Privacy Policy
Business and Contact Information
- Service: PALAP
- Operator: DLuminous
- Representative: DOE HOON LEE
- Business Registration No.: 697-24-02021
- Contact Email: help@dluminous.com
- Effective Date: August 20, 2026
1. General Provisions
DLuminous (the "Operator") respects and protects the privacy of users of PALAP (the "Service"). The Operator processes personal information only to the extent necessary to provide the Service and applies reasonable technical and organizational measures to protect such information in accordance with applicable laws and this Privacy Policy.
This Privacy Policy applies to the processing of personal information in connection with account registration and sign-in, workout and diet records, profiles, community features, rankings, subscriptions, advertising, notifications, customer inquiries, reports, and account deletion.
The Service is intended as a general fitness tracking and community service and is not designed primarily for children.
To provide the Service, the Operator may use third-party services and infrastructure, including Firebase Authentication, Cloud Firestore, Firebase Storage, RevenueCat, Google AdMob, Expo Push, and Slack.
The displayName used in PALAP is an in-service nickname or user identifier. The Operator does not require or collect a user's legal name for profile purposes.
2. Personal Information and Usage Information We Process
The Operator may process the following information in connection with the provision of the Service.
A. Account and Authentication Information
- User identifier (UID) generated through Firebase Authentication
- Account creation date and time and most recent sign-in date and time
- PALAP display name (displayName)
- Language code
- Time zone (timeZone)
- Sign-in provider and account identifiers required for authentication
If a user signs in through a third-party provider such as Google or Apple, the provider and Firebase Authentication may process information required for authentication, including an email address. The Operator does not use such information for the purpose of separately collecting it as PALAP profile information.
B. Profile and Service Settings
- Self-introduction (bio)
- Notification preferences and related settings
- Expo push token
- UID and in-service display name of blocked users
- Subscription status and status values used to determine access to Service features
C. Workout Records and Statistics
- Workout routines and exercises created or saved by the user
- Sets, repetitions, workout duration, weight, and selected weight unit
- Workout records and statistics by body part
- Workout dates, exercise history, and workout duration history
- Daily score, cumulative score, score history, and monthly score-related status
- Workout note content
- Exercise or routine identifiers associated with workout notes
D. Diet Records
- Date of record
- Meal category
- Food name
- Calories
- Total calories
- Internal identifiers used to distinguish diet entries
E. Community and Public Activity Information
- Posts, comments, photos, and polls
- Likes on posts and comments
- Author UID and in-service display name
- Language, posting time, and public interaction information
- Community images uploaded by the user
- Information required to process blocks and reports
F. Report Information
- Reporter UID
- Type of reported target
- Identifier of the reported post or comment
- UID of the reported content owner
- Report reason and additional details
- Relevant content excerpt or snapshot at the time of the report
- Records necessary to receive and process the report
G. Customer Support Information
When a user submits an inquiry through the in-app support feature, the following information may be processed:
- User UID
- Inquiry content and inquiry category
- App version and build version
- Device information submitted with the inquiry
- Date and time the inquiry was received
If a user contacts help@dluminous.com directly or requests account deletion by email, the Operator may process the email address and any identity-verification information voluntarily provided by the user to the extent necessary to handle the inquiry or request.
H. Subscription and Payment-Related Information
- Whether the user has an active PRO subscription
- Subscription product and validity status
- Transaction-related identifiers necessary to verify renewal, cancellation, or refund status
Subscription payments are processed through app marketplaces and payment platforms such as the Apple App Store and Google Play. The Operator does not directly collect or store users' payment card numbers.
I. Advertising and Technical Information
In connection with advertising services such as Google AdMob, the relevant provider may process technical information including:
- Device or app identifiers
- Advertising identifiers
- IP address
- Technical information relating to app and advertising usage
- Operating system and device environment information
The specific scope of processing may vary depending on the privacy settings of the operating system, the user's consent choices, and the policies of the relevant service provider.
J. Security and Service Stability Information
To maintain security, prevent abuse, diagnose errors, and provide the Service, the Operator may process device or app integrity information, request logs, internal processing status, and other technical information reasonably necessary for these purposes.
3. Purposes of Processing
The Operator processes personal information for the following purposes:
- Account registration, sign-in, user authentication, and account management
- Providing the Service based on the user's language and time zone
- Providing workout routines, workout records, workout notes, statistics, and scoring features
- Providing date-based diet records and workout/diet calendar features
- Providing profiles, community features, comments, likes, photos, and polls
- Providing blocking, reporting, content review, and community safety functions
- Providing rankings and public profile-related features
- Verifying subscription status and providing subscriber-only features
- Serving advertisements to free users and applying ad-free status to subscribers
- Sending notifications relating to comments, likes, important notices, customer-support responses, and other Service operations
- Receiving and responding to user inquiries and providing customer support
- Maintaining Service security, preventing abuse, analyzing errors, and improving stability
- Processing account deletion and personal information deletion requests
- Handling disputes, protecting rights, and complying with applicable legal obligations
The Operator uses personal information only within the scope reasonably related to the purposes described above. If personal information must be used for a separate purpose, the Operator will provide notice or obtain consent as required by applicable law.
4. Retention and Use Periods
The Operator retains personal information only for as long as reasonably necessary to fulfill the purposes for which it was processed. As a general rule, personal information is deleted without undue delay when the purpose of processing has been fulfilled or when another deletion event, such as account deletion, occurs.
However, information may be retained for an additional period where necessary to comply with applicable legal retention obligations, resolve disputes, prevent abuse, or comply with the separate retention policies of third-party service providers.
The principal retention periods are as follows.
A. Account and Service Information
Account information, profile settings, workout records, workout notes, diet records, and Service settings are generally processed until the user deletes the account.
B. Workout and Diet Calendar Information
Monthly workout and diet calendar data may be subject to the Service's data expiration policy. Under the current Service architecture, monthly calendar data may expire approximately 12 months after the end of the relevant month.
C. In-App Notifications
In-app notification items are retained for a limited period to provide the Service. Under the current Service architecture, they may expire approximately 30 days after creation.
D. Customer Support Records
Inquiry content and related information submitted through the in-app support feature may be retained for up to 365 days from the date of submission for customer support, service issue investigation, and dispute handling.
E. Reports and Enforcement Records
Information relating to reports and enforcement actions may be retained for as long as reasonably necessary to review reports, maintain community safety, prevent abuse, and handle disputes. Where a related dispute or legal obligation remains pending, such information may be retained for the period reasonably necessary to address that matter.
F. Subscription and Payment-Related Information
Subscription status and transaction-verification information directly managed by the Operator may be processed for as long as necessary to verify subscription status, provide access rights, provide customer support, handle refunds or disputes, and comply with applicable legal obligations. Subscription or transaction records independently held by Apple, Google, RevenueCat, or other third-party providers may be retained in accordance with their respective policies.
G. Transaction Records Required by Applicable Law
Where the Operator is required to retain transaction records under the Korean Act on the Consumer Protection in Electronic Commerce or other applicable law, such records may be retained separately for the legally required period.
- Records concerning labeling and advertising: 6 months
- Records concerning contracts or withdrawal of offers: 5 years
- Records concerning payment and supply of goods or services: 5 years
- Records concerning consumer complaints or dispute resolution: 3 years
Information not directly held by the Operator and independently retained by an app marketplace, payment platform, or other third-party provider is processed in accordance with that provider's policies and applicable law.
5. Deletion Procedures and Methods
The Operator deletes personal information without undue delay when the applicable retention period expires or the purpose of processing has been fulfilled.
Information stored electronically is deleted using the Service's data deletion functions or the deletion mechanisms provided by the relevant storage system, using reasonable methods designed to make recovery or reuse impracticable.
Where information must be retained for a certain period due to applicable law, dispute handling, or another legitimate reason, it will be separated from other information where appropriate, retained only for the necessary period, and then deleted.
6. Disclosure of Personal Information to Third Parties
The Operator does not sell users' personal information and, as a general rule, does not disclose personal information to third parties for purposes outside those described in this Privacy Policy.
Personal information may, however, be disclosed where:
- The user has provided prior consent;
- Disclosure is required or permitted by applicable law or requested through a lawful process by a competent authority; or
- Information is displayed to other users through a public feature intentionally used by the user.
Posts, comments, photos, polls, in-service display names, public profile information, ranking information, and other content submitted to public features may be visible to other users as part of the functionality of the Service.
App marketplaces such as the Apple App Store and Google Play may independently process user information in connection with payments and subscriptions in accordance with their own privacy policies.
7. Outsourced Processing and Cross-Border Transfers
The Operator may engage third-party service providers to process personal information and may transfer personal information outside the Republic of Korea to the extent necessary to provide the Service.
Cross-border transfers that are necessary for the performance of a contract with the user, including outsourced processing and storage, may be made pursuant to Article 28-8(1)(3) of the Korean Personal Information Protection Act. The Operator discloses information regarding such transfers in this Privacy Policy as required by applicable law.
Users may object to cross-border transfers through the methods described below. However, where authentication, data storage, or other cross-border processing is necessary to provide the Service, refusal may result in the inability to use all or part of PALAP.
A. Google LLC / Firebase
- Services Used: Firebase Authentication, Cloud Firestore, Firebase Storage, and Firebase infrastructure necessary to operate the Service
- Personal Information Transferred: User UID; authentication and account information; in-service display name; language code; timeZone; profile and settings information; push token and notification-related information; workout and diet records; workout notes; community content and activity information; uploaded images; information necessary to process customer inquiries and reports; and other Service data stored or processed through Firebase
- Destination Country: United States. Firebase Authentication is processed in U.S. data centers, and PALAP's primary Cloud Firestore and Firebase Storage region is us-central1 in the United States. Certain Firebase operational, support, and security processing may also occur in other countries where Google or its subprocessors operate facilities.
- Timing and Method of Transfer: At the time Firebase functionality is used, including account registration, sign-in, storage, retrieval, modification, deletion of Service data, and file uploads, through encrypted network communications
- Recipient: Google LLC
- Contact: Google Privacy Help Center (https://support.google.com/policies/answer/9581826)
- Purpose: User authentication, Service data storage and synchronization, file storage, server functionality, security, and Service stability
- Retention and Use Period: Until the relevant Service purpose has been fulfilled. Customer data is deleted in accordance with PALAP's account deletion and data deletion procedures, after which Google's contractual deletion procedures or any applicable legal retention obligations may continue to apply.
- How to Refuse and Effect of Refusal: Users may request that the relevant processing cease by deleting their account. Because Firebase authentication and data storage are essential to PALAP's core functionality, refusing such processing may make the Service unavailable or materially limit key features.
B. RevenueCat, Inc.
- Service Used: RevenueCat
- Personal Information Transferred: PALAP internal user identifiers; subscription product information; subscription status; Apple receipts or Google purchase tokens and other information necessary to verify subscription transactions; and information required to determine subscription access rights
- Destination Country: United States. RevenueCat states that customer data is stored in Amazon Web Services (AWS) data centers located in the United States.
- Timing and Method of Transfer: When a subscription is purchased, restored, renewed, canceled, or when subscription status is checked or synchronized, through encrypted network communications
- Recipient: RevenueCat, Inc.
- Contact: compliance@revenuecat.com
- Purpose: Verifying subscription status and eligibility, synchronizing transaction status, and applying access rights for paid features
- Retention and Use Period: For the period during which PALAP uses RevenueCat and for as long as necessary for subscription verification, customer support, and dispute handling. Under RevenueCat's Data Processing Addendum, Customer Personal Data may be returned or deleted upon request at the end or expiration of the processing relationship, subject to RevenueCat's standard backup and archival practices and any applicable legal obligations.
- How to Refuse and Effect of Refusal: Users may choose not to use paid subscription features or may contact help@dluminous.com regarding the processing or deletion of related personal information. Refusing the processing of subscription information may prevent the purchase or restoration of a PRO subscription or access to subscriber-only features.
C. 650 Industries, Inc. (Expo)
- Service Used: Expo Push
- Personal Information Transferred: Expo push token, notification content, and internal identifiers necessary to deliver notifications
- Destination Country: United States. Expo states that information relating to users outside the United States may be transferred to and processed in the United States for the provision of its services.
- Timing and Method of Transfer: When a push notification is sent to the user, through encrypted network communications
- Recipient: 650 Industries, Inc. (Expo)
- Contact: Expo Contact Page (https://expo.dev/contact)
- Purpose: Delivery of push notifications
- Retention and Use Period: Expo push tokens may be processed for as long as necessary to provide push notifications. Expo states that notification content is not stored after it is handed off to Google FCM or Apple APNs, subject to any additional retention required by applicable law.
- How to Refuse and Effect of Refusal: Users may disable push notifications through the operating system or PALAP notification settings. If disabled, users will not receive push notifications relating to comments, likes, important notices, customer-support responses, and similar Service events.
D. Slack
- Service Used: Slack
- Personal Information Transferred: User UID; inquiry or report content; inquiry category; app version; build version; device information submitted by the user; identifiers relating to reported content; relevant excerpts of reported content; and other information necessary to process inquiries or reports
- Destination Country: United States. Slack states that its default data storage location is the United States and that certain data may be processed in the United States to provide the service.
- Timing and Method of Transfer: When a user submits an inquiry or report, or when the relevant inquiry or report is transmitted by the server to the Operator, through encrypted network communications
- Recipient: Slack Technologies Limited
- Contact: privacy@slack.com
- Purpose: Internal transmission and handling of inquiries and reports, customer support, community safety, and operational response
- Retention and Use Period: For as long as reasonably necessary to process inquiries and reports and for related operational purposes. Data within Slack is retained or deleted in accordance with the data retention settings applicable to the relevant workspace.
- How to Refuse and Effect of Refusal: Users may avoid the cross-border transfer associated with these features by choosing not to use the inquiry or report functions. However, information concerning content that is reported by another user may still be processed where necessary for Service safety, dispute handling, and compliance with applicable law.
Third-party advertising SDKs such as Google AdMob may directly process advertising identifiers, IP addresses, device information, app-related technical information, and similar data from the user's device in connection with ad delivery. Additional information regarding advertising-related processing and user choices is provided in Section 8, "Automatically Collected Information and Advertising."
The Operator takes reasonable measures to protect personal information and user rights in connection with cross-border transfers as required by applicable law. If there is a material change to a cross-border recipient, destination country, processing purpose, or retention period, the Operator will update this Privacy Policy accordingly.
8. Automatically Collected Information and Advertising
PALAP does not operate its app service by using website cookies to track app users.
However, AdMob, Firebase, and other third-party SDKs or platforms necessary to operate the Service may automatically process device information, advertising identifiers, IP addresses, and technical information relating to app usage for service delivery, advertising, security, or error analysis.
Users may be able to limit certain processing through operating-system privacy settings, advertising tracking settings, or choices provided by the relevant platform. Even where those settings are restricted, certain technical information necessary to provide the Service may still be processed.
9. Public Information in Community, Profile, and Ranking Features
When a user participates in community features, content submitted by the user may be displayed to other users together with the user's in-service display name, posting time, number of likes, number of comments, and other public interaction information.
Rankings may display the user's in-service display name, score, tier, rank, and other information necessary to provide the ranking feature.
Depending on Service policy, certain users may be able to view another user's public profile, bio, or shareable routine information, or import routines using functionality provided by the Service.
Users must not post or exchange the following information in public community areas:
- Passwords or authentication credentials
- Government-issued identification numbers, including Korean resident registration numbers and passport numbers
- Phone numbers or personal email addresses
- Personal social media usernames, profile links, or account identifiers
- External messaging service IDs
- Home addresses or other information that enables direct contact with or identification of an individual
DLuminous and PALAP do not request passwords or personal information from users through posts, comments, or other public community content. Content that requests or shares such information may be restricted or removed without prior notice in order to protect users and maintain community safety.
10. User and Legal Representative Rights and How to Exercise Them
Subject to applicable law, users may exercise rights relating to their personal information, including rights to access, correct, delete, or restrict processing. Where applicable law permits or requires a legal representative to exercise rights on behalf of a user, that legal representative may exercise the applicable rights.
Requests may be submitted through features provided in the app or by contacting help@dluminous.com. Where permitted by applicable law, a duly authorized representative may also submit a request on behalf of the user.
The Operator may request only the minimum information reasonably necessary to verify that the requester is the account owner, a legal representative, or a duly authorized representative.
Requests to access, correct, delete, or restrict the processing of personal information may be submitted and handled through help@dluminous.com.
A request may be restricted in whole or in part to the extent permitted by applicable law where:
- The request may infringe the rights or privacy of another user;
- The information is necessary for reporting, enforcement, security, or dispute-handling purposes;
- Retention is required by applicable law; or
- The relevant information is independently controlled or retained by Apple, Google, RevenueCat, or another third-party provider.
11. Account Deletion and Deletion of Personal Information
Users may delete their account through the account deletion feature provided in the app.
Users may also request account deletion by emailing help@dluminous.com. For email-based deletion requests, the Operator will reasonably verify that the requester owns the relevant account before proceeding. Only the minimum information necessary to process the deletion request will be requested or processed for identity verification.
When an account is deleted, the following information directly managed by the Operator is subject to deletion in accordance with the Service's current deletion process:
- Push tokens and notification delivery registration information
- Community images uploaded by the user
- Posts and comments created by the user
- Likes placed by the user on posts and comments
- Workout and diet calendar records
- In-app notifications
- Workout profile and related Service data
- Basic user information
- Firebase Authentication account
For accounts using Sign in with Apple, the account deletion process may include revocation of the applicable Apple authentication token before deletion of the Firebase Authentication account.
However, the following information may be retained separately after account deletion only for the applicable purpose and period:
- In-app customer-support records: for up to 365 days from submission, as described in Section 4
- Report and enforcement records: for as long as reasonably necessary for report review, abuse prevention, dispute handling, or legal compliance
- Subscription or transaction records directly managed by the Operator where retention is required by applicable law: for the statutory periods described in Section 4
- Information independently retained by app marketplaces, payment platforms, RevenueCat, or other third parties: in accordance with the relevant provider's policies and applicable law
Temporary cache or backup data created in the course of providing the Service may not be deleted immediately and may be removed according to the refresh, backup, and deletion cycles of the relevant systems or infrastructure providers.
12. Security Measures
The Operator applies reasonable safeguards appropriate to the size of the Service and the nature of the information processed in order to reduce the risk of loss, theft, unauthorized disclosure, alteration, or destruction of personal information.
These measures include:
- Account access controls centered on authenticated users
- Server-side authorization and access controls
- Use of app integrity verification mechanisms such as App Check
- Restricting unnecessary access to personal information and user data
- Use of security features provided by infrastructure providers such as Firebase
- Processing only the minimum information necessary to operate the Service
- Monitoring and responding to abnormal use, reports, and security incidents
- Maintaining procedures for deleting relevant data when an account deletion request is processed
13. Children's Privacy
PALAP is not designed primarily for children.
Users who are below the age at which parental or guardian consent is required under the laws of their country or region must not use the Service without the required consent.
If the Operator becomes aware that personal information of a child has been processed without legally required parental or guardian consent, the Operator may take appropriate action in accordance with applicable law and Service procedures.
14. Privacy Contact and Changes to This Policy
Questions regarding privacy, requests to exercise privacy rights, or privacy-related complaints may be directed to:
- Privacy Officer: DOE HOON LEE
- Email: help@dluminous.com
If this Privacy Policy is amended, the Operator will provide notice through the app, website, or another reasonable method. Where a material change is made, the Operator will make reasonable efforts to provide notice before the change takes effect.
This Privacy Policy is effective as of August 20, 2026.