DOPA Privacy Policy

Version: v1.5 Effective Date: v1.0 release (TBD) Last Updated: 2026-08-27 Scope: DOPA mobile application (“the App”), version 1.0 Frameworks: Apple App Privacy / Google Play Data Safety / California CCPA·CPRA / Children’s COPPA / EU GDPR (informational) / South Korea PIPA as in force on the effective date, including the 2026 amendment effective 2026-09-11 (parallel — see Korean version)

This policy reflects the actual behavior of the App verbatim. All cognitive performance data is stored exclusively on the user’s device. As of policy v1.1, the App additionally offers an anonymous, opt-in usage statistics feature (default OFF, §2.6): if — and only if — you enable it, the App transmits counts-only aggregates of whitelisted event names over HTTPS, with no individual records and no identifiers. With the toggle OFF (the default), the App performs no outbound network transmission, preserving the v1.0 baseline. (See ADR-016 anonymous opt-in telemetry — a conditional extension, not a reversal, of ADR-014 v1 telemetry defer.) Crash reporting (Sentry) is inactive — the Sentry SDK is bundled but never initialized (no DSN), so it is inactive; if it is activated in a later version, this policy will be versioned again and the corresponding Apple App Privacy / Google Play Data Safety forms will be re-submitted.


1. At a Glance — What the App Does and Does Not Do

Your scores are yours — no account, no tracking, zero transmission by default.


2. Information Stored On Your Device

The App stores the following items, all of which remain on your device. (If you enable the anonymous usage statistics of §2.6, only counts-only aggregates leave the device — never the items below in raw form.)

Legal basis and required / optional split: §2.1–§2.4 are required to provide the App (performance of the service you requested — PIPA §15(1)4; GDPR Art. 6(1)(b) where applicable) and are all generated automatically on the device — nothing is typed in by you. §2.6 is optional and processed only on your explicit consent (PIPA §15(1)1; GDPR Art. 6(1)(a)) given via the opt-in toggle.

2.1 Identifiers (local-only) [required · auto-generated]

2.2 Cognitive Performance Data [required · auto-generated]

2.3 Device Environment [required · auto-generated]

The on-device database still contains disclaimer_accepted and calibration_status columns from an earlier version, but the corresponding steps have been retired from the App, so no new values are written to them. Neither leaves your device.

Items the App does not collect: name, contact information, email, phone number, government ID numbers, GPS location, photos / contacts / calendar, advertising identifiers (IDFA / GAID), demographic data, payment information, biometric identifiers.

2.5 Sensitive / Health Data — Position Statement

The cognitive performance data and breath pacer records processed by the App are not treated as “sensitive health data” by the App, on the following grounds.

  1. Non-medical processing — the App is not a medical device and does not pursue diagnosis, treatment, or prevention. The data is used as self-observation performance metrics, not as a measure of medical health.
  2. No external transmission or diagnostic use — there is no pathway for these records themselves to leave the device or be used for clinical decisions. (The opt-in telemetry of §2.6 transmits only counts of event names per anonymous segment — never reaction times, accuracy values, scores, or any other performance values.)
  3. Anonymous local processing — without direct identifiers, the records cannot be combined into identifiable health information outside the device.

This is the App’s good-faith interpretation. If future authoritative legal review, regulator interpretation, or relevant precedent reclassifies these records as sensitive / special-category data, the App will introduce additional consent flows and version this policy. Any medical-context feature (e.g., clinical scale outputs, medical-institution integration) triggers re-evaluation of §2.5. (The §2.6 telemetry was evaluated under this clause for policy v1.1: because it transmits only event-name counts and never the performance values themselves, the position above is unchanged.)

2.6 Anonymous Usage Statistics (Opt-In, Default OFF) [optional · opt-in]

If — and only if — you enable the “Share anonymous usage stats” toggle in the My tab (default: OFF), the App transmits the following, and nothing else:

Protections:

Legal character — anonymous information: the §2.6 aggregates are designed so that no individual can be identified from them even in combination with other information, taking reasonable time, cost, and technology into account. The App therefore treats them as anonymous information outside the scope of PIPA (§58-2) and, for the same reason, outside the scope of “personal data” under the GDPR. For transparency, the App nevertheless applies the processor disclosure (§4), the international-transfer disclosure (§5), and the consent-withdrawal mechanism (§6) to these aggregates voluntarily. This is a good-faith interpretation of the same kind as §2.5; if a regulator or court reads it differently, this policy will be versioned.

Operational note (verbatim disclosure): as of this policy version, the collection endpoint is not yet deployed — the App’s telemetry client is configured with an empty endpoint and performs no transmission even when the toggle is ON. This section governs the App’s behavior from the moment the endpoint is activated.


3. Data Location and Retention

3.1 Storage Location

All on-device, locally only.

No cloud sync, no advertising network, no analytics SDK. With the anonymous-usage-statistics toggle OFF (the default), the App makes no outbound network requests during normal operation. With the toggle ON, the only outbound transmission is the counts-only aggregates described in §2.6, sent over HTTPS to a collection endpoint operated for the App on Cloudflare infrastructure (see §4).

You can export a copy of your own data via My > Export data (JSON). This is a user-initiated share (OS share sheet) — the App never transmits your records externally on its own. (The only automatic transmission the App can perform is the opt-in, counts-only aggregates of §2.6, which never include your records.)

3.2 Retention


4. Third Parties / Service Providers

The App engages one infrastructure service provider, and only for the opt-in anonymous usage statistics described in §2.6:

Processor Role Data received Location
Cloudflare, Inc. (United States) Serverless receipt and storage infrastructure (Cloudflare Worker + D1 database) for the anonymous usage statistics Counts-only anonymous aggregates (§2.6) — no identifiers; the App’s ingestion endpoint does not store IP addresses US legal entity; database placement uses a data residency hint of Asia-Pacific (apac)

Cloudflare acts as an infrastructure processor only — it is not a third-party advertising or analytics company; it receives no personal information from the App, and no data is shared with any third party for advertising, profiling, or any purpose other than hosting the App’s own anonymous aggregates. The App embeds zero third-party analytics SDKs (transmission uses the platform’s built-in HTTPS client only), so Cloudflare receives only the §2.6 fields the App explicitly sends and nothing is auto-collected. With the §2.6 toggle OFF (default), Cloudflare receives nothing.

Sentry (crash reporting) is not active — the Sentry SDK is included in the App’s code but is never initialized (no DSN is configured), so no crash data is collected or transmitted. Crash reporting and the §2.6 usage statistics are two independent transmission tracks and are never merged. If Sentry (or an alternative) is activated in a future version, prior notice will be given, this policy will be versioned, and the Apple App Privacy / Google Play Data Safety records will be updated.


5. International Data Transfers

Opt-in usage statistics only. If you enable the anonymous usage statistics (§2.6), the counts-only aggregates are received and stored on infrastructure operated by Cloudflare, Inc., a United States corporation. The storage placement uses an Asia-Pacific data residency hint, but because the infrastructure operator is a US legal entity, this is disclosed as a cross-border transfer for the purposes of South Korea’s PIPA (see the Korean-language version of this policy for the PIPA narrative).

With the toggle OFF (the default), no data leaves the device and no international transfer occurs. (If a future version uses additional providers hosted outside your jurisdiction, prior notice and any required consents will be obtained before activation.)


6. Your Choices and Rights

You have the following choices regarding the App:

Region-specific Supplements

The choices above are the global baseline that applies to everyone. The following are jurisdiction-specific supplements; where a supplement adds or clarifies a right, it controls for residents of that jurisdiction.

California residents (CCPA / CPRA): The App processes no personal information for “sale” or “sharing” as defined under California law, and the anonymous usage statistics of §2.6 are counts-only aggregates not reasonably capable of being associated with, or linked to, a particular consumer or household. Categories of personal information collected under the CCPA/CPRA: none. You have the following rights, addressed as follows:

To make an inquiry about these rights, contact the operator at yejin255@naver.com (§9).

Children (COPPA): The App is not directed to children under 13 and does not knowingly collect personal information from children. The App’s age rating is 12+ (informational, attestation by operator). Age thresholds differ by jurisdiction by design — South Korea’s PIPA uses an under-14 threshold; see the Korean-language version §6 for the under-14 standard. The App takes the same “not directed to children + no knowing collection” position under both.

EU / EEA residents (GDPR): The anonymous usage statistics (§2.6) are designed to fall outside the scope of personal data (counts-only, no identifiers, k-anonymity with k = 5). To the extent any processing is nonetheless treated as processing of personal data, the legal basis is consent (the explicit opt-in toggle, OFF by default), and you have the following rights, exercised as follows:

If GDPR-relevant processing beyond §2.6 is introduced in a future version, separate notice and a lawful basis will be established at that time. No automated decision-making or profiling producing legal or similarly significant effects is performed.

South Korea residents (PIPA): See the Korean-language version (privacy_policy_v1.md) for the PIPA §30 narrative and the dispute-resolution bodies.


7. Device Permissions

Permission Purpose Effect of Denial
Notifications Trigger local notifications at user-configured times No notifications; all measurement features continue to work

Remote push, camera, location, photos, microphone, contacts, and calendar permissions are not requested.


8. Security

Because per-person data never leaves the device, most safeguards sit with the device and with you; the operator’s own measures apply only to the server-side store of the §2.6 anonymous aggregates.

Administrative

Technical

Physical

Incident notification (PIPA §34 as amended, effective 2026-09-11)


9. Contact — Privacy Officer and Grievances

Under PIPA §30-3 (effective 2026-09-11) ultimate responsibility for personal-information protection rests with the business owner — here the publisher personally — who also serves as the Privacy Officer. There is no separate department: access requests and grievances are handled directly by the Privacy Officer.

Automated decisions (PIPA §37-2 / GDPR Art. 22): the App makes no fully automated decision that significantly affects your rights or obligations (not applicable). The scores, baselines, and suggested timings the App displays are computed automatically from your own on-device performance as self-observation displays and affect no right, obligation, or condition of use — so there is no decision to which a right to explanation, objection, or human re-review would attach.

Behavioral information, cookies, and automatic collection devices: the App collects no behavioral information for targeted advertising or interest profiling and uses no cookies, advertising identifiers (IDFA / GAID), or fingerprinting; an opt-out procedure for behavioral tracking is therefore not applicable. The legal-documents hosting page is static and sets no tracking cookies.


10. Where This Policy Is Published, and Changes


11. Version History

Version Date Change
v1.0 2026-05-29 Initial release — DOPA v1.0 no outbound transmission, on-device SQLite only verbatim
v1.0 (amend) 2026-06-10 §3.1 / §6 Access updated for the new Settings > Data Export (JSON, user-initiated share) feature (DATA-A1 implementation, DATA-A7 alignment) — no change to the no-outbound-transmission position (export is user-driven)
v1.1 2026-06-11 Anonymous opt-in usage statistics introduced (ADR-016, conditional extension of ADR-014) — new §2.6 (counts-only aggregation of 53-event-name whitelist, segment dimensions region KR/US/OTHER · timezone-offset bucket · platform · app version, default OFF, k = 5); §4 names Cloudflare, Inc. (US) as infrastructure processor (Asia-Pacific residency hint); §5 cross-border transfer disclosure; §6 consent / immediate withdrawal / per-person-deletion-impossibility honest notice; §8 HTTPS · no IP storage · k-anonymity; iOS privacy manifest declared as Usage Data / Not Linked to You / No Tracking. Sentry remains not integrated (zero SDK code)
v1.2 2026-06-14 Competitive BP review — §1 At-a-Glance trust hook + absence checklist (H4); §4 Cloudflare = infrastructure not third-party analytics, zero analytics SDKs (H5); §6 GDPR named data-subject rights + supervisory-authority complaint (H2), CCPA named rights + Do-Not-Sell=none (M5), COPPA-13/PIPA-14 cross-ref (M6), Region-specific Supplements baseline header (M11), single-point-of-contact note (L1).
v1.3 2026-08-11 §6 / §9 contact address changed to the publisher’s own mailbox yejin255@naver.com — the previous address belonged to the Operator, so the published point of contact did not match the publishing entity. Now identical to the in-app contact (mailto), security.txt, and Terms §14. No change to substantive provisions (processing, retention, rights procedure) — contact designation only.
v1.4 2026-08-20 Alignment with the shipped app (store-metadata audit F3·F4) — (1) §2.4 over-declaration fix: removed “acknowledgment of the medical-device disclaimer (disclaimer_accepted)” and “calibration completion status” from the collected-items list, since no values are actually written to them; replaced with onboarding_completed, which is. The columns’ continued presence in the schema is disclosed transparently in a footnote. (2) Screen-name corrections: “Settings toggle” → the toggle in the My tab; “Settings > Data Export / Delete All Data” → “My > Export data / Delete all data” (matching the actual UI labels). (3) Removed references to retired screens: Weekly Mirror → the Rhythm and Progress tabs; focus chip → goal chip. No change to substantive provisions (collection, use, retention, disclosure) — factual corrections only.
v1.5 2026-08-27 Disclosure upgrade against the amended PIPA (effective 2026-09-11) (PIPA_2026_AUDIT_20260826.md), mirroring the Korean v1.5 — (1) §9: Privacy Officer title, §30-3 owner responsibility, same channel for access requests and grievances, no telephone helpline + 10-day email response commitment. (2) §10 now also states where the policy is published and keeps the revision-history commitment. (3) Server-side retention: “until the purpose is achieved” → §2.6 Legal character (anonymous information, PIPA §58-2) + §3.2 “destroyed when the service is discontinued” and method of destruction. (4) §2.6: the hard-coded “53 event names” removed (the code held 44 at audit time and the count moves with every contract revision) → “predefined whitelist maintained in the event contract”. (5) §8 restructured into administrative / technical / physical measures + incident-notification procedure per amended §34. (6) §6 baseline: Correction, Portability (§35-2 not applicable + JSON export), exercise by guardian / agent. (7) §2 sub-headings tagged [required · auto-generated] / [optional · opt-in] with the legal basis. (8) §9: automated-decision wording aligned to PIPA §37-2 with the note that scores / baselines are not decisions; behavioral information explicitly not collected. (9) §1 At-a-Glance: processor, in-app rights, contact. No change to what is collected, used, disclosed, or transferred — disclosure form only.
v1.1 (rev) 2026-06-11 Verification-driven corrections — §3.2 / §6 now reflect the implemented Settings > Delete All Data in-app wipe (under-declaration fix); §2.6 k = 5 precisely described as a server-side aggregation/analysis-time rule (measured in uploaded batches, “never lowered” over-promise removed), batch_id / schema identifier disclosed; §8 idempotency wording honestly qualified; toggle name aligned with the actual UI label (“Share anonymous usage stats”); §1 age-rating wording qualified (Apple 12+ / IARC region-dependent); §6 CCPA “none” qualified with the §2.6 transmission fact

Appendix: Connection to ADR-014 / ADR-016

The v1.0 minimalism of this policy was anchored in the decision to defer telemetry (ADR-014 v1 telemetry defer). As of policy v1.1, ADR-014 is conditionally extended — not reversed — by ADR-016 (anonymous opt-in telemetry): anonymous, opt-in, counts-only usage statistics are now permitted, under the invariants the original decision protected:

Accordingly, this v1.1 updates §2.6 / §3 / §4 / §5 / §6 / §8, the Apple App Privacy declaration moves from effectively “Data Not Collected” to “Usage Data / Not Linked to You / No Tracking” (the iOS privacy manifest already declares this), and the Apple App Privacy / Google Play Data Safety forms are re-filed to match.

Sentry (crash reporting) remains a separate, not-yet-activated transmission track — the Sentry SDK is included in the App but is never initialized (no DSN is configured), so zero crash data is collected or transmitted today, and crash reporting is never merged with the §2.6 aggregates. When Sentry (or an alternative) is activated in a future version:

This is the normal release lifecycle, not a workaround. This policy describes only what is actually implemented — pre-declaring unimplemented telemetry would be a misrepresentation and could itself be a basis for store rejection (over-declaration vs. actual behavior).