Skip to English content

StructMemo · Legal

StructMemo Privacy Policy

StructMemo 개인정보 처리방침

Effective Date: July 26, 2026

시행일: 2026년 7월 26일

StructMemo Privacy Policy

1. Overview and controller identity

StructMemo is a local-first structured note application. This policy explains how the production release handles information when you use local note features, create a backup, sign in, make a purchase, or explicitly request an AI feature.

The controller is Theorisis / Donggyu Kang. For privacy questions, email donggyu@theorisis.com.

StructMemo does not sell personal information and does not use information for cross-company advertising tracking.

2. Local content storage

The complete StructMemo note library is not automatically synchronized through StructMemo cloud storage. Basic local note features do not require an account.

Local persistent content may include:

  • workspaces, Thoughts, Code notes, folders, and hierarchy;
  • Version History, Upper Structures, and Saved Views;
  • Smart Gravity drafts and structure snapshots; and
  • visible AI Response blocks saved in the library.

Deleting the app removes this local app data unless you created an external backup. Deleting a StructMemo account does not automatically delete local Thoughts.

3. Full-library backup and restore

Settings → Data & Backup provides Back Up Entire Library and Restore Library Backup. An account is not required to use these local-library tools.

A .structmemo-backup file contains readable note content and the relationships needed to reconstruct the library. It may include all local content categories listed above. Store it securely. After you export it, the file is controlled by you and by the Files, iCloud Drive, or other document provider you selected.

The backup excludes:

  • authentication credentials, Apple tokens, and Keychain sessions;
  • StoreKit JWS values, transactions, and subscription state;
  • shared-credit wallets, grants, reservations, and ledgers;
  • API keys, server secrets, and transient backend request IDs; and
  • hidden reasoning and other provider-internal information.

Restore validates the selected backup and, after confirmation, replaces the current local library. It does not sign you in, restore or cancel a subscription, or grant AI Credits. StructMemo does not currently provide automatic iCloud synchronization.

4. Accounts and Sign in with Apple

Sign in with Apple is used for account authentication, subscription reconciliation, shared AI Credits, AI Response, Smart Gravity, Smart Naming, Restore Purchases, and account deletion. Core local note features remain available without signing in.

StructMemo receives Apple’s stable account subject identifier and, only when Apple supplies them, an email address and email-status fields. The current app does not send your Apple display name to the StructMemo service. Apple may provide a private relay email if you choose Hide My Email.

The service stores an internal user ID, a protected account-lineage value used to prevent account or promotional-credit relinking abuse, hashed StructMemo session credentials, login and session timestamps, and an encrypted Apple refresh token when Apple returns one. Raw Apple identity tokens and authorization codes are not stored as account records.

5. Purchases, subscriptions, and shared AI Credits

StructMemo Pro and StructMemo Pro Plus are purchased and billed through Apple StoreKit. Apple processes payment-card information. StructMemo does not receive or store payment-card numbers.

StructMemo verifies purchase and subscription information needed to determine entitlement and ownership. Records may include product and transaction identifiers, purchase, expiration, revocation, environment, verification, and account-ownership information. StructMemo stores a hash of the signed transaction payload rather than the StoreKit JWS value itself.

Shared AI Credit records include the plan and period, granted, reserved, settled, released, or refunded credits, feature, request and reservation identifiers, provider cost, model, token totals, status, and timestamps. These records operate and reconcile the service and may be linked to your StructMemo account.

6. AI features and explicit user initiation

AI processing begins only after an explicit user action. Depending on the feature, StructMemo may send the content necessary to perform your request through the StructMemo backend to OpenAI:

  • Smart Gravity: eligible selected Thought or Code content, titles, your organization instruction, and structural context after you request generation;
  • AI Response: the source Thought and an optional instruction after you confirm generation; and
  • Smart Naming: the current title and a bounded text preview when the feature is enabled and you perform the applicable save or naming action.

Generated AI Response text returns to the app and may be saved as a visible local response block. The StructMemo backend is not general cloud synchronization for the full note library.

7. OpenAI processing and retention

StructMemo uses OpenAI’s Responses API. Every current StructMemo Responses API request explicitly sets store: false, so StructMemo requests do not intentionally create persistent response objects through that API setting.

OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Under OpenAI’s default controls, abuse-monitoring logs may contain prompts and responses and may be retained for up to 30 days, or longer where legally required. Theorisis does not represent that its OpenAI project has Zero Data Retention or Modified Abuse Monitoring enabled.

For current details, see OpenAI’s API data controls.

8. Voice Capture and Read Aloud

Voice Capture starts only when you use the microphone control and grant microphone and speech-recognition permission. Raw audio is passed through Apple’s iOS speech-recognition framework for transcription. It is not sent to the StructMemo backend or OpenAI, and StructMemo does not store raw audio. Recognized text becomes local Thought content if you save it.

Read Aloud uses Apple’s on-device/system speech-synthesis framework to speak a transient copy of selected local text. StructMemo does not send Read Aloud text to its backend for speech generation and does not create an audio recording.

Apple’s processing of system speech services is governed by Apple’s settings and privacy terms.

9. Operational and diagnostic information

StructMemo retains the minimum account, subscription, transaction-verification, ownership, shared-credit, usage, and safety records needed to operate the service. Operational records may include a pseudonymous app-install identifier or its hash, internal user ID, request ID, feature and route, plan and entitlement path, status, model and provider, character or token totals, credit and cost totals, safe failure category, duration, and timestamps.

Ordinary operational diagnostics are designed not to log:

  • raw Thought titles, bodies, or note identifiers;
  • raw AI responses, full provider prompts, or backup contents;
  • authentication tokens or Apple authorization values; or
  • StoreKit signed JWS values, API keys, or server secrets.

Usage and accounting records may be associated with your account when you are signed in. StructMemo does not intentionally store raw IP addresses in its application records. Hosting, edge-network, and security providers may transiently process IP addresses and connection metadata to deliver and protect network requests.

10. Service providers and processors

  • Apple: Sign in with Apple, StoreKit billing and subscription management, purchase verification, system document providers, speech recognition, and speech synthesis.
  • OpenAI: processing the selected text, instructions, and context needed to provide requested AI features.
  • Render: hosting the StructMemo application backend and processing request and operational connection information.
  • Neon: managed database processing for the minimum account, entitlement, transaction, credit, usage, and safety records described in this policy.

These providers process information for Theorisis under their applicable service terms and data controls. A document provider you choose for an exported backup acts under your relationship with that provider.

11. International or cross-border processing

Apple, OpenAI, Render, and Neon operate internationally. Information sent to these providers may therefore be processed outside the country where you live. Categories are limited to the account, purchase, selected AI content, usage, security, and connection information described above and are transferred electronically when you use the relevant service.

Theorisis does not claim that all processing occurs in a particular country or infrastructure region. Provider routing and the live service configuration may change; provider retention and safeguards are governed by their applicable terms and configured controls.

12. Retention

  • Local library content remains on the device until you delete it, the app removes it through a feature, you replace the library during restore, or you delete the app.
  • External backups remain until you delete them from the destination you selected.
  • Account email and active Apple account fields remain while the account is active and are cleared from the user record through the implemented account-deletion flow.
  • StructMemo sessions have a 30-day expiry and may be revoked sooner by sign-out, account deletion, or security controls.
  • Transaction, entitlement, ownership, accounting, shared-credit, usage, security, fraud-prevention, and account-lineage records are kept as needed to reconcile purchases and credits, protect the service, meet accounting or legal obligations, and prevent duplicate or abusive claims. No shorter fixed period is promised where the required period depends on those purposes.
  • OpenAI’s default abuse-monitoring retention is described in Section 7.

13. Data deletion and user choices

You can:

  • delete or edit local content using available app controls;
  • delete an external backup from the provider where you saved it;
  • sign out, revoke Sign in with Apple access through Apple, or use Settings → Delete Account; and
  • manage or cancel a subscription through Apple’s subscription-management page.

Account deletion revokes available Apple authorization and StructMemo sessions, marks the StructMemo account deleted, clears email and other optional profile fields from the active user record, and expires active service entitlements in the implemented backend flow. Limited transaction, entitlement, ownership, accounting, credit, usage, security, fraud-prevention, and account-lineage records may remain for the purposes described above.

Deleting a StructMemo account does not cancel an Apple subscription, delete local Thoughts, or delete external backup files. Deleting the app removes local app data but does not delete an external backup or cancel an Apple subscription.

To request access, correction, or deletion assistance for service-side information, contact donggyu@theorisis.com. Theorisis may need to verify the request and may preserve records where necessary for the purposes described in this policy.

14. Security

StructMemo uses HTTPS for service requests, iOS Keychain for the local StructMemo session credential, hashed server-side session tokens, and encryption for stored Apple OAuth refresh tokens. Access to service data is limited to operating and protecting StructMemo.

No system is completely secure. Keep your device protected and store readable .structmemo-backup files securely. Do not share credentials, transaction payloads, or private notes in support messages unless strictly necessary and intentionally provided.

15. Children’s privacy

StructMemo is not directed to children under 13. Theorisis does not knowingly seek personal information from children under 13. If you believe a child supplied service-side personal information, contact Theorisis so the matter can be reviewed.

16. Policy changes

This policy may be updated when StructMemo’s features, providers, or data practices change. The current version and effective date will be published at this URL. Material changes will be communicated through an appropriate notice where required.

17. Contact and support

StructMemo 개인정보 처리방침

1. 개요 및 개인정보처리자

StructMemo는 로컬 우선 방식의 구조화 메모 앱입니다. 이 방침은 정식 출시 버전에서 로컬 메모 기능, 백업, 로그인, 구매 및 이용자가 직접 실행하는 AI 기능을 사용할 때 정보가 어떻게 처리되는지 설명합니다.

개인정보처리자는 Theorisis / Donggyu Kang입니다. 개인정보 관련 문의는 donggyu@theorisis.com으로 보내실 수 있습니다.

StructMemo는 개인정보를 판매하지 않으며, 다른 회사의 광고를 위한 이용자 추적에 정보를 사용하지 않습니다.

2. 로컬 콘텐츠 저장

전체 StructMemo 메모 라이브러리는 StructMemo 클라우드 저장소를 통해 자동으로 동기화되지 않습니다. 기본 로컬 메모 기능은 계정 없이 사용할 수 있습니다.

로컬에 지속적으로 저장되는 콘텐츠에는 다음 항목이 포함될 수 있습니다.

  • 워크스페이스, Thought, Code 메모, 폴더 및 계층 구조
  • 버전 기록, Upper Structure 및 Saved View
  • Smart Gravity 초안 및 구조 스냅샷
  • 라이브러리에 저장된, 화면에 보이는 AI Response 블록

외부 백업을 만들지 않은 상태에서 앱을 삭제하면 이러한 로컬 앱 데이터가 삭제됩니다. StructMemo 계정을 삭제해도 로컬 Thought가 자동으로 삭제되지는 않습니다.

3. 전체 라이브러리 백업 및 복원

설정 → 데이터 및 백업에서 전체 라이브러리 백업 라이브러리 백업 복원을 사용할 수 있습니다. 이 로컬 라이브러리 도구에는 계정이 필요하지 않습니다.

.structmemo-backup 파일에는 읽을 수 있는 메모 내용과 라이브러리 관계 정보가 들어 있으며, 위에 설명된 모든 로컬 콘텐츠 범주가 포함될 수 있습니다. 파일을 안전하게 보관하십시오. 내보낸 뒤에는 이용자와 이용자가 선택한 파일 앱, iCloud Drive 또는 기타 문서 제공업체가 해당 파일을 관리합니다.

백업에는 다음 항목이 포함되지 않습니다.

  • 인증 정보, Apple 토큰 및 키체인 세션
  • StoreKit JWS 값, 거래 내역 및 구독 상태
  • 공유 AI Credit 지갑, 지급, 예약 및 원장
  • API 키, 서버 비밀정보 및 일시적인 백엔드 요청 ID
  • 숨겨진 추론 및 기타 AI 제공업체 내부 정보

복원은 선택한 백업을 먼저 검증한 뒤, 확인 절차를 거쳐 현재 로컬 라이브러리를 교체합니다. 복원은 로그인, 구독 복원·취소 또는 AI Credit 지급을 수행하지 않습니다. StructMemo는 현재 자동 iCloud 동기화를 제공하지 않습니다.

4. 계정 및 Apple로 로그인

Apple로 로그인은 계정 인증, 구독 조정, 공유 AI Credits, AI Response, Smart Gravity, Smart Naming, 구매 복원 및 계정 삭제에 사용됩니다. 기본 로컬 메모 기능은 로그인하지 않아도 사용할 수 있습니다.

StructMemo는 Apple의 안정적인 계정 식별자를 받고, Apple이 제공하는 경우에만 이메일 주소와 이메일 상태 정보를 받습니다. 현재 앱은 Apple 표시 이름을 StructMemo 서비스로 보내지 않습니다. 이용자가 나의 이메일 가리기를 선택하면 Apple의 비공개 릴레이 이메일이 제공될 수 있습니다.

서비스는 내부 사용자 ID, 계정 또는 프로모션 Credit의 부정한 재연결을 막기 위한 보호된 계정 계보 값, 해시된 StructMemo 세션 정보, 로그인·세션 시각, 그리고 Apple이 발급한 경우 암호화된 Apple 갱신 토큰을 저장합니다. 원본 Apple ID 토큰과 인증 코드는 계정 기록으로 저장하지 않습니다.

5. 구매, 구독 및 공유 AI Credits

StructMemo Pro와 StructMemo Pro Plus는 Apple StoreKit을 통해 구매되고 결제됩니다. 결제 카드 정보는 Apple이 처리하며, StructMemo는 카드 번호를 받거나 저장하지 않습니다.

StructMemo는 이용 권한과 소유 관계를 확인하는 데 필요한 구매·구독 정보를 검증합니다. 제품 및 거래 식별자, 구매·만료·철회 시각, 환경, 검증 및 계정 소유 정보가 포함될 수 있습니다. StoreKit JWS 원문 대신 서명 거래 값의 해시를 저장합니다.

공유 AI Credit 기록에는 요금제와 기간, 지급·예약·정산·해제·환불된 Credit, 기능, 요청 및 예약 식별자, 제공업체 비용, 모델, 토큰 합계, 상태, 시각이 포함됩니다. 서비스 운영과 조정을 위해 사용되며 StructMemo 계정과 연결될 수 있습니다.

6. AI 기능과 이용자의 명시적 실행

AI 처리는 이용자가 명시적으로 기능을 실행한 뒤에만 시작됩니다. 기능에 따라 요청 수행에 필요한 다음 정보가 StructMemo 백엔드를 거쳐 OpenAI로 전송될 수 있습니다.

  • Smart Gravity: 이용자가 생성을 요청한 뒤 대상이 되는 Thought 또는 Code 내용, 제목, 정리 지시 및 구조적 문맥
  • AI Response: 이용자가 생성을 확인한 뒤 원본 Thought와 선택적 지시문
  • Smart Naming: 기능이 켜진 상태에서 해당 저장 또는 이름 짓기 동작을 수행할 때 현재 제목과 길이가 제한된 본문 미리보기

생성된 AI Response 텍스트는 앱으로 돌아오며 화면에 보이는 로컬 응답 블록으로 저장될 수 있습니다. StructMemo 백엔드는 전체 메모 라이브러리를 위한 일반 클라우드 동기화 서비스가 아닙니다.

7. OpenAI 처리 및 보유

StructMemo는 OpenAI Responses API를 사용합니다. 현재 StructMemo의 모든 Responses API 요청은 store: false를 명시적으로 설정하므로, 이 API 설정을 통해 지속적인 응답 객체를 의도적으로 만들지 않습니다.

OpenAI는 API 고객이 명시적으로 동의하지 않는 한 API 입력과 출력을 기본적으로 모델 학습에 사용하지 않는다고 안내합니다. OpenAI의 기본 통제에서는 악용 모니터링 로그에 프롬프트와 응답이 포함될 수 있고, 최대 30일 동안 보관될 수 있으며 법률상 필요한 경우 더 오래 보관될 수 있습니다. Theorisis는 현재 OpenAI 프로젝트에 Zero Data Retention 또는 Modified Abuse Monitoring이 적용되어 있다고 주장하지 않습니다.

최신 내용은 OpenAI의 API 데이터 통제 문서를 확인하십시오.

8. 음성 입력 및 소리 내어 읽기

음성 입력은 이용자가 마이크 버튼을 누르고 마이크 및 음성 인식 권한을 허용한 경우에만 시작됩니다. 원본 음성은 전사를 위해 Apple의 iOS 음성 인식 프레임워크로 전달됩니다. StructMemo 백엔드나 OpenAI로 보내지지 않으며 StructMemo는 원본 음성을 저장하지 않습니다. 인식된 텍스트를 저장하면 로컬 Thought 콘텐츠가 됩니다.

소리 내어 읽기는 Apple의 기기/시스템 음성 합성 프레임워크를 사용하여 선택한 로컬 텍스트의 일시적인 사본을 읽습니다. StructMemo는 음성 생성을 위해 이 텍스트를 백엔드로 보내지 않으며 오디오 녹음을 만들지 않습니다.

시스템 음성 서비스에 대한 Apple의 처리는 Apple 설정 및 개인정보 보호 조건에 따릅니다.

9. 운영 및 진단 정보

StructMemo는 서비스 운영에 필요한 최소한의 계정, 구독, 거래 검증, 소유권, 공유 Credit, 사용량 및 안전 기록을 보유합니다. 운영 기록에는 가명화된 앱 설치 식별자 또는 그 해시, 내부 사용자 ID, 요청 ID, 기능과 경로, 요금제와 이용 권한 경로, 상태, 모델과 제공업체, 글자·토큰 합계, Credit·비용 합계, 안전한 실패 범주, 처리 시간 및 시각이 포함될 수 있습니다.

일반 운영 진단은 다음 정보를 기록하지 않도록 설계되어 있습니다.

  • 원본 Thought 제목·본문 또는 메모 식별자
  • 원본 AI 응답, 전체 제공업체 프롬프트 또는 백업 내용
  • 인증 토큰 또는 Apple 인증 값
  • StoreKit 서명 JWS 값, API 키 또는 서버 비밀정보

로그인 상태에서는 사용량 및 회계 기록이 계정과 연결될 수 있습니다. StructMemo는 앱 데이터 기록에 원본 IP 주소를 의도적으로 저장하지 않습니다. 호스팅, 엣지 네트워크 및 보안 제공업체는 네트워크 요청을 전달하고 보호하기 위해 IP 주소와 연결 메타데이터를 일시적으로 처리할 수 있습니다.

10. 서비스 제공업체 및 처리위탁

  • Apple: Apple로 로그인, StoreKit 결제 및 구독 관리, 구매 검증, 시스템 문서 제공업체, 음성 인식 및 음성 합성
  • OpenAI: 이용자가 요청한 AI 기능 제공에 필요한 선택 텍스트, 지시 및 문맥 처리
  • Render: StructMemo 애플리케이션 백엔드 호스팅, 요청 및 운영 연결 정보 처리
  • Neon: 이 방침에 설명된 최소한의 계정, 이용 권한, 거래, Credit, 사용량 및 안전 기록을 위한 관리형 데이터베이스 처리

이 업체들은 관련 서비스 조건과 데이터 통제에 따라 Theorisis를 위해 정보를 처리합니다. 이용자가 백업을 저장하기 위해 선택한 문서 제공업체는 이용자와 해당 제공업체 사이의 관계에 따라 파일을 처리합니다.

11. 국외 처리

Apple, OpenAI, Render 및 Neon은 국제적으로 서비스를 운영하므로, 이들 업체에 전송된 정보는 이용자가 거주하는 국가 밖에서 처리될 수 있습니다. 처리 항목은 위에서 설명한 계정, 구매, 이용자가 선택한 AI 콘텐츠, 사용량, 보안 및 연결 정보로 제한되며, 이용자가 관련 기능을 사용할 때 전자적 방식으로 전송됩니다.

Theorisis는 모든 처리가 특정 국가 또는 인프라 리전에서 이루어진다고 단정하지 않습니다. 제공업체의 라우팅과 실제 서비스 설정은 변경될 수 있으며, 보유 기간과 보호조치는 각 제공업체의 적용 조건 및 설정된 통제에 따릅니다.

12. 보유 및 이용 기간

  • 로컬 라이브러리 콘텐츠는 이용자가 삭제하거나, 앱 기능으로 제거되거나, 복원 과정에서 라이브러리를 교체하거나, 앱을 삭제할 때까지 기기에 남습니다.
  • 외부 백업은 이용자가 선택한 저장 위치에서 직접 삭제할 때까지 남습니다.
  • 계정 이메일과 활성 Apple 계정 정보는 계정이 활성 상태인 동안 보유되며, 구현된 계정 삭제 절차를 통해 사용자 기록에서 지워집니다.
  • StructMemo 세션은 30일의 만료 기간을 가지며 로그아웃, 계정 삭제 또는 보안 통제에 따라 더 일찍 철회될 수 있습니다.
  • 거래, 이용 권한, 소유권, 회계, 공유 Credit, 사용량, 보안, 부정 이용 방지 및 계정 계보 기록은 구매와 Credit 조정, 서비스 보호, 회계 또는 법적 의무, 중복·부정 청구 방지에 필요한 기간 동안 보유됩니다. 필요한 기간이 목적에 따라 달라지는 기록에 대해 그보다 짧은 고정 기간을 약속하지 않습니다.
  • OpenAI의 기본 악용 모니터링 보유 기간은 제7항에 설명되어 있습니다.

13. 삭제 및 이용자 선택권

이용자는 다음과 같은 선택을 할 수 있습니다.

  • 앱에서 제공되는 기능으로 로컬 콘텐츠를 수정하거나 삭제
  • 저장한 문서 제공업체에서 외부 백업 파일을 직접 삭제
  • 로그아웃, Apple에서 Apple로 로그인 접근 철회, 또는 설정 → 계정 삭제 이용
  • Apple 구독 관리 페이지에서 구독 관리 또는 취소

계정 삭제는 사용 가능한 Apple 인증과 StructMemo 세션을 철회하고, StructMemo 계정을 삭제 상태로 전환하며, 활성 사용자 기록에서 이메일과 기타 선택적 프로필 정보를 지우고, 구현된 백엔드 절차에 따라 활성 서비스 이용 권한을 만료 처리합니다. 거래, 이용 권한, 소유권, 회계, Credit, 사용량, 보안, 부정 이용 방지 및 계정 계보 기록은 위 목적을 위해 제한적으로 남을 수 있습니다.

StructMemo 계정 삭제는 Apple 구독을 취소하지 않으며, 로컬 Thought나 외부 백업 파일을 삭제하지 않습니다. 앱을 삭제하면 로컬 앱 데이터는 제거되지만 외부 백업이나 Apple 구독은 삭제·취소되지 않습니다.

서비스 측 정보의 열람, 정정, 삭제 또는 동의 철회 관련 지원은 donggyu@theorisis.com으로 요청할 수 있습니다. Theorisis는 요청 확인을 위해 본인 확인을 요구할 수 있으며, 이 방침에 설명된 목적상 필요한 기록은 보존할 수 있습니다.

14. 보안

StructMemo는 서비스 요청에 HTTPS를 사용하고, 로컬 StructMemo 세션 정보는 iOS 키체인에 저장하며, 서버 세션 토큰은 해시 형태로 저장하고, 보관되는 Apple OAuth 갱신 토큰은 암호화합니다. 서비스 데이터 접근은 StructMemo 운영 및 보호에 필요한 범위로 제한합니다.

어떤 시스템도 완전히 안전할 수는 없습니다. 기기를 안전하게 보호하고, 읽을 수 있는 .structmemo-backup 파일을 안전하게 보관하십시오. 반드시 필요하고 이용자가 의도적으로 제공하는 경우가 아니라면 지원 메일에 인증 정보, 거래 자료 또는 비공개 메모를 보내지 마십시오.

15. 아동의 개인정보

StructMemo는 만 13세 미만 아동을 대상으로 하지 않으며, Theorisis는 만 13세 미만 아동의 개인정보를 의도적으로 수집하지 않습니다. 아동이 서비스 측 개인정보를 제공했다고 생각되면 검토할 수 있도록 Theorisis에 문의하십시오.

16. 방침 변경

StructMemo의 기능, 제공업체 또는 정보 처리 방식이 바뀌면 이 방침을 업데이트할 수 있습니다. 최신 방침과 시행일은 이 URL에 게시합니다. 중요한 변경은 필요한 경우 적절한 방법으로 알립니다.

17. 문의 및 지원

개인정보처리자: Theorisis / Donggyu Kang
이메일: donggyu@theorisis.com
지원: https://www.theorisis.com/structmemo/support
개인정보 처리방침: https://www.theorisis.com/structmemo/privacy