MARO / 뭐뭇노 개인정보 처리방침

시행일: 2026-09-23

기기에 저장되는 정보

식사 기록, 프리셋, 목표와 같은 일반 영양 기록은 앱의 로컬 저장소에 저장됩니다. iPhone·iPad에서는 같은 Apple 계정의 기기끼리 기록을 맞추기 위해 아래 「iPhone·iPad 기기 간 식단 동기화」에 적힌 범위가 MARO 서버에도 저장됩니다. Android에서는 사용자가 Google 계정을 연결한 경우에만 Google Drive로 동기화되며 MARO 서버에는 저장되지 않습니다.

iPhone·iPad 기기 간 식단 동기화

iPhone·iPad에서는 식단 기록, 하루 목표, 자주 먹는 음식, 사진을 제외한 AI 분석 내역이 MARO의 서버(Cloudflare Workers·D1, 기기별 1개 문서)에 저장되어 같은 Apple 계정의 기기끼리 자동으로 합쳐집니다. 별도 회원가입이나 로그인은 없고, 계정 키로는 앱이 만든 익명 설치 식별값만 사용하며 이름·이메일·Apple ID는 저장하지 않습니다. 분석 사진은 전송하지 않고 촬영한 기기에만 남습니다. 건강 앱에서 읽은 값도 이 동기화에 포함하지 않습니다. Apple의 심사 정책에 따라 이 영양 기록을 iCloud 앱 저장소에는 저장하지 않으며, 로컬 영양 저장소는 iCloud Backup 제외 대상으로 표시합니다. 저장된 문서는 앱에서 모든 기록 삭제를 선택하면 서버에서도 삭제되고, 아래 문의 주소로 삭제를 요청할 수도 있습니다.

iCloud AI 크레딧 계정 공유

iPhone 또는 iPad에서 iCloud와 이 앱의 iCloud 사용이 켜져 있으면 같은 Apple 계정의 기기가 같은 AI 크레딧 계정을 사용할 수 있도록 앱이 만든 익명 크레딧 계정 식별값만 이 앱 전용 iCloud 저장 공간에 보관합니다. 식단 기록, 하루 목표, 자주 먹는 음식, AI 분석 내역, 분석 사진과 건강 앱 기록은 iCloud 앱 저장 공간으로 동기화하지 않습니다. MARO는 영양 데이터가 있는 로컬 SQLite·분석 이미지 저장소와 위젯 App Group 저장소를 앱 시작 시 iCloud Backup 제외 대상으로 표시합니다. 이 익명 식별값은 크레딧 계정을 연결·통합할 때 MARO 서버로 전송될 수 있습니다. 실제 크레딧 잔액·구매·환불 내역과 로그인 세션은 iCloud에 저장하지 않고 MARO 서버에서 관리합니다. 설정 > Apple 계정 > iCloud에서 이 앱의 iCloud 사용을 끌 수 있습니다.

Android의 Google Drive 동기화

앱 설정에서 Google 계정을 연결하고 동의하면 같은 Google 계정의 Android 기기끼리 식단, 목표, 자주 먹는 음식, 사진을 제외한 AI 분석 내역을 동기화합니다. 앱 전용 비공개 저장 공간(appDataFolder)을 사용하며 일반 Drive 파일에는 접근하지 않습니다. Google 계정 식별값과 이메일은 계정 구분 및 기기 내 연결 표시에 사용합니다. 액세스 토큰은 Google 인증을 통해 얻어 Drive 요청에 사용하며 MARO 서버로 전송하지 않습니다. iCloud와 Google Drive는 서로 연결되지 않습니다. 계정을 바꾸면 이전 계정의 로컬 기록을 보관하고 선택한 계정의 기록을 엽니다. 연결 해제는 저장된 기록을 삭제하지 않습니다.

Apple 건강 및 Health Connect

앱 설정에서 연동을 켜고 OS 권한을 허용한 경우에만, 확정한 식단의 이름·기록 시각·칼로리·단백질·탄수화물·지방을 이 기기의 Apple 건강 또는 Health Connect에 반영합니다. 기본적으로 연결 이후 작성하거나 수정한 기록부터 반영하며, 기존 기록 포함은 별도로 선택합니다. MARO가 쓴 기록만 확인하여 중복을 줄이고 수정·삭제를 반영하며 다른 앱의 건강 기록은 가져오지 않습니다. 건강 앱의 데이터는 AI 분석, 광고, 마케팅 또는 MARO 서버 동기화에 사용하지 않습니다. 연동을 끄거나 클라우드 계정을 바꾸어도 이미 쓴 건강 기록은 남습니다.

앱 기록 삭제와 건강 기록 삭제

iPhone·iPad에서 설정의 모든 기록 삭제는 이 기기에 저장된 식단·목표·자주 먹는 음식·분석 내역을 삭제하고, MARO 서버에 저장된 같은 계정의 동기화 문서도 함께 삭제하여 같은 Apple 계정의 다른 기기에도 반영합니다. 이 영양 기록은 iCloud 앱 저장소로 동기화하지 않으며 로컬 영양 저장소는 iCloud Backup 제외 대상으로 표시합니다. Android에서 Google Drive 동기화를 연결한 경우에는 현재 Google 계정의 삭제가 동기화되어 같은 계정의 다른 Android 기기에도 반영됩니다. 건강 앱 기록은 기본적으로 유지하며, 별도 항목을 선택하면 이 기기에서 MARO가 쓴 모든 영양 기록의 삭제도 요청합니다. OS 권한이나 연결 상태 때문에 삭제가 대기할 수 있으며 건강 앱에서 MARO 기록을 직접 관리할 수도 있습니다.

AI 분석과 OpenAI 공유 동의

최초 AI 사진 또는 텍스트 분석 전에 MARO는 OpenAI와 공유되는 데이터와 영양 분석 목적을 설명하고 명시적인 허용을 받습니다. 허용한 경우 AI 사진 분석에 선택한 이미지가, AI 텍스트 등록에는 사용자가 입력한 음식 설명이 MARO의 Cloudflare Worker를 거쳐 OpenAI의 AI 서비스로 전송됩니다. 기존 분석의 AI 수정을 사용하면 원본 사진 또는 음식 설명, 사용자가 입력한 수정 지시와 기존 분석값도 결과 수정을 위해 OpenAI로 전송됩니다. 허용 전에는 선택한 사진·음식 설명·수정 지시·기존 분석값을 OpenAI에 보내는 분석 요청을 시작하거나 해당 AI 요청의 크레딧을 소비하지 않습니다. 앱의 자체 크레딧 계정·스토어 상태 확인은 이 제3자 데이터 공유 동의와 별개로 동작할 수 있습니다. 거부해도 수동 식단 기록과 이미 저장된 결과는 계속 사용할 수 있습니다. 설정의 AI 개인정보에서 이후 공유를 허용하거나 철회할 수 있으며, 철회하면 사진·텍스트 분석, 재시도와 AI 수정의 이후 OpenAI 전송이 중단됩니다. 이 동의 상태는 설치된 기기에만 저장하며 iCloud 또는 Google Drive로 동기화하지 않습니다. Worker는 이미지 파일이나 입력한 음식 설명 원문 자체를 애플리케이션 데이터베이스에 저장하지 않습니다. 중복 청구 방지와 동일 요청 재시도를 위해 성공한 분석 결과와 요청 식별자가 서버에 기록될 수 있습니다.

AI 크레딧 및 구매

무료·유료 AI 크레딧을 관리하기 위해 구매 식별자와 환경, 크레딧 잔액·원장, 구매 처리 기록, 해시된 세션 토큰을 저장합니다. 결제 카드나 은행 정보는 MARO가 받지 않으며 결제는 기기에 따라 Apple 또는 Google Play가 처리합니다. App Store에서는 Apple이 서명한 앱/구매 거래 식별자를 사용합니다. 미완료 App Store 구매의 고객 지원을 위해 구매 검증 자료를 암호화하여 최종 수신 후 최대 30일간 재검증에 사용하며, 지급이 완료되면 삭제합니다. 만료 자료는 매일 정리합니다. Apple이 환불을 확정하면 App Store Server Notifications로 받은 서명된 거래 식별자와 환불 정보를 저장하고, 해당 구매분에서 아직 사용하지 않은 크레딧만 회수합니다. 환불 요청 시 사용 정보를 Apple에 제공하는 것은 앱에서 별도로 동의한 경우에만 이루어집니다.

Google Play 구매

Android에서는 구매 검증과 중복 지급 방지를 위해 구매 토큰의 해시, 암호화한 구매 토큰, 상품·주문 식별자, 구매 시각·상태·국가 코드, 앱의 익명 크레딧 계정 연결값을 저장합니다. 암호화한 토큰은 Google Play 검증과 미완료 처리 재시도에 사용합니다. Google Play의 구매·취소·환불 알림과 검증 결과에 따라 크레딧을 지급하거나 해당 구매분의 남은 크레딧을 회수합니다. 구매 원장과 검증 기록은 중복 지급 방지·환불 처리·고객 지원에 필요한 동안 보관하며 개인정보 문의처에서 확인·삭제를 요청할 수 있습니다.

보관 및 안전

iPhone·iPad 기기 간 식단 동기화 문서는 기기가 마지막으로 올린 내용을 그대로 보관하며, 앱에서 모든 기록 삭제를 선택하거나 삭제를 요청하면 지워집니다. 거래 중복 지급 및 크레딧 무결성을 유지하는 데 필요한 기록은 서비스 운영과 부정 사용 방지를 위해 보관될 수 있습니다. 앱에는 OpenAI API 키나 Apple 서버 비밀키를 포함하지 않습니다. MARO는 사용자 데이터를 처리하는 Cloudflare, OpenAI 및 그 밖의 제3자 처리자가 이 방침과 적용되는 App Store 개인정보 요구사항에 상응하는 수준으로 사용자 데이터를 보호하도록 요구합니다.

문의

개인정보 처리, 보관 중인 정보 확인·삭제 요청 등은 maroaicustomer@gmail.com으로 연락해 주세요. 앱 사용 관련 안내는 MARO 지원 페이지를 확인해 주세요.

Contact

For privacy questions or to request access to or deletion of data held about you, email maroaicustomer@gmail.com.

English summary: MARO does not sync nutrition logs from iPhone or iPad to iCloud. If iCloud and this app's iCloud usage are enabled, MARO stores only an app-generated anonymous credit-account identifier in its private iCloud container so Apple devices on the same account can share AI credits. MARO marks its local nutrition SQLite storage, saved analysis-image directory, and widget app-group storage as excluded from iCloud Backup at native launch. That identifier may be sent to the MARO server when linking or merging credit accounts. Credit balances, purchase and refund history, sessions, meal logs, goals, presets, AI analysis history, photos and Health records are not written to the MARO iCloud app container. Before the first photo or text AI analysis, MARO explicitly asks permission to share the selected food photo or typed food description with OpenAI through the MARO Worker for nutrition analysis. AI edits can also send the original photo or text, the user's edit instruction, and existing analysis values. Before permission is granted, MARO does not send that selected content or revision data to OpenAI, start an OpenAI analysis request using it, or consume a credit for that AI request; MARO's first-party credit-account or store state may initialize separately. Users can deny sharing and keep manual logging, or grant/withdraw future sharing under Settings → AI privacy; withdrawal also blocks retries and AI edits. This consent preference remains local to the installation and is not synchronized through iCloud or Google Drive. The application database does not persist the source image file or the original typed food description. Server-side records include Apple-signed transaction identifiers, authoritative credit ledger data, hashed session tokens, request identifiers, and successful analysis results needed for idempotency and purchase integrity. Encrypted verification data for unfinished App Store purchases is available for support retries for up to 30 days after its last receipt, removed upon fulfillment, and purged daily after expiry. Google Play records include hashed and encrypted purchase tokens, product and order identifiers, purchase time, status, country code and the anonymous credit-account association. They support verification, retry, refund handling and duplicate prevention. Purchase records are retained as needed for these purposes; contact support for access or deletion requests. Payment-card data is handled by Apple or Google Play, not MARO. MARO requires Cloudflare, OpenAI and other third parties that process user data to provide the same or equivalent protection described in this policy and required by applicable App Store privacy rules.

Device connections: On Android, optional Google account authorization syncs food logs, goals, presets and photo-free analysis history through the private Google Drive appDataFolder, only between Android devices on the same account. Ordinary Drive files are not accessed. The account identifier and email distinguish and display the connected account locally; Google access tokens are used for Drive requests and are not sent to MARO servers. Switching accounts opens a separate local workspace, and disconnecting keeps its data. On Apple devices, iCloud is separate from Google Drive and is used only for the anonymous AI credit-account identifier described above; nutrition records are not synced to the MARO iCloud app container and their local storage is marked as excluded from iCloud Backup.

Health export: If you enable it and grant OS permissions, MARO writes confirmed meal names, timestamps, calories, protein, carbohydrates and fat to Apple Health or Health Connect on this device. Only records created or edited after connecting are included by default; including older logs is a separate choice. MARO checks only its own records for duplicate prevention and edits or deletions, without importing other apps' health records. Health-store data is not used for AI analysis, advertising, marketing or MARO server sync, and MARO does not copy Health-store data into its iCloud app container. Apple Health's own iCloud synchronization, when enabled by the user, is controlled by Apple and the operating system. Disabling export keeps existing health records. An additional, initially unselected deletion option requests deletion of all MARO nutrition records in this device's health store. Failed health deletions remain pending for retry.