UnHaze 개인정보처리방침

시행일: 2026년 8월 24일 · 한일소프트(HanilSoft) · 이전 버전: 2026년 8월 16일

요약

UnHaze는 계정 기반의 유료 구독 앱입니다. 앱을 처음 실행하면 이름·이메일 없이 무작위 식별자만 있는 계정이 자동으로 만들어지고, 가입 과정 마지막의 개인정보 안내 화면에서 동의한 때부터 이용자의 기록이 당사 서버(Google Cloud Firestore, 서울 리전)에 저장됩니다. 여기에는 기분 체크인과 흡입 기록에 직접 작성한 노트 원문이 포함됩니다. 서버 저장은 기기 변경·재설치 시 기록을 복원하기 위한 것이며, 제3자에게 제공하지 않습니다.

결제는 Apple이 처리합니다. 당사는 카드번호 등 결제수단 정보를 일절 수집하지 않으며, App Store 영수증을 검증한 결과인 구독 상태(등급·만료 시각·거래 식별자)만 계정에 기록합니다.

광고·추적이 없습니다. 앱에는 광고 SDK, 제3자 분석 SDK, 어트리뷰션 SDK가 없으며, 수집하는 모든 정보는 앱 기능 제공 목적으로만 사용합니다. 이용자는 선택적으로 Apple 또는 Google 계정을 연결할 수 있고, 앱 안에서 언제든 계정과 서버의 모든 기록을 삭제할 수 있습니다.

1. 수집·처리하는 개인정보의 항목과 목적

당사는 다음 정보를 처리합니다. 모든 항목의 목적은 앱 기능 제공(계정 식별, 기록 보관·복원, 이용권 관리)이며, 광고나 프로파일링에 사용하지 않습니다.

1.1 계정·인증 정보

항목내용보유
계정 식별자최초 실행 시 자동 발급되는 무작위 식별자(Firebase Authentication UID). 이름·이메일·전화번호·기기 고유번호를 포함하지 않습니다.계정 삭제 시까지
복원 코드다른 기기에서 계정을 되찾기 위한 무작위 코드계정 삭제 시까지
소셜 로그인 정보 (선택)Apple 또는 Google 계정을 연결한 경우, 해당 제공자가 전달하는 계정 식별자와 — 제공자·이용자 설정에 따라 — 이메일 주소가 Firebase Authentication에 저장됩니다. Apple의 “이메일 가리기”를 사용하면 실제 주소 대신 익명 릴레이 주소가 전달됩니다. 당사 데이터베이스에는 연결된 제공자의 종류만 기록하며, 이메일·이름을 별도로 저장하지 않습니다.계정 삭제 시까지
기기·환경 정보앱 버전, OS 종류, 언어, 타임존(요청 헤더로 전달되어 마지막 값만 기록)계정 삭제 시까지

1.2 서버에 저장되는 기록

항목내용보유
가입 답변성별, 출생연도, 사용 빈도, 기준 흡입량, 주간 지출액·통화, 목표(줄이기/끊기), 플랜 기간, 동기·고민 선택, 알림 허용 여부계정 삭제 시까지
흡입(퍼프) 기록시각·날짜·수량·기록 출처(앱/위젯), 이용자가 작성한 노트계정 삭제 시까지
기분 체크인날짜, 기분 등급(1~5), 감정 태그, 이용자가 직접 작성한 노트 원문(최대 2,000자). 당사는 내용을 검사·분석·필터링하지 않습니다.계정 삭제 시까지
일별 집계·스트릭일별 흡입 횟수·한도·달성 상태·절약 금액, 연속일·리셋 횟수계정 삭제 시까지
금연 플랜·습관 정보시작일·기간·한도 곡선·집중 영역계정 삭제 시까지
프로필이용자가 자유롭게 입력한 표시 이름(실명을 입력할 수도 있습니다), 가입일, 아바타 이모지계정 삭제 시까지
성취·팁 상태 및 앱 설정뱃지 해금 시각·진행률, 팁 열람 시각, 테마·외관·통화·알림 시각·햅틱계정 삭제 시까지
구독 상태이용권 등급, 만료 시각, 상품 ID, Apple 거래 식별자 — App Store 영수증 검증 결과계정 삭제 시까지
서버 운영 기록Google Cloud가 자동 생성하는 요청 로그(접속 시각, IP 주소, 상태 코드, 오류 메시지). 기록의 내용(노트 포함)은 로그에 남기지 않습니다.Google Cloud 기본 보존 정책에 따름

1.3 수집하지 않는 항목

카드번호 등 결제수단 정보(결제는 Apple이 처리합니다), 전화번호, 주소, 위치 정보, 연락처, 사진, 광고 식별자(IDFA), Apple 건강(HealthKit) 앱 데이터는 수집하지 않습니다.

2. 수집 방법과 동의 시점

  1. 최초 실행: 이용자를 구분하기 위한 계정(무작위 식별자)이 자동으로 발급됩니다.
  2. 가입 과정: 가입 질문에 대한 답변은 가입 진행을 위해 단계마다 서버에 저장됩니다.
  3. 기록 동기화: 흡입 기록·기분 체크인 등 이용 중 생성되는 기록의 서버 저장은 가입 과정 마지막의 개인정보 안내 화면에서 저장 항목을 확인하고 동의한 때부터 시작됩니다. 이 화면에는 이 방침의 링크가 함께 표시됩니다.
  4. 동의 후 제어: 동의한 뒤에도 앱 내 [설정 > 동기화]에서 기기 간 동기화를 끄거나, 이 기기의 기록은 남기고 서버의 기록만 삭제([설정 > 동기화 > 서버 데이터 삭제])할 수 있습니다.
  5. 소셜 로그인: Apple·Google 계정 연결은 선택 사항이며, 이용자가 로그인 버튼을 누른 경우에만 처리됩니다.

3. 민감정보(건강 정보) 처리에 대한 동의

흡입 기록과 기분 체크인(노트 원문 포함)은 건강에 관한 정보(민감정보)에 해당합니다. 가입 과정의 개인정보 안내 화면에서 이 사실을 안내하고 동의를 받으며, 이 정보는 기록 보관·복원 목적으로만 처리하고 제3자에게 제공하지 않습니다.

4. 결제 정보의 처리

5. 기기 내 저장 · 로컬 알림 · 위젯

모든 기록은 서버와 별개로 기기(iPhone) 내부 저장소에도 보관되어, 네트워크 없이도 기록·통계 기능이 동작합니다. 알림은 기기 내 로컬 알림으로만 동작하며 푸시 서버를 거치지 않습니다. 홈 화면 위젯은 같은 기기 내 저장 영역에서 오늘 기록만 읽어 표시하며 네트워크를 사용하지 않습니다. 인증 갱신 토큰은 iOS 키체인에 저장됩니다.

앱만 삭제하면 기기의 기록은 삭제되지만 서버의 기록과 계정은 남습니다. 서버 기록까지 삭제하려면 7장의 절차에 따라 계정을 삭제하십시오.

6. 처리 위탁 및 국외 이전

당사는 서비스 운영을 위해 다음과 같이 개인정보 처리를 위탁합니다.

수탁자국가위탁 항목목적보유·이용 기간
Google Cloud Platform
(Cloud Functions · Firestore · Hosting)
대한민국(서울 리전 asia-northeast3) 1.1·1.2의 계정 정보와 기록 서버 저장·운영 계정 삭제 시까지
Google LLC
(Firebase Authentication)
미국 등 계정 식별자, 인증 요청 정보, 소셜 로그인 시 제공자 식별자·이메일 계정 발급·인증·소셜 로그인 연결 계정 삭제 시까지

기록 데이터의 저장 리전은 서울(asia-northeast3)입니다. 다만 인증(Firebase Authentication)에 관한 정보는 Google LLC의 글로벌 인프라에서 처리되어 국외(미국 등)로 이전될 수 있습니다. Google의 방침은 policies.google.com/privacy 에서 확인하실 수 있습니다. 결제 과정에서 Apple이 처리하는 정보는 Apple이 독립적으로 처리하며 당사의 위탁 범위가 아닙니다.

7. 이용자의 권리와 행사 방법

8. 개인정보의 파기

보유 기간이 지나거나 처리 목적이 달성된 개인정보는 지체 없이, 복구할 수 없는 방법으로 파기합니다.

계정을 삭제하면 서버의 모든 기록과 인증 계정이 즉시 삭제됩니다. 별도 보관본이나 백업 사본을 유지하지 않습니다. 비활성 계정을 자동으로 삭제하지는 않습니다 — 이용자가 지우기 전까지 기록은 보존되며, 이용권이 만료되어도 기록은 삭제되지 않습니다(재결제 시 그대로 복원됩니다).

9. 안전성 확보 조치

10. 제3자 제공 · 광고 · 추적

11. 만 14세 미만 아동

UnHaze는 만 14세 미만 아동을 대상으로 하지 않으며, 만 14세 미만 아동의 개인정보를 알면서 수집하지 않습니다. 만 14세 미만 아동은 법정대리인의 동의 없이 서비스를 이용해서는 안 됩니다. 만 14세 미만 아동의 정보가 수집된 사실을 알게 된 경우 support@hanilsoft.net 로 알려주시면 지체 없이 삭제하겠습니다.

12. 건강 관련 안내 (중요)

UnHaze는 기록·습관 관리 도구이며 의료 기기나 의료 서비스가 아닙니다. 앱이 보여주는 통계·팁·안내는 일반적인 정보이며, 의학적 진단·치료·처방을 대신할 수 없습니다. 건강 문제는 반드시 의사 또는 약사와 상담하십시오.

위기 상황이라면 혼자 견디지 마십시오.
자살예방 상담전화 109 · 정신건강 상담전화 1577-0199 (24시간)
생명이 위급한 상황에서는 119 로 연락하십시오.

13. 개인정보 보호책임자

보호책임자한일소프트 (HanilSoft)
연락처support@hanilsoft.net

개인정보 침해에 대한 신고·상담이 필요하신 경우 아래 기관에 문의하실 수 있습니다.

14. 방침의 변경

변경 이력:

이 개인정보처리방침의 내용이 변경되는 경우 시행 7일 전부터 이 페이지에 공지합니다. 다만 이용자의 권리에 중대한 영향을 미치는 변경(수집 항목 추가, 이용 목적 변경 등)은 시행 30일 전에 공지하며, 필요한 경우 앱 내에서 다시 동의를 받습니다.

15. 사업자 정보

상호한일소프트 (HanilSoft)
이메일support@hanilsoft.net

Privacy Policy (English)

Effective: August 24, 2026 (previous version: August 16, 2026) · HanilSoft · This English text is provided for convenience. In case of any discrepancy, the Korean version above prevails.

Summary

UnHaze is an account-based paid subscription app. On first launch an account is created automatically with only a random identifier — no name or email. From the moment you accept the privacy notice at the end of sign-up, your records are stored on our server (Google Cloud Firestore, Seoul region) so they can be restored on another device. This includes the notes you write in mood check-ins and puff records, exactly as you wrote them. Server storage exists to keep and restore your records; it is never shared with third parties.

Billing is handled by Apple. We never collect card numbers or any other payment-method details; we only record your entitlement status (tier, expiry, transaction identifier) as the result of verifying the App Store receipt.

No advertising or tracking. The app contains no advertising, third-party analytics, or attribution SDKs, and everything we process is used solely to provide app functionality. You may optionally sign in with Apple or Google, and you can delete your account and every server record from inside the app at any time.

1. What we process

Everything below is processed for app functionality only — identifying your account, keeping and restoring your records, and managing your entitlement. Nothing is used for advertising or profiling.

1.1 Account and authentication

ItemWhat it isRetention
Account identifierA random Firebase Authentication UID issued automatically on first launch. No name, email, phone number, or device identifier.Until you delete your account
Restore codeA random code that lets you recover your account on another deviceUntil you delete your account
Social sign-in (optional)If you sign in with Apple or Google, the identifier the provider supplies — and, depending on the provider and your settings, your email address — is stored in Firebase Authentication. With Apple's "Hide My Email", an anonymous relay address is supplied instead of your real one. Our own database records only which provider is linked; we do not separately store your email or name.Until you delete your account
Device and environmentApp version, OS type, language, time zone (sent as request headers; only the latest values are kept)Until you delete your account

1.2 Records stored on our server

ItemWhat it isRetention
Sign-up answersGender, birth year, usage frequency, baseline puff count, weekly spend and currency, goal (reduce/quit), plan duration, motivations and concerns, notification preferenceUntil you delete your account
Puff recordsTime, date, quantity, source (app/widget), and any note you wroteUntil you delete your account
Mood check-insDate, mood rating (1–5), emotion tags, the note text you wrote, verbatim (up to 2,000 characters). We do not inspect, analyse, or filter its content.Until you delete your account
Daily aggregates and streaksPer-day puff counts, limits, compliance status, money saved, streak and reset countsUntil you delete your account
Quit plan and habit profileStart date, duration, limit curve, focus areasUntil you delete your account
ProfileThe display name you typed freely (it may be your real name if you choose to enter one), join date, avatar emojiUntil you delete your account
Achievements, tips and app settingsBadge unlock times and progress, tip read times, theme, appearance, currency, reminder times, hapticsUntil you delete your account
Subscription statusEntitlement tier, expiry time, product ID, Apple transaction identifier — the result of verifying the App Store receiptUntil you delete your account
Server operational logsRequest logs generated automatically by Google Cloud (time, IP address, status code, error text). Record content, notes included, is never logged.Per Google Cloud's default retention

1.3 What we do not collect

We do not collect payment-method details such as card numbers (Apple handles billing), phone numbers, postal addresses, location, contacts, photos, advertising identifiers (IDFA), or Apple Health (HealthKit) data.

2. When data is collected and consented to

  1. First launch: an account (random identifier) is issued automatically to tell users apart.
  2. Sign-up: your answers to the sign-up questions are saved to the server step by step as part of enrolment.
  3. Record sync: server storage of the records you create while using the app — puff records, mood check-ins, and the rest — begins only after you review and accept the privacy notice screen at the end of sign-up, which lists what is stored and links to this policy.
  4. After consenting, you can turn cross-device sync off in [Settings > Sync], or delete only the server copy while keeping this device's records ([Settings > Sync > Delete server data]).
  5. Social sign-in is optional and processed only when you tap a sign-in button.

3. Consent for health-related data

Puff records and mood check-ins (including note text) are information concerning health, treated as sensitive personal data under Korean law. The sign-up privacy notice states this before your records are stored, and this data is processed only to keep and restore your records — never shared with third parties.

4. Payments

5. On-device storage, local notifications, and the widget

All records are also kept in the app's local database on your iPhone, independent of the server, so logging and statistics work without a network connection. Notifications are scheduled locally on the device and pass through no push server. The home-screen widget reads only today's records from on-device shared storage and uses no network. The authentication refresh token is kept in the iOS Keychain.

Deleting only the app removes the device's records, but your account and the server's records remain — to remove those too, delete your account as described in section 7.

6. Processors and international transfer

ProcessorCountryDataPurposeRetention
Google Cloud Platform
(Cloud Functions · Firestore · Hosting)
Republic of Korea (Seoul region asia-northeast3) Account data and records in 1.1–1.2 Server storage and operations Until you delete your account
Google LLC
(Firebase Authentication)
United States and others Account identifier, authentication requests, and — with social sign-in — provider identifier and email Issuing and verifying accounts; social sign-in Until you delete your account

Your records are stored in the Seoul region (asia-northeast3). Authentication data handled by Firebase Authentication is processed on Google LLC's global infrastructure and may be transferred outside Korea (including to the United States); see policies.google.com/privacy. Payment data processed by Apple is handled by Apple independently and is outside our processing scope.

7. Your rights and choices

8. Deletion

Personal data whose retention period has ended or whose purpose has been fulfilled is destroyed without delay, using irrecoverable methods. Deleting your account immediately removes every server record and the authentication account. We keep no separate archive or backup copy. We do not auto-delete inactive accounts — your records are preserved until you delete them, and an expired entitlement never deletes your records (they are restored as-is when you subscribe again).

9. Security

All traffic between the app and our server uses HTTPS/TLS. The server database rejects all direct client access; only authenticated requests through our API are permitted, and every request passes token verification. Data is isolated per account, with no path to another account's data. The refresh token is kept in the iOS Keychain. Server logs never contain record content, including notes — only record type, identifier, and time.

10. No sale, advertising, or tracking

We do not sell your data or share it for advertising. The app contains no advertising, third-party analytics, or attribution SDKs and does not request App Tracking Transparency permission. Disclosure to authorities occurs only where required by applicable law.

11. Children

UnHaze is not directed to children under 14, and we do not knowingly collect their personal information. Children under 14 should not use the service without the consent of a legal guardian. Contact support@hanilsoft.net and we will delete such information promptly.

12. Health notice

UnHaze is a tracking and habit-management tool, not a medical device or a medical service. Its statistics, tips, and guidance are general information and cannot replace diagnosis, treatment, or prescription. Consult a doctor or pharmacist for health concerns.

If you are in crisis, you don't have to face it alone. In Korea, call 109 (suicide prevention) or 1577-0199 (mental health), available 24 hours; call 119 for medical emergencies. In the US, call or text 988. Elsewhere, contact your local emergency services.

13. Contact

HanilSoft · support@hanilsoft.net

14. Changes

Change history: August 24, 2026 — fully revised for accounts (automatic issuance, Apple/Google sign-in), paid subscriptions (App Store billing), and sync consent given during sign-up; descriptions of features not shipped in this version were removed. August 16, 2026 — added cross-device sync (including note text), processors, and deletion procedures. Changes are posted on this page at least 7 days before taking effect, or 30 days in advance where the change materially affects your rights, in which case we may ask for consent again in the app.