Your card is on its way...
Your card is on its way...
Privacy
Effective: 2026-05-28 · Last revised: 2026-07-20 · v2.9
Plain-language summary: /en/privacy-summary
dadokim (the “Company”) processes personal data for the following purposes.
※ No ad targeting · no pixels (no Meta, Google, or TikTok pixels). Mental-health-adjacent data is never used for advertising.
| Item | Basis | Retention |
|---|---|---|
| The line you type (raw text) | Optional · sensitive-data consent | Not stored (discarded after card generation · never saved to the DB) |
| Crisis-signal classification (safety level, for safe routing) | Optional consent · urgent protection of life | Safety stats: de-identified aggregates only, 90 days (no identifier/raw text/hash) · each card's safety level kept as card metadata, deleted with the card (below row) |
| Other sensitive details included in free text | Optional · sensitive-data consent | Not stored in dadokim's database · processed for card generation. We recommend not entering it |
| Anonymous identifier (UUID) | Required · automatic in the app or on functional gift/account web routes | 1 year (auto-deleted when inactive) |
| Consent evidence (scope · document version · timestamp · HMAC hashes of IP/device) | Required · consent administration · dispute handling | Deleted with the account · raw IP and raw device values are never stored |
| UTM · referrer · user-agent | Functional-route attribution · service operation · security | Identifying fields automatically cleared after no more than 1 year |
| Device · OS · browser | Required service operation · security | Identifying fields automatically cleared after no more than 1 year |
| Request-limit key (bucket based on anonymous ID or HMAC of IP) | Required · abuse and brute-force prevention | Up to 1 hour after the limit window expires |
| Email (optional account · receipts) | Optional · sign-in · recovery · payment receipts | 5 years when part of a payment record · otherwise deleted on request |
| Identifier · email · profile name in a Google account token (only when Google sign-in is chosen) | Optional · account authentication and linking | Raw token not stored · identifier and email deleted with the account |
| Card-generation metadata (category · safety level) | Required · automatic | Paid: 30 most recent (FIFO) · Free: 7-day TTL |
| Service-operation events (authentication · purchase · gift · push state · reports) | Required · app functionality · security · incident response | Up to 1 year · never includes your free-text line or card text |
| Web/API error and performance diagnostics (exception type · source-mapped stack frames without runtime values · trace/span timing · static SDK metadata) | Required · service reliability · security · incident response | Sentry Developer-plan active events: 30 days · production backups: 90 days |
| Push token · locale · timezone · tone · delivery slot · open/silent state | Optional · notification functionality and delivery reliability | Disabled rows: up to 90 days · long-inactive tokens: up to 180 days · deleted with the account |
| Optional gift-envelope message | Optional · gift-message delivery | For the gift-state period · may be hidden after report/block or moderation · message removed on account deletion |
| Gift-message report evidence (limited message snapshot · reason · action record) | Required · report handling · abuse prevention · dispute response | Up to 90 days from the report, then deleted or de-identified |
| Web account-deletion request evidence (HMAC hashes of email, OTP, and request IP · DK reference · status · action record) | Required · identity verification · deletion fulfillment · abuse prevention | Email/IP/OTP linkage hashes removed and record de-identified no later than 90 days from the request |
| App product-analytics events (screen use · purchase flow) | Optional · app Analytics consent | Deleted on withdrawal · maximum 1 year |
| One-line reply to a card (opt-in) | Optional · micro-consent | 30-day TTL · deleted with the account or on request |
| Remembered card memories | Optional · micro-consent | 30-day TTL · extendable by 30 days · physically deleted immediately when you delete it |
| ★Pinned cards | Optional · paid · confirm modal | Until you delete them |
| Star ratings · emoji · dwell · scroll | Optional · app Analytics consent | Deleted on withdrawal · maximum 1 year |
| App purchase history (Apple · Google Play · RevenueCat) | Required if you choose to purchase · app functionality · payment-service analytics | Legally required payment records: automatically deleted after no more than 5 years · RevenueCat customer data: deleted on account-deletion request or end of processing agreement |
| IAP refund-reconciliation exception (transaction ID · product · state · minimal payment metadata) | Required · refund idempotency · financial reconciliation | No complete provider payload · resolved payload 90 days · identity link 1 year · unresolved cases keep only transaction keys until reconciliation · resolved rows no more than 5 years |
| Apple refund-review consumption data (consent flag · delivery status · consumption percentage · whether a free sample or functionality information was provided before purchase · refund preference) | Separate optional consent · Apple refund review | Dadokim removes the submitted response after 90 days · minimal transaction status up to 5 years · request Apple-held access or deletion at privacy.apple.com |
| Past web-payment records (Polar · Merchant of Record) | Existing transaction fulfilment · legal obligations | Deleted after the applicable statutory retention period |
| Post-purchase survey responses | Optional · product improvement | Up to 1 year |
| Refund · withdrawal · dispute-handling records | Required · transaction fulfilment · legal obligation | Automatically deleted after no more than 5 years (including the 3-year minimum for consumer complaints and disputes) |
| Card-share token · historical referral relationship | Required · card sharing · historical feature audit | 14 days (token) · 1 year (historical relationship) |
| Safety Router logs (de-identified aggregates · no identifier / raw text / hash) | Safety statistics | 90 days |
| Magic-link token | Required · recovery | 15 min (expiry) · 1 hour after use |
※ After the LLM responds, dadokim stores neither the original raw text nor its hash in its database. Detected contact and financial identifiers are masked before the text is sent abroad to Anthropic. Anthropic's separate retention period and exceptions are listed in the international-transfer table below.
※ Detection of suicide / self-harm crisis signals (safety level) is processed for a card’s safe routing. Safety statistics (Safety Router logs) are retained only as de-identified aggregates (level · classification-pattern ID) for 90 days, with no personal identifier, raw text, or hash. Separately, each card keeps its safety level at generation time as card metadata (linked to the anonymous ID · deleted with the card under the paid 30-FIFO / free 7-day TTL), used for safe routing and abuse prevention. We do not combine this into an individual crisis history or mental-health profile, nor use it for notification targeting or segmentation. We ask you not to enter other special-category data (including sex life, sexual orientation, political or religious beliefs, trade-union membership, genetic or biometric data, medical diagnoses, or criminal history). When the server detects a defined special-category or crisis pattern, it blocks that dynamic text from being sent to Anthropic and uses a local safety or fallback path instead.
| Subprocessor | Scope of processing | Country · transfer method |
|---|---|---|
| Supabase, Inc. | Database · auth · storage | US · EU · KR / HTTPS TLS 1.3 |
| Vercel, Inc. | Hosting · CDN | US · Asia / HTTPS |
| Anthropic, PBC | LLM card generation · sends one line of free text after detected contact and financial identifiers are masked | Stored in the US · may be processed in the US, Europe, Asia, or Australia / HTTPS · normally deleted within 30 days · inputs and outputs flagged for Usage Policy violations may be kept up to 2 years and safety classification scores up to 7 years · legal exceptions · not used for training · ad hoc deletion of individual API requests is unavailable |
| Polar Software, Inc. | Past web-payment processing and existing transaction-record management | US / HTTPS · applicable statutory retention period |
| Resend, Inc. | Email delivery (verification · recovery · payment receipts) | US / HTTPS · auto-deleted 30 days after sending |
| RevenueCat, Inc. | Apple App Store and Google Play in-app purchase processing · purchase history (anonymous identifier · purchases) | US / HTTPS · until account deletion or end of processing agreement |
| Apple Inc. | App Store refund-review consumption data after separate optional consent (consent flag · delivery status · consumption percentage · whether a free sample or functionality information was provided before purchase · refund preference) | US and other Apple processing regions / HTTPS · as needed for the refund process · rights requests at privacy.apple.com |
| Google LLC | Optional Google account sign-in · Android FCM push delivery (account token · FCM token · Firebase Installation ID · app version · user agent · neutral notification payload) | US and other Google processing regions / HTTPS · raw sign-in token not stored · notification payload TTL up to 6 hours · FCM token unregistered on notification opt-out or account deletion · FID is an app-installation identifier not linked to a dadokim account and is removed from live and backup systems within up to 180 days after an explicit deletion request or rotated after 270 days of inactivity |
| Expo (650 Industries, Inc.) | Push notification relay (Expo push token · anonymous identifier · neutral notification payload) | US / HTTPS · payload processed transiently for delivery · Expo push token stored by the delivery service · dadokim database rows disabled up to 90 days or long-inactive up to 180 days · dadokim-held row deleted with the account |
| Functional Software, Inc. d/b/a Sentry | Web/API error monitoring · 10% sample of production server/edge transaction traces (no native Android SDK or Session Replay · request/user/free text/dynamic routes/non-static span attributes scrubbed before transmission) | United States / HTTPS · Developer-plan active events: 30 days · production backups: 90 days |
※ Anthropic does not use your data for training. If you decline free-text processing or international transfer, you can still use the category-only path.
※ More on the LLM API subprocessing policy: LLM model notice
Requests: privacy@dadokim.com · or Me > Account > Delete account in the app
Free text is optional. Before first use, you can separately choose whether to allow sensitive-data processing and international transfer to Anthropic. If you decline, you can use a category without writing a sentence. When using free text, please do not enter:
※ As you type, the PII patterns above are auto-detected and flagged client-side (not blocked). Your choice and the policy version are recorded as consent evidence.
anonymous_id cookie: anonymous identification only on functional gift, account, and API routes · 1 year. Not issued on SEO, legal, or FAQ pagesfirst_utm cookie: records UTM attribution once when present on a functional route · 1 year. Not issued on SEO, legal, or FAQ pagesCards in this service may include sentences generated or recommended by a generative LLM model. This is not a medical, psychological-counseling, treatment, or diagnostic service. For details, see the LLM model notice page.
A gift-envelope message is user-written content delivered to its recipient. It must not contain abuse, hate, threats, harassment, or another person's name, phone number, email, messaging ID, or other contact or personal information.
Reports and privacy questions: privacy@dadokim.com
This service (dadokim) is operated by Deepnode, and its representative, Oh Hanwool, also serves as the Privacy Officer (Personal Information Protection Act §31 · Enforcement Decree §32).
To report or get help with a privacy violation → Personal Information Protection Commission (privacy.go.kr · 182, no area code) · KISA (privacy@kisa.or.kr · 118)