Privacy Policy
Effective Date: April 1, 2026
fivehours ("Company," "we," "us," or "our") operates E:DA (잇다) ("Service"), a community-based attendance and group management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
| Category | Data Item | Purpose |
|---|---|---|
| Account | Email address | Account identification, duplicate prevention |
| Profile | Name (nickname) | Profile display, mention (@) functionality |
| Profile | Profile image | Profile display |
| Authentication | Social login provider (Google/Apple), Firebase UID | Login authentication, account linking |
1.2 Information Collected Automatically
| Category | Data Item | Purpose |
|---|---|---|
| Device | FCM device token, platform (iOS/Android) | Push notification delivery |
| Analytics | App usage data, crash reports | Service improvement and error detection |
1.3 Information Generated Through Service Use
| Category | Data Item | Description |
|---|---|---|
| Group Activity | Group join/leave records, member roles (owner/admin/member) | Group management and permissions |
| Attendance | Attendance records (present/late/absent/excused), check-in timestamps | Core attendance management feature |
| Events | Event registration/cancellation records | Event participation management |
| Posts | Articles, comments, activity feed cards | Community features |
| Messages | DM text, images, read receipts | Direct messaging feature |
| Workout Logs | Exercise type, sets, reps, weight, etc. | Workout tracking feature |
| Challenges | Challenge participation records, completion status | Challenge feature |
| Quizzes | Quiz response records | Quiz feature |
| Uploaded Images | Images attached to posts, DMs, profiles | Image upload feature |
1.4 Information We Do NOT Collect
- Location data: We do not track GPS or Wi-Fi-based location. Check-in is QR code-based only.
- Contacts: We do not access your device contacts.
- Payment information: We do not collect credit card, bank account, or other payment information.
- Cookies: We do not use web cookies. Firebase authentication tokens are stored in device local storage.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Account Management: To create and manage your account, verify your identity, and prevent fraudulent use.
- Service Delivery: To provide core features including group management, event management, attendance check-in, community boards, direct messaging, workout logs, challenges, quizzes, coach notes, and membership passes.
- Push Notifications: To send attendance reminders, event notifications, DM notifications, and group activity alerts.
- Service Improvement: To analyze usage patterns, improve service quality, and detect and fix errors.
- Communication: To respond to your inquiries and provide customer support.
- Legal Compliance: To comply with applicable laws and regulations.
We do not sell your personal information to third parties.
3. How We Share Your Information
We do not share your personal information with third parties except in the following circumstances:
- With your consent: When you have given explicit permission.
- Service providers: With trusted third parties who assist us in operating the Service (see Section 5).
- Legal requirements: When required by law, legal process, or government request.
- Safety: When necessary to protect the safety, rights, or property of our users or the public.
4. Data Retention and Deletion
| Data Category | Retention Period | Basis |
|---|---|---|
| Account information (email, name, profile image) | Deleted within 30 days of account deletion request | User consent |
| Service usage records (groups, attendance, posts, DMs, etc.) | Deleted within 30 days of account deletion request | User consent |
| FCM device tokens | Deleted immediately upon logout or account deletion | User consent |
| Service access logs | 3 months | Korean Telecommunications Business Act |
| Fraud-related records | 1 year | Fraud prevention |
After requesting account deletion, you have a 30-day grace period during which you may cancel the deletion request. After this period, your data will be permanently deleted.
5. Third-Party Service Providers
We use the following third-party service providers to operate the Service:
| Provider | Services | Data Shared | Location |
|---|---|---|---|
| Google LLC (Firebase) | Authentication (Firebase Auth), Push Notifications (FCM), Analytics | Email, Firebase UID, FCM token, usage data | United States |
| Apple Inc. | Authentication (Apple Sign-In) | Apple account authentication data | United States |
| Amazon Web Services, Inc. | Database hosting (RDS), Image storage (S3), Service hosting (ECS) | All service data | South Korea (Seoul Region) and United States |
| Cloudflare, Inc. | CDN, DNS | Service access data | United States and Global |
6. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our third-party service providers operate. These countries may have data protection laws that are different from your country. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
7. Your Rights
You have the following rights regarding your personal information:
- Access: You may request to view the personal information we hold about you.
- Correction: You may request correction of inaccurate personal information.
- Deletion: You may request deletion of your personal information.
- Restriction: You may request restriction of processing of your personal information.
- Account Deletion: You may delete your account at any time through the app settings.
- Data Portability: You may request your personal information in a structured format.
How to Exercise Your Rights
- In-app: Profile editing (name, profile image) and account deletion can be done directly in the app settings.
- Email: For all other requests, please contact us at [email protected].
- We will respond to your request within 10 business days.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Access Control: Access to personal information is restricted to authorized personnel only and reviewed regularly.
- Encryption: Data is encrypted in transit using TLS/HTTPS. Authentication data is encrypted by Firebase Auth. Database storage is encrypted using AWS RDS encryption.
- Image Security: Uploaded images are protected using AWS S3 server-side encryption.
- Monitoring: We maintain access logs for our data processing systems for a minimum of 1 year.
- Security Updates: Security systems are regularly updated to protect against threats.
9. Children's Privacy
The Service is not intended for children under the age of 14. We do not knowingly collect personal information from children under 14 years of age. During registration, users must confirm that they are 14 years of age or older.
If we become aware that we have collected personal information from a child under 14, we will take immediate steps to delete such information and terminate the associated account.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] so that we can take appropriate action.
10. Automated Data Collection
We do not use web cookies. On mobile devices, Firebase authentication tokens are stored in local device storage solely for maintaining login sessions.
Firebase Analytics may collect device identifiers and app usage data for service analysis purposes. You can opt out of analytics data collection through your device settings.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify affected users without undue delay via email or in-app notification.
- Report the breach to the relevant supervisory authority as required by applicable law.
- Take immediate steps to contain and remediate the breach.
12. Privacy Officer
| Role | Details |
|---|---|
| Title | CEO (Representative) |
| Organization | fivehours |
| [email protected] |
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer at the email address above.
13. Dispute Resolution
If you believe your privacy rights have been violated, you may file a complaint with:
- Personal Information Dispute Mediation Committee (Korea): 1833-6972 / www.kopico.go.kr
- Korea Internet & Security Agency (KISA): 118 / privacy.kisa.or.kr
- Supreme Prosecutors' Office Cybercrime Division: 1301 / www.spo.go.kr
- National Police Agency Cyber Bureau: 182 / ecrm.cyber.go.kr
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Notify users at least 7 days before the changes take effect through in-app announcements.
- For material changes that significantly affect user rights, we will provide at least 30 days advance notice.
- If you do not agree with the updated policy, you may delete your account.
Supplementary Provisions
- Effective Date: This Privacy Policy takes effect on April 1, 2026.
- Previous Version: None (initial version)
- Contact: [email protected]