Privacy Policy
How PaperRift handles your information.
This policy covers the PaperRift website, apps, authored Story Mode, optional AI-powered Living features, accounts, safety reports, support, and purchases.
Proposed effective: September 1, 2026 · Last updated: August 31, 2026
The Plain Works Co.,Ltd. (주식회사 더플레인웍스), business registration number 293-87-03653 (“Plain Works,” “PaperRift,” “we,” “us,” or “our”), is the controller or personal-information processor responsible for PaperRift unless a notice says otherwise.
Apple, Google, and other third parties process information under their own notices when acting independently. PaperRift is for adults and is not offered to anyone under 18.
1. Information we collect
Account, guest, and recovery data
- account or guest identifiers;
- sign-in, session, device, app-attestation, and recovery identifiers;
- age or adult-status confirmation and region or store territory; and
- settings, language, accessibility choices, and notification preferences.
Story and Living data
- titles started, choices, branch state, saves, progress, endings, relationships, and content-release version;
- personas and explicit Story Profile preferences;
- text you submit to Living, generated responses, conversation summaries, and bounded memory records;
- content-safety classifications, refusals, report identifiers, and limited investigation records; and
- content you deliberately send to support or in a report.
We do not create hidden mental-health, personality, or vulnerability diagnoses from story choices. We do not use private story text for advertising or ordinary product analytics.
Purchases and entitlements
- Apple transaction identifiers or Google purchase tokens and product identifiers;
- subscription and entitlement status, Story Credit grants and use, refunds, revocations, chargebacks, and reconciliation status; and
- limited store-country, currency, price, and tax-related metadata made available by the store.
Apple and Google process payment credentials. PaperRift does not receive your full payment-card number.
Technical, analytics, acquisition, and communications data
- IP address and request metadata for delivery, security, rate limiting, and fraud prevention;
- device and app version, operating system, locale, coarse region, performance, error, and security events;
- pseudonymous session, device, campaign, installation, and acquisition identifiers;
- event-level product analytics such as story start, scene completion, return, purchase state, and feature reliability; and
- messages, attachments, and related metadata when you contact hello@paperrift.com or legal@paperrift.com.
Raw player text, private transcripts, credentials, full receipts, and direct identifiers are prohibited from ordinary analytics and error logs.
2. Sources
We collect information directly from you and your device; from your interactions with PaperRift; from Apple or Google for verified transactions and store events; from security, analytics, model, infrastructure, and support providers acting for us; and from a person who submits a report concerning your use.
3. Why we use information
Depending on local law, our legal bases are contract performance, your request or consent, compliance with law, protection of vital interests, and our legitimate interests in operating a safe, reliable service. We use information to:
- provide Story Mode, save and synchronize state, restore access, and maintain accounts;
- generate requested Living responses and maintain bounded continuity;
- verify purchases, grant entitlements, maintain the Story Credit ledger, and process disputes;
- moderate input and output, prevent exploitation and abuse, handle reports, and secure PaperRift;
- diagnose errors, measure reliability, and improve product design without using private story text for ordinary analytics;
- answer support, privacy, legal, and rights requests; and
- send service, security, purchase, or policy notices and optional marketing only with any consent required by law.
Where Korean law requires a separate consent for a particular collection, sensitive-data use, unique-identifier use, marketing message, or overseas transfer, we will request it separately rather than treating this Policy as blanket consent.
4. Living and automated processing
When you use Living, PaperRift assembles a bounded prompt from the current fictional scene, approved character and persona data, relevant story state, and your input. A configured commercial AI provider processes that prompt to produce a response. PaperRift then applies automated safety, structure, canon, and entitlement checks before committing a response.
Living is artificial intelligence, not a human. We do not use Living or Story Profile data to make decisions with legal or similarly significant effects about employment, credit, housing, insurance, education, health care, or access to essential services.
Safety systems may refuse content, pause a generation, or flag a report for review. You may request human review of a material account or safety action at legal@paperrift.com.
We do not use private story text to train generalized PaperRift or third-party AI models. Provider processing is limited to operating the requested feature, safety and abuse controls permitted under commercial terms, and legal compliance.
5. When we disclose information
We disclose the minimum information reasonably needed to providers operating infrastructure, databases, storage, delivery, security, analytics, error monitoring, support, communications, and commercial AI; to Apple or Google for store transactions; to professional advisers and transaction counterparties under confidentiality; to authorities or others when reasonably necessary to comply with law or protect rights and safety; and to a successor in a corporate transaction subject to applicable duties.
We do not authorize providers to use private story text for their own advertising or generalized model training.
6. No sale or cross-context behavioral advertising
PaperRift does not sell personal information for money, share it for cross-context behavioral advertising, or use private story text for advertising. We use sensitive information, if any, only to provide requested features, secure PaperRift, enforce adult and safety boundaries, and comply with law—not to infer characteristics for advertising. If these practices change, we will update this Policy and provide any required control before the change.
7. Cookies and local storage
PaperRift uses necessary session and recovery cookies, a short-lived attribution cookie, and browser local storage for story continuity and a limited analytics outbox. See the Cookie and Local Storage Notice for current purposes and durations. We do not currently use third-party advertising cookies.
8. International processing
Plain Works is established in the Republic of Korea. Providers may process information in Korea, the United States, and other countries identified in our completed provider inventory. Where required, we rely on consent, adequacy decisions, contractual safeguards, or another lawful transfer mechanism and provide required overseas-transfer notices.
9. Retention
We keep information only as long as reasonably needed to provide PaperRift, honor your choices, secure systems, resolve disputes, prevent fraud, and meet legal, tax, accounting, and store obligations.
- A sealed web access session lasts no more than 6 days; a web recovery binding no more than 30 days; and verified web-attribution state no more than 5 minutes.
- Active story, profile, and Living data is kept while needed for requested history and continuity, unless you delete it or your account.
- Account deletion immediately fences new activity and removes authoritative profile, playthrough, persona, and Living content from the primary database when the deletion transaction completes.
- Pseudonymized purchase, credit-ledger, refund, deletion-receipt, security, fraud, dispute, and tax records may be retained when needed for those limited purposes.
- Support and rights-request records are retained for the request lifecycle and a reasonable period for quality, dispute, and compliance evidence.
- Backup copies and provider logs are isolated from ordinary use and age out under verified provider lifecycle schedules.
When retention ends, we delete, aggregate, or de-identify information. A legal hold or mandatory recordkeeping rule may extend retention only for affected information.
10. Your choices and rights
Subject to local law, you may request access, a portable copy, correction, deletion, restriction or objection, withdrawal of consent, human review of a qualifying automated decision, and an explanation of categories, sources, purposes, and recipients. We may verify identity proportionately. Authorized agents may submit requests where local law allows. We will not discriminate against you for exercising a privacy right.
Use in-product controls, the account-deletion page, or legal@paperrift.com. You may complain to the Personal Information Protection Commission of Korea or the privacy authority where you live.
California
If the California Consumer Privacy Act applies, California residents may request to know, access, delete, and correct personal information; opt out of sale or sharing; limit certain sensitive-information uses; and receive equal service for exercising their rights. PaperRift’s current no-sale/no-sharing practices are stated above.
EEA, United Kingdom, and Switzerland
Where applicable, you may exercise rights of access, rectification, erasure, restriction, portability, objection, consent withdrawal, and human review of qualifying automated decisions.
Canada
Where applicable, you may request access, challenge accuracy and completeness, withdraw consent subject to legal or contractual limits, and challenge our compliance.
11. Account deletion and subscriptions
Use paperrift.com/account-deletion or contact legal@paperrift.com if you cannot access the deletion flow. Do not email a password, recovery key, raw token, full receipt, or private transcript.
Deleting a PaperRift account does not cancel an Apple or Google subscription. Cancel it separately through the store.
12. Security
PaperRift uses measures designed to protect information, including encryption in transit, sealed and scoped session credentials, access controls, server-side purchase verification, release-integrity checks, data minimization, input/output safety checks, and deletion fences. No service can guarantee absolute security.
Report a suspected privacy or security incident to legal@paperrift.com. Do not conduct testing that accesses another user’s data or disrupts PaperRift.
13. Adults-only service
PaperRift is not directed to children and does not knowingly permit use by anyone under 18. If you believe a minor has used PaperRift or submitted personal information, contact legal@paperrift.com so we can investigate and delete information where appropriate.
14. Changes
We may update this Policy to reflect changes in PaperRift, law, or providers. We will post the updated date and give additional notice before a material change where required.
15. Privacy contact
Privacy Officer: JINYONG KIM
Email: legal@paperrift.com
The Plain Works Co.,Ltd.
901-C32 126, Wolbong-ro, Seobuk-gu
Cheonan-si, Chungcheongnam-do
Republic of Korea