rit.run app icon

rit.run Privacy Center

rit.run 개인정보 처리방침 · Privacy Policy

버전 1.5 · 발효일 / Effective Date: 2026-07-21 · Legal Center

Apple App Privacy disclosures, data-use purposes, and account privacy choices for rit.run.

운영자(책임자/Controller): 덴드로브 (Dendrove)

본 방침은 rit.run(이하 “앱”)에 적용됩니다. 위치기반서비스에는 별도의 위치기반서비스 이용약관이 함께 적용되며, 건강·정밀 위치정보 처리에 관한 추가 원칙은 본문과 부칙(HealthKit/Health Connect)에 따릅니다.

요약

  • 앱 기능 제공(러닝 기록/분석), 계정 운영·보안, 법적 준수, 고객 지원을 위해 필요한 정보를 수집·이용합니다.
  • 연락처 정보, 건강·피트니스, 정밀 위치, 이용자 콘텐츠, 식별자, 사용 데이터, 진단 데이터의 처리 범주를 아래에 공개합니다. 실제 App Store Connect 표시는 별도로 일치 여부를 확인해야 합니다.
  • 위치기반서비스 이용에는 별도의 위치기반서비스 이용약관이 적용됩니다.
  • 운동 기록을 게시글로 공유하는 경우 사용자가 선택한 공개 범위에 따라 운동 요약, 경로 지도, 출발/도착 지역, 사진·동영상, 본문이 Social feed에 표시될 수 있습니다.
  • 계정 없이 사용하는 게스트 운동은 이 기기의 guestFitness/v1 로컬 영역에만 저장되며, 로그인 후 사용자가 이관에 명시적으로 동의하기 전에는 Firestore, Cloud Storage 또는 운동 API로 전송되지 않습니다.
  • public 게시글과 허용 목록에 포함된 공개 소셜 정보는 계정 없는 사람에게 읽기 전용으로 표시될 수 있습니다. 응답에는 계정 UID, 원시 Storage 경로·토큰 또는 정밀 위치가 포함되지 않습니다.
  • 서비스 알림은 운동 기록/동기화 상태, 계정·보안, 서비스 변경, 고객지원 응답 등 운영상 필요한 목적으로 발송될 수 있습니다.
  • 건강 데이터정밀 위치(GPS 경로)는 기능 제공 및 러닝 분석에만 사용하며, 광고 타겟팅·판매·제3자 마케팅에 사용하거나 제공하지 않습니다.
  • 사용자는 언제든 열람·정정·삭제·처리정지·이식·동의철회를 요청할 수 있으며, 관할 감독기관에 불만 제기할 권리가 있습니다.

App Store 개인정보 라벨 요약

아래 항목은 앱 source에서 확인된 처리 범주를 사용자가 이해하기 쉽게 정리한 것입니다. App Store Connect console과의 일치 여부는 아직 확인되지 않았습니다.

연락처 정보

NameEmail Address
  • Used for Product Personalization
  • Linked to the user's identity
  • Used for tracking purposes

건강 및 피트니스

HealthFitness
  • Used for App Functionality
  • Linked to the user's identity

위치

Precise Location
  • Used for App Functionality
  • Linked to the user's identity

이용자 콘텐츠

Emails or Text MessagesPhotos or Videos
  • Emails or Text Messages: Analytics, Third-Party Advertising, Product Personalization, linked to identity, and tracking purposes
  • Photos or Videos: App Functionality and linked to identity

식별자

User IDDevice ID
  • Used for App Functionality and Product Personalization
  • Linked to the user's identity
  • Used for tracking purposes

1. 수집하는 정보

  • 계정/프로필/연락처: Google 또는 Apple 로그인으로 제공되는 이름, 이메일, 프로필 이미지, 사용자 ID/토큰; 로그인 로그(시각, 일부 IP)
  • 러닝/건강 데이터 (사용자 동의 시):
    • 정밀 위치/경로(GPS 트랙), 출발/도착 위치 요약, 거리, 속도/페이스, 이동고도, 운동 시간, 케이던스(가능 시)
    • 심박수 및 파생 통계(가능 시)
    • 신체 정보: 키, 몸무게, 생년월일, 성별(퍼포먼스 산출·개인화 목적)
  • 이용자 콘텐츠: 고객지원 이메일/메시지, Social feed 게시글 본문, 댓글, 사용자가 업로드하거나 제출하는 사진·동영상 및 관련 메타데이터
  • 게스트 모드: 게스트 연령 확인을 위한 국가 코드, 적용 최소 연령, 정책 버전, 선언 토큰의 발급·만료 시각과 App Check 무결성 신호가 Guest Public Feed 접근 제어를 위해 처리됩니다. 게스트 열람 응답에는 계정 UID, 원시 Storage 경로·토큰, 정밀 위치 또는 원시 운동 식별자를 포함하지 않습니다.
  • 서비스 알림 데이터: 알림 토큰, 알림 설정, 발송/수신 상태, 운동 기록·동기화·계정 보안·서비스 변경 관련 알림 로그
  • 기기/앱 정보 및 식별자: 기기 모델, OS/앱 버전, 언어/타임존, 내부 사용자 ID, 기기 ID, AAID/IDFA, 대략적 IP, 오류/충돌 및 성능 로그. 선택적 진단 오류 로그는 앱 내 동의가 있는 경우에만 계정과 연결해 전송합니다.
  • 사용 데이터/광고 데이터: 앱 사용 이벤트, 광고 노출/클릭, 캠페인 성과 이벤트(사용자 동의 및 플랫폼 설정에 따름)

2. 이용 목적 및 법적 근거(GDPR)

  • 계정 생성·로그인, 사용자 식별 및 접근 제어: 계약 이행
  • 운동 기록 저장, 통계/차트 제공, 개인화 분석: 계약 이행 및(해당 시) 동의
  • 제품 개인화, 앱 안정성·보안·부정행위 방지(로그/오류 분석): 정당한 이익 또는(원격 진단 오류 로그 등 해당 시) 동의
  • 고객 지원 및 문의 응대: 계약 이행/정당한 이익
  • 앱 내 광고 게재, 개발자 광고/마케팅, 제3자 광고 및 성과 측정: 동의 및 플랫폼 개인정보 설정
  • 법적 의무 준수 및 분쟁 대응: 법적 의무
  • 민감정보(건강)정밀 위치 처리: 명시적 동의

3. 민감정보·정밀 위치 처리 원칙

  • 서비스 제공·러닝 분석에 필요한 최소 범위에서만 처리합니다(목적 제한).
  • 건강, 피트니스, 정밀 위치 데이터는 광고 타겟팅, 판매, 제3자 마케팅용 공유 또는 추적 목적으로 사용/제공하지 않습니다.
  • 위치정보 수집·이용 조건, 이용자 권리 및 문의 연락처는 위치기반서비스 이용약관에도 함께 고지합니다.
  • 사용자가 운동 기록을 feed에 공유하지 않는 한 원시 경로가 공개 feed에 자동 게시되지 않습니다.
  • 동의 철회 시 신규 처리를 중단합니다(법적 보존의무나 분쟁 대응을 위한 보존은 예외).
  • 삭제 시, 원시 GPS 경로 및 건강 원본은 파기되며, 개인을 식별할 수 없는 집계/익명 처리 데이터는 서비스 품질 개선 목적으로 보존될 수 있습니다.

3-1. 게스트 모드와 Guest Public Feed

  • 게스트가 불러오거나 직접 기록한 운동은 계정 데이터와 분리된 이 기기의 로컬 저장소에 보관됩니다. 게스트 직접 기록은 로그인 후 별도 동의를 받은 경우에만 계정 영역으로 복사되며, 동의 없는 자동 업로드는 하지 않습니다.
  • Guest Public Feed는 과거와 신규 게시글에 동일하게 visibility == public 조건을 적용합니다. 별도 게시물별 publication 문서를 사용하지 않습니다.
  • 계정 없는 열람자에게는 본문, 작성자 표시 이름·handle, 제한된 운동 요약과 Backend가 전달하는 이미지 미리보기만 제공됩니다. 댓글·반응·팔로우·프로필·경로·위치·심박·칼로리·계정 식별정보는 제공하지 않습니다.
  • 작성자가 게시글을 비공개로 전환하거나 게시글·계정을 삭제하거나 계정이 비활성화되면 Backend가 fail-closed 방식으로 노출을 중단합니다.
  • 게스트 열람에는 계정 식별정보가 없으므로 로그인 상태의 차단·음소거 관계를 적용할 수 없습니다. 따라서 차단·음소거된 사람이 로그아웃한 뒤 작성자가 게스트 공개에 동의한 게시글을 볼 수 있습니다.

4. 외부 처리자, 연동 서비스 및 국외 처리

  • Firebase / Google Cloud: 계정 식별자, 프로필, 운동·건강·위치·콘텐츠, 운영 로그를 인증, 데이터베이스, Storage, API 운영 및 Analytics 목적으로 HTTPS/API 전송합니다. 확인된 배치는 Firestore nam5, Storage US-CENTRAL1, Backend asia-northeast1입니다.
  • Apple / Google 플랫폼: 사용자가 선택한 로그인, HealthKit/Health Connect 및 플랫폼 기능을 위해 계정·권한·건강 데이터가 각 플랫폼 API를 통해 처리됩니다.
  • Google Maps, OpenStreetMap, Open-Meteo: 지도, 경로 표시 및 날씨 기능을 위해 위치 또는 지도·날씨 질의가 HTTPS/API로 처리될 수 있습니다.
  • Garmin / COROS: 사용자가 연결한 경우 토큰, 운동·건강·경로 데이터가 동기화 및 연동 관리 목적으로 provider API를 통해 처리됩니다.
  • Google AdMob / Firebase Analytics: 광고 식별자, 광고·사용 이벤트, 기기/앱 정보가 광고 제공 및 측정 목적으로 처리될 수 있습니다. iOS에서는 ATT 승인 시에만 개인맞춤 광고를 요청하고, 그 외에는 비개인맞춤 광고를 요청합니다.
  • OpenAI: 운동 평가에는 필요한 운동 문맥과 자유 입력을, RunCover/배경 이미지 생성에는 선택한 이미지와 prompt 문맥을 전송할 수 있습니다. 운동 평가 요청은 store=false이고, 현재 background image workflow는 store=true를 사용할 수 있습니다. 전송은 HTTPS/API이며 standard paid API terms가 적용됩니다.
  • Google Gemini / Veo: RunCover 또는 생성형 미디어 기능에서 prompt, 이미지 및 선택된 운동 문맥이 HTTPS/API로 처리될 수 있으며 standard paid API terms가 적용됩니다.
  • ChatGPT connector: 사용자가 외부 연결을 실행한 경우 선택한 요청과 필요한 서비스 문맥이 해당 연결을 제공하기 위해 처리됩니다.
  • 이메일 제공업체: 고객지원, 권리 행사 및 운영 이메일의 주소와 본문을 전송·보관합니다. 현재 SMTP provider 설정은 배포 환경에서 확인되지 않았습니다.

Provider의 세부 처리 국가, 하위 처리자 및 보존기간은 사용 기능, 계정 설정, provider 약관에 따라 달라질 수 있습니다. 위 목록은 확인된 코드와 인프라에 따른 사실 목록이며, 계약·console·하위 처리자 검토가 완료되었다는 의미는 아닙니다. 당사는 건강·피트니스·정밀 위치 데이터를 광고 목적으로 제공하지 않습니다.

5. 보관 기간

  • 계정, 운동, 건강, 위치 및 콘텐츠: 기능 제공 중 또는 사용자가 해당 기록·계정의 삭제를 요청할 때까지 primary store에 보관합니다. 확인된 법적 보존 또는 분쟁 보존이 필요한 경우에는 근거와 기간을 별도로 적용해야 합니다.
  • Firestore 복구 데이터: PITR와 일일 backup이 활성화되어 있으며 일일 backup 보존기간은 30일입니다. 삭제 후에도 이 제한된 복구 기간 동안 잔존할 수 있습니다.
  • Cloud Storage: 삭제된 객체에는 7일 soft-delete window가 적용됩니다.
  • Cloud Logging: 확인된 `_Default` bucket은 30일, 잠긴 `_Required` bucket은 400일 보존입니다. `_Required`는 Google Cloud가 지정한 필수 audit log를 위한 것이며 일반 앱 콘텐츠 저장소로 사용하지 않습니다.
  • 선택적 앱 진단: 목표 보존기간은 30일이며 새 writer는 expiresAt을 기록하도록 준비되어 있습니다. 해당 writer는 아직 배포되지 않았고 기존 record에는 expiresAt이 없을 수 있으므로 전체 기록의 30일 삭제가 현재 입증된 것은 아닙니다.
  • 외부 provider와 지원 메시지: 해당 요청, 계정 설정 및 provider 약관에 따라 보관됩니다. provider 삭제 SLA, preservation hold 및 계약상 보존은 아직 운영 증거와 함께 조정되어야 합니다.

6. 이용자의 권리 및 행사 방법

  • 권리: 열람, 정정, 삭제, 처리 제한, 데이터 이동, 동의 철회, 자동화 의사결정에 대한 이의 제기
  • 방법: 앱 내 설정 > 프로필 > 계정삭제 또는 privacy@dendrove.com (권리 행사/일반 문의), 규제·감독기관 대응은 dpo@dendrove.com로 연락
  • 감독기관 민원: 한국 개인정보보호위원회(PIPC) 또는 거주지 관할 감독기관에 불만 제기 가능

7. 광고, 추적 및 개인화

  • 연락처 정보, 식별자, 일부 이용자 콘텐츠, 진단 및 광고 데이터의 추적 해당 여부는 기능, 사용자 동의, OS 설정 및 실제 App Store Connect 선언에 따라 판단해야 합니다.
  • 건강·피트니스·정밀 위치 데이터와 사진/동영상 원본은 광고 타겟팅에 사용되지 않습니다.
  • iOS에서는 ATT가 승인된 경우에만 개인맞춤 광고를 요청합니다. ATT 미승인·거부·제한 또는 안내 실패 시 서비스는 비개인맞춤 광고를 요청하며 앱 핵심 이용을 차단하지 않습니다. Android 광고 ID와 앱/OS 설정에서도 광고 선택을 관리할 수 있습니다.
  • (캘리포니아) 당사는 개인정보를 금전 대가로 판매하지 않습니다. 광고/측정 파트너 처리가 법령상 “공유” 또는 타겟팅 광고에 해당하는 경우, 사용자는 옵트아웃 및 민감정보 사용 제한을 요청할 수 있습니다. 이메일 제목에 [CCPA 요청]을 명시해 접수하실 수 있습니다.

8. 보안 조치

  • 전송구간 암호화(HTTPS/TLS), 저장 암호화(해당 시), 접근통제 및 최소권한, 비정상 접근 모니터링
  • 침해 발생 시 관련 법령에 따라 지체 없이 통지합니다.

9. 국제 이전

위 4항의 글로벌 provider를 이용하면 데이터가 거주국 밖에서 처리될 수 있습니다. 확인된 Google Cloud 배치는 Firestore nam5, Storage US-CENTRAL1, Backend asia-northeast1이며 전송은 HTTPS/API로 이뤄집니다. 적용 법률이 요구하는 경우 필요한 이전 근거·고지·동의 또는 계약상 보호조치를 적용합니다. 정확한 provider 하위 처리자와 계약 상태는 별도 검토 대상입니다.

10. 아동 보호

가입 최소 연령은 KR 14, US 13, GB 13, DE 16, ES 14, FR 15, IT 14이며 검토되지 않은 국가는 18세입니다. 기준 미만 사용자는 가입할 수 없고 guardian-consent flow는 제공하지 않습니다. 국가별 기준의 적정성은 법률 검토가 필요한 상태입니다.

11. 자동화 의사결정

법적 효과 또는 유사한 중대한 영향을 미치는 자동화된 의사결정을 수행하지 않습니다.

12. 지역별 고지(요약)

  • EEA/UK(GDPR/UK GDPR): 처리 근거는 위 2항 참조. 감독기관에 불만 제기 가능. 필요한 경우 EU/UK 대표를 지정하고 본 문서에 고지합니다.
  • 캘리포니아(CCPA/CPRA): 거주자는 열람/삭제/정정/옵트아웃/민감정보 사용 제한 요청 가능.
  • 대한민국(PIPA): 정보주체 권리(열람·정정·삭제·처리정지 등) 행사 가능. 국외 이전 시 보호조치 고지.

13. 연락처 및 계정/데이터 삭제

앱 내 설정 > 프로필 > 계정삭제 또는 privacy@dendrove.com으로 요청하세요. 일반 고객지원은 support@dendrove.com, 규제·감독기관 소통/법무 관련은 dpo@dendrove.com으로 연락해 주세요. 법정 보존 대상 등을 제외하고 파기합니다.

14. 변경 고지

본 방침 변경 시 앱 내 공지 또는 본 페이지의 “발효일” 갱신으로 안내합니다.

부칙: HealthKit / Health Connect 고지

  • Apple HealthKit: 수집한 건강 데이터는 기능 제공 및 개인화 분석에만 사용하며, 광고·마케팅·판매/공유 또는 추적 목적으로 사용하지 않습니다. iOS 설정에서 권한을 변경/철회할 수 있습니다.
  • Android Health Connect: 권한을 통해 접근하는 건강 데이터는 서비스 제공 목적에만 사용하며, 광고 타겟팅 또는 추적 목적으로 사용하지 않습니다. Android 설정에서 권한을 관리/철회할 수 있습니다.

Controller: Dendrove

This policy applies to the rit.run app (“App”). Location-based services are also governed by the separate Location-Based Service Terms, and additional rules for health and precise-location data are embedded throughout and in the HealthKit/Health Connect annex.

Summary

  • We collect data needed to provide features, including run logging and analysis, account operations, security, legal compliance, and customer support.
  • This policy now reflects the App Store Privacy Label categories for Contact Info, Health & Fitness, Location, User Content, Identifiers, Usage Data, and Diagnostics.
  • Location-based services are governed by the separate Location-Based Service Terms.
  • If you share a workout as a post, workout summaries, route maps, start/end areas, photos/videos, and post text may appear in the Social feed according to the visibility you select.
  • Guest workouts used without an account stay only in the guestFitness/v1 local area on this device and are not sent to Firestore, Cloud Storage, or workout APIs unless you later sign in and explicitly agree to move eligible guest-recorded workouts.
  • A public post and allowlisted public social information may appear to people without an account in read-only mode. Responses exclude account UIDs, raw Storage paths or tokens, and precise locations.
  • Service notifications may be sent for operational purposes such as workout recording or sync status, account and security events, service changes, and customer-support responses.
  • Health data and precise location / GPS routes are used for app functionality and run analysis, not for ad targeting, sale, or third-party marketing.
  • You may exercise access, rectification, deletion, restriction, portability, and withdrawal of consent at any time, and lodge a complaint with a supervisory authority.

App Store Privacy Label Summary

This section summarizes processing categories observed in the app source. Its parity with the current App Store Connect console has not been verified.

Contact Info

NameEmail Address
  • Used for Product Personalization
  • Linked to the user's identity
  • Used for tracking purposes

Health & Fitness

HealthFitness
  • Used for App Functionality
  • Linked to the user's identity

Location

Precise Location
  • Used for App Functionality
  • Linked to the user's identity

User Content

Emails or Text MessagesPhotos or Videos
  • Emails or Text Messages: Analytics, Third-Party Advertising, Product Personalization, linked to identity, and tracking purposes
  • Photos or Videos: App Functionality and linked to identity

Identifiers

User IDDevice ID
  • Used for App Functionality and Product Personalization
  • Linked to the user's identity
  • Used for tracking purposes

1. Data We Collect

  • Account/Profile/Contact Info: name, email, profile image, user IDs/tokens from Google or Apple sign-in; login logs (timestamps, partial IP)
  • Running/Health Data (with your consent):
    • Precise location / GPS routes, start/end location summaries, distance, speed/pace, elevation, workout time, cadence (if available)
    • Heart rate and derived metrics (if available)
    • Body metrics: height, weight, date of birth, gender (for performance metrics and personalization)
  • User Content: customer-support emails/messages, Social feed post text, comments, photos/videos uploaded or submitted through app features, and related metadata
  • Guest Mode: country code, applicable minimum age, policy version, declaration-token issue and expiry times, and App Check integrity signals are processed to control Guest Public Feed access. Guest responses exclude account UIDs, raw Storage paths or tokens, precise location, and raw workout identifiers.
  • Service Notification Data: notification tokens, notification settings, delivery/receipt status, and notification logs related to workout recording, sync, account security, and service changes
  • Device/App Info and Identifiers: device model, OS/app version, language/timezone, internal user ID, device ID, AAID/IDFA, coarse IP, crash/error logs, and performance logs. Optional diagnostic error logs are sent and linked to your account only after in-app consent.
  • Usage and Advertising Data: app usage events, ad impressions/clicks, and campaign performance events, subject to your consent and platform settings

2. Purposes & Legal Bases (GDPR)

  • Create/manage accounts, authenticate and control access: contract necessity
  • Store workouts, provide stats/charts, personalized analysis: contract necessity and, where applicable, consent
  • Product personalization, app stability, security, and fraud prevention: legitimate interests or, where applicable, consent
  • Customer support: contract necessity / legitimate interests
  • In-app ads, developer advertising or marketing, third-party advertising, and measurement: consent and platform privacy settings
  • Legal compliance and dispute handling: legal obligation
  • Processing of sensitive (health) and precise-location data: explicit consent

3. Handling of Sensitive & Precise Location Data

  • Processed strictly to the minimum extent for app functionality and run analysis (purpose limitation).
  • Health, fitness, and precise-location data are not used or provided for ad targeting, sale, third-party marketing, or tracking purposes.
  • Collection and use conditions, user rights, and contact details for location-information inquiries are also described in the Location-Based Service Terms.
  • Raw routes are not automatically posted to the public feed unless you share a workout to the feed.
  • Upon withdrawal of consent, we stop new processing, subject to statutory retention and dispute handling.
  • When you delete data, raw GPS traces and raw health data are erased; aggregated/de-identified statistics may be retained for service quality.

3.1 Guest Mode and Guest Public Feed

  • Workouts imported or recorded in guest mode are kept in local storage on this device, separate from account data. Eligible guest-recorded workouts are copied to an account only after a separate post-sign-in consent; there is no automatic upload without consent.
  • The Guest Public Feed applies the same visibility == public rule to historical and new posts. It does not use a separate per-post publication document.
  • Account-free viewers receive post text, author display name and handle, a limited workout summary, and image previews delivered by the backend. Comments, reactions, follows, profiles, routes, locations, heart rate, calories, and account identifiers are not provided.
  • The backend fails closed when a post becomes non-public, the post or account is deleted, or the author is no longer active and public.
  • Guest viewing has no account identity, so signed-in block and mute relationships cannot be applied. A blocked or muted person may therefore sign out and view public posts.

4. External Processors, Integrations, and Cross-Border Processing

  • Firebase / Google Cloud: account identifiers, profiles, workouts, health, location, content, and operational logs are processed for authentication, databases, Storage, API hosting, and Analytics through HTTPS/API. Verified placements are Firestore nam5, Storage US-CENTRAL1, and backend asia-northeast1.
  • Apple / Google platform services: account, permission, and health data are processed through the selected sign-in, HealthKit/Health Connect, and platform APIs.
  • Google Maps, OpenStreetMap, Open-Meteo: location or map/weather queries may be processed over HTTPS/API for map, route-display, and weather features.
  • Garmin / COROS: when connected by the user, tokens and workout, health, and route data are processed through provider APIs for synchronization and connection management.
  • Google AdMob / Firebase Analytics: advertising identifiers, ad/use events, and device/app information may be processed for advertising and measurement. On iOS, personalized ads are requested only after ATT authorization; otherwise the App requests non-personalized ads.
  • OpenAI: workout evaluation may process required workout context and free text; RunCover/background generation may process a selected image and prompt context. Workout evaluation uses store=false; the current background image workflow may use store=true. Requests use HTTPS/API under standard paid API terms.
  • Google Gemini / Veo: RunCover or generated-media features may process prompts, images, and selected workout context over HTTPS/API under standard paid API terms.
  • ChatGPT connector: when you initiate the external connection, the selected request and required service context are processed to provide that connection.
  • Email provider: addresses and message bodies are processed for support, rights requests, and operational email. The deployed SMTP provider was not verified.

Detailed processing countries, subprocessors, and retention periods may vary by feature, account setting, and provider terms. This is a factual inventory based on verified source and infrastructure, not evidence that contract, console, subprocessor, or legal review is complete. We do not provide health, fitness, or precise-location data for advertising.

5. Retention

  • Account, workout, health, location, and content data: retained in the primary store while the feature is provided or until you request deletion of the record or account. A separately identified basis and period must apply where statutory or dispute preservation is required.
  • Firestore recovery data: PITR and daily backups are enabled; daily backup retention is 30 days. Deleted data may remain recoverable during this bounded window.
  • Cloud Storage: deleted objects have a seven-day soft-delete window.
  • Cloud Logging: the verified `_Default` bucket retains data for 30 days and the locked `_Required` bucket for 400 days. `_Required` is for Google Cloud-required audit logs, not ordinary app-content storage.
  • Optional app diagnostics: target retention is 30 days and the new writer is prepared to add expiresAt. That writer is not deployed and legacy records may lack expiresAt, so 30-day deletion of all records is not yet proven.
  • External providers and support messages: retained according to the relevant request, account settings, and provider terms. Provider deletion SLAs, preservation holds, and contractual retention still require operational reconciliation.

6. Your Rights & How to Exercise

  • Rights: access, rectification, deletion, restriction, portability, withdrawal of consent, object to certain processing
  • How: in-app Settings > Profile > Delete Account, or privacy@dendrove.com (rights & general privacy), and dpo@dendrove.com for regulatory/legal matters.
  • Complaints: you may lodge a complaint with your local supervisory authority (e.g., Korea PIPC or your EEA/UK authority).

7. Ads, Tracking & Personalization

  • App Store tracking disclosures are limited to Contact Info, Identifiers, selected User Content, Diagnostics, and Advertising Data, subject to consent and OS settings.
  • Health, fitness, precise-location data, and original photos/videos are not used for ad targeting.
  • On iOS, the App requests personalized ads only after ATT authorization. If ATT is denied, restricted, unavailable, or the notice fails, the App requests non-personalized ads and does not block core use. You can also manage advertising choices through Android advertising ID and app/OS settings.
  • (California) We do not sell personal information for money. If ad/measurement partner processing is considered “sharing” or targeted advertising under applicable law, you may opt out or request limitation of sensitive data use by contacting us with subject: [CCPA Request].

8. Security

  • TLS in transit, encryption at rest (where applicable), access controls/least privilege, anomaly monitoring
  • We will notify you of breaches as required by law.

9. International Transfers

Use of the global providers in Section 4 may process data outside your country. Verified Google Cloud placements are Firestore nam5, Storage US-CENTRAL1, and backend asia-northeast1, using HTTPS/API transfers. Where applicable law requires it, we apply the required transfer basis, notice, consent, or contractual safeguards. Exact provider subprocessors and contract status remain subject to review.

10. Children

Signup minimum ages are KR 14, US 13, GB 13, DE 16, ES 14, FR 15, IT 14, and 18 for unreviewed countries. Users below the threshold cannot sign up, and no guardian-consent flow is offered. The country matrix remains subject to legal review.

11. Automated Decision-Making

We do not engage in automated decisions producing legal or similarly significant effects.

12. Regional Notices (Brief)

  • EEA/UK (GDPR/UK GDPR): see Section 2 for legal bases. You may lodge complaints with your supervisory authority. Where legally required, we will appoint and disclose our EU/UK representative here.
  • California (CCPA/CPRA): residents may request to know/delete/correct/opt out/limit sensitive data use.
  • Republic of Korea (PIPA): Data subject rights available; cross-border transfer safeguards will be disclosed where applicable.

13. Contact & Deletion

Use in-app Settings > Profile > Delete Account or privacy@dendrove.com. For general help contact support@dendrove.com; for regulatory/legal communications contact dpo@dendrove.com. Data will be erased except where retention is required by law.

14. Changes

We will announce changes via in-app notice or by updating the “Effective Date”.

Annex: HealthKit / Health Connect Notice

  • Apple HealthKit: health data is used only for features and personalized analysis; not for ads, marketing, sale/sharing, or tracking. You can change permissions in iOS Settings.
  • Android Health Connect: accessed health data is used only to provide services; not for ad targeting or tracking. You can manage permissions in Android Settings.