Overwater Privacy Policy
Version: 2.6 | Effective: on the app's initial release date
Overwater's primary service region is the Republic of Korea. The app also works from locations outside Korea, in which case it communicates with the non-Korean weather and weather-alert services listed below.
Core principles — Overwater collects only the minimum necessary
Overwater does not require sign-up. The app runs on an anonymous device identifier (Device ID). User content such as your to-dos and notes is stored locally on your device.
The app does not collect photos. There is no feature that sends a photo to our servers, and we do not request photo-library access.
The light meter uses the camera as a brightness sensor. The captured image is used only to compute brightness; it is never stored or transmitted.
The Today tab displays weather data and rule-based lifestyle guidance. It does not use Google Vertex AI to generate Today text, and the current app does not collect, store, or use demographic choices to personalize it.
Read-aloud audio is synthesized on your device. Brief text is never transmitted externally for voice synthesis.
AI text generation is used only for plant Wiki entries. A plant's scientific name is forwarded, and it does not include anything that identifies you.
Location data is used for weather and air-quality lookups. Forecasts are passed to Apple WeatherKit (United States) with met.no (Norway) as a fallback; Korean short-term forecasts, current conditions, and weather alerts go to the Korea Meteorological Administration public data portal; air quality goes to Korea Environment Corporation AirKorea; and (for US locations) weather alerts go to the NWS weather-alert API (api.weather.gov, NOAA, United States). The KMA transfer uses grid cell numbers rather than raw coordinates, and the AirKorea transfer uses monitoring-station names rather than coordinates. Air quality is provided only for locations in Korea. If the air-quality provider is switched to the Google Air Quality API (United States) — for example during an AirKorea outage — location coordinates are forwarded to that vendor, and we will state the switch in this policy.
Your current location's coordinates are not stored on our servers. However, an "additional location" you register yourself on the Today tab is stored in your anonymous profile as its name, coordinates, and country code, and is deleted when you delete it.
Crash and diagnostic data is sent to Sentry for app stability. No personally identifying information is collected by default.
There are no ads in the app today, and we collect no personal information for advertising purposes. To keep free features free, we may introduce in-app ads (including personalized ads) in the future; if we do, we will announce the items used and your opt-in choices in advance through a policy update and in-app notice.
Overwater complies with the Korean Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and the Act on Consumer Protection in Electronic Commerce, among other applicable laws.
1. Information we collect
Required
- Device identifier (Device ID): anonymous account identification, request authentication — generated automatically on first launch
- Client secret hash: request integrity verification (original value never stored)
Optional (only when you provide it)
- Additional location information (location name, latitude/longitude, country code): weather lookups for a location you registered on the Today tab — saved when you register the location yourself
Automatically collected
- Server access logs (IP, path, timestamp): security anomaly detection, rate limiting
- Crash and diagnostic data (Sentry): app stability improvement, exception/session tracking (no PII by default)
What we do not collect
- Sign-up information (name, email, phone number, date of birth) — Overwater has no sign-up flow
- Current location coordinates — used only for weather and air-quality lookups (Apple WeatherKit, met.no, KMA grid cell numbers, AirKorea monitoring-station names), and never stored on our servers in a form linked to an individual. (An "additional location" you register yourself is stored as an optional item listed above.)
- Demographic and lifestyle information (age group, gender, children, pets, plant location, daily rhythm) — not collected or stored by the current app and not used for personalization
- Photos and images — there is no feature that sends a photo to our servers, and we do not request photo-library access. The light meter uses the camera only as a brightness sensor and neither stores nor transmits the image
- To-dos, notes, and other user content — stored locally on device only
- Advertising identifiers (IDFA/AAID), behavioral tracking data — not collected today (if in-app ads are introduced, we will update this policy and notify you in advance)
2. Retention periods
- Device identifier / client secret hash: until device data is deleted or the user requests removal
- Additional location information (name, coordinates, country code): until you delete that location or delete your account
- Server access logs: 90 days
- Crash and diagnostic data (Sentry): retained according to the vendor's policy
3. Deletion procedure
- Electronic files are permanently deleted in a non-recoverable manner.
- Data is deleted without delay when retention expires or the purpose of processing is fulfilled.
- Where applicable law requires information to be retained for a set period, it is deleted without delay once that period ends.
4. Third-party sharing
We do not sell personal information. We do not currently share it for advertising; if in-app personalized ads are introduced, we will announce the shared items and your choices in advance through a policy update. Exceptions:
- With your prior consent
- When required by law (lawful requests from authorities)
- Coordinates shared with Apple WeatherKit (United States) for forecasts and met.no (Norway) as a forecast fallback; KMA grid cell numbers (not raw coordinates) shared with the Korea Meteorological Administration public data portal (Korea, not a cross-border transfer); monitoring-station names (not raw coordinates) shared with Korea Environment Corporation AirKorea (Korea, not a cross-border transfer, Korean locations only); observation-station codes shared with the Korea Hydrographic and Oceanographic Agency KHOA (Korea, not a cross-border transfer, Korean locations only); and coordinates shared with the NWS (api.weather.gov, United States) for US locations — for weather, air-quality, tide, and alert lookups
- A plant's scientific name shared with Google LLC Vertex AI / Gemini (United States) for plant Wiki entry text (no user information included)
- Location coordinates shared with Google Air Quality API / Google Maps Platform (United States) if the air-quality provider is switched — not currently in use; applies only during an AirKorea outage or similar
5. Processing entrustment
- Server hosting (Railway, United States): server operations and data storage
- Apple Inc. WeatherKit (United States): weather forecast lookups (location coordinates forwarded)
- MET Norway met.no (Norway): weather forecast fallback lookups (location coordinates forwarded)
- Korea Environment Corporation AirKorea data.go.kr (Korea, not a cross-border transfer): air-quality lookups (monitoring-station names forwarded; raw coordinates are not transmitted; Korean locations only)
- Google LLC (Google Air Quality API / Google Maps Platform, United States): air-quality lookups (location coordinates forwarded) — not currently in use; used only if the air-quality provider is switched, for example during an AirKorea outage
- Korea Meteorological Administration public data portal data.go.kr (Korea, not a cross-border transfer): Korean weather warnings, short-term forecasts, current conditions, climate normals, historical observations, and health weather indices (grid cell or station numbers forwarded; raw coordinates are not transmitted)
- Korea Hydrographic and Oceanographic Agency KHOA data.go.kr (Korea, not a cross-border transfer): tide and water-temperature lookups for the fishing tool (observation-station codes forwarded; Korean locations only)
- NOAA NWS api.weather.gov (United States): US weather warnings (location coordinates forwarded, US locations only)
- Google Cloud Vertex AI — plant Wiki entry (United States): plant Wiki entry text (scientific name); no personal information is forwarded
- Sentry (Functional Software, Inc., United States): mobile app crash and diagnostic data processing
6. Personal information of children under 14
Overwater does not require sign-up and may be used anonymously, including by children under 14.
The app is entirely free and has no paid subscriptions or in-app purchases, so there is no path for a child to make a purchase inside the app.
7. Your rights and how to exercise them
- Request access to, correction of, or deletion of your personal information. In-app data can be removed by the user directly or by uninstalling the app.
- Request deletion of server-stored data tied to your anonymous device identifier — contact the privacy officer below.
- Payment and refund enquiries: the app is entirely free and sells no paid products or subscriptions inside the app. There are no payment, refund, or cancellation procedures.
8. Automated collection (cookies, etc.)
The app does not use cookies. Device identification relies on a UUID stored locally on the device.
9. Privacy officer and external reporting channels
- Name: Jiwon Jeong
- Email: support@onsoonlabs.com
For privacy infringement reports or inquiries, you may contact:
- Personal Information Infringement Reporting Center (privacy.kisa.or.kr / 118)
- Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- Supreme Prosecutors' Office Cyber Investigation Division (spo.go.kr / 1301)
- National Police Agency Cyber Investigation Bureau (cyberbureau.police.go.kr / 182)
10. Scope
This policy applies to the Overwater mobile app and the onsoonlabs.com/overwater web pages. After navigating to external services (Apple (including WeatherKit), Google Cloud (Vertex AI), Google Maps Platform (Air Quality API — only if the provider is switched), MET Norway (met.no), the KMA public data portal, Korea Environment Corporation AirKorea, the KHOA, NWS, Sentry, etc.), the respective vendor policies apply.
11. Policy changes
This policy may be revised as laws and services change. We will provide advance notice as follows:
- General changes: announced at least 7 days before the effective date through in-app notices or updates.
- Material changes (such as added collection items or changes in purpose of use): announced at least 30 days before.
This policy is written based on the Korean Personal Information Protection Act, the Information and Communications Network Act, and the Act on Consumer Protection in Electronic Commerce.
Change history
Below is the revision record of this document prior to its effective date. The Plus paid subscription and payment items that appear in earlier rows were never actually sold or collected, and from v2.3 the app is entirely free.
| Version | Effective date | Summary of changes |
|---|---|---|
| 1.0 | 2026-04-01 | Initial version |
| 1.1 | 2026-04-05 | Added collection items related to posts and comments |
| 1.2 | 2026-04-19 | Disclosed that photos submitted for identification are sent to the server; reflected third-party provision to and processing entrustment with PlantNet and Google Vertex AI |
| 1.3 | 2026-04-21 | Changed the privacy officer contact to letters@overwater.app |
| 1.4 | 2026-05-08 | Unified the board naming as letters; disclosed cloud sync of plant and watering metadata for OAuth users (ADR-010); added Sentry crash and diagnostic data entrustment |
| 1.5 | 2026-05-14 | Removed all letters, OAuth, and sync items following the shift to a Personal Daily App; added Overwater Plus paid subscription items (Apple/Google IAP, 5-year retention); added the guardian approval procedure for users under 14 (Apple Ask to Buy / Google Family Link); added external reporting and remedy channels (KISA, Dispute Mediation Committee, Prosecutors' Office, Police Agency); stated the change-notice periods (7 days / 30 days); added a destination-country column for overseas transfers; unified the privacy officer email as hello@overwater.app across app, web, and docs |
| 1.6 | 2026-05-24 | Reflected the first-release policy. Plus features opened for free to mark the launch, no in-app IAP or subscription purchase, and removed the collection of payment and subscription receipts along with the Apple/Google payment entrustment items |
| 1.7 | 2026-06-25 | Reflected the Today tab shared-context architecture (ADR-019) and Cloud TTS v1 (ADR-020). Added Google Cloud Vertex AI (daily briefing text generation), Google Cloud Text-to-Speech (Plus voice synthesis), and the KMA public data portal (Korean weather alerts and short-term forecasts) to the entrustment and third-party provision tables. Stated the 25-hour server cache retention. Aligned product identity: cleaned up the retired "watering" and "personal plant registration" wording, and corrected the daily briefing payload to "location coordinates and an optional anonymous label" to match the actual code (plant metadata is not transmitted) |
| 1.8 | 2026-06-04 | Removed the launch-celebration wording about opening Plus to everyone for free (aligned with ADR-018 — not adopted). Removed the "not collected" notices for payment methods, subscription receipts, and subscription identifiers (the fact that in-app payment is not offered remains). Actual data-processing notices such as Plus voice synthesis are retained |
| 1.9 | 2026-07-25 | Reflected global (US) weather parity (R6). Added third-party provision and entrustment items for NOAA NWS (api.weather.gov, US), to which location coordinates are sent so that US users can retrieve weather alerts. Stated that location coordinates are used not only for weather lookups but also for Today tab AI briefing generation (the Overwater server does not store coordinates). Removed the "weather based on Seoul" fallback wording, replaced by guidance on setting a preferred region directly |
| 2.0 | 2026-07-25 | Reflected the weather data source switch. Moved forecasts to Apple WeatherKit (US) and added met.no (Norway) as a forecast fallback; added third-party provision and entrustment items for moving air quality lookups to the Google Air Quality API / Google Maps Platform (US). Open-Meteo (Germany) was narrowed to the role of weather and air quality fallback for when the app cannot reach the server. Stated that location coordinates are sent to the vendors above (the Overwater server does not store coordinates) |
| 2.1 | 2026-07-25 | Expanded the optional items for personalized AI summaries (children, pets that need walks, where plants are kept, daily rhythm — every item defaulting to "prefer not to say") and reflected them in the collection and retention tables. Corrected the advertising clause to "none at present; advance notice will be given if in-app advertising, including personalized advertising, is introduced" |
| 2.2 | 2026-08-15 | Aligned the document with actual processing through a full code review. (1) Added a new collection item for additional region information (name, coordinates, country code) — regions the user registers directly on the Today tab are stored in the anonymous profile, which had not been disclosed, and the statement that coordinates are not stored on the server was inaccurate for this item alone. (2) Replaced the default air quality provider, from the Google Air Quality API / Google Maps Platform (US) to Korea Environment Corporation AirKorea (Korea) — the transmitted item was corrected from coordinates to the monitoring station name, and the limitation to Korean locations was stated. The Google path remains in the code as a failover target, so it is kept as a conditional notice marked "not currently in use" (deleting it would turn a future switch into an undisclosed overseas transfer). (3) Corrected read-aloud to on-device synthesis — briefing text is not sent externally for voice synthesis, so the Google Cloud Text-to-Speech third-party provision and entrustment items were deleted. (4) Deleted all Open-Meteo items (removed from the code and no longer used). (5) Corrected the daily briefing payload to Vertex AI from "location coordinates" to "regional weather figures, an anonymous label, and the names of additional regions registered by the user" (the coordinates themselves are not transmitted). (6) Added the transmission of pest and disease diagnosis photos to Vertex AI (previously only identification was disclosed). (7) Added previously undisclosed processors — the KMA's ultra-short-term observations, climate normals, historical observations, and health weather indices, and the KHOA (fishing tides and water temperature). (8) Stated that the primary service region is the Republic of Korea and added onsoonlabs.com/overwater to the scope. (9) Deleted all plant species identification (PlantNet) items — the identification feature and its transmission path were removed from the product, so photos are no longer sent to PlantNet (France) and it was removed from third-party provision, entrustment, and scope (one fewer overseas transfer). Photo transmission remained only for pest and disease diagnosis to Google Vertex AI. (10) Added a notice for the light meter's camera use — the camera is used only as a brightness sensor, and images are neither stored nor transmitted. (11) Changed the privacy officer and inquiry contact from hello@overwater.app to support@onsoonlabs.com — it conflicted with the footer address of the canonical homepage (onsoonlabs.com/overwater), and contact details should not sit on a domain slated for retirement. (12) Deleted all photo-related items following the removal of pest and disease diagnosis — with no feature sending photos to the server, the photo clauses in the collection items, retention periods, third-party provision, entrustment, and core principles were all removed, and "photos are not collected" was stated. The photo library permission (NSPhotoLibraryUsageDescription) was removed as well. With the photo path gone, only text is sent to Vertex AI. (13) Added notices for the remaining Vertex AI call paths — fishing summaries (area names, marine figures) and the plant Wiki and shopping guide (scientific names) also use Vertex AI but had been missing from the tables |
| 2.3 | On the app's first release date | Reflected the confirmed move to a fully free app. Three places were corrected to match the fact that the app is free from beginning to end and that no payment path exists. (1) Removed the example "such as the future introduction of payment features" from the destruction procedure and restored it to statutory retention obligations in general. (2) Removed the qualifier "in the current version" and the guidance on guardian approval upon a future introduction of paid subscriptions from the children clause, stating instead that no payment path exists at all. (3) Changed the "subscription refunds and cancellation" item to "payment and refund inquiries" to make clear that no sales, payment, or refund procedure exists. Notices about actual data processing — collection, entrustment, overseas transfer — are unchanged |
| 2.4 | On the app's first release date | Reflected the removal of the Today LLM summary and the discontinuation of demographic collection. Removed the Today tab's Vertex AI text generation and its 25-hour generated-text cache, and discontinued the collection, storage, and personalization of age range, gender, children, pets, where plants are kept, and daily rhythm. The Vertex AI paths for fishing summaries and the plant Wiki and shopping guide were retained to match actual processing. Demographic data collected before this discontinuation was destroyed from the production database on 2026-08-22. |
| 2.5 | On the app's first release date | Reflected the removal of the plant shopping guide. It was the step that turned a scientific name from plant identification into purchase guidance; once identification was removed it became unreachable in the app, so its screen and server paths were deleted. The shopping-guide text generation entries were therefore removed from the core-principles summary, the third-party provision table (§4), and the entrustment table (§5). The Vertex AI paths that remain are the fishing summary and plant Wiki entries, and both notices are retained. Collection items, retention periods, and user rights are unchanged, and no processing or transfer item was added. v2.4 had not taken effect yet, but it had already been published at onsoonlabs.com/overwater/privacy, so its text is left as published and this is issued as a new version. |
| 2.6 | On the app's first release date | Reflected removal of the fishing Vertex AI path. The fishing tool now produces deterministic copy from Korea Meteorological Administration and Korea Hydrographic and Oceanographic Agency figures, so it no longer sends regional names or marine figures to Google Vertex AI. Accordingly, the fishing Vertex item was removed from the core-principles summary, the third-party provision table (§4), and the entrustment table (§5). The domestic KMA/KHOA lookup disclosures for the fishing tool and the Vertex AI path for plant Wiki entries remain because they match actual processing. Collection items, retention periods, and user rights are unchanged, and v2.5 had already been published at onsoonlabs.com/overwater/privacy, so its text is left as published and this is issued as a new version. |