1총칙 및 제로 날리지(Zero-Knowledge) 암호화 원칙
StrayKitty Studio(이하 "회사")는 개인정보 보호법, 정보통신망 이용촉진 및 정보보호 등에 관한 법률 등 관련 법령을 철저히 준수합니다.
NaMemo는 사용자의 메모 원문을 기기를 떠나기 전 로컬 기기 내에서 AES-256-GCM 알고리즘으로 직접 암호화합니다. 암호화 키는 사용자 기기의 보안 영역(TPM, Windows Hello, Touch ID, Face ID)에만 존재하며, 회사 서버나 데이터베이스에는 어떠한 복호화 키도 저장되지 않습니다. 따라서 개발사나 서버 관리자를 포함한 제3자는 사용자의 메모를 기술적으로 열람하거나 복호화할 수 없습니다.
2수집하는 개인정보 항목
| 구분 | 수집 항목 | 수집 목적 |
|---|---|---|
| 계정 연동 | Google OAuth ID, 이메일 주소, 프로필 이름 | 동기화 세션 유지 및 Pro 라이선스 검증 |
| 동기화 메타데이터 | 디바이스 UUID, OS 종류(Windows, Android, iOS, macOS), 앱 버전 | 기기 간 데이터 라우팅 및 동기화 충돌 방지 |
| 인앱 결제 정보 | 스토어 구매 토큰, 구독 상품 ID, 구독 만료일시, Pro 활성화 여부 | Google Play / Apple App Store 인앱결제 상태 확인 |
| 메모 데이터 | 암호화된 바이너리 암호문(Base64) 및 Nonce | 암호문 상태로만 저장 (원문 복호화 불가) |
| 생체/금융 정보 (미수집) | 지문, Face ID, 신용카드 번호 등 | 일절 수집하지 않음 (OS 및 앱스토어가 자체 처리) |
3개인정보의 처리 목적
기기 간 암호화 동기화 제공, Google 로그인을 통한 사용자 식별 및 PC Pro 라이선스 부여, 서비스 품질 유지 및 오류 제보 대응에 한하여 처리합니다.
4개인정보의 보유 및 이용 기간
원칙적으로 서비스 이용 기간 동안 보유하며, 계정 삭제 요청 시 지체 없이 파기합니다. 법령상 보존 의무가 있는 기록은 관련 법정 기간 동안 분리 보관합니다.
5개인정보의 파기 절차 및 방법
데이터베이스 내 사용자의 레코드 및 암호문을 즉시 완전 삭제하여 재생할 수 없도록 영구 파기합니다.
6제3자 제공 및 개인정보 처리 위탁
Supabase Inc.(AWS 기반 암호문 호스팅), Google LLC(OAuth 및 Google Play 결제), Apple Inc.(App Store 결제)에 인프라 업무를 위탁합니다.
7이용자의 권리와 행사 방법
이용자는 앱 내 설정에서 언제든지 Google 동기화 연결 해제 및 데이터 파기를 요청할 수 있습니다.
8기술적·관리적 보호 대책
AES-256-GCM 암호화, 메모리 상주 키 제로화(Zero-out), TLS 1.3 암호화 통신, OS 네이티브 생체인증 잠금을 적용합니다.
9암호화 키 분실 및 복구 불가에 대한 면책 (필독)
회사는 복호화 키나 비밀번호를 서버에 저장하지 않습니다. 이용자가 기기 고장/분실 또는 1회 발급된 '복구 키(Recovery Key)'를 분실한 경우, 회사는 이를 복구할 기술적 수단이 전무하며 이로 인한 데이터 유실에 대해 일체의 책임을 지지 않습니다. 사법기관의 영장 제출 명령이 있더라도 평문 원문 제공이 기술적으로 불가합니다.
10개인정보 보호책임자 및 문의처
문의 이메일: contact@straykittystudio.com | 공식 웹사이트: straykittystudio.com
부칙: 본 방침은 2026년 9월 11일부터 시행됩니다.
1Overview & Zero-Knowledge Architecture
StrayKitty Studio ("Company") is committed to protecting your privacy. NaMemo is architected around a strict Zero-Knowledge End-to-End Encryption model (AES-256-GCM).
All note content, titles, and tags are encrypted on your local device before transmission. Decryption keys are stored strictly in your device's hardware enclave (Windows Hello, TPM, Touch ID, Face ID). The Company has no technical capability to view, decrypt, or disclose your plaintext notes.
2Personal Information Collected
| Category | Data Collected | Purpose |
|---|---|---|
| Account Auth | Google OAuth ID, Email, Profile Name | Authentication & Pro license verification |
| Sync Metadata | Device UUID, OS type, App version | Routing & sync conflict resolution |
| In-App Purchase | Store purchase token, product ID, expiry date | Google Play / Apple App Store verification |
| Note Content | Encrypted binary ciphertext (Base64) & Nonce | Stored strictly in ciphertext (Indecipherable by Company) |
| Biometrics & Billing | Fingerprint, Face ID, Credit Card numbers | Never collected (handled entirely by OS & App Stores) |
3Purpose of Processing
Collected information is used exclusively to facilitate multi-device encrypted sync, authenticate Pro subscriptions via Google Sign-In, and provide technical customer support.
4Retention & Storage Period
Account and sync metadata are retained only while your account is active. Upon account deletion, all associated ciphertext and records are permanently removed, subject only to mandatory legal retention periods.
5Data Destruction Procedures
When data reaches its retention threshold or upon user request, database records and encrypted objects are irrevocably purged through unrecoverable cryptographic deletion.
6Third-Party Infrastructure
We utilize trusted global cloud providers: Supabase Inc. (AWS-based ciphertext database hosting), Google LLC (OAuth & Google Play Billing), and Apple Inc. (App Store In-App Purchases).
7User Rights & Control
Users may disconnect Google Sync, export local data, or delete all remote data at any time via the NaMemo application settings.
8Technical & Administrative Safeguards
We employ military-grade AES-256-GCM encryption, TLS 1.3 in-transit encryption, volatile memory zeroing (RAM wipe on lock), and hardware biometric protection.
9Key Loss Disclaimer & Operator Indemnification (MUST READ)
The Company does not store master keys or user passwords. If you lose access to your device, delete biometric authentication, or lose your one-time Recovery Key, the Company possesses zero technical ability to restore or decrypt your notes. Under no circumstances will StrayKitty Studio be held liable for any data loss, damages, or claims resulting from lost cryptographic keys.
10Privacy Officer & Contact Information
Email: contact@straykittystudio.com | Website: straykittystudio.com
Addendum: Effective as of September 11, 2026.
1総則およびゼロナレッジ(Zero-Knowledge)暗号化原則
StrayKitty Studio(以下「当社」)は利用者のプライバシーを厳格に保護します。NaMemoはゼロナレッジ・エンドツーエンド暗号化(AES-256-GCM)を基本構造として設計されています。
メモの本文・タイトル・タグは端末外へ送信される前に、利用者の端末内部でAES-256-GCMにより直接暗号化されます。復号キーは端末の安全領域(Windows Hello、Touch ID等)にのみ保持され、当社サーバーには一切保存されません。開発者を含め第三者がメモを閲覧・復号することは技術的に不可能です。
2収集する個人情報の項目
| 区分 | 収集項目 | 利用目的 |
|---|---|---|
| アカウント認証 | Google OAuth ID、メールアドレス、氏名 | 認証およびPC Proライセンス検証 |
| 同期メタデータ | デバイスUUID、OS種類、アプリバージョン | 同期競合の防止およびルーティング |
| アプリ内決済情報 | ストア購入トークン、商品ID、有効期限 | Google Play / App Store決済照合 |
| メモデータ | 暗号化されたバイナリ暗号文(Base64)・Nonce | 暗号文としてのみ保管(当社復号不可) |
| 生体・金融情報 | 指紋、Face ID、クレジットカード番号等 | 一切収集しません(OS及びストアが直接処理) |
3個人情報の利用目的
端末間暗号化同期の提供、Googleアカウントによる認証およびPC Proライセンスの適用、ならびにお問い合わせ対応にのみ利用します。
4個人情報の保有および利用期間
原則としてサービス利用期間中に限り保有し、退会またはアカウント削除要請があった場合は遅滞なく破棄します。
5データの破棄手順および方法
データベース内のユーザーレコードおよび暗号化データを完全に消去し、再生不可能な形式で永久破棄します。
6第三者提供およびインフラ委託
信頼できるクラウド事業者(Supabase Inc. / AWS、Google LLC、Apple Inc.)にインフラ業務を委託しています。
7利用者の権利および行使方法
利用者はアプリ内設定からいつでもクラウド同期の解除およびデータの全消去を要請することができます。
8技術的・管理的な保護対策
AES-256-GCM暗号化、TLS 1.3通信保護、ロック時のメモリ即時消去(RAM Zero-out)、OSネイティブ生体認証保護を導入しています。
9暗号化キー紛失時のデータ復旧不可および完全免責(必読)
当社はマスターキーやパスワードを保持しません。端末の故障・紛失や、初回発行される「復元キー(Recovery Key)」を紛失された場合、当社にはデータを復号・復旧する技術的手段が存在せず、これによるデータ消失について当社は一切の責任を負いません。
10個人情報保護管理者およびお問い合わせ窓口
お問い合わせ窓口:contact@straykittystudio.com | 公式サイト:straykittystudio.com
附則:本方針は2026年9月11日より施行されます。
1Zero-Knowledge-Prinzip & Grundlagen
StrayKitty Studio („Unternehmen“) schützt Ihre Daten nach dem Grundsatz der Zero-Knowledge-Ende-zu-Ende-Verschlüsselung (AES-256-GCM).
Alle Notizinhalte werden direkt auf Ihrem Endgerät verschlüsselt, bevor sie übertragen werden. Das Unternehmen verfügt über keinerlei Hauptschlüssel und kann Ihre Notizen technisch weder einsehen noch entschlüsseln.
2Erfasste personenbezogene Daten
| Kategorie | Daten | Zweck |
|---|---|---|
| Konto & Auth | Google OAuth ID, E-Mail-Adresse, Name | Sitzung & Pro-Lizenzprüfung |
| Metadaten | Geräte-UUID, Betriebssystem, App-Version | Synchronisations-Routing |
| In-App-Kauf | Kauf-Token, Produkt-ID, Ablaufdatum | Bestätigung über Play Store / App Store |
| Notizdaten | Verschlüsselter Chiffretext (Base64) & Nonce | Ausschließlich verschlüsselt gespeichert |
| Biometrie & Bankdaten | Fingerabdruck, Face ID, Kreditkartendaten | Werden niemals erhoben |
3Zweck der Datenverarbeitung
Die Datenverarbeitung dient ausschließlich der Durchführung der verschlüsselten Synchronisation und Lizenzverwaltung.
4Speicherdauer & Aufbewahrung
Daten werden nur für die Dauer des aktiven Nutzungsverhältnisses gespeichert und bei Kontolöschung unverzüglich entfernt.
5Löschung von Daten
Datensätze in Datenbanken werden auf Anfrage oder nach Fristablauf unwiderruflich physikalisch gelöscht.
6Drittanbieter-Infrastruktur
Infrastrukturpartner sind Supabase Inc. (AWS-Cloud), Google LLC und Apple Inc.
7Rechte der betroffenen Personen
Nutzer können in den App-Einstellungen jederzeit die Cloud-Synchronisation trennen und alle Cloud-Daten löschen.
8Technische Schutzmaßnahmen
Einsatz von AES-256-GCM, TLS 1.3, RAM-Säuberung beim Sperren und Gerätesicherheits-Enklaven.
9Haftungsausschluss bei Verlust kryptografischer Schlüssel (WICHTIG)
Das Unternehmen speichert keine Entschlüsselungsschlüssel. Bei Geräteverlust oder Verlust des Wiederherstellungsschlüssels (Recovery Key) ist eine Wiederherstellung technisch unmöglich. Das Unternehmen übernimmt keinerlei Haftung für daraus resultierende Datenverluste.
10Datenschutzbeauftragter & Kontakt
E-Mail: contact@straykittystudio.com | Website: straykittystudio.com
Stand: 11. September 2026.
1Principio de Conocimiento Cero (Zero-Knowledge)
StrayKitty Studio ("la Compañía") protege sus notas mediante cifrado de extremo a extremo de Conocimiento Cero (AES-256-GCM).
El texto plano de sus notas nunca sale de su dispositivo sin ser cifrado previamente. La Compañía no almacena claves maestras ni tiene capacidad para descifrar su información.
2Datos personales recopilados
| Categoría | Datos | Finalidad |
|---|---|---|
| Cuenta y Autenticación | Google OAuth ID, correo electrónico, nombre | Gestión de sesiones y licencia Pro |
| Metadatos | UUID de dispositivo, sistema operativo, versión | Enrutamiento de sincronización |
| Compras integradas | Token de compra, ID de producto, expiración | Verificación en Play Store / App Store |
| Notas | Texto cifrado binario (Base64) y Nonce | Almacenado únicamente como texto cifrado |
| Biometría y Tarjetas | Huella dactilar, Face ID, tarjetas bancarias | Nunca recopilados por la app |
3Finalidad del tratamiento
Los datos se procesan con el fin exclusivo de permitir la sincronización cifrada y verificar la suscripción PC Pro.
4Plazo de conservación
Los datos se conservan mientras la cuenta permanezca activa y se suprimen definitivamente tras la solicitud de baja.
5Eliminación de datos
Los registros de usuario y datos cifrados se purgan de las bases de datos de forma irrecuperable.
6Proveedores e infraestructura
La infraestructura se gestiona a través de Supabase Inc. (AWS), Google LLC y Apple Inc.
7Derechos del usuario
El usuario puede desvincular la sincronización y solicitar la supresión de datos directamente desde los ajustes de la app.
8Medidas de seguridad técnicas
Cifrado AES-256-GCM, TLS 1.3, borrado de claves en memoria RAM al bloquear la app y autenticación biométrica de SO.
9Exención de responsabilidad por pérdida de claves criptográficas
La Compañía no custodia claves maestras ni contraseñas. En caso de avería, pérdida del dispositivo o extravío de la Clave de Recuperación (Recovery Key), la Compañía carece de herramientas para recuperar sus notas y no asume responsabilidad alguna por la pérdida de datos.
10Contacto de privacidad
Correo: contact@straykittystudio.com | Sitio web: straykittystudio.com
Vigencia: 11 de septiembre de 2026.
1總則與零知識(Zero-Knowledge)端對端加密架構
StrayKitty Studio(以下稱「本公司」)極度重視隱私保護。NaMemo 採行零知識端對端加密(AES-256-GCM)設計原則。
所有記事標題、內文及標籤於離開裝置前均直接經 AES-256-GCM 加密。解密金鑰僅存放於本地裝置的安全防護區,伺服器絕不儲存明文或私鑰。任何第三方包括本公司開發人員均在技術上無法查閱您的記事內容。
2蒐集之個人資料項目
| 類別 | 項目 | 目的 |
|---|---|---|
| 帳號驗證 | Google OAuth ID、電子郵件、顯示名稱 | 身分驗證與 Pro 授權狀態比對 |
| 同步中繼資料 | 裝置 UUID、作業系統類型、應用程式版本 | 多端同步傳輸與版本衝突處理 |
| 應用程式內購買 | 商店收據憑證、產品 ID、到期時間 | Google Play / App Store 購買驗證 |
| 筆記資料 | 二進位加密密文(Base64)與 Nonce | 僅以密文形式儲存(本公司無法解密) |
| 生物辨識與金融資料 | 指紋、Face ID、信用卡資訊 | 絕不蒐集(完全由作業系統及商店處理) |
3個人資料處理目的
僅限於提供跨裝置加密同步、透過 Google 登入提供服務與 PC Pro 授權驗證,以及處理客戶諮詢。
4資料保留及利用期間
原則上於使用者使用服務期間留存;使用者要求刪除帳號時,本公司將即刻銷毀所有相關紀錄。
5資料銷毀程序及方法
雲端資料庫之紀錄與密文資料將被物理性完全刪除,達到不可逆之銷毀狀態。
6第三方基礎設施委託
本公司委由 Supabase Inc. (AWS 雲端)、Google LLC 與 Apple Inc. 提供底層雲端架構服務。
7使用者權利與行使方式
使用者得隨時於軟體設定中中斷雲端同步或刪除所有雲端資料。
8技術與管理保護措施
採用 AES-256-GCM、TLS 1.3 通訊加密、鎖定時記憶體即時清空 (RAM Zero-out) 及作業系統原生生物辨識保護。
9加密金鑰遺失不可還原與開發商免責 (必讀)
本公司不持有主金鑰或使用者密碼。若使用者因裝置故障、遺失或遺失一次性「還原金鑰(Recovery Key)」導致無法解密,本公司完全無任何技術途徑可予以還原,亦不承擔任何資料遺失之賠償責任。
10個人資料保護窗口
聯絡信箱:contact@straykittystudio.com | 官方網站:straykittystudio.com
生效日期:2026年9月11日。
1Principes et architecture Zero-Knowledge
StrayKitty Studio (« l'Éditeur ») protège la vie privée de ses utilisateurs par un chiffrement de bout en bout Zero-Knowledge (AES-256-GCM).
Toutes les notes sont chiffrées sur votre appareil local avant tout envoi. L'Éditeur ne détient aucune clé maîtresse et ne peut techniquement pas lire vos données.
2Données personnelles collectées
| Catégorie | Données | Finalité |
|---|---|---|
| Authentification | Google OAuth ID, courriel, nom | Gestion de session & licence Pro |
| Métadonnées | UUID d'appareil, OS, version | Routage et synchronisation |
| Achats intégrés | Jeton d'achat, ID de produit, expiration | Vérification Play Store / App Store |
| Contenu des notes | Texte chiffré binaire (Base64) & Nonce | Stocké uniquement sous forme chiffrée |
| Biométrie & Bancaire | Empreinte, Face ID, cartes de crédit | Jamais collectés par l'app |
3Finalité du traitement
Permettre la synchronisation chiffrée entre appareils et valider la licence PC Pro.
4Durée de conservation
Les données sont conservées pendant la durée d'utilisation active et supprimées lors de la clôture du compte.
5Procédures de suppression
Suppression définitive et irréversible des entrées dans les bases de données.
6Sous-traitants & Infrastructure
L'infrastructure est confiée à Supabase Inc. (AWS), Google LLC et Apple Inc.
7Droits des utilisateurs
Vous pouvez désactiver la synchronisation et effacer vos données cloud dans les paramètres de l'application.
8Mesures de sécurité techniques
AES-256-GCM, TLS 1.3, remise à zéro de la mémoire RAM au verrouillage et biométrie matérielle.
9Exonération totale pour perte de clés de chiffrement (À LIRE)
L'Éditeur ne stocke aucun mot de passe ni clé maîtresse. En cas de panne, de perte d'appareil ou d'égarement de votre Clé de Récupération (Recovery Key), l'Éditeur n'a aucun moyen technique de déchiffrer vos notes et décline toute responsabilité pour toute perte de données.
10Délégué à la protection des données & Contact
Courriel : contact@straykittystudio.com | Site : straykittystudio.com
Entrée en vigueur : 11 septembre 2026.