1. Scope of this policy
This Privacy Policy explains how Jadonglab handles information in connection with Pebbles, formerly known as Sip. It covers the iPhone and iPad app, widgets, the Apple Watch companion app, Pebbles Cloud, this website, and support and privacy communications.
The core journal works locally without registration, sign-in, or a subscription. Pebbles Cloud is optional and requires an auto-renewable subscription and a Pebbles account. The sections below distinguish local processing from cloud processing.
2. Local journal and on-device processing
Pebbles handles journal entries, titles, optional captions, timestamps, Day groupings, appearance settings, custom images, daily backgrounds, and app preferences to provide the local journal. This information stays on your device unless you activate Pebbles Cloud, intentionally share an exported image through Apple's share sheet, or otherwise choose to send it outside Pebbles.
Pebbles does not use app information for advertising, cross-service tracking, or sale. The app does not include third-party advertising or product-analytics SDKs.
Local journal state and preferences are stored in encrypted app-group storage. The encryption key is kept in Apple Keychain. Images are stored as local files protected by the operating system's data-protection features. Widgets use a limited local projection, and the Apple Watch companion receives a limited device-to-device projection through Apple's WatchConnectivity service.
3. Camera and selected photos
When you add an image, Pebbles can use a photo you take with the camera or an image you select through Apple's system Photos picker. Camera access occurs only after you choose the camera option. The Photos picker gives Pebbles access to the image you select rather than general access to your photo library.
Pebbles processes the selected image on your device to prepare, isolate, crop, resize, or encode it. An optimized copy is stored in Pebbles' local container. If you activate Pebbles Cloud, the processed image used by your journal may also be uploaded to your private cloud storage for backup, synchronization, recovery, and sharing. Removing the source from Photos does not automatically remove Pebbles' local or cloud copy.
4. Pebbles Cloud information
Pebbles Cloud is offered in Pocket with 3 GB, Box with 25 GB, and Warehouse with 100 GB of cloud storage. Monthly and annual options within the same tier include the same storage allowance. If you activate Pebbles Cloud, the service processes:
- Account and profile information: your verified email address, or Apple relay email when applicable; Cognito account identifier; display name; globally unique
@username; authentication provider; account status; and profile and privacy settings. - Subscription information: Pebbles Cloud product identifier, App Account Token, original App Store transaction identifier, entitlement status, expiration, and signed transaction or notification status. Pebbles does not receive your payment-card number.
- Synced journal content: Days, entry identifiers, titles, captions, dates and timestamps, appearance and background settings, processed photos, derived media, sync revisions, and sharing status.
- Service records: upload identifiers, media type and size, checksums, idempotency records, synchronization status, and limited operational records needed to protect and operate the service.
Pebbles Cloud does not change the local-first model. Your library remains on the current device, and a sign-out, subscription lapse, or cloud-account deletion does not intentionally erase the ordinary local journal already stored there.
5. Authentication and App Store purchases
Pebbles Cloud owners and people opening a shared Day authenticate through Amazon Cognito using Sign in with Apple or passwordless email. Email authentication uses a one-time code. Pebbles does not ask you to create a password and does not store a password.
Apple processes Pebbles Cloud purchases through StoreKit and the App Store. Apple provides signed transaction and subscription status information so Pebbles can activate, restore, renew, pause, expire, refund, or revoke cloud access as appropriate. Apple handles payment credentials, billing, and refund eligibility under its own terms and privacy practices.
6. Sharing
Exported images
Pebbles can create a recap image on your device and present Apple's system share sheet when you choose to share it. You select the destination and recipient. The selected service handles the shared copy under its own terms and privacy practices.
Pebbles Cloud Day links
A Pebbles Cloud owner can change Day link access to Public and then create a link for an individual Day. The link contains a pseudorandom token and opens a read-only Day only after the viewer signs in. A viewer does not need a Pebbles Cloud subscription or owner profile. Pebbles uses the viewer's account identifier to enforce authentication but does not create a relationship between the viewer and owner or retain a product-analytics view history.
The backend stores a hash of the active Day token rather than the raw token. The raw link still passes through the website or operating system when opened, so treat it as private. The website shows only a generic app-opening page and does not render journal content. Hosting and security systems may process the requested path as technical request information.
Changing Day link access to Private blocks all new shared-Day access. Stopping sharing invalidates that Day's current link. These actions cannot recall screenshots, downloads, messages, or other copies already kept by a recipient. A download URL already issued by Pebbles may remain usable for its short expiration period, which is no more than five minutes.
7. Cloud storage and security
Pebbles Cloud uses Amazon Web Services resources in the Asia Pacific (Seoul) Region. Account and journal records are stored in Amazon Cognito and DynamoDB. Processed journal images and backgrounds are stored in private Amazon S3 storage. API Gateway, Lambda, SQS, CloudWatch, SNS, and SES support requests, application processing, account deletion, operational monitoring, alerts, and email sign-in codes.
Cloud media is not placed at a permanent public URL. S3 public access is blocked, objects are encrypted at rest, and authenticated requests receive short-lived upload or download URLs. Access tokens, passwords, and raw journal content are not intended to be written to application logs.
No service can guarantee absolute security. Please protect your device, Apple Account, email account, and private Day links, and contact Jadonglab if you believe your account or link has been compromised.
8. Website information
This website does not provide a Pebbles Cloud account-management dashboard and does not use advertising pixels, cross-site tracking, or a website analytics script. It does not set advertising or analytics cookies.
The website is hosted by Vercel. Vercel's hosting and security systems may process your IP address, requested path, date and time, browser or user-agent information, approximate region derived from IP address, response status, and related diagnostic or security information to deliver and protect the site and diagnose service issues. Jadonglab does not use website requests to build individual advertising profiles.
Google Play waitlist
Joining the Google Play waitlist is optional and separate from using Pebbles or Pebbles Cloud. If you join, Jadonglabprocesses the email address, consent response, and submission time you provide. Tally may also process technical request information needed to deliver and protect the embedded form.
- Purpose: operating the waitlist and sending one notification when Pebbles becomes available on Google Play.
- Retention: until the launch notification is sent, followed by deletion within 30 days, or earlier if you withdraw consent. A minimal suppression record may be kept when needed to honor an opt-out.
- Providers: Vercel hosts the surrounding website, Tally provides the form and stores submissions, and Google Sheets stores a synchronized waitlist copy.
To withdraw before the notice is sent, email dkim@jadonglab.com. The launch notice will also include an unsubscribe option.
9. Support and privacy communications
If you contact Jadonglab, the information handled may include your email address, the name shown by your email service, message, attachments, and details you choose to provide, such as your device model, operating-system version, Pebbles version, or screenshots. This information is used to respond, investigate the issue, maintain support records, protect the service, and comply with legal obligations.
Please do not send passwords, one-time codes, private Day links, or unnecessary personal photos. Support and privacy communications are ordinarily kept while a request is active and for up to 12 months after the last correspondence, then deleted, unless a longer period is reasonably needed for security, a dispute, recordkeeping, or applicable law.
10. How information is used
Jadonglab uses information described in this policy to:
- provide and secure the local app and Pebbles Cloud;
- authenticate accounts and manage profiles;
- verify subscription status and provide the selected storage tier;
- back up, synchronize, restore, and share journal content;
- process account and content deletion requests;
- respond to support and privacy requests;
- detect abuse, diagnose failures, monitor service reliability, and protect users; and
- comply with applicable law and protect legal rights.
11. Service providers and disclosure
Jadonglab does not sell personal information and does not provide Pebbles information to advertisers, data brokers, or product-analytics providers. The following providers or categories of recipients handle limited information as needed:
- Apple: app distribution, StoreKit purchases, signed transaction information, App Store Server Notifications, Sign in with Apple, device backup, the Photos picker, WatchConnectivity, and the system share sheet.
- Amazon Web Services: authentication, one-time email codes, APIs, application processing, database and private media storage, account-deletion processing, logs, alerts, and service monitoring.
- Vercel: website hosting, delivery, security, and diagnostics, including the generic shared-link fallback.
- Tally and Google: the optional Google Play waitlist form and synchronized Google Sheets copy.
- Email providers: receiving and responding to support and privacy requests.
- Your chosen sharing destination:when you export content through Apple's system share sheet.
Information may also be disclosed when reasonably necessary to comply with applicable law or a lawful request, protect rights and safety, investigate abuse, or establish or defend legal claims.
12. International processing
Pebbles Cloud application data is processed using AWS resources in Seoul, Republic of Korea. If you use Pebbles Cloud from another country, your information is transmitted to that region.
Apple, Vercel, Tally, Google, email providers, and their subprocessors may also process information in countries where they operate. Their privacy notices describe their respective processing and transfer practices. Jadonglab uses providers for the limited purposes described above and applies contractual, technical, and organizational safeguards where applicable.
13. Retention and deletion
- Local journal:entries, preferences, and custom media remain on the relevant device until you remove the content, clear the app's local data, or remove the app. A daily background is removed when you remove or replace it and is otherwise automatically removed locally after 14 days.
- Device backups:copies included in an Apple device backup may remain until you delete that backup under your Apple settings and Apple's retention practices.
- Cloud account and content: profile, synced journal, media, sharing, and entitlement records are kept while needed to operate your account and subscription, until you delete the relevant content or request cloud-account deletion, subject to limited records required for security, disputes, transaction integrity, or applicable law.
- Pending uploads: abandoned pending S3 objects become eligible for automatic deletion after one day. Incomplete multipart uploads are aborted after seven days.
- Operational logs: production application logs are configured for retention of up to 90 days. Website technical information follows the applicable Vercel configuration and provider practices.
- Waitlist and support: the periods in Sections 8 and 9 apply.
When Pebbles accepts a cloud-account deletion request, it blocks shared access and signs the app out. An asynchronous deletion process removes active Pebbles account records, synced journal records, private cloud media, and the Cognito user. Deletion jobs are retried and monitored if a service operation fails. Recovery or service backups and limited security, transaction, or compliance records may remain until their applicable retention window expires and are not available for ordinary account use.
Canceling a Pebbles Cloud subscription does not by itself delete your Pebbles account or synced content. Deleting your Pebbles account or removing the app does not by itself cancel an Apple-managed subscription.
14. Your choices and rights
You control local journal information through Pebbles' edit, replace, and delete controls. To remove all local Pebbles data, remove Pebbles and its companion app from the relevant devices and manage any Apple device backups separately.
Pebbles Cloud provides profile and sharing controls in the app. You can stop sharing an individual Day, change Day link access to Private, or start cloud-account deletion from Settings → Account → Delete Account. The local journal already on the current device is preserved when the cloud account is deleted.
Apple subscription cancellation, refund requests, and Sign in with Apple settings are managed through Apple. See the Apple subscription instructions, Apple refund instructions, and Sign in with Apple settings.
Where applicable, you may request access, correction, deletion, restriction, or other available privacy rights by emailing dkim@jadonglab.com. Jadonglab may need to verify your identity and may retain information where required by law or necessary to protect legal rights. You may withdraw from the Google Play waitlist before the launch notice by using the same email address.
15. Children's privacy
Pebbles is not directed to children and does not knowingly use personal information from children for advertising or tracking. The Google Play waitlist is not directed to children. If you believe a child has provided personal information through Pebbles, the waitlist, or support, contact Jadonglab so the request can be reviewed and handled appropriately.
16. Changes to this policy
This policy may be updated when Pebbles' features, data practices, providers, or legal obligations change. The revised policy will be posted on this page with an updated date. Material changes will be highlighted where reasonably appropriate.
17. Contact
For privacy questions or requests, email dkim@jadonglab.com.
자동화연구소Privacy contact: 김동구
Business registration number: 657-10-03442
서울특별시 영등포구 당산로32길 9, 3층 303호 (당산동3가, 태경빌딩)
Effective date
This Privacy Policy is effective as of July 27, 2026.