Privacy Policy
Aspado (the “Company”) provides Kan, a goal-management app. This policy explains how the Company processes and protects personal information under Article 30 of Korea’s Personal Information Protection Act (“PIPA”).
1. Purposes and legal bases for processing
| Purpose | Legal basis |
|---|---|
| Account creation, sign-in, identity verification, and account security | PIPA Article 15(1)(4), performance of a contract |
| Local goal-grid storage, premium cloud synchronization, and recovery | PIPA Article 15(1)(4), performance of a contract |
| On-device storage of todos and completion records, and local notifications | PIPA Article 15(1)(4), performance of a contract |
| Operation of the suggestions board, comments, voting, and author display | PIPA Article 15(1)(4), performance of a contract |
| Subscription and access-entitlement verification and paid features | PIPA Article 15(1)(4), performance of a contract |
| Statutory retention of payment and supply records and response to access requests | Article 6 of Korea’s Electronic Commerce Consumer Protection Act and Article 6 of its Enforcement Decree |
| Customer inquiries and account-deletion requests | PIPA Article 15(1)(4), performance of a contract and response to user requests |
| Service security, fraud prevention, and error diagnosis | PIPA Article 15(1)(6), the Company’s legitimate interests |
| Personalized advertising and ad measurement | PIPA Article 15(1)(1), consent |
The Company does not use personal information for purposes other than those above. If a purpose changes, the Company will obtain any required consent or take other measures required by law.
2. Personal information processed
| Category | Information | Collection method |
|---|---|---|
| Account and authentication | Firebase UID, sign-in-provider identifier, email address, display name, profile image, and provider | Received when you sign in with Google or Apple |
| Goal grids | Core goal, sub-goals, action items, status, color, target date, creation and update times, and internal identifiers | Entered by you in the app |
| Todos and completion records | Title, body, tags, date, recurrence rule, linked action item, completion date, and creation and update times | Created on the device when you enter or complete a todo |
| Suggestions board | Suggestion titles and bodies, comments, voting activity, display name, and creation and update times | Collected when a signed-in user submits a suggestion or comment or votes |
| Subscription and entitlement | App and product identifiers, entitlement status and period, and grant reason. If store purchasing is offered and you make a purchase: store, order, transaction and original-transaction identifiers, transaction type and status, and purchase, expiration, and revocation times | Collected after sign-in when checking access or when verifying an App Store or Google Play purchase |
| Device and service | Operating system, app version, language and locale, platform, app-instance identifier, IP address, user agent, request path, status and duration, and security and error records | Generated automatically while using the app, server, Firebase, and Google Fonts |
| Advertising and consent | Advertising identifier, approximate location, app and device information, ad impressions and interactions, and consent choices | Collected automatically during consent and ad requests for free users |
| Customer support | Contact email, inquiry, account-deletion request, one-time verification code, deletion-request ID, email HMAC lookup value, identity-verification information, and processing record | Collected or generated through email or an in-app request |
Goal grids, todos, completion records, and app settings used without signing in remain on your device. Premium users’ goal grids are synchronized automatically after sign-in and while using the app through Cloud Firestore. Todos and completion records remain on the device only, regardless of sign-in status, and are not sent to Cloud Firestore.
Suggestion titles and bodies, comments, display names, and creation times are visible to other users. Voting activity is associated with your account, but other users see only the aggregate vote count. Do not post sensitive information or another person’s personal information on the suggestions board.
The Company does not collect government identification numbers, passport numbers, driver’s-license numbers, health information, biometric information, or other sensitive information for providing Kan.
3. Retention periods
| Information | Retention period |
|---|---|
| Account and authentication information and synchronized goal grids | Until account deletion |
| Goal grids, todos, and completion records stored on the device | Until you delete them or uninstall the app; account-scoped data is deleted during in-app account deletion |
| Suggestions, comments, votes, and author information | Until account deletion or deletion of the relevant board data; if other users participated in a suggestion, only a de-identified record with the author and original content removed is retained |
| Active subscription and entitlement information | Until account deletion or entitlement expiration, whichever occurs first |
| If a purchase occurs, minimum records of contracts, withdrawal, payment, and supply | Five years from the transaction date; legacy records without a purchase time are retained for five years from record creation |
| On-device app error records | Records older than seven days are deleted the next time the app starts, and all are deleted during account deletion |
| Customer inquiries, verification, and supported-deletion processing records | One year after the inquiry is completed |
| Deletion-request ID and irreversibly transformed account identifier | Until the Kan service is discontinued, to prevent recreation of a deleted account and misuse of previous authentication information |
If a purchase occurs, the Company retains the minimum transaction evidence required by Korea’s Electronic Commerce Consumer Protection Act for five years. After account deletion, the Company stores the app, store, and product identifiers; order, transaction, and original-transaction identifiers; transaction type and status; purchase, expiration, and revocation times; retention deadline; an app-scoped, versioned HMAC lookup value generated from the email instead of the plain-text email; and an opaque deletion-request ID as pseudonymous information separate from other personal information. Customer IDs, Firebase UIDs, direct identifiers such as plain-text email, purchase tokens and raw receipts are excluded from this statutory record.
If Firebase Authentication deletion temporarily fails after remote data was removed during a supported account deletion, the Company temporarily stores the Firebase UID and former customer number in the deletion record for a safe retry. Both values are deleted immediately when identity deletion and completion recording finish and are not included in the one-year support record or five-year statutory transaction record.
4. Destruction procedures and methods
Personal information is destroyed without undue delay when its retention period expires or its processing purpose is fulfilled. Electronic files and database records are permanently deleted so they cannot be restored or reproduced. The Company does not keep Kan users’ personal information on paper.
When account deletion completes, the Company deletes synchronized goal grids from Cloud Firestore; customer identifiers and user-generated data, including the user’s comments and votes, from Basecamp; and the Firebase Authentication account. If other users’ comments or votes are attached to a suggestion, the Company may retain a de-identified post after removing its author, title, body, and translations to protect those other users’ records. In-app account deletion also removes the account’s local data from the device.
Statutory transaction records are separated from ordinary customer data and automatically destroyed when each five-year period ends. Authentication information remaining in Firebase Authentication live or backup systems may take up to 180 days to be removed after the Company requests deletion. Deleted information in disaster-recovery backups is not used for the ordinary service and is destroyed when the backup retention period ends.
5. Third-party disclosures
The Company does not disclose personal information for a third party’s independent purposes. If disclosure is based on separate consent or law, the Company will provide prior notice of the recipient, purpose, information, and retention period.
6. Processing contractors
| Contractor | Processing work |
|---|---|
| Google LLC | Firebase Authentication, Cloud Firestore synchronization, Firebase App Check integrity verification, Google sign-in, Google Fonts delivery, AdMob advertising, and UMP consent management |
| Apple Inc. | Apple sign-in and, if store purchasing is offered, App Store payment, subscription, and purchase-entitlement verification |
Kan content synchronized through Cloud Firestore is stored in the Seoul, South Korea region (asia-northeast3). This policy will be updated if a contractor or its work changes.
7. International transfers
| Recipient | Country | Information | Timing and method | Purpose | Retention period |
|---|---|---|---|---|---|
| Google LLC (contact) | United States and countries where Google services operate | Sign-in identifier, email, display name, profile image, IP address, user agent, and app, device, and locale information | Encrypted transfer when using Google sign-in, Firebase, or Google Fonts | Authentication, security, cloud synchronization, app-integrity verification, and font delivery | Firebase Authentication information is removed from live and backup systems within up to 180 days after an account-deletion request. App Check tokens last up to seven days and replay-protection tokens up to 30 days. Other information follows Google’s service-specific policies |
| Google LLC (contact) | United States and other countries where Google services operate | Advertising identifier, approximate location, app and device information, IP address, user agent, ad impressions and interactions, and consent information | Encrypted transfer during consent checks and ad requests | Advertising, measurement, frequency capping, fraud prevention, and consent management | Portions of IP addresses in ad logs are anonymized after nine months and identifier information after 18 months. AdMob reports are retained for 90 or 2,555 days depending on report type |
| Apple Inc. (contact) | United States and countries where Apple services operate | Apple sign-in identifier, email or relay email, authentication token and code, and, if a purchase occurs, purchase and subscription identifiers | Encrypted transfer during Apple sign-in or App Store purchase verification | Sign-in, disconnection, and, if a purchase occurs, payment, subscription, and entitlement verification | For the duration of the Apple account or app connection and any period required by law |
International transfers necessary to perform a contract rely on PIPA Article 28-8(1)(3), and personalized-advertising transfers rely on consent under paragraph (1)(1). If you refuse these transfers, you cannot use Google or Apple sign-in or premium cloud synchronization. You can still use on-device features such as goal grids and todos without signing in. You may refuse advertising transfers in the consent form or review your choice under Settings > Ad Privacy Settings; refusing does not prevent use of non-advertising app features. To stop authentication-related transfers after creating an account, delete it under Settings > Account > Delete Account.
8. Automatic collection technologies and behavioral information
Kan does not directly install browser cookies. Authentication, security, font, and advertising services may automatically process app-instance identifiers, IP addresses, user agents, app, device, and locale information, advertising identifiers, approximate locations, and ad impressions and clicks for authentication security, app integrity, font delivery, advertising, measurement, frequency capping, and fraud prevention.
You can review advertising choices under Settings > Ad Privacy Settings and in the operating system’s privacy and advertising settings. In regions where consent is required, no ad request is made until the consent state permits it.
9. Rights of users and legal representatives
You may request access, correction, deletion, suspension of processing, and withdrawal of consent. In the app, you can delete the account and data after identity verification under Settings > Account > Delete Account. If you cannot use the app, follow the Kan Account Deletion Guide and contact support@aspado.app.
For an email request, the operator manually sends a one-time code to the Firebase-registered email address. You must reply from that email account with the code within 24 hours. An unverified request never changes the account or its data. After verification, Aspado’s recently reauthenticated sole owner runs the same automated deletion lifecycle as the in-app process. A supported request is completed and answered within 30 days after verification.
Account deletion and App Store or Google Play subscription cancellation are separate. If you have a subscription, cancel it separately in the applicable store. Disconnecting your sign-in provider is a separate step from account deletion, so remove Kan’s access in the provider’s account settings if necessary.
10. Children under 14
Kan does not offer account services to children under 14. If the Company learns that it processed such information without valid consent from a legal representative, it will delete the information without undue delay after verifying the child or representative.
11. Security measures
The Company applies least-privilege access and periodic review, encryption in transit and at rest, authentication-token validation, app-integrity verification, protection of access records, and physical-access restrictions.
12. Privacy officer and responsible function
- Privacy officer title: Privacy Officer
- Responsible function: Aspado Privacy
- Email: support@aspado.app
13. Remedies
- Privacy Infringement Report Center: 118, privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: +82-1833-6972, kopico.go.kr
- Supreme Prosecutors’ Office: +82-1301, spo.go.kr
- Korean National Police Agency: +82-182, ecrm.police.go.kr
14. Changes to this policy
This policy takes effect on September 15, 2026. Material changes will be announced in the app or on the website before they take effect, and changed policies will be retained and published by version.
Announcement date: September 15, 2026
Effective date: September 15, 2026