Privacy Policy
Effective Date: April 27, 2026 Last Updated: April 27, 2026
BENET ("we," "our," "us," or "the Company") respects your privacy and is committed to protecting your personal information. This Privacy Policy ("Policy") describes how we collect, use, share, and protect information when you use the BENET baby tracking application and related services ("Service").
By accessing or using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
1. Scope and Applicability
This Policy applies to personal information we collect through:
- The BENET mobile application (iOS, Android)
- Our website and marketing communications
- Customer support channels (email, in-app chat)
This Policy does not apply to third-party services you may access through the Service (e.g., social login providers, App Store/Play Store).
2. Information We Collect
2.1 Information You Provide
| Data | How Collected | Required? |
|---|---|---|
| Email address, name | Social login (Google, Apple, Kakao, Naver, LINE) | Required |
| Social account identifier (sub/uid) | OAuth authentication | Required |
| Profile image URL | Social login (if provided) | Optional |
2.2 Information You Enter While Using the Service
| Data | Purpose | Data Type |
|---|---|---|
| Baby profile (name, date of birth, gender, weight, height) | Core tracking service | Personal info about a minor, entered by parent |
| Feeding, sleep, diaper, growth records | Tracking and pattern analysis | Health-related (quasi-sensitive) |
| Voice recordings | Hands-free voice-based logging | Biometric (voice) |
| Photos and food label images | Food label scanning and meal planning | Personal |
| Push notification token (FCM/APNs) | Push notification delivery | Technical |
| Care Community member emails | Family invitation and sharing | Personal |
2.3 Automatically Collected Information
| Data | Purpose |
|---|---|
| App usage logs, crash/error reports | Service quality improvement (via Sentry) |
| Device model, OS version, app version | Technical support and compatibility |
| IP address, access timestamps | Security and fraud prevention |
| Subscription status, purchase receipts | RevenueCat subscription management |
We do NOT collect: advertising identifiers (IDFA / AAID), precise location, contacts, social graph, government IDs, financial account numbers, or passwords.
We do NOT use cookies (this is a native mobile app). No cross-site tracking occurs.
2.4 Apple App Tracking Transparency (ATT)
On iOS 14.5+, Apple requires apps to request permission before tracking users across apps and websites. BENET does not perform cross-app tracking and therefore does not display an ATT prompt.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Provide and sync the baby tracking service
- Power voice recognition and AI-based automatic logging (OpenAI Whisper / GPT)
- Enable family sharing (Care Community) features
- Process subscription payments and prevent fraud
- Diagnose and fix technical issues
- Respond to customer inquiries
- Comply with legal obligations and respond to legal process
- Protect the rights, safety, and property of BENET, our users, and others
3.1 Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on these legal bases:
| Processing | Legal Basis |
|---|---|
| Account creation, service delivery | Contract (Art. 6(1)(b)) |
| Voice recordings, AI analysis | Explicit Consent (Art. 6(1)(a), Art. 9(2)(a)) |
| Security, fraud prevention | Legitimate Interests (Art. 6(1)(f)) |
| Legal compliance (tax, accounting) | Legal Obligation (Art. 6(1)(c)) |
| Service improvement (Sentry, analytics) | Legitimate Interests (Art. 6(1)(f)) |
You may withdraw consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.
4. Automated Decision-Making and AI
We use AI to enhance the Service:
| Feature | Technology | Impact |
|---|---|---|
| Voice → Text transcription | OpenAI Whisper | Input convenience |
| Text → Structured log | OpenAI GPT | Automatic categorization |
| Pattern analytics | In-house algorithm | Statistical insights (informational only) |
These AI features do not make decisions that produce legal or similarly significant effects on you. You can review, edit, or delete any AI-generated record manually within the app.
5. Data Retention
| Category | Retention Period | Basis |
|---|---|---|
| Account information | Deleted immediately upon account deletion | Purpose fulfilled |
| Baby tracking records | Deleted immediately upon account deletion | Purpose fulfilled |
| Voice recordings | Deleted immediately after transcription | Purpose fulfilled |
| Payment records | 5 years | E-commerce law (various jurisdictions) |
| Customer support tickets | 3 years | Dispute resolution |
| Access logs (IP, timestamp) | 90 days | Security |
| Error logs (Sentry) | 90 days | Debugging |
We may retain information longer if required by law (e.g., tax, accounting, litigation).
6. How We Share Your Information
We do not sell your personal information and we do not share it for cross-context behavioral advertising.
6.1 Social Login Providers
| Recipient | Purpose | Data Shared | Retention |
|---|---|---|---|
| Google LLC | Google Sign-In | Email, name | Immediately discarded after authentication |
| Apple Inc. | Apple Sign-In | Email (relay ok), name | Immediately discarded after authentication |
| Kakao Corp. | Kakao Sign-In | Email, nickname | Immediately discarded after authentication |
| NAVER Corp. | Naver Sign-In | Email, nickname | Immediately discarded after authentication |
| LINE Corp. | LINE Sign-In | Email, nickname | Immediately discarded after authentication |
6.2 Service Providers (Sub-processors)
We use the following third-party companies to operate the Service. Each is bound by a data processing agreement.
| Provider | Service | Location | Data Safeguards |
|---|---|---|---|
| Railway Inc. | Server infrastructure | Singapore | SOC 2 Type II, TLS encryption |
| Supabase Inc. | Database, authentication | Republic of Korea (Seoul) | SOC 2 Type II, RLS, encryption at rest |
| OpenAI Inc. | Voice recognition (Whisper), AI analysis (GPT) | United States | Zero-retention API; inputs not used for training |
| Sentry Inc. | Error monitoring | United States | SOC 2 Type II, data scrubbing |
| RevenueCat Inc. | Subscription billing | United States | SOC 2 Type II, PCI-DSS |
| Apple Inc. / Google LLC | Push notifications, in-app purchases | United States | Platform-level |
6.3 Legal and Safety Disclosures
We may disclose information:
- To comply with applicable law, regulation, legal process, or governmental request
- To enforce our Terms of Service
- To protect the rights, safety, and property of BENET, users, or the public
- In connection with a merger, acquisition, or sale of assets (with notice to users)
7. International Data Transfers
The Service's core data is hosted in Singapore (application servers, Railway) and the Republic of Korea (database, Supabase). Certain sub-processors listed in Section 6.2 (e.g., OpenAI, Sentry) process limited data in the United States. Wherever you are located, your information may be transferred to and processed in these countries. Railway Inc. and Supabase Inc. are US-incorporated companies, but the data itself resides in the Singapore and Seoul regions respectively.
7.1 Safeguards for Transfers from the EEA/UK/Switzerland
Where required, we rely on:
- Standard Contractual Clauses (SCCs) adopted by the European Commission
- Data Processing Agreements (DPA) with all sub-processors
- Supplementary measures including TLS 1.2+ encryption in transit and at rest
Copies of SCCs are available upon request at info@benetfamily.com.
7.2 Safeguards for Transfers from Korea
For users in the Republic of Korea, these transfers are entrustment/storage necessary to perform our service contract. Under PIPA Article 28-8(1)(3), we disclose the required particulars in this Privacy Policy (Section 6) instead of obtaining separate consent. You may refuse these transfers by deleting your account; doing so limits use of the Service.
8. Your Privacy Rights
Depending on your location, you may have the following rights:
8.1 General Rights
- Access: Request a copy of your personal information
- Correction: Correct inaccurate or incomplete data
- Deletion: Request deletion ("right to be forgotten")
- Restriction: Request restriction of processing
- Portability: Receive your data in a structured, machine-readable format (JSON/CSV)
- Objection: Object to certain types of processing (e.g., legitimate interests)
- Withdraw Consent: Where processing is based on consent
- Complaint: Lodge a complaint with a supervisory authority (see Section 14)
8.2 California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act, you have the right to:
- Know what categories of personal information we collect, use, and share
- Delete personal information we've collected from you
- Correct inaccurate personal information
- Opt-out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising)
- Limit use of sensitive personal information (voice recordings, precise location)
- Non-discrimination for exercising your rights
Submit a verifiable consumer request to info@benetfamily.com. We will verify your identity by matching at least two data points from your account.
8.3 Other US State Residents
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or any state with comprehensive privacy law, you have similar rights to access, correct, delete, port, and opt-out of targeted advertising/profiling. We do not engage in targeted advertising.
8.4 EEA / UK / Switzerland Residents (GDPR / UK GDPR)
In addition to the rights above, you have the right to:
- Not be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions)
- Lodge a complaint with your local Data Protection Authority
8.5 How to Exercise Your Rights
- Primary: Use the Settings → Account → Delete Account feature in-app
- Email: info@benetfamily.com
- Response time: 30 days (may extend by another 60 days for complex requests with notice)
- Cost: Free, unless requests are manifestly unfounded or excessive
9. Children's Privacy (COPPA)
The Service is designed for parents and guardians to record information about their children.
9.1 Age Requirements
- The account holder must be at least 14 years old (age of digital consent in Korea). The Service is offered in South Korea and Japan and is not directed to users in the EEA.
- Baby profiles (information about children) are entered by the parent/guardian on behalf of the child.
- The Service is not directed to children under 13 in the United States.
9.2 COPPA Compliance (United States)
- We do not knowingly collect personal information directly from children under 13.
- We treat baby profile information as parent-provided data, with the parent acting as the data subject's representative.
- Parents can review, delete, or refuse further collection of their child's information at any time via the app or by contacting info@benetfamily.com.
If you believe we have inadvertently collected information directly from a child under 13 without verifiable parental consent, please contact us immediately and we will delete the information.
10. Data Security
We implement administrative, technical, and physical safeguards:
- Encryption: TLS 1.2+ for data in transit; AES-256 for sensitive data at rest
- Authentication: No passwords stored (OAuth-only). Social provider handles credential security.
- Access controls: Role-based access; Supabase Row-Level Security (RLS) isolates user data
- Minimum access: Only authorized personnel with a need-to-know have access
- Monitoring: Intrusion detection, anomaly alerting, 24/7 log review (Sentry)
- Audits: Regular security reviews and third-party penetration testing
No security system is impenetrable. We cannot guarantee absolute security.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify you without undue delay (within 72 hours where feasible, per GDPR Art. 34 / similar laws)
- Notify the relevant supervisory authorities as required by law
- Include in the notice: nature of the breach, categories and approximate number of records affected, consequences, and remedial measures
12. Do Not Track (DNT) and Global Privacy Control (GPC)
- Our mobile app does not track you across third-party apps or websites.
- We honor Global Privacy Control (GPC) signals for users on our web properties as an opt-out of sale/sharing.
- Because this is a native app with no cross-app tracking, DNT browser signals do not apply.
13. Data Controller and Contact
| Controller | BENET |
| Representative | Taewan Kim |
| Address | 71 Apgujeong-ro 29-gil, Gangnam-gu, Seoul, Republic of Korea |
| info@benetfamily.com | |
| Data Protection Officer (DPO) | Taewan Kim (info@benetfamily.com) |
For EEA/UK residents, we will appoint an Article 27 representative if required by GDPR.
14. Supervisory Authorities and Complaints
If you have concerns, please contact us first. You also have the right to lodge a complaint with:
| Region | Authority | Website |
|---|---|---|
| EU/EEA | Your local Data Protection Authority | edpb.europa.eu |
| United Kingdom | Information Commissioner's Office (ICO) | ico.org.uk |
| United States | Federal Trade Commission (FTC) | ftc.gov |
| California | California Privacy Protection Agency (CPPA) | cppa.ca.gov |
| South Korea | Personal Information Protection Commission | pipc.go.kr |
| Japan | Personal Information Protection Commission | ppc.go.jp |
15. Changes to This Policy
We may update this Policy from time to time.
- For material changes, we will provide at least 30 days' advance notice via in-app notice and email.
- For minor changes, we will provide 7 days' notice via in-app notice.
- Previous versions are available upon request at info@benetfamily.com.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy.
Revision History
| Version | Date | Summary |
|---|---|---|
| v1.0 | 2026-04-27 | Initial version |
This policy is effective as of April 27, 2026.