Privacy Policy

v2 · 4/2/2026

Privacy Policy

Effective Date: April 1, 2026

fivehours ("Company," "we," "us," or "our") operates E:DA (잇다) ("Service"), a community-based attendance and group management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use the Service.


1. Information We Collect

1.1 Information You Provide

CategoryData ItemPurpose
AccountEmail addressAccount identification, duplicate prevention
ProfileName (nickname)Profile display, mention (@) functionality
ProfileProfile imageProfile display
AuthenticationSocial login provider (Google/Apple), Firebase UIDLogin authentication, account linking

1.2 Information Collected Automatically

CategoryData ItemPurpose
DeviceFCM device token, platform (iOS/Android)Push notification delivery
AnalyticsApp usage data, crash reportsService improvement and error detection

1.3 Information Generated Through Service Use

CategoryData ItemDescription
Group ActivityGroup join/leave records, member roles (owner/admin/member)Group management and permissions
AttendanceAttendance records (present/late/absent/excused), check-in timestampsCore attendance management feature
EventsEvent registration/cancellation recordsEvent participation management
PostsArticles, comments, activity feed cardsCommunity features
MessagesDM text, images, read receiptsDirect messaging feature
Workout LogsExercise type, sets, reps, weight, etc.Workout tracking feature
ChallengesChallenge participation records, completion statusChallenge feature
QuizzesQuiz response recordsQuiz feature
Uploaded ImagesImages attached to posts, DMs, profilesImage upload feature

1.4 Information We Do NOT Collect

  • Location data: We do not track GPS or Wi-Fi-based location. Check-in is QR code-based only.
  • Contacts: We do not access your device contacts.
  • Payment information: We do not collect credit card, bank account, or other payment information.
  • Cookies: We do not use web cookies. Firebase authentication tokens are stored in device local storage.

2. How We Use Your Information

We use the information we collect for the following purposes:

  1. Account Management: To create and manage your account, verify your identity, and prevent fraudulent use.
  2. Service Delivery: To provide core features including group management, event management, attendance check-in, community boards, direct messaging, workout logs, challenges, quizzes, coach notes, and membership passes.
  3. Push Notifications: To send attendance reminders, event notifications, DM notifications, and group activity alerts.
  4. Service Improvement: To analyze usage patterns, improve service quality, and detect and fix errors.
  5. Communication: To respond to your inquiries and provide customer support.
  6. Legal Compliance: To comply with applicable laws and regulations.

We do not sell your personal information to third parties.


3. How We Share Your Information

We do not share your personal information with third parties except in the following circumstances:

  1. With your consent: When you have given explicit permission.
  2. Service providers: With trusted third parties who assist us in operating the Service (see Section 5).
  3. Legal requirements: When required by law, legal process, or government request.
  4. Safety: When necessary to protect the safety, rights, or property of our users or the public.

4. Data Retention and Deletion

Data CategoryRetention PeriodBasis
Account information (email, name, profile image)Deleted within 30 days of account deletion requestUser consent
Service usage records (groups, attendance, posts, DMs, etc.)Deleted within 30 days of account deletion requestUser consent
FCM device tokensDeleted immediately upon logout or account deletionUser consent
Service access logs3 monthsKorean Telecommunications Business Act
Fraud-related records1 yearFraud prevention

After requesting account deletion, you have a 30-day grace period during which you may cancel the deletion request. After this period, your data will be permanently deleted.


5. Third-Party Service Providers

We use the following third-party service providers to operate the Service:

ProviderServicesData SharedLocation
Google LLC (Firebase)Authentication (Firebase Auth), Push Notifications (FCM), AnalyticsEmail, Firebase UID, FCM token, usage dataUnited States
Apple Inc.Authentication (Apple Sign-In)Apple account authentication dataUnited States
Amazon Web Services, Inc.Database hosting (RDS), Image storage (S3), Service hosting (ECS)All service dataSouth Korea (Seoul Region) and United States
Cloudflare, Inc.CDN, DNSService access dataUnited States and Global

6. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our third-party service providers operate. These countries may have data protection laws that are different from your country. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.


7. Your Rights

You have the following rights regarding your personal information:

  1. Access: You may request to view the personal information we hold about you.
  2. Correction: You may request correction of inaccurate personal information.
  3. Deletion: You may request deletion of your personal information.
  4. Restriction: You may request restriction of processing of your personal information.
  5. Account Deletion: You may delete your account at any time through the app settings.
  6. Data Portability: You may request your personal information in a structured format.

How to Exercise Your Rights

  • In-app: Profile editing (name, profile image) and account deletion can be done directly in the app settings.
  • Email: For all other requests, please contact us at [email protected].
  • We will respond to your request within 10 business days.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  1. Access Control: Access to personal information is restricted to authorized personnel only and reviewed regularly.
  2. Encryption: Data is encrypted in transit using TLS/HTTPS. Authentication data is encrypted by Firebase Auth. Database storage is encrypted using AWS RDS encryption.
  3. Image Security: Uploaded images are protected using AWS S3 server-side encryption.
  4. Monitoring: We maintain access logs for our data processing systems for a minimum of 1 year.
  5. Security Updates: Security systems are regularly updated to protect against threats.

9. Children's Privacy

The Service is not intended for children under the age of 14. We do not knowingly collect personal information from children under 14 years of age. During registration, users must confirm that they are 14 years of age or older.

If we become aware that we have collected personal information from a child under 14, we will take immediate steps to delete such information and terminate the associated account.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] so that we can take appropriate action.


10. Automated Data Collection

We do not use web cookies. On mobile devices, Firebase authentication tokens are stored in local device storage solely for maintaining login sessions.

Firebase Analytics may collect device identifiers and app usage data for service analysis purposes. You can opt out of analytics data collection through your device settings.


11. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  1. Notify affected users without undue delay via email or in-app notification.
  2. Report the breach to the relevant supervisory authority as required by applicable law.
  3. Take immediate steps to contain and remediate the breach.

12. Privacy Officer

RoleDetails
TitleCEO (Representative)
Organizationfivehours
Email[email protected]

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer at the email address above.


13. Dispute Resolution

If you believe your privacy rights have been violated, you may file a complaint with:


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will:

  • Notify users at least 7 days before the changes take effect through in-app announcements.
  • For material changes that significantly affect user rights, we will provide at least 30 days advance notice.
  • If you do not agree with the updated policy, you may delete your account.

Supplementary Provisions

  • Effective Date: This Privacy Policy takes effect on April 1, 2026.
  • Previous Version: None (initial version)
  • Contact: [email protected]