혼잣말 개인정보처리방침

시행일 2026-09-11 (v2.1) · 개인정보처리자: 보라소프트(대표 정승현) · 문의 horongbul@gmail.com · 이용약관

당신의 일기는 단 1KB도 서버로 전송되지 않습니다.

1. 원칙

혼잣말은 계정 없이 쓰는 앱입니다. 일기·메모·일정·지출·사진·음성·감정 분석 결과·AI 대화는 전부 사용자의 기기 안에만 암호화(SQLCipher)되어 저장되고, 회사는 그 내용을 보관하지도 볼 수도 없습니다. 회사가 서버에 두는 것은 아래 2항의 최소 항목뿐이며, 그것도 공유일기 기능을 쓸 때만 생깁니다.

2. 수집·보관하는 개인정보와 목적

항목목적보관생기는 때
익명 ID (앱이 만든 무작위 22자)공유일기 연결 상대 식별, 구독 여부 확인사용자가 삭제를 요청할 때까지앱 첫 실행 시 자동 등록
암호화·서명 공개키종단간 암호화, 요청 위조 방지위와 같음앱 첫 실행
연결 관계 (어느 익명 ID 와 연결됐는지, 상태)공유일기 전달해제 시 즉시 삭제초대 링크 수락 시
구독 여부·만료일초대 기능 잠금/해제구독 종료 후 갱신구독 시
푸시 알림 토큰"새 댓글" 같은 고정 문구 알림토큰 갱신 또는 앱 삭제 시 교체·소멸알림 권한 허용 시
Google/Apple 계정 식별자의 해시 (SHA-256)재설치 뒤 익명 ID 되찾기사용자가 해제하거나 삭제 요청할 때까지"ID 보호"를 선택했을 때만
종단간 암호화된 상자 (일기·댓글·좋아요 암호문)상대 기기로 전달상대가 받아가면 즉시 삭제, 최대 7일공유·댓글·좋아요 시

회사는 이름·이메일·전화번호·주소·위치·기기 식별자·IP 주소·접속 기록을 수집하거나 저장하지 않습니다. 닉네임과 아바타는 기기 안에만 있고, 사용자가 초대 링크를 보내거나 일기를 공유할 때 상대의 기기로만 전달됩니다(서버는 저장하지 않음). 서버 오류 로그에는 오류 종류만 남고 요청 본문은 남지 않습니다.

3. 앱이 인터넷에 접속하는 경우 (전부)

경우상대보내는 것
온디바이스 AI 모델 내려받기huggingface.co모델 파일 요청(GET)만. 사용자 데이터 없음
공유일기sync.borasoft.net (연결 전에는 honjatmal-sync.borasoft.workers.dev)2항의 항목과 암호문 상자
푸시 토큰 발급Expo 푸시 서비스(exp.host)기기 푸시 토큰, 앱 ID
ID 보호 로그인Google / Apple로그인은 각 사의 화면에서 이뤄지고, 앱은 발급된 ID 토큰을 회사 서버에 한 번 보내 해시만 남깁니다. 이메일·이름은 요청하지 않습니다
구독 결제Google Play / App Store결제는 스토어가 처리. 앱은 영수증 확인 결과만 받음
그 외 모든 통신은 앱 안의 네트워크 가드가 차단하고, 차단 건수와 실제 전송량을 설정 화면에서 볼 수 있습니다. 광고·분석(애널리틱스)·크래시 리포팅 SDK 는 쓰지 않습니다. 사진·동영상 속 글자 인식(OCR)은 Google ML Kit 의 온디바이스 모델로 기기 안에서만 처리되며 아무것도 전송하지 않습니다.

4. 처리 위탁과 국외 이전

회사는 서버 운영을 위해 아래 사업자에게 처리를 위탁하며, 이들 서버는 국외에 있습니다.

수탁자업무이전되는 항목국가
Cloudflare, Inc.공유일기 서버·저장소(KV)·웹페이지 호스팅2항의 항목 전부(암호문 포함)미국 등 Cloudflare 네트워크
Expo (650 Industries, Inc.)푸시 알림 발송 중계푸시 토큰, 고정 알림 문구미국
Google LLC / Apple Inc.푸시 알림 최종 전달, ID 보호 로그인, 결제푸시 토큰 / ID 토큰 / 결제 정보(스토어 자체)미국
Google LLC (Firebase App Distribution)출시 전 테스트 빌드 배포 (테스터에게만)테스터 이메일 (테스터가 직접 제공)미국

회사는 위 사업자 외 누구에게도 개인정보를 제공하지 않으며, 판매하지 않습니다. 법령에 따른 수사기관 요청이 있어도 회사가 줄 수 있는 것은 익명 ID 와 연결 관계뿐이며 일기 내용은 회사에 없습니다.

5. 보관 기간과 파기

6. 안전조치

7. 이용자의 권리

8. 아동

앱은 만 14세 미만 아동을 대상으로 하지 않으며, 연령과 무관하게 같은 최소 수집 원칙이 적용됩니다.

9. 개인정보 보호책임자

보라소프트 대표 정승현 · horongbul@gmail.com. 개인정보 침해에 대한 신고·상담은 개인정보침해신고센터(privacy.kisa.or.kr, 118), 개인정보분쟁조정위원회(kopico.go.kr, 1833-6972)에서도 할 수 있습니다.

10. 변경

방침이 바뀌면 이 페이지와 앱 안에 시행일과 함께 알립니다. 이전 버전: v1 2026-09-09(공유일기 v1, 24시간 임시 코드 방식) → v2 2026-09-11(영구 익명 ID·연결 관계·푸시·ID 보호 추가) → v2.1 위탁·국외 이전·권리 항목 정리.


Honjatmal Privacy Policy

Effective 2026-09-11 (v2.1) · Controller: Borasoft (Seunghyun Jung) · Contact horongbul@gmail.com · Terms of Use

Not a single kilobyte of your diary is sent to our servers.

1. Principle

Honjatmal has no accounts. Entries, notes, schedules, expenses, photos, voice, emotion analysis and AI answers stay on your device, encrypted with SQLCipher. We cannot store or read them. The only server-side data is the minimal set in section 2, and it exists only if you use the shared diary.

2. What the server holds, and why

We do not collect or store names, email addresses, phone numbers, addresses, location, device identifiers, IP addresses or access logs. Your nickname and avatar live on your device and travel only to the devices of people you invite or share with. Error logs contain no request bodies.

3. Every network connection the app makes

Everything else is blocked by the in-app network guard, whose counters are visible in Settings. No ads, analytics or crash-reporting SDKs. Text recognition in photos and videos (OCR) runs on the device with Google ML Kit's on-device models and sends nothing.

4. Processors and international transfers

Cloudflare, Inc. (server, KV storage, web hosting — all section-2 items incl. ciphertext; Cloudflare network, incl. the US), Expo / 650 Industries, Inc. (push relay — token and fixed wording; US), Google LLC and Apple Inc. (push delivery, Protect-ID sign-in, payments; US), Google LLC / Firebase App Distribution (pre-release test builds — tester emails provided by testers; US). We share data with no one else and never sell it. Even under a lawful request, all we could hand over is anonymous IDs and link relationships; diary content is not in our possession.

5. Retention and deletion

Encrypted boxes: deleted on pickup, 7 days max. Links: deleted on unlink. Anonymous ID, keys, subscription status, recovery hash and push token: deleted promptly on request (section 7). On-device data: deleting the app deletes everything, irrecoverably.

6. Security

Device: full-database encryption (SQLCipher), key in the secure enclave/Keystore, biometric app lock. Transit: HTTPS plus end-to-end encryption (X25519 + XSalsa20-Poly1305); the server holds no decryption keys. Server: per-request Ed25519 signature verification, no body or IP logging, minimal retention.

7. Your rights

Access and correction happen in the app, since content lives on your device. Unlink from Settings → Shared diary. To disable Protect-ID or delete all server-side data, email us with your anonymous ID; an in-app "delete server data" button is planned. Turn off notifications in device settings to stop push. Export backups from Settings → Data.

8. Children

The app is not directed at children under 14; the same minimal-collection principle applies regardless of age.

9. Privacy officer

Seunghyun Jung, Borasoft — horongbul@gmail.com.

10. Changes

Changes are posted here and in the app with a new effective date. History: v1 2026-09-09 (shared diary v1, 24-hour codes) → v2 2026-09-11 (persistent anonymous ID, links, push, Protect-ID) → v2.1 processors, transfers and rights clarified.