숨런 · SoomRun
Privacy Policy — 2026-09-26
숨런은 로그인 없이 쓸 수 있고, 로그인하지 않으면 아무것도 수집하지 않습니다. 러닝 기록·위치·건강 데이터는 기본적으로 사용자의 기기에만 저장됩니다.
로그인을 선택한 경우에만 러닝 기록과 달린 경로가 백업 목적으로 사용자의 계정에 저장됩니다. 광고 SDK도, 제3자 분석 SDK도 쓰지 않습니다. 앱이 스스로 보내는 진단은 3-1에 하나도 빼지 않고 적어 두었습니다.
SOOM+ 구독의 결제는 Apple이 처리하며, 숨런은 결제 정보를 받지 않습니다.
계정은 선택입니다. 만들지 않아도 앱의 모든 기능이 동일하게 동작합니다. 기기를 바꾸거나 잃었을 때 기록을 되찾기 위한 백업 용도입니다.
로그인 수단은 Apple로 로그인과 Google로 로그인 두 가지입니다.
| 데이터 | 출처 | 목적 |
|---|---|---|
| 계정 식별자 | Apple / Google | 백업을 사용자와 연결 |
| 이메일 주소 | Apple / Google | 계정 식별 |
| 이름 | Apple / Google | 화면에 표시 |
| 데이터 | 목적 | 저장 위치 | 외부 전송 |
|---|---|---|---|
| 위치 (사용 중) | 러닝 경로와 거리 측정 | 기기 | 로그인한 경우에만 계정에 백업 |
| 걸음 수 (동작) | 지하·터널에서 GPS가 끊길 때 거리 추정 | 기기 | 없음 |
| 심박·에너지·케이던스·고도 (Apple 건강) | 러닝 중 지표 표시, 기록 상세 | 기기 | 로그인한 경우에만 계정에 백업 |
| 러닝 기록 | 과거 기록과의 비교("고스트") | 기기 | 로그인한 경우에만 계정에 백업 |
| 수면·심박 변이(HRV)·안정 심박 (Apple 건강, 선택) | 오늘의 준비도 계산 | 기기에서 계산에만 쓰고 저장하지 않음 | 없음 (로그인해도 백업하지 않음) |
| 체중 (Apple 건강) | 소모 열량 추정 | 기기 | 없음 |
SOOM+ 구독의 결제는 전적으로 Apple이 처리합니다.
무료 체험(첫 러닝 후 3주)의 시작 날짜 하나는 기기와 사용자 본인의 iCloud 키-값 저장소에 남습니다. 기기를 바꿔도 체험이 다시 시작되지 않게 하기 위한 것이며, 숨런의 서버로는 가지 않습니다. 그 저장소는 Apple이 사용자의 iCloud 계정 안에서 운영합니다.
앱이 멈추거나 죽으면 Apple이 하루에 한 번 묶어 주는 보고서(MetricKit)를 받아 숨런의 서버로 보냅니다. Apple이 만든 보고서를 그대로 올리므로 죽은 자리(스택)와 빌드 번호뿐 아니라 그 하루의 실행·메모리·네트워크 지표도 함께 들어 있습니다. 기기나 사람과는 잇지 않고, 러닝 기록·위치·건강 데이터는 들어가지 않습니다.
같은 통로로 러닝 한 건의 품질 요약도 보냅니다 — 측위가 몇 건 들어와 몇 건이 버려졌는지, 첫 측위까지 걸린 시간과 정확도 중간값, 신호가 끊겨 있던 시간, 걸음으로 메운 거리의 몫, 위치 권한 상태와 저전력 모드 여부, 폰·워치·불러온 것 중 어디서 온 러닝인지, 목표 도달로 끝났는지 종료 버튼으로 끝났는지, 결과가 난 레이스였는지, 건강 앱 쓰기·동네·날씨 조회가 됐는지 안 됐는지입니다. 거리와 시간은 3-5k·20-40m처럼 구간으로 접어 보냅니다. 좌표는 한 점도, 시각도, 기록 번호도, 동네 이름도, 사용자 식별자도 없습니다 — 어느 러닝인지 특정할 수 없도록 일부러 뺐습니다. 이 요약이 답하려는 질문은 "터널에서 거리가 왜 틀리나" 하나입니다.
같은 통로로 구독 화면의 집계도 보냅니다 — 결제 화면이 열린 횟수와, 연간·월간 중 무엇이 눌렸는지, 결제·취소·닫힘 중 어떤 결과였는지입니다. 여기에는 사용자 식별자도, 기기 식별자도, 두 사건을 같은 사람의 것으로 이을 식별자도 없습니다. 금액·영수증·거래번호도 들어가지 않습니다. 러닝 수는 5-19회 같은 구간으로 접혀 실립니다. 사람이 아니라 화면을 세는 집계입니다.
나 → 도움말 → 진단 보내기를 끄면 한 건도 나가지 않습니다. 기본값은 켜짐입니다. 제3자 분석 SDK나 광고 SDK는 쓰지 않습니다.
숨런은 사용자를 추적하지 않으며, 어떤 데이터도 광고에 사용하지 않습니다.
백업 저장과 로그인 처리를 위해 Google LLC의 Firebase를 사용합니다.
| 서비스 | 역할 | 저장되는 곳 |
|---|---|---|
| Firebase Authentication | 로그인 처리, 계정 식별자 발급 | Google 글로벌 인프라 (리전 선택 불가) |
| Cloud Firestore | 러닝 요약 기록(거리·시간·페이스·전적) | 대한민국 서울 (asia-northeast3) |
| Cloud Storage | 달린 경로(GPS 좌표) | 대한민국 서울 (asia-northeast3) |
러닝 기록과 경로는 국외로 나가지 않습니다. 계정 정보만 국외에 보관되며, 「개인정보 보호법」 제28조의8에 따라 아래와 같이 알려 드립니다.
| 항목 | 내용 |
|---|---|
| 이전받는 자 | Google LLC |
| 이전 국가 | Google 글로벌 인프라 — Firebase Authentication은 저장 리전을 선택할 수 없습니다 |
| 이전 항목 | 계정 식별자, 이메일 주소, 이름 |
| 이전 일시·방법 | 로그인할 때, 암호화된 통신(HTTPS)으로 전송 |
| 보유·이용 기간 | 계정을 삭제할 때까지 |
| 이전 목적 | 로그인 처리와 계정 식별 |
거부 방법
나 → 계정 삭제로 이전된 데이터를 모두 삭제할 수 있습니다.러닝을 마친 뒤 "영수증" 이미지를 만들어 공유할 수 있습니다.
나 → 모든 기록 삭제로 언제든 전부 지울 수 있습니다. 로그인 상태라면 백업된 기록도 함께 지워집니다.나 → 계정 삭제로 계정과 서버에 저장된 모든 기록·경로를 지울 수 있습니다. 이 작업은 되돌릴 수 없습니다.워치에서 단독으로 측정한 러닝은 워치에 저장되었다가 iPhone과 연결될 때 사용자의 기기 사이에서만 전달됩니다. 워치 앱은 직접 네트워크를 사용하지 않습니다. 백업은 iPhone이 로그인 상태일 때만 이루어집니다.
숨런은 만 13세 미만 아동을 대상으로 하지 않으며, 아동의 개인정보를 의도적으로 수집하지 않습니다.
이 방침이 바뀌면 이 페이지의 최종 수정일을 갱신합니다.
숨런은 주식회사 엑스티아이(XTI Co.,Ltd.)가 운영합니다. 개인정보 처리에 관한 업무를 총괄하고 이용자의 문의·불만을 처리하는 책임자는 다음과 같습니다.
개인정보의 열람·정정·삭제·처리정지 요구는 위 연락처로 받으며, 지체 없이 처리합니다. 앱 안의 나 → 모든 기록 삭제와 계정 삭제로 직접 지울 수도 있습니다. 개인정보 침해에 대한 상담·신고는 개인정보침해신고센터(privacy.kisa.or.kr, 국번 없이 118)나 개인정보분쟁조정위원회(www.kopico.go.kr, 1833-6972)에 할 수 있습니다.
manager@x-ti.org
SoomRun works without an account, and if you never sign in, nothing leaves your phone. Your runs, location, and health data stay on your device by default.
Only if you choose to sign in are your runs and the routes you ran stored in your account as a backup. There are no advertising SDKs and no third-party analytics SDKs. Everything the app sends by itself is listed in 3-1, with nothing left out.
Apple handles all payment for SOOM+. SoomRun never sees your payment details.
An account is optional. Every feature works the same without one. Its only purpose is getting your runs back after you change or lose a phone.
You can sign in with Apple or with Google.
| Data | Where it comes from | Why |
|---|---|---|
| Account identifier | Apple / Google | Links the backup to you |
| Email address | Apple / Google | Identifies the account |
| Name | Apple / Google | Shown on screen |
| Data | Purpose | Stored | Sent off device |
|---|---|---|---|
| Location (while in use) | Measuring your route and distance | Your device | Backed up only if you sign in |
| Step count (motion) | Estimating distance when GPS drops in tunnels | Your device | Never |
| Heart rate, energy, cadence, elevation (Apple Health) | Metrics during a run, and in run details | Your device | Only if you sign in, backed up to your account |
| Run history | Comparing against your past runs (the "ghost") | Your device | Backed up only if you sign in |
| Sleep, heart rate variability (HRV), resting heart rate (Apple Health, optional) | Today's readiness | Used on the device for the calculation only, never stored | Never (not backed up even when signed in) |
| Body weight (Apple Health) | Estimating active energy | Your device | Never |
Apple handles all payment for SOOM+.
For the free trial (three weeks from your first finish), a single start date is stored on your device and in your own iCloud key-value store, so that changing devices does not restart the trial. It is never sent to SoomRun. That store is operated by Apple inside your own iCloud account.
When the app stalls or dies, Apple hands over a daily report (MetricKit) and SoomRun sends it to its own server. It goes up as Apple wrote it, so besides the stack trace and the build number it also carries that day's launch, memory and network metrics. It is tied to no device and no person, and carries no runs, no location and no health data.
The same channel carries a quality summary of one run: how many location fixes arrived and how many were thrown away, how long the first fix took and the median accuracy, how long the signal was lost, the share of distance filled in from step count, the location permission state and whether Low Power Mode was on, whether the run came from the phone, the watch or an import, whether it ended by reaching the goal or by the stop button, whether it was a decided race, and whether writing to Health and looking up the neighbourhood and the weather succeeded. Distance and duration are folded into ranges such as 3-5k and 20-40m. No coordinate, no timestamp, no record id, no neighbourhood name, no user identifier — all deliberately left out so that no single run can be picked out of it. The only question it exists to answer is why distance goes wrong in a tunnel.
The same channel carries subscription-screen counts: how often the purchase screen opened, whether the yearly or monthly plan was tapped, and whether it ended in a purchase, a cancellation or a dismissal. It carries no user identifier, no device identifier, and no identifier that could tie two events to the same person. No prices, receipts or transaction numbers. Your number of runs is folded into a range such as 5-19. It counts screens, not people.
Turn it off at Me → Help → Send diagnostics and nothing leaves at all. It is on by default. There is no third-party analytics SDK and no ad SDK.
SoomRun does not track you, and none of your data is ever used for advertising.
SoomRun uses Firebase, operated by Google LLC, to handle sign-in and store backups.
| Service | Role | Where it lives |
|---|---|---|
| Firebase Authentication | Sign-in, account identifiers | Google's global infrastructure (no region choice) |
| Cloud Firestore | Run summaries (distance, time, pace, win–loss) | Seoul, South Korea (asia-northeast3) |
| Cloud Storage | Route coordinates | Seoul, South Korea (asia-northeast3) |
Your runs and routes never leave South Korea. Only account details are held abroad, disclosed here as required by Article 28-8 of the Personal Information Protection Act (PIPA).
| Recipient | Google LLC |
| Country | Google's global infrastructure — Firebase Authentication offers no choice of storage region |
| What is transferred | Account identifier, email address, name |
| When and how | At sign-in, over encrypted HTTPS |
| Retention | Until you delete your account |
| Purpose | Handling sign-in and identifying the account |
How to refuse
Me → Delete account erases everything transferred.After a run you can generate a "receipt" image to share.
Me → Delete all runs erases everything at any time. If you are signed in, the backup is erased along with it.Me → Delete account erases your account and every run and route stored on the server. This cannot be undone.Runs recorded standalone on the watch are stored there and handed to your iPhone when they reconnect — between your own devices only. The watch app uses no network of its own. Backup happens on the iPhone, and only while you are signed in.
SoomRun is not directed at children under 13 and does not knowingly collect their data.
If this policy changes, we update the date at the top of this page.
SoomRun is operated by XTI Co.,Ltd. (주식회사 엑스티아이). The person responsible for personal information handling, and for your questions and complaints, is:
Requests to access, correct, delete or stop processing your data go to the address above and are handled without delay. You can also delete everything yourself in the app, under Me → Delete all runs, and by deleting your account.
manager@x-ti.org