Privacy Policy

Effective: June 25, 2026

ILJI ("we," "us," or "our") operates the ILJI mobile application (the "Service"). This Privacy Policy explains what information we collect, why we collect it, and how we protect it.


1. Information We Collect

1-1. Account Information

DataPurposeRetention
Email addressAccount identification, login, password reset, security alertsUntil account deletion
PasswordAuthentication (stored as a one-way hash; never stored in plaintext in our database)Until account deletion
Social login identifiers (Google, Kakao, Apple)Identity verification for social sign-inUntil account deletion
Internal identifierInternal data association and access controlUntil account deletion
Display name (within teams)Member identification in team calendarsUntil account deletion
Subscription status (plan, renewal date)Pro plan entitlementUntil account deletion

1-2. Data You Enter

The following data is entered by you for your own scheduling and personal management. We process this data only as needed to provide the Service. We do not sell it or use it for advertising or marketing.

DataExamplesRetention
AppointmentsTitle, date, memo, recurring schedules, D-Day countdowns, and other scheduling information you createUntil you delete it or delete your account
ContactsName, phone, email, address, memo, etc.Until you delete it or delete your account
PhotosBefore/after comparison and other photos you attachAutomatically deleted from the server 90 days after upload
Templates & message draftsCustom forms, message text you createUntil you delete it or delete your account (message templates are stored on-device only)
Change historyWho changed what and when in your appointmentsUntil the appointment is deleted or account deletion

Third-party information: If you enter another person's contact details or appointment information into the Service, you are responsible for ensuring you have the right to do so under applicable laws. We store this data on your behalf and do not independently collect consent from those individuals.

1-3. Documents & Signatures

DataStorageRetention
Business profile (name, address, phone, email), payment instructionsEncrypted, on-device onlyCleared on logout or app removal. Never sent to our servers
Signature imageOn-device onlyLost on app removal or device change. Never sent to our servers
PDF documentsGenerated on the fly (not stored on our servers)

When you share a PDF, it may include contact information, business details, photos, and signature images. Once shared via an external app, the recipient's handling of that data is governed by their own policies.

1-4. Location

DataWhen CollectedPurposeRetention
Location coordinates, addressOnce, when you start a service timer on a team appointmentRecord of where work beganUntil the appointment is deleted
  • Location is captured once at timer start — we never track you in the background.
  • Personal appointments do not send location to our servers.
  • Your location is visible only to you, not to other team members.
  • If you deny location permission, the timer still works — it just won't record a location.

1-5. Payment Information

DataProcessed ByPurpose
Credit card and payment method detailsApple App Store / Google Play (we never receive these)In-app purchases
Purchase receipts, subscription statusUs (via RevenueCat)Pro plan entitlement

We never collect or store your card number, bank account, or other payment credentials. All payments are processed through the Apple or Google in-app purchase systems, and we only receive the transaction result (receipt identifier and subscription status) via RevenueCat.

1-6. Automatically Collected Information

DataPurposeRetention
Crash & diagnostic logs: app version, OS, device info, error detailsIdentifying and fixing app errorsPer error monitoring service retention policy
Approximate location (city-level, derived from IP)Inferred from your connection IP (not sent by the app). Used for diagnosticsPer error monitoring service retention policy
Language setting, timezoneDiagnostics, localizationPer error monitoring service retention policy

We minimize and mask personal information in diagnostic logs and process only the information needed to maintain service stability.


2. How We Use Your Information

Legal BasisApplies To
Your consentLocation permission, camera/photo permission, contacts permission
Performance of contract (providing the Service)Account data, your content, payment information, team collaboration data
Legal obligationsPayment and refund records retention
Legitimate interestsError diagnostics, fraud and abuse prevention

3. Sharing Your Information

We do not sell your data, and we do not share it for advertising or marketing purposes. We may disclose your information only in these circumstances:

  • When required by law or a valid legal process
  • With your explicit consent
  • In connection with a merger or acquisition (with prior notice)

Content you add to a team calendar is visible to other team members — this is a core feature of the Service. When you send messages or PDFs through your device's SMS app or share sheet, the data leaves our Service and is subject to the receiving app's or recipient's own policies.


4. Service Providers

We use the following third-party service providers to operate the Service:

ProviderServiceLocation
Supabase, Inc.Data storage, authentication, file managementSouth Korea (Seoul)
RevenueCat, Inc.In-app subscription managementUnited States
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsUnited States
Google LLCSign-in, address search, map display, ILJI AI (template generation & schedule analysis)United States
Kakao Corp.Sign-in, address searchSouth Korea
Apple Inc.Sign-in (Sign in with Apple)United States
Resend, Inc.Transactional email (sign-up confirmation, password reset, security alerts)Japan (Tokyo)

5. International Data Transfers

Your primary data (appointments, contacts, photos) is stored in Supabase's Seoul, South Korea data center. Some information is transferred to servers outside South Korea as described below:

DataRecipientCountryWhenRetention
Crash logs (pseudonymous ID, device/OS info, approximate location from IP)SentryUnited StatesWhen an app error occurs30 days
Subscription status, receipt identifiersRevenueCatUnited StatesOn purchase or subscription changePer RevenueCat policy
Your ILJI AI template generation promptGoogle (Gemini API)United StatesWhen you request template generationPer Google policy
Your ILJI AI schedule analysis question + schedule data with personal information removedGoogle (Gemini API)United StatesWhen you request schedule analysisPer Google policy
OAuth credentialsGoogleUnited StatesWhen you sign in with GooglePer Google policy
OAuth credentialsAppleUnited StatesWhen you sign in with ApplePer Apple policy
Address search queries, coordinatesGoogle (Places/Maps)United StatesWhen you search for an address or view a mapPer Google policy
Email address, email contentResendJapan (Tokyo)When we send transactional emails1 day

6. Your Rights

RightHow to Exercise
AccessView your data directly in the app, or contact us for a copy
CorrectionEdit your data directly in the app
DeletionDelete individual items in the app, or use "Delete Account" to remove everything
Restriction of processingContact us at the address below

7. Data Deletion

7-1. Account Deletion

When you delete your account through the app, we immediately and permanently delete or disconnect from your account:

  • All personal appointments, contacts, templates, recurring rules, D-Day items, and ILJI AI usage logs (template generation & schedule analysis)
  • ILJI AI schedule analysis conversations stored on your device (encrypted)
  • Your change history records
  • Your profile and authentication record

Photos are not deleted immediately when you delete your account. They are automatically deleted after the 90-day retention period measured from upload. Photos shared with a team may remain as part of the team's work records.

If you belong to a team, you will be removed from the team first. Data you contributed to team calendars (team appointments, team photos) remains with the team. If you are the Owner of a team with remaining members, account deletion is blocked until you transfer ownership or otherwise resolve the team. If you are the only remaining member, the team and its data are deleted as well.

7-2. Regular Deletion

  • Individual deletions: marked as deleted, then permanently removed from the server after 60 days.
  • Photos: automatically deleted from the server 90 days after upload.

7-3. Legal Retention

Where required by Korean law, certain records (such as payment and refund history) may be retained for the period specified by the applicable statute, even after account deletion.


8. Security

  • On-device encryption: Sensitive fields (contacts, memos, message templates) are encrypted and stored locally. Encryption keys are managed by the device's secure enclave.
  • Business profile protection: Your business profile and payment instructions are stored in a separate encrypted storage on your device.
  • Encryption in transit: All communications use TLS 1.2 or higher.
  • Access control: Row-level access controls on the server database ensure you can only access your own data or data belonging to your teams. File storage is accessible only through temporary access URLs.
  • Photo metadata removal: GPS and other metadata are stripped from photos at upload time.
  • Phone number hashing: Phone numbers are stored as one-way hashes for lookup purposes; plaintext search on the server is not performed.
  • Login security: Rate-limited login attempts and password reset cooldowns.
  • Error log scrubbing: Personal data patterns and sensitive fields are masked before any error log is transmitted. If scrubbing fails, the content is emptied (fail-closed).
  • Access management: The sole operator holds all administrative privileges and follows the principle of least privilege. All service management consoles are protected with two-factor authentication (2FA), and credentials are stored in an encrypted password management tool.

9. Device Permissions

PermissionPurposeIf Denied
CameraTake work photosYou can still attach photos from your gallery
Photo library (read)Select photos to attachPhoto attachment unavailable
Photo library (save)Save photos from the viewer to your deviceSaving unavailable (in-app viewing still works)
Location (while using)Record location once when starting a team service timerTimer works without recording location
Contacts (Android)Caller ID integrationCaller ID feature unavailable
NotificationsAppointment reminders (local notifications only)No reminders

All permissions are optional and can be changed at any time in your device's system settings. On iOS, contact selection uses the system picker and requires no separate permission; Caller ID uses a CallKit Directory Extension.


10. AI Features (ILJI AI)

ILJI AI provides template generation for creating work templates from natural language and schedule analysis for asking questions about your schedule. Both features use Google's AI service.

10-1. ILJI AI Template Generation

  • Sent: The natural-language prompt you type (e.g., "Create an AC repair estimate template")
  • Not sent: Other Service data that is not needed for template generation

We keep only the minimum usage record needed to manage the Service. The prompt and generated result are not stored.

10-2. ILJI AI Schedule Analysis

  • Sent: Your question and the schedule information needed for analysis, excluding sensitive information
  • Not sent: Sensitive information and photos that are not needed for analysis

Only information with sensitive details excluded is sent to the AI service. Conversations are stored only on your device and are not synced to our servers. We keep only the minimum usage record needed to manage the Service.

10-3. Important

Do not include personal information (client names, phone numbers, addresses) directly in your questions or prompts. AI results are for reference only — review and edit them before use.

10-4. Opting Out

You are not required to use ILJI AI. All regular template and schedule features work without it.


11. Children

The Service is intended for users aged 14 and older. We do not knowingly collect information from anyone under 14. If we learn that a user is under 14, we will promptly delete their account and associated data.


12. Advertising & Tracking

We do not collect advertising identifiers (ADID/IDFA), use cookies for tracking, or collect behavioral data for targeted advertising. There are no ads in the Service.


13. Automated Decision-Making

We do not make automated decisions that produce legal or similarly significant effects on you.


14. Contact Us

OperatorILJI / Business Registration No. 338-69-00732
Mail-Order Sales Registration No.제2026-인천서구-2468호
Representative / Data Protection OfficerJungwoo Cheon
Emailsupport@ilji.app
Address11F, 1103-T21, 588 Jungbong-daero, Seo-gu, Incheon, South Korea

15. Changes to This Policy

If we make changes to this policy, we will notify you at least 7 days in advance (or 30 days for material changes) through an in-app notice or email.