Minseok Song / KEYPLE (the developer) provides HaruStar, a personal daily-review app. This policy explains the app's data handling, optional services and your choices. It applies to the app, not to separate website traffic processing. As of October 5, 2026, the app and Pro sales are being prepared; feature and purchase availability depend on the installed version.
1. Local records and selected photos
Dates, daily ratings, review text, selected photos, detailed rating categories, tags, drafts and preferences are stored on your device for recording and reviewing your days. Basic recording does not require app registration or Google sign-in. The developer does not operate a server that receives these records, provide a public feed, perform AI analysis or embed advertising or behavioral analytics SDKs in the current app. Purchase administration is described separately in section 7.
Photos are accessed when you choose them through the device's photo picker, and app-managed copies are saved. Original photo files may retain embedded metadata. Permissions can be managed in device settings. Operating-system or account-level device backups may separately include app data according to your settings.
2. Optional Google connection
Google connection is optional. Sign-in and permission prompts begin when you choose to connect. The Google Sign-In SDK manages authentication credentials; the app uses the connected account's identifier and email to show and verify the account and detect an account change during backup or restore. Basic sign-in permissions include openid, userinfo.email and userinfo.profile. The app does not analyze your Google profile or send Google account details to RevenueCat.
Drive access uses the per-file scope drive.file to create and manage the app's backup files, not a permission to read your entire Drive. File identifiers, creation times, sizes, checksums and backup metadata are used to list, verify, restore and maintain app backups. Credentials are managed by Google's SDK, not placed in exported records or sent to a developer backup server.
The app's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google account information and backup contents are not sold, used for advertising, shared with data brokers or used to train AI models.
3. Manual Google Drive backups
When you start a backup, the app transfers saved records directly from your device to your own Google Drive, in the HaruStar Backups folder. This is a manual backup, not automatic synchronization or a background transfer that resumes after the app closes. Backup creation requires Pro; account connection, Drive restoration and backup-history deletion are available without Pro.
- New backups consist of review JSON, shared photo files when selected, and a final manifest describing the backup. They are not new ZIP archives.
- You can choose whether to include photos. Saved reviews, ratings, detailed rating categories and tags are included. Drafts, reminder and theme preferences, purchase status and authentication credentials are excluded.
- Matching verified photos may be reused across backups to reduce repeated uploads. The final manifest is uploaded and verified last, before the backup is marked complete.
- Old Drive ZIP backups are supported for restoration compatibility only. The current app does not offer manual ZIP file export or import.
These files have no additional app password or app-level encryption. HTTPS protects Google requests in transit, but this is not an end-to-end-encrypted vault. Protect your device and Google account, and do not share backup folders or files unintentionally. Drive storage and quota belong to your Google account; there is no separate developer backup server.
4. Backup retention and restoration
After a new backup is verified, the app attempts to keep the latest two verified backups and moves older app backups to Google Drive Trash, rather than permanently deleting them. Cleanup failures, unsupported or damaged backups and concurrent work can leave more copies. Unreferenced shared photo or record files are eligible for cleanup only after surviving manifests have been checked and the files are at least 24 hours old; failed manifest checks stop that cleanup.
Deleting an entry in backup history moves the selected backup to Trash. Shared photos may remain while other backups reference them; unreferenced shared-file cleanup is performed during a later successful backup. Google Drive controls Trash retention and final deletion.
Restoration verifies the backup before replacing saved records. Restoring a backup made without photos replaces saved records with records without those photos; existing drafts are preserved. A backup is independent of later local edits, deletion or app removal. Manage unwanted older copies separately in Drive and its Trash.
5. Excel export and sharing
Pro can generate an XLSX file on your device for all records or a selected period. It can include daily reviews, ratings, tags, photo counts and timestamps, with optional detailed ratings and weekly, monthly and yearly summaries. Photo files and drafts are excluded. XLSX is an analysis export, not a restorable backup.
Export does not introduce an additional network service or Google permission. You choose the destination in the operating-system share sheet; the receiving app or storage provider then handles the shared file under its own settings and policies. Creating a file does not confirm that an external destination has saved it. App-generated temporary export files are cleaned up after sharing or on later cleanup; system and receiving-app copies must be managed separately.
6. Reminders and widgets
If enabled, reminders are scheduled locally through the operating system. Depending on your device and app version, notifications and widgets may display ratings, record status or record text and permit local input. There is no developer push server receiving that content. People who can see your lock screen or home screen may see it. Manage reminder permissions, notification previews and widgets through app and device settings.
7. Pro purchases and RevenueCat
Pro is intended as a one-time, non-renewing lifetime purchase. Actual store products and sales are not yet ready as of this policy's effective date; this document does not announce a price or an available purchase.
In builds configured to use RevenueCat, the SDK may initialize and check purchase entitlements when the app starts, even before a purchase. Apple App Store or Google Play handles payment; RevenueCat handles receipt validation, purchase reporting, restoration and Pro entitlements. Relevant data may include an anonymous app customer identifier, product and transaction identifiers, purchase history and entitlement status, and app, SDK, operating-system and store information required for those operations. Providers also process network information under their policies. Additional automatic device-identifier collection is disabled in the app configuration; this does not eliminate the anonymous purchase identifier or normal service requests.
The app does not send Google account details, review text, photos, ratings, tags or drafts to RevenueCat. The developer does not receive your payment-card number. Store and provider purchase records follow their policies and applicable legal retention requirements; cancellation and refund requests use the original store's procedures.
8. Providers and support inquiries
Google provides optional sign-in and Drive storage; Apple and Google provide store payment services when available; RevenueCat provides configured purchase and entitlement management. These providers may process data on infrastructure outside your country under their policies. Optional backup files are sent to Google only when you start a backup, while configured purchase checks are described in section 7. Provider policies and contacts are linked below.
If you email support, your email address and the information you choose to send are used to answer the request and handle necessary follow-up. They are retained only while needed for those purposes or applicable legal obligations, then deleted. Do not send private reviews or photos, passwords, access tokens or complete purchase receipts. Redact personal information from screenshots.
9. Security and your controls
The app uses operating-system app storage, SDK credential management, limited Google permissions and HTTPS for Google requests. No security measure guarantees absolute protection. The developer cannot remotely access or recover device-only records or browse your private Drive backups.
- View, edit or delete records and manage selected photos in the app. A photo may remain while another record or draft still references it.
- Manage permissions, reminders, widgets and app storage through app and device settings. Removing local data does not remove previously shared files or cloud backups.
- Disconnect signs out of Google on this device; it does not delete Drive files or revoke every Google permission.
- Revoke access through Google account connections. Revocation also does not delete existing backups.
- Manage Drive files, Trash, exported XLSX copies and operating-system backups at their respective storage locations.
You can decline Google connection and continue basic local recording. The current app does not provide a replacement manual ZIP export/import flow.
10. Privacy requests and policy updates
For access, correction, deletion or restriction requests concerning information handled by the developer, contact Minseok Song / KEYPLE at keyplest@gmail.com. A legal representative may also contact us. We may ask for the minimum information needed to verify and fulfil the request. For device-only records and your own Drive files, use the app, device and Google controls because the developer cannot delete them remotely.
Material changes to data handling will be described in an updated policy with an effective date. Additional Google data uses require appropriate disclosure and consent before access. Visiting the website is separately covered by the KEYPLE website Privacy Policy.