Newey AI

Privacy Policy

Newey AI (“we”, “us”) takes your privacy seriously and complies with applicable privacy laws. This policy explains what data we process, why, and how.

Last updated: July 27, 2026 · This version takes effect on July 21, 2026. Until then, the previous version (effective July 10, 2026) applies. The provisions on shared glossaries (Sections 2, 3, 5, and 7) take effect later, on August 21, 2026; glossary sharing will not open before that date, and nothing you have already stored is published or shared as a result of this change. The provisions on the additional sign-in options (Sections 3, 6, 7, and 8) were announced on July 23, 2026. Those describing Microsoft sign-in took effect on publication the same day — Microsoft sign-in adds no new category of data (email address and name only; no profile picture), involves no one processing data on our behalf, and your data flows to Microsoft only if you yourself choose that sign-in method. Those describing sign-in by email one-time code, which is delivered by a new processor, were first announced to take effect on July 30, 2026; later the same day, before the option was offered, that announcement was corrected and the provisions took effect on publication of the correction — the delivery processor’s data-processing agreement (including EU Standard Contractual Clauses) was already in force, this disclosure was already published, and no data reaches the processor before you yourself request a sign-in code. Nothing changes for the existing Google sign-in. The provisions on our domain, email routing, and off-site audit-record storage provider (Sections 6 and 7) were announced on July 27, 2026. Those describing what that provider already does — operating the domain name service for our website and relaying the email you send to our published contact addresses — take effect on publication, because they correct an omission: this processing has been in place since July 14, 2026 and should have been listed here then. Those describing the encrypted off-site copy of our internal security audit records take effect on August 3, 2026, after seven days’ notice, and no audit record is copied off-site before that date. The provisions on how long we keep security records, and on the limit the off-site copy places on erasure (Sections 5, 7, and 9) were also announced on July 27, 2026. Those describing what we already do — that security records are kept for two years, including after an account is deleted, and that we remove your email address and IP address from them when you ask us to erase your data — take effect on publication, because they too correct an omission rather than change anything. The provision that makes the off-site copy write-once takes effect on August 26, 2026 after 30 days’ notice, because it limits what we are able to erase; that protection is not switched on before then. The provisions on the provider that delivers our operational alerts (Sections 6 and 7) were also announced on July 27, 2026 and take effect on publication, because they too correct an omission rather than change anything: alerts about the operation of the Service — which can contain your email address in masked form, an internal account identifier, and the IP address of a sign-up attempt — have been delivered through that provider since July 11, 2026 and should have been listed here then. The provisions stating why personal data may be sent abroad and what protects it there (Section 7) and the name of our Privacy Officer (Section 14) were also announced on July 27, 2026 and take effect on publication, for the same reason: they complete what this policy should already have said rather than change anything. The agreements they describe were already in force, the person named has held that role since this policy was first published, and what we collect, why, who receives it, and how long it is kept are all unchanged.

1. Overview

This policy applies to Newey AI (newey.ai, the “Service”), our real-time interpretation caption service. We collect only the minimum personal data necessary to provide the Service, and we do not use it for any purpose other than those disclosed in this policy.

The Service is currently offered as a free beta and does not collect payment information. We do not use advertising tools, and our visit and usage analytics tools (Google Analytics, PostHog) operate only where you have consented — see Cookies and Analytics.

2. Audio and Caption Data

Your audio is not stored on or routed through our servers

Your audio is sent directly from your browser to a specialized speech-processing provider in the United States. Our servers only issue a temporary authentication key; they do not receive, store, or route your audio. The real-time transcription and translation stream (live captions) does not pass through our servers either, unless you turn on Audience sharing (off by default — see below). If you choose to save an ended session, its summary, transcript, and translation text are kept in your account (Sections 3 and 5). Private sessions and sessions you do not save are never stored on our servers.

If you turn on the Audience sharingfeature yourself (off by default), that session’s caption text is (1) displayed in real time to audience members (third parties) who hold the share link, and (2) temporarily routed through our servers to deliver it. Our servers only relay it from memory without storing the caption text, and it is immediately discarded when you turn sharing off or the session ends. You can turn sharing on and off at any time during a session.

Your display settings are kept only in your browser’s storage (localStorage) and never leave your device. Your glossary is stored in your browser as well, and a copy is also mirrored to your account so the browser extension and your other devices can read it — this account copy is stored like other account data (not end-to-end encrypted), is replaced whenever you save, and is deleted together with your account. Only you can access it, unless you publish a glossary (below). Session caption records, where you choose to save them, are retained in your account and can be accessed from multiple devices (Sections 3 and 5), with an encrypted copy also kept in the browser for immediate display.

Shared glossaries (from August 21, 2026 — off unless you publish one). The Service lets you publish one of your glossaries so that other people can install a copy of it. If you choose to publish one — and only then — we store a snapshot of that glossary on our servers, together with the listing details you provide, and make it available to anyone browsing the shared-glossary marketplace within the Service (an unlimited and unidentified group of third parties). We publish it under your account display name — the name on your account, which may be your real name if that is what your account uses (for example, the name provided by Google or Microsoft when you signed in). We show you the exact name before you publish, and you can change your display name in the Service settings; your email address is never shown. We also show listing statistics such as the number of installations. Editing your own glossary afterwards does not change the snapshot, and unpublishing it — or deleting your account — deletes the snapshot from our servers and stops further installations. It does not delete copies that other people have already installed: those copies become part of their data and cannot be recalled, by you or by us (Section 5). Nothing in your glossary is published unless you publish it.

In addition, portions of the transcript text may be sent to the API of a large language model (LLM) provider in the United States in two cases: (1) only where you have turned on the Smart Context (AI suggestions) feature yourself — this feature is off by default — and (2) where a session record is saved to your account, a short excerpt of the transcript is sent once to generate an automatic session title. In both cases the text is transmitted transiently for that processing only and is not stored by our servers. Only where we have configured a fallback, an alternative LLM provider (also in the United States) may perform the same processing.

3. Data We Collect

What we collect and process on our servers:

Personal data we process
CategoryItemsCollection method
Account informationEmail address, name, profile pictureProvided by Google when you sign in with your Google account (OAuth); provided by Microsoft (email address and name only — we do not collect your profile picture from Microsoft) when you sign in with your Microsoft account; or entered by you when you sign in with an email one-time code (email address only)
Language and region preferenceYour preferred interface language and your country or regionSet from the language settings your browser sends (Accept-Language) when you first sign up — we do not use IP-based geolocation — and editable by you at any time in the Service settings; kept as account data and deleted together with your account
Session metadataCaption session start and end times, selected languages, usage time (seconds)Generated automatically while you use the Service
Usage recordsPer-account ledger of caption usage time (monthly and daily aggregates)Generated automatically while you use the Service
Saved session records (optional)Summary, transcript, and translation text of ended sessions you choose to save, and session titlesOnly where you choose to save a session — private and unsaved sessions are excluded
Glossary (optional)Terms and background context you add to your glossaryMirrored to your account when you save it, so the browser extension and your other devices can read it — stored like other account data (not end-to-end encrypted), replaced on every save, and deleted together with your account
Shared glossary (optional — from August 21, 2026)A snapshot of the glossary you publish (terms, translation pairs, background context), the listing details you provide (listing name, description, preset icon and color choice, categories, language tags), your account display name (shown publicly as the publisher), the share code, when it was published or updated, whether it is still published, and how many times it has been installedOnly where you yourself publish a glossary — the snapshot and listing are then available to anyone browsing the marketplace (Section 2). Published under your account display name, which may be your real name unless you change it in the Service settings; we show you the name before you publish. Your email address is not shown
Content reports (optional)The report category and description you submit about a shared glossary, a contact email address if you choose to give one, and the IP address the report was sent fromOnly where you submit a report about shared content — no account is needed to report. Reports are kept as a record of what was reported and of what we did about it
Access logsIP address, browser information (User-Agent)Collected automatically while managing your login session — destroyed together with the session information when the session expires or you log out
Passkey information (optional)Public key, credential identifier, device typeOnly where you register passkey sign-in yourself — passwords and biometric data are not stored
Behavioral information (optional)Cookie and browser-storage identifiers, pages visited and usage history, and, when you are logged in, linkage to an internal user identifier (a pseudonymized ID — not your email or name)Google Analytics and PostHog — only where you consent to analytics tracking (Section 8)

We do not collect original audio, payment information, or government-issued identifiers. Transcription and translation text is not stored on our servers during real-time processing; it is processed only for session records you choose to save (the table above) and for the opt-in AI suggestion and Audience sharing features described in Section 2.

4. How We Use Your Data

  • Identifying you and maintaining your login state (account information, session cookies)
  • Managing free usage limits and preventing abuse (session metadata, usage records)
  • Operating the Service, responding to incidents, and improving quality (statistical use of session metadata)
  • Personalizing your experience and understanding, in aggregate, which languages and regions our users come from (language and region preference)
  • Improving the Service through visit and usage analytics (behavioral information — only where you consent)
  • Fulfilling legal obligations and responding to disputes

5. Data Retention

  • When you delete your account or your agreement with us ends, we destroy the personal data we have collected without delay — except for the security records described below and anything we must keep by law. You can delete your account directly in the Service settings (“My data”) or request deletion at contact@newey.ai.
  • Information we are required to retain under applicable law is kept for the period prescribed by that law — see Country-Specific Privacy Terms for examples.
  • Security records, and the encrypted off-site copy of them. We keep an internal record of security-relevant actions on the Service — such as signing in, deleting an account, exporting your data, and administrative access — noting what was done, when, the account email address, and the IP address. It contains no captions, transcripts, glossaries, or anything else you created. We keep these records for 2 years, including after an account is deleted: their purpose is to show what happened, which they cannot do if what they record can be made to disappear. If you ask us to erase your data, we remove your email address and IP address from these records, leaving only an internal account reference, the kind of action, and when it happened — and once your account is deleted, that reference no longer resolves to anyone.
  • From August 3, 2026 we also store an encrypted copy of those security records off-site (Sections 6 and 7), so that our record of a security incident does not sit only in the system such an incident would affect. From August 26, 2026 that copy is write-once: once written it cannot be changed or deleted by anyone, including us and including in response to an erasure request, until it expires and is destroyed automatically 3 years after it was written. That is longer than the 2 years above, because the copy exists to prove the records were not tampered with, and it has to outlast the originals to do that. We rely on Article 17(3)(e) of the GDPR — retention necessary for the establishment, exercise, or defence of legal claims — together with our obligation to keep our own security records; a record that can be edited on request is not a record. The copy is encrypted before it leaves our servers with a key we keep offline and never give to the provider, and we use it only to investigate a security incident, to answer an audit, or to deal with a legal claim. Until August 26, 2026 no such write-once protection is in place.
  • Data stored only in your browser (display settings and the local cache of session records) is not held by us and can be deleted by you directly in your browser. The glossary’s account copy (Section 3) is replaced whenever you save and is destroyed together with your account.
  • Session records you choose to save are retained in your account, and you can delete them individually or all at once, or export them, within the Service. When you delete your account, saved session records are destroyed together without delay.
  • Shared glossaries: a limit on erasure you should know about before you publish. A glossary snapshot you publish is retained until you unpublish it or delete your account; either destroys the snapshot on our servers without delay and stops further installations. Copies that other users have already installed are not deleted. An installed copy becomes part of that user’s own glossary — their data, on their devices and in their account — and neither you nor we can recall it. This is an inherent consequence of letting other people keep what they installed, and it is a practical limit on your right to erasure. We tell you this before you publish so that you can decide accordingly: publish nothing you may later need to withdraw from the people who already have it. Content reports (Section 3) are retained as a record of moderation even after the reported content is removed.

6. Processors and Third Parties

We use service providers (processors) to operate the Service. They process personal data only for the tasks we assign to them, and are not permitted to use it for any other purpose.

Processing overview
ProcessorTaskData processedNotes
Soniox Inc. (United States)Real-time speech recognition (speech-to-text)Audio streamed during a caption sessionSession-scoped processing using temporary credentials; not retained by us after the purpose is fulfilled
Google LLC (United States)OAuth account authentication (Sign in with Google)Email, name, profile pictureWhen you sign in with your Google account
Microsoft Corporation (United States)OAuth account authentication (Sign in with Microsoft)Email, nameWhen you sign in with your Microsoft account — we do not collect your profile picture from Microsoft
Resend (Plus Five Five, Inc., United States)Sign-in email delivery (one-time codes)Recipient email address and the one-time sign-in code contained in the emailOnly when you request a sign-in code by email — no other user data is included in the email
Railway Corp. (United States)Server and database hostingAll server-stored items in Section 3Hosting infrastructure
Cloudflare, Inc. (United States)Domain name (DNS) service, network delivery, and inbound email routingConnection data such as IP address and requested address when you reach our domain; the full content of any email you send to our published contact addressesInfrastructure for our domain. Email you send us — including requests to exercise your rights — passes through this provider on its way to our mailbox
Cloudflare, Inc. (United States) — audit record archiveOff-site storage of our internal security audit recordsA copy of our internal security and alert records, which include the account email address and IP address associated with a recorded actionTakes effect August 3, 2026; not in use before then. We encrypt each copy before it is uploaded, so this provider holds ciphertext only and has no means to read it — the decryption key is kept offline by us and is never sent to the provider
Google LLC (United States) — AI featuresAI-assisted service featuresPortions of text processed by those featuresOnly where you enable an optional AI feature (off by default) or save a session record; transmitted transiently and not retained by us. A given request is processed by one of the two providers listed for these features, depending on our service configuration at the time
Anthropic PBC (United States)AI-assisted service featuresPortions of text processed by those featuresSame conditions as the row above — one of the two providers configured for these features (for example, as a fallback)
ntfy.sh (United States)Delivery of operational alerts to the person on callAlerts about the operation of the Service. These contain an internal account identifier and your email address in masked form where an alert concerns your account (for example, a new sign-up, an account deletion, or a data export), and the IP address of a sign-up attempt where an alert concerns sign-up rate limiting. They contain no captions, transcripts, glossaries, or anything else you createdA public notification service, so we keep what is sent to the items described here. The provider does not publish where its servers are; the public service resolves into United States address space. Messages are held there only long enough to be delivered (12 hours by default) and are then deleted
Google LLC (United States) — Google AnalyticsVisit analyticsCookie identifiers, pages visited and usage historyOnly where you consent to analytics cookies (Section 8)
PostHog Inc. (United States) — EU (Germany) regionProduct usage analyticsBrowser-storage identifiers, pages visited and usage history, internal pseudonymized user identifierOnly where you consent to analytics tracking (Section 8) — data is stored on EU (Frankfurt) servers

Apart from the processing described above, we do not provide personal data to third parties and we do not sell personal data. Lawful requests from authorities based on applicable law are an exception.

7. International Data Transfers

To provide the Service, personal data is transferred internationally as set out below. If you do not want your personal data transferred abroad, you may stop using the Service and request account deletion; in that case, however, the Service cannot be provided.

These transfers are necessary to perform our contract with you — to provide the Service you have asked for — and that necessity, together with the disclosure in this section, is the basis on which they are made.

Where a provider processes personal data on our behalf, we rely on a data processing agreement with that provider which incorporates the European Commission’s Standard Contractual Clauses, together with the United Kingdom addendum where the provider offers one, so that the protection that travels with your data does not depend on the law of the country it arrives in. The Clauses themselves are published by the European Commission; if you want to know which of them we rely on for a particular transfer, ask us at the address in Section 14. Not every recipient in the table below sits under such an agreement, and we would rather name the exceptions than let the sentence above be read as covering all of them: the public notification service that delivers our operational alerts is used without an individual agreement, which is why what we send it is limited to the items its row describes; and where you sign in with an account you already hold with another company, your sign-in reaches that company under the terms you have with it.

International transfer overview
RecipientCountryContactData transferredPurpose and methodRetention period
Soniox Inc.United Statessoniox.comAudio streamed during a caption sessionReal-time speech recognition (speech-to-text) — audio transmitted over the network during a sessionUntil the purpose of processing is fulfilled
Google LLCUnited Statespolicies.google.com/privacyEmail, name, profile pictureAccount authentication (OAuth) — transmitted at sign-inIn accordance with Google account policy
Microsoft CorporationUnited Statesprivacy.microsoft.comEmail, name (no profile picture)Account authentication (OAuth) — transmitted at sign-inIn accordance with Microsoft account policy
Resend (Plus Five Five, Inc.)United Statesresend.com/legal/privacy-policyRecipient email address and the one-time sign-in code (only when you request a sign-in code by email)Sign-in email delivery — transmitted when you request a sign-in codeCodes expire within minutes; delivery records are handled in accordance with the processing contract
Railway Corp.United Statesrailway.comAccount information, session metadata, usage records, saved session records (summary, transcript, translation text — where you choose to save them), shared glossary snapshots and listing details (where you choose to publish one), and content reports submitted to usServer and database hosting — stored persistently while the Service operatesUntil account deletion
Cloudflare, Inc.United States (globally distributed network)cloudflare.com/privacypolicyConnection data such as IP address and requested address when you reach our domain; the full content of any email you send to our published contact addressesDomain name (DNS) service, network delivery, and inbound email routing — processed as your request or email passes through the networkFor the time needed to route the request or deliver the email
Cloudflare, Inc. (audit record archive)European Union (storage location) — recipient established in the United Statescloudflare.com/privacypolicyA copy of our internal security and alert records, including the account email address and IP address associated with a recorded action — encrypted by us before upload, so the recipient holds ciphertext onlyOff-site storage of security audit records — transmitted monthly. Takes effect August 3, 2026; nothing is transmitted before then3 years from the date each copy is stored, then destroyed automatically (longer than the 2 years we keep the records in our own systems — see Section 5)
Google LLC (AI features)United Statespolicies.google.com/privacyPortions of text (only when an optional AI feature is used or a session record is saved)AI-assisted service features — transmitted when the features are used; a given request is processed by one of the two providers configured for these features, depending on our service configuration at the timeUntil the purpose of processing is fulfilled
Anthropic PBCUnited Statesanthropic.comPortions of text (only when an optional AI feature is used or a session record is saved)AI-assisted service features — transmitted when the features are used; one of the two providers configured for these features (for example, as a fallback)Until the purpose of processing is fulfilled
ntfy.shUnited States (the provider does not publish a server location; the public service resolves into United States address space)ntfy.shOperational alerts about the Service, containing an internal account identifier and your email address in masked form, and the IP address of a sign-up attempt where the alert concerns sign-up rate limitingDelivery of operational alerts to the person on call — transmitted when the event occursHeld by the provider only long enough to deliver the message (12 hours by default), then deleted
Google LLC (Google Analytics)United Statespolicies.google.com/privacyCookie identifiers, pages visited and usage history (only with analytics-cookie consent)Visit analytics — transmitted while you use the ServiceUp to 14 months after collection (Google Analytics retention setting)
PostHog Inc. (PostHog)Germany (EU Frankfurt region)posthog.comBrowser-storage identifiers, pages visited and usage history, pseudonymized user identifier (only with analytics-tracking consent)Product usage analytics — transmitted while you use the ServiceUp to 1 year after collection (PostHog retention policy)

8. Cookies and Analytics

We distinguish between strictly necessary cookies required to provide the Service (such as login) and optional analytics cookies used only with your consent. We do not use cookies for advertising or personalized tracking.

Cookies in use
CookieCategoryPurposeDuration
better-auth.session_token (prefixed with __Secure- over HTTPS)NecessaryMaintaining your login session7 days (automatically extended with use)
Temporary authentication cookies such as better-auth.stateNecessaryPreventing forged requests (CSRF) during the sign-in process (Google or Microsoft OAuth)For the duration of the sign-in process (a few minutes)
newey:localeFunctionalRemembering your selected display language1 year
_ga, _ga_* (Google Analytics)Analytics (optional)Distinguishing visitors and visit/usage statisticsUp to 2 years — set only with consent
ph_* (PostHog — localStorage, not a cookie)Analytics (optional)Distinguishing visitors and product usage statistics — no cookie is setStored only with consent; collection stops when consent is withdrawn
  • Necessary and functional cookies are used without separate consent to the extent needed to provide the Service; if you block them in your browser settings, some features such as login will be unavailable.
  • Analytics cookies are set only if you accept them in the consent banner shown on your first visit. If you decline or make no choice, analytics cookies are not set. Even in that case, under Google Consent Mode a cookieless, non-identifying aggregate signal may be sent; this signal is not used to identify individual users.
  • Your consent choice is stored only in your browser (localStorage), and you can change (withdraw) it at any time below.

분석 쿠키 동의 관리

현재 상태: 확인 중…

거부로 변경하면 이후 방문 통계 수집이 즉시 중단됩니다. 이미 저장된 쿠키는 브라우저 설정에서 삭제할 수 있습니다.

9. Your Rights

  • You may request access to, correction of, deletion of, or restriction of the processing of your personal data at any time. Contact contact@newey.ai, and we will act without delay (and no later than within the statutory deadline) and inform you of the outcome.
  • You can also exercise the most common rights yourself, at any time, in the Service settings (“My data”): delete your account and the data associated with it (subject to the one limit described below), or export your data as a downloadable file.
  • One limit on erasure you should know about. The internal security records described in Data Retention are kept even after an account is deleted, and from August 26, 2026 the encrypted off-site copy of them cannot be altered or deleted at all until it expires. When you ask us to erase your data we remove your email address and IP address from those records in our live systems, and we tell you plainly that the off-site copy remains until it is destroyed automatically at the end of its period, and when that will be. We will not tell you a copy has been deleted when it has not.
  • You may exercise your rights through a legal representative or an authorized agent; we may request documentation confirming the lawful representation.
  • Additional rights that apply in your country or region — and how to lodge a complaint with your local authority — are described in Country-Specific Privacy Terms.

10. Children's Privacy

The Service is not directed at children under the age of 14 — or under any higher minimum age that applies in your jurisdiction — and we do not knowingly collect children’s personal data. If we confirm that a child’s information has been collected, we will destroy it without delay.

11. Security

  • Encryption in transit: all of the Service’s communications (including audio transmission) are encrypted with TLS.
  • Data minimization by design: real-time audio and the live transcription stream are designed not to be stored on our servers, reducing the risk of exposure; only the session records you choose to save are retained in your account.
  • Local encryption: the local cache of the glossary and session caption records stored on your device is encrypted with AES-256-GCM. The encryption key is kept in the browser’s secure storage in a non-exportable (non-extractable) form and is not transmitted externally. Saved session records are stored on managed database infrastructure, scoped so that no other user can access them; with opt-in end-to-end encryption enabled, the server stores ciphertext only.
  • Access control: secret values, such as database connection credentials, are managed only in the server environment and are not exposed to the client.
  • Session security: HttpOnly and Secure attributes are applied to authentication cookies, and the origin of API requests is verified.

12. Country-Specific Privacy Terms

  • EEA and United Kingdom (GDPR / UK GDPR). In addition to the rights in Section 9, you have the right of access (Art. 15), the right to erasure (Art. 17), the right to data portability (Art. 20), and the right to object to processing (Art. 21), and you may lodge a complaint with the supervisory authority in your place of residence. Our legal bases are performance of a contract (Art. 6(1)(b)), your consent for optional analytics (Art. 6(1)(a)), and legitimate interests (Art. 6(1)(f), preventing abuse).
  • Japan (APPI). You may request disclosure, correction, or suspension of use of your retained personal data under the Act on the Protection of Personal Information — exercise these rights as described in Section 9. Personal data is handled by processors in the countries listed in Section 7; information about the personal-data protection systems of those countries is available on request (Section 14), and by agreeing to this policy and using the Service you consent to these transfers. Our business name, address, and representative are provided without delay on request. You may also contact the Personal Information Protection Commission (ppc.go.jp) with complaints.
  • Republic of Korea. You have the rights of access, correction and deletion, and suspension of processing under the Personal Information Protection Act; the statutory retention periods referred to in Section 5 include communication log records (3 months, Protection of Communications Secrets Act) and, if the Service becomes paid, records of contracts and withdrawal of subscription (5 years, Act on Consumer Protection in Electronic Commerce). You may seek redress through the Personal Information Infringement Report Center (privacy.kisa.or.kr, dial 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972). The entrusted processors and their assigned tasks are disclosed in Section 6.
  • United States (California — CCPA / CPRA). We do not sell personal information or share it for cross-context behavioral advertising. You may request disclosure of the categories collected, as well as deletion and correction, and you will not be discriminated against for exercising your rights.
  • Other jurisdictions. If the privacy law of your country of residence grants you additional rights, those rights are not limited by this policy — contact us to exercise them.

13. Changes to This Policy

If we add to, delete from, or amend this policy, we will give notice through in-service announcements starting at least 7 days before the effective date. For material changes affecting your rights — such as new categories of data collected or new third-party disclosure — we will give notice 30 days before the effective date and, where required, obtain your consent again.

The dated list of all past revisions is available in the revision history.

For matters relating to the terms of use of the Service, please see the Terms of Service.

14. Contact

For inquiries, complaints, or remedies concerning the processing of personal data — including requests for the information described in Section 12 — contact our Privacy Officer, Joosuk Son, Representative Director, at contact@newey.ai. We will respond and act without delay.