Seokgamoney Privacy Policy
Version 2.2 · Effective 6 October 2026
This revision takes effect on 6 October 2026. Until then, Version 2.0 applies. See the change history in Section 15 for what changed.
This is a translation. The Korean version is the governing text.
At a glance
We collect only your Google, Apple, Kakao or LINE login details, step counts, LUCK and items, Wish Lantern content and purchase records. No phone number, date of birth or precise location.
Photos you use for the moktak, mala beads or outfits stay on your phone and are never uploaded. Only a photo attached to a Wish Lantern is stored on our servers.
Wish Lantern text is processed by OpenAI to check for inappropriate content and to translate it.
Your conversations with the AI monk are processed by AI to write replies and are stored on our servers so the conversation can continue.
You can delete your account from App › Profile › Settings and more, and your data is erased. Ad tracking can be turned off in your phone settings.
Bug Hole Inc. ("the Company") operates the mobile application Seokgamoney ("the Service") and complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws. This policy explains, in plain language, what personal information we collect and why, how long we keep it, who processes it on our behalf, and how you can exercise your rights.
1. Information we collect and how
We collect only the minimum information needed to run the Service. "Required" items in 1.1 to 1.3 are necessary to perform the service contract with you and are processed without separate consent under Article 15(1)(4) of the Personal Information Protection Act. Among the automatically collected items in 1.4, those used for service stability, fraud prevention and nonpersonalised ads rest on Article 15(1)(6) (legitimate interest), while the advertising identifier and behavioural data for personalised ads are used on iOS only if you allow tracking (ATT), in the EEA and UK only if you consent on the ad consent screen, and elsewhere (including Android in Korea) on the basis of the notice and opt out tools in Section 7 (resetting or deleting the advertising ID, opting out of ad personalisation), in line with the Korean Personal Information Protection Commission's Guidelines on Online Personalised Advertising. "Optional" items are collected only with your consent, and you can use every core feature without agreeing to them.
1.1. Signup and account (required)
| Category | Items | Source |
|---|---|---|
| Google login | Email address, profile name (never displayed. Used only to help identify the account), Google account identifier | Provided by Google when you link your account |
| Apple login | Apple account identifier, email address (Apple's relay address if you chose "Hide My Email") | Provided by Apple when you link your account |
| Kakao login | Kakao member number (a unique identifier Kakao assigns per app). We do not receive your name, email or profile photo | Provided by Kakao when you link your account |
| LINE login | LINE user identifier (a unique identifier LINE assigns per service provider). We do not receive your name, email or profile photo | Provided by LINE when you link your account |
| Common | Internal user ID (Firebase UID), app language, operating system, app version, signup time, the versions of the Terms, this policy and the wish AI processing consent you agreed to and when, result of the age 14 confirmation | Generated automatically or entered by you at signup |
1.2. Using the Service (required)
| Feature | Items | Source |
|---|---|---|
| Walking rewards | Daily step count | Motion and fitness sensors and health data on your device (iOS Motion & Fitness and step counts from the Apple Health app, Android Physical Activity Recognition and Health Connect step counts). On iOS, we only read step counts recorded in the Apple Health app by Apple devices (iPhone and Apple Watch). Manually entered steps and steps recorded by other apps are not used. Raw sensor and health data are processed only on your device, and only the resulting step count is stored on our servers. On Android, we request Health Connect background read permission so that steps taken while the app is closed can count toward rewards. This permission is not used for any health data other than step counts. Health data is never used for advertising or marketing and is never shared with third parties. |
| LUCK economy | LUCK earned and spent, moktak and mala tap counts, practice (attendance) records | Generated as you use the Service |
| Boutique and customization | Items owned, equipped state, items purchased with LUCK | Generated as you use the Service |
| Wish Lanterns | Wish text (up to 120 characters), display name (up to 40 characters), avatar look, language, an optional photo, submission, approval, rejection and appeal records, reports and blocks from other users, records of praying together | Entered or attached by you |
| Friend invites | Invite code, internal IDs of inviter and invitee, reward records | Generated as you use the Service |
| Push notifications | Device push token (FCM), per category notification settings and when you changed them | Generated when you allow notifications |
| Support and reports | Email address, message, attachments | Sent by you by email |
| AI monk chat | What you type, the AI monk's replies, time of each message, a one line memo used to continue the conversation, usage count | Collected when you send a message. The conversation and memo are sent to an AI language model to generate replies |
1.3. Paid purchases (required, when you pay)
| Items | Source |
|---|---|
| App Store transaction identifier (Apple transaction ID or Google purchase token), product ID, purchase, refund and cancellation time, payment status, an encrypted account token that links the purchase to your account | Provided by Apple App Store or Google Play |
We never collect or store card numbers, bank accounts or other payment method details. Apple and Google process those under their own privacy policies.
1.4. Automatically collected information (required)
- Usage records, access times, in app events (screens viewed, features used), device model, OS version, app version, approximate location at country or region level (estimated from IP address), app integrity token (Firebase App Check)
- Advertising identifier (iOS IDFA, Android Advertising ID). On iOS it is used for personalised ads only if you allow tracking through App Tracking Transparency. If you decline, you see nonpersonalised ads.
- Ad impressions, clicks and rewarded ad completion records
1.5. Optional items (only with your consent)
| Item | Purpose | Notes |
|---|---|---|
| Marketing and event notification opt in and its timestamp | Push notifications about new items, events and offers | Off by default. Change any time in app settings |
1.6. Information we do not collect or never send off your device
- Photos used for moktak, mala beads and Magic Tee and Magic Pants. Photos you pick from your library and the processed results are stored only on your device and are never uploaded. They are deleted when you delete the app.
- We do not collect phone numbers, dates of birth, gender, precise location, government ID numbers, or sensitive information such as religion or political views. However, anything you choose to write in an AI monk chat may be included in the chat record, so we recommend not sharing sensitive information there.
- A photo attached to a Wish Lantern is the one exception and is stored on our servers (see 1.2).
2. Why we use your information
| Purpose | Information used |
|---|---|
| Identifying you, signing you in, syncing across devices, recovering your account | 1.1 |
| Awarding LUCK for steps, moktak, mala and practice. Paying rewards. Preventing fraudulent earning | 1.2, 1.4 |
| Providing paid and free features such as boutique items and Wish Lanterns. Verifying purchases. Handling refunds and cancellations. Restoring purchases | 1.2, 1.3 |
| Reviewing Wish Lantern posts (AI screening, and human review where needed), translating them, displaying them publicly, handling reports, blocks and appeals | 1.2 |
| Friend invite rewards, detection of multiple accounts and abuse, and a 7 day rejoin restriction after account deletion | 1.1, 1.2, 1.4 |
| Sending service notifications (practice reminders, rewards received, moderation results) | 1.2 |
| Sending marketing and event notifications | 1.5 (with consent) |
| Serving ads, verifying rewarded ad views, measuring ad performance, personalised ads (with consent on iOS and in the EEA/UK. Elsewhere on the basis of the notice and opt out in Section 7) | 1.4 |
| Keeping the Service stable, analysing errors, usage statistics, improving features | 1.4 |
| Responding to violations of the Terms, resolving disputes, meeting legal obligations | All |
| Individually notifying you of important changes to the Terms or this policy | 1.1 |
| Providing AI monk chat (AI generated replies), managing free and extra usage, and showing help contacts in a crisis | 1.2 |
3. How long we keep your information
We destroy personal information without delay once its purpose is fulfilled, except as follows.
| Information | Retention | Basis |
|---|---|---|
| Account, LUCK, item and practice records | Until you delete your account. Destroyed immediately on deletion | Providing the Service |
| Wish Lantern posts (text, photo, display name) | No longer shown to other users once the display period ends (1 day basic, 7 days premium). Destroyed when you ask us to delete the post. On account deletion they stop being shown immediately, are kept for 30 days, then destroyed | Providing the Service (your lantern history), handling reports and disputes right after account deletion |
| Rejection, appeal and refund request records for paid Wish Lanterns, and how they were handled | 3 years from handling | Records of consumer complaints and dispute resolution (Article 6 of the Electronic Commerce Act Enforcement Decree) |
| Other lantern moderation, report, block and operator action records | Until account deletion | Preventing repeat abuse, handling appeals (Company standard) |
| Friend invite records (invite code, internal IDs of inviter and invitee, invite reward records. For Kakao and LINE login users the internal ID contains the member number or user identifier) | Until the Service ends (kept after account deletion). On deletion you are removed from the other person's friend roster immediately | Providing the Service, preventing duplicate invite rewards (legitimate interests) |
| Payment, refund and cancellation records | 5 years | Records of payment and supply of goods (Electronic Commerce Act) |
| Records of contracts and withdrawals | 5 years | Electronic Commerce Act |
| Access logs (time, IP address) | 3 months | Article 41 of the Enforcement Decree of the Protection of Communications Secrets Act (three month retention of log and access tracking records) |
| Internal ID and reason for accounts restricted for abuse (multiple accounts, fraud, refund abuse) | 1 year from restriction | Preventing abuse by registering again (legitimate interest) |
| An irreversibly hashed value of the login identifier of a deleted account, the deletion time, and whether a friend invite code was used | Until the Service ends | Preventing immediate rejoining and duplicate invite rewards (legitimate interests) |
| AI monk chat records (messages, replies, memo) | [TO CONFIRM: retention period]. Erased on account deletion | Providing the Service (continuing earlier conversations) |
| Support emails | 3 years after resolution | Records of consumer complaints and dispute resolution (Article 6 of the Electronic Commerce Act Enforcement Decree) |
Information we must keep by law after account deletion is stored separately and used only for that purpose. Information we keep under our own standards is erased on account deletion, except where the table above states its own retention period.
4. Sharing with third parties
We do not share your personal information with third parties, except in the following cases.
- When you have given prior consent.
- When required by law, or by an investigative agency or court following the procedures set by law.
- Public Wish Lanterns. When you post a Wish Lantern, the wish text, display name, avatar look, attached photo (if any), the number of people who prayed together and translations are shown to other logged in users of the Service. This is a disclosure you choose by posting. Your account ID and email are never shown.
- Behavioural data sent to advertising partners. The ad SDKs listed in Section 7 collect advertising identifiers and device information directly to serve ads.
5. Processors we entrust
We entrust the following processing to service providers and supervise them under Article 26 of the Personal Information Protection Act.
| Processor | Entrusted work |
|---|---|
| Google LLC (Firebase) | Authentication, database and file storage, server functions, push delivery, app integrity checks, usage analytics |
| Apple Inc. | Sign in with Apple, in app payment processing and receipt verification |
| Kakao Corp. | Kakao login, unlinking your Kakao account when you delete your account |
| LY Corporation | LINE login, unlinking your LINE account when you delete your account |
| Google LLC (Google Play) | In app payment processing and purchase verification |
| OpenAI, L.L.C. | AI screening and translation of Wish Lantern posts (large language model). Wish text passes through a relay server the Company runs in Korea (Seoul). Attached photos and account information are not sent |
| Amazon Web Services, Inc. | Hosting the AI monk chat server and chat record database (Seoul region) |
| [TO CONFIRM: model provider legal name] | Generating AI monk replies (large language model). The conversation and memo are sent |
6. International transfers
Because the processors above process and store data outside Korea, we transfer personal information abroad under Article 28-8(1)(3) of the Personal Information Protection Act (outsourcing and storage necessary to perform the contract with you) and disclose the details here.
| Recipient (contact) | Country | When and how | Items | Purpose | Retention |
|---|---|---|---|---|---|
| Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA (googlekrsupport@google.com), Firebase Authentication, Analytics, Cloud Messaging, App Check | USA | Sent over the network as you use the Service | Account data in 1.1, push token in 1.2, usage records, device info and app integrity token in 1.4 | Authentication, analytics, push delivery, app integrity checks | Until account deletion or end of engagement |
| Google LLC (as above), Firebase Firestore and Storage | Republic of Korea (Seoul region) | Sent over the network as you use the Service | Stored data in 1.1, 1.2, 1.3 and Wish Lantern photos | Data and file storage | Until account deletion or end of engagement |
| Google LLC (as above), Cloud Functions | Republic of Korea (Seoul region) | As you use the Service | Items in 1.2 and 1.3 handled by server functions | Reward payment, purchase verification, Wish Lantern moderation and translation | Until account deletion or end of engagement |
| Apple Inc., One Apple Park Way, Cupertino, CA, USA (apple.com/legal/privacy/contact) | USA | Sent over the network at login and purchase | Apple account identifier, email, transaction data | Login, payment processing | Until end of engagement |
| LY Corporation, Kioi Tower, 1-3 Kioicho, Chiyoda-ku, Tokyo, Japan (lycorp.co.jp/en/company/privacypolicy) | Japan | Sent over the network at LINE login and account deletion | LINE user identifier, login token | Login, account unlinking | Until end of engagement |
| OpenAI, L.L.C., San Francisco, CA, USA (privacy@openai.com) | USA | Sent over the network when you submit a Wish Lantern | Wish text, language | Moderation and translation | Per OpenAI's data retention policy |
| [TO CONFIRM: model provider legal name, address, privacy contact] | [TO CONFIRM: country] | Sent over the network when you chat with the AI monk | Conversation, memo, language | Generating replies | [TO CONFIRM: provider retention policy] |
| AppLovin Corp., 1100 Page Mill Road, Palo Alto, CA, USA (privacy@applovin.com) | USA | Sent directly by the SDK when an ad is requested | Advertising ID, device and OS info, IP address, app info, impression and click records | Serving and measuring ads | Period set in the AppLovin privacy policy |
| Unity Technologies, 30 3rd Street, San Francisco, CA, USA (DPO@unity3d.com) | USA | Sent directly by the SDK when an ad is requested | As above | Serving and measuring ads | Period set in the Unity privacy policy |
| Bytedance Pte. Ltd. (Pangle), 1 Raffles Quay, #26-10, Singapore (contact via https://www.pangleglobal.com/privacy) | Singapore | Sent directly by the SDK when an ad is requested | As above | Serving and measuring ads | Period set in the Pangle privacy policy |
You can refuse the transfer of personalised advertising data to ad partners through iOS App Tracking Transparency or by deleting or resetting your Android Advertising ID. If you do not want any transfer, you may stop using the Service by deleting your account. The Service cannot be provided without these transfers.
7. Behavioural information for advertising and how to opt out
| Item | Details |
|---|---|
| Behavioural information collected | Advertising identifier (IDFA / Android Advertising ID), in app usage events, ad impressions, clicks and views, device and OS info, country level location |
| How | Collected automatically by the advertising and analytics SDKs bundled in the app while you use it |
| Purpose | Serving ads, verifying rewarded ad views, measuring ad performance, and interest based personalised ads (with ATT consent on iOS, with ad consent in the EEA/UK, and elsewhere on the basis of the notice and opt out tools in this table) |
| Retention | The Company keeps it until account deletion, and ad partners keep it per their own policies |
| Ad partners that collect and process it | DARO (DelightRoom Co., Ltd.), Google AdMob (Google LLC), AppLovin (AppLovin Corp.), Unity Ads (Unity Technologies), Pangle (Bytedance Pte. Ltd.) |
| Your controls | On iOS, Settings › Privacy & Security › Tracking › turn off Seokgamoney. On Android, Settings › Google › Ads › "Opt out of Ads Personalization", or delete or reset the Advertising ID. EEA and UK users can "Ad privacy settings" on the Profile screen. Android users elsewhere, including Korea, see no separate in app consent screen. The device settings above are the opt out |
We do not collect behavioural information for personalised advertising from users we know to be under 14, and we never identify you from behavioural data alone. If you opt out, you still see ads, but they are not based on your interests.
Partner privacy policies are available from DARO · Google · AppLovin · Unity · Pangle
8. Destruction of personal information
- Procedure. Information whose retention period has ended or purpose has been fulfilled is destroyed without delay (within 5 days). Information subject to a legal retention period is moved to separate storage and destroyed when that period ends.
- Method. Electronic files are permanently deleted in a way that cannot be recovered. On account deletion, your Firebase authentication account and user document are deleted immediately. Your Wish Lantern posts and photos stop being shown immediately, are kept for 30 days, then deleted. Only payment and dispute records we must keep by law are stored separately for the periods in Section 3.
- Inactive accounts. We do not convert accounts to a dormant state. You can delete a long unused account yourself at any time.
9. Your rights and how to exercise them
- You may at any time request access, correction, deletion, suspension of processing, withdrawal of consent, and data portability for your personal information.
- How
- Delete account. App › Profile › Settings and more › Delete account. Processed immediately, and LUCK, items and purchase benefits are lost with it. Wish Lanterns stop being shown immediately and are deleted after 30 days.
- Change notification consent. App › Profile › Settings and more › Notifications (service and marketing notifications are controlled separately).
- Opt out of ad tracking. Device settings described in Section 7.
- Revoke motion and fitness permission. Device Settings › Seokgamoney › Motion & Fitness (iOS), Physical activity and Health Connect (Android). Only walking rewards stop. Every other feature keeps working.
- Delete a Wish Lantern or appeal a rejection. You can appeal a rejection on its result screen. To delete a posted wish, email the contact in Section 11.
- Other access, correction or portability requests. Email the contact in Section 11. We respond within 10 days of receiving your request.
- Requests may be made by you, your legal guardian, or an authorised representative. We may ask you to confirm your identity through your signup email.
- Where the law limits access, correction or deletion, we will tell you why.
- You are responsible for keeping your information accurate and for not posting other people's personal information in Wish Lanterns or elsewhere.
10. Children under 14
- Only people aged 14 or older may use the Service. After login you must confirm on the consent screen that you are 14 or older. If you leave without confirming, you are logged out and no Service data is stored.
- We do not currently offer signup for children under 14 with a legal guardian's consent. If we introduce it, we will first add to this policy how consent is verified under Article 22-2 of the Personal Information Protection Act and how guardian information is handled.
- If we learn that we have collected personal information from a child under 14, we destroy it without delay. If a user tells us they are under 14, Service access stops at once, and the account and its personal information are deleted after a 7 day notice period. The user may delete the account at any time during that period, and a guardian may request deletion through the contact in Section 11.
11. Data protection officer and complaints
| Data protection officer | Myunggeun Hong, CEO |
| Department | Seokgamoney Service Operations |
| seokgamoney108@gmail.com | |
| Address | 2415, 2F, 19 Beopwon-ro 3-gil, Seocho-gu, Seoul, Republic of Korea |
Contact us at the address above for any privacy question, complaint or remedy request. We will respond without delay.
You may also contact the following Korean authorities.
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
- Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- Supreme Prosecutors' Office Cybercrime Division (spo.go.kr / 1301)
- National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)
12. Security measures
Under Article 29 of the Personal Information Protection Act we take the following measures.
- Organisational. Only a minimum number of staff handle personal information. Moderation and operator tools are accessible only to approved operator accounts, and every operator action is logged. We maintain an internal management plan.
- Technical. All traffic is encrypted with TLS. Database and file storage enforce access rules so that your data can be read or written only by you, by operators the Company authorises, and by server functions, and only Wish Lanterns you make public are shown to other users. App integrity checks (App Check) reduce the risk of tampered apps reaching our servers. Purchases are verified by our server directly with Apple and Google, and purchases are linked to accounts with one way encrypted tokens. Ad rewards are paid only through callbacks verified by our server.
- Physical. Data is stored in Google Cloud and Amazon Web Services data centres holding security certifications such as ISO 27001. The Company operates no physical servers of its own.
13. Automatic data collection tools
The Service uses no web cookies. The following SDKs collect usage information automatically.
| SDK | Data | Purpose | How to refuse |
|---|---|---|---|
| Firebase Analytics | In app events, device info, approximate location | Usage statistics, improvement | Change device ad tracking settings. Full refusal requires deleting the app |
| DARO, Google AdMob and mediation (AppLovin, Unity Ads, Pangle) | See Section 7 | Advertising | See Section 7 |
| Firebase Cloud Messaging | Push token | Notifications | Turn off device notification permission or in app notifications |
| Firebase App Check | App integrity token | Security | Cannot be refused (required to operate the Service) |
14. Notice of use and provision
If the Company comes to meet the thresholds of Article 20-2 of the Personal Information Protection Act and Article 15-3 of its Enforcement Decree (1,000,000 or more data subjects, or 50,000 or more data subjects' sensitive or unique-identifier data), we will notify you at least once a year, by email or app notification, of how your personal information has been used and provided.
15. Changes to this policy
- We announce changes, with reasons, in the app and on this page at least 7 days before they take effect.
- Changes that matter to your rights (items collected, purposes, third party sharing, retention) are announced 30 days in advance and notified individually by your signup email or app notification.
- Change history
| Version | Effective | Summary |
|---|---|---|
| v1.0 | 10 June 2026 | First version (English) |
| v2.0 | 23 September 2026 | Korean governing version added. Added Google login, paid purchases, Wish Lanterns (OpenAI screening and translation), friend invites, push notifications, ad mediation, international transfers and behavioural data. Introduced age 14 confirmation and consent flow |
| v2.1 | 6 October 2026 | Added Kakao login and LINE login. New items collected (Kakao member number, LINE user identifier), new processors (Kakao Corp., LY Corporation) and a new international transfer (LY Corporation, Japan). Added the retention period for rejoin restriction records. Added DARO to ad partners. Corrected the retention period for friend invite records. |
| v2.2 | 6 October 2026 | Added items collected, purposes, retention and processors for AI monk chat |
This policy takes effect on 6 October 2026.
16. Additional information for users in the EEA and UK
If you use the Service in the European Economic Area or the United Kingdom, the GDPR and UK GDPR also apply. Our legal bases are performance of the contract (1.1 to 1.3), legitimate interests (service stability, fraud prevention, nonpersonalised advertising) and consent (personalised advertising, marketing notifications, wish AI processing). In addition to the rights in Section 9, you have the right to object to processing and to lodge a complaint with the supervisory authority in your country. Your data is processed in the Republic of Korea, a country covered by an EU adequacy decision. Transfers to processors in the USA and other third countries rely on appropriate safeguards such as the Standard Contractual Clauses concluded with each processor. AI screening of Wish Lanterns is followed by human review and an appeal process, so it is not a solely automated decision with legal effect. The Company has not appointed an EEA or UK representative. Contact us through Section 11.