Effective: October 7, 2026 (first effective June 5, 2026)
This Policy takes effect on October 7, 2026. Until then, the previous policy applies.
가야김 (Gaya Ghym; the "Operator") establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act of Korea to protect users' personal information and to handle related concerns promptly. The Korean version governs; this English version is provided for convenience.
1. The Operator processes only the minimum information necessary to provide the Service and, as a rule, does not collect information that directly identifies users, such as names, email addresses, or phone numbers. This does not apply to the email address in Article 2(6) or the refund information in Article 2(9), which users provide themselves.
2. The Service has no account registration.
3. Because the information the Operator processes is linked by the installation identifier in Article 2(2)(iii), the Operator treats it as personal information under the Personal Information Protection Act of Korea (the "Act") and protects it under this Policy.
1. Information users select or enter while using the Service:
2. Information generated automatically while the Service is used:
3. When a user requests and uses reports:
4. Answers users type themselves on the intervention screen (Q1) are stored only on their device and are not sent to the Operator.
5. When a user uses "Send Feedback," the Operator collects the message together with the app version, OS version, device model, language setting, installation source, and Firebase installation ID. The Operator does not automatically attach the user's name or email address; anything the user writes in the message is processed with it.
6. Email addresses users provide by email (contact@nownowlife.com) to join the beta are kept separately from the information in paragraphs 1 through 3 and are not linked to it.
7. Payments for paid plans are processed by the app stores (Apple App Store, Google Play). The Operator does not collect payment details such as card numbers. The Service checks only whether a purchase exists, through the app store on the user's device, to provide paid features.
8. The Operator does not store IP addresses together with the information in paragraphs 1 through 3. However, to prevent excessive requests when feedback is sent, IP addresses are kept for up to 2 hours and then deleted automatically; the processors in Article 6 may keep access logs for security under their own policies.
9. When a user requests a refund under the Terms of Use that cannot be made through the app store, the Operator receives the minimum information needed for the refund (account holder, bank, and account number).
The Operator processes personal information only for the following purposes.
| Purpose | Information | Legal basis |
|---|---|---|
| 1. Showing the intervention screen; providing records and statistics to the user | Article 2(1), (2) | Performance of a contract (Act, Art. 15(1)(4)) |
| 2. Writing, reviewing, and delivering reports and sending arrival alerts | Article 2(1) to (3) | Performance of a contract (Act, Art. 15(1)(4)) |
| 3. Improving the Service and developing report and insight features, including reflecting report ratings | Article 2(1) to (3) | Legitimate interests of the Operator (Act, Art. 15(1)(6)) and use within a scope reasonably related to the original purpose (Act, Art. 15(3)) |
| 4. Statistics and scientific research, including research on psychological, impulse, emotional, and behavioral patterns and the development and testing of report generation | Pseudonymized information from Article 2(1) to (3) | Processing of pseudonymized information (Act, Art. 28-2) |
| 5. Reviewing and acting on feedback | Article 2(5) | Taking steps at the user's request (Act, Art. 15(1)(4)) |
| 6. Sending beta invitations and answering inquiries | Article 2(6) | Taking steps at the user's request (Act, Art. 15(1)(4)) |
| 7. Processing refunds under the Terms of Use and keeping transaction records | Article 2(9) | Performance of a contract and the Act on Consumer Protection in Electronic Commerce |
| 8. Preventing abuse | Article 2(8) | Legitimate interests of the Operator (Act, Art. 15(1)(6)) |
1. Information in Article 2(1) to (3) stored on the server is kept for 5 years from the date each item was collected (for report text, the date of delivery) and then destroyed without delay. Notification tokens are kept until replaced or deleted. If the user requests deletion under Article 9(2), the information is destroyed regardless of the retention period.
2. Feedback in Article 2(5) is kept for 3 years from collection and then destroyed.
3. Information that has been aggregated across users so that no individual can be identified (anonymous information) is outside the scope of the Act and may be kept without time limit and used to improve the Service and for research.
4. The Operator may pseudonymize information in Article 2(1) to (3) for the purposes in Article 3(4); pseudonymized information is processed for 5 years from pseudonymization. Additional information that could restore the original is kept separately, with the safeguards required by the Act and records of processing.
5. Information stored on the device is deleted from the device when the app is deleted. However, the installation identifier is kept in the operating system's secure storage (iOS) or device backup (Android, depending on backup settings) so that reports can continue after reinstallation, and it remains after the app is deleted. Users can delete it with the app's data reset.
6. If the user reinstalls the app, the Operator may use the installation identifier to continue providing reports based on information stored on the server and to restore the user's records. Information in Article 2(4) is not restored.
7. Email addresses in Article 2(6) are kept until beta invitations and inquiries are completed and are destroyed without delay upon request.
8. Account details in the refund information in Article 2(9) are destroyed without delay once the refund is complete; transaction records such as refund date and amount are kept for 5 years under the Act on Consumer Protection in Electronic Commerce.
The Operator does not sell or provide users' personal information to third parties, does not display ads, and does not use third-party SDKs for advertising or tracking, except where specifically required by law.
1. The Operator entrusts the following processing to the processors below, some of which takes place outside Korea.
| Processor (contact) | Task | Information transferred | Country | When and how | Retention |
|---|---|---|---|---|---|
| Google LLC — Cloud Firestore (support.google.com/policies) | Storing usage records, reports, and report ratings | Article 2(1) to (3) | Republic of Korea (Seoul region) | Over the network when the Service is used | Per Article 4 |
| Google LLC — Firebase Authentication (support.google.com/policies) | Authorizing server writes (anonymous sign-in) | Anonymous auth ID, IP address | United States and other countries with Google data centers | Over the network when the Service is used | IP addresses for a few weeks; auth data until deleted by the Operator (removed from backups within 180 days) |
| Google LLC — Firebase App Check, Installations, Cloud Messaging (support.google.com/policies) | Verifying genuine app requests, identifying installations, sending report alerts | Attestation data, Firebase installation ID, notification token | United States and other countries with Google data centers | Over the network when the Service is used or alerts are sent | Attestation data not retained; IDs and tokens until deleted by the Operator (removed from backups within 180 days) |
| Google LLC — Apps Script, Google Sheets, Gmail (support.google.com/policies) | Storing and notifying feedback | Article 2(5) | United States and other countries with Google data centers | Over the network when feedback is sent | Per Article 4(2) |
| Apple Inc. — Apple Push Notification service (apple.com/legal/privacy) | Delivering report alerts to iOS devices | Notification token, alert content | United States | Over the network when alerts are sent | Per Apple's policies |
| Cloudflare, Inc. (privacyquestions@cloudflare.com) | Relaying requests and preventing abuse | Request content, IP address | United States and the Cloudflare data center countries that handle the request | Over the network on each request | Request content not kept after relaying; rate-limit records (IP address) set by the Operator for up to 2 hours; other security logs per Cloudflare's policies |
| Anthropic, PBC (privacy@anthropic.com) | Assisting in writing reports | Information in Article 2(1) to (3) needed to write the report (excluding Article 2(4)) | United States | Over the network when the Operator writes a report the user requested | Up to 30 days (set so that it is not used for model training) |
| OpenAI, L.L.C. (privacy@openai.com) | Generating insight sentences | Statistical figures summarized so that no individual can be identified (excluding the installation identifier, times, and Article 2(4)) | United States | Over the network when insights are generated | Generally up to 30 days |
2. The overseas transfers in paragraph 1 are processing and storage entrustments necessary to conclude and perform the contract with users, and are disclosed in this Policy under Article 28-8(1)(3) of the Act.
3. Users may ask the Operator, at the contact in Article 12, to stop overseas transfers. Because these transfers are necessary to provide the Service, stopping them may limit use of the Service. Transfers to Anthropic, PBC occur only when the user requests a report, and to OpenAI, L.L.C. only when insights are generated, so users can also refuse them by not using those features.
4. Information sent to Anthropic, PBC and OpenAI, L.L.C. is not used for model training. Each company generally keeps it for up to 30 days to prevent abuse and provide its service, and may keep it longer where required by law.
5. When the Operator uses overseas services for research and development, it sends only aggregated information combining multiple users so that no individual can be identified, or synthetic data containing no real user's information, and never information at the level of an individual user, except to the extent that the user has separately consented.
6. Any change or addition of processors will be disclosed in this Policy.
1. The Service uses the following permissions, which users can revoke at any time in device settings.
Android
iOS
The Operator destroys personal information without delay once the retention period ends or the purpose is achieved, deleting electronic files in a way that cannot be recovered.
1. Users may at any time request access to, correction, deletion, or suspension of processing of their personal information.
2. Users can request deletion of the information in Article 2(1) to (3) stored on the server by using the app's data reset; the Operator completes deletion within 10 days of receiving the request. The app deletes the installation identifier only after confirming that the server received the request. If the reset is done offline, the request is sent the next time the device is online, or after reinstallation if the app is deleted first.
3. Deletion under paragraph 2 does not cover:
4. Requests regarding feedback in Article 2(5), email addresses in Article 2(6), and other rights can be made at the contact in Article 12; the Operator acts within 10 days and informs the user of the result.
The Operator encrypts information in transit (HTTPS), restricts access to stored information to the Operator, and uses app attestation (App Check) to reduce illegitimate requests. When processing pseudonymized information, the Operator keeps the additional information needed to restore it separately.
1. The Operator does not operate cookies, advertising identifiers, or other tools that collect behavioral information for advertising or external tracking on its website or app.
2. Collection of usage records to provide the Service is governed by Article 2(2).
The Operator designates the following privacy officer, who oversees personal information processing and handles complaints and remedies. Name: Gaya Ghym · Contact: contact@nownowlife.com
The Service is not directed at users under 16, and the Operator does not knowingly collect personal information from children under 16.
Users may contact the following Korean authorities to report or seek advice on privacy infringements:
Changes to this Policy and their effective date are posted on the Service website at least 7 days in advance, or at least 30 days in advance for material changes to users' rights.
Business name: 가야김 (Gaya Ghym) · Representative: Gaya Ghym · Business registration no.: 448-15-02596
Address: Room 501-301A, 5F Gyeu Building, 61 Daehak-ro 12-gil, Jongno-gu, Seoul, Republic of Korea · Phone: +82-10-9206-4393 · Email: contact@nownowlife.com
© 2026 nownow · Notice your now, now.