Privacy Policy

Scribe Fairy · Effective: 2026-09-23 · Last updated: 2026-09-23

This revision adds OpenAI, L.L.C. (USA) as a processor for AI features (correction, organize, ask) (Section 4). Each AI request is processed by either Google or OpenAI; the items, purpose, and timing of the transfer are unchanged.

This revision adds aggregate usage statistics (Sections 1 and 3). That collection begins with app versions released on or after the effective date (0.1.27 and later) and can be turned off in the app settings.

한국어 · English

Scribe Fairy (the "Service") values your privacy and processes personal data as described below. Core features such as recording, editing, and saving can be used without any sign-up, and the memos you create are stored only on your device and are not sent to our servers. However, some features — AI correction (Fairy Mana) and Drive backup — require Google sign-in, and only when you use those features is data transmitted or stored within the scope defined below.

1. Information we collect and store

2. Device permissions

3. Third parties, advertising, and analytics

The Service does not sell or provide your personal data to third parties. We use a crash-diagnostics tool for app stability and a usage-analytics tool for product improvement and ad-performance measurement (both below). We do not collect which screens you view or how long you view them, and no user content (memo text, email) is sent to either tool.

Crash diagnostics (Firebase Crashlytics): when the app crashes or hits an error, the diagnostics and crash data described in Section 1 is sent to and processed by Firebase Crashlytics, operated by Google LLC (USA). It is used only to diagnose errors and improve app stability — never for advertising or user profiling — and your memo content is not sent. For details, see Firebase Privacy. You can turn it off at any time in the app's settings.

Advertising (Google AdMob): the Service shows native (in-feed) ads between memo list items and on the calendar (My Diary) screen via Google AdMob. In this process Google may collect and process your Advertising ID and device information for ad delivery and fraud prevention; the processor is Google LLC (USA). For details, see the Google Ads policy. You can reset or delete your Advertising ID in your device settings. Premium (PRO) subscribers are not shown ads.

Usage statistics (Firebase Analytics) — applies to app versions released on or after the effective date (0.1.27 and later). To see whether the app's main features are actually used, and to measure how ad campaigns perform (whether an install leads to real use), we send only the fact that a defined action occurred to Google LLC (USA). What is sent: first app open, first voice memo saved, AI correction run (the correction level number), subscription activated (product ID), mana topped up (product ID) and similar actions, plus the device model, OS version, app version, country, and app-instance identifier the tool attaches automatically (items of the same kind may be added as features grow). Your memo text and titles, email, Google account identifier, and the anonymous device identifier are never sent, and we do not collect which screens you view. Aggregate results are linked to Google Ads for campaign conversion measurement only — not for remarketing (custom audiences). You can turn this off at any time in Settings > Information > "Send usage statistics" (on by default). Where consent is required (EEA, UK and similar), we do not send ad-purpose signals unless you accept Google's consent form. For details, see Firebase Privacy.

4. AI features (correction, organize, ask) and cross-border processing entrustment

Only when you run an AI feature (correction, organize, or ask), the memo text needed for that feature is sent through our server to an overseas AI service for processing. If you do not use these features, your memos are not sent off your device. AI features are monetized (Fairy Mana), so using them requires Google sign-in and running one deducts mana from your account (Section 6).

Server infrastructure uses services from Cloudflare, Inc. (USA), and communication data passes through that infrastructure for in-transit processing.

5. Google Drive backup (optional)

This feature works only when you turn it on yourself in settings. If you do not back up, your memos exist only on your device.

6. Payments · Fairy Mana (items stored on the server)

Premium (PRO) subscription is handled through Google Play billing. Payment methods and card details are processed by Google and are not collected by the Service. To verify that a subscription is valid, the following information is stored on our servers.

Fairy Mana (AI-correction credits) is a consumable used to run AI correction. To tie the mana balance to your Google account so it persists across reinstalls and device changes, Google sign-in is required and the following information is stored on our servers. Top-up payments are handled through Google Play, and card/payment details are processed by Google and not collected by the Service.

The above server-stored data is stored and processed on the database infrastructure of Cloudflare, Inc. (USA).

7. Retention and destruction

Memos and settings stored on your device are deleted when you delete the app. On-device data is configured to be excluded from Google auto-backup, so apart from the encrypted backup you turn on yourself, it is not copied off the device. You can delete backups saved to your Drive yourself.

Customer-inquiry (complaint / dispute handling) records are kept for 3 years from the date of resolution to meet consumer-protection and dispute-record obligations, and then destroyed. On destruction, the records — including email address and inquiry content — are deleted.

Retention periods for other records stored on the server are as follows, after which they are destroyed. Records concerning payment and supply of goods (subscription entitlement and mana top-up history) are kept for 5 years to meet legal, accounting, and tax record-keeping obligations, after which the personal identifier (account identifier) is removed (pseudonymized) and only the transaction fact remains. Operational device-link information is deleted 1 year after last use. Sign-in session records are kept for at most 180 days from issue, expiring sooner if unused for 90 days, and are deleted on sign-out or expiry. Destruction is carried out by an administrator after confirming the affected count.

Records of an executed account-data deletion (time of processing, the administrator, and a summary of what was processed) are kept to prevent abuse such as repeatedly claiming the free trial mana. The account identifier is not stored in its original form; we store only an irreversible fingerprint (HMAC-SHA-256 keyed with a server-side secret), from which the account cannot be identified or linked to other information. These records are automatically deleted 1 year after processing.

8. Your rights

You can delete all data stored on your device by deleting the app. The AI-correction and backup features can each be left unused or turned off in settings, and if unused no related transmission occurs.

You may request deletion of the account identifier, balance, and purchase history stored on the server. You can do this from within the app (Settings → Delete account & data), which opens a pre-filled email, or by contacting us directly (see Contact). We verify the request and delete the data; a record of the deletion is kept for 1 year as an irreversible fingerprint, and records that must be legally retained are pseudonymized (see Section 7). Region-specific rights are described in Sections 9 and 10.

9. California residents (CCPA/CPRA)

In the past 12 months we may process the following categories of personal information: identifiers (Google account identifier, an anonymous device identifier, and — for ads — an advertising identifier), commercial information (subscription and mana top-up records), internet/usage activity (per-day request counts for abuse prevention, and aggregate in-app event counts used for product improvement and ad-performance measurement), and diagnostic data (crash reports: error type/message, stack trace, device model, OS and app version). We collect these to provide and secure the Service, as described above.

10. EEA & UK (GDPR / UK GDPR)

The data controller is the operator of the Service (see Contact). We process personal data on these legal bases: consent (advertising, and ad-purpose analytics signals where consent is required — both obtained through Google's consent form), performance of a contract (subscription and mana), legitimate interests (fraud/abuse prevention using the anonymous device identifier, app-stability crash diagnostics, and aggregate usage statistics for product improvement — each of which you can switch off in settings), and legal obligation (record retention in Section 7).

11. Children's privacy

The Service is not directed to children. We do not knowingly collect personal data from children under 13 (or the minimum age required in your country or region). If you believe a child has provided personal data, contact us and we will delete it.

12. Changes to this policy

If this policy changes, we will give notice through the app or this page.

13. Contact

Privacy inquiries: boomdiboom1@gmail.com


This document is provided to users as a public document. It may be revised in line with applicable law or service changes. In case of any discrepancy, the Korean version prevails.