1. Personal Information We Collect and How We Collect It
The Company collects the following personal information.
a. Required items
- Account: email address, password (stored encrypted), or Apple/Google account identifier
- Nickname (auto-generated, changeable)
- Date of birth (to verify users are at least 14 years old)
- Device identification: push notification token, operating system type
b. Optional items
- Profile photo, short bio
- Location (when attaching weather to a record): latitude and longitude. Relayed through the efilog server for a weather lookup only and never written to our database. To reduce repeated lookups, coordinates rounded to about 1 km (two decimal places) are held in server memory for up to 10 minutes and then discarded. Of the results, the weather condition, temperature, and city name are stored as part of that record.
- Contacts (when sending a Time Letter to someone who has not signed up yet): processed on-device only, never stored on our servers
- Phone verification result (when subscribing to efilog premium): only whether verification succeeded and when it occurred is stored; the phone number itself is not stored.
- Microphone (when attaching a voice recording — premium only): used only at the moment the user explicitly starts a recording. No always-on listening or background use. Recorded data is handled as an attachment under Section 1-c of this policy
c. User-generated content
- Records you write, comments, inspirations, follow relationships, and reports or blocks you create
- Time Letter delivery information: the users you designate as recipients, the users you invite as co-senders, the scheduled arrival time, and the time it was opened
- Attached photos (JPEG): EXIF metadata (GPS, device, capture time) is automatically removed before upload
- Attached videos (MP4) — efilog premium only: compressed on the client (720p) at upload → metadata atoms (udta, meta, ilst) removed on the server and creation/modification timestamps reset to 0. No GPS, device, or capture-time exposure.
- Attached voice recordings (M4A/AAC) — efilog premium only: recorded directly via the microphone (up to 60 seconds each, up to 3 per record). On upload, the server removes the same atom metadata as videos and zeroes timestamps. We perform no analysis of recorded voices (recognition, transcription, speaker identification, voiceprint extraction, etc.), and access is possible only through a private bucket with signed URLs.
d. Automatically generated and collected information
- Service usage records, access logs, error logs (excluding personally identifiable information)
- Push notification delivery and receipt records
e. Payment information (when using efilog premium)
- In-app purchase receipt information from the App Store or Google Play: payment platform, product ID, subscription plan, purchase token, order number, subscription status, and start and expiry times
- Payment credentials such as card or bank account numbers are handled directly by Apple and Google; efilog neither collects nor stores them.
f. Collection methods
- Entered directly by users during sign-up and use of the service
- Collected automatically through the mobile operating system (iOS/Android) and the SDKs bundled with the app (push notifications, location, contacts, photo picking, voice recording, in-app purchases)