Kirocal Legal

Privacy Policy

This Privacy Policy explains how Kirocal handles information when you use the app. Kirocal is a personal finance, subscription, asset, and receipt-management app.

Effective date: July 7, 2026  ·  Last updated: July 7, 2026

1. Who We Are

Kirocal is provided by HungBok (“HungBok,” “HeungBok,” “HeungBok Lee,” “we,” “us,” or “our”). For privacy questions, contact [email protected].

This Policy applies to the Kirocal iOS app and does not replace the privacy notices of Apple, iCloud, an AI provider, or any other third-party service you choose to use through the app.

2. Privacy at a Glance

Core finance dataYour entries, assets, subscriptions, and receipt records are designed to be stored on your device.
No Kirocal account requiredThe app does not require you to create a Kirocal user account for core features.
No ads or cross-app trackingKirocal does not use advertising SDKs or sell personal information.
Optional external processingAI receipt analysis, exchange-rate updates, App Store purchases, and optional iCloud backups involve third-party services.
Important: A receipt can contain personal or sensitive information. If AI Receipt Analysis is enabled, Kirocal may send the full receipt file and its visible contents to the selected AI provider for analysis. Read Section 6 before using that feature.

3. Information Kirocal Processes

Kirocal processes information that you enter, import, scan, photograph, or choose to attach to the app. The exact information depends on the features you use.

CategoryExamplesPurpose
Financial and budgeting recordsIncome, expenses, transfers, adjustments, dates, amounts, currencies, categories, tags, memos, recurring rules, subscriptions, payment-method labels, asset names, balances, and related notes.To create, display, calculate, organize, and restore your personal finance records.
Receipt contentReceipt images, scans, PDFs, virtual receipt images, merchant details, dates, item names, prices, taxes, discounts, order or invoice identifiers, payment details, and other text visible in a receipt.To store, display, search, generate a virtual receipt, and optionally analyze receipt content.
Settings and customizationLanguage, appearance, accent color, app icon choice, currencies, exchange-rate preferences, custom icons, notification settings, and export/import options.To personalize the app and apply your preferences.
Optional sensitive payment-method detailsInformation you voluntarily enter for a payment method, such as a full identifier or card number, expiration month/year, and CVC.To display the payment-method information you choose to keep in Kirocal. Kirocal does not process payments or connect to a card issuer.
Subscription entitlement dataPremium product identifier, current entitlement, expiration or renewal status, and transaction-related status supplied through Apple StoreKit.To determine access to Premium features and restore eligible purchases.
Optional AI provider credentialsAPI keys you enter for a supported third-party AI provider.To authenticate requests that you choose to send directly to that provider for AI Receipt Analysis.

Kirocal does not connect to your bank, card issuer, brokerage, or other financial institution, and it does not initiate payments or transfers on your behalf.

4. Local Storage, Keychain, and Backups

Local app storage

Core Kirocal records are stored in the app’s local storage on your device. We do not operate a separate Kirocal account system or a general-purpose Kirocal backend that receives a copy of those records.

Apple Keychain

Kirocal uses Apple Keychain storage for information that needs extra local protection, including optional AI-provider API keys, optional sensitive payment-method details, and usage-limit records. Keychain retention is controlled by iOS and can differ from ordinary app storage; deleting the app may not remove every Keychain item automatically.

Exports and backups

You may create an export or backup file. The contents depend on the options selected in the app. A full backup can include your finance records, receipt files, settings, custom icons, sensitive payment-method details, and AI-provider API keys. AI-provider keys are not included in ordinary exports unless the relevant option is selected, but a full backup includes them.

Backups saved to the device remain in Kirocal’s local app storage. When you select iCloud as the backup destination and iCloud is available, the backup is stored in your Apple iCloud container at Documents/KirocalBackups and may sync through Apple’s iCloud service. You are responsible for choosing a secure export destination and protecting any backup file you share, upload, or store outside Kirocal.

5. Device Permissions

  • Camera: requested only when you choose to photograph or scan a receipt. You can deny or revoke access in iOS Settings; camera-based receipt capture will then be unavailable.
  • Photos: Kirocal uses Apple’s system photo picker when you select a receipt image. The app receives the photo or item you select rather than requesting broad access to your photo library.
  • Files: Kirocal accesses a file only when you choose it through the system file picker, for example to attach a receipt or import a backup.
  • Notifications: requested only if you enable record or subscription-payment reminders. Notifications are scheduled locally on your device.
  • iCloud: used only when you choose the optional iCloud backup destination and your device’s iCloud configuration permits it.

6. AI Receipt Analysis

AI Receipt Analysis is an optional feature intended to extract suggested receipt fields. It is not required to create, edit, or store receipts. You can disable it in Kirocal Settings.

What is sent: When AI Receipt Analysis runs, Kirocal sends the attached receipt image, scan, PDF, or other receipt file—together with instructions to extract receipt fields—to the AI provider selected in your Settings. The file may include every item visible in it, such as merchant details, dates, purchases, totals, telephone numbers, addresses, order or invoice numbers, masked or unmasked payment-related text, and other personal information. Do not use AI Receipt Analysis with material you are not authorized to share.

When the AI setting is enabled, Kirocal may begin analysis after you attach, scan, import, or photograph a non-manual receipt, and analysis can also be started from the Analyze control. Disable AI Receipt Analysis before attaching receipts if you do not want the app to send receipt content to an AI provider.

The AI result is returned to the app as suggested fields for your review. AI output can be inaccurate, incomplete, or unsuitable for your circumstances. You remain responsible for reviewing and correcting it before saving a record or relying on it.

The built-in AI option uses the Google Gemini API. You may instead select Google Gemini, OpenAI, Anthropic, or xAI and enter your own API key. Your key is stored locally in Apple Keychain and is sent directly to the provider you select to authenticate that provider request. Provider processing, retention, account association, service availability, and data-use practices are controlled by the selected provider’s own terms and privacy policy.

7. Third-Party Services

Kirocal may connect directly from your device to the following services when you use the corresponding feature. These services are not operated by HungBok. Their privacy notices govern their processing of information received by them.

ServiceWhen UsedInformation Involved
Apple App Store and StoreKitPurchasing, restoring, or checking Premium access.Apple processes billing and purchase transactions. Kirocal uses StoreKit entitlement information to determine Premium access.
Apple iCloudOnly when you select iCloud backup and it is available.The backup file and its included contents are stored or synchronized through your iCloud account.
Google GeminiBuilt-in AI Receipt Analysis or a user-selected Gemini provider.The receipt file and extraction instruction; your own Gemini API key where you use your own key.
OpenAI, Anthropic, or xAIOnly when you select that provider and configure an API key.The receipt file and extraction instruction, plus the API credential needed to authenticate the request.
Frankfurter APIWhen you request currency or exchange-rate updates.The selected base and quote currency codes. Standard network information, such as an IP address, may be processed by the service as part of serving the request.

Provider links: Apple, Google, OpenAI, Anthropic, xAI, and Frankfurter.

8. Advertising, Tracking, and Accounts

Kirocal does not use advertising SDKs, does not sell personal information, and does not use your data for cross-app or cross-site behavioral advertising. Kirocal does not require a Kirocal account for its core features and does not include a Kirocal-operated analytics or crash-reporting SDK in the current app build.

This statement does not limit the independent data practices of Apple, iCloud, an AI provider, the exchange-rate service, or another third-party service that you choose to use.

9. Your Choices and Deletion

  • You can edit or delete finance records, receipts, assets, subscriptions, and settings within Kirocal where the relevant control is available.
  • You can disable AI Receipt Analysis or remove a third-party AI API key in Kirocal Settings.
  • You can deny or revoke Camera and Notifications permissions through iOS Settings.
  • You can delete backup files using Kirocal’s backup controls or through the storage location where you saved or exported them, including iCloud Drive where applicable.
  • You can stop using Kirocal at any time by removing the app and managing any active Premium subscription through your Apple Account. Because iOS Keychain may retain certain protected items after an app is deleted, removing the app alone may not remove every locally stored Keychain item.

Because core data is ordinarily stored on your device rather than on a Kirocal-operated server, we generally cannot access, retrieve, modify, or delete your local records for you. For questions about your data choices, contact us at [email protected].

10. Security

Kirocal relies on iOS security features, local app storage, Apple Keychain for designated sensitive values, and HTTPS for supported network requests. However, no storage method, device, network connection, third-party service, backup, or AI service is completely secure. Protect your device, Apple Account, backup destinations, and API keys. Do not place information in a receipt, memo, export, or AI request unless you are comfortable with the applicable storage and sharing described in this Policy.

11. Children

Kirocal is not directed to children. Do not use the app to submit a child’s personal information unless you have lawful authority to do so. If you believe personal information has been submitted in a way that requires action, contact us at [email protected].

12. International Processing

If you use iCloud, an AI provider, the App Store, or the exchange-rate service, information may be processed in countries other than the one where you live, according to that provider’s infrastructure and policies. By using an optional third-party service through Kirocal, you understand that the provider’s international data-transfer practices may apply.

13. Changes to This Policy

We may update this Privacy Policy when Kirocal’s features, third-party integrations, or legal requirements change. The updated policy will be posted on this page with an updated “Last updated” date. Review this page periodically for changes.

14. Contact

For privacy questions or concerns about Kirocal, contact:

HungBok
Email: [email protected]