Sign In

Privacy Policy

Last Updated: July 8, 2026
Marux (the "Company") operates the SuperAlarm application and related services (collectively, the "Service") and takes your privacy seriously. This Privacy Policy explains what information the Company processes, why and for how long it processes that information, with whom the information may be shared or to whom its processing may be entrusted, and what rights you may exercise regarding your personal information.
The Company primarily administers this Policy in accordance with the Personal Information Protection Act of the Republic of Korea. Where privacy laws in your place of residence apply, the Company provides the rights and safeguards required by those laws.

1. Data Controller

β€’
Operator: Marux
β€’
Address: 602-A51, 150 Jungdae-ro, Songpa-gu, Seoul 05828, Republic of Korea
β€’

2. Information We Process

The Company may process the following information to the extent necessary to provide the Service. The information actually processed may vary depending on your device settings, consent choices, features used, and region.
Category
Information That May Be Processed
How It Is Collected
App and device information
Device model, operating system and app version, language and country settings, time zone, screen and network status, app instance or installation identifiers
Automatically generated and collected while you use the Service
Service usage information
App launches, screen views, button selections, alarm settings and feature usage, session information, acquisition and campaign information
Automatically generated and collected while you use the Service
Account and service identifiers
Anonymous user identifier, push notification token, subscription status, and purchase-related identifiers
Generated while providing the Service or collected through an app marketplace or service provider
Diagnostic and error information
Crash records, error messages, time of error and app state, device and operating system information, performance information, and diagnostic logs
Automatically submitted to identify bugs and improve Service stability
Advertising information
Advertising identifiers (such as IDFA, where permitted by you), device and app information, ad impressions, clicks and conversions, and approximate location or network-derived country and region information
Automatically collected through advertising SDKs based on your consent and device settings
Customer support information
Email address, inquiry details, images, videos or files you attach, support history, and logs submitted for troubleshooting
Provided when you use customer support
Network information
IP address, access time, request records, and security logs
Automatically generated and collected through servers or external services
As a rule, the Company does not ask you to submit government-issued identification numbers, passport numbers, financial account passwords, or other unique identifiers or sensitive information. Please do not include unnecessary personal information or another person's personal information in customer support inquiries or attachments.

3. Device Permissions and On-Device Processing

Device features or permissions such as notifications, camera and depth-sensing capabilities, biometric authentication, motion and fitness, microphone, photos and media, and location may be required to provide alarm and mission features. The permissions requested depend on the features you choose and your device environment.
β€’
The Company explains the purpose of a permission when it is needed and follows the device operating system's permission request process.
β€’
You may change or withdraw permissions at any time in your device settings. However, related features may not work properly if a required permission is not granted.
β€’
To the extent possible, raw sensor, camera, biometric, and media information generated while you complete alarms and missions is processed in real time on your device. The Company does not store raw information that is unnecessary for the relevant feature on its servers or use it to identify you.
β€’
If you submit images or videos during customer support, or if diagnostic logs are submitted automatically, those materials may be transmitted to and processed on servers for troubleshooting.

4. Purposes and Legal Bases for Processing

The Company processes personal information for the following purposes and on the following legal bases. If the law in a particular region requires a different legal basis, that law will apply.
Purpose
Main Information Processed
Examples of Legal Bases
Providing alarms, missions, push notifications, and core features
App and device information, anonymous user identifier, push token, feature usage information
Performance of a contract or provision of the Service at your request
Verifying subscription status and providing paid features
Purchase and subscription identifiers, anonymous user identifier
Performance of a contract
Receiving customer inquiries and resolving issues
Email address, inquiry details and attachments, support history, diagnostic logs
Performance of a contract, your request, or the Company's legitimate interests
Detecting errors, maintaining security, preventing abuse, and improving quality
Crash, error and performance information, diagnostic logs, network information
Legitimate interests in Service stability and security, or compliance with legal obligations
Analyzing usage and improving the product
App and device information, Service usage information, analytics identifiers
Your consent or legitimate interests in de-identified and minimized analytics
Providing advertising, measuring ad performance, and optimizing campaigns
Advertising identifiers, ad interaction and conversion information, app and device information
Your prior consent where required
Complying with legal obligations and handling disputes
Relevant usage, support, and transaction records
Compliance with legal obligations and the establishment, exercise, or defense of legal claims

5. External Services and Processing Providers

The Company may use the following third-party tools and infrastructure to operate the Service. Each provider may act as a processor handling information on the Company's instructions or as an independent controller for certain processing.
Provider / Service
Purpose
Information That May Be Processed
Google Firebase Authentication
Anonymous user identification and Service connection
Anonymous user identifier, app and device information, access information
Google Firebase Cloud Messaging
Sending push notifications
Push token, anonymous user identifier, app and device information
Google Firebase Analytics
Service usage analysis and improvement
App instance identifier, app and device information, usage events, approximate regional information
Google Firebase Crashlytics
Crash and error analysis and stability improvements
Crash records, diagnostic logs, app, device, and operating system information
Google Firebase databases and storage
Storing customer support and Service data
Inquiry details, attachments, anonymous user identifier, and related Service information
PostHog
Service usage analysis and product improvement
Analytics identifier, app and device information, usage events, and session information
RevenueCat
Subscription status management and purchase analytics
Anonymous user identifier, purchase and subscription information, app and device information, attribution information
Apple App Store / Google Play
Payment processing and subscription provision
Payment and subscription information and information associated with your app marketplace account
Google AdMob
Advertising, frequency management, ad fraud prevention, and performance measurement
Advertising identifier, IP address, app and device information, ad interaction information, approximate regional information
Meta Ads
Advertising campaign measurement, attribution, and optimization
Advertising identifier, app and device information, app events, ad click, install, and conversion information
Information processed by an external provider for its own purposes and under its own responsibility may be subject to that provider's privacy policy. For more information, please see:
The Company maintains this list based on the tools and configurations actually included in the app and updates this Policy when there is a material change to a processing provider.

6. Advertising and Disclosure to Third Parties

The Company may use tools related to Google AdMob and Meta Ads to provide ads or measure ad impressions, clicks, installs, and conversions.
β€’
Where legal consent or device operating system permission is required to access an advertising identifier or track activity, the Company completes that process first.
β€’
Contextual or non-personalized ads may still be displayed if you do not permit tracking or consent to personalized advertising.
β€’
You may change advertising choices through iOS privacy and tracking settings, Google ad settings, or Meta ad settings. Additional opt-out requests may be submitted through customer support.
β€’
The Company does not sell your personal information for monetary consideration. However, some regional laws may broadly define the provision of identifiers for personalized advertising as "sharing" or "targeted advertising." Users in those regions may exercise the right to opt out as described in Section 10.
The Company may disclose information only to the extent necessary in the following circumstances:
1.
When you have consented in advance
2.
When disclosure is required by law or necessary to respond to a public authority's request made through lawful procedures
3.
In connection with a merger, acquisition, asset transfer, or other business transfer; in such cases, the Company will provide prior notice or implement required safeguards in accordance with applicable law
4.
When legally permitted to prevent an imminent threat to life, physical safety, or property

7. International Data Transfers

The Service is offered globally, and the servers of the Company and its external service providers may be located outside your country of residence. Accordingly, personal information may be processed in the Republic of Korea, the United States, European Union member states, and other countries where external providers operate.
Recipient
Destination Country / Region
Information Transferred and Purpose
Timing and Method
Retention Period
Google Cloud
United States, Republic of Korea, Singapore, and locations of processing facilities
Authentication, notification, analytics, error diagnostics, storage, and advertising information described in Section 5
Transmitted over encrypted networks when you use the Service
Period determined by Company settings, contracts, and provider policies
PostHog
United States and locations of processing facilities
Analytics identifier, usage events, app and device information / product analytics
Transmitted over encrypted networks when you use the Service
Up to one year or a shorter period under Company settings
RevenueCat
United States and locations of processing facilities
Anonymous user identifier, purchase, subscription, and attribution information / subscription management
Encrypted transmission when verifying purchases and using the Service
Period required by Company settings, contracts, and legal obligations
Meta
United States and locations of Meta processing facilities
Advertising identifier, app events, and ad performance information / ad measurement and optimization
Encrypted transmission while using the Service, based on consent and settings
Period determined by Meta policies and user settings
Apple / Google Play
United States and locations of each provider's processing facilities
Purchase and subscription information / payment and subscription processing
Transmitted through the relevant app marketplace at the time of purchase
Period required by each provider's policies and legal obligations
Where international transfers apply, the Company uses contractual safeguards, standard contractual clauses, adequacy decisions, certification mechanisms, and other transfer mechanisms recognized under applicable law. Personal information of users in Europe is not necessarily required to remain exclusively on servers in Europe. When it is transferred outside Europe, the Company implements a lawful transfer basis and safeguards required by the GDPR and other applicable laws.
If you do not agree to an international transfer, you may ask customer support to opt out of processing related to optional analytics or personalized advertising. However, restricting processing necessary for push notifications, subscription verification, security, or error response may make certain features unavailable.

8. Retention Periods

The Company retains personal information only for as long as necessary to fulfill the purposes of processing. As a rule, personal information managed directly by the Company is deleted or anonymized within a maximum of one year from the date of collection or last use. It may be deleted sooner if the purpose is fulfilled earlier or if you make a valid deletion request.
Information Type
Standard Retention Period
Analytics events and identifiers
Up to one year from collection
Automatically submitted crash, error, and diagnostic logs
Up to one year from collection
Customer support inquiries, attachments, and support history
Up to one year after the inquiry is resolved
Push tokens and Service connection identifiers
For the Service provision period or up to one year after last use
Advertising performance and attribution information managed by the Company
Up to one year from collection
Raw sensor and media information processed on-device for alarm and mission features
Not stored on servers as a rule and not retained after real-time on-device processing
Only the information necessary may be retained beyond the periods above in the following circumstances:
β€’
When applicable law requires retention for a specified period
β€’
When necessary to investigate fraud, a security incident, or a dispute, or to establish, exercise, or defend legal claims
β€’
When you have expressly consented to further retention
β€’
When an external provider retains information as an independent controller under its own legal obligations and policies
The retention periods above may not apply to anonymized statistical information that cannot identify a particular user.

9. Deletion of Personal Information

When a retention period expires or the purpose of processing is fulfilled, personal information is deleted or anonymized without undue delay using methods that make recovery difficult.
β€’
Electronic files are deleted using secure procedures designed to make recovery difficult.
β€’
Paper documents, if any, are shredded or otherwise disposed of securely.
β€’
Information remaining in backups is deleted according to the applicable backup rotation cycle. Until then, access is restricted so the information is not used for purposes other than recovery.
β€’
Information that must be retained by law is separated from other information and used only for the legally required purpose.

10. Your Rights and How to Exercise Them

Depending on applicable law, you may request:
β€’
Confirmation of whether and how your personal information is processed, and access to that information
β€’
Correction or completion of inaccurate personal information
β€’
Deletion of personal information
β€’
Suspension or restriction of processing
β€’
Withdrawal of consent
β€’
Objection to processing
β€’
Receipt of personal information in a structured, commonly used format or transfer of that information to another provider
β€’
Opt-out of the sale or sharing of personal information for personalized advertising or of targeted advertising
β€’
Appeal of a refusal to act on a rights request
You may exercise your rights through in-app customer support or by contacting team@superalarm.me. Deletion requests may be submitted in the same way. The Company may request the minimum information necessary to verify your identity and will notify you of the outcome within the period required by applicable law.
If a legal guardian or duly authorized agent submits a request, the Company may ask for documentation verifying that person's authority. A request may be restricted in whole or in part when there is a legitimate reason, such as a statutory retention obligation, protection of another person's rights, or response to a legal claim. The Company will explain the reason for the restriction.

11. Automatic Collection Technologies and Your Choices

The Service may use app instance identifiers, SDKs, advertising identifiers, and similar technologies to understand app operation and usage.
β€’
Analytics: Firebase Analytics and PostHog are used to analyze feature usage and Service performance.
β€’
Error diagnostics: Diagnostic logs and crash information are automatically submitted to collect bugs and improve Service stability.
β€’
Advertising: Tools related to Google AdMob and Meta Ads may process information to provide ads and measure performance.
β€’
Device settings: You may change tracking permissions, advertising identifier settings, notifications, and other permission settings on your device.
β€’
Customer support requests: You may ask customer support to opt out of or change choices related to analytics and personalized advertising processing.
Processing necessary for security, abuse prevention, subscription verification, Service operation, and error diagnostics may continue. Changes apply to future processing and may not apply retroactively to information that was already lawfully processed.

12. Children's Privacy

The Service is not generally designed for children under 14, and the Company does not knowingly collect personal information from children under 14 without consent from a legal guardian. If a higher age threshold applies in your region, the Company follows that threshold.
If you are a parent or guardian and believe that a child has provided personal information without appropriate consent, please contact team@superalarm.me. After reviewing the matter, the Company will delete the information or take other protective measures as required by applicable law.

13. Security Measures

The Company implements reasonable safeguards in light of its size, the nature of the information processed, and the level of risk.
β€’
Technical safeguards such as encryption in transit
β€’
Data access minimization and access controls
β€’
Reasonable separation of production and development environments
β€’
Security updates and vulnerability response
β€’
Monitoring of errors and abnormal access
β€’
Review of privacy and security practices when selecting external processors
β€’
Confidentiality and internal controls for personnel who handle personal information
No method of transmission over the internet or electronic storage can be guaranteed to be completely secure. If a security incident occurs, the Company will investigate its impact and provide required notices and response measures in accordance with applicable law.

14. Additional Regional Notices

14.1 Republic of Korea

Users in the Republic of Korea may exercise rights under the Personal Information Protection Act, including access, correction, deletion, suspension of processing, and withdrawal of consent. For consultation or remedies concerning a privacy violation, you may contact:
β€’
Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 (without an area code in Korea)

14.2 European Economic Area and United Kingdom

Users in the EEA and United Kingdom may have rights under the GDPR or UK GDPR, including access, correction, deletion, restriction of processing, portability, withdrawal of consent, and objection to processing based on legitimate interests. You may also lodge a complaint with the supervisory authority in your country of residence.
The Company reviews the exceptions and designation requirements applicable to small organizations and will add information about a legally required point of contact to this Policy where applicable.

14.3 United States

Users in certain U.S. states may have rights under applicable state law to confirm and access, correct, delete, or obtain a copy of personal information; opt out of targeted advertising or the sale or sharing of personal information; and appeal the outcome of a request. The Company will not discriminate against you in a manner prohibited by law because you exercise your rights.
The Company does not sell personal information for monetary consideration. If limited disclosure through advertising SDKs constitutes a "sale," "sharing," or "targeted advertising" under certain state laws, you may opt out through customer support.

15. Changes to This Privacy Policy

The Company may revise this Policy to reflect changes in law, Service features, or personal information processing practices. If a material change is made, the Company will provide notice before it takes effect through an in-app notice, website, or another reasonable method. If additional consent is required, the Company will obtain it using the procedures required by applicable law.
You can identify the latest version by the "Last Updated" date at the top of this document.

16. Contact Us

For questions about personal information processing, rights requests, deletion requests, or this Policy, please contact us through:
β€’
β€’
In-app: Customer Support
β€’
Address: 602-A51, 150 Jungdae-ro, Songpa-gu, Seoul 05828, Republic of Korea
The Company will make reasonable efforts to review your inquiry and respond within the period required by applicable law.