EN KO

Privacy Policy

Effective: October 7, 2026 (first effective June 5, 2026)

This Policy takes effect on October 7, 2026. Until then, the previous policy applies.

가야김 (Gaya Ghym; the "Operator") establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act of Korea to protect users' personal information and to handle related concerns promptly. The Korean version governs; this English version is provided for convenience.

Article 1 (Principles)

1. The Operator processes only the minimum information necessary to provide the Service and, as a rule, does not collect information that directly identifies users, such as names, email addresses, or phone numbers. This does not apply to the email address in Article 2(6) or the refund information in Article 2(9), which users provide themselves.

2. The Service has no account registration.

3. Because the information the Operator processes is linked by the installation identifier in Article 2(2)(iii), the Operator treats it as personal information under the Personal Information Protection Act of Korea (the "Act") and protects it under this Policy.

Article 2 (Personal Information Processed)

1. Information users select or enter while using the Service:

  1. Target apps: the names of the apps the user designates as target apps
  2. Intervention responses: choices on the intervention screen (Q1 and Q2), mood responses, and whether the target app was opened
  3. Settings: app settings such as the number of target apps

2. Information generated automatically while the Service is used:

  1. Usage records: launch times and days of target apps, per-session and daily usage time, launch intervals and rapid repeat launches, time spent on each step of the intervention screen, mood changes within a single flow, and aggregate total screen time and times of use (including late night). This does not include which apps other than target apps the user uses.
  2. Derived information: figures the Service computes and displays, such as switch rate, most-launched apps, and time reclaimed; permission status; and the type of plan in use (free, monthly, yearly, lifetime). Payment dates, amounts, and receipts are not included.
  3. Device information: app version, device model, and a random value generated at installation (the "installation identifier")

3. When a user requests and uses reports:

  1. Report requests: time of request, chosen report type (Cautious, Balanced, Bold), and language
  2. Report text: the report written and delivered by the Operator, kept on the server and stored on the user's device
  3. Report ratings: ratings the user leaves on each sentence of a report (whether it helped and why) and notes the user writes (up to 1,000 characters)
  4. Notification token: a value issued to the device to send an alert when a report arrives

4. Answers users type themselves on the intervention screen (Q1) are stored only on their device and are not sent to the Operator.

5. When a user uses "Send Feedback," the Operator collects the message together with the app version, OS version, device model, language setting, installation source, and Firebase installation ID. The Operator does not automatically attach the user's name or email address; anything the user writes in the message is processed with it.

6. Email addresses users provide by email (contact@nownowlife.com) to join the beta are kept separately from the information in paragraphs 1 through 3 and are not linked to it.

7. Payments for paid plans are processed by the app stores (Apple App Store, Google Play). The Operator does not collect payment details such as card numbers. The Service checks only whether a purchase exists, through the app store on the user's device, to provide paid features.

8. The Operator does not store IP addresses together with the information in paragraphs 1 through 3. However, to prevent excessive requests when feedback is sent, IP addresses are kept for up to 2 hours and then deleted automatically; the processors in Article 6 may keep access logs for security under their own policies.

9. When a user requests a refund under the Terms of Use that cannot be made through the app store, the Operator receives the minimum information needed for the refund (account holder, bank, and account number).

Article 3 (Purposes and Legal Bases)

The Operator processes personal information only for the following purposes.

PurposeInformationLegal basis
1. Showing the intervention screen; providing records and statistics to the userArticle 2(1), (2)Performance of a contract (Act, Art. 15(1)(4))
2. Writing, reviewing, and delivering reports and sending arrival alertsArticle 2(1) to (3)Performance of a contract (Act, Art. 15(1)(4))
3. Improving the Service and developing report and insight features, including reflecting report ratingsArticle 2(1) to (3)Legitimate interests of the Operator (Act, Art. 15(1)(6)) and use within a scope reasonably related to the original purpose (Act, Art. 15(3))
4. Statistics and scientific research, including research on psychological, impulse, emotional, and behavioral patterns and the development and testing of report generationPseudonymized information from Article 2(1) to (3)Processing of pseudonymized information (Act, Art. 28-2)
5. Reviewing and acting on feedbackArticle 2(5)Taking steps at the user's request (Act, Art. 15(1)(4))
6. Sending beta invitations and answering inquiriesArticle 2(6)Taking steps at the user's request (Act, Art. 15(1)(4))
7. Processing refunds under the Terms of Use and keeping transaction recordsArticle 2(9)Performance of a contract and the Act on Consumer Protection in Electronic Commerce
8. Preventing abuseArticle 2(8)Legitimate interests of the Operator (Act, Art. 15(1)(6))
Article 4 (Retention)

1. Information in Article 2(1) to (3) stored on the server is kept for 5 years from the date each item was collected (for report text, the date of delivery) and then destroyed without delay. Notification tokens are kept until replaced or deleted. If the user requests deletion under Article 9(2), the information is destroyed regardless of the retention period.

2. Feedback in Article 2(5) is kept for 3 years from collection and then destroyed.

3. Information that has been aggregated across users so that no individual can be identified (anonymous information) is outside the scope of the Act and may be kept without time limit and used to improve the Service and for research.

4. The Operator may pseudonymize information in Article 2(1) to (3) for the purposes in Article 3(4); pseudonymized information is processed for 5 years from pseudonymization. Additional information that could restore the original is kept separately, with the safeguards required by the Act and records of processing.

5. Information stored on the device is deleted from the device when the app is deleted. However, the installation identifier is kept in the operating system's secure storage (iOS) or device backup (Android, depending on backup settings) so that reports can continue after reinstallation, and it remains after the app is deleted. Users can delete it with the app's data reset.

6. If the user reinstalls the app, the Operator may use the installation identifier to continue providing reports based on information stored on the server and to restore the user's records. Information in Article 2(4) is not restored.

7. Email addresses in Article 2(6) are kept until beta invitations and inquiries are completed and are destroyed without delay upon request.

8. Account details in the refund information in Article 2(9) are destroyed without delay once the refund is complete; transaction records such as refund date and amount are kept for 5 years under the Act on Consumer Protection in Electronic Commerce.

Article 5 (Provision to Third Parties)

The Operator does not sell or provide users' personal information to third parties, does not display ads, and does not use third-party SDKs for advertising or tracking, except where specifically required by law.

Article 6 (Processors and Overseas Transfers)

1. The Operator entrusts the following processing to the processors below, some of which takes place outside Korea.

Processor (contact)TaskInformation transferredCountryWhen and howRetention
Google LLC — Cloud Firestore
(support.google.com/policies)
Storing usage records, reports, and report ratingsArticle 2(1) to (3)Republic of Korea (Seoul region)Over the network when the Service is usedPer Article 4
Google LLC — Firebase Authentication
(support.google.com/policies)
Authorizing server writes (anonymous sign-in)Anonymous auth ID, IP addressUnited States and other countries with Google data centersOver the network when the Service is usedIP addresses for a few weeks; auth data until deleted by the Operator (removed from backups within 180 days)
Google LLC — Firebase App Check, Installations, Cloud Messaging
(support.google.com/policies)
Verifying genuine app requests, identifying installations, sending report alertsAttestation data, Firebase installation ID, notification tokenUnited States and other countries with Google data centersOver the network when the Service is used or alerts are sentAttestation data not retained; IDs and tokens until deleted by the Operator (removed from backups within 180 days)
Google LLC — Apps Script, Google Sheets, Gmail
(support.google.com/policies)
Storing and notifying feedbackArticle 2(5)United States and other countries with Google data centersOver the network when feedback is sentPer Article 4(2)
Apple Inc. — Apple Push Notification service
(apple.com/legal/privacy)
Delivering report alerts to iOS devicesNotification token, alert contentUnited StatesOver the network when alerts are sentPer Apple's policies
Cloudflare, Inc.
(privacyquestions@cloudflare.com)
Relaying requests and preventing abuseRequest content, IP addressUnited States and the Cloudflare data center countries that handle the requestOver the network on each requestRequest content not kept after relaying; rate-limit records (IP address) set by the Operator for up to 2 hours; other security logs per Cloudflare's policies
Anthropic, PBC
(privacy@anthropic.com)
Assisting in writing reportsInformation in Article 2(1) to (3) needed to write the report (excluding Article 2(4))United StatesOver the network when the Operator writes a report the user requestedUp to 30 days (set so that it is not used for model training)
OpenAI, L.L.C.
(privacy@openai.com)
Generating insight sentencesStatistical figures summarized so that no individual can be identified (excluding the installation identifier, times, and Article 2(4))United StatesOver the network when insights are generatedGenerally up to 30 days

2. The overseas transfers in paragraph 1 are processing and storage entrustments necessary to conclude and perform the contract with users, and are disclosed in this Policy under Article 28-8(1)(3) of the Act.

3. Users may ask the Operator, at the contact in Article 12, to stop overseas transfers. Because these transfers are necessary to provide the Service, stopping them may limit use of the Service. Transfers to Anthropic, PBC occur only when the user requests a report, and to OpenAI, L.L.C. only when insights are generated, so users can also refuse them by not using those features.

4. Information sent to Anthropic, PBC and OpenAI, L.L.C. is not used for model training. Each company generally keeps it for up to 30 days to prevent abuse and provide its service, and may keep it longer where required by law.

5. When the Operator uses overseas services for research and development, it sends only aggregated information combining multiple users so that no individual can be identified, or synthetic data containing no real user's information, and never information at the level of an individual user, except to the extent that the user has separately consented.

6. Any change or addition of processors will be disclosed in this Policy.

Article 7 (App Permissions)

1. The Service uses the following permissions, which users can revoke at any time in device settings.

Android

  1. Accessibility Service: to detect when a target app comes to the foreground and show the intervention screen. It does not read or collect screen content, typed text, passwords, or messages.
  2. Display over other apps: to show the intervention screen on top of the target app.
  3. Usage access: to read usage statistics such as screen time.
  4. Notification access: to pause media playing in the target app when the intervention screen appears. Notification content is not read, stored, or sent.
  5. Calendar (optional): to show current or upcoming events on the intervention screen. Event data is used only on the device and is not sent to the Operator.
  6. Notifications: to send service notices, summaries, and report arrival alerts.
  7. Device admin: only to run the screen-lock feature the user has turned on.

iOS

  1. Screen Time: to show the intervention screen when a target app is launched and to read usage time for target apps and the device as a whole. Usage information for individual non-target apps is not sent to the Operator.
  2. Notifications: for service notices, links to the intervention screen, and report arrival alerts.
  3. Calendar (optional): same as Android item 5.
Article 8 (Destruction)

The Operator destroys personal information without delay once the retention period ends or the purpose is achieved, deleting electronic files in a way that cannot be recovered.

Article 9 (User Rights)

1. Users may at any time request access to, correction, deletion, or suspension of processing of their personal information.

2. Users can request deletion of the information in Article 2(1) to (3) stored on the server by using the app's data reset; the Operator completes deletion within 10 days of receiving the request. The app deletes the installation identifier only after confirming that the server received the request. If the reset is done offline, the request is sent the next time the device is online, or after reinstallation if the app is deleted first.

3. Deletion under paragraph 2 does not cover:

  1. Anonymous information under Article 4(3), which cannot identify any individual and is outside the scope of the Act.
  2. Information already pseudonymized under Article 4(4). Under Article 28-7 of the Act, provisions on access, correction, deletion, and suspension do not apply to it, so it may be kept and used for research for the period in Article 4(4) even after a data reset.

4. Requests regarding feedback in Article 2(5), email addresses in Article 2(6), and other rights can be made at the contact in Article 12; the Operator acts within 10 days and informs the user of the result.

Article 10 (Security Measures)

The Operator encrypts information in transit (HTTPS), restricts access to stored information to the Operator, and uses app attestation (App Check) to reduce illegitimate requests. When processing pseudonymized information, the Operator keeps the additional information needed to restore it separately.

Article 11 (Automatic Collection Tools)

1. The Operator does not operate cookies, advertising identifiers, or other tools that collect behavioral information for advertising or external tracking on its website or app.

2. Collection of usage records to provide the Service is governed by Article 2(2).

Article 12 (Privacy Officer)

The Operator designates the following privacy officer, who oversees personal information processing and handles complaints and remedies. Name: Gaya Ghym · Contact: contact@nownowlife.com

Article 13 (Children)

The Service is not directed at users under 16, and the Operator does not knowingly collect personal information from children under 16.

Article 14 (Remedies)

Users may contact the following Korean authorities to report or seek advice on privacy infringements:

  1. Personal Information Dispute Mediation Committee: +82-1833-6972 (www.kopico.go.kr)
  2. Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  3. Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  4. Korean National Police Agency: 182 (ecrm.police.go.kr)
Article 15 (Changes)

Changes to this Policy and their effective date are posted on the Service website at least 7 days in advance, or at least 30 days in advance for material changes to users' rights.

Business name: 가야김 (Gaya Ghym) · Representative: Gaya Ghym · Business registration no.: 448-15-02596
Address: Room 501-301A, 5F Gyeu Building, 61 Daehak-ro 12-gil, Jongno-gu, Seoul, Republic of Korea · Phone: +82-10-9206-4393 · Email: contact@nownowlife.com

© 2026 nownow · Notice your now, now.