MysteryBox Back to site

Legal

MysteryBox Privacy Policy

This Privacy Policy explains how MysteryBox collects, uses, discloses, retains, and protects personal information when you use the MysteryBox app and this website, and describes the rights you have with respect to that information.

Effective date: August 22, 2026 Last updated: August 22, 2026 Applies to: MysteryBox for iOS and Android

Plain-language summary

Before the full policy below, here is what matters most, stated plainly:

  1. The photograph you submit for an appraisal is read by Ackee SLM, the model we built and run ourselves. It is not sent to any third-party AI company to produce your title, era, condition, or price estimate.
  2. We do keep the photographs you submit, and we use them to improve Ackee SLM over time. That is a real, ongoing use of your data, and we say so here rather than only in the fine print below.
  3. A short background note shown beneath your appraisal is written by a third-party language model, depending on availability Anthropic's Claude, Groq, or Google's Gemini. That request contains only the title and era our own model already determined. It never includes your photograph, your price estimate, or any other personal information.
  4. We do not sell your personal information to anyone, we do not use it for advertising, and there is no advertising or analytics SDK of any kind built into the app.
  5. You can delete a single appraisal, your entire appraisal history, or your account, at any time, from inside the app, without needing to contact us.

The rest of this Policy explains all of this, and more, in full detail.

Scope of this Policy

This Policy explains how MysteryBox ("MysteryBox," "we," "us," or "our") collects, uses, stores, shares, transfers, and protects your personal information when you use the MysteryBox mobile application, this website, or any other feature we describe as part of the "Service."

This Policy applies whenever you download or use the MysteryBox app, create an account, submit a photograph for appraisal, view or manage your appraisal history, sign in with a third-party account, or contact us through this website or by email.

MysteryBox is presently developed and operated by an independent developer rather than through a separate corporate entity. References in this Policy to "MysteryBox" mean that developer, acting as the party responsible for the Service.

By downloading, accessing, or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Service.

Information We Collect

We collect the categories of information below based on which parts of the Service you actually use, and on the principle of data minimization: we do not ask a feature to collect more than that feature needs to work.

2.1 Account and identity information

When you register, sign in, recover a password, upload a profile photo, or manage your account, we may process:

  • A username, and an email address if you provide one or sign in with a third-party account;
  • A salted password hash and a hashed one-time account-recovery code, if you register with a password;
  • The minimum profile information disclosed by a third-party sign-in provider, such as Apple, Google, Naver, or Kakao, typically a unique identifier and an email address, which may be a provider-generated relay address (for example, Apple's "Hide My Email");
  • An avatar photograph, if you choose to upload one.

2.2 Item images and appraisal data

When you photograph an item for appraisal, we process:

  • The photograph or photographs you submit ("Item Images"), typically one to two per appraisal;
  • Any descriptive note you optionally add before or after submitting an item;
  • The resulting appraisal ("Appraisal Record"): a title, an estimated era, a condition assessment, a confidence score, and a price range, together with the date and time it was generated.

2.3 Device, connection, and technical information

In the ordinary course of operating the Service, our servers automatically record:

  • IP address, request timestamp, and the API endpoint called, used for security, abuse prevention, and troubleshooting;
  • A session token issued when you sign in, used to authenticate later requests, and invalidated when you sign out or after it expires.

Your language preference and whether you have completed onboarding are stored only on your own device and are never transmitted to us.

2.4 Support and communication information

If you write to us by email or through the contact form on this website, we process the name, email address, and message content you provide, solely to respond to you.

Please do not send us your account password, or anything you would not want to appear in an email, when you write to us.

Information We Do Not Collect

Consistent with the data-minimization principle described above, the Service does not request, and contains no mechanism to collect, any of the following:

  • Precise or approximate geolocation data;
  • Contacts, calendar entries, or health, fitness, or biometric data;
  • Advertising identifiers such as IDFA, and no data used or shared for third-party advertising or cross-app tracking;
  • Browsing activity outside the Service;
  • Audio or video recordings. On Android, the system permission list includes microphone access, inherited from a third-party document-scanning library used to detect the edges of a photographed item. The Service does not record, transmit, or process audio, and no feature exercises that permission;
  • Payment card or other financial account information. MysteryBox is free to use and contains no in-app purchases or subscriptions.

We also do not integrate any third-party analytics, advertising, or crash-reporting software development kit into the app. No such component is present in the app's dependencies.

How We Use Information

We use the information described above for the following purposes, and for no purpose incompatible with them:

  1. Providing the core functionality of the Service: analyzing an Item Image to produce an Appraisal Record, and returning that result to you.
  2. Creating and maintaining your account: authenticating sign-in, preserving your appraisal history across sessions and devices, and enabling account recovery.
  3. Improving Ackee SLM. Item Images you submit are used to train and evaluate later versions of our appraisal model, for the reasons and subject to the limits described in Section 5.
  4. Responding to you when you send a question or a report through email or the contact form.
  5. Maintaining the security of the Service by detecting and preventing abuse, unauthorized access, and attempts to circumvent its safeguards.
  6. Complying with legal obligations, when processing is necessary under applicable law, regulation, legal process, or an enforceable governmental request.

We do not use your personal information to serve advertising, and we do not sell, rent, or trade it to any third party for money or anything else of value.

Automated Processing, Ackee SLM, and Third-Party AI Providers

The Service depends on machine learning models to function, so we think it is worth being precise about exactly which model sees which piece of your data, rather than describing it only in general terms.

5.1 Ackee SLM (our own model)

Every Item Image you submit is analyzed by Ackee SLM, a model we designed and that runs exclusively on infrastructure we operate. Your Item Image is not transmitted to any third-party artificial intelligence provider for this purpose. The title, era, condition, and price range shown to you are produced entirely by this first-party process.

5.2 Use of Item Images to improve Ackee SLM

We keep the Item Images you submit and use them, together with any correction you make to a result, to train and evaluate future versions of Ackee SLM. This is a real use of your data, and we would rather say so plainly here than describe it only in general language: your photographs become part of a training dataset. That data is used only to improve appraisal accuracy. We never sell it, license it to a third party, or use it to train any model besides Ackee SLM, and we never use it for advertising or profiling.

You can ask that your previously submitted Item Images be excluded from future training and deleted, as described in Sections 9 and 10. One limit worth being upfront about: a model cannot be selectively "untrained" once a training run is finished, so a request like this cannot reach back and change a model version already trained before you made it. It will, however, be honored in full for every version we build afterward.

5.3 Third-party language models used for background context

Beneath an Appraisal Record, the Service displays a short, general background note about the type and period of item identified. That note is written by a third-party large language model. Depending on which provider is available at the time, this may be a model from Anthropic, accessed through the OpenRouter API, Groq, or Google.

Whichever provider is in use receives only two fields: the title and the estimated era that Ackee SLM has already worked out. It never receives your Item Image, your price estimate, your account identifiers, your IP address, or any other personal information. By submitting an item for appraisal, you consent to this limited disclosure, for the sole purpose of generating the background note described here.

Each of these providers processes that limited, non-identifying text under its own terms, independently of us. Anthropic's own commercial terms of service state that it does not train its models on customer content submitted through its commercial API. Groq and Google publish their own data-use terms for their respective APIs, which we encourage you to review if you want the specifics of how each provider treats API content; we do not control, and are not responsible for, any provider's practices beyond the narrow request described above.

5.4 Automated decision-making

The price range and condition assessment the Service produces are automatically generated estimates. They are not a decision that produces a legal effect concerning you or similarly significantly affects you, and no Appraisal Record is used, by us or, to our knowledge, by any third party, as an automated basis for a legal, financial, insurance, or contractual decision about you. When a photograph does not support a reliable reading, the Service is built to decline and ask for a better one rather than guess, and every Appraisal Record is presented as a starting-point range, not a certified valuation.

How We Share and Disclose Information

MysteryBox does not sell your personal information, and does not share it for targeted advertising or cross-context behavioral advertising. We share or entrust the processing of information only with the following categories of recipients, and only as necessary:

  • Third-party AI providers. Anthropic, Groq, and Google, limited strictly to the title and estimated era of an item, for the purpose described in Section 5.3.
  • Sign-in providers. Apple, Google, Naver, or Kakao, solely to the extent necessary to complete an authentication request you initiate. We do not send those providers your Item Images, Appraisal Records, or notes.
  • Infrastructure providers. The hosting and network providers that run the servers the Service operates on, to the extent necessary to store your data and route your requests.
  • Legal compliance and safety. Where disclosure is required to comply with a valid legal process, such as a court order or subpoena, or to protect the rights, property, or safety of a user, the public, or ourselves, to the extent permitted and required by law.
  • Business transfer. If the Service were acquired by, merged with, or transferred to another party, your information may be transferred as part of that transaction. We would notify you, through the Service or by other reasonable means, before your information becomes subject to a different privacy policy.

We do not disclose personal information to any other third party, and in particular we do not disclose it to data brokers, advertising networks, or analytics companies, because no such recipient is integrated into the Service.

Cross-Border Data Transfers

7.1 Where your data is processed. MysteryBox is developed and operated from the Republic of Korea, and your account data and Item Images are primarily stored and processed there.

7.2 Transfers to service providers. Some of the providers we rely on are located elsewhere, including the United States, where the third-party AI providers referenced in Section 5.3 are based. When that is the case, the personal data disclosed to that provider, limited in every case to the title and estimated era of an item, may be processed outside the Republic of Korea. Where applicable law requires it, we take reasonable steps to make sure such transfers are subject to appropriate safeguards, such as the provider's own compliance with a recognized cross-border transfer mechanism.

7.3 EEA, UK, and Swiss users. If you are located in the European Economic Area, the United Kingdom, or Switzerland, any transfer of your personal data outside those regions is made under the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another transfer mechanism permitted by law. You may contact us at privacy@mysterybox.app if you would like more information about the safeguards in place for a specific transfer.

7.4 A general note. Data protection law, and the practices of the AI providers described in Section 5.3, may differ between the Republic of Korea, the United States, and your own location, including with respect to government access and available legal remedies.

Information Storage and Retention

8.1 We try not to hold on to information longer than it actually serves a purpose described in this Policy, except where a longer period is required by law, by a legal hold, or to work through a dispute. In practice, that works out to the following:

How long we keep things
What it isHow long we keep itWhy
Account information (username, email, password hash)Until you delete your accountDeleted immediately on account deletion; see Section 10
Item Images and Appraisal RecordsUntil you delete the item or your accountNo automatic expiration while your account is active
Session tokens30 daysInvalidated immediately when you sign out
Background-context text (Section 5.3)Retained indefinitelyCached against an item's title and era, not against your account
Connection and request logs (IP address, timestamp)Up to 12 monthsUsed for security and troubleshooting
Support and correspondence recordsUp to 24 monthsUsed to handle and follow up on your inquiry
Routine system backupsUp to 14 days, rollingSee Section 8.3
Legal hold dataDuration of the holdWhere required by law or a dispute

8.2 Expiration. Information beyond its retention period is deleted or irreversibly anonymized. Anonymized information is no longer personal information and may be retained afterward for statistics or service improvement, unless law requires otherwise.

8.3 Backups. The database underlying the Service is backed up on a recurring schedule and retained for a rolling period of up to fourteen days, as a safeguard against accidental data loss or corruption, before being automatically overwritten. A record deleted from the live Service may therefore continue to exist in a backup for up to that period before being permanently purged.

Your Rights

9.1 Basic rights. Depending on where you live, you may have some or all of the following rights with respect to your personal information:

  • Right to know how we process your personal information;
  • Right of access and copy, to obtain a copy of the personal information we hold about you;
  • Right to correction, to correct inaccurate personal information;
  • Right to deletion, to request that we delete your personal information, as described in Section 10;
  • Right to withdraw consent previously given, including your consent to the disclosure described in Section 5.3, without affecting processing already carried out before withdrawal;
  • Right to object or restrict processing, where applicable law provides for it;
  • Right to data portability, where applicable law provides for it, with respect to data you have given us;
  • Right to non-discrimination for exercising any of these rights;
  • Right to opt out of sale or targeted-advertising sharing (relevant to California, Virginia, and similar state residents): MysteryBox does not sell personal information and does not share it for targeted or cross-context behavioral advertising, so no opt-out mechanism is needed for either;
  • Right to lodge a complaint with a data protection regulator, as described in Section 15.

9.2 How to exercise your rights. Most of these rights are already a control inside the app: your appraisal history and account details are visible in Settings, and you can correct, delete, or export items yourself. For anything else, email privacy@mysterybox.app with the subject line "Privacy Request," and include your account's username or email address so we can verify the request.

9.3 Response timelines. Self-service actions inside the app take effect immediately. For an emailed request, we aim to respond within 30 days. Where California's CCPA/CPRA applies, we will respond within the 45-day period that law allows, extendable once by an additional 45 days for a complex request. Where the EEA/UK GDPR applies, we will respond within 30 days, extendable by up to two months for a complex request. In each case we will tell you if an extension is needed and why.

9.4 Identity verification. To protect your account, we may ask you to confirm your request from your registered email address or provide information sufficient to verify that the account is yours before we act on it.

9.5 When we may decline a request. We may decline or partially fulfill a request where doing so is necessary to comply with a legal obligation, where the request would infringe another person's rights, where there is good reason to believe the request is fraudulent or abusive, or where the underlying information is otherwise exempt from disclosure under applicable law. We will explain the reason where we can.

9.6 Remedies. If you disagree with how we have handled your request, you may lodge a complaint with your local data protection authority, as described in Section 15, or raise it with us again under Section 17.

Deleting Your Account and Data

10.1 You may delete individual items, your entire appraisal history, or your account, from within the app, without needing to contact us:

  • Deleting a single appraisal. Available from your scan history at any time.
  • Deleting your entire appraisal history. Available as a single action from the same screen.
  • Deleting your account. Available from Settings as "Delete Account."

10.2 Deleting your account is permanent and irreversible, not a deactivation. It removes your account record, active sessions, every Appraisal Record associated with it, your avatar image, and the underlying Item Image files from our active storage, immediately and without a waiting period, subject only to the short backup-retention window described in Section 8.3.

10.3 This in-app deletion mechanism is offered in accordance with Apple's App Store Review Guideline 5.1.1(v) and the equivalent Google Play policy, and satisfies a request to delete your personal information for purposes of the rights described in Section 9.

10.4 Before deleting your account, you may want to note down or screenshot any appraisal you would like to keep, since deletion cannot be undone.

Minors

11.1 The Service is not directed to children and is not designed to appeal primarily to them. We do not knowingly collect personal information from a child under 14 years of age, which is the age of consent for data-processing purposes under Korea's Personal Information Protection Act.

11.2 Where local law sets a different threshold, for example 13 years old under the United States' Children's Online Privacy Protection Act, we apply that threshold instead, and we do not collect personal information from a child under it without a parent or legal guardian's consent where one is required.

11.3 If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us at privacy@mysterybox.app, and we will take steps to delete that information and any associated account.

Information Security

12.1 Technical and organizational measures. We take reasonable measures to protect your information, including:

  • Encryption in transit between the app and our servers (HTTPS/TLS);
  • Passwords and account-recovery codes stored exclusively as salted PBKDF2-HMAC-SHA256 hashes, never in plain text or in a reversibly encrypted form;
  • Session authentication using randomly generated, server-validated tokens rather than credentials cached on our servers;
  • Item Images and account data stored on infrastructure we directly control, rather than in a publicly accessible location.

12.2 Security incident notification. If a security incident affects your personal information, we will take reasonable steps to investigate and contain it, and we will notify affected users, and any regulator to whom notice is legally required, within the timelines applicable law sets. Where the law does not specify a longer period, we aim to begin that notification within 72 hours of confirming the incident.

12.3 Your responsibilities. No method of transmission or storage is completely secure. Please use a strong, unique password, keep your device's operating system up to date, and contact privacy@mysterybox.app if you notice anything about your account that looks wrong.

Third-Party Services We Rely On

13.1 The Service depends on the third-party sign-in providers described in Section 2.1 and the third-party AI providers described in Section 5.3. This website may also link to destinations such as an app store listing.

13.2 These third parties are independently operated, and their own privacy policies and terms apply to their handling of any information they receive. We encourage you to review those policies before relying on a third-party service.

13.3 This Policy governs only MysteryBox's own collection and use of your information; it does not govern, and we are not responsible for, the practices of any third party.

Cookies and Similar Technologies

14.1 This website may use cookies or local storage to keep you signed in, remember basic preferences, and understand, in aggregate, which pages are visited. The MysteryBox mobile app does not use browser cookies; the local, on-device settings described in Section 2.3 serve the equivalent purpose there.

14.2 You can manage or delete cookies through your browser settings. Doing so may affect sign-in or other functions on this website.

14.3 We respect Global Privacy Control (GPC) signals. We do not respond separately to Do Not Track (DNT) signals, because no consistent industry standard for DNT has been adopted; in any case, we do not use tracking cookies for advertising.

Regional Privacy Rights

15.1 California (CCPA/CPRA)

If you are a California resident, you have the right to know the categories of personal information we have collected and disclosed, the right to request deletion or correction of your personal information, and the right to limit the use of sensitive personal information, each subject to the exceptions the law allows. MysteryBox does not sell personal information and does not share it for targeted or cross-context behavioral advertising, and we respect opt-out preference signals such as Global Privacy Control. We will not discriminate against you for exercising these rights. To make a request, email privacy@mysterybox.app.

15.2 European Economic Area, United Kingdom, and Switzerland (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we process your personal information on the following legal bases: performance of a contract (providing the Service you asked for), our legitimate interest (security and fraud prevention, and improving Ackee SLM as described in Section 5.2), a legal obligation, or your consent, where consent is the basis stated in this Policy, such as in Section 5.3. You have the rights described in Articles 15 through 22 of the GDPR, including access, correction, deletion, restriction, portability, and objection, and the right to lodge a complaint with the supervisory authority in your country of residence.

15.3 Notice under Korean law (Personal Information Protection Act)

Because MysteryBox is operated from the Republic of Korea and a significant part of its content and user base relates to Korea, the following notice is provided in the form required under Article 15 and related provisions of the Personal Information Protection Act ("PIPA") for information collected on the basis of your consent.

Items collected
Username; email address, if provided or supplied by a sign-in service; password, stored only in hashed form; Item Images; Appraisal Records; profile image; freeform notes; connection data (IP address, request timestamp).
Purpose of collection and use
Providing the appraisal service; account creation and authentication; keeping your appraisal history; improving Ackee SLM; responding to inquiries; keeping the Service secure.
Retention and use period
Until you withdraw consent, delete the relevant item, or delete your account, as described in Section 8, subject to the routine backup-retention period described there.
Right to refuse consent and consequences
You may decline to provide the items above. Because an Item Image is required to generate an appraisal, declining to provide one means the core appraisal feature cannot be used; account creation with only a username remains possible where you sign in without an email-based method.

MysteryBox is presently operated as an independent, single-developer project. A designated Personal Information Protection Officer, where one becomes applicable under PIPA, can be reached using the contact details in Section 18.

15.4 Other regions

To the extent required by applicable law in other jurisdictions, such as Brazil's LGPD, Canada's PIPEDA, or Australia's Privacy Act, we will honor the corresponding rights those laws provide when you contact us at privacy@mysterybox.app.

Policy Updates

16.1 We may update this Policy to reflect changes in the Service, in applicable law, or in our data practices.

16.2 If we make a material change, such as adding a new category of data we collect, a new recipient of your data, or a new purpose for using it, we will let you know inside the app, in addition to updating the "Last updated" date at the top of this page, at least 14 days before the change takes effect.

16.3 We encourage you to check back periodically. Continuing to use the Service after a revised Policy takes effect means you accept it. If you do not agree with an update, please stop using the Service and delete your account as described in Section 10.

Dispute Resolution

17.1 If you have a concern about how we have handled your personal information, please contact us first at privacy@mysterybox.app. Most concerns can be resolved this way.

17.2 If we are unable to resolve a concern directly, you may pursue the remedies described in Section 9.6 and Section 15, including lodging a complaint with your local data protection authority.

17.3 Nothing in this Policy limits any non-waivable right or remedy that mandatory law in your jurisdiction grants you.

Contact Us

If you have a question, complaint, or request regarding this Policy, your personal information, or account or data deletion, you can reach us at:

privacy@mysterybox.app for privacy questions and rights requests
support@mysterybox.app for general support

MysteryBox is developed and operated by an independent developer based in the Republic of Korea, and is not currently organized as a separate corporate entity. We aim to acknowledge and substantively respond to any request made under this Policy within 30 days.

This Policy is written in English. Where the Service or this Policy is made available in Korean or another language for your convenience, the English version governs to the maximum extent permitted by applicable law in the event of any conflict.