Scope
Aegis mobile application (Android, iOS) and related online services
Published: 17 April 2026 · Effective: 17 April 2026 · Version: 1.0
This policy is drafted to comply with the Korean Personal Information Protection Act (PIPA), Google Play Data safety requirements, Apple App Store App Privacy requirements, the EU/UK GDPR, and the California CCPA/CPRA.
1. General Provisions & Data Controller
INFYNI ("we", "us", "Company") operates the Aegis application and related services (the "Service"). This Privacy Policy describes the categories of personal data we collect, how we use and store it, who we share it with, and the rights available to you.
Aegis provides AI-assisted research and analysis tools for publicly available market information. Aegis does not provide investment advice and is not a broker or financial adviser; outputs must be treated as informational only.
2. Information We Collect
2.1 Categories of Personal Data
Category
Examples
When Collected
Account data
Email address, display name (optional), profile image URL (social sign-in), service UID
When you sign up or sign in with Google
Authentication
Google Sign-In tokens (validated, not persisted), email verification status
At sign-in/refresh via Firebase Authentication
Device & push
FCM registration token, notification opt-in state, OS family & version, app version, device locale
On first launch and token rotation
Service usage
Watchlist items, alert settings (price, disclosure), UI preferences (theme, sort), local search history
When you use in-app features
AI prompt content
Natural-language prompts and context (ticker symbols, question text) you provide
When you request an AI analysis
Diagnostics
Crash reports, non-identifying event logs
Automatically, with your consent
2.2 Data We Do Not Collect
We do not collect precise location (GPS), contacts, call or SMS logs, raw photo/video media, health or biometric identifiers. We do not collect your brokerage credentials, bank account numbers, or payment card data.
2.3 Sources
Information you provide directly within the app.
Information shared by social sign-in providers (Google) within the scope you authorize.
Automatically generated telemetry created by the app SDKs during normal operation.
3. Purposes and Legal Bases
Purpose
Data
Legal Basis
Account creation & authentication
Email, UID, auth state
Performance of a contract (GDPR art. 6(1)(b)), consent
Core features (watchlist, preferences, alerts)
Service usage data
Performance of a contract
AI analysis request and response
Prompt content
Performance of a contract, legitimate interests (service quality)
Push notifications
FCM token, alert settings
Consent (OS permission)
Security, fraud and abuse prevention
Diagnostics, app version
Legitimate interests
Legal obligations & dispute handling
Minimum necessary
Legal obligation
4. Retention Period
On account deletion: we erase associated data without undue delay unless retention is required by law.
Dormant accounts: accounts inactive for 12 consecutive months may be deactivated or deleted after prior notice.
Crash/diagnostic logs: up to 90 days from collection.
FCM tokens: until the token becomes invalid or your account is removed.
AI prompts: retained only for the time necessary to serve the response; we do not use them to train the underlying models. Local conversation history can be cleared by you at any time.
Statutory retention (where applicable): e-commerce records 5 years, consumer complaints 3 years, advertising records 6 months (Korea).
5. Sharing With Third Parties
We do not sell personal data and do not share it for cross-context behavioral advertising. We share data only with the processors listed below, or with your explicit consent, or where required by law.
The list may be updated as our service evolves; material changes will be communicated via in-app notice or email.
7. AI Features Disclosure
AI features call external generative AI providers (Google Gemini, OpenAI ChatGPT, Anthropic Claude).
Your prompts and supporting context are transmitted to the selected provider and processed under their policies. We do not use them for advertising or profiling.
AI output may be inaccurate or biased and is not investment advice. Verify information with authoritative sources before acting on it.
Please avoid entering sensitive data (e.g., national IDs, financial credentials) into AI prompts.
8. Your Rights and How to Exercise Them
Right of access, rectification, erasure ("right to be forgotten").
Right to restrict or object to processing, and to withdraw consent.
Right to data portability.
Right not to be subject to solely automated decisions with legal effect.
Use "Settings > Account > Delete Account" in the app to remove your data, or follow the web flow at Account Deletion. For other requests, contact us using section 15 below. We respond within 10 business days, or the timeframe required by applicable law.
9. Data Destruction
Procedure: data is destroyed without undue delay once the purpose is fulfilled or the retention period ends.
Electronic records: permanently deleted via managed-database APIs with cryptographic key destruction where applicable.
Paper records: shredded or incinerated.
10. Security Measures
Transport security: TLS 1.2+ enforced; HSTS enabled.
Storage: managed databases with server-side AES-256 encryption.
On-device secrets: stored in iOS Keychain / Android Keystore.
Vulnerability management: dependency and Firestore Security Rules reviews.
Incident response: notifications and reporting per applicable law.
11. Cookies and Automated Collection
The mobile app does not use web cookies. We do not access advertising identifiers (IDFA/AAID) and we do not embed third-party ad or analytics SDKs that perform cross-app tracking.
12. Children's Privacy
The Service is not directed to children under 14 (or the age defined as a child by your local law). We do not knowingly collect personal data from children. If a parent or guardian becomes aware of such collection, please contact us and we will promptly delete the data.
13. California Residents (CCPA/CPRA)
You have the right to know, delete, correct, and to limit the use of sensitive personal information.
We do not "sell" personal information and do not "share" it for cross-context behavioral advertising.
You may exercise your rights via the contact in section 15; you will not be discriminated against for doing so.
14. EU/UK Residents (GDPR/UK GDPR)
You have rights of access, rectification, erasure, restriction, portability, and objection.
Legal bases include contract performance, consent, legitimate interests, and legal obligation.
International transfers rely on appropriate safeguards such as Standard Contractual Clauses.
You may lodge a complaint with your national supervisory authority.
15. Contact & Data Protection Officer
Operator: INFYNI Service: Aegis (bundle ID com.infyni.aegis) Data Protection Officer: Junwoo Yang Email:preconsciouss@gmail.com
16. Changes to this Policy
We may update this policy from time to time. Material changes will be announced in-app or by email at least 7 days in advance (30 days where required by law).