Privacy
Privacy Policy
This is an archived version — effective August 15, 2026. It was superseded on September 9, 2026 and is no longer in force. The current policy is here.
PaperDay ("the app") is an Android and iOS app made by CarrotSoftClan. The app does not collect your personal data. There is no sign-up, there is no service server, and the app does not transmit anything outside your device.
"We collect nothing" would not be the whole story, however. There are cases in which content on your device can leave it — only when you choose to enable or run them — and this policy states them. See section 4, "When information can leave your device".
1. What we do not collect
- There is no sign-up or login. We do not receive any information that could identify you — no name, email address, phone number or social account.
- We do not use advertising identifiers, device identifiers, usage logs or statistics, analytics tools, or crash reporting.
- The app shows no advertising and contains no advertising-network code.
- The app has no service server. There is nowhere for data to be collected, and nowhere to send it.
- We receive no payment information. This is a paid app, and purchase and payment are handled entirely by the store that distributes it (Google Play and the like). The app neither receives nor stores any payment information — payment method, purchase history or otherwise — and contains no code that carries out a payment.
The Android build does not declare the internet permission (android.permission.INTERNET). Without that permission the app cannot communicate with any address at all. You can confirm this yourself in the permission list Android shows at install time. iOS has no equivalent permission gate; there, instead, the app contains no code that reaches the network on its own. Either way, there is no code that sends information to a company server. (Where the operating system fetches a photo's original from your own iCloud in order to display it, see section 2 below.)
2. Where the things you write are kept
Alarms, to-dos, subscriptions, contracts, medication, anniversaries, daily routine, timetable and diary are all stored only on this device, in the app's own storage area.
- Android: the automatic cloud backup and device-to-device transfer that Android provides are explicitly disabled by the app. App data is not backed up to your Google account.
- iOS: app data is stored in the app's documents area, and if you have iCloud device backup switched on, it may be included in that backup. See section 4-c below.
- Photos attached to the diary are not copied by the app. It remembers only the location of the photo you chose and reads it when it needs to be shown. The original stays in your photo library, and the app never accesses anything beyond the photos you choose yourself — it does not read your whole library. (Only photos restored from a backup file are kept in the app's storage area.)
- On iOS, if the original photo is held in iCloud Photos, the operating system downloads it from your own iCloud in order to display it.
- The app does not request permission to read your device's general storage, nor camera permission.
3. Permissions the app requests, and what they are for
Every permission below exists to perform a function on the device. No permission is used to send information anywhere.
a. Android
| Permission | Used for |
|---|---|
| Notifications | Showing alarm, medication, billing-date and expiry notifications |
| Full-screen intent | Showing the full-screen alarm view over the lock screen |
| Exact alarms | Scheduling alarms to ring at exactly the time you set |
| Run at startup | Re-registering scheduled alarms so they survive a restart |
| Wake lock · foreground service | Keeping sound and screen going while an alarm is ringing |
| Vibration | Alarm and notification vibration |
| Display over other apps | Bringing up the alarm view while you are in another app |
| Read · write calendar | Used only when you enable the optional "device calendar sync". It is not requested at first launch. See section 4-a below. |
| Biometrics | App lock (fingerprint / face). Authentication is handled by the device; biometric data is never passed to the app. |
b. iOS
On iOS the app asks for your permission at the point of use. Notifications are requested at first launch; the rest are requested when you use the relevant feature.
| Item | Used for |
|---|---|
| Notifications | Showing alarm, medication, billing-date and expiry notifications |
| Calendar | Used only when you enable the optional "device calendar sync". See section 4-a below. |
| Photos | Attaching a photo to the diary. Only the photo you choose is accessed; your whole library is not read. |
| Face ID · Touch ID | App lock. Authentication is handled by the device; biometric data is never passed to the app. |
4. When information can leave your device
The app transmits nothing on its own. However, depending on choices you make, content can end up outside the device in the cases below. In each case the transfer is performed not by this app but by the operating system or by a service you selected.
a. Device calendar sync (optional · off by default)
With this feature on, an item's title, time, repeat rule and location are written to the device calendar you select. Notes and detailed content are not written.
If you select a synced calendar — a Google account calendar, for example — that account's sync mechanism carries the content off your device. This transfer is performed by the operating system and that account service, not by this app, and any subsequent handling follows that provider's privacy policy. If you select a local calendar that stays on the device, nothing leaves it.
- Because medication is health-related information, it can be switched off separately from the other kinds. To-dos, daily routine, timetable and medication each have their own toggle.
- Turning sync off stops any further writing. Items already written to the calendar remain there, so you will need to remove them yourself.
b. Exporting a backup file (only when you run it)
When you run an export, the app's data and your diary photos are written as a single file, and you choose where it is saved.
Backup files are sealed so they can't be read directly. If you want stronger protection, you can password-protect a backup.
Sealing exists to prevent accidental exposure — another app scanning your storage, an automatic upload to the cloud, a file sent to the wrong person. It does not stop someone who obtains the file and sets out to analyse it, so set a password if that is part of what you need to guard against.
If you forget the password, there is no way to open that backup. We hold no server, no copy of your password, and no copy of the backup, so we cannot open it for you.
- Choose a folder on the device and the file stays on the device.
- Choose a cloud document provider (Drive, for example) and it is stored with that provider. This is not the app uploading anything; it is the destination you selected. Any subsequent handling follows that provider's policy.
- Calendar file (.ics) export is not sealed. Calendar apps have to be able to read it, so it cannot be sealed, and the exported entries appear in it as they are. As with a backup, you choose where it is saved.
c. iOS device backup (iCloud)
On iOS, app data is stored in the app's documents area, and if you have iCloud device backup switched on, it may be included in that backup. This is the standard backup iOS provides for installed apps, and it is stored in your own iCloud account. CarrotSoftClan cannot access that backup.
- If you would rather it were not included, you can exclude this app — or turn iCloud backup off entirely — under Settings > Apple Account > iCloud > iCloud Backup.
- On Android, the equivalent automatic backup is already disabled by the app (see section 2).
5. Third-party provision · processing on our behalf · overseas transfer
None. The app does not collect personal data, so there is nothing to provide to a third party and nothing to have processed on our behalf, and no personal data is transferred overseas.
The calendar or storage destination you select in section 4 is a relationship between you and that provider; CarrotSoftClan is not providing or entrusting your information to them, and cannot see the content.
6. Retention and deletion
- Everything is held on the device only, so deleting it in the app deletes it immediately.
- Uninstalling the app removes what the app stored along with it. Because we hold no copy, there is no separate account-deletion procedure or deletion-request channel to go through.
- However, the original photos you attached to the diary remain in your photo library — the app never made copies of them.
- Likewise, files you exported under section 4, items written into a calendar, and any copy included in an iOS device backup remain where they are. You will need to remove those yourself.
7. Your rights
You can view, correct and delete your data yourself, in the app, at any time. As we hold no personal data, there is nothing to request from us — but if you have any question about this policy, please write to the address below.
8. Children under 14
The app does not ask your age and collects no personal data at all, so it does not collect the personal data of children under 14 either.
9. Contact
- Business name: CarrotSoftClan (캐럿소프트클랜) · Owner Kim Gwanbin · Business Registration No. 339-77-00517
- Privacy officer: Kim Gwanbin
- Email: contact@carrotsoftclan.com
10. Changes to this policy
This policy may be revised as the law or the app changes. Any revision will be announced on this page.