Privacy Policy

Effective date: September 20, 2026

Article 1 (General)

  • OpenStock AI (the "Company") values the personal information of openalarm (the "Service") users and complies with applicable laws, including the Personal Information Protection Act of Korea.
  • This Privacy Policy explains what information the Company processes, for what purposes, for how long, and the rights users may exercise.

Article 2 (Personal Information Collected and Collection Methods)

  • Registration (required): email address, password (stored encrypted)
  • Profile (optional): nickname
  • Information generated or collected during use of the Service: alarm data (times, repeat days, labels, snooze settings, AI automation rules and dismissal-confirmation policies), alarm usage records (behavioral events such as when alarms were scheduled, fired, snoozed, dismissed, edited, or skipped), to-dos (title, notes, due time, notification settings, importance flags), diaries (date, content, weather and mood entries, AI replies), schedule-sharing codes, connection relationships, schedule proposals, inquiries and responses
  • Location information (optional): names, latitude/longitude, and radius of places the user saves directly on to-dos — used only for arrival notifications at those places
  • Sound files (optional): alarm sounds and video files uploaded by the user
  • Automatically collected items: login session cookies, device time zone, service usage and security logs (such as suspicious-access detection records). If push notifications are allowed in the native app, the device's push token and OS type (iOS/Android) are linked to the account and stored.
  • Collection methods: the sign-up screen, direct user input while using the Service, and automatic generation/collection during use
  • Storage location: collected information is stored on the Supabase servers described in Article 4. Some information, such as notification settings and alarm-sound caches, is stored only on the device and is not transmitted to the server (see Article 9).

Article 3 (Purposes of Collection/Use and Retention Periods)

  • Member management — identification, login, account closure / Retention: until account closure
  • Service provision — core features such as alarms, to-dos, location reminders, diaries, and schedule sharing / Retention: until account closure
  • AI analysis — usage-pattern analysis, AI-based alarm suggestions and automatic application, AI diary replies / Retention: until account closure
  • Customer support — responding to inquiries, answers, delivering notices / Retention: until account closure
  • Prevention of misuse — security log analysis / Security event records may be retained after account closure for the purpose of preventing misuse
  • Where retention is required by applicable law, the relevant information is stored separately for the required period (e.g., three years for consumer complaint and dispute records under the Act on Consumer Protection in Electronic Commerce).

Article 4 (Outsourcing of Processing and Overseas Transfer)

  • The Company outsources personal-information processing as follows to operate the Service, and some outsourced work is performed overseas. Related matters are disclosed in this Policy pursuant to Article 28-8(1)(iii) of the Personal Information Protection Act.
  • Supabase Inc. (USA) — authentication, database, file storage / Information transferred: authentication data (email, encrypted password), profile (nickname, time zone, AI automation level), all service data including alarms, usage records, to-dos (including location data), diaries, sharing relationships, and inquiries, AI analysis results and suggestion history, uploaded sound and video files (Supabase Storage) / Timing and method: transmitted and stored over the network as needed during use of the Service / Purpose: data storage and processing for Service operation / Retention: until account closure or termination of the outsourcing contract
  • ※ Uploaded sound and video files are stored in a public-URL repository — anyone who knows a file's URL can access it. Please do not upload files that contain personally identifiable content.
  • Vercel Inc. (USA) — web application hosting and scheduled analysis jobs (Cron) / Transferred items, timing, purpose, and retention are the same as for Supabase
  • AI analysis providers — OpenAI (USA) or DeepSeek (China); one of the two is used depending on operational configuration / Transferred items: alarm usage statistics, alarm labels and settings, to-do/schedule and location-reminder settings, times and metadata of individual alarm events needed for analysis, past suggestions and user responses. When generating AI diary replies, the diary text and excerpts of recent diaries are also sent. Email and password are not included in analysis inputs, but personally entered labels, diaries, etc. may contain personal information / Timing and method: transmitted via API calls when analysis runs / Purpose: AI analysis and reply generation / Retention: per each provider's policy
  • Push notification providers — Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) / Transferred items: device push token, notification title and body, in-app navigation data / Timing and method: API calls when notifications are sent / Purpose: delivering notifications to the device. Tokens are deleted on logout, account closure, or when found invalid; each provider's processing and retention follow its own policy.
  • Users who do not want overseas transfer may refuse it via Settings > Delete Account; however, the Service cannot be used in that case.

Article 5 (Provision to Third Parties)

  • The Company does not, in principle, provide users' personal information to third parties.
  • Exceptions apply where the user has consented in advance or where a request is grounded in applicable law.

Article 6 (Destruction Procedures and Methods)

  • When a user closes their account via Settings > Delete Account, the account information, alarms, usage records, to-dos, diaries, sharing relationships, and sound files are deleted without delay.
  • Location information is deleted together with the corresponding to-do.
  • Information in electronic file form is deleted using methods that prevent recovery.

Article 7 (Users' Rights, Obligations, and How to Exercise Them)

  • Users may at any time request to view, correct, delete, or suspend the processing of their personal information (Articles 35-37 of the Personal Information Protection Act).
  • How to exercise: edit or delete directly in the app's Settings, or request via Settings > Contact Admin or the customer inquiry line. The Company takes action without delay.
  • Children under 14 may not register, and the Company does not collect personal information from children under 14.
  • Location and notification permissions can be revoked at any time in device settings; related features may be limited upon revocation.

Article 8 (Automated Processing by AI)

  • Based on alarm usage history and to-do/location-reminder settings, the Service's AI suggests or automatically applies alarm times and automation rules. No camera, microphone, sleep sensor, or wearable is used.
  • AI analysis primarily uses aggregated statistics; alarm and schedule settings and individual events needed for analysis may also be transmitted. Diary text is transmitted for AI diary replies. See Article 4 for the specific items transferred.
  • Automated processing results are reference suggestions, not a medical service that measures or diagnoses sleep quality. The automation level can be checked in the app's settings, and opt-out or explanation requests can be made via Settings > Contact Admin.
  • Analysis accuracy depends on how much alarm usage history has accumulated. Please verify important schedules and appointments yourself.

Article 9 (Automatic Collection Devices — Installation, Operation, and Refusal)

  • Cookies: used only to maintain the login session. Refusing cookies prevents login and limits use of the Service.
  • On-device storage: notification settings, alarm-sound caches, etc. are stored only on the device and are not transmitted to the Company's servers. They are removed when the app is deleted or the account is closed.

Article 10 (Security Measures)

  • Passwords are stored encrypted, and data transmission is encrypted with TLS.
  • Access to personal information is minimized, and rate limits are applied to externally guessable access paths such as sharing codes.

Article 11 (Privacy Officer and Inquiries)

  • Privacy Officer: Dowon Kim (CEO)
  • Contact: +82-70-8027-1568
  • How to inquire: Settings > Contact Admin in the app

Article 12 (Remedies for Rights Infringement)

  • Reports and consultations regarding personal-information infringement may be directed to the organizations below.
  • Personal Information Infringement Report Center (KISA) 118 · Personal Information Dispute Mediation Committee 1833-6972 · Supreme Prosecutors' Office Cyber Investigation Division 1301 · National Police Agency Cyber Bureau 182

Article 13 (Changes to This Policy)

  • Changes to this Policy are announced in the app at least 7 days before the effective date; material changes to users' rights are announced at least 30 days in advance.

openalarm