This English translation is provided for reference; the Korean version prevails.
Orosi Privacy Policy
Effective date: October 10, 2026
HOSI (the “Operator”) operates Orosi (오로시, the “App”), an app for recording feelings. In accordance with Article 30 of the Personal Information Protection Act of Korea, the Operator establishes and publishes this Privacy Policy to explain how users’ personal information is processed and protected, and to handle related concerns promptly.
| Item | Details |
|---|---|
| Operator | HOSI (sole proprietorship), Representative: Hoseung Kang (강호승) |
| Chief Privacy Officer | Hoseung Kang (Representative) |
| Contact | hello@orosi.day |
| Published at | https://orosi.day/privacy/ |
At a glance
- Your entries, such as journal text, feelings, and answers to questions, are stored on your device and are not sent to the Operator.
- No sign-up or login is required.
- Usage statistics are off by default. They are sent to an analytics service in the European Union (Aptabase) only if a user aged 14 or older turns them on.
- Every feature of the App works without usage statistics, and you can turn them off at any time after turning them on.
- Inquiry emails sent to hello@orosi.day pass through Cloudflare, a U.S. company, and are stored in Google’s Gmail (5-2).
1. Purposes of processing and personal information processed
The Operator processes the following personal information.
| Category | Purpose | Items | Legal basis | Retention period |
|---|---|---|---|---|
| Usage statistics (optional) | Analyzing and improving how App features are used | Items in 1-2 | User consent (Article 15(1)1 of the Personal Information Protection Act) | Up to 5 years from collection, or until the Operator deletes its management app or account at the analytics service, whichever comes first |
| Handling inquiries and rights requests | Answering inquiries; receiving, handling, and reporting the results of requests such as access, correction, deletion, or suspension of processing | Sender’s email address, name written in the email, email subject, body, and attachments, dates and times received and answered | Rights requests: compliance with legal obligations (Article 15(1)2 of the Act; Articles 35 to 38 of the Act). General inquiries: the Operator’s legitimate interest in answering inquiries (Article 15(1)6 of the Act), limited to what is needed to answer | 1 year from the date handling is completed |
Usage statistics are processed with the user’s consent. Inquiry and rights-request information is processed without consent on the bases in the table above. The Operator does not process personal information for purposes other than those above. If a purpose changes, the Operator will notify users in advance as required by law and obtain new consent where necessary.
1-1. Records processed on your device
Journal text, feelings, answers to questions, entry dates, book titles, reflections and insights, the name the App calls you, and App settings are processed on your device for recording, viewing, and reflection features. They are not sent to the Operator or to the statistics server, and the Operator does not view or keep them. The entry database is stored encrypted on the device.
The App does not use contacts, photos, the camera, the microphone, or GPS location.
1-2. Items processed for usage statistics
| Category | Items |
|---|---|
| Feature-use information sent by the App | The fact that you opened the App, turned on usage statistics, saved your first entry, reopened a past entry, opened a reflection, saved an insight, or exported. Predefined values such as text size and appearance settings and the reflection type (intermediate or book reflection) |
| Information sent along by the analytics SDK | Event time, a temporary session number kept only in memory, app version and build number, OS name and version, SDK version, whether it is a development build, and a locale value (a fixed value set by the App, unrelated to the device language) |
| Information processed by the analytics service during transmission | IP address and device connection information (User-Agent). The analytics service states that it does not store these or write them to application logs, and processes them only temporarily to derive the information below |
| Information derived and kept by the analytics service | Approximate location estimated from the IP address (country code and region; the city is not kept) and a usage identifier used only for this App that changes every day |
| Information not sent | Journal text, feelings, answers to questions, entry dates, book titles, reflections and insights, the name the App calls you, contacts, advertising ID, hardware ID, device model |
The analytics service states that it keeps, for each event, the country code and region, event time, session number, daily usage identifier, OS name and version, device model, locale, app version and build number, SDK version, and the predefined values sent by the App. Of these, the device model is stored as an empty value because the App’s analytics SDK does not send it (based on the analytics service’s published server code). Feature-use times, session records, approximate location, and the daily usage identifier remain on the server. The Operator does not treat this information as fully anonymous merely because no name is sent or the identifier changes daily, and treats it as personal information in this Policy. It is not used for personalized advertising or combined with information from other companies’ apps or websites.
2. Retention and destruction
Records on your device remain on the device until you delete them. You can delete entries one by one in the App, or erase the records in the App with Delete All in Settings or by deleting the App. Because the Operator keeps no server copy of your records, deleted records cannot be restored without a file you exported beforehand. This does not guarantee immediate and complete physical erasure from the storage medium.
Usage statistics are kept for up to 5 years from collection, or until the Operator deletes its management app or account at the analytics service, whichever comes first, and are then deleted by the analytics service. The analytics service states that collection stops immediately when the Operator deletes its management app, and that on the Operator’s request it deletes all raw statistics for this App and confirms the deletion in writing. The analytics service states that it deletes the key used to create the daily usage identifier within 48 hours of creating it. However, encrypted backups of the database containing these keys and account information are kept in the same region (Germany) for 7 days, and backups of the statistics data are managed by the sub-processor Tinybird within its EU region. The analytics service does not offer a shorter retention period. Turning off usage statistics or deleting the App does not immediately delete statistics already sent.
Inquiry and rights-request records are deleted from the mailbox without delay once 1 year has passed from the date handling was completed. Google, which provides the mailbox service, states that it generally takes about 2 months for deleted data to be completely removed from its storage systems and that data can remain in encrypted backups for up to 6 months. Cloudflare, which provides the email forwarding service, states that it does not store email content, and it keeps forwarding records for 31 days.
Personal information in electronic files is deleted in a way that cannot be recovered. Information kept by processors is deleted according to each processor’s deletion procedures.
Export files and operating system backups
In Settings you can export your records as a JSON file or import an earlier file. Export files are unencrypted plain text. You decide where to keep a file and with whom to share it. Import is processed on the device, and the Operator does not receive the file. Deleting records in the App does not delete files you have kept or shared separately.
Operating system backups are separate from the App’s export feature. If you use system backups on iOS, the encrypted entry database may be included in the backup. The Operator does not receive or manage these backup copies. Depending on the device and backup method, the encryption key that opens your records may not be restored together, so system backups alone do not guarantee recovery of your records. Deleting records in the App does not guarantee that system backup copies made earlier are also deleted.
3. Usage statistics — optional and off by default
- Statistics are sent only if you confirm that you are 14 or older and agree to send usage statistics on the last introduction screen at first launch, or choose “Send” in Settings > Usage statistics. The analytics SDK is not started and no statistics are sent before you turn it on.
- While you use the App, statistics are collected in device memory and sent over an encrypted connection (HTTPS) about once a minute or when the App moves to the background. Statistics that could not be sent are not written to device storage.
- Choosing Settings > Usage statistics > “Don’t send” withdraws your consent. When turned off, no new sends start and queued statistics are discarded. A send that had already started before you turned it off may finish. Nothing is sent at the moment you turn it off.
- Even if you do not consent or you withdraw consent, you can keep using every feature of the App, including entries, lock, and export.
- You can request access to or deletion of statistics already sent using the methods in Section 9.
4. Entrustment of personal information processing
The Operator entrusts personal information processing as follows.
| Processor | Entrusted work |
|---|---|
| Technov Solutions SRL (service name Aptabase, Romania) | Receiving, storing, aggregating, and querying usage statistics |
| Tinybird Data S.L. (Madrid, Spain) — sub-processor of Aptabase | Analytics database (storing and querying statistics; EU region: Frankfurt, Germany) |
| Amazon Web Services EMEA SARL (Luxembourg) — sub-processor of Aptabase | Cloud hosting and infrastructure (servers, receiving statistics, account information database; eu-central-1 region: Frankfurt, Germany) |
| Cloudflare, Inc. (United States) | Forwarding inquiry emails sent to hello@orosi.day to the Operator’s mailbox (Cloudflare Email Routing) |
| Google LLC (United States) | Receiving and storing inquiry emails (Gmail) |
The Operator entrusts processing to Aptabase under the Data Processing Agreement (DPA) included in the Aptabase terms of service. The agreement provides, among other things, that processing takes place only within the scope and purposes set by the Operator, that technical and organizational safeguards are applied, and that sub-processors are bound by the same obligations. The list of sub-processors can also be found in Annex IV of the agreement, and Aptabase is required to notify the Operator 30 days in advance when it adds or replaces a sub-processor.
Cloudflare’s Data Processing Addendum and list of sub-processors are available on Cloudflare’s website. Gmail is provided under Google LLC’s Terms of Service and Privacy Policy. If a processor changes, the Operator will update this Policy without delay.
5. Transfer of personal information outside Korea
The Operator transfers personal information outside Korea (entrustment of processing and storage) in the following two cases.
5-1. Usage statistics (optional)
| Item | Details |
|---|---|
| Legal basis for the transfer | Article 28-8(1)5 of the Personal Information Protection Act. On September 16, 2025, the Personal Information Protection Commission recognized that the level of personal information protection in the member states of the European Union (EU) and the countries of the European Economic Area (EEA) is substantially equivalent to that of the Act. On October 8, 2026, the analytics service replied to the Operator’s inquiry that these statistics are processed in Germany and Romania, both of which are EU member states |
| Items transferred | The usage statistics items in 1-2 (feature-use information, analytics SDK information, IP address and device connection information, and the approximate location and daily usage identifier derived from them) |
| Destination countries | Germany (receiving statistics and application servers, analytics storage and querying, account information and keys, and backups — the AWS eu-central-1 region and the Tinybird EU region in Frankfurt) and Romania (operations and support access by Technov Solutions SRL staff), based on the analytics service’s reply of October 8, 2026. Aptabase states that statistics in its EU region, including those handled by sub-processors, are processed and stored only within the EU and are not transferred outside the EU |
| Time and method of transfer | While usage statistics are on, sent about once a minute or when the App moves to the background, over the internet through an encrypted connection (HTTPS) |
| Recipient and contact | Technov Solutions SRL (service name Aptabase, Romania) · privacy inquiries support@aptabase.com · company contact office@technov.ro. Sub-processors: Tinybird Data S.L. (Madrid, Spain) and Amazon Web Services EMEA SARL (Luxembourg); the contact point given by the analytics service is support@aptabase.com (Section 4) |
| Recipient’s purpose of use | Receiving, storing, aggregating, and querying App usage statistics for the Operator (providing the analytics service) |
| Retention and use period | Up to 5 years from collection, or until the Operator deletes its management app or account, whichever comes first |
| How to refuse the transfer, procedure, and effect | If you do not consent to usage statistics at first launch, or choose Settings > Usage statistics > “Don’t send”, no further transfer takes place. You can use every feature of the App even if you refuse. Statistics already transferred remain for the retention period above, and you can request deletion and other actions using the methods in Section 9 |
If the analytics service changes where it processes the statistics so that they are processed outside the EU or EEA, the Operator will determine a new legal basis for the transfer, take the necessary measures, such as introducing a separate consent procedure, and update this Policy.
5-2. Inquiry emails
| Item | Details |
|---|---|
| Legal basis for the transfer | Article 28-8(1)3(a) of the Personal Information Protection Act (entrustment of processing and storage needed to handle inquiries and rights requests in the service relationship with users, disclosed in this Policy) |
| Items transferred | The inquiry information in the table in Section 1 (sender’s email address, name written in the email, email subject, body, and attachments, date and time received) and email forwarding records (sender and recipient addresses, subject, message ID, forwarding date and time, sender authentication results, processing status) |
| Destination countries | Cloudflare: Cloudflare, headquartered in the United States, receives and immediately forwards emails on its network operated around the world. Cloudflare states that it primarily stores information in the United States and the European Economic Area (EEA) and may access it from around the world for its operations. Google: Google states that it maintains servers around the world and that information may be processed on servers outside the country where you live. As of October 7, 2026, the countries of the operating data centers published by Google are the United States, Chile, Uruguay, Taiwan, Japan, Singapore, Ireland, the Netherlands, Denmark, Finland, Germany, Belgium, and the United Kingdom. Google does not state separately in which of these countries Gmail data is stored |
| Time and method of transfer | When a user sends an email to hello@orosi.day, it is forwarded through Cloudflare and stored in the Operator’s Gmail mailbox via internet email transmission |
| Recipients and contacts | Cloudflare, Inc. (United States, 101 Townsend Street, San Francisco, CA 94107) · privacyquestions@cloudflare.com. Google LLC (United States, 1600 Amphitheatre Parkway, Mountain View, CA 94043) · Google privacy inquiries |
| Recipients’ purposes of use | Cloudflare: forwarding emails and checking them to prevent spam and phishing emails from being forwarded. Google: receiving and storing emails |
| Retention and use period | Cloudflare: email content is not stored, and forwarding records are kept for 31 days. Google: until the Operator deletes the email 1 year after the date handling is completed (after deletion, generally about 2 months until complete removal from Google’s storage systems, and up to 6 months in encrypted backups) |
| How to refuse the transfer, procedure, and effect | If you do not want the transfer, you can choose not to send an email. Viewing, editing, deleting, and exporting entries and turning off usage statistics can be done in the App without email. However, inquiries and rights requests about statistics already sent are currently accepted only by email, so these requests cannot be received if you do not send an email |
6. Provision of personal information to third parties
The Operator does not provide users’ personal information to third parties. The entrustment and transfers outside Korea in Sections 4 and 5 are arrangements for processing on the Operator’s behalf and differ from provision to third parties.
7. Installation, operation, and refusal of automatic collection tools
The App includes an analytics SDK (Aptabase React Native SDK) for usage statistics. The SDK does not use cookies, advertising IDs, or hardware IDs. It starts only if the user turns on usage statistics, and it keeps the temporary session number and unsent statistics only in memory without writing them to device storage. The feature that automatically sends error details is not turned on. The way to refuse is described in Section 3.
8. Measures to ensure the security of personal information
- The entry database on the device is stored encrypted.
- The App checks that only predefined events and values are sent as statistics, and does not send an event if it contains a value that is not allowed.
- Statistics are sent only over an encrypted connection (HTTPS).
- In its data processing agreement, the statistics processor provides for measures such as encryption of data in transit and at rest, restricted access to production systems with multi-factor authentication, separation of data by app, and backups and monitoring.
- The Operator limits access to the statistics management screen and the inquiry mailbox to the Chief Privacy Officer.
The screen lock prevents others from seeing the screen and is separate from encryption of stored data. Users must manage the device lock, the files they export, and the protection of other apps and storage. The Operator does not guarantee security or physical erasure in every device environment.
9. Rights of users and legal representatives and how to exercise them
- You can view, edit, delete, and export records on your device directly in the App. The Operator does not hold these records, so you do not need to ask the Operator.
- You can withdraw consent to usage statistics at any time in Settings > Usage statistics > “Don’t send”.
- To request access to, correction or deletion of, or suspension of processing of usage statistics already sent and inquiry information, please email hello@orosi.day. The Chief Privacy Officer receives and handles requests directly and will notify you of the result within 10 days of receiving the request. If a request is handled only in part, postponed, or refused, the Operator will also tell you the reason and how to object.
- The Operator forwards requests about usage statistics to the analytics service (support@aptabase.com) and receives its support under the data processing agreement. Usage statistics contain no name, contact information, or account information, and the analytics service states that it cannot find a specific user’s statistics on its own and has no feature for deleting only a specific user’s statistics. The daily usage identifier and session number cannot be seen in the App, and the key used to create the identifier is deleted within 48 hours, so it may be difficult for both the Operator and the analytics service to find a specific user’s statistics. If individual action is difficult, the Operator will tell you the reason, consider possible measures such as deleting all statistics for this App, and notify you of the result.
- The Operator asks only for the minimum information needed to confirm that the requester is the person concerned or a legitimate representative, and does not ask for journal content or export files.
- You can also exercise your rights through a legal representative or a person you have authorized. In that case, the Operator may ask for material confirming the authorization.
- Requests for access and suspension of processing may be restricted under Article 35(4), Article 37(2), and other provisions of the Personal Information Protection Act.
- If you disagree with the result, you can object by emailing hello@orosi.day, and the Operator will review the matter again and notify you of the result.
10. Personal information of children under 14
Orosi is not primarily intended for children under the age of 14, and the Operator does not operate a procedure for obtaining the consent of a legal representative to process the personal information of children under 14. Usage statistics can be turned on only by users aged 14 or older, so children under 14 should not turn them on. Records on the device are not sent to the Operator, so they can be used regardless of age. If the Operator becomes aware that statistics from a child under 14 have been sent, it will check with the analytics service and take necessary measures such as deletion.
11. Chief Privacy Officer and handling of concerns
The Operator has designated the following Chief Privacy Officer, who oversees personal information processing and handles users’ inquiries, complaints, and remedies for damage. The Chief Privacy Officer also personally handles privacy work, concerns, and rights requests.
| Item | Details |
|---|---|
| Chief Privacy Officer | Hoseung Kang (Representative) |
| Contact (email) | hello@orosi.day |
The Operator will answer and handle inquiries without delay.
12. Remedies for infringement of rights
If a matter cannot be resolved through the Operator, or if you need counseling or dispute resolution about an infringement of personal information, you can file a report or request counseling with the institutions below (Korean services).
- Personal Information Dispute Mediation Committee: 1833-6972 (in Korea, no area code), www.kopico.go.kr
- Personal Information Infringement Report Center: 118 (in Korea, no area code), privacy.kisa.or.kr
- Korean National Police Agency: 182 (in Korea, no area code), ecrm.police.go.kr
13. Changes to this Privacy Policy and where to find it
- This Privacy Policy applies from October 10, 2026.
- This Policy is continuously published at https://orosi.day/privacy/ and can also be opened from Settings > Privacy Policy in the App. This English reference translation is at https://orosi.day/en/privacy/. If the two versions differ, the Korean version prevails.
- When this Policy changes, the Operator will post the changes and the effective date on this page and publish previous versions together with the periods in which they applied.
- Changes that significantly affect users’ rights, such as changes to the items processed, purposes of processing, entrustment, or transfers outside Korea, will be announced before they take effect on this page and in the app update notes, together with a table comparing the content before and after the change. Changes that require new consent under the law will be applied only after consent is obtained again in the App.
- Previous privacy policies: none (first version)