Chaeon Studio (the "Company") complies with the Personal Information Protection Act and other applicable laws, and establishes and discloses this Privacy Policy to protect users' personal information and respect their rights.
1. Personal Information Collected and Collection Methods
The Company collects the minimum personal information necessary to provide the Service. The items and methods are as follows.
| Category | Items collected | Method |
|---|---|---|
| Guest | Routine/record/note data, anonymous device identifier (deviceId) | Stored on device (not sent to server) |
| Member login | Email address, social login identifier (Google/Apple `sub`), name (optional), issued token (JWT) | At login |
| Backup & sync | Routine/record/note data | When uploaded to server after login |
| Paid subscription (IAP) | Purchase receipt information, subscription status/expiry | At purchase/verification (no payment method or card data collected) |
| Notifications | Push token | When notifications are allowed |
| Diagnostics & analytics | Crash logs, performance data, anonymous/pseudonymous events, device/OS info | During app use (with consent) |
- Guest data is stored only on the device and is not transmitted to the server.
- The Company does not collect location, contacts, photos, or advertising identifiers (IDFA). The Service does not use location.
- Payments are processed by Apple/Google; the Company does not collect or store payment method information such as credit card numbers.
2. Purposes of Processing
The Company processes the collected personal information only for the following purposes.
- Providing the Service: routine management, recording, statistics, and reminders
- Member management: login authentication, identity verification, and prevention of fraudulent use
- Backup & sync: storing Member data and providing cross-device continuity
- Subscription management: verifying purchase receipts and confirming subscription status
- Service improvement: crash diagnostics and anonymous usage analytics (with consent)
3. Retention and Use Period
1. Member personal information is retained until account withdrawal (deletion) and is permanently destroyed without delay upon a deletion request.
2. Guest data exists only on the device and is erased when the app is deleted.
3. Where applicable laws require retention for a certain period, such information is stored separately for the statutory period and then destroyed.
- Records of contracts, payments, and withdrawal of subscription under the Act on Consumer Protection in Electronic Commerce: 5 years
- Service use log records under the Protection of Communications Secrets Act: 3 months
4. Provision to Third Parties
The Company does not sell users' personal information or provide it to third parties beyond the purposes stated in this Policy, except where based on law or upon a lawful request by an investigative agency.
5. Outsourcing of Processing
For stable provision of the Service, the Company outsources personal information processing tasks as follows. Each processor handles personal information only within the scope of the outsourced purpose.
| Processor | Outsourced task | Items processed |
|---|---|---|
| Amazon Web Services | Server and database hosting | Member info, backup data |
| Apple, Google | Social login authentication, in-app payment processing | Login identifiers, receipts |
| Expo (EAS) | App update delivery, push notification sending | Push token, anonymous device identifier |
| Sentry | Crash and error diagnostics | Anonymous/pseudonymous diagnostic data (no PII) |
| PostHog | Anonymous product usage analytics | Anonymous/pseudonymous events (no PII) |
Diagnostics and analytics tools are configured not to transmit personal information (PII), and users can opt out of analytics data collection in the app settings.
6. Personal Information of Children Under 14
The Service does not primarily target children under the age of 14 and does not knowingly collect their personal information. If the Company becomes aware that a child's personal information has been collected, it destroys it without delay.
7. Notice on Data Tracking and Advertising Identifiers
The Service does not use IDFA, advertising identifiers, or cross-app tracking. Accordingly, it does not request Apple App Store App Tracking Transparency (ATT) consent, and reports "not used for tracking" in App Privacy and Google Play Data Safety.
8. Rights of Data Subjects and How to Exercise Them
1. Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information.
2. Users can request immediate deletion of their account and server data through "Settings → Delete account" in the app. To delete part of the data while keeping the account, users may contact chaeon.studio@gmail.com.
3. Rights may be exercised in writing, by email, and similar means, and the Company will act without delay.
9. Procedure and Method of Destruction
1. The Company destroys personal information without delay when the retention period has elapsed or the processing purpose has been achieved.
2. Information in electronic file form is permanently deleted by technical means that prevent recovery, and printed materials are shredded or incinerated.
10. Measures to Ensure Security
The Company takes the following measures for the safe processing of personal information.
- Encryption of data in transit (HTTPS)
- Minimization of access privileges to personal information and access control
- Secure storage of authentication tokens and secrets (e.g., Secrets Manager)
- Management of database access logs and prevention of external exposure
11. Processing of Push Notification Tokens
Where a user has allowed notifications, the Company processes the push token to send notifications. Users can stop receiving notifications at any time by disabling them in device settings.
12. Data Protection Officer
The Company designates the following Data Protection Officer to take overall responsibility for personal information processing and to handle user complaints and remedies.
- Data Protection Officer: Chaeyeon Seo
- Contact: chaeon.studio@gmail.com
13. Remedies for Rights Infringement
Users may apply for dispute resolution or consultation with the following organizations in Korea to obtain relief from personal information infringement.
- Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr)
- Personal Information Infringement Report Center (118, privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Division (1301, www.spo.go.kr)
- National Police Agency Cyber Bureau (182, ecrm.police.go.kr)
14. Duty to Notify
Any addition, deletion, or modification of this Privacy Policy will be announced in advance, together with the effective date and the changes, within the Service or on the Company website (chaeon.studio).