1. Who We Are
Kirocal is provided by HeungBok Lee, doing business as HungBok (“HungBok,” “we,” “us,” or “our”). For privacy questions or requests, contact [email protected].
This Policy applies to the Kirocal mobile application for iOS and Android, Kirocal’s website, and related support services (collectively, the “Services”). Platform or version-specific features may differ. This Policy explains Kirocal’s practices and does not replace the privacy notices that Apple, Google, an advertising partner, an AI provider, or another third party provides for its own processing.
2. Privacy at a Glance
3. Information Kirocal Processes
Kirocal processes information that you enter, import, scan, photograph, or choose to attach to the app. The exact information depends on the features you use.
| Category | Examples | Purpose |
|---|---|---|
| Financial and budgeting records | Income, expenses, transfers, adjustments, dates, amounts, currencies, categories, tags, memos, recurring rules, subscriptions, payment-method labels, asset names, balances, and related notes. | To create, display, calculate, organize, and restore your personal finance records. |
| Receipt content | Receipt images, scans, PDFs, virtual receipt images, merchant details, dates, item names, prices, taxes, discounts, order or invoice identifiers, payment details, and other text visible in a receipt. | To store, display, search, generate a virtual receipt, and optionally analyze receipt content. |
| Settings and customization | Language, appearance, accent color, app icon choice, currencies, exchange-rate preferences, custom icons, notification settings, and export/import options. | To personalize the app and apply your preferences. |
| Service and template selections | Names or identifiers of services you select from convenience templates, such as a streaming, software, utility, or subscription service, and any schedule or transaction details you create from that template. | To display the selected service, its identifying name or icon where lawfully available, and to create the record you request. These selections are not sent to advertisers for ad personalization. |
| Optional sensitive payment-method details | Information you voluntarily enter for a payment method, such as a full identifier or card number, expiration month/year, and CVC. | To display the payment-method information you choose to keep in Kirocal. Kirocal does not process payments or connect to a card issuer. |
| Subscription entitlement data | Premium product identifier, current entitlement, expiration or renewal status, and transaction-related status supplied through Apple StoreKit. | To determine access to Premium features and restore eligible purchases. |
| Optional AI provider credentials | API keys you enter for a supported third-party AI provider. | To authenticate requests that you choose to send directly to that provider for AI Receipt Analysis. |
| Support and diagnostic information | Your email address and message; app and OS version, device model, locale, time zone, feature status, and record counts included in a prefilled support message. If the local data store fails, the email composer may also attach the App’s database files, which can contain your finance and receipt records. | To respond to support requests, diagnose data-store failures, protect the App, and improve reliability. You can review, edit, remove attachments from, or cancel the message before sending. |
| Analytics and app-usage data | App-instance or installation identifiers, sessions, screens viewed, feature interactions, approximate timestamps, app version, device model, operating system, language, general region, performance, and diagnostics. We do not intentionally place finance amounts, receipt text, card details, API keys, or free-form memos in analytics events. | To understand feature use, diagnose problems, measure releases, prevent abuse, and improve the Services. |
| Advertising data | IP address, approximate location inferred from IP, advertising identifiers such as IDFA or Android Advertising ID when permitted, App Set ID or app/developer-bounded identifiers, ad views and clicks, app launches and taps, consent signals, and advertising diagnostics. | To request, deliver, personalize where permitted, limit, measure, frequency-cap, secure, and prevent fraud in advertising. |
| Website data | IP address, browser and device information, page views, referrer, cookie or local-storage identifiers, and consent choices when Kirocal uses Google Analytics or related measurement on its website. | To operate, secure, measure, and improve the website. Where required, non-essential analytics begins only after consent. |
| Network request information | IP address, user agent, device or app identifiers, request time, and ordinary request metadata that a service receives when handling a request. | To deliver requested features, maintain security, detect fraud, and operate the relevant service. |
Kirocal does not connect to your bank, card issuer, brokerage, or other financial institution, and it does not initiate payments or transfers on your behalf.
4. Storage, Cloud Features, Secure Storage, Exports, and Backups
Local app storage
Core Kirocal records are stored in the App’s local database on your device. We do not operate a separate Kirocal account system or a general-purpose Kirocal backend that receives a copy of those records.
Optional iCloud sync
If you enable iCloud Sync, which is available without a Premium subscription on supported Apple versions, the App uses your private Apple CloudKit container to synchronize entries, receipts, transfers, recurrence data, and related records across devices signed in to the same Apple Account. Apple processes and stores that data under its terms and privacy policy. Turning sync off stops the App from using CloudKit after the required relaunch, but may not by itself delete copies already held in iCloud or on another device.
Platform secure storage
Kirocal uses Apple Keychain on iOS and Android Keystore-backed secure storage on Android for optional AI-provider API keys, optional sensitive payment-method details, and AI usage-limit records. Platform retention can differ from ordinary App storage; uninstalling or restoring the App may not remove or may later restore every protected item, depending on operating-system and backup behavior.
Exports and backups
You may create an export or backup file. The contents depend on the options selected in the app. A full backup can include your finance records, receipt files, settings, custom icons, sensitive payment-method details, and AI-provider API keys. AI-provider keys are not included in ordinary exports unless the relevant option is selected, but a full backup includes them.
Backups saved to the device remain in App-managed local storage. If you select iCloud as the destination, the backup is stored in your iCloud container at Documents/KirocalBackups. Exports leave the App through the destination or share option you select. You are responsible for protecting exported or backed-up files and for deleting copies from every location where you placed them.
5. Device Permissions
- Camera: requested only when you choose to photograph or scan a receipt. You can deny or revoke access in iOS or Android Settings; camera-based capture will then be unavailable.
- Photos and media: Kirocal uses the platform’s system picker where available. The App receives the item you select rather than requesting broad library access unless a feature clearly requests broader permission.
- Files: Kirocal accesses a file only when you choose it through the system file picker, for example to attach a receipt or import a backup.
- Notifications: requested only if you enable record or subscription-payment reminders. Notifications are scheduled locally on your device.
- iCloud: used only when you enable iCloud Sync or choose iCloud as a backup destination and your Apple Account and device configuration permit it.
6. AI Receipt Analysis
AI Receipt Analysis is optional, disabled by default, and not required to create, edit, or store a receipt manually. It extracts suggested receipt fields. You can enable or disable it at any time in Kirocal Settings.
Before the first transfer to the AI provider you select, Kirocal displays the provider’s name, the categories of receipt data to be sent, and the purpose of the transfer, and asks you to take an affirmative action to permit it. Kirocal does not treat closing the disclosure, navigating away, or selecting a refusal option as consent, and no receipt is sent if you decline. After you grant permission and enable the feature, analysis may run when you select the Analyze control or as described in the disclosed receipt workflow. Kirocal asks again if you select a different provider or the relevant data use materially changes. Disabling the feature prevents new AI requests but cannot recall information already sent.
The AI result is returned to the app as suggested fields for your review. AI output can be inaccurate, incomplete, or unsuitable for your circumstances. You remain responsible for reviewing and correcting it before saving a record or relying on it.
The built-in option sends requests directly to the Google Gemini API using an App-provided credential. You may instead select Google Gemini, OpenAI, Anthropic, or xAI and enter your own API key. Your key is stored using platform secure storage and sent directly to the selected provider to authenticate your request. The selected provider may process and retain submitted content and request metadata under its terms, privacy notice, account settings, and API plan. Review those materials before use; do not submit a receipt if the provider’s practices are unacceptable to you.
Kirocal does not use receipt content sent for AI analysis to personalize advertising or populate analytics events. To the extent HungBok selects or controls a service provider, we require it to protect personal data consistently with this Policy and applicable Apple and Google Play requirements. A provider you independently select and access using your own key may also process data under your direct agreement with that provider.
7. Third-Party Services
Kirocal may connect directly from your device to the following services when you use the corresponding feature. We limit data to what is reasonably necessary for disclosed purposes. Advertising data may be used for personalization or cross-context measurement only where permitted by platform rules, applicable law, and your consent choices. Core finance records and receipt contents are not provided to advertising partners for those purposes.
| Service | When Used | Information Involved |
|---|---|---|
| Apple App Store and StoreKit | Purchasing, restoring, or checking Premium access. | Apple processes billing and purchase transactions. Kirocal uses StoreKit entitlement information to determine Premium access. |
| Google Play and Google Play Billing | Installing or updating the Android app; purchasing, restoring, or checking Premium access. | Google processes store, billing, purchase, device, and account-related information. Kirocal uses entitlement information to provide Premium access. |
| Apple iCloud and CloudKit | When you enable iCloud Sync or select iCloud backup. | Synced App records, receipt data, or a backup file and all content included in it. |
| Google Analytics for Firebase | When analytics collection is permitted for the relevant App installation or website session. | App-instance identifiers, usage events, device/app information, general region, performance, and diagnostics. Advertising identifiers or Google signals are used only when enabled and permitted. |
| Google Mobile Ads (AdMob) and disclosed ad partners | When an ad-supported version requests or displays advertising. | IP address, approximate location, ad or app-scoped identifiers, app interactions, ad impressions/clicks, consent signals, and diagnostics for advertising, measurement, analytics, and fraud prevention. |
| Google Gemini | Built-in AI Receipt Analysis or a user-selected Gemini provider. | The receipt file and extraction instruction; your own Gemini API key where you use your own key. |
| OpenAI, Anthropic, or xAI | Only when you select that provider and configure an API key. | The receipt file and extraction instruction, plus the API credential needed to authenticate the request. |
| Frankfurter API | When you request currency or exchange-rate updates. | The selected base and quote currency codes. Standard network information, such as an IP address, may be processed by the service as part of serving the request. |
| Your email provider and HungBok’s email service | Only when you choose to send a support message. | Your email address, message, prefilled diagnostics, and any attachments that remain in the composer when you send. |
Provider links: Apple, Google, Google partner technology, OpenAI, Anthropic, xAI, and Frankfurter. The current list of ad partners and their purposes is also presented in the consent-management interface where required.
8. Analytics, Advertising, Tracking, and Consent
Google Analytics
Kirocal may use Google Analytics for Firebase in its mobile apps and Google Analytics on its website. Analytics helps measure installations, sessions, screens, feature interactions, releases, performance, and errors. Kirocal does not intentionally send finance amounts, receipt contents, payment credentials, API keys, or free-form notes to Analytics. An App installation may be represented by a randomly generated app-instance identifier.
Google AdMob
Ad-supported versions may use Google Mobile Ads (AdMob). The SDK may automatically collect and share IP address, user-product interactions, diagnostics, and device or account identifiers, including the Android Advertising ID, App Set ID, IDFA, or app/developer-bounded identifiers where available and permitted. Google and disclosed advertising partners may use this data to deliver contextual, personalized, or limited ads; measure impressions, clicks, conversions, and frequency; perform analytics; and prevent invalid traffic and fraud.
Ads are third-party content and may link to external services. Kirocal does not control every ad or the destination’s privacy practices. We require advertising providers used by Kirocal to comply with applicable law, store rules, and protections consistent with this Policy. Mediation or additional ad partners will be disclosed in the consent interface and this Policy as required.
Consent and platform controls
- iOS: If Kirocal seeks access to IDFA or engages in tracking as Apple defines it, the App will first request permission through App Tracking Transparency. Refusing ATT does not block core record-keeping features; ads may instead be contextual or limited.
- Android: You can reset or delete the Android Advertising ID in Android Settings. Kirocal and its SDKs will respect the resulting platform signal and will not substitute a prohibited persistent identifier for advertising.
- EEA, UK, and Switzerland: Where required, Kirocal uses Google’s User Messaging Platform or another Google-certified consent-management platform before requesting personalized ads or non-essential analytics storage. The interface identifies relevant partners and purposes and provides a privacy-options entry point to withdraw or change consent.
- Other regions: Kirocal provides any legally required notice, opt-out, restricted-data-processing, or “Do Not Sell or Share” choice. Global Privacy Control signals are honored where applicable to the processing.
Kirocal does not sell personal and sensitive user data for money. Advertising disclosures may constitute “sharing” or targeted advertising under some laws; where that applies, you may opt out through the in-App privacy choices or applicable device controls. Kirocal does not require a Kirocal account for core features.
9. Retention, Your Choices, Consent, and Deletion
Local records remain until you delete them, use the in-App reset controls, restore over them, or remove the App, subject to platform secure-storage and backup behavior. Device and cloud backups remain until deleted from the relevant location. CloudKit-synced records remain according to your deletions, sync state, other devices, and Apple’s retention practices. AI providers, app stores, advertising services, exchange-rate services, and email providers retain information under their policies.
Kirocal configures Google Analytics user-level and event-level data retention for no more than 14 months, unless a shorter period is selected or required. Standard aggregated reports may remain longer because Google’s retention control does not apply to those reports. Advertising data is retained by Google and the applicable ad partners for the periods stated in their policies and as needed for billing, measurement, security, fraud prevention, and legal compliance. Consent records are kept as needed to demonstrate and honor your choices. We retain support messages and attachments only as long as reasonably necessary to answer the request, diagnose the issue, prevent abuse, meet legal obligations, and maintain appropriate records; we then delete or de-identify them where reasonably practicable.
- You can edit individual records or use Kirocal’s reset controls to delete entries or all App data. If iCloud Sync is active, deletions are intended to sync to other connected devices; allow synchronization to finish.
- You can withdraw consent for future AI sharing by disabling AI Receipt Analysis and can remove a user-provided AI API key in Settings. Contact the selected provider about data already received.
- You can change analytics and advertising consent through Kirocal’s privacy options where offered, deny iOS ATT, and reset or delete the Android Advertising ID through device settings. A change affects future processing and cannot recall data already lawfully processed.
- You can deny or revoke Camera, Photos/Media, and Notifications permissions through iOS or Android Settings.
- You can delete App-managed backups using Kirocal’s backup controls and must separately delete exported copies or iCloud data from the locations where they are stored.
- You can review and cancel a support email before sending it. After sending, you may request deletion from HungBok, subject to legal and security exceptions.
- You can stop using Kirocal by removing the App and managing any active Premium subscription through your Apple Account or Google Play account. Deleting the App does not cancel a subscription or necessarily remove cloud, secure-storage, analytics, advertising, or exported copies.
Because core data is ordinarily held on your device or in your private iCloud container, HungBok generally cannot access, retrieve, or delete it for you. For information held in our support mailbox, or for privacy questions, email [email protected].
10. Security
Kirocal uses iOS and Android security controls, App sandboxing, platform secure storage for designated sensitive values, private CloudKit storage when enabled, and HTTPS or TLS for supported network requests. Access is limited to what is reasonably necessary to operate and support the Services. No method is completely secure. Protect your device, Apple or Google account, backup destinations, email drafts, and API keys. Storing a full card number or CVC creates heightened risk; Kirocal is not a payment processor or certified card vault.
11. Children
Kirocal is a general-audience personal finance tool. It is not designed, directed, or marketed to children, is not intended for the Apple Kids Category, and is not intended to be enrolled in Google Play’s Designed for Families program. The Services are not intended for anyone under 13, or under the higher minimum digital-consent age that applies where they live.
We do not knowingly collect personal information from children or knowingly serve them personalized advertising. A parent or guardian who believes a child submitted information to HungBok, Analytics, an advertising partner, or a support channel should contact us. We will investigate and delete information under our control where required. Do not use AI, support, or export features to disclose a child’s information unless you have lawful authority.
12. International Processing and Your Rights
Apple, Google, analytics and advertising partners, AI providers, exchange-rate services, and email providers may process information in countries other than where you live. Their transfer mechanisms and regional terms apply. Where law provides rights to access, correct, delete, restrict, object to, opt out of sale, sharing, targeted advertising, or profiling, withdraw consent, or receive a copy of information held by HungBok, you may exercise them through Kirocal’s privacy choices or by contacting us. You may also complain to a local data-protection authority. Rights may be limited by law and often must be exercised directly on your device or with the provider that holds the data.
13. Policy Changes
We may update this Policy when Kirocal’s platforms, features, advertising or analytics partners, third-party integrations, or legal requirements change. We will post the revision with a new date and, when reasonably practicable, provide an in-App notice for a material change. A new type of personal-data sharing will not rely solely on continued use where law, Apple, or Google Play requires a new disclosure or consent.
14. Contact
For privacy questions or concerns about Kirocal, contact:
HeungBok Lee, doing business as HungBok
Email: [email protected]
Version History
Previous published versions of this Privacy Policy are preserved for reference.