Privacy Policy

Effective Date: May 11, 2026 (v5.2)

Elpis Studio ("Company") values the privacy of D.off app ("Service") users and establishes this Privacy Policy in accordance with applicable laws.

1. Information We Collect

We collect the following information to provide our service:

2. How We Use Information

3. Data Retention and Deletion

Data is deleted immediately upon account deletion, except where retention is required by law. Device integrity records (Section 8) are retained for the duration of the 7-day cooldown plus 90 days, after which they are anonymized; this minimal retention is necessary to enforce the self-control commitment that users opt into.

4. Third-Party Sharing

We do not share personal information with third parties except as required by law. We rely on the following infrastructure providers, who process data only as our processors:

5. App Usage Data

D.off uses the UsageStats permission (Android) or Family Controls / DeviceActivity entitlement (iOS) to query app usage time. iOS users: see Section 12 (Family Controls) for the equivalent — iOS handles app monitoring internally without exposing raw usage to D.off. This data is:

6. Your Rights

You can request access, correction, or deletion of your data at any time through account settings. Deleting your account also removes the device hash association, though the hash itself remains in the deviceBlocklist record described in Section 8 for the duration of any active cooldown.

7. Contact

Privacy inquiries: chrislee.krh@gmail.com

8. Service Providers (Subprocessors)

D.off uses the following third-party service providers for core infrastructure:

9. International Data Transfer

All subprocessors above are located in the United States. By using the Service, you consent to international data transfer to the United States under Articles 17(3) and 28-8 of the Korean Personal Information Protection Act and applicable EU/UK SCCs where relevant.

10. Device Attestation & Re-registration Cooldown

D.off is a self-control tool. To prevent users from circumventing their own self-imposed limits by deleting and recreating their account, we use device attestation:

The legal basis for this processing is performance of the self-control commitment that you have voluntarily entered into by using the Service (Article 6(1)(b) GDPR; KISA personal information processing for service delivery).

11. Sign in with Apple

On iOS, D.off supports Sign in with Apple as one of multiple sign-in methods (Apple App Store Guideline 4.8). When you use this method:

12. iOS Screen Time Data (Family Controls)

On iOS 16+ devices, D.off uses Apple's Family Controls framework to apply restrictions to apps that you yourself select.

13. Local Data Storage & Encryption

D.off stores app data on your device using the following mechanisms:

← Back to D.off