개인정보 처리방침
최종 업데이트: 2026-10-10
이 앱은 사진과 영상을 기기 안에 모아 두고 다시 보는 보관함입니다. 운영: 라임하우스(Limehouse). 보관함의 사진·영상·태그·점수는 기기 안에 있고(빼지 않으면 iPhone·iCloud 기기 백업에도 들어갑니다. 아래 4), 운영자의 서버로 보내지 않습니다. 계정이 없고, 광고·추적 도구와 외부 분석 도구를 쓰지 않습니다. 끌 수 있는 주간 사용 통계(아래 1)만 직접 집계합니다.
1. 기기 밖으로 나가는 정보
- 문제 신고와 성능 보내기: 사용자가 직접 보낼 때만 나갑니다. 적은 내용, 기기의 브라우저 정보(iOS 버전과 기기 종류), 보낸 시각, 직전에 앱에서 일어난 일의 종류와 시간(화면 종류, 오류 종류, 측정값)만 담기고, 성능 보내기에는 앱 빌드 번호도 담깁니다. 파일 이름, 경로, 태그, 캡션, 사진·영상과 그 미리보기는 담기지 않고, 항목을 가리키는 값은 그 신고 안에서만 통하는 가짜 번호(
~1같은)로 바뀝니다. 운영자가 문제를 고치는 데만 씁니다. - 주간 사용 통계: 앱을 어떻게 쓰는지 알기 위해, 한 주에 한 번 그 주의 요약을 보냅니다. 기본으로 켜져 있고 설정 › 개인정보의 "사용 통계 보내기"로 끌 수 있습니다(끄면 아직 보내지 않은 주의 기록도 바로 지웁니다). 담기는 것: 어느 주인지(예: 2026년 45주), 앱 빌드 번호, 그 주에 앱을 연 날 수, 점수·좋아요·북마크를 한 날 수, 전에 본 항목을 다시 연 날 수, 보관함 항목 수의 구간(예: 50~199개), 그 주에 가져온 항목 수의 구간, 프리미엄 여부, 정해진 기능 목록(피드, 뷰어, 상세, 태그, 편집, 잠금, 휴지통, 데스크탑 연결, 백업, 설정, 프리미엄 안내) 각각을 쓴 날 수. 사용자나 기기를 가리키는 번호가 없어 주와 주를 이을 수 없고, 사진·영상·파일 이름·태그·캡션, 날짜와 시각, 기기 모델, 언어는 담기지 않습니다. 서버는 같은 값의 요약끼리 개수만 더해 두고 접속 IP를 기록하지 않습니다. 테스트 빌드(TestFlight, 개발 빌드)는 보내지 않습니다.
- 데스크탑 연결: 같은 Wi-Fi의 데스크탑 브라우저로 보관함을 볼 때, 두 기기가 서로를 찾도록 연결 정보(기기의 로컬 네트워크 주소·포트, 그 연결 동안 쓰는 접속 토큰, 기기가 그 컴퓨터를 기억하게 하는 무작위 연결 번호)가 중계 서버를 지나갑니다. 중계 서버는 이를 저장하지 않습니다. 사진·영상과 백업 파일은 중계 서버를 지나지 않고 같은 네트워크 안에서 기기와 데스크탑 사이로만 오갑니다.
- 공유로 받은 이미지: Safari 등에서 이미지를 길게 눌러 이 앱으로 공유하면, 앱이 그 이미지 하나를 그 이미지가 있는 사이트에서 직접 내려받습니다(브라우저가 이미지를 여는 것과 같고, 쿠키·로그인 정보를 쓰지 않습니다). 그 사이트는 다른 다운로드처럼 접속 IP를 봅니다. 이미지와 그 주소는 운영자의 서버로 보내지 않습니다.
2. 기기 안에서만 쓰는 권한
- 사진 보관함: 사용자가 고른 사진·영상을 가져오고, 원하면 가져온 원본을 사진 보관함에서 지웁니다.
- 카메라: 데스크탑 연결 QR을 읽을 때만. 촬영한 화면은 저장하지 않습니다.
- Face ID: 잠금 해제. 얼굴 정보는 Apple이 기기 안에서 처리하고 앱은 성공 여부만 받습니다.
- 로컬 네트워크: 데스크탑 연결.
3. 처리 위탁
- Cloudflare: 중계 서버, 문제 신고 접수, 주간 사용 통계 집계. 요청을 처리하는 동안 접속 IP를 봅니다.
- GitHub: 문제 신고를 운영자만 보는 비공개 저장소에 보관합니다.
- Apple: 앱 배포(TestFlight, App Store).
정보를 판매하지 않습니다.
4. 백업과 삭제
보관함은 기기 안에 있으니, 앱을 지우면 보관함도 지워집니다. 데스크탑 연결의 백업 받기로 만든 파일은 사용자의 데스크탑에만 있습니다. iOS 기기 백업(iCloud 백업 포함)을 켜 두었다면 보관함이 기본으로 그 백업에 들어가고, 그 백업은 Apple의 방침을 따릅니다(iCloud 백업은 고급 데이터 보호를 켜야 Apple도 열어 볼 수 없습니다). 설정 › 개인정보의 "기기 백업에서 빼기"를 켜면 보관함이 기기 백업에서 빠집니다. 보낸 문제 신고의 삭제는 아래 이메일로 요청하면 처리합니다. 주간 사용 통계는 누구의 것인지 가리킬 값이 없어 개별로 찾아 지울 수 없습니다.
5. 문의
개인정보 관련 문의·삭제 요청: hello@limehouse.studio
6. 변경
본 방침이 바뀌면 이 페이지의 최종 업데이트 날짜를 갱신합니다.
Privacy Policy
Last updated: 2026-10-10
The app keeps your photos and videos on your device so you can look back at them. Operated by Limehouse. Your vault (photos, videos, tags, scores) stays on your device (and in your iPhone or iCloud backups unless you exclude it, see section 4) and is never sent to our servers. There are no accounts, no ads, no tracking and no analytics SDKs; the only usage data is the weekly statistics below (section 1), which you can turn off.
1. What leaves the device
- Problem reports and performance snapshots, only when you send one: the text you type, your device's browser string (iOS version and device type), when it was sent, and the kinds and timing of recent events (screen type, error type, measurements); performance snapshots also carry the app build. No file names, paths, tags, captions, photos, videos or thumbnails; any value that points at an item is replaced by a pseudonym (like
~1) valid only inside that report. Used only to fix problems. - Weekly usage statistics, to learn how the app is used: once a week, a summary of the past week. On by default; turn it off in Settings › Privacy ("Send usage stats"), which also deletes any week not yet sent. It contains: which week (e.g. 2026 week 45), the app build number, the number of days the app was opened, days with a score, like or bookmark, days an earlier-seen item was opened again, the vault size as a range (e.g. 50–199 items), the number of items added that week as a range, whether Premium is active, and for a fixed list of features (feed, viewer, detail, tags, edit, lock, trash, desktop connection, backup, settings, Premium screens) the number of days each was used. There is no id for you or your device, so weeks cannot be linked to each other; no photos, videos, file names, tags, captions, dates or times, device model or language. The server only adds up counts of identical summaries and does not log the connecting IP. Test builds (TestFlight, development) never send it.
- Desktop connection: to let a desktop browser on the same Wi-Fi find your device, connection details (local network address and port, an access token valid for that session, and a random pairing id that lets your device remember the computer) pass through our relay, which does not store them. Photos, videos and backup files never pass through the relay; they travel only between your device and your desktop on your network.
- Images you share into the app: when you long-press an image in Safari (or another app) and share it to the app, the app downloads that one image directly from the site that hosts it, as a browser would, without cookies or logins. That site sees your IP address as with any download. Neither the image nor its address is sent to our servers.
2. Permissions used on the device only
- Photo library: import the items you pick and, if you ask, delete the imported originals.
- Camera: scan the desktop connection QR code; nothing is saved.
- Face ID: unlock; Apple handles face data on the device and the app only learns success or failure.
- Local network: desktop connection.
3. Processors
- Cloudflare: the relay, report intake and the weekly statistics counts; sees the connecting IP while handling a request.
- GitHub: stores problem reports in a private repository only the operator can read.
- Apple: app distribution (TestFlight, App Store).
We do not sell any information.
4. Backups and deletion
Deleting the app deletes the vault. Backup files made with the desktop connection live only on your desktop. If iOS device backup (including iCloud Backup) is on, the vault is included in that backup by default, which follows Apple's policy (iCloud Backup is readable by Apple unless Advanced Data Protection is on). Turning on "Exclude from device backup" in Settings › Privacy leaves the vault out of device backups. To delete a report you sent, email us. Weekly statistics carry nothing that identifies whose they are, so they cannot be found and deleted individually.