Aegis

Privacy Policy

Scope Aegis mobile application (Android, iOS) and related online services

Published: 17 April 2026 · Effective: 17 April 2026 · Version: 1.0

This policy is drafted to comply with the Korean Personal Information Protection Act (PIPA), Google Play Data safety requirements, Apple App Store App Privacy requirements, the EU/UK GDPR, and the California CCPA/CPRA.

1. General Provisions & Data Controller

INFYNI ("we", "us", "Company") operates the Aegis application and related services (the "Service"). This Privacy Policy describes the categories of personal data we collect, how we use and store it, who we share it with, and the rights available to you.

Aegis provides AI-assisted research and analysis tools for publicly available market information. Aegis does not provide investment advice and is not a broker or financial adviser; outputs must be treated as informational only.

2. Information We Collect

2.1 Categories of Personal Data

CategoryExamplesWhen Collected
Account dataEmail address, display name (optional), profile image URL (social sign-in), service UIDWhen you sign up or sign in with Google
AuthenticationGoogle Sign-In tokens (validated, not persisted), email verification statusAt sign-in/refresh via Firebase Authentication
Device & pushFCM registration token, notification opt-in state, OS family & version, app version, device localeOn first launch and token rotation
Service usageWatchlist items, alert settings (price, disclosure), UI preferences (theme, sort), local search historyWhen you use in-app features
AI prompt contentNatural-language prompts and context (ticker symbols, question text) you provideWhen you request an AI analysis
DiagnosticsCrash reports, non-identifying event logsAutomatically, with your consent

2.2 Data We Do Not Collect

We do not collect precise location (GPS), contacts, call or SMS logs, raw photo/video media, health or biometric identifiers. We do not collect your brokerage credentials, bank account numbers, or payment card data.

2.3 Sources

3. Purposes and Legal Bases

PurposeDataLegal Basis
Account creation & authenticationEmail, UID, auth statePerformance of a contract (GDPR art. 6(1)(b)), consent
Core features (watchlist, preferences, alerts)Service usage dataPerformance of a contract
AI analysis request and responsePrompt contentPerformance of a contract, legitimate interests (service quality)
Push notificationsFCM token, alert settingsConsent (OS permission)
Security, fraud and abuse preventionDiagnostics, app versionLegitimate interests
Legal obligations & dispute handlingMinimum necessaryLegal obligation

4. Retention Period

5. Sharing With Third Parties

We do not sell personal data and do not share it for cross-context behavioral advertising. We share data only with the processors listed below, or with your explicit consent, or where required by law.

6. Processors & International Transfers

ProcessorFunctionData CategoriesRegionTransfer Method
Google LLC (Firebase · GCP)Authentication, Firestore, Cloud Messaging, Hosting, Crashlytics (if enabled)Account, usage, FCM token, logsUnited States and Google global regionsEncrypted transport; Standard Contractual Clauses
Google LLC (Gemini API)Generative AI responsesPrompt contentUnited StatesTLS over HTTPS; SCCs
OpenAI, L.L.C. (ChatGPT API)Generative AI responsesPrompt contentUnited StatesTLS over HTTPS; SCCs
Anthropic, PBC (Claude API)Generative AI responsesPrompt contentUnited StatesTLS over HTTPS; SCCs
Apple Inc. (APNs)iOS push notification deliveryPush tokenUnited StatesEncrypted transport

The list may be updated as our service evolves; material changes will be communicated via in-app notice or email.

7. AI Features Disclosure

8. Your Rights and How to Exercise Them

Use "Settings > Account > Delete Account" in the app to remove your data, or follow the web flow at Account Deletion. For other requests, contact us using section 15 below. We respond within 10 business days, or the timeframe required by applicable law.

9. Data Destruction

10. Security Measures

11. Cookies and Automated Collection

The mobile app does not use web cookies. We do not access advertising identifiers (IDFA/AAID) and we do not embed third-party ad or analytics SDKs that perform cross-app tracking.

12. Children's Privacy

The Service is not directed to children under 14 (or the age defined as a child by your local law). We do not knowingly collect personal data from children. If a parent or guardian becomes aware of such collection, please contact us and we will promptly delete the data.

13. California Residents (CCPA/CPRA)

14. EU/UK Residents (GDPR/UK GDPR)

15. Contact & Data Protection Officer

Operator: INFYNI
Service: Aegis (bundle ID com.infyni.aegis)
Data Protection Officer: Junwoo Yang
Email: preconsciouss@gmail.com

16. Changes to this Policy

We may update this policy from time to time. Material changes will be announced in-app or by email at least 7 days in advance (30 days where required by law).

↑ Back to top