Privacy Policy
Effective Date: May 11, 2026 (v5.2)
Elpis Studio ("Company") values the privacy of D.off app ("Service") users and establishes this Privacy Policy in accordance with applicable laws.
1. Information We Collect
We collect the following information to provide our service:
- Required: Email address, password (encrypted)
- Social login: Nickname, profile photo (optional)
- App usage data: App usage time, group settings (stored locally)
- Automatic: Device info, OS version, app version
- Device integrity signals: Anonymized device hash derived from Google Play Integrity API (Android) or Apple DeviceCheck (iOS), used solely to prevent abuse of the self-control mechanism
- Diagnostics & analytics: Firebase Analytics (Google Analytics for Firebase / GA4), Crashlytics crash reports, and Performance Monitoring collect aggregated, non-advertising usage events, crash logs, and performance metrics to keep the app stable and improve features. Not used for cross-app tracking or advertising.
2. How We Use Information
- Account registration and management
- Service delivery (screen time management, statistics)
- Customer support
- Service improvement
- Security & fraud prevention — enforcing the 7-day re-registration cooldown described in Section 8
3. Data Retention and Deletion
Data is deleted immediately upon account deletion, except where retention is required by law. Device integrity records (Section 8) are retained for the duration of the 7-day cooldown plus 90 days, after which they are anonymized; this minimal retention is necessary to enforce the self-control commitment that users opt into.
4. Third-Party Sharing
We do not share personal information with third parties except as required by law. We rely on the following infrastructure providers, who process data only as our processors:
- Google Firebase (authentication, Firestore, Cloud Functions)
- Google Firebase Analytics (GA4), Crashlytics, and Performance Monitoring — aggregated usage analytics, crash diagnostics, and performance metrics (Google's own privacy policy applies)
- Google Play Integrity API — Android device attestation tokens (Google's own privacy policy applies)
- Apple DeviceCheck — iOS device attestation tokens (Apple's own privacy policy applies)
- RevenueCat — subscription billing receipts
5. App Usage Data
D.off uses the UsageStats permission (Android) or Family Controls / DeviceActivity entitlement (iOS) to query app usage time. iOS users: see Section 12 (Family Controls) for the equivalent — iOS handles app monitoring internally without exposing raw usage to D.off. This data is:
- Processed only on your device (no server transmission)
- Used solely for quota management
- Automatically deleted when the app is uninstalled
6. Your Rights
You can request access, correction, or deletion of your data at any time through account settings. Deleting your account also removes the device hash association, though the hash itself remains in the deviceBlocklist record described in Section 8 for the duration of any active cooldown.
7. Contact
Privacy inquiries: chrislee.krh@gmail.com
8. Service Providers (Subprocessors)
D.off uses the following third-party service providers for core infrastructure:
- Google Firebase (Authentication, Firestore, Cloud Functions, Storage) — Google LLC, United States.
- Google Firebase Analytics (GA4) / Crashlytics / Performance Monitoring (aggregated usage analytics, crash diagnostics, performance metrics) — Google LLC, United States.
- RevenueCat (subscription receipt validation) — RevenueCat, Inc., United States.
- Apple App Store / Google Play (in-app purchase processing) — Apple Inc. / Google LLC.
- Anthropic Claude API (optional AI-generated reflections, B2G feature only) — Anthropic, PBC, United States.
9. International Data Transfer
All subprocessors above are located in the United States. By using the Service, you consent to international data transfer to the United States under Articles 17(3) and 28-8 of the Korean Personal Information Protection Act and applicable EU/UK SCCs where relevant.
- Categories transferred: same as §1 collected items.
- Recipients' purpose and retention: same as §3 retention policy and §8 entrusted services.
- Right to refuse: You may refuse the transfer by deleting your account, in which case Service use may be limited.
- B2G (organization) data sharing: Organization administrators see only member nicknames, join dates, monthly average usage time, and quota compliance rate (aggregated). Individual app package names, time-of-day usage patterns, and transcription content are NOT shared with the organization.
10. Device Attestation & Re-registration Cooldown
D.off is a self-control tool. To prevent users from circumventing their own self-imposed limits by deleting and recreating their account, we use device attestation:
- What we collect: A SHA-256 hash derived from a Google Play Integrity (Android) or Apple DeviceCheck (iOS) attestation token. This hash does not contain advertising identifiers, IMEI, MAC address, or other persistent device identifiers we control.
- When we collect: Only at sign-up and when you first save a blocking group, never during normal app use.
- Purpose: If the same device hash already has a record of active blocking sessions and you sign up under a new account, a 7-day cooldown is applied during which all blocking remains active.
- Opt out: You may decline by not signing up; the cooldown is part of the core self-control mechanism and cannot be disabled while using the Service. Uninstalling removes all locally stored data immediately.
- What it is not: This hash is never used for advertising, cross-app tracking, profile building, or third-party sharing. The Google/Apple attestation APIs themselves are subject to their own privacy policies.
The legal basis for this processing is performance of the self-control commitment that you have voluntarily entered into by using the Service (Article 6(1)(b) GDPR; KISA personal information processing for service delivery).
11. Sign in with Apple
On iOS, D.off supports Sign in with Apple as one of multiple sign-in methods (Apple App Store Guideline 4.8). When you use this method:
- Data collected: Apple ID identifier (Firebase UID), email address (real or Apple-relay), and — only on first sign-in — your full name if you choose to share it. Re-login does not transmit your name again (Apple SDK policy).
- Hide My Email: If you select "Hide My Email," Apple issues a private relay address (
*@privaterelay.appleid.com) and forwards email to your real inbox. D.off stores only the relay address — your real email is never disclosed to D.off. All account flows (password recovery, account deletion, support contact) operate on the relay address.
- Display name preservation: Because Apple delivers your name only on first sign-in, D.off backs up your display name to device-local storage to restore it during subsequent logins on the same device. If you sign in on a new device, your display name will be empty until you re-enter it in Settings.
- Account deletion (Guideline 5.1.1(v)): When you delete your D.off account, the app calls Apple's
/auth/revoke endpoint to invalidate D.off's authorization on Apple's side. This is in addition to deleting your Firebase account and all Firestore user data. After deletion, no link between your Apple ID and D.off remains.
- No data sale or marketing: D.off does not send any external marketing emails to Sign in with Apple users. Email is used only for transactional purposes (verification, password recovery) initiated by you.
12. iOS Screen Time Data (Family Controls)
On iOS 16+ devices, D.off uses Apple's Family Controls framework to apply restrictions to apps that you yourself select.
- Data collected: Only opaque tokens representing user-selected apps. D.off cannot see app names, bundle IDs, or actual usage time — these are handled internally by iOS.
- Processing: All data is stored only in the device-local ManagedSettings store and is never transmitted to any external server.
- Purpose: Applying user-configured blocks, schedules, and unlock challenges. No third-party monitoring, surveillance, or remote control.
- Your rights: You can revoke at any time via iOS Settings → Screen Time → D.off permissions. All ManagedSettings are automatically deleted immediately upon app uninstallation.
- Apple policy: This feature operates under Apple's Family Controls Distribution Entitlement approval, and Apple's Privacy Policy (apple.com/legal/privacy) applies in conjunction.
13. Local Data Storage & Encryption
D.off stores app data on your device using the following mechanisms:
- Local database (RxDB / IndexedDB): Quota settings, app group selections, transcription journal entries, weekly stats, and category preferences are stored in your device's local IndexedDB store. Data is kept inside the app sandbox and is not accessible to other apps on the same device.
- Device-level encryption: D.off relies on OS-level full-disk / file-based encryption (Android FBE for Android 10+, iOS File Data Protection) to protect data at rest. D.off does not apply an additional application-layer encryption key on top of this storage. As a result, data confidentiality depends on you keeping a device passcode/biometric lock enabled and your device not being jailbroken or rooted.
- Sensitive token storage: Apple Sign-In access tokens (used only for the Guideline 5.1.1(v) revoke flow at account deletion) and the device-time anchor used for the cooldown mechanism are stored in OS-secured storage: iOS Keychain (with
kSecAttrAccessibleWhenUnlockedThisDeviceOnly, iCloud sync disabled) and Android EncryptedSharedPreferences (Keystore-backed AES-256-GCM). These items are bound to the device and are not included in encrypted iCloud or Google Drive backups.
- In transit: All network requests to Firebase, Cloud Functions, RevenueCat, and Apple/Google identity endpoints use HTTPS (TLS 1.2+). No cleartext HTTP traffic is permitted by the app's network security configuration.
- Removal: Uninstalling D.off removes the entire app sandbox, including the local database and all stored tokens, from the device.
← Back to D.off