Privacy Policy

Effective 2026-08-11

Routibly works without an account, so there is very little to collect. This page sets out exactly what that “very little” is.

In short
  • No account. We never ask for your email, name, or phone number.
  • Routines, to-dos, evening reflections, and how today felt stay on your device — they are never sent to our server.
  • What reaches our server: your notification token (if notifications are on), routines you choose to share, anonymous signals such as reports and save counts, and comments or likes you leave on the website.
  • No advertising identifiers, and no usage analytics.
  • Everything on your device can be erased at once with “Reset all data” in the app's settings.

1. What this policy covers

The Routibly mobile app (iOS and Android) and the routibly.app website, including the blog and Discover pages.

Operator: 타입쓰리소프트 (Type3 Soft.)

2. There is no account

No sign-in, no email, no phone number, no social login. There is no sign-up step at all.

Instead, the first time the app opens it generates a random value (a UUID) on the device and keeps it in the device's secure storage. It is not there to recognise a person — it confirms that a shared post belongs to this device and lets announcements reach the same device. It is not linked to your name or contact details, and it disappears when you delete the app.

3. What stays on your device

The following is stored only in the app's storage on your device. It is never sent to our server, and we cannot see it.

  • Routines, to-dos, and what you have checked off
  • Evening reflections and how today felt (the mood you pick and your one-line note)
  • The name you go by, your wake time, and other first-run answers
  • App settings such as reminder times, themes, the app icon, and the illustrations you have collected

Evening reflections and one-line notes are never uploaded under any circumstance. Sharing a routine does not carry them along.

Deleting the app deletes all of this with it — unless you have exported a backup file, it cannot be recovered.

4. What is stored on our server

Five things. For each one, here is when it is created and how it goes away.

  • Notification token — while notifications are on, we store your device identifier, the notification token, and your display language. It is used for one thing: sending announcements. We do not record whether you opened or tapped one, and we do not send different notifications based on what you do. Turning notifications off unregisters the token and deletes it from our server.
  • Routines you share to Discover — only routines you actively choose to share. We store the routine's name, its steps and times, the name you want shown, your optional note, whether you agreed to be considered for an Editors' pick, the language you wrote in, and your device identifier so you can take the post down later. Reflections, one-line notes, and moods are not included.
  • Reports — reporting a post in Discover increases that post's report count by one. There is no field for a reason, so nothing but a reference to the post is sent, and no device identifier is attached, so who reported it is not recorded. After three reports a post is hidden automatically and an operator reviews it.
  • Save and view counts — opening or saving a preset or a Discover post increases that item's number by one. The request carries no device identifier and no other content, so the server holds only a per-item total, never who tapped it.
  • Likes and comments on the website's blog — the display name, the comment text, an anonymous visitor value kept in your browser, and a one-way transformation of the connecting IP address used to prevent flooding. The IP address itself is not stored.

Requests the app makes to read content (Editors' picks, presets, announcements, offers) carry no device identifier.

As with any web service, our infrastructure providers may process ordinary connection information such as IP addresses for security and abuse prevention.

5. What never touches our server

  • Day-card image sharing — the card is rendered into an image on your device and goes straight to the system share sheet, your photo library, or another app. It does not pass through our server. We ask for permission only to save into your photo library; we do not read from it.
  • Backup files — the app encrypts a backup on your device with the passphrase you choose (PBKDF2-SHA256, 210,000 iterations, AES-256-GCM) and exports it as a single file. That file lives wherever you save it (Files, a cloud drive, and so on) and is never uploaded to us. The app does not store the passphrase, so if you forget it, we cannot open the file either.

6. What we don't do

  • We do not send usage analytics.
  • We do not use advertising identifiers (IDFA or Advertising ID) — which is why no tracking prompt appears.
  • There are no advertising or analytics SDKs in the app.
  • We do not sell personal information.

7. Processors and international transfers

We rely on the following companies to run the service.

  • Cloudflare, Inc. — hosting for the website and API, and storage for the data described in section 4
  • Expo (650 Industries, Inc.) — issuing notification tokens, delivering announcement notifications, and distributing app updates
  • Apple (APNs) and Google (FCM) — the final leg that delivers a notification to your device
  • RevenueCat, Inc. — checking purchase status for paid features (see section 14); only an anonymous identifier and the store receipt are involved

These providers run on global infrastructure, so the data above may be processed and stored on servers outside your country, including in the United States. The categories and purposes are the same as in section 4, and each provider keeps the data only as long as that purpose requires.

8. Sharing with third parties

We do not sell personal information or hand it to anyone for advertising or marketing. We respond to lawful requests only to the extent required.

The infrastructure in section 7 processes data on our behalf to run the service; that is not third-party sharing.

9. Retention and deletion

  • Notification token — until you turn notifications off, at which point it is deleted immediately. Tokens found to be invalid when we send are removed automatically.
  • Shared routines — until you take the post down, at which point it is deleted. Posts that accumulate reports are hidden first and reviewed.
  • Report counts and save/view counts — they are numbers attached to a post or preset, so they disappear with it. Nothing points to a person, so there is nothing to single out.
  • Blog comments — kept until deleted. Write to us if you would like one removed.
  • Data on your device — until you delete it. We hold no copy.

10. How to delete your data

  • Everything on the device — “Reset all data” in the app's settings clears routines, to-dos, reflections, and settings. The device identifier and the list of posts you shared are kept on purpose, so that you can still find and take down your Discover posts after a reset.
  • A routine you shared — it lives on the server, so a reset does not remove it. Open the post in the Discover tab and delete it, and it is removed from the server — before or after a reset, whenever you like.
  • Announcement notifications — turning notifications off in the app's settings unregisters the token.
  • Deleting the app — removes the on-device data and the device identifier. Posts you already shared are not removed automatically, so take them down first if you want them gone.

If any of this is difficult, write to us. Tell us enough to identify the post and we will take care of it.

11. Your rights

You can ask to access, correct, delete, or restrict processing of your data. Because there is no account, we have limited ways to verify identity, so we identify server-side data by the device identifier or the post itself.

Data on your device is yours to read, edit, and delete directly in the app.

12. Children

The app is not directed at any particular age group and does not ask for your age. We do not knowingly collect personal information from children under the age set by local law (13 in many countries, 14 in Korea). If we learn that such information has reached us, we delete it.

13. How we keep it safe

The strongest safeguard is collecting very little in the first place. Beyond that, traffic is served over HTTPS, backup files are encrypted on your device with your own passphrase, comment IP addresses are stored only as a one-way value, and the admin console is restricted to authorised operators.

14. Payments

Purchases of paid features (Routibly Plus) go through the App Store and Google Play. Payment details such as card numbers are handled by those stores and never reach us.

RevenueCat, Inc. checks your purchase status on our behalf — what is unlocked and until when. It uses an anonymous identifier the app creates and the receipt the store issues; no name or email is involved. This is why reinstalling the app still restores purchases through your store account.

15. Contact and privacy officer

For questions about privacy, or to ask for access or deletion, please write to us. We read what arrives and reply.

  • Privacy officer: 타입쓰리소프트 대표 박태훈
  • Email: support@type3soft.com

16. Where else you can turn

If you are in Korea, you can also consult or file a report with the authority below. You are welcome to write to us first either way.

  • Korea Internet & Security Agency, Privacy Infringement Report Centre — privacy.kisa.or.kr · 118 (within Korea)

17. Business information

The registration number and address are shown as filed in Korean, since that is the form in which they can be looked up.

  • Company: 타입쓰리소프트 (Type3 Soft.)
  • Representative: 박태훈
  • Business registration number: 520-03-03778
  • Address: 서울 강북구 한천로 105길 23 109-1201
  • Email: support@type3soft.com

18. Changes to this policy

If this policy changes, the new version and its effective date are posted on this page. Significant changes are also announced in the app.

Effective date: 2026-08-11

Back to home