Goyo Privacy Policy
Effective date: 2026-05-31 · Operator: namssy · Contact: namsy013@gmail.com
Goyo (the “App”) takes your privacy seriously and complies with applicable laws, including the Korean Personal Information Protection Act (PIPA). This policy explains what information the App collects and how it is used, stored, and destroyed.
1. Information We Collect and Purpose
| Category | Items | Collection method | Purpose |
|---|---|---|---|
| Health & biometric data | Heart rate, blood oxygen saturation (SpO₂), apnea training records (duration, table, air hunger, etc.) | Bluetooth (BLE) sensor integration and in-app logging (with your consent) | Provide and visualize training records, AI coaching analysis |
| App usage data | Feature usage statistics, event logs | Automatic collection (Firebase Analytics) | Service improvement and usage analysis |
| Diagnostic data | Crash logs, device/OS information | Automatic collection (Firebase Crashlytics) | Stability improvement and error response |
| Identifier | Anonymous identifier (Firebase anonymous UID) | Generated automatically on first launch | Data synchronization and usage management |
The App does not collect direct identity information such as your name, email address, or phone number. Authentication is handled anonymously, and the generated anonymous UID does not identify any specific individual.
2. Sensitive Data and Separate Consent
Health and biometric data such as heart rate and SpO₂ are sensitive data. The App collects the following consents separately within the App and records the consent date. You may withdraw consent at any time in Settings → Privacy.
- Biometric data collection consent: collection and logging of biometric data such as heart rate and SpO₂
- AI analysis server transmission consent: transmission and processing of training data on the server for AI coaching analysis
If you do not consent, the relevant features (biometric data logging, AI analysis) are not provided, but the remaining features such as the basic timer remain available.
3. Processing Entrustment and Overseas Transfer
| Processor | Items processed | Location |
|---|---|---|
| Google Firebase (Authentication · Firestore · Analytics · Crashlytics) | Anonymous authentication, training data storage, usage and diagnostic data | Google data centers |
| Google Cloud Vertex AI | Training data processing for AI coaching analysis | United States (us-central1), etc. |
If you consent to AI analysis, your training data may be processed overseas (e.g., in the United States). This processing is solely for the purpose of providing AI coaching results.
4. Retention and Destruction
- Local data is stored encrypted (SQLCipher) on your device.
- Server data is retained for the period necessary to provide the service, and you can delete server and local data using the in-app “Delete data” feature.
- When you withdraw consent or request deletion, the relevant data is destroyed without delay.
5. Security Measures
- Encryption at rest: the local DB is encrypted with SQLCipher (AES-256)
- Encryption in transit: all network communication uses HTTPS (TLS)
- Integrity protection: App Check (Play Integrity / App Attest)
6. Your Rights
- Withdraw consent (Settings → Privacy)
- Delete data (Settings → Privacy → Delete data)
- Contact: namsy013@gmail.com
7. Children’s Personal Information
The App is not directed at children under the age of 14 and does not knowingly collect children’s personal information.
8. Medical Disclaimer
The App’s AI analysis and all feedback are for reference only to help improve athletic performance, and are not medical diagnosis or advice. Consult a professional for health-related decisions.
9. Notice of Changes
If this policy changes, we will provide notice through the App or this page.