Hai AI alarm assistant

Privacy Policy

Effective date: August 10, 2026 · Version 2.3

Hai processes personal data as necessary to provide alarms, briefings, routines, weather, travel, Google account integrations, user-selected read-only external data connections, and subscription services.

1. Controller and Contact

Service: Hai

Data controller: Kevinhouse

Representative and privacy officer: Minhyung Yoo

Telephone: +82-10-4648-4401

Contact: ryukevinhouse@gmail.com

Privacy inquiries and requests for access, correction, deletion, restriction, consent withdrawal, Google permission revocation, or account deletion may be submitted through this contact.

2. Data We Process

Hai does not ordinarily collect national identification numbers, complete payment card numbers, or Google, Todoist, or Notion account passwords. Raw payment methods handled by Google Play are not stored on Hai servers. Because private feed or calendar URLs may contain access tokens, Hai encrypts them at rest and displays only the host rather than the full URL in the app.

3. Purposes of Use

4. Google User Data and External Data Connections

Hai processes Google user data only through read-only scopes explicitly approved by the user. It is used only to provide or improve prominent user-facing features such as routines, alarms, briefings, summaries, recommendations, and travel guidance requested by the user.

Hai does not use Google user data for advertising, retargeting, personalized ads, credit scoring, data brokerage, sale, or independent general-purpose model training unrelated to a requested feature. Hai does not transfer it to third parties or permit human access except to provide the requested feature, respond to a security incident, comply with law, or with the user's explicit consent.

Hai's use of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Users may review permissions in the app or revoke access from Google's connected apps and services page. Features that depend on revoked permissions may stop working.

YouTube features are also governed by the YouTube Terms of Service and the Google Privacy Policy.

RSS, Atom, podcast, ICS, and WebCal sources are retrieved read-only from URLs entered by the user. Hai processes only public material or material the user is authorized to access and blocks requests to local networks, private network ranges, and known cloud metadata endpoints.

Todoist and Notion are connected through each provider's OAuth approval screen using read-only access. Hai processes Todoist tasks due today or overdue and metadata such as titles, statuses, and dates from Notion pages, databases, or data sources the user shared and selected. Hai does not create, edit, or delete items in these external services.

Users may disconnect each external connection in app settings. Disconnection immediately deletes the related OAuth token, original source URL, selected data source, and cache. Routines that depend on the connection may stop until reconfigured.

5. AI Processing

Hai uses Gemini models through Google Cloud Vertex AI. User prompts, alarm or routine settings, Google service data authorized and required for the selected routine, user-selected external connection data, location, weather, and travel data may be sent to Google Cloud only as necessary to generate briefings, summaries, and recommendations.

Hai does not use this data for its own general-purpose model training, advertising, or data sales. Google Cloud does not use customer data to train or fine-tune general-purpose AI models without the customer's prior permission, although limited prompt logging may occur for service security and abuse detection under Google Cloud terms and settings. Generated output may be inaccurate, incomplete, or outdated, and users should verify important decisions against original data and official sources.

6. App Permissions and Device Features

If required permissions are denied or restricted by the operating system, related features may be delayed or unavailable. Hai does not currently request microphone, camera, contacts, or broad storage access.

When verifying a Google Play purchase, the Play Integrity API checks the app package and version, signing certificate, licensing status, device integrity, and request hash. Hai uses the verdict returned by Google to validate the billing request and does not store the raw device attestation certificate or request hash as part of the user's profile.

7. Retention, Deletion, and Pseudonymized Statistics

When a deletion request is accepted, Hai immediately removes sessions, device tokens, Google connection credentials, and external connection tokens, original URLs, selections, and caches; disables alarms; and holds the account in a recovery-pending state for 7 days. During this period, account data is not used to provide the ordinary Service and is processed only for recovery or final deletion. If no verified recovery request is completed before the deadline, identifiable briefing and prompt text and Google or external service data are finally deleted.

After final deletion, Hai may retain pseudonymized or aggregated statistics under a random retention identifier, such as month-level usage, country or language, plan, feature category, processing status, usage or length range, and cost range, for up to 24 months and then delete them. These records exclude original content, titles, names, organizations, event or file names, addresses, links, exact timestamps, Google identifiers, Google, Todoist, or Notion tokens, external source URLs, and raw external data.

Payment, contract, consumer inquiry, and dispute records that must be retained by law are separated from ordinary service data and access-restricted after account deletion. Billing records may include the account email, product, order and purchase identifiers, plan, amount, status, and processing time needed to prove the transaction. Support records may include the account email, inquiry, reply, and handling time.

8. Third-Party Disclosure, Processors, and International Transfers

Hai does not sell personal data or disclose it to independent third parties without separate consent or a legal basis. The processing engagements and international transfers necessary to provide the service are described below.

Users may refuse this processing by declining or revoking Google permissions or individual external connections, or by not using location and weather features. Refusal may make the relevant routine, location, weather, travel, or billing-verification feature unavailable. Details are available in the Google Privacy Policy, WeatherAPI.com Privacy Policy, Todoist Privacy Policy, and Notion Privacy Policy.

9. Security and User Rights

Hai uses encrypted transport, encryption at rest for external URLs and OAuth tokens, access controls, secret separation, log access restrictions, server-side URL validation, and least-privilege practices. Users may request access, correction, deletion, suspension or restriction of processing, data portability, consent withdrawal, Google permission or external connection revocation, or information about automated output. Requests are processed after identity verification within the period required by applicable law.

10. Legal Bases and Sensitive Data

Hai processes personal data as necessary to perform a contract and provide the Service, with consent, to comply with legal obligations, and for legitimate interests in security, fraud prevention, and service reliability. Where processing relies on consent, withdrawal does not affect the lawfulness of processing before withdrawal.

Precise location may be treated as sensitive data in some jurisdictions. Hai processes it only when a user enables location permission or supplies an address and only as needed for weather and travel features. It is not used for advertising targeting or to infer sensitive characteristics.

11. Regional Rights and Complaints

Users in Korea may exercise rights under the Personal Information Protection Act and seek relief from the competent privacy authorities. Users in the EEA and United Kingdom may have rights to access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Users in certain U.S. states may request access, correction, deletion, and a copy of covered personal data where applicable.

Hai does not sell personal data or share it for cross-context behavioral advertising and does not process sensitive data for advertising. Hai does not discriminate against users for exercising applicable privacy rights.

12. Automated Processing and Advertising

Hai uses AI to generate briefings and recommendations, but it does not make solely automated decisions that produce legal or similarly significant effects on users. Hai currently does not use third-party behavioral advertising SDKs and does not use Google user data, location, or briefing content to build advertising profiles.

13. Destruction and Incident Response

Electronic files are deleted using methods designed to make recovery reasonably impracticable when their retention purpose ends. Database records and authentication tokens are access-disabled and deleted. Backup data is restricted to recovery purposes and overwritten or deleted under regular backup life cycles.

If a personal data incident occurs, Hai investigates the impact and takes measures such as access blocking, token revocation, and log review. Affected users and regulators will be notified when required by applicable law.

14. Children and International Users

Hai is not directed to children under 14. A user under 14 may not create an account or use the service without valid parental or guardian consent. If another country requires consent at a higher age, that local threshold applies. Hai deletes a child's data if it learns that it was collected without required consent.

15. Policy Changes

Hai will provide notice through the app or public policy page before materially changing its processing purposes, practices, or providers and will obtain additional consent where required. Prior versions and change history are available upon request.

August 10, 2026: added disclosures for the data categories, retention and deletion, AI processing, and international processing of read-only RSS, podcast, external calendar, Todoist, and Notion connections.

Business Information

Business name: Kevinhouse

Representative: Minhyung Yoo

Business address: Room 401, 54 Mokdongjungangbuk-ro 7na-gil, Yangcheon-gu, Seoul, Republic of Korea

Business registration number (Republic of Korea): 305-47-69724

Mail-order business registration number: 2026-Seoul Yangcheon-0913

Registration authority: Yangcheon-gu Office, Seoul

Telephone: +82-10-4648-4401

Contact: ryukevinhouse@gmail.com