Effective Date: August 26, 2026
Previous Documents:

Privacy Policy

Aspado (the “Company”) provides Kan, a goal-management app. This policy explains how the Company processes and protects personal information under Article 30 of Korea’s Personal Information Protection Act (“PIPA”).

PurposeLegal basis
Account creation, sign-in, identity verification, and securityPIPA Article 15(1)4 (contract)
Storage, synchronization, and recovery of goals and tasksPIPA Article 15(1)4
Subscription verification and paid featuresPIPA Article 15(1)4
Statutory retention of payment and supply recordsKorea’s Electronic Commerce Consumer Protection Act, Article 6
Support and account-deletion requestsPIPA Article 15(1)4
Security, abuse prevention, and diagnosticsPIPA Article 15(1)6 (legitimate interests)
Personalized advertising and measurementPIPA Article 15(1)1 (consent)

We do not use personal information for unrelated purposes without obtaining required consent or taking other measures required by law.

2. Personal information we process

CategoryInformationCollection method
Account and authenticationProvider identifier, email, display name, profile image, sign-in providerGoogle or Apple sign-in
User contentCore and supporting goals, action items, tasks, completion records, status, color, target dates, and timestampsEntered in the app and sent when synchronization is selected
Subscription and entitlementApp, store and product identifiers; subscription status; order, transaction and original-transaction identifiers; transaction type and status; purchase, expiry and revocation timesApp Store or Google Play purchase verification
Device and serviceOS, app version, language, app-instance identifier, IP address, user agent, security and error recordsGenerated during app and server use
Advertising and consentAdvertising identifier, approximate location, impressions, interactions, and consent choicesAdvertising and consent flows
SupportContact email, inquiry, deletion request, one-time verification code, deletion-request ID, email HMAC lookup value, ownership-verification and processing recordsCollected or generated during an email or in-app request

Unsigned goals, tasks, and settings are generally stored on the device. Account-linked content is sent to the cloud after sign-in and synchronization. Kan does not collect government identifiers, health data, biometrics, or other sensitive information to provide the service.

3. Retention periods

InformationRetention
Account, authentication, and synchronized user contentUntil account deletion
Active subscription entitlementUntil account deletion or entitlement expiry, whichever occurs first
Minimum contract, withdrawal, payment, and supply recordsFive years from the transaction date, or record creation when no historic purchase time exists
On-device error recordsUp to seven days
Support, ownership-verification, and deletion-processing recordsOne year after the request is closed

To meet Korean electronic-commerce record duties, we retain only minimum transaction evidence for five years: app, store and product identifiers; order, transaction and original-transaction identifiers; transaction type and status; purchase, expiry and revocation times; the retention deadline; an app-scoped, versioned HMAC lookup value derived from email instead of the plain-text email; and an opaque deletion-request ID. The HMAC value and deletion-request ID are pseudonymous. These records are separated from customer data and exclude direct identifiers such as customer IDs, Firebase UIDs and plain-text email, as well as purchase tokens and raw receipts.

If Firebase Authentication deletion temporarily fails after remote data has been removed during a support-assisted deletion, we temporarily keep the Firebase UID and former customer number in the active deletion lifecycle so the same request can safely resume. We erase both immediately after authentication deletion and completion recording finish; neither is included in the one-year support record or the five-year statutory transaction record.

4. Destruction procedures and methods

When information is no longer needed, we permanently delete electronic files and database records so they cannot be restored. We do not retain Kan users’ personal information on paper.

Account deletion removes synchronized goals and tasks from Cloud Firestore, customer identifiers and user-generated data from Basecamp, and the sign-in account from Firebase Authentication. In-app deletion also removes that account’s local data from the device. Minimum statutory transaction records remain separated and are automatically destroyed when each five-year period ends.

Firebase Authentication information remaining in live or backup systems may take up to 180 days to be removed after our deletion request. Deleted backup data is not used for ordinary service and is destroyed when the backup expires.

5. Disclosure to third parties

We do not disclose personal information for a third party’s independent purposes. Where separate consent or law permits disclosure, we provide the recipient, purpose, fields, and retention period in advance.

6. Processing contractors

ContractorProcessing activity
Google LLCFirebase Authentication, Cloud Firestore synchronization, Firebase App Check, Google Sign-In, AdMob advertising, and UMP consent management
Apple Inc.Sign in with Apple and App Store payment, subscription, and entitlement verification

Synchronized Kan content is stored in the Seoul, South Korea Cloud Firestore region (asia-northeast3). Contractor changes are published in this policy.

7. International transfers

RecipientCountryInformationTiming and methodPurposeRetention
Google LLC (contact)United StatesSign-in identifier, email, display name, profile image, IP address, user agentEncrypted transfer during Google sign-in and authenticationAuthentication, security, abuse preventionDeletion requested at account deletion; live and backup removal may take up to 180 days
Google LLCCountries where Google operates servicesApp-integrity data, advertising identifier, approximate location, app/device data, ad interactions and consentEncrypted transfer during validation and ad requestsIntegrity, advertising, measurement, frequency capping, fraud prevention, consentApp Check tokens up to seven days and replay-protection tokens up to 30 days. Advertising logs remove part of IP addresses after 9 months and identifying information after 18 months; AdMob reports are retained for 90 or 2,555 days depending on report type
Apple Inc. (contact)United States and Apple service countriesApple identifier, email or relay email, authentication token/code, purchase and subscription identifiersEncrypted transfer during Apple sign-in or purchase verificationSign-in, disconnection, payment, subscription, entitlementDuration of the Apple account or app relationship and periods required by law

Contract-related transfers rely on PIPA Article 28-8(1)3; personalized advertising relies on consent under Article 28-8(1)1. Delete the account at Settings > Account > Delete Account, or revisit advertising choices at Settings > Ad Privacy Settings.

8. Automatic collection and behavioral information

Kan does not directly install browser cookies. Authentication, security, and advertising SDKs may process app-instance identifiers, IP addresses, user agents, advertising identifiers, approximate locations, and ad interactions for security, app integrity, advertising, measurement, frequency capping, and fraud prevention. You can revisit choices at Settings > Ad Privacy Settings and in the operating system’s privacy and advertising settings. No ad request is made in consent-required regions until the consent state permits it.

9. Rights of data subjects and representatives

You may request access, correction, deletion, suspension, or withdrawal of consent. In Kan, use Settings > Account > Delete Account and verify your identity. If you cannot use the app, follow the Kan account deletion instructions or email [email protected].

For an email request, the owner manually sends a one-time code to the Firebase-registered email address. Reply from that mailbox within 24 hours to complete verification. An unverified request never changes the account or its data. After verification, Aspado’s sole owner, with a recent reauthentication, runs the same automated deletion lifecycle as the in-app flow. Public support requests are completed within 30 days after verification, and we reply with the result.

Account deletion does not cancel an App Store or Google Play subscription; cancel it in the store. Provider authorization is also separate, so remove Kan access in Google or Apple settings if needed.

10. Personal information of children under 14

Kan does not offer account services to children under 14. If we learn that such information was processed without valid parental consent, we verify the request and delete it without undue delay.

11. Security measures

We apply least privilege, periodic access reviews, encryption in transit and at rest, token validation, app-integrity checks, protected access records, and physical access controls.

12. Privacy officer and responsible function

  • Privacy officer title: Privacy Officer
  • Responsible function: Aspado Privacy
  • Email: [email protected]

13. Remedies for infringement

Users in Korea may contact the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), Supreme Prosecutors’ Office (1301, spo.go.kr), or Korean National Police Agency (182, ecrm.police.go.kr).

14. Changes to this policy

This policy applies from August 26, 2026. Material changes will be announced before they take effect. Previous versions remain available in the version history.

Published: August 26, 2026 Effective: August 26, 2026