นโยบายความเป็นส่วนตัว
Effective Date: April 6, 2026 | Last Updated: May 4, 2026 (v3 Enhanced)
Elpis Studio ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application SoberShield ("App"), in accordance with applicable data protection laws including the Korean Personal Information Protection Act (PIPA, including the September 11, 2026 amendment), GDPR, UK GDPR, and CCPA/CPRA.
1. Information We Collect
Sensitive information (health and location data) is collected only with separate consent from general personal information consent at registration (Korean PIPA §23 and applicable laws).
| Category | Data | Purpose |
|---|---|---|
| Account | Email, username, birth year | Account creation, service delivery, age verification (under-14 block) |
| Optional Profile | Profile photo, language, region | Personalized experience |
| Health Data (Sensitive) | Drinking/smoking records, craving logs, FTND/AUDIT scores | Core sobriety tracking features. Collected after separate consent. |
| Location (Sensitive) | GPS coordinates (volatile), risk zone coordinates and radius, coordinates recorded when a suspected drunk-driving alert occurs | Safe-zone classification (on-device), danger zone alerts. Raw GPS used for safe-zone classification and risk-zone coordinates/radius are stored encrypted on your device and are NOT transmitted to our servers. However, when a suspected drunk-driving alert occurs, the coordinates at that moment are included in the alert record and stored encrypted with your isolated key for multi-device sync. In addition, when you trigger an SOS, a link to your current location is sent to the emergency contacts you designated. Separate consent under Korean Location Information Act §15 |
| Device | Bluetooth device names (vehicle) | Pre-drive safety alerts (delivery not guaranteed) |
| Community | Posts, comments, photos (optional), nickname, profile photo | Community features. Posts, comments, nickname, and profile photo are publicly visible to other users. Photos have location/EXIF metadata automatically stripped before upload |
| AI Coaching (AI Manager) | Conversation history; nickname, addiction type, and recent records included in system prompts | AI Manager response generation. Transmitted to Anthropic, PBC's Claude API in the United States for processing (see §6 below). API data is NOT used to train Claude models. Logs auto-deleted after 7 days. |
| Family Alerts (optional, Premium) | Family member photos and names | Displayed on your own device's screen during SOS alerts. Never transmitted to our servers; stored locally on your device only |
| Payments | Subscription status (processed by RevenueCat) | Premium service delivery |
| Automatic | App usage data, crash logs | Service improvement, bug fixes. PII (email, IP, JWT, coordinates, etc.) is automatically redacted before transmission |
2. How We Collect Information
- Directly from you when you create an account and use the App
- Automatically generated during App usage (location, device info, usage data)
- Third-party login providers: Google Sign-In, Kakao Login (subject to their respective policies)
3. How We Use Your Information
- Service Delivery: Sobriety tracking, AI coaching (information provision only), safe zone alerts, community features
- Account Management: Identity verification, fraud prevention, under-14 block
- Service Improvement: De-identified analytics, bug fixes, new feature development
- Notifications: Milestone celebrations, check-ins, danger zone alerts (delivery not guaranteed by OS)
- B2G Services: De-identified aggregate statistics for organizational administrators
4. Data Retention
- Location (raw GPS coordinates): Used for safe-zone classification and discarded immediately after; NOT stored on our servers. Risk-zone information (coordinates/radius) is stored encrypted on your device only (no server sync). Coordinates included in suspected drunk-driving alert records are an exception and are stored encrypted for multi-device sync.
- Drinking and Smoking Records: Stored on your device first. Optionally synced to our servers for multi-device access, with per-user isolation keys restricting access.
- AI Coaching Conversations: Anthropic API logs auto-deleted after 7 days. User conversation history on our side is stored on the user's device first.
- Account Deletion: All data deleted within 30 days of account deletion request. Storage photos and reports are also automatically removed on account deletion.
- Legal Requirements: Transaction records retained for 5 years; access logs for 3 months (as required by Korean law)
- On-Device Data: Automatically deleted when the App is uninstalled (no recovery possible after 1 year of uninstall)
5. Third-Party Sharing
We do not share your personal information with third parties without your consent, except:
- When you have given prior consent
- When required by law or legal process (see Terms §12-A Subpoena Policy)
- B2G Services: Organization administrators receive only monthly aggregate sobriety/cessation statistics, your nickname, and join date. Individual drinking/smoking records, location, and photos are NOT shared with the organization.
We do NOT sell your personal information or share it for cross-context behavioral advertising (California "Do Not Sell" right honored).
6. Service Providers (Subprocessors)
| Provider | Service | Country | Safeguards |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Storage, FCM, Hosting, Crashlytics) | Data storage, authentication, push notifications, hosting, crash logs | United States / multi-region | Google Cloud DPA + SCCs + GDPR/CCPA certification |
| RevenueCat, Inc. | Subscription receipt validation and management | United States | SOC 2 Type II |
| Anthropic, PBC (Claude API) | AI Manager response generation | United States | Commercial Terms + DPA (with SCCs) automatically apply. API data is NOT used to train models. Logs auto-deleted after 7 days (per Sep 14, 2025 policy). |
| Twilio (SMS Gateway, when used) | SOS emergency SMS dispatch | United States | Twilio DPA |
International Data Transfer (Korean PIPA §28-8 / GDPR Art. 46): All subprocessors above are located in the United States. By using the App you consent to international data transfer to the United States under Articles 17(3) and 28-8 of the Korean Personal Information Protection Act. For EU residents, EU Standard Contractual Clauses (Decision 2021/914) apply. The categories transferred, the purpose of processing by each recipient, and retention periods are described in §1 and §4.
7. Your Rights
You may exercise the following rights at any time:
- Access, correct, or delete your personal information
- Request suspension of data processing
- Delete your account (Settings > Delete Account in the App)
- Withdraw consent for location data collection (disable in App settings)
- Withdraw consent for AI Manager international data transfer (by discontinuing AI Manager use)
- Opt out of marketing notifications (App settings)
To exercise your rights, use the in-app settings or contact us at chrislee.krh@gmail.com. We respond within 10 days after identity verification (or 45 days for CCPA/GDPR requests).
8. Data Security
- On-device encryption: RxDB AES-256 + IndexedDB sandboxing
- In-transit encryption: HTTPS / TLS 1.3
- Access control: Firebase Security Rules + Firebase App Check (blocks tampered clients)
- Authentication: Password hashing (bcrypt/scrypt), OAuth standards (Google/Kakao)
- Photo metadata removal: EXIF/GPS/XMP metadata automatically stripped before upload (blocks Strava-2018-style location leakage)
- Crash log PII redaction: Email, IP, JWT, coordinates, passwords automatically removed before Crashlytics transmission
- BLE security: Only device name stored; readings discarded on device
- Sensitive data additional encryption: Emergency contact phone numbers, etc.
- Periodic security audits: KISA self-assessment + data protection impact assessment
- Incident response: 24-hour notification to KISA (privacy.kisa.or.kr / 118), affected users notified
9. Location Information (Korean Location Information Act §15 Separate Consent)
- Data Collected: GPS coordinates (latitude/longitude), and the coordinates recorded at the time of a suspected drunk-driving alert
- Purpose: Alerts when approaching user-defined risk zones (bars, convenience stores, etc.)
- When Collected: Only when location tracking is enabled by the user
- Processing: Raw GPS coordinates used for safe-zone classification are processed on-device only and are not stored on our servers. Risk-zone information (coordinates/radius) is likewise stored encrypted on your device and is not transmitted to our servers. However, when a suspected drunk-driving alert occurs, the coordinates at that moment are included in the alert record and stored encrypted with your isolated key for multi-device sync.
- Opt-out: Can be disabled anytime in App settings (immediate effect)
- Legal basis: Korean Location Information Act §15 separate consent (separate checkbox at registration)
10. Children's Privacy (PIPA §22-2 / COPPA)
We do not knowingly collect personal information from children under 14 years of age (Korean PIPA §22-2). At registration, we verify birth year and reject sign-ups from users under 14. If we become aware that we have collected such information, we will promptly delete it. We do not market the Service to children.
US residents (COPPA): We do not knowingly collect personal information from children under 13. If a parent or guardian becomes aware that their child has provided us with personal information, please contact us at chrislee.krh@gmail.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material adverse changes will be notified through in-app announcements or push notifications at least 30 days in advance; other changes at least 7 days in advance.
12. Contact Us
- Data Controller: Elpis Studio
- Email: chrislee.krh@gmail.com
For complaints, you may also contact:
- Korean Personal Information Infringement Report Center: privacy.kisa.or.kr / 118
- Korean Personal Information Dispute Mediation Committee: kopico.go.kr / 1833-6972
- EU residents: Your national Data Protection Authority (e.g., UK ICO, France CNIL, Germany BfDI)
- California residents: California Attorney General (oag.ca.gov/privacy)
13. Additional Rights for US, EU, and UK Residents
(a) California (CCPA/CPRA)
California residents have the following rights: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of Sale/Sharing (we do not sell), Right to Limit Use of Sensitive Personal Information, Right to Non-Discrimination. Submit requests to chrislee.krh@gmail.com; we respond within 45 days (extendable by 45 days).
(b) EU/EEA/UK (GDPR/UK GDPR)
EU/EEA/UK residents have the rights under GDPR Articles 13/15/16/17/18/20/21/22 (information, access, rectification, erasure, restriction, portability, objection, automated decision-making opt-out). Transfers to US processors rely on EU Standard Contractual Clauses (Decision 2021/914) and Anthropic's DPA.
Submit requests or complaints to chrislee.krh@gmail.com or your national Data Protection Authority (e.g., UK ICO, France CNIL, Germany BfDI).
14. Korean PIPA September 2026 Amendment Notice
Effective September 11, 2026, the amended Korean Personal Information Protection Act imposes administrative fines of up to 10% of total revenue for repeated violations or large-scale damages. We comply with this enhanced regime through periodic security audits (KISA self-assessment), data protection impact assessments, and incident response procedures.
15. US Health Breach Notification Rule (HBNR) Compliance
Per the FTC's Health Breach Notification Rule (16 CFR Part 318) as expanded on July 29, 2024, this service qualifies as a self-help health application. We comply as follows:
- No advertising or tracking pixels: We do not integrate Meta Pixel, Google Analytics, Pinterest, TikTok, AppsFlyer, Branch, or any advertising SDK. Verified via source-code audit, May 2026.
- Breach notification: In the event of a breach affecting US residents, we will notify the FTC and affected users within 60 days. Media notification applies if 500 or more individuals are affected.
- No third-party sharing of health data: Drinking/smoking logs, craving records, FTND/AUDIT scores, and similar health data are never shared with advertisers or marketing networks.
This clause expresses our proactive measures against the pixel-leak patterns established in FTC enforcement against BetterHelp 2023 ($7.8M), GoodRx 2023 ($1.5M), Premom 2023 ($200K), Cerebral 2024 ($7M), and Monument/Tempest 2024 ($2.5M).
16. iOS App Tracking Transparency (ATT) Statement
We do not perform user tracking as defined by Apple's App Tracking Transparency framework (NSPrivacyTracking=false). The app does not transmit any advertising identifier (IDFA, IDFV) to advertising networks or third-party trackers, and does not link user activity across apps or websites owned by other companies. Therefore the iOS App Store review prompt for ATT permission is not triggered. The PrivacyInfo.xcprivacy files (app + widget) declare zero tracking domains.
17. Dispute Resolution — Arbitration Option and Opt-Out Right
Users may choose their preferred dispute resolution method.
- Default: Korean law and the Seoul Central District Court as the competent court (Terms §13).
- Option: US residents may elect individual arbitration under the American Arbitration Association (AAA) Consumer Arbitration Rules. A class action waiver applies.
- 30-Day Opt-Out Right: Within 30 days of account creation, you may opt out of the arbitration clause by emailing chrislee.krh@gmail.com with the subject line "Arbitration Opt-Out". Upon opt-out, the default dispute resolution procedure (§13) applies.
- Korean residents: Korean mandatory consumer protection laws (Act on Regulation of Terms and Conditions §14) prevail over arbitration agreements where applicable.