Faith Mirror

Faith Mirror 개인정보 처리방침 / Privacy Policy

시행일 / Effective date: 2026-07-12
최종 업데이트 / Last updated: 2026-08-17
문의 / Contact: app.2weeks@gmail.com

변경 요약 / Changes (2026-08-17): Android(Google Play) 출시에 맞춰 Android의 저장 방식(Room·DataStore·Android Keystore), 시스템 백업 제외와 내보내기, 기기 내 AI(Gemini Nano, Gemma/LiteRT-LM)와 약 560MB 모델 다운로드, 생체 인증(BiometricPrompt), 원격 설정 안내를 추가했습니다. iOS 관련 내용은 그대로입니다. / Added Android details for the Google Play release — Room·DataStore·Android Keystore storage, system-backup exclusion and export-only transfer, on-device AI (Gemini Nano, Gemma/LiteRT-LM) including the ~560 MB model download, BiometricPrompt, and remote configuration. iOS statements are unchanged.

한국어 · English


한국어

1. 한눈에 보기

Faith Mirror는 기기 우선(device-first) 앱입니다. 회원가입이 없고 별도의 Faith Mirror 서버도 운영하지 않습니다. 테스트 결과, 성장 플랜, 저널 등 대부분의 데이터는 사용자의 기기 안에 머뭅니다. AI 요청은 사용자가 선택한 방식에 따라 기기 안에서 처리되거나(iOS: Apple 기기 내 모델 / Android: Gemini Nano 또는 내려받은 Gemma 모델), iOS에서 명시적으로 선택한 Apple Private Cloud Compute 또는 동의 후 설정한 OpenAI로 전송될 수 있습니다. 이 방침은 iOS(App Store)와 Android(Google Play) 앱 모두에 적용됩니다.

2. 기기에 저장되는 정보

다음 정보가 기기 안 저장소 — iOS에서는 SwiftData, UserDefaults, Keychain 등 Apple이 제공하는 저장소, Android에서는 Room 데이터베이스, Jetpack DataStore 및 Android Keystore 기반 암호화 저장소 — 에 보관될 수 있습니다.

OpenAI API 키는 iOS에서는 잠금 해제된 이 기기에서만 사용할 수 있도록 Keychain에, Android에서는 Android Keystore로 보호되는 암호화 저장소(EncryptedSharedPreferences)에 저장됩니다. 알림은 서버를 거치지 않고 기기 안에서 예약·표시되는 로컬 알림입니다. 기본 알림 문구는 플랜 세부 내용을 표시하지 않으며, 상세 문구 옵션을 제공하는 경우 사용자가 직접 켠 경우에만 적용됩니다.

3. 로컬 저장과 백업

Faith Mirror는 기록을 이 기기에만 저장하며 자동 클라우드 저장 기능을 제공하지 않습니다. Android 앱은 시스템 백업에서 제외되도록 설정되어(allowBackup=false) 운영체제가 앱 데이터를 Google 클라우드 백업이나 기기 간 전송에 포함하지 않으며, 데이터가 기기를 떠나는 것은 사용자가 직접 시작한 동작(백업 내보내기, 공유, 동의한 AI 전송)뿐입니다. 다른 곳에 보관하려면 설정에서 백업 파일을 직접 내보내 주세요. OpenAI API 키는 백업에 포함되지 않습니다.

4. AI 처리 방식 (선택)

AI 처리는 사용자가 AI 요청 버튼을 누를 때만 시작됩니다.

5. Apple Private Cloud Compute (iOS 전용, 선택)

사용자가 설정에서 Private Cloud Compute를 선택하고 AI 요청을 시작하면 기능에 필요한 다음 정보가 암호화되어 Apple의 PCC 서버에서 처리될 수 있습니다.

Apple은 PCC로 보낸 요청 데이터와 응답을 저장하지 않고 Apple이 접근할 수도 없으며 요청 처리에만 사용한다고 밝힙니다. PCC에는 인터넷 연결, 지원되는 OS·기기 및 사용자별 일일 사용 한도가 적용됩니다. PCC를 사용할 수 없으면 Faith Mirror가 지원되는 기기 내 모델을 사용할 수 있지만 OpenAI로 자동 전송하지 않습니다.

6. 기기 내 AI (Android, 선택)

Android에서는 두 가지 기기 내 처리 방식을 사용합니다.

기기 내 처리에서는 5항에 적힌 기능별 정보와 생성된 답변이 기기를 떠나지 않습니다. Android는 Apple Private Cloud Compute를 사용하지 않습니다.

7. OpenAI 전송, 동의 및 보관 (iOS·Android, 선택)

OpenAI는 사용자가 본인의 API 키를 등록하고 명시적으로 동의한 뒤 OpenAI를 직접 선택하거나 자동 방식의 대체 모델로 요청할 때만 사용되며, 동의 전에는 어떤 내용도 전송되지 않습니다. 키 확인 시 API 키와 최소 확인 요청이 api.openai.com으로 전송됩니다. AI 요청에는 5항에 적힌 기능별 정보가 포함될 수 있습니다. 종교적 성찰과 자유 입력 내용은 민감정보일 수 있습니다. 요청은 사용자의 OpenAI 계정에서 처리되며 Faith Mirror 서버를 거치지 않습니다.

OpenAI는 사용자의 API 계정에 적용되는 OpenAI 서비스 약관, API 데이터 제어 정책비즈니스 데이터 개인정보 보호 약속에 따라 요청을 처리합니다. 실제 보관 기간은 계정, 조직 및 프로젝트 설정과 당시 정책에 따라 달라질 수 있으며 악용 방지 로그가 보관될 수 있습니다. Faith Mirror는 OpenAI가 보관한 기록을 관리할 수 없습니다. OpenAI 플랫폼에서 데이터 제어를 확인하고 OpenAI 개인정보 포털에서 관련 요청을 할 수 있습니다.

설정에서 API 키 삭제를 선택하거나 OpenAI 전송 동의를 끄면 이후 OpenAI 전송만 중단됩니다. 기기 내 모델(및 iOS의 PCC)은 계속 사용할 수 있습니다. 모든 데이터 삭제는 API 키, 동의 기록 및 AI 방식 설정도 삭제합니다.

8. 보안과 생체 인증

저널 잠금에는 기기 인증을 사용합니다 — iOS에서는 Apple의 기기 소유자 인증(Face ID, Touch ID 또는 기기 암호), Android에서는 BiometricPrompt(기기에 따라 지문·얼굴 인식 또는 화면 잠금)를 사용합니다. Faith Mirror는 얼굴이나 지문 원본 등 생체정보를 받거나 저장하지 않고 인증 성공 여부만 전달받습니다. OpenAI API 키는 iOS에서는 Keychain에, Android에서는 Android Keystore 기반 암호화 저장소에 저장되며, PCC·OpenAI 네트워크 전송과 모델·설정 다운로드에는 암호화된 연결이 사용됩니다. 보호된 저널이 백업에 포함되면 내보내기 전에 기기 인증을 다시 요청합니다.

9. 백업과 공유

백업 파일은 비밀번호 기반 AES-256-GCM 암호화(PBKDF2 키 유도)를 기본으로 사용합니다. 사용자는 경고를 확인한 뒤 암호화하지 않은 평문 내보내기를 선택할 수 있습니다. Android에서는 백업 파일의 저장 위치를 문서 선택기(Storage Access Framework)에서 직접 선택합니다. 내보낸 백업과 결과 이미지는 사용자가 iOS 또는 Android 시스템 공유 시트에서 직접 선택하고 완료한 앱, 사람 또는 저장 위치로만 전달되며, 전달 이후에는 해당 수신자와 서비스의 정책이 적용됩니다.

앱의 모든 데이터 삭제 기능이나 앱 삭제는 이미 내보내거나 공유한 사본을 삭제하지 않습니다. 평문 백업 및 공유 대상은 특히 신중하게 관리해 주세요.

10. 광고, 분석 및 추적 없음

Faith Mirror는 광고, 행동 분석·추적 SDK 또는 데이터 브로커를 사용하지 않습니다. 다른 회사의 앱이나 웹사이트 활동과 데이터를 결합해 사용자를 추적하지 않으며 데이터를 판매하지 않습니다.

앱은 실행 시 버전 안내와 검증된 콘텐츠 갱신을 위한 작은 공개 설정 파일을 개발자의 공개 GitHub 저장소에서 HTTPS로 가져옵니다. 이 요청에 개인 데이터는 포함되지 않으며, GitHub는 IP 주소와 같은 표준 접속 정보를 볼 수 있습니다. 콘텐츠 파일은 해시 검증을 통과한 경우에만 적용됩니다.

오류 수집(Sentry)은 기본적으로 비활성화되어 있으며, 운영자가 Android 릴리스 빌드에 수집 주소(DSN)를 설정해 안정성 진단을 활성화한 경우에만 Sentry가 충돌 기술 정보(앱/OS 버전, 기기 종류, 오류 스택)를 받을 수 있습니다. 기본 PII, 스크린샷, 화면 계층, 사용자 상호작용 브레드크럼은 비활성화하고 사용자·요청 객체는 전송 전에 제거합니다. 저널, 테스트 답변, 플랜 메모, API 키와 사용자 프로필을 Sentry에 의도적으로 보내지 않습니다. 이 기능은 광고나 사용자 추적이 아니라 앱 안정성 개선에만 사용하며, 활성화 전에는 이 정책과 스토어 데이터 공개를 갱신합니다. Sentry 개인정보 처리방침도 적용됩니다.

11. 보관과 삭제

기기 기록과 생성된 AI 답변은 사용자가 삭제할 때까지 보관됩니다.

iOS에서는 앱을 삭제하는 것만으로 Keychain 또는 내보낸 파일의 삭제를 보장할 수 없습니다. Android에서는 앱을 삭제하면 기기의 앱 데이터가 함께 삭제되지만 내보낸 파일은 남습니다. 완전한 삭제가 필요하면 앱을 삭제하기 전에 앱 안의 삭제 기능과, 해당하는 경우 OpenAI 계정의 데이터 관리 기능을 사용하고 내보낸 파일은 별도로 삭제해 주세요.

12. 어린이

Faith Mirror는 만 13세 미만 어린이를 대상으로 하지 않으며 어린이의 정보를 의도적으로 수집하지 않습니다.

13. 정책 변경

이 방침이 변경되면 이 문서와 최종 업데이트 날짜를 갱신합니다. Apple PCC, OpenAI 등 기기 밖으로 보내는 정보나 목적이 실질적으로 변경되면 새 안내 또는 필요한 동의를 제공합니다.

14. 문의

개인정보와 관련한 문의는 app.2weeks@gmail.com으로 보내주세요.


English

1. At a glance

Faith Mirror is a device-first app with no account sign-up and no Faith Mirror-operated server. Most information—including test results, growth plans, and journals—remains on your device. Depending on the option you choose, an AI request may be processed on device (iOS: an Apple on-device model / Android: Gemini Nano or a downloaded Gemma model), sent to Apple Private Cloud Compute after you explicitly select it on iOS, or sent to OpenAI after you configure and consent to that service. This policy applies to both the iOS (App Store) and Android (Google Play) apps.

2. Information stored on your device

The following information may be stored in on-device storage—on iOS, Apple storage such as SwiftData, UserDefaults, and Keychain; on Android, the Room database, Jetpack DataStore, and Android Keystore-backed encrypted storage:

Your OpenAI API key is stored on iOS in Keychain so it is accessible only while this device is unlocked, and on Android in encrypted storage protected by the Android Keystore (EncryptedSharedPreferences). Notifications are local notifications scheduled and shown on the device without any server. By default, notification text uses generic wording without plan details; if a detailed-wording option is offered, it applies only when you turn it on.

3. Local storage and backups

Faith Mirror stores records only on this device and does not provide automatic cloud storage. The Android app is excluded from system backups (allowBackup=false), so the operating system does not include app data in Google cloud backup or device-to-device transfer; data leaves the device only through actions you start yourself—a backup export, a share, or an AI transfer you consented to. To keep a copy elsewhere, export a backup file yourself from Settings. Your OpenAI API key is never included in a backup.

4. AI processing choices (optional)

AI processing starts only when you tap an AI request button.

5. Apple Private Cloud Compute (iOS only, optional)

When you select Private Cloud Compute in Settings and start an AI request, the following information needed by the feature may be encrypted and processed on Apple’s PCC servers:

Apple states that request data and responses sent to PCC are not stored or accessible to Apple and are used only to fulfill the request. PCC requires a network connection and a supported OS and device, and a per-user daily usage limit applies. If PCC is unavailable, Faith Mirror may use a supported on-device model but never sends the request to OpenAI automatically.

6. On-device AI (Android, optional)

Android uses two kinds of on-device processing:

With on-device processing, the feature-specific information listed in section 5 and the generated responses never leave the device. Android does not use Apple Private Cloud Compute.

OpenAI is used only after you add your own API key, explicitly consent, and make a request with OpenAI selected directly or available as the Automatic fallback; nothing is transmitted before you consent. Key validation sends the key and a minimal validation request to api.openai.com. An AI request may include the feature-specific information listed in section 5. Faith reflections and free-form text may be sensitive. Requests are processed under your OpenAI account and never pass through a Faith Mirror server.

OpenAI processes requests under the OpenAI Services Agreement, API data controls, and business data privacy commitments that apply to your API account. Actual retention depends on your account, organization, and project settings and then-current policies; abuse-monitoring logs may be retained. Faith Mirror cannot manage records held by OpenAI. Review controls on the OpenAI Platform and submit related requests through the OpenAI Privacy Portal.

Deleting the API key or withdrawing OpenAI consent stops only future OpenAI transfers. The on-device model (and PCC on iOS) remains available. Delete All Data also removes the key, consent record, and AI-provider preference.

8. Security and device authentication

Journal locks use device authentication—on iOS, Apple’s device-owner authentication (Face ID, Touch ID, or device passcode); on Android, BiometricPrompt (fingerprint, face recognition, or the screen lock, depending on the device). Faith Mirror receives only the authentication result and never receives or stores face images, fingerprints, or other biometric data. The OpenAI API key stays in Keychain on iOS and in Android Keystore-backed encrypted storage on Android, and PCC and OpenAI transfers as well as model and configuration downloads use encrypted connections. If a backup includes a protected journal, Faith Mirror authenticates again before export.

9. Backups and sharing

Password-based AES-256-GCM encryption (with PBKDF2 key derivation) is the default for backup files. You may choose plaintext export only after acknowledging a warning. On Android, you choose where the backup file is saved through the document picker (Storage Access Framework). Exported backups and result images go only to the app, person, or location you select and confirm in the iOS or Android system share sheet; after delivery, the recipient’s policies apply.

Delete All Data and uninstalling Faith Mirror do not remove copies you have already exported or shared. Take particular care with plaintext backups and sharing recipients.

10. No ads, analytics, or tracking

Faith Mirror has no advertising, behavioral analytics or tracking SDKs, or data-broker sharing. We do not combine your data with activity from other companies’ apps or websites for tracking, and we do not sell data.

At launch, the app fetches a small public configuration file over HTTPS from the developer’s public GitHub repository for update notices and verified content refreshes. No personal data is included in this request; GitHub can see standard connection information such as your IP address. Content files are applied only after passing hash verification.

Crash reporting (Sentry) is disabled by default; only when the operator configures a reporting address (DSN) for an Android release build and thereby enables crash diagnostics may Sentry receive technical crash diagnostics such as app/OS version, device type, and error stack. Default PII, screenshots, view hierarchies, and user-interaction breadcrumbs are disabled; user and request objects are removed before sending. We do not intentionally send journals, assessment answers, plan notes, API keys, or user profiles to Sentry. This is for app stability, not advertising or tracking; this policy and the store data disclosure will be updated before it is enabled. Sentry’s Privacy Policy also applies.

11. Retention and deletion

Device records and generated AI responses remain until you delete them.

On iOS, uninstalling alone cannot guarantee deletion of Keychain or exported copies. On Android, uninstalling also removes the app’s data on the device, but exported files remain. When complete deletion is required, use the in-app deletion controls and, when applicable, OpenAI account controls before uninstalling, then delete exported files separately.

12. Children

Faith Mirror is not directed to children under 13 and does not knowingly collect their information.

13. Changes

If this policy changes, we update this document and its last-updated date. A material change to information or purposes involving transfers off the device—such as Apple PCC or OpenAI—receives a new disclosure or consent when required.

14. Contact

For privacy questions, contact app.2weeks@gmail.com.