MindDeck · Privacy Policy
RION Inc. · Revised October 3, 2026
- Your diary entries, selected cards, and photos are stored only on this device. They are never kept on our servers.
- Card suggestions, diary drafts, and the reflection chat are powered by AI (OpenAI). The text you write and your diary pass through our server for that request only and are not stored there.
- We do not collect your name, phone number, or location. You can delete all records anytime in Settings.
1. What we process, why, and where
- Diary data (your one line, selected emotion and need cards, diary text): writing, keeping, and rereading your diary. Stored on this device only.
- Photo records (one photo you pick, downsized; a title; emotion cards): stored on this device only. Never sent to our server or to AI.
- User identifier (a hash of the anonymous key provided by Toss): telling records apart on the device, daily usage limits, usage statistics. Sent to the server only as a further-hashed pseudonym.
- Android user key (SHA-256 hash of the Google account ID): created at first sign-in with Google, used for daily limits and usage statistics. Email, name and photo are not sent to our server.
- AI processing data (your one line and thought, card names, the finished diary text, your answers in the reflection chat): card suggestions, diary drafts, the comfort note, reflection chat. Sent through our server to OpenAI (USA) for processing and not stored on our server. The reflection chat is not stored on the device either. Only the returned comfort sentence is saved on the device with that entry.
- Usage records (screen views, taps, card IDs, time per step, whether a diary was completed, edited, saved, or deleted, app version, notification consent result): service improvement and statistics. Stored on the server under a pseudonym. Text, diary content, search terms, and photos are never collected.
- Server access logs (daily hash of IP address, request time, result): managing usage limits and preventing abuse. Raw IP addresses are not stored.
- Advertising: the Toss Ads SDK in the Toss mini-app and Google AdMob in the Android app. AdMob uses the advertising ID and device information to show and measure ads; users in the EEA and similar regions can choose in the consent form. Diary content and card names are never passed to ads.
- Push notifications: sent through Toss only if you turn them on in Settings. Consent is managed by Toss and can be withdrawn anytime in the Toss app settings.
2. How long we keep it
- Diary and photos (device): until you delete them. Deleting app data removes them too, and we cannot restore them.
- AI processing data: discarded by our server as soon as the response is returned. OpenAI does not use API inputs for training and retains them for up to 30 days for abuse monitoring (OpenAI API data policy).
- Usage records (pseudonymous): deleted automatically after 180 days. Server access and usage-limit logs: 90 days. AI usage metrics (token counts, no personal identification): 90 days.
3. Overseas transfer
- Recipient: OpenAI, L.L.C. (USA) · privacy@openai.com
- When and how: at the time of a card suggestion, diary generation, comfort note, or reflection chat request · over HTTPS via our server.
- What: your one line and thought, card names, tone, the finished diary text, and your reflection chat answers.
- Recipient: Google LLC (USA)
- When and how: Google Sign-In and rewarded ad requests and display in the Android app · sent directly from the device to Google.
- What: sign-in = Google account authentication (processed on the device; only a hash reaches our server) · ads = advertising ID, device and app information, IP address.
- Basis: processing entrusted as necessary to provide the service, disclosed in this policy (Personal Information Protection Act, Article 28-8(1)(iii)).
4. Third parties and processors
- We do not provide personal information to third parties, except when required by law.
- Processors: Amazon Web Services (server hosting, Seoul) · OpenAI (AI processing, USA) · Viva Republica, Inc. / Toss (mini-app runtime, anonymous identifier, Ads SDK, push notification delivery) · Google LLC (Google Sign-In and AdMob ads in the Android app).
5. Your rights
- You can delete records one by one or all at once inside the app.
- Usage records on the server are pseudonymous, so we cannot look up or correct a specific user's records. To request deletion, contact us below.
- In the Android app, you can reset or delete the advertising ID in device Settings → Google → Ads.
- You can remove the Google Sign-In connection in your Google Account → Security → Third-party apps.
- We do not collect personal information from children under 14.
6. Privacy officer
- Privacy Office · rion@riontech.kr
- B-504, Jiseong Hall 1, Osan University, 45 Cheonghak-ro, Osan-si, Gyeonggi-do, Korea · RION Inc.
7. Security and device permissions
- Encrypted connections (HTTPS), certificate-based server access only, automatic security patches, token-protected admin console.
- Photo library (optional): used only when you pick one photo in Photo Record. The diary works fully without this permission.
8. Nature of the service and changes
- MindDeck is a self-journaling tool. It does not replace diagnosis, treatment, or counseling.
- This policy applies from the official launch date. Changes are announced on this screen and on the published page with the revision date. Latest revision: October 3, 2026 (comfort note, Google Sign-In and AdMob ads in the Android app added; privacy officer listed by department).
This English text is a translation for convenience. If it differs from the Korean version, the Korean version prevails.