FoodLog 개인정보처리방침
요약
- 식사, 사진, 체중, 목표 칼로리처럼 사용자가 직접 남긴 기록을 계정에 저장해 앱 기능을 제공합니다.
- AI 칼로리 추정과 삽화 생성은 사용자가 요청하고 앱에서 따로 동의한 경우에만 OpenAI에 보냅니다. 계정 이름·이메일·식별자·체중을 자동 첨부하지 않습니다.
- 광고를 보여 주지 않고, 광고나 일반 행동 분석용 SDK를 쓰지 않으며, 개인정보를 판매하지 않습니다.
- 앱에서 기록을 내보내거나 계정을 삭제할 수 있습니다. 삭제 후에도 일부 정보가 남는 경우는 아래 7항에 적었습니다.
1. 이 방침이 적용되는 범위
이 방침은 Gomsoon Labs LLC(이하 “회사”)가 운영하는 iOS·Android 앱 FoodLog와 이 지원 페이지에 적용됩니다. 회사 주소는 2108 N St Ste N, Sacramento, CA 95816, United States이고, 연락처는 support@gomsoonlabs.ai입니다.
이 방침은 이용약관과 별개입니다. 이용약관에 동의한다고 해서 아래 4항의 AI 전송에 동의한 것이 되지 않습니다.
2. 처리하는 정보와 목적
| 구분 | 정보 | 목적 |
|---|---|---|
| 계정 | Google 또는 Apple 로그인으로 받는 이름, 이메일 주소, 프로필 사진 주소, 계정 식별자 | 로그인, 계정 유지, 기기 간 기록 동기화, 문의 응대 |
| 식사 기록 | 식사 시각, 이름, 설명, 음식 항목, 추정 칼로리와 범위, 사용자가 고친 값 | 기록 보관과 표시, 기간별 추이 |
| 사진과 삽화 | 사용자가 고른 식사 사진(위치 정보 등 사진 메타데이터를 지운 JPEG), 사용자가 요청해 만든 AI 삽화 | 기록 표시, 요청 시 AI 추정 |
| 체중 | 사용자가 입력한 체중과 시각, 표시 단위 | 체중 기록과 추이 |
| 목표 칼로리(선택) | 직접 입력한 목표와 변경 이력. 만 18세 이상이 자동 추천용 프로필을 입력하고 목표를 저장하면 생년월일, 추정에 쓰는 성별, 키, 활동량, 목표와 계산 결과도 저장합니다 | 하루 목표 칼로리 제안과 기록. 계산은 기기에서 하며 AI에 보내지 않습니다 |
| 연령 제한 기록 | 계정에 연결된 확인 시각. 서버 저장이 완료될 때까지 기기에 해당 계정 식별자를 임시 저장 | 기기 간 이용 제한 유지. 서버 기록은 계정 삭제 또는 제한 해제 시 삭제하며, 임시 기기 기록은 서버 저장 성공 또는 계정 삭제 시 삭제 |
| AI 이용 동의 | 안내 버전, 동의·거절·철회 상태, 시각 | 동의한 경우에만 AI 기능 제공 |
| 건강 관련 정보 저장 동의 | 안내 버전, 동의·거절·철회 상태, 시각 | 동의한 경우에만 식사·체중·목표 기록의 새 저장과 수정 허용 |
| 이미지 신고 | 신고한 기록의 식별자, 신고 사유, 시각 | AI 생성 콘텐츠 관리 |
| 체험과 구독 | 체험·구독 상태, 상품, 기간, 스토어 거래 번호, AI 사용량과 요청 처리 기록, 체험 재사용 방지 표식 | 권한 확인, 사용량 관리, 중복 지급 방지, 결제 문의 대응 |
| 문의 | 이메일 주소, 문의 내용, 사용자가 남긴 앱 버전·운영체제·앱 언어, 첨부한 스크린샷 | 문의 답변과 요청 처리 |
| 자동으로 생기는 정보 | 서버 요청 기록(IP 주소, 사용자 에이전트, 요청 시각, 결과) | 보안, 남용 방지, 장애 대응 |
기기 위치 권한, 주소록, 광고 식별자를 사용하지 않습니다. 사용자가 메모나 문의에 직접 적은 정보는 그 내용에 포함될 수 있습니다. 카메라와 사진 접근은 사용자가 해당 버튼을 누를 때만 요청합니다.
기기에는 작성 중인 초안, 업로드 대기 기록, 사진 캐시가 저장됩니다. 로그아웃하거나 계정을 삭제하면 이 기기에서 지웁니다.
식사·체중·목표 정보에는 건강과 관련된 민감한 내용이 포함될 수 있습니다. 필요하지 않은 병력이나 다른 사람의 개인정보는 메모에 적지 말아 주세요.
앱은 식사·사진·체중·목표 칼로리 기록을 처음 저장하기 전에 저장 항목(선택 프로필과 계산·추정 결과 포함), 목적, 보관 기간, 거절·철회 영향을 보여 주고 이용약관·AI 이용 동의와 별도로 동의를 받습니다. 동의하지 않거나 철회하면 기록의 새 저장·수정과 AI 기능을 쓸 수 없습니다. 로그인, 기존 기록 보기·내보내기·삭제, 계정 삭제, 구독 관리, 문의는 계속 쓸 수 있습니다. 동의와 철회는 설정 > 데이터 및 개인정보 > 개인정보 및 AI 이용 > 건강 관련 정보 저장에서 할 수 있습니다. 철회해도 이미 저장한 기록은 자동으로 삭제되지 않습니다. 식사는 식사 상세 화면, 체중은 체중 기록에서 삭제하고 현재 목표는 목표 화면에서 해제할 수 있습니다. 목표 변경 이력과 프로필까지 모두 지우려면 계정을 삭제해 주세요. 보관 기준은 7항에 안내합니다.
3. 정보를 받는 방법
- 사용자가 앱에 직접 입력하거나 고른 정보
- Google 또는 Apple 로그인 시 그 회사가 전달하는 정보
- App Store·Google Play 결제를 구독 관리 업체가 확인해 전달하는 정보
- 앱이 서버에 요청할 때 자동으로 생기는 기록
4. AI 기능
AI 칼로리 추정과 삽화 생성은 선택 기능입니다. 처음 쓸 때 앱이 무엇을 보내는지 보여 주고 동의를 따로 받습니다. 동의하지 않아도 직접 기록하는 기능은 그대로 쓸 수 있습니다.
- 사진으로 추정: 사용자가 고른 사진, 선택한 메모, 앱 언어
- 설명으로 추정: 식사 설명, 앱 언어
- 삽화 생성: 식사 설명
계정의 이름·이메일·식별자, 체중·목표 칼로리 프로필, 결제 정보를 자동으로 붙여 보내지 않습니다. 다만 사용자가 사진이나 설명에 직접 포함한 정보는 함께 전송될 수 있습니다. OpenAI는 OpenAI의 API 정책상 고객이 따로 선택하지 않으면 API 데이터를 모델 학습에 쓰지 않으며, 회사는 그 공유를 선택하지 않았습니다. OpenAI는 남용 방지를 위해 요청 기록을 기본 최대 30일 보관할 수 있습니다.
AI 결과는 추정값입니다. 삽화는 기록용 그림이며 실제 음식 사진이나 분석 근거가 아닙니다.
동의는 앱의 설정 > 데이터 및 개인정보 > 개인정보 및 AI 이용에서 철회할 수 있습니다. 철회하면 새 요청을 보내지 않습니다. 이미 받은 결과와 기록은 남고, 이미 보낸 요청은 되돌릴 수 없습니다.
5. 처리를 맡기는 업체
| 업체 | 맡기는 일 | 정보 | 위치 |
|---|---|---|---|
| Google LLC (Firebase) | 로그인, 데이터베이스, 사진 저장, 서버 기능, 서버 기록 | 2항의 계정·기록·사진·체험·구독 정보, 서버 요청 기록 | 미국(데이터베이스·사진·서버 기능은 us-central1) |
| OpenAI OpCo, LLC | AI 칼로리 추정, 삽화 생성, 삽화 안전 검토 | 4항의 정보(동의한 경우만) | 미국 소재 업체. API 처리와 지원에는 업체의 하위 처리업체가 관여할 수 있습니다(처리업체 목록). |
| RevenueCat, Inc. | 스토어 구독 상태 확인과 구매 현황 관리 | 계정 식별자, 구매·구독 정보 및 기기 유형·운영체제·앱/SDK 버전 등 구독 처리에 필요한 기술 정보 | 미국 |
Apple과 Google은 로그인과 스토어 결제를 각자의 정책에 따라 직접 처리합니다. 회사는 카드 번호 같은 결제 수단 정보를 받지 않습니다.
지원 웹사이트는 Cloudflare를 통해 제공되며, 페이지 요청 시 IP 주소와 브라우저 정보 등 기술 정보가 처리될 수 있습니다. 이메일 문의는 Google Workspace(Gmail)를 통해 수신·회신하며, 이메일 주소·문의 내용·첨부 파일을 처리합니다. Cloudflare는 미국·유럽경제지역 등을 포함한 글로벌 네트워크에서 처리하며, Google Workspace의 처리 위치도 서비스 계약·설정과 하위 처리업체에 따라 달라질 수 있습니다. 업체 처리 정보는 Cloudflare 방침과 Google 처리 계약에서 확인할 수 있습니다.
회사는 개인정보를 판매하거나 광고 목적으로 제공하지 않습니다. 서비스 운영에 필요한 위탁 처리와 법령에 따른 경우 외에는 제3자에게 제공하지 않습니다.
6. 국외 처리
회사는 미국 법인입니다. 계정과 기록의 클라우드 저장에는 미국 서버를 사용하며, 로그인·기록 동기화·AI 요청 등 해당 기능을 사용할 때 정보가 네트워크로 전송됩니다. 받는 자, 항목, 목적은 5항과 같고, 보관 기간은 7항과 같습니다.
국외 처리를 원하지 않으면 AI 기능에 동의하지 않거나 철회할 수 있습니다(OpenAI 전송 중단). 계정 저장 자체는 미국 서버로만 제공되므로, 거부하려면 서비스를 이용하지 않거나 계정을 삭제해야 합니다.
기록 저장과 구독 확인은 요청한 서비스를 제공하기 위한 위탁 처리이며, 선택한 AI 기능은 앱에서 별도로 전송 동의를 받습니다. 업체별 정보·목적·처리 위치는 위 표, 보관 기준은 아래 7항에 안내합니다. 국외 처리 관련 질문이나 권리 요청은 지원 이메일로 보내 주세요.
7. 보관 기간과 삭제
계정 정보와 기록은 계정이 있는 동안 보관합니다. 사용자는 앱에서 각 기록을 지우거나 계정 전체를 삭제할 수 있습니다. 계정 삭제는 로그인 계정, 식사·사진·체중·프로필과 앱 내 이용 기록을 대상으로 합니다. 아래의 결제 관련 기록, 처리 기록, 외부 업체 기록 등은 별도로 구분합니다.
- 삭제한 사진 파일: 저장소의 복구 기능 때문에 최대 7일 뒤 자동 삭제
- AI 삽화의 임시 복구 사본: 응답이 끊기거나 앱이 종료돼도 같은 요청의 삽화를 다시 받을 수 있도록 서버가 최대 7일 보관합니다. 앱이 삽화를 받으면 바로 삭제를 요청하고, 그 요청이 실패했거나 앱이 삽화를 받지 못했다면 7일 뒤 정기 작업으로 삭제합니다. 계정 삭제 시에는 바로 삭제합니다. 식사에 저장한 삽화는 이 사본과 별도로 식사 기록과 함께 보관되므로, 식사를 지워도 아직 정리되지 않은 임시 사본이 최대 7일 남을 수 있습니다. 중복 차감 방지와 이용 확인에 쓰는 요청 기록(상태, 시각, 이미지 크기·해시)은 이미지 없이 계정이 있는 동안 남고 계정 삭제 시 삭제합니다.
- 일반 서버 요청 기록: 30일 보관. 클라우드의 필수 감사 로그는 별도로 400일 보관
- 이미 OpenAI에 보낸 요청: OpenAI 정책에 따름(기본 최대 30일)
- 스토어 거래 번호와 계정 식별자의 연결: 계정 삭제 시 해당 계정과의 연결을 제거합니다. 다른 계정으로 이전된 구매 연결은 제거하지 않습니다.
- 체험 재사용 방지 표식: 이메일 주소에서 비밀 키로 만든 값이며 원래 이메일은 저장하지 않습니다. 익명 정보는 아닙니다. 보관 기간 최초 체험부터 12개월 동안 재체험 제한에 사용하고 이후 정기 작업으로 삭제합니다. 계정 삭제 시 기존 계정 식별자는 제거하며, 만료된 표식은 재체험 제한에 사용하지 않습니다.
- 삭제 처리 기록(상태와 시각): 완료 후 90일을 기준으로 정기 삭제합니다. 진행 중·실패·외부 고객 삭제 재시도에 필요한 기록은 처리가 끝날 때까지 유지합니다.
- RevenueCat의 구매 기록: 앱 계정 삭제 후 약 2시간이 지나면 정기 작업이 RevenueCat 고객 기록 삭제를 시도합니다. 실패하면 재시도하므로 외부 기록 삭제는 더 늦어질 수 있습니다. 스토어 구독 해지와는 별개입니다.
- 지원 이메일 대화: 해결 후 12개월 이내 삭제합니다. 불필요한 건강정보 첨부는 목적이 끝나면 먼저 삭제합니다.
- 처리 완료한 AI 신고: 처리 완료 후 30일 이내 삭제하며, 계정 삭제 시에도 함께 삭제합니다.
- 법령상 보관 의무: 법령이나 유효한 법적 요청에 따라 일부 정보를 보존해야 하는 경우에는 해당 정보만 분리해 필요한 기간 동안 보관하고, 보존 사유가 끝나면 삭제합니다.
클라우드 업체의 복구·보안 사본은 해당 업체의 삭제 절차에 따라 정리되며 활성 데이터 삭제와 최종 소멸 시점이 다를 수 있습니다. 현재 데이터베이스 백업과 시점 복구 기능은 쓰지 않습니다. 도입하면 백업에 남는 기간을 이 방침에 적습니다. 자세한 삭제 방법은 계정 삭제 안내를 확인해 주세요.
8. 이용자의 권리
- 열람·정정: 앱에서 기록을 보고 고칠 수 있습니다. 고치기는 2항의 건강 관련 정보 저장 동의가 있을 때 가능합니다.
- 내보내기: 설정 > 데이터 및 개인정보 > 데이터 내보내기
- 삭제: 각 기록 삭제, 또는 설정 > 계정 > 계정 삭제
- 건강 관련 정보 저장 동의 철회: 2항
- AI 동의 철회: 4항
- 그 밖의 요청: 열람, 정정, 삭제, 처리 정지 요청은 support@gomsoonlabs.ai로 보내 주세요. 본인 확인을 요청할 수 있습니다. 적용 법령의 기한 안에 처리하고, 추가 확인이나 처리 시간이 필요하면 알려 드립니다.
거주 지역의 적용 법령에 따라 개인정보 처리 확인, 사본 제공, 동의 철회, 삭제 및 요청 거절에 대한 이의제기 등 추가 권리를 행사할 수 있습니다. 요청이나 이의제기는 같은 지원 이메일로 보내 주세요. 권리를 행사했다는 이유로 불이익을 주지 않습니다. 건강 관련 정보는 건강정보 처리 안내에서도 설명합니다.
9. 이용 연령
FoodLog는 만 14세 이상부터 이용할 수 있습니다. 신체 정보에 기반한 하루 목표 칼로리 자동 추천은 만 18세 이상에게만 제공합니다. 이 기능의 연령 제한은 식사·사진·체중 기록이나 음식의 칼로리 추정에는 적용되지 않습니다. 로그인한 뒤 본인이 만 14세 미만이라고 확인하면 계정에 연결된 제한 기록(확인 시각)을 서버에 저장하고 새 기록 추가·수정과 AI 기능 이용을 제한합니다. 이 제한 기록에 생년월일이나 정확한 나이는 저장하지 않습니다. 제한된 계정에서도 기록 내보내기, 계정 삭제, 구독 관리, 문의와 로그아웃은 할 수 있습니다. 제한 기록은 계정 삭제 시 함께 삭제되며, 제한만으로 기존 기록이 자동 삭제되지는 않습니다.
로그인 화면에서는 Google 또는 Apple 로그인을 진행하기 전에 만 14세 이상인지 본인이 답하도록 합니다. 이 확인을 위해 생년월일을 받지 않으며, 답변은 해당 화면에서만 일시적으로 사용하고 기기 저장소나 서버에 저장하지 않습니다.
10. 안전 조치
- 본인 계정으로 로그인한 경우에만 자신의 기록과 사진을 읽고 쓸 수 있게 접근 규칙을 둡니다.
- 앱과 서버 사이의 통신은 암호화됩니다.
- AI 서비스 키 같은 서버 비밀 정보는 앱에 넣지 않습니다.
- 사진을 저장하기 전에 위치 등 사진 메타데이터를 지웁니다.
11. 개인정보 보호책임자와 문의
개인정보 업무 및 고충처리 담당: Gomsoon Labs LLC 고객지원
이메일: support@gomsoonlabs.ai
개인정보 침해에 대한 상담과 구제는 아래 기관에도 요청할 수 있습니다.
- 개인정보분쟁조정위원회: 1833-6972, www.kopico.go.kr
- 개인정보침해신고센터(한국인터넷진흥원): 118, privacy.kisa.or.kr
- 대검찰청: 1301, www.spo.go.kr
- 경찰청: 182, ecrm.police.go.kr
12. 방침 변경
이 방침이 바뀌면 변경 내용과 시행일을 이 페이지에 게시합니다. 추가 안내나 새로운 동의가 필요한 변경은 적용 법령에 따라 처리합니다.
FoodLog Privacy Policy
Summary
- We store the records you create, such as meals, photos, weights, and calorie targets, in your account to run the app.
- AI calorie estimates and illustrations are sent to OpenAI only when you ask for them and have given separate consent in the app. We do not automatically attach your account name, email, account ID, or weight.
- We don’t show ads, don’t use advertising or general behavioral analytics SDKs, and don’t sell personal information.
- You can export your records or delete your account in the app. Section 7 lists what may remain after deletion.
1. Scope
This policy applies to FoodLog, the iOS and Android app operated by Gomsoon Labs LLC (“we”), and to these support pages. Our address is 2108 N St Ste N, Sacramento, CA 95816, United States. Contact: support@gomsoonlabs.ai.
This policy is separate from the Terms of Use. Agreeing to the Terms of Use does not mean you agree to the AI transfers in section 4.
2. What we process and why
| Category | Data | Purpose |
|---|---|---|
| Account | Name, email address, profile photo address, and account ID received through Google or Apple sign-in | Sign-in, keeping your account, syncing records across devices, answering support requests |
| Meal records | Meal time, name, description, food items, estimated calories and range, values you changed | Storing and showing records, trends over time |
| Photos and illustrations | Meal photos you choose (JPEG with location and other photo metadata removed) and AI illustrations you request | Showing records, AI estimates when you ask |
| Weight | Weights and times you enter, display unit | Weight records and trends |
| Calorie target (optional) | Manually entered targets and target history. When users aged 18 or older complete a profile for automatic recommendations and save a target, we also store birth date, sex used for the estimate, height, activity level, goal, and calculation results | Suggesting and recording a daily calorie target. The calculation runs on your device and is not sent to AI |
| Age restriction record | Account-linked confirmation time. The account ID is temporarily stored on the device until the server save completes | Maintaining the restriction across devices. The server record is removed upon account deletion or restriction release; the temporary device record is removed after a successful server save or account deletion |
| AI consent | Notice version, accepted/declined/withdrawn status, time | Providing AI features only with consent |
| Health-related information storage consent | Notice version, accepted/declined/withdrawn status, time | Allowing new or edited meal, weight, and target records only with consent |
| Image reports | ID of the reported record, reason, time | Managing AI-generated content |
| Trial and subscription | Trial and subscription status, product, period, store transaction number, AI usage and request records, trial reuse mark | Checking access, managing usage, preventing duplicate grants, answering billing questions |
| Support | Email address, your message, the app version, operating system, and app language you leave in it, screenshots you attach | Answering and handling requests |
| Generated automatically | Server request logs (IP address, user agent, time, result) | Security, abuse prevention, troubleshooting |
We do not use device location permissions, your address book, or advertising identifiers. Information you include in notes or support messages may still be part of that content. The app asks for camera or photo access only when you tap the matching button.
Your device keeps drafts, pending uploads, and a photo cache. They are removed from the device when you sign out or delete your account.
Meals, weight, and goal information may include sensitive health-related information. Please avoid unnecessary medical history or other people’s personal information in notes.
Before you first save a meal, photo, weight, or calorie target record, the app shows what is stored (including the optional profile and calculated or estimated results), why, how long it is kept, and what declining or withdrawing means, and asks for consent separate from the Terms of Use and AI consent. If you decline or withdraw, you can’t add or edit records and AI features are unavailable. You can still sign in, view, export, and delete existing records, delete your account, manage your subscription, and contact us. You can give or withdraw consent in Settings > Data & privacy > Privacy & AI use > Health-related information. Withdrawing does not automatically delete saved records. Delete meals from the meal details screen and weights from weight history, and clear the current target on the target screen. To remove target history and the profile as well, delete your account. Retention is described in section 7.
3. How we get data
- Data you enter or choose in the app
- Data Google or Apple passes to us when you sign in
- App Store and Google Play purchase data that our subscription provider verifies and passes to us
- Logs created automatically when the app makes a server request
4. AI features
AI calorie estimates and illustrations are optional. The first time you use them, the app shows what will be sent and asks for separate consent. You can keep logging by hand without it.
- Estimate from a photo: the photo you chose, an optional note, the app language
- Estimate from a description: the meal description, the app language
- Illustration: the meal description
We do not automatically attach your account name, email, account ID, weight or calorie target profile, or payment information. Information you include in a photo or description may still be sent. Under OpenAI’s API policy, API data is not used to train models unless the customer opts in, and we have not opted in. OpenAI may keep request logs for abuse monitoring for up to 30 days by default.
AI results are estimates. Illustrations are pictures for your log, not real food photos and not the basis for an estimate.
You can withdraw consent in Settings > Data & privacy > Privacy & AI use. After that, no new requests are sent. Results and records you already have stay, and requests already sent can’t be recalled.
5. Service providers
| Provider | Work | Data | Location |
|---|---|---|---|
| Google LLC (Firebase) | Sign-in, database, photo storage, server functions, server logs | Account, record, photo, trial, and subscription data in section 2; server request logs | United States (database, photos, and server functions in us-central1) |
| OpenAI OpCo, LLC | AI calorie estimates, illustrations, illustration safety checks | Data in section 4 (only with consent) | US-based provider. API processing and support may involve its subprocessors. |
| RevenueCat, Inc. | Checking subscription status and managing purchase history | Account ID, purchase and subscription data and technical information needed for subscription processing, such as device type, operating system, and app/SDK version | United States |
Apple and Google handle sign-in and store payments under their own policies. We don’t receive payment card numbers or similar payment details.
The support website is served through Cloudflare, which may process technical information such as your IP address and browser details when you request a page. We receive and reply to support emails through Google Workspace (Gmail), processing email addresses, message content, and attachments. Cloudflare processes information through its global network, including the US and EEA. Google Workspace processing locations may vary with service terms, configuration, and subprocessors. See Cloudflare’s policy and Google’s processing terms.
We do not sell personal information or share it for advertising. We disclose it for the service processing described above and as required by law.
6. Processing outside your country
We are a US company. Cloud account and record storage uses US servers. Data is transmitted when you use features such as sign-in, record sync, and AI requests. Recipients, data, and purposes are in section 5, and retention is in section 7.
If you don’t want this, you can decline or withdraw AI consent, which stops transfers to OpenAI. Your account itself is stored only on US servers, so to refuse that you need to stop using the service or delete your account.
Record storage and subscription verification use service providers to deliver the service you request; optional AI transfers require separate in-app consent. Provider data, purposes, and locations are described above, and retention is in section 7. Contact our support email with questions or rights requests about overseas processing.
7. Retention and deletion
We keep account data and records while your account exists. You can delete individual records or your whole account in the app. Account deletion covers your sign-in account, meals, photos, weight, profile, and in-app activity records. Billing-related records, processing logs, and provider records below are handled separately:
- Deleted photo files: removed automatically after up to 7 days because of the storage service’s recovery feature
- Temporary recovery copies of AI illustrations: kept on the server for up to 7 days so the same request can return its illustration if the response is lost or the app closes. The app asks for the copy to be deleted as soon as it receives the illustration. If that request fails or the app never receives the illustration, scheduled cleanup deletes the copy after 7 days. Account deletion removes it right away. Illustrations you save to a meal are stored separately with that meal, so after you delete a meal, a copy not yet cleaned up can remain for up to 7 days. Request records used to prevent double charges and check usage (status, time, image size and hash) contain no image, are kept while your account exists, and are deleted with your account.
- General server request logs: retained for 30 days. Required cloud audit logs are retained separately for 400 days
- Requests already sent to OpenAI: under OpenAI’s policy (up to 30 days by default)
- The link between a store transaction number and an account ID: We remove the link to the deleted account during account deletion, without removing purchase links transferred to another account.
- Trial reuse mark: a value made from your email address with a secret key. We don’t store the email itself. It is not anonymous data. Retention The mark prevents repeat trials for 12 months from the first trial, then is removed by scheduled cleanup. We remove the previous account ID on account deletion. Expired marks do not prevent another trial.
- Deletion job record (status and time): Completed deletion records are scheduled for cleanup after 90 days. Records needed for pending or failed deletions or external customer deletion retries remain until processing finishes.
- Purchase records at RevenueCat: A scheduled job attempts to delete the RevenueCat customer record after an approximately two-hour delay following app account deletion. Failures are retried, so external deletion may take longer. This does not cancel a store subscription.
- Support email conversations: We delete support conversations within 12 months after resolution and remove unnecessary health-related attachments earlier when their purpose ends.
- Resolved AI reports: deleted within 30 days after resolution, or as part of account deletion.
- Legal retention duties: If a law or valid legal request requires preservation, we retain only the affected information separately for the necessary period and delete it when the preservation requirement ends.
Provider recovery or security copies are handled under the provider’s deletion process, so removal from active storage and final erasure may occur at different times. We don’t currently use database backups or point-in-time recovery. If we start, we will add how long backups keep data to this policy. See Delete your account for the steps.
8. Your rights
- Access and correction: view and edit your records in the app. Editing requires the health-related information storage consent in section 2.
- Export: Settings > Data & privacy > Export data
- Deletion: delete individual records, or Settings > Account > Delete account
- Withdrawing health-related information storage consent: section 2
- Withdrawing AI consent: section 4
- Other requests: email support@gomsoonlabs.ai to ask for access, correction, deletion, or a stop to processing. We may ask you to confirm your identity. We handle requests within the deadlines required by applicable law and let you know if further verification or processing time is needed.
Depending on applicable law where you live, you may also confirm processing, request a copy, withdraw consent, request deletion, or appeal a denied request. Send requests or appeals to the same support email. We do not penalize you for exercising privacy rights. See our Consumer Health Data Privacy Notice for health-related information.
9. Age
FoodLog is available to people aged 14 or older. Automatic daily calorie target recommendations based on body measurements are available only to users aged 18 or older. This feature-specific age limit does not apply to meal, photo, or weight logging, or to estimating the calories in food. If you confirm after signing in that you are under 14, we store an account-linked restriction record (the confirmation time) on our server and restrict adding or editing records and using AI features. This restriction record does not contain your birth date or exact age. A restricted account can still export records, delete the account, manage its subscription, contact us, and sign out. The restriction record is deleted with the account; the restriction alone does not automatically delete existing records.
On the sign-in screen, we ask you to confirm that you are at least 14 before proceeding with Google or Apple sign-in. We do not collect a birth date for this check. The answer is used temporarily on that screen and is not saved to device storage or our servers.
10. Security
- Access rules let you read and write only your own records and photos while signed in to your account.
- Traffic between the app and our servers is encrypted.
- Server secrets such as AI service keys are not built into the app.
- Location and other photo metadata are removed before a photo is saved.
11. Privacy contact
Privacy inquiries and complaints: Gomsoon Labs LLC Customer Support
Email: support@gomsoonlabs.ai
Users in Korea can also contact these agencies for advice and remedies:
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Privacy Infringement Report Center (KISA): 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office: 1301, www.spo.go.kr
- Korean National Police Agency: 182, ecrm.police.go.kr
12. Changes
When this policy changes, we post the changes and effective date on this page. We provide additional notice or obtain new consent when required by applicable law.