얼마야? 개인정보처리방침
주식회사 프로릭소프트(이하 "회사")는 얼마야? 앱(이하 "앱")을 쓰는 분의 개인정보를 「개인정보 보호법」 등 관련 법령에 따라 처리합니다. 이 방침은 앱이 무엇을 모으고, 어디로 보내고, 언제 지우는지를 있는 그대로 적은 것입니다.
시행일: 2026년 8월 5일
0. 이 앱의 구조 — 먼저 알아 두실 것
얼마야?는 총무 한 사람이 쓰는 앱입니다. 함께 간 참가자는 앱을 깔지 않으며 회사와 아무 관계가 없습니다. 참가자의 이름과 전화번호는 총무가 대신 입력합니다.
그래서 이 방침에는 두 종류의 사람이 나옵니다.
- 이용자 — 앱을 설치하고 정산을 만드는 총무
- 참가자 — 총무가 이름을 적어 넣은 사람. 앱을 쓰지 않습니다
참가자 정보에 대한 회사의 책임 범위는 6항에 따로 적었습니다.
1. 모으는 정보
계정
- 익명 계정 식별자(uid) — 가입 절차 없이 앱을 켜면 자동으로 발급됩니다. 이름도 이메일도 묻지 않습니다
- Apple / Google 계정 식별자와 이메일 — 이용자가 "계정 연동"을 직접 누른 경우에만. 기기를 바꿔도 정산을 되찾기 위한 것입니다. 연동하지 않아도 앱은 전부 동작합니다
이용자가 입력한 정산 데이터
- 모임 이름, 기간, 통화, 환율
- 참가자 이름, 전화번호(선택), 선입금액, 입금 확인 여부
- 지출 내역 — 항목명, 분류, 금액, 통화, 결제자, 분담 대상, 결제 날짜
- 영수증 사진과 판독 결과 — 이용자가 찍거나 앨범에서 고른 것
- 내 사람들 — 자주 넣는 사람의 이름·전화번호. 다음 정산에서 다시 쓰기 위한 이용자 개인 목록입니다
- 내 정보 — 이용자가 직접 적은 표시 이름과 전화번호(선택)
자동으로 쌓이는 정보
- 판독 사용량 — 하루에 영수증을 몇 장 읽었는지. 비용 상한을 지키기 위한 숫자이며 내용은 담지 않습니다
- 오류 기록 — 앱이 비정상 종료한 경우 기기 모델, OS 버전, 앱 버전, 오류 위치 (Firebase Crashlytics)
- 광고 식별자 — 광고를 보여 주기 위해 기기가 제공하는 광고 식별자 (Google AdMob). iOS 에서는 추적 허용을 묻지 않습니다 — 묻지 않으므로 맞춤형이 아닌 광고만 나갑니다
모으지 않는 것: 위치 정보, 연락처 전체, 결제 카드 정보, 통장 거래 내역. 입금 확인은 이용자가 통장을 보고 직접 체크하는 방식이며, 앱이 은행과 연결되지 않습니다.
2. 왜 모으는가
| 정보 | 목적 |
|---|---|
| 익명 계정 식별자 | 이용자의 정산을 그 사람 것으로 구분하고, 남이 못 읽게 막기 위해 |
| Apple / Google 연동 | 기기를 바꾸거나 초기화한 뒤 정산을 되찾기 위해 |
| 정산 데이터 | 분담액 계산, 정산서 작성·공유라는 앱의 본래 기능 |
| 영수증 사진 | 금액·항목 자동 판독과 증빙 보관 |
| 내 사람들·내 정보 | 다음 정산에서 다시 입력하지 않기 위해 |
| 판독 사용량 | 하루 한도를 지켜 비용이 폭주하지 않게 하기 위해 |
| 오류 기록 | 앱이 죽은 원인을 찾아 고치기 위해 |
| 광고 식별자 | 앱 안 광고 표시 |
3. 영수증 사진이 어디로 가는가
이 항목만 따로 적습니다. 이용자가 알아야 할 가장 중요한 흐름입니다.
- 이용자가 영수증을 찍거나 앨범에서 고릅니다
- 사진이 회사의 저장소(Google Firebase Storage, 대한민국 서울 리전)에 올라갑니다
- 서버가 그 사진을 Google 의 Gemini API 로 보내 글자를 읽습니다
- 읽은 결과(가게 이름, 금액, 항목)가 저장되고, 이용자가 화면에서 확인한 뒤에야 지출로 들어갑니다. 자동으로 확정되지 않습니다
- 원본 사진은 계속 보관됩니다 — 나중에 금액을 두고 이야기가 나왔을 때 원본이 없으면 증빙이 되지 않기 때문입니다
영수증을 쓰지 않고 금액을 직접 입력해도 정산은 전부 동작합니다.
4. 제3자에게 넘기는 경우
회사는 개인정보를 팔지 않습니다. 서비스를 굴리기 위해 아래 사업자의 시스템을 씁니다.
| 받는 곳 | 무엇을 | 왜 |
|---|---|---|
| Google (Firebase) | 계정 식별자, 정산 데이터, 영수증 사진, 오류 기록 | 인증·데이터 저장·오류 수집 |
| Google (Gemini API) | 영수증 사진 | 사진 속 글자·금액 판독 |
| Google (AdMob) | 광고 식별자, 기기·앱 정보 | 앱 안 광고 표시 |
정산 데이터와 영수증 사진은 대한민국 서울 리전(asia-northeast3) 에 저장됩니다. 판독을 위해 Google 의 Gemini API 로 보내는 순간에는 국외 서버가 처리할 수 있으며, 이는 Google Cloud 의 데이터 처리 계약(DPA)과 보안 인증(ISO 27001, SOC 2 등)에 따라 보호됩니다.
법령에 따라 수사기관 등이 적법한 절차로 요구하는 경우 외에는 그 밖의 제3자에게 제공하지 않습니다.
5. 기기 권한
권한은 그 기능을 쓰는 순간에만 요청하며, 거부해도 앱의 다른 기능은 전부 동작합니다.
- 카메라 / 사진 — 영수증을 찍거나 앨범에서 고를 때. 고른 사진만 올라갑니다
- 연락처 — 이용자가 "연락처에서 가져오기" 를 눌렀을 때만 읽습니다. 고른 사람만 저장되고, 나머지 연락처는 어디에도 보내지 않습니다. 참가자 이름은 직접 입력해도 됩니다
이 앱은 iOS 추적 권한을 요청하지 않습니다. 광고는 맞춤형이 아닌 것만 나갑니다.
6. 참가자 정보 — 이용자가 넣는 남의 정보
참가자는 앱을 쓰지 않으므로 회사에 직접 동의할 방법이 없습니다. 그 정보는 이용자가 자기 정산을 관리하기 위해 직접 입력한 것이며, 이용자 본인의 정산 안에서만 쓰입니다. 다른 이용자에게 보이지 않고, 검색되지 않으며, 광고에 쓰이지 않습니다.
- 전화번호는 선택입니다. 넣지 않아도 정산·분담 계산·정산서 공유가 전부 동작합니다. 꼭 필요하지 않다면 이름만 적으시길 권합니다
- 정산서를 이미지·문자로 공유하면 거기 적힌 이름과 금액이 받는 사람에게 보입니다. 전화번호는 정산서에 적히지 않습니다
- 영수증 원본 링크를 공유 문구에 넣으면, 링크를 받은 사람은 누구나 그 영수증을 볼 수 있습니다(로그인 없이 열립니다). 민감한 영수증은 링크를 빼고 공유하세요
- 웹 정산서 링크(아래 6-1)를 만들면 이름과 금액이 담긴 페이지가 링크를 가진 사람에게 열립니다
- 참가자 정보를 입력하기 전에 당사자에게 알리고 동의를 받을 책임은 이용자에게 있습니다
- 참가자 본인은
contact@frolicsoft.com으로 자신의 정보 삭제를 요청할 수 있습니다
6-1. 웹 정산서 링크
앱을 쓰지 않는 참가자도 정산서를 볼 수 있도록, 총무가 공개 링크를 만들 수 있습니다.
- 링크에는 모임 이름·기간, 참가자 이름, 금액, 지출 항목, 항목별 분담액만 담깁니다. 전화번호는 담기지 않습니다 — 가려서 넣는 것이 아니라 아예 싣지 않습니다. 영수증 사진도 담기지 않습니다
- 로그인 없이 열립니다. 추측할 수 없는 긴 주소가 유일한 접근 통제이므로, 링크를 받은 사람은 누구나 볼 수 있습니다. 아는 사람에게만 보내세요
- 검색엔진에 올라가지 않도록 막아 두었습니다
- 총무가 언제든 끊을 수 있습니다. 앱의 정산 화면 → 웹 링크 → 링크 끊기. 끊으면 그 주소는 더 이상 열리지 않습니다
- 링크를 새로 만들면 이전 링크는 자동으로 끊깁니다
- 정산을 지우거나 계정을 지우면 링크도 함께 끊깁니다
- 링크에 담긴 내용은 만든 시점의 스냅샷입니다. 그 뒤 금액을 고쳐도 링크의 내용은 그대로이며, 총무가 링크를 다시 만들어야 반영됩니다
7. 얼마나 보관하고 언제 지우는가
- 정산 데이터는 이용자가 지울 때까지 보관합니다. 자동 삭제 기한을 두지 않습니다 — 지난 모임의 금액은 나중에 다시 들춰 볼 일이 실제로 있습니다
- 정산 하나를 지우면 그 안의 참가자·지출·영수증 기록과 저장된 영수증 사진 원본까지 함께 지워집니다. 지운 뒤에는 예전에 공유한 영수증 링크도, 웹 정산서 링크도 열리지 않습니다
- 계정을 지우면 이용자의 모든 정산, 영수증 사진, 내 사람들, 내 정보, 판독 사용량, 인증 계정이 전부 지워집니다. 되돌릴 수 없습니다
- 오류 기록은 Firebase Crashlytics 의 정책에 따라 최대 90일간 보관됩니다
8. 지우는 방법
앱 안에서 직접 지울 수 있습니다.
- 정산 목록 화면 오른쪽 위 계정 아이콘을 누릅니다
- 계정 삭제를 누릅니다
- 지워질 정산 건수를 확인하고 진행합니다
앱을 이미 지웠거나 앱에서 처리가 안 되는 경우 contact@frolicsoft.com 으로 요청하시면 확인 후 처리합니다.
9. 이용자의 권리
이용자는 언제든 자신의 개인정보를 열람·정정·삭제·처리정지 요청할 수 있습니다. 정산 데이터는 앱 안에서 직접 고치고 지울 수 있으며, 그 밖의 요청은 contact@frolicsoft.com 으로 접수하면 10일 이내에 조치합니다. 정당한 사유로 지연되는 경우 그 사유를 알려 드립니다.
10. 안전조치
- 전송 구간은 전부 HTTPS/TLS 로 암호화됩니다
- 저장된 데이터는 Google Cloud 의 저장 시 암호화가 적용됩니다
- 접근 제어 — 서버 보안 규칙이 정산 데이터를 소유한 이용자 본인만 읽고 쓰도록 막습니다. 다른 이용자는 요청해도 거부됩니다
- 영수증 판독 결과는 서버만 기록할 수 있으며, 앱에서 고칠 수 없습니다
11. 만 14세 미만 아동
이 앱은 만 14세 미만을 대상으로 하지 않으며, 아동의 개인정보를 알면서 수집하지 않습니다. 아동의 정보가 수집된 사실을 알게 되면 즉시 삭제합니다.
12. 개인정보 보호책임자
- 개인정보 보호책임자: 프로릭소프트 개인정보보호팀
- 이메일:
contact@frolicsoft.com
개인정보 침해에 대한 신고나 상담은 아래 기관에도 문의할 수 있습니다.
- 개인정보침해 신고센터 (privacy.kisa.or.kr / 국번없이 118)
- 대검찰청 사이버수사과 (www.spo.go.kr / 국번없이 1301)
- 경찰청 사이버수사국 (ecrm.police.go.kr / 국번없이 182)
13. 방침이 바뀌면
변경되는 경우 시행일 7일 전부터 이 페이지에 변경 사유와 내용을 안내합니다. 이용자에게 불리한 중요한 변경은 30일 전에 알립니다.
본 개인정보처리방침은 2026년 8월 5일부터 시행됩니다.
How Much? — Privacy Policy
Frolicsoft Corp. ("we") processes the personal data of people who use the How Much? app ("the app") in accordance with the Korean Personal Information Protection Act and related laws. This policy states plainly what the app collects, where it goes, and when it is deleted.
Effective: 5 August 2026
0. How the app works — read this first
How Much? is an app used by one organizer. The other people at the gathering never install it and have no relationship with us. Their names and phone numbers are entered by the organizer on their behalf.
So this policy talks about two kinds of people.
- User — the organizer who installs the app and creates settlements
- Participant — someone the organizer typed in. They do not use the app
Section 6 covers participant data separately.
1. What we collect
Account
- Anonymous account identifier (uid) — issued automatically when the app is first opened. We ask for no name and no email
- Apple / Google account identifier and email — only if the user taps "link account" themselves, so that settlements can be recovered after changing devices. The app works fully without linking
Settlement data entered by the user
- Gathering name, dates, currency, exchange rates
- Participant names, phone numbers (optional), prepaid amounts, payment confirmation
- Expenses — title, category, amount, currency, payer, who shares it, date
- Receipt photos and the text read from them — taken or picked by the user
- Saved people — names and phone numbers the user reuses across settlements
- Profile — a display name and phone number the user types in (optional)
Collected automatically
- Receipt scan usage — how many receipts were read today. A count only; it holds no receipt content
- Crash reports — device model, OS version, app version and crash location when the app terminates abnormally (Firebase Crashlytics)
- Advertising identifier — the device advertising identifier used to serve ads (Google AdMob). On iOS we do not ask for tracking permission — because we never ask, only non-personalized ads are served
What we do not collect: location, your full contact list, payment card details, or bank transaction records. Payment confirmation is something the organizer ticks off manually — the app is not connected to any bank.
2. Why we collect it
| Data | Purpose |
|---|---|
| Anonymous account identifier | To keep each user's settlements theirs and unreadable by others |
| Apple / Google link | To recover settlements after a device change or reset |
| Settlement data | Calculating shares and producing the settlement summary — the app's purpose |
| Receipt photos | Reading amounts automatically and keeping proof |
| Saved people, profile | So the same names need not be typed again |
| Scan usage | Enforcing a daily limit so costs cannot run away |
| Crash reports | Finding and fixing what made the app die |
| Advertising identifier | Showing ads in the app |
3. Where receipt photos go
This flow is stated separately because it is the most important one to understand.
- The user photographs a receipt or picks one from the photo library
- The image is uploaded to our storage (Google Firebase Storage, Seoul, South Korea)
- Our server sends that image to Google's Gemini API to read the text
- The result (merchant, amounts, line items) is stored, and becomes an expense only after the user reviews it on screen. Nothing is confirmed automatically
- The original image is retained — without the original, the figures cannot be verified if a disagreement comes up later
The app works fully if amounts are typed in without using receipts at all.
4. Sharing with third parties
We do not sell personal data. We use the following providers to run the service.
| Recipient | What | Why |
|---|---|---|
| Google (Firebase) | Account identifier, settlement data, receipt photos, crash reports | Authentication, storage, crash reporting |
| Google (Gemini API) | Receipt photos | Reading text and amounts from the image |
| Google (AdMob) | Advertising identifier, device and app information | Serving ads in the app |
Settlement data and receipt photos are stored in the Seoul region (asia-northeast3), South Korea. While a receipt is being read, Google's Gemini API may process it outside Korea; this is covered by Google Cloud's data processing agreement and security certifications (ISO 27001, SOC 2 and others).
We disclose data to no other third party except where law enforcement follows lawful process.
5. Device permissions
Permissions are requested at the moment the feature is used, and declining one leaves the rest of the app fully working.
- Camera / Photos — to photograph a receipt or pick one. Only the image you choose is uploaded
- Contacts — read only when the user taps "import from contacts". Only the people you pick are saved; the rest of your contacts are never sent anywhere. Names can always be typed in instead
This app does not request iOS tracking permission. Only non-personalized ads are served.
6. Participant data — other people's information, entered by the user
Participants do not use the app, so they have no way to consent to us directly. That information is entered by the user to manage their own settlement and is used only inside that user's settlements. It is not visible to other users, not searchable, and never used for advertising.
- Phone numbers are optional. Settlements, share calculations and sharing all work without them. If you do not need them, enter names only
- Sharing a settlement as an image or message shows the names and amounts written on it to whoever receives it. Phone numbers are not printed on it
- If you include a receipt link in the shared message, anyone who receives that link can open the receipt without signing in. Leave the link out when the receipt is sensitive
- Creating a web settlement link (see 6-1) publishes a page showing names and amounts to anyone holding that link
- It is the user's responsibility to inform participants and obtain their consent before entering their information
- A participant may request deletion of their own information at
contact@frolicsoft.com
6-1. Web settlement links
So that participants without the app can see the settlement, the organizer can create a public link.
- The link carries only the gathering name and dates, participant names, amounts, expense items and each person's share of them. Phone numbers are not included — not masked, simply never put there. Receipt photos are not included either
- It opens without signing in. An unguessable long address is the only access control, so anyone holding the link can view it. Send it only to people you mean to
- Search engines are blocked from indexing it
- The organizer can revoke it at any time: Settlement screen → Web link → Revoke link. Once revoked, the address no longer opens
- Creating a new link automatically revokes the previous one
- Deleting the settlement or your account also revokes the link
- The link shows a snapshot taken when it was created. Editing amounts afterwards does not change it until the organizer creates a new link
7. Retention and deletion
- Settlement data is kept until the user deletes it. There is no automatic expiry — figures from past gatherings genuinely do get looked up again later
- Deleting one settlement also deletes its participants, expenses, receipt records and the stored receipt images themselves. Previously shared receipt links and web settlement links stop working
- Deleting your account deletes all of your settlements, receipt images, saved people, profile, scan usage and the authentication account. This cannot be undone
- Crash reports are retained up to 90 days under Firebase Crashlytics' policy
8. How to delete
You can do it inside the app.
- Tap the account icon at the top right of the settlement list
- Tap Delete account
- Confirm after checking how many settlements will be removed
If you have already uninstalled the app, or the in-app path fails, write to contact@frolicsoft.com and we will handle it after verification.
9. Your rights
You may at any time request access to, correction of, deletion of, or suspension of processing of your personal data. Settlement data can be edited and deleted directly in the app; other requests sent to contact@frolicsoft.com are acted on within 10 days. If there is a legitimate reason for delay, we tell you what it is.
10. Safeguards
- All transport is encrypted with HTTPS/TLS
- Stored data is covered by Google Cloud encryption at rest
- Access control — server security rules allow only the owning user to read and write their settlement data. Requests from anyone else are refused
- Receipt reading results can be written only by the server; the app cannot alter them
11. Children under 14
The app is not directed at children under 14 and we do not knowingly collect their personal data. If we learn that we have, we delete it immediately.
12. Contact
- Data Protection Officer: Frolicsoft Privacy Team
- Email:
contact@frolicsoft.com
Complaints about personal data may also be raised with the Korea Internet & Security Agency's Privacy Center (privacy.kisa.or.kr, 118 in Korea).
13. Changes to this policy
Changes are posted on this page at least 7 days before they take effect. Changes unfavourable to users are announced 30 days in advance.
This privacy policy is effective from 5 August 2026.