Today, Stamped 개인정보처리방침

본 개인정보처리방침은 LugomLabs가 제공하는 iOS 카메라 앱 오늘, 찍다 / Today, Stamped와 Google Play 심사 제출을 준비 중인 Today, Stamped Android 2.0.0에 적용됩니다. 앱은 회원가입 및 로그인 기능을 제공하지 않으며, 촬영한 사진과 동영상을 개발자 서버로 업로드하지 않습니다. iOS 2.0.0 이상에서는 사용자가 별도로 동의한 경우에만 앱 개선을 위한 선택형 사용 통계를 전송합니다. 분석 동의를 거절하거나 철회해도 촬영, 날씨, 구입을 포함한 앱 기능에 불이익이 없습니다.

운영자 LugomLabs
앱 이름 iOS: 오늘, 찍다 / Today, Stamped · Android: Today, Stamped 2.0.0 심사 제출 준비 중
적용 대상 iOS 및 Android 앱
선택형 통계 적용 버전 iOS 2.0.0 이상 · Android 미적용
공고일·시행일 2026-07-31
문의 supportlugomlabs@gmail.com

1. 기기 안에서 처리하는 정보

앱은 기능 제공을 위해 아래 정보를 사용자 기기 안에서 또는 iOS·Android 시스템 기능을 통해 처리합니다.

  • 카메라 프리뷰와 사진 촬영을 위한 카메라 입력
  • 동영상 촬영 중 오디오 녹음을 위한 마이크 입력
  • 사진·동영상과 썸네일, 즐겨찾기 상태를 보관하기 위한 앱 전용 기기 저장공간
  • 사용자가 선택한 사진을 불러오고 결과물을 내보내기 위한 iOS 사진 보관함 또는 Android MediaStore·기기 미디어 저장소 접근
  • 날씨 스탬프를 선택했을 때 현재 날씨와 지역 정보를 표시하기 위한 위치 정보
  • 언어, 필터, 스탬프, 촬영 비율, 동작 설정과 분석 동의 상태 같은 앱 내 선택값
  • 유료 스탬프 묶음의 구입과 복원을 위한 앱 마켓 상품·권리 상태
  • Android 실시간 날씨 요청을 보호하기 위해 앱이 생성·기기에 저장하는 앱 전용 무작위 설치 식별자
  • Android 정식 앱 여부를 확인하기 위한 Google Play Integrity 증명과 짧은 유효기간의 Apple WeatherKit 개발자 토큰

촬영한 사진과 동영상은 앱 전용 기기 저장공간에 보관되고, 사용자가 선택하면 사진 앱·기기 미디어 저장소로 내보내거나 공유할 수 있습니다. 미디어 원본은 LugomLabs 또는 TelemetryDeck 서버로 전송되지 않습니다.

2. 선택형 사용 통계

iOS 2.0.0 이상에서는 사용자가 앱 안에서 명시적으로 동의한 경우에만 TelemetryDeck을 이용해 앱 개선을 위한 선택형 사용 통계를 처리합니다. 분석 SDK는 동의 전에는 시작되지 않으며, 앱의 개인정보 설정에서 언제든 끌 수 있습니다. Android에는 아직 이 분석 기능을 적용하지 않았으며, 적용 버전이 정해지면 시행 전에 이 방침을 다시 개정합니다.

선택형 사용 통계에는 다음 정보가 포함될 수 있습니다.

  • 앱 버전·빌드, 운영체제, 기기 모델·아키텍처·화면 크기·배율·방향과 SDK 버전
  • 앱 언어·선호 언어·지역·로케일·시간대·색상 모드·화면 배치 방향과 App Store·TestFlight·개발 빌드 여부
  • 동작 줄이기, 굵은 글씨, 색상 반전, 대비·투명도, 색상 외 구분, 선호 글자 크기 등 접근성 환경 설정 여부
  • 기기 공급업체 식별자를 앱 전용 salt와 함께 단방향 해시한 식별자, 무작위 세션 식별자와 세션 통계
  • 선택한 스탬프의 카테고리·안정 스타일 ID·이용 가능 상태와 열어 본 스탬프 묶음의 안정 ID
  • 구입 시작·결과와 복원 결과의 제한된 상태 코드. StoreKit 거래 ID는 포함하지 않음
  • 사진·동영상 촬영 완료 여부, 스탬프 카테고리, 화면 비율과 미디어 저장 성공·제한된 실패 분류
  • 날씨 불러오기 결과 분류와 가져온 사진 편집 완료 여부

TelemetryDeck은 분석 이벤트의 IP 주소를 저장하지 않는다고 안내합니다. 앱의 해시 식별자는 서버에서 다시 해시되며, 이 통계는 광고, 데이터 판매, 개인별 자동화 결정이나 다른 회사의 앱·웹사이트를 넘나드는 추적에 사용하지 않습니다.

3. 분석 이벤트로 전송하지 않는 정보

  • 정확한 좌표, 도시명, 현재 날씨·온도·예보 값
  • 사진·동영상 원본, 썸네일, 파일명, 앨범 정보
  • 촬영 시각 원본, EXIF와 그 밖의 미디어 메타데이터
  • 사용자가 입력하거나 선택한 문구의 실제 내용
  • StoreKit 거래 ID, 영수증, 결제 정보
  • 이름, 이메일 주소, 전화번호, 광고 식별자와 다른 회사의 앱·웹사이트 활동

4. 정보 처리 목적

  • 실시간 카메라 프리뷰와 사진 촬영 제공
  • 필터와 스탬프가 적용된 사진 및 동영상 저장
  • 사진 불러오기·편집·내보내기, 앱 내부 보관함과 즐겨찾기 제공
  • 날씨 스탬프 선택 시 현재 위치 기반 날씨와 지역 정보 표시
  • Android 날씨 요청이 Google Play가 인식한 정식 앱에서 시작되었는지 확인하고 WeatherKit 자격 증명을 보호
  • 앱 내 언어·촬영 설정·선택 상태 유지와 앱 내 구입·복원 제공
  • 스탬프·묶음·촬영·저장·날씨·편집 기능의 이용 및 제한된 실패 경향 분석
  • 구입·복원 흐름의 품질 개선과 지원 기기·접근성 환경에 맞춘 제품 개선

5. 위치 정보와 날씨 서비스

위치 권한은 사용자가 실제로 이용할 수 있는 날씨 스탬프를 선택했을 때만 요청됩니다. iOS와 Android 앱은 각 플랫폼의 위치·지오코딩 기능과 Apple WeatherKit을 사용해 날씨와 지역 정보를 가져옵니다. 정확한 좌표, 앱 언어와 시간대는 암호화된 통신으로 앱에서 Apple WeatherKit에 직접 전송됩니다. Android의 Cloudflare 중계 서버에는 좌표, 도시명, 날씨 값, 위치 권한 결과 또는 Apple의 날씨 응답이 전송되지 않습니다. 날씨 스탬프를 적용한 미디어에는 도시명, 기온, 날씨 상태, 촬영 시점 정보가 화면에 표시될 수 있습니다. 정확한 위치와 날씨 결과는 LugomLabs 서버나 TelemetryDeck에 저장되지 않습니다.

Android에서는 WeatherKit 비밀 키를 앱에 넣지 않기 위해 Google Play Integrity 증명, 앱 전용 무작위 설치 식별자, 무작위 요청 식별자, 앱 버전과 요청 시각을 Cloudflare 중계 서버로 전송합니다. 중계 서버는 앱의 패키지·버전·Google Play 인식·라이선스·기기 무결성을 확인한 뒤 약 120초 동안만 유효한 WeatherKit 개발자 토큰을 돌려줍니다. 앱은 그 토큰과 현재 좌표를 Apple WeatherKit에 직접 보내며, 토큰과 무결성 증명을 앱에 영구 저장하지 않습니다.

위치 권한과 선택형 사용 통계는 목적과 철회 방법이 다른 독립된 선택입니다. 분석에 동의하지 않아도 날씨 스탬프를 사용할 수 있고, 위치 권한을 허용하지 않아도 분석 동의 여부에는 영향이 없습니다.

6. 보관 위치, 기간 및 삭제 기준

  • 사진·동영상, 썸네일, 즐겨찾기와 앱 설정은 사용자 기기에 저장됩니다.
  • 앱 내부 미디어는 보관함에서 삭제할 수 있고, 앱 삭제 시 앱 전용 저장 정보도 운영체제 정책에 따라 삭제됩니다.
  • 사진 앱이나 Android 미디어 저장소로 내보낸 미디어는 해당 시스템 앱에서 별도로 삭제해야 합니다.
  • Android 앱 전용 무작위 설치 식별자는 날씨 인증을 처음 요청할 때 기기에 생성되고 백업·기기 이전에서 제외되며, 앱을 삭제하면 제거됩니다.
  • Play Integrity 증명, 무작위 요청 식별자와 WeatherKit 개발자 토큰은 요청 처리 중에만 사용하고 앱 또는 중계 서버의 데이터베이스에 보관하지 않습니다.
  • 고객지원 이메일은 문의 대응 완료 후 최대 3개월 동안 보관합니다.
  • 선택형 사용 통계는 분석 목적이 유지되고 TelemetryDeck 데이터셋을 운영하는 동안 처리합니다.

동의 철회 후 앱은 새로운 분석 이벤트 생성을 중단합니다. 철회 전에 동의 상태에서 전송된 통계는 이름이나 연락처와 연결되지 않아 특정 사용자의 기록만 다시 식별해 열람·정정·삭제하기 어려울 수 있습니다. 분석 목적이 끝나거나 TelemetryDeck 이용을 종료해 데이터셋을 삭제하면 해당 통계 이용도 종료되며, 공급자 시스템의 삭제와 백업 정리는 TelemetryDeck의 정책과 절차에 따릅니다.

7. 고객지원 문의 시 처리되는 정보

사용자가 이메일로 고객지원을 요청하는 경우, 문의 대응을 위해 발신 이메일 주소, 문의 내용, 사용자가 자발적으로 제공한 첨부 자료가 처리될 수 있습니다.

  • 처리 목적: 문의 확인, 오류 대응, 서비스 개선
  • 보관 기간: 문의 대응 완료 후 최대 3개월 보관 후 삭제

8. 제3자 제공, 처리위탁 및 외부 서비스

LugomLabs는 사용자의 정보를 판매하지 않으며, 법령에 근거가 있거나 사용자가 별도로 동의한 경우를 제외하고 제3자에게 제공하지 않습니다. 앱과 공개 문서 운영에는 다음 외부 서비스를 이용합니다.

  • Apple 시스템 서비스·Apple WeatherKit·StoreKit: iOS·Android 날씨 조회, iOS 사진 선택·저장, App Store 구입과 복원
  • Android 시스템 서비스·Google Play: Android 위치·지오코딩·MediaStore 처리, 앱 내 구입·복원, Play Integrity를 통한 앱·기기 무결성 확인
  • TelemetryDeck GmbH: 사용자가 동의한 iOS 선택형 사용 통계의 수신, 저장과 분석 화면 제공
  • Cloudflare, Inc.: Android WeatherKit 단기 토큰 중계, 앱 소개·고객지원·개인정보처리방침 정적 파일 전송, 네트워크 보안과 캐시 제공

Cloudflare는 공개 페이지 또는 Android 중계 서버 요청을 처리하면서 IP 주소, 요청 시각·경로, 기기·네트워크 환경 같은 운영 메타데이터를 네트워크 운영과 보안을 위해 자동 처리할 수 있습니다. 중계 서버의 애플리케이션 로그와 저장소에는 요청 본문, 설치 식별자, Play Integrity 토큰, 좌표 또는 날씨 값을 기록하지 않으며, 제한된 오류 코드·상태만 운영 점검에 사용할 수 있습니다.

9. 외부 서비스 및 국외 처리 안내

선택형 사용 통계를 처리하는 TelemetryDeck GmbH는 독일 아우크스부르크에 소재하며, 분석 데이터는 TelemetryDeck이 안내하는 유럽연합(EU) 역내 인프라에서 처리됩니다.

  • 처리자: TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg, Germany
  • 연락처: datenschutz@telemetrydeck.com
  • 처리 지역: 유럽연합(EU) 역내 인프라
  • 처리 항목: 위 2항에 기재된 선택형 사용 통계
  • 시점 및 방법: 사용자가 동의한 뒤 이벤트가 발생할 때 암호화된 네트워크로 전송
  • 이용 목적: 앱 이용 분석과 품질 개선
  • 처리 기간: 위 6항의 보관·삭제 기준이 충족될 때까지

사용자는 분석 동의를 선택하지 않거나 앱 설정에서 철회하여 국외 처리를 거부할 수 있으며, 거부해도 앱 기능 이용에는 불이익이 없습니다. 자세한 내용은 TelemetryDeck Privacy PolicyPrivacy FAQ에서 확인할 수 있습니다.

Android 날씨 기능을 사용할 때는 Apple, Google과 Cloudflare의 국외 인프라에서 다음 정보가 암호화된 통신으로 처리될 수 있습니다. 제공자의 실제 처리 지역과 공급자 측 보관은 요청 경로와 각 제공자의 정책에 따라 달라질 수 있습니다.

  • Apple Inc.: 정확한 좌표, 언어·시간대와 WeatherKit 요청을 날씨 제공 목적으로 처리합니다. 좌표는 앱에서 Apple로 직접 전송되며 LugomLabs 중계 서버를 거치지 않습니다.
  • Google LLC: Android 날씨 요청 시 Play Integrity 토큰과 앱·라이선스·기기 무결성 판정에 필요한 정보를 부정 이용 방지와 자격 증명 보호 목적으로 처리합니다.
  • Cloudflare, Inc.: 무작위 설치·요청 식별자, 앱 버전, 요청 시각, 불투명한 Play Integrity 토큰과 네트워크 운영 메타데이터를 WeatherKit 단기 토큰 발급·보안 목적으로 처리합니다. 위치·도시·날씨 값은 받지 않습니다.
  • 시점·기간: 사용자가 Android 날씨 스탬프를 선택해 실시간 날씨를 요청할 때 전송합니다. LugomLabs 중계 로직은 요청 본문을 영구 저장하지 않으며, 제공자 측 운영 정보는 각 제공자의 보관·삭제 정책에 따릅니다.

Android 날씨 기능을 사용하지 않거나 위치 권한을 허용하지 않으면 이 날씨 요청은 발생하지 않습니다. 다만 거부하면 현재 위치 기반 날씨가 필요한 스탬프는 정상적으로 표시되지 않을 수 있습니다. 자세한 내용은 Apple 개인정보 보호정책, Google 개인정보처리방침, Cloudflare 개인정보 보호정책에서 확인할 수 있습니다.

10. 이용자의 권리 및 행사 방법

  • 사용자는 iOS 설정 또는 Android 설정에서 카메라, 마이크, 사진/미디어, 위치 권한을 변경할 수 있습니다.
  • 앱 내부 보관함에서 미디어와 즐겨찾기를 관리하고, 내보낸 미디어는 사진 앱 또는 Android 갤러리·미디어 앱에서 관리할 수 있습니다.
  • iOS 2.0.0 이상에서는 앱의 개인정보 설정에서 선택형 사용 통계를 언제든 켜거나 끌 수 있습니다.
  • Android에서 앱을 삭제하면 기기에 저장된 앱 전용 무작위 설치 식별자가 제거됩니다.
  • 고객지원 문의 정보의 열람·정정·삭제·처리정지를 원하면 아래 개인정보 보호 담당자에게 이메일로 요청할 수 있습니다.

11. 안전성 확보 조치

  • 네트워크로 전송되는 정보는 암호화된 통신을 사용합니다.
  • Android 날씨 중계 서버는 Play Integrity 검증과 짧은 유효기간의 WeatherKit 토큰을 사용하고, 위치 정보는 중계 서버와 분리합니다.
  • 분석용 기기 식별자는 앱에서 앱 전용 salt와 함께 단방향 해시한 뒤 전송하고 TelemetryDeck 서버에서 다시 해시합니다.
  • 고객지원 메일, 호스팅 계정과 분석 대시보드의 접근 권한을 운영에 필요한 범위로 제한합니다.
  • 분석 이벤트 계약으로 위치·미디어·사용자 입력·거래 ID 등 금지 필드를 관리하고 수집 범위를 정기적으로 점검합니다.

12. 개인정보처리방침 변경

본 방침은 앱 기능 변경, 법령 변경, 운영 정책 변경에 따라 수정될 수 있습니다. 수집 항목, 처리 목적, 외부 서비스, 적용 플랫폼·버전 또는 보관 정책이 달라지는 경우 변경 내용과 시행일을 이 페이지에 공개합니다. 일정이 정해지지 않은 Android 분석 기능은 실제 적용 버전이 확정된 뒤 별도 개정합니다.

이전 방침: 2026-07-28 시행 개인정보처리방침 · 2026-06-18 시행 개인정보처리방침

13. 개인정보 보호 담당자 및 권리구제

담당 부서 LugomLabs 개인정보 보호 담당
문의 방법 supportlugomlabs@gmail.com

개인정보 침해에 대한 상담이나 분쟁조정이 필요한 경우 아래 기관에 문의할 수 있습니다.

미디어는 사용자 기기에 저장됩니다. 위치 정보는 실제 날씨 스탬프를 선택했을 때만 사용하며, Android의 좌표는 Cloudflare 중계 서버를 거치지 않고 Apple WeatherKit으로 직접 전송됩니다. 선택형 사용 통계는 iOS 2.0.0 이상에서 별도로 동의한 경우에만 전송됩니다. Android 분석 기능은 아직 적용하지 않았습니다.

Today, Stamped Privacy Policy

This Privacy Policy applies to Today, Stamped on iOS and Today, Stamped for Android 2.0.0, now being prepared for Google Play review. The app has no account registration or login and does not upload captured photos or videos to a developer server. On iOS 2.0.0 and later, optional usage analytics is sent only after separate, explicit consent. Declining or withdrawing consent does not affect capture, weather, purchases, or any other app feature.

Operator LugomLabs
App names iOS: Today, Stamped · Android: Today, Stamped 2.0.0 in preparation for review
Applies to iOS and Android apps
Optional analytics iOS 2.0.0 and later · Not yet available on Android
Published and effective July 31, 2026
Contact supportlugomlabs@gmail.com

1. Information Processed on Your Device

The app processes the following information on your device or through iOS and Android system features.

  • Camera input for live preview and photo capture
  • Microphone input while recording videos
  • App-private device storage for photos, videos, thumbnails, and Favorites
  • iOS Photos or Android MediaStore/device media storage access to import a selected photo or export a result
  • Location to show weather and place information when you select a weather stamp
  • In-app choices such as language, filter, stamp, aspect ratio, motion preferences, and analytics consent
  • Store product and entitlement state needed for in-app purchases and restoration
  • An app-specific random installation identifier created and stored by Android to protect live weather requests
  • A Google Play Integrity proof used to verify the Android release and a short-lived Apple WeatherKit developer token

Captured media is kept in app-private storage and may be exported to Photos, device media storage, or a share destination when you choose. Media originals are not sent to LugomLabs or TelemetryDeck servers.

2. Optional Usage Analytics

On iOS 2.0.0 and later, TelemetryDeck is used only when you explicitly opt in. The analytics SDK does not start before consent and can be turned off at any time in the app's Privacy settings. Analytics is not yet enabled on Android. This policy will be updated before an Android version begins using it.

Optional analytics may include:

  • App version and build, operating system, device model and architecture, screen size, scale, orientation, and SDK version
  • App and preferred language, region, locale, time zone, color mode, layout direction, and App Store, TestFlight, or development context
  • Accessibility setting states such as Reduce Motion, Bold Text, color inversion, contrast, transparency, differentiation without color, and preferred text size
  • A one-way hashed identifier derived from the vendor identifier with an app-specific salt, a random session ID, and session statistics
  • Selected stamp category, stable style ID, access level, and the stable ID of a stamp pack whose preview was opened
  • Limited purchase, result, and restoration status codes; StoreKit transaction IDs are excluded
  • Completed photo or video capture, stamp category, aspect ratio, and media-save success or a limited failure category
  • Weather-load result category and whether an imported-photo edit was completed

TelemetryDeck states that it does not store IP addresses. The app-hashed identifier is hashed again on the server. Analytics is not used for advertising, data sales, automated decisions about individuals, or tracking across other companies' apps or websites.

3. Information Never Sent in Analytics Events

  • Precise coordinates, city names, weather, temperature, or forecast values
  • Photos, videos, thumbnails, filenames, or album information
  • Original capture time, EXIF, or other media metadata
  • The actual content of words entered or selected by the user
  • StoreKit transaction IDs, receipts, or payment information
  • Name, email address, phone number, advertising identifier, or activity in other companies' apps or websites

4. Purposes of Processing

  • Provide live camera preview and photo capture
  • Save photos and videos with selected filters and stamps
  • Provide photo import, editing, export, the in-app library, and Favorites
  • Show current weather and place information when a weather stamp is selected
  • Verify that an Android weather request comes from a Google Play-recognized release and protect WeatherKit credentials
  • Keep in-app settings and choices and provide in-app purchases and restoration
  • Analyze use and limited failure trends for stamps, packs, capture, saving, weather, and editing
  • Improve purchase and restoration quality and support for device and accessibility environments

5. Location and Weather Services

Location is requested only when you select a weather work you can use. On both iOS and Android, the app uses platform location and geocoding features together with Apple WeatherKit. Precise coordinates, app language, and time zone are sent directly from the app to Apple WeatherKit over encrypted transport. The Android Cloudflare broker does not receive coordinates, city names, weather values, the location-permission result, or Apple's weather response. Media saved with a weather stamp may visibly include place, temperature, weather condition, and capture-time information. Precise location and weather results are not stored on LugomLabs servers or sent to TelemetryDeck.

To keep the WeatherKit private key out of the Android app, Android sends a Google Play Integrity proof, an app-specific random installation identifier, a random request identifier, app version, and request time to the Cloudflare broker. The broker verifies the package, version, Google Play recognition, license, and device integrity, then returns a WeatherKit developer token that is valid for about 120 seconds. The app sends that token and the current coordinates directly to Apple WeatherKit. Integrity proofs and developer tokens are not persisted by the app.

Location permission and optional analytics are separate choices with different purposes and controls. You can use weather stamps without enabling analytics, and your location choice does not change analytics consent.

6. Storage, Retention, and Deletion

  • Media, thumbnails, Favorites, and app settings are stored on your device.
  • You can delete media in the in-app library. App-private data is removed under operating-system rules when the app is deleted.
  • Media exported to Photos or Android media storage must be deleted separately in that system app.
  • The Android app-specific random installation identifier is created on the device upon the first live-weather authorization request, excluded from backup and device transfer, and removed when the app is deleted.
  • Play Integrity proofs, random request identifiers, and WeatherKit developer tokens are used only while handling a request and are not stored in an app or broker database.
  • Support emails are retained for up to 3 months after a request is resolved.
  • Optional analytics is processed while the analytics purpose remains active and the TelemetryDeck dataset is maintained.

After consent is withdrawn, the app stops creating new analytics events. Previously sent analytics is not connected to names or contact details, so it may not be possible to re-identify, access, correct, or delete only one person's events. Use of the analytics ends when its purpose ends or the TelemetryDeck dataset is deleted. Provider-side deletion and backup cleanup follow TelemetryDeck's policies and procedures.

7. Support Requests

If you contact us by email, your sender email address, message, and any attachments you voluntarily provide may be processed to respond to your request.

  • Purpose: review the request, respond to issues, and improve the service
  • Retention: deleted within up to 3 months after the support request is resolved

8. Third Parties, Processors, and External Services

LugomLabs does not sell user information and does not provide it to third parties except with a legal basis or separate user consent. The app and its public documents use:

  • Apple system services, Apple WeatherKit, and StoreKit for iOS and Android weather, iOS photo selection and export, and App Store purchases and restoration
  • Android system services and Google Play for location, geocoding, MediaStore handling, in-app purchases and restoration, and Play Integrity app/device verification
  • TelemetryDeck GmbH to receive, store, and provide analysis tools for consented optional iOS analytics
  • Cloudflare, Inc. to broker short-lived Android WeatherKit tokens, deliver static app, support, and privacy pages, and provide network security and caching

When handling a public page or Android broker request, Cloudflare may automatically process operational metadata such as an IP address, request time and path, and device or network information for network operations and security. The broker's application logs and storage do not record request bodies, installation identifiers, Play Integrity tokens, coordinates, or weather values; limited error codes and statuses may be used for operational review.

9. External Services and International Processing

TelemetryDeck GmbH is located in Augsburg, Germany, and states that analytics data is processed in infrastructure within the European Union.

  • Processor: TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg, Germany
  • Contact: datenschutz@telemetrydeck.com
  • Region: Infrastructure within the European Union
  • Data: Optional analytics described in Section 2
  • Timing and method: Encrypted network transfer when an event occurs after consent
  • Purpose: App usage analysis and quality improvement
  • Duration: Until the criteria in Section 6 are met

You may refuse this processing by not opting in or by withdrawing consent in the app. Refusal does not limit app features. See the TelemetryDeck Privacy Policy and Privacy FAQ for details.

When Android weather is used, Apple, Google, and Cloudflare may process the following information in infrastructure outside your country over encrypted transport. Actual processing regions and provider-side retention may vary with the request route and each provider's policy.

  • Apple Inc.: Precise coordinates, language, time zone, and a WeatherKit request are processed to provide weather. Coordinates go directly from the app to Apple and do not pass through the LugomLabs broker.
  • Google LLC: A Play Integrity token and information needed for app, license, and device-integrity verdicts are processed when Android weather is requested, for abuse prevention and credential protection.
  • Cloudflare, Inc.: A random installation and request identifier, app version, request time, opaque Play Integrity token, and network operational metadata are processed to issue and secure a short-lived WeatherKit token. It does not receive location, city, or weather values.
  • Timing and duration: Transfer occurs when you select an Android weather stamp and request live weather. The LugomLabs broker does not persist the request body; provider-side operational information follows each provider's retention and deletion policy.

These weather requests do not occur if you do not use Android weather or do not grant location permission. Refusal may prevent a current-location weather stamp from displaying correctly. For details, see the Apple Privacy Policy, Google Privacy Policy, and Cloudflare Privacy Policy.

10. User Controls

  • You can change camera, microphone, photo/media, and location permissions in iOS Settings or Android Settings.
  • You can manage media and Favorites in the in-app library and exported media in Photos or an Android gallery/media app.
  • On iOS 2.0.0 and later, you can turn optional analytics on or off at any time in the app's Privacy settings.
  • Deleting the Android app removes the app-specific random installation identifier stored on the device.
  • You may request access, correction, deletion, or restriction of support records by contacting the privacy contact below.

11. Security Measures

  • Information sent over a network uses encrypted transport.
  • The Android weather broker uses Play Integrity verification and short-lived WeatherKit tokens, while keeping location information separate from the broker.
  • The analytics device identifier is one-way hashed with an app-specific salt before transmission and hashed again by TelemetryDeck.
  • Access to support email, hosting accounts, and the analytics dashboard is limited to operational needs.
  • An analytics event contract prohibits location, media, user-entered text, transaction IDs, and other disallowed fields.

12. Changes to This Policy

This policy may be updated when app features, laws, or operating policies change. Changes to data, purposes, external services, platform or version scope, or retention will be published here with an effective date. Android analytics has no set schedule and will be covered by a separate update before it is enabled.

Previous policies: Privacy Policy effective July 28, 2026 · Privacy Policy effective June 18, 2026

13. Privacy Contact

Team LugomLabs Privacy
Contact supportlugomlabs@gmail.com

Media stays on your device. Location is used only when you select a weather stamp. Android coordinates go directly to Apple WeatherKit without passing through the Cloudflare broker. Optional analytics is sent on iOS 2.0.0 and later only after separate consent. Analytics is not yet enabled on Android.

Today, Stamped プライバシーポリシー

本プライバシーポリシーは、iOSのToday, Stampedと、Google Playの審査提出を準備中の Android版Today, Stamped 2.0.0に適用されます。アカウント登録やログイン機能はなく、撮影した写真や動画を 開発者サーバーへアップロードしません。iOS 2.0.0以降では、ユーザーが別途明示的に同意した場合にのみ、 アプリ改善のための任意の利用統計を送信します。同意を拒否・撤回しても、撮影、天気、購入などの機能には影響しません。

運営者 LugomLabs
アプリ名 iOS: Today, Stamped · Android: Today, Stamped 2.0.0 審査提出準備中
対象 iOSおよびAndroidアプリ
任意の利用統計 iOS 2.0.0以降 · Androidは未適用
公表日・施行日 2026-07-31
連絡先 supportlugomlabs@gmail.com

1. 端末内で処理する情報

アプリは機能提供のため、以下の情報を端末内またはiOS・Androidのシステム機能を通じて処理します。

  • ライブプレビューと写真撮影のためのカメラ入力
  • 動画撮影中の音声録音のためのマイク入力
  • 写真・動画、サムネイル、お気に入りを保存するためのアプリ専用端末ストレージ
  • 選択した写真の読み込みや結果の書き出しのためのiOS写真ライブラリまたはAndroid MediaStore・端末メディアストレージへのアクセス
  • 天気スタンプ選択時に天気と地域情報を表示するための位置情報
  • 言語、フィルター、スタンプ、撮影比率、動作設定、分析同意状態などのアプリ内選択値
  • アプリ内購入と復元に必要なストア商品・権利状態
  • Androidのライブ天気要求を保護するため、アプリが生成し端末に保存するアプリ専用のランダムなインストール識別子
  • Android正規版を確認するGoogle Play Integrity証明と、有効期間の短いApple WeatherKit開発者トークン

撮影したメディアはアプリ専用ストレージに保存され、ユーザーが選択した場合に写真アプリ、端末メディアストレージ、 または共有先へ書き出されます。メディア原本はLugomLabsやTelemetryDeckのサーバーには送信されません。

2. 任意の利用統計

iOS 2.0.0以降では、ユーザーが明示的に同意した場合にのみTelemetryDeckを使用します。 分析SDKは同意前には開始されず、アプリのプライバシー設定でいつでもオフにできます。 Androidではまだ分析機能を有効にしておらず、導入前に本ポリシーを改定します。

任意の利用統計には、次の情報が含まれる場合があります。

  • アプリのバージョン・ビルド、OS、端末モデル・アーキテクチャ、画面サイズ・倍率・向き、SDKバージョン
  • アプリ言語・優先言語・地域・ロケール・タイムゾーン・表示モード・レイアウト方向、App Store・TestFlight・開発環境の区分
  • 「視差効果を減らす」、太字、色反転、コントラスト・透明度、色以外で区別、文字サイズなどのアクセシビリティ設定状態
  • ベンダー識別子をアプリ専用saltとともに一方向ハッシュ化した識別子、ランダムなセッションID、セッション統計
  • 選択したスタンプのカテゴリ・安定スタイルID・利用可能状態、プレビューを開いたスタンプパックの安定ID
  • 購入開始・結果と復元結果の限定的な状態コード。StoreKit取引IDは含みません
  • 写真・動画の撮影完了、スタンプカテゴリ、画面比率、保存成功または限定的な失敗分類
  • 天気読み込み結果の分類と、読み込んだ写真の編集完了有無

TelemetryDeckはIPアドレスを保存しないと説明しています。アプリでハッシュ化した識別子はサーバーでも再度ハッシュ化されます。 広告、データ販売、個人への自動的な意思決定、他社のアプリやウェブサイトをまたぐ追跡には使用しません。

3. 分析イベントとして送信しない情報

  • 正確な座標、都市名、天気・気温・予報の値
  • 写真・動画、サムネイル、ファイル名、アルバム情報
  • 撮影時刻の原本、EXIF、その他のメディアメタデータ
  • ユーザーが入力または選択した言葉の実際の内容
  • StoreKit取引ID、レシート、決済情報
  • 氏名、メールアドレス、電話番号、広告識別子、他社のアプリやウェブサイトでの活動

4. 処理目的

  • ライブカメラプレビューと写真撮影の提供
  • 選択したフィルターやスタンプを適用した写真・動画の保存
  • 写真の読み込み・編集・書き出し、アプリ内ライブラリとお気に入りの提供
  • 天気スタンプ選択時の現在地に基づく天気と地域情報の表示
  • Androidの天気要求がGoogle Playに認識された正規版からのものか確認し、WeatherKit認証情報を保護
  • アプリ設定・選択状態の保持と、アプリ内購入・復元の提供
  • スタンプ、パック、撮影、保存、天気、編集機能の利用状況と限定的な失敗傾向の分析
  • 購入・復元の品質と、端末・アクセシビリティ環境への対応改善

5. 位置情報と天気サービス

位置情報は、利用可能な天気スタンプを選択した場合にのみ要求します。iOSとAndroidの両方で、 各プラットフォームの位置情報・ジオコーディング機能とApple WeatherKitを使用します。 正確な座標、アプリ言語、タイムゾーンは、暗号化通信でアプリからApple WeatherKitへ直接送信されます。 AndroidのCloudflare中継サーバーには、座標、都市名、天気の値、位置情報の許可結果、Appleの天気応答は送信されません。 天気スタンプを適用したメディアには、地域、気温、天気、撮影時点の情報が表示される場合があります。 正確な位置と天気結果はLugomLabsのサーバーに保存されず、TelemetryDeckにも送信されません。

WeatherKitの秘密鍵をAndroidアプリに含めないため、AndroidはGoogle Play Integrity証明、 アプリ専用のランダムなインストール識別子、ランダムな要求識別子、アプリバージョン、要求時刻をCloudflare中継サーバーへ送信します。 中継サーバーはパッケージ、バージョン、Google Playの認識、ライセンス、端末の完全性を確認し、 約120秒間だけ有効なWeatherKit開発者トークンを返します。アプリはそのトークンと現在の座標をApple WeatherKitへ直接送信し、 Integrity証明と開発者トークンを永続保存しません。

位置情報の許可と任意の利用統計は、目的と管理方法が異なる独立した選択です。 分析を有効にしなくても天気スタンプを利用でき、位置情報の選択が分析同意に影響することもありません。

6. 保存場所、期間、削除基準

  • メディア、サムネイル、お気に入り、アプリ設定はユーザーの端末に保存されます。
  • アプリ内ライブラリでメディアを削除できます。アプリ削除時、専用データはOSの規則に従って削除されます。
  • 写真アプリやAndroidのメディアストレージへ書き出したメディアは、そのシステムアプリで別途削除する必要があります。
  • Androidのアプリ専用ランダムインストール識別子は、最初のライブ天気認証要求時に端末で生成され、バックアップ・端末移行から除外され、アプリ削除時に削除されます。
  • Play Integrity証明、ランダム要求識別子、WeatherKit開発者トークンは要求処理中のみ使用し、アプリまたは中継サーバーのデータベースに保存しません。
  • サポートメールは対応完了後、最大3か月間保存します。
  • 任意の利用統計は、分析目的が継続しTelemetryDeckデータセットを運用している間処理します。

同意撤回後、アプリは新しい分析イベントの生成を停止します。すでに送信された統計は氏名や連絡先に結び付いていないため、 特定ユーザーのイベントだけを再識別して閲覧・訂正・削除することが難しい場合があります。 分析目的の終了またはデータセットの削除により利用を終了し、提供者側の削除・バックアップ整理はTelemetryDeckの方針と手順に従います。

7. サポートへのお問い合わせ

メールでお問い合わせいただく場合、返信のために送信元メールアドレス、お問い合わせ内容、 ユーザーが任意で提供した添付資料を取り扱うことがあります。

  • 目的: お問い合わせ内容の確認、不具合対応、サービス改善
  • 保存期間: 対応完了後、最大3か月以内に削除

8. 第三者、処理委託、外部サービス

LugomLabsはユーザー情報を販売せず、法的根拠または別途同意がある場合を除き第三者へ提供しません。 アプリと公開文書の運営では、次のサービスを利用します。

  • Appleのシステムサービス、Apple WeatherKit、StoreKit:iOS・Androidの天気、iOSでの写真選択・書き出し、App Storeでの購入・復元
  • Androidのシステムサービス、Google Play:位置・ジオコーディング・MediaStore処理、アプリ内購入・復元、Play Integrityによるアプリ・端末確認
  • TelemetryDeck GmbH:同意を得たiOSの任意利用統計の受信・保存・分析画面提供
  • Cloudflare, Inc.:Android用WeatherKit短期トークンの中継、アプリ紹介・サポート・プライバシーページの配信、ネットワーク保護、キャッシュ

Cloudflareは、公開ページまたはAndroid中継サーバーの要求処理時に、IPアドレス、要求時刻・経路、 端末・ネットワーク情報などの運用メタデータを、ネットワーク運用とセキュリティのために自動処理する場合があります。 中継サーバーのアプリケーションログと保存領域には、要求本文、インストール識別子、Play Integrityトークン、 座標、天気の値を記録せず、限定的なエラーコード・状態のみを運用確認に使用する場合があります。

9. 外部サービスと国外処理

TelemetryDeck GmbHはドイツ・アウクスブルクに所在し、分析データは同社が案内するEU域内インフラで処理されます。

  • 処理者:TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg, Germany
  • 連絡先:datenschutz@telemetrydeck.com
  • 地域:EU域内インフラ
  • 情報:第2項の任意利用統計
  • 時点・方法:同意後、イベント発生時に暗号化されたネットワークで送信
  • 目的:利用分析と品質改善
  • 期間:第6項の基準を満たすまで

同意しない、またはアプリ設定で撤回することで処理を拒否でき、アプリ機能に不利益はありません。 詳細はTelemetryDeck Privacy Policyおよび Privacy FAQをご覧ください。

Androidの天気機能を使用すると、Apple、Google、Cloudflareの国外インフラで、次の情報が暗号化通信により処理される場合があります。 実際の処理地域と提供者側の保存期間は、要求経路および各提供者の方針によって異なる場合があります。

  • Apple Inc.:天気提供のため、正確な座標、言語、タイムゾーン、WeatherKit要求を処理します。座標はアプリからAppleへ直接送信され、LugomLabsの中継サーバーを通りません。
  • Google LLC:Androidの天気要求時に、Play Integrityトークンとアプリ・ライセンス・端末の完全性判定に必要な情報を、不正利用防止と認証情報保護のために処理します。
  • Cloudflare, Inc.:ランダムなインストール・要求識別子、アプリバージョン、要求時刻、不透明なPlay Integrityトークン、ネットワーク運用メタデータを、WeatherKit短期トークンの発行・保護のために処理します。位置・都市・天気の値は受信しません。
  • 時点・期間:Androidで天気スタンプを選び、ライブ天気を要求した時に送信します。LugomLabsの中継ロジックは要求本文を永続保存せず、提供者側の運用情報は各提供者の保存・削除方針に従います。

Androidの天気機能を使用しない、または位置情報を許可しない場合、この天気要求は発生しません。 ただし拒否すると、現在地の天気を必要とするスタンプが正しく表示されない場合があります。詳細は AppleプライバシーポリシーGoogleプライバシーポリシーCloudflareプライバシーポリシーをご覧ください。

10. ユーザーによる管理

  • カメラ、マイク、写真/メディア、位置情報の権限は、iOS設定またはAndroid設定で変更できます。
  • アプリ内ライブラリでメディアとお気に入りを管理し、書き出したメディアは写真アプリまたはAndroidのギャラリー・メディアアプリで管理できます。
  • iOS 2.0.0以降では、アプリのプライバシー設定で任意の利用統計をいつでもオン・オフにできます。
  • Androidアプリを削除すると、端末に保存されたアプリ専用のランダムなインストール識別子も削除されます。
  • サポート記録の閲覧・訂正・削除・処理制限は、下記の連絡先へ依頼できます。

11. 安全管理措置

  • ネットワーク送信には暗号化通信を使用します。
  • Androidの天気中継サーバーはPlay Integrity検証と短期WeatherKitトークンを使用し、位置情報を中継サーバーから分離します。
  • 分析用端末識別子はアプリ専用saltとともに一方向ハッシュ化して送信し、TelemetryDeckでも再度ハッシュ化します。
  • サポートメール、ホスティング、分析ダッシュボードへのアクセスを運用上必要な範囲に制限します。
  • 分析イベント契約により、位置、メディア、ユーザー入力、取引IDなどの禁止項目を管理します。

12. 本ポリシーの変更

本ポリシーは、アプリ機能、法令、運営方針の変更に応じて更新される場合があります。 情報、目的、外部サービス、対象プラットフォーム・バージョン、保存方針の変更は、施行日とともに本ページで公開します。 Androidの分析導入時期は未定であり、有効化前に別途改定します。

以前のポリシー: 2026-07-28施行プライバシーポリシー · 2026-06-18施行プライバシーポリシー

13. プライバシーに関する連絡先

担当 LugomLabs プライバシー担当
連絡先 supportlugomlabs@gmail.com

メディアはユーザーの端末に保存されます。位置情報は天気スタンプ選択時だけ使用し、 Androidの座標はCloudflare中継サーバーを通らずApple WeatherKitへ直接送信されます。 任意の利用統計はiOS 2.0.0以降で別途同意した場合にのみ送信されます。 Androidではまだ分析を有効にしていません。