PRIVACY NOTICE

Privacy Policy

Effective date: 2026-09-16

The Zzazan team (the "Operator") establishes and discloses this privacy policy to protect the personal data of users of Zzazan (the "Service") and to comply with applicable law.

The Operator's purpose is to store and share family photos safely, and processes only the minimum personal data necessary for that purpose.

This English text is a convenience translation. The Service is operated under the laws of the Republic of Korea, and the Korean version prevails in the event of any discrepancy.

Article 1 (Categories of personal data processed)

1. To operate your account (required, regardless of consent)

ItemFormNotes
Social login account identifierStored only as a cryptographic hashThe raw identifier issued by the provider is not retained
Anonymous (guest) account identifierAn opaque value issued by the serverIssued when you start without signing in; no social provider details or email address are attached to it (see 1-2)
Device registration identifierAn opaque value generated by the appHardware identifiers (IMEI and the like) are not collected
Consent historyType, notice version, time of consent, screen where consent was given, time of withdrawalArticle 4
Service usage recordsTime and type of request (actor and target are hashed)Automatically deleted after 90 days

1-2. If you use the Service without signing in (guest)

You can start using the Service without a social sign-in. In that case the only thing created on the server is an anonymous account and its identifier; no social provider details or email address are attached to it.

  • Photos and videos, face analysis results, and child information are stored only on your device and are never sent to a server. Cloud storage, family sharing, and server sync are not available to guests, and that restriction is enforced by the server.
  • Accordingly, while you are a guest no consent to original backup or child information sync is requested, and no consent record is created — there is as yet no processing for such a consent to refer to (Article 5).
  • If you link a social account, the same account carries over (the account identifier is preserved); original backup and child information sync are turned on by default upon linking (Article 1(2)(3)). If an account already exists for the social account you link, you are signed in to that existing account and the guest account is discarded; the two accounts are never merged. Either way, the data stored on your device remains.
  • Data that exists only on your device cannot be restored from the server. Deleting the app deletes it too.
  • Guest accounts that go unused are subject to cleanup (Article 7).

Usage statistics (Article 6(4)) are sent from the app directly to Google on the same terms for guests, and can be turned off in the app settings.

1-3. Error diagnostics (collected automatically)

When the app terminates unexpectedly or a core operation fails, diagnostic data is sent from the app directly to Google (Firebase Crashlytics) so the cause can be found. The Operator's servers neither collect nor relay this data.

  • App version and build, operating system version, device model, runtime environment
  • Crash stack traces, session identifier, installation identifier (Firebase Installation ID)
  • The kind of operation that failed and its cause code, HTTP status, retry count, and approximate connectivity (offline, low data, cellular, Wi-Fi)

The list above is closed — nothing outside it is included. What is excluded, and how long the data is kept, is set out in Article 6(5).

1-4. If you contact us

When you write to us through the contact form on the web (zzazan.ai/en/contact), the following is processed. The app's "Contact us" opens the same page.

  • The email address for our reply, and your message
  • Device details you type in yourself (device model, OS version, app version) — optional
  • The inquiry topics you selected

Messages sent through the contact form reach our support team via Google Forms (Google LLC) (Article 6(2)(3)), and are destroyed without delay once the reply is complete (Article 7). Please do not include photos, videos, or information about your child in an inquiry.

2. If you use original backup (provided by default once a social account is linked)

Original backup is a premise of the Service, provided by default to accounts that have linked a social account. No separate consent screen is shown; consent to this clause is recorded when the account is prepared, and the consent history keeps the screen of origin as "default setting"(Article 5(1)). If you do not want backups, simply do not run one (automatic upload is off by default); nothing below is stored on the server until you back up.

  • Original photo and video files, and converted images used for display
  • Backup management data (file size, integrity hash, version history)
  • Shared album composition data
Original files keep their capture metadata (EXIF) intact. That may include the capture time, device information, and capture location coordinates. The Operator stores originals exactly as uploaded and does not alter them.

3. If you use child information sync (on by default once a social account is linked — can be turned off in Settings)

Child information sync is on by default for accounts that have linked a social account. No separate consent screen is shown; consent to this clause is recorded when the account is prepared, with "default setting" as the screen of origin (Article 5(1)). A guardian can turn it off at any time in the app settings, and doing so deletes the items below from the server immediately (Article 4(4)). If no child is registered, there is nothing to sync.

  • Your child's name, nickname, date of birth, reference time zone, and relationship to the guardian
  • Links between photos and the child, along with tags, place labels, and growth records

3-2. Only if you use a paid subscription

This section applies only where a paid subscription product is offered in the app. While the app has no purchase or plan entry point, the item below is not processed; from the moment subscription products are offered, it is handled as follows.

ItemFormNotes
Subscription purchase recordsTransaction data issued and signed by Apple (product tier, transaction identifier, expiry date)Processed only to determine subscription status and apply your storage quota. Received from Apple; contains no payment instrument details

You can cancel a subscription in iOS Settings ▸ Apple Account ▸ Subscriptions, or from the Storage screen in the app (Manage subscription). Refunds follow Apple's refund process. Once a cancellation or refund takes effect, your storage quota returns to the free tier, and purchase records are handled under Article 7.

4. What the Operator does not collect

  • Any face recognition data — face feature values, face crop images, and detection coordinates exist only on the user's device and are never transmitted to a server.
  • Email addresses from social accounts are neither matched nor stored, and separate social accounts are never merged into one account automatically.
  • Previous values of edited child information — these are not retained in any form, including records and logs.
  • Raw search terms, a child's name and date of birth, and precise location are never written to logs.
  • Payment instrument data (such as card numbers) — paid subscriptions are processed by the Apple App Store; the operator never receives payment instrument details.

Article 2 (Purposes of processing)

PurposeItems processed
Member identification, sign-in, account managementArticle 1(1)
Maintaining the anonymous account of a user who started without signing inArticle 1(1)(1-2)
Photo and video backup and restoreArticle 1(2)
Sharing photos with family and managing permissionsArticle 1(2)
Organizing photos per child and growth recordsArticle 1(3)
Automatic organization by capture regionLocation coordinates in originals (Article 3)
Determining subscription status and applying the storage quota (where subscriptions are offered)Article 1(3-2)
Service stability and abuse preventionUsage records (hashed)
Diagnosing errors and improving stabilityArticle 1(1-3)
Handling your inquiry and replying to itArticle 1(1-4)

The Operator does not use personal data for purposes beyond those above, and will obtain consent in advance should a purpose change.

Article 3 (Processing of location data)

  1. The Operator does not perform real-time location tracking. Your movement history and current position are neither collected nor accumulated.
  2. Capture location coordinates contained in photo originals are retained together with the originals when you back up the originals (Article 1(2)).
  3. Automatic organization by capture region (for example "Aewol, Jeju") is computed solely inside the Operator's servers, and no coordinates are sent to external map or place services for that computation. The only location data the server keeps separately is one representative coordinate per photo group.
  4. If you allow the device location permission, the photo map screen uses your current position only to choose where the map opens. That position is used on the device alone — it is never stored, never attached to photos, and never sent to a server. If you decline the permission, the map still opens, framed around all of your photos. The map itself is rendered by Apple Maps built into the device.

Article 4 (Children's personal data)

  1. The Service exists so that a guardian can store and share photos and information about their own child. The party who signs up and uses the Service is the guardian (an adult); children do not create accounts themselves.
  2. A guardian signing in with a social account, using the app, and registering their child's information themselves (the subject of "Child information sync" — name, nickname, date of birth and the like) is treated as consent of the legal representative. The Operator provides the Service on the premise that the guardian holds legal custody of the child.
  3. Child information sync is on by default once a social account is linked, and no separate consent screen is shown (Article 1(3), Article 5(1)). A guardian can turn it off at any time in the app settings, and the remaining features, including photo backup, keep working while it is off. Features that need child information — server search, automatic organization by capture region, and sharing a child's profile with a family group — do not work while it is off.
  4. When a guardian turns child information sync off (withdrawal of consent), child information held on the server is deleted immediately, with no grace period.
  5. The Operator does not market to children, nor use children's data for profiling or advertising. Face recognition data is never stored on a server.

Article 5 (Consent and withdrawal)

  1. Original backup and child information sync are provided by default to accounts that have linked a social account (Article 1(2)(3)); consent to both is recorded without a separate consent screen when the account is prepared, and those records keep "default setting" as their screen of origin. When you turn child information sync off or back on yourself in the app settings, that record carries the settings screen as its origin, which distinguishes it from the default setting. The server rejects consent records that carry no screen of origin.
  2. Each consent record retains which screen it was given on and the version of the notice text shown at the time.
  3. While you use the Service as a guest (without signing in), no consent regarding server storage is requested and no consent record is created. Once you link a social account, original backup and child information sync are recorded by default under Article 1(2)(3) (Article 1(1-2)).
  4. You may turn child information sync off at any time in the app settings (withdrawal of consent). The app has no withdrawal setting for original backup.
    • Turning child information sync off: child information held on the server is deleted immediately, with no grace period. (Data on your device and originals already backed up are retained.)
    • Original backup: if you do not want backups, simply do not run one. Originals already backed up are handled under Article 7 when you delete them individually or delete your account. If you want original backup processing to stop, you may request it through the contact in Article 10.
  5. When this policy is amended, we announce it through the in-app notice described in Article 11. Because neither original backup nor child information sync has a consent screen, there is no re-consent procedure. If you do not agree with an amendment, you can turn child information sync off in the app settings and request that original backup processing stop through the contact in Article 10.

Article 6 (Provision to third parties, entrustment, and transfer abroad)

1. Provision to third parties

The Operator does not provide your personal data to third parties. However, photos are disclosed to family members you yourself invite to a shared album, within the permissions you set (view, download, edit, re-share) — this follows from your own choice. When you cancel a share or revoke a permission, access is blocked immediately.

2. Entrusted processing

ProcessorEntrusted workData location
Amazon Web ServicesStorage and delivery of photo and video filesRepublic of Korea (Seoul)
Apple Inc.In-app purchase (App Store) processing and subscription managementApple global infrastructure, including the United States
SupabaseDatabase, authentication, and server function hostingRepublic of Korea (Seoul)
Google LLC (Google Analytics for Firebase, Firebase Crashlytics)Usage analytics and error diagnosticsGoogle global data centers, including the United States
Google LLC (Google Forms)Receiving submissions from the web contact formGoogle global data centers, including the United States

Until a paid subscription is offered, no entrustment to Apple Inc. takes place. Once subscriptions are offered, processing follows the scope in the table above (Article 1(3-2)).

3. Notice regarding transfer abroad

Your photos and information are stored within the Republic of Korea (Seoul). However, a global content delivery network (CDN) is used to deliver photos quickly, and in that process transmitted data may pass through, or be temporarily cached at, points of presence outside Korea.

ItemDetails
Data transferredPhoto and video files you requested (for delivery purposes only)
Destination country and processorAmazon Web Services global points of presence (varies by request location)
Timing and methodWhen you view or download a photo, over encrypted connections
Purpose and retentionFaster delivery — temporary caches expire within 24 hours

Even cached files are reachable only through requests bearing a temporary address valid for 60 seconds, and the Operator does not store those addresses.

Google's tools (Google Analytics for Firebase and Firebase Crashlytics) are also used for usage statistics and error diagnostics, which involves the following transfer abroad.

ItemDetails
Data transferredThe usage statistics listed in Article 6(4) and the error diagnostics in Article 1(1-3) (photos and videos, child information, precise location, and raw search terms are not included)
Destination country and processorGoogle LLC (Google global data centers, including the United States)
Timing and methodIntermittently during app use, over encrypted connections
Purpose and retentionService improvement, usage statistics, and error diagnostics — event data 2 months, user-level identifiers 14 months (reset on activity), error diagnostics 90 days

Inquiries submitted through the web contact form are likewise transferred abroad, as follows.

ItemDetails
Data transferredYour email address, your message, and any device details you typed in
Destination country and processorGoogle LLC (Google global data centers, including the United States)
Timing and methodWhen you send the inquiry, over an encrypted connection
Purpose and retentionHandling your inquiry and replying to it — destroyed without delay once the reply is complete

4. Additionally

Product usage statistics are sent directly from the app to Google via the analytics tool (Google Analytics for Firebase); the Operator's servers neither collect nor relay analytics data.

CategoryDetails
CollectedUsage statistics such as screen views, feature usage counts and durations, app version, device model and operating system, approximate region (IP-based), app instance identifier, session information
Not collectedPhotos and videos, a child's name and date of birth, precise location, raw search terms, the advertising identifier (IDFA)
PurposeUnderstanding service usage and improving features (no advertising, marketing, or profiling)

Retention

CategoryRetentionNotes
Usage statistics (events)2 monthsDeleted automatically per the GA data retention setting
Usage statistics (user-level identifiers)14 monthsThe retention period resets while the app is in use

Sending usage statistics can be turned off at any time in the app settings, and transmission stops immediately once it is off.

5. Error diagnostics (Firebase Crashlytics)

Error diagnostics are likewise sent from the app directly to Google; the Operator's servers neither collect nor relay them.

CategoryDetails
CollectedThe items in Article 1(1-3) — app and device environment, crash stack traces, the kind of operation that failed and its cause code, and the like
Not collectedA child's name and date of birth, face recognition data, location, raw search terms, original photos and videos, download tokens and signed file addresses, raw account and device identifiers, the advertising identifier (IDFA)
PurposeKeeping the Service stable and finding the cause of errors (no advertising, marketing, or profiling)
Retention90 days — deleted automatically per the Crashlytics retention policy

Article 7 (Retention period and destruction)

SubjectPeriodMethod
Deleted photosPermanently deleted after 30 daysThe 30 days are fixed by system constraints and cannot be shortened arbitrarily. Recovery is possible at any point within those 30 days
Child information (on withdrawal of consent)Deleted immediatelyNo grace period
On account deletionFully deleted after a 30-day grace periodCancellable during the grace period. While it lasts, only your own download and cleanup are allowed and family access is blocked immediately
Unused guest accountsCleaned up when left unusedOnly the anonymous account data on the server is deleted; data stored on your device is not erased. The 30-day grace period for account deletion does not apply
Re-registration restriction data30 daysOnly a hash value is kept, to prevent immediate re-registration after account deletion
Subscription purchase records (where subscriptions are offered)Destroyed without delay once the subscription endsRetained for the statutory period where applicable law requires it. Payment instrument data is never stored in the first place (Article 1(4))
Service usage records90 daysExist only in hashed form and are deleted automatically
Inquiry content and email addressDestroyed without delay once the reply is completeSubmissions received through the web contact form (Article 1(1-4))
Error diagnostics90 daysDeleted automatically per the Crashlytics retention policy (Article 6(5))
Consent historyFor the life of the accountEvidence of consent and withdrawal. Deleted together when the account is fully deleted

Destruction method: electronic files are deleted irrecoverably, and the actual files in storage are deleted as well (including a step that verifies their absence afterwards).

Lifetime of face recognition data stored on your device

As stated in Article 1, face feature values and related face recognition data exist only on your device and are never sent to the server. Their lifetime on the device is as follows.

  • Face recognition data is deleted together with the app when you delete the app. It may, however, be included in device backups you have set up (such as iCloud); keeping or deleting those backups is managed by you and your backup provider.
  • Deleting a child profile does not delete the face recognition data stored on the device. This is so that photos reconnect immediately if you register the same child again.
  • To delete all face recognition data on the device, delete the app. iOS removes all of the app's local data along with it.

Article 8 (Your rights and how to exercise them)

You may do the following at any time.

  • Access and correct your personal data (directly in the app)
  • Turn child information sync off (withdraw consent) (app settings) — original backup has no withdrawal item in the app settings and follows Article 5(4)
  • Delete photos and restore them within 30 days
  • Delete your account (cancellable during the 30-day grace period)
  • Sign out (app settings) — you sign out on each device from the app on that device. If you need to cut off access from a device you no longer have, contact us at the address below

For requests that are hard to complete inside the app, contact us at the address below and we will act without delay and report back.

Article 9 (Security measures)

  • All data is separated per account, and access to anything other than your own data is blocked at the database level (deny-by-default).
  • Social account identifiers and the actor information in usage records are stored only as hashes, so the originals cannot be reconstructed.
  • File access is possible only through temporary addresses with a short validity period, and revoking a permission blocks access already in progress.
  • Connections are encrypted, and server access rights are limited to the minimum scope.

Article 10 (Privacy contact)

If you need advice about an infringement of your personal data, you may contact the following Korean authorities.

  • Korea Internet & Security Agency, Privacy Infringement Report Center (privacy.kisa.or.kr / 118)
  • Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
  • Supreme Prosecutors' Office, Cyber Investigation Division (spo.go.kr / 1301)
  • Korean National Police Agency, Cyber Bureau (ecrm.police.go.kr / 182)

Article 11 (Changes to this policy)

If this policy changes, we will announce it in the app at least 7 days before the effective date (30 days for material changes). Changes are communicated through the in-app notice and the revision history on this page; because neither original backup nor child information sync has a consent screen, there is no re-consent procedure (Article 5(5)).