Privacy Policy — Annyeong

Last updated: 2 September 2026

Annyeong is operated by Marverik LLC (“Annyeong”, “we”, “us”). We are the data controller for the personal data described in this policy.

This policy covers:

Where something applies only to a particular part of Annyeong, we say so.

For questions about this policy or your personal data, contact [email protected].

Annyeong is an independent, fan-made project. It is not affiliated with, endorsed by, or connected to HYBE Corporation, BIGHIT MUSIC, or BTS.


1. The short version

2. What we collect

Account and sign-in information

Email address. We use your email to create and access your account, send sign-in links and send important service communications.

Sign-in links are single-use. Standard sign-in links expire after 15 minutes and account-activation links expire after 72 hours. We do not store the sign-in secret itself in a form that can be used to recover it.

Date of birth and age. Annyeong is available only to people aged 18 or older. When you create an account, we collect your date of birth and ask you to confirm that you are 18 years of age or older. We use your date of birth to determine whether you meet Annyeong’s minimum age requirement and to calculate your age. Your exact date of birth is kept private: it is never displayed to other members and never sent to their devices. Your age in whole years, calculated from your date of birth, is shown on your full profile and can be used by other members to filter Discover by age range. There is currently no setting to hide your age from other members.

If the 18+ check fails during registration, the date is not stored as part of an account.

Age confirmation at registration is self-declared. In some cases, we may require additional age verification, described next.

Additional age verification

Why we may ask. Where we have a specific, reasonable reason to verify whether an account meets our 18+ age requirement, we may require additional age verification. This may arise from information available to us, including profile information, a profile photo, a verification selfie, information provided by the member, or reports concerning the account. Additional age verification is not part of ordinary registration and is initiated following human review.

What we collect. We may ask you to upload image(s) of a government-issued photo identification document, such as a passport or identity card. We need to be able to clearly see your photograph and date of birth. Depending on the type of document, we may ask for more than one side or page where this is necessary to complete the review. You may cover information that is not required for age verification, such as your address or document number, provided that the information required for the verification remains clearly visible and readable.

How we use the document. We use the document only to determine whether you meet Annyeong’s 18+ age requirement, whether the submitted document can reasonably be relied upon for age verification, and whether it appears to belong to you. A human reviewer considers the document, the photograph, the date of birth, and any material inconsistencies that would prevent us from reasonably relying on the document for age verification. Annyeong does not perform forensic or governmental authentication of identity documents and does not use submitted documents as a general identity-verification service. Documents submitted for age verification are never displayed publicly or to other members and are not used for advertising, unrelated profiling, or other unrelated purposes.

Document consistency checks. Where a document contains a machine-readable zone (MRZ), a reviewer may manually enter the MRZ into our verification system to perform an internal consistency check. The check may include validating standard MRZ check digits and checking whether the date of birth contained in the MRZ is internally consistent with the information being reviewed. This check is optional and advisory only. A successful MRZ consistency check does not establish that a document is genuine, and an MRZ result never determines the outcome of age verification by itself. The MRZ text and information temporarily parsed from it are not retained after the check. We retain only the advisory result of the consistency check and when the check was performed.

Human review. Age-verification decisions are made by a person. Automated or mathematical consistency checks may assist the reviewer, but no account is approved or suspended solely on the basis of an automated age-verification decision.

Storage and deletion. Document images are stored temporarily in private storage while they are required for the age-verification review. After the relevant review is completed, the uploaded document images are deleted from active storage. This applies whether the verification is approved; the verification establishes that the account does not meet the 18+ requirement; the document does not appear to belong to the account holder; the document cannot reasonably be relied upon for age verification; or a new document needs to be submitted. If deletion cannot be completed immediately because of a technical failure, the system retries the deletion until it is confirmed. We record when deletion of an uploaded document has been confirmed.

What we retain after review. After the document images are deleted, we may retain limited information necessary to record, administer, audit, and secure the age-verification process. This may include: the verification status and outcome; when verification was requested; the verification deadline; when documents were submitted; when the review was completed; the verification attempt number; the type and role of the document submitted; reviewer and administrative audit information; the review outcome or reason; whether an MRZ consistency check was performed; the advisory MRZ consistency result and the time it was performed; confirmation that document deletion was completed; and limited technical metadata about the submitted file, such as its content type, dimensions, size, and cryptographic checksum, where retained by the system for audit, integrity, or security purposes. We do not retain the uploaded document image, raw MRZ text, document number, address, or an OCR transcription of the document after the review.

Where age verification is approved, the verified date of birth may become the date of birth associated with your Annyeong account, including where it corrects a date of birth you previously provided. Where verification establishes that a person is under 18, we record the outcome of the verification but do not retain the underage date of birth from the document as an additional verification record.

During and after verification. While additional age verification is pending, some account functions or profile visibility may be restricted. If age verification is not completed within the stated deadline, the account may be suspended. An account may also be suspended if the verification establishes that the person is under 18; cannot reasonably confirm that the submitted document can be relied upon for age verification; or indicates that the submitted document does not belong to the account holder. If you believe an age-verification or suspension decision was made in error, contact [email protected] to request a review. A person reviews the case before any decision is changed.

Section 8 describes how long age-verification records are kept.

Google Sign-In. If you choose Google Sign-In, we receive information needed to authenticate you, including your Google account identifier and email address. We do not receive your Google password.

Sign in with Apple. If you choose Sign in with Apple, we receive your Apple account identifier and either your email address or an Apple private relay address, depending on your Apple settings. We also store an encrypted token used to revoke the Apple authorization when required, including when your account is deleted.

Username and first name. Your username is required and is visible to other members. A first name is optional and is shown only according to your visibility settings.

Session information. We keep information such as when a session was created and last used, the platform used and a device label. App sessions expire after 30 days and web sessions after 24 hours unless ended sooner.

Annyeong does not use passwords and does not currently support passkeys.

Profile information

Depending on the feature, profile information may include:

A profile photo is required before you can appear in Discover. Profile photos are reviewed by our team before being shown to other members. Submitting a profile photo also requires a verification selfie, described next.

When you submit a profile photo for review, we ask you to take a one-time verification selfie using your device camera (it cannot be picked from your photo library). The selfie has exactly one purpose: our review team compares it against the profile photo to confirm the photo shows you. The comparison is done by a human — we do not use facial recognition, automated face matching, or any other biometric processing, and we never create biometric templates from it. The selfie is never shown to other members, never appears on your profile, and is never displayed back to you in the app.

Where supported by the client, uploaded images are resized and metadata such as embedded location information is removed before or during processing.

Gender is optional and private by default. Separate settings control whether it appears on your profile and whether it may be used in discovery filtering. We do not infer your gender from your name, photos or behaviour.

Languages. You choose between one and five languages you speak. At least one language is required to complete your profile. Your languages are shown on your full profile and can be used by other members to filter Discover. They are used only as a filter that a member chooses; we do not use them for ranking or automated matching. There is no setting to hide them; you can change them at any time, but at least one must remain.

If you take the Annyeong quiz to earn the Annyeong Badge, we store information required to operate it, including attempts, question results and badge status.

Location information

During onboarding, you can either provide device location or choose a city manually.

Annyeong does not collect location in the background.

If you provide device location, the reading is used to determine your general home area. The raw location reading is not retained as your stored home point. Instead, Annyeong stores a deliberately offset point roughly 3–4 km away from the source area and uses that point when calculating distance ranges.

Other members may see:

Other members do not receive your stored coordinates or an exact distance.

The World Map uses aggregated place information rather than exposing individual member coordinates. Small groups of members may be aggregated into a larger area or omitted from a separate map count.

Home-location changes are limited under Annyeong’s location rules. We keep records relating to location changes and requests to review an exception.

Travel Mode is an Annyeong Plus feature that lets you temporarily set a destination. Other members may see that you are visiting a city, but not the dates or duration of your trip. Travel-session information includes the destination and relevant dates.

Messages and social interactions

Annyeong stores the social interactions required to provide the service, including:

Messages. In a 1:1 conversation, a message can contain text or one image. Private group chats are text-only. Messages cannot be edited after sending.

Images selected for chat are processed to reduce metadata exposure, including embedded location metadata.

Read state. We store information about when you last read a conversation so Annyeong can show your own unread state. We do not provide read receipts to the other participant.

Message reactions.

Hellos (안녕). A Hello is a social action and does not contain free-text content.

Connections.

Shared events.

Blocks. Blocks are not disclosed to the blocked person.

Reports. A report may include a category and optional free-text detail. Report information is available only through Annyeong’s moderation and safety processes and is not shown to the reported member.

Events. We store attendance and the visibility settings you choose. When you mark yourself as going to an event, your attendance is visible by default: you appear in the event’s attendee list and your attendance is shown to everyone. You can turn either setting off at any time in the event’s settings. If you withdraw from an event, both settings reset to private.

Moderation and account enforcement

When we investigate reports, review accounts, or enforce our Terms, Community Guidelines, or safety rules, we may process information including account and profile information, relevant content, reports submitted by members, moderation reasons, moderator decisions and notes, enforcement actions, timestamps, and related audit information.

We use this information to enforce our rules, protect members, investigate misuse, prevent repeated violations, handle appeals, and maintain the safety and integrity of Annyeong.

Internal moderator notes, internal risk assessments, and security information are used for operating and protecting the service and are not routinely included in enforcement notices sent to members.

When we restrict, suspend, or terminate an account, we provide a notice explaining the applicable reason for the action and how to request a review, except where applicable law does not require or permit such notice.

Moderation and enforcement records are retained only for as long as reasonably necessary for enforcement, safety, security, appeals, dispute resolution, prevention of repeated abuse, and applicable legal obligations. Section 8 has the details.

Spotify information

Where available, you may choose to connect Spotify or provide Spotify listening-history data.

We may store:

Uploaded history files are processed and deleted within 24 hours. We do not retain the raw play-by-play export after that processing period.

Your listening card is hidden by default unless you choose to show it.

Disconnecting Spotify removes your active Spotify connection, tokens, imported data and aggregates handled by Annyeong.

Spotify separately processes your Spotify account under Spotify’s own terms and privacy policy.

Notifications

We store:

Notification content is kept intentionally limited. Message notifications do not contain the message body.

Annyeong Plus subscriptions

If you subscribe through Google Play or the Apple App Store, the store processes the payment.

Annyeong does not receive your card number, bank-account details or complete payment credentials.

We receive information required to provide and manage the subscription, such as:

These identifiers are also used to prevent a single store purchase from being incorrectly associated with multiple Annyeong accounts and to support subscription administration.

Google Play and the Apple App Store separately process purchase information under their own privacy policies.

Marketing website and waitlist

The marketing website at annyeong.io and its waitlist are separate from the Annyeong application system.

If you join the waitlist, we may collect the information you provide, such as:

Waitlist information is used for Annyeong launch and marketing communications. Joining the waitlist is not required to use an existing Annyeong account.

Marketing emails may use open and click measurement provided by our email delivery service. We use this information to understand engagement with Annyeong communications.

We do not sell this engagement information or use it for third-party advertising.

The marketing website may use consent-based analytics and campaign measurement, including Google Analytics and X campaign measurement. Non-essential analytics and measurement technologies are intended to load only after the required consent has been given.

Marketing consent is separate from accepting Annyeong’s Terms and is not required to use the service. You can withdraw marketing consent through available settings or the unsubscribe link in marketing emails.

Technical and security information

We maintain server, security and audit information needed to operate and protect the service.

Security and audit records may include:

Our logging controls are designed not to include private-message content or private location coordinates in ordinary security audit records.

In-app announcements. When we show you an in-app announcement, we record that you acknowledged or dismissed it, so that it is not shown to you again.

Some app preferences, such as interface preferences, may remain only on your device.

App installation and device-association information

When you use Annyeong, we generate a random identifier for that installation of the Annyeong app. We may associate this installation identifier with the Annyeong accounts that are used on the same app installation.

We collect and store the installation identifier, the associated account identifier, the first and most recent time the installation was observed, and the relevant app build information.

We use this information to protect the safety, security, and integrity of Annyeong, including to identify account relationships that may be relevant to trust and safety investigations, detect and investigate abuse, spam, fraud, ban evasion, or other misuse of the service, and help enforce our Terms and Community Guidelines.

The installation identifier is generated by Annyeong. We do not use this feature to collect hardware identifiers such as an IMEI, MAC address, or device serial number, and we do not use advertising identifiers for this purpose. The identifier is not used for advertising or cross-app tracking.

For users in the EEA and UK, we process this information on the basis of our legitimate interests in protecting our users and preventing abuse, fraud, and misuse of the service.

We retain app installation association information while the associated Annyeong account remains in existence. This information is deleted as part of our account deletion process.

We may process this information using service providers acting on our behalf that provide infrastructure, hosting, security, or related technical services. We do not sell this information or share it with third parties for advertising purposes.

3. What we deliberately do not do

We do not:

Age verification using a government-issued ID is described in section 2. It is limited to confirming that you are 18 or older; we do not offer or perform general identity verification.

The marketing website is different from the app and may use consent-based analytics and campaign measurement as described in sections 2 and 13.

4. Why we use your data

Where the GDPR or similar law applies, we rely on the legal basis appropriate to the processing.

PurposeInformationMain legal basis
Creating and operating your accountemail, sign-in information, sessionsPerformance of our contract with you
Enforcing the 18+ eligibility ruledate of birth / age-gate resultLegitimate interests in operating an adults-only community and enforcing service eligibility
Additional, risk-based age verificationgovernment-issued ID images during the review; age-verification recordsLegitimate interests in enforcing the 18+ age requirement, protecting minors, preventing misuse and maintaining the safety and integrity of the service; where applicable law imposes an age-assurance obligation, compliance with that legal obligation
Providing profiles, Discover, Hellos, connections, chat and eventsprofile (including your age and languages), location area, content and social informationPerformance of our contract with you
Providing Travel Mode and other paid Annyeong Plus functionalityfeature and account informationPerformance of our contract with you
Google or Apple authenticationprovider identifiers and related account informationPerformance of our contract with you
Optional gender visibility/filtering and Spotify featuresinformation you choose to provideConsent where applicable
Push notificationspush token and preferencesConsent through device permissions and performance of the service
Safety, moderation, account enforcement, abuse prevention and evidence preservationreports, moderation information, enforcement actions and notices, relevant content and security recordsLegitimate interests in protecting members, investigating abuse and maintaining the safety and integrity of the service
Preserving information required for valid legal process or legal obligationsrelevant recordsLegal obligation where applicable and legitimate interests in establishing, exercising or defending legal claims
Annyeong Plus billing administration and purchase-integrity controlssubscription and store identifiersPerformance of our contract and legitimate interests in preventing fraud or misuse
Marketing emails and marketing-site analyticscontact, consent and measurement informationConsent
Recording legal and consent choicesacceptance and consent recordsCompliance obligations and legitimate interests in demonstrating and honouring those choices

Where processing is based on consent, you may withdraw that consent without affecting processing that took place before withdrawal.

5. What other members can see

Depending on your settings and use of Annyeong, other members may see information such as:

Information such as your first name, gender, Spotify listening card and event attendance depends on the visibility controls available for those features. Event attendance is visible by default and can be turned off, as described in section 2.

Other members do not receive your:

Blocking is not disclosed to the blocked person.

6. Who we share data with

We use service providers where necessary to operate Annyeong. Depending on the feature, these may include providers for:

Our primary production infrastructure, including servers, database and stored application media, is hosted in Frankfurt, Germany.

The Expo push service processes the push token and notification information required to deliver notifications.

Our email delivery provider processes email addresses and the content needed to deliver service and marketing emails. For marketing communications it may also process open and click events.

Google Analytics processes analytics information on the marketing website when enabled after the required consent.

Some third parties process information as independent controllers for their own services, including:

We do not sell your personal data.

We may disclose relevant information where required by valid legal process, where required by applicable law, or where necessary to protect the rights or safety of Annyeong members or others.

7. International transfers

Marverik LLC is established in the United States, while Annyeong’s primary production infrastructure is located in the European Union.

Some providers involved in operating Annyeong may process personal data in other countries.

Where international transfers of personal data are subject to specific legal requirements, we use the applicable safeguards or transfer mechanisms required by data-protection law.

You can contact [email protected] for more information about international transfers relevant to your data.

8. How long we keep data

We keep personal data for as long as needed to provide Annyeong and for the specific purposes described below.

While your account is active

Your account, profile and content are generally kept while your account remains active.

Messages remain available as part of the relevant conversation while the account and conversation exist.

Standard sign-in links expire after 15 minutes and account-activation links expire after 72 hours.

App sessions expire after 30 days and web sessions after 24 hours, although associated security or sign-in records may remain as described below.

Spotify listening export files are deleted within 24 hours after processing.

Waitlist data is kept for Annyeong launch communications until those communications end, you withdraw or unsubscribe where applicable, or you ask us to delete it, subject to records we may need to keep to honour that choice.

When account deletion becomes final

After the 7-day grace period ends, the account deletion becomes final.

The deletion process removes or clears data including:

The email address on the active account record is replaced so it can no longer be used as the account’s login address.

The deleted account cannot be restored after deletion becomes final.

Verification selfies

Selfie uploads you start but never submit are deleted within 24 hours. Submitted selfies are kept privately for as long as your account exists, whatever the review outcome and including selfies replaced by a newer one when you change your profile photo. The image files are erased when your account deletion becomes final. A limited record that a review took place (its date, outcome and reviewer actions, without the image) remains as part of our moderation records. We may introduce a shorter retention period for reviewed selfies; if we do, we will update this policy first.

Messages and images after deletion — 180 days

When deletion becomes final, the deleted member’s message content disappears from normal Annyeong conversations and is no longer available through the product.

A restricted copy of messages and sent chat images is retained for up to 180 days after final deletion.

This limited retention exists for safety and evidence-preservation purposes, including allowing serious abuse to be reported after a member has deleted their account and allowing Annyeong to preserve information relevant to a serious safety investigation or valid legal process.

The restricted copy is not available through the normal app or ordinary administrative interfaces.

Unless relevant content has been preserved as part of a specific moderation or legal matter, the restricted copy is deleted after 180 days.

Email safety digest — 180 days

After final deletion, Annyeong keeps a keyed, non-reversible value derived from the deleted account’s email address for up to 180 days.

Its purpose is to allow a serious late safety report to be associated with the correct deleted account without retaining the active account email for that purpose.

The digest is deleted after the retention period.

Age-verification records

Government-issued ID images submitted for additional age verification are deleted from active storage after the review is completed, as described in section 2, regardless of whether your account continues to exist.

The limited age-verification records listed in section 2 (status, outcome, timestamps, attempt number, document type, audit information, the advisory MRZ result and file metadata) are kept only for as long as reasonably necessary to administer the verification process, maintain security and audit records, enforce Annyeong’s age requirement, handle appeals or disputes, and meet applicable legal obligations. After account deletion they are handled as safety, security and legal records under the rules below.

Moderation evidence

Where messages, images or other relevant information have been preserved as evidence in a specific moderation case, that evidence may be retained for up to 12 months after the case is closed.

Evidence may be kept longer while:

Access to moderation evidence is restricted and logged.

When the applicable evidence-retention period ends, the underlying content is removed while limited records showing that the moderation process occurred may remain.

Deleting an account is not intended to remove evidence of serious abuse, undermine the safety of other members, or prevent Annyeong from responding to valid legal process.

Accordingly, certain limited records may remain after account deletion where relevant to:

These records may include reports, information provided in reports, block relationships, moderation cases and decisions, enforcement actions and their recorded reasons, age-verification records, security/audit events, and limited account identifiers.

Some of these safety and security records do not currently have a fixed automated deletion period. They are not used to reactivate or reconstruct a deleted account.

Backups

Our infrastructure providers keep encrypted backups of our database for a limited period for disaster recovery. Deleted data may remain in those backups until they are cycled out, and is not used to restore deleted accounts.

Sign-in and account-security records

Certain historical sign-in and session records remain after deletion for security, abuse-investigation and evidence-preservation purposes.

These may include:

These records cannot be used to sign back into the deleted account.

Some of these records do not currently have a fixed automated deletion period.

Location and Travel history

The active home location, home city association and stored offset home-location point are deleted when account deletion becomes final.

Historical records relating to home-location changes, requests to review a home-location change and Travel Mode sessions may remain after deletion.

These records may include:

Annyeong may retain these limited historical records for safety investigations, evidence preservation and responding to valid legal process.

These records do not allow the deleted account to be restored and are not shown to other members.

There is currently no fixed automated deletion period for these historical records.

Username and conversation history

A deleted member’s username is permanently retired so that another person cannot later assume an identity that may still appear in other members’ historical conversations or safety records.

Other members’ conversation history may retain message placeholders and references showing that an interaction occurred with a now-deleted account. Deleted message content itself is handled under the retention rules above.

Some connection or conversation records may therefore remain because they also form part of another member’s account history.

Subscription and purchase records

Subscription records and store purchase identifiers may remain after account deletion for purposes such as:

We do not retain your payment-card or bank-account details because Annyeong never receives them from the stores.

We retain records showing:

These records are kept to document and honour legal and consent choices.

9. Deleting your account

You can request deletion:

Account deletion requires a fresh confirmation sent to your email address.

Once deletion is confirmed:

During the grace period, the account has not yet been permanently erased. You may request recovery and explicitly restore it.

Simply attempting to sign in does not automatically restore a deletion-pending account.

After 7 days, deletion becomes final and cannot be reversed. The erasure and retention rules described in section 8 then apply.

A suspended account can also be deleted. Deleting an account does not erase or invalidate safety or moderation records that Annyeong is entitled or required to retain.

10. Your rights

Depending on where you live, you may have rights concerning your personal data, including rights to:

Many settings can be managed directly in Annyeong, including profile information, visibility settings, Spotify connection and account deletion.

For other requests, contact [email protected].

We may need to verify that a request relates to the correct account before acting on it.

Withdrawal of consent does not affect processing that lawfully occurred before withdrawal.

Some information may not be deleted immediately, or may need to be retained, where there is a valid safety, legal, fraud-prevention, accounting, evidentiary or compliance reason. Section 8 describes the main categories.

11. Security

We use technical and organizational safeguards designed to protect personal data.

These include:

Restricted copies of deleted-message content are not exposed through the normal Annyeong product or ordinary administrative interfaces and are used only through controlled safety processes.

No online service can guarantee absolute security. If a personal-data breach requires notification under applicable law, we will notify the affected people and relevant authorities as required.

12. Children

Annyeong is an 18+ service.

You must be at least 18 years old to create an account.

We do not knowingly allow people under 18 to maintain an Annyeong account. Where we have a specific, reasonable reason to believe that an account may belong to someone under 18, we may require additional age verification as described in section 2. If verification is not completed, or if we determine that an account belongs to someone under 18, the account may be suspended or removed.

If you believe that a person under 18 is using Annyeong, contact [email protected].

13. Cookies, analytics and marketing measurement

Mobile app

The Annyeong mobile app does not use browser cookies and does not contain advertising or third-party analytics/tracking SDKs.

Web app

app.annyeong.io uses technologies required to operate the signed-in service, including security/session functionality.

The web app does not use advertising analytics for user profiling.

Marketing website

annyeong.io is the separate public marketing website.

It may use:

Non-essential analytics and campaign-measurement technologies are loaded only where the required consent has been given.

You can decline non-essential analytics without losing access to the marketing website.

Marketing emails

Marketing emails may contain:

We use this engagement information to understand which Annyeong communications are useful and to improve future communications.

We do not sell this information or use it for third-party advertising.

Every marketing email provides a way to unsubscribe.

14. Changes to this policy

We may update this Privacy Policy as Annyeong changes.

If a change materially affects how we use personal data, we will provide appropriate notice before the change takes effect where required.

The Last updated date at the top shows when this policy was most recently revised.

15. Contact

Marverik LLC

Email: [email protected]

Website: https://annyeong.io

You can contact us at the email above for:

Annyeong is an independent fan-made project and is not affiliated with HYBE Corporation, BIGHIT MUSIC or BTS.

A fan-made project — not affiliated with HYBE or BTS · 💜