Privacy Policy
1. Who We Are
Dotori is developed and operated by Luvia Soft ("the Company," "we," "us"). This policy applies to the Dotori mobile application (iOS/Android) and describes how we handle personal data in compliance with South Korea's Personal Information Protection Act (PIPA) and applicable international privacy laws.
2. Information We Collect
2.1 Account identifiers
When you first open Dotori, the app automatically creates an anonymous Firebase identifier on your device so our servers can recognize your installation — no sign-in is required and no personal information is attached to this identifier by default.
If you choose to sign in with Google, Apple, or Kakao, we additionally receive the email address, display name, and profile photo URL provided by that login method, linked to your device identifier. Signing in lets your premium subscription and account carry over if you reinstall the app or switch devices.
2.2 Subscription status
We use RevenueCat to validate your App Store/Google Play purchases, linked to your account identifier. We receive your subscription/entitlement status (e.g., active, expired) — not your payment card details, which are handled entirely by Apple or Google.
2.3 Usage analytics
We use Firebase Analytics to understand how the app is used in aggregate — for example, sign-in method, screens visited, and account creation/deletion events. This data does not include the content of your health records.
2.4 Guardian (family notification) feature — Premium
If you enable the optional Guardian feature, a temporary pairing code is created to connect your account with a family member's; it expires automatically within 24 hours. Once connected, we store both accounts' identifiers along with the nickname, relationship label, and preferred notification language you set — solely to route medication/visit alert notifications between you and your guardian. No vitals, medication, or medical record content is included in these notifications or stored on our servers.
2.5 AI Health Report — Premium, opt-in
If you use the AI health summary feature, we send aggregated statistics (e.g., averages and trends calculated from your vitals) to Google's Gemini API through our server, to generate a plain-language summary. Your raw, record-by-record health data is never transmitted for this feature.
2.6 Device permissions
- Camera / Photo Library: used only when you choose to attach a photo to a medical or checkup record, or take a photo of your own medication. Photos stay in the app's local storage unless you create a backup yourself.
- Notifications: used to remind you about medication times and upcoming medical/checkup appointments. These reminders are scheduled entirely on your device.
2.7 Medication image lookup (Korea only)
If your device region is Korea, searching for a medication by name sends that search term to the Korea Pharmaceutical Information Center's public drug-identification API (via data.go.kr) to retrieve an official pill/package image. No other personal information is included in this request.
2.8 Support & operational records
If you contact us by email, we receive whatever information you choose to include in that message. If you withdraw your account, we log the event (account identifier, platform, and timestamp) for a limited time for operational and fraud-prevention purposes.
3. What We Do Not Do
- We do not upload your vitals, medication logs, or medical/checkup records to our servers.
- We do not sell your personal information.
- We do not share your health data with advertisers or data brokers.
4. How We Use Information
We use the information above to operate and secure the app, validate your premium subscription, deliver the reminders and guardian alerts you've configured, generate AI summaries you request, respond to support inquiries, and understand aggregate usage to improve the app.
5. Third-Party Processors
| Service | Purpose |
|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging, Analytics) | Account identity, premium status sync, push notifications, usage analytics |
| RevenueCat | Subscription/purchase validation |
| Google Gemini API | AI health summary generation (Premium, opt-in only) |
| Korea data.go.kr / KPIC | Public medication image lookup (Korea-locale users only) |
These providers process data on our behalf under their own security and privacy commitments; your data may be stored or processed outside your country of residence (including the United States) as a result.
6. Backups
If you create a backup, it is saved to your own Google Drive or iCloud account — never to a Luvia Soft server. We have no access to these backup files.
7. Data Retention
Local health data remains on your device until you delete it or uninstall the app. Account-related server data is retained while your account is active and deleted when you withdraw your account, except for brief operational logs kept for fraud prevention.
8. Your Rights
You can view, edit, export, or delete your local health data at any time within the app — this is never restricted, even on the free tier or after a trial ends. You may withdraw your account at any time from Settings. To exercise any additional rights under PIPA, GDPR, or similar laws (such as requesting a copy of server-held data), contact us using the information below.
9. Children's Privacy
Dotori is designed for adult users and is not directed at children. We do not knowingly collect personal information from children.
10. Security
We apply reasonable technical and organizational safeguards, including encrypted network transport and access-controlled cloud infrastructure, to protect the limited data we process.
11. Changes to This Policy
If we make material changes to this policy, we will update the effective date above and, where appropriate, notify you in the app.
12. Contact
Questions about this policy or your data can be sent to elliekwon@luvia-soft.com.
개인정보처리방침
1. 운영 주체
도토리는 루비아소프트(Luvia Soft)(이하 "회사")가 개발·운영합니다. 본 방침은 도토리 모바일 앱(iOS/Android)에 적용되며, 개인정보보호법 및 관련 국제 개인정보 법령을 준수하여 개인정보 처리 방식을 안내합니다.
2. 수집하는 정보
2.1 계정 식별자
도토리를 처음 실행하면 서버가 설치 단위를 식별할 수 있도록 기기에 익명 Firebase 식별자가 자동 생성됩니다. 로그인은 필수가 아니며, 기본적으로 이 식별자에는 개인정보가 연결되지 않습니다.
Google, Apple, 카카오로 로그인하시면 해당 로그인 수단이 제공하는 이메일 주소, 표시 이름, 프로필 사진 URL이 추가로 수집되어 계정 식별자와 연결됩니다. 로그인하시면 앱을 재설치하거나 기기를 변경해도 프리미엄 구독·계정 정보가 유지됩니다.
2.2 구독 상태
RevenueCat을 통해 App Store/Google Play 결제 내역을 검증하며, 이는 계정 식별자와 연결됩니다. 수신하는 정보는 구독·이용권 상태(예: 활성/만료)이며, 결제 카드 정보는 전혀 수신하지 않습니다(Apple/Google이 전담 처리).
2.3 이용 분석(Analytics)
Firebase Analytics를 이용해 로그인 방식, 방문 화면, 계정 생성·탈퇴 이벤트 등 앱 이용 현황을 집계 수준에서 파악합니다. 이 데이터에는 건강 기록의 내용이 포함되지 않습니다.
2.4 보호자(가족 알림) 기능 — 프리미엄
보호자 기능을 사용하시면 상대방 계정과 연결하기 위한 임시 코드가 생성되며, 24시간 내 자동 만료됩니다. 연결이 완료되면 알림 발송 목적으로만 두 계정의 식별자와 사용자가 설정한 닉네임·관계·알림 언어가 저장됩니다. 바이탈·복용약·진료기록의 실제 내용은 알림이나 서버에 포함되지 않습니다.
2.5 AI 건강 리포트 — 프리미엄, 선택 기능
AI 건강 요약 기능을 사용하시면 사용자의 바이탈 기록에서 계산된 집계 통계(평균·추세 등)만 서버를 통해 Google Gemini API로 전송되어 요약문을 생성합니다. 날짜별 원본 기록은 이 기능을 위해 전송되지 않습니다.
2.6 기기 권한
- 카메라/사진 라이브러리: 진료·검진 기록에 사진을 첨부하거나 복용약 사진을 직접 촬영할 때만 사용됩니다. 사진은 사용자가 직접 백업하지 않는 한 앱 내부 저장소에만 보관됩니다.
- 알림: 복용 시간, 진료·검진 예약을 안내하기 위해 사용되며, 모든 알림 예약은 기기 내에서만 처리됩니다.
2.7 약 이미지 조회 (한국 전용)
기기 국가가 한국인 경우, 약 이름으로 검색하면 검색어가 한국약학정보원의 공공 의약품 식별 API(data.go.kr 경유)로 전송되어 공식 약 이미지를 조회합니다. 이 요청에는 다른 개인정보가 포함되지 않습니다.
2.8 고객 문의 및 운영 기록
이메일로 문의하시면 보내주신 내용을 수신합니다. 회원 탈퇴 시 부정 이용 방지 및 운영 목적으로 계정 식별자, 플랫폼, 일시가 제한된 기간 동안 기록됩니다.
3. 하지 않는 것
- 바이탈·복용약·진료기록을 서버에 업로드하지 않습니다.
- 개인정보를 판매하지 않습니다.
- 건강 데이터를 광고주나 데이터 브로커와 공유하지 않습니다.
4. 정보 이용 목적
위 정보는 앱 운영·보안, 프리미엄 구독 검증, 설정하신 알림·보호자 알림 발송, 요청하신 AI 요약 생성, 문의 응대, 그리고 앱 개선을 위한 집계 이용 현황 파악 목적으로만 사용됩니다.
5. 제3자 처리 위탁
| 서비스 | 목적 |
|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging, Analytics) | 계정 식별, 프리미엄 상태 동기화, 푸시 알림, 이용 분석 |
| RevenueCat | 구독·결제 검증 |
| Google Gemini API | AI 건강 요약 생성 (프리미엄, 선택 시에만) |
| 한국 data.go.kr / 한국약학정보원(KPIC) | 공공 의약품 이미지 조회 (한국 로케일 사용자 전용) |
위 제공업체는 각자의 보안·개인정보 기준에 따라 회사를 대신하여 정보를 처리하며, 이 과정에서 데이터가 거주 국가 외(미국 등)에서 저장·처리될 수 있습니다.
6. 백업
백업을 생성하면 사용자 본인의 Google Drive 또는 iCloud 계정에 저장되며, 루비아소프트 서버에는 저장되지 않습니다. 회사는 이 백업 파일에 접근할 수 없습니다.
7. 보유 기간
기기 내 건강 데이터는 사용자가 직접 삭제하거나 앱을 삭제할 때까지 보관됩니다. 계정 관련 서버 데이터는 계정이 활성 상태인 동안 보관되며, 탈퇴 시 삭제됩니다(부정 이용 방지를 위한 짧은 기간의 운영 기록은 예외).
8. 이용자의 권리
앱 내에서 언제든지 기기 내 건강 데이터를 열람·수정·내보내기·삭제할 수 있으며, 이는 무료 이용자나 트라이얼 종료 후에도 제한되지 않습니다. 설정 화면에서 언제든지 계정을 탈퇴할 수 있습니다. 개인정보보호법·GDPR 등에 따른 추가 권리(서버 보관 정보의 열람 요청 등) 행사를 원하시면 아래 연락처로 문의해 주세요.
9. 아동의 개인정보
도토리는 성인 사용자를 대상으로 설계되었으며 아동을 대상으로 하지 않습니다. 회사는 아동의 개인정보를 고의로 수집하지 않습니다.
10. 안전성 확보 조치
회사는 처리하는 제한된 정보를 보호하기 위해 전송 구간 암호화, 접근 통제가 적용된 클라우드 인프라 등 합리적인 기술적·관리적 보호조치를 적용합니다.
11. 방침 변경
본 방침이 중요하게 변경되는 경우 상단의 시행일을 갱신하고, 필요한 경우 앱 내 공지를 통해 안내합니다.
12. 문의처
본 방침이나 개인정보 처리에 대한 문의는 elliekwon@luvia-soft.com으로 보내주세요.