해빗 개인정보 처리방침
해빗은 습관 관리, 캐릭터, 선택형 클라우드 백업, 라운지, 챌린지와 보상형 광고를 제공하기 위해 아래 정보를 처리합니다. 걸음 수 자동 검증 미션을 선택하면 건강·피트니스 데이터인 일별 누적 걸음 수에 접근할 수 있습니다. 건강 데이터는 광고 또는 개인 맞춤화에 사용하거나 판매하지 않습니다.
1. 처리 목적과 항목
1.1 앱 기본 기능과 기기 저장
- 습관 이름·유형·금액·알림 시간과 요일, 날짜별 달성 횟수
- 적립금 사용 금액·날짜·메모, 월 목표, 하루 마감 편지·기분·정산 결과와 통계
- 닉네임, 캐릭터 성장·상태·보유 및 착용 아이템·위치와 크기, 당근·경험치·출석·업적·보상·친구 캐릭터
- 피드백, 정산 시각, 알림음, 배경 음악, 언어, 알림 예약 ID와 앱 운영 상태
- Android ID를 바탕으로 구성한 Android 설치 식별자 또는 다른 플랫폼에서 임의 생성한 설치 식별자, 추천 식별자
- 사용자가 선택한 프로필 이미지. 앱 전용 기기 저장소에 보관하며 클라우드 백업에 포함하지 않습니다.
1.2 선택형 계정 연결과 클라우드 백업
Google, Apple 또는 Kakao 계정을 연결하면 공급자 계정 식별자, 허용된 이메일·이름·닉네임·프로필 정보, 인증 토큰, Supabase 사용자 ID·세션, 설치 식별자와 동기화 대상 앱 데이터가 처리될 수 있습니다. Kakao 로그인에서는 허용된 경우 Kakao ID, 플랫폼 정보와 프로필 이미지 URL도 인증 메타데이터에 저장될 수 있습니다.
클라우드 교체 동기화 전 복구를 위해 기존 서버 데이터 전체의 안전 백업 사본, 레코드 수, 백업 사유와 시각이 Supabase에 저장될 수 있습니다. 계정 연결은 선택 사항입니다.
1.3 라운지
온보딩을 마치고 닉네임을 설정하면 라운지 순위 동기화를 위해 소셜 로그인과 별개의 익명 Supabase 인증 ID와 세션이 자동 생성될 수 있습니다. 닉네임, 소개, 언어, 캐릭터와 착용 상태, 누적 당근, 연속 출석, 게시글, 댓글, 반응, 신고와 차단 정보가 저장될 수 있습니다.
닉네임, 캐릭터, 누적 당근, 연속 출석, 순위와 공개 게시물·댓글·반응 수는 다른 라운지 이용자에게 표시될 수 있습니다. 소셜 계정 이름과 기기의 프로필 이미지 파일은 공개하지 않습니다.
1.4 챌린지·푸시·번역
챌린지에 참여하면 설치·추천 식별자 기반 참여자 키, 닉네임, 캐릭터, 역할·준비 상태, 방·미션 정보, 채팅, 완료·기여 기록, 응원 내역이 Supabase에 저장되고 같은 방 팀원에게 표시될 수 있습니다. 알림을 허용하면 Expo Push Token, 플랫폼, 언어와 알림 전달 상태도 저장됩니다.
채팅 번역을 실행하면 방·참여자·댓글 식별자, 목표 언어와 채팅 원문이 Supabase 서버 함수를 거쳐 Google Cloud Translation에서 처리되고 번역 결과가 수신 기기에 캐시될 수 있습니다.
1.5 챌린지 자동 검증
사용자가 미션 설명을 확인하고 운영체제 권한을 허용한 경우에만 작동합니다.
- 걸음 수 미션은 Apple HealthKit, Android Health Connect 또는 지원되는 Android 기기의 Google Local Recording API에서 일별 누적 걸음 수를 읽습니다.
- 밤 10시 이후 휴대폰 미사용 미션은 iOS Family Controls·DeviceActivity 또는 Android 사용 정보 접근으로 22:00~24:00 사이 사용 여부를 기기에서 판정합니다.
- 개별 걸음 샘플, 운동 경로, 위치, 심박수, 수면, 체중, 의료 기록, 앱 이름, 패키지 식별자, 방문 사이트와 개별 사용 이벤트는 서버에 업로드하지 않습니다.
- 일별 누적 걸음 수, 목표 진행량, 성공·실패, 측정 출처·플랫폼, 시간대 오프셋과 검증 시각만 챌린지 진행을 위해 동기화될 수 있습니다.
1.6 추천·초대와 광고
추천 링크를 만들거나 열면 초대자·수신자의 추천 및 설치 식별자, 연결된 인증 사용자 ID와 수락 날짜가 Supabase에 저장될 수 있습니다. 수신자 수락 등록은 링크를 열 때 자동 처리될 수 있습니다.
보상형 광고 이용 시 Google Mobile Ads SDK가 IP 주소와 대략적 위치, 광고 식별자 또는 앱 세트 ID, 앱·광고 상호작용과 진단 정보를 처리할 수 있습니다. 광고 요청은 비개인 맞춤 옵션으로 전송합니다.
해빗은 전화번호, GPS 기반 정확한 위치, 연락처, 마이크 녹음, SMS, 통화 기록 또는 결제정보를 앱에서 수집하지 않으며 별도의 행동 분석·오류 추적 SDK와 생성형 AI 서비스를 사용하지 않습니다.
2. 이용 목적
- 습관·적립금·목표·통계·하루 마감과 캐릭터·보상 제공
- 리마인더, 하루 마감 알림과 챌린지 푸시 제공
- 선택형 계정 인증, 클라우드 백업·복원·복구
- 라운지 순위·게시글·댓글·반응·신고·차단 제공
- 챌린지 팀 채팅·번역·미션 검증과 진행 공유
- 추천 및 광고 보상, 보안, 장애 대응과 부정 사용 방지
3. 보유 및 이용 기간
| 정보 | 보유 기간 |
|---|---|
| 기기 앱 데이터·설치/추천 식별자·번역 캐시·프로필 이미지 | 앱 삭제 또는 운영체제 앱 데이터 삭제 시까지 |
| 소셜 인증·클라우드 데이터·안전 백업 | 클라우드 계정 삭제 또는 삭제 요청 완료 시까지 |
| 라운지 익명 프로필과 활동 | 별도 라운지 데이터 삭제 또는 요청 완료 시까지 |
| 개별 삭제한 라운지 게시글·댓글 | 본문은 비워지지만 삭제 상태와 일부 메타데이터는 전체 라운지 데이터 삭제 전까지 유지될 수 있음 |
| 챌린지 멤버·미션 진행 | 방 나가기 또는 방 삭제 시까지 |
| 챌린지 채팅·응원·상호작용 | 방 삭제 시까지. 작성자가 나가도 다른 참여자가 남아 있으면 유지될 수 있음 |
| 챌린지 푸시 토큰 | 챌린지 멤버 또는 방 삭제 시까지 |
| 계정과 연결되지 않은 추천 기록 | 별도 자동 삭제 기간이 설정되어 있지 않아 이메일 삭제 요청 시까지 남을 수 있음 |
챌린지 방의 만료 시각만으로 서버 행이 즉시 자동 삭제되지는 않습니다. 법령상 별도 보존이 필요한 경우 해당 기간 동안 분리 보관한 후 파기합니다.
4. 다른 이용자에 대한 공개·제공
- 라운지 이용자: 닉네임, 캐릭터, 누적 당근, 연속 출석, 순위와 공개 콘텐츠
- 같은 챌린지 방 참여자: 닉네임, 캐릭터, 준비 상태, 채팅, 미션 진행·기여, 일별 걸음 수 기반 진행 결과와 응원
해빗은 개인정보를 판매하지 않으며 공개·공유 기능, 서비스 제공에 필요한 처리 위탁, 법령상 근거 또는 별도 동의가 있는 경우를 제외하고 제3자에게 제공하지 않습니다.
5. 외부 서비스와 처리 위탁
| 서비스 | 업무 | 정보 |
|---|---|---|
| Supabase | 인증, 데이터베이스, 서버 함수와 백업 | 인증·설치 식별자, 앱 백업, 라운지, 챌린지, 추천 정보 |
| 로그인, 번역, 광고·UMP, Android 푸시와 걸음 수 | 인증·프로필, 번역 채팅, 광고·동의·푸시 정보, 기기 걸음 수 | |
| Apple | 로그인, HealthKit·Family Controls·DeviceActivity, APNs | 인증·허용된 이메일/이름, 기기 내 건강·사용 판정, 푸시 정보 |
| Kakao | 선택형 로그인 | 토큰, Kakao ID, 허용된 이메일·닉네임·프로필 이미지 URL |
| Expo | 챌린지 푸시 중계 | Expo Push Token, 알림 제목·본문과 챌린지 식별정보 |
자세한 내용은 개인정보 제3자 제공 및 처리위탁 동의에서도 확인할 수 있습니다.
6. 국외 처리
Supabase, Google, Apple, Kakao와 Expo의 인프라 위치에 따라 인증, 클라우드 저장, 번역, 광고와 푸시 정보가 국외에서 처리될 수 있으며 기능 이용 시 암호화된 네트워크로 전송됩니다. 정확한 계약 법인, 처리 국가와 공급자별 보유기간은 코드만으로 확인되지 않아 실제 계약·프로젝트 리전 확인 후 보완해야 합니다.
7. 권한·자동 저장과 거부 방법
앱은 SecureStore, AsyncStorage와 앱 문서 저장소에 식별자, 세션, 앱 데이터, 설정과 프로필 이미지를 저장합니다. 웹에서는 브라우저 저장공간에 세션을 저장할 수 있습니다. 앱이 직접 웹 쿠키를 생성하지는 않지만 외부 로그인 페이지는 공급자 쿠키를 사용할 수 있습니다.
운영체제 설정에서 알림, 사진, 건강, 활동 인식, 스크린 타임·사용 정보와 광고 추적 권한을 철회할 수 있고, 앱 설정에서 광고 개인정보 선택 화면을 다시 열 수 있습니다. 브라우저 또는 앱 데이터를 삭제하면 로그인 유지·복원·추천·라운지·챌린지 기능이 제한될 수 있습니다.
8. 파기와 이용자 권리
처리 목적 또는 보유기간이 끝난 전자 정보는 확인 후 복구하기 어려운 방식으로 삭제합니다. 이용자는 개인정보의 열람, 정정, 삭제, 처리정지와 동의 철회를 요청할 수 있습니다.
- 클라우드 계정·백업: 설정 > MY > 계정 삭제
- 라운지 전체 데이터: 라운지 > 방패 아이콘 > 내 라운지 데이터 삭제
- 기기 로컬 데이터·프로필 이미지: 앱 삭제 또는 운영체제 앱 데이터 삭제
- 챌린지·추천 데이터와 기타 요청: yellowboxer1@naver.com
클라우드 계정 삭제는 로컬 데이터, 별도 라운지 익명 계정과 설치 식별자 기반 챌린지 기록을 함께 삭제하지 않습니다. 이메일 요청은 필요한 범위에서 본인 또는 정당한 대리인임을 확인한 후 처리합니다.
9. 안전성 확보와 어린이
인증 세션을 보안 저장소에 보관하고 Supabase 행 수준 보안과 인증된 서버 함수로 접근을 제한합니다. 해빗은 어린이를 주요 대상으로 하지 않지만, 현재 만 14세 미만 가입 제한 또는 법정대리인 동의를 확인하는 별도 기술 절차는 제공하지 않습니다.
10. 개인정보 보호 문의
- 개인정보 보호책임자: 박건호
- 직책: 개인정보 보호책임자
- 이메일: yellowboxer1@naver.com
- 전화번호: 010-5475-6150
기능·법령·스토어 정책 또는 외부 서비스가 바뀌면 처리방침을 수정하고 중요한 변경은 앱, 스토어 또는 이 페이지에서 알립니다.
Habbit Privacy Policy
Habbit processes the information below to provide habit management, characters, optional cloud backup, the Lounge, challenges, and rewarded ads. If you choose automatic step verification, Habbit may access daily cumulative step count, which is health and fitness data. Health data is not used or sold for advertising or personalization.
1. Information and Purposes
1.1 On-device app data
- Habit names, types, amounts, reminders, and completion counts
- Virtual savings usage, dates, memos, goals, daily letters, mood, settlement results, and statistics
- Nickname, character state and outfit, positioning, carrots, experience, attendance, achievements, rewards, and friend characters
- Feedback, settlement time, sound, music, language, notification IDs, and operational state
- An Android installation identifier based on Android ID, or a randomly generated installation identifier on other platforms, and a referral identifier
- A user-selected profile image stored in app-specific device storage and excluded from cloud backup
1.2 Optional accounts and cloud backup
If you connect Google, Apple, or Kakao, provider account identifiers, permitted email, name, nickname and profile information, tokens, Supabase user ID and session, installation identifier, and synchronized app data may be processed. Kakao ID, platform, and profile-image URL may also be stored in authentication metadata when permitted.
Before cloud replacement sync, a complete safety backup of existing server data, record counts, reason, and time may be stored in Supabase. Connecting an account is optional.
1.3 Lounge
After onboarding, setting a nickname may automatically create a separate anonymous Supabase ID and session for Lounge ranking sync. Nickname, bio, language, character and outfit, carrot total, attendance streak, posts, comments, reactions, reports, and blocks may be stored. Nickname, character, rank, public content, and reaction counts may be visible to Lounge users. Social-account names and local profile images are not public.
1.4 Challenges, push, and translation
Challenges may store an installation-identifier-based participant key, nickname, character, role and readiness, room and mission data, chat, completion and contribution records, and cheers in Supabase and show them to teammates. If notifications are allowed, Expo Push Token, platform, language, and delivery state are also stored.
Translation sends room, participant and comment identifiers, target language, and chat text through a Supabase function to Google Cloud Translation. Results may be cached on receiving devices.
1.5 Automatic verification
- With permission, step missions read daily cumulative steps from Apple HealthKit, Android Health Connect, or Google Local Recording API on supported Android devices.
- The no-phone-after-10-p.m. mission determines use between 22:00 and 24:00 on device through iOS Family Controls and DeviceActivity or Android Usage Access.
- Individual step samples, routes, location, heart rate, sleep, weight, medical records, app names, package IDs, visited sites, and individual usage events are not uploaded.
- Daily steps, progress, pass/fail, source, platform, timezone offset, and verification time may be synchronized for challenge progress.
1.6 Referrals and ads
Creating or opening a referral link may store inviter and recipient referral or installation identifiers, linked auth user IDs, and acceptance date. Recipient acceptance may be registered automatically when the link is opened.
Google Mobile Ads SDK may process IP address and approximate location, advertising or app-set identifiers, app/ad interactions, and diagnostics. Requests use non-personalized ad options. Habbit does not collect phone numbers, precise GPS location, contacts, microphone recordings, SMS, call logs, or payment information, and does not use separate analytics, crash-reporting, or generative-AI services.
2. Purposes of Use
Information is used for habits, virtual savings, goals, statistics, characters and rewards, reminders and challenge push, optional authentication and cloud recovery, Lounge and challenge features, chat translation and verification, referral and ad rewards, security, recovery, and misuse prevention.
3. Retention
| Information | Retention |
|---|---|
| Local app data, identifiers, cache, and profile image | Until app or operating-system app data deletion |
| Social authentication, cloud data, and safety backups | Until cloud account deletion or completed request |
| Anonymous Lounge identity and activity | Until separate Lounge deletion or completed request |
| Individually deleted Lounge content | Body is cleared; limited metadata may remain until the Lounge identity is deleted |
| Challenge membership and mission progress | Until leaving or room deletion |
| Challenge chat, cheers, and interactions | Until room deletion; may remain after the author leaves while others remain |
| Challenge push token | Until challenge membership or room deletion |
| Unlinked referral records | No separate automatic deletion period; may remain until an email request |
A challenge expiration timestamp does not itself immediately delete server rows.
4. Public and Third-Party Sharing
Lounge users may receive nickname, character, carrot total, attendance streak, rank, and public content. Same-room challenge members may receive nickname, character, readiness, chat, progress and contribution, daily-step-based progress, and cheers. Habbit does not sell personal information and otherwise shares it only for selected public features, necessary processing, legal requirements, or separate consent.
5. Service Providers
- Supabase: authentication, database, server functions, backup, Lounge, challenges, and referrals
- Google: sign-in, Cloud Translation, Mobile Ads and UMP, Android push, and device steps
- Apple: sign-in, HealthKit, Family Controls and DeviceActivity, and APNs
- Kakao: optional sign-in, including permitted Kakao ID, email, nickname, and profile-image URL
- Expo: challenge push relay using push token and notification content
See also Third-Party Consent.
6. International Processing
Authentication, cloud storage, translation, ads, and push information may be processed internationally depending on Supabase, Google, Apple, Kakao, and Expo infrastructure, and is transmitted over encrypted networks when features are used. Exact contracting entities, countries, and provider retention periods cannot be determined from code alone and must be supplemented after checking contracts and project regions.
7. Permissions, Storage, and Choices
The app uses SecureStore, AsyncStorage, and app document storage for identifiers, sessions, app data, settings, and profile images. Web sessions may use browser storage. The app does not directly create web cookies, but external sign-in pages may use provider cookies.
You may revoke notification, photo, health, activity-recognition, screen-time or usage-access, and ad-tracking permissions in system settings, reopen ad privacy choices in the app, or clear browser or app data. Some sign-in, restore, referral, Lounge, or challenge features may then be limited.
8. Deletion and Your Rights
Electronic information is deleted in a manner intended to make recovery difficult after its purpose or retention period ends. You may request access, correction, deletion, restriction, or withdrawal of consent.
- Cloud account and backup: Settings > MY > Delete account
- All Lounge data: Lounge > shield icon > Delete my Lounge data
- Local data and profile image: delete the app or operating-system app data
- Challenge, referral, and other requests: yellowboxer1@naver.com
Cloud account deletion does not also delete local data, the separate anonymous Lounge account, or installation-identifier-based challenge records. Email requests may require identity or representative verification.
9. Security and Children
Sessions are stored in secure storage and access is limited through Supabase row-level security and authenticated server functions. Habbit is not primarily directed to children, but currently has no separate technical flow to restrict users under 14 or verify guardian consent.
10. Contact
- Privacy Officer: Gunho Park
- Title: Privacy Officer
- Email: yellowboxer1@naver.com
- Phone: +82-10-5475-6150
Material changes will be announced through the app, store page, or this page.