Privacy Policy
Last updated: 2026-09-14
1. Data Controller
HIPPie is operated by BHware.Co (Representative: ByungHyun Lim; Business Registration No. 579-88-03535; Sejong City, Republic of Korea), which runs the hippie.land website and the HIPPie mobile application. Our Privacy Officer is the representative above. For any privacy matter, contact: admin@hippie.land
2. Data We Collect
- Account data — Username, email, and password (stored in a non-recoverable form).
- Capture and device details — Camera and device information used to confirm a photo or video was genuinely captured on your device and to prevent forgery. This includes the per-device public key and attestation receipt issued through Apple's device-integrity service (App Attest), used only to confirm the app is an unmodified genuine install and stored per account and app install.
- Original records — HIPPie does not store your original photo or video on its servers; it keeps only the minimal information needed to confirm that content is an original.
- Social and messaging content — Posts, captions, comments, stories, likes, follows, blocks, reports, uploaded media, and direct messages you choose to send through HIPPie.
- Creator and badge activity — Records of HIPPie camera captures, visibility choices, reports, and HIPPie-Verified badge eligibility signals.
- Technical and log data — IP address and request metadata are used for rate limiting, abuse prevention, and security. Anti-abuse counters do not store your IP, account identifier, or email address themselves — only a value derived from them in a non-recoverable form — and they are automatically deleted within 2 days; moderation audit logs that include the request IP are deleted after 365 days (1 year). After an unexpected exit, the app asks once whether you want to allow future crash diagnostics. Before you opt in, it stores only a local prompt-needed flag, not the crash stack. If you allow it, future crashes may send HIPPie an obfuscated stack trace, app version, OS version, and error source without an account ID, device ID, authentication token, photo, or video. These reports are not linked to your account and are deleted within 90 days. We do not send usage analytics and do not use third-party advertising trackers.
- Payment records — When you buy a paid feature, a transaction reference from the app store. Card and payment-instrument details are handled by the app store, not by HIPPie.
- Transfer tracing records — When a creator sends a protected copy to someone, that copy is linked to the transfer record (sender, recipient, time), so a leaked copy can be traced back to that transfer. This does not monitor your device or how you store the file; it only allows after-the-fact matching.
3. Purpose of Processing
- Showing whether a checked copy matches a HIPPie original
- Operating social, messaging, and creator features you choose to use
- Protecting creators, viewers, and the service from abuse and fraud
- HIPPie-Verified badge eligibility, service improvement, and security
4. Legal Basis
Under the EU GDPR, processing relies on legitimate interest (Art. 6(1)(f)) for verification, security, and abuse prevention, and on consent (Art. 6(1)(a)) for account creation and optional features. Under Korea's Personal Information Protection Act (PIPA), we process personal data with your consent and as necessary to perform the service (Arts. 15, 22).
5. Data Retention
Account and original records are kept while your account is active or as needed to provide creator proof and viewer checks; you can delete individual records or your account at any time. Where you make a purchase, transaction and consumer records are retained as required by Korean law (e-commerce records for 5 years; consumer complaint and dispute records for 3 years). Server-side originals are deleted immediately after processing. Additional periods: stories expire after 24 hours; email verification codes expire after 15 minutes; unconfirmed sign-up requests (email, username, nickname, and the password in a non-reversible form) are deleted after 24 hours; sign-in refresh tokens expire after 7 days; anti-abuse counters (which hold only a non-recoverable value derived from your IP, account identifier, or email address, never those values themselves) are deleted within 2 days; moderation audit logs are deleted after 365 days (1 year); opt-in crash diagnostics are deleted within 90 days; encrypted server backups are kept in a rotation of the 30 most recent copies. Your original photos and videos themselves exist only in the encrypted vault on your device, never on our servers — deleting the app, clearing its data, or losing the device removes that vault permanently, and only a backup file you exported yourself can bring it back.
Direct messages: we store a message on our servers to deliver it and to show it in your conversation. You can delete a single message or a whole conversation at any time — whether you sent it or received it, however old it is — and you choose whether it is deleted only for you or for everyone in the conversation. Deleting for everyone erases the message text from our database for both sides at once; deleting only for you removes it from your own view only — the message text stays stored for the other participant until it is deleted for everyone or the retention limit below applies; a daily sweep erases message text nobody can reach any more (for example, after the other account was deleted). Where we set a maximum retention period for messages, message text older than that period is erased even if nobody deleted it; when no such period is set, we do not delete readable messages by age. One exception to deletion: if content is reported, we keep a copy of the reported content and the context needed to review it. That copy survives deletion, is used only to handle the report and any appeal, and is kept no longer than that purpose requires. In conversations with end-to-end encryption turned on, the server relays and stores only ciphertext it cannot read, and deletes it within 7 days after delivery is confirmed.
Minimal records kept after deletion: when you delete your account, the account and your posts, comments, stories, messages, media and sessions are all deleted. Three things are kept in a limited form, on the basis of our legitimate interest in defending legal claims and responding to repeat abuse. (1) Copies of content included in reports that other users filed — purpose: evidence for handling the report and any appeal. Retention: 12 months from the day the report is closed, after which the copy is deleted automatically. Access: operators only, and each access is written to the audit log. (2) Terms-consent receipts — purpose: proof that consent was given. The account identifier is pseudonymised at deletion, so the receipt no longer identifies you. Retention: 5 years from the day the account is deleted, after which the receipt is deleted automatically. (3) Operator-action audit records — only the fact that an action was taken remains; the target identifier and IP address are removed at deletion. Retention: 365 days (1 year). In addition, the record that an original was registered (its non-recoverable fingerprint value and the registration time) stays, detached from any owner information, so that nobody can later register the same original as their own.
6. Data Sharing and Sub-processors
We do not sell personal data. Public records show only the creator-facing information needed for viewers to understand an original record. We use a limited set of service providers that process data only to operate HIPPie: Apple Inc. (App Store / StoreKit for purchases, App Attest for device integrity); Amazon Web Services (Amazon SES) for verification and password emails; and Railway Corp. (Railway) for cloud hosting of our servers. They may also process data to protect security or meet legal obligations.
7. International Data Transfer
Some sub-processors (Apple, Amazon Web Services, and Railway) may process data on servers outside Korea or the EEA, including the United States. Where this happens, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision, and, where Korean law requires, your consent to overseas transfer.
8. Your Rights
- Right of access — Review your account and original record history in the app.
- Right to erasure — Delete individual records, messages or conversations, or your account. (GDPR Art. 17 / PIPA Art. 36)
- Right to object / restrict — Make a record private or ask us to stop optional processing where the law gives you that right.
- Right to data portability — Ask for a copy of your account and original record history where available.
To exercise these rights, contact us at admin@hippie.land — we respond within one month (extendable where the law allows for complex requests) and provide access or portability copies in a machine-readable format (JSON). EU residents may also lodge a complaint with their supervisory authority; Korean residents may contact the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the Privacy Infringement Report Center (privacy.kisa.or.kr, 118).
9. Adults Only
HIPPie is an adults-only service for users aged 19 and over. We do not knowingly collect personal data from anyone under 19, and we do not offer registration with the consent of a legal guardian. If you believe a person under 19 has provided personal data, contact us and we will delete it.
10. Automated Decisions
HIPPie-Verified badge eligibility is determined automatically from your camera-origin records and account signals. This does not produce legal or similarly significant effects on you, and you can contact us for a human review of any badge decision.
11. Security
We use reasonable security measures for accounts, original records, and viewer checks, including encrypted connections, protected (non-recoverable) passwords, an on-device encrypted vault, rate limits, account lockout, and abuse prevention. No online service can promise perfect security.
12. Contact
For privacy inquiries, or to reach our Privacy Officer: admin@hippie.land

