Privacy Policy

DuDa Privacy Policy

Effective date: October 3, 2026

Revision notice (posted October 1, 2026; effective date changed on October 3, 2026): This policy applies from October 3, 2026. The only change is the addition of Google sign-in (Section 2 on sign-in, Section 4 on processing outside Korea, Section 6 on account deletion and disconnection, and the reference links). Google sign-in is available starting with app version 1.10.0.

NLAP (service name DuDa, referred to as “DuDa” below) protects your personal information in accordance with applicable laws, including Korea’s Personal Information Protection Act, and clearly explains how it is processed. This is an English translation of the Korean privacy policy. If the two differ, the Korean version applies.

1. Personal information we process and why

Account and sign-in: Supabase user identifier (UUID), sign-in provider, email address (including Apple’s private relay email), and the name, nickname, and profile image passed on by the provider. Used to identify members, sign you in, recover accounts, and provide your profile.

Health records: record date, hives and itch scores and their total, detailed itch scores, affected body areas and names of other areas, swelling, notes, hospital visit times, records of medications taken, injections, and other treatments along with names you enter yourself, food records (food name, meal, where you ate, tags, and anything you enter yourself), and symptom photos you select or take along with their storage paths. Used for daily records, viewing trends, syncing across devices, and account-based storage.

Inquiries and errors: the content of inquiries or reports, their handling status, error type and technical error details, and user UUID. Used to respond to inquiries and investigate service problems.

Error reports: When an error occurs in the app, we send the error type and details, a screenshot of the app screen at the moment of the error (which may include records or photos visible on the screen at that time), related request and activity logs, user UUID, an app installation identifier (a value created by Sentry), device and operating system information, and IP address to Sentry, an error analysis service. This is used only to find the cause of errors and prevent them from happening again.

Operational and diagnostic information: number of accesses and most recent access time (UTC), app version, operating system type and version, and device model and manufacturer. Used to check service compatibility and respond to errors. Versions 1.6 and earlier also stored the device name, serial number, identifier for vendor (iOS IDFV), and build information in account information. Starting with 1.7.0, these are no longer stored and are replaced with the summary information above when the new version is first launched. Accounts that have not run the new version still contain the previous values.

For health records and photos, we process what you enter yourself or select or take and save. Photo attachments use the system photo picker, and camera permission is requested when you choose the photo-taking feature.

We do not request the advertising identifier or precise location. The IP address and access logs used to connect to the service may be processed to provide the network and for security.

2. Kakao, Apple, and Google sign-in

With Kakao sign-in, your Kakao service user identifier and the information you allow on the consent screen are passed to Supabase Authentication. With Apple sign-in, we process your Apple user identifier, the email address provided on request (which may be a private relay address), and the name that may be provided at first authentication. With Google sign-in, we receive your Google account identifier, email address and whether it has been verified, name, and profile photo URL through Supabase Authentication. We use this information only for the account and sign-in purposes described in Section 1, and DuDa does not access any other Google account data.

Kakao, Apple, and Google each process the information involved in sign-in as independent personal information controllers. DuDa does not provide symptom scores, notes, hospital, injection, or steroid-use records, or symptom photos to Kakao, Apple, or Google. You can also separately disconnect or manage your provider account information in each provider’s settings.

Even if you use different sign-in methods, signing in with accounts that have the same verified email address may link them to a single DuDa account.

3. Sharing with third parties and outsourced processing

DuDa does not sell personal information or use it for targeted advertising, and does not provide it to independent third parties unless you separately consent or the law requires it.

To provide the service, we entrust Supabase, Inc. with authentication, database, file storage, and account deletion functions; Cloudflare, Inc. with delivering the app update policy and with static web hosting, CDN, and security processing for duda.nlap.app; and Functional Software, Inc. (Sentry) with collecting, storing, and analyzing app error information. These processors handle information to the extent necessary and according to DuDa’s instructions.

4. Processing outside Korea and storage location

The primary storage region for the Supabase project’s database and Storage is AWS Seoul (ap-northeast-2). However, Supabase, Inc., located in the United States, and its approved subprocessors may access or process IP addresses, user agents, request times, and account and service data from outside Korea for service operation, support, and security. Data is transmitted over an encrypted network while you use the app, and is processed until you delete your account or until the end of the retention period described below.

When the app checks the update policy or when you visit duda.nlap.app, Cloudflare, Inc., located in the United States, may process your IP address, user agent, request URL and time, and security events on its global edge network. This is used to deliver the update policy and the website, optimize transmission, and defend against attacks, and is retained for the period set by Cloudflare’s service and security log policies.

If you choose Apple sign-in, the authentication request and your Apple user identifier, email, and name, and whether they are provided, may be processed by Apple Inc., located in the United States, and related infrastructure. The transfer takes place at the time of the sign-in request, and retention and deletion follow Apple’s Privacy Policy and your settings.

If you choose Google sign-in, the authentication request and your Google account identifier, email, name, and profile photo URL may be processed by Google LLC, located in the United States, and related infrastructure. The transfer takes place at the time of the sign-in request, and retention and deletion follow Google’s Privacy Policy and your settings.

When an error occurs in the app, the error type and details, a screenshot of the app screen at the moment of the error, related request and activity logs, user UUID, app installation identifier, device and operating system information, and IP address are transmitted at that time over an encrypted network to Functional Software, Inc. (Sentry, contact: [email protected]), located in the United States. This is for analyzing the cause of errors and preventing them from happening again, and the information is kept by Sentry for 30 days and then automatically deleted.

If you do not want error reports to be sent, you can ask to opt out by emailing [email protected]. After verifying your identity, we will delete the error information that we can find and delete, and for information that is difficult to find or delete separately, we will let you know that it is automatically deleted after 30 days. The current app has no setting to turn off error reporting, so if an error occurs later, information may be sent again; this information is also automatically deleted after 30 days. Even if you opt out, you can continue to use the recording features as before.

5. Retention period

While your account is in use, we keep your account and profile, health records and photos, inquiry and error information, and minimal operational information. When you delete an individual record in the app, a soft delete that removes it from the screen may be applied. When you delete your account, your account and sign-in information are deleted, and your existing records are anonymized and their link to your account is removed.

The app’s temporary files, cache, and settings may remain on your device until they are overwritten, the app is deleted, or the operating system clears them. Information needed for legal retention obligations, dispute handling, or service providers’ security backups and logs is stored separately to the extent and for the period necessary for that purpose and then deleted.

App error information is kept by Sentry for 30 days and then deleted, and may remain during this period even after you delete your account.

6. How to delete data and delete your account

You can request account deletion in the app’s settings. If the app is not installed, you can request additional deletion at duda.nlap.app/account-deletion. When you delete your account, your account and sign-in information are deleted, and your existing records are anonymized and their link to your account is removed. Existing records and photos are not restored to or reconnected with a new account.

Deleting your DuDa account does not delete your Kakao, Apple, or Google provider account or the connection on the provider’s side. If you sign in again with the same social account, a new DuDa account with no past records is created. For additional deletion requests, we will verify your identity and the data concerned and then let you know the result.

7. Your rights

You can request access to, correction or deletion of, or suspension of processing of your personal information, and you can withdraw your consent. If you make a request using the contact below, we will verify your identity and the information concerned and then let you know how it will be handled and the result.

Withdrawing consent or deleting your account does not by itself delete existing records. If you delete individual records in the app or request additional deletion by email below, we will verify your identity and the data concerned and then let you know the result.

8. Security measures

DuDa applies technical and administrative measures such as encrypted communication, authentication-based access, least privilege and minimal logging, and access policy management. Because health information and photos are sensitive, please also take care when using shared devices and when sharing your screen or photos.

9. Automatic collection and cookies

The app does not use advertising SDKs or behavioral analytics SDKs, and uses the Sentry SDK for error reporting (Sections 1 and 4). duda.nlap.app also does not itself set cookies for targeted advertising or behavioral analytics. However, Cloudflare may automatically process IP addresses, user agents, and request logs to deliver and secure the website.

10. Privacy contact

Privacy Officer: DuDa operator

Please send requests for access, correction, deletion, or suspension of processing of your personal information, or any questions about how it is processed, by email.

11. Changes to this policy

If this policy changes because of changes to the service or the law, we will notify you in the app or on the website before the effective date. We will explain important changes separately in a way that is easy to understand.