개인정보 처리방침
Culprit의 데이터 처리, 보관, 삭제, 제3자 서비스 정보를 확인하세요.
데이터 사용
앱 기능 제공, 동기화, 지원 응답, 안정성 개선에 필요한 정보만 다룹니다.
삭제와 보관
계정 또는 데이터 삭제는 앱 안의 삭제 기능이나 지원 이메일을 통해 요청할 수 있습니다.
추적 제한
광고 목적의 제3자 추적이나 개인정보 판매를 전제로 설계하지 않았습니다.
This Privacy Policy explains how Culprit collects, uses, and shares information when you use the app. By using the app, you consent to the practices described here.
1. Information We Collect
1.1 You provide
- Account data: Culprit works without signing in. On first use it creates a private guest account — a random identifier with no name or email — so your entries can be saved to our servers. If you choose to link an account (Settings → Account), we receive what you link: on iOS an Apple ID identifier and the email Apple provides, a Google account identifier and email, or an email address and password; on Android a Google account identifier and email, or an email address and password
- Onboarding responses: primary symptoms selected, food groups you chose to test, Lite/Standard mode preference
- Meal logs: food names, meal type, time, optional ingredients, optional notes
- Symptom check-ins: 0–5 severity ratings (bloating, cramping, diarrhea, constipation, fatigue, brain fog, skin reaction, headache), and the meal you link the check-in to (if any)
- Reintroduction outcomes: which foods you tested, start/end timestamps, and whether you reported no / mild / strong reaction
1.2 Automatically collected
- Anonymized app version, OS version, device model, coarse locale
- Subscription state via RevenueCat (a pseudonymous app user ID — the same random identifier as your guest or linked account — entitlement status and product ID; on Android a Google Play purchase token)
- Crash reports (only if you opt in via your device settings)
1.3 Not collected
- Precise location, contacts, advertising identifiers (IDFA), microphone, audio, camera
- HealthKit data (iOS) or Health Connect data (Android)
- Cross-app tracking identifiers of any kind
2. How We Use Information
- Provide the core program (elimination phase tracking, reintroduction scheduling, washout enforcement)
- Calculate your baseline symptom statistics at the end of the elimination phase
- Generate qualitative pattern summaries from your reintroduction test results
- Process subscription purchases and manage entitlements
- Schedule on-device local notifications (test-day and washout-end reminders — not sent to our servers)
- Improve app quality via anonymized aggregate metrics
- Comply with legal obligations
3. AI and Automated Analysis
The first time you open your pattern report after finishing a reintroduction test, the app asks for your permission to use AI for the plain-language notes in the report. When you allow it, our server (a Supabase Edge Function) sends pseudonymised data to Anthropic’s Claude API to draft a one-to-two-sentence summary of how each tested food group related to your logged symptoms. The prompt contains only: a row identifier, food names and food-group names, a numeric confidence score, the reaction-timing window (immediate / delayed / late), and a numeric delta score relative to your baseline. No account ID, email address, display name or raw symptom rows are sent to Anthropic. If you decline, or turn the option off in Settings → AI, nothing is sent and the report uses fixed wording instead. The resulting summary is stored in our database so the same report is not re-generated on repeat views. We call this pseudonymised rather than anonymous because the underlying logs stay linked to your account in our systems and the summary is written back to it. Anthropic processes this data on our behalf under its commercial API terms, may retain API inputs and outputs for up to 30 days, and does not use them to train its models; we do not hold a zero-data-retention agreement.
To prevent abuse, the number of AI-written reports is limited per account and per network. For this we keep only counts (dates, numbers, and a salted one-way hash of the network address) — never your logs, report text or food names. When a limit is reached the report is still produced, with fixed wording instead of AI-written notes.
The pattern report is shown in the app using qualitative labels only (“Frequently observed before symptoms”, “Sometimes observed before symptoms”, “Worth watching”, “No clear pattern”). Numeric confidence scores and percentages are never shown to you and are not intended as clinical measurements.
4. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Backend, auth, database, Edge Functions | Account and logs (scoped by row-level security) |
| RevenueCat | Subscription management | Pseudonymous app user ID, subscription status, product ID |
| Anthropic (Claude) | Qualitative pattern summary for the report | Food group names, outcome status, timing window, delta score (no identifiers) |
| Apple (iOS only) | In-app purchases; Sign in with Apple only if you choose to link or sign in with it | Purchase receipt; Apple ID identifier and email only if you use Sign in with Apple |
| Google Play billing (Android); Sign in with Google only if you choose to link or sign in with it | Purchase token; Google account identifier and email only if you use Sign in with Google |
We do not sell your data. We do not participate in any ad network.
5. Data Storage and Security
- Data is stored on Supabase with TLS in transit and encryption at rest
- Row-level security ensures each user can only read and write their own records
- AI calls are made server-side via a Supabase Edge Function; your app never holds third-party API keys
- API keys are kept out of version control
6. Data Retention and Deletion
We keep your entries until you delete them. A guest account lives on this device’s sign-in session: if you delete the app or sign out of a linked account, a guest’s entries can no longer be reached, so link an account if you want to keep them.
Delete your data from Settings → Delete account (guests: Delete my data), or see how to delete your account and data. This immediately and permanently removes your profile, meal logs, symptom check-ins, reintroduction results, baseline and pattern reports from our servers, and the app then continues with a new empty guest session. OOTSSU apps share one sign-in service: your sign-in record (email, Apple/Google identifier, or the guest identifier) is deleted too unless you use the same sign-in in another OOTSSU app, in which case it is kept only for that app and no Culprit data remains linked to it. We keep counts of AI report requests (dates and numbers, no content) so that deleting and starting over cannot reset the free allowance; daily counts are deleted after 35 days, network-hash counts after 7 days, and a free account’s lifetime counter (a single number) stays. Purchase records held by Apple, Google and RevenueCat are kept for billing and tax and are not deleted by this; deleting does not cancel a subscription. Records required for legal, tax or fraud-prevention purposes are kept as the law requires.
7. Your Rights
Depending on your jurisdiction (GDPR, CCPA, PIPA, etc.) you may have the right to access, correct, delete, export, object to, restrict processing, or withdraw consent. To exercise any of these rights, email ootssu@ootssu.com. We respond within 30 days.
8. Children's Privacy
The app is not directed to children under 16. We do not knowingly collect personal data from children.
9. International Transfers
Your data may be stored or processed in countries other than your own (e.g., United States for Supabase, RevenueCat, Anthropic). By using the app, you consent to such transfers subject to appropriate safeguards.
10. Cookies and Tracking
The app does not use cookies or advertising trackers. We do not participate in ad networks or cross-app tracking. App Tracking Transparency prompts are not shown because no such tracking occurs.
11. Changes
Material changes will be announced via in-app notice or email at least 7 days before taking effect.
12. Contact
Email: ootssu@ootssu.com. We are the data controller responsible for personal information processed through the app.
지원이 필요하신가요?
앱, 계정, 결제, 데이터 삭제 문의는 이메일로 보내주세요.