Privacy Policy (Heapo)
Effective date: July 22, 2026 Last updated: July 22, 2026
Heapo (the "Service") is a photo and video cloud app that lets you safely store your photos and videos in groups and view them together. The operator of Heapo (the "Operator") respects your privacy and complies with applicable data protection laws, including the Republic of Korea's Personal Information Protection Act (PIPA). This policy explains what information the Service collects, and why, how, and for how long it is used, stored, and deleted.
1. Information We Collect
The Service collects only the minimum information necessary.
1.1 Account information (at sign-up / sign-in)
- Email address, name or nickname (display name)
- Social login identifiers and authentication data β Google, Apple, and email sign-in (via Firebase Authentication)
- An internal account identifier (ID) used within the Service
- If you sign in with Apple and choose "Hide My Email," the anonymized relay email address provided by Apple
Your actual password is handled by the authentication providers (Firebase / Apple / Google); the Operator does not store it.
1.2 Content you provide
- The photo and video files you upload, and any metadata embedded in those files (capture date/time, device information, and location data if it is embedded in the file β i.e., EXIF data)
- Captions, tags, and capture dates you add to photos and videos
- Likes (hearts), comments, and guest messages
- Group / album structure, group membership relationships, and guest share link information
1.3 Payment and subscription information (for paid subscriptions)
- Subscription tier and status, storage usage
- Purchase receipts and validation tokens issued by the App Store / Google Play (used to verify subscription validity)
Actual payment method details such as credit card or bank account numbers are handled by Apple (App Store) and Google (Google Play); the Operator does not collect or store them.
1.4 Information accessed through device permissions
- Photo library: to upload selected (or all) photos and videos and to automatically upload new photos (background sync)
- Camera: to capture and immediately upload photos and videos
- Microphone: to record sound while capturing videos
1.5 Information collected automatically during operation
- Access IP address, access date/time, device and OS information, service usage records, and error logs (for service delivery, security, and troubleshooting)
The Service does not use advertising identifiers, analytics, crash reporting, or any other tracking SDKs, and does not track user behavior for advertising purposes.
2. How We Use Information
- To identify members and provide sign-in / authentication
- To store, convert (e.g., HEICβJPEG, video encoding), display, and share photos and videos within groups
- To provide interactive features such as likes and comments
- To process payments for paid subscriptions, verify purchases, and manage storage quotas
- To respond to inquiries and deliver notices
- To operate and maintain the Service, ensure security, prevent abuse, and comply with legal obligations
3. Device Permissions
The Service requests the following permissions only to the extent necessary to perform the related features. You can change or revoke any permission at any time in your device settings.
| Permission | Purpose | | --- | --- | | Photos / media access | Upload photos and videos and auto-upload new photos | | Camera | Capture and upload photos and videos | | Microphone | Record sound when capturing videos | | Notifications (if applicable) | Service-related announcements | | Background execution | Automatically upload new photos (background sync) |
If you deny a permission, you can still use the rest of the Service that does not depend on that feature.
4. Sharing and Processing by Third Parties
The Operator does not sell your personal information. However, to provide the Service, the following international providers are used to process information or provide infrastructure, strictly to the extent necessary.
| Provider | Purpose | Data processed | | --- | --- | --- | | Google LLC (Firebase Authentication, Google Sign-In) | Member authentication / sign-in | Email, account identifier, authentication token | | Apple Inc. (Sign in with Apple) | Social sign-in | Account identifier, relay email (if chosen) | | Apple Inc. (App Store) / Google LLC (Google Play) | In-app subscription billing and validation | Purchase receipts / validation tokens |
About content sharing
When you upload photos or videos to a group or share them via a guest share link, members of that group and anyone who receives the share link can view the shared photos, videos, and related comments. This is a core function of the Service, and you decide the scope of sharing. You can control who can see your content through per-item public/private settings and group invitation management.
5. International Transfer
The providers above (such as Google and Apple) may store and process data on servers located outside the Republic of Korea. By using the Service, you consent to such international transfer to the extent necessary to provide the Service. The Operator complies with the protective measures required by applicable law.
6. Data Retention and Deletion
- Personal information is deleted without undue delay when you delete your account or once the purpose of collection and use has been fulfilled.
- Any copies remaining in backups after deletion are removed within a reasonable period (in principle, within 30 days).
- Where applicable law requires retention for a certain period (e.g., payment and contract records under e-commerce laws), such data is stored separately for the legally required period and then destroyed.
7. Account Deletion and Data Removal
- You can delete your account directly from within the app via [Settings] β [Account] β [Delete Account].
- When you delete your account, your account information and the content you uploaded (photos, videos, etc.) are deleted and cannot be recovered.
- If you have any difficulty deleting your data or account, or need any additional request handled, please contact us using the details below.
8. Security Measures
- Authentication tokens are stored securely in the device's secure storage (iOS Keychain, Android Keystore).
- Communication between the app and our servers is protected with HTTPS (encrypted transmission).
- Access to personal information is minimized, and security vulnerabilities are reviewed and remediated.
9. Your Rights
You may exercise the following rights regarding your personal information:
- Request access to, correction of, deletion of, or suspension of processing of your personal information
- Withdraw consent and delete your account
You can exercise these rights through in-app features or by contacting us below, and the Operator will act without undue delay in accordance with applicable law.
10. Children's Privacy
The Service is not primarily directed to children under the age of 14 (or under the minimum age set by the applicable country/region), and does not knowingly collect personal information from such children. If we become aware that we have collected a child's personal information, we will delete it without undue delay. Content that includes children (such as family photos) is uploaded under the responsibility and consent of the user (guardian).
11. Changes to This Policy
This Privacy Policy may be revised in response to changes in law or the Service. In the event of a material change, we will notify you through an in-app notice or other appropriate means. The revised policy takes effect on the effective date stated in the notice.
12. Contact
For inquiries, complaints, or requests to exercise your rights regarding the processing of personal information, please contact:
- Service name: Heapo
- Email: juny3738@gmail.com
If you are located in the Republic of Korea and are not satisfied with our response, you may also contact the Korea Internet & Security Agency (KISA) Privacy Center (privacy.kisa.or.kr, dial 118 without an area code) or other relevant authorities.