Effective July 16, 2026 · Last updated August 10, 2026

한국어 방침 · The Korean policy governs notices to users in South Korea. If a service agreement and this policy differ, the term more favorable to the data subject applies where required by law.

MOADAY Privacy Policy

linqen (the “operator”) provides MOADAY, a project-first schedule service. This policy covers both the Android app and the moaday.site web app.

1. Information, purposes, legal bases, and retention

CategoryInformationPurpose and basisRetention
Google sign-in and accountFirebase user ID, name, email, Google profile-photo URL, provider data, IP address, user-agent, platform and app identifiersAuthentication, account identification, security, and service delivery; necessary to enter into and perform the service agreementUntil account deletion. Firebase deletion and backup removal may take up to 180 days; authentication IP records may be kept for a few weeks under Google's policy
MOADAY profileChosen display name, optional cropped and resized profile image stored as a 160×160 WebP file, update timeIn-app identity and cross-device sync; contract performanceUntil changed or the account is deleted
Projects, events, membershipsProject name, color, icon, owner/member IDs; event title, date, time, completion status, author ID; display name and timestampsSave, share, and synchronize schedules at the user's request; contract performanceUntil the item, project, membership, or account is deleted
InvitationsTen-character code, project ID/name, owner/creator ID, active status, creation and expiry timeInvitation and joining requested by usersBecomes unusable after seven days and is deleted no later than the next monthly retention sweep
Policy acceptanceCommunity Guidelines version and acceptance time; per-account device markerEvidence of UGC safety-policy acceptance and service operationUntil account deletion
Safety reports and blocksReporter, target user, project and content IDs; target type, reason, optional details, block choice, status and time; blocker/blocked IDs and source projectModeration, abuse prevention, user protection and terms enforcement; legitimate interests and legal obligationsUp to 24 months from submission or creation, then deleted no later than the next monthly retention sweep. A user's outgoing blocks are deleted earlier when that account is deleted. Only information subject to a legal hold or active dispute is retained separately as required
Optional usage and error analyticsGeneral actions and screens, app version/language, app-instance/device data, coarse IP-derived region, fixed error source/class/current screen. No project or event names, email, user ID, raw error messages, stack traces, referrers, or page URL query strings are addedProduct improvement and error diagnosis; separate consentUp to two months under the current Google Analytics user/event retention setting. Withdrawal immediately stops new events; aggregate reports may not be affected by that setting
Essential security and access dataFirebase Installation ID, App Check/reCAPTCHA or Play Integrity tokens and limited device/app metadata, web IP and request informationRequest verification, abuse prevention, and web delivery; contract performance and legitimate security interestsApp Check token up to seven days, replay-protection token up to 30 days; Hosting IP records for a few months under Google's policy; otherwise under provider policy or until account deletion
Support, rights, deletion requestsSender email, request, handling record and replyCustomer support and fulfillment of privacy/deletion rightsUp to 12 months after completion; longer only as necessary for an active legal dispute

MOADAY does not display in-app advertising; request an advertising ID, contacts, payment data, precise GPS location, camera, or microphone access; or sell personal information. Do not put health, biometric, political, government-ID or other sensitive information in project fields. MOADAY does not require such information, make it public, or separately process pseudonymized data.

2. Collection and choices

3. User-directed sharing

RecipientInformationPurposeDuration
Authenticated members of your projectDisplay name, project/event content and status, internal member/author IDsSchedule collaboration and sync you requestedWhile the project or membership exists
Signed-in person to whom a user gives a valid invite codeProject name and invite metadata before joining; project data after joiningInvitation confirmation and joiningUntil invite expiry/deletion or membership termination

Share codes only with people you trust. MOADAY does not sell or disclose information beyond this user-directed sharing except where law requires it or urgent protection of life and safety permits it.

4. Processors

MOADAY's core stack includes Firebase Authentication, Cloud Firestore, Firebase App Check, Firebase Hosting, and Firebase Installations.

ProcessorTask
Google LLC, the applicable Google Cloud contracting entity, and published subprocessorsFirebase Authentication, Cloud Firestore, Firebase Hosting, Installations, App Check, reCAPTCHA/Play Integrity: authentication, storage, sync, web delivery, and security
Google LLCGoogle Analytics for Firebase usage/error analytics for users who consent
Google Asia Pacific Pte. Ltd. and Google Workspace subprocessorsSend and store support, privacy-rights, and deletion-request email at contact@linqen.co.kr

We contractually limit processing to its purpose and require access controls, safeguards, incident notification, deletion, and subprocessor oversight. See Google's current Firebase and Workspace subprocessor lists.

5. International transfers

Recipient/contactInformationCountryTime/methodPurpose/retention
Google LLC and applicable Google Cloud contracting entity
Privacy contact
Account ID, name, email, photo URL, IP, user-agent and app dataUnited StatesEncrypted transfer during sign-in/authenticationFirebase Authentication; until account deletion, removal up to 180 days, IP a few weeks
Google LLC and applicable Google Cloud contracting entity
Privacy contact
Profile, project, event, membership, invite, report, block and request IDsUnited States (Firestore multi-region nam5: Iowa/Oklahoma, witness South Carolina)Encrypted transfer during storage and syncCloud Firestore; periods in section 1, deletion/backup removal up to 180 days
Google LLC and published subprocessors
Privacy contact
Installation ID, integrity/reCAPTCHA tokens, IP, limited device/app and web-request dataUnited States and Google global infrastructure countriesEncrypted transfer during access and verificationHosting, Installations, App Check and reCAPTCHA; essential security periods in section 1
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Analytics privacy contact
Optional analytics described in section 1United States and countries where Google Analytics processes dataEncrypted transfer after consent when events occurProduct improvement/error diagnosis; user/event data up to two months
Google Asia Pacific Pte. Ltd., 70 Pasir Panjang Road #03-71, Singapore 117371
Workspace privacy contact
Email, support/privacy/deletion request and handling recordSingapore, United States, and published subprocessor countriesEncrypted transfer when email is sent or receivedHandle requests; up to 12 months after completion, provider deletion up to 180 days

You may refuse required Firebase transfers by not signing in or deleting the account, but login, storage, and synchronization will be unavailable. You may deny or withdraw optional Analytics transfers without affecting core service.

6. Deletion

We delete information when its period expires or its purpose ends. A least-privilege operator runs a monthly retention tool that calculates legacy and current invitation, report, and block expiry from creation/expiry timestamps and deletes expired records after a dry-run review. Other Firestore documents and the Firebase Authentication account are removed through deletion APIs; localStorage entries are erased in the app; and the offline cache is scheduled for clearing on the next launch after account deletion. Electronic records are logically deleted so they are no longer available through the service, and provider backups expire through their rotation. Any legally required record is separated and used only for that obligation.

7. Cookies, local storage, and offline cache

8. Your rights

You may request access, correction, deletion, restriction or cessation of processing, and withdraw optional consent. You can edit your name/photo and delete the account in Profile. If you cannot use the app, email contact@linqen.co.kr from the Google email used for MOADAY. Do not send passwords or invite codes. We may verify identity or authority, respond within the period required by applicable law, and explain any lawful limitation and available appeal route. MOADAY is intended for adults aged 18 or older; a lawful representative may be asked to prove authority.

9. Security

Controls include Firebase Authentication and App Check; Firestore rules requiring both project membership records and IDs; denial of ordinary-client access to reports; least-privilege operator accounts with multi-factor authentication; encrypted transport; input type/length validation; signed and hash-verified Android releases; web security headers; operating procedures and periodic review. Operators access only what they need.

10. Privacy contact

Controller: linqen (MOADAY operator)
Privacy and complaints team: MOADAY Privacy
Email: contact@linqen.co.kr

11. Changes

This policy took effect on July 16, 2026. On August 10, 2026, we reconciled the data inventory, retention, user sharing, processors, international transfers, automatic collection, deletion, and rights sections with the implementation and provider documentation. Material future changes will be announced in the app or web service before taking effect.

Back to MOADAY · 한국어 방침