정책 문서 홈

해빗 개인정보 처리방침

시행일: 2026년 8월 8일

해빗은 습관 관리, 캐릭터, 선택형 클라우드 백업, 라운지, 챌린지와 보상형 광고를 제공하기 위해 아래 정보를 처리합니다. 걸음 수 자동 검증 미션을 선택하면 건강·피트니스 데이터인 일별 누적 걸음 수에 접근할 수 있습니다. 건강 데이터는 광고 또는 개인 맞춤화에 사용하거나 판매하지 않습니다.

1. 처리 목적과 항목

1.1 앱 기본 기능과 기기 저장

1.2 선택형 계정 연결과 클라우드 백업

Google, Apple 또는 Kakao 계정을 연결하면 공급자 계정 식별자, 허용된 이메일·이름·닉네임·프로필 정보, 인증 토큰, Supabase 사용자 ID·세션, 설치 식별자와 동기화 대상 앱 데이터가 처리될 수 있습니다. Kakao 로그인에서는 허용된 경우 Kakao ID, 플랫폼 정보와 프로필 이미지 URL도 인증 메타데이터에 저장될 수 있습니다.

클라우드 교체 동기화 전 복구를 위해 기존 서버 데이터 전체의 안전 백업 사본, 레코드 수, 백업 사유와 시각이 Supabase에 저장될 수 있습니다. 계정 연결은 선택 사항입니다.

1.3 라운지

온보딩을 마치고 닉네임을 설정하면 라운지 순위 동기화를 위해 소셜 로그인과 별개의 익명 Supabase 인증 ID와 세션이 자동 생성될 수 있습니다. 닉네임, 소개, 언어, 캐릭터와 착용 상태, 누적 당근, 연속 출석, 게시글, 댓글, 반응, 신고와 차단 정보가 저장될 수 있습니다.

닉네임, 캐릭터, 누적 당근, 연속 출석, 순위와 공개 게시물·댓글·반응 수는 다른 라운지 이용자에게 표시될 수 있습니다. 소셜 계정 이름과 기기의 프로필 이미지 파일은 공개하지 않습니다.

1.4 챌린지·푸시·번역

챌린지에 참여하면 설치·추천 식별자 기반 참여자 키, 닉네임, 캐릭터, 역할·준비 상태, 방·미션 정보, 채팅, 완료·기여 기록, 응원 내역이 Supabase에 저장되고 같은 방 팀원에게 표시될 수 있습니다. 알림을 허용하면 Expo Push Token, 플랫폼, 언어와 알림 전달 상태도 저장됩니다.

채팅 번역을 실행하면 방·참여자·댓글 식별자, 목표 언어와 채팅 원문이 Supabase 서버 함수를 거쳐 Google Cloud Translation에서 처리되고 번역 결과가 수신 기기에 캐시될 수 있습니다.

1.5 챌린지 자동 검증

사용자가 미션 설명을 확인하고 운영체제 권한을 허용한 경우에만 작동합니다.

1.6 추천·초대와 광고

추천 링크를 만들거나 열면 초대자·수신자의 추천 및 설치 식별자, 연결된 인증 사용자 ID와 수락 날짜가 Supabase에 저장될 수 있습니다. 수신자 수락 등록은 링크를 열 때 자동 처리될 수 있습니다.

보상형 광고 이용 시 Google Mobile Ads SDK가 IP 주소와 대략적 위치, 광고 식별자 또는 앱 세트 ID, 앱·광고 상호작용과 진단 정보를 처리할 수 있습니다. 광고 요청은 비개인 맞춤 옵션으로 전송합니다.

해빗은 전화번호, GPS 기반 정확한 위치, 연락처, 마이크 녹음, SMS, 통화 기록 또는 결제정보를 앱에서 수집하지 않으며 별도의 행동 분석·오류 추적 SDK와 생성형 AI 서비스를 사용하지 않습니다.

2. 이용 목적

3. 보유 및 이용 기간

정보보유 기간
기기 앱 데이터·설치/추천 식별자·번역 캐시·프로필 이미지앱 삭제 또는 운영체제 앱 데이터 삭제 시까지
소셜 인증·클라우드 데이터·안전 백업클라우드 계정 삭제 또는 삭제 요청 완료 시까지
라운지 익명 프로필과 활동별도 라운지 데이터 삭제 또는 요청 완료 시까지
개별 삭제한 라운지 게시글·댓글본문은 비워지지만 삭제 상태와 일부 메타데이터는 전체 라운지 데이터 삭제 전까지 유지될 수 있음
챌린지 멤버·미션 진행방 나가기 또는 방 삭제 시까지
챌린지 채팅·응원·상호작용방 삭제 시까지. 작성자가 나가도 다른 참여자가 남아 있으면 유지될 수 있음
챌린지 푸시 토큰챌린지 멤버 또는 방 삭제 시까지
계정과 연결되지 않은 추천 기록별도 자동 삭제 기간이 설정되어 있지 않아 이메일 삭제 요청 시까지 남을 수 있음

챌린지 방의 만료 시각만으로 서버 행이 즉시 자동 삭제되지는 않습니다. 법령상 별도 보존이 필요한 경우 해당 기간 동안 분리 보관한 후 파기합니다.

4. 다른 이용자에 대한 공개·제공

해빗은 개인정보를 판매하지 않으며 공개·공유 기능, 서비스 제공에 필요한 처리 위탁, 법령상 근거 또는 별도 동의가 있는 경우를 제외하고 제3자에게 제공하지 않습니다.

5. 외부 서비스와 처리 위탁

서비스업무정보
Supabase인증, 데이터베이스, 서버 함수와 백업인증·설치 식별자, 앱 백업, 라운지, 챌린지, 추천 정보
Google로그인, 번역, 광고·UMP, Android 푸시와 걸음 수인증·프로필, 번역 채팅, 광고·동의·푸시 정보, 기기 걸음 수
Apple로그인, HealthKit·Family Controls·DeviceActivity, APNs인증·허용된 이메일/이름, 기기 내 건강·사용 판정, 푸시 정보
Kakao선택형 로그인토큰, Kakao ID, 허용된 이메일·닉네임·프로필 이미지 URL
Expo챌린지 푸시 중계Expo Push Token, 알림 제목·본문과 챌린지 식별정보

자세한 내용은 개인정보 제3자 제공 및 처리위탁 동의에서도 확인할 수 있습니다.

6. 국외 처리

Supabase, Google, Apple, Kakao와 Expo의 인프라 위치에 따라 인증, 클라우드 저장, 번역, 광고와 푸시 정보가 국외에서 처리될 수 있으며 기능 이용 시 암호화된 네트워크로 전송됩니다. 정확한 계약 법인, 처리 국가와 공급자별 보유기간은 코드만으로 확인되지 않아 실제 계약·프로젝트 리전 확인 후 보완해야 합니다.

7. 권한·자동 저장과 거부 방법

앱은 SecureStore, AsyncStorage와 앱 문서 저장소에 식별자, 세션, 앱 데이터, 설정과 프로필 이미지를 저장합니다. 웹에서는 브라우저 저장공간에 세션을 저장할 수 있습니다. 앱이 직접 웹 쿠키를 생성하지는 않지만 외부 로그인 페이지는 공급자 쿠키를 사용할 수 있습니다.

운영체제 설정에서 알림, 사진, 건강, 활동 인식, 스크린 타임·사용 정보와 광고 추적 권한을 철회할 수 있고, 앱 설정에서 광고 개인정보 선택 화면을 다시 열 수 있습니다. 브라우저 또는 앱 데이터를 삭제하면 로그인 유지·복원·추천·라운지·챌린지 기능이 제한될 수 있습니다.

8. 파기와 이용자 권리

처리 목적 또는 보유기간이 끝난 전자 정보는 확인 후 복구하기 어려운 방식으로 삭제합니다. 이용자는 개인정보의 열람, 정정, 삭제, 처리정지와 동의 철회를 요청할 수 있습니다.

클라우드 계정 삭제는 로컬 데이터, 별도 라운지 익명 계정과 설치 식별자 기반 챌린지 기록을 함께 삭제하지 않습니다. 이메일 요청은 필요한 범위에서 본인 또는 정당한 대리인임을 확인한 후 처리합니다.

9. 안전성 확보와 어린이

인증 세션을 보안 저장소에 보관하고 Supabase 행 수준 보안과 인증된 서버 함수로 접근을 제한합니다. 해빗은 어린이를 주요 대상으로 하지 않지만, 현재 만 14세 미만 가입 제한 또는 법정대리인 동의를 확인하는 별도 기술 절차는 제공하지 않습니다.

10. 개인정보 보호 문의

기능·법령·스토어 정책 또는 외부 서비스가 바뀌면 처리방침을 수정하고 중요한 변경은 앱, 스토어 또는 이 페이지에서 알립니다.

공고일 및 시행일: 2026년 8월 8일 · Habbit Privacy Policy

Habbit Privacy Policy

Effective date: August 8, 2026

Habbit processes the information below to provide habit management, characters, optional cloud backup, the Lounge, challenges, and rewarded ads. If you choose automatic step verification, Habbit may access daily cumulative step count, which is health and fitness data. Health data is not used or sold for advertising or personalization.

1. Information and Purposes

1.1 On-device app data

1.2 Optional accounts and cloud backup

If you connect Google, Apple, or Kakao, provider account identifiers, permitted email, name, nickname and profile information, tokens, Supabase user ID and session, installation identifier, and synchronized app data may be processed. Kakao ID, platform, and profile-image URL may also be stored in authentication metadata when permitted.

Before cloud replacement sync, a complete safety backup of existing server data, record counts, reason, and time may be stored in Supabase. Connecting an account is optional.

1.3 Lounge

After onboarding, setting a nickname may automatically create a separate anonymous Supabase ID and session for Lounge ranking sync. Nickname, bio, language, character and outfit, carrot total, attendance streak, posts, comments, reactions, reports, and blocks may be stored. Nickname, character, rank, public content, and reaction counts may be visible to Lounge users. Social-account names and local profile images are not public.

1.4 Challenges, push, and translation

Challenges may store an installation-identifier-based participant key, nickname, character, role and readiness, room and mission data, chat, completion and contribution records, and cheers in Supabase and show them to teammates. If notifications are allowed, Expo Push Token, platform, language, and delivery state are also stored.

Translation sends room, participant and comment identifiers, target language, and chat text through a Supabase function to Google Cloud Translation. Results may be cached on receiving devices.

1.5 Automatic verification

1.6 Referrals and ads

Creating or opening a referral link may store inviter and recipient referral or installation identifiers, linked auth user IDs, and acceptance date. Recipient acceptance may be registered automatically when the link is opened.

Google Mobile Ads SDK may process IP address and approximate location, advertising or app-set identifiers, app/ad interactions, and diagnostics. Requests use non-personalized ad options. Habbit does not collect phone numbers, precise GPS location, contacts, microphone recordings, SMS, call logs, or payment information, and does not use separate analytics, crash-reporting, or generative-AI services.

2. Purposes of Use

Information is used for habits, virtual savings, goals, statistics, characters and rewards, reminders and challenge push, optional authentication and cloud recovery, Lounge and challenge features, chat translation and verification, referral and ad rewards, security, recovery, and misuse prevention.

3. Retention

InformationRetention
Local app data, identifiers, cache, and profile imageUntil app or operating-system app data deletion
Social authentication, cloud data, and safety backupsUntil cloud account deletion or completed request
Anonymous Lounge identity and activityUntil separate Lounge deletion or completed request
Individually deleted Lounge contentBody is cleared; limited metadata may remain until the Lounge identity is deleted
Challenge membership and mission progressUntil leaving or room deletion
Challenge chat, cheers, and interactionsUntil room deletion; may remain after the author leaves while others remain
Challenge push tokenUntil challenge membership or room deletion
Unlinked referral recordsNo separate automatic deletion period; may remain until an email request

A challenge expiration timestamp does not itself immediately delete server rows.

4. Public and Third-Party Sharing

Lounge users may receive nickname, character, carrot total, attendance streak, rank, and public content. Same-room challenge members may receive nickname, character, readiness, chat, progress and contribution, daily-step-based progress, and cheers. Habbit does not sell personal information and otherwise shares it only for selected public features, necessary processing, legal requirements, or separate consent.

5. Service Providers

See also Third-Party Consent.

6. International Processing

Authentication, cloud storage, translation, ads, and push information may be processed internationally depending on Supabase, Google, Apple, Kakao, and Expo infrastructure, and is transmitted over encrypted networks when features are used. Exact contracting entities, countries, and provider retention periods cannot be determined from code alone and must be supplemented after checking contracts and project regions.

7. Permissions, Storage, and Choices

The app uses SecureStore, AsyncStorage, and app document storage for identifiers, sessions, app data, settings, and profile images. Web sessions may use browser storage. The app does not directly create web cookies, but external sign-in pages may use provider cookies.

You may revoke notification, photo, health, activity-recognition, screen-time or usage-access, and ad-tracking permissions in system settings, reopen ad privacy choices in the app, or clear browser or app data. Some sign-in, restore, referral, Lounge, or challenge features may then be limited.

8. Deletion and Your Rights

Electronic information is deleted in a manner intended to make recovery difficult after its purpose or retention period ends. You may request access, correction, deletion, restriction, or withdrawal of consent.

Cloud account deletion does not also delete local data, the separate anonymous Lounge account, or installation-identifier-based challenge records. Email requests may require identity or representative verification.

9. Security and Children

Sessions are stored in secure storage and access is limited through Supabase row-level security and authenticated server functions. Habbit is not primarily directed to children, but currently has no separate technical flow to restrict users under 14 or verify guardian consent.

10. Contact

Material changes will be announced through the app, store page, or this page.