Privacy policy
Readyden is operated by 백종만 (Pleiara Studio). This policy explains the information we process to provide the service, why we use it, and how it is protected and deleted.
1. Information and purposes
Account access: depending on whether you choose Apple, Google, Kakao or email, we process account identifiers, email, names or profile names, and authentication information. Passkeys store public keys and registration details. Readyden does not receive raw face or fingerprint data or passkey private keys.
Storage, sync and family sharing: we process the family group, storage locations, gear details, notes, purchase information, camping and care records, photos and attachments you save. Other members can view records shared with your family group.
Notifications: when enabled, we process APNs tokens and notification settings. Notifications may contain camping or gear names. You can control their display in your device settings.
Subscriptions: App Store and RevenueCat process account, product and transaction identifiers, purchase, renewal and refund records, and subscription status to provide Pro and restore purchases. Readyden does not receive payment card or bank account numbers.
Operations and security: service providers may process IP addresses, request times, authentication, access and error logs. We do not request advertising IDs, address book access or GPS location, and do not sell personal information or use it for advertising tracking.
2. Optional usage statistics
Only when you turn on Share usage statistics in Settings → Privacy, we add up daily counts of feature use and visits through invitation links, labels and notifications. It is off by default. All features remain available when it is off.
These counts exclude account, family and device identifiers, search terms, gear names, photos, files, invitation codes and full links. They do not track individual journeys or count unique people. Your consent choice is stored with your account so it can be applied.
You can turn sharing off at any time. When offline, sending stops on that device immediately, and withdrawal is applied on the server after reconnection. A particular person’s contribution cannot be separated from counts already aggregated.
Export of app usage statistics to PostHog is currently disabled. Before enabling an external analytics service, we will update this policy with its provider, processing location and retention details. We do not use automatic screen capture or session replay.
3. Photos, invitations and AI connections
Gear and text recognition in photos runs on your device. Saving a photo with gear uploads it for sync.
You share invitations through your device’s mail or messaging apps. Readyden does not collect recipients’ address books, email addresses or phone numbers, or send invitation emails on your behalf. Your chosen mail or messaging service has its own policy.
AI connections require your authorization. The external AI service receives gear, storage, camping and care information returned by the tools. You can separately allow changes to gear storage locations. AI connections use dedicated credentials that do not contain your app sign-in token, account identifier, email or profile. They cannot access photos, attachments, account settings or billing information. Personal information you enter in gear or trip names may, however, appear in tool results.
To manage a connection, Readyden stores the approving account, family group, connecting app, permissions, expiry and credential hashes. Connections last up to 30 days. Revoking access in Manage AI connections blocks subsequent requests and token refreshes; a request already running may finish. Expired connections are regularly cleaned up. Revocation records and remaining credentials become eligible for cleanup no later than seven days after revocation. Information already received by an AI service is subject to its own use and retention policies; review them before connecting.
4. Service providers and international processing
Supabase provides authentication, the database, file storage, sync and server functions. The primary data region is Seoul, South Korea. International operations, support and subprocessors are covered by Supabase’s data processing agreement and subprocessor list.
RevenueCat, Inc. (United States) processes account identifiers and purchase information on US infrastructure for subscription management, purchase restoration and purchase analytics.
Resend (Plus Five Five, Inc., United States) processes email addresses, sign-in email contents and delivery status. Our sending domain uses the Tokyo, Japan region; this does not mean all Resend data is stored only in Japan.
Apple, Google and Kakao process information required for the sign-in method you select and services such as App Store payments and APNs. Cloudflare, Inc. (United States) serves web pages and links and relays AI connection credentials and requests and responses, including gear, storage, camping and care information, through its global network. Caching of AI responses and Readyden Worker request logs are disabled. Cloudflare’s own security and operational data processing follows its policies. Information is transmitted over the network when these services are requested, synced or used to send email or notifications.
Contact contact@pleiara.com to ask about or object to international processing. Functions that depend on this processing, such as sign-in, sync or subscriptions, may become unavailable. Usage statistics and AI connections are optional. Providers’ retention, backup and subprocessing terms are available in the official documents below.
5. Retention and deletion
We retain your account and saved records for as long as needed to provide the service. Request deletion in Settings → Delete account. A family group with no remaining members is deleted with its records and files. Shared records remain available to other members when they remain in the group.
Deletion includes authentication information, your profile, personal notification settings and consent preferences. Failed Apple revocation and RevenueCat customer deletion are retried. The identifiers and encrypted Apple tokens needed for retries are removed when processing completes. Staged Apple tokens for accounts whose deletion did not proceed are cleaned up after seven days.
Aggregate counts are regularly removed after they are more than 90 days old. Unreferenced uploads and replaced photos become eligible for cleanup after seven days. Photos and files still referenced by records, including restorable gear and history, are retained.
Transaction records are retained for five years for payment administration, disputes and applicable legal requirements, then cleaned up. Account identifiers are pseudonymized when an account is deleted. Completed subscription event records are cleaned up after 90 days; raw webhook payloads are not retained. Backups, security logs and information providers must retain by law may follow separate retention terms.
Deleting your Readyden account does not cancel an App Store subscription. Cancel it separately in the App Store.
6. Protection, rights and contact
We use transport protection, private file storage, family-level access controls, server secret management and retention cleanup. End-to-end encryption of all photos and attachments is not currently provided; systems with operational access can process the data.
You may request access, correction, deletion, restriction of processing, withdrawal of consent, and other rights under applicable law. If you cannot use the app, email us. We verify your authority to make the request and explain any restrictions required by law or the rights of other family members.
Operator and privacy contact: 백종만 (Pleiara Studio), contact@pleiara.com. Material changes will be announced on this page and in the app when appropriate.
Official documents
Supabase DPA · Supabase subprocessors · RevenueCat DPA · RevenueCat privacy · Resend DPA · Resend subprocessors · Cloudflare privacy · Google Sign-In privacy