Milcat Privacy Policy

1. Personal Information and Purposes

The Company processes the following information to the extent needed to provide the Service.

  • Account and authentication: identifiers from Apple, Google, or Naver, a provided email address, nickname, profile icon, and profile image. These are used for sign-in, account creation or linking, member identification, and profile display. Raw sign-in provider tokens are not stored as account information.
  • Household and care data: Household identifiers, member relationships and roles, Household time zone, cat information, care records, schedules and feeding plans, inventory, and health-notebook records. These are used for Household collaboration and record and notification features.
  • Conversation, AI, and files: Household chat, personal AI conversations and prompts and responses, AI runs and proposals, images and audio attachments selected by the User, and attachment text, transcripts, and metadata. These are used for chat, AI responses, file processing, and User-approved actions.
  • Billing: subscription status, store transaction and subscription identifiers, receipt-verification results, and minimum verification values used to prevent duplicate AI-credit processing. These are used for entitlement checks, billing synchronization, refund and dispute handling, and duplicate-grant prevention. The Company does not collect card numbers or other payment-method information processed directly by the store.
  • Notifications and support: notification preferences, device push tokens and installation identifiers, support messages and categories, an optional contact email, and the minimum diagnostic context needed to handle a support request. These are used for notifications, support, bug and suggestion handling, and security.
  • Operations and security: security, Household, and administrator audit records, minimal error information for failed requests, and minute-level aggregates. These are used for security, error handling, operations, and dispute handling. Operational analytics do not store request bodies, cookies, authorization headers, raw tokens, raw IP addresses, or raw User-Agent values.
  • Anonymous client diagnostics: To detect and fix unexpected app failures, the app may automatically transmit the following diagnostics over encrypted connections: fixed error kind, surface and code; app version and build; operating-system major/minor version; and a server-generated one-way aggregation fingerprint. These are not used to identify or track a device or person. The Company does not collect or store exception text, stack traces, login credentials, Apple authorization codes or nonces, account/Household/install/device identifiers, IP addresses, user agents, endpoint URLs, or user content.

2. Device Permissions and Optional Functions

  1. The Service requests permissions for photo selection, camera capture, audio recording, notifications, and device-calendar functions when the User chooses the related function. The Company processes selected items or generated files only to the extent needed for that function and does not use the camera or microphone continuously.
  2. Calendar integration is a one-way device feature that creates or updates a device copy of Service schedules. Existing device-calendar event content and events that are not part of the account are not sent to the Company’s server.
  3. If notifications are allowed, the Service may register a push token and installation identifier needed to deliver them. If the User declines or disables notifications, the Service does not send notifications to that device.

3. Retention and Deletion

  1. Account, Household, cat, care, schedule, inventory, and health records are processed while the account or relevant Household exists and become subject to deletion after deletion or fulfillment of the purpose. Records shared in a Household may remain for joint use and history with the link to the author account removed.
  2. Messages, personal AI conversations, AI proposals, and search data become subject to deletion one year after creation. Care history, schedule occurrences and corrections, and inventory, billing, and AI-credit ledgers may be retained while the related account or Household exists for history and settlement.
  3. Files not linked to a message become subject to deletion after 24 hours. Original attachments linked to a message become subject to deletion after 90 days. Transcripts, extracted text, and metadata may remain for the retention period of the related message.
  4. Security, Household, and administrator audit records; support messages and diagnostic context; failed-request records; and operational aggregates become subject to deletion 90 days after creation. Invalid or account-deleted push tokens and installation information also become subject to deletion. Anonymous client diagnostic aggregates and bounded samples are deleted after 30 days, and random per-event retry receipts after 8 days.
  5. When an account is deleted, the Company deletes the stored personal account information, personal AI conversations and personal attachments, and data belonging only to a Household owned by that Member. Records shared into another Household may remain for joint use with the author link removed. Minimal irreversible verification values needed to prevent abuse or duplicate free benefits, and minimum billing evidence required by law, may be retained separately from other personal information.
  6. Payment and supply records may be retained for the periods required by laws including the Act on the Consumer Protection in Electronic Commerce, Etc. Store subscription references and payment verification values are retained only to the minimum extent needed. An irreversible digest used to prevent duplicate AI-credit purchases may remain while that purpose continues.

4. Processors, Disclosures, and International Transfers

The Company uses the following providers or external services only to the extent needed for the Service. Information for an optional function is not sent to that function’s provider when the User does not use it.

Processors

  • AWS: operation of servers, databases, and private object storage, including storage for profile images and chat attachments.
  • Naver Corp.: when Naver sign-in is used, processing of Naver account identifiers, provided email, and profile information for authentication and account linking.
  • Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM): delivery of push notifications to devices that allow notifications. Device tokens and notification payloads needed for delivery are used.

International transfers

  • Google LLC: when Google sign-in is used, account identifiers and provided email and profile information are transferred for authentication and account linking.
  • Apple Inc.: when Apple sign-in is used, Apple account identifiers and provided email are transferred for authentication and account linking.
  • OpenAI OpCo, LLC: only when the User requests AI chat or transcription of an audio or video attachment, information needed to generate the response or transcript is transferred, including the conversation, selected attachments, and related care records within that scope.

If the User does not use AI chat, information for an AI request is not transferred to OpenAI. An AI request may include recent conversation turns, information directly entered or attached by the User, and the cat, Household, schedule, feeding, inventory, health, and AI-proposal information needed for the response. The Company does not transfer account email, social sign-in information, billing information, or the identity of another member beyond what is needed for the response. Information the User directly includes in a conversation or attachment may nevertheless be transferred with that content.

Whether information sent to OpenAI is stored, and how provider abuse-prevention and security records are retained, follows the provider’s policy and the Company’s contract and settings. The same applies to the processing and retention scope for audio and video transcription. The provider’s actual processing and retention practices are described in OpenAI’s privacy information.

5. Deletion Procedure and Method

When a retention period ends or a purpose is fulfilled, the Company determines that the information is eligible for deletion and removes it from databases and object storage using methods designed to make recovery difficult. Minimum billing evidence and irreversible verification values required by law are kept separately from other personal information and deleted when their retention period ends. Information remaining in backup copies is access-restricted until removed through the backup rotation and disposal process.

6. User Rights and Contact

Within the scope provided by applicable law, Users may request access, correction or deletion, suspension of processing, and withdrawal of consent. Requests may be submitted through the Service’s account or support functions or the Company’s official contact channel, and the Company will handle them under applicable law.

Privacy contact: [email protected]

7. Security Measures

The Company applies reasonable safeguards including access control, encryption in transit, storage-access controls, security updates, deletion jobs, and log review.

Addendum

This Policy (v1.1.1) is posted on September 29, 2026 and takes effect on the same date.