개인정보 처리방침
PulseCalm의 데이터 처리, 보관, 삭제, 제3자 서비스 정보를 확인하세요.
데이터 사용
앱 기능 제공, 동기화, 지원 응답, 안정성 개선에 필요한 정보만 다룹니다.
삭제와 보관
계정 또는 데이터 삭제는 앱 안의 삭제 기능이나 지원 이메일을 통해 요청할 수 있습니다.
추적 제한
광고 목적의 제3자 추적이나 개인정보 판매를 전제로 설계하지 않았습니다.
This Privacy Policy explains how PulsCalm collects, uses, and shares information.
1. Information We Collect
No sign-in required
PulseCalm opens without an account. The first time it needs to save something to our servers, it creates a private guest account on your device: a random identifier with no email address or name. You can optionally connect an account later (Settings → Connect an account: email, Apple or Google) to keep your records if you change phones.
1.1 You provide
- Account: the random guest identifier. If you connect an account, also your email address, an Apple user identifier (and relay or real email) or a Google account identifier.
- Session history: which calming sessions you completed (technique, length, whether AI-written).
- Situation note: the optional free-text note you write in Settings. It stays on your device unless you turn on AI-personalized sessions (see section 3).
1.2 HealthKit data (with your permission)
- Heart rate variability (HRV, SDNN) — the only HealthKit measurement PulseCalm uses.
HealthKit is read on your device. Each new HRV reading (a number in milliseconds and its timestamp) is stored in your account to build your personal baseline, and when a possible stress pattern is noticed, the HRV value, your baseline, the level, and the time of day are stored with it. PulseCalm does not upload other HealthKit data, and does not write to Apple Health.
1.3 Automatically collected
- Subscription state via RevenueCat
- Crash reports (Apple-level, opt-in)
1.4 Not collected
- Camera/photos, microphone/audio, location, contacts, IDFA, browsing history
2. How We Use Information
- Detect stress patterns and generate recovery sessions
- Display your session history and compute your personal baseline
- Email your weekly report to your account email, if you request it (requires a connected account and Pro)
- Process subscription purchases
3. AI and Automated Analysis
Pro subscribers can turn on AI-personalized sessions. The first time, PulseCalm asks for your permission, and nothing is sent without it (you can turn it off in Settings). When on, our server forwards the following to Anthropic's Claude API to write a short calming script: your current HRV reading, your personal baseline, the time of day and weekday, how many sessions you did today, your preferred technique, and the situation note you wrote (if any). Your name, email and account identifier are not sent. Anthropic does not use this data to train models and deletes it within 30 days under its commercial terms. When AI is off or unavailable, sessions come from templates stored on your device. To enforce fair-use limits our server keeps a per-account daily count of AI requests (no content).
4. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Backend, auth, database | Account identifier (guest identifier or connected account), session history, HRV readings and stress-pattern records, subscription flag |
| RevenueCat | Subscription management | Pseudonymous account identifier (the same random identifier, never your name or email), purchase history, entitlement |
| Anthropic (Claude) | AI insight generation | Only if you turn on AI-personalized sessions: HRV reading, baseline, time of day, session count, preferred technique and your situation note. No name, email or account identifier. |
| Apple | Sign in with Apple, IAP, HealthKit | Authentication token and (optionally) email if you sign in with Apple; purchase receipt; HealthKit permissions |
| Sign in with Google (optional) | Authentication token and account identifier | |
| Resend | Weekly report email (only if you request it) | Your account email and the report figures |
We do not sell your data. HealthKit data is not shared with advertising networks or used for marketing.
5. Security
- TLS in transit, encryption at rest
- Row-level security for user data isolation
- HealthKit is read on-device; only the HRV values described above are stored
6. Retention
Retained while you use PulseCalm. When you delete your data in the app (Settings → Delete My Data for guests, Delete Account for connected accounts), your session history, stress-pattern records, HRV readings and profile are removed immediately. Your sign-in record is removed too, unless the same login is still used by another OOTSSU app — in that case only the PulseCalm data is removed. The daily AI-request counter (no health or message content) is kept while the sign-in record exists so that fair-use limits cannot be reset by deleting, and is removed with the sign-in record. If deletion cannot be completed (for example, you are offline), nothing is deleted and the app shows the reason. Backups rotate out within about 30 days. See how to delete your data.
7. Your Rights
Deletion is available in the app at any time, including for guests. For access, correction or export, email ootssu@ootssu.com.
8. HealthKit Disclosures
- HealthKit data is used only for the app's stated features.
- HealthKit data is not used for advertising.
- HealthKit data is not disclosed to third parties for their marketing purposes.
- You may revoke HealthKit permissions at any time in iOS Settings → Privacy & Security → Health.
9. Children's Privacy
Not directed to children under 16.
10. International Transfers
Data may be processed in the United States via Supabase, RevenueCat, and Anthropic.
11. Cookies and Tracking
No cookies. No IDFA. No ad networks.
12. Changes
Material changes announced via in-app notice or email at least 7 days before taking effect.
13. Contact
Email: ootssu@ootssu.com
지원이 필요하신가요?
앱, 계정, 결제, 데이터 삭제 문의는 이메일로 보내주세요.