Apple로 로그인할 때 Firebase 사용자 식별자, Apple 인증 정보, 사용자가 제공하기로 선택한 이름과 이메일 주소 또는 Apple 비공개 릴레이 주소가 처리될 수 있습니다. 프로필 이름과 색상은 기기 또는 공유 여행 서버에 저장될 수 있으며, 프로필 이미지는 현재 기기에만 저장됩니다.
여행 및 경비
여행 이름과 기간, 참가자, 통화와 환율, 가맹점, 금액, 카테고리, 날짜와 시간, 결제자, 결제수단, 인원별 분담액, 메모, 정산 기록, 카드·현금·공금의 이름과 잔액 등이 처리됩니다. 개인 여행은 기본적으로 기기에 저장되며, 공유 여행을 사용할 때 필요한 데이터가 Firebase에 동기화됩니다.
알림 및 기술 정보
공유 여행 알림과 보안을 위해 APNs 기기 토큰, 플랫폼, Firebase App Check 정보, 앱 식별자, IP 주소와 요청 시각 등 기술 정보가 처리될 수 있습니다. 알림 권한은 iOS 설정에서 언제든지 변경할 수 있습니다.
구매 정보
Passport 구독과 평생 이용권 구매는 App Store와 StoreKit에서 처리됩니다. warikan은 이용 권한 확인에 필요한 구매 상태만 확인하며 전체 카드 번호나 결제 계좌 정보를 직접 수집하지 않습니다.
2. 공유 여행
공유 여행에서는 여행 및 참가자 정보, 지출, 결제자와 결제수단, 분담 금액, 공금, 메모와 정산 기록이 초대받은 멤버에게 표시될 수 있습니다. 민감한 개인정보나 서비스 이용에 필요하지 않은 타인의 정보를 입력하지 마세요.
3. 영수증 인식
영수증 이미지는 가맹점명, 금액, 통화, 날짜·시간과 카테고리를 인식하는 데만 사용됩니다. 지원되는 환경에서는 Apple Private Cloud Compute에서 일시적으로 처리될 수 있으며, 사용할 수 없는 경우 기기 내 텍스트 인식을 사용합니다.
영수증 원본은 warikan의 Firebase나 별도 서버에 업로드되지 않고 여행 데이터에도 저장되지 않습니다. Apple에 따르면 Private Cloud Compute의 요청 데이터는 결과 반환 후 보관되지 않으며 Apple도 접근할 수 없도록 설계되어 있습니다.
Apple 및 Google 기능을 사용하는 동안 계정 인증 정보, 공유 여행 데이터, 기기 토큰, 보안 정보와 영수증 인식 요청이 미국 및 각 제공자가 인프라를 운영하는 국가에서 암호화된 네트워크를 통해 처리될 수 있습니다. 처리 기간은 목적 달성 또는 계정·관련 데이터 삭제 시까지이며, 관계 법령이나 각 제공자의 정책에 따른 보관 기간이 적용될 수 있습니다.
7. 보관 및 삭제
기기 데이터: 앱에서 여행을 삭제하거나 앱을 삭제할 때 제거할 수 있습니다.
계정 정보: 계정 삭제 시까지 보관합니다.
공유 여행: 호스트가 여행을 삭제하거나 호스트 계정을 삭제할 때까지 보관합니다.
알림 토큰: 계정 삭제, 토큰 무효화 또는 등록 해제 시까지 보관합니다.
공유 여행의 일반 멤버가 계정을 삭제하면 계정 연결과 프로필 식별 정보는 삭제 또는 익명화됩니다. 다른 멤버의 정산 기록을 유지하기 위해 기존 지출·분담·정산 기록은 익명화된 참가자 정보와 함께 남을 수 있습니다. 호스트가 계정을 삭제하면 해당 호스트가 관리하는 공유 여행 데이터도 함께 삭제될 수 있습니다.
8. 이용자의 권리와 계정 삭제
이용자는 개인정보의 열람, 정정, 삭제, 처리 정지와 동의 철회를 요청할 수 있습니다. 계정은 앱의 계정 > 계정 삭제에서 직접 삭제할 수 있습니다. 앱 삭제만으로 서버 계정이 자동 삭제되지는 않습니다.
앱을 사용할 수 없다면 [email protected]으로 요청해 주세요. 본인 확인을 위해 계정 관련 정보를 요청할 수 있습니다.
9. 보호 조치와 추적 방침
warikan은 전송 구간 암호화, Firebase Authentication, App Check, 공유 여행별 접근 제한과 데이터 최소화를 적용합니다. 타사 광고 SDK를 사용하지 않으며 서로 다른 회사의 앱과 웹사이트를 연결하는 광고 추적을 하지 않습니다.
서비스 또는 관련 법령이 변경되면 이 방침을 수정할 수 있습니다. 중요한 변경은 시행 전에 앱 또는 공식 웹사이트에서 안내합니다.
Privacy Policy
Privacy Policy
Last updated and effective: August 20, 2026
warikan processes only the information needed to record and settle travel expenses.
We do not track you for advertising.
We do not sell personal information.
We do not store original receipt images on our servers.
1. Information we process
Account and profile
When you use Sign in with Apple, we may process a Firebase user ID, Apple authentication information, and the name and email address—or Apple private relay address—you choose to provide. Your profile name and color may be stored on your device or the shared-trip server. Profile images are currently stored only on your device.
Trips and expenses
We process trip names and dates, participants, currencies and exchange rates, merchants, amounts, categories, transaction dates and times, payers, payment methods, individual shares, notes, settlements, and the names and balances of cards, cash, and common funds. Personal trips are stored on your device by default. Data required for a shared trip is synchronized with Firebase when you use sharing.
Notifications and technical information
To provide shared-trip notifications and protect the service, we may process an APNs device token, platform, Firebase App Check information, app identifiers, IP address, and request time. You can change notification permission at any time in iOS Settings.
Purchases
Passport subscriptions and lifetime purchases are processed through the App Store and StoreKit. warikan checks only the purchase status needed to determine access and does not directly collect your full card number or bank account details.
2. Shared trips
Trip and participant information, expenses, payers and payment methods, individual shares, common-fund activity, notes, and settlements may be visible to invited members. Do not enter sensitive information or another person’s information that is not needed for the service.
3. Receipt recognition
Receipt images are used only to identify the merchant, amount, currency, date, time, and category. On supported devices, an image may be processed temporarily by Apple Private Cloud Compute. When that service is unavailable, recognition runs on the device.
Original receipts are not uploaded to warikan’s Firebase or any separate operator server and are not saved as part of your trip. According to Apple, request data handled by Private Cloud Compute is not retained after the response is returned and is designed to remain inaccessible to Apple.
4. How we use information
Record and summarize travel expenses and manage payment methods and common funds
Calculate individual shares and recommend settlement routes
Create, invite to, synchronize, and notify members about shared trips
Authenticate accounts, verify purchases, and protect the service
Recognize receipts, answer support requests, and resolve errors
5. Service providers
Apple
We use Sign in with Apple, the App Store, StoreKit, APNs, and Private Cloud Compute for authentication, purchases, notifications, and receipt recognition.
We use Firebase Authentication, Cloud Firestore, Cloud Functions, and Firebase App Check for authentication, shared-trip synchronization, notifications, security, and account deletion.
When Apple or Google services are used, authentication information, shared-trip data, device tokens, security information, and receipt-recognition requests may be processed over encrypted connections in the United States and other countries where those providers operate infrastructure. Information is retained until its purpose is fulfilled or the account and related data are deleted, subject to applicable law and each provider’s policies.
7. Retention and deletion
On-device data can be removed by deleting a trip in the app or deleting the app.
Account information is retained until the account is deleted.
Shared-trip data is retained until the host deletes the trip or the host account is deleted.
Notification tokens are retained until account deletion, invalidation, or deregistration.
If a regular member deletes their account, the account link and identifying profile information are deleted or anonymized. Existing expense, share, and settlement records may remain with an anonymized participant so other members can preserve their accounts. If a host deletes their account, shared trips managed by that host may also be deleted.
8. Your rights and account deletion
You may request access, correction, deletion, restriction, or withdrawal of consent. Delete your account directly in Account > Delete Account. Deleting the app alone does not automatically delete a server account.
If you cannot access the app, contact [email protected]. We may request account information to verify your identity.
9. Security and tracking
warikan uses encrypted transport, Firebase Authentication, App Check, access controls for each shared trip, and data minimization. We do not use third-party advertising SDKs or track activity across other companies’ apps and websites for advertising.
We may update this policy when the service or applicable laws change. Material changes will be announced in the app or on the official website before they take effect.