TabTabHelp 개인정보처리방침

시행일: 2026년 9월 2일 · 운영자: TabTabHelp / Proxima-E · 개인정보·삭제 문의: admin@pc2.kr

Read in English

TabTabHelp는 가족이 서로 동의한 일시적 원격 도움을 위한 서비스입니다. 이 방침은 앱과 연결 서버에 적용됩니다.

1. 처리하는 정보와 목적

2. Controller 앱의 광고 출시 상태·동의 및 비식별 집계

적용 범위: 광고와 아래 광고·사업 지표 처리는 자녀가 사용하는 Controller 앱에만 적용됩니다. 부모님이 사용하는 Host Android 앱에는 Google Mobile Ads SDK와 UMP가 포함되지 않으며, 광고 표시·광고 요청·광고 식별자 접근·광고 성과 또는 광고 분석 이벤트 전송을 전혀 수행하지 않습니다.

iOS 1.0 App Store 출시 상태: 첫 iOS 출시본은 광고 구성을 비활성화했습니다. 이 빌드는 Google UMP나 Mobile Ads SDK를 초기화하지 않고, 광고를 요청·표시하지 않으며, IDFA 등 광고 식별자에 접근하거나 ad_impression, ad_paid, ad_load_failed 이벤트를 전송하지 않습니다. 도움 세션이 끝나면 광고와 무관한 session_completed 비식별 집계만 ad_eligible=0으로 전송할 수 있습니다. 아래 광고 제공 설명은 광고가 명시적으로 활성화된 이후 Controller 버전에만 적용됩니다.

광고 또는 비식별 통계 경로로 절대 전송하지 않는 정보: 부모(Host) 기기의 화면 이미지·픽셀, 원격 터치·좌표, 입력 텍스트, 전화번호·표시 이름, FCM 토큰·기기 인증 토큰, 페어링 키·세션 키, 세션 원문 또는 암호화 페이로드를 Google Mobile Ads의 앱 제공 데이터, onPaidEvent 지표 또는 Cloudflare Analytics Engine 이벤트에 넣지 않습니다.

3. 승인된 세션의 화면·창 콘텐츠 접근과 비저장

부모님이 매 도움 세션을 직접 허용한 경우에만, 부모님용 Host Android 앱의 AccessibilityService가 실시간 원격 도움을 위해 화면 스크린샷과 창 콘텐츠에 접근합니다. 화면에 실제로 보이는 경우 이 콘텐츠에는 다음 정보가 포함될 수 있습니다.

이는 화면에 보일 수 있는 정보를 원격으로 표시하기 위한 접근이며, TabTabHelp가 위 항목을 별도 필드로 추출·분류하거나 구조화하여 수집한다는 뜻은 아닙니다. 도움 세션 중 화면/창 콘텐츠는 페어링된 자녀(Controller) 기기로, 원격 탭·스와이프·명령과 비밀번호 입력란이 아닌 텍스트 입력은 부모님 기기로 종단간 암호화되어 전달됩니다. Cloudflare Worker, D1, Durable Object, 감사 이벤트 및 애플리케이션 로그에는 화면·창 콘텐츠, 명령 또는 입력 텍스트의 평문이나 암호문을 저장하지 않습니다. Worker는 암호화된 이진 데이터를 현재 세션의 상대 기기로 중계할 뿐이며, 이 콘텐츠를 광고 또는 분석에 사용하지 않습니다.

비밀번호 입력란은 원격 텍스트 입력 대상으로 허용하지 않습니다. 잠금 화면 및 앱이 보호하는 콘텐츠는 도움 기능이 지원하지 않거나 차단될 수 있습니다. 세션이 끝나면 화면 캡처·표시와 원격 조작이 중단됩니다.

4. 외부 처리자와 전송

5. 보존 및 자동 정리

6. 선택권·삭제 요청·문의

Controller 앱 상단의 개인정보 설정에서 이 방침을 언제든 확인할 수 있습니다. 광고가 활성화된 Controller 버전에서 광고 개인정보 선택을 다시 확인하거나 변경하려면, UMP가 요구할 때 같은 화면에 표시되는 광고 개인정보 설정을 여세요. 표시되는 선택 항목은 지역, 적용 법률과 Google UMP 제공 가능 여부에 따라 다를 수 있습니다. iOS 1.0에는 이 광고 설정이 표시되지 않습니다.

언제든 앱에서 가족 연결을 끊어 원격 도움을 중지할 수 있습니다. 기기 등록 정보, FCM 토큰 또는 남아 있는 서버 메타데이터의 삭제를 요청하거나 이 방침에 문의하려면 운영자 주소 admin@pc2.kr로 이메일을 보내 주세요. 요청에는 인증 토큰, 연결 코드, 화면 내용, 비밀번호를 적지 마세요. 처리 전 요청자 확인에 필요한 최소한의 정보만 안내하며, 확인 가능한 요청은 서버 기록에서 삭제합니다.

7. 방침 변경

처리 목적, 데이터 종류, 처리자 또는 보존 기간이 바뀌면 이 페이지의 시행일을 갱신해 공개합니다.

TabTabHelp Privacy Policy

Effective September 2, 2026 · Operator: TabTabHelp / Proxima-E · Privacy and deletion requests: admin@pc2.kr

TabTabHelp provides temporary, attended remote help between family members. This policy applies to the apps and connection service.

1. Information processed and why

  • Device registration: We keep a random device ID, role, platform, last-seen time, and an irreversible SHA-256 pepper hash of the device authentication token in Cloudflare D1 for authentication, abuse prevention, and connection status. The original token is returned to the app once at registration and is not stored by the Worker or D1.
  • Push token: We keep the FCM registration token in D1 and send it to Firebase Cloud Messaging to wake the app for help requests and status changes. A newly registered token replaces the previous one.
  • Pairing and session metadata: We process pairing, device and request identifiers; the display name entered by the child; the Controller public key; request, session, status, expiry and end-reason metadata; timestamps; and allow-listed audit event names and roles. These records support family pairing, consent for each request, session security, and operational review.
  • Optional phone numbers: Phone numbers entered for the parent and child stay in operating-system-protected local storage and are used to open the Phone app when the user chooses a calling feature. The parent's number is not sent to the TabTabHelp service or Host. If a child's number is entered, it is end-to-end encrypted with the pairing key for the Host, which keeps it in encrypted local storage. The Worker and D1 relay only the ciphertext envelope for up to 10 minutes.
  • Short-lived security values: Pepper hashes for pairing codes, QR tokens, one-time WebSocket nonces and rate limits, plus encrypted key and pairing metadata envelopes, are processed in D1. Pairing codes and envelopes expire after 10 minutes, WebSocket nonces after 2 minutes, and an envelope is deleted immediately after successful receipt.
  • Local termination signal: The Controller briefly keeps only an allow-listed notification type, end reason and Worker end time in one local storage slot so it can apply a safe session end after returning to the app. It excludes device, pairing, request, session and token IDs and is consumed and deleted on app start or resume and before a new session. Invalid, stale or more-than-35-minute-old values are deleted.

2. Controller advertising release state, consent, and aggregated metrics

Advertising and the metrics below apply only to the child's Controller app. The parent's Android Host app does not include Google Mobile Ads or UMP and does not request ads, access advertising identifiers, or send advertising performance or analytics events.

iOS 1.0 App Store release state: Advertising is disabled in the first iOS release. This build does not initialize Google UMP or the Mobile Ads SDK, request or display ads, access IDFA or another advertising identifier, or send ad_impression, ad_paid, or ad_load_failed events. After a help session it may send only the advertising-independent session_completed aggregate with ad_eligible=0. The general advertising description below applies only to a later Controller release in which advertising is explicitly enabled.

  • A Controller release with advertising explicitly enabled may show a home banner and an interstitial after a completed session. Google Mobile Ads may process an available advertising identifier, device and app details, language, IP and network information for ad delivery, frequency control, fraud prevention, and measurement. TabTabHelp does not send or store advertising identifiers in its Worker, Analytics Engine, or D1.
  • Personalized, non-personalized, or limited ads may be served according to region, applicable law, Google UMP consent, device settings, and availability. The Controller's privacy settings keep this policy available and show Google's privacy-options form when UMP requires it.
  • Allow-listed paid-event data is limited to ad placement and format, revenue micros, currency, precision, and app version. Allow-listed Cloudflare Analytics Engine events use bounded session outcome and duration buckets, platform and app version, ad eligibility, impressions, revenue, and load-failure fields for service and ad operations. They contain no device ID, event UUID, advertising identifier, or free text. Under Cloudflare's current Analytics Engine policy, these aggregate data points are retained for three months.
  • For duplicate prevention, D1 keeps only the authenticated random device ID, app-generated event UUID, and creation time for 30 days. Metric content and event type are not stored in D1, and the event UUID is not sent to Analytics Engine. The Controller retries queued metrics for no more than 28 days.

Never sent through advertising or aggregate-metrics paths: Host screen images or pixels, remote touches or coordinates, entered text, phone numbers or display names, FCM or device authentication tokens, pairing or session keys, and session plaintext or encrypted payloads.

3. Approved-session access to screen and window content; no server storage

Only when the parent directly approves each help session, the parent Host Android app's AccessibilityService accesses screen screenshots and window content for live remote help. If visibly present on screen, that content can include:

  • precise or approximate location;
  • name, email address, personal or user IDs, address, phone number, race or ethnicity, political or religious beliefs, sexual orientation or gender identity, and other personal information;
  • payment or bank information, purchases, credit or other financial information;
  • health or fitness information;
  • email, SMS, MMS, or in-app messages;
  • photos or videos; voice, sound, music, or other audio; files or documents; calendar; and contacts; and
  • in-app search history, installed apps, web browsing history, and device or other IDs.

This is access to display what is visibly on the screen, not extraction, classification, or structured collection of those categories. During the help session, screen and window content is end-to-end encrypted to the paired Controller, while supported remote taps, swipes, commands, and text for non-password fields are end-to-end encrypted to the Host. The Worker relays encrypted binary data only to the other device in the current session. It does not store screen or window content, commands, or entered text in the Worker, D1, Durable Objects, audit events, or application logs, in plaintext or encrypted form, and does not use that content for advertising or analytics.

Remote text entry is not allowed in password fields. Lock screens and app-protected content are unsupported or may be blocked. When the session ends, screen capture/display and remote control stop.

4. Service providers

  • Cloudflare provides Workers, D1, Durable Objects, and Analytics Engine. API and socket connections use HTTPS/WSS, and session content is end-to-end encrypted before relay. Analytics Engine receives only the allow-listed aggregate Controller fields described above.
  • Google Firebase Cloud Messaging processes registration tokens and bounded data fields used to wake the app and make it fetch current state. Its payload excludes free text, screen content, remote commands, entered text, phone numbers, display names, authentication tokens, session IDs, and pairing keys.
  • Google Mobile Ads and User Messaging Platform process ad delivery, advertising privacy choices, and ad performance only in a Controller release with advertising enabled. iOS 1.0 and the Host app make no ad or ad-analytics requests to them.

5. Retention and automatic cleanup

  • An active one-to-one family pairing remains until a user chooses to disconnect it. Device registration currently has no automatic expiry and an independent device row may remain after disconnection.
  • Disconnecting clears sensitive local pairing information, immediately revokes the server pairing, ends active sessions, and deletes temporary envelopes.
  • Expired pairing codes, envelopes, WebSocket nonces, and rate-limit rows are cleaned daily and may remain until the next daily run.
  • Ended, declined, or expired help and session metadata and audit events become eligible for deletion after 30 days. Disconnected pairing metadata and metric duplicate-prevention rows also become eligible after 30 days. A daily cleanup can add approximately 24 hours before physical deletion.
  • The Controller metric queue retries an item for at most 28 days from its local creation time, then deletes it without sending.
  • Cloudflare Workers Logs: Production disables automatic invocation logs and traces. It persists only code-emitted failure and warning logs with 5% head sampling. Service-defined fields are limited to level, event, and, when needed, a random per-API-invocation correlation requestId and bounded reason, role, route, or source. These messages do not contain tokens, device/pairing/help-request/session IDs, phone numbers, display names, screen or command payloads, entered text, or coordinates. Cloudflare may process request, response, IP, and network metadata to provide the service. On the current Workers Free plan, persisted logs are retained for three days, and this repository configures no Logpush or other external log destination.

6. Choices, deletion requests, and contact

You can review this policy from the Controller's privacy settings. In a Controller release with advertising enabled, you can reopen the advertising privacy form when UMP requires it to change or withdraw available choices. Available choices depend on region, applicable law, and Google UMP availability. iOS 1.0 does not show this advertising setting.

You can disconnect the family pairing in the app at any time. To request deletion of device registration, an FCM token, or remaining server metadata, or to ask about this policy, email the operator at admin@pc2.kr. Do not include an authentication token, pairing code, screen content, or password. We will request only the minimum information needed to verify the request and delete verifiable server records.

7. Policy changes

If purposes, data types, service providers, or retention periods change, we will update the effective date published on this page.