개인정보 처리방침
Culprit의 데이터 처리, 보관, 삭제, 제3자 서비스 정보를 확인하세요.
데이터 사용
앱 기능 제공, 동기화, 지원 응답, 안정성 개선에 필요한 정보만 다룹니다.
삭제와 보관
계정 또는 데이터 삭제는 앱 안의 삭제 기능이나 지원 이메일을 통해 요청할 수 있습니다.
추적 제한
광고 목적의 제3자 추적이나 개인정보 판매를 전제로 설계하지 않았습니다.
This Privacy Policy explains how Culprit collects, uses, and shares information when you use the app. By using the app, you consent to the practices described here.
1. Information We Collect
1.1 You provide
- Account data: on iOS, an Apple ID identifier via Sign in with Apple and the email Apple provides; on Android, a Google account identifier and email via Sign in with Google, or the email address and password you register directly
- Onboarding responses: primary symptoms selected, food groups you chose to test, Lite/Standard mode preference
- Meal logs: food names, meal type, time, optional ingredients, optional notes
- Symptom check-ins: 0–5 severity ratings (bloating, cramping, diarrhea, constipation, fatigue, brain fog, skin reaction, headache), and the meal you link the check-in to (if any)
- Reintroduction outcomes: which foods you tested, start/end timestamps, and whether you reported no / mild / strong reaction
1.2 Automatically collected
- Anonymized app version, OS version, device model, coarse locale
- Subscription state via RevenueCat (a pseudonymous app user ID, entitlement status, product ID; on iOS a hashed Apple ID, on Android a Google Play purchase token)
- Crash reports (only if you opt in via your device settings)
1.3 Not collected
- Precise location, contacts, advertising identifiers (IDFA), microphone, audio, camera
- HealthKit data (iOS) or Health Connect data (Android)
- Cross-app tracking identifiers of any kind
2. How We Use Information
- Provide the core program (elimination phase tracking, reintroduction scheduling, washout enforcement)
- Calculate your baseline symptom statistics at the end of the elimination phase
- Generate qualitative pattern summaries from your reintroduction test results
- Process subscription purchases and manage entitlements
- Schedule on-device local notifications (test-day and washout-end reminders — not sent to our servers)
- Improve app quality via anonymized aggregate metrics
- Comply with legal obligations
3. AI and Automated Analysis
When you open your pattern report, a Supabase Edge Function sends pseudonymised data to Anthropic's Claude API to draft a one-to-two-sentence plain-language summary of how each tested food group related to your logged symptoms. The prompt contains only: food group names, reintroduction outcome status (confirmed trigger / confirmed safe / inconclusive), reaction-timing window (immediate / delayed / late), and a numeric delta score relative to your baseline. No personally identifying information — no account ID, no email, no display name, no raw symptom rows — is shared with Anthropic. Anthropic's privacy terms apply to this processing. The resulting summary is cached in our database so the same report is not re-generated on repeat views. We call this pseudonymised rather than anonymous because the underlying logs stay linked to your account in our systems and the summary is written back to it. Anthropic deletes request inputs and outputs within 30 days under its standard commercial API terms; we do not hold a zero-data-retention agreement.
The pattern report is shown in the app using qualitative labels only ("Frequently observed before symptoms", "Sometimes observed before symptoms", "Worth watching", "No clear pattern"). Numeric confidence scores and percentages are never shown to you and are not intended as clinical measurements.
4. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Backend, auth, database, Edge Functions | Account and logs (scoped by row-level security) |
| RevenueCat | Subscription management | Pseudonymous app user ID, subscription status, product ID |
| Anthropic (Claude) | Qualitative pattern summary for the report | Food group names, outcome status, timing window, delta score (no identifiers) |
| Apple (iOS only) | Sign in with Apple, in-app purchases | Apple ID identifier, purchase receipt |
| Google (Android only) | Sign in with Google, Google Play billing | Google account identifier and email, purchase token |
We do not sell your data. We do not participate in any ad network.
5. Data Storage and Security
- Data is stored on Supabase with TLS in transit and encryption at rest
- Row-level security ensures each user can only read and write their own records
- AI calls are made server-side via a Supabase Edge Function; your app never holds third-party API keys
- API keys are kept out of version control
6. Data Retention
We retain data while your account is active. You can delete your account at any time from Settings → Delete Account. Upon deletion, associated personal data is deleted or anonymized within 30 days, except records required for legal, tax, or fraud-prevention purposes.
7. Your Rights
Depending on your jurisdiction (GDPR, CCPA, PIPA, etc.) you may have the right to access, correct, delete, export, object to, restrict processing, or withdraw consent. To exercise any of these rights, email ootssu@ootssu.com. We respond within 30 days.
8. Children's Privacy
The app is not directed to children under 16. We do not knowingly collect personal data from children.
9. International Transfers
Your data may be stored or processed in countries other than your own (e.g., United States for Supabase, RevenueCat, Anthropic). By using the app, you consent to such transfers subject to appropriate safeguards.
10. Cookies and Tracking
The app does not use cookies or advertising trackers. We do not participate in ad networks or cross-app tracking. App Tracking Transparency prompts are not shown because no such tracking occurs.
11. Changes
Material changes will be announced via in-app notice or email at least 7 days before taking effect.
12. Contact
Email: ootssu@ootssu.com. We are the data controller responsible for personal information processed through the app.
지원이 필요하신가요?
앱, 계정, 결제, 데이터 삭제 문의는 이메일로 보내주세요.