SmartThings Rules Copilot
개인정보 처리방침
시행일자: 2026년 7월 19일
본 서비스(이하 "SmartThings Rules Copilot")는 사용자의 개인정보와 스마트싱스 계정 데이터를 매우 중요하게 다루며, 데이터 보호 및 투명한 관리 원칙을 준수하기 위해 최선을 다하고 있습니다. 본 방침은 서비스를 통해 처리되는 데이터 항목, 이용 목적, 보관 기간 및 보안 관리 정책에 대해 상세히 안내합니다.
제 1 조 (서비스의 목적 및 역할)
SmartThings Rules Copilot은 사용자의 스마트싱스(SmartThings) 계정 환경(위치, 기기 목록, 기존 자동화 룰) 정보를 중계하여, 사용자가 사전에 연결한 AI 환경(Claude MCP, ChatGPT Actions 등)에서 자연어 대화로 정교한 자동화 규칙(Rule JSON)을 설계하고 이를 사용자 승인 하에 계정에 안전하게 전송 및 제어할 수 있도록 보조하는 중개형 도구입니다.
제 2 조 (처리하는 데이터 및 보관 기간)
서비스는 동작상 반드시 필요한 핵심 데이터에 한해 암호화 처리 및 임시 저장을 수행하며, 보관 기간이 경과하면 즉시 자동으로 파기합니다.
| 처리 데이터 항목 | 보관 및 파기 정책 |
|---|---|
| SmartThings Personal Access Token (PAT) | 서버 측 연결별 격리 저장소에서 즉시 AES-GCM 256-bit 방식으로 암호화되어 임시 저장되며, 등록 후 24시간 내에 자동 영구 파기됩니다. |
| AI 연동 유지용 OAuth 토큰 및 세션 정보 | Claude 또는 ChatGPT가 사용하는 OAuth access token은 1시간 동안 유효합니다. 반복 승인을 줄이기 위한 refresh token과 승인 기록은 최대 30일 동안 보관될 수 있습니다. |
| 브라우저 연결 쿠키 | st_rule_copilot HttpOnly 쿠키는 브라우저와 AI 연결을 같은 임의 연결 식별자에 묶기 위해 사용되며, 최대 30일 동안 유지될 수 있습니다. 이 쿠키에는 SmartThings PAT, Claude/GPT OAuth 토큰, Authorization 헤더가 저장되지 않습니다. |
| 스마트싱스 환경 및 기기 메타데이터 | 연동 기기의 이름, ID, 배치된 방 이름, 사용 가능한 기능(Capabilities) 및 기존 Rule 정보는 세션 동작 시간 동안에만 처리되며 별도로 서버 영구 저장소에 보관하지 않습니다. |
제 3 조 (데이터 보안 및 암호화)
본 서비스는 사용자의 인증 정보 유출을 차단하기 위해 브라우저 로컬 저장소(localStorage) 및 쿠키에 평문 토큰을 일절 저장하지 않습니다. 브라우저 쿠키에는 임의 연결 식별자만 저장되며, 모든 주요 연동 토큰은 서버 영역으로 격리되어 관리됩니다. 암호화 키를 포함한 접근 권한은 다중 레이어로 제한됩니다. 서비스는 PAT, Authorization 헤더 및 요청 본문과 같은 민감한 원문 정보를 애플리케이션 로그로 기록하지 않습니다.
제 4 조 (데이터 삭제 권리 및 연결 방식의 구분)
사용자는 원할 때 언제든지 서비스 화면을 통해 자신의 연동 정보 및 저장 데이터를 완전히 삭제할 수 있습니다.
- 연결 해제 (Disconnect): 서버의 연결별 격리 저장소에 임시 저장된 스마트싱스 토큰(PAT) 정보만 즉시 완전히 파기합니다. AI와의 연동 정보는 보존되므로, 차후 개인 장치에서 토큰만 재입력하여 바로 승인 상태를 재사용할 수 있습니다.
- 연결 초기화 (Reset): 서버에 임시 저장된 스마트싱스 PAT 뿐만 아니라, 공유된 AI 승인 정보 및 현재 브라우저의 연결 세션 쿠키까지 완전히 소멸시켜 최초 상태로 되돌립니다. 공용 PC 또는 공동 기기에서는 반드시 사용을 마친 후 연결 초기화를 실행하십시오.
제 5 조 (대화형 실행 안전 정책)
공식 GPT/Claude 지침은 최종 변경 내용이나 상태 변경 대상을 보여주고 사용자의 명시적 확인을 받은 뒤 write 도구를 호출하도록 요구합니다. 서버는 인증, 입력 스키마, 요청 제한, SmartThings 응답과 동일 PAT를 사용한 재조회 결과를 검증하지만, 외부 AI 채팅에서 실제 확인이 있었는지는 독립적으로 검증하지 않습니다. 호출 뒤에는 요청, 응답, 재조회 결과를 대화창에 반환합니다.
제 6 조 (오픈 베타 테스트 특별 고지 및 문의)
본 서비스는 현재 오픈 베타(Beta) 단계로 제공됩니다. 서비스 사용에 따른 보안 이슈, 개인정보 처리에 대한 기타 문의 사항은 본 앱의 배포 채널 또는 프로젝트 관리자를 통해 문의해 주시기 바랍니다.
SmartThings Rules Copilot
Privacy Policy
Effective Date: July 19, 2026
This service ("SmartThings Rules Copilot") highly values the privacy and security of your SmartThings credentials. We are committed to full transparency regarding data handling. This policy outlines the categories of data we process, the limited scope of their retention, and the strict technical security safeguards in place.
Section 1 (Scope & Purpose)
SmartThings Rules Copilot serves as an integration helper that relays metadata (Locations, Devices, and Rules) from your SmartThings environment. It enables you to safely draft home automation rules in natural language using authorized AI clients (such as Claude MCP or ChatGPT Actions). Official client instructions require explicit confirmation before a write tool is called.
Section 2 (Processed Data & Retention Period)
We process only the minimum amount of data required for integration, applying immediate server encryption and strict automated purge cycles.
| Data Categories | Retention and Purge Policy |
|---|---|
| SmartThings Personal Access Token (PAT) | Encrypted immediately with AES-GCM 256-bit in an isolated per-connection server store. Automatically and permanently purged within 24 hours. |
| AI Integration OAuth Tokens | OAuth access tokens used by Claude or ChatGPT are valid for one hour. Refresh tokens and authorization records may be retained for up to 30 days to prevent repetitive approvals on your private devices. |
| Browser Connection Cookie | The st_rule_copilot HttpOnly cookie keeps the browser and AI connection tied to the same random connection identifier for up to 30 days. It does not store SmartThings PATs, Claude/GPT OAuth tokens, or Authorization headers. |
| SmartThings Environment Metadata | Device names, room configurations, capabilities, and existing automation rules are parsed temporarily during active sessions and are never saved to permanent server storage. |
Section 3 (Data Security & Encryption)
To prevent unauthorized credential leakage, raw tokens are never saved on the browser’s local storage or cookies. Browser cookies store only a random connection identifier, while token handling is isolated to our secure backend environment. The service does not record raw sensitive data such as PATs, authorization headers, or request payloads in application logs.
Section 4 (User Rights & Data Deletion Levels)
You can revoke access and delete all stored tokens and sessions at any time using the UI console:
- Disconnect SmartThings: Wipes the encrypted SmartThings PAT from its isolated per-connection server store. Retains OAuth authorization and browser session data, allowing for quick reconnects later on trusted personal devices.
- Reset Connection: Purges the server-side PAT, terminates the OAuth links with the AI platforms, and clears browser session cookies. If you are using this app on a public or shared computer, you must perform a Reset Connection upon completion.
Section 5 (Execution Consent Policy)
Official GPT and Claude instructions require the client to show the final proposed rule structure (JSON) or status change target and obtain your explicit confirmation before calling a write tool. The server validates authentication, input schemas, rate limits, SmartThings responses, and same-PAT readbacks, but it cannot independently verify that confirmation occurred in an external AI chat. After a call, the request, API response, and subsequent verification readback are reported back into the chat.
Section 6 (Open Beta Inquiries)
This service is currently provided as an open beta. For questions, feedback, or data deletion inquiries, please reach out through the app distribution channel or to the project administrator.