Routinery Privacy Policy
Effective: August 20, 2026
Summary of Key Updates
August 2026
- Added disclosure on the provision of personal data to external AI tools you connect yourself (MCP) — Article 4-2
- Added disclosure on the cross-border transfer arising from that provision — Article 4-3
- Added a section on sensitive personal data and age requirements — Article 4-4
- Added a section on AI model training — Article 11-2
- Expanded the items collected, retention periods, user rights, and security measures
- Added company identification details — Article 12
March 2026
We updated this Privacy Policy to improve transparency and reflect changes in our data practices:
- Added information about cookies and tracking technologies
- Introduced Meta Pixel for advertising performance measurement
- Included Monetai for user experience optimization
- Expanded details on cross-border data transfers
- Clarified regional consent practices and opt-out options
- Confirmed that we do not sell personal information
- Updated how we notify users of policy changes, allowing flexible notice methods depending on the nature of the update and legal requirements
- Added information regarding web-based subscription payments processed via a third-party Merchant of Record (Paddle)
By using our services, you acknowledge that you have reviewed this Privacy Policy.
We process personal data in accordance with applicable laws including the Korean Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
We do not sell personal information.
We will only process marketing, personalized advertising, or non-essential tracking with your prior consent where required by applicable law.
You may withdraw your consent at any time through in-app or website settings.
Article 1 (Purpose of Processing Personal Information)
We process personal information only for the following purposes:
Membership Registration and Management (Contract performance) Managing user accounts, preventing misuse, and providing notices.
Customer Support and Inquiry Handling (Legitimate interest) Responding to inquiries and resolving issues.
Service Provision (Contract performance) Delivering features, including personalized routines based on user-provided information.
Service Improvement and Analysis (Legitimate interest) Analyzing usage patterns to improve features and performance.
Operational Messaging (Legitimate interest) Sending essential service-related notifications.
Marketing and Advertising (Consent) Sending promotional content only where the user has opted in.
Payment Processing and Subscription Management (Contract performance) Processing web-based subscription payments, managing billing status, verifying transactions, and providing access to paid features. Payment transactions are processed by a third-party payment provider acting as Merchant of Record.
Location-Based Reminder Feature (Consent) Location data is collected and used only to provide the location-based routine reminder feature that the user has explicitly enabled. This feature operates only when the user grants the necessary location permission through their device settings. Location data is not collected or used unless this feature is activated by the user.
Providing the External AI Tool Integration (Consent) We provide an MCP (Model Context Protocol) integration that allows an external AI tool you connect yourself to read your own routine data, and to create, duplicate, modify, and delete your routines at your instruction. This feature operates only where you have completed the connection process and given separate consent. Personal data of users who have not connected an AI tool is not provided to any external AI tool.
Article 2 (Retention Period)
We retain personal data only as long as necessary for the purposes stated above or as required by law.
Upon account deletion or withdrawal of consent, personal data will be deleted or anonymized.
Where retention is required by law, data will be securely stored for the legally mandated period and then deleted.
Retention for the external AI tool integration (MCP) is as follows.
| Item | Retention |
|---|---|
| Access token | 1 hour |
| Refresh token | 30 days (the previous token is destroyed immediately upon refresh) |
| Integration request records — timestamp, request identifier, request method and path, outcome, latency, pseudonymised user identifier | 30 days |
| Write-operation audit records — routine content before and after the change, user identifier, tool name, connected AI tool identifier | 90 days |
| Routines deleted through the MCP integration (recoverable state) | Approximately 10 days from deletion. Data older than 10 days is permanently deleted when you open the app and it synchronises, so if you do not open the app for a long period the actual permanent deletion may occur later. |
Integration request records do not store the content of routines, reflections, or notes, nor mood and condition entries, and the user identifier is stored in pseudonymised form. However, the IP address at the time of the request is processed in order to apply rate limits and block abnormal access.
Write-operation audit records are created only when a routine is created, modified, or deleted, and include the routine content before and after the change. Per-habit notes are always included; routine descriptions, notification text, and start conditions are included only where that field was modified. Post-routine reflections and mood entries are not included. Read requests are not audit-logged.
The above records may be retained after account deletion until each retention period expires, and are deleted automatically when it does.
Article 3 (Items Collected)
Required Information Anonymous ID, login email, country, nickname, gender, age group
Usage Data Login records, IP address, device information, service usage history, including per-habit completion results and the start and end time of each routine run Behavioral data such as interaction patterns, feature usage, event logs, session duration, and page or screen interactions may also be collected as part of service usage.
Optional Information (with consent) Profile image, preferences, and routine content, which comprises: routine names and descriptions; the list, order, and duration of constituent habits; per-habit notes; routine schedules (repeat pattern, per-weekday start times, start mode, and free-text start conditions); notification settings and notification text; mood and condition entries; post-routine reflections; routine reviews
Payment-related Information When you make a purchase via our web-based payment page, we may receive limited transaction-related information from our payment provider, including:
- Email address
- Transaction status
- Order ID
- Billing country
- User identifier
- Payment method type (e.g., card, Apple Pay, Google Pay)
We do not collect or store full payment card numbers or other sensitive financial information.
Location Data (Optional, with consent) Location data may be collected when the user enables the location-based reminder feature. This data is used solely to provide location-triggered routine notifications and is not collected otherwise.
Please note. Depending on what you enter, mood and condition entries, post-routine reflections, per-habit notes, and routine names and descriptions may contain information about your health, medication and exercise habits, or mental and emotional state. Processing of such information is governed by Article 4-4.
Article 4 (Outsourcing and Cross-border Transfers)
The items listed in the tables below are the principal items handled for each function. Where a processor provides service operation or storage infrastructure, personal data listed in Article 3 may be stored and processed on that infrastructure.
The processors listed in this Article act on our instructions and on our behalf. An external AI tool that you connect yourself does not process personal data on our instructions or for our purposes — it processes data for your purposes and for the provider's own purposes. Such provision is therefore not outsourcing but provision to a third party, and is governed by Articles 4-2 and 4-3.
1. Outsourcing of Processing
We entrust certain personal data processing tasks to trusted service providers:
| Service Provider | Location | Purpose | Data Processed | Retention | Safeguards |
|---|---|---|---|---|---|
| Google Cloud / Firebase | USA | Infrastructure, authentication | User identifiers, profile image | Contract duration | SCC, ISO 27001, encryption |
| AWS | USA | Infrastructure and storage | User identifiers, profile image | Contract duration | ISO 27001, SOC 2 |
| Amplitude | USA | Analytics | Usage data | Contract duration | GDPR DPA, ISO 27001 |
| Google AdMob | USA | Advertising | Ad identifiers, usage data | Contract duration | SCC-based DPA |
| Airbridge | Korea / US servers | Attribution | Ad identifiers | Contract duration | GDPR DPA, ISMS |
| FlareLane | Korea (US infra) | Messaging | User identifiers, usage data | Contract duration | ISMS-P, ISO (in progress) |
| Monetai | Korea | UX optimization | Behavioral data | Contract duration | ISO 27001, DPA (in progress) |
| Paddle | UK / Global | Payment processing (Merchant of Record), tax handling, invoicing | Transaction data, billing country, email | Contract duration | GDPR compliance, DPA, encryption |
| Sentry (Functional Software, Inc.) | USA | Error monitoring and performance tracking | Device information, OS, app version, error logs, IP address | Contract duration | GDPR DPA, data minimization, encryption in transit |
Paddle acts as the Merchant of Record, meaning it is the legal seller responsible for processing payments, handling taxes (including VAT), and issuing receipts.
We ensure that processors handle data only as instructed and implement appropriate safeguards, as set out in the table above.
2. Cross-border Transfers
Personal data may be transferred to countries such as the United States and the United Kingdom.
Where required under applicable data protection laws, such transfers are conducted based on appropriate legal mechanisms, including Standard Contractual Clauses (SCCs).
Transfers are conducted via encrypted communication and protected by:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements (DPAs)
- Technical and organizational safeguards
In particular, certain service providers located outside your country may process personal data on our behalf, including:
- Analytics and infrastructure providers (e.g., Google, AWS, Amplitude, Sentry)
- Attribution and advertising partners (e.g., AppsFlyer, Airbridge)
- Payment provider (Paddle), acting as Merchant of Record, which processes transaction data such as email address, billing country, and order information
Payment-related data may be processed globally by our payment provider in accordance with applicable data protection laws.
Location data, if collected, may also be processed by infrastructure providers located outside your country in accordance with the safeguards described above.
Article 4-2 (Provision of Personal Data to External AI Tools You Connect)
1. We provide your own personal data to an external AI tool that you have connected through the MCP (Model Context Protocol) integration. This occurs only where you have completed the connection process and given separate consent. We do not sell personal data, and under this Article we do not provide personal data to any third party you have not connected.
2. Terms of provision
| Recipient | The external AI service provider you connected (see the table in Article 4-3(2)) |
| Purpose | ① Reading and analysing routine data at your request and generating a response; creating, duplicating, modifying, or deleting routines at your instruction ② The recipient's own purposes: providing and maintaining its service, abuse and safety review, and — depending on that provider's policy and your account settings there — training and improving AI models. We cannot control or restrict the purposes under ② (see Article 11-2). |
| Items provided | See section 3 below |
| Retention and use | Determined by each AI service provider's privacy policy and by your settings in that service. We cannot control or guarantee this. |
| Right to refuse | You may refuse. Refusal means only that the MCP integration cannot be used; there is no restriction or disadvantage of any kind to the rest of the service. |
3. Items provided
- Routine names and descriptions, the list and order of constituent habits, per-habit duration, per-habit notes
- Routine schedules (repeat pattern, per-weekday start times, start mode, start conditions), notification settings, notification text, and similar routine configuration data
- Routine completion records (per-habit results, start and end time of each run) and your day-end cutoff setting
- Mood and condition entries, post-routine reflections
The following are not provided:
- Account information and email address, other than an anonymous identifier
- Profile information (nickname, gender, age group, country) and profile image
- Location data collected from your device (GPS coordinates)
- Login records, IP address, device information, behavioural data
- Payment method, payment amount, subscription product details
4. Please note
- We do not collect sleep time as a separate item. However, because per-weekday scheduled start times are provided together with the actual start and end times of each run, your daily rhythm — including wake-up and bedtime — may be discernible.
- Location coordinates are not provided, but where you have typed a place name into a routine start condition, that text may be provided.
- No tool exposes subscription status. However, where a free account exceeds the routine count limit or requests a subscription-only feature, the error message may indirectly reveal that there is no active subscription.
5. Scope
A connected AI tool can access your entire routine history through repeated requests. Each individual request is limited to a maximum range of 31 days (default 7 days); this does not limit cumulative access.
6. Permissions granted
At your request, a connected AI tool can read routines, routine settings, and completion records; create and duplicate routines; modify routines (add, change, remove, or reorder habits; change name, description, schedule, start mode, notification settings); and delete routines. It can also generate links that open a specific screen in the Routinery app and include them in its response.
For create, duplicate, modify, and delete requests, our server first returns a description of the change and a confirmation code to the connected AI tool, and applies the change only where that tool submits the confirmation code again. Displaying the change to you and obtaining your confirmation is performed by the connected AI tool, and we cannot control or guarantee that the tool actually seeks your confirmation.
It cannot execute routines remotely, create or alter completion records, or read or change account information, email address, or payment details.
Selecting read-only versus write access, or selecting which data items are shared, is not currently supported. Consenting to the integration grants the permissions above together.
7. Withdrawal of consent
You may stop the integration at any time. See Article 6.
Article 4-3 (Cross-border Transfer Arising from the External AI Tool Integration)
1. Why the transfer occurs, and what is transferred
Our MCP server is located in the Republic of Korea (Seoul region). Because the AI service providers you may connect are located outside Korea, personal data provided under Article 4-2 is transferred out of Korea. The items transferred are those listed in Article 4-2(3).
2. Recipients, countries, purposes, and retention
| AI tool | Recipient | Country | Purpose | Retention | Privacy contact |
|---|---|---|---|---|---|
| Claude | Anthropic PBC (EEA, UK, Switzerland: Anthropic Ireland, Limited) | United States (Ireland) | Processing your request and generating a response | Per that provider's policy and your account settings | privacy@anthropic.com DPO: dpo@anthropic.com |
| ChatGPT | OpenAI OpCo, LLC (EEA, UK, Switzerland: OpenAI Ireland Limited) | United States (Ireland) | Processing your request and generating a response | Per that provider's policy and your account settings | privacy@openai.com DPO: dpo@openai.com Requests: dsar@openai.com |
| Gemini CLI | Google LLC (EEA, UK, Switzerland: Google Ireland Limited) | United States (Ireland) | Processing your request and generating a response | Per that provider's policy and your account settings | googlekrsupport@google.com |
| Cursor | Anysphere, Inc. | United States | Processing your request and generating a response | Per that provider's policy and your account settings | hi@cursor.com |
MCP is an open standard, so you may connect other MCP-capable tools not listed above. In that case the provider of that tool becomes the recipient.
The authorisation screen displays the name the requesting tool registered for itself and the address you will be returned to after approving. We do not verify whether the displayed name matches the actual provider. You should therefore not rely on the displayed name alone — confirm that it is the tool you have just tried to connect and that the displayed address belongs to that tool before approving.
We cannot control or guarantee retention after transfer.
3. Timing and method
- Timing: individually, each time you make a request involving routine data in the connected AI tool
- Method: online transmission over encrypted communication (TLS)
- Route
| Connected tool | Route |
|---|---|
| Claude (web), ChatGPT (web connector) | our server → AI service provider's server |
| Cursor, Gemini CLI, Claude Desktop and other tools that run on your device | our server → your device → AI service provider's server |
On either route, the data is ultimately processed on the AI service provider's servers.
4. Onward transfers
A client you connect (for example Cursor, Gemini CLI, or another MCP client) forwards the personal data it receives from us to the AI model provider it uses. In that case the final recipient and the country of processing depend on the model you selected in that client, and we can neither verify nor control this. Please review that client's privacy policy and model settings before connecting. The scope of what we can disclose is limited to the first recipient you connected directly.
5. Safeguards and complaint handling
This transfer is based on your separate consent, and no data processing agreement (DPA, Standard Contractual Clauses, or similar) is in place between us and the recipient. We apply TLS encryption in transit, limit the validity period of access tokens, and minimise the items provided.
Complaints regarding this transfer may be submitted to hello@routinery.app. Where a deletion or suspension request must be made to the recipient, we will direct you to that provider's request channel; we do not guarantee the outcome of the recipient's action.
Notice for users in the European Economic Area, the United Kingdom, and Switzerland
This transfer relies on explicit consent under GDPR Article 49(1)(a). No appropriate safeguards under GDPR Article 46, such as Standard Contractual Clauses, are in place between us and the recipient. The following risks therefore apply:
- An adequacy decision of the European Commission finding that the recipient's country provides a level of protection equivalent to the EEA may not apply.
- Public authorities in that country may be able to access the transferred data.
- You may not be able to obtain the level of legal remedy guaranteed under the GDPR.
You consent with knowledge of these risks. If you do not consent, only the MCP integration is unavailable; there is no restriction on the rest of the service.
6. How to refuse, and the effect of refusal
- How to refuse: decline consent to the integration, or — if already connected — stop it as described in Article 6. No further transfer will occur.
- Effect: only the MCP integration becomes unavailable. There is no restriction or disadvantage of any kind to the rest of the service.
- Limitation: data already transferred before refusal is handled under the relevant provider's policy and cannot be recalled by us. You may request deletion directly from that provider using the contacts above.
Article 4-4 (Sensitive Personal Data and Age Requirements)
1. We do not collect sensitive personal data as a distinct field. However, depending on what you enter, mood and condition entries, post-routine reflections, per-habit notes, and routine names and descriptions may contain information about your health, medication and exercise habits, or mental and emotional state. In addition, routine schedules combined with actual run times may reveal health-related lifestyle patterns such as your wake-up and bedtime.
2. Where such information is provided to an external AI tool you have connected, we obtain consent to the provision of sensitive personal data separately from the consents under Articles 4-2 and 4-3. For users in the European Economic Area, the United Kingdom, and Switzerland, such information may constitute a special category of personal data under the GDPR, and we obtain explicit consent.
3. You may refuse this consent. Refusal means only that the MCP integration cannot be used; there is no restriction on the rest of the service. There is currently no option to use the MCP integration while excluding only these items, so refusing this consent means the MCP integration cannot be used at all.
4. Under the Terms of Service, children under the age of 14 may not register for an account and may not use this feature. However, we rely on the age information you enter and do not operate a separate age verification process. Where the law of your country of residence sets a higher age of consent for information society services than 14, you may use this feature only once you have reached that age. Where we become aware that a user under the age of 14 has registered, we will delete that personal data and the account without delay.
5. When an external AI tool is connected, the content of free-form text fields is provided as written. In addition, when a routine is created, modified, or deleted, the routine content before and after the change is retained in the audit records described in Article 2 for 90 days, and per-habit notes are always included even where that field was not modified. Please consider this before entering sensitive content.
Article 5 (Destruction of Personal Information)
Personal data is deleted when no longer needed.
- Electronic data: securely deleted
- Physical data: shredded or destroyed
Article 6 (User Rights)
Users may:
- Access, correct, or delete data
- Withdraw consent
- Object to processing
- Request data portability
Requests can be made via in-app settings or email.
Rights concerning the external AI tool integration (MCP)
You may stop the MCP integration by any of the following.
| Method | Effect |
|---|---|
| Disconnect Routinery from within the connected AI tool | Where that tool notifies our server of the disconnection, the issued tokens are deleted immediately. |
| Email hello@routinery.app requesting disconnection | We will act on your request and destroy the tokens issued for your account. |
| Delete or deactivate your account | All integration requests are rejected immediately, regardless of token validity. |
| Take no action | The access token expires after 1 hour and the refresh token after up to 30 days, ending access. |
Whether an AI tool notifies our server of a disconnection depends on that tool's implementation, and we do not verify or guarantee the behaviour of individual tools. Where no notification is made, issued tokens may remain valid until they expire, so to cut off access immediately please delete or deactivate your account.
There is no limit on the number of AI tools that may be connected to one account at the same time, and neither the app nor the web provides a feature for viewing the list of connected tools or disconnecting an individual tool.
If you email hello@routinery.app, we will report the AI tools currently connected to your account, based on the integration records we hold.
Article 7 (Security Measures)
We implement:
- Access control
- Encryption
- Monitoring and logging
- Internal policies and training
Measures for the external AI tool integration (MCP)
- Authentication: OAuth 2.0. Account credentials such as your password are never given to an external AI tool.
- Token management: access tokens expire after 1 hour, refresh tokens after 30 days; on refresh the previous token is destroyed immediately. Account validity is verified on every integration request, and requests from deleted or deactivated accounts are rejected immediately.
- Log minimisation: integration request records store a pseudonymised user identifier, and tokens, authorisation codes, and other credentials are not stored. Response content for read requests (the actual text of routines, reflections, and notes) is not stored. For write operations, however, the routine content before and after the change is stored as an audit record under Article 2.
- Change confirmation and encryption in transit: for create, duplicate, modify, and delete operations, the change and a confirmation code are returned first and the change is applied only where the confirmation code is submitted again; TLS is applied to all integration traffic.
Article 8 (Cookies and Tracking Technologies)
We use cookies and similar technologies to:
- Improve website functionality and user experience
- Analyze usage patterns
- Optimize marketing and advertising performance
Cookies and tracking technologies may be used when you access certain web-based content or pages provided as part of our services.
In particular, such technologies may be applied on specific web pages or content experiences to measure performance and improve user experience.
1. Types of Cookies
- Essential
- Analytics
- Advertising
2. Third-party Tracking
We may use third-party tracking tools such as:
- Meta Pixel (for advertising performance and retargeting)
- Analytics tools
These tools may collect device information, browsing activity, and interaction data.
Where required by law, Meta Pixel and similar advertising technologies are activated only after obtaining user consent.
3. Legal Basis and Regional Practices
Depending on applicable law, cookies and tracking technologies may be used based on either prior consent or legitimate interest with opt-out options.
- EEA/UK: Prior consent required
- Other regions: Applied where permitted by law, with opt-out available
4. Control
Users can manage or withdraw their preferences at any time through browser settings, cookie controls, or in-app privacy settings.
5. Tracking on Payment Pages
Tracking technologies (such as Meta Pixel, Airbridge, or similar analytics tools) may also be used on web-based payment pages to:
- Measure conversion events
- Analyze payment funnel performance
- Optimize advertising campaigns
Such tracking is implemented in compliance with applicable laws and, where required, only after obtaining user consent.
Article 9 (Behavioral Data Collection)
We collect behavioral data (as described in Article 3) to:
- Improve services
- Personalize experiences
- Measure advertising performance (with consent where required)
Tools include:
- Firebase, Amplitude
- AppsFlyer
- Meta Pixel
- Monetai
Users may opt out via settings.
Article 10 (Additional Use Without Consent)
We may process data without additional consent where permitted by law and compatible with the original purpose.
Provision of personal data to external AI tools under Article 4-2 does not rely on this Article and takes place solely on the basis of your separate consent.
Article 11 (Use of Non-identifiable Content)
Non-identifiable user content may be used for marketing.
Identifiable data is never used without consent.
Article 11-2 (AI Model Training)
1. We do not use your personal data to train AI models, and we do not sell your personal data. The personalised routine suggestions described in Article 1(3) are provided by simple matching on information you enter and do not use an AI model. Personal data provided under Article 4-2 is transmitted only to the AI tool you connected yourself; we do not transmit personal data to AI services you have not connected.
2. Whether transmitted data is retained or used for model training is determined by the policy of the AI service provider you connected and by your settings in that service, and we cannot control or guarantee this. Policies differ between services and can change. You can check and change the training setting directly in each service.
| AI tool | Where to check |
|---|---|
| Claude | Settings → Privacy → model improvement setting |
| ChatGPT | Settings → Data controls → model improvement setting |
| Gemini | Google Account → Gemini Apps Activity |
| Cursor | Settings → Privacy |
Article 12 (Controller and Data Protection Officer)
| Item | Details |
|---|---|
| Controller | Routinery Inc. |
| Business registration number | 204-86-59204 |
| Address | 70 Naruteo-ro, Unit 202 (Jamwon-dong, Yeongseo Building), Seocho-gu, Seoul 06526, Republic of Korea |
| Telephone | +82-2-2088-7044 |
| Data Protection Officer | Inseok Seo |
| hello@routinery.app |
Article 13 (Contact)
Email: hello@routinery.app
Article 14 (User Remedies)
Users may contact relevant authorities for data protection issues.
Article 15 (Changes to this Policy)
We may update this Privacy Policy to reflect changes in applicable laws, regulations, or our services.
If we make material changes that affect your rights or how your personal data is processed, we will provide prior notice through appropriate channels such as in-app notifications, email, or website notices, where required by applicable law.
For minor changes or updates that do not significantly affect your rights, we may update this Privacy Policy without prior notice, and the updated version will be effective upon posting.
The "Effective" date at the top of this Policy indicates when the current version took effect.