D-Day Keep Privacy Policy

First Published: May 21, 2026 · This Revision Published: August 25, 2026

CodeSand Co., Ltd. (the "Company") treats the personal information of users of D-Day Keep (the "Service") with care and complies with applicable law, including the Personal Information Protection Act of Korea. This Policy is written so that Users can see what information the Company collects, when, where it is sent, what it is used for, and when it is erased.

All core features of the Service are available without signing up. Signing in is optional, for cloud backup, multi-device synchronization, and the like. In this Policy, "User" means anyone who uses the Service regardless of whether they have signed up, "Member" means a signed-in User, and "Guest" means a User who uses the Service without signing in (the same as Article 1 of the Terms of Service).

1. Personal Information Collected

Common to all of the below: the information below is transmitted over the network at the time the User uses the feature concerned. The Company does not collect precise location (GPS), contacts, call or message logs, health information, payment-instrument information such as credit card numbers, or unique identifying information such as resident registration numbers. The app does not request location permission.

NameMembers only
Items collected
The nickname or profile name provided by the social account. For Sign in with Apple, the name provided once at first sign-in
When collected
When signing in with a Kakao, Google, or Apple account
Sent to · stored by
Supabase Inc. (United States / Singapore)
Purpose of use
Member identification and profile display. The Company does not perform real-name verification.
Email AddressMembers · when contacting us
Items collected
① The email address of the social account (where that account has consented to provide it) ② A reply email address the User enters when submitting an inquiry or bug report (optional)
When collected
① When signing in ② When an inquiry or bug report is submitted
Sent to · stored by
① Supabase Inc. ② The inquiry-intake server operated by the Company (Republic of Korea)
Purpose of use
Member identification, replying to inquiries

Email addresses are removed from error diagnostics ("Crash Data" below) before transmission.

Photos or VideosOnly when the User selects them
Items collected
① Photos set as the background of a D-Day ② Screenshots attached to an inquiry or bug report (up to 3, optional). Videos are not collected.
When collected
When the User selects a photo directly from the device's photo library. Background photos are uploaded regardless of whether the User has signed up.
Sent to · stored by
① Supabase Inc. storage ② The inquiry-intake server operated by the Company
Purpose of use
Displaying background photos, multi-device synchronization and restoration after reinstalling the app, responding to inquiries

The Company does not access photos the User has not selected, and does not attach screen captures to error diagnostics.

Other User ContentWhat the User enters
Items collected
The title, date, time, icon, color, theme, pinned state, and notification settings of a D-Day; D-Day information created via a share link; the title and content of inquiries and bug reports
When collected
Members: synchronized to the server when a D-Day is registered or edited. Users who have not signed up: stored only inside the device and not synchronized to the server. However, if a share link is created, the information of that D-Day is stored on the server regardless of whether the User has signed up.
Sent to · stored by
Supabase Inc. / inquiry content goes to the inquiry-intake server operated by the Company
Purpose of use
Cloud backup and multi-device synchronization, provision of share links, responding to inquiries

Statistical analytics and error diagnostics do not include content entered by the User, such as D-Day titles and memos.

User IDAll Users
Items collected
The service account identifier (including the anonymous account identifier issued automatically on first launch of the app where the User has not signed up), the user identifiers issued by Kakao, Google, and Apple, and the per-installation identifier included in error reports
When collected
On first launch of the app (automatic issuance of the anonymous account), when signing in, and when an error occurs
Sent to · stored by
Supabase Inc. / Functional Software, Inc. (Sentry)
Purpose of use
Per-user data isolation, Member identification, de-duplication of error reports

Member identifiers are not passed to statistical analytics (Firebase Analytics).

Device IDAll Users
Items collected
The app instance identifier that the analytics tool issues automatically for each app installation, and the Android advertising identifier (AAID)
When collected
When the app is launched, and when an advertisement is displayed (Android)
Sent to · stored by
Google LLC (United States)
Purpose of use
Preventing duplicate counting in statistical analytics, delivery of advertisements

On iOS the Company does not request App Tracking Transparency (ATT) consent and therefore does not collect or use the advertising identifier (IDFA). On Android, ad personalization can be turned off in the device settings.

Coarse LocationCountry, region, and city level
Items collected
① The country, region, and city inferred from the connection IP when an error report is transmitted ② The language and country values set on the device (for example, KR) ③ The country and region estimated from the connection IP in the course of analytics and ad processing
When collected
① When an error occurs ② When the app is launched ③ When analytics events are sent and when advertisements are displayed
Sent to · stored by
① Functional Software, Inc. (Sentry) ② Supabase Inc. ③ Google LLC
Purpose of use
Understanding the environment in which an error occurred, usage statistics by country, delivery of advertisements

The app does not request location permission and does not collect precise location such as GPS. Error reports do not store the IP address itself; only the country, region, and city inferred from the IP are recorded.

Purchase HistoryStored only on the device
Items collected
The type of Paid Product purchased, and whether the ad-removal entitlement is held
When collected
When a Paid Product is purchased or a purchase is restored
Sent to · stored by
Stored only inside the device; not transmitted to the Company's servers. The parties that hold the payment and the purchase history are the Apple App Store and Google Play.
Purpose of use
Applying the ad-removal entitlement

The seller of Paid Products is each App Marketplace, and the Company does not collect or store payment-instrument information such as credit card numbers. Purchase restoration is carried out on the basis of the App Marketplace account.

Product InteractionAll Users · cannot be turned off
Items collected
Screen navigation and feature-usage events (registering, deleting, and decorating a D-Day, the D-Day category selected, changes to notification settings, changes of language or theme, onboarding progress, sign-in method, adding a widget, account deletion, and the like), user properties (the theme selected, the app language, the band of the number of D-Days registered), and the usage environment recorded when the app is launched (OS type, app version, device language and country settings, number of installed widgets)
When collected
When the app is launched, and when the feature concerned is used
Sent to · stored by
Google LLC (Firebase Analytics) / the usage environment goes to Supabase Inc.
Purpose of use
Improvement of the Service, analysis of usage statistics

Collection of this item cannot currently be turned off inside the app. If you do not want it to be collected, please stop using the app and delete it. The events do not include content entered by the User, such as D-Day titles.

Crash DataOnly when an error occurs
Items collected
The type, message, and stack trace of the error, the time of occurrence, the app version and release identifier, the device model and OS version, the screen-navigation trail immediately before the error, and tags indicating where the error occurred
When collected
Transmitted only when an error occurs in an app distributed through the stores. Nothing is transmitted in normal use.
Sent to · stored by
Functional Software, Inc. (Sentry, Germany EU region)
Purpose of use
Ensuring the stability of the Service, analyzing the causes of errors

Screenshots are not attached, email addresses and IP addresses are removed before transmission, and performance data tracking how fast the app runs is not collected.

Other Diagnostic DataWhen an inquiry is submitted
Items collected
The app version, OS version, device model name, language selected in the app, and sign-in method, attached automatically to an inquiry or bug report (including the Member identifier where the User is signed in)
When collected
When an inquiry or bug report is submitted
Sent to · stored by
The inquiry-intake server operated by the Company (Republic of Korea)
Purpose of use
Reproducing the problem and responding to the inquiry

The information needed for notifications and home screen widgets to work is processed only inside the device and is not transmitted separately.

2. Purpose of Use of Personal Information

The Company uses the personal information it collects only for the following purposes, and where a purpose changes it will give notice in advance and obtain any consent required.

The Company does not use the D-Day information and photos registered by Users for advertising or marketing purposes.

3. Retention and Use Period, and Destruction

a. Where a Member has deleted their account

When you run Settings → Account → Delete Account in the app, the following information is destroyed without delay. It cannot be recovered.

In addition, the linkage with the Kakao and Google accounts is released and the sign-in session is ended.

The following information is not deleted immediately by the account-deletion procedure alone; it is destroyed at the times set out below.

b. Where the Service is used without signing up

The Service automatically issues an anonymous account when the app is first launched. Only the minimum information needed for authentication — an anonymous identifier and the times of creation and access, for example — is recorded in that account; information by which the User could be identified, such as a name or email address, is not included.

The list of registered D-Days is stored only inside the device and is not synchronized to the server, so it disappears when the app is deleted. However, where a background photo has been set or a share link created, that photo and the D-Day information are linked to the anonymous account and stored on the server.

If a User who has been using the Service without signing up later signs in, a new Member account is issued and the list of D-Days stored on the device is moved to the new account. The former anonymous account is then no longer used, but its record and the photos linked to it remain on the server.

The Company does not currently apply a separate automatic destruction standard to anonymous account records. Anonymous account records do not contain information by which the User could be identified, and the Company does not use them for any purpose other than providing the Service. If you want a photo linked to an anonymous account deleted, deleting the background photo of the D-Day concerned in the app deletes it from the server as well.

c. Items with a fixed period

d. Items retained under applicable law

Payment and refund records for Paid Products are retained by the Apple App Store and Google Play, the sellers, in accordance with their own policies and applicable law; the Company does not hold them.

e. Method of destruction

Information in the form of electronic files is permanently deleted by a method that makes it impossible to recover or reproduce.

4. Provision of Personal Information to Third Parties

The Company does not provide Users' personal information to third parties. The following are exceptions.

Where the content of a D-Day is shown to the other party through a share link that the User created and sent themselves, that is disclosure by the User's own choice, not provision to a third party by the Company.

5. Outsourcing of Personal Information Processing

The Company outsources the processing of personal information to the following providers in order to provide the Service. The Company requires the safe management of personal information through its outsourcing agreements, and where a processor or the content of the outsourced work changes, it will disclose this through this Privacy Policy.

Supabase Inc.Privacy Policy ↗
Outsourced task
Operation of the authentication server, storage of user data and photos, handling of share links
Location
United States / Singapore
Outsourced task
Kakao account sign-in authentication
Location
Republic of Korea
Outsourced task
Google account sign-in authentication, delivery of AdMob advertisements, analysis of app usage statistics and remote app configuration, processing of Google Play in-app purchases
Location
United States
Outsourced task
Apple ID sign-in authentication, processing of App Store in-app purchases
Location
United States
Functional Software, Inc. (Sentry)Privacy Policy ↗
Outsourced task
Collection and analysis of error diagnostics
Location
Germany (Sentry EU region)

The sellers of Paid Products are the Apple App Store and Google Play, which process payments in accordance with their own terms and privacy policies. The Company does not collect or store payment-instrument information. Detailed transfer information for providers whose processing location is outside Korea is set out in Section 6.

6. Overseas Transfer of Personal Information

In the course of providing the Service, the Company transfers personal information outside Korea as described below. These transfers fall under outsourced processing and storage for the conclusion and performance of a contract with the data subject under Article 28-8(1)(iii) of the Personal Information Protection Act of Korea, and disclosure of the following through this Privacy Policy serves in place of the required notice.

Timing and method of transfer (common to the providers below): transmitted over the network from time to time, at the moment the User uses the feature concerned. Error diagnostics, however, are transmitted only when an error occurs. Each provider's contact point can be found via the Privacy Policy link on its card.

Supabase Inc.Privacy Policy ↗
Country
United States / Singapore
Items
Account identifier (including the anonymous account identifier), email address, nickname or profile name, D-Day information, uploaded photos, notification and widget settings, usage environment (OS, app version, device language and country settings, number of installed widgets), share link information
Purpose
Operation of the authentication server, cloud backup and multi-device synchronization, provision of share links
Retention
The same as the periods set out in Section 3.
Country
United States
Items
The user identifier and email address on Google sign-in, the app instance identifier, the Android advertising identifier (AAID), app usage records and user properties, device information, app version, and the country and region estimated from the connection IP
Purpose
Sign-in authentication, delivery of AdMob advertisements, analysis of usage statistics, remote app configuration, processing of Google Play payments
Retention
Until termination of the outsourcing agreement or fulfillment of the purpose of use
Country
United States
Items
Apple user identifier, email address (where the User has consented to provide it), name (where provided at first sign-in)
Purpose
Apple ID sign-in authentication, processing of App Store payments
Retention
Until termination of the outsourcing agreement or fulfillment of the purpose of use
Functional Software, Inc. (Sentry)Privacy Policy ↗
Country
Germany (Sentry EU region). The recipient is a U.S. company.
Items
The type, message, and stack trace of the error, the time of occurrence, the app version and release identifier, the device model and OS version, the screen-navigation trail immediately before the error, tags for where the error occurred, the per-installation identifier, and the country, region, and city inferred from the connection IP
Purpose
Ensuring the stability of the Service and analyzing errors
Retention
30 days after collection

A User who does not wish their personal information to be transferred outside Korea may express that refusal to the data protection officer in Section 11. However, refusing overseas transfer limits the use of features that rely on the server, such as cloud backup, multi-device synchronization, and D-Day sharing.

7. Advertising Identifiers and Personalized Advertising

The Service displays AdMob advertisements to Users who have not purchased the ad-removal product.

For details, please refer to the Google Privacy Policy.

8. User Rights and How to Exercise Them

Users may exercise the following rights at any time.

They may be exercised in the following ways.

The legal representative of a child under 14 years of age may exercise the above rights on the child's behalf. Where the Company receives a request for access, correction, deletion, or suspension of processing and there is legitimate cause under applicable law to restrict that request, it will inform you of that cause.

9. Measures to Secure Personal Information

The Company implements the following measures.

10. Personal Information of Children under 14

The Company does not accept sign-ups from children under 14 years of age. If it becomes aware that the personal information of a child under 14 has been collected, it will destroy that information without delay.

11. Data Protection Officer and Remedies for Infringement of Rights

The Company has designated a data protection officer. Users' inquiries and complaints about the processing of personal information, remedies for harm, and requests for access are handled by the department below.

To obtain relief for infringement of personal information, Users may apply for dispute resolution or counseling to the following bodies.

12. Changes to This Policy

Effective Date: August 25, 2026 (originally effective May 21, 2026)
The content of this Policy may be added to, deleted from, or modified in line with changes in law, policy, or the Service; where it is changed, the reason and the effective date will be stated and posted on the Service website.


© 2026 CodeSand Co., Ltd. Business Registration No. 368-87-03020.