Privacy Policy

Toasterz values your personal information and complies with relevant laws, including the Personal Information Protection Act.

1. Service Overview

Service Name : SourFriend

Company : Toasterz Inc.

Service Description : Mobile app and web service integrated with smart fermentation IoT devices

2. Personal Information We Collect

Required Information

  • ·Email address

Automatically Collected for Core App Functions

  • ·A Firebase Installation ID (FID) and a Firebase Cloud Messaging (FCM) registration token may be created when the app initializes, before you grant notification or optional analytics permission. The FID identifies the app installation; SourFriend does not store it in its account database or use it as the account identifier.
  • ·App, device, network, and account-activity metadata needed to operate and secure the service (app version, device model and device information, OS version, language or region settings, IP address, device ID, client type, account-linked actions, and timestamps)

Optional or User-Provided Information

  • ·Starter profiles, feeding and check-in records, care plans, fermentation and device readings, letters, and photos you choose to save with these features. These stored photos are separate from photos submitted only to AI Chat.
  • ·AI Chat messages and photos you choose to submit, together with relevant starter and care context needed for the reply (starter profile and age, care state and location, recent feeding outcomes, environment and device observations, and relevant dialogue and Memory context)
  • ·Saved memories selected from future chats when Automatic Memory is enabled, and Learning Insights generated with separate consent from aggregated feeding records, previous insights and fermentation activity.
  • ·Weekly letters generated with the shared AI Chat & Weekly Letters consent from relevant starter care records and eligible recent chat context; saved memories are used only while Automatic Memory is enabled.
  • ·AI response reports you submit, including the report reason, optional comment, and a snapshot of the reported model response
  • ·If you purchase or restore a subscription, we process your SourFriend account identifier, store platform, subscription product, purchase token or transaction identifier, verification time, and access, expiry and introductory-period information. We also record claimed promotional access, eligible device access and chat usage to provide the correct features and message allowance. Purchase references are encrypted in our database. Apple or Google handles payment; SourFriend does not receive or store payment-card numbers or bank-account details.
  • ·Only after you choose to allow app analytics and ad measurement, selected app-usage events, an app-instance identifier, permitted app and device information, and approximate region are sent to Google through Firebase Analytics and may be used in linked Google Ads to measure our campaigns. When signed in, these events are linked to your SourFriend account ID.
  • ·With the same optional analytics consent, predefined diagnostic error codes indicate that a feature such as AI Chat failed. These events do not include chat text, uploaded photos, raw error messages or stack traces.

3. Purpose of Collection and Use

  • ·User registration and management
  • ·Providing and operating SourFriend services
  • ·Maintaining Firebase app installation state, applying Firebase Remote Config settings, and delivering notifications. Device notification permission controls whether notifications are displayed; it does not necessarily prevent installation identifiers or messaging tokens from being created.
  • ·User content storage and management
  • ·Generating AI replies and helping keep AI Chat safe using the content you submit and the relevant starter, care, feeding, environment, device-observation, dialogue, and Memory context described above. The same optional consent enables personalized weekly letters about your starter and recent activity.
  • ·With the relevant consent, selecting and using saved memories from future chats to personalize replies, and analyzing aggregated feeding records and previous insights about every two weeks to generate Learning Insights.
  • ·Reviewing reported AI responses, enforcing safety, and handling incidents using the submitted reason, optional comment, and response snapshot
  • ·Verifying and restoring purchases, checking subscription and device access, applying promotional access and chat allowances, and preventing the same purchase from being claimed by a different SourFriend account.
  • ·Operating, securing, troubleshooting, and preventing abuse of the service using account-linked activity and device or network metadata
  • ·With your optional consent, we use app-usage analytics to understand feature use, diagnose failures, improve SourFriend, and measure the effectiveness of our ad campaigns, including actions such as your first feeding. This choice does not enable personalized advertising.
  • ·Sending notifications (when opted in)
  • ·Customer support
  • ·Bluetooth Low Energy (BLE) connection to smart fermenters and reception of status data

4. Retention and Use Period

  • ·Account, profile, and user-created service data are retained while your account is active and removed from active systems when the account-deletion workflow is completed.
  • ·The FID is installation-scoped. SourFriend does not store it in its account database or use it as the account identifier, and SourFriend account deletion does not delete it. Account associations to FCM tokens stored by SourFriend are removed during account deletion; installation-scoped identifiers and tokens otherwise follow Firebase's lifecycle.
  • ·Account-linked activity logs and related IP address, device ID, client, device, and timestamp metadata are retained while the account is active for service operation, security, troubleshooting, and abuse prevention, and are removed from active systems during account deletion, subject only to the limited legal and security exceptions below.
  • ·SourFriend does not persist AI Chat photos on its servers, in its database or object storage, or in chat history or Memory. The app creates a sanitized temporary upload copy and deletes that copy on a best-effort basis after the request. Separately, the image picker or operating system may retain temporary cache files until normal operating-system cleanup. The photo is sent to Amazon Bedrock for the current processing request.
  • ·SourFriend keeps up to the 100 most recent successful exchanges in each AI chat conversation; each exchange includes your message and the assistant’s reply. The conversation expires 90 days after its last successful exchange and is removed through the cleanup process. A new successful exchange extends that conversation’s expiry. Restart Chat deletes the current conversation history, but not separately saved memories. If you report a response, a copy is retained in a separate report record and is not deleted by Restart Chat or routine chat-history cleanup.
  • ·Saved memories remain until you remove them, turn Automatic Memory off, or complete account deletion; starter-specific memories are also removed when that starter is deleted. Restart Chat or chat-history expiry does not delete saved memories, and deleting a memory does not delete the original chat message. Delete all your memory clears existing memories but leaves future saving enabled. Turning Automatic Memory off clears existing memories and stops future saving. Learning Insights require separate consent; withdrawing that consent clears stored Learning snapshots from active SourFriend systems. Account deletion removes associated Memory and Learning data.
  • ·Turning AI Chat & Weekly Letters off stops new generation. Existing letters remain in your archive until you delete them or account deletion removes them. Notification settings do not delete letters or stop generation.
  • ·AI response reports, including the reason, optional comment, and reported response snapshot, are retained separately while your account is active so they can be reviewed. They survive Restart Chat and routine chat-history expiry and are removed during account deletion, subject only to the limited legal, security, fraud-prevention, and dispute-resolution exceptions below.
  • ·Subscription and entitlement records are kept while your SourFriend account is active and removed from our active database when the account-deletion workflow completes, subject to the limited retention exceptions below. Deleting SourFriend records does not delete the stores’ own transaction records.
  • ·Withdrawing this optional consent stops future app analytics and ad-measurement collection and resets local analytics data and identifiers used going forward. Information already transmitted remains subject to the applicable Firebase and linked Google Ads retention and deletion processes; account deletion does not guarantee deletion of the installation-scoped FID or previously transmitted analytics and ad-measurement information.
  • ·We may retain limited records only when required by law or reasonably necessary for security, fraud prevention, or dispute resolution. Access is restricted, and the records are deleted or de-identified when the applicable purpose or retention period ends.

5. Disclosure to Third Parties

We share the information described below for the stated service purposes and, only with your optional consent, for app analytics and ad campaign measurement.

The following providers process the limited information described here:

  • ·Google Firebase and linked Google Ads: An installation-scoped FID and an FCM registration token may be created at app initialization before notification or optional analytics permission. Firebase also processes app/device metadata and Remote Config; notification permission controls display. Only with your optional app analytics and ad-measurement consent, Firebase Analytics processes the app-usage events, app-instance identifier, app/device information, approximate region and limited diagnostic codes described above for product analytics and diagnosing failures. Selected app-usage events and associated identifiers, app/device information and approximate region may also be used in linked Google Ads to measure campaign performance. Events include your SourFriend account ID when signed in. Personalized advertising remains disabled. The app’s custom analytics events exclude names, email addresses, chat and photo contents, raw error messages, stack traces, and SourFriend device, Bluetooth and Wi-Fi data.
  • ·Amazon Web Services (AWS): hosting and storage for SourFriend service data, including saved memories; AI Chat / Weekly Letters and Learning Insights processing through Amazon Bedrock; and required deletion of memory retained from an earlier provider-hosted memory system. Relevant conversation and saved-memory context may be included in a model request when the corresponding optional features are enabled.
  • ·Apple App Store and Google Play: We exchange the purchase reference and relevant account and product identifiers with the store to verify and restore purchases and check current access. The stores process payment and their own transaction records under their respective privacy policies.

We manage service-provider processing through applicable contracts, service configuration, access controls, and security procedures, and disclose the purposes and categories of data processed. Provider handling is also subject to the provider's applicable service terms and law.

6. Outsourcing of Personal Information Processing

We outsource personal information processing as follows for service provision:

Service Provider : Amazon Web Services (AWS)

Outsourced Tasks : Amazon Web Services (AWS): hosting and storage for SourFriend service data, including saved memories; AI Chat / Weekly Letters and Learning Insights processing through Amazon Bedrock; and required deletion of memory retained from an earlier provider-hosted memory system. Relevant conversation and saved-memory context may be included in a model request when the corresponding optional features are enabled.

AI Chat & Weekly Letters (Optional)

With your consent, SourFriend sends the message and photo you submit and relevant starter profile and age, care state and location, recent feeding outcomes, environment and device observations, and relevant dialogue and Memory context to Amazon Bedrock to generate the reply and help keep the chat safe. SourFriend does not persist the photo on its servers, in its database or object storage, or in chat history or Memory. The sanitized temporary upload copy is deleted on a best-effort basis after the request; the image picker or operating system may independently retain temporary cache files until normal operating-system cleanup. The same consent also enables scheduled weekly letters. To write them, SourFriend sends relevant starter details, feeding and check-in records, environment and device observations, and eligible recent chat context to Amazon Bedrock. Relevant saved memories are included only while Automatic Memory is enabled. Scheduled generation may run while the app is closed.

AI Chat and Weekly Letters share one optional consent. You may decline or turn them off together in Settings > AI Preferences. This stops new chat and weekly-letter generation requests. A request already sent to the provider cannot be recalled, but its unfinished result will not be added to your chat or letter archive after withdrawal. Existing chat history and letters remain available under the retention rules in this policy. Notification settings control alerts separately; disabling alerts does not stop letter generation. Core non-AI app functions remain available.

Automatic Memory (Optional)

When you enable Automatic Memory, the Terra model may select useful details from future conversations, such as preferences, names, interests or information about your starter, and ask SourFriend to save, update or remove them. These details are stored as separate memory records in SourFriend’s systems, associated with your account or a particular starter. Relevant saved memories may be sent to Amazon Bedrock with later requests to personalize replies. We do not ask for confirmation before every save.

In Settings > AI Preferences, you can review, correct or delete individual saved memories. Delete all your memory clears existing memories, including manually saved and automatically remembered details, but leaves Automatic Memory enabled for new details from future chats. To stop future saving, turn Automatic Memory off; this also removes existing memories. Where memory was stored in an earlier provider-hosted memory system, deletion is verified in the background and may take additional time.

Learning Insights (Optional)

With separate Learning Insights consent and sufficient data, SourFriend sends aggregated feeding records, fermentation outcomes, environment and device observations, and previous insights to Amazon Bedrock about every two weeks to identify useful patterns and generate updated insights.

You may decline or revoke Learning Insights consent in Settings > AI Preferences. Revocation stops new analyses and clears stored Learning snapshots from active SourFriend systems; account deletion also removes associated Learning data.

Cross-border transfer for optional AI features

  • ·Recipient: Amazon Web Services, Inc. (privacy contact: aws-korea-privacy@amazon.com)
  • ·Processing locations: United States (Oregon) for Terra model inference through Amazon Bedrock; South Korea (Seoul) for SourFriend service hosting and saved-memory storage, model safety checks, and any required deletion from the earlier provider-hosted memory system.
  • ·Data categories: AI Chat messages and photos; starter profile and age, care state and location; feeding outcomes, environment and device observations; relevant dialogue and Memory context; and, for Learning Insights, aggregated feeding records and previous insights. Weekly Letters use the relevant starter care records, recent chat and permitted saved-memory context described above.
  • ·Timing and method: encrypted network transfer when you submit an AI Chat request, including relevant saved-memory context when enabled, and about every two weeks when Learning Insights is enabled and sufficient data exists. Terra may request memory changes during a conversation; SourFriend stores those changes in its own service database. Where earlier provider-hosted memory remains, requests needed to verify and complete its deletion are also sent. The shared AI Chat & Weekly Letters consent also permits encrypted transfers for scheduled weekly letter generation while enabled.
  • ·Purposes: generating and safeguarding AI replies, extracting and using Automatic Memory for personalization, and generating periodic Learning Insights. This includes generating scheduled weekly letters under the shared chat-and-letters consent.
  • ·Recipient retention: for the period needed to perform the contracted processing for the enabled feature. Any temporary handling required under applicable AWS service terms, security processes, or law is governed by those terms and law; outputs retained by SourFriend follow Section 4 of this policy.
  • ·How to refuse and effect: decline or revoke the relevant feature in Settings > AI Preferences. New transfers for that feature stop. AI Chat & Weekly Letters, new Automatic Memory, or Learning Insights will be unavailable or no longer personalized, but core non-AI app functions remain available.

7. User Rights

Users may exercise the following rights at any time:

  • ·Request access, modification, and deletion of personal information
  • ·Account withdrawal (via in-app 'Delete Account' feature)
  • ·Request deletion of your SourFriend account and associated data outside the app
  • ·Decline or withdraw consent for AI Chat & Weekly Letters, Automatic Memory, or Learning Insights at any time in Settings > AI Preferences
  • ·Opt out of notifications (device settings)
  • ·App analytics and ad measurement are off until you explicitly allow both. You may continue without either and withdraw this consent at any time in Settings; withdrawing it stops future collection for both purposes.

8. Personal Information Protection Measures

  • ·Encrypted communication (HTTPS/SSL)
  • ·Access control and management
  • ·Security program installation and periodic inspections

9. App Permission Notice

We may request the following device permissions to provide our services. You may deny these permissions; however, related features may be limited if you do so.

Bluetooth (BLE) [Optional device connection]

Purpose : To discover, connect to, and receive status data (e.g., temperature and humidity) from SourFriend smart fermenters

Information used : Nearby BLE device identifiers (device name, signal strength, etc.) and fermentation environment data received after connection

If denied : You cannot connect devices or use remote monitoring features.

Location / nearby devices [Device setup]

Purpose : Depending on the operating system, these permissions support nearby Bluetooth or Wi-Fi discovery and reading the current Wi-Fi network name while setting up a SourFriend device. They are not used to track your GPS location.

Information used : Nearby network/device information and the current Wi-Fi network name needed for setup. SourFriend does not use this permission to collect or store GPS coordinates. This is separate from the approximate region included in optional analytics.

If denied : Automatic device or network discovery may be unavailable; available setup options depend on the operating system.

Bluetooth [iOS]

Purpose : To discover and connect to smart fermenters

Information used : Nearby BLE device identifiers

If denied : You cannot use device connection features.

Camera and selected photos [Optional]

Purpose : Taking or selecting a photo for your starter, feeding records or letters, attaching a photo to AI Chat, or saving a result to your photo library when you choose to do so.

Data used : Only the photos you capture or select for the requested feature. Stored service photos and temporary AI Chat photos are handled as described above.

Effect of refusal : The corresponding camera, photo-selection or save-to-library action may be unavailable. Text-based functions remain available.

Notifications [Optional]

Purpose : Service alerts such as fermentation completion and feeding reminders

Information used : Device token for push notifications

If denied : You will not receive push notifications.

These permissions are used only to provide the service. We do not use information obtained through permissions for purposes other than those stated in this policy, nor do we provide it to third parties. You may change permission settings in your device settings.

10. Privacy Officer and Contact Information

Company Name : Toasterz Inc.

Address : Room 124, 2, Toegye-ro 36-gil, Jung-gu, Seoul, Republic of Korea

Email : contact@toasterz.team

Website : https://www.toasterz.team

Originally effective January 15, 2025. Revised September 23, 2026 to explain optional app analytics and ad campaign measurement and the related consent, provider processing and retention controls.