Privacy Policy
This Privacy Policy (“Policy”) explains what personal information Terrafarm (“Company”) collects, uses, discloses, and stores in connection with Oneul and its related web/mobile applications (the “Service”), and describes your rights and how you can exercise them. By accessing or using the Service, you agree to this Policy.
1. Personal Information We Collect
- Account identifiers: Email, name (nickname), profile image (optional), password (hashed), social login identifiers (when using Apple/Google, etc.).
- Subscription/Billing information: Purchase receipt tokens, subscription status, billing history (period/plan/renewal), store country/currency information (to the extent provided by the store).
- App usage information: Access timestamps, device/OS/app version, crash logs, feature-use events (e.g., create, save, sync), push tokens.
- Content: Journal text and photos you create/upload, and related metadata (e.g., capture time, resolution). The default is private.
- AI processing inputs: Journal text/photos transmitted for AI features (analysis/summaries/suggestions).
- Support/Inquiry: Email, logs, screenshots, and other information you provide to customer support.
- Cookies/Similar technologies: Essential/analytics cookies on our website (see “Cookies” below).
2. How We Collect Information
- Directly from you when you sign up/log in, make purchases, upload content, or submit support requests.
- Automatically for performance, security, and analytics (e.g., crashes, event logs).
- Via store integrations and server-to-server verification for payment/subscription confirmation.
3. Purposes of Use
- Provide the Service: Account management, journal creation/storage/sync, multi-device support.
- Subscriptions/Billing: Verify subscription status, handle renewal/cancellation, validate receipts, support charges/refunds.
- AI features: Run generative AI functions for analysis/summaries/recommendations.
- Improvement/Analytics: Usage statistics, performance/crash analysis, quality improvement.
- Security: Prevent misuse, access control, audit logs.
- Support/Notices: Respond to inquiries, notify about changes to Terms/Policy, subscription/transition notices.
- Legal compliance: Tax/accounting, consumer protection, dispute resolution, and other legal obligations.
4. Retention and Storage Period
- Account information: Retained until deletion of the account. After deletion, backups/logs are purged within up to 30 days (unless longer retention is required by law).
- Payment/transaction records: Retained for up to 5 years under applicable e-commerce and related laws.
- Customer complaints/disputes: Retained for up to 3 years under applicable laws.
- Access logs/IP: Retained for up to 6 months for legal or security purposes.
- AI processing data: Retained for the period necessary to provide the feature and then deleted. See Section 7 for external AI provider retention policies.
5. Sharing with Third Parties & International Transfers
We do not sell your personal information to third parties without your consent. However, to the extent necessary to provide the Service, we may engage the following processors/partners or transfer data overseas with appropriate safeguards.
- Apple / Google (app stores): In-app purchases, subscription management, refunds (locations: each company’s global infrastructure).
- RevenueCat: Subscription status/receipt validation, promotions (U.S./EU, etc.).
- Firebase (Google): Authentication, Analytics, Crashlytics, FCM push (U.S./global).
- OpenAI and other AI model providers: Processing user-requested journal analysis/summaries/recommendations (U.S./global). We oversee compliance with the providers’ retention and security policies.
- Cloud/Hosting: App/data hosting, backups, image storage (e.g., S3) (global).
- Other essential services: Email delivery, customer support, logging/monitoring.
For international transfers, we will provide notice/obtain consent as required by law and apply appropriate safeguards such as Standard Contractual Clauses (SCCs), including details on recipients, destination countries, timing/method, purposes/items transferred, and retention/use periods.
6. Your Rights
- Access/Rectification/Deletion: Request via the in-app account/settings pages or by emailing oneul@terrafarm.ai.
- Restriction of processing: You may request limitations on processing where permitted by law.
- Withdrawal of consent/Account deletion: Use the in-app account deletion feature or contact us by email.
- Complaints/Inquiries: If you disagree with our response, you may contact your data protection authority.
7. Notices Regarding AI Features
- Text/images you choose to provide may be transmitted to external AI model providers for AI features (analysis/summaries/recommendations) and processed there.
- We monitor external providers’ retention periods and security policies.
- AI outputs are informational and not professional advice. For health or mental-health and other sensitive matters, consult qualified professionals.
8. Children’s Personal Information (Under 14)
Use by children under 14 may require consent from a legal guardian. If such consent cannot be verified, access to the Service may be restricted. We may conduct guardian verification where necessary.
9. Security Measures
- Encryption in transit/at rest, password hashing, access control/segregation of duties, audit logs, backup and recovery.
- Contractual safeguards for processors and periodic reviews.
- In the event of a personal data breach, we will promptly notify/report as required by law and take measures to mitigate harm.
10. Cookies and Similar Technologies
- Strictly necessary cookies: For sign-in persistence, security, and core functionality.
- Analytics cookies: Aggregated, de-identified usage statistics for Service improvement.
- You can refuse/delete cookies in your browser settings, but some features may be limited.
11. Marketing/Push Notifications
- We may send essential notices about the Service and subscription/billing.
- Optional marketing notifications are based on prior consent and can be opted out at any time in app settings.
12. Third-Party Links/Services
The Service may contain links to third-party websites/services. Please review their privacy policies. The Company is not responsible for third-party practices.
13. Information on Automated Decision-Making
AI recommendations/summaries are intended to improve user experience and do not by themselves make automated decisions that produce legal effects or similarly significant impacts. You may stop using AI features at any time (disable relevant features or uninstall the app).
14. Data Protection Officer & Contact
For privacy inquiries, reports, or requests to exercise your rights, please contact:
15. Changes to This Policy
If we change this Policy, we will provide prior notice within the Service or by email or other reasonable means. Notices will include the effective date and a summary of key changes.
Addendum
- This Policy takes effect on 2025-10-02.
- Prior versions are replaced by this Policy.