This is a reference translation. If it differs from the Korean original, the Korean original prevails. View the Korean original
Tyranote Privacy Policy
Purring Butter (Representative: Jongseung Park, the "Company"), in providing Tyranote (the "Service"), complies with applicable laws including the Personal Information Protection Act (개인정보 보호법) and processes personal information as described below. The Company will not sell users' data under any circumstances.
1. Data Processing Principles
- Notes and tasks (when not signed in): Stored only on the user's device, encrypted with AES-256-GCM, and not sent to the Company's servers. To guard against mistakes and errors, the device also keeps copies of the last 14 days, encrypted in the same way.
- Notes and tasks (when signed in with Sync turned on): Also stored on the Company's servers for sync across devices. They are protected by encryption in transit (TLS) and server-side encryption at rest, so plaintext is not exposed even if the database is leaked. However, the Company can decrypt them to operate the Service, such as for sync and recovery, and does not use their content for advertising or marketing, or provide or sell it to third parties.
- Usage statistics (optional): Only if the user consents, the app sends usage statistics that contain no note content, to improve the Service and address errors (see the table in Section 2 below). When the app is first launched, the user chooses "Sounds good" or "No thanks"; before a choice is made, or if "No thanks" is chosen, nothing is sent. A randomly generated installation identifier (pseudonymized information) is used; no email, name, note content, or search terms are included, and IP addresses are not stored.
- Advertising: Advertising in the Service consists of a single ad card selected directly by the Company. No external ad SDKs, advertising identifiers, personalized ads, or tracking are used, and only the number of impressions and clicks per ad is aggregated through the usage statistics described above.
2. Information Collected and When
| When | Items | Required/Optional |
|---|---|---|
| App use — only with consent | Usage statistics — random installation identifier, app version, operating system, display language, feature usage counts (creating notes and how they were created, completion, setting due dates, etc.), error type codes (save failures, sync errors, etc.), ad impression and click counts | Optional (consent) |
| Account sign-up and sign-in | Email address, password (stored as a one-way hash) | Required |
| Sign-in, device management, and security | Device identifier, device name (hostname), operating system, access IP address, access date and time | Required (service provision and security) |
| Using Sync | Content of notes, tasks, and folders | When Sync is turned on |
| Send feedback | Account email, feedback subject and content, app version, operating system, and display language | Optional |
| Inquiries (email) | Email address, content of inquiry | Optional |
The installation identifier for usage statistics is not linked to the account (and is not included in feedback either).
3. Purposes of Use
- Account identification and authentication, and providing sync across devices (entirely free — no paid plans or payments)
- Device management and security — displaying the list of signed-in devices, detecting abnormal access, and preventing brute-force attacks and fraudulent use
- Service improvement and quality control — understanding usage (such as the number of active users), finding and fixing errors, and measuring ad performance
- Responding to feedback and inquiries, and Service announcements
4. Retention and Use Period
- In principle, personal information is destroyed without delay once the purpose has been achieved.
- Usage statistics: Event records are automatically deleted after 400 days. A per-installation summary (first and last use dates, version, operating system, language) is retained for as long as the Service is operated. If consent is withdrawn (turned off in Settings), all records for that installation are deleted without delay.
- Feedback: Destroyed upon account deletion. Otherwise, retained for 3 years as records of consumer complaints and dispute resolution (Act on the Consumer Protection in Electronic Commerce (전자상거래법)).
- Access records: 3 months (Protection of Communications Secrets Act (통신비밀보호법)). Only the most recent access IP address per device is retained and is overwritten when updated.
- Upon account deletion: Email, password, device information, synced data, and feedback are destroyed (except for information required to be retained by law). They may remain in server backups for up to 7 days.
5. Provision to Third Parties
The Company does not provide users' personal information to third parties, except where required by law or upon a lawful request from an investigative agency.
6. Outsourcing of Processing and Cross-Border Transfer
The Company entrusts processing to the vendors below to provide the Service, and in the course of this, personal information is transferred outside Korea (Article 28-8 of the Personal Information Protection Act).
| Recipient (contact) | Country | Items transferred | Time and method of transfer | Purpose of use | Retention and use period |
|---|---|---|---|---|---|
| Supabase Inc. (supabase.com/privacy) | Republic of Korea (stored in the Seoul region). Access for operations and support purposes from the United States | Account (email, password hash), device information and access records, synced data (encrypted), usage statistics (if consented), feedback | Transmitted over the network as needed while using the Service | Database and backups | Retention periods in Section 4 above (backups up to 7 additional days) |
| Railway Corp. (railway.com/legal/privacy) | Singapore | Same as above (all requests processed by the server) | Transmitted over the network as needed while using the Service | Running the server (hosting) | Not stored (only during processing). Server logs do not record email, IP addresses, or note content (internal identifiers only), and logs are deleted after at most 30 days |
| Resend, Inc. (resend.com/legal/privacy-policy) | United States | Email address, verification code | When sending verification emails | Sending verification and password reset emails | Sending records for 30 days (backups up to 7 additional days) |
| GitHub, Inc. (docs.github.com/site-policy/privacy-policies) | United States | Access IP address (processed directly by GitHub when downloading app installation files and updates) | When installing or checking for updates | Distributing installation files and updates | Per GitHub's policy |
To refuse cross-border transfer: If you use the app without signing in, your account and sync information will not be transferred, and if you turn off usage statistics in Settings, statistics will not be transferred either. In this case, you cannot use sync across devices. Distribution of installation and update files (GitHub) cannot be refused.
7. Rights of Data Subjects
- Users may at any time request access to, correction, deletion, or suspension of processing of their personal information, and may withdraw consent.
- Usage statistics can be turned off at any time in Settings → Other → "Send error & usage reports", and turning it off automatically deletes past records for that installation.
- Requests are accepted at the contact below, and the Company will act on them without delay.
8. Method of Destruction
Electronic files are deleted using methods that make them unrecoverable, and printed materials are shredded or incinerated.
9. Security Measures
- Encryption of on-device data (AES-256-GCM, with keys stored in the operating system's credential manager or Keychain), and encryption of synced data at rest
- Storing passwords as one-way hashes (plaintext is not retained), and encryption in transit (HTTPS/TLS)
- Minimizing access privileges, restricting administrative functions to operator accounts, and retaining access records
10. Cookies and Other Automatic Collection Tools
The app does not use cookies. The website may use cookies to improve the Service, and you can refuse them in your browser settings.
11. Chief Privacy Officer and Contact
- Chief Privacy Officer: Jongseung Park
- Email: [email protected]
- Business: Purring Butter · Business registration number 680-03-04138 · 830-28 Hwanggeum-dong, Suseong-gu, Daegu, Republic of Korea
12. Service Region
The Service is not directed to residents of the European Economic Area (EEA), the United Kingdom, Switzerland, or mainland China, and the Company does not advertise, sell, or localize the Service targeting those regions. The app's support for multiple languages does not mean that it is directed to those regions.
13. Notice of Changes
This Policy may change due to changes in laws or the Service, and any changes will be announced on the website and in the app.
- Effective date: October 3, 2026
- Revision history: 2026-10-03 Made usage statistics consent-based (optional; deleted upon withdrawal), detailed the items, countries, and refusal method for cross-border transfer, and specified the service region. 2026-10-02 Service name changed to Tyranote; added usage statistics, Send feedback, and automatic on-device copies; removed payment-related wording (entirely free)