Privacy Policy
Hai processes personal data as necessary to provide alarms, briefings, routines, weather, travel, Google account integrations, user-selected read-only external data connections, and subscription services.
1. Controller and Contact
Service: Hai
Data controller: Kevinhouse
Representative and privacy officer: Minhyung Yoo
Telephone: +82-10-4648-4401
Contact: ryukevinhouse@gmail.com
Privacy inquiries and requests for access, correction, deletion, restriction, consent withdrawal, Google permission revocation, or account deletion may be submitted through this contact.
2. Data We Process
- Account data: Google account identifier, email or email hash, display name, login session, authentication tokens
- Google integration data: OAuth scopes, access token, refresh token, grant and revocation status
- Location and time data: country, city, address, latitude, longitude, timezone, home/work/destination addresses
- Alarm and routine data: alarm time, repeat days, alarm title, sound and vibration settings, routine title, routine options, user prompts
- Google service data: Calendar events, Tasks, and YouTube subscriptions, videos, and playlists
- External connection data: RSS, Atom, podcast, ICS, and WebCal URLs; display labels; provider hosts; synchronization status and cache; Todoist and Notion OAuth tokens and account or workspace display data; and identifiers and metadata for Notion databases or data sources selected by the user
- Briefing and AI data: user prompts, generated briefings, AI responses, errors, quality diagnostics, model and token usage
- Billing data: Google Play product ID, purchase token, order ID, subscription status, billing cycle, expiration date, billing history
- Customer support data: account email, inquiry subject and message, status, administrator reply, submission and response times
- Device and operations data: OS, app version, internal device identifier, notification token, permission status, error logs, server request logs, security logs, and Google Play app, licensing, and device integrity verdicts
- Automatically collected data: access time, IP address, request path, response status, app usage, feature execution and failure records
Hai does not ordinarily collect national identification numbers, complete payment card numbers, or Google, Todoist, or Notion account passwords. Raw payment methods handled by Google Play are not stored on Hai servers. Because private feed or calendar URLs may contain access tokens, Hai encrypts them at rest and displays only the host rather than the full URL in the app.
3. Purposes of Use
- Google login, account identification, session maintenance, and account switching
- Scheduling and triggering alarms and showing notifications or full-screen alarm experiences
- Running Calendar, Tasks, and YouTube based routines and generating briefings
- Running routines and generating briefings from new RSS, Atom, and podcast items, ICS or WebCal events, Todoist tasks, and selected Notion metadata connected by the user
- Providing weather, air quality, location naming, travel time, and transit summaries
- Managing subscriptions, usage limits, payment verification, subscription recovery, refunds, and cancellation support
- Verifying the integrity of Google Play installations and billing requests and preventing tampering or fraudulent payments
- Customer support, troubleshooting, security, abuse prevention, service improvement, and analytics
4. Google User Data and External Data Connections
Hai processes Google user data only through read-only scopes explicitly approved by the user. It is used only to provide or improve prominent user-facing features such as routines, alarms, briefings, summaries, recommendations, and travel guidance requested by the user.
- Gmail features are coming soon. The current release does not request Gmail access or access, collect, store, or process Gmail data.
- Google Calendar data is used for schedule, event-location, and schedule-based travel briefings.
- Google Tasks data is used for due, priority, and upcoming task briefings.
- YouTube data is used for subscribed-channel videos, playlists, music, and video recommendations.
- Google Drive features are coming soon. The current release does not request Drive access or access, collect, store, or process Drive data.
- Google Maps data is used for location naming, travel time, and transportation summaries.
Hai does not use Google user data for advertising, retargeting, personalized ads, credit scoring, data brokerage, sale, or independent general-purpose model training unrelated to a requested feature. Hai does not transfer it to third parties or permit human access except to provide the requested feature, respond to a security incident, comply with law, or with the user's explicit consent.
Hai's use of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Users may review permissions in the app or revoke access from Google's connected apps and services page. Features that depend on revoked permissions may stop working.
YouTube features are also governed by the YouTube Terms of Service and the Google Privacy Policy.
RSS, Atom, podcast, ICS, and WebCal sources are retrieved read-only from URLs entered by the user. Hai processes only public material or material the user is authorized to access and blocks requests to local networks, private network ranges, and known cloud metadata endpoints.
Todoist and Notion are connected through each provider's OAuth approval screen using read-only access. Hai processes Todoist tasks due today or overdue and metadata such as titles, statuses, and dates from Notion pages, databases, or data sources the user shared and selected. Hai does not create, edit, or delete items in these external services.
Users may disconnect each external connection in app settings. Disconnection immediately deletes the related OAuth token, original source URL, selected data source, and cache. Routines that depend on the connection may stop until reconfigured.
5. AI Processing
Hai uses Gemini models through Google Cloud Vertex AI. User prompts, alarm or routine settings, Google service data authorized and required for the selected routine, user-selected external connection data, location, weather, and travel data may be sent to Google Cloud only as necessary to generate briefings, summaries, and recommendations.
Hai does not use this data for its own general-purpose model training, advertising, or data sales. Google Cloud does not use customer data to train or fine-tune general-purpose AI models without the customer's prior permission, although limited prompt logging may occur for service security and abuse detection under Google Cloud terms and settings. Generated output may be inaccurate, incomplete, or outdated, and users should verify important decisions against original data and official sources.
6. App Permissions and Device Features
- Location: provides local weather, location names, departure points, and travel guidance.
- Notifications: displays alarms, briefing status, and service notices.
- Exact alarm, full-screen intent, and display-over-other-apps access: presents an alarm at the scheduled time on the lock screen or over other apps.
- Foreground service, wake lock, and vibration: maintains the alarm experience and vibration while an alarm is active.
- Boot completed: restores saved alarm schedules after the device restarts.
If required permissions are denied or restricted by the operating system, related features may be delayed or unavailable. Hai does not currently request microphone, camera, contacts, or broad storage access.
When verifying a Google Play purchase, the Play Integrity API checks the app package and version, signing certificate, licensing status, device integrity, and request hash. Hai uses the verdict returned by Google to validate the billing request and does not store the raw device attestation certificate or request hash as part of the user's profile.
7. Retention, Deletion, and Pseudonymized Statistics
- Account, alarms, routines, and settings: until account deletion or service termination
- Google OAuth tokens and connection status: until disconnection, permission revocation, or account deletion
- Todoist and Notion OAuth tokens and connection status: until disconnection, permission revocation, or account deletion
- RSS, Atom, podcast, ICS, and WebCal URLs, selected Notion data sources, and external connection caches: until disconnection or account deletion; caches may be replaced when a connection is refreshed
- YouTube authorized data: only as long as needed for the feature, and refreshed or deleted within 30 days of the last retrieval and deleted within 30 days after revocation
- Briefing history: generally up to 120 days or the latest 200 entries per user
- AI usage and tool execution logs: generally up to 45 days
- Device synchronization logs: generally up to 21 days
- Location-name cache: up to 30 days for the same coordinates and language
- Login sessions: up to 180 days after issuance or until logout or account deletion
- Contract and withdrawal records: 5 years
- Payment and service-supply records: 5 years
- Consumer complaint, dispute, and support inquiry records: 3 years after the latest handling
- Display and advertising records: 6 months
- Account data in deletion-pending status: 7 days after acceptance of the deletion request or until recovery
- Pseudonymized and aggregated statistics: up to 24 months after account deletion
When a deletion request is accepted, Hai immediately removes sessions, device tokens, Google connection credentials, and external connection tokens, original URLs, selections, and caches; disables alarms; and holds the account in a recovery-pending state for 7 days. During this period, account data is not used to provide the ordinary Service and is processed only for recovery or final deletion. If no verified recovery request is completed before the deadline, identifiable briefing and prompt text and Google or external service data are finally deleted.
After final deletion, Hai may retain pseudonymized or aggregated statistics under a random retention identifier, such as month-level usage, country or language, plan, feature category, processing status, usage or length range, and cost range, for up to 24 months and then delete them. These records exclude original content, titles, names, organizations, event or file names, addresses, links, exact timestamps, Google identifiers, Google, Todoist, or Notion tokens, external source URLs, and raw external data.
Payment, contract, consumer inquiry, and dispute records that must be retained by law are separated from ordinary service data and access-restricted after account deletion. Billing records may include the account email, product, order and purchase identifiers, plan, amount, status, and processing time needed to prove the transaction. Support records may include the account email, inquiry, reply, and handling time.
8. Third-Party Disclosure, Processors, and International Transfers
Hai does not sell personal data or disclose it to independent third parties without separate consent or a legal basis. The processing engagements and international transfers necessary to provide the service are described below.
- Google LLC and affiliates: in the United States and other Google service regions, account data, tokens, Google user data, location, prompts, device tokens, and billing status are processed to provide Google Sign-In, Firebase Authentication, Firestore, Cloud Run, Firebase Cloud Messaging, Vertex AI, Calendar, Tasks, YouTube, Google Maps Platform, and Google Play. Data is transferred over encrypted networks when the relevant feature is used and processed for Hai's stated retention period or the period required by Google's agreement and applicable law.
- WeatherAPI.com, operated by Zoomash Ltd.: in the United Kingdom and other service regions, latitude, longitude, location query, language, and weather request data are processed to provide weather, forecasts, air quality, and location names. Data is transferred over encrypted networks when weather is requested or refreshed and processed for request handling and the provider's security and operational logging period.
- Todoist, operated by Doist Inc.: when a user connects Todoist and selects a related routine, OAuth authorization, account display data, and read-only retrieval of tasks due today or overdue are processed in the provider's service regions.
- Notion, operated by Notion Labs, Inc.: when a user connects Notion and selects a related routine, OAuth authorization, workspace display data, and read-only retrieval of metadata from user-shared and selected pages, databases, or data sources are processed in the United States and other service regions.
- Operators of feed, podcast, or calendar hosts specified by the user: when a user adds or refreshes a connection, the host may process the server address, IP address, request time, and conditional request headers in its service region. Hai does not control the independent privacy practices of these hosts.
Users may refuse this processing by declining or revoking Google permissions or individual external connections, or by not using location and weather features. Refusal may make the relevant routine, location, weather, travel, or billing-verification feature unavailable. Details are available in the Google Privacy Policy, WeatherAPI.com Privacy Policy, Todoist Privacy Policy, and Notion Privacy Policy.
9. Security and User Rights
Hai uses encrypted transport, encryption at rest for external URLs and OAuth tokens, access controls, secret separation, log access restrictions, server-side URL validation, and least-privilege practices. Users may request access, correction, deletion, suspension or restriction of processing, data portability, consent withdrawal, Google permission or external connection revocation, or information about automated output. Requests are processed after identity verification within the period required by applicable law.
10. Legal Bases and Sensitive Data
Hai processes personal data as necessary to perform a contract and provide the Service, with consent, to comply with legal obligations, and for legitimate interests in security, fraud prevention, and service reliability. Where processing relies on consent, withdrawal does not affect the lawfulness of processing before withdrawal.
Precise location may be treated as sensitive data in some jurisdictions. Hai processes it only when a user enables location permission or supplies an address and only as needed for weather and travel features. It is not used for advertising targeting or to infer sensitive characteristics.
11. Regional Rights and Complaints
Users in Korea may exercise rights under the Personal Information Protection Act and seek relief from the competent privacy authorities. Users in the EEA and United Kingdom may have rights to access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Users in certain U.S. states may request access, correction, deletion, and a copy of covered personal data where applicable.
Hai does not sell personal data or share it for cross-context behavioral advertising and does not process sensitive data for advertising. Hai does not discriminate against users for exercising applicable privacy rights.
12. Automated Processing and Advertising
Hai uses AI to generate briefings and recommendations, but it does not make solely automated decisions that produce legal or similarly significant effects on users. Hai currently does not use third-party behavioral advertising SDKs and does not use Google user data, location, or briefing content to build advertising profiles.
13. Destruction and Incident Response
Electronic files are deleted using methods designed to make recovery reasonably impracticable when their retention purpose ends. Database records and authentication tokens are access-disabled and deleted. Backup data is restricted to recovery purposes and overwritten or deleted under regular backup life cycles.
If a personal data incident occurs, Hai investigates the impact and takes measures such as access blocking, token revocation, and log review. Affected users and regulators will be notified when required by applicable law.
14. Children and International Users
Hai is not directed to children under 14. A user under 14 may not create an account or use the service without valid parental or guardian consent. If another country requires consent at a higher age, that local threshold applies. Hai deletes a child's data if it learns that it was collected without required consent.
15. Policy Changes
Hai will provide notice through the app or public policy page before materially changing its processing purposes, practices, or providers and will obtain additional consent where required. Prior versions and change history are available upon request.
August 10, 2026: added disclosures for the data categories, retention and deletion, AI processing, and international processing of read-only RSS, podcast, external calendar, Todoist, and Notion connections.
Business Information
Business name: Kevinhouse
Representative: Minhyung Yoo
Business address: Room 401, 54 Mokdongjungangbuk-ro 7na-gil, Yangcheon-gu, Seoul, Republic of Korea
Business registration number (Republic of Korea): 305-47-69724
Mail-order business registration number: 2026-Seoul Yangcheon-0913
Registration authority: Yangcheon-gu Office, Seoul
Telephone: +82-10-4648-4401
Contact: ryukevinhouse@gmail.com