개인정보 처리방침 · Privacy Policy
마디 개인정보 처리방침
시행일 2026-10-07 · 적용 범위: 마디 iPhone 앱. 비보리랩 계정 자체는 비보리랩 개인정보 처리방침을 따릅니다. English version
1. 요약
마디는 인터넷 없이 쓰는 영상·음악 재생, 연습, NAS, PDF, 영상 편집 앱입니다. 로그인하지 않으면 비보리랩(이하 "운영자")에게 전달되는 개인정보가 없습니다. 광고, 분석, 추적, 크래시 수집 도구를 넣지 않았습니다.
2. 기기 안에만 있는 것
- 보관함의 파일(영상·음악·PDF·편집 결과): 앱의 문서 폴더에 있고 파일 앱에서 보입니다. 서버로 올리지 않습니다.
- 재생 위치, 마디표(마디 경계·이름·반복 방법), 박자, 연습 기록(연습 시간·마디마다 반복 횟수), 설정: 기기에만 저장됩니다(기기 백업에는 포함될 수 있습니다). 파형과 박 찾기는 기기 안에서 계산하며 캐시는 iOS 가 지울 수 있습니다.
- 녹음(따라 하기·녹음 단추): 기기 안 m4a 파일입니다. 녹음 단추로 만든 것은 보관함 '녹음' 폴더에 남고, '따라 하기' 쉼 동안의 녹음은 들려준 뒤 다음 녹음으로 덮어써 남기지 않습니다.
- 목소리·반주 나누기와 코드·조·음 보기: 앱 안에 든 모델과 계산으로 iPhone 안에서만 합니다. 나눈 소리와 분석 결과는 기기의 임시 공간(캐시)에만 있고 서버로 보내지 않습니다. 설정 '저장 공간'에서 지울 수 있고, iOS 가 공간이 모자라면 지울 수 있습니다.
- 마디표 파일(.madi): 직접 '보내기'를 누를 때만 만들어 iOS 공유 시트로 넘깁니다(경계·이름·박자만, 소리는 없습니다).
- NAS(SMB) 주소와 사용자 이름: 기기에만 저장되고, 비밀번호는 iPhone 키체인에만 저장됩니다(다른 기기로 옮겨지지 않음). 연결은 같은 와이파이 안에서만 이뤄집니다.
- Pro 구매: 결제는 Apple 이 처리하고, 앱은 기기에서 App Store 구매 기록으로 확인합니다. 운영자는 결제 수단이나 Apple ID 를 받지 않습니다.
3. 로그인했을 때(선택)
나란을 결제 중인 분이 Pro 를 열 때만 로그인합니다. 로그인하지 않아도 앱은 그대로 쓸 수 있습니다. 로그인은 Apple 로그인 또는 Google 로그인(비보리랩 계정, auth.vivory.app)이며 새 계정을 만들지 않습니다.
- 서버에 남는 것: 이 앱의 기기 기록 하나(앱 이름, 이용권 갱신 키의 SHA-256 값, 기기 종류 이름, 만든 시각과 마지막 확인 시각, 끊은 시각). 갱신 키 원문은 서버에 저장하지 않습니다.
- Apple 로그인을 쓰면 Apple 이 확인한 같은 이메일의 기존 계정에 Apple 사용자 식별자를 이어 둡니다.
- 기기에 남는 것: 이용권 토큰(30일), 갱신 키, 계정 이메일. 모두 키체인에 저장됩니다.
- 인터넷이 될 때 하루에 한 번 이용권을 새로 받습니다(auth.vivory.app). 이때 접속 IP 와 시각이 서버 로그에 짧게 남습니다(통상 30일 이내 삭제).
- 이용 목적: 나란 결제 여부를 확인해 Pro 를 여는 것뿐입니다.
4. 권한
- 로컬 네트워크: 집 NAS 나 컴퓨터의 공유 폴더에 연결할 때, 그리고 '컴퓨터에서 보내기(Wi-Fi)' 화면을 연 동안 같은 와이파이의 컴퓨터가 파일을 주고받을 때만 씁니다. 그 주소에는 화면에 보이는 무작위 열쇠가 들어 있고, 화면을 닫으면 멈춥니다.
- 카메라: '카메라 거울'(춤 연습 때 내 모습을 화면에 비춤)과 종이 악보·문서 스캔에만 씁니다. 카메라 화면은 저장하거나 보내지 않고, 스캔은 PDF 로 보관함에만 저장됩니다.
- 마이크: 내 소리를 녹음해 원곡과 비교할 때, 그리고 튜너로 악기 음높이를 잴 때만 씁니다. 녹음은 기기 안에만 있고, 튜너는 소리를 저장하지 않고 그 자리에서 음높이만 잽니다.
- 음성 인식: 자막이 없는 파일을 '받아쓰기'할 때만 씁니다. 인식은 iPhone 안에서만 하고(기기 안 인식만 요청), 소리를 Apple 서버나 비보리랩 서버로 보내지 않습니다. 만든 자막은 보관함에 .srt 파일로 저장됩니다.
- 사진 고르기(가져오기): 사진 앱에서 직접 고른 영상·사진만 보관함으로 복사합니다. 이때는 사진 보관함 전체를 읽지 않습니다.
- 사진(읽기·쓰기): '폰 용량 정리'에서 비슷한 사진·스크린샷·큰 영상을 찾고, 고른 항목을 지우거나 영상을 줄여 새로 저장할 때만 씁니다. 비슷한 사진 판정은 이 iPhone 안에서만 하고, 사진과 판정 결과를 어디로도 보내지 않습니다. 지운 항목은 사진 앱 '최근 삭제된 항목'에 30일 동안 남습니다.
- 사진 추가: 편집한 영상을 사진 앱에 저장할 때 씁니다.
- 미디어 및 Apple Music: '음악 앱에서 가져오기'에서 직접 고른 곡(보호되지 않은 곡)만 보관함에 복사합니다. 음악 보관함 목록이나 재생 기록은 따로 저장하거나 보내지 않습니다. Apple Music 구독 곡은 보호돼 있어 가져올 수 없습니다.
5. 보유 기간과 삭제
- 앱을 지우면 기기 안의 파일과 기록이 함께 지워집니다.
- 앱에서 로그아웃하거나 비보리랩 계정 페이지에서 기기를 끊으면 그 기기의 갱신 키는 더 쓸 수 없습니다. 기기 기록은 계정을 삭제할 때 함께 삭제됩니다.
- 계정 삭제: 앱 설정의 '계정 관리 · 계정 삭제' 또는 auth.vivory.app/account. 요청하면 지체 없이, 늦어도 10일 안에 삭제합니다.
6. 처리 위탁과 국외 이전
개인정보를 판매하거나 광고에 쓰지 않습니다. 로그인한 경우에만 다음 사업자를 거칩니다.
- Apple Inc.(미국): Apple 로그인, App Store 구매
- Google LLC(미국): Google 로그인
- Oracle Cloud(Oracle Corporation): 계정·기기 기록 저장(대한민국 서울 리전)
- Cloudflare, Inc.(미국): 전송·보안(트래픽 경유)
7. 아동
만 14세 미만 아동의 개인정보를 알면서 수집하지 않습니다. 로그인하지 않으면 누구의 개인정보도 받지 않습니다.
8. 이용자의 권리와 문의
열람·정정·삭제·처리정지를 언제든 요청할 수 있습니다. 개인정보 보호책임자: 조제이 대표(비보리랩), contact@vivory.app, 070-8095-9243. 일반 문의: contact@vivory.app. 개인정보침해신고센터(privacy.kisa.or.kr, 국번 없이 118)에서도 상담을 받을 수 있습니다.
9. 변경
이 방침을 바꿀 때는 이 페이지에 시행일과 함께 게시합니다.
Madi Privacy Policy (English)
Effective 2026-10-07. Scope: the Madi iPhone app. The Vivory Lab account itself follows the Vivory Lab Privacy Policy.
1. Summary
Madi is an offline video and music player with practice tools, NAS playback, PDF tools and simple video editing. If you do not sign in, no personal data reaches Vivory Lab ("we"). The app contains no advertising, analytics, tracking or crash reporting SDKs.
2. What stays on your device
- Files in your library (video, music, PDF, edited exports) live in the app's Documents folder, visible in the Files app. They are never uploaded.
- Playback positions, section markers, beat grids, practice records (practice time and repeat counts) and settings are stored only on the device (they may be included in your device backup). Waveforms and beat detection are computed on the device.
- Vocal and accompaniment separation, chords, key and the spectrogram are computed on the iPhone by a model bundled with the app. Separated audio and analysis results stay in the device cache and are never sent to a server. You can delete them in Settings (저장 공간), and iOS may remove them when space runs low.
- Recordings (echo practice and the record button) are m4a files on the device. Record-button takes stay in the library '녹음' folder; echo-practice takes are played back once and then overwritten.
- Section-marker files (.madi) are created only when you tap Share, and handed to the iOS share sheet (boundaries, names and beat only, no audio).
- NAS (SMB) addresses and user names are stored on the device; passwords are stored only in the iPhone Keychain (this device only). Connections stay inside your local network.
- Pro purchases are processed by Apple and checked on the device through the App Store. We never receive your payment method or Apple ID.
3. If you sign in (optional)
Sign-in exists only so that people who already pay for our app Naran can unlock Pro. The app works without it. Sign in uses Sign in with Apple or Google (Vivory Lab account, auth.vivory.app) and never creates a new account.
- Stored on our server: one device record for this app (app name, the SHA-256 hash of a refresh key, a device type label, created and last-checked times, and when it was disconnected). The refresh key itself is not stored.
- With Sign in with Apple, we link the Apple user identifier to the existing account that has the same email verified by Apple.
- Stored on the device: an entitlement token (30 days), the refresh key and the account email, all in the Keychain.
- When online, the app renews the entitlement about once a day at auth.vivory.app. The IP address and time are kept briefly in server logs (normally deleted within 30 days).
- Purpose: only to check whether you pay for Naran and unlock Pro.
4. Permissions
- Local network: only to connect to a NAS or a shared folder on your computer, and while the Wi-Fi transfer screen is open so a computer on the same Wi-Fi can send and receive files. Its address contains a random key shown on screen, and it stops when the screen closes.
- Camera: only for the camera mirror (shows you on screen while you practice dance) and for scanning paper sheet music or documents. The camera view is never saved or sent; scans are saved only as PDFs in your library.
- Microphone: only to record your voice to compare with the original, and for the tuner. Recordings stay on the device; the tuner measures pitch in memory and never stores audio.
- Speech recognition: only when you tap Transcribe (받아쓰기) on a file without subtitles. Recognition runs on the device only (on-device recognition is required); audio is never sent to Apple's servers or to Vivory Lab. The result is saved as an .srt file in your library.
- Photo picking (import): only the videos and photos you pick are copied into the library; this does not read your whole photo library.
- Photos (read and write): only in Phone cleanup (폰 용량 정리), to find similar photos, screenshots and large videos, and to delete the items you choose or save a smaller copy of a video. Similar photos are detected on the device only; photos and results are never sent anywhere. Deleted items stay in the Photos app's Recently Deleted album for 30 days.
- Add to Photos: to save an edited video to the Photos app.
- Media and Apple Music: only the songs you pick in Import from Music (음악 앱에서 가져오기) are copied into the library, and only songs that are not copy-protected. Your music library list and listening history are never stored or sent. Apple Music subscription songs are protected and cannot be imported.
5. Retention and deletion
- Deleting the app removes its files and records from the device.
- Signing out in the app, or disconnecting the device on your Vivory Lab account page, makes that device's refresh key unusable. Device records are deleted together with the account.
- Account deletion: Settings in the app (계정 관리 · 계정 삭제) or auth.vivory.app/account. We delete without delay and within 10 days at the latest.
6. Processors and transfers abroad
We do not sell personal data or use it for advertising. Only when you sign in, data passes through:
- Apple Inc. (USA): Sign in with Apple, App Store purchases
- Google LLC (USA): Sign in with Google
- Oracle Cloud (Oracle Corporation): account and device records (Seoul region, Korea)
- Cloudflare, Inc. (USA): delivery and security (traffic passes through)
7. Children
We do not knowingly collect personal data from children under 14. Without sign-in the app sends no one's personal data.
8. Your rights and contact
You may request access, correction, deletion or suspension of processing at any time. Data protection officer: 조제이 (대표), Vivory Lab, contact@vivory.app, 070-8095-9243. General contact: contact@vivory.app. In Korea you may also contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, dial 118).
9. Changes
Changes are posted on this page with a new effective date.