snap.log Privacy Policy

Effective date: 27 July 2026 · 한국어

avarlabs Co., Ltd. ("the Company") complies with the Personal Information Protection Act, the Act on the Protection and Use of Location Information and other applicable laws of the Republic of Korea, and establishes and discloses this privacy policy in order to protect users' personal information and to handle related concerns promptly and smoothly.

This policy applies to the mobile application snap.log (스냅로그) provided by the Company (the "Service").

This is an English translation provided for convenience. In case of any discrepancy, the Korean version prevails.

Read this first. snap.log is a personal journaling app. Photos, videos and audio stay on your device by default; the only things that go to a server are the features you turn on yourself (Backup & sync, AI recall and Pinpoint are all off by default). This policy states specifically what goes where when each feature is turned on.

Article 1 (Purposes of processing personal information)

The Company processes personal information for the purposes below. It is not used for any purpose other than these, and if a purpose changes the Company will take the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.

  1. Identifying and managing users
    Identifying and authenticating users through an anonymous session or social sign-in (Google/Apple), syncing records across devices, and preventing abuse of the Service
  2. Providing the journaling service
    Storing and retrieving the records you create (notes, photos, videos, audio, location) and presenting them as a timeline, album, calendar and map
  3. Providing optional features
    Cloud backup and sync, AI recall (natural-language question answering) and automatic place logging (Pinpoint) — each only if you turn it on in Settings
  4. Managing subscriptions and payments
    Verifying purchases, restores and renewals of paid plans, and eligibility for the free trial
  5. Improving the Service and keeping it stable
    Usage statistics, analysis and resolution of errors and failures, and development of new features
  6. Serving advertising
    Showing ads to users on the free tier (no ads are shown to users on a paid plan)

Article 2 (Categories of personal information processed)

1. Account information

TypeCollected
RequiredUser identifier (UID) — generated automatically and anonymously on first launch; no sign-up is required
OptionalOn social sign-in: email address, social account identifier

If you choose Hide My Email with Sign in with Apple, an anonymised relay address is provided instead. We do not collect your name, profile picture or phone number.

2. Information you create yourself

3. Location information

4. Information kept on the device and never sent to a server

5. Information generated or collected automatically

Article 3 (Where information is stored and how far it travels)

Because of how the Service is built, where a given piece of information is stored depends on your settings. The following table is the whole of it.

InformationStored inCondition
Record body (note, tags, time, location, address)Google Cloud FirestoreAlways
Named placesGoogle Cloud FirestoreAlways
Original photosCloudflare R2 (cdn.avarlabs.com)Only if Backup & sync is on
Original videosNever transmitted
Video poster image (thumbnail)Cloudflare R2If Backup & sync is on
720p compressed videoCloudflare R2Paid plan + "Video backup" turned on
Audio track of videosCloudflare R2Only if AI recall is on (input for speech recognition)
Voice memosCloudflare R2If Backup & sync is on
AI recall conversationsCloudflare D1If AI recall is on
Semantic search vectors for recordsCloudflare VectorizeIf AI recall is on
App settingsDevice storageNever sent to a server

Original video files are never transmitted to a server under any circumstances. Even with video backup on, only a re-encoded 720p copy is uploaded; the original stays on your device (and in your photo library).

Article 4 (The AI recall feature)

"AI recall" generates answers to natural-language questions about your own records. It is off by default and only works if you turn it on in Settings. The app asks for your consent, naming the recipient and the categories of data, before anything is sent. When it is on, the following happens.

Turning AI recall off stops indexing and requests deletion of the vectors already created. Audio-track files that have already been uploaded are not deleted automatically, so if you want them removed please ask using the contact details in Article 12.

Article 5 (Entrustment of personal information processing)

To provide the Service, the Company entrusts the processing of personal information as follows.

ProcessorEntrusted workCategories processed
Google LLC (Firebase)Authentication, record database, usage analytics, serverless processingUID, email, record body, location, usage events
Cloudflare, Inc.Media file storage and delivery, AI recall backend, conversation and search-index storagePhotos, video derivatives, audio, conversations, record vectors
OpenAI, L.L.C.AI recall answer generation, image tag generation, speech transcriptionQuestions, related record content, images, audio
RevenueCat, Inc.Subscription state management and purchase validationUID, purchase history
Functional Software, Inc. (Sentry)Error and crash collection and analysisUID, email, error information, device and app version
Google LLC (AdMob)Advertising (free tier only)Advertising identifier, device information
Apple Inc. / Google LLCSocial sign-in authentication, in-app purchasesSocial account identifier, email, payment information

When entering into an entrustment agreement the Company stipulates the measures necessary for personal information to be managed safely — including that the processor affords protection equal to or greater than that described in this policy — and will disclose any change of processor through this policy.

Article 6 (Transfer of personal information overseas)

Most of the processors in Article 5 are located outside the Republic of Korea, so using the Service involves transferring personal information abroad.

You may refuse the overseas transfer of your personal information, but some or all of the Service may then be unavailable to you. If you leave Backup & sync, AI recall and Pinpoint turned off, the range of information transferred abroad is greatly reduced.

Article 7 (Retention period and destruction)

  1. The Company retains personal information for as long as you use the Service and destroys it without delay when you close your account.
  2. Where retention is required by law, the information is kept for that period. (Act on Consumer Protection in Electronic Commerce: contract and withdrawal records 5 years, payment records 5 years, consumer complaint and dispute records 3 years.)
  3. When you delete an individual record in the app, that record and the files linked to it are deleted.
  4. Method of destruction: personal information stored electronically is permanently deleted so that it cannot be restored.

Article 8 (Your rights and how to exercise them)

  1. You may at any time request access to, correction of, deletion of, or suspension of the processing of your personal information.
  2. Rights you can exercise directly in the app: viewing, editing and deleting records; turning off Backup & sync, AI recall and Pinpoint; signing out.
  3. Other requests may be made by email using the contact details in Article 12, and the Company will act on them without delay.
  4. To have your account and data deleted, please follow the account and data deletion request instructions. The same page is linked from Settings > Account in the app.
  5. You may withdraw location, photo-library, notification and other permissions in your operating system settings at any time. The corresponding feature then stops working, but records already saved are kept.

Article 9 (Measures to secure personal information)

Ads are shown to users on the free tier, and the advertising identifier may be used in the process. You can reset the advertising identifier or limit personalised advertising in your operating system settings.

No ads are shown on a paid plan.

Article 11 (Children under 14)

The Service is not directed at children under the age of 14, and the Company does not knowingly collect personal information from children under 14. If the Company becomes aware that it has collected such information, it will destroy it without delay.

Article 12 (Privacy officer and contact)

The Company has overall responsibility for personal information processing and has designated a privacy officer as below to handle user complaints and remedy damage relating to that processing.

If you need to report or consult about an infringement of your personal information, you may contact the following bodies in the Republic of Korea.

Article 13 (Changes to this policy)

This policy applies from its effective date. If its contents are added to, removed or amended because of changes in law, policy or the Service, the changes will be announced in the app or on this page at least 7 days before they take effect — or 30 days before, if they materially change users' rights.