개인정보처리방침
Privacy Policy
시행일 · Effective: 2026-09-03
한국어
요약
메모리드는 적어 둔 것을 기기 안에 둡니다. 기억 본문, 검색어, 붙인 사진, 음성으로 말한 것은 개발자에게 전송되지 않습니다. 개발자가 볼 수 있는 서버 자체가 없습니다.
기기를 벗어나는 것은 아래 2장에 적은 다섯 가지뿐이고, 그중 둘(백업·공유)은 사용자가 직접 해야 일어납니다.
1. 기기 안에만 있는 것
다음은 어디로도 전송되지 않습니다.
- 기억 본문 — 백업을 켜지 않았다면 기기 안의 데이터베이스에만 있습니다
- 검색어 — 검색은 전부 기기 안에서 처리합니다. 검색어를 담는 통신이 없습니다
- 뜻으로 찾기에 쓰는 계산값(임베딩) — 기기 안에서 만들고 기기 안에서만 씁니다
- 음성으로 말한 것 — 기기 안의 음성 인식만 사용합니다. 소리는 녹음 파일로 남지 않고, 글자로 옮긴 뒤 사라집니다
- 붙인 사진 — 백업을 켜지 않았다면 앱 전용 폴더에만 있습니다. 다른 앱이 읽을 수 없고 갤러리에도 등록하지 않습니다. 사진에 박힌 촬영 위치·기기 정보(EXIF)는 앱이 그림을 다시 저장하면서 떨어져 나갑니다
- 무엇을 언제 열어 봤는지 — 기기 안에만 기록합니다
- 앱 잠금 — 잠금은 기기의 인증 기능을 부르는 것이고, 앱은 그 정보에 접근하지 않습니다
2. 기기를 벗어나는 것
2.1 사용 통계 (Google Analytics for Firebase) — 기본 켜짐
앱이 어떻게 쓰이는지 보려고 다음을 보냅니다.
- 지금 보고 있는 화면의 이름 (
main,search,lock같은 정해진 이름) - 정해진 목록의 동작 이름과 횟수 — 저장·수정·삭제·검색·검색 결과 0건. 검색에는 결과가 몇 건이었는지와 뜻으로도 찾았는지가 숫자로 함께 갑니다
- Google이 자동으로 덧붙이는 것 — 기기 모델, OS 버전, 앱 버전, 언어, 통신사, 도시 단위의 대략적인 위치, 앱 설치마다 만들어지는 식별자, 광고 ID
보내지 않는 것: 검색어, 기억 본문, 글자 수, 사진 장수, 어느 기억인지. 앱의 코드 구조상 이 자리에 글자를 실을 수 없게 되어 있습니다 — 숫자와 참·거짓만 지나갈 수 있습니다.
이 통계는 현재 버전에서는 끌 수 없습니다. 끄는 스위치를 준비하고 있으며, 붙는 대로 이 문단을 고치겠습니다.
2.2 Google Drive 백업 — 기본 꺼짐, 사용자가 이어야 합니다
설정에서 Google 계정을 이어 둔 경우에만 동작합니다. 저절로 돌지 않습니다 — 설정의 [백업 및 동기화]를 직접 누른 그때만 한 바퀴 돕니다.
- 보내는 곳: 사용자 본인의 Google Drive 안에, 이 앱만 접근할 수 있는 숨은 폴더(
appDataFolder). 개발자는 그 폴더를 볼 수 없습니다 - 보내는 것: 기억 본문과 붙인 사진
- 앱에서 기억을 지우면 Drive에서도 지워집니다
- 설정의 [Google Drive 연결 끊기]를 누르면 이 기기의 연결만 끊깁니다. 이미 올라간 것을 통째로 버리려면 Google Drive에서 직접 지워야 합니다
- 계정 정보는 어느 계정에 잇고 있는지 보여 주기 위한 이메일 주소만 앱 안에서 씁니다. 개발자에게 전송되지 않습니다
2.3 업데이트 확인
앱을 열 때 한 번, 새 버전이 있는지 묻습니다. 이때 나가는 것은 앱의 빌드 식별 정보(빌드 지문, 배포 채널, 지금 깔린 번들 번호, 기기마다 고정된 배포 그룹 값)와 접속 IP입니다. 업데이트를 강제할지 정하는 설정값은 Google Firebase Remote Config에서 받아 옵니다. 기억 본문과 검색어는 이 통신을 지나지 않습니다.
받는 곳: memoread-ota.memo-read.workers.dev(개발자가 운영하는 서버)와 Google Firebase Remote Config.
2.4 [공유]로 다른 앱에 보낼 때
기억을 길게 눌러 [공유]를 고르고 받을 앱을 직접 골랐을 때, 그 한 건의 본문만 그 앱으로 건네집니다. 앱 자체는 이때 통신하지 않습니다 — 안드로이드의 공유창에 글자를 넘길 뿐입니다. 넘어간 뒤의 일은 받은 앱의 방침을 따릅니다.
2.5 광고
광고는 두 자리에 섭니다 — 홈 화면 맨 아래의 배너 한 칸과 메모조회 목록 안의 카드 하나입니다. 광고를 골라 보여 주는 일은 Google AdMob이 하고, 그때 기기의 광고 ID와 기기 종류·앱 버전·대략적인 위치를 씁니다.
기억 본문과 검색어는 광고에 쓰이지 않습니다. 앱이 광고에 넘기는 값이 없습니다 — 광고는 화면에 서 있을 뿐이고, 무엇을 적었는지도 무엇을 찾았는지도 모릅니다.
광고 ID는 사용자의 것입니다. 안드로이드 설정의 개인정보 보호 → 광고에서 초기화하거나 맞춤 광고를 끌 수 있습니다.
3. 오류 보고
현재 버전은 오류 보고를 전송하지 않습니다. 앱이 죽어도 개발자에게 아무것도 가지 않습니다. 나중에 붙인다면 이 방침을 먼저 고치겠습니다.
4. 권한
| 권한 | 왜 필요한가 |
|---|---|
| 마이크 | 말한 것을 글자로 옮기는 데만 씁니다. 소리는 기기 안에서 처리하고 어디로도 보내지 않습니다. 거절해도 글로 적는 길은 그대로 열려 있습니다 |
| 인터넷 | 위 2장의 통신에 씁니다 |
| 광고 ID | Google 광고 SDK가 넣는 권한이며, 광고를 고르는 데 씁니다(2.5) |
사진 접근 권한은 요구하지 않습니다. 안드로이드의 사진 선택기가 고른 사진만 앱에 건네지므로, 앨범 전체를 볼 권한이 필요 없습니다.
5. 보관 기간과 지우는 방법
- 기억을 지우면 그 자리에서 본문·사진·계산값이 사라집니다. 휴지통이 없어 되돌릴 자리도, 본문이 기기에 남는 기간도 없습니다
- 설정의 "메모 초기화"는 자동 스냅샷과 사진 파일까지 함께 치웁니다
- 백업을 이어 두었다면 지운 것이 Drive에서도 지워집니다
- 앱을 삭제하면 기기 안의 모든 것이 함께 사라집니다. Drive에 올라간 것은 Google Drive에서 직접 지워야 합니다
- 사용 통계는 Google의 보관 정책을 따르며, 개인을 식별하는 형태로 저장되지 않습니다
6. 개발자가 볼 수 있는 것
개발자가 볼 수 있는 것은 2.1의 사용 통계와 2.3의 업데이트 확인 기록 뿐입니다. 기억 본문을 담아 둘 서버가 없으므로, 개발자는 사용자가 무엇을 적었는지 알 방법이 없습니다.
7. 제3자
- Google (Firebase Analytics) — 2.1의 통계를 처리합니다
- Google (Drive) — 2.2의 백업이 저장되는 곳입니다. 사용자 본인의 저장 공간입니다
- Google (AdMob) — 2.5의 광고를 고르고 보여 줍니다
- Google (Firebase Remote Config) — 2.3의 업데이트 판단에 쓰는 설정값을 줍니다
- Cloudflare — 2.3의 업데이트 서버가 도는 곳입니다
그 밖의 어떤 곳에도 데이터를 넘기지 않으며, 사용자가 적은 것과 찾은 것은 위 어느 곳으로도 나가지 않습니다.
8. 유럽(EEA)·영국·스위스 사용자의 권리
유럽경제지역·영국·스위스에 계신 분에게는 GDPR과 그에 준하는 법이 정한 권리가 있습니다.
- 광고에 대한 동의 — 광고를 청하기 전에 동의 창을 띄우고, 개인 정보를 맞춤 광고에 써도 되는지 묻습니다. 답을 받은 뒤에만 광고를 청합니다
- 동의 철회 — 광고 ID는 안드로이드 설정의 개인정보 보호 → 광고에서 언제든 초기화하거나 맞춤 광고를 끌 수 있습니다. 앱에 기록된 동의를 철회하려면 10장의 주소로 알려 주세요
- 열람·정정·삭제·이동·반대 — 기억 본문은 애초에 개발자에게 오지 않으므로, 그에 대한 요청은 앱 자체가 답합니다. 기억을 지우거나 앱을 삭제하면 데이터가 사라집니다. 2.1의 통계와 2.3의 기록에 대해서는 10장의 주소로 알려 주세요
- 법적 근거 — 통계와 업데이트 확인은 앱을 운영하고 개선하기 위한 정당한 이익에, 위 지역의 광고는 사용자의 동의에, Drive 백업은 계정을 이을 때 주신 동의에 근거합니다
- 이의 제기 — 거주 국가의 개인정보 감독기구에 진정을 넣을 수 있습니다
9. 어린이
이 앱은 어린이를 대상으로 만들지 않았습니다. 어린이의 정보를 알면서 수집하지 않습니다.
10. 방침이 바뀔 때
이 문서를 고치고 시행일을 갱신합니다. 기기를 벗어나는 것이 새로 생기는 변경은 앱 안에서 미리 알립니다.
11. 문의
billiard.bible.dev@gmail.com
English
Summary
MemoRead keeps what you write on your device. Your notes, your search terms, the photos you attach, and anything you say out loud are never sent to the developer. There is no server the developer could see them on.
Only the five things listed in section 2 leave your device, and two of them (backup and sharing) happen only when you do them yourself.
1. What never leaves your device
None of the following is transmitted anywhere:
- Note contents — unless you turn on backup, they exist only in a database on your device
- Search terms — all searching happens on your device. No request carries a search term
- The values used for meaning-based search (embeddings) — created on your device, used only on your device
- Anything you say by voice — only on-device speech recognition is used. Audio is not kept as a recording; it is turned into text and discarded
- Attached photos — unless you turn on backup, they stay in a private app folder. Other apps cannot read them and they are not added to your gallery. Capture location and device details embedded in the photo (EXIF) are stripped when the app re-saves the image
- What you opened and when — recorded only on your device
- App lock — the lock calls your device's own authentication; the app never sees that information
2. What leaves your device
2.1 Usage statistics (Google Analytics for Firebase) — on by default
To understand how the app is used, the following is sent:
- The name of the screen you are on (a fixed set of names such as
main,search,lock) - Event names and counts from a fixed list — save, edit, delete, search, zero-result search. A search also carries how many results there were and whether meaning-based search contributed, as numbers
- Information Google adds automatically — device model, OS version, app version, language, carrier, approximate location at city level, an identifier generated per app installation, and the advertising ID
Not sent: search terms, note contents, character counts, photo counts, or which note was involved. The app's code is structured so that no text can be placed here — only numbers and true/false values can pass through.
These statistics cannot be turned off in the current version. A switch is being prepared, and this section will be updated when it ships.
2.2 Google Drive backup — off by default; you connect it
This runs only if you have connected a Google account in Settings. It never runs on its own — one round happens at the moment you tap Backup & sync in Settings.
- Where it goes: a hidden folder inside your own Google Drive that only this app can access (
appDataFolder). The developer cannot see that folder - What is sent: note contents and attached photos
- Deleting a note in the app also deletes it from Drive
- Disconnect Google Drive in Settings disconnects this device only. To discard what has already been uploaded, delete it yourself in Google Drive
- The only account information used is the email address, shown so you can see which account is connected. It is not transmitted to the developer
2.3 Update checks
Once when you open the app, it asks whether a newer version exists. What leaves the device is build identification (build fingerprint, release channel, the bundle number currently installed, and a rollout-group value fixed per device) plus your connecting IP address. The configuration values that decide whether an update is required are fetched from Google Firebase Remote Config. Note contents and search terms do not pass through these requests.
Recipients: memoread-ota.memo-read.workers.dev (a server operated by the developer) and Google Firebase Remote Config.
2.4 Sharing to another app
When you press and hold a note, choose Share, and pick an app yourself, only that one note's text is handed to that app. The app itself does not make a network request here — it passes text to Android's share sheet. What happens afterwards is governed by the receiving app's policy.
2.5 Advertising
Ads appear in two places: a banner at the bottom of the home screen, and a card inside the notes list. Google AdMob chooses and serves these ads, using your device's advertising ID, device type, app version, and approximate location.
Note contents and search terms are not used for advertising. The app passes no values to the ad system — the ads simply sit on the screen and know neither what you wrote nor what you searched for.
The advertising ID belongs to you. You can reset it or opt out of personalised ads in Android Settings → Privacy → Ads.
3. Crash reports
The current version does not transmit crash reports. If the app crashes, nothing is sent to the developer. If this is added later, this policy will be updated first.
4. Permissions
| Permission | Why it is needed |
|---|---|
| Microphone | Used only to turn speech into text. Audio is processed on your device and is not sent anywhere. If you decline, writing by hand still works |
| Internet | Used for the communications described in section 2 |
| Advertising ID | Added by the Google Mobile Ads SDK and used to serve ads (see 2.5) |
No photo access permission is requested. Android's photo picker hands the app only the photos you select, so permission to see your whole gallery is not needed.
5. Retention and deletion
- Deleting a note removes its contents, photos, and computed values at that moment. There is no trash, so there is nothing to restore and no period during which the contents remain on the device
- Reset notes in Settings also clears automatic snapshots and photo files
- If backup is connected, deletions are applied in Drive as well
- Uninstalling the app removes everything on the device. Anything uploaded to Drive must be deleted in Google Drive yourself
- Usage statistics follow Google's retention policy and are not stored in a form that identifies you
6. What the developer can see
The developer can see only the usage statistics in 2.1 and the update-check records in 2.3. There is no server holding note contents, so the developer has no way to know what you wrote.
7. Third parties
- Google (Firebase Analytics) — processes the statistics in 2.1
- Google (Drive) — where the backup in 2.2 is stored; this is your own storage
- Google (AdMob) — selects and serves the ads in 2.5
- Google (Firebase Remote Config) — supplies the update rules in 2.3
- Cloudflare — hosts the update server in 2.3
No data is passed to anyone else, and what you write and what you search for go to none of the above.
8. Your rights in the EEA, the UK, and Switzerland
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR and equivalent laws give you rights over your personal data.
- Consent for advertising. Before ads are requested, you are shown a consent form and asked whether your data may be used for personalised advertising. Ads are requested only after you answer
- Withdrawing consent. You can reset or opt out of the advertising ID at any time in Android Settings → Privacy → Ads. To withdraw consent recorded in the app, contact the address in section 11
- Access, correction, deletion, portability, and objection. Because note contents never reach the developer, requests about them are answered by the app itself — deleting a note or uninstalling the app removes the data. For the statistics in 2.1 and the records in 2.3, contact the address in section 11
- Legal basis. Statistics and update checks rely on legitimate interest in operating and improving the app; advertising in the regions above relies on your consent; Drive backup relies on the consent you give when connecting your account
- Complaints. You may lodge a complaint with your national data protection authority
9. Children
This app is not directed at children. The developer does not knowingly collect information from children.
10. Changes to this policy
This document will be updated and the effective date revised. Changes that introduce something new leaving your device will be announced inside the app beforehand.
11. Contact
billiard.bible.dev@gmail.com