Last updated: 2026-07-27
Effective date: 2026-07-27
This document is the canonical Privacy Policy for Cadence (the "App"), a mobile app for iOS and Android that helps you build three daily habits — sleep, exercise, and reading — with a coach by your side. The App is operated by Kooku (the "Developer", contact: [email protected]).
The Korean (한국어) version follows the English text. The two versions are intended to convey the same meaning. If they conflict, the English version governs.
What changed (2026-07-22): Cadence added an optional account (sign in with Apple, Google, or Kakao) and an optional community where you can back up your records and share daily habit cards with other members. Using the App without signing in remains fully local — nothing is uploaded. If you do sign in, some data is sent to and stored on our server. This policy now describes both modes.
Cadence is a personal habit coach for three daily habits — sleep, exercise, and reading. There are two ways to use it:
We do not sell your data, and we do not share it for advertising.
When you are not signed in, the following never leave your device. They are stored locally (SQLite) and only the App reads them:
| What | Source |
|---|---|
| Sleep, heart rate, exercise, steps | Apple Health (iOS) / Health Connect (Android), with your explicit per-type permission |
| Habit inputs (bedtime, caffeine/screen-off times, exercise/reading minutes, book + progress) | You type or tap them in |
| Morning result, condition/energy rating, personal memos | You type or tap them in |
Only anonymous analytics and crash reports (§4) are sent in this mode.
If you choose to sign in, the following is sent to and stored on our server (Cloudflare — see §5). Signing in is entirely optional.
a) Account & authentication. You sign in through Apple, Google, or Kakao. Cadence receives and stores a provider subject identifier (an opaque ID that identifies you to that provider) and the provider name. Depending on the provider and what you agree to share, the provider may also transmit your email and/or display name:
Each provider is an independent controller of the data it processes; see §7 for links.
We also record which version of this Policy, the Terms of Service, and the EULA you accepted, and when (consent record), and your minimum-age confirmation for the community.
For each device you sign in on, we store basic device information: platform (iOS/Android), OS version, device model, app version, language, and when the device was last active. We use this to support multiple devices per account (backup/restore, notifications) and to troubleshoot device-specific issues — never for advertising.
b) Backup of your records. So you can restore on a new device, your local records are mirrored to your account as an opaque backup (full-row copies of sleep/exercise/reading/books/settings/morning results). The server stores this backup without reading its contents — your private memos and raw health samples are kept as opaque data and are not parsed, indexed, or shown to anyone.
c) Community (only if you join). Joining the community is a further, separate choice. When you join:
We send anonymous app-usage events and crash reports to PostHog (analytics) to understand whether the App works and to find bugs. This includes an anonymous device/install ID, app version, OS, platform, and event names (e.g. "app opened", "reading logged") — never the contents of your health data, memos, or community posts.
Signed-in data (§3) is stored on Cloudflare, Inc. infrastructure (Workers, D1 database, KV, and R2 object storage for avatars), which processes data on our behalf. Backups may be retained for a limited disaster-recovery window (database point-in-time recovery and nightly backup dumps). Cloudflare operates globally, so your data may be processed outside your country, including the United States. By signing in you consent to this transfer.
To deliver community reaction notifications, we use Firebase Cloud Messaging (Google) and the Apple Push Notification service. A device push token is generated and stored on our server (devices) with your device information (platform, OS version, device model, app version, and locale — see §3a). You can turn reaction notifications off, and you can revoke the notification permission in your device settings at any time.
We use no advertising SDKs and no attribution SDKs.
| Permission | Platform | Why |
|---|---|---|
| Health access (sleep, heart rate, exercise, steps) | iOS, Android | Read your sleep/activity to track habits and weekly goals (on-device) |
| Notifications | iOS, Android | Local reminders (bedtime/wake) and, if signed in, community reaction pushes |
| Camera | iOS, Android | Scan a book barcode (ISBN); optionally take a photo for your community avatar |
| Photo library | iOS, Android | Choose a photo for your community avatar (only when you pick one) |
Exact alarms, boot-completed, wake lock (SCHEDULE_EXACT_ALARM, USE_EXACT_ALARM, RECEIVE_BOOT_COMPLETED, WAKE_LOCK) | Android only | Deliver scheduled reminders at the exact time and survive reboots/battery-saver |
You can revoke any permission at any time via device settings (iOS: Settings → Cadence; Android: Settings → Apps → Cadence).
You may at any time: revoke any permission; sign out; delete your account in-app (30-day soft delete as above); uninstall to remove local data; or email [email protected] to request deletion of analytics data. If you reside in the EEA, UK, or California, you also have rights to access, correct, and port your data — email us and we will assist.
Cadence is not directed to children under 14, and the community requires you to be at least 14 (a neutral age check is shown before you can join). We do not knowingly collect data from children under 14. If you believe a child under 14 has created an account, contact us and we will delete it.
We may update this policy. The "Last updated" date will change and, for material changes, we will show an in-app notice and ask signed-in users to re-accept. Continued use after the effective date means you accept the update.
For any privacy question or request: [email protected]
Cadence는 수면·운동·독서 세 가지 습관을 곁의 코치와 함께 쌓도록 돕는 iOS·Android 앱입니다. 두 가지 사용 방식이 있습니다.
어떤 데이터도 판매하지 않으며, 광고 목적으로 공유하지 않습니다.
로그인하지 않으면 아래 항목은 기기를 떠나지 않습니다. 로컬(SQLite)에 저장되며 앱만 읽습니다.
| 항목 | 출처 |
|---|---|
| 수면·심박수·운동·걸음수 | Apple 건강(iOS) / Health Connect(Android), 종류별 명시 동의 시 |
| 습관 입력(취침 시각, 카페인·화면끄기 시각, 운동·독서 분, 책·진도) | 사용자 직접 입력 |
| 아침 결과·컨디션/활력 점수·개인 메모 | 사용자 직접 입력 |
이 모드에서는 익명 분석·크래시 리포트(§4)만 전송됩니다.
로그인을 선택하면 아래 항목이 서버(Cloudflare — §5)로 전송·저장됩니다. 로그인은 전적으로 선택입니다.
가) 계정·인증. Apple·Google·Kakao로 로그인합니다. Cadence는 해당 제공자가 회원을 식별하는 주체 식별자(불투명 ID)와 제공자 이름을 받아 저장합니다. 제공자와 동의 범위에 따라 이메일·표시 이름도 전달될 수 있습니다.
각 제공자는 자신이 처리하는 데이터의 독립 관리자입니다(링크는 §7).
또한 본 정책·이용약관·EULA의 어느 버전에 언제 동의했는지(동의 기록)와 커뮤니티 최소 연령 확인을 기록합니다.
로그인한 각 기기에 대해 기본 기기 정보를 저장합니다: 플랫폼(iOS/Android), OS 버전, 기기 모델, 앱 버전, 언어, 마지막 사용 시점. 계정당 여러 기기 지원(백업/복원·알림)과 기기별 문제 해결에 사용하며 — 광고에는 사용하지 않습니다.
b) 기록 백업. 새 기기에서 복원할 수 있도록, 로컬 기록이 계정에 불투명 백업(수면·운동·독서·책·설정·아침 결과의 전체 행 사본)으로 미러링됩니다. 서버는 이 백업의 내용을 읽지 않습니다 — 개인 메모·건강 원본 샘플은 불투명 데이터로 보관되며 파싱·색인·타인 노출되지 않습니다.
c) 커뮤니티(참여 시에만). 커뮤니티 참여는 별도의 추가 선택입니다. 참여하면:
앱 동작 검증·버그 발견을 위해 익명 사용 이벤트·크래시 리포트를 PostHog로 전송합니다. 익명 디바이스/설치 ID, 앱 버전, OS, 플랫폼, 이벤트 이름(예: "앱 진입", "독서 기록")이 포함되며, 건강 데이터·메모·커뮤니티 게시물의 본문은 절대 포함되지 않습니다.
로그인 데이터(§3)는 Cloudflare, Inc. 인프라(Workers, D1 데이터베이스, KV, 아바타용 R2 오브젝트 스토리지)에 저장되며, Cloudflare가 당사를 대신해 처리합니다. 백업은 제한된 재해복구 기간 동안 보관될 수 있습니다(DB 시점 복구, 야간 백업 덤프). Cloudflare는 전 세계에서 운영되므로 데이터가 대한민국 밖(미국 포함)에서 처리될 수 있습니다. 로그인함으로써 이 이전에 동의하게 됩니다.
커뮤니티 반응 알림 전송을 위해 Firebase Cloud Messaging(Google)과 Apple 푸시 알림 서비스(APNs)를 사용합니다. 기기 푸시 토큰이 생성돼 기기 정보(플랫폼·OS 버전·기기 모델·앱 버전·로케일 — §3가)와 함께 서버(devices)에 저장됩니다. 반응 알림은 끌 수 있으며, 기기 설정에서 알림 권한을 언제든 철회할 수 있습니다.
광고 SDK·트래킹 SDK는 사용하지 않습니다.
| 권한 | 플랫폼 | 사유 |
|---|---|---|
| 건강 접근(수면·심박수·운동·걸음수) | iOS, Android | 습관·주간 목표 표시를 위해 수면·활동 읽기(기기 내) |
| 알림 | iOS, Android | 로컬 리마인더(취침/기상) 및 로그인 시 커뮤니티 반응 푸시 |
| 카메라 | iOS, Android | 책 바코드(ISBN) 스캔; 선택 시 커뮤니티 아바타 사진 촬영 |
| 사진 앨범 | iOS, Android | 커뮤니티 아바타 사진 선택(사용자가 고를 때만) |
| 정확 알람·부팅 완료·웨이크락 | Android 전용 | 예약 리마인더의 정확한 시각 도착 및 재부팅/절전 생존 |
기기 설정에서 모든 권한을 언제든 철회할 수 있습니다(iOS: 설정 → Cadence / Android: 설정 → 앱 → Cadence).
언제든: 권한 철회, 로그아웃, 앱 내 계정 삭제(위 30일 소프트 삭제), 앱 삭제로 로컬 데이터 제거, 또는 이메일로 분석 데이터 삭제 요청이 가능합니다. EEA·영국·캘리포니아 거주자는 접근·정정·이동 권리도 가지며, 이메일 주시면 돕겠습니다.
Cadence는 만 14세 미만 아동을 대상으로 하지 않으며, 커뮤니티는 만 14세 이상만 이용할 수 있습니다(참여 전 중립 연령 확인 표시). 만 14세 미만 아동의 데이터를 알면서 수집하지 않습니다. 만 14세 미만 아동이 계정을 만들었다고 판단되면 연락 주시면 삭제하겠습니다.
본 정책을 갱신할 수 있습니다. "최종 갱신" 날짜가 바뀌며, 중대한 변경 시 앱 내 안내를 표시하고 로그인 사용자에게 재동의를 요청합니다. 효력일 이후 계속 사용하면 갱신에 동의하는 것으로 간주됩니다.
개인정보 관련 문의·요청: [email protected]