ObsiKO 개인정보처리방침
시행일: 2026년 7월 25일 · 개정: 2026년 9월 13일 · 운영: Studio HyZet · 문의: support@obsiko.com
ObsiKO(이하 “앱”)는 나만의 우주를 만드는 AI 지식관리 앱입니다. 앱은 로컬 우선(local-first)으로 설계되어, 회원가입·로그인 없이 동작하며 사용자의 글과 파일은 기본적으로 사용자 기기(또는 사용자가 지정한 볼트 폴더)에만 저장됩니다.
본 방침은 앱의 모든 배포판(App Store — iOS·iPadOS, Mac App Store, 직접 배포 데스크탑, 웹)에 적용되며, 배포판에 따라 다른 부분은 아래에 따로 표시했습니다.
1. 운영자가 수집하지 않는 것
- 운영자는 분석·추적 도구(Analytics, 광고 식별자, 위치추적 등)를 앱에 탑재하지 않습니다.
- 앱에는 계정 시스템이 없으며, 앱에서 이메일·이름 등 개인정보를 수집하지 않습니다. (웹사이트에서 사용자가 직접 신청하는 뉴스레터 구독은 4항을 참고하세요.)
- 사용자의 노트·문서·이미지 등 콘텐츠는 운영자 서버로 전송되지 않으며, 사용자가 지정한 폴더에만 보관됩니다.
2. 사용자가 기능을 쓸 때 외부로 전송되는 것
일부 기능은 동작을 위해 제3자 서비스에 요청을 보냅니다. 해당 기능을 사용할 때만 전송이 발생하며, 보내는 내용은 그 기능에 필요한 최소한입니다.
| 기능 | 전송 대상(제3자) | 전송되는 내용 |
| 사전 찾기 | 위키백과/위키낱말사전, dictionaryapi.dev, 국립국어원 우리말샘(opendict.korean.go.kr) | 찾으려는 단어 |
| 번역 | Google 번역, MyMemory | 번역할 텍스트 |
| 맞춤법 검사(한국어) | 네이버 맞춤법 검사기(응답이 없으면 부산대학교 바른한글 맞춤법 검사기) | 검사할 텍스트 — 처음 사용할 때 앱 안에서 확인을 받습니다 |
| 맞춤법 검사(영어·일본어) | LanguageTool | 검사할 텍스트 — 처음 사용할 때 앱 안에서 확인을 받습니다 |
날씨 삽입({{weather}}) | Open-Meteo, ipapi.co | 대략적 위치 또는 IP 기반 위치(좌표) |
| 이미지 검색 | Openverse, Wikimedia, Pixabay·Pexels·Giphy(ObsiKO 프록시 경유) | 검색어 |
| AI 채팅(에이전트 패널) | 사용자가 고른 제공자(Anthropic·Google·OpenAI) | 사용자가 입력한 프롬프트 및 참조로 선택한 노트 |
| AI 맞춤법 검사 | 검사할 텍스트 |
| AI 낭독(TTS) | 읽어줄 텍스트(선택 영역 또는 노트 본문) |
| 음성·영상 전사 | 전사할 오디오·영상 파일 |
| AI 이미지 생성 | 이미지 설명(프롬프트) |
| 가계부 자동 입력(결제 문자 붙여넣기) | 사용자가 붙여넣은 결제 문자 내용(금액·가맹점·일시 등) |
AI 기능에 대하여
- AI 기능은 기본적으로 꺼져 있으며, 사용자가 설정에서 자신의 API 키를 직접 입력해야 동작합니다.
- 외부 AI 제공자로 처음 보낼 때 앱은 제공자·보낼 내용·제공자의 처리 방식(공식 문서로 확인한 사실)을 보여 주고, 사용자가 [허용하고 보내기]를 눌렀을 때만 전송합니다. 허락은 제공자와 내용 종류(글·이미지·음성)별로 이 기기에만 기록되며, AI 에이전트 ▸ 에이전트 옵션 ▸ 외부 AI 전송 허락에서 언제든 거둘 수 있습니다. 사용자가 누르지 않은 자동 작업(개인화 기억 자동 축적 등)은 허락이 없으면 전송하지 않습니다.
- 기기 안 AI(Apple Intelligence 등)는 내용을 기기 밖으로 보내지 않습니다.
ai: deny 속성이나 .obsiko-ai-ignore로 보호한 노트는 AI 검색·첨부·에이전트 도구 어디로도 보내지 않습니다.
- Google Gemini API는 Google 약관상 만 18세 이상만 이용할 수 있습니다. 또한 Gemini 무료 등급으로 보낸 내용은 Google이 제품 개선에 사용하고 사람이 검토할 수 있습니다(앱은 무료·유료 키를 구별할 수 없습니다).
- 입력한 API 키는 운영자 서버로 전송되지 않습니다. 저장 위치는 플랫폼마다 다릅니다 — iOS·macOS는 키체인, Windows는 자격증명 관리자, 브라우저판·Android는 앱(브라우저) 로컬 저장소에 그대로 저장되므로 공용 기기에서는 키를 넣지 말고 다 쓰면 지워 주세요.
- GitHub 연동(웹으로 공유·기기 간 동기화·공유 페이지 댓글)은 선택 기능입니다. 로그인 토큰은 기기 보안 저장소(브라우저판은 브라우저 안)에 보관되고, 공유한 글은 GitHub의 비밀(secret) Gist에, 동기화 볼트는 사용자의 비공개 저장소에 저장됩니다 — 비밀 Gist는 주소를 아는 사람은 누구나 볼 수 있습니다. 공유 페이지 댓글 로그인은 obsiko.com에 30일 쿠키(httpOnly)를 둡니다. 운영자는 이 내용을 저장하지 않으며 GitHub의 개인정보처리방침이 적용됩니다.
- 브라우저판은 노트·검색 색인·버전 이력·설정을 브라우저 저장소(localStorage·IndexedDB·OPFS)에 둡니다. 브라우저의 "사이트 데이터 지우기"로 삭제할 수 있습니다.
- App Store·Mac App Store 버전은 채팅만 동작합니다. 직접 배포 데스크탑 버전은 여기에 더해 볼트 파일을 읽고 쓰는 에이전트 도구를 제공하며, 이때 에이전트가 읽은 파일의 내용이 해당 AI 제공자로 전송될 수 있습니다.
- 각 제3자 서비스의 데이터 처리는 해당 서비스의 개인정보처리방침을 따릅니다. AI 제공자의 보관 기간(2026년 9월 13일 각 제공자 공식 문서 기준): Anthropic 30일 안에 삭제(이용정책 위반 시 더 길 수 있음) · OpenAI 오·남용 감시 목적으로 최대 30일 · Google 유료 등급 55일(무료 등급은 별도 명시 없음). Anthropic·OpenAI API와 Google 유료 등급은 보낸 내용을 모델 학습에 쓰지 않는다고 밝히고 있습니다.
가계부(결제 문자 자동 입력) 기능에 대하여
- 이 기능은 사용자가 결제 문자를 복사한 뒤 앱에서 직접 붙여넣을 때만 동작합니다. 앱은 문자나 알림을 자동으로 읽거나 백그라운드에서 감시하지 않습니다. 클립보드 접근은 사용자가 붙여넣기를 실행하는 순간에만 이뤄집니다.
- 붙여넣은 결제 문자는 금액·가맹점 등으로 정리하기 위해 위 표의 AI 제공자로 전송되며(AI 기능이 켜져 있을 때), 정리된 가계부 항목은 사용자의 볼트 폴더(기기)에만 저장됩니다. 운영자 서버로 전송·보관되지 않습니다.
3. ObsiKO 프록시 서버
이미지 검색·우리말샘 사전 일부는 CORS 우회와 API 키 보호를 위해 운영자의 프록시 서버(obsiko.com)를 경유합니다. 이 과정에서 요청 IP 주소가 일시적으로(요청 빈도 계산용으로 최대 10분) 처리될 수 있으며, 이는 오로지 오·남용 방지(요청 빈도 제한) 목적입니다. 운영자는 이 데이터를 사용자 신원과 연결하거나 별도로 장기 보관·판매하지 않습니다. 검색어 자체는 응답을 잠시 캐시하는 데만 쓰이며 저장되지 않습니다.
4. 웹사이트 뉴스레터 구독
이메일 주소는 사용자가 웹사이트(obsiko.com)에서 직접 메일링 구독을 신청한 경우에만 수집됩니다. 앱에는 구독 기능이 없으며, 앱 사용만으로는 이메일이 수집되지 않습니다.
- 수집 항목: 이메일 주소(및 선택한 언어)
- 이용 목적: 업데이트·새 릴리스 안내
- 처리 수탁: 메일 발송 서비스 Resend
- 보관 기간: 구독 해지 시까지. 해지는 메일 하단의 수신 거부 링크 또는 support@obsiko.com으로 요청하면 즉시 처리됩니다.
5. 광고
ObsiKO는 앱과 웹사이트 어디에도 광고를 넣지 않습니다. 광고 네트워크 스크립트나 광고 식별자를 사용하지 않으며, 광고 목적으로 쿠키를 심지 않습니다.
6. 데이터 보관·삭제
사용자의 콘텐츠는 사용자 기기/폴더에 있으므로, 해당 파일을 삭제하면 즉시 제거됩니다. 운영자는 사용자 콘텐츠 사본을 보관하지 않습니다. 뉴스레터 이메일은 4항에 따라 구독 해지 시 삭제됩니다.
7. 아동
앱은 아동을 대상으로 하지 않으며, 아동으로부터 개인정보를 의도적으로 수집하지 않습니다.
8. 변경
본 방침은 기능 변경에 따라 갱신될 수 있으며, 변경 시 본 페이지에 시행일과 함께 게시합니다.
9. 문의
개인정보 관련 문의: support@obsiko.com
ObsiKO Privacy Policy
Effective: July 25, 2026 · Revised: September 13, 2026 · Operator: Studio HyZet · Contact: support@obsiko.com
ObsiKO (the “App”) is a Markdown editor optimized for Korean writing. It is designed to be local-first: it works without any account or sign-in, and your notes and files are stored only on your device (or the vault folder you choose).
This policy applies to every distribution of the App (App Store for iOS/iPadOS, Mac App Store, direct-download desktop, and web). Where a distribution differs, it is noted below.
1. What we do NOT collect
- The App contains no analytics, tracking, advertising identifiers, or location-tracking SDKs.
- The App has no account system, and collects no personal data such as email or name. (For the newsletter you can opt into on our website, see section 4.)
- Your content (notes, documents, images) is never sent to our servers; it stays in the folder you choose.
2. What is sent when you use certain features
Some features send requests to third-party services to function. Transmission happens only when you use that feature, and only the minimum needed.
| Feature | Third party | What is sent |
| Dictionary lookup | Wikipedia/Wiktionary, dictionaryapi.dev, Korean Urimalsam (opendict.korean.go.kr) | The word you look up |
| Translation | Google Translate, MyMemory | The text to translate |
| Spell check (Korean) | Naver spell checker (Pusan National Univ. Bareun Hangeul checker if Naver does not respond) | The text to check — the App asks you once, inside the App, before the first check |
| Spell check (English/Japanese) | LanguageTool | The text to check — the App asks you once, inside the App, before the first check |
Weather insert ({{weather}}) | Open-Meteo, ipapi.co | Approximate or IP-based location (coordinates) |
| Image search | Openverse, Wikimedia, Pixabay/Pexels/Giphy (via ObsiKO proxy) | Your search query |
| AI chat (agent panel) | The provider you choose (Anthropic, Google, OpenAI) | Your prompt and any notes you select as references |
| AI spell check | The text to check |
| AI read-aloud (TTS) | The text to read (selection or note body) |
| Audio/video transcription | The audio or video file to transcribe |
| AI image generation | Your image description (prompt) |
| Ledger auto-entry (pasting a payment text) | The payment text you paste (amount, merchant, date, etc.) |
About the AI features
- AI features are off by default and require you to enter your own API key in Settings.
- The first time anything is sent to an external AI provider, the App shows the provider, what will be sent, and how that provider handles it (facts checked against its official documents), and sends only after you press [Allow and send]. Permission is recorded per provider and content type (text, images, audio) on this device only, and can be withdrawn anytime under AI Agent ▸ Agent options ▸ External AI sending allowed. Automatic tasks you did not trigger (such as automatic personal memory) send nothing without permission.
- On-device AI (such as Apple Intelligence) never sends your content off the device.
- Notes protected with the
ai: deny property or .obsiko-ai-ignore are never sent to AI search, attachments, or agent tools.
- Under Google’s terms, the Google Gemini API is for people 18 or older. Content sent on the Gemini free tier may be used by Google to improve its products and reviewed by people (the App cannot tell a free key from a paid one).
- Your API key is never sent to our servers. Where it is stored depends on the platform: the Keychain on iOS/macOS, Credential Manager on Windows, and plain app/browser local storage on the browser version and Android — so do not enter keys on a shared device, and clear them when you are done.
- GitHub features (share to the web, device sync, comments on shared pages) are optional. The sign-in token is kept in your device’s secure storage (inside the browser on the browser version); shared notes go to a secret GitHub Gist and synced vaults to your private repository — a secret Gist is readable by anyone who has the link. Signing in to comment sets a 30-day httpOnly cookie on obsiko.com. We store none of this content; GitHub’s privacy policy applies.
- The browser version keeps notes, search indexes, version history and settings in browser storage (localStorage, IndexedDB, OPFS). You can remove them with your browser’s “clear site data”.
- The App Store and Mac App Store versions provide chat only. The direct-download desktop version additionally offers agent tools that read and write files in your vault; in that case the contents of the files the agent reads may be sent to the AI provider you chose.
- Each third party processes data under its own privacy policy. AI provider retention (per each provider’s official documents as of September 13, 2026): Anthropic deletes within 30 days (longer for usage-policy violations) · OpenAI up to 30 days for abuse monitoring · Google 55 days on the paid tier (not stated for the free tier). The Anthropic and OpenAI APIs and Google’s paid tier state that they do not train models on what you send.
About the household-ledger (payment-text auto-entry) feature
- This feature works only when you copy a payment text message and paste it into the App yourself. The App does not automatically read your messages or notifications, and does not monitor anything in the background. Clipboard access happens only at the moment you perform the paste.
- The pasted payment text is sent to the AI provider listed above (when an AI feature is enabled) to be parsed into amount, merchant, etc. The resulting ledger entry is stored only in your vault folder (on your device) and is never sent to or stored on our servers.
3. ObsiKO proxy server
Image search and part of the Urimalsam dictionary go through our proxy (obsiko.com) to bypass CORS and protect API keys. In this process your request IP address may be processed transiently (up to 10 minutes, as a request counter), solely for abuse prevention (rate limiting). We do not link this to your identity, nor retain or sell it. Search queries are used only to cache responses briefly and are not stored.
4. Website newsletter
We collect an email address only if you sign up for our mailing list on the website (obsiko.com). The App has no sign-up feature; simply using the App never results in email collection.
- What we collect: your email address (and the language you selected)
- Purpose: news about updates and new releases
- Processor: Resend (email delivery service)
- Retention: until you unsubscribe. Use the unsubscribe link in any email, or write to support@obsiko.com, and we will remove you immediately.
5. Advertising
ObsiKO shows no ads — not in the app, not on the website. We use no ad-network scripts and no advertising identifiers, and we set no cookies for advertising.
6. Retention & deletion
Your content lives on your device/folder; deleting those files removes them immediately. We keep no copy of your content. Newsletter emails are deleted when you unsubscribe, as described in section 4.
7. Children
The App is not directed to children and does not knowingly collect personal information from children.
8. Changes
We may update this policy as features change; updates are posted here with a new effective date.
9. Contact
Privacy questions: support@obsiko.com