Effective Date: September 15, 2026

Privacy Policy

Aspado (the “Company”) provides Kan, a goal-management app. This policy explains how the Company processes and protects personal information under Article 30 of Korea’s Personal Information Protection Act (“PIPA”).

PurposeLegal basis
Account creation, sign-in, identity verification, and account securityPIPA Article 15(1)(4), performance of a contract
Local goal-grid storage, premium cloud synchronization, and recoveryPIPA Article 15(1)(4), performance of a contract
On-device storage of todos and completion records, and local notificationsPIPA Article 15(1)(4), performance of a contract
Operation of the suggestions board, comments, voting, and author displayPIPA Article 15(1)(4), performance of a contract
Subscription and access-entitlement verification and paid featuresPIPA Article 15(1)(4), performance of a contract
Statutory retention of payment and supply records and response to access requestsArticle 6 of Korea’s Electronic Commerce Consumer Protection Act and Article 6 of its Enforcement Decree
Customer inquiries and account-deletion requestsPIPA Article 15(1)(4), performance of a contract and response to user requests
Service security, fraud prevention, and error diagnosisPIPA Article 15(1)(6), the Company’s legitimate interests
Personalized advertising and ad measurementPIPA Article 15(1)(1), consent

The Company does not use personal information for purposes other than those above. If a purpose changes, the Company will obtain any required consent or take other measures required by law.

2. Personal information processed

CategoryInformationCollection method
Account and authenticationFirebase UID, sign-in-provider identifier, email address, display name, profile image, and providerReceived when you sign in with Google or Apple
Goal gridsCore goal, sub-goals, action items, status, color, target date, creation and update times, and internal identifiersEntered by you in the app
Todos and completion recordsTitle, body, tags, date, recurrence rule, linked action item, completion date, and creation and update timesCreated on the device when you enter or complete a todo
Suggestions boardSuggestion titles and bodies, comments, voting activity, display name, and creation and update timesCollected when a signed-in user submits a suggestion or comment or votes
Subscription and entitlementApp and product identifiers, entitlement status and period, and grant reason. If store purchasing is offered and you make a purchase: store, order, transaction and original-transaction identifiers, transaction type and status, and purchase, expiration, and revocation timesCollected after sign-in when checking access or when verifying an App Store or Google Play purchase
Device and serviceOperating system, app version, language and locale, platform, app-instance identifier, IP address, user agent, request path, status and duration, and security and error recordsGenerated automatically while using the app, server, Firebase, and Google Fonts
Advertising and consentAdvertising identifier, approximate location, app and device information, ad impressions and interactions, and consent choicesCollected automatically during consent and ad requests for free users
Customer supportContact email, inquiry, account-deletion request, one-time verification code, deletion-request ID, email HMAC lookup value, identity-verification information, and processing recordCollected or generated through email or an in-app request

Goal grids, todos, completion records, and app settings used without signing in remain on your device. Premium users’ goal grids are synchronized automatically after sign-in and while using the app through Cloud Firestore. Todos and completion records remain on the device only, regardless of sign-in status, and are not sent to Cloud Firestore.

Suggestion titles and bodies, comments, display names, and creation times are visible to other users. Voting activity is associated with your account, but other users see only the aggregate vote count. Do not post sensitive information or another person’s personal information on the suggestions board.

The Company does not collect government identification numbers, passport numbers, driver’s-license numbers, health information, biometric information, or other sensitive information for providing Kan.

3. Retention periods

InformationRetention period
Account and authentication information and synchronized goal gridsUntil account deletion
Goal grids, todos, and completion records stored on the deviceUntil you delete them or uninstall the app; account-scoped data is deleted during in-app account deletion
Suggestions, comments, votes, and author informationUntil account deletion or deletion of the relevant board data; if other users participated in a suggestion, only a de-identified record with the author and original content removed is retained
Active subscription and entitlement informationUntil account deletion or entitlement expiration, whichever occurs first
If a purchase occurs, minimum records of contracts, withdrawal, payment, and supplyFive years from the transaction date; legacy records without a purchase time are retained for five years from record creation
On-device app error recordsRecords older than seven days are deleted the next time the app starts, and all are deleted during account deletion
Customer inquiries, verification, and supported-deletion processing recordsOne year after the inquiry is completed
Deletion-request ID and irreversibly transformed account identifierUntil the Kan service is discontinued, to prevent recreation of a deleted account and misuse of previous authentication information

If a purchase occurs, the Company retains the minimum transaction evidence required by Korea’s Electronic Commerce Consumer Protection Act for five years. After account deletion, the Company stores the app, store, and product identifiers; order, transaction, and original-transaction identifiers; transaction type and status; purchase, expiration, and revocation times; retention deadline; an app-scoped, versioned HMAC lookup value generated from the email instead of the plain-text email; and an opaque deletion-request ID as pseudonymous information separate from other personal information. Customer IDs, Firebase UIDs, direct identifiers such as plain-text email, purchase tokens and raw receipts are excluded from this statutory record.

If Firebase Authentication deletion temporarily fails after remote data was removed during a supported account deletion, the Company temporarily stores the Firebase UID and former customer number in the deletion record for a safe retry. Both values are deleted immediately when identity deletion and completion recording finish and are not included in the one-year support record or five-year statutory transaction record.

4. Destruction procedures and methods

Personal information is destroyed without undue delay when its retention period expires or its processing purpose is fulfilled. Electronic files and database records are permanently deleted so they cannot be restored or reproduced. The Company does not keep Kan users’ personal information on paper.

When account deletion completes, the Company deletes synchronized goal grids from Cloud Firestore; customer identifiers and user-generated data, including the user’s comments and votes, from Basecamp; and the Firebase Authentication account. If other users’ comments or votes are attached to a suggestion, the Company may retain a de-identified post after removing its author, title, body, and translations to protect those other users’ records. In-app account deletion also removes the account’s local data from the device.

Statutory transaction records are separated from ordinary customer data and automatically destroyed when each five-year period ends. Authentication information remaining in Firebase Authentication live or backup systems may take up to 180 days to be removed after the Company requests deletion. Deleted information in disaster-recovery backups is not used for the ordinary service and is destroyed when the backup retention period ends.

5. Third-party disclosures

The Company does not disclose personal information for a third party’s independent purposes. If disclosure is based on separate consent or law, the Company will provide prior notice of the recipient, purpose, information, and retention period.

6. Processing contractors

ContractorProcessing work
Google LLCFirebase Authentication, Cloud Firestore synchronization, Firebase App Check integrity verification, Google sign-in, Google Fonts delivery, AdMob advertising, and UMP consent management
Apple Inc.Apple sign-in and, if store purchasing is offered, App Store payment, subscription, and purchase-entitlement verification

Kan content synchronized through Cloud Firestore is stored in the Seoul, South Korea region (asia-northeast3). This policy will be updated if a contractor or its work changes.

7. International transfers

RecipientCountryInformationTiming and methodPurposeRetention period
Google LLC (contact)United States and countries where Google services operateSign-in identifier, email, display name, profile image, IP address, user agent, and app, device, and locale informationEncrypted transfer when using Google sign-in, Firebase, or Google FontsAuthentication, security, cloud synchronization, app-integrity verification, and font deliveryFirebase Authentication information is removed from live and backup systems within up to 180 days after an account-deletion request. App Check tokens last up to seven days and replay-protection tokens up to 30 days. Other information follows Google’s service-specific policies
Google LLC (contact)United States and other countries where Google services operateAdvertising identifier, approximate location, app and device information, IP address, user agent, ad impressions and interactions, and consent informationEncrypted transfer during consent checks and ad requestsAdvertising, measurement, frequency capping, fraud prevention, and consent managementPortions of IP addresses in ad logs are anonymized after nine months and identifier information after 18 months. AdMob reports are retained for 90 or 2,555 days depending on report type
Apple Inc. (contact)United States and countries where Apple services operateApple sign-in identifier, email or relay email, authentication token and code, and, if a purchase occurs, purchase and subscription identifiersEncrypted transfer during Apple sign-in or App Store purchase verificationSign-in, disconnection, and, if a purchase occurs, payment, subscription, and entitlement verificationFor the duration of the Apple account or app connection and any period required by law

International transfers necessary to perform a contract rely on PIPA Article 28-8(1)(3), and personalized-advertising transfers rely on consent under paragraph (1)(1). If you refuse these transfers, you cannot use Google or Apple sign-in or premium cloud synchronization. You can still use on-device features such as goal grids and todos without signing in. You may refuse advertising transfers in the consent form or review your choice under Settings > Ad Privacy Settings; refusing does not prevent use of non-advertising app features. To stop authentication-related transfers after creating an account, delete it under Settings > Account > Delete Account.

8. Automatic collection technologies and behavioral information

Kan does not directly install browser cookies. Authentication, security, font, and advertising services may automatically process app-instance identifiers, IP addresses, user agents, app, device, and locale information, advertising identifiers, approximate locations, and ad impressions and clicks for authentication security, app integrity, font delivery, advertising, measurement, frequency capping, and fraud prevention.

You can review advertising choices under Settings > Ad Privacy Settings and in the operating system’s privacy and advertising settings. In regions where consent is required, no ad request is made until the consent state permits it.

You may request access, correction, deletion, suspension of processing, and withdrawal of consent. In the app, you can delete the account and data after identity verification under Settings > Account > Delete Account. If you cannot use the app, follow the Kan Account Deletion Guide and contact support@aspado.app.

For an email request, the operator manually sends a one-time code to the Firebase-registered email address. You must reply from that email account with the code within 24 hours. An unverified request never changes the account or its data. After verification, Aspado’s recently reauthenticated sole owner runs the same automated deletion lifecycle as the in-app process. A supported request is completed and answered within 30 days after verification.

Account deletion and App Store or Google Play subscription cancellation are separate. If you have a subscription, cancel it separately in the applicable store. Disconnecting your sign-in provider is a separate step from account deletion, so remove Kan’s access in the provider’s account settings if necessary.

10. Children under 14

Kan does not offer account services to children under 14. If the Company learns that it processed such information without valid consent from a legal representative, it will delete the information without undue delay after verifying the child or representative.

11. Security measures

The Company applies least-privilege access and periodic review, encryption in transit and at rest, authentication-token validation, app-integrity verification, protection of access records, and physical-access restrictions.

12. Privacy officer and responsible function

  • Privacy officer title: Privacy Officer
  • Responsible function: Aspado Privacy
  • Email: support@aspado.app

13. Remedies

14. Changes to this policy

This policy takes effect on September 15, 2026. Material changes will be announced in the app or on the website before they take effect, and changed policies will be retained and published by version.

Announcement date: September 15, 2026

Effective date: September 15, 2026