쉼호흡(Breathest) 개인정보처리방침
아스라소프트(Aslla Soft, 이하 "개발자")는 '쉼호흡(Breathest)' 앱(이하 "앱")과 관련하여 「개인정보 보호법」 제30조에 따라 다음과 같이 개인정보처리방침을 수립·공개합니다.
1. 핵심 요약
- 앱은 회원가입·로그인이 없고, 개발자가 운영하는 서버가 없습니다.
- 알림 시각·선택한 테마·세션 기록·직접 만든 호흡 패턴·구매 상태 캐시 등 앱 사용 데이터는 전부 이용자의 기기 안에만 저장됩니다. 개발자는 이 데이터에 접근할 수 없습니다.
- 앱이 외부로 데이터를 보내는 유일한 경로는 인앱 결제(테마 구매) 처리를 대행하는 RevenueCat, Inc.이며, 그 외 분석·광고 SDK는 없습니다.
- 건강 데이터를 수집하지 않습니다(Apple HealthKit·Android Health Connect 등 건강 플랫폼 연동 없음). 앱은 웰니스 도구이며 의료행위를 대신하지 않습니다.
2. 기기 내에만 저장되는 정보
앱은 다음 정보를 이용자의 기기 내부 저장공간에만 저장합니다. 이 정보는 개발자에게 전송되지 않습니다.
| 정보 | 용도 | 저장 위치 |
|---|---|---|
| 알림(종) 예약 시각 | 정해진 시각에 알림을 울리기 위함 | 기기 내 앱 전용 공간(로컬 알림 예약) |
| 선택한 테마·오늘의 테마 기록 | 화면·소리 구성 표시 | 기기 내 앱 전용 공간 |
| 세션 기록(호흡 세션 수행 이력) | 이용 현황을 이용자 본인에게 보여주기 위함 | 기기 내 앱 전용 공간 |
| 직접 만든 커스텀 호흡 패턴(이름 포함) | 이용자가 정의한 패턴 저장·재사용 | 기기 내 앱 전용 공간 |
| 구매 상태 캐시(엔타이틀먼트) | 오프라인에서도 구매한 테마를 바로 보여주기 위함(온라인 접속 시 RevenueCat 응답으로 갱신됨) | 기기 내 앱 전용 공간 |
- 이 정보들은 계정·이메일·전화번호 등 실명 식별자와 결합되지 않습니다.
- 앱을 삭제하면 위 데이터는 기기에서 함께 삭제되며 복구할 수 없습니다(별도 백업 기능 없음).
3. 결제 정보 및 RevenueCat 처리위탁·국외이전
- 테마 구매는 Apple App Store 또는 Google Play의 인앱 결제로 처리됩니다. 개발자는 신용카드 번호 등 결제 수단 정보를 수집하거나 전달받지 않습니다.
- 구매 처리, 구매 상태 동기화, 구매 복원(재설치 시 이미 산 테마 복구)을 위해 RevenueCat, Inc.(미국 소재)에 아래 정보의 처리를 위탁하며, 이 과정에서 정보가 국외로 이전됩니다.
- 앱은 RevenueCat이 자동 생성하는 익명 앱 사용자 ID만 사용합니다. 이름·이메일·전화번호 등 실명 식별자를 RevenueCat에 별도로 전달하지 않으며, 광고 식별자(IDFA 등)와 연동하지도 않습니다.
개인정보의 국외 이전에 관한 사항 (「개인정보 보호법」 제28조의8)
| 항목 | 내용 |
|---|---|
| 이전받는 자 | RevenueCat, Inc. |
| 이전되는 국가 | 미국 — RevenueCat이 자사 개인정보처리방침에서 "Amazon Web Services(AWS) 미국 소재 인프라에 저장한다"고 명시함 [1] |
| 이전 일시 및 방법 | 이용자가 인앱 결제(구매·구매 복원)를 실행할 때마다, 앱에 내장된 RevenueCat SDK가 네트워크(TLS 암호화 전송)로 즉시 전송 |
| 이전되는 개인정보 항목 | 구매 이력(구매한 상품 ID·구매 일시), RevenueCat이 발급한 익명 앱 사용자 ID, 기기 유형·운영체제 정보 |
| 이전받는 자의 이용 목적 | 결제(구매) 처리, 구매 상태 동기화·복원, 영수증 위변조 등 부정거래 방지, 구매 통계 제공 [2][3] |
| 이전받는 자의 보유·이용 기간 | RevenueCat의 자체 데이터 보유정책 및 개발자와 체결한 계약(Data Processing Addendum)에 따르며, 위탁 목적 달성 시까지 보유합니다. 이용자가 개발자에게 삭제를 요청하면 RevenueCat 측 삭제 절차를 통해 처리를 요청합니다 [4] |
| 이전 거부 방법·절차·효과 | 인앱 결제(테마 구매) 기능을 이용하지 않으면 이 정보는 애초에 전송되지 않습니다. 다만 앱의 유료 테마 구매·복원 기능은 이 국외 이전 없이는 제공될 수 없으므로, 이미 발생한 구매 건에 대한 이전을 사후에 거부할 경우 해당 구매의 정상 처리·복원이 불가능해질 수 있습니다 |
| 법적 근거 | 「개인정보 보호법」 제28조의8제1항제3호 — 정보주체와의 계약 체결·이행을 위해 필요한 처리위탁에 관한 사항을 개인정보처리방침을 통해 공개하는 방법으로 고지 |
- RevenueCat은 이용자 개인정보에 대해 GDPR상 처리자(processor)이며, 개발자가 관리자(controller)로서의 책임을 집니다 [4].
- RevenueCat은 자사 개인정보처리방침에서 데이터를 다른 관할권으로 이전할 경우 실사를 거치고 계약적 의무(Data Processing Addendum)를 적용한다고 명시합니다 [1][5].
4. 앱이 사용하는 기기 권한
| 권한 | 용도 | 필수 여부 |
|---|---|---|
| 알림 | 정해진 시각의 종 알림, 세션 안내(기기 내 로컬 알림) | 선택(거부 시 알림 기능만 제한) |
앱은 카메라·위치·연락처·마이크 등 다른 민감 권한을 요청하지 않습니다.
5. 개인정보의 제3자 제공
개발자는 위 3.항의 RevenueCat 처리위탁·국외이전 외에는 개인정보를 제3자에게 제공하지 않습니다. 광고·분석 목적의 제3자 제공은 없습니다.
6. 광고 및 분석 도구
앱에는 광고 SDK와 분석(애널리틱스) SDK가 없습니다. 광고 식별자(IDFA/광고 ID)를 수집하거나 다른 앱·웹사이트에서의 이용자 추적(Tracking)에 사용하지 않습니다.
7. 건강정보 관련 고지
앱은 신체 데이터를 측정하거나 Apple HealthKit·Android Health Connect 등 건강 플랫폼과 연동하지 않으며, 건강 데이터를 수집하지 않습니다. 이 앱은 웰니스 도구이며 의료행위를 대신하지 않습니다. 이 앱은 의료기기가 아니며 진단·치료를 하지 않습니다. 진료를 받고 있거나 증상이 이어진다면 의료 전문가와 상담해야 합니다.
8. 개인정보의 보유 및 이용 기간, 파기
- 기기 내 로컬 데이터: 이용자가 앱 내에서 삭제하거나 앱을 기기에서 삭제할 때까지 보유하며, 앱 삭제 시 함께 삭제됩니다.
- RevenueCat에 위탁된 구매 관련 정보: 위 3.항의 보유·이용 기간을 따릅니다.
- 관계 법령에 따른 보존: 「전자상거래 등에서의 소비자보호에 관한 법률 시행령」 제6조에 따라 대금결제 및 재화(테마)의 공급에 관한 기록은 5년, 계약 또는 청약철회 등에 관한 기록은 5년, 소비자 불만 또는 분쟁처리에 관한 기록은 3년 보존할 수 있습니다 [6]. 개발자는 자체 서버가 없어 이 기록을 별도로 보관하지 않으며, 관련 기록은 Apple/Google/RevenueCat이 각자의 정책에 따라 보관합니다.
- 위 기간 경과 또는 처리 목적 달성 시 지체 없이 파기하며, 전자적 파일 형태의 정보는 복구할 수 없는 방법으로 삭제합니다.
9. 정보주체의 권리와 행사 방법
- 로컬에 저장된 데이터(알림 시각·테마 선택·세션 기록·커스텀 패턴)는 이용자가 앱 안에서 직접 열람·수정·삭제할 수 있으며, 앱을 삭제하면 전부 삭제됩니다.
- RevenueCat에 위탁된 구매 관련 정보(익명 앱 사용자 ID·구매 이력)에 대한 열람·삭제를 원하면 아래 연락처로 요청할 수 있으며, 개발자가 RevenueCat 대시보드/API를 통해 삭제를 요청합니다.
- 만 14세 미만 아동을 포함해 앱은 연령과 무관하게 회원가입 절차나 실명 식별정보 수집이 없습니다.
10. 안전성 확보조치
- 기기 내 데이터는 운영체제가 제공하는 앱별 저장공간(iOS/Android 샌드박스)에 저장되며, 다른 앱이 접근할 수 없습니다.
- RevenueCat으로 전송되는 정보는 SDK를 통해 TLS로 암호화되어 전송됩니다 [7].
- 개발자가 운영하는 서버가 없으므로 서버 침해로 인한 대량 유출 위험 자체가 구조적으로 낮습니다.
11. 개인정보 보호책임자 및 문의처
- 상호: 아스라소프트(Aslla Soft)
- 사업자등록번호: 840-02-04238
- 개인정보 보호책임자: 이현우
- 문의: ih0995132@gmail.com
- RevenueCat, Inc. 개인정보 관련 문의: compliance@revenuecat.com [1]
12. 고지 의무
이 방침이 변경되는 경우 앱 또는 개발자 웹사이트를 통해 사전에 고지합니다.
Breathest — Privacy Policy
Aslla Soft ("the developer") publishes this privacy policy for the app "Breathest" ("the app") in accordance with Article 30 of Korea's Personal Information Protection Act (PIPA).
1. Summary
- The app has no sign-up and no login, and the developer operates no server.
- App-usage data — bell schedule, chosen theme, session history, custom breathing patterns you create, and a cached purchase status — is stored only on your device. The developer cannot access it.
- The only way the app sends data off your device is through RevenueCat, Inc., which processes in-app purchases (theme purchases). There is no analytics or advertising SDK.
- No health data is collected. The app does not integrate with Apple HealthKit, Android Health Connect, or any health platform. The app is a wellness tool and does not substitute for medical care.
2. Data stored only on your device
| Data | Purpose | Where it is stored |
|---|---|---|
| Scheduled bell/notification time | Ringing the bell at the set time | App-private storage on your device (local notification) |
| Chosen theme / today's theme record | Displaying visuals and sound | App-private storage |
| Session history | Showing your own usage to you | App-private storage |
| Custom breathing patterns you create (including their names) | Saving and reusing patterns you define | App-private storage |
| Cached purchase status (entitlements) | Showing owned themes immediately while offline (refreshed from RevenueCat when online) | App-private storage |
- None of this is combined with a real-world identifier such as an account, email, or phone number.
- Deleting the app removes this data from your device; it cannot be recovered (there is no backup feature).
3. Payments and RevenueCat processing / cross-border transfer
- Theme purchases are processed through Apple App Store or Google Play in-app purchases. The developer never collects or receives payment details such as card numbers.
- To process purchases, sync purchase status, and restore purchases after a reinstall, the app outsources processing of the data below to RevenueCat, Inc. (based in the United States), which involves an international transfer of data.
- The app uses only the anonymous app user ID that RevenueCat generates automatically. No name, email, or phone number is passed to RevenueCat, and it is not linked to an advertising identifier (such as IDFA).
International transfer disclosure (PIPA Article 28-8)
| Item | Detail |
|---|---|
| Recipient | RevenueCat, Inc. |
| Destination country | United States — RevenueCat's own privacy policy states personal data is stored on Amazon Web Services (AWS) infrastructure in the USA [1] |
| Timing and method | Sent immediately, over an encrypted (TLS) network connection, by the RevenueCat SDK embedded in the app, each time you make or restore a purchase |
| Data items transferred | Purchase history (purchased product IDs and purchase timestamps), the anonymous app user ID issued by RevenueCat, device type and OS information |
| Recipient's purpose of use | Processing payments, syncing/restoring purchase status, fraud prevention (receipt validation), and providing purchase analytics/dashboards [2][3] |
| Recipient's retention period | Governed by RevenueCat's own data retention practices and the Data Processing Addendum between the developer and RevenueCat; retained until the outsourcing purpose is fulfilled. On a deletion request to the developer, the developer requests deletion through RevenueCat [4] |
| How to refuse, and the effect of refusing | If you do not use in-app purchases, this data is never sent. However, purchasing or restoring paid themes cannot be provided without this transfer, so refusing it after a purchase has already occurred may prevent that purchase from being processed or restored normally |
| Legal basis | PIPA Article 28-8(1)(3) — outsourcing necessary for concluding and performing a contract with the data subject, disclosed through this privacy policy |
- Under the GDPR, RevenueCat acts as a processor, while the developer is the controller responsible for end-user data [4].
- RevenueCat's privacy policy states that when it transfers data to another jurisdiction, it does so following due diligence and subject to contractual obligations (its Data Processing Addendum) [1][5].
4. Device permissions used by the app
| Permission | Purpose | Required? |
|---|---|---|
| Notifications | Ringing the bell at the scheduled time, session guidance (local notification) | Optional (declining only limits notifications) |
The app does not request camera, location, contacts, microphone, or other sensitive permissions.
5. Third-party provision of personal information
Other than the RevenueCat processing/international transfer described in Section 3, the developer does not provide personal information to any third party, including for advertising or analytics purposes.
6. Advertising and analytics
The app contains no advertising SDK and no analytics SDK. It does not collect an advertising identifier (IDFA / advertising ID) and does not use one to track you across other apps or websites.
7. Health information notice
The app does not measure any physiological data and does not integrate with Apple HealthKit, Android Health Connect, or any health platform, so it collects no health data. The app is a wellness tool and does not substitute for medical care. It is not a medical device and does not diagnose or treat any condition. If you are under medical care or your symptoms persist, consult a medical professional.
8. Retention and destruction
- Local, on-device data: retained until you delete it in the app or delete the app itself; it is removed when the app is deleted.
- Purchase-related data processed by RevenueCat: governed by the retention terms in Section 3.
- Retention required by law: under Article 6 of the Enforcement Decree of Korea's Act on Consumer Protection in Electronic Commerce, records of payment and supply of goods (themes) may be kept for 5 years, records of contracts or withdrawal of subscription for 5 years, and records of consumer complaints or dispute resolution for 3 years, where the developer maintains such records directly [6]. The developer runs no server and keeps no such records itself; any such records are held by Apple, Google, or RevenueCat under their own policies.
- Data is destroyed without delay once these periods elapse or the purpose of processing is achieved; electronic files are deleted using a method that prevents recovery.
9. Your rights and how to exercise them
- You can view, change, or delete locally stored data (bell schedule, theme choice, session history, custom patterns) directly in the app; deleting the app deletes all of it.
- To request access to or deletion of the purchase-related data processed by RevenueCat (anonymous app user ID and purchase history), contact the address below; the developer will request deletion through RevenueCat's dashboard or API.
- The app has no sign-up flow and collects no real-name identifiers from users of any age, including children under 14.
10. Security measures
- On-device data is stored in the app-private storage sandbox provided by the operating system (iOS/Android) and is not accessible to other apps.
- Data sent to RevenueCat is encrypted in transit (TLS) by the SDK [7].
- Because the developer operates no server, the app is not exposed to the kind of large-scale breach risk that comes with server-side storage.
11. Privacy officer and contact
- Company: Aslla Soft
- Business registration number: 840-02-04238
- Privacy officer: Hyeonu Lee
- Contact: ih0995132@gmail.com
- RevenueCat, Inc. privacy contact: compliance@revenuecat.com [1]
12. Changes
Any change to this policy will be announced in advance through the app or the developer's website.