DOPA Privacy Policy
Version: v1.5 Effective Date: v1.0 release (TBD) Last Updated: 2026-08-27 Scope: DOPA mobile application (“the App”), version 1.0 Frameworks: Apple App Privacy / Google Play Data Safety / California CCPA·CPRA / Children’s COPPA / EU GDPR (informational) / South Korea PIPA as in force on the effective date, including the 2026 amendment effective 2026-09-11 (parallel — see Korean version)
This policy reflects the actual behavior of the App verbatim. All cognitive performance data is stored exclusively on the user’s device. As of policy v1.1, the App additionally offers an anonymous, opt-in usage statistics feature (default OFF, §2.6): if — and only if — you enable it, the App transmits counts-only aggregates of whitelisted event names over HTTPS, with no individual records and no identifiers. With the toggle OFF (the default), the App performs no outbound network transmission, preserving the v1.0 baseline. (See ADR-016 anonymous opt-in telemetry — a conditional extension, not a reversal, of ADR-014 v1 telemetry defer.) Crash reporting (Sentry) is inactive — the Sentry SDK is bundled but never initialized (no DSN), so it is inactive; if it is activated in a later version, this policy will be versioned again and the corresponding Apple App Privacy / Google Play Data Safety forms will be re-submitted.
1. At a Glance — What the App Does and Does Not Do
Your scores are yours — no account, no tracking, zero transmission by default.
- The App is a wellness self-observation tool. It is not a medical device. It does not diagnose, treat, or prevent any disease. (See
health_disclaimer_v1.md.) - The App does not collect data by default. The only outbound transmission the App can ever perform is the anonymous, opt-in usage statistics described in §2.6 — counts-only aggregates with no identifiers, sent only if you explicitly turn the toggle ON (default OFF).
- The App does not sell any personal information. The App does not share any personal information with third parties for cross-context behavioral advertising.
- The App is not directed to children. The App’s age rating is 12+ on Apple; under IARC (Google Play) the estimated rating is region-dependent (estimated; final attestation by operator).
- The App does not use the IDFA / advertising identifiers, and does not request App Tracking Transparency (ATT) permission.
NSPrivacyTrackingis set tofalse. The iOS privacy manifest declares the opt-in usage statistics as Usage Data / Not Linked to You / No Tracking. - What the App does not have (trust checklist): no account · zero advertising SDKs · zero third-party analytics SDKs · crash reporting inactive (the Sentry SDK is bundled but never initialized — no DSN) · no advertising identifiers (IDFA / GAID) · no GPS / location permission · no camera / microphone / contacts / photos / calendar permission.
- One service provider: Cloudflare, Inc. (US) receives and stores the opt-in anonymous aggregates only — it is an infrastructure processor, not an advertising or analytics third party (§4, §5).
- Your rights are exercised inside the App: view in the Rhythm and Progress tabs, take a copy via My > Export data, erase via My > Delete all data — no request to the operator is needed (§6).
- Contact for privacy inquiries and grievances: Seo YeJin, Privacy Officer · yejin255@naver.com (§9).
2. Information Stored On Your Device
The App stores the following items, all of which remain on your device. (If you enable the anonymous usage statistics of §2.6, only counts-only aggregates leave the device — never the items below in raw form.)
Legal basis and required / optional split: §2.1–§2.4 are required to provide the App (performance of the service you requested — PIPA §15(1)4; GDPR Art. 6(1)(b) where applicable) and are all generated automatically on the device — nothing is typed in by you. §2.6 is optional and processed only on your explicit consent (PIPA §15(1)1; GDPR Art. 6(1)(a)) given via the opt-in toggle.
2.1 Identifiers (local-only) [required · auto-generated]
- Local anonymous ID — a random identifier generated on the device at install time. The App does not collect names, email addresses, phone numbers, postal addresses, government IDs, social security numbers, or any direct identifier.
2.2 Cognitive Performance Data [required · auto-generated]
- Session timestamps, cycle counts, response times, and accuracy for the three cognitive tasks (task switching, N-back, digit-symbol substitution)
- Breath pacer cycle completion (cycles_completed: 0~3)
- User-chosen goal (goal chip), and prior video / task history
2.3 Device Environment [required · auto-generated]
- Device model name (used locally for device-specific normalization of cognitive metrics)
2.4 Consent and Settings [required · auto-generated]
- Onboarding completion status (
onboarding_completed) - Notification permission status
- Analytics opt-in flag (
analytics_opt_in— default OFF). Controls the anonymous usage statistics transmission described in §2.6; you can turn it ON or OFF at any time via the “Share anonymous usage stats” toggle in the My tab. - Selected language (i18n)
The on-device database still contains
disclaimer_acceptedandcalibration_statuscolumns from an earlier version, but the corresponding steps have been retired from the App, so no new values are written to them. Neither leaves your device.
Items the App does not collect: name, contact information, email, phone number, government ID numbers, GPS location, photos / contacts / calendar, advertising identifiers (IDFA / GAID), demographic data, payment information, biometric identifiers.
2.5 Sensitive / Health Data — Position Statement
The cognitive performance data and breath pacer records processed by the App are not treated as “sensitive health data” by the App, on the following grounds.
- Non-medical processing — the App is not a medical device and does not pursue diagnosis, treatment, or prevention. The data is used as self-observation performance metrics, not as a measure of medical health.
- No external transmission or diagnostic use — there is no pathway for these records themselves to leave the device or be used for clinical decisions. (The opt-in telemetry of §2.6 transmits only counts of event names per anonymous segment — never reaction times, accuracy values, scores, or any other performance values.)
- Anonymous local processing — without direct identifiers, the records cannot be combined into identifiable health information outside the device.
This is the App’s good-faith interpretation. If future authoritative legal review, regulator interpretation, or relevant precedent reclassifies these records as sensitive / special-category data, the App will introduce additional consent flows and version this policy. Any medical-context feature (e.g., clinical scale outputs, medical-institution integration) triggers re-evaluation of §2.5. (The §2.6 telemetry was evaluated under this clause for policy v1.1: because it transmits only event-name counts and never the performance values themselves, the position above is unchanged.)
2.6 Anonymous Usage Statistics (Opt-In, Default OFF) [optional · opt-in]
If — and only if — you enable the “Share anonymous usage stats” toggle in the My tab (default: OFF), the App transmits the following, and nothing else:
- Counts-only aggregates of event names. The App counts occurrences of event names drawn from a fixed, predefined whitelist (maintained in the App’s event-contract document; the number of names may change between App versions — e.g., app opened, session started, session completed) and transmits those counts. No individual event rows, no precise timestamps, no user or session identifiers, and no event payloads (cognitive scores, goal text, device model, etc.) are ever transmitted.
- Coarse segment dimensions attached to those counts:
- region —
KR/US/OTHER(3 values only, derived from the device’s Region setting; never GPS or precise location, which the App does not request or use) - timezone-offset bucket (e.g., UTC+9 — derived from the device clock’s UTC offset; not your precise time, not an IANA timezone string)
- platform (
ios/android) - app version
- event-contract version
- region —
- A batch deduplication identifier and a schema identifier.
batch_idis a deterministic hash of the transmitted batch (used only so duplicate retransmissions of the same batch can be absorbed); it is unrelated to you or your device and cannot be linked to any identity. The schema identifier (dopa_telemetry_v1) names the aggregation format version.
Protections:
- Opt-in only — the toggle defaults to OFF. With the toggle OFF, the App performs no outbound transmission whatsoever (the v1.0 baseline behavior is preserved exactly).
- Immediate withdrawal — turning the toggle OFF stops transmission immediately (see §6).
- k-anonymity (k = 5) — the transmitted and stored unit is per-batch counts; when segment statistics are produced (server-side aggregation / analysis), a k = 5 rule (measured in uploaded batches) merges any segment with fewer than 5 samples into an “other” bucket, so sparse segment combinations cannot single out an individual. (k is a server-side parameter and may be raised as the user base grows.)
- No tracking — no IDFA / GAID, no per-install identifier is transmitted, no cross-app or cross-site tracking. The iOS privacy manifest declares this data as Usage Data / Not Linked to You / No Tracking.
- No new SDKs — transmission uses the platform’s built-in HTTPS client only; no third-party analytics SDK is embedded, so no third party can auto-collect anything beyond the fields listed above.
Legal character — anonymous information: the §2.6 aggregates are designed so that no individual can be identified from them even in combination with other information, taking reasonable time, cost, and technology into account. The App therefore treats them as anonymous information outside the scope of PIPA (§58-2) and, for the same reason, outside the scope of “personal data” under the GDPR. For transparency, the App nevertheless applies the processor disclosure (§4), the international-transfer disclosure (§5), and the consent-withdrawal mechanism (§6) to these aggregates voluntarily. This is a good-faith interpretation of the same kind as §2.5; if a regulator or court reads it differently, this policy will be versioned.
Operational note (verbatim disclosure): as of this policy version, the collection endpoint is not yet deployed — the App’s telemetry client is configured with an empty endpoint and performs no transmission even when the toggle is ON. This section governs the App’s behavior from the moment the endpoint is activated.
3. Data Location and Retention
3.1 Storage Location
All on-device, locally only.
- Cognitive performance / session data: device-local SQLite database (
dopa.db) - Settings / language selection: device-local MMKV key-value store
- Audio / video assets: bundled within the App’s static assets
No cloud sync, no advertising network, no analytics SDK. With the anonymous-usage-statistics toggle OFF (the default), the App makes no outbound network requests during normal operation. With the toggle ON, the only outbound transmission is the counts-only aggregates described in §2.6, sent over HTTPS to a collection endpoint operated for the App on Cloudflare infrastructure (see §4).
You can export a copy of your own data via My > Export data (JSON). This is a user-initiated share (OS share sheet) — the App never transmits your records externally on its own. (The only automatic transmission the App can perform is the opt-in, counts-only aggregates of §2.6, which never include your records.)
3.2 Retention
- Data is retained while the App is installed and you do not actively delete it.
- Uninstalling the App causes the operating system to remove the SQLite / MMKV areas, deleting all records.
- My > Delete all data performs an immediate in-app wipe of all local data (all SQLite tables + MMKV). It also clears the analytics opt-in consent record, so no further §2.6 transmission occurs afterwards.
- Anonymous aggregates transmitted under §2.6 (only if you opted in) are retained server-side as statistical records. Retention period: as anonymous information (see §2.6, Legal character) they are kept without a fixed expiry and are destroyed when the App’s service is discontinued (no server-side automatic deletion schedule is implemented; if one is, this section will be updated). Method of destruction: the relevant server-side database / tables are deleted irrecoverably. They contain no identifiers and cannot be traced back to you or your device; see §6 for the honest consequence of this for per-person deletion.
4. Third Parties / Service Providers
The App engages one infrastructure service provider, and only for the opt-in anonymous usage statistics described in §2.6:
| Processor | Role | Data received | Location |
|---|---|---|---|
| Cloudflare, Inc. (United States) | Serverless receipt and storage infrastructure (Cloudflare Worker + D1 database) for the anonymous usage statistics | Counts-only anonymous aggregates (§2.6) — no identifiers; the App’s ingestion endpoint does not store IP addresses | US legal entity; database placement uses a data residency hint of Asia-Pacific (apac) |
Cloudflare acts as an infrastructure processor only — it is not a third-party advertising or analytics company; it receives no personal information from the App, and no data is shared with any third party for advertising, profiling, or any purpose other than hosting the App’s own anonymous aggregates. The App embeds zero third-party analytics SDKs (transmission uses the platform’s built-in HTTPS client only), so Cloudflare receives only the §2.6 fields the App explicitly sends and nothing is auto-collected. With the §2.6 toggle OFF (default), Cloudflare receives nothing.
Sentry (crash reporting) is not active — the Sentry SDK is included in the App’s code but is never initialized (no DSN is configured), so no crash data is collected or transmitted. Crash reporting and the §2.6 usage statistics are two independent transmission tracks and are never merged. If Sentry (or an alternative) is activated in a future version, prior notice will be given, this policy will be versioned, and the Apple App Privacy / Google Play Data Safety records will be updated.
5. International Data Transfers
Opt-in usage statistics only. If you enable the anonymous usage statistics (§2.6), the counts-only aggregates are received and stored on infrastructure operated by Cloudflare, Inc., a United States corporation. The storage placement uses an Asia-Pacific data residency hint, but because the infrastructure operator is a US legal entity, this is disclosed as a cross-border transfer for the purposes of South Korea’s PIPA (see the Korean-language version of this policy for the PIPA narrative).
With the toggle OFF (the default), no data leaves the device and no international transfer occurs. (If a future version uses additional providers hosted outside your jurisdiction, prior notice and any required consents will be obtained before activation.)
6. Your Choices and Rights
You have the following choices regarding the App:
- Access — all your performance records are visible in the App’s Rhythm and Progress tabs and its session Result screen. There is no separate access request required, because the records reside on your device. You can also obtain a full copy via My > Export data (JSON, user-initiated share).
- Correction — the stored items (§2) are objective records generated automatically from your own performance; there is no typed-in field (name, contact, etc.) to correct. Records you consider wrong are handled through deletion: the App has no per-session delete, so the route is My > Delete all data and re-recording.
- Deletion — My > Delete all data performs an immediate in-app wipe of all local data (SQLite + MMKV) and also clears the analytics opt-in consent. Uninstalling the App likewise deletes all data on your device.
- Stop processing — declining notification permission stops notification processing; not using the App stops all measurement.
- Portability — My > Export data (JSON) gives you a complete, machine-readable copy that you can take anywhere. (The App is not a covered entity under PIPA’s data-portability right, §35-2, which applies only to controllers above a size threshold; the export is provided voluntarily and offers the equivalent.)
- Exercise by a guardian or agent — a legal guardian or an authorized agent may contact the operator through the §9 mailbox. Because the operator cannot access data on your device, viewing or erasing it can only be done on the device itself.
- Anonymous usage statistics (§2.6) — strictly opt-in via the toggle in the My tab (default OFF). Turning the toggle OFF at any time stops all transmission immediately. Honest limitation: aggregates already transmitted contain no identifiers, so your individual contribution to an anonymous count cannot be located or deleted afterwards — the same property that makes the data incapable of identifying you also makes per-person erasure technically impossible.
Region-specific Supplements
The choices above are the global baseline that applies to everyone. The following are jurisdiction-specific supplements; where a supplement adds or clarifies a right, it controls for residents of that jurisdiction.
California residents (CCPA / CPRA): The App processes no personal information for “sale” or “sharing” as defined under California law, and the anonymous usage statistics of §2.6 are counts-only aggregates not reasonably capable of being associated with, or linked to, a particular consumer or household. Categories of personal information collected under the CCPA/CPRA: none. You have the following rights, addressed as follows:
- Right to know / access — your records reside on your device; view them in the Rhythm and Progress tabs or the Result screen, or export via My > Export data (JSON).
- Right to delete — My > Delete all data wipes all local data; uninstalling does the same.
- Right to correct — records are self-generated on-device and can be deleted/regenerated through normal use.
- Right to opt out of sale / sharing — not applicable: the App does not sell or share personal information, so no “Do Not Sell or Share My Personal Information” mechanism or toggle is required.
- Right to limit use of sensitive personal information — the App collects no “sensitive personal information” as defined by the CPRA (see §2.5).
- Right to non-discrimination — exercising any choice (e.g., leaving §2.6 OFF) carries no penalty; all features remain fully available.
To make an inquiry about these rights, contact the operator at yejin255@naver.com (§9).
Children (COPPA): The App is not directed to children under 13 and does not knowingly collect personal information from children. The App’s age rating is 12+ (informational, attestation by operator). Age thresholds differ by jurisdiction by design — South Korea’s PIPA uses an under-14 threshold; see the Korean-language version §6 for the under-14 standard. The App takes the same “not directed to children + no knowing collection” position under both.
EU / EEA residents (GDPR): The anonymous usage statistics (§2.6) are designed to fall outside the scope of personal data (counts-only, no identifiers, k-anonymity with k = 5). To the extent any processing is nonetheless treated as processing of personal data, the legal basis is consent (the explicit opt-in toggle, OFF by default), and you have the following rights, exercised as follows:
- Right of access & data portability — all your records are on your device and viewable in the Rhythm and Progress tabs or the Result screen; you can obtain a full machine-readable copy via My > Export data (JSON). No request to the operator is needed.
- Right to erasure — My > Delete all data wipes all local data immediately; uninstalling does the same. (Per-person erasure of already-transmitted anonymous aggregates is technically impossible because they contain no identifier — see the honest limitation above.)
- Right to restriction & objection — turn the §2.6 toggle OFF (default) to stop the only processing that could leave the device; declining notification permission or not using the App stops all other processing.
- Right to withdraw consent — the §2.6 toggle turned OFF withdraws consent immediately and is as easy as giving it.
- Right to rectification — records are self-generated on your device; you can delete and regenerate them via normal use.
- Right to lodge a complaint — you may lodge a complaint with your local EU/EEA supervisory authority (Data Protection Authority).
If GDPR-relevant processing beyond §2.6 is introduced in a future version, separate notice and a lawful basis will be established at that time. No automated decision-making or profiling producing legal or similarly significant effects is performed.
South Korea residents (PIPA): See the Korean-language version (privacy_policy_v1.md) for the PIPA §30 narrative and the dispute-resolution bodies.
7. Device Permissions
| Permission | Purpose | Effect of Denial |
|---|---|---|
| Notifications | Trigger local notifications at user-configured times | No notifications; all measurement features continue to work |
Remote push, camera, location, photos, microphone, contacts, and calendar permissions are not requested.
8. Security
Because per-person data never leaves the device, most safeguards sit with the device and with you; the operator’s own measures apply only to the server-side store of the §2.6 anonymous aggregates.
Administrative
- The operator is a single person (the publisher, who is also the Privacy Officer); access to the server-side store and the deployment account is granted to that one person only (least privilege).
- This policy is checked against the App’s actual behavior at every release, and every change is published in the version history (§10, §11).
Technical
- With the §2.6 toggle OFF (the default), data does not leave the device and communication-channel exposure is not applicable.
- The opt-in usage statistics (§2.6) are transmitted exclusively over HTTPS (TLS) — encrypted in transit.
- The App’s ingestion endpoint does not store IP addresses, and ingestion is idempotent — duplicate retransmissions of the same batch are designed to be absorbed without inflating counts (in rare edge cases anonymous totals may be slightly overcounted; no personal records exist to be duplicated).
- k-anonymity (k = 5) merging is applied server-side at aggregation / analysis time — when segment statistics are produced — so that sparse segments cannot single out an individual (§2.6).
- The server-side store and deployment account are protected by the infrastructure provider’s (Cloudflare) account authentication and access controls.
- On-device security depends on device-level protections (OS passcode, app sandbox).
- Code integrity: official Apple App Store / Google Play distribution channels only.
Physical
- The operator runs no servers or physical facilities of its own. The server-side store lives in the processor’s (Cloudflare) data centers, whose physical access controls apply (§4).
Incident notification (PIPA §34 as amended, effective 2026-09-11)
- If personal information is lost, stolen, leaked, forged, altered, or damaged — or the operator becomes aware that this may have happened — the operator will notify affected data subjects without delay of what happened (items, time, circumstances), what they can do to limit harm, the contact point (§9), and how to claim damages or apply for dispute mediation (§9), and will report to the Personal Information Protection Commission or KISA where the statutory thresholds are met.
- Given the App’s design, however, on-device data cannot be accessed or leaked by the operator, and the server-side data are identifier-free aggregates from which no affected individual can be determined. In that situation, individual notice is replaced by a notice in the App and on the legal-documents page (§10).
9. Contact — Privacy Officer and Grievances
- Name: Seo YeJin
- Title: Publisher (sole proprietor) and Privacy Officer
- Email: yejin255@naver.com (single point of contact for privacy inquiries, rights and access requests, objections, and grievances)
- Telephone: no telephone helpline is operated. Inquiries and rights requests received by email are answered within 10 days of receipt (the statutory handling period for access requests under the PIPA Enforcement Decree). Because the App holds no account or contact details and all personal data stays on your device, there is no rights request the operator could carry out for you over the phone.
- App Store / Play Store developer page: TBD
Under PIPA §30-3 (effective 2026-09-11) ultimate responsibility for personal-information protection rests with the business owner — here the publisher personally — who also serves as the Privacy Officer. There is no separate department: access requests and grievances are handled directly by the Privacy Officer.
Automated decisions (PIPA §37-2 / GDPR Art. 22): the App makes no fully automated decision that significantly affects your rights or obligations (not applicable). The scores, baselines, and suggested timings the App displays are computed automatically from your own on-device performance as self-observation displays and affect no right, obligation, or condition of use — so there is no decision to which a right to explanation, objection, or human re-review would attach.
Behavioral information, cookies, and automatic collection devices: the App collects no behavioral information for targeted advertising or interest profiling and uses no cookies, advertising identifiers (IDFA / GAID), or fingerprinting; an opt-out procedure for behavioral tracking is therefore not applicable. The legal-documents hosting page is static and sets no tracking cookies.
10. Where This Policy Is Published, and Changes
- Publication: in the App under My > Privacy Policy, and at https://dopa-legal.pages.dev/en/privacy.html (Korean: https://dopa-legal.pages.dev/ko/privacy.html).
- Changes: if this policy changes, the App will display an in-App notice, publish the change on the page above, or use a store update notice. Material changes (including changes adverse to users — items collected, purposes, processors, disclosures, international transfers) become effective 30 days after notice. Non-material / routine changes become effective 7 days after notice. (Aligned with
terms_of_service_v1.en.md§13.) - Revision history: every version is listed in §11; the full text of an earlier version is available on request through §9.
11. Version History
| Version | Date | Change |
|---|---|---|
| v1.0 | 2026-05-29 | Initial release — DOPA v1.0 no outbound transmission, on-device SQLite only verbatim |
| v1.0 (amend) | 2026-06-10 | §3.1 / §6 Access updated for the new Settings > Data Export (JSON, user-initiated share) feature (DATA-A1 implementation, DATA-A7 alignment) — no change to the no-outbound-transmission position (export is user-driven) |
| v1.1 | 2026-06-11 | Anonymous opt-in usage statistics introduced (ADR-016, conditional extension of ADR-014) — new §2.6 (counts-only aggregation of 53-event-name whitelist, segment dimensions region KR/US/OTHER · timezone-offset bucket · platform · app version, default OFF, k = 5); §4 names Cloudflare, Inc. (US) as infrastructure processor (Asia-Pacific residency hint); §5 cross-border transfer disclosure; §6 consent / immediate withdrawal / per-person-deletion-impossibility honest notice; §8 HTTPS · no IP storage · k-anonymity; iOS privacy manifest declared as Usage Data / Not Linked to You / No Tracking. Sentry remains not integrated (zero SDK code) |
| v1.2 | 2026-06-14 | Competitive BP review — §1 At-a-Glance trust hook + absence checklist (H4); §4 Cloudflare = infrastructure not third-party analytics, zero analytics SDKs (H5); §6 GDPR named data-subject rights + supervisory-authority complaint (H2), CCPA named rights + Do-Not-Sell=none (M5), COPPA-13/PIPA-14 cross-ref (M6), Region-specific Supplements baseline header (M11), single-point-of-contact note (L1). |
| v1.3 | 2026-08-11 | §6 / §9 contact address changed to the publisher’s own mailbox yejin255@naver.com — the previous address belonged to the Operator, so the published point of contact did not match the publishing entity. Now identical to the in-app contact (mailto), security.txt, and Terms §14. No change to substantive provisions (processing, retention, rights procedure) — contact designation only. |
| v1.4 | 2026-08-20 | Alignment with the shipped app (store-metadata audit F3·F4) — (1) §2.4 over-declaration fix: removed “acknowledgment of the medical-device disclaimer (disclaimer_accepted)” and “calibration completion status” from the collected-items list, since no values are actually written to them; replaced with onboarding_completed, which is. The columns’ continued presence in the schema is disclosed transparently in a footnote. (2) Screen-name corrections: “Settings toggle” → the toggle in the My tab; “Settings > Data Export / Delete All Data” → “My > Export data / Delete all data” (matching the actual UI labels). (3) Removed references to retired screens: Weekly Mirror → the Rhythm and Progress tabs; focus chip → goal chip. No change to substantive provisions (collection, use, retention, disclosure) — factual corrections only. |
| v1.5 | 2026-08-27 | Disclosure upgrade against the amended PIPA (effective 2026-09-11) (PIPA_2026_AUDIT_20260826.md), mirroring the Korean v1.5 — (1) §9: Privacy Officer title, §30-3 owner responsibility, same channel for access requests and grievances, no telephone helpline + 10-day email response commitment. (2) §10 now also states where the policy is published and keeps the revision-history commitment. (3) Server-side retention: “until the purpose is achieved” → §2.6 Legal character (anonymous information, PIPA §58-2) + §3.2 “destroyed when the service is discontinued” and method of destruction. (4) §2.6: the hard-coded “53 event names” removed (the code held 44 at audit time and the count moves with every contract revision) → “predefined whitelist maintained in the event contract”. (5) §8 restructured into administrative / technical / physical measures + incident-notification procedure per amended §34. (6) §6 baseline: Correction, Portability (§35-2 not applicable + JSON export), exercise by guardian / agent. (7) §2 sub-headings tagged [required · auto-generated] / [optional · opt-in] with the legal basis. (8) §9: automated-decision wording aligned to PIPA §37-2 with the note that scores / baselines are not decisions; behavioral information explicitly not collected. (9) §1 At-a-Glance: processor, in-app rights, contact. No change to what is collected, used, disclosed, or transferred — disclosure form only. |
| v1.1 (rev) | 2026-06-11 | Verification-driven corrections — §3.2 / §6 now reflect the implemented Settings > Delete All Data in-app wipe (under-declaration fix); §2.6 k = 5 precisely described as a server-side aggregation/analysis-time rule (measured in uploaded batches, “never lowered” over-promise removed), batch_id / schema identifier disclosed; §8 idempotency wording honestly qualified; toggle name aligned with the actual UI label (“Share anonymous usage stats”); §1 age-rating wording qualified (Apple 12+ / IARC region-dependent); §6 CCPA “none” qualified with the §2.6 transmission fact |
Appendix: Connection to ADR-014 / ADR-016
The v1.0 minimalism of this policy was anchored in the decision to defer telemetry (ADR-014 v1 telemetry defer). As of policy v1.1, ADR-014 is conditionally extended — not reversed — by ADR-016 (anonymous opt-in telemetry): anonymous, opt-in, counts-only usage statistics are now permitted, under the invariants the original decision protected:
- “We know exactly what we send” — no third-party SDK auto-collection; the App’s own endpoint receives only the fields the App explicitly transmits (§2.6).
- Explicit opt-in, immediate withdrawal —
analytics_opt_indefaults to OFF; the toggle in the My tab is the consent and the withdrawal mechanism. - No identity linkage — no user/session identifiers transmitted, no account, no tracking.
Accordingly, this v1.1 updates §2.6 / §3 / §4 / §5 / §6 / §8, the Apple App Privacy declaration moves from effectively “Data Not Collected” to “Usage Data / Not Linked to You / No Tracking” (the iOS privacy manifest already declares this), and the Apple App Privacy / Google Play Data Safety forms are re-filed to match.
Sentry (crash reporting) remains a separate, not-yet-activated transmission track — the Sentry SDK is included in the App but is never initialized (no DSN is configured), so zero crash data is collected or transmitted today, and crash reporting is never merged with the §2.6 aggregates. When Sentry (or an alternative) is activated in a future version:
- §2 will add crash data, diagnostics
- §4 will name Sentry Inc. (or alternative)
- §5 will be updated for the corresponding international transfer with notice and any required consent
- App Tracking Transparency status will be re-evaluated (currently
false— no tracking) - Apple App Privacy / Google Play Data Safety records will be re-filed
- this policy will be versioned again (v1.2+)
This is the normal release lifecycle, not a workaround. This policy describes only what is actually implemented — pre-declaring unimplemented telemetry would be a misrepresentation and could itself be a basis for store rejection (over-declaration vs. actual behavior).