Privacy Policy

Effective 18 August 2026 · version 2.0
This English text is a convenience translation of the Korean original. Where the two differ, the Korean version governs.

Sprout Grow Labs (CEO: Kim Eunhee, the "Company") complies with the Korean Personal Information Protection Act and other applicable law, and publishes this Privacy Policy so that users' personal data is handled safely.

🍡 In short — Mallang does not sell advertising and does not sell personal data. Your device calendar, reminders, health data and lock screen photos never leave your device, and what friends see is only what you chose to share. Delete your account and everything is erased immediately.

1. What we collect and how

We collect only the minimum needed to run the Service — what you enter, and what is generated automatically as you use it. Items without a marker are required; items marked "(optional)" can be declined without losing access to the Service.

CategoryItemsWhen collected
Social sign-insocial account identifier, name (nickname), email (where provided)on Apple or Google sign-in (Kakao coming soon)
Guestthe name (nickname) you enterwhen you start as a guest — stored on the device only
Optional profile (optional)gender, birthday (month and day)if you enter it on the start screen (skippable)
Service useroutines (name, icon, schedule, records) and streaks; focus session records (category, time, break tags); events, to-dos and timetables you enter; Mallangotchi (name, stage, vigor, dango gifts, pokes); guestbook notes, replies and reactions; Discover posts, grabs and reports; invite codes and connections (couple, friend, family); block lists; character, theme and lock screen settings; D-Dayin the course of using the Service
Proof photos (optional)photos you take or choosewhen you attach a proof photo to a routine (camera permission)
Device and notificationspush device token, OS, app version, error logson app launch and when you allow notifications
Usage analyticsusage events (screen views, whether and roughly how often features are used), member identifier, sign-in method, gender and birth year (if entered), device, app and OS information, IP address and approximate regionin the course of using the app (Amplitude — see section 7)
Health data (optional)step count, exercise minutes, sleep, water intake, mindful minutesif you separately consent to Apple Health / Health Connect integration
Device calendar and reminders (optional)titles, times and calendar names of events and reminders stored on your deviceif you turn on calendar sync and allow permission — read-only
Saving photos (optional)none (the save permission only)when you save a lock screen wallpaper you made to Photos

We do not collect resident registration numbers, card or bank details, or any other payment information. Mallang is entirely free and has no in-app purchases. We do not collect the advertising identifier (IDFA), do not request App Tracking Transparency consent, and do not track users across other companies' apps or websites.

2. Information processed only on your device

The following is processed entirely on your device and never sent to our servers.

🍡 Health data gets special treatment. Health data is used solely to decide whether a routine finished itself. It is never used for advertising or analytics, never shared with third parties and never stored on our servers. You can withdraw the integration at any time in your device settings, and processing stops immediately when you do.

3. Why we use it

4. What other users can see

Mallang is used together with other people, so some information is shown to them. The table below sets out exactly what — this is not the same as the Company providing personal data to third parties.

WhereWhat is shownWho sees it
Friend home and guestbookname, character, the completion status and streak of routines you chose to share, guestbook notes, replies and reactions, proof photos on shared routines, and your Mallangotchi (name, stage, vigor)connections you accepted (couple, friend, family)
Study roomsnickname (can be turned off), character and stage, focusing/resting status, total focus time todayothers in the same room — account identifiers are never exposed
Study statsthe last 62 days of study timer records — daily focus time, start and end times to the minute, break time and what you focused on (routine or subject name). Gym and general timer records are not included.connections you accepted, and others in the same study room — account identifiers are never exposed
Discover (shared routines)the name and setup of routines you chose to share, and the author's name (anonymous is an option), a streak summary and how many people grabbed itall users — posted after the Company approves it

5. How long we keep it

  1. Personal data is destroyed without delay when you delete your account. Running [My → Delete account] deletes your original proof photos first, then the account, and the linked profile, backups, shared routines, guestbook, connections (including the other side's list), notifications, push tokens, Mallangotchi and focus records are deleted immediately in cascade. There is no grace period.
  2. Signing up again with the same social account issues a new member identifier; previous records are not restored.
  3. Notes you left on other users' homes remain with the author information removed (shown as "deleted user").
  4. Usage events may remain in the analytics tool in aggregate, non-identifying form; even then, the link to your member identifier is severed when you delete your account. You can request deletion at the contact in section 9.
  5. Where law requires retention, we keep the data for that period (for example, three years for consumer complaint and dispute records under the Korean Act on Consumer Protection in Electronic Commerce).

6. Providing data to third parties

We do not provide or sell users' personal data to third parties. Information is shown to other users according to the audience you chose, as set out in section 4. Lawful requests grounded in legislation are an exception.

7. Processing on our behalf and overseas transfer

We entrust processing to the parties below to run the Service. Where a processor is located overseas, we disclose the following under Article 28-8 of the Korean Personal Information Protection Act. Transfer happens automatically over the network as you use the Service.

ProcessorWork entrusted and items transferredCountryRetention
Supabase, Inc.
(Supabase)
database, authentication and storage — everything stored on our servers per section 1 (credentials, profile, record backups, social data, proof photos)Republic of Korea (Seoul region)until you delete your account
Amplitude, Inc.
(Amplitude)
usage analytics — member identifier, usage events, gender and birth year (if entered), device, app and OS information, IP addressUnited Statesthe period set in the processing agreement, from the date of collection
Apple Inc. (APNs)
Google LLC (FCM)
push notification delivery — device token, notification title and bodyUnited Statesas long as delivery requires

You may refuse overseas transfer. To refuse the analytics transfer (Amplitude), write to the privacy officer at mallang-privacy@sproutgrowlabs.com and we will act without delay; refusing does not limit your use of the Service. Database and authentication (Supabase) and push delivery are, however, essential to providing the Service, so refusing those may limit the relevant features or membership.

Processing agreements require compliance with data protection law, prohibit processing beyond the stated purpose, restrict sub-processing and mandate safeguards; we supervise accordingly. Any change of processor is disclosed in this policy.

8. Children under 14

Children under 14 may use the Service only with a legal guardian's consent. Where we learn that data belongs to a child, we verify guardian consent and, if it cannot be confirmed, destroy the data without delay.

9. Your rights

10. Destruction of personal data

Personal data is destroyed without delay once its retention period has passed or its purpose has been fulfilled. Electronic files are deleted irrecoverably; printed material is shredded or incinerated.

11. Security measures

12. Privacy officer

CategoryDetails
Privacy officerKim Eunhee (CEO)
Contactmallang-privacy@sproutgrowlabs.com

You can report or seek advice on privacy infringement from the Korea Internet & Security Agency's Privacy Infringement Report Centre (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).

13. Changes to this policy

If this policy is added to, removed from or amended, we announce it in the app's notices and on this page from 7 days before it takes effect (30 days for changes material to users' rights).

Revision history

Addendum

This policy (version 2.0) takes effect on 18 August 2026 and replaces the previous policy (version 1.0, effective 23 July 2026).