01 · OverviewLocal-first by design
Kihya Memo is a local-first note app that does not require registration or mandatory login. Note text, file names, folder paths, attachments, and search terms are stored on the user’s device by default and are not transmitted to Kihya servers.
This policy is separate from Kihya’s commerce privacy policy. When you choose to open an external website in your system browser, that site’s privacy and cookie policies apply there.
02 · DataInformation the app handles
- Original notes and files: safe UTF‑8 Markdown, text and source content in its original extension; file and folder names and paths; photos, PDFs, archives, and other files you choose to store. These remain in app‑managed local storage or an external file you explicitly select.
- Local auxiliary data: ordinary pre-save versions and a recent crash-recovery draft. These stay in app-private local storage, are hidden from the system file browser, and are excluded from Drive sync, cloud backup, device migration, and full ZIP export. Separate pre-overwrite sync safety records are described in Section 04.
- Optional remote-server data: when you add an SFTP, FTP, or FTPS folder, the app handles the display name, protocol, host, port, user name, starting path, SSH host-key fingerprint, credentials, directory listings, and files you choose to open or save. Credentials use device-only protected storage; downloaded baselines, recovery drafts, and local history stay in an app-private area excluded from Google Drive sync, cloud backup, device migration, and ZIP export. Server host, user name, paths, file names, credentials, and remote contents are not sent to Analytics.
- Recently Deleted: deleted notes and folders first move to a hidden recoverable area. You may optionally protect this screen using Face ID, Touch ID, device passcode, Android biometrics, or system lock. The app receives only the operating system’s success or failure result and does not read or store biometric data or your passcode.
- Optional Google account data: if you connect Google Drive, the app uses an OAuth access token and displays the connected account email inside the app. The email is used only to show connection status and is not included in Analytics events.
- Product analytics: Firebase Analytics may process a random app‑instance ID, device and operating‑system information, app version, approximate region, sessions, screens, app lifecycle, and feature‑use events. Note content, file or folder names and paths, searches, attachments, and Google account information are never included. The app allows Analytics storage for measurement but denies ad storage, ad user data, and ad personalization by default, and disables advertising-identifier collection and Apple ad-attribution features.
03 · PurposeWhy data is used
- To create, read, edit, rename, move, search, preview, export, and recover the files you choose.
- To provide local versions, crash recovery, and recoverable deletion.
- When requested, to sync original files, merge changes, create conflict copies, and mirror recoverable deletion through the user’s own Google Drive.
- To connect directly to an SFTP, FTP, or FTPS server the user configures; browse a selected starting path; and open, compare, safely save, and locally recover supported remote text files.
- To understand aggregate app stability and feature usage so we can improve the product without reading what users write.
Not used for: advertising, credit decisions, sale of personal information, profiling based on note contents, cross‑app tracking, or any purpose unrelated to the functions described here.
04 · GoogleGoogle user data and limited access
Google OAuth and the Drive API are used only when a user explicitly selects Connect Google Drive in Settings. Before continuing, the app explains the expected Google permission screen and tells users to cancel if the app name is unfamiliar or an unverified‑app warning appears.
- drive.file: creates, views, and modifies files that Kihya Memo created or that the user connected to this app, and moves an app-deleted Drive item to Google Drive trash. It does not allow the app to read or manage the user’s entire Drive.
- drive.appdata: stores a small workspace identifier and immutable sync safety records. Immediately before sync would replace one different supported safe UTF‑8 text or source document with another, the app may preserve the two pre-change texts, normalized path, file identifier, time, and checksums so either version can be recovered. This protection applies only to supported text files up to 2 MB; attachments and the current working copy of a document are not stored here. The area is hidden from the normal Drive file list.
Google user data is processed solely to provide user‑requested file sync, change merging, conflict‑copy creation, and recoverable deletion. It is not sold or used for advertising, credit evaluation, profiling, or unrelated analytics, and is not disclosed to third parties except when legally required or explicitly requested by the user. Kihya personnel do not inspect note contents for ordinary operations.
Kihya Memo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
05 · RetentionStorage, deletion, and recovery
- Local originals: remain until you delete them, clear app data, or uninstall the app, subject to the operating system’s storage behavior. External files you selected may remain outside the app.
- Versions and recovery drafts: remain in app-private local storage according to app settings and use. Saving normally or discarding changes removes the related crash draft. “Delete all version history” removes versions, not current notes or crash drafts.
- Recently Deleted: remains recoverable until you explicitly restore or permanently delete items. Version history and the hidden deleted area are excluded from cloud backup, device migration, and ZIP export.
- Google Drive: disconnecting Drive or uninstalling the app does not automatically delete original files already on the device or in Drive, or hidden sync safety records. You may delete the visible “Kihya Memo” folder and Kihya Memo’s hidden app data yourself in Google Drive management. Items deleted in the app move to Google Drive trash when sync is connected.
- Remote servers: a saved connection remains until you remove it or erase the app. Removing it deletes that device’s profile, credential, cache, baseline, recovery drafts, and local remote-file history; it does not delete any server file. Remote auxiliary data is not included in Drive sync, cloud backup, device migration, or ZIP export. The first release does not delete server items or queue an unconfirmed upload for later.
- Analytics: transmitted data is encrypted in transit. User- and event-level retention is limited to two months, without resetting the retention period on new activity. Google explains that this setting does not remove standard aggregated reports. Clearing app data may reset the device’s app‑instance ID, but it does not guarantee immediate removal of data already sent or aggregated statistics.
Deletion requests: email help@kihya.com. We act on data Kihya can reliably identify and control. Because Kihya Memo has no Kihya account and does not link Analytics to an email address or Analytics User‑ID, an email address alone cannot identify a historical Analytics installation. Local files and Google Drive content remain under your control; support can explain the steps but cannot remotely access or delete them. Data that is already irreversibly de‑identified or aggregated may remain.
06 · SharingService providers and disclosures
Kihya does not sell personal information or Google user data. Google services process data only as needed to provide optional OAuth, Drive synchronization, and Firebase Analytics under their applicable terms and safeguards. An SFTP, FTP, or FTPS connection goes directly from the device to the server address the user entered; Kihya does not proxy, receive, or store its credentials or file contents. The user’s server operator and network provider may process that traffic under their own terms. Optional Analytics data sharing and links to Google advertising products are disabled for this release, and the app denies advertising storage, advertising user data, and ad personalization. Information may also be disclosed when required by law, necessary to protect a person’s urgent safety or rights, or explicitly directed by the user.
External pages open only after the user chooses a link. Their cookies and accounts are handled by the browser and that website; Kihya Memo does not receive them.
07 · ChoiceYour controls and rights
- Use all core note features without connecting Google Drive.
- Disconnect Drive at any time in Settings or revoke access from Google Account third-party connections.
- Choose whether to add a remote server and which protocol to use. You can remove a connection and all of its device-local credentials, cache, drafts, and history without changing files on that server.
- Open, share, move, or export your original Markdown, text, source, and related files.
- Restore or permanently delete items from Recently Deleted.
- Request access, correction, deletion, restriction, or other applicable privacy rights by contacting us. We ask only for the platform, requested scope, and other minimum information needed to respond, and explain when data cannot be reliably identified or is controlled directly by you.
08 · SecuritySafeguards and practical limits
We apply reasonable technical and organizational safeguards appropriate to the app, including device-only protected credential storage, strict SSH host-key verification, TLS certificate and host-name verification without automatic downgrade for FTPS, minimum Drive scopes, and data-minimized analytics events. SFTP, FTPS, Google, and Analytics traffic is encrypted in transit. If you deliberately select plain FTP, its user name, password, file names, and contents are not encrypted and may be observed or changed by someone with network access. The app requires an explicit warning acknowledgment and keeps an unencrypted badge visible; use this option only on a trusted legacy network when SFTP or FTPS is unavailable. No storage or transmission method can guarantee absolute security, and device security remains important for locally stored files.
When seeking support, do not send note contents, file or folder names and paths, searches, attachments, Google account information, passwords, or authentication codes. This site contains no form that asks you to upload such data.
09 · LinksExternal information pages
Kihya Memo opens only the memo website, guide, privacy policy, support, and non-commerce company pages when the user selects them. Android 1.0 has no retailer, regulated-goods, order, payment, or age-confirmation entry point. The app does not receive browser account or cookie data.
10 · ContactQuestions, rights, and policy changes
For product support or privacy requests, email help@kihya.com. When you email us, Kihya processes the sender address, message, and reply history only to answer the request, exercise applicable rights, protect security, and meet legal obligations. We retain this information only as long as needed for those purposes; you may request deletion, subject to necessary legal, dispute, security, and abuse-prevention exceptions. Kihya Co., Ltd. operates Kihya Memo. Material changes will be posted on this page before they take effect when reasonably practicable, with the updated date shown below.
Original Korean policy posted:
August 11, 2026
Multilingual remote-access update:
August 14, 2026