기억타래는 「개인정보 보호법」 제30조에 따라 정보주체의 권리 보호와 고충의 신속한 처리를 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다.
기억타래는 로컬 우선(Local-first) 서비스로, 일기·메모·기기 내 사진은 기기에만 저장되며 서버로 수집하지 않습니다. 로그인 없이 핵심 기능을 사용할 수 있으며, 아래 개인정보는 로그인·결제·알림 등 이용자가 선택한 기능을 사용할 때에만 처리됩니다.
기억타래는 다음 목적으로만 개인정보를 처리하며, 목적 외 용도로 이용하지 않습니다. 목적이 변경되는 경우 「개인정보 보호법」 제18조에 따라 별도 동의 등 필요한 조치를 합니다.
| 항목 | 목적 | 보유 기간 |
|---|---|---|
| 소셜 로그인 고유 식별자·세션 토큰 | 회원 식별·로그인 유지 | 회원 탈퇴 시까지 |
| 앱 스토어 구매 식별값·상품 ID | 크레딧 결제 처리 | 관련 법령 기간(5년) |
| 앱 스토어 구독 검증 정보·구독 상태·만료일 | 구독 결제·관리 | 구독 기간·관련 법령 기간 |
| 기기 푸시 토큰 | 그림일기 배달 등 서비스 알림 | 회원 탈퇴 시까지 |
동의를 거부할 권리가 있습니다. 거부하면 계정이 만들어지지 않아 로그인 기능(그림일기 배달·모임·백업)은 이용할 수 없지만, 기기 안에서 일기를 쓰는 것은 계속 가능합니다.
| 처리업무 | 구분 | 항목 |
|---|---|---|
| 회원 식별·로그인 | 필수 | 소셜 로그인 제공자(구글·애플·네이버)의 고유 식별자, 세션 토큰(리프레시 토큰의 해시값)·기기 라벨·만료/폐기 상태 |
| 크레딧 결제 | 필수 | 앱 스토어가 발급한 구매 식별값·상품 ID |
| 구독 결제·관리 | 필수 | 앱 스토어가 발급한 구매 검증 정보(영수증/구매 토큰)·구독 상품 ID·구독 상태·만료일시·플랫폼 |
| 알림 | 필수 | 기기 푸시 토큰·플랫폼(android/ios) |
| 서비스 이용 통계 | 자동 | 앱이 생성한 익명 기기 식별자(서버에는 일방향 해시만 저장) |
본 서비스는 만 14세 이상을 대상으로 하며, 만 14세 미만 아동의 개인정보는 수집하지 않습니다.
이용자의 개인정보를 제3자에게 제공하지 않습니다.
보유기간 경과·처리목적 달성·계정 삭제 시 지체 없이 파기합니다. 파기 사유가 발생한 개인정보는 보호책임자의 확인을 거쳐, 전자적 파일은 복구 불가능한 방법으로 영구 삭제합니다. (본 서비스는 개인정보를 종이 문서로 보관하지 않습니다.)
이용자는 언제든지 개인정보의 열람·정정·삭제·처리정지를 요구할 수 있습니다. 앱 내 ‘계정 삭제’ 로 직접 삭제하거나 아래 보호책임자 연락처로 요청하시면 지체 없이 조치합니다.
접근 권한 통제, 전송구간 암호화(HTTPS), 개인정보 최소 수집, 부정 이용 방지를 위해 보관하는 식별값의 일방향 해시 처리(복원 불가).
본 앱은 쿠키 등 개인정보 자동 수집 장치를 사용하지 않습니다.
정보주체는 「개인정보 보호법」 제35조에 따른 개인정보 열람청구를 아래로 신청할 수 있으며, 신속하게 처리합니다. (앱 내 ‘계정 삭제’ 로 직접 삭제도 가능합니다.)
본 방침이 변경되면 시행일과 함께 본 페이지에 고지하며, 이전 처리방침은 본 페이지에서 확인할 수 있습니다. · 시행일: 2026-07-03
In accordance with Article 30 of the Personal Information Protection Act (PIPA), MemoryTarae establishes and discloses the following privacy policy to protect the rights of data subjects and handle related grievances promptly.
MemoryTarae is a local-first service: your diary, notes, and on-device photos are stored only on your device and are not collected by our server. You can use the core features without signing in, and the personal data below is processed only when you use optional features such as sign-in, payment, or notifications.
MemoryTarae processes personal data only for the purposes below and does not use it for other purposes. If the purpose changes, we take necessary measures such as obtaining separate consent under Article 18 of PIPA.
| Items | Purpose | Retention |
|---|---|---|
| Social login unique identifier & session token | Member identification and login | Until account deletion |
| App store purchase identifier & product ID | Credit payment processing | Statutory period (5 years) |
| App store subscription verification info, status & expiry | Subscription payment and management | Subscription period & statutory period |
| Device push token | Service notifications such as diary delivery | Until account deletion |
You have the right to refuse consent. If you refuse, no account is created and signed-in features (diary delivery, groups, backup) are unavailable, but you can keep writing your diary on your device.
| Task | Type | Items |
|---|---|---|
| Member ID & login | Required | The unique identifier from the social login provider (Google, Apple, Naver); session token (hash of the refresh token), device label, expiry/revocation state |
| Credit payment | Required | The purchase identifier and product ID issued by the app store |
| Subscription payment & management | Required | The purchase verification info (receipt/purchase token), subscription product ID, status, expiry, and platform issued by the app store |
| Notifications | Required | Device push token and platform (android/ios) |
| Service usage statistics | Automatic | An app-generated anonymous device identifier (stored only as a one-way hash) |
This service is intended for users aged 14 or older; we do not collect personal data of children under 14.
We do not provide your personal data to third parties.
We destroy data without delay upon expiry of the retention period, fulfillment of the purpose, or account deletion. Personal data subject to destruction is erased after the data protection officer’s confirmation; electronic files are permanently erased by an unrecoverable method. (This service does not keep personal data in paper form.)
You may at any time request access, correction, deletion, or suspension of processing of your personal data. You can delete directly via the in-app ‘Delete account’ or request it via the data protection officer below, and we will act without delay.
Access-permission control, transport encryption (HTTPS), minimal collection of personal data, and one-way (irreversible) hashing of identifiers retained for fraud prevention.
This app does not use cookies or other automatic personal-data collection devices.
Under Article 35 of PIPA, data subjects may file a request to access their personal data at the contact below, and we will handle it promptly. (You can also delete directly via the in-app ‘Delete account’.)
If this policy changes, we will post it here with the effective date, and the previous policy can be viewed on this page. · Effective: 2026-07-03