ystia Open ystia
YSTIA

Privacy Policy

The privacy policy for the ystia app: account information, hospital research results and notifications.

Updated 28 September 2026 · 개정일 2026년 9월 28일

Who operates ystia

App name: ystia. Google Play developer name: Brainpill.

ystia is operated personally by Joon Nyung Heo, 50-1 Yonsei-ro, Seodaemun-gu, Seoul, Republic of Korea. The operator is also the privacy contact: jnheo@jnheo.com. This address does not imply that the hospital publishes the app.

This policy covers ystia’s mobile and Mac apps, review website and connected result-sharing service. ystia is for invited hospital physicians and researchers. It is a research application, not a medical device, and must not be used for diagnosis or treatment decisions. The offline demo uses synthetic data.

Information and purposes

  • Account and access: email address, identity-provider and ystia user identifiers, hospital membership and role. We use these to verify email-link sign-in and enforce hospital access. An active invitation is required; downloading the app does not grant access to records.
  • Research results: patient and study identifiers, processing identifiers, arrival and completion times, progress, research measurements and generated review images. The processing Mac uploads these so authorized members of the same hospital can review them. Raw DICOM stays on the processing Mac. Shared results are not necessarily anonymous; identifiers may be present in metadata or image pixels.
  • Notifications: installation identifiers, notification and Live Activity tokens, platform, preferences and selected processing subscriptions. These route requested updates to authorized devices.
  • Operations: processing events, access and administrative audit records, delivery status and error codes. Infrastructure and authentication providers also process request metadata, including IP addresses and user agents, for service delivery and security.
  • Support: your email address and information you choose to send, used to resolve support and privacy requests. Please do not send patient information, images, passwords, tokens or verification links in ordinary email or store feedback.

We use data for these service, access-control, security and support purposes. We do not sell personal information, use it for advertising, or include advertising-tracking SDKs. “Track progress” means following a processing run.

Providers and international processing

Google Cloud hosts the service, database and private result storage in Seoul. This regional deployment does not mean that authentication, messaging, global network operations or every provider copy remains in Korea.

  • Google Cloud / Google Identity Platform: account verification and cloud operations receive the data needed for those functions. Google documents Firebase Authentication processing in the United States.
  • Google Firebase Cloud Messaging: Android messaging uses installation and delivery identifiers and notification payloads on Google’s global infrastructure. Optional push can be left disabled.
  • Apple Push Notification service: iOS notifications and Live Activities send device/activity tokens and notification payloads to Apple. Apple describes international processing and generally US storage in its privacy policy.

Transmission takes place electronically over encrypted connections when you sign in, use the service, or receive updates. Provider contact and location information is available from Google’s data protection contact, Google’s provider/location register, Firebase privacy information and Apple’s privacy policy. Contact the ystia privacy contact for questions about the arrangements applicable to your hospital.

You can decline optional notifications and still use online review. Email authentication and the associated processing are necessary for online access; the synthetic offline demo can be used without signing in. Hospital research-data permissions are administered separately by the responsible hospital.

Notifications, storage and security

Default push messages contain generic processing information. Numerical research volumes may appear only when the hospital policy allows them and you opt in. Push payloads do not contain patient-ID text or image pixels. Device notification settings control lock-screen visibility. Delivery depends on the network and operating system and is not guaranteed.

The mobile apps cache review images in memory and clear them on sign-out or known loss of authorization. They do not create a persistent image library. Credentials use iOS Keychain or Android Keystore-backed encryption. Web sign-in uses a session cookie. There are no advertising cookies. Saved sign-in can refresh while identity and hospital access remain valid.

Requests use HTTPS and the server checks hospital access. Access is restricted to authorized users and service operators. This is not end-to-end encryption against the operator. Keep your device locked and use sign-out when you no longer need access.

Retention

  • Cloud results: scheduled daily cleanup removes study snapshots, events, summaries and generated images once a run reaches 90 days from its first cloud receipt. This includes incomplete runs. Later updates do not restart the clock. Cleanup failures are retried; a retired run is hidden while cleanup finishes. An opaque run-ID retirement marker remains to prevent an old Mac upload from recreating expired records; it contains no patient identifier, image or measurement.
  • Accounts: kept until deletion is requested or an account-administration process removes it. Disabling hospital access alone does not erase the account. After a verified deletion request, access is disabled immediately; operator-controlled account, membership, device, subscription and session data are removed and authentication-provider deletion is initiated within 30 days.
  • Service records: audit and notification-delivery history are cleaned up after 90 days. Expired browser sessions are removed by maintenance.
  • Infrastructure logs: the configured default cloud log bucket retains records for 30 days. Google’s required administration/security log bucket retains records for 400 days. These are separate from the result database.
  • Support and privacy correspondence: retained while the request is being handled, then removed from the operator’s active support records within 90 days of resolution.

Cloud image recovery copies have a seven-day soft-delete period. The database retains its latest seven daily backups and seven days of transaction logs. Recovery copies expire through their normal cycle and are not available through the app. Restoration must reapply recorded deletion and expiry decisions.

Google documents up to 180 days for authentication and Firebase installation-ID erasure from live and backup systems after the relevant provider deletion mechanism is invoked. Disabling a ystia notification registration alone does not invoke every device’s installation-ID deletion. Android sign-out initiates device-token/installation cleanup and retries failures when the app runs again. Provider retention does not extend ystia access.

The processing Mac, hospital records, and copies separately saved by an authorized user remain under their respective control. Deleting a viewer account does not delete a hospital’s research records.

Your rights and account deletion

Contact jnheo@jnheo.com to request access, correction, deletion, restriction of processing or withdrawal of an optional choice. Use your registered email address so we can verify the request. An authorized representative can contact us with appropriate proof of authority. If you cannot access your registered email, ask for an alternative verification method without sending identity documents in the initial email.

Request account deletion without reinstalling or signing in. We verify the request, process it under the timetable above and explain any specific limitation. Signing out or uninstalling alone does not delete your central account. Patient-record requests are coordinated with the responsible hospital.

We publish changes on this page with an updated effective date and communicate material changes through the service. Questions or complaints can be sent to the privacy contact above.

개인정보 처리방침

앱 이름: ystia. Google Play 개발자 표시명: Brainpill.

ystia의 개인 운영자 및 개인정보 문의 책임자는 Joon Nyung Heo입니다. 주소는 서울특별시 서대문구 연세로 50-1이며, 문의 이메일은 jnheo@jnheo.com입니다. 이 주소가 해당 병원을 앱의 발행자로 표시하는 것은 아닙니다.

이 방침은 ystia 모바일·Mac 앱, 웹 검토 화면 및 연결된 결과 공유 서비스에 적용됩니다. 초대받은 병원 의사와 연구자를 위한 연구용 앱으로, 의료기기가 아니며 진단이나 치료 결정에 사용해서는 안 됩니다. 오프라인 데모에는 합성 자료를 사용합니다.

처리하는 정보와 목적

  • 계정: 이메일, 인증 서비스 및 ystia 사용자 식별자, 병원 소속과 권한을 이메일 링크 로그인 및 병원별 접근 통제에 사용합니다. 앱 설치만으로 병원 자료에 접근할 수 없으며 유효한 초대가 필요합니다.
  • 연구 결과: 처리 Mac에서 환자·검사·처리 식별자, 도착·완료 시각, 진행 상태, 연구 측정값 및 생성된 검토 영상을 전송받아 해당 병원의 권한 있는 사용자에게 제공합니다. 원본 DICOM은 Mac에 남습니다. 공유 자료는 익명 자료라고 볼 수 없으며 메타데이터나 영상에 식별정보가 포함될 수 있습니다.
  • 알림: 설치 식별자, 알림 및 Live Activity 토큰, 운영체제, 알림 설정과 구독을 업데이트 전달에 사용합니다.
  • 운영·문의: 처리 이벤트, 접근·관리 기록, 알림 전달 결과, 기술 오류 및 문의 내용을 서비스 운영, 보안과 요청 처리에 사용합니다. 클라우드와 인증 제공업체는 IP 주소와 사용자 에이전트 등 요청 정보를 처리할 수 있습니다.

개인정보를 판매하거나 광고 목적으로 사용하지 않으며 광고 추적 SDK를 포함하지 않습니다. 일반 이메일이나 스토어 피드백에는 환자 정보·영상, 비밀번호, 인증 토큰 또는 로그인 링크를 보내지 마세요.

서비스 제공업체와 국외 처리

Google Cloud의 서울 리전에 앱 서버, 데이터베이스와 결과 저장소를 배치합니다. 그러나 인증, 메시지 전달, 글로벌 네트워크 운영까지 모두 국내에 한정되는 것은 아닙니다. Google Identity Platform을 통한 이메일 인증을 사용하며, Google은 Firebase Authentication의 미국 처리를 안내하고 있습니다. Android 알림은 Google Firebase Cloud Messaging의 글로벌 인프라를, iOS 알림과 Live Activity는 Apple Push Notification service를 사용합니다. Apple은 자사 방침에서 국외 처리 및 일반적인 미국 저장을 설명합니다.

로그인·서비스 이용·알림 전달 시 각 기능에 필요한 계정 정보, 기기 토큰, 메시지 내용 등이 암호화된 통신으로 전송됩니다. 제공업체 및 위치와 문의 방법은 Google 제공업체 목록, Google 개인정보 문의, Firebase 안내, Apple 개인정보 처리방침에서 확인할 수 있습니다. 병원에 적용되는 처리 관계는 ystia 개인정보 책임자에게 문의해 주세요.

선택적 알림을 사용하지 않아도 온라인 결과 검토는 가능합니다. 온라인 접근에는 이메일 인증과 그에 수반되는 처리가 필요하며, 로그인하지 않고 합성 자료 데모를 사용할 수 있습니다. 병원 연구자료의 이용 권한은 해당 병원이 별도로 관리합니다.

알림과 보호조치

기본 푸시는 일반적인 처리 상태만 전달합니다. 연구 측정값은 병원 설정과 사용자 선택이 모두 허용한 경우에만 표시됩니다. 푸시에는 환자 ID 문자나 영상 픽셀을 넣지 않습니다. 잠금화면 표시는 기기 설정으로 관리하며 알림 도착을 보장하지 않습니다.

모바일 영상은 메모리에 임시 저장하고 로그아웃 또는 권한 상실 확인 시 지웁니다. 지속적인 영상 보관함을 생성하지 않습니다. 인증 정보는 iOS Keychain 또는 Android Keystore 기반 암호화로 보호합니다. 웹은 로그인 세션 쿠키를 사용하고 광고 쿠키는 사용하지 않습니다. HTTPS, 병원별 권한 확인과 운영 접근 제한을 적용하지만 운영자에 대해서까지 종단간 암호화된 서비스는 아닙니다.

보유기간과 파기

  • 클라우드 결과: 최초 클라우드 수신 후 90일이 된 처리 건을 매일 정리합니다. 미완료 건도 포함되며 업데이트가 기간을 연장하지 않습니다. 정리 대상으로 전환한 자료는 접근을 차단하고, 삭제 실패 시 재시도합니다. 오래된 Mac 업로드로 자료가 다시 생성되지 않도록 환자 식별정보·영상·측정값이 없는 불투명한 처리 ID 표식을 남깁니다.
  • 계정: 삭제 요청 또는 계정 관리 절차에 따른 삭제 시까지 보관합니다. 병원 접근 권한 해제만으로 계정이 삭제되지는 않습니다. 삭제 요청의 본인확인 후 즉시 접근을 차단하며 30일 이내 운영자 관리 범위의 계정·소속·기기·구독·세션 정보를 삭제하고 인증 제공업체의 계정 삭제를 시작합니다.
  • 운영 기록: 감사 및 알림 전달 기록은 90일 후 정리하고 만료된 웹 세션도 제거합니다. 기본 클라우드 로그는 30일, Google의 필수 관리·보안 로그는 400일 보관합니다.
  • 문의 기록: 처리 중 보관하고 해결 후 90일 이내 운영자의 활성 문의 기록에서 삭제합니다.

영상 저장소의 복구용 사본은 삭제 후 7일간 남을 수 있습니다. 데이터베이스는 최근 일일 백업 7개와 7일간의 트랜잭션 로그를 유지합니다. 일반 앱에서 접근할 수 없으며 정상 백업 주기로 소멸합니다. 복원 시 기존 삭제·보관기간 결정을 다시 적용해야 합니다.

Google은 해당 삭제 절차 시작 후 인증 및 Firebase 설치 식별자의 운영·백업 시스템 삭제에 최대 180일이 걸릴 수 있다고 설명합니다. 서버의 알림 등록 해제만으로 모든 기기의 설치 식별자가 삭제되는 것은 아닙니다. Android 로그아웃은 토큰·설치 식별자 정리를 시작하고 실패하면 앱이 다시 실행될 때 재시도합니다. 이 기간이 ystia 접근을 연장하지는 않습니다.

처리 Mac, 병원 연구기록과 사용자가 별도로 저장한 사본은 각 관리주체의 통제를 받습니다. 연구자 계정 삭제가 병원 자료 전체의 삭제를 의미하지 않습니다.

권리 행사와 연락 방법

열람, 정정, 삭제, 처리정지 또는 선택사항 철회는 jnheo@jnheo.com으로 요청할 수 있습니다. 등록한 이메일로 요청하면 본인확인 후 처리하고 결과와 구체적인 제한 사유를 안내합니다. 적법한 대리인도 위임 확인을 거쳐 요청할 수 있습니다. 등록 이메일을 사용할 수 없으면 처음부터 신분증을 보내지 말고 대체 확인 방법을 문의해 주세요.

계정 삭제 요청은 로그인이나 앱 재설치 없이 가능합니다. 로그아웃 또는 앱 삭제만으로 중앙 계정이 삭제되지 않습니다. 환자 연구자료에 관한 요청은 담당 병원과 협의합니다. 방침 변경 시 이 페이지의 시행일을 갱신하고 중요한 변경은 서비스에서 안내합니다.