Effective Date: May 18, 2026
Article 1. Information We Collect
Zeph collects the minimum information necessary to provide the service.
1. Account Information
- Email address and name (via Google OAuth or Apple Sign-In)
- Profile photo (optional, provided by OAuth provider)
2. Device Information
- Device type (iOS, Android, Chrome, etc.)
- Device nickname and model
- App version
- Push notification token (for delivery)
3. Service Data
- Push messages (encrypted for Pro users, plaintext for Free users)
- Files (uploaded via pre-signed URLs to S3)
- Encryption keys (stored on server for cross-device sync)
- Subscription and quota usage data
Article 2. What We Do NOT Collect
Zeph does not collect or store:
- IP addresses
- Access logs or browsing history
- Location data
- Analytics or tracking data
- Advertising identifiers
Article 3. Purpose of Use
Collected information is used solely for:
- User authentication
- Device-to-device data delivery
- Push notification delivery (FCM/APNs)
- Subscription management
- Service operation and issue resolution
Article 4. Retention and Deletion
Your data is retained while your account is active. Upon account deletion, all data is permanently destroyed.
Exceptions required by law:
- Transaction records: 5 years (Electronic Commerce Act)
- Consumer dispute records: 3 years (Electronic Commerce Act)
Article 5. Third-Party Disclosure
Zeph does not share your personal information with third parties.
Exceptions:
- When you have given explicit consent
- When required by law or legal process
Article 6. Cookies
Zeph uses essential cookies for authentication and local storage for user preferences (theme, language). No third-party tracking or advertising cookies are used.
Article 7. International Data Transfer
Your data may be processed on AWS infrastructure located outside your country. All data in transit is protected by TLS 1.3.
Article 8. Security
- Push content encryption: AES-256-GCM (Pro tier)
- Encryption keys are stored on the server for cross-device synchronization
- All API communication: TLS 1.3
- Access tokens: JWT with 15-minute expiry
- API keys: SHA-256 hashed before storage
Article 9. Children
Zeph is not intended for children under 14. Contact app@lemoncloud.io if you believe a child has provided personal information.
Article 10. Your Rights
You may view, correct, or delete your personal information at any time through in-app settings.
Contact: app@lemoncloud.io
Article 11. Changes
This policy may be updated for legal or service changes. We will notify you in advance through the app or email.