Privacy
Effective: June 1, 2026 | Last revised: June 16, 2026
1. To provide our services, XenLook collects the following personal information:
Required Information: Email address, password (encrypted), nickname, service usage records, access logs, and device information (OS, browser, IP address).
Optional Information: Profile image, date of birth, gender, and areas of interest.
Social Logins: Basic profile information provided by the social platform, such as your name, email, and profile picture.
Automatically Collected Information: Cookies, access frequency, service usage patterns, and AI agent conversation metadata.
2. Collection Methods: Information is collected automatically or provided directly by you during sign-up, service use, customer inquiries, or event participation.
Collected personal information is used exclusively for the following purposes: providing and managing services; user identification and authentication; improving AI agent service quality (after anonymization); delivering personalized services and recommendations; analyzing service usage statistics; providing customer support and resolving complaints; sending service-related announcements and event information (with your consent); fulfilling legal obligations and resolving disputes; filtering harmful content and ensuring service security; responding to crisis situations (hotline guidance and, after Human-in-the-Loop review when legally required, notifying relevant authorities).
1. Upon account termination, your personal information is promptly deleted. However, in the following cases, data will be retained for the specified period:
Records concerning contracts or subscription cancellations: 5 years (Act on Consumer Protection in Electronic Commerce)
Records concerning payment and supply of goods or services: 5 years (Act on Consumer Protection in Electronic Commerce)
Records concerning consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
Records concerning access (log data): 3 months (Protection of Communications Secrets Act)
AI service operation records as required by the AI Framework Act: 5 years
Content filtering and enforcement records: 5 years
2. Once the retention period expires or the purpose of processing has been fulfilled, the relevant personal information will be deleted within five (5) days.
1. As a general rule, the Company does not provide user personal information to third parties. The following cases are exceptions:
- With the user's prior consent.
- When required by law or upon request from an investigative agency following legally prescribed procedures for investigative purposes.
2. When using external AI services, conversation content (minimal context) may be routed through the provider's servers. Transmitted data is minimized and encrypted, and its retention period is subject to each provider's policy. The Company does not guarantee 'immediate deletion' by the third-party provider.
3. Plaintext conversation data from successful turns within the Companion Local Vault (see Article 8, Sections 8 & 9) is not routed through external AI servers as described in Section 2. Local inference is processed on the user's device using XenLook 4b-Ko, and the Company does not provide this plaintext to third-party AI providers.
To enhance our services, we may entrust personal information processing to third-party service providers. When we do, we will disclose the details of this arrangement in accordance with applicable laws and regulations, and we will manage and supervise these providers to ensure they handle your personal information securely.
① You (or your legal representative) may exercise the following rights at any time: request access to your personal information, request correction of any inaccuracies, request deletion, and request to suspend processing.
② You can exercise these rights through your account settings or by contacting us via email at [email protected]. We will take prompt action on such requests.
③ You may request to view, download, or delete your AI agent's conversation history.
④ Conversation content stored locally on your device within Local Vault is managed directly by you through your local file paths and Companion settings for access, deletion, and transfer. The Company cannot provide server-side access for content not present in our chat-history database under Article 6, Sections ①-③. Account and access logs are supported within the scope of Article 3.
① We use cookies to provide you with a personalized service experience.
② You may refuse cookie storage via your web browser settings. Please note that this may result in limitations to certain service features.
③ Cookies expire upon browser closure or logout.
① In Cloud Mode (default), conversations with your AI agent may be used for service quality assurance and AI model improvement after being de-identified (anonymized). This policy does not apply to conversation turns processed in your Companion Local Vault (see Sections 8 and 9).
② In Cloud Mode, you may consent to or refuse the use of your AI conversation data for training purposes. Refusing will not result in any disadvantage to your use of the service.
③ “Private Mode” is a separate, unreleased feature and is distinct from the Companion Local Vault (see Section 8). For conversations that are not saved to the server, please refer to the Local Vault options described in Sections 8 and 9.
④ By default, AI chat and search are processed in the cloud (e.g., via services like Google Vertex AI, DeepSeek). The Companion local vault processes data on your device only when you opt in separately. Plaintext conversations for these turns are not stored in company databases.
⑤ You may withdraw your consent for AI training on your conversation data at any time. Upon withdrawal, you can also request the deletion of your data previously used for training.
⑥ The Company publishes a transparency report detailing its data usage practices at least once per year.
⑦ Users covered by the EU GDPR may exercise their Right to Data Portability.
⑧ Companion Local Vault (Optional, Experimental): If you complete the legal consent and configuration to process conversations with the local daemon, the plaintext of those conversation turns will not be stored in the Company's chat database (chat-history). While text may be temporarily displayed in your browser session or memory, the plaintext of successful local turns is not transmitted to Company servers. The conversation content is stored at a local path you specify on your device; you are solely responsible for its backup, security, and any loss.
⑨ Even when using the Local Vault, essential data for account and service operation (such as login IP, cookies, and service access logs) may be processed in accordance with Article 3. If the local daemon is not running, conversations are not automatically sent to the cloud (fallback is blocked), and the server-side conversation storage policies (Article 8, Sections 1 & 2) will not apply unless you manually switch back to Cloud Mode.
⑩ (Legal Basis and Notification) The Local Vault is activated by your **separate consent** in accordance with Article 15, Paragraph 2 of the Personal Information Protection Act. Purpose of Collection and Use: To process experimental Korean-language conversations on the user's device. Data Collected: The plaintext of the corresponding conversation turn (not stored in the Company's database). Retention: Stored at the user-designated local path and managed under the user's responsibility. Right to Refuse: You may remain in Cloud Mode without any disadvantage. Consent withdrawal and re-consent for policy changes are managed via the in-chat wizard and the `COMPANION_VAULT_LEGAL_VERSION` identifier. In v1, file attachments and media generation turns may not be eligible for the Local Vault. A pre-filter for crisis and harmful content (L1) is processed within the browser; if content is blocked, it is not transmitted to the server.
We implement the following measures to ensure data security: Administrative measures (internal management plans, minimizing staff access to personal data, and regular training); Technical measures (data encryption, access control management, security program operation, and access log retention); and Physical measures (controlled access to server rooms and data storage facilities).
① When collecting personal information from children under 14 years of age, the Company shall obtain consent from a legal guardian.
② Legal guardians of children under 14 years of age may request to view, correct, or delete the child's personal information.
① To provide our AI services, your conversation data (minimal context) may be transferred to international AI providers, including Google LLC (Vertex AI Gemini), Anthropic (Claude via Vertex AI), DeepSeek, xAI (Grok), OpenAI (images), Suno (music), and Fal.ai (video). For paid plans, web search queries are sent to Google LLC (Programmable Search or Vertex AI Google Search grounding). The free (Explorer) plan does not offer web search. Service infrastructure, including CDN and security, may be routed through Cloudflare, Inc.
② For international transfers, we will notify you of the data being transferred, the destination country, the date and method of transfer, the recipient's purpose of use, and the retention period, and we will obtain your consent prior to the transfer.
③ Conversation plaintext from successful turns in the Companion Local Vault is not transferred internationally (see Article 8, Sections 8 and 9). International data transfers in Cloud Mode are governed by Article 11, Sections 1 and 2, and the table in Article 12.
④ For users in regions subject to GDPR (including the EU and UK), cross-border data transfers will be supported by GDPR Article 46 mechanisms such as EU Commission Standard Contractual Clauses (SCCs) or adequacy decisions, integrated into our contractual and consent procedures. Please refer to the bottom of the table in Article 12 for country-specific transfer bases, including those for China (e.g., DeepSeek) and the United States.
The processor listed below operates on on-premises infrastructure within the Republic of Korea. Personal data is not transferred internationally.
| Recipient | Country of Transfer | Data Transferred | Purpose of Use | Retention Period |
|---|---|---|---|---|
| XenLook 4b-Ko (proprietary engine) | South Korea | Conversation content (encrypted) | AI response generation | Service operation and quality improvement |
Minimal information may be encrypted and transferred to the recipients below to provide our services.
| Recipient | Country of Transfer | Data Transferred | Purpose of Use | Retention Period | Legal Basis |
|---|---|---|---|---|---|
| Google LLC (Vertex AI Gemini) | United States | Minimal conversation context (encrypted) | Primary conversational AI responses | Per provider's policy | EU SCCs · Google DPA / User Consent |
| Anthropic (via Google Vertex AI) | United States | Minimal conversation context (encrypted) | Supplementary, research, and AI response generation | Per provider policy | EU SCCs · Google/Anthropic DPA / User Consent |
| DeepSeek | China | Minimal conversation context (encrypted) | Fallback AI responses | Per provider policy | User Consent · Necessity (PIPL) / EU SCC Review |
| xAI (Grok 4 Fast) | United States | Minimal conversation context (encrypted) | Fallback AI responses | Per provider policy | User Consent / EU SCCs |
| OpenAI (GPT-Image-2) | United States | Image generation prompts (encrypted) | AI image generation | Per provider policy | User Consent / EU SCCs · OpenAI DPA |
| Suno | United States | Music generation prompts (encrypted) | AI music generation | As per provider policy | User Consent / EU SCCs |
| Fal.ai | United States | Video generation prompts (encrypted) | AI video generation | As per provider policy | User Consent / EU SCCs |
| Google Search | United States | Search queries (minimized, encrypted) | Web search for paid plans (source links, snippets) | Per provider policy | User Consent / EU SCCs |
| Cloudflare Inc. | United States | Connection information (IP address, headers) | CDN, Security, WAF | Per provider policy | EU SCCs · Cloudflare DPA / User Consent |
Legal Basis: EU/UK — SCCs or Adequacy Decisions · US — SCCs and Vendor DPAs · China (DeepSeek) — User Consent and Minimum Necessary Transfer (PIPL) · Other — Consent and Article 11 Notice
The Company appoints a Chief Privacy Officer (CPO) to oversee all matters related to the processing of personal information.
Chief Privacy Officer: Nam Ki-yeon (Co-CEO) · [email protected] · Personal Information Dispute Mediation Committee: 1833-6972
For remedies concerning personal information infringement, you may consult the following organizations:
Personal Information Dispute Mediation Committee: (toll-free) 1833-6972 (www.kopico.go.kr)
KISA Privacy Center: (toll-free) 118 (privacy.kisa.or.kr)
Supreme Prosecutors' Office: (toll-free) 1301 (www.spo.go.kr)
National Police Agency Cyber Bureau: (toll-free) 182 (ecrm.cyber.go.kr)
This policy is effective from the date of implementation. Should there be any additions, deletions, or modifications due to changes in laws, policies, or security technologies, we will notify you through service announcements at least seven (7) days prior to the effective date of the changes.
① In the event of a personal data breach, XenLook will promptly notify affected users of the incident, the categories of data compromised, measures to minimize harm, and our contact information.
② For users in the EU, we will notify the supervisory authority within 72 hours, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay, as required by Article 34.
③ For users in China, notifications will be made in accordance with Article 57 of the Personal Information Protection Law (PIPL). For users in Korea, we will take one or more remedial measures without delay, in accordance with Article 34 of the Personal Information Protection Act.
① XenLook does not perform fully automated decision-making that produces legal or similarly significant effects concerning you using AI. All critical decisions are subject to human review.
② In accordance with GDPR Article 22, users in the EU have the right to request human intervention in automated processing. You may exercise this right by contacting us at [email protected].
③ If you object to an automated decision or request human review, XenLook will notify you of the outcome within seven (7) business days.
This Privacy Policy is effective as of June 1, 2026.