Location Privacy Policy
Operator: Foo AI Corp. · Effective: 2026-09-20 · Document version: loc-2026-09-20 · Contact: support@fadetalk.app
Current status: not yet in service. We do not operate the location-based service (Near) yet. The feature is disabled on the server, so neither the apps nor the web ask for location permission, and no coordinate or area identifier is transmitted, stored or recorded.
This document is published ahead of launch on purpose. Each clause below applies from the day we complete the location-based service filing and enable the feature, and the status line on this page is updated at the same time.
1. Scope
This Policy covers the personal location data Foo AI Corp. processes in order to provide FadeTalk’s location-based service (“Near”). The terms of that service are in the Location-Based Service Terms; all other personal data is covered by the Privacy Policy. We process no location data for users who have not consented to Near.
Chat, accounts and every other feature read no device location. The coarse country/region our hosting and web-analytics providers derive from an IP address is connection metadata (Privacy Policy §1), not the personal location data this Policy governs.
2. Purpose and Retention
art. 21-2; Enforcement Decree art. 25-2(i)
There is one purpose: showing people nearby and connecting chat requests. We use it for nothing else — no advertising, no marketing, no profiling. What is stored, and for how long:
| Item | Detail | Retention |
|---|---|---|
| Cell identifier | The pair of integers your device produces by snapping your coordinates to a fixed grid cell of at least about 3 km², plus the latitude band, grid version, audience and expiry. One row per user, overwritten. No coordinates, accuracy, altitude, speed or bearing. | At most 30 minutes. After expiry it is no longer readable, and a job running at least every 6 hours deletes the row. |
| Near settings | Consent timestamp, audience, notification method and frequency, pause and withdrawal timestamps. Settings, not location. | Until you delete your account |
| Statutory activity records | See clause 3. They contain no location. | 6 months |
| Consent and withdrawal records | Which item (collection/use, disclosure, notification method, notification frequency, audience), whether it was granted, the notice text shown on screen, the document version, and when | As long as needed to evidence that consent was obtained. On account deletion the link to the account identifier is removed. |
| Destruction records | The public ID, the number of records destroyed, and when — so that destruction is itself provable | As long as needed to evidence the destruction |
| Staff access log / authority changes | Access by location-handling staff; grants, changes and revocations of that authority | 1 year · at least 5 years |
| Chat requests · mutual hiding | Who was asked and when (no location); mutual invisibility after a report or a declined request | Requests are deleted on expiry or on accept/decline · hiding lasts 30 days |
| Query budget records | Daily counts and a cryptographic value used only to tell whether the cell changed (the original cell cannot be recovered from it). These exist to stop bulk collection and tracking. | 30 days |
While the feature is disabled none of the rows above is created.
3. Statutory Activity Records: Basis and Retention
Decree art. 25-2(ii); Act art. 16(2)
- Basis — art. 16(2) requires automatic recording and retention of the fact that location data was collected, used or disclosed. We keep these records to comply.
- When — in the same database transaction as the act itself. Collection and use are recorded even when there is nobody nearby to show.
- What — the kind of act (collect / use / disclose), who requested it, how it was obtained, the method, the recipient, and a timestamp at 10-minute granularity. The location itself is not recorded — no column could hold it.
- Repeats inside one 10-minute window — a repeated disclosure to the same person within the same window is recorded once, and that window is the granularity of every timestamp you are shown.
- Retention — 6 months; an automatic job deletes older entries.
- Immutability — after writing, modification and deletion are refused by the database. Only marking a notification delivered, and destruction required by law, run through their own procedure; anything else fails.
4. How Location Data Is Destroyed
Decree art. 25-2(iii); Act arts. 23, 24(4)
- When the purpose is met — an expired cell identifier is excluded from every query, so it is neither used nor disclosed again, and a job running at least every 6 hours deletes the row. We do not describe this as instant physical deletion.
- On withdrawal or a deletion request — the stored cell identifier is deleted in the same operation, your entries in the statutory records are destroyed through the controlled procedure, and the count and time of that destruction are recorded. That record exists so that “never collected” and “destroyed on withdrawal” remain distinguishable.
- Conflicting periods — while consent stands, the 6-month retention duty in clause 3 governs. On withdrawal we destroy your entries, except records the law requires us to keep, which are retained for the statutory period and then destroyed.
- Method — rows are deleted from the database so they cannot be restored. Anything left in point-in-time backups is purged within 7 days. We never print location data or export it to a separate file, so there is no paper-destruction procedure.
- On account deletion — your Near settings and cell identifier go with the account. Statutory records remain with the account identifier detached and are destroyed at the end of the clause 3 period, or immediately if you withdraw and ask for destruction.
5. Disclosure to Third Parties
Decree art. 25-2(iv); Act art. 19(2)
We disclose location data only where you have consented to disclosure, and only within the scope below. That consent is a separate item from collection/use consent; declining it means Near is unavailable, and nothing else changes.
| Item | Detail |
|---|---|
| Recipients | Other FadeTalk users using Near at the same time (friends, or everyone nearby, per your audience setting) |
| Data | Distance band (same / adjacent / this area) and the display name, if one is set. The ID code and the profile photo are shown only to mutual friends. For anyone who is not your friend a single-use reference goes with the card instead; it is never displayed and expires with the card. |
| Purpose | Showing people nearby and connecting chat requests |
| When and how | Displayed on screen when a recipient queries Near. No file transfer, no API feed, nothing on a schedule. |
| Never included | Coordinates, maps, distance in metres or kilometres, bearing, movement history, past locations |
| Never disclosed to | Anyone you blocked, anyone hidden for 30 days by a report or declined request, anyone paused or withdrawn |
| Precondition | Only accounts with a verified email address we can deliver to, because that is how each disclosure is notified (clause 6). An address our mail cannot reach cannot carry a notice, so an account holding only Apple’s private relay address — issued when you hide your email while signing in with Apple — cannot use Near, and no disclosure occurs for it. |
| Recorded | Every disclosure is recorded in the statutory records and notified to you (clause 6). |
We do not sell location data and do not disclose it for advertising or marketing. Processors unrelated to Near, including the AI reply-suggestion provider, receive none. Where a law enforcement request is lawful we disclose only what is required, and the fact is written to the statutory records and the access log.
While the feature is disabled no disclosure occurs.
6. Notifying You of Disclosures
Decree art. 25-2(v); Act art. 19(3)–(5), Decree art. 24
- Contents — recipient, date and time (10-minute granularity) and purpose, shown in Provision records in the app, on the device the location came from.
- Method — all three are emailed to your account’s verified email address. Email is the channel, and having one is also what makes you eligible for Near (clause 5). If you read the entry in Provision records before the mail goes out, that reading discharges the notice and no mail is sent.
- App notification — if you chose app notifications, a content-free alert goes out alongside the email. It names neither the other person nor any location, it never replaces or delays the email, and on its own it does not discharge the notice.
- Timing — per disclosure by default, which means one notice every time a disclosure happens. You may batch every 10/20/30 disclosures or every 10/20/30 days (30 days maximum), and switch back at any time.
- If we cannot reach you — with no verified email address we can deliver to, Near does not run, and any cell identifier still held is deleted in the same request. Nothing is stored and nothing is disclosed, so there is nothing to notify.
- Access — the records screen shows only records about you; it cannot be used to enumerate the people you saw.
7. Guardians of Children Aged 8 or Under
Decree art. 25-2(vi); Act arts. 26, 25
- We do not provide the art. 26 service under which a guardian may consent on behalf of a child aged 8 or under or another protected person. There is therefore no guardian consent flow, and no feature that lets anyone look up another person’s location as a guardian.
- FadeTalk does not accept registrations from anyone under 14, and the Near consent step requires the same confirmation. Accounts found to belong to someone under 14 are deleted. As a result we process no location data of children under 14 and operate no legal-guardian consent flow.
- If you believe you are the guardian of an affected user, contact support@fadetalk.app. After verifying as the law requires, we will stop location processing for that account and destroy the data.
8. Location Information Manager
Decree art. 25-2(vii); Decree art. 20(1)(i)
- Name and title: JEEHO SONG, Chief Executive Officer
- Role: Location Information Manager (위치정보관리책임자)
- Contact: support@fadetalk.app · 359 Gangnam-daero, Seocho-gu, Seoul, Republic of Korea
- Designations and changes are recorded with their date, and those records are kept for at least 5 years.
9. For Reference: Your Rights and How to Use Them
Added for convenience, beyond the statutory contents.
- Pause — one action from the list screen or Settings, effective immediately; we never refuse it.
- Withdraw consent — Settings → Near → Withdraw consent, or support@fadetalk.app.
- Access, correction, deletion — Settings → Near → Provision records, or support@fadetalk.app.
- Change audience or notification settings — Settings → Near.
- If we have suspended your account — pausing, withdrawing consent and access are not affected. Signing in again with the same method gives you a credential limited to those three plus a read of your Near settings; it cannot query Near, give consent or change settings. The same requests are accepted by email to support@fadetalk.app.
- Remedies — Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), Privacy Infringement Report Center / KISA (118, privacy.kisa.or.kr), Korea Communications Commission (kcc.go.kr). Users elsewhere may also contact their local data-protection authority.
10. For Reference: Processors and Cross-Border Processing
Added for transparency, beyond the statutory contents.
- Cell identifiers and statutory records are stored and processed in our database (Neon, Singapore) and API servers (Fly.io, Singapore), under contracts restricting use beyond the assigned task and onward sub-processing.
- Notice emails pass through our email provider (Resend, United States). The body carries the recipient (a display name and a partly masked ID code), the time of disclosure (10-minute granularity) and the purpose; it carries no coordinates and no cell identifier.
- App notifications pass through notification providers (Expo · Apple · Google, United States), but their contents include no location, cell identifier or other person’s details.
- Cell-related fields are stripped from error monitoring (Sentry) and usage analytics before sending.
- The AI reply-suggestion provider receives no location data.
11. For Reference: Security Measures
Added beyond the statutory contents.
- No column anywhere can hold coordinates, accuracy or a movement history, so a location history cannot come into existence.
- Statutory records cannot be modified or deleted once written (database trigger).
- Staff access is least-privilege and logged for 1 year.
- Data is encrypted in transit, and query budgets (distinct cells per day, observations per pair) limit bulk collection and tracking.
- A reported position implying a physically impossible movement is rejected.
12. Publication and Changes
This Policy is published at fadetalk.app/location-policy and linked from the Near consent screen in the apps and on the web. If we change it, we publish the change and its effective date the same way, and announce any change unfavourable to users in-Service before it takes effect.
This English text is provided for a global audience; the Korean version is the authoritative text and prevails in case of any conflict.
Business registration 284-81-02702 · CEO JEEHO SONG · 359 Gangnam-daero, Seocho-gu, Seoul, Republic of Korea
Location-Based Service Terms · Privacy Policy · Terms of Service · Support