English version is below.
이 개인정보처리방침은 Google Play 개발자 ‘DPC Labs’(이하 ‘개발자’)가 제공하는 Android 앱 ‘스탑잇(StopIt)’(패키지 이름 com.uiery.keep, 옛 이름 ‘지키자’, 이하 ‘앱’)에 적용됩니다. 앱에는 회원 가입·로그인 기능이 없으며, 이름·이메일·전화번호 같은 연락처를 받지 않습니다.
앱을 쓰는 동안 아래 서비스가 다음 정보를 자동으로 처리합니다.
Google Analytics for Firebase(앱 이용 통계): 앱 인스턴스 ID, 기기 정보(모델·OS·언어), 앱 버전, 화면·기능 이용 기록, IP 주소로 추정한 대략적 위치(국가·도시)
Firebase Crashlytics(오류 분석): 비정상 종료 기록, 그 시점의 앱 상태·기기 정보, 설치 ID
Firebase 클라우드 메시징·Firebase 설치(알림 전송): Firebase 설치 ID, 앱 버전
Amplitude(앱 이용 통계): Amplitude 기기 ID, 기기·OS 정보, 앱 버전, 정해 둔 일부 기능 이용 기록, 이용 상태(예: 프리미엄 이용 여부), IP 주소로 추정한 국가·도시
차단하려고 고른 앱·웹사이트 목록, 루틴, 잠금 기록, 앱 사용 시간은 기기 안에서만 처리하며 위 서비스로 보내지 않습니다. 통계에는 앱 이름·패키지 이름·사이트 이름을 담지 않습니다. 앱은 광고 ID를 쓰지 않고, 성별·연령 같은 인구통계 정보를 수집하지 않습니다.
스탑잇 프리미엄(월간·연간 구독, 평생 이용권) 결제는 Google Play 결제 시스템이 처리합니다. 카드 번호 같은 결제 수단과 결제 계정 정보는 Google이 받아 관리하며(Google 개인정보처리방침 적용) 개발자는 받지 않습니다.
기기 안: 이용 권한을 확인하려고 Google Play에 구매 상태를 묻고, 구매 상태·종류(월간·연간·평생)와 관련 시각처럼 이용 권한 판단에 필요한 값만 기기에 저장합니다. 주문 번호·구매 토큰·가격은 저장하지 않으며, 이 값은 기기 백업과 기기 이전에 포함되지 않습니다.
통계: 결제 화면을 개선하려고 Firebase 애널리틱스와 Amplitude에 프리미엄 이용 여부와 결제 단계 기록(결제 화면을 연 곳, 고른 요금제 종류, 무료 체험·할인 적용 여부, 결제 실패 사유)을 보냅니다. 주문 번호·구매 토큰·결제 수단은 보내지 않습니다. Google Play로 결제가 끝나면 Firebase 애널리틱스가 결제 완료 기록(상품 ID, 가격, 통화 등)을 자동으로 남길 수 있습니다.
구독 해지와 환불은 Google Play에서 할 수 있으며 Google Play 정책과 관계 법령을 따릅니다.
웹사이트 차단은 Android VpnService로 만든 기기 안 VPN으로 동작합니다. 잠금 중에만 켜지고, 사용자가 고른 사이트의 주소(DNS) 조회만 막으며 나머지 조회는 그대로 통과시킵니다. 원격 VPN 서버에 연결하지 않고, 방문 기록·DNS 조회 내용·막힌 사이트 이름을 개발자나 제3자에게 보내지 않으며, 다른 앱의 통신을 가로채거나 수익화에 쓰지 않습니다.
잠금 기록에 고른 사이트가 날마다 몇 번 막혔는지 보여 드리려고, 사이트별 하루 차단 횟수를 기기 안에만 30일 동안 저장한 뒤 자동으로 지웁니다. 이 기록은 기기 백업과 기기 이전에 포함되지 않습니다.
하루 한 번 Firebase 애널리틱스로 그날의 요약만 보냅니다. 차단 횟수 구간(1~5회·6~20회·21회 이상), 차단된 사이트 수 구간(1곳·2~3곳·4곳 이상), 잠금 종류(타이머·루틴·둘 다)뿐이며, 사이트 이름·주소·정확한 횟수·시각은 담지 않습니다. Amplitude로는 보내지 않습니다.
루틴에 넣어 둔 웹사이트 목록은 다른 루틴 정보와 함께 Android 앱 데이터 백업(사용자 본인의 Google 계정)에 포함될 수 있습니다.
앱이 기기 안에 저장하는 정보(차단할 앱·웹사이트 목록, 루틴, 잠금 기록, 앱 사용 시간, 구매 상태 등)는 앱을 삭제하거나 앱 데이터를 지우면 함께 삭제됩니다. 사이트별 하루 차단 횟수는 그 전이라도 30일이 지나면 자동으로 지워집니다.
Android 백업이 켜져 있으면 루틴·잠금 기록 같은 앱 데이터가 사용자 본인의 Google 계정 백업에 포함될 수 있으며, 이 백업은 Google 계정의 백업 설정에서 관리할 수 있습니다. 막은 웹사이트 기록과 구매 상태는 백업에 포함되지 않습니다.
Google과 Amplitude가 처리하는 정보의 보유 기간은 제5조에 적었습니다.
개발자는 개인정보를 제3자에게 제공하지 않습니다. 앱 운영을 위해 아래 업체에 처리를 맡기며, 업체의 서버가 국외에 있어 정보가 국외로 이전됩니다.
① Google LLC(미국 등 Google 데이터 센터, 문의: https://policies.google.com/privacy)
항목: 앱 인스턴스 ID·Firebase 설치 ID, 기기 정보, 앱 이용 기록, 프리미엄 이용 여부·결제 단계 기록·결제 완료 기록, 웹사이트 차단 하루 요약, 대략적 위치, 비정상 종료 기록
목적: 이용 통계, 오류 분석, 알림 전송
보유: 애널리틱스 이벤트 단위 데이터 2개월(사용자 단위 데이터 14개월), Crashlytics 90일, Firebase 설치 ID는 삭제 요청 뒤 180일 이내 삭제
② Amplitude, Inc.(미국, 문의: privacy@amplitude.com)
항목: Amplitude 기기 ID, 기기 정보, 일부 기능 이용 기록, 프리미엄 이용 여부·결제 기록, IP로 추정한 국가·도시
목적: 이용 통계
보유: 이용 통계 목적을 달성하거나 삭제를 요청하면 지체 없이 삭제
이전 시기와 방법: 앱을 쓰는 동안 수시로 암호화 통신(HTTPS)으로 전송합니다.
거부 방법과 효과: 통계·오류 전송만 따로 끄는 설정은 없습니다. 원하지 않으면 앱을 삭제해 이후 전송을 멈출 수 있고, 이 경우 앱을 쓸 수 없습니다. 이미 보낸 정보의 삭제는 제9조의 이메일로 요청해 주세요.
정보주체는 개발자에 대해 언제든지 다음 개인정보 보호 관련 권리를 행사할 수 있습니다.
개인정보 열람 요구
오류 등이 있을 경우 정정 요구
삭제 요구
처리 정지 요구
권리 행사는 제9조의 이메일로 요청할 수 있으며, 법정대리인이나 위임을 받은 대리인을 통해서도 할 수 있습니다. 개발자는 요청에 지체 없이 답변하고 처리합니다.
개발자는 원칙적으로 개인정보 처리 목적이 달성되면 지체 없이 해당 개인정보를 파기합니다. 파기의 절차와 기한은 다음과 같습니다.
앱: 기기 안에 저장된 정보는 앱을 삭제하거나 앱 데이터를 지우면 기기에서 삭제되며, 사이트별 하루 차단 횟수는 30일이 지나면 자동으로 지워집니다.
Google(Firebase)·Amplitude: 제5조의 보유 기간이 끝나거나 삭제를 요청하면 각 업체의 정책에 따라 삭제됩니다(Google: https://policies.google.com/technologies/retention?hl=ko).
앱: 이용자의 개인정보가 불필요하게 되었을 때에는 개인정보의 처리가 불필요한 것으로 인정되는 날 즉시 파기합니다.
Google(Firebase)·Amplitude: 제5조의 보유 기간에 따릅니다.
앱은 쿠키를 쓰지 않습니다. 제1조의 서비스가 앱 인스턴스 ID·Firebase 설치 ID·Amplitude 기기 ID를 자동으로 만들어 쓰며, 앱 데이터를 지우거나 앱을 다시 설치하면 새로 만들어집니다. 스탑잇 1.9.9 이상은 광고를 표시하지 않고 광고 ID를 쓰지 않습니다. 1.9.8 이하에는 Google AdMob 광고가 있었고, 그 버전을 계속 쓰면 AdMob이 광고를 위해 광고 ID 등을 처리할 수 있습니다(https://policies.google.com/privacy). 최신 버전으로 업데이트하면 멈춥니다.
개발자는 개인정보 처리에 관한 업무를 총괄해서 책임지고, 개인정보 처리와 관련한 정보주체의 불만 처리와 피해 구제를 위해 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.
개인정보 보호책임자: 박의엘 (DPC Labs 대표)
이메일: parkuiery@gmail.com
정보주체는 앱을 이용하면서 생긴 개인정보 보호 관련 문의, 불만 처리, 피해 구제 등을 위 이메일로 문의할 수 있으며, 개발자는 지체 없이 답변하고 처리합니다.
그 밖에 개인정보 침해에 대한 신고나 상담이 필요하면 아래 기관에 문의할 수 있습니다.
개인정보분쟁조정위원회: www.kopico.go.kr / 1833-6972
개인정보침해신고센터: privacy.kisa.or.kr / 국번 없이 118
대검찰청: www.spo.go.kr / 국번 없이 1301
경찰청 사이버범죄 신고시스템: ecrm.police.go.kr / 국번 없이 182
앱은 자체 서버를 두지 않고 계정·비밀번호를 받지 않습니다. 기기 밖으로 보내는 정보는 모두 암호화 통신(HTTPS)으로 전송하고, 분석 도구의 관리 화면은 개발자 계정으로만 접근합니다.
이 방침은 2026년 10월 8일부터 적용됩니다. 방침이 바뀌면 바뀐 내용과 시행일을 이 페이지에 알립니다.
This Privacy Policy applies to the Android app “StopIt” (스탑잇; package name com.uiery.keep; formerly “지키자”) provided by the Google Play developer “DPC Labs” (“we”). The app has no sign-up or login and does not ask for your name, email address or phone number.
While you use the app, the following services process this information automatically:
Google Analytics for Firebase (usage statistics): app instance ID, device information (model, OS, language), app version, screen and feature usage events, and approximate location (country, city) inferred from your IP address.
Firebase Crashlytics (crash analysis): crash reports, app state and device information at the time of the crash, and an installation ID.
Firebase Cloud Messaging and Firebase Installations (notifications): Firebase installation ID and app version.
Amplitude (usage statistics): Amplitude device ID, device and OS information, app version, a limited set of feature-usage events, your plan status (for example, whether Premium is active), and country/city inferred from your IP address.
The apps and websites you choose to block, your routines, lock history and app usage time are processed only on your device and are not sent to these services. Statistics never include app names, package names or site names. The app does not use the advertising ID and does not collect demographic information such as gender or age.
Payments for StopIt Premium (monthly and yearly subscriptions, lifetime purchase) are processed by Google Play's billing system. Your payment method (such as card numbers) and payment account details are collected and managed by Google under Google's Privacy Policy; we never receive them.
On your device: to check your access, the app asks Google Play for your purchase status and stores on your device only what it needs to decide access, such as the status, the type (monthly, yearly, lifetime) and related times. It does not store order numbers, purchase tokens or prices, and these values are excluded from device backups and transfers.
Statistics: to improve the purchase screen, the app sends Firebase Analytics and Amplitude whether Premium is active and purchase-step events (where the purchase screen was opened, which plan type was chosen, whether a free trial or discount applied, and why a payment failed). Order numbers, purchase tokens and payment methods are not sent. When a purchase completes through Google Play, Firebase Analytics may automatically record a purchase event (product ID, price, currency, etc.).
You can cancel subscriptions and request refunds through Google Play; Google Play policies and applicable law apply.
Website blocking works through an on-device VPN built with Android's VpnService. It runs only while a lock is active, blocks DNS lookups only for the sites you chose, and lets every other lookup pass unchanged. It never connects to a remote VPN server, never sends your browsing history, DNS queries or the names of blocked sites to us or any third party, and never intercepts or monetizes traffic from other apps.
To show in your lock history how many times each of your chosen sites was blocked each day, the app keeps per-site daily counts on your device only, for 30 days, then deletes them automatically. This record is excluded from device backups and transfers.
Once a day the app sends Firebase Analytics a summary only: a range of blocked attempts (1–5, 6–20, 21+), a range of blocked sites (1, 2–3, 4+) and the lock type (timer, routine, or both). It contains no site names, addresses, exact counts or times, and is not sent to Amplitude.
Website lists you save in routines may be included, together with other routine data, in Android's app-data backup to your own Google Account.
Information the app stores on your device (the apps and websites you block, routines, lock history, app usage time, purchase status, etc.) is deleted when you uninstall the app or clear its data. Per-site daily block counts are deleted automatically after 30 days, even before that.
If Android backup is on, app data such as routines and lock history may be included in the backup in your own Google Account, which you can manage in your Google Account's backup settings. Website blocking records and purchase status are not included in backups.
Retention periods for information processed by Google and Amplitude are listed in section 5.
We do not provide your personal information to third parties. We use the following processors to run the app. Their servers are outside Korea, so information is transferred abroad:
① Google LLC (USA and other Google data centers; contact: https://policies.google.com/privacy)
Items: app instance ID and Firebase installation ID, device information, app usage events, Premium status, purchase-step and purchase-completion events, the daily website-blocking summary, approximate location, crash reports.
Purpose: usage statistics, crash analysis, notifications.
Retention: Analytics event-level data 2 months (user-level data 14 months); Crashlytics 90 days; Firebase installation IDs deleted within 180 days of a deletion request.
② Amplitude, Inc. (USA; contact: privacy@amplitude.com)
Items: Amplitude device ID, device information, a limited set of feature-usage events, Premium status and purchase events, country/city inferred from IP.
Purpose: usage statistics.
Retention: deleted without delay once the usage-statistics purpose is achieved or when you ask us to delete it.
When and how: sent from time to time while you use the app, over encrypted connections (HTTPS).
How to refuse and what happens: there is no separate switch for statistics and crash reporting. Uninstalling the app stops further transfers, and you will not be able to use the app. To delete information already sent, email us at the address in section 9.
You may at any time ask us to give you access to, correct, delete, or stop processing your personal information. Send requests to the email in section 9; you may also make them through a legal representative or someone you have authorized. We respond and act on requests without delay.
We delete personal information without delay once the purpose of processing has been achieved.
In the app: information stored on your device is deleted from the device when you uninstall the app or clear its data; per-site daily block counts are deleted automatically after 30 days.
Google (Firebase) and Amplitude: deleted when the retention periods in section 5 end or when you ask us to delete it, under each provider's policies (Google: https://policies.google.com/technologies/retention).
The app does not use cookies. The services in section 1 create and use an app instance ID, a Firebase installation ID and an Amplitude device ID; clearing the app's data or reinstalling creates new ones. StopIt 1.9.9 and later shows no ads and does not use the advertising ID. Versions 1.9.8 and earlier included Google AdMob ads; if you keep using such a version, AdMob may process the advertising ID and other data for ads (https://policies.google.com/privacy). Updating to the latest version stops this.
DPC Labs is responsible for how personal information is handled in the app and for privacy complaints and remedies.
Privacy officer: Park Uiel (Representative, DPC Labs)
Email: parkuiery@gmail.com
Send any privacy question, complaint or request for remedy about the app to this email; we respond and act without delay.
If you are in Korea, you can also contact:
Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
Personal Information Infringement Report Center (KISA): privacy.kisa.or.kr / 118
Supreme Prosecutors' Office: www.spo.go.kr / 1301
Korean National Police Agency Cyber Crime Reporting System: ecrm.police.go.kr / 182
The app runs no servers of its own and collects no accounts or passwords. Everything sent off the device travels over encrypted connections (HTTPS), and access to the analytics consoles is limited to the developer's accounts.
This policy is effective from October 8, 2026. If it changes, we will post the changes and the new effective date on this page.