← Re:spec Alarm

Privacy Policy

Effective Date: July 28, 2026
Last Updated: September 15, 2026


Potential Labs Inc. ("Company," "we," "us," or "our") values your privacy. This Privacy Policy explains how information is collected, used, and protected in the mobile application "Re:spec Alarm" ("Service"). This policy is intended for users in the United States, Canada, and Australia, and reflects applicable requirements including the California Consumer Privacy Act (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Australia's Privacy Act 1988.

The Service can be used in a guest state without any account registration or login. We do not collect account-identifying information such as your real name or email address.

We do not sell your personal information for money. The Service displays one banner advertisement at the top of the home screen; no advertising is shown on the alarm ringing screen. For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we obtain advertising consent through Google's User Messaging Platform (UMP) using the IAB TCF framework; if consent is not given, non-personalized ads are shown instead of personalized ads, and if no consent decision is obtained (for example, the consent form fails to load or goes unanswered), no ad is requested. We share a limited set of information — an app-level advertising identifier, device/app information, IP address, approximate location, ad interaction data, and two conversion events — with advertising platforms in order to serve ads and to measure the performance of our advertising, which California law treats as "sharing" for cross-context behavioral advertising. We do not provide advertising platforms with your name, email address, phone number, or anything you have written. California residents may opt out; see Section 9. We can also disable advertising entirely through remote (server-side) configuration.

In this policy, "personal information" means information about an identifiable individual, including information that on its own may not identify you but that could reasonably be combined with other information to identify you.


1. Information We Collect and Purpose

We collect the minimum information necessary to provide the Service, as follows.

Data Collected Purpose Retention Period
Alarm & settings data (alarm time, repeat days, custom message text, goal count, alarm mode, default alarm sound) Core function: creating and running alarms Stored locally on device; deleted when the app is uninstalled
Nickname Generating personalized custom messages Stored locally on device; deleted when the app is uninstalled
Emotion category selection Generating personalized custom messages; service usage analytics Retained as a user property for the duration of Service use (see Section 6)
Free-text responses and AI conversation input Generating personalized custom messages Original text not stored on Company servers. On-device conversation history is retained for 30 days, then automatically deleted. Transmitted to Amplitude for service analytics (Section 6)
Character-length of generated custom messages Analytics: dwell-time calibration, generation-error detection, message quality improvement 2 years from collection
Custom message (text) for voice synthesis Text-to-speech (TTS) voice synthesis Processed on Company backend; automatically deleted within a maximum of 1 day after completion
Generated voice audio Playback of TTS output Stored on Company backend (cloud storage) for a maximum of 1 day, then automatically deleted
Voice/audio (microphone speech) Speech-to-text (STT) based alarm mission Processed and stored on device; deleted when the app is uninstalled (original audio not stored on Company servers)
Usage & diagnostic data (event metadata, device identifiers, advertising identifier (Android Advertising ID), approximate location, device/app information) Service usage analytics, quality improvement, fraud prevention, ad serving, and advertising performance measurement 2 years from collection

Nickname guidance: We recommend using a nickname rather than your real name, and we advise users not to voluntarily enter real-name or other identifying information.

Automatic collection: Usage and diagnostic data may be collected automatically through analytics SDKs during use of the Service. As a mobile application, the Service does not use web cookies. Opt-out methods are described in Section 8.

Advertising identifier: The Service uses the Android Advertising ID (AAID) for analytics, ad serving, and advertising performance measurement. This is a resettable, device-level identifier. You can reset or delete it at any time under Settings → Privacy → Ads on your device. We do not combine it with information that directly identifies you, such as your name or phone number.

Advertising performance measurement: To measure the performance of our advertising, we transmit app installation and launch records, together with two conversion events (onboarding completed, alarm set), to an advertising platform. These transmissions never include anything you have written — custom message text, free-text responses, and speech-recognition transcripts are excluded — and we do not provide the platform with account, email, or phone identifiers. See Section 6 for the recipient.

We process information for ad serving and advertising performance measurement only to the extent described above. The Service displays one banner advertisement at the top of the home screen; no advertising is shown on the alarm ringing screen. For users in the EEA, the United Kingdom, and Switzerland, we obtain advertising consent through Google's User Messaging Platform (UMP) using the IAB TCF framework; if consent is not given, non-personalized ads are shown instead of personalized ads, and if no consent decision is obtained, no ad is requested. Any marketing-related processing beyond this scope will require separate consent and an update to this policy.


2. Processing of Voice/Audio Information

The Service may process microphone input, speech-recognition result text, and text for voice synthesis in order to provide speech recognition (STT) and voice synthesis (TTS) features.

Speech recognition: The Service processes microphone input in two situations: (1) when you choose to answer by voice during a conversation, and (2) when you speak your custom message aloud during an alarm mission. In each case, a screen explaining the purpose of microphone access is shown before the system permission request appears. Speech is converted to text on-device via the Android operating system's speech-recognition feature (SpeechRecognizer), either to check whether it matches your set custom message or to register it as a conversational response. Recognition results are processed on-device; we do not operate our own speech-recognition server and do not transmit or collect the original audio or recognition results to our servers.

Voice output (TTS): To read custom messages aloud, the Service either (i) uses the Android operating system's on-device voice synthesis feature (TextToSpeech), or (ii) performs voice synthesis via a Company-operated backend (based on Google Cloud Platform) for more natural-sounding audio. In case (ii), the synthesis-target text (custom message) is transmitted over the network to the Company backend and voice-synthesis provider, and the generated audio is temporarily stored in the Company backend's cloud storage (maximum 1 day) before automatic deletion. The text and audio are used solely for voice synthesis, are not used for model training, and related processing/transfers follow Section 6.

Depending on how the Android SpeechRecognizer/TextToSpeech and any recognition/synthesis engine you select operate, audio or text may be transmitted to the servers of the relevant provider (e.g., Google), in which case that provider's privacy policy applies.

You may revoke microphone permission at any time in your device's app permission settings. Permissions such as "full-screen notification," "battery optimization exemption," and "exact alarm" are used only to display and run alarms on time and do not collect personal information.


3. AI Custom Message Generation and Sensitive Information

When you select the AI custom-message generation method while adding an alarm, we collect and process your answers to two question flows — (1) an emotion category selection, and (2) a free-text response or conversational reply with the AI — to generate a personalized custom message. Original response text is processed transiently on-device for message generation, and is transmitted to Amplitude for service analytics (Section 6).

Responses may contain potentially sensitive information such as your emotions or goals. We do not use such responses for any purpose other than message generation (e.g., model training) without your explicit consent, and this feature is not a substitute for medical or psychological counseling. You may report inappropriate AI responses through the in-app "Report Inappropriate Response" feature or the contact in Section 11. Delegation and cross-border transfer of responses follow Section 6.

For analytics purposes, generated custom messages are transmitted to Amplitude (Section 6), and this is used solely to improve the accuracy of message-viewing detection, to check for anomalies in the generation process, and to improve message quality going forward. However, when a generated custom message is output as voice (TTS), the message text may be transmitted to and processed by the Company backend and voice-synthesis provider, as described in Sections 2 and 6.

We analyze your conversation content to infer your emotional state on-device only; this inference result (emotional state, tendencies, needs, etc.) is stored only locally and is not transmitted to or collected by our servers. However, in the course of this inference, the original conversation text is transmitted to Google Gemini for analysis, to which the delegation/cross-border transfer provisions of Section 6 apply.

This section will be amended and disclosed if data-processing methods change.


4. Retention and Use Period

Personal information is destroyed without delay upon fulfillment of the processing purpose or upon app deletion. Alarm, settings, nickname, and similar data are stored locally on-device and are deleted when the app is uninstalled. Where retention is required by applicable law, we retain the information for the period prescribed by that law.


5. Disclosure to Third Parties

We do not, in principle, disclose your personal information externally. However, it may be disclosed in limited legal exceptions, such as pursuant to law or a lawful request by an investigative authority.


6. Delegation of Processing and Cross-Border Transfer

We delegate the processing of personal information to the following service providers. Because these providers are located outside your country (primarily the United States), such delegation involves a cross-border transfer of data.

Recipient (Contact) Country Data Transferred Timing/Method Purpose Retention Period
Google LLC — Firebase AI Logic / Vertex AI Gemini (080-822-1422) United States (us-central1) User answer text for AI questions; conversation text for emotional-state inference Network transmission upon message-generation / inference request AI-based custom message generation; emotional-state inference Used solely for result generation; not used for model training
Google LLC — Google Cloud Platform (Cloud Run, Cloud Storage, etc.) (080-822-1422) United States Custom message text; generated voice audio Network transmission upon TTS request Voice synthesis (TTS) processing and delivery of result audio Automatically deleted within a maximum of 1 day after completion; not used for model training
Amplitude, Inc. (privacy@amplitude.com) United States Event metadata (length, count, duration, type, etc.); onboarding emotion category (positive/negative/free, retained as a user property for the duration of Service use); device identifiers; approximate location (IP-based); text written by the user and custom messages delivered by an alarm — speech-recognition transcripts and recordings are not included Automatic transmission during app use Service usage analytics Events: 2 years; emotion category retained for the duration of Service use
Google LLC — Google Analytics for Firebase / GA4 (080-822-1422) United States App event and user data (app instance identifiers, etc.) Automatic transmission during app use Service usage analytics Event data 2 months; user data 14 months
Google LLC — Firebase (080-822-1422) United States App instance identifier; usage/diagnostic data Automatic transmission during app use App Check (app integrity verification) and AI backend integration Duration of Service provision
Meta Platforms, Inc. (https://www.facebook.com/help/contact/540977946302970) United States App install and launch records; metadata of two conversion events (onboarding completed, alarm set); advertising identifier (Android Advertising ID); device/app information; IP address — no user-authored content and no speech-recognition transcripts Automatic transmission during app use Advertising performance measurement and ad optimization Per Meta's Data Policy
Google LLC (for users in the United States) / Google Ireland Limited (for users elsewhere) — Google AdMob (https://policies.google.com/privacy) United States / Ireland Advertising identifier (Android Advertising ID); device/app information; IP address; approximate location; ad interaction data such as impressions and clicks — no user-authored content and no speech-recognition transcripts Network transmission when an ad is requested during app use Ad serving and ad measurement Per Google's policies (policies.google.com/privacy, business.safety.google/adsservices)

Objection to cross-border transfer: You may contact the Privacy Officer in Section 11 (privacy@potential-labs.com) to object to the cross-border transfer of your personal information. If you object, we will exclude your personal information from cross-border transfer. However, features that necessarily require cross-border transfer (AI custom message generation, voice synthesis, service usage analytics, etc.) may then be restricted.


7. Destruction Procedure and Method

Procedure: Personal information whose processing purpose has been fulfilled is destroyed without delay; where retention is legally required, it is stored separately before destruction.

Method: Electronic files are permanently deleted using technical methods that render them unrecoverable, and on-device local data (conversation history, etc.) is deleted when the app is uninstalled or when the retention period for each item (e.g., 30 days for conversation history) has elapsed. Custom message text and voice audio temporarily stored on the Company backend for TTS are automatically deleted upon completion or within a maximum of 1 day. To request immediate deletion of data transmitted to third-party AI services (Google Gemini) during message generation/inference, or of voice files stored on the server, contact the Privacy Officer in Section 11.


8. Automatically Collected Information and Opt-Out

The Service does not use web cookies. Usage and diagnostic data for analytics are collected through analytics SDKs, and you may refuse collection via device settings or by uninstalling the app. During analysis, we do not transmit speech-recognition transcripts or recordings. (Amplitude collects event metadata along with device identifiers and approximate (IP-based) location. Location is only an approximate estimate based on IP; we do not use GPS precise location or location permissions.)

Current product analytics use Amplitude and Google Analytics for Firebase (GA4); advertising performance measurement uses the Meta (Facebook) SDK, and ad serving uses Google AdMob. GA4's data retention is 2 months for event data and 14 months for user data. Firebase is also used for AI backend integration and App Check.

Opting out of advertising measurement: You can prevent identifier-based measurement by deleting your advertising ID under Settings → Privacy → Ads on your device. We also maintain the ability to disable advertising performance measurement entirely through server-side configuration; you may request this via the contact in Section 11. Ad serving can likewise be disabled entirely through remote (server-side) configuration.

Managing advertising consent: If you are in the EEA, the United Kingdom, or Switzerland, you can change or withdraw your advertising consent at any time from "Manage ad consent" in the app's settings. This item appears only in regions where consent is required and is not shown elsewhere.


9. Your Rights

You may at any time request access to, correction of, deletion of, or restriction of processing of your personal information. On-device local data is deleted immediately when the app is uninstalled, and permissions such as the microphone can be revoked in device settings. Other requests may be made to the Privacy Officer in Section 11 (in writing, by email, etc.), and we will act without delay. These rights may be exercised through a legal representative or authorized agent.

For California residents (CCPA/CPRA): You have the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell your personal information for money. We do share an advertising identifier, device/app information, IP address, approximate location, ad interaction data, and two conversion events with advertising platforms for ad serving and advertising performance measurement, which California law treats as "sharing" for cross-context behavioral advertising. To opt out, contact us using the details in Section 11 or use the "Do Not Sell or Share My Personal Information" link on this site; we will disable advertising measurement and personalized ad serving for your device. We will not discriminate against you for exercising these rights.

For Canadian residents (PIPEDA) and Australian residents (Privacy Act 1988): You have the right to access and correct your personal information and to lodge a complaint with the relevant regulator (see Section 13).


10. Age Restriction

The Service is intended for users aged 13 and older. Use by children under 13 is not permitted. We do not knowingly collect personal information from children under 13, and if such collection is confirmed, we will destroy it without delay. This is consistent with the U.S. Children's Online Privacy Protection Act (COPPA).


11. Privacy Officer

We designate the following Privacy Officer to oversee personal information processing and to handle user inquiries, complaints, and remedies.

Privacy Officer: Chunghwan Kim (CEO)
Department: Operations Team
Contact: privacy@potential-labs.com / +82-10-7940-5395


12. Security Measures

Administrative: Minimization of personal information processing; restriction of processing authority and access control.

Technical: Data transmitted externally is protected with encrypted communication (HTTPS/TLS), and backend requests are subject to integrity verification (Firebase App Check / Play Integrity). Most user data, such as alarm and settings data, is stored in on-device storage rather than on Company servers. However, custom message text and generated voice audio for TTS are processed/stored on the Company backend for a maximum of 1 day before automatic deletion.


13. How to Lodge a Complaint

You may contact the following authorities for dispute resolution or consultation regarding privacy:


14. Changes to This Privacy Policy

  1. This Privacy Policy took effect on July 28, 2026, and the amended policy takes effect on September 15, 2026.

  2. (Amendment history) September 15, 2026: Disclosed that the items transmitted to Amplitude for service analytics include text written by the user and custom messages delivered by an alarm (Section 1 collection table, Section 3, Section 6), and corrected the previous statement that such content is not transmitted during analysis (Section 8). Speech-recognition transcripts and recordings are still not transmitted.

  3. September 10, 2026: Following the introduction of a banner advertisement on the home screen, removed the previous statement that no advertising is displayed inside the app and disclosed that a banner ad is shown on the home screen, that advertising consent is obtained in the EEA, the United Kingdom, and Switzerland (Google UMP / IAB TCF), and that non-personalized ads are shown where consent is not given (Preamble, Section 1). Added Google advertising (AdMob) as a processor and cross-border recipient for ad serving and measurement (Section 6), and described how to change or withdraw consent via "Manage ad consent" in the app's settings (Section 8).

  4. (Amendment history) August 11, 2026: Added Meta Platforms, Inc. as a processor and cross-border recipient for advertising performance measurement (Section 6), and specified the scope of the events transmitted and the exclusion of user-authored content (Section 1). Disclosed that the Android Advertising ID is used for analytics and advertising performance measurement, together with how to reset or delete it (Sections 1 and 8). Clarified our position on "sale" and "sharing" under CCPA/CPRA and added an opt-out route (Preamble, Section 9).

  5. This policy may be amended in accordance with changes in law, guidelines, or internal Company policy. As the Service has no separate user account (email), changes will be announced through in-app notices and the Google Play Store listing. Changes materially affecting user rights will be announced at least 30 days in advance; other changes at least 7 days in advance.


Inquiries regarding this Privacy Policy: privacy@potential-labs.com

Posted URL: https://respec-time.respec.app/en/privacy/

© 2026 Potential Labs Inc.