D-Day Keep Privacy Policy
First Published: May 21, 2026 · This Revision Published: August 25, 2026
CodeSand Co., Ltd. (the "Company") treats the personal information of users of D-Day Keep (the "Service") with care and complies with applicable law, including the Personal Information Protection Act of Korea. This Policy is written so that Users can see what information the Company collects, when, where it is sent, what it is used for, and when it is erased.
All core features of the Service are available without signing up. Signing in is optional, for cloud backup, multi-device synchronization, and the like. In this Policy, "User" means anyone who uses the Service regardless of whether they have signed up, "Member" means a signed-in User, and "Guest" means a User who uses the Service without signing in (the same as Article 1 of the Terms of Service).
1. Personal Information Collected
Common to all of the below: the information below is transmitted over the network at the time the User uses the feature concerned. The Company does not collect precise location (GPS), contacts, call or message logs, health information, payment-instrument information such as credit card numbers, or unique identifying information such as resident registration numbers. The app does not request location permission.
NameMembers only
- Items collected
- The nickname or profile name provided by the social account. For Sign in with Apple, the name provided once at first sign-in
- When collected
- When signing in with a Kakao, Google, or Apple account
- Sent to · stored by
- Supabase Inc. (United States / Singapore)
- Purpose of use
- Member identification and profile display. The Company does not perform real-name verification.
Email AddressMembers · when contacting us
- Items collected
- ① The email address of the social account (where that account has consented to provide it) ② A reply email address the User enters when submitting an inquiry or bug report (optional)
- When collected
- ① When signing in ② When an inquiry or bug report is submitted
- Sent to · stored by
- ① Supabase Inc. ② The inquiry-intake server operated by the Company (Republic of Korea)
- Purpose of use
- Member identification, replying to inquiries
Email addresses are removed from error diagnostics ("Crash Data" below) before transmission.
Photos or VideosOnly when the User selects them
- Items collected
- ① Photos set as the background of a D-Day ② Screenshots attached to an inquiry or bug report (up to 3, optional). Videos are not collected.
- When collected
- When the User selects a photo directly from the device's photo library. Background photos are uploaded regardless of whether the User has signed up.
- Sent to · stored by
- ① Supabase Inc. storage ② The inquiry-intake server operated by the Company
- Purpose of use
- Displaying background photos, multi-device synchronization and restoration after reinstalling the app, responding to inquiries
The Company does not access photos the User has not selected, and does not attach screen captures to error diagnostics.
Other User ContentWhat the User enters
- Items collected
- The title, date, time, icon, color, theme, pinned state, and notification settings of a D-Day; D-Day information created via a share link; the title and content of inquiries and bug reports
- When collected
- Members: synchronized to the server when a D-Day is registered or edited. Users who have not signed up: stored only inside the device and not synchronized to the server. However, if a share link is created, the information of that D-Day is stored on the server regardless of whether the User has signed up.
- Sent to · stored by
- Supabase Inc. / inquiry content goes to the inquiry-intake server operated by the Company
- Purpose of use
- Cloud backup and multi-device synchronization, provision of share links, responding to inquiries
Statistical analytics and error diagnostics do not include content entered by the User, such as D-Day titles and memos.
User IDAll Users
- Items collected
- The service account identifier (including the anonymous account identifier issued automatically on first launch of the app where the User has not signed up), the user identifiers issued by Kakao, Google, and Apple, and the per-installation identifier included in error reports
- When collected
- On first launch of the app (automatic issuance of the anonymous account), when signing in, and when an error occurs
- Sent to · stored by
- Supabase Inc. / Functional Software, Inc. (Sentry)
- Purpose of use
- Per-user data isolation, Member identification, de-duplication of error reports
Member identifiers are not passed to statistical analytics (Firebase Analytics).
Device IDAll Users
- Items collected
- The app instance identifier that the analytics tool issues automatically for each app installation, and the Android advertising identifier (AAID)
- When collected
- When the app is launched, and when an advertisement is displayed (Android)
- Sent to · stored by
- Google LLC (United States)
- Purpose of use
- Preventing duplicate counting in statistical analytics, delivery of advertisements
On iOS the Company does not request App Tracking Transparency (ATT) consent and therefore does not collect or use the advertising identifier (IDFA). On Android, ad personalization can be turned off in the device settings.
Coarse LocationCountry, region, and city level
- Items collected
- ① The country, region, and city inferred from the connection IP when an error report is transmitted ② The language and country values set on the device (for example, KR) ③ The country and region estimated from the connection IP in the course of analytics and ad processing
- When collected
- ① When an error occurs ② When the app is launched ③ When analytics events are sent and when advertisements are displayed
- Sent to · stored by
- ① Functional Software, Inc. (Sentry) ② Supabase Inc. ③ Google LLC
- Purpose of use
- Understanding the environment in which an error occurred, usage statistics by country, delivery of advertisements
The app does not request location permission and does not collect precise location such as GPS. Error reports do not store the IP address itself; only the country, region, and city inferred from the IP are recorded.
Purchase HistoryStored only on the device
- Items collected
- The type of Paid Product purchased, and whether the ad-removal entitlement is held
- When collected
- When a Paid Product is purchased or a purchase is restored
- Sent to · stored by
- Stored only inside the device; not transmitted to the Company's servers. The parties that hold the payment and the purchase history are the Apple App Store and Google Play.
- Purpose of use
- Applying the ad-removal entitlement
The seller of Paid Products is each App Marketplace, and the Company does not collect or store payment-instrument information such as credit card numbers. Purchase restoration is carried out on the basis of the App Marketplace account.
Product InteractionAll Users · cannot be turned off
- Items collected
- Screen navigation and feature-usage events (registering, deleting, and decorating a D-Day, the D-Day category selected, changes to notification settings, changes of language or theme, onboarding progress, sign-in method, adding a widget, account deletion, and the like), user properties (the theme selected, the app language, the band of the number of D-Days registered), and the usage environment recorded when the app is launched (OS type, app version, device language and country settings, number of installed widgets)
- When collected
- When the app is launched, and when the feature concerned is used
- Sent to · stored by
- Google LLC (Firebase Analytics) / the usage environment goes to Supabase Inc.
- Purpose of use
- Improvement of the Service, analysis of usage statistics
Collection of this item cannot currently be turned off inside the app. If you do not want it to be collected, please stop using the app and delete it. The events do not include content entered by the User, such as D-Day titles.
Crash DataOnly when an error occurs
- Items collected
- The type, message, and stack trace of the error, the time of occurrence, the app version and release identifier, the device model and OS version, the screen-navigation trail immediately before the error, and tags indicating where the error occurred
- When collected
- Transmitted only when an error occurs in an app distributed through the stores. Nothing is transmitted in normal use.
- Sent to · stored by
- Functional Software, Inc. (Sentry, Germany EU region)
- Purpose of use
- Ensuring the stability of the Service, analyzing the causes of errors
Screenshots are not attached, email addresses and IP addresses are removed before transmission, and performance data tracking how fast the app runs is not collected.
Other Diagnostic DataWhen an inquiry is submitted
- Items collected
- The app version, OS version, device model name, language selected in the app, and sign-in method, attached automatically to an inquiry or bug report (including the Member identifier where the User is signed in)
- When collected
- When an inquiry or bug report is submitted
- Sent to · stored by
- The inquiry-intake server operated by the Company (Republic of Korea)
- Purpose of use
- Reproducing the problem and responding to the inquiry
The information needed for notifications and home screen widgets to work is processed only inside the device and is not transmitted separately.
2. Purpose of Use of Personal Information
The Company uses the personal information it collects only for the following purposes, and where a purpose changes it will give notice in advance and obtain any consent required.
- Identification and authentication of Members
- Provision of the Service — D-Day countdowns, cloud backup, multi-device synchronization, notifications, home screen widgets, D-Day sharing
- Provision of Paid Products (ad removal, support) and restoration of purchases
- Delivery of advertisements
- Improvement of the Service and analysis of usage statistics
- Ensuring the stability of the Service and analysis of errors
- Responding to customer inquiries and handling disputes
- Prevention of fraudulent use and security of the Service
The Company does not use the D-Day information and photos registered by Users for advertising or marketing purposes.
3. Retention and Use Period, and Destruction
a. Where a Member has deleted their account
When you run Settings → Account → Delete Account in the app, the following information is destroyed without delay. It cannot be recovered.
- All D-Days stored on the server
- All uploaded background photos
- The list of D-Days stored inside the device, and the notification and widget settings
In addition, the linkage with the Kakao and Google accounts is released and the sign-in session is ended.
The following information is not deleted immediately by the account-deletion procedure alone; it is destroyed at the times set out below.
- Share link records — expire 90 days after the date of creation and are automatically deleted from the server within 7 days after expiry.
- The account record (sign-in identifier, email, name) and usage-environment statistics — are not deleted by in-app account deletion alone. If you make a request to the data protection officer in Section 11, they will be destroyed without delay once your identity has been verified.
b. Where the Service is used without signing up
The Service automatically issues an anonymous account when the app is first launched. Only the minimum information needed for authentication — an anonymous identifier and the times of creation and access, for example — is recorded in that account; information by which the User could be identified, such as a name or email address, is not included.
The list of registered D-Days is stored only inside the device and is not synchronized to the server, so it disappears when the app is deleted. However, where a background photo has been set or a share link created, that photo and the D-Day information are linked to the anonymous account and stored on the server.
If a User who has been using the Service without signing up later signs in, a new Member account is issued and the list of D-Days stored on the device is moved to the new account. The former anonymous account is then no longer used, but its record and the photos linked to it remain on the server.
The Company does not currently apply a separate automatic destruction standard to anonymous account records. Anonymous account records do not contain information by which the User could be identified, and the Company does not use them for any purpose other than providing the Service. If you want a photo linked to an anonymous account deleted, deleting the background photo of the D-Day concerned in the app deletes it from the server as well.
c. Items with a fixed period
- Error diagnostics — destroyed 30 days after collection.
- Share links — expire 90 days after the date of creation and are deleted within 7 days after expiry. If the User deletes the D-Day concerned in the app, the link is withdrawn at that moment.
d. Items retained under applicable law
- Records of consumer complaints or dispute handling (including inquiries and bug reports) — 3 years (the Act on the Consumer Protection in Electronic Commerce, etc. of Korea)
- Other information whose retention is required by applicable law — the period specified by that law
Payment and refund records for Paid Products are retained by the Apple App Store and Google Play, the sellers, in accordance with their own policies and applicable law; the Company does not hold them.
e. Method of destruction
Information in the form of electronic files is permanently deleted by a method that makes it impossible to recover or reproduce.
4. Provision of Personal Information to Third Parties
The Company does not provide Users' personal information to third parties. The following are exceptions.
- Where the User has consented in advance
- Where there is a provision in applicable law, or where an investigative authority makes a request for investigative purposes in accordance with the procedures and methods prescribed by law
Where the content of a D-Day is shown to the other party through a share link that the User created and sent themselves, that is disclosure by the User's own choice, not provision to a third party by the Company.
5. Outsourcing of Personal Information Processing
The Company outsources the processing of personal information to the following providers in order to provide the Service. The Company requires the safe management of personal information through its outsourcing agreements, and where a processor or the content of the outsourced work changes, it will disclose this through this Privacy Policy.
- Outsourced task
- Operation of the authentication server, storage of user data and photos, handling of share links
- Location
- United States / Singapore
- Outsourced task
- Kakao account sign-in authentication
- Location
- Republic of Korea
- Outsourced task
- Google account sign-in authentication, delivery of AdMob advertisements, analysis of app usage statistics and remote app configuration, processing of Google Play in-app purchases
- Location
- United States
- Outsourced task
- Apple ID sign-in authentication, processing of App Store in-app purchases
- Location
- United States
Functional Software, Inc. (Sentry)Privacy Policy ↗ - Outsourced task
- Collection and analysis of error diagnostics
- Location
- Germany (Sentry EU region)
The sellers of Paid Products are the Apple App Store and Google Play, which process payments in accordance with their own terms and privacy policies. The Company does not collect or store payment-instrument information. Detailed transfer information for providers whose processing location is outside Korea is set out in Section 6.
6. Overseas Transfer of Personal Information
In the course of providing the Service, the Company transfers personal information outside Korea as described below. These transfers fall under outsourced processing and storage for the conclusion and performance of a contract with the data subject under Article 28-8(1)(iii) of the Personal Information Protection Act of Korea, and disclosure of the following through this Privacy Policy serves in place of the required notice.
Timing and method of transfer (common to the providers below): transmitted over the network from time to time, at the moment the User uses the feature concerned. Error diagnostics, however, are transmitted only when an error occurs. Each provider's contact point can be found via the Privacy Policy link on its card.
- Country
- United States / Singapore
- Items
- Account identifier (including the anonymous account identifier), email address, nickname or profile name, D-Day information, uploaded photos, notification and widget settings, usage environment (OS, app version, device language and country settings, number of installed widgets), share link information
- Purpose
- Operation of the authentication server, cloud backup and multi-device synchronization, provision of share links
- Retention
- The same as the periods set out in Section 3.
- Country
- United States
- Items
- The user identifier and email address on Google sign-in, the app instance identifier, the Android advertising identifier (AAID), app usage records and user properties, device information, app version, and the country and region estimated from the connection IP
- Purpose
- Sign-in authentication, delivery of AdMob advertisements, analysis of usage statistics, remote app configuration, processing of Google Play payments
- Retention
- Until termination of the outsourcing agreement or fulfillment of the purpose of use
- Country
- United States
- Items
- Apple user identifier, email address (where the User has consented to provide it), name (where provided at first sign-in)
- Purpose
- Apple ID sign-in authentication, processing of App Store payments
- Retention
- Until termination of the outsourcing agreement or fulfillment of the purpose of use
Functional Software, Inc. (Sentry)Privacy Policy ↗ - Country
- Germany (Sentry EU region). The recipient is a U.S. company.
- Items
- The type, message, and stack trace of the error, the time of occurrence, the app version and release identifier, the device model and OS version, the screen-navigation trail immediately before the error, tags for where the error occurred, the per-installation identifier, and the country, region, and city inferred from the connection IP
- Purpose
- Ensuring the stability of the Service and analyzing errors
- Retention
- 30 days after collection
A User who does not wish their personal information to be transferred outside Korea may express that refusal to the data protection officer in Section 11. However, refusing overseas transfer limits the use of features that rely on the server, such as cloud backup, multi-device synchronization, and D-Day sharing.
7. Advertising Identifiers and Personalized Advertising
The Service displays AdMob advertisements to Users who have not purchased the ad-removal product.
- Android — Google AdMob may use the advertising identifier (AAID) to personalize advertisements. Users can turn off ad personalization or reset the advertising identifier in the device settings.
- iOS — the Company does not request App Tracking Transparency (ATT) consent and therefore does not collect or use the advertising identifier (IDFA). Should we introduce it in future, we will obtain consent in advance.
For details, please refer to the Google Privacy Policy.
8. User Rights and How to Exercise Them
Users may exercise the following rights at any time.
- Request access to their personal information
- Request correction where there is an error
- Request deletion
- Request suspension of processing
- Delete their account (withdraw consent)
They may be exercised in the following ways.
- Directly in the app — deleting an individual D-Day or background photo in the app deletes it from the server as well. Deletion of the entire account is available at Settings → Account → Delete Account.
- By email — if you make a request to the data protection officer in Section 11, we will handle it without delay once your identity has been verified and reply with the result.
The legal representative of a child under 14 years of age may exercise the above rights on the child's behalf. Where the Company receives a request for access, correction, deletion, or suspension of processing and there is legitimate cause under applicable law to restrict that request, it will inform you of that cause.
9. Measures to Secure Personal Information
The Company implements the following measures.
- Access control — row level security (RLS) policies are applied to the database so that a User can access only the data belonging to their own account.
- Isolation of storage — uploaded photos are kept in private storage, separated into per-account folders, and no one can access another User's folder.
- Encryption in transit — all communication between the app and the server is encrypted with TLS.
- No passwords are kept — the Service uses social sign-in only, so the Company neither collects nor keeps Users' passwords.
- No handling of payment-instrument information — payment is processed by the App Marketplace, and the Company's systems do not handle payment-instrument information.
- Protection of share links — the address of a share link is generated as an unguessable random string and expires once its validity period has passed.
- Minimization of error diagnostics — email addresses and IP addresses are removed from error reports before transmission, screenshots are not attached, and content entered by the User is not included.
10. Personal Information of Children under 14
The Company does not accept sign-ups from children under 14 years of age. If it becomes aware that the personal information of a child under 14 has been collected, it will destroy that information without delay.
11. Data Protection Officer and Remedies for Infringement of Rights
The Company has designated a data protection officer. Users' inquiries and complaints about the processing of personal information, remedies for harm, and requests for access are handled by the department below.
- Department: Privacy Team, CodeSand Co., Ltd.
- Email: dkeep@reply.codesand.co.kr
- In-app: Settings → Report a Bug / Feature Request
- Hours: Weekdays 10:00–18:00 (KST, excluding public holidays)
To obtain relief for infringement of personal information, Users may apply for dispute resolution or counseling to the following bodies.
- Personal Information Dispute Mediation Committee — 1833-6972 (kopico.go.kr)
- Privacy Infringement Report Center (KISA) — 118, no area code (privacy.kisa.or.kr)
- Supreme Prosecutors' Office — 1301, no area code (spo.go.kr)
- National Police Agency Cyber Investigation Bureau — 182, no area code (ecrm.police.go.kr)
12. Changes to This Policy
Effective Date: August 25, 2026 (originally effective May 21, 2026)
The content of this Policy may be added to, deleted from, or modified in line with changes in law, policy, or the Service; where it is changed, the reason and the effective date will be stated and posted on the Service website.
© 2026 CodeSand Co., Ltd. Business Registration No. 368-87-03020.