alull-legal

alull 프로덕트의 개인정보처리방침 및 법적 고지

개인정보처리방침 — 순칼로리

운영자는 순칼로리(이하 “본 앱”) 이용자의 개인정보를 중요하게 생각하며, 「개인정보 보호법」 등 관련 법령 및 Google Play 데이터 보안 요건을 준수합니다.

요약: 본 앱은 회원가입·로그인이 없습니다. 이름·이메일·전화번호를 받지 않습니다. 식단·운동 기록과 프로필은 기기 안에 저장됩니다. 데이터가 기기 밖으로 나가는 경로는 「친구 피드」 하나뿐이며, 선택 기능입니다. 건강 앱(건강 / Health Connect) 연동은 기본 꺼짐이고 읽기 전용입니다. 광고·분석 도구·인앱 결제가 없습니다.


1. 처리하는 개인정보 항목

1-1. 기기에만 저장되고 밖으로 나가지 않는 것

항목 저장 위치
음식 기록(음식명·그램·kcal·끼니·날짜) 기기 SQLite
운동 기록(운동명·분·kcal·날짜) 기기 SQLite
즐겨찾기(음식·운동) 기기 SQLite
최근 기록 별도로 저장하지 않고 위 음식 기록에서 뽑아 보여줍니다
프로필(성별·나이·키·체중·활동량·목표 순칼로리·목표체중·목표 유형·목표 방식·목표 기간·건강앱 연동 여부·온보딩 완료 여부) 기기 저장소
홈 위젯 표시값(남은 예산·순칼로리·목표) 기기 위젯 저장소

⚠️ 앱을 삭제하면 기기에서 사라지지만, 그것만으로 모든 사본이 지워진다고 보장할 수 없습니다. 안드로이드는 앱이 백업을 끄지 않으면 Google 자동 백업을 적용합니다. 본 앱은 2026-08-27 현재 백업 제외 설정을 두고 있지 않으므로, 이용자 기기에서 백업이 켜져 있으면 위 기기 저장 데이터가 이용자 본인의 Google 계정으로 복사되어 기기 이전 시 복원될 수 있습니다. 이 백업은 Google 과 이용자 사이의 것이며 운영자는 접근할 수 없습니다.

1-2. 건강 관련 정보 (선택 · 기본 꺼짐)

이용자가 설정에서 켜고 기기의 건강 앱(iOS 건강 / Android Health Connect) 권한을 허용한 경우에만 읽기 전용으로 접근합니다. 앱이 건강 앱에 무언가를 쓰는 코드는 없습니다.

건강 권한 무엇에 쓰나 기기에 저장하나 서버로 나가나
활동 소모 칼로리(READ_ACTIVE_CALORIES_BURNED) 그날의 ‘소모’ 합계에 더함 저장 안 함 (화면을 열 때 그날치를 읽음) 부분적으로 — 아래 ⚠️
걸음수(READ_STEPS) 홈 화면 배너 표시 저장 안 함 아니오

⚠️ 활동 소모 칼로리는 분리되지 않습니다. 친구 피드에 하루 요약을 공유하면 ‘소모’ 항목은 수동으로 입력한 운동 + 건강 앱에서 읽은 활동 소모가 합쳐진 하나의 숫자로 전송됩니다. 둘을 나누어 보내지 않으며, 받는 쪽도 나눌 수 없습니다.

체중은 건강 앱에서 읽지 않습니다 — 프로필 화면에서 직접 입력합니다. (2026-09-16: 그전까지 요청만 하고 읽지 않던 체중 권한을 앱에서 걷어냈습니다.)

2. 친구 피드를 쓸 때 서버로 전송되는 정보

친구 피드는 선택 기능입니다.

⚠️ “쓴다”의 시점은 화면을 여는 순간입니다. 친구 피드 화면을 처음 열면, 그룹을 만들거나 참여하지 않았더라도 앱이 서버로부터 익명 기기 식별자와 인증 토큰을 발급받습니다. 화면을 한 번도 열지 않으면 앱은 네트워크로 아무것도 보내지 않습니다.

항목 설명
익명 기기 식별자 서버가 발급한 무작위 값. 실명·이메일·전화번호와 연결되지 않습니다
기기 인증 토큰 서버가 발급하고 기기 안에만 보관합니다. 서버에는 그 토큰의 해시(SHA-256)만 저장됩니다. 다른 사람이 내 기록에 접근하지 못하게 하기 위한 것입니다
닉네임 이용자가 직접 입력한 값
친구그룹 이름 · 초대코드 · 그룹 개설자 식별자  
하루 요약 섭취(kcal) · 소모(kcal) · 순칼로리 · 목표 순칼로리 · 한줄메모(선택, 80자)
좋아요 누가 어느 글에 눌렀는지
신고 누가 어느 글을 왜 신고했는지(사유는 선택 입력)
시각 정보 글 작성 시각, 기기 최초 등록·최종 접속 시각, 그룹 참여·개설 시각, 신고 접수·처리 시각

나가지 않는 것

3. 앱 권한 및 사용 목적

아래는 설치 파일(APK)이 선언하는 전체 권한 목록입니다. 앱이 직접 선언한 것과 라이브러리가 자동으로 추가한 것을 구분해 표기했습니다.

앱이 직접 선언한 권한 (건강 권한은 모두 선택 · 기본 꺼짐 · 읽기 전용)

권한 사용 목적
android.permission.health.READ_ACTIVE_CALORIES_BURNED 활동 소모 칼로리 읽기
android.permission.health.READ_STEPS 걸음수 읽기
android.permission.INTERNET 친구 피드(§2) 를 켰을 때 하루 요약을 서버로 보내는 데만 씁니다. 친구 피드가 꺼져 있으면(기본값) 앱은 인터넷에 접속하지 않습니다

라이브러리가 자동으로 추가하는 권한 (앱이 직접 요청하지 않음)

권한 출처 · 사용 목적
WAKE_LOCK androidx.work. 홈 위젯 기능이 쓰는 안드로이드 표준 라이브러리(Jetpack Glance → WorkManager)가 함께 들여옵니다
ACCESS_NETWORK_STATE 같은 출처(androidx.work)
RECEIVE_BOOT_COMPLETED 같은 출처(androidx.work)
FOREGROUND_SERVICE 같은 출처(androidx.work)
com.alull.sunkal.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION androidx.core. 앱 내부 브로드캐스트를 앱 자신으로 제한하는 서명 수준 권한(외부에 노출되지 않으며 이용자 정보와 무관)

⚠️ 위 네 개(WAKE_LOCK·ACCESS_NETWORK_STATE·RECEIVE_BOOT_COMPLETED·FOREGROUND_SERVICE)를 쓰는 코드가 앱에 한 줄도 없습니다. 본 앱에는 알림·백그라운드 작업·부팅 시 자동 실행 기능이 없습니다. 라이브러리가 들여온 채 사용되지 않는 상태입니다.

요청하지 않는 권한: 위치(GPS)·연락처·카메라·마이크·사진/미디어·전화·문자·캘린더· 저장소·알림·광고 식별자. 인앱 결제 권한(BILLING)도 없습니다.

⚠️ 친구 피드는 인터넷 접근을 필요로 하며, 그 권한은 위 목록에 아직 없습니다. 기능을 실제로 여는 시점에 인터넷 권한이 추가되고, 이 표도 함께 갱신됩니다.

4. 제3자 제공 및 처리위탁

5. 보유 및 파기

6. 이용자의 권리

7. 신고 처리

친구 피드의 글은 신고할 수 있습니다. 신고하면 그 글은 신고한 사람의 피드에서 즉시 사라지고, 서로 다른 이용자 3명이 신고하면 모든 이용자의 피드에서 내려갑니다. 신고 내역(대상 글·신고자·사유·시각)은 서버에 저장됩니다.

🔶 ⚠️ 운영자의 신고 확인 창구는 2026-08-27 현재 열려 있지 않습니다. 자동 숨김은 위와 같이 작동하지만, 운영자가 신고 목록을 조회하는 기능은 아직 사용할 수 없는 상태입니다. 열리는 대로 이 문단을 갱신합니다.

8. 만 14세 미만 아동

본 앱은 만 14세 미만 아동을 특정 대상으로 하지 않습니다. 별도의 연령 확인 절차는 두고 있지 않으며, 아동의 개인정보를 별도로 수집하지 않습니다.

🔶 확인 필요: 체중·걸음수 등 건강 관련 정보의 민감정보 별도 동의 요건이 본 앱에 적용되는지는 법률 판단이 필요한 사항입니다. 현재 앱은 운영체제의 건강 앱 권한 프롬프트 외에 별도의 인앱 동의 절차를 두고 있지 않습니다. 확인 후 이 문단을 갱신합니다.

9. 안전성 확보 조치

10. 처리방침의 변경 · 권익침해 구제방법

변경 시 이 페이지 상단의 “최종 수정일”을 갱신합니다.


Privacy Policy — 순칼로리 (Sunkal, English)

Summary: No account and no sign-in; we do not collect your name, email, or phone number. Your meal and exercise records and your profile are stored on your device. The only path off the device is the optional Friend Feed. Health-app integration (Apple Health / Health Connect) is off by default and read-only. There are no ads, no analytics, and no in-app purchases.

1. Data We Process

1-1. Stored on your device only

Item Where
Food records (name, grams, kcal, meal, date) On-device SQLite
Exercise records (name, minutes, kcal, date) On-device SQLite
Favourites (food and exercise) On-device SQLite
Recent items Not stored separately; derived from your food records
Profile (sex, age, height, weight, activity level, net-calorie goal, target weight, goal type, goal mode, goal period, health-integration flag, onboarding flag) On-device storage
Home-widget values (remaining budget, net calories, goal) On-device widget storage

⚠️ Uninstalling removes the data from the device, but that alone does not guarantee every copy is gone. Android applies Google Auto Backup unless an app opts out, and as of 2026-08-27 this app does not set a backup exclusion. If backup is enabled on your device, the on-device data above may be copied to your own Google account and restored when you move to a new device. That backup is between you and Google; the operator cannot access it.

1-2. Health data (optional, off by default)

Accessed read-only, and only if you turn it on and grant the OS health permission. The app contains no code that writes anything to the health app.

Health permission Used for Stored on device? Sent to the server?
Active calories burned (READ_ACTIVE_CALORIES_BURNED) Added to the day’s “burned” total No (read when you open the screen) Partly — see ⚠️ below
Steps (READ_STEPS) Home-screen banner No No

⚠️ Active calories cannot be separated. When you share a daily summary to the Friend Feed, “burned” is a single number combining exercise you entered manually and active calories read from the health app. They are not sent separately and the receiving side cannot split them.

Weight is not read from the health app — you enter it on the profile screen. (2026-09-16: the weight permission, which had been requested but never read, was removed from the app.)

2. Data sent to the server when you use the Friend Feed

The Friend Feed is optional.

⚠️ “Using it” begins the moment you open the screen. On first opening the Friend Feed the app obtains an anonymous device identifier and an auth token from the server, even if you never create or join a group. If you never open that screen, the app sends nothing over the network.

Item Notes
Anonymous device identifier A random value issued by the server. Not linked to a real name, email, or phone number
Device auth token Issued by the server and kept only on the device; the server stores only its SHA-256 hash, so that nobody else can reach your records
Nickname Entered by you
Group name, invite code, group owner identifier  
Daily summary Intake (kcal), burned (kcal), net calories, net-calorie goal, optional one-line note (80 chars)
Likes Who liked which post
Reports Who reported which post and why (reason text optional)
Timestamps Post time, device first-registration and last-seen time, group join/creation time, report filing and resolution time

What does not leave the device

3. Permissions

Below is the complete list of permissions declared by the installed package (APK), split between those the app declares itself and those added automatically by libraries.

Declared by the app (health permissions are all optional, off by default, read-only)

Permission Purpose
android.permission.health.READ_ACTIVE_CALORIES_BURNED Read active calories burned
android.permission.health.READ_STEPS Read step count
android.permission.INTERNET Used only to send the daily summary to the server when the Friend Feed (§2) is on. With the Friend Feed off (the default) the app makes no network connections

Added automatically by libraries (not requested by the app itself)

Permission Source · Purpose
WAKE_LOCK androidx.work, pulled in by the standard Android libraries behind the home widget (Jetpack Glance → WorkManager)
ACCESS_NETWORK_STATE Same source (androidx.work)
RECEIVE_BOOT_COMPLETED Same source (androidx.work)
FOREGROUND_SERVICE Same source (androidx.work)
com.alull.sunkal.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION androidx.core. Signature-level permission restricting internal broadcasts to the app itself; not exposed externally and unrelated to user data

⚠️ The app contains no code at all that uses those four (WAKE_LOCK, ACCESS_NETWORK_STATE, RECEIVE_BOOT_COMPLETED, FOREGROUND_SERVICE). There is no notification, background-work, or run-at-boot feature. They are present but unused.

Never requested: location (GPS), contacts, camera, microphone, photos/media, phone, SMS, calendar, storage, notifications, advertising identifier. There is no in-app billing permission (BILLING) either.

⚠️ The Friend Feed requires internet access, and that permission is not yet in the list above. It will be added when the feature is actually enabled, and this table will be updated with it.

4. Third-party Sharing & Processors

5. Retention & Deletion

6. Your Rights

7. Reports

Posts in the Friend Feed can be reported. A reported post disappears immediately from the reporter’s own feed, and once 3 distinct users report it, it is hidden from everyone. Report records (post, reporter, reason, time) are stored on the server.

🔶 ⚠️ The operator’s review channel is not open as of 2026-08-27. Automatic hiding works as described, but the function for the operator to review the report list is not yet usable. This paragraph will be updated when it is.

8. Children

The app is not specifically directed to children under 14. There is no separate age verification step, and no personal data is collected from children specifically.

🔶 Needs confirmation: whether health-related information such as weight and step count triggers a separate consent requirement for sensitive data under Korean law is a legal question. The app currently provides no in-app consent step beyond the operating system’s own health-permission prompt. This paragraph will be updated once confirmed.

9. Security

10. Changes & Complaints (Korea)

We will update the “Last updated” date at the top of this page when this policy changes.