WebGongbang (the "Operator"), which operates Daily Logs (the "Service"), establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information and rights of data subjects and to handle related grievances promptly.
This is an English translation provided for convenience. In case of any discrepancy between the Korean and English versions, the Korean version prevails.
1. Purposes of Processing Personal Information
The Service processes collected personal information for the following purposes. If a purpose changes, we will obtain prior consent.
- Member management: member identification, sign-up verification, identity confirmation, fraud prevention, blocking sign-ups by children under 14
- Service provision: schedule/task/routine management, records/journals/notes, attachment storage, notifications
- AI analysis features (optional): providing emotion/pattern analysis based on the journal/record text you write
- Paid service billing: subscription/payment processing, refunds, payment fraud prevention
- Service improvement: usage statistics, new feature development, error tracking
- Customer support: responding to inquiries, dispute handling, announcements
2. Personal Information We Collect
2-1. Required items (at sign-up)
- Email address
- Password (stored with one-way encryption)
- Name or nickname
- Time and version of consent to the Terms and this Privacy Policy
2-2. Items collected via social login
- Google login: email address, name, profile photo URL, social provider identifier
- Kakao login: email address, nickname, profile photo URL, social provider identifier
- Naver login: email address, name, profile photo URL, social provider identifier
2-3. Information collected automatically during use
- IP address, access time, browser/device information (User-Agent)
- Android app: FCM token (for push notifications), OS version, app version, device identifier
- Service usage records: page views, feature usage, error logs
- Cookies and session identifiers
2-4. Content you enter or upload
- Text content of records, journals, tasks, routines, and notes
- Attached images, audio recordings, drawings, and document files (transmitted with encryption to Cloudflare R2 storage)
- Photo metadata (EXIF) included in attached photos: date taken, camera make/model, lens/exposure and similar capture information. GPS location (latitude/longitude) is stored only if you explicitly enable location saving in Settings; the default is OFF. Stored location data is used only to display photo information to you.
- Location you attach to a record (optional): latitude/longitude, accuracy, place name/address, and the time it was captured. This is collected only when you tap "Add location" while writing a record; if you enabled photo location saving, the capture location of attached photos is also applied to the record. To look up a place name, the coordinates (rounded to a roughly 100 m grid) are sent to Google Maps Platform (Geocoding API); turning off Settings > Location > "Look up place names" stops this and stores coordinates only. You can remove location data from a record at any time, and it is deleted together with the record.
- Tags, folders, and user settings
2-5. When purchasing paid services
- Google Play purchase token, order ID, subscription product ID
- ※ Payment instrument details such as credit card numbers are processed by Google Play; the Service does not store them.
3. Retention and Use Period
The Service destroys personal information immediately upon account deletion or when the processing purpose is achieved, except for the following items retained for the stated periods and reasons.
| Item |
Retention period |
Basis |
| Member information (email, name, password) |
Deleted immediately upon account deletion |
Service provision |
| User content (records, journals, notes, attachments) |
Deleted immediately upon account deletion |
Service provision |
| Long-term inactive members (dormancy policy) |
Automatic account deletion 395 days after last access (notified 30/15/5 days in advance) |
Article 17 of the Terms of Service (active paid subscribers excluded) |
| Access logs, IP addresses |
3 months (deleted immediately upon account deletion) |
Protection of Communications Secrets Act, Art. 15-2 |
| Service usage records (activity logs) |
90 days (deleted immediately upon account deletion) |
Service improvement and security (internal policy) |
| AI feature usage records |
90 days (deleted immediately upon account deletion) |
Cost management and abuse prevention (internal policy) |
| Transaction records (contracts, withdrawal of offers, payments) |
5 years — even after account deletion, only these records are kept separately in pseudonymized form (personal identifiers removed) and automatically destroyed 5 years after the transaction date |
E-Commerce Act Enforcement Decree, Art. 6 |
| Administrator processing records (audit logs) |
1 year |
Standards for Security Measures for Personal Information, Art. 8 |
4. Outsourcing of Personal Information Processing
To provide the Service smoothly, we outsource the following processing tasks to external providers. Outsourcing contracts specify safeguards required under Article 26 of the Personal Information Protection Act.
| Processor (location) |
Outsourced task |
Entrusted information |
Retention period |
| Cloudflare, Inc. (R2) — USA |
Attachment storage/delivery and database backup storage |
Files you upload (images, audio, drawings, documents), database backup files |
Attachments: deleted immediately upon account deletion / Backups: up to 60 days |
| Google LLC (Firebase Cloud Messaging) — USA |
Push notification delivery |
FCM token, notification payload |
Until token expiry or account deletion |
| Google LLC (Firebase Analytics / Crashlytics) — USA |
Android app usage statistics and crash diagnostics |
App usage events, device model/OS version, app version, diagnostic information upon errors (no identifying information such as name or email is sent) |
Per Firebase policy (up to 14 months) |
| Google LLC (Google Maps Platform, Geocoding API) — USA |
Place name/address lookup for record locations (reverse geocoding) |
Coordinates (latitude/longitude rounded to a roughly 100 m grid), response language (no identifying information is sent) |
Service-side cache 30 days / Google retention per Google policy |
| Google LLC (Google Play Billing) — USA |
Paid subscription payment processing |
Purchase token, order ID, subscription product ID |
As required by applicable law |
| Google LLC (Google Calendar) — USA |
Two-way schedule sync (only if you explicitly connect your calendar) |
Title, date/time, and memo of tasks/events |
Until you disconnect or delete your account |
| Google LLC (reCAPTCHA) — USA |
Bot protection at sign-up and password reset |
IP address, browser information, page interaction signals |
Per Google policy |
| OpenAI, L.L.C. — USA |
AI analysis / AI chat features (only when you use these features) |
Your written text (journals, records, notes, routines, etc.) to the extent necessary for AI processing. No account-identifying information such as name or email is sent |
Discarded after processing (up to 30 days per OpenAI policy) |
| DirectSend Co., Ltd. — Republic of Korea |
Sign-up / password-reset email delivery |
Email address, name, message content |
Discarded immediately after delivery |
| Functional Software, Inc. (Sentry) — USA |
Error tracking and diagnostics |
Upon errors: user ID, device information, stack trace |
Up to 90 days |
| Google LLC (Google Analytics 4) — USA |
Service usage/traffic statistics |
Anonymized IP, page views, events (no identifying information such as name or email is sent) |
Up to 14 months |
Any change to outsourced tasks or processors will be disclosed through this Privacy Policy.
4-1. Cross-Border Transfer of Personal Information
The Service entrusts the processing/storage of personal information to the overseas processors (USA) listed above, pursuant to Article 28-8(1)3 of the Personal Information Protection Act, as necessary to provide the Service.
- Items transferred: same as the "Entrusted information" column above
- Destination country: United States (see the table for each processor's location)
- Time and method of transfer: transmitted over encrypted connections (TLS) at the time the relevant feature is used
- Recipients' contact: each processor's privacy contact (Cloudflare: privacyquestions@cloudflare.com / Google: googlekrsupport@google.com / OpenAI: privacy@openai.com / Sentry: privacy@sentry.io)
- Retention period: same as the "Retention period" column above
- How to refuse and consequences: you may refuse cross-border transfer by not using the relevant features (attachments, push notifications, AI features, calendar sync, paid billing) or by deleting your account; in that case use of those features or of the Service may be limited. Inquiries: support@dailylog.kr
4-2. Use of Google User Data and Limited Use Compliance
The Service's Google Calendar integration requests only the following minimal permissions (scopes) via Google APIs, and each scope is used solely for the user-facing feature described below.
- calendar.calendarlist.readonly (read calendar list): used only to display your list of calendars so you can choose which calendar to sync when connecting.
- calendar.events (read/write events): used only for two-way synchronization (create, update, delete) between the calendar you selected and your tasks/events in the Service.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We do not use data received from Google Calendar (including raw, aggregated, or derived data) to create, train, or improve generalized AI/ML (artificial intelligence or machine learning) models.
- We do not use such data for advertising, and we do not sell or transfer it to third parties.
- Humans do not read such data, except for security purposes, to comply with applicable law, or with your explicit consent.
- If you connect an AI assistant yourself (the MCP feature described in 5-1), tasks it retrieves may include items synced from your calendar; this occurs only to provide the user-facing feature you initiated, and such data is likewise never used to train AI/ML models.
5. Provision to Third Parties
The Service processes personal information only within the scope stated in Section 1 and does not provide it to third parties in principle, except when:
- you have given separate consent;
- required by law or unavoidable to comply with legal obligations;
- requested by an investigative agency under procedures and methods prescribed by law; or
- clearly necessary for the urgent protection of life, body, or property of you or a third party where prior consent cannot be obtained.
5-1. User-directed transmission: AI assistant connection (MCP)
As a paid add-on feature, the Service allows you to connect an external AI assistant of your choice (such as Claude or Cursor) to your own data (records, tasks, routines, journals, notes, etc.) using a personal access token that you issue yourself or an OAuth authorization that you approve yourself (MCP).
- User-directed transmission: data transmission through this feature is a user-directed act — you send your own data to the external AI service you have chosen, using a token you issued or an OAuth authorization you approved yourself. It does not constitute the Service providing personal information to a third party.
- External AI service policies apply: the handling of transmitted data (including whether it is stored or used for training) is governed by the privacy policy of the AI service you connect (e.g., Anthropic, OpenAI). We recommend reviewing that AI service's privacy policy before connecting.
- Metadata only: the Service retains only API call metadata (call time, tool type, success status, processing time) for service operation and abuse prevention, and does not store the content of calls (the data payloads sent or received).
- Token revocation: you may revoke any token you have issued at any time in Settings, which blocks the connection.
6. Rights of Data Subjects and Legal Representatives, and How to Exercise Them
You may exercise the following rights at any time:
- Request notification of processing status
- Request access to your personal information
- Request correction or deletion of errors
- Request suspension of processing
- Request data portability (download)
- Withdraw consent (account deletion or withdrawal of marketing consent)
6-1. How to exercise your rights
- Directly in the app: Settings → Profile/Account menu — edit information, delete account
- Data copy request (portability): from Settings → Request My Data Copy, we prepare all of your account data in a machine-readable format (JSON) and email a download link to your registered address. This is free of charge regardless of your plan, and the link is valid for 72 hours. Locked entries are included as-is in their encrypted form, openable only with the per-entry password you set.
- By email: send a request to support@dailylog.kr with your registered email address
- Via a legal representative: possible upon submission of a power of attorney and ID copy
We act on such requests without delay (at the latest within one month of receipt), and while a correction/deletion request is being processed, we do not use or provide the personal information concerned.
6-2. Cases where rights may be limited
- Where access/processing is prohibited or restricted by law
- Where it may harm another person's life or body, or unjustly infringe another person's property or interests
- For information subject to statutory retention under Section 3 (deletion restricted during the retention period)
7. Destruction of Personal Information
We destroy personal information without delay once the retention period elapses or the processing purpose is achieved.
7-1. Procedure
Information subject to destruction is selected and destroyed with the approval of the responsible officer.
7-2. Method
- Electronic files: permanently deleted using methods that prevent recovery
- Paper documents: shredded or incinerated
8. Security Measures
Pursuant to Article 29 of the Personal Information Protection Act, we implement:
- Administrative measures: minimizing personnel handling personal information, regular training, internal management plans
- Technical measures: one-way password encryption, TLS 1.2+ transport encryption, database access control, intrusion prevention systems
- End-to-end encryption of secret entries: notes/journals you mark as secret are encrypted with AES-256 on your device before storage; the encryption key is never stored on our servers, so even the Operator cannot read the content
- Physical measures: access control to server/data rooms (per outsourced data center security policies)
- Access records: access logs to personal information systems retained for at least 1 year
- Regular inspection: external security review and vulnerability assessment at least once a year
9. Cookies and Automatically Collected Information
- Purpose: maintaining login sessions, saving preferences, usage statistics
- How to refuse: browser settings → Privacy/Security → block or selectively allow cookies
- Effect of refusal: login may not persist and some features may be limited
10. Privacy Officer
| Item |
Details |
| Officer |
Chongmyung Park (Privacy Officer, Representative of WebGongbang) |
| Contact |
support@dailylog.kr |
You may direct any privacy-related inquiries, complaints, or requests for remedy to the Privacy Officer; we will respond and act without delay.
11. Remedies for Infringement
For reports or consultations regarding privacy infringement, you may contact (Republic of Korea):
12. Changes to This Privacy Policy
If this policy is amended due to changes in laws, policies, or security technology, we will give notice via in-service announcements or email at least 7 days before the effective date (30 days for material changes). Material changes will require renewed consent.
13. Contact
14. Account and Data Deletion
You may delete your account and all related data at any time.
Delete in the app
- Log in to the Daily Logs app.
- Go to Settings → Profile.
- Tap "Delete Account" at the bottom.
- Confirm to proceed. (Accounts registered with email require password confirmation.)
Request deletion by email
Data deleted
- Account information (email, name, profile)
- All records and notes
- Daily/weekly/monthly/yearly journals
- Tasks and routines
- All attachments (images, audio recordings, drawings, documents, etc.)
- AI analysis results and AI chat conversations
- Tags and folders
- Subscription information
※ Deleted data cannot be recovered.
Processing time
Deletion in the app is processed immediately. Email requests are processed within 3 business days.
15. Additional Notice for Users in the EU/EEA (GDPR)
If you reside in the European Union (EU) or the European Economic Area (EEA), the following applies in addition to the other sections of this policy, in accordance with the EU General Data Protection Regulation (GDPR). The controller of your personal data is the operator identified in Section 10.
15-1. Legal bases for processing (GDPR Art. 6)
| Processing activity |
Legal basis |
| Account creation and login, core features (logs, journals, tasks, notes, routines), paid subscription processing |
Performance of a contract (Art. 6(1)(b)) |
| AI-based analysis (mood analysis, summaries and drafts, etc.) |
Consent (Art. 6(1)(a)) — you can withdraw it at any time in Settings |
| Marketing and product news notifications |
Consent (Art. 6(1)(a)) — withdrawable at any time |
| Service security (unauthorized access detection, access logs), usage statistics for service improvement |
Legitimate interests (Art. 6(1)(f)) |
| Retention of payment and transaction records required by law |
Compliance with a legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
15-2. Your rights as an EU/EEA user
In addition to the rights described in Section 6, you may exercise the following rights under the GDPR. The methods in Section 6-1 apply, and we will inform you of the outcome within one month of receiving your request.
- Right of access (Art. 15): access to, and a copy of, your personal data being processed
- Right to rectification (Art. 16): correction of inaccurate personal data
- Right to erasure (Art. 17): deletion of your personal data, including account deletion (except data we are legally required to retain)
- Right to restriction (Art. 18) and right to object (Art. 21): restriction of, or objection to, processing based on legitimate interests
- Right to data portability (Art. 20): provided free of charge in a structured, machine-readable format (JSON) via the "Request My Data Copy" feature described in Section 6-1
- Right to withdraw consent (Art. 7): withdraw consent for consent-based processing (AI analysis, marketing) at any time — this does not affect the lawfulness of processing before withdrawal
- Automated decision-making: we do not carry out solely automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you. AI analysis results are reference information to support your personal reflection only.
15-3. International transfers
Our servers are located in the Republic of Korea, and personal data of EU/EEA users is transferred to and processed in the Republic of Korea. The Republic of Korea is covered by an adequacy decision of the European Commission (December 17, 2021), so such transfers are lawful under GDPR Art. 45 without additional safeguards. Transfers to US-based processors listed in Section 4 (Cloudflare, OpenAI, Google, etc.) rely on lawful transfer mechanisms provided by each processor, such as the EU Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework.
15-4. Complaints to a supervisory authority
EU/EEA users have the right to lodge a complaint with a data protection supervisory authority in the member state of their habitual residence, place of work, or the place of the alleged infringement. We would, however, appreciate the chance to address your concerns first — please contact the Privacy Officer in Section 10.
Revision History
- Amended September 22, 2026 (current) — added record location (place/route) data items and the Google Maps Platform transfer notice for place-name lookup (2-4)
- Amended September 5, 2026 — reflected the in-app data copy request (portability) feature (6-1); added the GDPR notice for EU/EEA users (15)
- Amended July 21, 2026 — added Google user data and Limited Use compliance notice (4-2); reflected minimized calendar permissions (scopes)
- Amended July 16, 2026 — added cross-border transfer notice; supplemented outsourcing entries (Firebase Analytics/Crashlytics, Google Calendar, reCAPTCHA); added photo location (EXIF) notice; named the Privacy Officer; added AI assistant connection (MCP) notice (5-1)
- Effective May 28, 2026