Effective Date: 2026-08-07 · Last Modified: 2026-08-07
1. Summary
For easy reading, here is a summary first. See the sections below for details.
| Stored only on your device | Daily self-assessment records, card completion logs, completion rates, practice responses |
| Stored on our servers | Account information, content posted to the social feed/chat, anonymous usage statistics |
| Sale / advertising use | We do not. We do not use health-related information for advertising or marketing, and we do not sell it to third parties |
| Advertising / tracking SDKs | Not used |
| Deletion | You can delete your account and data within the app |
2. Information Stored Only on Your Device and Never Transmitted
The following is stored only on your device and is never transmitted to the Company's servers.
- Daily self-assessment — your responses to six items: arousal, mood, energy, calm, clarity, and comfort
- Card completion log — which cards you completed and when
- Completion rate — the percentage of that day's assigned items you completed in each of the body, mind, and social domains
- Practice responses — the answers you write for social practice cards
Storage method: an encrypted local database (Android: Room / iOS: GRDB, with SQLCipher applied). Recommendation calculations are also performed on your device, and no data is sent externally during this process.
If you delete the app, this information is deleted from your device along with it, and the Company cannot recover it.
3. Information Stored on Our Servers
3.1 Account Information
- Email address, information you enter in your profile (e.g., display name)
- If you sign in with a Google account, the identifier and email provided by Google
- Purpose: creating, authenticating, and maintaining your account · Legal basis: performance of contract
3.2 Content You Post (Social Feed and Chat)
- Posts, comments, chat messages, report records
- Purpose: providing the Service, safety management · Legal basis: performance of contract, legitimate interest (safety)
- ⚠️ Chat messages pass through our servers in order to be delivered to the recipient. This is not end-to-end encryption.
3.3 Usage Statistics
- Statistics based on an anonymous identifier (install_id), such as onboarding progress events
- Not linked to your account and does not identify you personally.
- Purpose: improving the Service · Legal basis: legitimate interest
3.4 Pre-Registration Email (Pre-Launch)
- The email address collected via our landing page, and referral information (language, referral campaign)
- Purpose: sending a one-time launch notification · Legal basis: consent
- This list is configured so that it cannot be queried externally at the system level.
4. Information We Do Not Collect
In the interest of transparency, the Company does not collect the following:
- Location data · contacts · photos/camera · microphone recordings
- Advertising identifiers (such as IDFA)
- Apple Health (HealthKit) and Health Connect data — we do not integrate with these
- Activity on third-party apps or websites
We do not use advertising SDKs or tracking SDKs. Accordingly, the Service does not display an iOS tracking-permission prompt.
5. Handling of Health-Related Information
Because BioHACK is a health and wellness service, much of the information you enter may constitute health information or sensitive information under applicable law.
The Company commits to the following:
- We do not sell health-related information.
- We do not use health-related information for advertising or marketing purposes, and we do not provide it to third parties for those purposes.
- Where required by law, we obtain separate, explicit consent.
The Company is not a Covered Entity under the U.S. HIPAA. BioHACK is not a medical institution and does not provide medical services.
6. Third-Party Disclosure and Processing Entrustment
The Company does not sell personal information. To the extent necessary to operate the Service, we entrust processing to the following:
| Processor | Processing Activity | Location |
|---|---|---|
| Supabase | Authentication, database, realtime communication | Japan (Tokyo) — AWS ap-northeast-1 |
| Account sign-in (OAuth) | United States, among others | |
| Cloudflare R2 | Audio content delivery (download only) | Global CDN |
| Apple / Google | Payment processing (upon introduction of subscriptions) | Each company's own policies |
We may provide information to relevant authorities where required by law, or where necessary to prevent an imminent risk to life or bodily safety.
7. Cross-Border Transfer
Users' personal information is stored in Japan. In accordance with Article 28-8 of the Personal Information Protection Act of Korea (PIPA), we provide the following disclosure:
| Item | Details |
|---|---|
| Recipient of transfer | Supabase, Inc. (contact channel published at supabase.com/privacy) |
| Country of transfer | Japan — Amazon Web Services Tokyo region (ap-northeast-1) |
| Timing and method of transfer | Continuously during use of the Service, via encrypted transmission over telecommunications networks |
| Items transferred | All items collected as listed in Section 3 above (account identifier, email, profile, activity records, posts, chat) |
| Purpose of use | Providing the Service, including authentication, data storage, and realtime communication |
| Retention period | Until account withdrawal or termination of the processing agreement |
In addition, Google account sign-in (OAuth) is processed in the United States, and audio content delivery is processed through Cloudflare's global CDN. The CDN only delivers content and does not store account information, but your connecting IP address is processed during transmission.
If you do not wish to consent, your use of the Service may be limited — because our storage infrastructure is located outside Korea, we cannot provide account functionality without this transfer.
When transferring personal information of EU residents, we rely on Standard Contractual Clauses (SCCs) or another lawful transfer mechanism.
Raw measurement data is not transferred outside Korea. Raw sensor data — such as heart rate and sleep data — as well as audio and video, are stored only on your device and are never sent to our servers (ADR-0004). The items listed above under "Items transferred" are account and activity records.
8. Retention Period
- Account information: for as long as your account remains active. Deleted without delay upon request (deletion from backups may take up to 30 days)
- Posts and messages: deleted together when you delete them. However, where necessary for handling a report or dispute, retained until that purpose is achieved
- Usage statistics: anonymized and retained for statistical purposes
- On-device records: deleted together when you delete the app
9. Your Rights
Regardless of where you reside, you may request the following:
- Access — confirm what information we hold about you
- Correction — correction of inaccurate information
- Deletion — deletion of your account and related information
- Restriction of / objection to processing — request that specific processing be stopped
- Portability — receive your information in a machine-readable format
- Withdrawal of consent — stop processing that is based on consent
How to delete your account 1. In the app: iOS — Me tab → Delete Account · Android — Profile → Delete Account 2. Without the app installed: https://biohack.iaiu.net/delete-account
Deleting your account also deletes your account information, posts, and chat messages. If you have a subscription, you must cancel it separately, through the App Store or Google Play, for billing to stop.
Submit requests to: support@iaiu.net
10. Children's Personal Information
The Service is intended for users 16 and older. We do not knowingly collect personal information from anyone under 16, and if we become aware that we have done so, we delete it immediately.
11. Security
- Encryption in transit (TLS)
- On-device database encryption (SQLCipher)
- Minimized access privileges and row-level security policies
However, no method of transmission or storage can guarantee complete security.
12. Region-Specific Additional Notices
- EU / UK (GDPR): The legal basis for processing is indicated in each section above. You have the right to lodge a complaint with a supervisory authority.
- U.S. — California (CCPA/CPRA): We do not sell personal information or share it for behavioral advertising purposes. You may request that we limit the use of sensitive information.
- U.S. — Washington (My Health My Data), Nevada (SB 370): We do not sell or share consumer health data without consent.
- Republic of Korea: You have the right to request access, correction, deletion, and suspension of processing under the Personal Information Protection Act.
13. Changes
If the Company changes this Policy, it will notify you via in-app notice. Material changes will be announced at least 30 days before they take effect.
14. Contact
Data Protection Officer: Kim Chang-myoung (Representative) Email: privacy@iaiu.net Address: 17 Bundang-ro 201beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea (Seohyeon-dong) [경기도 성남시 분당구 분당로201번길 17 (서현동)] Business Entity: IAIU · Business Registration Number 213-08-81338