QuestionDiary 개인정보처리방침
시행일: 2026년 9월 27일 · 최종 개정 2026년 9월 28일 · 한일소프트(HanilSoft)
요약
QuestionDiary는 기기 안에서 먼저 동작하는 일기 앱입니다. 매일 한 질문에 답을 쓰고, 1년 뒤 같은 날짜에 그때의 답을 다시 만납니다. 답변(일기 본문)은 이용자의 iPhone에만 저장되며, 이용자가 백업을 직접 켜기 전에는 당사 서버로 전송되지 않습니다. 백업은 기본값이 꺼짐인 선택 기능입니다.
계정은 이름·이메일 없이 만들어집니다(Apple을 연결하면 그때 이메일 또는 가리기 주소가 더해집니다). 광장 탭에 처음 들어가거나, 백업을 켜거나, 설정에서 Apple·Google 계정을 연결할 때 무작위 식별자만 있는 익명 계정이 자동으로 발급됩니다. 그 전까지 앱은 당사 서버에 어떤 요청도 보내지 않습니다. Apple·Google 연결은 기기를 잃어도 같은 계정으로 돌아오기 위한 선택 기능입니다. Google 연결은 고유 식별자만 받고, Apple 연결은 Apple의 "이메일 가리기"를 고를 수 있도록 이메일을 요청합니다(가리기를 고르면 Apple의 릴레이 주소가 전달됩니다). 이름은 어느 쪽도 요청하지 않습니다.
광장에 올린 질문은 공개됩니다. 광장은 이용자들이 서로에게 묻고 싶은 질문을 올리고 가져가는 공간입니다. 올린 질문 본문은 다른 모든 이용자에게 보이며, 작성자의 이름이나 식별자는 표시되지 않습니다.
광장 질문에 "광장에 공개"를 골라 단 답은 모든 이용자에게 공개됩니다. 광장 질문에 답을 쓸 때마다 공개 범위를 고르며, 기본값은 "나만 보기"입니다. 나만 보기 답은 일기처럼 이 iPhone에만 저장되고, 이용자가 매번 직접 "광장에 공개"를 고른 답만 공개됩니다. 공개된 답에는 작성자의 이름이나 식별자가 표시되지 않고 "익명"으로 보입니다. 일기(매일의 답)는 어떤 경우에도 공개되지 않습니다.
광고는 있지만 추적은 하지 않습니다. 앱은 무료이며 오늘·기록·광장 탭 하단의 배너, 설정 탭의 네이티브 광고 한 칸, 그리고 가끔 뜨는 전면 광고(Google AdMob)로 운영됩니다. 앱 추적 투명성(ATT) 권한을 요청하지 않고 광고 식별자(IDFA)를 쓰지 않으며, 광고는 비개인화 방식으로 제공됩니다. 사용자 수·유지율을 세기 위해 Firebase Analytics를 쓰지만 일기 본문·답 본문·질문 원문·사용자 코드는 어떤 분석 이벤트에도 담기지 않습니다. 계정과 서버의 모든 기록은 앱 안에서 언제든 삭제할 수 있습니다.
1. 수집·처리하는 개인정보의 항목과 목적
1.1 기기에만 저장되는 정보 (서버로 전송되지 않음)
아래 정보는 iPhone의 앱 전용 저장 공간에만 보관됩니다. 백업을 켜지 않으면 당사는 이 정보를 받지 않으며, 볼 수도 없습니다.
- 일기 답변 본문, 답변한 날짜, 그날의 질문 원문(스냅샷)
- 이용자가 직접 쓰거나 광장에서 가져와 특정 날짜에 배정한 질문
- 광장 질문에 "나만 보기"로 단 답(답 본문, 답한 광장 질문의 원문·카테고리·언어 스냅샷). 광장에는 표시되지 않으며 일기(기록 탭)에도 섞이지 않습니다
- 알림 시각, 외관, 앱 잠금 등 앱 설정
- 연속 기록·통계 등 위 기록에서 계산되는 값
앱 잠금(Face ID·Touch ID)은 iOS의 인증 기능을 호출할 뿐이며, 생체 정보는 기기 밖으로 나가지 않고 앱도 성공·실패 결과만 받습니다. 리마인더는 기기 안에서 예약되는 로컬 알림이며 네트워크를 쓰지 않습니다.
1.2 계정 정보 (광장 첫 진입, 백업 켬 또는 Apple·Google 연결 시점부터)
| 항목 | 내용 | 목적 | 보유 기간 |
|---|---|---|---|
| 계정 식별자 | Firebase Authentication이 발급하는 무작위 익명 UID. 이름·이메일·전화번호 없음 | 이용자 구분, 요청 인증 | 계정 삭제 시까지 |
| 연결한 로그인 수단 (선택) | Apple 또는 Google로 계정을 연결한 경우, 그 서비스가 이 앱용으로 발급하는 고유 식별자와 연결 여부(apple.com·google.com). 이름·프로필 사진은 요청하지 않습니다(Google: 신원 확인(openid) 범위만 요청) | 기기를 잃거나 바꿔도 같은 계정으로 다시 로그인 | 계정 삭제 시까지 |
| 이메일 주소 (Apple 연결 시) | Apple 연결 때 Apple이 전달하는 이메일. Apple 시트에서 "이메일 가리기"를 고르면 실제 주소 대신 Apple 릴레이 주소가 전달됩니다. Firebase Authentication의 사용자 레코드에만 저장되며, 당사 서버 데이터베이스·로그·이용 통계에는 담지 않고 이메일을 보내는 데 쓰지 않습니다 | Apple 계정 연결 상태 유지(Apple·Firebase의 계정 식별) | 계정 삭제 시까지 |
| 사용자 코드 | 기기 이전을 위해 발급되는 10자 무작위 코드 | 새 기기에서 같은 계정 복원 | 계정 삭제 시까지 |
| 기기·환경 정보 | 앱 버전, OS 종류, 언어, 시간대 (요청 헤더로 전달되며 최신 값만 보관) | 호환성 확인, 오류 대응 | 계정 삭제 시까지 |
| 이용 시각 | 계정 생성 시각, 마지막 접속 시각, 마지막 로그아웃 시각 | 운영·이상 징후 확인 | 계정 삭제 시까지 |
| 백업 설정 상태 | 백업 켬/끔 여부 | 동기화 동작 결정 | 계정 삭제 시까지 |
1.3 백업 기록 (이용자가 백업을 켠 경우에만)
백업을 켜면 1.1의 기록이 당사 서버에 사본으로 저장됩니다. 여기에는 일기 답변 본문과 질문 원문이 그대로 포함됩니다. 백업의 목적은 기기 변경·재설치 시 기록을 복원하는 것뿐이며, 당사는 그 내용을 열람·분석하거나 다른 목적에 쓰지 않습니다.
- 저장 항목: 일기 답변(본문·날짜·질문 스냅샷), 날짜별 질문 배정, 광장 질문에 "나만 보기"로 단 답(광장 질문 id, 질문 원문 스냅샷, 카테고리, 언어, 답 본문 최대 5,000자), 앱 설정, 프로필
- 기기에서 지운 기록은 서버 사본에도 본문 없이 "삭제됨" 표시만 남습니다.
- 보유 기간: 백업을 끄는 즉시 서버 사본이 삭제됩니다. 계정을 삭제해도 삭제됩니다.
1.4 광장 (이용자가 광장 기능을 쓴 경우에만)
| 항목 | 내용 | 공개 범위 | 보유 기간 |
|---|---|---|---|
| 게시한 질문 | 질문 본문(4~120자), 카테고리, 언어, 게시 시각, 작성자 UID | 본문·카테고리·언어는 모든 이용자에게 공개. 작성자 UID는 표시되지 않음 | 작성자가 삭제하거나 당사가 제거할 때까지 |
| 공개 답 | 광장 질문에 "광장에 공개"를 골라 단 답: 답 본문(2~500자, 줄바꿈 10개까지), 답한 질문, 상태, 게시 시각, 작성자 UID, 신고 수, 중복 게시 방지용 본문 지문(해시). 작성자 UID는 1인 1답 확인·"내 활동"·계정 삭제 시 정리·차단 처리에만 쓰입니다 | 본문과 게시 시각(상대 시각)은 모든 이용자에게 공개되며 작성자는 "익명"으로 표시됩니다. 작성자 UID·신고 수·지문은 표시되지 않고 어떤 응답에도 담기지 않음 | 작성자가 삭제하거나 당사가 제거할 때까지 공개됩니다. 작성자 삭제·당사 제거·계정 삭제 시 본문과 지문을 비우고 기록은 "삭제됨" 상태로 남습니다. 이때 남는 것은 작성자 UID·답한 질문·시각·신고 수·상태뿐이며, 한 사람이 한 질문에 답 하나만 쓰는 규칙과 신고 이력(삭제 후 다시 올려 신고를 없애는 것 방지)을 지키는 데만 쓰입니다 |
| 감정 표현(리액션) | 어떤 질문에 어떤 감정 표현(❤️ 좋아요 · 👍 좋은 질문 · 🤔 생각하게 돼요 · 🥹 뭉클해요 · 😂 재밌어요 중 하나)을 남겼는지. 질문당 1개, 바꾸거나 취소할 수 있음. 기존 좋아요는 ❤️로 옮겨졌습니다 | 종류별 수와 합계만 공개. 누가 남겼는지는 표시되지 않음 | 취소, 질문 삭제 또는 계정 삭제 시까지 |
| 가져오기 | 어떤 질문을 몇 번 가져갔는지(합계) | 합계만 공개 | 질문 삭제 시까지 |
| 신고 | 신고한 질문, 선택한 사유(7종 중 하나), 신고자 UID. 자유 서술 없음 | 비공개. 작성자에게 전달되지 않음 | 질문 삭제 시까지 |
| 답 신고 | 신고한 공개 답, 선택한 사유(질문 신고와 같은 7종 중 하나), 신고자 UID. 자유 서술 없음 | 비공개. 작성자에게 전달되지 않음 | 신고자가 계정을 삭제할 때까지. 신고한 답이 삭제·제거되어도 신고 기록과 답의 신고 수는 남습니다(삭제 후 다시 올려 신고를 없애는 것 방지). 신고자가 계정을 삭제하면 그 신고 기록은 삭제되고 답의 신고 수는 유지됩니다 |
| 차단 목록 | 두 종류입니다. ① 질문 작성자 차단: 질문에서 차단한 작성자의 UID — 그 사람의 질문만 숨깁니다. ② 답 작성자 숨기기("이 사람의 답 숨기기"): 차단에 쓴 답의 id와 그 답 작성자의 UID — 그 사람의 답만 숨깁니다. ②의 작성자 UID는 서버에서만 보관하며 이용자에게도 돌려주지 않습니다(차단 목록에는 답 id와 날짜만 담깁니다) | 비공개 | 해제 또는 계정 삭제 시까지 |
광장 게시물은 계정과 별개로 보관됩니다. 계정을 삭제해도 이미 올린 질문은 광장에 남습니다. 계정 삭제 뒤에는 그 질문을 이용자와 연결할 수 없고 이용자도 지울 수 없게 되므로, 남기고 싶지 않은 질문은 광장 › 내 게시물에서 먼저 삭제하십시오. 다른 이용자가 이미 자기 일기로 가져간 질문은 그 이용자의 기기에 사본으로 남습니다.
공개 답은 질문과 다릅니다 — 계정을 삭제하면 이용자가 올린 공개 답은 모두 삭제됩니다(본문을 비우고 목록에서 사라집니다). 공개 답은 올린 뒤 고칠 수 없으며, 작성자는 언제든 질문 상세나 광장 › ⋯ › 내 활동에서 지울 수 있습니다(지우면 본문과 지문을 비웁니다). 공개 답은 다른 이용자가 자기 일기로 가져갈 수 없습니다.
1.5 운영 보호 정보
- 일일 한도 카운터 — 질문·답 게시, 감정 표현, 가져오기, 신고, 백업 요청의 하루 횟수. 계정 식별자와 날짜로만 구성되며 7일 후 자동 삭제됩니다.
- 복원 시도 기록 — 사용자 코드 복원을 무차별 대입으로부터 보호하기 위해 요청 IP 주소의 해시값과 시도 횟수를 보관합니다. IP 원문은 저장하지 않으며 2일 후 자동 삭제됩니다.
1.6 광고와 이용 통계 (모든 이용자)
| 항목 | 처리자 | 내용 | 목적 | 보유 기간 |
|---|---|---|---|---|
| 기기 식별자 | Google AdMob · Firebase Analytics | 광고 SDK가 만드는 재설정 가능한 식별자, Firebase 앱 인스턴스 ID. IDFA는 쓰지 않습니다. | 광고 게재·부정 클릭 방지, 사용자 수 집계 | Google의 보유 정책(Analytics 사용자 데이터 14개월) |
| 광고 데이터 | Google AdMob | 어떤 광고가 노출·클릭됐는지, 앱 버전·OS·기기 종류·언어 | 광고 게재와 성과 측정 | Google의 보유 정책 |
| 대략적인 위치 | Firebase Analytics | IP 주소로 추정한 국가·도시 수준. 위치 서비스는 쓰지 않습니다. | 지역별 이용 통계 | Google의 보유 정책 |
| 앱 이용 이벤트 | Firebase Analytics | 답변 저장·질문 교체·회상 열람·광장 게시·광장 질문에 답 저장/게시(나만 보기·공개 중 어느 쪽인지만)·감정 표현(고른 종류만)·백업 켬 등 행위의 종류와 횟수만. 본문·질문·질문 id·날짜·코드는 담지 않습니다. | 기능 개선, 유지율 파악 | Google의 보유 정책(이벤트 14개월) |
이 항목은 계정과 연결되지 않습니다 — 당사는 분석 SDK에 계정 식별자를 넘기지 않습니다. 광고는 EEA·영국 이용자에게 Google의 동의 양식을 먼저 보여주며, 동의하지 않아도 비개인화 광고로 앱을 계속 쓸 수 있습니다. Google의 광고 개인정보 설정은 adssettings.google.com, 방침은 policies.google.com/technologies/ads에서 확인할 수 있습니다.
2. 수집 방법과 동의 시점
- 앱을 설치하고 일기를 쓰는 것만으로는 어떤 정보도 서버로 전송되지 않습니다.
- 광장 탭에 처음 들어갈 때 익명 계정이 발급됩니다. 광장·백업·계정 연결을 쓰지 않으면 발급되지 않습니다.
- 백업을 켤 때 익명 계정이 발급되고(이미 있으면 재사용) 1.3의 사본 전송이 시작됩니다. 백업 화면에는 전송되는 내용이 명시되어 있습니다.
- 설정 › 백업 · 기기 이전에서 Apple 또는 Google을 연결하거나 그 계정으로 로그인할 때 익명 계정이 발급되고(이미 있으면 재사용) 1.2의 로그인 수단 식별자가 그 계정에 연결됩니다. 이 단계는 선택 사항이며, Apple·Google의 로그인 화면은 각 회사가 직접 제공합니다.
- 광장에 질문이나 공개 답을 올리거나 감정 표현·가져오기·신고·차단을 할 때 1.4의 정보가 그 행위와 함께 처리됩니다. "나만 보기"로 단 답은 저장할 때 서버로 전송되지 않습니다(백업을 켠 경우 1.3의 사본만 전송).
- 1.6의 광고·이용 통계는 온보딩을 마친 뒤 앱을 쓰는 동안 처리됩니다. 광고 SDK는 온보딩 중에는 시작되지 않습니다.
3. 처리 위탁 및 국외 이전
| 수탁자 | 국가 | 위탁 항목 | 목적 | 보유·이용 기간 |
|---|---|---|---|---|
| Google Cloud Platform (Cloud Functions · Firestore · Hosting) |
대한민국(서울 리전 asia-northeast3) |
1.2~1.5의 계정 정보, 백업 기록, 광장 데이터 | 서버 저장·운영 | 각 항목의 보유 기간 |
| Google LLC (Firebase Authentication · Google 계정 로그인) |
미국 등 | 익명 계정 식별자, 연결한 Apple·Google 로그인 수단의 고유 식별자, Apple 연결 시 이메일(또는 릴레이 주소), 인증 요청 정보 | 계정 발급·인증 토큰 관리, Google 계정 연결 시 본인 확인 | 계정 삭제 시까지 |
| Apple Inc. (Apple로 로그인) |
미국 등 | Apple 계정 연결 시 Apple이 이 앱용으로 발급하는 고유 식별자, 이메일(또는 가리기 릴레이 주소), 인증 토큰 | Apple 계정으로 본인 확인 | Apple의 방침에 따름. 당사는 식별자만 계정 삭제 시까지 보관 |
| Google LLC (AdMob · Firebase Analytics) |
미국 등 | 1.6의 광고·이용 통계 항목 | 광고 게재·성과 측정, 사용자 수 집계 | Google의 보유 정책 |
백업 기록과 광장 데이터의 저장 리전은 서울(asia-northeast3)입니다. 다만 인증(Firebase Authentication)·광고(AdMob)·이용 통계(Firebase Analytics)에 관한 정보는 Google LLC의 글로벌 인프라에서 처리되어 국외(미국 등)로 이전될 수 있습니다. Google의 방침은 policies.google.com/privacy 에서 확인하실 수 있습니다.
4. 이용자의 권리와 행사 방법
모든 권리는 앱 안에서 직접 행사할 수 있습니다. 계정에 이름이 없고 이메일도 Apple 연결 시에만 있으므로, 이메일 문의로 특정 계정을 찾으려면 사용자 코드가 필요합니다.
- 열람·복사 — 일기는 앱의 기록 탭에서 언제든 볼 수 있습니다. 백업 상태와 사용자 코드는 나 › 설정 › 백업 · 기기 이전에서 확인합니다.
- 백업 중단과 서버 사본 삭제 — 백업 · 기기 이전에서 백업을 끄면 서버 사본이 즉시 삭제됩니다. 이 기기의 일기는 남습니다.
- 광장 게시물 삭제 — 광장 › 내 게시물에서 각 질문을 삭제합니다.
- 답 삭제 — 공개 답과 나만 보기 답은 질문 상세의 내 답 ⋯ 또는 광장 › ⋯ › 내 활동 › 답에서 삭제합니다. 공개 답은 고칠 수 없고, 지운 뒤 다시 쓸 수 있습니다. 다만 신고가 누적되어 숨겨진 상태에서 지운 답과 당사가 제거한 답이 있던 질문에는 다시 답할 수 없습니다.
- 차단 해제 — 광장 › ⋯ › 차단 관리에서 질문 작성자 차단과 답 작성자 숨기기를 각각 해제합니다.
- 계정 삭제 — 백업 · 기기 이전 › 계정 탈퇴. 계정, 사용자 코드, 서버의 모든 백업 기록(나만 보기 답의 백업 사본 포함), 인증 계정(연결한 Apple·Google 로그인 수단 포함)이 삭제됩니다. 광장에 올린 공개 답도 모두 삭제되고, 남긴 감정 표현·신고·차단 기록도 삭제됩니다. 다만 광장에 올린 질문은 남습니다(1.4). 이 기기의 일기를 남길지 함께 지울지 선택할 수 있습니다. 되돌릴 수 없습니다.
- 문의·이의 — support@hanilsoft.net
5. 개인정보의 파기
보유 기간이 지나거나 처리 목적이 달성된 개인정보는 지체 없이, 복구할 수 없는 방법으로 파기합니다.
- 백업을 끄면 서버 사본이 즉시 삭제됩니다.
- 계정을 삭제하면 서버의 백업 기록, 사용자 코드, 계정 문서, 인증 계정이 즉시 삭제됩니다. 별도 보관본이나 백업 사본을 유지하지 않습니다.
- 계정을 삭제하면 이용자가 올린 공개 답이 모두 삭제(본문과 지문을 비움)되고, 감정 표현 기록이 삭제되어 합계에서 빠지며, 이용자가 한 신고 기록(질문·답)과 차단 목록도 삭제됩니다. 신고로 쌓인 게시물의 신고 수는 유지됩니다. 광장에 올린 질문은 1.4에 따라 남습니다.
- 광장 게시물은 1.4에 따라 작성자가 삭제하거나 당사가 제거할 때 삭제됩니다. 신고에 의해 숨겨진 게시물(질문·답)은 다른 이용자에게 보이지 않으며, 검토 후 삭제될 수 있습니다.
- 일일 한도 카운터는 7일, 복원 시도 기록은 2일 후 자동 삭제됩니다.
- 비활성 계정을 자동으로 삭제하지는 않습니다.
6. 안전성 확보 조치
- 앱과 서버 간 모든 통신은 HTTPS(TLS)로 암호화합니다.
- 서버 데이터베이스는 클라이언트 직접 접근을 전면 차단하며, 당사 API를 통한 인증된 요청만 허용합니다. 모든 요청은 인증 토큰 검증을 거칩니다.
- 백업 기록은 계정 단위로 격리되며, 다른 계정의 기록에 접근하는 경로가 없습니다.
- 기기 내 인증 토큰은 iOS 키체인에 저장합니다.
- 서버 로그에는 일기 본문·답 본문·질문 원문·사용자 코드·IP 원문을 남기지 않습니다. 로그에는 종류·식별자·시각만 기록합니다.
- 분석 이벤트에도 같은 원칙을 적용합니다 — 이벤트 이름과 파라미터는 코드에서 고정되어 있으며 자유 텍스트를 담을 수 없습니다.
- 이용자가 앱 잠금을 켜면 앱이 백그라운드에서 돌아올 때 생체 인증을 요구하고, 앱 전환 화면에서 내용을 가립니다.
7. 제3자 제공 · 광고 · 추적
- 당사는 이용자의 개인정보를 판매하거나 광고 목적으로 제공하지 않습니다.
- 광장 게시물(질문·공개 답)은 서비스의 성격상 다른 이용자에게 공개되지만, 이는 이용자가 게시 행위로 직접 공개하는 것이며 제3자 제공이 아닙니다.
- 앱에는 Google AdMob(광고)과 Firebase Analytics(이용 통계) SDK가 포함되어 있습니다. 어트리뷰션 SDK나 그 밖의 제3자 분석 SDK는 없습니다.
- 앱 추적 투명성(ATT) 대상 추적을 수행하지 않으며, 추적 권한을 요청하지 않고 광고 식별자(IDFA)를 쓰지 않습니다. 광고는 비개인화 방식입니다.
- 광고 SDK가 처리하는 정보는 Google이 자체 방침에 따라 처리하며, 당사는 그 정보를 받아 보관하지 않습니다.
- 법령에 근거한 수사기관의 적법한 요청이 있는 경우에 한해 관련 법령이 정한 절차에 따라 제공될 수 있습니다.
8. 광장의 신고·차단과 게시물 관리
- 모든 질문과 공개 답은 게시 전에 서버에서 자동 검사를 거칩니다(길이, 연락처·링크 포함 여부, 금칙어, 중복 등).
- 이용자는 어떤 질문이든, 어떤 공개 답이든 신고할 수 있습니다(답은 질문 상세의 답 ⋯ › 신고). 서로 다른 이용자 3명이 신고하면 그 질문이나 답은 자동으로 숨겨지며, 당사는 신고를 24시간 이내에 검토하여 가이드라인 위반 게시물을 제거합니다. 숨겨진 답은 작성자만 내 활동에서 숨김 안내와 함께 볼 수 있습니다.
- 차단은 두 가지이며 서로 영향을 주지 않습니다. 질문에서 작성자 차단을 하면 그 사람의 질문만 목록에 나타나지 않습니다. 답의 ⋯에서 "이 사람의 답 숨기기"를 하면 그 사람의 답만 답 목록에 나타나지 않습니다. 둘 다 광장 › ⋯ › 차단 관리에서 해제할 수 있습니다.
- 신고 사유는 작성자에게 전달되지 않습니다.
- 익명성의 한계. 공개 답에는 이름이나 식별자가 표시되지 않고, 답 작성자의 UID는 어떤 응답에도 담기지 않습니다. 다만 누군가 한 사람의 답을 숨긴 뒤 여러 질문의 답 목록을 숨기기 전과 비교하면 "같은 사람이 쓴 답들"을 한 묶음으로 추려 낼 수 있습니다. 이 묶음은 UID·이름이나 그 사람이 올린 질문과는 연결되지 않습니다. 그래도 답의 내용이나 올린 시각(예: 질문을 올린 직후 단 답)으로 작성자를 짐작할 수는 있으므로, 공개 답에는 나를 알아볼 수 있는 내용을 쓰지 마십시오.
9. 만 14세 미만 아동
QuestionDiary는 만 14세 미만 아동을 대상으로 하지 않으며, 만 14세 미만 아동의 개인정보를 알면서 수집하지 않습니다. 만 14세 미만 아동은 법정대리인의 동의 없이 서비스를 이용해서는 안 됩니다. 만 14세 미만 아동의 정보가 수집된 사실을 알게 된 경우 support@hanilsoft.net 로 알려주시면 지체 없이 삭제하겠습니다.
10. 개인정보 보호책임자
| 보호책임자 | 한일소프트 (HanilSoft) |
|---|---|
| 연락처 | support@hanilsoft.net |
개인정보 침해에 대한 신고·상담이 필요하신 경우 아래 기관에 문의하실 수 있습니다.
- 개인정보침해 신고센터 — 국번없이 118 · privacy.kisa.or.kr
- 개인정보 분쟁조정위원회 — 1833-6972 · kopico.go.kr
- 대검찰청 사이버수사과 — 1301 · 경찰청 사이버수사국 — 182
11. 방침의 변경
변경 이력:
- 2026년 9월 27일 — 최초 제정. 같은 날 광고(Google AdMob 배너·전면)와 이용 통계(Firebase Analytics) 도입에 따라 1.6·3·7항을 신설·개정했습니다. ATT 미요청·비개인화 광고 원칙을 명시했습니다.
- 2026년 9월 28일 — 선택 기능인 Apple·Google 계정 연결 도입에 따라 1.2·2·3·4항을 개정했습니다. Google은 고유 식별자만 받고, Apple은 "이메일 가리기" 선택을 제공하기 위해 이메일을 요청합니다(Firebase Authentication 레코드에만 저장). 이름은 요청하지 않습니다.
- (1.1 출시일 — 게시 전 확정) — 앱 1.1의 광장 답하기·감정 표현 도입에 따라 요약·1.1·1.3·1.4·1.5·1.6·2·4·5·6·7·8항을 개정했습니다. 광장 질문에 "나만 보기"(기본값, 기기에만 저장·백업을 켠 경우 사본) 또는 "광장에 공개"로 답을 달 수 있고, 공개 답은 익명으로 모든 이용자에게 보이며 계정 삭제 시 삭제됩니다. 좋아요를 감정 표현 5종으로 바꾸고 기존 좋아요는 ❤️로 옮겼습니다. 답 신고, 질문 차단과 답 숨기기의 분리, 익명성의 한계를 명시했습니다. 이 개정의 시행일은 1.1 출시일이며, 위 머리말의 시행일·최종 개정일은 게시 시점에 함께 갱신합니다.
이 개인정보처리방침의 내용이 변경되는 경우 시행 7일 전부터 이 페이지에 공지합니다. 다만 이용자의 권리에 중대한 영향을 미치는 변경(수집 항목 추가, 이용 목적 변경 등)은 시행 30일 전에 공지하며, 필요한 경우 앱 내에서 다시 동의를 받습니다.
12. 사업자 정보
| 상호 | 한일소프트 (HanilSoft) |
|---|---|
| 이메일 | support@hanilsoft.net |
Privacy Policy (English)
Effective: September 27, 2026 · Last revised September 28, 2026 · HanilSoft · This English text is provided for convenience. In case of any discrepancy, the Korean version above prevails.
Summary
QuestionDiary is a local-first journaling app. You answer one question a day and meet that answer again one year later on the same date. Your answers (diary text) are stored only on your iPhone and are never sent to our server unless you turn on Backup, which is off by default.
Accounts have no name or email (an email or Hide My Email address is added only if you link Apple). An anonymous account with a random identifier is created automatically the first time you open the Plaza tab, turn on Backup, or link an Apple or Google account in Settings. Until then the app makes no requests to our server at all. Linking Apple or Google is an optional way to get back to the same account if you lose your device. Google linking receives only the identifier that service issues; Apple linking requests your email so that Apple can offer "Hide My Email" (choosing it sends an Apple relay address instead). Neither requests your name.
Questions you post to the Plaza are public. The Plaza is where users share questions they'd like to ask each other. The text of a posted question is visible to every user; your name or identifier is never shown.
Answers you choose to make public on Plaza questions are visible to all users. Each time you answer a Plaza question you choose who can see it, and the default is "Only me". Only-me answers stay on this iPhone like your diary; only answers for which you explicitly chose "Public in the Plaza" are public. Public answers show no name or identifier and appear as "Anonymous". Your diary (your daily answers) is never made public.
Ads, but no tracking. The app is free and supported by banners at the bottom of the Today, Journal and Plaza tabs, a native ad card in Settings, plus occasional interstitials (Google AdMob). We never request App Tracking Transparency permission or use the advertising identifier (IDFA); ads are non-personalised. We use Firebase Analytics to count users and retention, but diary text, answer text, question text, and user codes never appear in any analytics event. You can delete your account and all server data from inside the app at any time.
1. What we process
1.1 Data that stays on your device (never sent to us)
- Diary answers, the date of each answer, and a snapshot of that day's question
- Questions you wrote yourself or imported from the Plaza and assigned to a date
- Answers you wrote to Plaza questions as "Only me" (answer text and a snapshot of the Plaza question's text, category, and language). They never appear in the Plaza and are not part of your diary (Journal tab)
- App settings such as reminder time, appearance, and app lock
- Streaks and statistics computed from the above
App lock (Face ID / Touch ID) calls the iOS authentication system; biometric data never leaves the device and the app only receives a pass/fail result. Reminders are local notifications scheduled on the device and use no network.
1.2 Account data (from the first Plaza visit, when Backup is turned on, or when you link Apple/Google)
| Data | Details | Purpose | Retention |
|---|---|---|---|
| Account identifier | Random anonymous UID issued by Firebase Authentication. No name, email, or phone number | Telling users apart; authenticating requests | Until you delete your account |
| Linked sign-in method (optional) | If you link Apple or Google, the app-specific identifier that service issues and which methods are linked (apple.com, google.com). We do not request your name or profile photo (Google: the identity-only openid scope) | Signing back in to the same account after losing or changing your device | Until you delete your account |
| Email address (Apple linking only) | The email Apple passes when you link Apple. If you choose "Hide My Email" in the Apple sheet, an Apple relay address is passed instead of your real one. Stored only in the Firebase Authentication user record; never written to our server database, logs, or usage statistics, and never used to send you email | Keeping the Apple link to your account (account identification by Apple and Firebase) | Until you delete your account |
| User code | A random 10-character code for moving to a new device | Restoring the same account on another device | Until you delete your account |
| Device and environment | App version, OS type, language, time zone (sent as request headers; only the latest values are kept) | Compatibility checks; troubleshooting | Until you delete your account |
| Timestamps | Account creation, last seen, last logout | Operations; abuse detection | Until you delete your account |
| Backup setting | Whether Backup is on | Deciding whether to sync | Until you delete your account |
1.3 Backup records (only if you turn Backup on)
With Backup on, a copy of the data in 1.1 is stored on our server. This includes the full text of your diary answers and questions. Backup exists solely to restore your records when you change or reinstall your device; we do not read, analyse, or otherwise use its content.
- Stored: diary answers (text, date, question snapshot), per-date question assignments, answers you wrote to Plaza questions as "Only me" (Plaza question ID, question text snapshot, category, language, answer text up to 5,000 characters), app settings, profile
- When you delete a record on your device, the server copy keeps only a "deleted" marker with no content.
- Retention: the server copy is deleted immediately when you turn Backup off, and when you delete your account.
1.4 Plaza (only if you use the Plaza)
| Data | Details | Visibility | Retention |
|---|---|---|---|
| Posted questions | Text (4–120 characters), category, language, posted time, author UID | Text, category, and language are public to all users. The author UID is never displayed | Until the author deletes it or we remove it |
| Public answers | Answers to Plaza questions for which you chose "Public in the Plaza": answer text (2–500 characters, up to 10 line breaks), the question answered, status, posted time, author UID, report count, and a fingerprint (hash) of the text to prevent duplicate posts. The author UID is used only to enforce one answer per person, show "My activity", clean up on account deletion, and apply blocks | Text and posted time (shown as relative time) are public to all users; the author appears as "Anonymous". The author UID, report count, and fingerprint are never displayed or included in any response | Public until the author deletes it or we remove it. When the author deletes it, we remove it, or you delete your account, the text and fingerprint are cleared and the record stays in a "removed" state. What remains is only the author UID, the question answered, timestamps, report count, and status, used solely to enforce one answer per person per question and to keep report history (so deleting and reposting can't wipe reports) |
| Reactions | Which reaction you left on which question (one of ❤️ Love it · 👍 Good question · 🤔 Makes me think · 🥹 Touching · 😂 Fun). One per question; you can change or remove it. Earlier likes were moved to ❤️ | Per-kind counts and the total only; who reacted is never shown | Until removed, the question is deleted, or you delete your account |
| Imports | How many times a question was imported (total) | Totals only | Until the question is deleted |
| Reports | The reported question, one of seven fixed reasons, and the reporter's UID. No free text | Private; never shown to the author | Until the question is deleted |
| Answer reports | The reported public answer, one of the same seven fixed reasons, and the reporter's UID. No free text | Private; never shown to the author | Until the reporter deletes their account. Report records and the answer's report count remain even if the reported answer is deleted or removed (so deleting and reposting can't wipe reports). When the reporter deletes their account, their report records are deleted and the answer's report count is kept |
| Block list | Two kinds. ① Question-author blocks: the UID of an author you blocked from a question — hides only that person's questions. ② Answer-author hides ("Hide this person's answers"): the ID of the answer you used and that answer's author UID — hides only that person's answers. The author UID in ② is kept on the server only and is never returned, not even to you (the block list contains only the answer ID and date) | Private | Until unblocked or account deletion |
Plaza posts are stored separately from your account. Deleting your account does not delete questions you already posted. After account deletion they can no longer be linked to you, and you can no longer delete them, so remove anything you don't want to leave behind in Plaza › My posts first. A question another user has already imported into their diary stays as a copy on that user's device.
Public answers are different from questions — deleting your account deletes all public answers you posted (the text is cleared and they disappear from lists). Public answers cannot be edited after posting; you can delete them at any time from the question's detail screen or Plaza › ⋯ › My activity (deleting clears the text and fingerprint). Other users cannot import public answers into their diaries.
1.5 Operational safeguards
- Daily limit counters — how many questions and answers you posted, reactions, imports, reports, and backup requests you made today. Consist of your account identifier and the date only; auto-deleted after 7 days.
- Restore attempts — to protect user-code restore from brute force we keep a hash of the requesting IP address and an attempt count. The raw IP is never stored; auto-deleted after 2 days.
1.6 Advertising and usage statistics (all users)
| Data | Processor | Details | Purpose | Retention |
|---|---|---|---|---|
| Device identifiers | Google AdMob · Firebase Analytics | A resettable identifier generated by the ads SDK and the Firebase app-instance ID. IDFA is not used. | Ad serving and fraud prevention; counting users | Google's retention policy (Analytics user data: 14 months) |
| Advertising data | Google AdMob | Which ads were shown or tapped; app version, OS, device model, language | Ad serving and measurement | Google's retention policy |
| Coarse location | Firebase Analytics | Country/city inferred from IP address. Location Services are not used. | Regional usage statistics | Google's retention policy |
| Usage events | Firebase Analytics | Only the kind and count of actions such as saving an answer, swapping a question, viewing a recall, posting to the Plaza, saving or posting an answer to a Plaza question (only whether it was only-me or public), reacting (only the kind chosen), turning Backup on. No text, questions, question IDs, dates, or codes. | Product improvement; retention | Google's retention policy (events: 14 months) |
None of this is linked to your account — we never pass an account identifier to the analytics SDK. Users in the EEA and UK see Google's consent form before any ad; declining still lets you use the app with non-personalised ads. Manage Google's ad settings at adssettings.google.com; Google's policy is at policies.google.com/technologies/ads.
2. When data is collected
- Installing the app and writing your diary sends nothing to our server.
- The first time you open the Plaza tab, an anonymous account is created. If you never use the Plaza, Backup, or account linking, none is created.
- When you turn Backup on, an anonymous account is created (or reused) and the transfer described in 1.3 begins. The Backup screen states what is sent.
- When you link Apple or Google, or sign in with one of them, in Settings › Backup & device transfer, an anonymous account is created (or reused) and the sign-in identifier in 1.2 is attached to it. This step is optional, and the Apple/Google sign-in screens are provided by those companies.
- Posting a question or public answer, reacting, importing, reporting, or blocking on the Plaza processes the data in 1.4 as part of that action. Saving an "Only me" answer sends nothing to our server (only the backup copy in 1.3, if Backup is on).
- The advertising and usage data in 1.6 is processed while you use the app after onboarding. The ads SDK does not start during onboarding.
3. Processors and international transfer
| Processor | Country | Data | Purpose | Retention |
|---|---|---|---|---|
| Google Cloud Platform (Cloud Functions · Firestore · Hosting) |
Republic of Korea (Seoul region asia-northeast3) |
Account data, backup records, and Plaza data in 1.2–1.5 | Server storage and operations | As stated per item |
| Google LLC (Firebase Authentication · Sign in with Google) |
United States and others | Anonymous account identifier, identifiers of linked Apple/Google sign-in methods, the email (or relay address) from Apple linking, and authentication requests | Issuing accounts and managing auth tokens; verifying you when you link Google | Until you delete your account |
| Apple Inc. (Sign in with Apple) |
United States and others | When you link Apple: the app-specific identifier, your email (or a Hide My Email relay address), and the authentication token Apple issues | Verifying you with your Apple Account | Per Apple's policy; we keep only the identifier, until you delete your account |
| Google LLC (AdMob · Firebase Analytics) |
United States and others | Advertising and usage data in 1.6 | Ad serving and measurement; counting users | Google's retention policy |
Backup records and Plaza data are stored in the Seoul region (asia-northeast3). Authentication (Firebase Authentication), advertising (AdMob), and usage-statistics (Firebase Analytics) data is processed on Google LLC's global infrastructure and may be transferred outside Korea (including to the United States); see policies.google.com/privacy.
4. Your rights and choices
Everything below can be done directly in the app. Because accounts carry no name, and an email only when Apple is linked, we can only locate a specific account by its user code if you contact us by email.
- Access and copy — your diary is always available in the Journal tab. Backup status and your user code are in Me › Settings › Backup & device transfer.
- Stop backup and delete the server copy — turn Backup off; the server copy is deleted immediately. Records on this device are kept.
- Delete Plaza posts — Plaza › My posts.
- Delete answers — delete a public or only-me answer from ⋯ on your answer in the question's detail screen, or in Plaza › ⋯ › My activity › Answers. Public answers can't be edited; delete and write again. However, you can't answer a question again if your answer to it was deleted while hidden after reports, or removed by us.
- Unblock — Plaza › ⋯ › Blocked lets you remove question-author blocks and answer-author hides separately.
- Delete your account — Backup & device transfer › Delete account. Deletes the account, user code, all backup records on the server (including backup copies of only-me answers), and the authentication account (including any linked Apple/Google sign-in). All public answers you posted are deleted too, as are your reactions, reports, and block list. Questions you posted remain, however (see 1.4). You choose whether to keep the diary on this device. This cannot be undone.
- Questions and objections — support@hanilsoft.net
5. Deletion
- Turning Backup off deletes the server copy immediately.
- Deleting your account immediately deletes backup records, the user code, the account document, and the authentication account. We keep no separate archives or backup copies.
- Deleting your account also deletes all your public answers (text and fingerprint cleared), deletes your reactions (removing them from the totals), and deletes your report records (questions and answers) and block list. Report counts already accumulated on posts are kept. Questions you posted remain as described in 1.4.
- Plaza posts are deleted as described in 1.4. Posts (questions or answers) hidden by reports are invisible to other users and may be deleted after review.
- Daily limit counters expire after 7 days; restore-attempt records after 2 days.
- Inactive accounts are not deleted automatically.
6. Security
- All traffic between the app and our server is encrypted with HTTPS (TLS).
- The database is closed to direct client access; only authenticated requests through our API are accepted, and every request is token-verified.
- Backup records are isolated per account; there is no path to another account's records.
- Auth tokens on the device are stored in the iOS Keychain.
- Server logs never contain diary text, answer text, question text, user codes, or raw IP addresses — only event type, identifiers, and timestamps.
- The same rule applies to analytics events: their names and parameters are fixed in code and cannot carry free text.
- With app lock on, the app requires biometric authentication when returning from the background and hides its content in the app switcher.
7. No sale, advertising, or tracking
- We never sell your data or share it for advertising.
- Plaza posts (questions and public answers) are shown to other users by the nature of the feature; you publish them yourself, and this is not third-party sharing.
- The app contains the Google AdMob (advertising) and Firebase Analytics (usage statistics) SDKs. It contains no attribution SDK and no other third-party analytics SDK.
- We perform no tracking under App Tracking Transparency, never request tracking permission, and do not use the advertising identifier (IDFA). Ads are non-personalised.
- Data processed by the ads SDK is handled by Google under its own policies; we do not receive or store it.
- Data may be disclosed only where required by law, following the procedures the law prescribes.
8. Plaza moderation: reports, blocks, and removal
- Every question and public answer is automatically checked on the server before it is published (length, contact details or links, blocked words, duplicates, and similar).
- Any user can report any question or public answer (for an answer: ⋯ › Report on the answer in the question's detail screen). Reports from three different users hide the question or answer automatically, and we review reports within 24 hours and remove content that violates the guidelines. A hidden answer remains visible only to its author, in My activity, with a notice that it was hidden.
- There are two kinds of blocking, and they do not affect each other. Block this author on a question hides only that person's questions from your lists. "Hide this person's answers" from an answer's ⋯ hides only that person's answers from answer lists. You can undo either in Plaza › ⋯ › Blocked.
- Report reasons are never shown to the author.
- Limits of anonymity. Public answers show no name or identifier, and the answer author's UID is never included in any response. However, someone who hides one person's answers and then compares answer lists across several questions before and after could pick out a group of "answers written by the same person". That group is not linked to a UID, a name, or the questions that person posted. People may still guess who wrote an answer from its content or timing (for example, an answer posted right after a question), so don't write anything in a public answer that could identify you.
9. Children
QuestionDiary is not directed at children under 14 and we do not knowingly collect their data. Children under 14 must not use the service without parental consent. If you learn that a child under 14 has provided data, email support@hanilsoft.net and we will delete it promptly.
10. Contact
HanilSoft · support@hanilsoft.net
11. Changes
Change history: September 27, 2026 — first version; revised the same day to add sections 1.6, 3, and 7 for advertising (Google AdMob banners and interstitials) and usage statistics (Firebase Analytics), stating the no-ATT, non-personalised-ads principle. September 28, 2026 — revised sections 1.2, 2, 3, and 4 for optional Apple/Google account linking; Google linking receives only an identifier, Apple linking requests your email to offer "Hide My Email" (stored only in the Firebase Authentication record); no name is requested. (1.1 release date — to be set before publishing) — revised the Summary and sections 1.1, 1.3, 1.4, 1.5, 1.6, 2, 4, 5, 6, 7, and 8 for answering and reactions on the Plaza in app version 1.1: you can answer a Plaza question as "Only me" (the default; stored on your device, with a copy only if Backup is on) or "Public in the Plaza"; public answers are shown anonymously to all users and are deleted when you delete your account; likes were replaced by five reactions, with existing likes moved to ❤️; answer reports, the separation of question blocks and answer hides, and the limits of anonymity are described. This revision takes effect on the 1.1 release date; the effective and last-revised dates at the top of this page will be updated when it is published. Changes are posted on this page at least 7 days before taking effect, or 30 days in advance where the change materially affects your rights, in which case we may ask for consent again in the app.