Privacy Policy
Last updated: 2026-09-20
JungleZip (the 'Company') treats the letters you keep in Dear Future Me (the 'Service') as the most sensitive data, and processes personal information as described below in line with applicable law, including Korea's Personal Information Protection Act. Our principle is to keep your letters on your device wherever possible, and to process on our servers only what a feature needs.
1. Information We Collect
- Account (optional): if you sign in with email/password, Google or Apple, your email address and account identifier (Firebase Authentication). Core features work on your device without signing in.
- Letters: voice letterings, transcribed text, the question answered, timestamps, and photos or videos you attach or import. These are stored on your device by default.
- Synced data (when signed in): transcribed text, questions, created/delivery times, lettering length and weekly essay text. Audio, photos and videos are not included.
- Social connections (optional): if you connect Threads or Instagram, the access token and username for that service, and the posts of your own that you pick (text, photos, videos).
- Calendar (optional): when importing anniversaries, calendar events are read on your device only and never sent to our servers.
- Usage data: free-use counts for AI features, app events (e.g. saving a letter, skipping a question) and crash diagnostics (Firebase Analytics & Crashlytics). When signed in these may be linked to your account identifier. They never contain the content of your letters.
2. How Voice Data Is Handled
- Original audio is never sent to our servers. It is stored on your device under iOS data protection.
- With iCloud backup (on by default), audio backs up only to your own iCloud (Apple CloudKit private database), which we cannot access. You can turn it off in Settings.
- Transcription uses Apple speech recognition. With 'More accurate transcription' (on by default), audio is sent to Apple's servers for recognition under Apple's privacy policy. Turn it off to recognise on-device only, on supported devices.
3. How AI Features Work
- Picture of the day: that letter's text and any photos you pick pass through a server function to OpenAI for image generation.
- Memoir, event and whole-life essays: the text of the letters you choose passes through a server function to OpenAI for writing.
- Reflection: letter text is sent to OpenAI to extract emotions, keywords, people and intentions; the results are stored only on your device.
- Weekly essays are made on your device without our servers.
- Our servers return the result to the app and do not store the request (text or photos). Generated pictures and text are stored on your device.
4. How We Use Information
- Providing the service: storing letters, revisiting past letters, generating pictures, essays and memoir chapters, reflection, and importing social posts.
- Notifications: daily reminders and past-record arrival reminders (if enabled, scheduled on your device).
- Account identification, cross-device sync and backup restore.
- Managing AI feature usage, improving quality and diagnosing errors.
5. Processors and International Transfers
- Google LLC (USA) — Firebase Authentication, Cloud Firestore, Cloud Functions, Analytics, Crashlytics: sign-in, sync, server functions, usage analytics and crash diagnostics. Transferred over the network as you use the Service, and kept until account deletion or the end of the processing agreement.
- OpenAI, L.L.C. (USA) — picture and text generation, reflection: when you run one of these features, that letter's text and any photos you pick are sent. We receive only the result; OpenAI processes it under its API data policy.
- Meta Platforms, Inc. (USA) — Threads and Instagram connections: if you authorise a connection, we call Meta's APIs to fetch your own posts.
- Apple Inc. (USA) — iCloud backup and speech recognition: processed in your own Apple account under Apple's privacy policy.
- If you do not want your data transferred abroad, you can skip sign-in, AI features and social connections, or turn the related settings off; those features will then be unavailable.
- We do not share or sell personal information to third parties for any other purpose, and do not use it for advertising.
6. Threads and Instagram
- Only if you connect an account do we read your own posts, using the Threads (threads_basic) and Instagram (instagram_business_basic) permissions. We never publish, edit or delete anything.
- Under Meta's policy, only professional (Business or Creator) Instagram accounts can be connected.
- Access tokens are kept only on our server (Firestore) and never sent to your device. Only the posts you pick are saved, on your device; none are stored on our server.
- Disconnecting in Settings deletes the access token from our server immediately. You can also remove this app's access in the Threads or Instagram app settings.
7. Retention and Deletion
- Letters on your device are kept until you delete them or the app.
- Synced data and AI usage counts are kept until you delete them or request account deletion, and are destroyed without delay on request.
- Social access tokens are deleted immediately when you disconnect.
- 'Settings > Data > Delete everything · Leave' in the app deletes the letters on your device, your iCloud audio backup, and on our server your synced data, AI usage letters, social access tokens and the sign-in account itself.
- If you've already removed the app and can't leave from within it, email us at the address below; we will complete it within 7 days and confirm.
- Electronic files are deleted in a way that cannot be recovered.
8. Your Rights
- You may at any time request access to, correction or deletion of, or suspension of processing of your personal information.
- You can edit and delete letters in the app, and export a .zip backup in Settings. Other requests can be sent to the email below.
- We do not collect personal information from children under 14.
9. Security
- All communication between the app and our servers is encrypted (HTTPS).
- Secret keys for AI and social services are never in the app; they are kept only in the server's secret store.
10. Privacy Officer and Contact
- Privacy officer: Namhoon Won (JungleZip). For privacy questions, access or deletion requests, or complaints, contact us at the address below.
11. Changes to This Policy
- If this policy changes, we will announce it on this page and in the app before it takes effect. The last-updated date is shown at the top of this page.
Operated by: JungleZip
Privacy officer contact: support@dearfutureme.net