Privacy Policy
Scribe Fairy · Effective: 2026-09-23 · Last updated: 2026-09-23
This revision adds OpenAI, L.L.C. (USA) as a processor for AI features (correction, organize, ask) (Section 4). Each AI request is processed by either Google or OpenAI; the items, purpose, and timing of the transfer are unchanged.
This revision adds aggregate usage statistics (Sections 1 and 3). That collection begins with app versions released on or after the effective date (0.1.27 and later) and can be turned off in the app settings.
한국어 · English
Scribe Fairy (the "Service") values your privacy and processes personal data as described below.
Core features such as recording, editing, and saving can be used without any sign-up, and the
memos you create are stored only on your device and are not sent to our servers. However,
some features — AI correction (Fairy Mana) and Drive backup — require Google sign-in, and
only when you use those features is data transmitted or stored within the scope defined below.
1. Information we collect and store
- Stored locally on your device (not sent to any server): the text and word (eojeol) data
of memos you record or write, character formatting, your correction dictionary, your frequent-edit history,
and app settings. This data is stored only on your device and is not sent to our servers.
- Voice (recording) files: if you only use dictation, speech is processed by your device's
operating-system speech recognition and only the transcribed text result is saved on your
device (see Section 2 below). However, if you turn on "Keep original audio" in
settings, or attach audio to a diary entry, the recording is saved as a file
on your device (diary audio attachments are recordings by design, so a file is always kept
regardless of the "Keep original audio" setting). These files are
never sent to our servers; they are uploaded — encrypted — only to
your own Google Drive, and only if you turn on the Drive backup described in
Section 5. Deleting an attachment in the app deletes it from both the device and the backup.
Memos recorded with quick record on the lock screen (if you turn it on) are
kept temporarily in an app-private folder on the device until you open the app, then moved into
your memo list; they are never sent anywhere.
- Photo and image attachments: photos and drawings you attach to memos or diary entries are
saved on your device. As with the recordings above, they are never sent to our servers and
are uploaded — encrypted — only to your own Google Drive if you turn on Drive backup.
- Anonymous device identifier: a randomly generated value (16 bytes)
created on first launch is stored on the device and used for AI-correction usage limits and subscription
verification. It is not directly linked to your name or contact; however, when you are signed in,
it is stored on the server linked to your Google account identifier to enforce the subscription's
3-device limit (see Section 6). A new value is issued if you delete and reinstall the app.
- Google account email (only when signing in for backup / AI correction): to show the
connected account on screen, the email address is stored only on your device, in its secure (Keystore-backed) storage. It is not
sent to our servers.
- Google account identifier (only when using Fairy Mana): when you use the paid AI-correction
feature (Fairy Mana), your Google account's unique identifier (sub) along with your mana
balance and top-up history are stored on our servers, to tie the mana balance to your account. Your email
and name are not stored on our servers (see Section 6).
- Customer-inquiry records (only when you contact support): if you submit an inquiry or
complaint by email or similar, your email address and the content of the inquiry are
recorded on our server (admin console) for consumer-dispute handling and record-keeping. For payment-related
inquiries, a purchase token may also be recorded for matching.
- Diagnostics and crash data: if the app crashes or hits an error, the
error type, error message, and stack trace, along with your device model, OS version,
and app version and the anonymous device identifier above, are sent to a diagnostics
tool (Firebase Crashlytics) to find the cause and improve stability.
Your content — memo text, email — is not sent; where an error message
could carry a fragment of your text, that part is stripped before sending.
You can turn this off in Settings > Information > "Send crash reports" (on by default).
- Usage statistics (aggregate): to improve the app and measure ad performance, the
fact that a defined action occurred (first voice memo saved, AI correction run, subscription
activated, mana topped up, and the like) is sent to a usage-analytics tool (Firebase Analytics), together with
your device model, OS version, app version, country, and an app-instance identifier.
Your memo text and titles, email, account identifier, and the anonymous device identifier are not sent,
and we do not collect which screens you view. You can turn this off in
Settings > Information > "Send usage statistics" (on by default). See
Section 3 for details.
- Network communication: when the above features are used, standard connection information
(such as IP address) may be temporarily logged by infrastructure providers during transmission.
2. Device permissions
- Microphone: used to transcribe speech into text and, when you turn it on, to record audio (see §1). Speech recognition is handled by
your device's operating-system speech-recognition service; when network-based recognition is used to improve
accuracy, speech may be sent to and temporarily processed by the OS provider (e.g. Google). That processing
follows the OS provider's privacy policy, and the Service (our servers) does not collect or store voice
recordings. Turning on "Use on-device recognition only" in the app settings requests
device-only processing, in which case speech is not sent over the network (works on devices with an offline
voice pack installed).
- Internet: used for AI correction, Google Drive backup, subscription verification,
serving ads, and sending crash reports and usage statistics.
- Biometrics: only when you turn on "App lock" in the app settings, used to
lock the app with the fingerprint, face, or screen lock (PIN/pattern) registered on your device. Biometric
data is processed entirely inside the device's operating system; the app receives only whether
authentication succeeded. The Service does not collect, store, or transmit biometric data.
3. Third parties, advertising, and analytics
The Service does not sell or provide your personal data to third parties. We use a
crash-diagnostics tool for app stability and a usage-analytics tool for product
improvement and ad-performance measurement (both below). We do not collect which screens you view or how
long you view them, and no user content (memo text, email) is sent to either tool.
Crash diagnostics (Firebase Crashlytics): when the app crashes or hits an error, the
diagnostics and crash data described in Section 1 is sent to and processed by Firebase Crashlytics,
operated by Google LLC (USA). It is used only to diagnose errors and improve app stability — never
for advertising or user profiling — and your memo content is not sent. For details, see
Firebase Privacy.
You can turn it off at any time in the app's settings.
Advertising (Google AdMob): the Service shows native (in-feed) ads between
memo list items and on the calendar (My Diary) screen via Google AdMob. In this process Google may collect and process your Advertising ID
and device information for ad delivery and fraud prevention; the processor is Google LLC (USA). For details, see the
Google Ads policy.
You can reset or delete your Advertising ID in your device settings.
Premium (PRO) subscribers are not shown ads.
Usage statistics (Firebase Analytics) — applies to app versions released on or after the
effective date (0.1.27 and later). To see whether the app's main features are actually used, and to measure
how ad campaigns perform (whether an install leads to real use), we send only the fact that a defined
action occurred to Google LLC (USA). What is sent: first app open, first voice memo saved, AI
correction run (the correction level number), subscription activated (product ID), mana topped up (product
ID) and similar actions, plus the device model, OS version, app version, country, and app-instance
identifier the tool attaches automatically (items of the same kind may be added as features grow).
Your memo text and titles, email, Google account identifier, and the anonymous device identifier are never
sent, and we do not collect which screens you view. Aggregate results are linked to Google Ads for
campaign conversion measurement only — not for remarketing (custom audiences). You can turn this off at any
time in Settings > Information > "Send usage statistics" (on by default).
Where consent is required (EEA, UK and similar), we do not send ad-purpose signals unless you accept
Google's consent form. For details, see
Firebase Privacy.
4. AI features (correction, organize, ask) and cross-border processing entrustment
Only when you run an AI feature (correction, organize, or ask), the memo text needed for that
feature is sent through our server to an overseas AI service for processing. If you do not use these features, your
memos are not sent off your device. AI features are monetized (Fairy Mana), so using them
requires Google sign-in and running one deducts mana from your account (Section 6).
- Recipient (processor): Google LLC (Gemini API) and OpenAI, L.L.C. (OpenAI API)
— depending on our service configuration, each request is processed by one of the two (the same request is never sent to both).
- Country of transfer: United States
- Items transferred: depends on the feature you run.
- AI correction: the word (eojeol) text of the target memo, plus the correction dictionary and frequent-edit rules you registered.
- AI organize: the full body of the target memo.
- AI ask: your question, together with excerpts drawn from multiple memos in the selected/detected period (each labeled with its date).
Personal data such as name or contact is not transferred; an anonymous device identifier is processed alongside for abuse prevention.
- Purpose of transfer: generating suggestions to correct speech-recognition errors, spelling,
and spacing (correction); organizing the title/paragraphs and generating subheadings (organize); generating an
answer to your question (ask)
- Method and time of transfer: sent over encrypted communication (HTTPS) at the moment you
run the AI feature
- Retention and use period: our server does not store or log memo content
or correction results (it only relays them). For abuse prevention, only the anonymous device
identifier and per-day request counts are recorded on the server. On paid tiers, the processor
(Google) does not use inputs or outputs to improve products or train AI models.
The processor (OpenAI) does not use API inputs or outputs to train its models and retains
them for up to 30 days for abuse monitoring before deleting them (unless a longer period is required by law).
Server infrastructure uses services from Cloudflare, Inc. (USA), and communication data passes
through that infrastructure for in-transit processing.
5. Google Drive backup (optional)
This feature works only when you turn it on yourself in settings. If you do not back up, your
memos exist only on your device.
- What is backed up: the memo / diary database (text, formatting, settings) together with
attachment files (voice recordings and photos).
- Storage location: saved to your own Google Drive. Our servers do not
keep or read backup files.
- Encryption: backup files are encrypted on the device (AES-256-GCM) with a
password you choose, then uploaded. The plaintext password is not stored.
If you forget the password, the backup cannot be recovered.
- Emergency copy on the device: each backup also keeps the latest one of the
same encrypted backup file inside the device (an app-private folder other apps cannot read), so you can restore
on this device even without internet or when the upload to Drive fails. It is never sent anywhere and
is deleted when you uninstall the app.
- Access scope: Drive access requests only the minimum permission that can access
files the app created (
drive.file); it does not access your other Drive
files.
- Revocation: you can disconnect in settings, or revoke the app's permission in your Google
account security settings. You can delete uploaded backup files yourself.
6. Payments · Fairy Mana (items stored on the server)
Premium (PRO) subscription is handled through Google Play billing. Payment methods and card
details are processed by Google and are not collected by the Service. To verify that a subscription is valid, the
following information is stored on our servers.
- Stored items: purchase token, product ID, subscription state, expiry time,
Google account identifier, and the anonymous device identifier linked to your
account to enforce the 3-device limit
- Purpose: verifying subscription entitlement (extend on renewal, release on cancellation
or refund)
- Retention period: kept for as long as needed to verify subscription entitlement.
Fairy Mana (AI-correction credits) is a consumable used to run AI correction. To tie the mana
balance to your Google account so it persists across reinstalls and device changes, Google sign-in is
required and the following information is stored on our servers. Top-up payments are handled through
Google Play, and card/payment details are processed by Google and not collected by the Service.
- Stored items: Google account unique identifier (sub), mana balance, whether free mana was
granted, and (on top-up) purchase token, product ID, top-up quantity, grant status, and processing time
- Purpose: managing and deducting the mana balance, verifying purchases, and preventing
duplicate grants
- Retention period: kept for as long as needed to manage the mana balance and account, and
deleted upon your request.
- The sign-in token is used to verify only the account identifier (sub); email and name are
not stored on the server.
- Sign-in session: so that you do not have to sign in with Google repeatedly, the server
stores a hash of a session identifier it issued, the account identifier (sub), the anonymous
device identifier, and the issue, expiry and last-used times. Kept for at most 180 days,
and it expires sooner if unused for 90 days. Deleted on
sign-out or expiry.
The above server-stored data is stored and processed on the database infrastructure of
Cloudflare, Inc. (USA).
7. Retention and destruction
Memos and settings stored on your device are deleted when you delete the app. On-device data is
configured to be excluded from Google auto-backup, so apart from the encrypted backup you turn
on yourself, it is not copied off the device. You can delete backups saved to your Drive yourself.
Customer-inquiry (complaint / dispute handling) records are kept for 3 years from the
date of resolution to meet consumer-protection and dispute-record obligations, and then destroyed. On
destruction, the records — including email address and inquiry content — are deleted.
Retention periods for other records stored on the server are as follows, after which they are
destroyed. Records concerning payment and supply of goods (subscription entitlement and mana top-up history) are
kept for 5 years to meet legal, accounting, and tax record-keeping obligations, after which the
personal identifier (account identifier) is removed (pseudonymized) and only the transaction fact
remains. Operational device-link information is deleted 1 year after last use. Sign-in session records are kept for at most 180 days from issue, expiring sooner if unused for 90 days, and are deleted on sign-out or expiry. Destruction is
carried out by an administrator after confirming the affected count.
Records of an executed account-data deletion (time of processing, the administrator, and a
summary of what was processed) are kept to prevent abuse such as repeatedly claiming the free trial
mana. The account identifier is not stored in its original form; we store only an irreversible fingerprint
(HMAC-SHA-256 keyed with a server-side secret), from which the account cannot be identified or linked to
other information. These records are automatically deleted 1 year after processing.
8. Your rights
You can delete all data stored on your device by deleting the app. The AI-correction and backup features can
each be left unused or turned off in settings, and if unused no related transmission occurs.
You may request deletion of the account identifier, balance, and purchase history stored on
the server. You can do this from within the app (Settings → Delete account & data),
which opens a pre-filled email, or by contacting us directly (see Contact). We verify the request and delete the
data; a record of the deletion is kept for 1 year as an irreversible fingerprint, and records that must be legally
retained are pseudonymized (see Section 7). Region-specific rights are described
in Sections 9 and 10.
9. California residents (CCPA/CPRA)
In the past 12 months we may process the following categories of personal information: identifiers
(Google account identifier, an anonymous device identifier, and — for ads — an advertising identifier),
commercial information (subscription and mana top-up records), internet/usage
activity (per-day request counts for abuse prevention, and aggregate in-app event counts used for product
improvement and ad-performance measurement), and diagnostic data (crash
reports: error type/message, stack trace, device model, OS and app version). We collect these to provide and
secure the Service, as described above.
- We do not sell your personal information. For users in the United States we serve
non-personalized ads only, so we do not "share" your personal information for cross-context
behavioral advertising as defined by the CPRA. We link aggregate conversion events to Google Ads
for campaign measurement only; we do not build remarketing audiences.
- You have the right to know/access, delete, and correct
your personal information, and the right to opt out of sale/share (already the default here
via non-personalized ads), without discriminatory treatment.
- To exercise these rights, use the in-app deletion request or the Contact below. You can also reset or delete
your advertising identifier in your device settings, and turn off usage statistics in the app's settings.
10. EEA & UK (GDPR / UK GDPR)
The data controller is the operator of the Service (see Contact). We process personal data on these legal bases:
consent (advertising, and ad-purpose analytics signals where consent is required — both obtained
through Google's consent form), performance of a contract (subscription and mana),
legitimate interests (fraud/abuse prevention using the anonymous device identifier, app-stability
crash diagnostics, and aggregate usage statistics for product improvement — each of which you can switch off in
settings), and legal obligation (record retention in Section 7).
- You have the right to access, rectify, erase, restrict, port, and object to processing of
your personal data, and to withdraw consent at any time (for ads, via the app's
"Ad privacy options"; for usage statistics, via Settings > Information > Send usage
statistics).
- You may lodge a complaint with your local data-protection supervisory authority.
- International transfers: some data is processed in the United States by Google LLC (AI
correction, ads, crash diagnostics, and usage statistics), OpenAI, L.L.C. (AI correction, organize, and ask)
and Cloudflare, Inc. (server infrastructure). These providers rely on recognized transfer
safeguards (such as Standard Contractual Clauses) for transfers out of the EEA/UK.
11. Children's privacy
The Service is not directed to children. We do not knowingly collect personal data from children under
13 (or the minimum age required in your country or region). If you believe a child has provided
personal data, contact us and we will delete it.
12. Changes to this policy
If this policy changes, we will give notice through the app or this page.
13. Contact
Privacy inquiries: boomdiboom1@gmail.com
This document is provided to users as a public document. It may be revised in line with
applicable law or service changes. In case of any discrepancy, the Korean version prevails.