Privacy Policy
Effective Date: July 28, 2026
Last Updated: July 28, 2026
Potential Labs Inc. ("Company," "we," "us," or "our") values your privacy. This Privacy Policy explains how information is collected, used, and protected in the mobile application "Re:spec Alarm" ("Service"). This policy is intended for users in the United States, Canada, and Australia, and reflects applicable requirements including the California Consumer Privacy Act (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Australia's Privacy Act 1988.
The Service can be used in a guest state without any account registration or login. We do not collect account-identifying information such as your real name or email address.
We do not sell or share your personal information for cross-context behavioral advertising.
In this policy, "personal information" means information about an identifiable individual, including information that on its own may not identify you but that could reasonably be combined with other information to identify you.
1. Information We Collect and Purpose
We collect the minimum information necessary to provide the Service, as follows.
| Data Collected | Purpose | Retention Period |
|---|---|---|
| Alarm & settings data (alarm time, repeat days, custom message text, goal count, alarm mode, default alarm sound) | Core function: creating and running alarms | Stored locally on device; deleted when the app is uninstalled |
| Nickname | Generating personalized custom messages | Stored locally on device; deleted when the app is uninstalled |
| Emotion category selection | Generating personalized custom messages; service usage analytics | Retained as a user property for the duration of Service use (see Section 6) |
| Free-text responses and AI conversation input | Generating personalized custom messages | Original text not stored on Company servers. On-device conversation history is retained for 30 days, then automatically deleted. Only non-identifying information such as character length is transmitted for analytics |
| Character-length of generated custom messages | Analytics: dwell-time calibration, generation-error detection, message quality improvement | 2 years from collection |
| Custom message (text) for voice synthesis | Text-to-speech (TTS) voice synthesis | Processed on Company backend; automatically deleted within a maximum of 1 day after completion |
| Generated voice audio | Playback of TTS output | Stored on Company backend (cloud storage) for a maximum of 1 day, then automatically deleted |
| Voice/audio (microphone speech) | Speech-to-text (STT) based alarm mission | Processed and stored on device; deleted when the app is uninstalled (original audio not stored on Company servers) |
| Usage & diagnostic data (event metadata, device identifiers, approximate location, device/app information) | Service usage analytics, quality improvement, and fraud prevention | 2 years from collection |
Nickname guidance: We recommend using a nickname rather than your real name, and we advise users not to voluntarily enter real-name or other identifying information.
Automatic collection: Usage and diagnostic data may be collected automatically through analytics SDKs during use of the Service. As a mobile application, the Service does not use web cookies. Opt-out methods are described in Section 8.
We do not currently collect personal information for marketing purposes. If introduced in the future, we will obtain separate consent and update this policy.
2. Processing of Voice/Audio Information
The Service may process microphone input, speech-recognition result text, and text for voice synthesis in order to provide speech recognition (STT) and voice synthesis (TTS) features.
- Speech recognition: The Service processes microphone input in two situations: (1) when you choose to answer by voice during a conversation, and (2) when you speak your custom message aloud during an alarm mission. In each case, a screen explaining the purpose of microphone access is shown before the system permission request appears. Speech is converted to text on-device via the Android operating system's speech-recognition feature (SpeechRecognizer), either to check whether it matches your set custom message or to register it as a conversational response. Recognition results are processed on-device; we do not operate our own speech-recognition server and do not transmit or collect the original audio or recognition results to our servers.
- Voice output (TTS): To read custom messages aloud, the Service either (i) uses the Android operating system's on-device voice synthesis feature (TextToSpeech), or (ii) performs voice synthesis via a Company-operated backend (based on Google Cloud Platform) for more natural-sounding audio. In case (ii), the synthesis-target text (custom message) is transmitted over the network to the Company backend and voice-synthesis provider, and the generated audio is temporarily stored in the Company backend's cloud storage (maximum 1 day) before automatic deletion. The text and audio are used solely for voice synthesis, are not used for model training, and related processing/transfers follow Section 6.
Depending on how the Android SpeechRecognizer/TextToSpeech and any recognition/synthesis engine you select operate, audio or text may be transmitted to the servers of the relevant provider (e.g., Google), in which case that provider's privacy policy applies.
You may revoke microphone permission at any time in your device's app permission settings. Permissions such as "full-screen notification," "battery optimization exemption," and "exact alarm" are used only to display and run alarms on time and do not collect personal information.
3. AI Custom Message Generation and Sensitive Information
When you select the AI custom-message generation method while adding an alarm, we collect and process your answers to two question flows — (1) an emotion category selection, and (2) a free-text response or conversational reply with the AI — to generate a personalized custom message. Original response text is processed transiently on-device for message generation, and any values transmitted externally for analytics are separately processed into non-identifying information such as character length rather than the original text.
Responses may contain potentially sensitive information such as your emotions or goals. We do not use such responses for any purpose other than message generation (e.g., model training) without your explicit consent, and this feature is not a substitute for medical or psychological counseling. You may report inappropriate AI responses through the in-app "Report Inappropriate Response" feature or the contact in Section 11. Delegation and cross-border transfer of responses follow Section 6.
For analytics purposes, only the character-length information of generated custom messages is collected — not the original text — and this is used solely to improve the accuracy of message-viewing detection, to check for anomalies in the generation process, and to improve message quality going forward. However, when a generated custom message is output as voice (TTS), the message text may be transmitted to and processed by the Company backend and voice-synthesis provider, as described in Sections 2 and 6.
We analyze your conversation content to infer your emotional state on-device only; this inference result (emotional state, tendencies, needs, etc.) is stored only locally and is not transmitted to or collected by our servers. However, in the course of this inference, the original conversation text is transmitted to Google Gemini for analysis, to which the delegation/cross-border transfer provisions of Section 6 apply.
This section will be amended and disclosed if data-processing methods change.
4. Retention and Use Period
Personal information is destroyed without delay upon fulfillment of the processing purpose or upon app deletion. Alarm, settings, nickname, and similar data are stored locally on-device and are deleted when the app is uninstalled. Where retention is required by applicable law, we retain the information for the period prescribed by that law.
5. Disclosure to Third Parties
We do not, in principle, disclose your personal information externally. However, it may be disclosed in limited legal exceptions, such as pursuant to law or a lawful request by an investigative authority.
6. Delegation of Processing and Cross-Border Transfer
We delegate the processing of personal information to the following service providers. Because these providers are located outside your country (primarily the United States), such delegation involves a cross-border transfer of data.
| Recipient (Contact) | Country | Data Transferred | Timing/Method | Purpose | Retention Period |
|---|---|---|---|---|---|
| Google LLC — Firebase AI Logic / Vertex AI Gemini (080-822-1422) | United States (us-central1) | User answer text for AI questions; conversation text for emotional-state inference | Network transmission upon message-generation / inference request | AI-based custom message generation; emotional-state inference | Used solely for result generation; not used for model training |
| Google LLC — Google Cloud Platform (Cloud Run, Cloud Storage, etc.) (080-822-1422) | United States | Custom message text; generated voice audio | Network transmission upon TTS request | Voice synthesis (TTS) processing and delivery of result audio | Automatically deleted within a maximum of 1 day after completion; not used for model training |
| Amplitude, Inc. (privacy@amplitude.com) | United States | Event metadata (length, count, duration, type, etc.); onboarding emotion category (positive/negative/free, retained as a user property for the duration of Service use); device identifiers; approximate location (IP-based) | Automatic transmission during app use | Service usage analytics | Events: 2 years; emotion category retained for the duration of Service use |
| Google LLC — Google Analytics for Firebase / GA4 (080-822-1422) | United States | App event and user data (app instance identifiers, etc.) | Automatic transmission during app use | Service usage analytics | Event data 2 months; user data 14 months |
| Google LLC — Firebase (080-822-1422) | United States | App instance identifier; usage/diagnostic data | Automatic transmission during app use | App Check (app integrity verification) and AI backend integration | Duration of Service provision |
Objection to cross-border transfer: You may contact the Privacy Officer in Section 11 (privacy@potential-labs.com) to object to the cross-border transfer of your personal information. If you object, we will exclude your personal information from cross-border transfer. However, features that necessarily require cross-border transfer (AI custom message generation, voice synthesis, service usage analytics, etc.) may then be restricted.
7. Destruction Procedure and Method
- Procedure: Personal information whose processing purpose has been fulfilled is destroyed without delay; where retention is legally required, it is stored separately before destruction.
- Method: Electronic files are permanently deleted using technical methods that render them unrecoverable, and on-device local data (conversation history, etc.) is deleted when the app is uninstalled or when the retention period for each item (e.g., 30 days for conversation history) has elapsed. Custom message text and voice audio temporarily stored on the Company backend for TTS are automatically deleted upon completion or within a maximum of 1 day. To request immediate deletion of data transmitted to third-party AI services (Google Gemini) during message generation/inference, or of voice files stored on the server, contact the Privacy Officer in Section 11.
8. Automatically Collected Information and Opt-Out
The Service does not use web cookies. Usage and diagnostic data for analytics are collected through analytics SDKs, and you may refuse collection via device settings or by uninstalling the app. During analysis, we do not transmit identifiable content such as custom message text or speech-recognition transcripts. (Amplitude collects event metadata along with device identifiers and approximate (IP-based) location. Location is only an approximate estimate based on IP; we do not use GPS precise location or location permissions.)
Current product analytics use Amplitude and Google Analytics for Firebase (GA4). GA4's data retention is 2 months for event data and 14 months for user data. Firebase is also used for AI backend integration and App Check.
9. Your Rights
You may at any time request access to, correction of, deletion of, or restriction of processing of your personal information. On-device local data is deleted immediately when the app is uninstalled, and permissions such as the microphone can be revoked in device settings. Other requests may be made to the Privacy Officer in Section 11 (in writing, by email, etc.), and we will act without delay. These rights may be exercised through a legal representative or authorized agent.
For California residents (CCPA/CPRA): You have the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale or sharing of personal information. As stated above, we do not sell or share your personal information. We will not discriminate against you for exercising these rights.
For Canadian residents (PIPEDA) and Australian residents (Privacy Act 1988): You have the right to access and correct your personal information and to lodge a complaint with the relevant regulator (see Section 13).
10. Age Restriction
The Service is intended for users aged 13 and older. Use by children under 13 is not permitted. We do not knowingly collect personal information from children under 13, and if such collection is confirmed, we will destroy it without delay. This is consistent with the U.S. Children's Online Privacy Protection Act (COPPA).
11. Privacy Officer
We designate the following Privacy Officer to oversee personal information processing and to handle user inquiries, complaints, and remedies.
- Privacy Officer: Chunghwan Kim (CEO)
- Department: Operations Team
- Contact: privacy@potential-labs.com / +82-10-7940-5395
12. Security Measures
- Administrative: Minimization of personal information processing; restriction of processing authority and access control.
- Technical: Data transmitted externally is protected with encrypted communication (HTTPS/TLS), and backend requests are subject to integrity verification (Firebase App Check / Play Integrity). Most user data, such as alarm and settings data, is stored in on-device storage rather than on Company servers. However, custom message text and generated voice audio for TTS are processed/stored on the Company backend for a maximum of 1 day before automatic deletion.
13. How to Lodge a Complaint
You may contact the following authorities for dispute resolution or consultation regarding privacy:
- United States — Federal Trade Commission (FTC): www.ftc.gov
- Canada — Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca
- Australia — Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au
14. Changes to This Privacy Policy
- This Privacy Policy is effective as of July 28, 2026.
- This policy may be amended in accordance with changes in law, guidelines, or internal Company policy. As the Service has no separate user account (email), changes will be announced through in-app notices and the Google Play Store listing. Changes materially affecting user rights will be announced at least 30 days in advance; other changes at least 7 days in advance.
Inquiries regarding this Privacy Policy: privacy@potential-labs.com
Posted URL: https://respec-time.respec.app/en/privacy/