Privacy policy
1. Operator and your rights
HalleluYang is operated by Sungkuk Kim. Contact 1doman.official@gmail.com for access, correction, deletion, restriction, consent withdrawal or support. We verify only the information needed to identify the requester. Never send passwords, verification codes or card numbers. Policy changes and their effective date will appear here.
2. Information on your device
Prayer history, goals, shielding settings, opaque Screen Time app-selection tokens and guest carrots and items stay on your device. We do not read messages or posts in selected apps or send app-selection tokens to our server, analytics or advertisers. Local information can remain until you erase it or delete the app; operating-system device backups may retain a separate copy. You can pray without signing in.
3. Accounts and optional prayer backup
We use Apple or Kakao identifiers and any provided email for authentication and store account carrots, rewards, purchases, equipped items and referrals. Reward verification uses information such as completion time and duration to provide the service and prevent duplicate rewards. Separately consented prayer backup includes timestamps, prayer identifiers, duration, starting path and goals. These activities can reveal religious interests. There is no feature collecting freely written personal prayers. Turning prayer backup off deletes backed-up prayer history from the active server; necessary reward and purchase ledgers are separate.
4. Purchases, ads and optional analytics
Apple processes payment. We verify signed transactions, products, prices, currencies and refunds, not card numbers. RevenueCat receives a random member identifier and purchase/refund information, not prayer records or email. Rewarded ads are optional and request non-personalized AdMob ads; Google may process approximate location derived from IP addresses, app- or developer-scoped device identifiers, ad views/interactions, crashes, performance and other diagnostics for advertising and analytics. Use ad privacy choices in Settings where available. App improvement is off by default. If enabled, GA4 receives screen use, onboarding, ad reward and purchase stages, device/app details and a random app-instance identifier. We exclude prayers, history, prayer IDs, blocked apps, email, member IDs, raw receipts and referral codes. Turning it off stops future collection and resets the local analytics identifier, but does not immediately erase previously sent data.
5. Providers and international processing
Information is sent over encrypted connections when the relevant feature is used. Supabase Pte. Ltd. (privacy@supabase.com) provides authentication and account, prayer-backup, reward and purchase storage. The business database is in Tokyo, Japan; operational, security and support services may use other countries through Supabase and its subprocessors. RevenueCat, Inc. (compliance@revenuecat.com) processes random member IDs and transactions on US AWS infrastructure for purchase and refund reporting. Google Firebase/Analytics and AdMob process the analytics/ad information above in global facilities, including the United States. Provider links below explain infrastructure, subprocessors and contact options. Apple and Kakao also apply their own authentication/payment policies. You may use guest prayer, disable prayer backup or analytics, or decline ads. Without account processing, account backup, account items and purchases will be unavailable.
6. Retention by type
Authentication and account reward, purchase and item records are kept until account deletion. Prayer history is deleted on backup consent withdrawal or account deletion. RevenueCat customer deletion is requested on account deletion and failures are retried. GA4 event retention is set to 2 months and user retention to 14 months from last activity, renewed by new activity. Expired records follow Google's periodic deletion process; separate aggregate reports are not subject to these limits. Ad data and records independently held by Apple and Kakao follow their policies. Support email is deleted within one year after resolution; an ongoing dispute or legal retention requirement may require restricted retention for that purpose and period.
7. Account deletion and residual records
In Settings → Account and backup → Delete account, verify your identity and confirm permanent deletion. Active-server account links, prayer history, carrots, items and personal purchase history are deleted, and RevenueCat customer deletion is requested. This does not delete your Apple/Kakao account or Apple's transaction records. Referral rewards already issued to other people may remain without a link to you. Limited transaction-verification hashes and processing outcomes may remain for the service's operating lifetime to prevent replayed rewards or purchases after re-registration. They do not restore a departed member's name, email or prayers. Guest information requires separate local deletion.
8. Encrypted backups and restoration
Business recovery backups are encrypted on an operator-managed device and exclude authentication passwords and login sessions. Archives older than 30 days are removed by the daily 04:00 Korea-time job. If the device is offline or a job fails, expiration runs first at the next execution, so deletion can be delayed. Older backups are not edited individually after account/history deletion and expire on this cycle. Isolated restoration compares current membership, consent and history to exclude deleted accounts and prayers. Operational recovery requires deletion reconciliation; unverified backups are never restored into production.
9. Safeguards and provider policies
We use encrypted transport, account-level access controls, a restricted backup account, encrypted archives, purchase-signature verification and access management. Provider policies and international processing information are linked below.
Supabase · Supabase subprocessors · Firebase · GA4 retention · Google · RevenueCat · Apple · Kakao