개인정보 처리방침

숨결 (Soomgyul) · 시행일 2026년 8월 17일 · 버전 1.1

요약

1. 기기에만 저장되는 정보

아래 정보는 운영체제가 제공하는 앱 전용 저장소에 기록되며, 앱은 이를 외부로 전송하는 코드를 포함하고 있지 않습니다.

이 정보에는 이름, 전화번호, 생년월일 등 직접적인 식별 정보가 포함되지 않습니다. 앱은 그런 정보를 묻지 않습니다. 이메일 주소는 사용자가 직접 로그인을 선택한 경우에만 사용되며, 그 처리는 아래 3항에서 설명합니다.

2. 건강 데이터 (Apple 건강 · Health Connect)

사용자가 앱 안에서 건강 연동을 켜고 시스템 권한 시트에서 명시적으로 허용한 경우에만, 숨결은 iOS의 Apple 건강(HealthKit) 또는 Android의 Health Connect에서 다음 데이터를 읽기 전용으로 가져옵니다. 두 플랫폼 모두에서 앱은 건강 데이터를 쓰지 않습니다. 허용하지 않아도 나머지 기능은 모두 그대로 동작합니다.

데이터사용 목적
심박수세션 직전·직후 구간의 평균 심박을 비교해 “이번 세션의 효과” 카드를 계산
안정 시 심박수주 단위 추이 표시, 개입 알림의 기준선(baseline) 계산
심박 변이도(HRV, RMSSD)주 단위 추이 표시(기기가 값을 제공하는 경우에 한함)
수면 세션저녁 세션 수행 여부와 수면 기록의 관계를 사용자 본인이 보도록 표시
걸음 수심박 상승이 운동 때문인지 구분하기 위한 보조 신호. 걷는 중에는 알림을 보내지 않기 위해 사용

백그라운드 읽기

“긴장 감지 알림” 기능을 켠 경우, 앱은 백그라운드에서 주기적으로(약 15분 간격) 최근 구간의 심박·걸음 수를 읽습니다. Android에서는 READ_HEALTH_DATA_IN_BACKGROUND 권한을, iOS에서는 시스템의 백그라운드 앱 새로 고침(BGAppRefreshTask)을 사용합니다. 이 판정은 전적으로 기기 안에서 이루어지며, 판정 결과로 발송되는 알림도 기기가 직접 띄우는 로컬 알림입니다. 서버를 경유하는 푸시 알림이 아닙니다.

전송하지 않습니다

읽어온 건강 데이터와 그로부터 계산한 값(예: 심박 변화량)은 기기 저장소에만 남습니다. 개발자를 포함해 누구도 이 데이터를 원격에서 조회할 수 없습니다.

Apple Watch용 앱이 함께 설치된 경우, 워치 앱도 자신의 HealthKit 권한을 요청해 세션 중 심박수를 읽고 이를 iPhone으로 직접 전달합니다. 이 데이터 역시 두 기기를 벗어나지 않습니다.

3. 계정과 구매 정보 (Firebase · RevenueCat)

계정 (Firebase Authentication)

앱은 실행 시 Google LLC의 Firebase Authentication에 익명으로 로그인합니다. 이 과정은 자동으로 이루어지며, 그 결과 Firebase가 생성한 무작위 식별자(uid) 하나가 만들어집니다. 이때 Firebase는 통신에 수반되는 정보(IP 주소, 기기·앱 정보 등)를 함께 처리합니다. 익명 계정에는 이름이나 이메일이 연결되지 않습니다.

로그인은 선택 사항입니다. 프로필 탭 → 계정에서 이메일·Google·Apple로 로그인하면, 해당 자격 증명이 기존 익명 계정에 연결되고 다음 정보가 Firebase로 전달됩니다.

목적은 계정 식별과 구독 복원이며, 광고나 행태 분석에 사용하지 않습니다. 로그인 여부와 관계없이 어떤 기능도 잠기지 않습니다. 비밀번호는 Firebase Authentication이 처리하며 앱은 저장하지 않습니다. 측정값, 세션 기록, 스크리닝 답변, 건강 데이터는 Firebase로 전송되지 않습니다. Firebase의 처리 내용은 firebase.google.com/support/privacy를 참고하세요.

로그인한 계정은 앱 안에서 직접 삭제할 수 있습니다(5항 참조).

구매 정보 (RevenueCat)

숨결 플러스 구독을 구매하거나 복원할 때, 구독 상태 확인을 위해 RevenueCat, Inc.의 SDK가 다음 정보를 처리합니다.

목적은 구매 검증과 기기 간 구독 복원에 한정되며, 광고나 행태 분석에 사용하지 않습니다. 결제 수단 정보(카드번호 등)는 앱도 RevenueCat도 받지 않습니다. 결제는 Apple App Store 또는 Google Play가 처리합니다.

RevenueCat의 처리 내용은 revenuecat.com/privacy를 참고하세요.

건강 데이터, 측정값, 스크리닝 답변은 RevenueCat으로 전송되지 않습니다.

4. 수집하지 않는 것

숨결은 App Tracking Transparency 정의상의 추적(tracking)을 하지 않습니다. 다른 회사의 데이터와 결합해 광고 목적으로 사용하는 일이 없으므로 ATT 동의 요청도 표시하지 않습니다.

5. 권한 철회와 데이터 삭제

6. 보관 기간

기기 내 데이터(측정·세션·스크리닝 답변·건강 데이터)는 사용자가 삭제하기 전까지 기기에 남으며, 개발자가 보관하는 사본이 없습니다. 계정 기록은 계정이 삭제될 때까지 Firebase에 남고, 구매 관련 기록은 RevenueCat과 각 앱 스토어의 보관 정책을 따릅니다.

7. 아동

숨결은 만 13세 미만(대한민국 기준 만 14세 미만) 아동을 대상으로 하지 않으며, 아동으로부터 개인정보를 의도적으로 수집하지 않습니다.

8. 변경 및 문의

이 방침이 변경되면 이 페이지의 시행일과 버전을 갱신합니다. 데이터 처리 방식이 실질적으로 바뀌는 경우(예: 서버 동기화 도입) 앱 안에서도 별도로 알립니다.

문의: entanglecare@gmail.com

English

Privacy Policy

Soomgyul (숨결) · Effective 17 August 2026 · Version 1.1

Summary

1. Information stored on your device

The following is written to the app's own storage area provided by the operating system. The app contains no code that transmits it anywhere.

None of this includes directly identifying information such as your name, phone number or date of birth. The app never asks for it. An email address is involved only if you choose to sign in, and is handled as described in section 3.

2. Health data (Apple Health · Health Connect)

Only if you turn the health integration on in the app and then explicitly grant permission in the system sheet, Soomgyul reads the following from Apple Health (HealthKit) on iOS or Health Connect on Android, read-only. On both platforms the app never writes health data back. Declining leaves every other part of the app working normally.

DataWhat it is used for
Heart rateComparing the average heart rate just before and just after a session, to show a "session effect" card
Resting heart rateWeekly trend, and the baseline used by the tension-detection nudge
Heart rate variability (RMSSD)Weekly trend, where your device provides the value
Sleep sessionsLetting you see, for yourself, how evening sessions line up with your sleep record
StepsA supporting signal to tell exercise-driven heart rate apart from tension, so no nudge is sent while you are moving

Background reads

If you turn on the tension-detection nudge, the app periodically (roughly every 15 minutes) reads a recent window of heart rate and step data in the background — using the READ_HEALTH_DATA_IN_BACKGROUND permission on Android, and the system's background app refresh (BGAppRefreshTask) on iOS. That evaluation happens entirely on your device, and any resulting notification is a local notification raised by the device itself — not a push notification routed through a server.

Never transmitted

Health data read from Health Connect, and anything computed from it (such as a heart-rate delta), stays in on-device storage only. Nobody, including the developer, can retrieve it remotely.

If the Apple Watch app is installed, it requests its own HealthKit authorisation to read your heart rate during a session and relays it directly to your iPhone. That data likewise never leaves the two devices.

3. Account and purchase data (Firebase · RevenueCat)

Account (Firebase Authentication)

At launch the app signs in anonymously to Firebase Authentication, operated by Google LLC. This happens automatically and produces a single random identifier (a uid). Firebase also processes what is inherent to that request — your IP address and device/app information. No name or email is attached to an anonymous account.

Signing in is optional. If you sign in with email, Google or Apple from Profile → Account, the credential is linked to your existing anonymous account and the following is passed to Firebase:

This is used to identify your account and restore your subscription, never for advertising or behavioural analytics. No feature is locked behind signing in. Your password is handled by Firebase Authentication and is never stored by the app. Measurements, session logs, screening answers and health data are never sent to Firebase. See firebase.google.com/support/privacy for what Firebase processes.

A signed-in account can be deleted from inside the app (see section 5).

Purchase data (RevenueCat)

When you buy or restore a Soomgyul Plus subscription, the SDK of RevenueCat, Inc. processes:

This is used solely to validate purchases and restore subscriptions across your devices, never for advertising or behavioural analytics. Neither the app nor RevenueCat receives your payment details; payment is handled by the Apple App Store or Google Play.

See revenuecat.com/privacy for what RevenueCat processes.

Health data, measurements and screening answers are never sent to RevenueCat.

4. What we do not collect

Soomgyul does not track in the App Tracking Transparency sense. Your data is never combined with other companies' data for advertising, so no ATT permission prompt is shown.

5. Withdrawing permission and deleting data

6. Retention

On-device data (measurements, session log, screening answers and health values) stays on your device until you delete it, and the developer keeps no copy of it. Account records remain with Firebase until the account is deleted. Purchase-related records follow the retention policies of RevenueCat and the respective app store.

7. Children

Soomgyul is not directed to children under 13 (under 14 in the Republic of Korea) and does not knowingly collect personal information from them.

8. Changes and contact

If this policy changes, the effective date and version at the top of this page are updated. If the way data is handled changes materially — for example, if server sync were introduced — we will also say so inside the app.

Contact: entanglecare@gmail.com