Skip to English content

StructMemo · Privacy

StructMemo Privacy Policy

StructMemo 개인정보 처리방침

Policy ID: structmemo-privacy · Version: 2026-09-10.1 · Effective 2026-09-10

방침 ID: structmemo-privacy · 버전: 2026-09-10.1 · 2026-09-10 시행

StructMemo Privacy Policy

1. Overview and controller identity

StructMemo is a local-first structured note application. This policy explains how the production release handles information when you use local note features, create a backup, sign in, make a purchase, explicitly request an AI feature, or expressly publish content through Signals.

The controller is Theorisis LLC. For privacy questions, email donggyu@theorisis.com.

StructMemo does not sell personal information and does not use information for cross-company advertising tracking.

2. Local content storage

The complete StructMemo note library is not automatically synchronized through StructMemo cloud storage. Basic local note features do not require an account.

Local persistent content may include:

  • workspaces, Thoughts, Code notes, folders, and hierarchy;
  • Version History, Upper Structures, and Saved Views;
  • Smart Gravity drafts and structure snapshots; and
  • visible AI Response blocks saved in the library.

Deleting the app removes this local app data unless you created an external backup. Deleting a StructMemo account does not automatically delete local Thoughts.

3. Full-library backup and restore

Settings → Data & Backup provides Back Up Entire Library and Restore Library Backup. An account is not required to use these local-library tools.

A .structmemo-backup file contains readable note content and the relationships needed to reconstruct the library. It may include all local content categories listed above. Store it securely. After you export it, the file is controlled by you and by the Files, iCloud Drive, or other document provider you selected.

The backup excludes:

  • authentication credentials, Apple tokens, and Keychain sessions;
  • StoreKit JWS values, transactions, and subscription state;
  • shared-credit wallets, grants, reservations, and ledgers;
  • API keys, server secrets, and transient backend request IDs; and
  • hidden reasoning and other provider-internal information.

Restore validates the selected backup and, after confirmation, replaces the current local library. It does not sign you in, restore or cancel a subscription, or grant AI Credits. StructMemo does not currently provide automatic iCloud synchronization.

4. Accounts and Sign in with Apple

Sign in with Apple is used for account authentication, subscription reconciliation, shared AI Credits, AI Response, Smart Gravity, Smart Naming, Restore Purchases, and account deletion. Core local note features remain available without signing in.

StructMemo receives Apple’s stable account subject identifier and, only when Apple supplies them, an email address and email-status fields. The current app does not send your Apple display name to the StructMemo service. Apple may provide a private relay email if you choose Hide My Email.

The service stores an internal user ID, a protected account-lineage value used to prevent account or promotional-credit relinking abuse, hashed StructMemo session credentials, login and session timestamps, and an encrypted Apple refresh token when Apple returns one. Raw Apple identity tokens and authorization codes are not stored as account records.

5. Purchases, subscriptions, and shared AI Credits

StructMemo Pro and StructMemo Pro Plus are purchased and billed through Apple StoreKit. Apple processes payment-card information. StructMemo does not receive or store payment-card numbers.

StructMemo verifies purchase and subscription information needed to determine entitlement and ownership. Records may include product and transaction identifiers, purchase, expiration, revocation, environment, verification, and account-ownership information. StructMemo stores a hash of the signed transaction payload rather than the StoreKit JWS value itself.

Shared AI Credit records include the plan and period, granted, reserved, settled, released, or refunded credits, feature, request and reservation identifiers, provider cost, model, token totals, status, and timestamps. These records operate and reconcile the service and may be linked to your StructMemo account.

6. AI features and explicit user initiation

AI processing begins only after an explicit user action. Depending on the feature, StructMemo may send the content necessary to perform your request through the StructMemo backend to OpenAI:

  • Smart Gravity: eligible selected Thought or Code content, titles, your organization instruction, and structural context after you request generation;
  • AI Response: the source Thought and an optional instruction after you confirm generation;
  • Smart Naming: the current title and a bounded text preview when the feature is enabled and you perform the applicable save or naming action; and
  • Living Layer generation (Studio): the text prompt you enter and a bounded structural schema after you ask the app to generate a Living Layer. The result is a procedural recipe that is rendered on your device.

Generated AI Response text returns to the app and may be saved as a visible local response block. The StructMemo backend is not general cloud synchronization for the full note library.

Every plan receives one included Living Layer generation per account per UTC day. On paid plans, further generations use monthly AI Credits only after you explicitly confirm the request. StructMemo keeps usage and cost records for these requests (provider work claims and the credit ledger) as operational records; StructMemo does not log the prompt text itself.

7. OpenAI processing and retention

StructMemo uses OpenAI’s Responses API. Every current StructMemo Responses API request explicitly sets store: false, so StructMemo requests do not intentionally create persistent response objects through that API setting. This includes Living Layer generation requests. Signals public-content safety screening (Section 16) uses OpenAI’s moderation endpoint; see the same OpenAI documentation linked below for that endpoint’s data controls.

OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Under OpenAI’s default controls, abuse-monitoring logs may contain prompts and responses and may be retained for up to 30 days, or longer where legally required. Theorisis does not represent that its OpenAI project has Zero Data Retention or Modified Abuse Monitoring enabled.

For current details, see OpenAI’s API data controls.

8. Voice Capture and Read Aloud

Voice Capture starts only when you use the microphone control and grant microphone and speech-recognition permission. Raw audio is passed through Apple’s iOS speech-recognition framework for transcription. It is not sent to the StructMemo backend or OpenAI, and StructMemo does not store raw audio. Recognized text becomes local Thought content if you save it.

Read Aloud uses Apple’s on-device/system speech-synthesis framework to speak a transient copy of selected local text. StructMemo does not send Read Aloud text to its backend for speech generation and does not create an audio recording.

Apple’s processing of system speech services is governed by Apple’s settings and privacy terms.

9. Operational and diagnostic information

StructMemo retains the minimum account, subscription, transaction-verification, ownership, shared-credit, usage, and safety records needed to operate the service. Operational records may include a pseudonymous app-install identifier or its hash, internal user ID, request ID, feature and route, plan and entitlement path, status, model and provider, character or token totals, credit and cost totals, safe failure category, duration, and timestamps.

Ordinary operational diagnostics are designed not to log:

  • raw Thought titles, bodies, or note identifiers;
  • raw AI responses, full provider prompts, Living Layer prompt text, or backup contents;
  • authentication tokens or Apple authorization values; or
  • StoreKit signed JWS values, API keys, or server secrets.

Usage and accounting records may be associated with your account when you are signed in. StructMemo does not intentionally store raw IP addresses in its application records. Hosting, edge-network, and security providers may transiently process IP addresses and connection metadata to deliver and protect network requests.

10. Service providers and processors

  • Apple: Sign in with Apple, StoreKit billing and subscription management, purchase verification, system document providers, speech recognition, and speech synthesis.
  • OpenAI: processing the selected text, instructions, and context needed to provide requested AI features.
  • Render: hosting the StructMemo application backend and processing request and operational connection information.
  • Neon: managed database processing for the minimum account, entitlement, transaction, credit, usage, and safety records described in this policy.
  • Cloudflare, Inc.: R2 object storage for image bytes you expressly publish through Signals (public appearance or Vision images, Photo Note public image revisions, and shared layer-package rendered states) and for moderation evidence copies of those images. The bucket is private: the StructMemo backend reads each object on request, with no public bucket URLs and no CDN cache. Private library content is never stored there.

These providers process information for Theorisis under their applicable service terms and data controls. A document provider you choose for an exported backup acts under your relationship with that provider.

11. International or cross-border processing

Apple, OpenAI, Render, Neon, and Cloudflare operate internationally. Information sent to these providers may therefore be processed outside the country where you live. Categories are limited to the account, purchase, selected AI content, expressly published public content, usage, security, and connection information described above and are transferred electronically when you use the relevant service.

Theorisis does not claim that all processing occurs in a particular country or infrastructure region. Provider routing and the live service configuration may change; provider retention and safeguards are governed by their applicable terms and configured controls.

12. Retention

  • Local library content remains on the device until you delete it, the app removes it through a feature, you replace the library during restore, or you delete the app.
  • External backups remain until you delete them from the destination you selected.
  • Account email and active Apple account fields remain while the account is active and are cleared from the user record through the implemented account-deletion flow.
  • StructMemo sessions have a 30-day expiry and may be revoked sooner by sign-out, account deletion, or security controls.
  • Transaction, entitlement, ownership, accounting, shared-credit, usage, security, fraud-prevention, and account-lineage records are kept as needed to reconcile purchases and credits, protect the service, meet accounting or legal obligations, and prevent duplicate or abusive claims. No shorter fixed period is promised where the required period depends on those purposes.
  • Image objects for content you expressly published through Signals, and their moderation evidence copies, remain in private object storage while the content is public or under review. When you unpublish or delete the content or delete your account, the stored object is queued for deletion and is removed from object storage when StructMemo processes the deletion queue.
  • Report and moderation audit records are retained for as long as needed for safety, dispute, and legal purposes.
  • OpenAI’s default abuse-monitoring retention is described in Section 7.

13. Data deletion and user choices

You can:

  • delete or edit local content using available app controls;
  • delete an external backup from the provider where you saved it;
  • unpublish or delete content you published through Signals using the app’s controls;
  • sign out, revoke Sign in with Apple access through Apple, or use Settings → Delete Account; and
  • manage or cancel a subscription through Apple’s subscription-management page.

Account deletion revokes available Apple authorization and StructMemo sessions, marks the StructMemo account deleted, clears email and other optional profile fields from the active user record, and expires active service entitlements in the implemented backend flow. Limited transaction, entitlement, ownership, accounting, credit, usage, security, fraud-prevention, and account-lineage records may remain for the purposes described above.

Unpublishing or deleting content you published through Signals, or deleting your account, immediately makes that content non-public in the StructMemo database and queues the stored image object for deletion as described in Section 12. Report and moderation audit records may be retained for safety, dispute, and legal purposes.

Deleting a StructMemo account does not cancel an Apple subscription, delete local Thoughts, or delete external backup files. Deleting the app removes local app data but does not delete an external backup or cancel an Apple subscription.

To request access, correction, or deletion assistance for service-side information, contact donggyu@theorisis.com. Theorisis may need to verify the request and may preserve records where necessary for the purposes described in this policy.

14. Security

StructMemo uses HTTPS for service requests, iOS Keychain for the local StructMemo session credential, hashed server-side session tokens, and encryption for stored Apple OAuth refresh tokens. Access to service data is limited to operating and protecting StructMemo.

No system is completely secure. Keep your device protected and store readable .structmemo-backup files securely. Do not share credentials, transaction payloads, or private notes in support messages unless strictly necessary and intentionally provided.

15. Children’s privacy

StructMemo is not directed to children under 13. Theorisis does not knowingly seek personal information from children under 13. If you believe a child supplied service-side personal information, contact Theorisis so the matter can be reviewed.

16. Signals public-content safety screening and public images

When you expressly choose content for publication through Signals, StructMemo may send only the candidate public content needed for safety screening to OpenAI: candidate public text, sanitized candidate public images, and server-rendered Layers Included or Process View candidate public images. This processing occurs before the content becomes publicly readable.

When you expressly publish a photo-bearing Signal (a Photo Note public image), the server re-encodes the image as a JPEG of at most 2048 pixels on its longest side and at most 5 MiB. Embedded EXIF, orientation, and ICC metadata is not retained: the upload is rejected or the metadata is stripped during re-encoding. The sanitized image is screened by OpenAI’s moderation endpoint together with the Signal text and is then stored in the private object storage described in Section 10. Image-bearing Signals are subject to a monthly allowance by plan: 1 on Free, 12 on Pro, and 30 on Pro Plus.

StructMemo does not send your private Thought, private Vision, complete private library, content you did not select for publication, email, Apple ID, StructMemo internal user or content ID, authentication secret or token, or original EXIF or location information for this screening.

Automated moderation may permit safe content to become public, reject violating content before publication, or keep uncertain content private for human review. See the proposed bilingual StructMemo Public Content Terms.

17. Policy changes

This policy may be updated when StructMemo’s features, providers, or data practices change. The current version and effective date will be published at this URL. Material changes will be communicated through an appropriate notice where required.

Changes in version 2026-09-10.1: added Cloudflare R2 private object storage for expressly published Signals images and moderation evidence copies (Sections 10–12); described Photo Note public image re-encoding, screening, and monthly allowances (Section 16); described Living Layer generation in Studio, its included daily generation, AI Credit use, and operational records (Sections 6, 7, and 9); and described how unpublishing, deleting content, or deleting an account affects stored public images and moderation records (Sections 12 and 13).

18. Contact and support

StructMemo 개인정보 처리방침

1. 개요 및 개인정보처리자

StructMemo는 로컬 우선 방식의 구조화 메모 앱입니다. 이 방침은 정식 출시 버전에서 로컬 메모 기능, 백업, 로그인, 구매, 이용자가 직접 실행하는 AI 기능 및 Signals를 통한 명시적 공개 기능을 사용할 때 정보가 어떻게 처리되는지 설명합니다.

개인정보처리자는 Theorisis LLC입니다. 개인정보 관련 문의는 donggyu@theorisis.com으로 보내실 수 있습니다.

StructMemo는 개인정보를 판매하지 않으며, 다른 회사의 광고를 위한 이용자 추적에 정보를 사용하지 않습니다.

2. 로컬 콘텐츠 저장

전체 StructMemo 메모 라이브러리는 StructMemo 클라우드 저장소를 통해 자동으로 동기화되지 않습니다. 기본 로컬 메모 기능은 계정 없이 사용할 수 있습니다.

로컬에 지속적으로 저장되는 콘텐츠에는 다음 항목이 포함될 수 있습니다.

  • 워크스페이스, Thought, Code 메모, 폴더 및 계층 구조
  • 버전 기록, Upper Structure 및 Saved View
  • Smart Gravity 초안 및 구조 스냅샷
  • 라이브러리에 저장된, 화면에 보이는 AI Response 블록

외부 백업을 만들지 않은 상태에서 앱을 삭제하면 이러한 로컬 앱 데이터가 삭제됩니다. StructMemo 계정을 삭제해도 로컬 Thought가 자동으로 삭제되지는 않습니다.

3. 전체 라이브러리 백업 및 복원

설정 → 데이터 및 백업에서 전체 라이브러리 백업 라이브러리 백업 복원을 사용할 수 있습니다. 이 로컬 라이브러리 도구에는 계정이 필요하지 않습니다.

.structmemo-backup 파일에는 읽을 수 있는 메모 내용과 라이브러리 관계 정보가 들어 있으며, 위에 설명된 모든 로컬 콘텐츠 범주가 포함될 수 있습니다. 파일을 안전하게 보관하십시오. 내보낸 뒤에는 이용자와 이용자가 선택한 파일 앱, iCloud Drive 또는 기타 문서 제공업체가 해당 파일을 관리합니다.

백업에는 다음 항목이 포함되지 않습니다.

  • 인증 정보, Apple 토큰 및 키체인 세션
  • StoreKit JWS 값, 거래 내역 및 구독 상태
  • 공유 AI Credit 지갑, 지급, 예약 및 원장
  • API 키, 서버 비밀정보 및 일시적인 백엔드 요청 ID
  • 숨겨진 추론 및 기타 AI 제공업체 내부 정보

복원은 선택한 백업을 먼저 검증한 뒤, 확인 절차를 거쳐 현재 로컬 라이브러리를 교체합니다. 복원은 로그인, 구독 복원·취소 또는 AI Credit 지급을 수행하지 않습니다. StructMemo는 현재 자동 iCloud 동기화를 제공하지 않습니다.

4. 계정 및 Apple로 로그인

Apple로 로그인은 계정 인증, 구독 조정, 공유 AI Credits, AI Response, Smart Gravity, Smart Naming, 구매 복원 및 계정 삭제에 사용됩니다. 기본 로컬 메모 기능은 로그인하지 않아도 사용할 수 있습니다.

StructMemo는 Apple의 안정적인 계정 식별자를 받고, Apple이 제공하는 경우에만 이메일 주소와 이메일 상태 정보를 받습니다. 현재 앱은 Apple 표시 이름을 StructMemo 서비스로 보내지 않습니다. 이용자가 나의 이메일 가리기를 선택하면 Apple의 비공개 릴레이 이메일이 제공될 수 있습니다.

서비스는 내부 사용자 ID, 계정 또는 프로모션 Credit의 부정한 재연결을 막기 위한 보호된 계정 계보 값, 해시된 StructMemo 세션 정보, 로그인·세션 시각, 그리고 Apple이 발급한 경우 암호화된 Apple 갱신 토큰을 저장합니다. 원본 Apple ID 토큰과 인증 코드는 계정 기록으로 저장하지 않습니다.

5. 구매, 구독 및 공유 AI Credits

StructMemo Pro와 StructMemo Pro Plus는 Apple StoreKit을 통해 구매되고 결제됩니다. 결제 카드 정보는 Apple이 처리하며, StructMemo는 카드 번호를 받거나 저장하지 않습니다.

StructMemo는 이용 권한과 소유 관계를 확인하는 데 필요한 구매·구독 정보를 검증합니다. 제품 및 거래 식별자, 구매·만료·철회 시각, 환경, 검증 및 계정 소유 정보가 포함될 수 있습니다. StoreKit JWS 원문 대신 서명 거래 값의 해시를 저장합니다.

공유 AI Credit 기록에는 요금제와 기간, 지급·예약·정산·해제·환불된 Credit, 기능, 요청 및 예약 식별자, 제공업체 비용, 모델, 토큰 합계, 상태, 시각이 포함됩니다. 서비스 운영과 조정을 위해 사용되며 StructMemo 계정과 연결될 수 있습니다.

6. AI 기능과 이용자의 명시적 실행

AI 처리는 이용자가 명시적으로 기능을 실행한 뒤에만 시작됩니다. 기능에 따라 요청 수행에 필요한 다음 정보가 StructMemo 백엔드를 거쳐 OpenAI로 전송될 수 있습니다.

  • Smart Gravity: 이용자가 생성을 요청한 뒤 대상이 되는 Thought 또는 Code 내용, 제목, 정리 지시 및 구조적 문맥
  • AI Response: 이용자가 생성을 확인한 뒤 원본 Thought와 선택적 지시문
  • Smart Naming: 기능이 켜진 상태에서 해당 저장 또는 이름 짓기 동작을 수행할 때 현재 제목과 길이가 제한된 본문 미리보기
  • Living Layer 생성(Studio): 이용자가 앱에 Living Layer 생성을 요청한 뒤 입력한 텍스트 프롬프트와 길이가 제한된 구조 스키마. 결과는 절차적 레시피 형태로 반환되어 이용자의 기기에서 렌더링됩니다.

생성된 AI Response 텍스트는 앱으로 돌아오며 화면에 보이는 로컬 응답 블록으로 저장될 수 있습니다. StructMemo 백엔드는 전체 메모 라이브러리를 위한 일반 클라우드 동기화 서비스가 아닙니다.

모든 요금제는 계정당 UTC 기준 하루 1회의 Living Layer 생성을 기본으로 제공합니다. 유료 요금제에서 그 이상의 생성은 이용자가 명시적으로 확인한 뒤에만 월간 AI Credits를 사용합니다. StructMemo는 이러한 요청의 사용량 및 비용 기록(제공업체 작업 청구 기록과 Credit 원장)을 운영 기록으로 보유하며, 프롬프트 텍스트 자체는 기록하지 않습니다.

7. OpenAI 처리 및 보유

StructMemo는 OpenAI Responses API를 사용합니다. 현재 StructMemo의 모든 Responses API 요청은 store: false를 명시적으로 설정하므로, 이 API 설정을 통해 지속적인 응답 객체를 의도적으로 만들지 않습니다. Living Layer 생성 요청도 여기에 포함됩니다. 제16항의 Signals 공개 콘텐츠 안전성 검사는 OpenAI의 모더레이션 엔드포인트를 사용하며, 해당 엔드포인트의 데이터 통제는 아래에 연결된 같은 OpenAI 문서를 확인하십시오.

OpenAI는 API 고객이 명시적으로 동의하지 않는 한 API 입력과 출력을 기본적으로 모델 학습에 사용하지 않는다고 안내합니다. OpenAI의 기본 통제에서는 악용 모니터링 로그에 프롬프트와 응답이 포함될 수 있고, 최대 30일 동안 보관될 수 있으며 법률상 필요한 경우 더 오래 보관될 수 있습니다. Theorisis는 현재 OpenAI 프로젝트에 Zero Data Retention 또는 Modified Abuse Monitoring이 적용되어 있다고 주장하지 않습니다.

최신 내용은 OpenAI의 API 데이터 통제 문서를 확인하십시오.

8. 음성 입력 및 소리 내어 읽기

음성 입력은 이용자가 마이크 버튼을 누르고 마이크 및 음성 인식 권한을 허용한 경우에만 시작됩니다. 원본 음성은 전사를 위해 Apple의 iOS 음성 인식 프레임워크로 전달됩니다. StructMemo 백엔드나 OpenAI로 보내지지 않으며 StructMemo는 원본 음성을 저장하지 않습니다. 인식된 텍스트를 저장하면 로컬 Thought 콘텐츠가 됩니다.

소리 내어 읽기는 Apple의 기기/시스템 음성 합성 프레임워크를 사용하여 선택한 로컬 텍스트의 일시적인 사본을 읽습니다. StructMemo는 음성 생성을 위해 이 텍스트를 백엔드로 보내지 않으며 오디오 녹음을 만들지 않습니다.

시스템 음성 서비스에 대한 Apple의 처리는 Apple 설정 및 개인정보 보호 조건에 따릅니다.

9. 운영 및 진단 정보

StructMemo는 서비스 운영에 필요한 최소한의 계정, 구독, 거래 검증, 소유권, 공유 Credit, 사용량 및 안전 기록을 보유합니다. 운영 기록에는 가명화된 앱 설치 식별자 또는 그 해시, 내부 사용자 ID, 요청 ID, 기능과 경로, 요금제와 이용 권한 경로, 상태, 모델과 제공업체, 글자·토큰 합계, Credit·비용 합계, 안전한 실패 범주, 처리 시간 및 시각이 포함될 수 있습니다.

일반 운영 진단은 다음 정보를 기록하지 않도록 설계되어 있습니다.

  • 원본 Thought 제목·본문 또는 메모 식별자
  • 원본 AI 응답, 전체 제공업체 프롬프트, Living Layer 프롬프트 텍스트 또는 백업 내용
  • 인증 토큰 또는 Apple 인증 값
  • StoreKit 서명 JWS 값, API 키 또는 서버 비밀정보

로그인 상태에서는 사용량 및 회계 기록이 계정과 연결될 수 있습니다. StructMemo는 앱 데이터 기록에 원본 IP 주소를 의도적으로 저장하지 않습니다. 호스팅, 엣지 네트워크 및 보안 제공업체는 네트워크 요청을 전달하고 보호하기 위해 IP 주소와 연결 메타데이터를 일시적으로 처리할 수 있습니다.

10. 서비스 제공업체 및 처리위탁

  • Apple: Apple로 로그인, StoreKit 결제 및 구독 관리, 구매 검증, 시스템 문서 제공업체, 음성 인식 및 음성 합성
  • OpenAI: 이용자가 요청한 AI 기능 제공에 필요한 선택 텍스트, 지시 및 문맥 처리
  • Render: StructMemo 애플리케이션 백엔드 호스팅, 요청 및 운영 연결 정보 처리
  • Neon: 이 방침에 설명된 최소한의 계정, 이용 권한, 거래, Credit, 사용량 및 안전 기록을 위한 관리형 데이터베이스 처리
  • Cloudflare, Inc.: 이용자가 Signals를 통해 명시적으로 공개한 이미지 데이터(공개 appearance 또는 Vision 이미지, Photo Note 공개 이미지 수정본, 공유된 레이어 패키지 렌더링 상태)와 해당 이미지의 모더레이션 증거 사본을 위한 R2 객체 저장소. 버킷은 비공개이며, StructMemo 백엔드가 요청 시마다 객체를 직접 읽습니다. 공개 버킷 URL이나 CDN 캐시는 사용하지 않습니다. 비공개 라이브러리 콘텐츠는 이곳에 저장되지 않습니다.

이 업체들은 관련 서비스 조건과 데이터 통제에 따라 Theorisis를 위해 정보를 처리합니다. 이용자가 백업을 저장하기 위해 선택한 문서 제공업체는 이용자와 해당 제공업체 사이의 관계에 따라 파일을 처리합니다.

11. 국외 처리

Apple, OpenAI, Render, Neon 및 Cloudflare는 국제적으로 서비스를 운영하므로, 이들 업체에 전송된 정보는 이용자가 거주하는 국가 밖에서 처리될 수 있습니다. 처리 항목은 위에서 설명한 계정, 구매, 이용자가 선택한 AI 콘텐츠, 명시적으로 공개한 공개 콘텐츠, 사용량, 보안 및 연결 정보로 제한되며, 이용자가 관련 기능을 사용할 때 전자적 방식으로 전송됩니다.

Theorisis는 모든 처리가 특정 국가 또는 인프라 리전에서 이루어진다고 단정하지 않습니다. 제공업체의 라우팅과 실제 서비스 설정은 변경될 수 있으며, 보유 기간과 보호조치는 각 제공업체의 적용 조건 및 설정된 통제에 따릅니다.

12. 보유 및 이용 기간

  • 로컬 라이브러리 콘텐츠는 이용자가 삭제하거나, 앱 기능으로 제거되거나, 복원 과정에서 라이브러리를 교체하거나, 앱을 삭제할 때까지 기기에 남습니다.
  • 외부 백업은 이용자가 선택한 저장 위치에서 직접 삭제할 때까지 남습니다.
  • 계정 이메일과 활성 Apple 계정 정보는 계정이 활성 상태인 동안 보유되며, 구현된 계정 삭제 절차를 통해 사용자 기록에서 지워집니다.
  • StructMemo 세션은 30일의 만료 기간을 가지며 로그아웃, 계정 삭제 또는 보안 통제에 따라 더 일찍 철회될 수 있습니다.
  • 거래, 이용 권한, 소유권, 회계, 공유 Credit, 사용량, 보안, 부정 이용 방지 및 계정 계보 기록은 구매와 Credit 조정, 서비스 보호, 회계 또는 법적 의무, 중복·부정 청구 방지에 필요한 기간 동안 보유됩니다. 필요한 기간이 목적에 따라 달라지는 기록에 대해 그보다 짧은 고정 기간을 약속하지 않습니다.
  • 이용자가 Signals를 통해 명시적으로 공개한 콘텐츠의 이미지 객체와 그 모더레이션 증거 사본은 콘텐츠가 공개 상태이거나 검토 중인 동안 비공개 객체 저장소에 보관됩니다. 콘텐츠를 비공개로 전환하거나 삭제하거나 계정을 삭제하면 저장된 객체는 삭제 대기열에 등록되며 StructMemo가 삭제 대기열을 처리할 때 객체 저장소에서 제거됩니다.
  • 신고 및 모더레이션 감사 기록은 안전, 분쟁 및 법적 목적에 필요한 기간 동안 보유됩니다.
  • OpenAI의 기본 악용 모니터링 보유 기간은 제7항에 설명되어 있습니다.

13. 삭제 및 이용자 선택권

이용자는 다음과 같은 선택을 할 수 있습니다.

  • 앱에서 제공되는 기능으로 로컬 콘텐츠를 수정하거나 삭제
  • 저장한 문서 제공업체에서 외부 백업 파일을 직접 삭제
  • 앱 기능으로 Signals를 통해 공개한 콘텐츠를 비공개로 전환하거나 삭제
  • 로그아웃, Apple에서 Apple로 로그인 접근 철회, 또는 설정 → 계정 삭제 이용
  • Apple 구독 관리 페이지에서 구독 관리 또는 취소

계정 삭제는 사용 가능한 Apple 인증과 StructMemo 세션을 철회하고, StructMemo 계정을 삭제 상태로 전환하며, 활성 사용자 기록에서 이메일과 기타 선택적 프로필 정보를 지우고, 구현된 백엔드 절차에 따라 활성 서비스 이용 권한을 만료 처리합니다. 거래, 이용 권한, 소유권, 회계, Credit, 사용량, 보안, 부정 이용 방지 및 계정 계보 기록은 위 목적을 위해 제한적으로 남을 수 있습니다.

Signals를 통해 공개한 콘텐츠를 비공개로 전환하거나 삭제하거나 계정을 삭제하면, 해당 콘텐츠는 StructMemo 데이터베이스에서 즉시 비공개 상태가 되며 저장된 이미지 객체는 제12항에 설명된 삭제 대기열에 등록됩니다. 신고 및 모더레이션 감사 기록은 안전, 분쟁 및 법적 목적을 위해 보유될 수 있습니다.

StructMemo 계정 삭제는 Apple 구독을 취소하지 않으며, 로컬 Thought나 외부 백업 파일을 삭제하지 않습니다. 앱을 삭제하면 로컬 앱 데이터는 제거되지만 외부 백업이나 Apple 구독은 삭제·취소되지 않습니다.

서비스 측 정보의 열람, 정정, 삭제 또는 동의 철회 관련 지원은 donggyu@theorisis.com으로 요청할 수 있습니다. Theorisis는 요청 확인을 위해 본인 확인을 요구할 수 있으며, 이 방침에 설명된 목적상 필요한 기록은 보존할 수 있습니다.

14. 보안

StructMemo는 서비스 요청에 HTTPS를 사용하고, 로컬 StructMemo 세션 정보는 iOS 키체인에 저장하며, 서버 세션 토큰은 해시 형태로 저장하고, 보관되는 Apple OAuth 갱신 토큰은 암호화합니다. 서비스 데이터 접근은 StructMemo 운영 및 보호에 필요한 범위로 제한합니다.

어떤 시스템도 완전히 안전할 수는 없습니다. 기기를 안전하게 보호하고, 읽을 수 있는 .structmemo-backup 파일을 안전하게 보관하십시오. 반드시 필요하고 이용자가 의도적으로 제공하는 경우가 아니라면 지원 메일에 인증 정보, 거래 자료 또는 비공개 메모를 보내지 마십시오.

15. 아동의 개인정보

StructMemo는 만 13세 미만 아동을 대상으로 하지 않으며, Theorisis는 만 13세 미만 아동의 개인정보를 의도적으로 수집하지 않습니다. 아동이 서비스 측 개인정보를 제공했다고 생각되면 검토할 수 있도록 Theorisis에 문의하십시오.

16. Signals 공개 콘텐츠 모더레이션(안전성 검토·관리) 및 공개 이미지

이용자가 Signals를 통해 콘텐츠를 공개하기로 명시적으로 선택하면, StructMemo는 안전성 검사에 필요한 공개 후보 콘텐츠만 OpenAI에 전송할 수 있습니다. 전송 대상은 공개 후보 텍스트, 정제된 공개 후보 이미지, 서버가 렌더링한 Layers Included 또는 Process View 공개 후보 이미지입니다. 이 처리는 콘텐츠가 공개적으로 열람되기 전에 수행됩니다.

이용자가 사진이 포함된 Signal(Photo Note 공개 이미지)을 명시적으로 공개하면, 서버는 이미지를 긴 변 최대 2048픽셀, 최대 5 MiB의 JPEG로 다시 인코딩합니다. 포함된 EXIF, 방향 및 ICC 메타데이터는 보존되지 않으며, 업로드가 거부되거나 재인코딩 과정에서 제거됩니다. 정제된 이미지는 Signal 텍스트와 함께 OpenAI 모더레이션 엔드포인트로 검사된 뒤 제10항에 설명된 비공개 객체 저장소에 저장됩니다. 이미지가 포함된 Signal에는 요금제별 월간 허용량이 적용됩니다(Free 1개, Pro 12개, Pro Plus 30개).

StructMemo는 이 검사를 위해 비공개 Thought, 비공개 Vision, 전체 비공개 라이브러리, 공개 대상으로 선택하지 않은 콘텐츠, 이메일, Apple ID, StructMemo 내부 사용자·콘텐츠 ID, 인증 비밀정보·토큰, 원본 EXIF 또는 위치정보를 전송하지 않습니다.

자동 모더레이션(안전성 검토·관리)은 안전한 콘텐츠를 즉시 공개하거나, 위반 콘텐츠를 공개 전에 거부하거나, 불확실한 콘텐츠를 사람의 검토를 위해 비공개로 유지할 수 있습니다. 한국어와 영어로 제공되는 제안된 StructMemo 공개 콘텐츠 약관을 확인하십시오.

17. 방침 변경

StructMemo의 기능, 제공업체 또는 정보 처리 방식이 바뀌면 이 방침을 업데이트할 수 있습니다. 최신 방침과 시행일은 이 URL에 게시합니다. 중요한 변경은 필요한 경우 적절한 방법으로 알립니다.

2026-09-10.1 버전의 변경 사항: 명시적으로 공개된 Signals 이미지와 모더레이션 증거 사본을 위한 Cloudflare R2 비공개 객체 저장소를 추가했습니다(제10~12항). Photo Note 공개 이미지의 재인코딩, 검사 및 월간 허용량을 설명했습니다(제16항). Studio의 Living Layer 생성, 기본 제공되는 일일 생성, AI Credit 사용 및 운영 기록을 설명했습니다(제6, 7, 9항). 콘텐츠 비공개 전환·삭제 또는 계정 삭제가 저장된 공개 이미지와 모더레이션 기록에 미치는 영향을 설명했습니다(제12, 13항).

18. 문의 및 지원

개인정보처리자: Theorisis LLC
이메일: donggyu@theorisis.com
지원: https://www.theorisis.com/structmemo/support
개인정보 처리방침: https://www.theorisis.com/structmemo/privacy