개인정보처리방침

시행일: 2026년 8월 1일 · 솔트앤코드

1. 수집하는 개인정보

· 계정: 이메일 주소 또는 Apple/Google 계정 식별자 (비밀번호는 수집하지 않습니다)
· 회개 기록: 카테고리, 시각, 시점(지연 구간), 기도 방식 등 최소한의 이용 정보
· 자유 서술(상황·다짐)의 보관: 기기에서 암호화된 형태(암호문)로만 저장되며, 회사는 평문을 알 수 없습니다
· 인공지능 처리: 이용자가 적은 상황은 개인화된 기도문 생성을 위해서만 일시 처리되며, 생성 후 저장되지 않고 인공지능 모델 학습에 사용되지 않습니다
· 저녁 돌아봄: 날짜와 선택 항목(평안/걸림)
· 알림: 알림을 켜신 경우에만, 알림 발송을 위한 기기 푸시 토큰
· 이용 통계: 서비스 개선을 위한 익명 이용 신호(예: 돌이킴 완료·구독 여부)로, 회개 내용·자유 서술은 포함되지 않으며 제3자 분석 도구에 전송하지 않습니다
· 구독 정보: 구독 상태·상품·만료일 (결제 카드 정보는 Apple이 처리하며 회사는 수집하지 않습니다)

2. 이용 목적

기록의 백업과 기기 간 동기화, 회복 여정 통계 제공, 무료 체험·구독 상태 관리, 문의 대응. 마케팅 목적의 프로파일링에는 사용하지 않습니다.

3. 보관 및 파기

개인정보는 회원 탈퇴(계정 삭제) 시 지체 없이 파기됩니다. "모든 기록 삭제"와 "계정 삭제"는 앱 내 설정에서 언제든지 직접 실행할 수 있으며, 실행 시 기기와 서버의 데이터가 삭제되고 복구되지 않습니다. 관련 법령에 따라 보존 의무가 있는 정보(전자상거래 거래기록 등)는 해당 기간 동안 분리 보관 후 파기합니다.

4. 처리 위탁 및 국외 이전

서비스 운영을 위해 다음 업체에 처리를 위탁하며, 각 수탁자는 위탁 목적 범위에서만 정보를 처리합니다.
· Supabase Inc. (데이터 보관·인증 / 서버 소재: AWS 서울 리전)
· Anthropic PBC (기도문 생성을 위한 인공지능 처리 / 미국 — 입력은 생성 목적으로만 일시 처리되며 모델 학습에 사용되지 않습니다)
· Apple Inc. (로그인·결제 처리)
· Google LLC (로그인)
· RevenueCat Inc. (구독 상태 관리 / 미국)
보관 중인 기록 원문(암호문 포함)은 Anthropic·RevenueCat·Apple·Google에 제공되지 않습니다.

5. 안전성 확보 조치

전송 구간 암호화(TLS), 자유 서술의 기기 내 암호화(AES), 행 수준 접근 제어(RLS)로 본인 외 접근을 차단합니다. 앱 자체에 생체인증·PIN 잠금을 제공합니다.

6. 이용자의 권리

이용자는 자신의 개인정보에 대한 열람·정정·삭제·처리정지를 요구할 수 있습니다. 앱 내 설정에서 직접 실행하거나 contact@saltandcode.net으로 요청할 수 있으며, 회사는 지체 없이 처리합니다.

7. 아동의 개인정보

만 14세 미만 아동의 개인정보는 수집하지 않습니다.

8. 개인정보 보호책임자

성명: 이준수
연락처: contact@saltandcode.net

이 방침은 2026년 8월 1일부터 적용됩니다. 변경 시 앱 내 공지합니다.

Privacy Policy

Effective: August 1, 2026 · Salt and Code

1. Who we are

Salt and Code (솔트앤코드) ("we", "us") is the data controller for personal data processed in the Closer app.

Contact: contact@saltandcode.net

This policy explains what we collect, why, and the rights you have. It applies to everyone who uses Closer, with additional sections below for the EU/EEA, the UK, and California.

2. What we collect

· Account: your email address, or an Apple/Google account identifier. We never collect or store passwords.
· Records of turning back: category, time, how long it had been on your heart, and how you prayed.
· Free text you write (the situation, your commitments): encrypted on your device before storage. We hold only ciphertext and cannot read the original.
· AI processing: what you write about a situation is sent for prayer generation only at that moment. It is not stored afterward and is not used to train AI models.
· Evening reflection: the date and which option you chose.
· Notifications: a device push token, only if you turn notifications on.
· Usage signals: anonymous product events (for example, that a prayer was completed) used to improve the Service. These never include what you wrote, and we do not send them to any third-party analytics provider.
· Subscription: status, product, and expiry date. Card and payment details are handled by Apple; we never receive them.

3. Sensitive data — please read

Closer is a faith app. What you record reveals religious beliefs, which is sensitive personal information under California law and a special category of personal data under the GDPR (Art. 9).

We process it for one purpose only: to provide the Service you asked for. We do so with your consent, which you give through your own affirmative act of writing and saving this content. You may withdraw that consent at any time by deleting your records or your account in Settings; withdrawing does not affect processing that already happened. If the Service is made available in the EU/EEA or the UK, we will rely on your explicit consent (GDPR Art. 9(2)(a)).

We never use this data for advertising, profiling, or automated decision-making, and we never sell or share it.

4. Why we use it, and our legal bases

Under the GDPR we rely on the following legal bases:

· To create and maintain your account, store and sync your records, and manage your trial and subscription — performance of our contract with you (Art. 6(1)(b)).
· To process the faith-related content you write — your explicit consent (Art. 9(2)(a)), as described above.
· To keep the Service secure and reliable, and to understand anonymous usage so we can improve it — our legitimate interests (Art. 6(1)(f)), balanced against your rights.
· To send you notifications — your consent, given when you turn them on (Art. 6(1)(a)). You can turn them off at any time in Settings.
· To meet accounting, tax, and other legal obligations — compliance with a legal obligation (Art. 6(1)(c)).

We do not use your data for marketing profiling.

5. How long we keep it

We keep your data while your account exists. When you delete your account, your personal data is deleted without undue delay from both your device and our servers, and it cannot be recovered.

You can also delete all records at any time from Settings without deleting your account.

Where law requires us to retain certain records — for example transaction records for tax or consumer-protection purposes — we keep only those records, separately, for the required period, and then delete them.

6. Who processes data for us, and where

We use the following processors. Each may process data only on our instructions and only for the purpose shown.

· Supabase Inc. — database and authentication. Servers: AWS Seoul region.
· Anthropic PBC (United States) — AI prayer generation. Input is processed only to produce your prayer, is not retained afterward, and is not used to train models.
· Apple Inc. — sign-in and payment processing.
· Google LLC — sign-in.
· RevenueCat Inc. (United States) — subscription status management.

Stored record content — including the encrypted text — is never provided to Anthropic, RevenueCat, Apple, or Google.

International transfers: your data may be processed outside your country, including in the Republic of Korea and the United States. For transfers of personal data out of the EU/EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with the technical measures described in section 7. You may request a copy of the relevant safeguards at contact@saltandcode.net.

7. How we protect it

Encryption in transit (TLS); on-device AES encryption of everything you write freely, so the plaintext never leaves your device; and row-level access control on the server so no one but you can reach your rows. The app itself also offers Face ID / PIN locking.

No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal data breach where the law requires it.

8. Your privacy rights (EU/EEA and UK)

If you are in the EU/EEA or the UK, you have the right to:

· access the personal data we hold about you;
· have inaccurate data corrected;
· have your data erased ("right to be forgotten");
· restrict or object to our processing;
· receive your data in a portable, machine-readable format;
· withdraw consent at any time, without affecting processing already carried out.

Many of these you can exercise yourself, immediately, in Settings — deleting individual records, deleting all records, or deleting your account. For anything else, write to contact@saltandcode.net and we will respond within one month.

You also have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner's Office).

9. California privacy rights (CCPA/CPRA)

If you are a California resident:

Categories we collect: identifiers (email or account identifier); commercial information (subscription status); internet or device activity (anonymous product events, push token); and sensitive personal information (religious beliefs, as described in section 3). We collect these for the business purposes in section 4.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.

We use sensitive personal information only to provide the Service you asked for, and not to infer characteristics about you — so the right to limit its use does not restrict any additional processing, because we perform none.

You have the right to know, to delete, and to correct your personal information, and not to receive discriminatory treatment for exercising these rights. You can exercise deletion directly in Settings, or contact contact@saltandcode.net. You may use an authorized agent to submit a request; we may ask you to verify the request.

10. Children

Closer is not intended for children. We do not knowingly collect personal data from anyone under 13, or under the minimum age of digital consent in your country. If you believe a child has provided us with personal data, contact contact@saltandcode.net and we will delete it.

11. Changes to this policy

If we make significant changes, we will give notice in the app before they take effect. This policy takes effect on August 1, 2026.

Questions or requests: contact@saltandcode.net