Privacy Policy
Aspado (the “Company”) provides Kan, a goal-management app. This policy explains how the Company processes and protects personal information under Article 30 of Korea’s Personal Information Protection Act (“PIPA”).
1. Purposes and legal bases for processing
| Purpose | Legal basis |
|---|---|
| Account creation, sign-in, identity verification, and security | PIPA Article 15(1)4 (contract) |
| Storage, synchronization, and recovery of goals and tasks | PIPA Article 15(1)4 |
| Subscription verification and paid features | PIPA Article 15(1)4 |
| Statutory retention of payment and supply records | Korea’s Electronic Commerce Consumer Protection Act, Article 6 |
| Support and account-deletion requests | PIPA Article 15(1)4 |
| Security, abuse prevention, and diagnostics | PIPA Article 15(1)6 (legitimate interests) |
| Personalized advertising and measurement | PIPA Article 15(1)1 (consent) |
We do not use personal information for unrelated purposes without obtaining required consent or taking other measures required by law.
2. Personal information we process
| Category | Information | Collection method |
|---|---|---|
| Account and authentication | Provider identifier, email, display name, profile image, sign-in provider | Google or Apple sign-in |
| User content | Core and supporting goals, action items, tasks, completion records, status, color, target dates, and timestamps | Entered in the app and sent when synchronization is selected |
| Subscription and entitlement | App, store and product identifiers; subscription status; order, transaction and original-transaction identifiers; transaction type and status; purchase, expiry and revocation times | App Store or Google Play purchase verification |
| Device and service | OS, app version, language, app-instance identifier, IP address, user agent, security and error records | Generated during app and server use |
| Advertising and consent | Advertising identifier, approximate location, impressions, interactions, and consent choices | Advertising and consent flows |
| Support | Contact email, inquiry, deletion request, one-time verification code, deletion-request ID, email HMAC lookup value, ownership-verification and processing records | Collected or generated during an email or in-app request |
Unsigned goals, tasks, and settings are generally stored on the device. Account-linked content is sent to the cloud after sign-in and synchronization. Kan does not collect government identifiers, health data, biometrics, or other sensitive information to provide the service.
3. Retention periods
| Information | Retention |
|---|---|
| Account, authentication, and synchronized user content | Until account deletion |
| Active subscription entitlement | Until account deletion or entitlement expiry, whichever occurs first |
| Minimum contract, withdrawal, payment, and supply records | Five years from the transaction date, or record creation when no historic purchase time exists |
| On-device error records | Up to seven days |
| Support, ownership-verification, and deletion-processing records | One year after the request is closed |
To meet Korean electronic-commerce record duties, we retain only minimum transaction evidence for five years: app, store and product identifiers; order, transaction and original-transaction identifiers; transaction type and status; purchase, expiry and revocation times; the retention deadline; an app-scoped, versioned HMAC lookup value derived from email instead of the plain-text email; and an opaque deletion-request ID. The HMAC value and deletion-request ID are pseudonymous. These records are separated from customer data and exclude direct identifiers such as customer IDs, Firebase UIDs and plain-text email, as well as purchase tokens and raw receipts.
If Firebase Authentication deletion temporarily fails after remote data has been removed during a support-assisted deletion, we temporarily keep the Firebase UID and former customer number in the active deletion lifecycle so the same request can safely resume. We erase both immediately after authentication deletion and completion recording finish; neither is included in the one-year support record or the five-year statutory transaction record.
4. Destruction procedures and methods
When information is no longer needed, we permanently delete electronic files and database records so they cannot be restored. We do not retain Kan users’ personal information on paper.
Account deletion removes synchronized goals and tasks from Cloud Firestore, customer identifiers and user-generated data from Basecamp, and the sign-in account from Firebase Authentication. In-app deletion also removes that account’s local data from the device. Minimum statutory transaction records remain separated and are automatically destroyed when each five-year period ends.
Firebase Authentication information remaining in live or backup systems may take up to 180 days to be removed after our deletion request. Deleted backup data is not used for ordinary service and is destroyed when the backup expires.
5. Disclosure to third parties
We do not disclose personal information for a third party’s independent purposes. Where separate consent or law permits disclosure, we provide the recipient, purpose, fields, and retention period in advance.
6. Processing contractors
| Contractor | Processing activity |
|---|---|
| Google LLC | Firebase Authentication, Cloud Firestore synchronization, Firebase App Check, Google Sign-In, AdMob advertising, and UMP consent management |
| Apple Inc. | Sign in with Apple and App Store payment, subscription, and entitlement verification |
Synchronized Kan content is stored in the Seoul, South Korea Cloud Firestore region (asia-northeast3). Contractor changes are published in this policy.
7. International transfers
| Recipient | Country | Information | Timing and method | Purpose | Retention |
|---|---|---|---|---|---|
| Google LLC (contact) | United States | Sign-in identifier, email, display name, profile image, IP address, user agent | Encrypted transfer during Google sign-in and authentication | Authentication, security, abuse prevention | Deletion requested at account deletion; live and backup removal may take up to 180 days |
| Google LLC | Countries where Google operates services | App-integrity data, advertising identifier, approximate location, app/device data, ad interactions and consent | Encrypted transfer during validation and ad requests | Integrity, advertising, measurement, frequency capping, fraud prevention, consent | App Check tokens up to seven days and replay-protection tokens up to 30 days. Advertising logs remove part of IP addresses after 9 months and identifying information after 18 months; AdMob reports are retained for 90 or 2,555 days depending on report type |
| Apple Inc. (contact) | United States and Apple service countries | Apple identifier, email or relay email, authentication token/code, purchase and subscription identifiers | Encrypted transfer during Apple sign-in or purchase verification | Sign-in, disconnection, payment, subscription, entitlement | Duration of the Apple account or app relationship and periods required by law |
Contract-related transfers rely on PIPA Article 28-8(1)3; personalized advertising relies on consent under Article 28-8(1)1. Delete the account at Settings > Account > Delete Account, or revisit advertising choices at Settings > Ad Privacy Settings.
8. Automatic collection and behavioral information
Kan does not directly install browser cookies. Authentication, security, and advertising SDKs may process app-instance identifiers, IP addresses, user agents, advertising identifiers, approximate locations, and ad interactions for security, app integrity, advertising, measurement, frequency capping, and fraud prevention. You can revisit choices at Settings > Ad Privacy Settings and in the operating system’s privacy and advertising settings. No ad request is made in consent-required regions until the consent state permits it.
9. Rights of data subjects and representatives
You may request access, correction, deletion, suspension, or withdrawal of consent. In Kan, use Settings > Account > Delete Account and verify your identity. If you cannot use the app, follow the Kan account deletion instructions or email [email protected].
For an email request, the owner manually sends a one-time code to the Firebase-registered email address. Reply from that mailbox within 24 hours to complete verification. An unverified request never changes the account or its data. After verification, Aspado’s sole owner, with a recent reauthentication, runs the same automated deletion lifecycle as the in-app flow. Public support requests are completed within 30 days after verification, and we reply with the result.
Account deletion does not cancel an App Store or Google Play subscription; cancel it in the store. Provider authorization is also separate, so remove Kan access in Google or Apple settings if needed.
10. Personal information of children under 14
Kan does not offer account services to children under 14. If we learn that such information was processed without valid parental consent, we verify the request and delete it without undue delay.
11. Security measures
We apply least privilege, periodic access reviews, encryption in transit and at rest, token validation, app-integrity checks, protected access records, and physical access controls.
12. Privacy officer and responsible function
- Privacy officer title: Privacy Officer
- Responsible function: Aspado Privacy
- Email: [email protected]
13. Remedies for infringement
Users in Korea may contact the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), Supreme Prosecutors’ Office (1301, spo.go.kr), or Korean National Police Agency (182, ecrm.police.go.kr).
14. Changes to this policy
This policy applies from August 26, 2026. Material changes will be announced before they take effect. Previous versions remain available in the version history.
Published: August 26, 2026 Effective: August 26, 2026