing except where restoration is necessary for security, disaster recovery, legal compliance, or service continuity.

When the purpose of collection or use has been fulfilled, the applicable retention period has expired, or deletion is required by applicable law, we will delete, de-identify, anonymize, or otherwise securely dispose of personal information unless retention is required or permitted for legal, tax, accounting, audit, security, fraud-prevention, dispute-resolution, enforcement, creator-program, payout, backup, or other legitimate purposes.

Electronic records are deleted using technical methods designed to make the records unrecoverable or not reasonably capable of being restored in ordinary course. Physical records, if any, are destroyed by shredding, incineration, or another secure destruction method.

5. Outsourcing of Personal Information Processing

We may outsource certain personal information processing activities to service providers that process personal information on our behalf. These service providers are permitted to process personal information only as necessary to provide services to us, subject to contractual, platform, technical, organizational, or legal safeguards.

Type of Outsourced ProviderOutsourced Processing Activities
Cloud hosting and storage providersHosting, storage, database operation, content storage, backup, service infrastructure, reliability, and security
AI image-generation or image-processing providersProcessing uploaded images, including Face Data where necessary, to generate requested outputs, perform safety or abuse-prevention checks, maintain service reliability, and support requested image-processing features
Analytics providersUsage analytics, performance analytics, crash analytics, diagnostic data processing, product analytics, and service-quality measurement
Payment platforms and app storesSubscription processing, top-up purchase processing, purchase verification, refunds, chargebacks, billing support, and transaction records
Payout providersProcessing creator withdrawals or payouts where available, payout status updates, transaction references, payout-provider identifiers, and related payout records
Customer support providersSupport ticket handling, user inquiries, complaint management, user communications, and issue resolution
Security, fraud-prevention, and moderation providersFraud detection, abuse prevention, spam prevention, content safety review, prohibited content detection, security monitoring, incident response, and enforcement support
Communications and infrastructure providersEmail delivery, service notices, operational communications, infrastructure monitoring, and related technical services

We select and manage service providers using appropriate safeguards designed to protect personal information. We may update the list or types of outsourced providers as the Service evolves.

6. Provision of Personal Information to Third Parties

We do not sell personal information. We do not sell, rent, or trade Face Data.

We may provide or disclose personal information to third parties only where necessary for the purposes described in the Fraw Privacy Policy and this Addendum, including where:

  • you direct us to do so;
  • it is necessary to provide, operate, secure, support, or legally administer the Service;
  • it is necessary to process payments, subscriptions, purchases, refunds, chargebacks, payouts, or related records;
  • it is necessary to operate public-facing creator features or published extensions;
  • it is necessary to detect or prevent fraud, abuse, security incidents, prohibited content, policy violations, or misuse of the Service;
  • it is necessary to comply with applicable law, legal process, valid governmental requests, court orders, or regulatory obligations;
  • it is necessary to enforce our Terms or protect the rights, safety, or property of Fraw, our users, or others;
  • it is part of a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable confidentiality and legal protections.

If you publish an extension or otherwise use public-facing creator features, certain information may be visible to other users, such as your display name or creator name, extension title, extension description, related public metadata, and content you choose to make public through the Service.

7. Overseas Processing and International Transfers

We operate the Service using cloud infrastructure, service providers, and technical systems that may be located in countries or regions other than Korea. As a result, personal information of users located in Korea may be processed, stored, accessed, or transferred outside Korea.

This may include account information, device and usage information, transaction records, support information, creator-program, withdrawal, or payout-status information where applicable, user content, uploaded images, generated content, extension assets, and Face Data where such information is processed as part of the Service.

We transfer personal information outside Korea only where reasonably necessary to provide, operate, secure, support, analyze, improve, or legally administer the Service, or where otherwise permitted by applicable law.

The following table describes the general overseas processing and transfer practices for the Service.

Recipient or Type of RecipientCountries or RegionsCategories of InformationPurpose of TransferTransfer MethodRetention Period
Cloud hosting and storage providersCountries or regions where the provider operates infrastructure, which may include the United States and other regionsAccount information, user content, generated content, extension assets, Face Data where stored as part of the Service, logs, technical data, and backupsHosting, storage, service operation, reliability, security, backup, and infrastructure supportEncrypted transmission over network connections, provider APIs, cloud infrastructure, and secure administrative access controlsFor as long as necessary to provide the Service, or as otherwise described in the Fraw Privacy Policy and this Addendum
AI image-generation or image-processing providersCountries or regions where the provider operates or processes requests, which may include the United States and other regionsUploaded images, Face Data where the uploaded image contains a human face, prompts, processing metadata, generated outputs, and related safety or abuse-prevention dataGenerating requested outputs, safety checks, abuse prevention, service reliability, debugging, and support of requested image-processing featuresEncrypted API transmission or secure service integrationDuring processing and for any limited technical, safety, security, abuse-prevention, service-reliability, debugging, or legal retention period permitted by the provider terms and service configuration
Analytics, crash, and diagnostic providersCountries or regions where the provider operates infrastructure, which may include the United States and other regionsDevice information, app information, usage events, crash logs, diagnostic data, performance data, and technical identifiersAnalytics, reliability, crash reporting, debugging, product improvement, security, and service-quality measurementSDK, API, or encrypted network transmissionFor as long as necessary for analytics, security, debugging, and service improvement, or as configured in provider settings
App stores and payment platformsCountries or regions where the platform operatesTransaction, subscription, purchase, refund, chargeback, and billing-related recordsPurchase processing, subscription management, payment verification, refunds, billing support, and compliancePlatform APIs, app store systems, payment platform systems, and encrypted network transmissionAs determined by the applicable platform terms, legal obligations, and transaction-record requirements
Payout providersCountries or regions where the provider operatesCreator account identifiers, withdrawal requests, payout status, payout amount, transaction reference, payout provider identifier, and related payout records. Payout account information, identity information, tax information, or compliance information may be collected directly by the payout provider under its own terms.Processing creator withdrawals or payouts, payout tracking, fraud prevention, accounting, audit, dispute resolution, and complianceProvider account flow, provider APIs, and encrypted network transmissionAs determined by the payout provider’s terms, privacy policy, and legal obligations, and as necessary for Fraw’s creator-program records
Customer support and communications providersCountries or regions where the provider operatesContact information, support requests, complaints, communications, device information, account identifiers, and related support recordsCustomer support, user communications, issue resolution, service notices, and operational communicationsSupport tools, email systems, APIs, and encrypted network transmissionFor as long as necessary to provide support, resolve issues, maintain business records, and comply with legal obligations
Security, fraud-prevention, and moderation providersCountries or regions where the provider operatesAccount identifiers, device and usage signals, uploaded or generated content where necessary, moderation records, fraud signals, security logs, and related recordsFraud prevention, abuse prevention, content safety, prohibited content detection, security monitoring, incident response, and enforcement supportSDK, API, secure service integration, or encrypted network transmissionFor as long as necessary for security, fraud prevention, moderation, enforcement, legal compliance, and dispute resolution

Where required by applicable law, we take appropriate steps to protect personal information transferred outside Korea. These steps may include contractual safeguards, data-processing agreements, provider due diligence, access controls, encryption in transit, encryption at rest where supported by the applicable storage system, technical and organizational security measures, and other recognized transfer mechanisms.

Some overseas transfers may be necessary to provide the Service. If you do not want your personal information to be transferred outside Korea, you may choose not to use the Service, or you may contact us to exercise your rights where available under applicable law. However, refusing or objecting to certain overseas transfers may limit or prevent your ability to use some or all of the Service.

8. Rights of Users Located in Korea

Subject to applicable law, users located in Korea may have rights regarding their personal information, including the right to:

  • request access to personal information;
  • request correction of inaccurate or incomplete personal information;
  • request deletion of certain personal information;
  • request suspension of processing of certain personal information;
  • withdraw consent where processing is based on consent;
  • request information about the processing, outsourcing, or overseas transfer of personal information where required by law;
  • raise complaints or inquiries regarding the handling of personal information.

You may manage certain information directly through your account settings or available in-app controls. Account deletion is available in the app. You may delete individual saved images, generated content, and gallery items through available in-app controls. For saved extensions in your extension library or similar account area, individual deletion may not be available; saved extensions may instead be archived through available in-app controls. Draft, temporary, or unsaved extensions may be deleted individually where deletion controls are provided.

When you delete your account, we will schedule deletion or de-identification of personal information associated with your account from active systems within a reasonable period, subject to the exceptions described in the Fraw Privacy Policy and this Addendum.

To exercise your rights, contact us using the details in the Privacy Contact section below or use available in-app privacy or account controls. We may need to verify your identity before fulfilling a request.

We may decline, limit, or delay a request where permitted by applicable law, including where we cannot verify your identity, where fulfilling the request would conflict with legal obligations, security requirements, fraud-prevention needs, creator-program administration, dispute-resolution needs, payment or payout processing requirements, or the rights and freedoms of others.

9. Children’s Personal Information

The Service is not intended for children below the age permitted under applicable law to use the Service without parental consent.

We do not knowingly collect personal information from children in violation of applicable law. Where required by Korean law, if we knowingly collect personal information from a child under the applicable age threshold, we will obtain consent from the child’s legal representative before collecting, using, disclosing, or otherwise processing the child’s personal information.

If you believe a child has provided us with personal information unlawfully, please contact us so we can investigate and take appropriate action.

10. Security Measures

We use reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include:

  • encryption in transit using TLS;
  • encryption at rest where supported by the applicable storage system;
  • access controls and permission management;
  • internal access limitations based on need to know;
  • logging and monitoring of systems where appropriate;
  • technical safeguards designed to protect against unauthorized access, alteration, loss, or disclosure;
  • review and management of service providers;
  • procedures for responding to security incidents;
  • employee or contractor confidentiality obligations where applicable.

However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Data Breach Notification

If we become aware of a personal information breach affecting users located in Korea, we will take steps to investigate, mitigate, and respond to the incident in accordance with applicable law.

Where required by Korean law, we will notify affected users and report to the competent authority within the legally required timeframe. The notice may include information such as the nature of the breach, the categories of information affected, timing of the breach, measures taken by Fraw, steps users may take to reduce harm, and contact information for inquiries.

12. Privacy Contact

If you have questions, concerns, complaints, or requests regarding this Korea Privacy Addendum or our handling of personal information, you may contact us using the details below:

  • Untitled Labs Limited
  • Address: 20/F, Harbourside HQ, 8 Lam Chak Street, Kowloon Bay, Kowloon
  • Support Email: hi@fraw.ai
  • Company Registration: 71095371

We will review and respond to privacy-related requests in accordance with applicable law and our internal procedures. Depending on the nature of your request, we may need to verify your identity before responding or taking action.

Where required by applicable Korean law, we will provide additional contact information, privacy manager details, representative details, or other required information through this Korea Privacy Addendum, within the Service, on our website, or by other reasonable means.

You may also contact the Korean Personal Information Protection Commission or other competent authorities if you believe your personal information rights have been violated.

13. Changes to This Korea Privacy Addendum

We may update this Korea Privacy Addendum from time to time.

If we make material changes, we may provide notice through the Service, by email, on our website, or by other reasonable means, as required by applicable law.

Your continued use of the Service after the updated Korea Privacy Addendum becomes effective means you acknowledge the revised Addendum.