개인정보처리방침
Privacy Policy
매일 한 장의 타로 카드와 맞춤 운세를 제공하는 Garmin Connect IQ 워치페이스
1. 개요
Pulse Arcana(개인 운영 프로젝트)(이하 “운영자”)는 Pulse Arcana(이하 “앱”) 이용자의 개인정보를 중요하게 생각합니다. 이 방침은 앱이 어떤 정보를 수집·이용·보관하고 이용자가 어떤 권리를 갖는지 설명합니다.
앱에서 전송되는 정보는 Garmin이 아니라 운영자에게 제출됩니다. Garmin은 운영자의 정보 처리에 대한 책임을 부담하지 않습니다.
- 원본 Garmin 기기 식별자는 서버로 전송하지 않고 앱별 SHA-256 해시값만 전송합니다.
- 건강·날씨 정보는 당일 카드와 운세를 선택하기 위해 사용합니다.
- 원본 건강 수치는 요청 처리 후 서버 데이터베이스에 별도 저장하지 않습니다.
- 당일 발급 기록에는 가명 기기 ID와 선택 결과·파생 조건을 저장하며 3일 TTL을 설정합니다.
- 개인정보를 판매하거나 맞춤 광고에 사용하지 않습니다.
2. 처리하는 정보와 목적
| 구분 | 항목 | 목적 |
|---|---|---|
| 가명 기기 정보 | 앱 namespace와 Garmin 기기 식별자를 SHA-256 처리한 64자리 값, 요청 ID | 기기·날짜별 카드 발급, 중복 요청 방지, 하루 요청 횟수 제한과 서비스 남용 방지 |
| 건강·활동 정보 | 현재·안정·평균 심박수와 최근 심박 샘플(최대 24개), 스트레스, Body Battery, 걸음 수 | 카드 선택 시드와 현재 상태에 가까운 운세 선택 |
| 날씨 정보 | 날씨 조건·범주와 섭씨 온도 | 현재 환경에 가까운 운세 선택 |
| 기기·지역 설정 | 현지 날짜, 시간대 오프셋, 시스템 언어에서 결정한 locale(ko/en), 화면 크기, 기기 part number | 현지 날짜 기준 일일 발급, 언어 및 화면 크기에 맞는 콘텐츠 제공 |
| 서비스 결과 | 선택된 카드·방향·운세, 파생된 상태 범주, 요청 횟수와 처리 시각 | 동일 날짜 응답의 일관성, 재시도와 고객 문의 대응 |
심박수 등 건강 관련 정보는 오락 목적의 운세 선택에만 사용되며 의료 진단, 치료, 보험·고용·신용 결정에 사용되지 않습니다.
3. 수집 방법과 이용 근거
정보는 사용자가 앱을 설치하고 Garmin 권한을 허용한 상태에서, 앱의 백그라운드 일일 카드 요청을 통해 자동 전송됩니다. 사용자는 Garmin 기기 또는 Connect IQ 관리 화면에서 권한을 거부하거나 앱을 삭제하여 이후 처리를 중단할 수 있습니다. 필요한 권한이나 통신을 허용하지 않으면 원격 카드와 맞춤 운세 기능이 제한되고 앱에 포함된 대체 화면이 표시될 수 있습니다.
4. 보유 기간과 파기
| 정보 | 보유 기간 | 파기 방법 |
|---|---|---|
| 요청에 포함된 원본 건강·활동·날씨 수치 | 요청 처리 중에만 사용하며 데이터베이스에 원본 수치로 별도 저장하지 않음 | 요청 처리 후 별도로 보존하지 않으며 일반적인 런타임 메모리 수명주기에 따라 해제 |
| 가명 기기 ID, 요청 ID·횟수, 카드·운세 결과와 파생 상태 범주 | 레코드 생성 후 3일 TTL | Amazon DynamoDB TTL로 자동 삭제. AWS 처리 특성상 만료와 실제 삭제 사이에 지연이 있을 수 있음 |
| 운영 로그 | 14일 | Amazon CloudWatch 보존 정책으로 자동 삭제. 로그에는 해시 기기 ID 앞 12자리, 날짜, 카드 ID, 요청 횟수와 오류 정보가 포함될 수 있음 |
| 워치에 저장된 카드·운세 캐시와 임시 신호 snapshot | 새 데이터로 교체하거나 앱을 삭제할 때까지 | 앱 저장소 갱신 또는 앱 삭제 |
5. 제3자 제공과 처리 위탁
운영자는 개인정보를 판매·대여하거나 광고 사업자에게 제공하지 않습니다. 법률상 의무가 있는 경우를 제외하고 이용자의 개인정보를 독립적인 제3자에게 제공하지 않습니다.
서비스 운영을 위해 다음 사업자에게 처리를 위탁합니다.
| 수탁자 | 업무 | 처리 위치 |
|---|---|---|
| Amazon Web Services, Inc. 및 관련 법인 | API Gateway, Lambda, DynamoDB, S3, CloudWatch를 이용한 요청 처리·저장·로그·콘텐츠 제공 | 대한민국 서울 리전(ap-northeast-2) |
대한민국 밖에서 앱을 이용하는 경우 정보가 인터넷을 통해 대한민국으로 전송되어 처리될 수 있습니다.
6. 이용자의 권리
이용자는 관련 법률이 허용하는 범위에서 개인정보의 열람, 정정, 삭제, 처리정지와 동의 철회를 요청할 수 있습니다. 앱 삭제는 이후의 자동 수집을 중단하며, 서버의 당일 발급 기록은 위 보유 기간에 따라 자동 만료됩니다.
권리 행사는 아래 이메일로 요청할 수 있습니다. 운영자는 요청자 확인에 필요한 최소한의 정보를 요청할 수 있으며, 법률이 정한 기간 내에 처리 결과 또는 제한 사유를 안내합니다.
7. 안전성 확보 조치
- HTTPS를 통한 전송
- 원본 Garmin 기기 식별자의 앱 내부 SHA-256 처리
- S3 공개 접근 차단과 짧은 유효기간의 서명 URL
- AWS 접근 권한 최소화, 저장 데이터 암호화와 요청 형식 검증
- 요청 횟수 제한, 로그 보유기간 제한과 오류 모니터링
어떠한 전송·저장 방식도 절대적인 보안을 보장할 수는 없습니다. 침해 사실을 확인하면 관련 법률에 따라 필요한 조치를 취합니다.
8. 자동화된 처리와 오락 목적 고지
앱은 건강·날씨 상태 범주와 미리 작성된 운세 사이의 거리를 계산해 가장 가까운 문구를 자동 선택합니다. 이 처리는 이용자에게 법적 또는 이와 유사한 중대한 영향을 주는 결정을 하지 않습니다. 카드와 운세는 오락 목적이며 의료·정신건강·재무·법률 조언이 아닙니다.
9. 정책 페이지의 쿠키
이 정적 개인정보처리방침 페이지 자체는 쿠키, 광고, 분석 스크립트 또는 사용자 추적 기술을 사용하지 않습니다. 호스팅 제공자가 보안 및 서비스 제공을 위해 기본 접속 로그를 처리할 수 있으며, 그 처리는 해당 제공자의 방침을 따릅니다.
10. 변경과 문의
2026-09-09 (1.1): 개인정보 문의 이메일을 face_foundry@naver.com으로 변경하고 개인 운영 프로젝트의 운영 주체 표기를 정리했습니다.
이 방침이 변경되면 같은 URL에 시행일과 변경 내용을 게시합니다. 수집·이용·보관 또는 제공 방식이 중대하게 변경되는 경우 관련 법률이 요구하는 추가 고지나 동의를 진행합니다.
운영 주체: Pulse Arcana (개인 운영 프로젝트)
개인정보 보호 담당: Pulse Arcana 개인정보 보호 담당
이메일: face_foundry@naver.com
1. Overview
Pulse Arcana, an independently operated project (the “Operator”), respects the privacy of Pulse Arcana (the “App”) users. This policy explains what information the App processes, why it is processed, how long it is retained, and the choices available to users.
Information transmitted by the App is submitted to the Operator, not to Garmin. Garmin is not responsible for the Operator's processing of that information.
- The raw Garmin device identifier is not sent to the server. The App sends an app-specific SHA-256 hash.
- Health and weather information is used to select the daily card and a matching fortune.
- Raw health measurements are not retained as raw database records after the request is processed.
- Daily issuance records contain a pseudonymous device ID, selection results, and derived condition labels, with a three-day TTL.
- Personal information is not sold or used for personalized advertising.
2. Information processed and purposes
| Category | Information | Purpose |
|---|---|---|
| Pseudonymous device information | A 64-character SHA-256 value derived from the App namespace and Garmin device identifier; request ID | Issue a card per device and local date, prevent duplicate requests, enforce daily limits, and reduce abuse |
| Health and activity information | Current, resting, and average heart rate; up to 24 recent heart-rate samples; stress; Body Battery; and steps | Create the card selection feed and select a fortune close to the user's current state |
| Weather information | Weather condition and category, and temperature in Celsius | Select a fortune close to current environmental conditions |
| Device and regional settings | Local date, time-zone offset, locale selected from the system language (ko/en), screen dimensions, and device part number | Provide one daily result based on local date and content suitable for the language and screen size |
| Service results | Selected card, orientation and fortune; derived condition labels; request count; processing timestamps | Keep same-day responses consistent, support retries, and respond to service inquiries |
Health-related information, including heart rate, is used only to select entertainment content. It is not used for medical diagnosis, treatment, or insurance, employment, credit, or other consequential decisions.
3. How information is collected
Information is transmitted automatically by the App's background daily-card request after the user installs the App and grants the relevant Garmin permissions. Users can stop future processing by denying permissions through their Garmin device or Connect IQ management interface, or by uninstalling the App. If required permissions or communications are unavailable, remote card and personalized-fortune features may be limited and the bundled fallback display may be shown.
4. Retention and deletion
| Information | Retention | Deletion |
|---|---|---|
| Raw health, activity, and weather measurements in a request | Used during request processing and not separately retained as raw database fields | Not intentionally retained after processing and released through the normal runtime memory lifecycle |
| Pseudonymous device ID, request IDs and count, card and fortune results, and derived condition labels | Three-day TTL from record creation | Automatically deleted through Amazon DynamoDB TTL; actual deletion may occur after expiration due to AWS processing behavior |
| Operational logs | 14 days | Automatically deleted by the Amazon CloudWatch retention policy. Logs may contain the first 12 characters of the hashed device ID, local date, card ID, request count, and error information |
| Card and fortune cache and temporary signal snapshot stored on the watch | Until replaced or the App is removed | App storage update or App removal |
5. Sharing and service providers
The Operator does not sell or rent personal information or provide it to advertising companies. Personal information is not disclosed to independent third parties except when required by law.
The following service provider processes information on behalf of the Operator:
| Provider | Services | Processing location |
|---|---|---|
| Amazon Web Services, Inc. and relevant affiliates | Request processing, storage, logging, and content delivery through API Gateway, Lambda, DynamoDB, S3, and CloudWatch | Seoul, Republic of Korea (ap-northeast-2) |
If the App is used outside the Republic of Korea, information may be transmitted over the internet to and processed in the Republic of Korea.
6. User rights and choices
Subject to applicable law, users may request access to, correction or deletion of, or restriction of processing of their personal information, and may withdraw consent. Uninstalling the App stops future automatic collection. Server-side daily issuance records expire according to the retention periods above.
Requests may be sent to the email address below. The Operator may request the minimum information needed to verify the requester and will respond, or explain any lawful limitation, within the period required by applicable law.
7. Security measures
- Transmission over HTTPS
- App-side SHA-256 hashing of the raw Garmin device identifier
- Blocked public S3 access and short-lived signed URLs
- Least-privilege AWS access, encryption at rest, and request validation
- Daily request limits, limited log retention, and error monitoring
No transmission or storage method can guarantee absolute security. If a breach is confirmed, the Operator will take the measures required by applicable law.
8. Automated processing and entertainment notice
The App calculates the distance between health and weather condition labels and a set of pre-written fortunes to select the closest text automatically. This process does not make decisions that produce legal or similarly significant effects. Cards and fortunes are for entertainment only and are not medical, mental-health, financial, or legal advice.
9. Cookies on this policy page
This static privacy-policy page does not itself use cookies, advertising, analytics scripts, or user-tracking technologies. Its hosting provider may process basic access logs for security and service delivery under the provider's own policy.
10. Changes and contact
2026-09-09 (1.1): Updated the privacy contact email to face_foundry@naver.com and clarified the operator name for this independently operated project.
Changes to this policy will be posted at the same URL with the effective date and a description of the change. If the App materially changes how information is collected, used, retained, or disclosed, the Operator will provide any additional notice or obtain any consent required by applicable law.
Operator: Pulse Arcana (an independently operated project)
Privacy contact: Pulse Arcana Privacy Contact
Email: face_foundry@naver.com
