Korea Privacy Addendum
Effective Date: 1 June 2026
Last Updated: 1 June 2026
This Korea Privacy Addendum supplements the Fraw Privacy Policy and applies to users located in the Republic of Korea. This Addendum explains additional information about how Untitled Labs Limited (“Fraw,” “we,” “us,” or “our”) collects, uses, discloses, outsources, transfers, retains, destroys, and protects personal information in connection with the Fraw mobile application, website, software, official functions, extensions, creator tools, and related services.
This Addendum should be read together with the Fraw Privacy Policy. If there is any conflict between this Addendum and the Fraw Privacy Policy, this Addendum will apply to users located in the Republic of Korea to the extent required by applicable Korean privacy laws.
1. Personal Information We Collect and Use
We collect and use personal information only to the extent reasonably necessary to provide, operate, secure, support, improve, and legally administer the Service. The categories of personal information we may collect and use are described below.
| Category | Examples | Purpose of Use |
|---|---|---|
| Account information | Name, username, display name, profile information, email address, phone number where applicable, login credentials, authentication information, account identifiers | Account creation, login, authentication, account management, user support, service notices, security, fraud prevention, and enforcement of our Terms |
| Third-party login information | Information received from Apple ID, Google login, or other supported authentication providers | Account signup, login, authentication, account linking, security, and fraud prevention |
| Device, technical, diagnostic, and usage information | Device type, operating system, app version, browser type, language settings, IP address, approximate location derived from IP, general region, device or app identifiers, crash logs, diagnostic data, usage events, timestamps, and performance data | Service operation, debugging, analytics, reliability, security, abuse prevention, fraud prevention, feature improvement, and legal compliance |
| Transaction, subscription, top-up, and purchase information | App store transaction records, subscription status, renewal status, purchase records, top-up records, refunds, chargebacks, and billing-related records | Subscription management, purchase verification, credit management, billing support, refund handling, chargeback management, accounting, audit, fraud prevention, and legal compliance |
| User content and generated content | Text prompts, uploaded images, generated images, image transformations, extension configurations, creator publication data, moderation records, and related inputs or outputs | Providing image-generation features, generating requested outputs, operating official functions, supporting extensions, moderation, safety review, fraud prevention, user support, and enforcement of our Terms |
| Face Data and face-containing content | Photographs, images, or visual content containing a human face that you voluntarily upload, capture, select, or otherwise submit, together with non-identifying image characteristics such as face position, orientation, framing, alignment, image composition, or similar non-identifying information used only to generate the requested image transformation | Providing user-requested image-processing features, transmitting images to third-party AI image-generation or image-processing providers where necessary, returning generated results, saving content to your account gallery if you choose to keep it, content safety, abuse prevention, legal compliance, and enforcement of our Terms |
| Extension-related information | Extension names, descriptions, prompts, configurations, reference images, thumbnails, before-and-after images, generated examples, publication status, archive status, and usage records | Creating, editing, saving, archiving, publishing, unpublishing, moderating, operating, and administering extensions and related creator features |
| Creator-program and withdrawal-related information | Creator account status, creator-program records, withdrawal eligibility, withdrawal requests, payout preferences where applicable, payout status, payout amount, payout provider identifier, transaction reference, fraud-prevention signals, and related creator-program communications | Administering creator rewards or Diamonds, processing and tracking withdrawal requests, preventing misuse, maintaining accurate records, resolving disputes, accounting, audit, legal compliance, and enforcing our Terms and creator policies |
| Referral, rewards, and fraud-prevention information | Invitations, referral attribution, signup events, conversion events, account relationships, device signals, payment signals, suspected abuse or manipulation records | Operating referral or reward programs, determining eligibility, preventing abuse, investigating manipulation, enforcing program rules, and protecting platform integrity |
| Support, inquiry, complaint, and communication information | Support requests, feedback, reports, complaints, correspondence, and related records | Responding to inquiries, providing support, investigating issues, resolving disputes, enforcing our Terms, protecting users and the Service, and maintaining business records |
| Legal, security, and compliance records | Security logs, abuse-prevention records, moderation records, legal requests, dispute records, enforcement records, and audit records | Security, fraud prevention, abuse prevention, legal compliance, regulatory compliance, dispute resolution, enforcement of our Terms, and protection of legal rights |
2. Face Data and Biometric-Related Clarification
Fraw allows users to upload, capture, edit, transform, rebuild, blend, or otherwise process images that may contain a human face. We process Face Data only to provide the image-processing features requested by the user and for related safety, security, abuse-prevention, service-reliability, legal-compliance, and enforcement purposes.
Fraw does not use Face Data to identify you as a real-world person, verify your identity, authenticate your account, create a biometric identification profile, perform facial recognition, perform identity matching, or determine sensitive attributes.
Fraw does not create or store biometric templates, faceprints, face-geometry scans, or other biometric identifiers. Fraw does not use Face Data for advertising, marketing, cross-context behavioral advertising, interest-based advertising, resale, independent profiling, or unrelated model training.
Where Face Data is transmitted to third-party AI image-generation or image-processing providers, it is transmitted only where necessary to generate the requested output, perform related safety or abuse-prevention checks, maintain service reliability, or support the requested feature, subject to the provider terms, service configuration, contractual safeguards, platform terms, data- processing agreements, or equivalent safeguards described in the Fraw Privacy Policy.
3. Creator Payout and Withdrawal Records
For the global version of the Service, Fraw does not directly collect government identification documents, tax identification numbers, tax forms, or other formal identity-verification or tax records from users as part of the standard account signup, login, creator participation, or withdrawal flow.
Account signup and login may be supported through third-party authentication providers, such as Apple ID or Google login.
Creator payouts may be processed through third-party payout providers, such as PayPal, where available. When you use a third-party payout provider, you may be required to provide payout account information, identity information, tax information, or other compliance-related information directly to that provider. That provider’s collection, use, retention, disclosure, and protection of such information are governed by its own terms, privacy policy, and legal obligations.
Fraw may receive or retain limited information from or about the payout process, such as your Fraw account identifier, creator account status, withdrawal eligibility, withdrawal requests, payout status, payout amount, transaction reference, payout provider identifier, fraud-prevention signals, and related creator-program records.
4. Retention and Destruction of Personal Information
We retain personal information only for as long as reasonably necessary for the purposes described in the Fraw Privacy Policy and this Addendum, unless a longer retention period is required or permitted by applicable law.
The following table describes our general retention practices for users located in Korea.
| Category | Retention Period |
|---|---|
| Account information | Retained while your account is active. After account deletion, account information is deleted or de-identified from active systems within a reasonable period, unless retention is required or permitted for legal, security, fraud-prevention, dispute-resolution, tax, accounting, audit, enforcement, creator-program, payout, or backup purposes. |
| Temporary processing images | Images uploaded for AI processing that are not saved to your account gallery, associated with a saved extension, or otherwise retained as part of an account feature are deleted from active systems within 48 hours after generation is complete, unless a longer period is necessary for security, abuse prevention, legal compliance, dispute resolution, technical troubleshooting, enforcement of our Terms, or protection of legal rights. |
| Saved gallery images and generated content | Retained while your account is active, or until you delete them through available in-app controls, subject to legal, security, fraud-prevention, dispute-resolution, enforcement, creator-program, payout, accounting, audit, and backup-retention requirements. |
| Original input images | Retained only where saved to your account, gallery, extension, project, history, or other account feature at your request or as part of a feature you use. Such images are retained while needed to provide the relevant feature, or until you delete the relevant image, gallery item, project, account content, or account, subject to the exceptions described in the Fraw Privacy Policy. |
| Face Data and face-containing content | Retained as described in the Fraw Privacy Policy, including Section 3.6 (Retention of Face-Containing Images). |
| Draft, temporary, or unsaved extension assets | Retained while the draft, temporary, or unsaved extension remains available in your account or in the relevant creation flow. Draft, temporary, or unsaved extensions may be deleted individually through available controls where such controls are provided. |
| Saved private extension assets | Retained while the private extension remains active, archived, visible in your account, or otherwise available through the Service. Archiving a private extension does not delete the extension or its associated assets. Individual deletion may not be available for saved private extensions. |
| Published or public extension assets | Retained while the extension remains published, active, archived, visible in your account, previously used by a user, or otherwise available through the Service. Individual deletion may not be available for saved published or public extensions. |
| Archived extension assets | Retained where needed to support account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement of our Terms, and backup-retention purposes. |
| Creator-program, withdrawal, payout-status, transaction, fraud-prevention, accounting, audit, and compliance records | Retained for the period required or permitted for creator-program administration, withdrawal processing, payout tracking, accounting, audit, fraud-prevention, legal, and compliance obligations, even after you delete your account, archive an extension, unpublish an extension, or stop participating in creator features. |
| Support, complaint, moderation, security, and abuse-prevention records | Retained for the period reasonably necessary to respond to requests, investigate reports, moderate content, resolve disputes, enforce our Terms, comply with law, protect rights and safety, and maintain appropriate business records. |
| Backups | Deleted information may remain in encrypted backups for a limited period until those backups are overwritten or deleted according to our backup retention schedule. Backup copies are not used for active processing except where restoration is necessary for security, disaster recovery, legal compliance, or service continuity. |
When the purpose of collection or use has been fulfilled, the applicable retention period has expired, or deletion is required by applicable law, we will delete, de-identify, anonymize, or otherwise securely dispose of personal information unless retention is required or permitted for legal, tax, accounting, audit, security, fraud-prevention, dispute-resolution, enforcement, creator-program, payout, backup, or other legitimate purposes.
Electronic records are deleted using technical methods designed to make the records unrecoverable or not reasonably capable of being restored in ordinary course. Physical records, if any, are destroyed by shredding, incineration, or another secure destruction method.
5. Outsourcing of Personal Information Processing
We may outsource certain personal information processing activities to service providers that process personal information on our behalf. These service providers are permitted to process personal information only as necessary to provide services to us, subject to contractual, platform, technical, organizational, or legal safeguards.
| Type of Outsourced Provider | Outsourced Processing Activities |
|---|---|
| Cloud hosting and storage providers | Hosting, storage, database operation, content storage, backup, service infrastructure, reliability, and security |
| AI image-generation or image-processing providers | Processing uploaded images, including Face Data where necessary, to generate requested outputs, perform safety or abuse-prevention checks, maintain service reliability, and support requested image-processing features |
| Analytics providers | Usage analytics, performance analytics, crash analytics, diagnostic data processing, product analytics, and service-quality measurement |
| Payment platforms and app stores | Subscription processing, top-up purchase processing, purchase verification, refunds, chargebacks, billing support, and transaction records |
| Payout providers | Processing creator withdrawals or payouts where available, payout status updates, transaction references, payout-provider identifiers, and related payout records |
| Customer support providers | Support ticket handling, user inquiries, complaint management, user communications, and issue resolution |
| Security, fraud-prevention, and moderation providers | Fraud detection, abuse prevention, spam prevention, content safety review, prohibited content detection, security monitoring, incident response, and enforcement support |
| Communications and infrastructure providers | Email delivery, service notices, operational communications, infrastructure monitoring, and related technical services |
We select and manage service providers using appropriate safeguards designed to protect personal information. We may update the list or types of outsourced providers as the Service evolves.
6. Provision of Personal Information to Third Parties
We do not sell personal information. We do not sell, rent, or trade Face Data.
We may provide or disclose personal information to third parties only where necessary for the purposes described in the Fraw Privacy Policy and this Addendum, including where:
- you direct us to do so;
- it is necessary to provide, operate, secure, support, or legally administer the Service;
- it is necessary to process payments, subscriptions, purchases, refunds, chargebacks, payouts, or related records;
- it is necessary to operate public-facing creator features or published extensions;
- it is necessary to detect or prevent fraud, abuse, security incidents, prohibited content, policy violations, or misuse of the Service;
- it is necessary to comply with applicable law, legal process, valid governmental requests, court orders, or regulatory obligations;
- it is necessary to enforce our Terms or protect the rights, safety, or property of Fraw, our users, or others;
- it is part of a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable confidentiality and legal protections.
If you publish an extension or otherwise use public-facing creator features, certain information may be visible to other users, such as your display name or creator name, extension title, extension description, related public metadata, and content you choose to make public through the Service.
7. Overseas Processing and International Transfers
We operate the Service using cloud infrastructure, service providers, and technical systems that may be located in countries or regions other than Korea. As a result, personal information of users located in Korea may be processed, stored, accessed, or transferred outside Korea.
This may include account information, device and usage information, transaction records, support information, creator-program, withdrawal, or payout-status information where applicable, user content, uploaded images, generated content, extension assets, and Face Data where such information is processed as part of the Service.
We transfer personal information outside Korea only where reasonably necessary to provide, operate, secure, support, analyze, improve, or legally administer the Service, or where otherwise permitted by applicable law.
The following table describes the general overseas processing and transfer practices for the Service.
| Recipient or Type of Recipient | Countries or Regions | Categories of Information | Purpose of Transfer | Transfer Method | Retention Period |
|---|---|---|---|---|---|
| Cloud hosting and storage providers | Countries or regions where the provider operates infrastructure, which may include the United States and other regions | Account information, user content, generated content, extension assets, Face Data where stored as part of the Service, logs, technical data, and backups | Hosting, storage, service operation, reliability, security, backup, and infrastructure support | Encrypted transmission over network connections, provider APIs, cloud infrastructure, and secure administrative access controls | For as long as necessary to provide the Service, or as otherwise described in the Fraw Privacy Policy and this Addendum |
| AI image-generation or image-processing providers | Countries or regions where the provider operates or processes requests, which may include the United States and other regions | Uploaded images, Face Data where the uploaded image contains a human face, prompts, processing metadata, generated outputs, and related safety or abuse-prevention data | Generating requested outputs, safety checks, abuse prevention, service reliability, debugging, and support of requested image-processing features | Encrypted API transmission or secure service integration | During processing and for any limited technical, safety, security, abuse-prevention, service-reliability, debugging, or legal retention period permitted by the provider terms and service configuration |
| Analytics, crash, and diagnostic providers | Countries or regions where the provider operates infrastructure, which may include the United States and other regions | Device information, app information, usage events, crash logs, diagnostic data, performance data, and technical identifiers | Analytics, reliability, crash reporting, debugging, product improvement, security, and service-quality measurement | SDK, API, or encrypted network transmission | For as long as necessary for analytics, security, debugging, and service improvement, or as configured in provider settings |
| App stores and payment platforms | Countries or regions where the platform operates | Transaction, subscription, purchase, refund, chargeback, and billing-related records | Purchase processing, subscription management, payment verification, refunds, billing support, and compliance | Platform APIs, app store systems, payment platform systems, and encrypted network transmission | As determined by the applicable platform terms, legal obligations, and transaction-record requirements |
| Payout providers | Countries or regions where the provider operates | Creator account identifiers, withdrawal requests, payout status, payout amount, transaction reference, payout provider identifier, and related payout records. Payout account information, identity information, tax information, or compliance information may be collected directly by the payout provider under its own terms. | Processing creator withdrawals or payouts, payout tracking, fraud prevention, accounting, audit, dispute resolution, and compliance | Provider account flow, provider APIs, and encrypted network transmission | As determined by the payout provider’s terms, privacy policy, and legal obligations, and as necessary for Fraw’s creator-program records |
| Customer support and communications providers | Countries or regions where the provider operates | Contact information, support requests, complaints, communications, device information, account identifiers, and related support records | Customer support, user communications, issue resolution, service notices, and operational communications | Support tools, email systems, APIs, and encrypted network transmission | For as long as necessary to provide support, resolve issues, maintain business records, and comply with legal obligations |
| Security, fraud-prevention, and moderation providers | Countries or regions where the provider operates | Account identifiers, device and usage signals, uploaded or generated content where necessary, moderation records, fraud signals, security logs, and related records | Fraud prevention, abuse prevention, content safety, prohibited content detection, security monitoring, incident response, and enforcement support | SDK, API, secure service integration, or encrypted network transmission | For as long as necessary for security, fraud prevention, moderation, enforcement, legal compliance, and dispute resolution |
Where required by applicable law, we take appropriate steps to protect personal information transferred outside Korea. These steps may include contractual safeguards, data-processing agreements, provider due diligence, access controls, encryption in transit, encryption at rest where supported by the applicable storage system, technical and organizational security measures, and other recognized transfer mechanisms.
Some overseas transfers may be necessary to provide the Service. If you do not want your personal information to be transferred outside Korea, you may choose not to use the Service, or you may contact us to exercise your rights where available under applicable law. However, refusing or objecting to certain overseas transfers may limit or prevent your ability to use some or all of the Service.
8. Rights of Users Located in Korea
Subject to applicable law, users located in Korea may have rights regarding their personal information, including the right to:
- request access to personal information;
- request correction of inaccurate or incomplete personal information;
- request deletion of certain personal information;
- request suspension of processing of certain personal information;
- withdraw consent where processing is based on consent;
- request information about the processing, outsourcing, or overseas transfer of personal information where required by law;
- raise complaints or inquiries regarding the handling of personal information.
You may manage certain information directly through your account settings or available in-app controls. Account deletion is available in the app. You may delete individual saved images, generated content, and gallery items through available in-app controls. For saved extensions in your extension library or similar account area, individual deletion may not be available; saved extensions may instead be archived through available in-app controls. Draft, temporary, or unsaved extensions may be deleted individually where deletion controls are provided.
When you delete your account, we will schedule deletion or de-identification of personal information associated with your account from active systems within a reasonable period, subject to the exceptions described in the Fraw Privacy Policy and this Addendum.
To exercise your rights, contact us using the details in the Privacy Contact section below or use available in-app privacy or account controls. We may need to verify your identity before fulfilling a request.
We may decline, limit, or delay a request where permitted by applicable law, including where we cannot verify your identity, where fulfilling the request would conflict with legal obligations, security requirements, fraud-prevention needs, creator-program administration, dispute-resolution needs, payment or payout processing requirements, or the rights and freedoms of others.
9. Children’s Personal Information
The Service is not intended for children below the age permitted under applicable law to use the Service without parental consent.
We do not knowingly collect personal information from children in violation of applicable law. Where required by Korean law, if we knowingly collect personal information from a child under the applicable age threshold, we will obtain consent from the child’s legal representative before collecting, using, disclosing, or otherwise processing the child’s personal information.
If you believe a child has provided us with personal information unlawfully, please contact us so we can investigate and take appropriate action.
10. Security Measures
We use reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include:
- encryption in transit using TLS;
- encryption at rest where supported by the applicable storage system;
- access controls and permission management;
- internal access limitations based on need to know;
- logging and monitoring of systems where appropriate;
- technical safeguards designed to protect against unauthorized access, alteration, loss, or disclosure;
- review and management of service providers;
- procedures for responding to security incidents;
- employee or contractor confidentiality obligations where applicable.
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Data Breach Notification
If we become aware of a personal information breach affecting users located in Korea, we will take steps to investigate, mitigate, and respond to the incident in accordance with applicable law.
Where required by Korean law, we will notify affected users and report to the competent authority within the legally required timeframe. The notice may include information such as the nature of the breach, the categories of information affected, timing of the breach, measures taken by Fraw, steps users may take to reduce harm, and contact information for inquiries.
12. Privacy Contact
If you have questions, concerns, complaints, or requests regarding this Korea Privacy Addendum or our handling of personal information, you may contact us using the details below:
- Untitled Labs Limited
- Address: 20/F, Harbourside HQ, 8 Lam Chak Street, Kowloon Bay, Kowloon
- Support Email: hi@fraw.ai
- Company Registration: 71095371
We will review and respond to privacy-related requests in accordance with applicable law and our internal procedures. Depending on the nature of your request, we may need to verify your identity before responding or taking action.
Where required by applicable Korean law, we will provide additional contact information, privacy manager details, representative details, or other required information through this Korea Privacy Addendum, within the Service, on our website, or by other reasonable means.
You may also contact the Korean Personal Information Protection Commission or other competent authorities if you believe your personal information rights have been violated.
13. Changes to This Korea Privacy Addendum
We may update this Korea Privacy Addendum from time to time.
If we make material changes, we may provide notice through the Service, by email, on our website, or by other reasonable means, as required by applicable law.
Your continued use of the Service after the updated Korea Privacy Addendum becomes effective means you acknowledge the revised Addendum.