Privacy Policy

Seokgamoney Privacy Policy

Version 2.2 · Effective 6 October 2026

This revision takes effect on 6 October 2026. Until then, Version 2.0 applies. See the change history in Section 15 for what changed.

This is a translation. The Korean version is the governing text.

At a glance

We collect only your Google, Apple, Kakao or LINE login details, step counts, LUCK and items, Wish Lantern content and purchase records. No phone number, date of birth or precise location.

Photos you use for the moktak, mala beads or outfits stay on your phone and are never uploaded. Only a photo attached to a Wish Lantern is stored on our servers.

Wish Lantern text is processed by OpenAI to check for inappropriate content and to translate it.

Your conversations with the AI monk are processed by AI to write replies and are stored on our servers so the conversation can continue.

You can delete your account from App › Profile › Settings and more, and your data is erased. Ad tracking can be turned off in your phone settings.

Bug Hole Inc. ("the Company") operates the mobile application Seokgamoney ("the Service") and complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws. This policy explains, in plain language, what personal information we collect and why, how long we keep it, who processes it on our behalf, and how you can exercise your rights.

1. Information we collect and how

We collect only the minimum information needed to run the Service. "Required" items in 1.1 to 1.3 are necessary to perform the service contract with you and are processed without separate consent under Article 15(1)(4) of the Personal Information Protection Act. Among the automatically collected items in 1.4, those used for service stability, fraud prevention and nonpersonalised ads rest on Article 15(1)(6) (legitimate interest), while the advertising identifier and behavioural data for personalised ads are used on iOS only if you allow tracking (ATT), in the EEA and UK only if you consent on the ad consent screen, and elsewhere (including Android in Korea) on the basis of the notice and opt out tools in Section 7 (resetting or deleting the advertising ID, opting out of ad personalisation), in line with the Korean Personal Information Protection Commission's Guidelines on Online Personalised Advertising. "Optional" items are collected only with your consent, and you can use every core feature without agreeing to them.

1.1. Signup and account (required)

CategoryItemsSource
Google loginEmail address, profile name (never displayed. Used only to help identify the account), Google account identifierProvided by Google when you link your account
Apple loginApple account identifier, email address (Apple's relay address if you chose "Hide My Email")Provided by Apple when you link your account
Kakao loginKakao member number (a unique identifier Kakao assigns per app). We do not receive your name, email or profile photoProvided by Kakao when you link your account
LINE loginLINE user identifier (a unique identifier LINE assigns per service provider). We do not receive your name, email or profile photoProvided by LINE when you link your account
CommonInternal user ID (Firebase UID), app language, operating system, app version, signup time, the versions of the Terms, this policy and the wish AI processing consent you agreed to and when, result of the age 14 confirmationGenerated automatically or entered by you at signup

1.2. Using the Service (required)

FeatureItemsSource
Walking rewardsDaily step countMotion and fitness sensors and health data on your device (iOS Motion & Fitness and step counts from the Apple Health app, Android Physical Activity Recognition and Health Connect step counts). On iOS, we only read step counts recorded in the Apple Health app by Apple devices (iPhone and Apple Watch). Manually entered steps and steps recorded by other apps are not used. Raw sensor and health data are processed only on your device, and only the resulting step count is stored on our servers. On Android, we request Health Connect background read permission so that steps taken while the app is closed can count toward rewards. This permission is not used for any health data other than step counts. Health data is never used for advertising or marketing and is never shared with third parties.
LUCK economyLUCK earned and spent, moktak and mala tap counts, practice (attendance) recordsGenerated as you use the Service
Boutique and customizationItems owned, equipped state, items purchased with LUCKGenerated as you use the Service
Wish LanternsWish text (up to 120 characters), display name (up to 40 characters), avatar look, language, an optional photo, submission, approval, rejection and appeal records, reports and blocks from other users, records of praying togetherEntered or attached by you
Friend invitesInvite code, internal IDs of inviter and invitee, reward recordsGenerated as you use the Service
Push notificationsDevice push token (FCM), per category notification settings and when you changed themGenerated when you allow notifications
Support and reportsEmail address, message, attachmentsSent by you by email
AI monk chatWhat you type, the AI monk's replies, time of each message, a one line memo used to continue the conversation, usage countCollected when you send a message. The conversation and memo are sent to an AI language model to generate replies

1.3. Paid purchases (required, when you pay)

ItemsSource
App Store transaction identifier (Apple transaction ID or Google purchase token), product ID, purchase, refund and cancellation time, payment status, an encrypted account token that links the purchase to your accountProvided by Apple App Store or Google Play

We never collect or store card numbers, bank accounts or other payment method details. Apple and Google process those under their own privacy policies.

1.4. Automatically collected information (required)

  • Usage records, access times, in app events (screens viewed, features used), device model, OS version, app version, approximate location at country or region level (estimated from IP address), app integrity token (Firebase App Check)
  • Advertising identifier (iOS IDFA, Android Advertising ID). On iOS it is used for personalised ads only if you allow tracking through App Tracking Transparency. If you decline, you see nonpersonalised ads.
  • Ad impressions, clicks and rewarded ad completion records

1.5. Optional items (only with your consent)

ItemPurposeNotes
Marketing and event notification opt in and its timestampPush notifications about new items, events and offersOff by default. Change any time in app settings

1.6. Information we do not collect or never send off your device

  • Photos used for moktak, mala beads and Magic Tee and Magic Pants. Photos you pick from your library and the processed results are stored only on your device and are never uploaded. They are deleted when you delete the app.
  • We do not collect phone numbers, dates of birth, gender, precise location, government ID numbers, or sensitive information such as religion or political views. However, anything you choose to write in an AI monk chat may be included in the chat record, so we recommend not sharing sensitive information there.
  • A photo attached to a Wish Lantern is the one exception and is stored on our servers (see 1.2).

2. Why we use your information

PurposeInformation used
Identifying you, signing you in, syncing across devices, recovering your account1.1
Awarding LUCK for steps, moktak, mala and practice. Paying rewards. Preventing fraudulent earning1.2, 1.4
Providing paid and free features such as boutique items and Wish Lanterns. Verifying purchases. Handling refunds and cancellations. Restoring purchases1.2, 1.3
Reviewing Wish Lantern posts (AI screening, and human review where needed), translating them, displaying them publicly, handling reports, blocks and appeals1.2
Friend invite rewards, detection of multiple accounts and abuse, and a 7 day rejoin restriction after account deletion1.1, 1.2, 1.4
Sending service notifications (practice reminders, rewards received, moderation results)1.2
Sending marketing and event notifications1.5 (with consent)
Serving ads, verifying rewarded ad views, measuring ad performance, personalised ads (with consent on iOS and in the EEA/UK. Elsewhere on the basis of the notice and opt out in Section 7)1.4
Keeping the Service stable, analysing errors, usage statistics, improving features1.4
Responding to violations of the Terms, resolving disputes, meeting legal obligationsAll
Individually notifying you of important changes to the Terms or this policy1.1
Providing AI monk chat (AI generated replies), managing free and extra usage, and showing help contacts in a crisis1.2

3. How long we keep your information

We destroy personal information without delay once its purpose is fulfilled, except as follows.

InformationRetentionBasis
Account, LUCK, item and practice recordsUntil you delete your account. Destroyed immediately on deletionProviding the Service
Wish Lantern posts (text, photo, display name)No longer shown to other users once the display period ends (1 day basic, 7 days premium). Destroyed when you ask us to delete the post. On account deletion they stop being shown immediately, are kept for 30 days, then destroyedProviding the Service (your lantern history), handling reports and disputes right after account deletion
Rejection, appeal and refund request records for paid Wish Lanterns, and how they were handled3 years from handlingRecords of consumer complaints and dispute resolution (Article 6 of the Electronic Commerce Act Enforcement Decree)
Other lantern moderation, report, block and operator action recordsUntil account deletionPreventing repeat abuse, handling appeals (Company standard)
Friend invite records (invite code, internal IDs of inviter and invitee, invite reward records. For Kakao and LINE login users the internal ID contains the member number or user identifier)Until the Service ends (kept after account deletion). On deletion you are removed from the other person's friend roster immediatelyProviding the Service, preventing duplicate invite rewards (legitimate interests)
Payment, refund and cancellation records5 yearsRecords of payment and supply of goods (Electronic Commerce Act)
Records of contracts and withdrawals5 yearsElectronic Commerce Act
Access logs (time, IP address)3 monthsArticle 41 of the Enforcement Decree of the Protection of Communications Secrets Act (three month retention of log and access tracking records)
Internal ID and reason for accounts restricted for abuse (multiple accounts, fraud, refund abuse)1 year from restrictionPreventing abuse by registering again (legitimate interest)
An irreversibly hashed value of the login identifier of a deleted account, the deletion time, and whether a friend invite code was usedUntil the Service endsPreventing immediate rejoining and duplicate invite rewards (legitimate interests)
AI monk chat records (messages, replies, memo)[TO CONFIRM: retention period]. Erased on account deletionProviding the Service (continuing earlier conversations)
Support emails3 years after resolutionRecords of consumer complaints and dispute resolution (Article 6 of the Electronic Commerce Act Enforcement Decree)

Information we must keep by law after account deletion is stored separately and used only for that purpose. Information we keep under our own standards is erased on account deletion, except where the table above states its own retention period.

4. Sharing with third parties

We do not share your personal information with third parties, except in the following cases.

  1. When you have given prior consent.
  2. When required by law, or by an investigative agency or court following the procedures set by law.
  3. Public Wish Lanterns. When you post a Wish Lantern, the wish text, display name, avatar look, attached photo (if any), the number of people who prayed together and translations are shown to other logged in users of the Service. This is a disclosure you choose by posting. Your account ID and email are never shown.
  4. Behavioural data sent to advertising partners. The ad SDKs listed in Section 7 collect advertising identifiers and device information directly to serve ads.

5. Processors we entrust

We entrust the following processing to service providers and supervise them under Article 26 of the Personal Information Protection Act.

ProcessorEntrusted work
Google LLC (Firebase)Authentication, database and file storage, server functions, push delivery, app integrity checks, usage analytics
Apple Inc.Sign in with Apple, in app payment processing and receipt verification
Kakao Corp.Kakao login, unlinking your Kakao account when you delete your account
LY CorporationLINE login, unlinking your LINE account when you delete your account
Google LLC (Google Play)In app payment processing and purchase verification
OpenAI, L.L.C.AI screening and translation of Wish Lantern posts (large language model). Wish text passes through a relay server the Company runs in Korea (Seoul). Attached photos and account information are not sent
Amazon Web Services, Inc.Hosting the AI monk chat server and chat record database (Seoul region)
[TO CONFIRM: model provider legal name]Generating AI monk replies (large language model). The conversation and memo are sent

6. International transfers

Because the processors above process and store data outside Korea, we transfer personal information abroad under Article 28-8(1)(3) of the Personal Information Protection Act (outsourcing and storage necessary to perform the contract with you) and disclose the details here.

Recipient (contact)CountryWhen and howItemsPurposeRetention
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA (googlekrsupport@google.com), Firebase Authentication, Analytics, Cloud Messaging, App CheckUSASent over the network as you use the ServiceAccount data in 1.1, push token in 1.2, usage records, device info and app integrity token in 1.4Authentication, analytics, push delivery, app integrity checksUntil account deletion or end of engagement
Google LLC (as above), Firebase Firestore and StorageRepublic of Korea (Seoul region)Sent over the network as you use the ServiceStored data in 1.1, 1.2, 1.3 and Wish Lantern photosData and file storageUntil account deletion or end of engagement
Google LLC (as above), Cloud FunctionsRepublic of Korea (Seoul region)As you use the ServiceItems in 1.2 and 1.3 handled by server functionsReward payment, purchase verification, Wish Lantern moderation and translationUntil account deletion or end of engagement
Apple Inc., One Apple Park Way, Cupertino, CA, USA (apple.com/legal/privacy/contact)USASent over the network at login and purchaseApple account identifier, email, transaction dataLogin, payment processingUntil end of engagement
LY Corporation, Kioi Tower, 1-3 Kioicho, Chiyoda-ku, Tokyo, Japan (lycorp.co.jp/en/company/privacypolicy)JapanSent over the network at LINE login and account deletionLINE user identifier, login tokenLogin, account unlinkingUntil end of engagement
OpenAI, L.L.C., San Francisco, CA, USA (privacy@openai.com)USASent over the network when you submit a Wish LanternWish text, languageModeration and translationPer OpenAI's data retention policy
[TO CONFIRM: model provider legal name, address, privacy contact][TO CONFIRM: country]Sent over the network when you chat with the AI monkConversation, memo, languageGenerating replies[TO CONFIRM: provider retention policy]
AppLovin Corp., 1100 Page Mill Road, Palo Alto, CA, USA (privacy@applovin.com)USASent directly by the SDK when an ad is requestedAdvertising ID, device and OS info, IP address, app info, impression and click recordsServing and measuring adsPeriod set in the AppLovin privacy policy
Unity Technologies, 30 3rd Street, San Francisco, CA, USA (DPO@unity3d.com)USASent directly by the SDK when an ad is requestedAs aboveServing and measuring adsPeriod set in the Unity privacy policy
Bytedance Pte. Ltd. (Pangle), 1 Raffles Quay, #26-10, Singapore (contact via https://www.pangleglobal.com/privacy)SingaporeSent directly by the SDK when an ad is requestedAs aboveServing and measuring adsPeriod set in the Pangle privacy policy

You can refuse the transfer of personalised advertising data to ad partners through iOS App Tracking Transparency or by deleting or resetting your Android Advertising ID. If you do not want any transfer, you may stop using the Service by deleting your account. The Service cannot be provided without these transfers.

7. Behavioural information for advertising and how to opt out

ItemDetails
Behavioural information collectedAdvertising identifier (IDFA / Android Advertising ID), in app usage events, ad impressions, clicks and views, device and OS info, country level location
HowCollected automatically by the advertising and analytics SDKs bundled in the app while you use it
PurposeServing ads, verifying rewarded ad views, measuring ad performance, and interest based personalised ads (with ATT consent on iOS, with ad consent in the EEA/UK, and elsewhere on the basis of the notice and opt out tools in this table)
RetentionThe Company keeps it until account deletion, and ad partners keep it per their own policies
Ad partners that collect and process itDARO (DelightRoom Co., Ltd.), Google AdMob (Google LLC), AppLovin (AppLovin Corp.), Unity Ads (Unity Technologies), Pangle (Bytedance Pte. Ltd.)
Your controlsOn iOS, Settings › Privacy & Security › Tracking › turn off Seokgamoney. On Android, Settings › Google › Ads › "Opt out of Ads Personalization", or delete or reset the Advertising ID. EEA and UK users can "Ad privacy settings" on the Profile screen. Android users elsewhere, including Korea, see no separate in app consent screen. The device settings above are the opt out

We do not collect behavioural information for personalised advertising from users we know to be under 14, and we never identify you from behavioural data alone. If you opt out, you still see ads, but they are not based on your interests.

Partner privacy policies are available from DARO · Google · AppLovin · Unity · Pangle

8. Destruction of personal information

  1. Procedure. Information whose retention period has ended or purpose has been fulfilled is destroyed without delay (within 5 days). Information subject to a legal retention period is moved to separate storage and destroyed when that period ends.
  2. Method. Electronic files are permanently deleted in a way that cannot be recovered. On account deletion, your Firebase authentication account and user document are deleted immediately. Your Wish Lantern posts and photos stop being shown immediately, are kept for 30 days, then deleted. Only payment and dispute records we must keep by law are stored separately for the periods in Section 3.
  3. Inactive accounts. We do not convert accounts to a dormant state. You can delete a long unused account yourself at any time.

9. Your rights and how to exercise them

  1. You may at any time request access, correction, deletion, suspension of processing, withdrawal of consent, and data portability for your personal information.
  2. How
    • Delete account. App › Profile › Settings and more › Delete account. Processed immediately, and LUCK, items and purchase benefits are lost with it. Wish Lanterns stop being shown immediately and are deleted after 30 days.
    • Change notification consent. App › Profile › Settings and more › Notifications (service and marketing notifications are controlled separately).
    • Opt out of ad tracking. Device settings described in Section 7.
    • Revoke motion and fitness permission. Device Settings › Seokgamoney › Motion & Fitness (iOS), Physical activity and Health Connect (Android). Only walking rewards stop. Every other feature keeps working.
    • Delete a Wish Lantern or appeal a rejection. You can appeal a rejection on its result screen. To delete a posted wish, email the contact in Section 11.
    • Other access, correction or portability requests. Email the contact in Section 11. We respond within 10 days of receiving your request.
  3. Requests may be made by you, your legal guardian, or an authorised representative. We may ask you to confirm your identity through your signup email.
  4. Where the law limits access, correction or deletion, we will tell you why.
  5. You are responsible for keeping your information accurate and for not posting other people's personal information in Wish Lanterns or elsewhere.

10. Children under 14

  1. Only people aged 14 or older may use the Service. After login you must confirm on the consent screen that you are 14 or older. If you leave without confirming, you are logged out and no Service data is stored.
  2. We do not currently offer signup for children under 14 with a legal guardian's consent. If we introduce it, we will first add to this policy how consent is verified under Article 22-2 of the Personal Information Protection Act and how guardian information is handled.
  3. If we learn that we have collected personal information from a child under 14, we destroy it without delay. If a user tells us they are under 14, Service access stops at once, and the account and its personal information are deleted after a 7 day notice period. The user may delete the account at any time during that period, and a guardian may request deletion through the contact in Section 11.

11. Data protection officer and complaints

Data protection officerMyunggeun Hong, CEO
DepartmentSeokgamoney Service Operations
Emailseokgamoney108@gmail.com
Address2415, 2F, 19 Beopwon-ro 3-gil, Seocho-gu, Seoul, Republic of Korea

Contact us at the address above for any privacy question, complaint or remedy request. We will respond without delay.

You may also contact the following Korean authorities.

  • Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
  • Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
  • Supreme Prosecutors' Office Cybercrime Division (spo.go.kr / 1301)
  • National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)

12. Security measures

Under Article 29 of the Personal Information Protection Act we take the following measures.

  1. Organisational. Only a minimum number of staff handle personal information. Moderation and operator tools are accessible only to approved operator accounts, and every operator action is logged. We maintain an internal management plan.
  2. Technical. All traffic is encrypted with TLS. Database and file storage enforce access rules so that your data can be read or written only by you, by operators the Company authorises, and by server functions, and only Wish Lanterns you make public are shown to other users. App integrity checks (App Check) reduce the risk of tampered apps reaching our servers. Purchases are verified by our server directly with Apple and Google, and purchases are linked to accounts with one way encrypted tokens. Ad rewards are paid only through callbacks verified by our server.
  3. Physical. Data is stored in Google Cloud and Amazon Web Services data centres holding security certifications such as ISO 27001. The Company operates no physical servers of its own.

13. Automatic data collection tools

The Service uses no web cookies. The following SDKs collect usage information automatically.

SDKDataPurposeHow to refuse
Firebase AnalyticsIn app events, device info, approximate locationUsage statistics, improvementChange device ad tracking settings. Full refusal requires deleting the app
DARO, Google AdMob and mediation (AppLovin, Unity Ads, Pangle)See Section 7AdvertisingSee Section 7
Firebase Cloud MessagingPush tokenNotificationsTurn off device notification permission or in app notifications
Firebase App CheckApp integrity tokenSecurityCannot be refused (required to operate the Service)

14. Notice of use and provision

If the Company comes to meet the thresholds of Article 20-2 of the Personal Information Protection Act and Article 15-3 of its Enforcement Decree (1,000,000 or more data subjects, or 50,000 or more data subjects' sensitive or unique-identifier data), we will notify you at least once a year, by email or app notification, of how your personal information has been used and provided.

15. Changes to this policy

  1. We announce changes, with reasons, in the app and on this page at least 7 days before they take effect.
  2. Changes that matter to your rights (items collected, purposes, third party sharing, retention) are announced 30 days in advance and notified individually by your signup email or app notification.
  3. Change history
VersionEffectiveSummary
v1.010 June 2026First version (English)
v2.023 September 2026Korean governing version added. Added Google login, paid purchases, Wish Lanterns (OpenAI screening and translation), friend invites, push notifications, ad mediation, international transfers and behavioural data. Introduced age 14 confirmation and consent flow
v2.16 October 2026Added Kakao login and LINE login. New items collected (Kakao member number, LINE user identifier), new processors (Kakao Corp., LY Corporation) and a new international transfer (LY Corporation, Japan). Added the retention period for rejoin restriction records. Added DARO to ad partners. Corrected the retention period for friend invite records.
v2.26 October 2026Added items collected, purposes, retention and processors for AI monk chat

This policy takes effect on 6 October 2026.

16. Additional information for users in the EEA and UK

If you use the Service in the European Economic Area or the United Kingdom, the GDPR and UK GDPR also apply. Our legal bases are performance of the contract (1.1 to 1.3), legitimate interests (service stability, fraud prevention, nonpersonalised advertising) and consent (personalised advertising, marketing notifications, wish AI processing). In addition to the rights in Section 9, you have the right to object to processing and to lodge a complaint with the supervisory authority in your country. Your data is processed in the Republic of Korea, a country covered by an EU adequacy decision. Transfers to processors in the USA and other third countries rely on appropriate safeguards such as the Standard Contractual Clauses concluded with each processor. AI screening of Wish Lanterns is followed by human review and an appeal process, so it is not a solely automated decision with legal effect. The Company has not appointed an EEA or UK representative. Contact us through Section 11.