ChapterN. Back

Privacy Policy · Effective 2026-09-09

Privacy Policy

Zenumaik Co., Ltd. (the "Company") operates the ChapterN app and website and processes personal information under Korea's Personal Information Protection Act. This Policy explains the information processed, its purposes and retention periods, the use of external providers, and how to exercise your rights. Acknowledging this Policy does not constitute consent to all processing. We obtain separate consent where required.

1. Personal Information We Process

We receive information that users enter, or external sign-in and payment services provide, during registration, use, inquiries, and applications. Device, connection, and usage information is generated automatically when the Service is used.

Category Information
Account and age Google or Apple user identifier and email, sign-in provider, internal Member identifier, display name, birth year and month, registration and access times, terms confirmation records, and account status
Service use Reading position, choices, endings and progress, favorites, ratings, reading and notification settings, device identifier, push token, app version and language, and device country setting
Connection and diagnostics IP address, access time, browser and device information, request and error records, and Firebase Crashlytics crash and diagnostic information
Usage analytics App screen and web page views, work discovery, searches, reading and choices, reading time, Chapter openings and completions, endings, favorites, purchased products, amounts, currencies and transaction identifiers, and analytics app or browser identifiers. These may be linked to an internal Member identifier when signed in
Payments and refunds Store transaction and product identifiers, receipt verification information, payment and refund times, prices, currencies and store regions, and Ink and access records. Direct bank-transfer refunds also require a contact email, account holder name, bank, and account details
Reports and inquiries Inquiry text, reported items, positions and categories, reply email, receipt and handling records, and Member identifier when signed in
Marketing communications (optional) Member identifier, push token, app language, and consent, withdrawal, and delivery records. For web launch notifications: email address, selected language, and confirmation of meeting the minimum age
App usage and advertising measurement AppsFlyer installation identifier; installation, launch, registration, reading-start, Chapter-completion, Chapter-opening and purchase occurrences and times; app, device, operating-system and language information; IP address and IP-based approximate location; installation-source information; and device performance and diagnostic information collected by the SDK
Aggregate advertising measurement iOS app, ad-network and placement identifiers, redownload status, installation/registration/purchase conversion stages, an advertising-report transaction value for deduplication and receipt time (Section 10)

Where verification is necessary for account protection, refunds, or infringement reports, we may receive the minimum additional transaction records and information needed to establish identity, age, legal-representative relationships, authority to act, payment authorization, or relevant rights. We explain the purpose and required information; unnecessary personal information may be redacted or replaced with alternative evidence. Supporting information follows the retention period of the relevant inquiry, refund, or dispute record. Information unnecessary for verification is not collected or is promptly deleted.

We do not request payment card numbers, Korean resident registration numbers, or precise location. Birth information that fails age verification is not stored. The app marketplace country or region signal used to select an age requirement is not stored as the Member's country of residence. Full bank account numbers used for direct refunds are deleted after transfer confirmation; necessary transaction evidence is retained.

2. Purposes and Legal Bases

Purpose Basis
Authentication, account and reading-record management, Content delivery, notifications, ratings, inquiries, payments, and refunds Processing necessary to enter into or perform a contract: Article 15(1)(4) of the Personal Information Protection Act
Statutory duties, including retaining transaction records Compliance with legal duties: Article 15(1)(2)
Preventing account abuse and payment fraud, security and error response, fact-finding and legal claims or defense in rights disputes, usage analytics, service improvement, and advertising performance measurement Legitimate interests: Article 15(1)(6)
Receiving advertising communications User consent: Article 15(1)(1)

Processing based on legitimate interests is limited to what is needed for service safety, improvement, specific rights disputes, and limited advertising performance measurement and is performed only where permitted after balancing users' rights. Marketing communications are optional and separate from the app usage and advertising measurement described in Section 10.

3. AI Training and Automated Decisions

The Company does not use users' personal information to train generative AI models or send it to external generative AI while they read. During registration, we automatically compare the submitted birth year and month against the applicable minimum age. Because we do not collect the exact day of birth, in the year a user reaches the minimum age we confirm eligibility only after their birth month has passed. You may request an explanation or review through Section 8. Where statutory rights concerning automated decisions apply, we handle requests accordingly.

4. Third-Party Disclosure and Service Providers

We disclose personal information to third parties only with consent or another legal basis. We entrust the following operations to providers and use contracts and oversight to ensure that personal information is processed securely. Before disclosing information in response to a court or investigative authority, we verify the legal basis and scope and provide only the minimum necessary information. A request alone does not authorize disclosure.

Provider Entrusted work
Google LLC (Firebase and Google Cloud) Authentication, storage, server and website operations, Content delivery, and push notifications
Google LLC (Firebase Analytics, GA4, BigQuery, and Crashlytics) Service usage statistics and error analysis
AppsFlyer Ltd. Measurement and analysis of app installations, usage stages, and advertising performance, fraud prevention, and SKAdNetwork aggregate reporting

Google and Apple sign-in and marketplace payments used directly by users are also subject to those providers' privacy policies. The Company exchanges identifiers and verification information needed to confirm sign-ins and payments with those platforms.

When providing Ink delivery and consumption information for Apple's refund review, we obtain separate consent for that transaction. Declining does not prevent you from requesting a refund. Aggregate advertising measurement is described in Section 10.

5. International Transfers

We distinguish the following legal bases for international transfers and disclose the recipients, information, purposes, countries, timing, methods, and retention periods below.

The legal basis for an international transfer is assessed separately from the collection and use bases in Section 2. Access by affiliates outside the EU/EEA and onward transfers to other countries must also meet the requirements and safeguards applicable to that access or transfer.

Recipient and contact Information and purpose Country, timing, and method Retention
Google LLC · Privacy contact Account and connection information for Firebase authentication United States; encrypted network transmission during sign-in and account use Deletion requested upon account deletion; removal from the provider's live and backup systems may take up to 180 days
Google LLC · same contact Web connection and usage information for website operations Japan; network transmission when visiting the website Access-record periods in Section 6
Google LLC · same contact Device, push, diagnostic, and analytics information for notifications, security, error handling, and analytics United States and countries hosting Google's global processing facilities; network transmission when using the relevant features. See the official facility-country lists below Feature-specific periods in Section 6
Apple Inc. · Privacy contact Authentication and payment verification information, and separately consented refund-review information, for sign-in, payment, and refund handling United States and other countries hosting Apple's processing facilities; network transmission when using the relevant features Until the processing purpose is fulfilled or for applicable statutory retention periods
AppsFlyer Ltd. · privacy@appsflyer.com App usage, advertising measurement, and aggregate advertising information in Section 1, for measurement, analysis, fraud prevention, and aggregate reporting Processing facilities in the European Union; encrypted network transmission on app launch and relevant activity. See below for support and maintenance locations User-level information: up to 24 months. Aggregated information that cannot identify individuals: up to 25 months

Primary Member and Content data is stored in Google Cloud's Seoul region in Korea. Overseas diagnostic and push services use the global infrastructure described in Firebase's processing-location information and the facility-country lists linked there.

Storage and processing of information entrusted by the Company to AppsFlyer within the European Union rely on the equivalence recognition under Article 28-8(1)(5) of Korea's Personal Information Protection Act. Affiliates in Israel, the United States, the United Kingdom, Germany, China, Hong Kong, India, and Japan may participate in support and maintenance. Provider roles and locations are listed in AppsFlyer’s subprocessor information.

You may contact admin@zenumaik.com to refuse international transfers or request suspension of processing. Refusing processing necessary for contract performance, such as authentication, may prevent use of the relevant account features. Refusing optional advertising disclosure does not disadvantage your use of the Service. The Company applies safeguards such as encryption and access restrictions to international transfers.

6. Retention Periods

We promptly delete personal information when its purpose is fulfilled or a Member deletes their account. The following records are retained separately as required by law.

Record Period Basis
Contracts and withdrawals, payments and supply 5 years Korean electronic commerce law
Consumer complaints and disputes 3 years Korean electronic commerce law
Display and advertising records 6 months Korean electronic commerce law
Service connection records 3 months Where retention is required under the Protection of Communications Secrets Act

Other periods are as follows:

Marketing information follows the periods in the Marketing Communications Consent. Statistics that no longer identify individuals may be retained separately.

7. Deletion Methods

Electronic files are deleted using methods that make recovery difficult. Statutory records are kept separately with restricted access and deleted when their retention period ends. Backups are used only for recovery, and previously received deletion requests are reapplied when data is restored.

8. Your Rights and How to Exercise Them

You may request access, correction, deletion, suspension of processing, withdrawal of consent, and account deletion. Requests may also be made by a legal representative or authorized agent. Where provided by law, you may exercise rights concerning data portability or automated decisions.

We may request the minimum information needed to verify that the requester is the individual concerned or a lawful representative. For representatives, we verify the authorization or legal-representative relationship. Unnecessary personal information may be redacted or replaced with alternative evidence. Requests and supporting information are used to handle the relevant rights request.

Access, correction, deletion, suspension, and other requests are handled under the conditions and deadlines prescribed by applicable law. Requests may be limited in whole or part where the law permits, including statutory retention duties or protection of another person's life, physical safety, property, or other rights. Suspension may also be limited as permitted by law where it would prevent contract performance and the user has not clearly expressed an intention to terminate the contract. If a request is limited or refused, we explain the grounds and reasons; you may object through the same contact channel.

We do not impose unjustified disadvantages for refusing optional consent or exercising your rights. However, stopping processing strictly necessary for a feature, such as authentication or payment, may prevent us from providing that feature; we explain the impact where applicable. Withdrawal of marketing consent is handled separately from requests concerning service analytics or advertising measurement.

9. Registration Age

Registration is for users aged 15 or older, or 18 or older through Indonesian app storefronts. We do not offer parental-consent registration below the minimum age. If a user is found to be below the minimum age, their account and personal information are deleted, except for records retained separately for refunds and statutory duties.

10. Automatic Collection and Advertising Measurement

Service Analytics and Temporary Storage

The app uses Firebase Analytics and Crashlytics to process usage statistics and error information. The website uses the following storage:

Stored item Purpose and contents Duration and controls
Language cookie (__session) Remembers the selected language; contains no Member sign-in information Up to one year from language selection. Can be deleted or blocked in browser settings
Web analytics cookies (_ga, etc.) Google Analytics visit and usage analysis Up to 13 months from storage. Can be deleted or blocked in browser settings
Web reader session storage Temporarily stores reading position and choices Removed when the browser tab or session ends or site data is deleted, as explained below

You can browse with cookies blocked, although the selected language may not be remembered. Manage cookies through your browser's site-data and cookie settings. Web cookie controls do not control app SDK processing; requests concerning app measurement can be submitted through Section 8.

The web reader also temporarily stores your position and choices in browser session storage. That stored state itself is not sent to Company servers, although reading-progress, choice, and other analytics events are sent separately as described in Section 1. Closing the browser tab or session, or deleting site data, clears the temporary state.

App Usage and Advertising Measurement

The app uses AppsFlyer to measure installations, launches, and the occurrence of registration, reading starts, Chapter completions, Chapter openings, and purchases. AppsFlyer analyzes this information on the Company’s behalf and uses device, connection, performance, and diagnostic information for service protection and fraud prevention. We do not send Member IDs, emails, phone numbers, work titles, search terms, reading content, purchase amounts, or receipts to AppsFlyer.

We do not collect advertising identifiers (IDFA or Android advertising ID) or use features that send user-level events to advertising providers. However, installation identifiers and device and connection information are processed, so this information is not entirely anonymous. Requests concerning measurement information can be submitted through the contact channel in Section 8.

Aggregate Advertising Measurement

The iOS app uses Apple's SKAdNetwork to measure installations, registrations, and purchases resulting from ChapterN advertising. In the current app, the AppsFlyer SDK sets conversion values on the device based on installation, registration, and purchase stages. Apple's operating system sends results to the ad network and AppsFlyer under its privacy protections. Results may be delayed or omit some fields.

AppsFlyer processes app, ad-network and placement identifiers, redownload status, conversion values, advertising-report transaction values, and receipt times to provide aggregate reports to the Company. Advertising-report transaction values are used for duplicate detection and are distinct from app marketplace purchase transaction identifiers. AppsFlyer's processing locations and retention periods are described in Sections 5 and 6.

Where the Company directly receives aggregate advertising records from older app versions using its own receiving endpoint, the transaction value used for duplicate detection is hashed and the records are stored in Google Cloud's Seoul region in the Republic of Korea. That receiving endpoint processes requests in Japan; aggregate records and access logs follow the periods in Section 6.

Advertising conversion values contain no Member ID, email, phone number, advertising ID (IDFA), purchase amount or purchase transaction identifier, search terms, or reading content. The Company does not link received aggregate advertising records to account- or device-level service usage records. This is distinct from the installation-identifier-based general AppsFlyer measurement described above. Apple's platform processing is subject to the Apple Privacy Policy.

The Company does not use individual conversion-tracking SDKs or web pixels from Meta, TikTok, X, or Google, or advertising features that match email addresses or phone numbers. Placing advertisements on these platforms does not itself disclose ChapterN Member information. Before introducing advertising features that use personal information, we establish the necessary notices and consent for the actual processing involved.

11. Security Measures

We limit access to personal information to people who need it for their duties and apply necessary safeguards, including access controls, encryption, access-log management, and security updates. If a personal information breach occurs, we notify users and competent authorities as required by law.

12. Privacy Officer and Contact

For Korean privacy complaints, contact the Privacy Infringement Report Center at 118. For mediation, contact the Personal Information Dispute Mediation Committee at 1833-6972.

13. Policy Changes

When this Policy changes, we announce the effective date and key changes. Processing that requires new consent begins only after that consent is obtained.

Effective Date

This Policy takes effect on September 9, 2026.