DOT / SERVICE POLICY
Privacy Policy
Effective: September 22, 2026 · Last updated: September 22, 2026
pause (the “Operator”) explains below the personal data processed in the dot app and its introduction website, the purposes and retention periods, and how users can exercise their rights. This Policy applies to personal records created by users and information processed while providing the service.
1. Operator and privacy contact
Service: dot / Operating brand: pause
Privacy and rights requests: support@pauselabs.app
Send privacy inquiries and requests for account deletion, access, correction, or suspension of processing to this address. We perform only the identity checks necessary for the request. Do not send your login password, full payment card number, or entire journal text.
2. Data processed and purposes
| Feature | Data processed | Purpose |
|---|---|---|
| Accounts and login | App account identifier; social login provider and identifier; email, name, and profile information supplied by the provider; authentication sessions and tokens | Distinguishing accounts, maintaining login, checking access rights, and account management |
| Personal reflections | Situation text, answers to CBT questions, emotion type, initial and reassessed intensity, creation and modification times, service date, time zone, and optional representative keyword | Saving, viewing, editing, and deleting personal records; analyzing emotional changes, keywords, days of the week, and time periods |
| Stars, calendar, and bookmarks | Stars linked to records, representative records for each date, and bookmark status | Displaying a personal universe, viewing the calendar, bookmarking, and searching records |
| Writing limits and ad rewards | Account identifier, usage count, credit grants and consumption, reward request tokens and transaction identifiers, and verification status | Managing the free allowance and rewarded-ad credits; preventing duplicate rewards and abuse |
| Subscriptions | App user identifier, product and subscription identifiers, purchase, expiration and renewal status, transaction information, and verification results | Checking Premium eligibility, restoring purchases, and handling payment inquiries |
| Advertising SDK | IP addresses, device and advertising identifiers, interactions such as ad views and clicks, and app/device diagnostics. Actual data may vary with the SDK, operating system, and consent status | Delivering and measuring ads, verifying rewards, diagnosing errors, and preventing fraud |
| Optional reminders | Reminder enabled status, hour and minute, and notification permission status stored on the device | Scheduling, changing, and canceling end-of-day reminders using device time |
| Inquiries | Email address, inquiry content, information attached by the user, and minimal necessary verification information | Responding to inquiries, verifying accounts, handling rights requests and disputes |
| Access and security | IP addresses, request times, error and access information, security and rate-limit records processed by server and hosting services | Providing the service, responding to outages, limiting abnormal requests, and maintaining security |
Information required for accounts and storage is used to provide those features. Keywords, bookmarks, reminders, and content users choose to write are optional. Basic journaling is available without reminders or keywords. dot does not directly collect full payment card numbers or social account passwords.
3. Collection methods and legal grounds
Information is collected through user input, social login providers, app stores and subscription verification services, advertising SDKs, and the processing of service requests. We process information only as necessary on a lawful basis applicable to the processing, such as entering into or performing the service contract, meeting legal obligations, or separate consent. Permissions or consent needed for optional features are explained when the feature is used.
Emotions and free-text entries may contain sensitive information, including health information. The Operator does not use this information for ad targeting. Where processing sensitive information is necessary, legal requirements must be met, including separate consent distinct from acceptance of general terms where required. Publishing this Policy does not replace consent to sensitive information processing. Avoid recording unnecessary personal information about others, such as health information, contact details, or national identification numbers.
4. Retention and erasure
- Accounts, personal records, keywords, bookmarks, and stars: Retained until account deletion or deletion of the individual record. Information no longer needed to provide the service is deleted without delay. Deleting an individual record affects that record and linked information; the account remains.
- Operational data backups: Backups containing deleted information are retained for up to seven days after deletion and then removed in sequence. These backups are for disaster recovery and do not mean that users are offered a record restoration feature. The seven-day period does not uniformly apply to transaction or security information independently retained by external providers.
- Usage counts and writing credits: Managed while the account is in use to provide the service and prevent duplicate use. Deleting a record does not restore that day’s usage allowance or consumed credits.
- Inquiries: Unnecessary information is deleted after the inquiry’s purpose is fulfilled. If legally subject to retention, such as consumer complaints or disputes, only the necessary portions are kept for the periods below.
- Device-stored information: Stored until the relevant settings are changed, drafts are cleared, data is cleared on sign-out, or app data is deleted. Data included in operating-system backups follows the user’s device and cloud settings.
Only where the Operator is subject to retention obligations under applicable laws, including Korean electronic commerce law, the following records are retained separately and erased after the required period. Entire journal texts are not retained merely on the grounds that payment records must be kept.
| Records subject to statutory retention | Period |
|---|---|
| Contracts and withdrawal from contracts | 5 years |
| Payments and supply of goods or services | 5 years |
| Consumer complaints and dispute handling | 3 years |
| Representations and advertising | 6 months |
Electronic information is deleted using methods that make recovery difficult. Paper documents, if any, are destroyed by shredding or similar methods. Information subject to mandatory retention is separated from ordinary service data, with access and purpose restrictions. We explain the grounds and scope of retention when responding to rights requests.
5. External disclosures and processing providers
Journals and CBT answers are not disclosed to other users. The Operator does not sell personal records or attach journal text to AdMob ad requests or RevenueCat subscription requests. We use the external services below for authentication, record storage, subscription verification, advertising, and website operation. We distinguish processing on our instructions from providers’ independent processing and apply legally required contracts, disclosures, and consent procedures.
- Supabase: account authentication, database, server functions, and record storage.
- RevenueCat: processing purchase information and verifying subscription eligibility.
- Google AdMob: delivering and measuring rewarded ads and verifying ad rewards.
- Google and supported Apple services: social login or store purchases. Their policies also apply to processing of the store accounts themselves.
- Cloudflare: website delivery, access request processing, and security.
Information may be disclosed within the scope of a lawful request or the user’s separate consent. If changes to purposes, data, or recipients require separate consent, we notify users and obtain that consent beforehand.
6. International transfers
Storing information on overseas providers’ servers or allowing it to be processed or accessed abroad may constitute an international transfer. For outsourced processing and storage necessary to enter into or perform a contract, we review the requirements of Article 28-8(1)(3) of Korea’s Personal Information Protection Act. For disclosures or optional processing outside those requirements, a lawful transfer basis, such as separate consent, applies. Using an overseas provider does not automatically authorize every transfer.
International transfer details under review: The table below reflects services currently used and publicly available materials. Actual contracting entities, countries used for servers, logs, and support, and provider-specific retention periods must be finalized using account contracts and project settings. Some details remain unconfirmed, so this document still requires final review before launch.
| Service, recipient, and contact | Data, purpose, timing, and method | Countries and retention status |
|---|---|---|
| Supabase Supabase, Inc. in its public DPA; the applicable contracting entity still requires confirmation privacy@supabase.com | Account and authentication information, journals and CBT answers, emotions, keywords, bookmarks, stars, credits, and subscription verification data. Encrypted network communication during authentication, storage, retrieval, synchronization, and server requests | Primary database region: Singapore. Additional processing countries for support, logs, Edge Functions, and other services require separate confirmation. Operational database data is retained until deletion/account deletion; backup policy is up to seven days after deletion. Provider-side exceptional retention periods require confirmation |
| RevenueCat, Inc. compliance@revenuecat.com | App user ID, product, transaction and subscription status, and SDK-related information. SDK/API communication during subscription checks, purchases, restoration, and transaction updates | United States and other locations described in official policies. Applicable subprocessor countries and retention periods must be finalized. Journal and CBT text is not sent. Deleting external purchase information requires a separate request procedure |
| Google AdMob Google Asia Pacific Pte. Ltd. googlekrsupport@google.com (Google’s Korean-language privacy contact) Google Privacy Policy | IP addresses, device and advertising identifiers, ad interactions and diagnostics, and reward verification tokens. Through ad SDK communication, ad use, and reward verification | Contracting entity: Google Asia Pacific Pte. Ltd. Google states that it processes personal information on servers worldwide. The countries receiving dot’s ad data remain under review; the contracting entity does not imply storage solely in Singapore. Retention depends on data type and purpose. Examples in Google’s retention policy describe anonymizing ad server logs by removing parts of IP addresses after nine months and cookie information after 18 months. These are not uniform deletion deadlines for all AdMob data. Legal obligations, security, and other grounds may require longer retention. Deleting a dot account does not immediately delete all information held by Google. Google retention policy |
| Google / Apple The entity applicable to login or store accounts requires confirmation Google / Apple | Login authentication requests and information needed for store purchases and restoration. Communication with the relevant service when a user requests login or payment | Applicable contracts and processing vary by region, store, and login method. Recipient countries and retention periods must be finalized for each service actually used |
| Cloudflare, Inc. privacyquestions@cloudflare.com | Website access information, including IP addresses, browser, requested URL, and access time. Request forwarding, content delivery, and security processing during website visits | Official policy describes processing in the United States, European Economic Area, and globally. Countries and access/security log retention periods require confirmation based on actual settings. The journal database is not sent to the website |
Send questions about international transfers, objections, or consent withdrawal requests to support@pauselabs.app. Refusing transfers necessary for authentication and record storage may prevent us from providing account-based storage. Not using optional features such as ads or reminders can limit processing associated with those features. Withdrawing consent or deleting an account does not replace cancellation of a store subscription.
Google’s AdMob GDPR guidance describes publishers and Google as separate, independent controllers. We therefore do not characterize all AdMob processing as simple outsourced storage and review the appropriate disclosure and transfer grounds under applicable law and contracts. Non-personalized ads do not, by themselves, eliminate all separate consent or notice requirements. Google’s guidance on roles
7. Advertising, identifiers, and choices
Current ad requests in the app are configured for non-personalized ads. Even non-personalized ads may process identifiers and IP addresses for measurement, security, and fraud prevention. Depending on region and consent status, a consent or privacy choices screen may appear before ads are served. Availability of a privacy choices menu depends on the advertising consent tool’s requirements.
You can manage advertising ID deletion/reset and app tracking permissions in your operating system. Menu locations vary by device and OS version. Watching ads to obtain additional writing credits is optional; basic free writing remains available without watching ads.
8. Device storage, reminders, and the website
Your device stores login state, drafts and CBT answers in progress, language and guide acknowledgement status, and reminder settings. Drafts are stored in local app storage without additional encryption, so protect your device lock and account access. Drafts not yet saved to the server differ from synchronized records and may disappear when app data is deleted.
End-of-day reminders are local notifications scheduled on the device. The current implementation does not send reminder settings or push tokens to a notification server. Notification text does not include your journal entries, keywords, or CBT answers. You can turn reminders off in the app or revoke notification permission in the operating system.
The website stores your language choice in browser storage, which you can clear in browser settings. The website code contains no separate visitor analytics or advertising scripts. Hosting and security providers may nevertheless process information when handling access requests.
9. Editing and deleting records and accounts
- Individual records: Use Edit or Delete at the bottom of the record detail screen. After confirmation, the record and linked CBT and star data are deleted.
- Account deletion: Go to Settings → Delete account in the app and follow the notices and confirmation process. Your account and linked personal records are deleted.
- If you cannot access the app: Request dot account deletion by email. Provide your login email and provider; we process the request after minimal identity verification.
Deletion cannot be undone in the app. Statutory retention and operational backups of up to seven days follow Section 4. Deleting a Supabase account and deleting transaction records held by external payment providers are different procedures. For external processors’ information, we review the request scope and legal obligations and make separate deletion requests or take necessary follow-up action. Your entire Google or Apple account is not deleted. The latest app completes account deletion after confirming cancellation of Google Play subscription renewal. App Store subscriptions require separate cancellation; you may also delete your account immediately after acknowledging that subscriptions are not automatically canceled. Canceling renewal does not automatically refund amounts already paid.
10. Your rights
You may request access, correction, erasure, suspension of processing, and withdrawal of consent for your personal data. Requests through representatives are permitted within the scope of applicable law. We verify identity or legitimate representation only as necessary and respond within statutory time limits. If legal retention obligations or other grounds prevent us from fulfilling all or part of a request, we explain the reason and available measures.
Emotion analysis is a statistical summary of records you enter. It is not a diagnosis or a feature for automated decisions that significantly affect you. We do not currently offer a feature that sends journal text to a separate AI model to generate counseling responses.
11. Security measures
We manage access to records through authentication, per-user data access restrictions, encrypted communications, and server-side authorization checks. Administrative access is limited to what work requires; security settings, logs, backups, and access to external services are reviewed. Draft encryption is described in Section 8. These measures do not mean end-to-end encryption or complete protection against every attack. If a personal data breach is confirmed, we carry out required notifications and reporting and measures to minimize harm under applicable law.
12. Children and policy changes
dot is intended for users aged 14 and older. We do not intentionally collect information from children under 14 and take measures consistent with applicable law if we become aware of such collection. Changes to this Policy are announced in the app or on the website with the effective date and key changes. Notice alone does not replace separate consent where required.
13. Contact and remedies
Privacy contact: support@pauselabs.app. In addition to seeking resolution with the Operator, you can consult official authorities for advice, reporting, and dispute mediation, including Korea’s Privacy Portal.