TabTabHelp 개인정보처리방침
시행일: 2026년 9월 2일 · 운영자: TabTabHelp / Proxima-E · 개인정보·삭제 문의: admin@pc2.kr
TabTabHelp는 가족이 서로 동의한 일시적 원격 도움을 위한 서비스입니다. 이 방침은 앱과 연결 서버에 적용됩니다.
1. 처리하는 정보와 목적
- 기기 등록 정보: 무작위 기기 ID, 역할, 플랫폼, 마지막 접속 시각과 기기 인증 토큰의 비가역 SHA-256 pepper 해시를 Cloudflare D1에 보관합니다. 원본 기기 토큰은 등록 시 앱에 한 번만 전달되며 Worker/D1에는 저장하지 않습니다. 이는 기기 인증, 악용 방지, 연결 상태 확인을 위한 것입니다.
- 푸시 토큰: FCM 등록 토큰을 Cloudflare D1에 보관하고 Firebase Cloud Messaging으로 전달해 도움 요청·상태 변경을 깨우는 알림을 보냅니다. 새 토큰이 등록되면 기존 토큰을 대체합니다.
- 연결 및 세션 메타데이터: 두 기기의 연결 ID, 기기 ID, 자녀가 입력한 표시 이름, Controller 공개키, 연결 생성·해제 시각, 도움 요청 ID·역할·흐름·상태·시각, 세션 ID·상태·만료·종료 사유, 그리고 허용 목록의 감사 이벤트 이름·역할·시각을 Cloudflare D1에 보관합니다. 이는 가족 연결, 매번의 도움 수락, 세션 보안과 운영 점검을 위한 것입니다.
- 선택 전화번호: Controller에 입력한 부모님·자녀 전화번호는 운영체제가 보호하는 로컬 저장소에 보관하며, 사용자가 전화 기능을 선택했을 때 전화 앱을 여는 데 사용합니다. 부모님 번호는 TabTabHelp 서버나 Host로 보내지 않습니다. 자녀 번호는 입력한 경우에만 페어링 키로 종단간 암호화해 Host에 전달하고, Host는 이를 암호화된 로컬 저장소에 보관합니다. Worker/D1은 이때 최대 10분 동안 암호문 봉투만 중계합니다.
- 짧은 수명 보안값: 연결 코드/QR 토큰의 pepper 해시, 일회용 WebSocket 토큰 nonce 해시, 속도 제한용 pepper 해시, 암호화된 키·연결 메타데이터 봉투를 Cloudflare D1에서 처리합니다. 연결 코드와 봉투의 수명은 10분, WebSocket nonce는 2분입니다. 봉투는 정상 수신 시 즉시 삭제됩니다.
- Controller의 종료 알림 로컬 신호: 백그라운드 종료 알림을 누르지 않고 앱으로 돌아와도 안전한 종료 사유를 적용할 수 있도록, Controller 기기의 로컬 저장소 한 칸에 정해진 종료 알림 종류·종료 사유·Worker 종료 시각만 잠시 보관합니다. 기기·연결·요청·세션·토큰 ID와 FCM 원본 추가 필드는 보관하지 않습니다. 앱 시작/복귀 때 한 번 읽고 지우며, 새 세션 전에도 지웁니다. 현재 세션의 서버 생성 시각보다 오래됐거나 35분이 지난 값, 손상된 값과 30초의 허용 오차를 넘는 미래 값은 적용하지 않고 삭제합니다.
2. Controller 앱의 광고 출시 상태·동의 및 비식별 집계
적용 범위: 광고와 아래 광고·사업 지표 처리는 자녀가 사용하는 Controller 앱에만 적용됩니다. 부모님이 사용하는 Host Android 앱에는 Google Mobile Ads SDK와 UMP가 포함되지 않으며, 광고 표시·광고 요청·광고 식별자 접근·광고 성과 또는 광고 분석 이벤트 전송을 전혀 수행하지 않습니다.
iOS 1.0 App Store 출시 상태: 첫 iOS 출시본은 광고 구성을 비활성화했습니다. 이 빌드는 Google UMP나 Mobile Ads SDK를 초기화하지 않고, 광고를 요청·표시하지 않으며, IDFA 등 광고 식별자에 접근하거나 ad_impression, ad_paid, ad_load_failed 이벤트를 전송하지 않습니다. 도움 세션이 끝나면 광고와 무관한 session_completed 비식별 집계만 ad_eligible=0으로 전송할 수 있습니다. 아래 광고 제공 설명은 광고가 명시적으로 활성화된 이후 Controller 버전에만 적용됩니다.
- Google Mobile Ads: 광고가 명시적으로 활성화된 Controller 버전은 홈 배너와 세션 완료 뒤 전면 광고를 표시할 수 있습니다. Google Mobile Ads SDK는 광고 제공·빈도 제어·부정 사용 방지·성과 측정을 위해, 이용 가능한 경우 광고 식별자(예: Android 광고 ID 또는 IDFA)와 기기/앱 정보(운영체제, 기기 모델, 언어, 앱 식별자·버전, IP·네트워크 정보 등)를 처리할 수 있습니다. TabTabHelp Worker, Cloudflare Analytics Engine 또는 D1에는 광고 식별자를 전송하거나 저장하지 않습니다.
- 맞춤형·비맞춤형·제한된 광고: 지역, 적용 법률, Google User Messaging Platform(UMP) 동의 상태, 기기 설정과 광고 제공 가능 여부에 따라 맞춤형 광고, 비맞춤형 광고 또는 제한된 광고가 제공될 수 있습니다. Controller 앱 상단의 개인정보 설정에서 개인정보처리방침을 언제든 확인할 수 있고, UMP가 개인정보 옵션을 요구하는 경우 광고 개인정보 설정을 열어 동의/선택 화면을 다시 표시하고 이용 가능한 선택을 변경하거나 철회할 수 있습니다.
- 광고 수익 측정: Controller 앱은 Google Mobile Ads의
onPaidEvent가 제공하는 광고 위치·형식, 수익 금액(value_micros), 통화 코드, 정밀도와 앱 버전만 허용 목록에 따라 전송합니다. 광고 클릭 URL이나 광고 소재 내용은 전송하지 않습니다. - Cloudflare Analytics Engine 비식별 집계: Controller 앱은 세션 완료 여부·시간 구간·종료 사유·플랫폼·앱 버전·광고 가능 여부와 광고 노출·수익·로드 실패의 허용 목록 필드만
session_completed,ad_impression,ad_paid,ad_load_failed이벤트로 전송합니다. 앱 버전은 보수적인 숫자형 릴리스 버전 또는unknown만, 광고 오류 도메인은 Google Mobile Ads SDK의 고정 허용값 또는unknown만 허용하며 오류 메시지는 전송하지 않습니다. Analytics Engine에는 기기 ID, 이벤트 UUID, 광고 식별자 또는 자유 입력 필드를 넣지 않으며 서비스 품질과 광고 운영을 위한 집계에만 사용합니다. Cloudflare의 현재 Analytics Engine 정책에 따라 이 집계 데이터 포인트는 3개월 동안 보관됩니다. - 중복 방지 메타데이터: 세션 완료 이벤트는 앱에만 저장한 무작위 UUID 네임스페이스와 고엔트로피 로컬 세션 ID에서 결정적 UUIDv5 이벤트 ID를 만들어, 앱 재시작 뒤 같은 완료를 다시 처리해도 같은 ID를 사용합니다. 광고 이벤트 ID는 무작위 UUIDv4입니다. 이 파생에 사용한 네임스페이스와 로컬 세션 ID는 광고·사업 지표의 로컬 전송 대기열, HTTP 요청, D1 중복 방지 행 또는 Analytics Engine에 넣지 않습니다. Controller의 로컬 대기열 wrapper에는 생성 시각만 추가하며 HTTP 전송 전에 제거합니다. 28일이 지난 항목과 시각이 없거나 손상됐거나 비정상적으로 미래인 항목은 전송하지 않고 삭제합니다. Cloudflare D1에는 인증된 기기의 무작위 기기 ID, 앱이 만든 이벤트 UUID와 생성 시각만 30일 동안 보관합니다. 이벤트 종류와 광고·세션 지표 내용은 D1에 저장하지 않으며, Analytics Engine에는 이벤트 UUID도 전달하지 않습니다. 30일이 지난 중복 방지 행은 일일 정리 대상입니다.
광고 또는 비식별 통계 경로로 절대 전송하지 않는 정보: 부모(Host) 기기의 화면 이미지·픽셀, 원격 터치·좌표, 입력 텍스트, 전화번호·표시 이름, FCM 토큰·기기 인증 토큰, 페어링 키·세션 키, 세션 원문 또는 암호화 페이로드를 Google Mobile Ads의 앱 제공 데이터, onPaidEvent 지표 또는 Cloudflare Analytics Engine 이벤트에 넣지 않습니다.
3. 승인된 세션의 화면·창 콘텐츠 접근과 비저장
부모님이 매 도움 세션을 직접 허용한 경우에만, 부모님용 Host Android 앱의 AccessibilityService가 실시간 원격 도움을 위해 화면 스크린샷과 창 콘텐츠에 접근합니다. 화면에 실제로 보이는 경우 이 콘텐츠에는 다음 정보가 포함될 수 있습니다.
- 정확한 위치 또는 대략적인 위치
- 이름, 이메일 주소, 개인 또는 사용자 ID, 주소, 전화번호, 인종 또는 민족, 정치적 또는 종교적 신념, 성적 지향 또는 성 정체성, 그 밖의 개인 정보
- 결제 또는 은행 정보, 구매 내역, 신용 또는 그 밖의 금융 정보
- 건강 또는 피트니스 정보
- 이메일, SMS, MMS 또는 앱 내 메시지
- 사진 또는 동영상, 음성·소리·음악 또는 그 밖의 오디오, 파일 또는 문서, 캘린더, 연락처
- 앱 내 검색 기록, 설치된 앱, 웹 탐색 기록, 기기 또는 그 밖의 ID
이는 화면에 보일 수 있는 정보를 원격으로 표시하기 위한 접근이며, TabTabHelp가 위 항목을 별도 필드로 추출·분류하거나 구조화하여 수집한다는 뜻은 아닙니다. 도움 세션 중 화면/창 콘텐츠는 페어링된 자녀(Controller) 기기로, 원격 탭·스와이프·명령과 비밀번호 입력란이 아닌 텍스트 입력은 부모님 기기로 종단간 암호화되어 전달됩니다. Cloudflare Worker, D1, Durable Object, 감사 이벤트 및 애플리케이션 로그에는 화면·창 콘텐츠, 명령 또는 입력 텍스트의 평문이나 암호문을 저장하지 않습니다. Worker는 암호화된 이진 데이터를 현재 세션의 상대 기기로 중계할 뿐이며, 이 콘텐츠를 광고 또는 분석에 사용하지 않습니다.
비밀번호 입력란은 원격 텍스트 입력 대상으로 허용하지 않습니다. 잠금 화면 및 앱이 보호하는 콘텐츠는 도움 기능이 지원하지 않거나 차단될 수 있습니다. 세션이 끝나면 화면 캡처·표시와 원격 조작이 중단됩니다.
4. 외부 처리자와 전송
- Cloudflare: Worker, D1, Durable Object 및 Analytics Engine 인프라를 제공하는 처리자입니다. 앱과 Worker 사이의 API/소켓 연결은 HTTPS/WSS 전송 암호화를 사용합니다. 세션 화면·명령 데이터는 전송 전 기기에서 종단간 암호화되므로 Cloudflare가 내용을 읽을 수 있도록 보관하지 않습니다. Analytics Engine에는 위 Controller 허용 목록의 비식별 집계 필드만 전송합니다.
- Google Firebase Cloud Messaging: 푸시 알림 처리자입니다. FCM에는 등록 토큰과
type,requestId,pairingId,expiresAt,initiatorRole만 전송하며,session_ended알림에만 정해진 값의endReason(host_user,controller_user,timeout,connection_error,capture_error)을 추가합니다. 이는 앱을 깨우고 최신 상태를 다시 조회하게 하는 비민감 메타데이터이며, FCM data payload에는 자유 입력 문구, 화면·창 콘텐츠, 원격 명령, 입력 텍스트, 전화번호, 표시 이름, 기기 인증 토큰, 세션 ID 또는 페어링 키를 넣지 않습니다. - Google Mobile Ads 및 User Messaging Platform: 광고가 활성화된 Controller 버전에서만 광고 제공, 광고 개인정보 선택과 광고 성과 처리를 담당합니다. iOS 1.0과 Host 앱은 이 처리자에게 광고 요청이나 광고 분석 이벤트를 보내지 않습니다.
5. 보존 및 자동 정리
- 활성 1:1 가족 연결은 사용자가 앱에서 가족 연결 끊기를 선택할 때까지 유지됩니다. 등록 기기 정보에는 현재 자동 삭제 기한이 없으며, 연결 해제 뒤에도 독립 기기 등록 행은 남을 수 있습니다.
- 연결 해제 시 앱은 로컬의 페어링 키·연결 ID·저장된 연락처 등 민감한 페어링 정보를 지우고, 서버는 즉시 연결 관계를 폐기하며 진행 중 세션을 종료하고 임시 봉투를 삭제합니다.
- Controller의 종료 알림 로컬 신호는 앱 시작/복귀 시 소비·삭제되고 새 세션 시작 전에도 삭제됩니다. 앱 데이터 삭제 시에도 함께 지워집니다.
- 만료된 연결 코드·암호화 봉투·WebSocket nonce·속도 제한 행은 매일 정리합니다. 만료 시점부터 다음 일일 정리까지 남을 수 있습니다.
- 종료·거절·만료된 도움/세션 메타데이터와 감사 이벤트는 해당 종료 또는 이벤트 시점부터 30일 후 삭제 대상입니다. 해제된 페어링 메타데이터는 해제 시점부터 30일 후 삭제 대상입니다. 일일 정리 주기 때문에 실제 물리 삭제는 그 다음 정리 실행 시점(통상 최대 약 24시간 추가)일 수 있습니다.
- 광고·사업 지표의 이벤트 종류와 내용은 D1에 저장하지 않습니다. 중복 방지를 위한 기기 ID·이벤트 UUID·생성 시각만 생성 시점부터 30일 후 삭제 대상이며, 일일 정리 주기 때문에 실제 삭제는 통상 최대 약 24시간 추가될 수 있습니다.
- Controller의 광고·사업 지표 로컬 전송 대기열은 각 항목의 로컬 생성 시각부터 최대 28일까지만 재시도하며, 그 뒤에는 서버로 보내지 않고 삭제합니다.
- Cloudflare Workers Logs: 운영 배포는 자동 호출 로그(invocation log)와 trace를 비활성화하고, 코드가 명시적으로 내는 실패·경고 로그만 5% head sampling으로 Cloudflare 대시보드에 보관합니다. 서비스가 기록하는 필드는
level,event, 필요한 경우 API 호출마다 새로 만든 임의의 상관관계용requestId와 제한된reason,role,route,source뿐입니다. 토큰, 기기·연결·도움 요청·세션 ID, 전화번호, 표시 이름, 화면·명령 페이로드, 입력 텍스트 또는 좌표는 넣지 않습니다. Cloudflare는 서비스 제공 과정에서 요청·응답 및 IP·네트워크 메타데이터를 처리할 수 있습니다. 현재 Workers Free 운영 기준 보존 기간은 3일이며, 이 저장소에는 Logpush나 외부 로그 저장 목적지가 구성되어 있지 않습니다.
6. 선택권·삭제 요청·문의
Controller 앱 상단의 개인정보 설정에서 이 방침을 언제든 확인할 수 있습니다. 광고가 활성화된 Controller 버전에서 광고 개인정보 선택을 다시 확인하거나 변경하려면, UMP가 요구할 때 같은 화면에 표시되는 광고 개인정보 설정을 여세요. 표시되는 선택 항목은 지역, 적용 법률과 Google UMP 제공 가능 여부에 따라 다를 수 있습니다. iOS 1.0에는 이 광고 설정이 표시되지 않습니다.
언제든 앱에서 가족 연결을 끊어 원격 도움을 중지할 수 있습니다. 기기 등록 정보, FCM 토큰 또는 남아 있는 서버 메타데이터의 삭제를 요청하거나 이 방침에 문의하려면 운영자 주소 admin@pc2.kr로 이메일을 보내 주세요. 요청에는 인증 토큰, 연결 코드, 화면 내용, 비밀번호를 적지 마세요. 처리 전 요청자 확인에 필요한 최소한의 정보만 안내하며, 확인 가능한 요청은 서버 기록에서 삭제합니다.
7. 방침 변경
처리 목적, 데이터 종류, 처리자 또는 보존 기간이 바뀌면 이 페이지의 시행일을 갱신해 공개합니다.
TabTabHelp Privacy Policy
Effective September 2, 2026 · Operator: TabTabHelp / Proxima-E · Privacy and deletion requests: admin@pc2.kr
TabTabHelp provides temporary, attended remote help between family members. This policy applies to the apps and connection service.
1. Information processed and why
- Device registration: We keep a random device ID, role, platform, last-seen time, and an irreversible SHA-256 pepper hash of the device authentication token in Cloudflare D1 for authentication, abuse prevention, and connection status. The original token is returned to the app once at registration and is not stored by the Worker or D1.
- Push token: We keep the FCM registration token in D1 and send it to Firebase Cloud Messaging to wake the app for help requests and status changes. A newly registered token replaces the previous one.
- Pairing and session metadata: We process pairing, device and request identifiers; the display name entered by the child; the Controller public key; request, session, status, expiry and end-reason metadata; timestamps; and allow-listed audit event names and roles. These records support family pairing, consent for each request, session security, and operational review.
- Optional phone numbers: Phone numbers entered for the parent and child stay in operating-system-protected local storage and are used to open the Phone app when the user chooses a calling feature. The parent's number is not sent to the TabTabHelp service or Host. If a child's number is entered, it is end-to-end encrypted with the pairing key for the Host, which keeps it in encrypted local storage. The Worker and D1 relay only the ciphertext envelope for up to 10 minutes.
- Short-lived security values: Pepper hashes for pairing codes, QR tokens, one-time WebSocket nonces and rate limits, plus encrypted key and pairing metadata envelopes, are processed in D1. Pairing codes and envelopes expire after 10 minutes, WebSocket nonces after 2 minutes, and an envelope is deleted immediately after successful receipt.
- Local termination signal: The Controller briefly keeps only an allow-listed notification type, end reason and Worker end time in one local storage slot so it can apply a safe session end after returning to the app. It excludes device, pairing, request, session and token IDs and is consumed and deleted on app start or resume and before a new session. Invalid, stale or more-than-35-minute-old values are deleted.
2. Controller advertising release state, consent, and aggregated metrics
Advertising and the metrics below apply only to the child's Controller app. The parent's Android Host app does not include Google Mobile Ads or UMP and does not request ads, access advertising identifiers, or send advertising performance or analytics events.
iOS 1.0 App Store release state: Advertising is disabled in the first iOS release. This build does not initialize Google UMP or the Mobile Ads SDK, request or display ads, access IDFA or another advertising identifier, or send ad_impression, ad_paid, or ad_load_failed events. After a help session it may send only the advertising-independent session_completed aggregate with ad_eligible=0. The general advertising description below applies only to a later Controller release in which advertising is explicitly enabled.
- A Controller release with advertising explicitly enabled may show a home banner and an interstitial after a completed session. Google Mobile Ads may process an available advertising identifier, device and app details, language, IP and network information for ad delivery, frequency control, fraud prevention, and measurement. TabTabHelp does not send or store advertising identifiers in its Worker, Analytics Engine, or D1.
- Personalized, non-personalized, or limited ads may be served according to region, applicable law, Google UMP consent, device settings, and availability. The Controller's privacy settings keep this policy available and show Google's privacy-options form when UMP requires it.
- Allow-listed paid-event data is limited to ad placement and format, revenue micros, currency, precision, and app version. Allow-listed Cloudflare Analytics Engine events use bounded session outcome and duration buckets, platform and app version, ad eligibility, impressions, revenue, and load-failure fields for service and ad operations. They contain no device ID, event UUID, advertising identifier, or free text. Under Cloudflare's current Analytics Engine policy, these aggregate data points are retained for three months.
- For duplicate prevention, D1 keeps only the authenticated random device ID, app-generated event UUID, and creation time for 30 days. Metric content and event type are not stored in D1, and the event UUID is not sent to Analytics Engine. The Controller retries queued metrics for no more than 28 days.
Never sent through advertising or aggregate-metrics paths: Host screen images or pixels, remote touches or coordinates, entered text, phone numbers or display names, FCM or device authentication tokens, pairing or session keys, and session plaintext or encrypted payloads.
3. Approved-session access to screen and window content; no server storage
Only when the parent directly approves each help session, the parent Host Android app's AccessibilityService accesses screen screenshots and window content for live remote help. If visibly present on screen, that content can include:
- precise or approximate location;
- name, email address, personal or user IDs, address, phone number, race or ethnicity, political or religious beliefs, sexual orientation or gender identity, and other personal information;
- payment or bank information, purchases, credit or other financial information;
- health or fitness information;
- email, SMS, MMS, or in-app messages;
- photos or videos; voice, sound, music, or other audio; files or documents; calendar; and contacts; and
- in-app search history, installed apps, web browsing history, and device or other IDs.
This is access to display what is visibly on the screen, not extraction, classification, or structured collection of those categories. During the help session, screen and window content is end-to-end encrypted to the paired Controller, while supported remote taps, swipes, commands, and text for non-password fields are end-to-end encrypted to the Host. The Worker relays encrypted binary data only to the other device in the current session. It does not store screen or window content, commands, or entered text in the Worker, D1, Durable Objects, audit events, or application logs, in plaintext or encrypted form, and does not use that content for advertising or analytics.
Remote text entry is not allowed in password fields. Lock screens and app-protected content are unsupported or may be blocked. When the session ends, screen capture/display and remote control stop.
4. Service providers
- Cloudflare provides Workers, D1, Durable Objects, and Analytics Engine. API and socket connections use HTTPS/WSS, and session content is end-to-end encrypted before relay. Analytics Engine receives only the allow-listed aggregate Controller fields described above.
- Google Firebase Cloud Messaging processes registration tokens and bounded data fields used to wake the app and make it fetch current state. Its payload excludes free text, screen content, remote commands, entered text, phone numbers, display names, authentication tokens, session IDs, and pairing keys.
- Google Mobile Ads and User Messaging Platform process ad delivery, advertising privacy choices, and ad performance only in a Controller release with advertising enabled. iOS 1.0 and the Host app make no ad or ad-analytics requests to them.
5. Retention and automatic cleanup
- An active one-to-one family pairing remains until a user chooses to disconnect it. Device registration currently has no automatic expiry and an independent device row may remain after disconnection.
- Disconnecting clears sensitive local pairing information, immediately revokes the server pairing, ends active sessions, and deletes temporary envelopes.
- Expired pairing codes, envelopes, WebSocket nonces, and rate-limit rows are cleaned daily and may remain until the next daily run.
- Ended, declined, or expired help and session metadata and audit events become eligible for deletion after 30 days. Disconnected pairing metadata and metric duplicate-prevention rows also become eligible after 30 days. A daily cleanup can add approximately 24 hours before physical deletion.
- The Controller metric queue retries an item for at most 28 days from its local creation time, then deletes it without sending.
- Cloudflare Workers Logs: Production disables automatic invocation logs and traces. It persists only code-emitted failure and warning logs with 5% head sampling. Service-defined fields are limited to
level,event, and, when needed, a random per-API-invocation correlationrequestIdand boundedreason,role,route, orsource. These messages do not contain tokens, device/pairing/help-request/session IDs, phone numbers, display names, screen or command payloads, entered text, or coordinates. Cloudflare may process request, response, IP, and network metadata to provide the service. On the current Workers Free plan, persisted logs are retained for three days, and this repository configures no Logpush or other external log destination.
6. Choices, deletion requests, and contact
You can review this policy from the Controller's privacy settings. In a Controller release with advertising enabled, you can reopen the advertising privacy form when UMP requires it to change or withdraw available choices. Available choices depend on region, applicable law, and Google UMP availability. iOS 1.0 does not show this advertising setting.
You can disconnect the family pairing in the app at any time. To request deletion of device registration, an FCM token, or remaining server metadata, or to ask about this policy, email the operator at admin@pc2.kr. Do not include an authentication token, pairing code, screen content, or password. We will request only the minimum information needed to verify the request and delete verifiable server records.
7. Policy changes
If purposes, data types, service providers, or retention periods change, we will update the effective date published on this page.