Last revised · June 17, 2026
This Privacy Policy (the "Policy") sets out how the Moneywood service (the "Service"), operated by Always summer (the "Company"), collects, uses, and discloses personal information. The Company values users' personal information and makes best efforts to protect it in accordance with applicable privacy laws, including the Personal Information Protection Act.
Personal information means information relating to a living individual that can identify that individual by itself (such as name or resident registration number), or information that can be easily combined with other information to identify the individual.
The Service collects the following personal information: 1. Required information: email address (for login and service delivery) 2. Optional information: name, nickname, profile image (collected with user consent or from social login providers) 3. Automatically collected information: access logs, IP address, OS version, device model, app version, browser type (web), usage patterns, and push notification tokens 4. Payment-related information: Paid subscriptions (Pro) are currently in preparation; the payment and in-app-purchase processing described in this item and elsewhere in this Policy (including retention, processing entrustment, and international transfer) applies only from the launch of paid Pro subscriptions. Paid mobile subscriptions are processed through Apple App Store (iOS) or Google Play Store (Android) in-app purchases. The Service does not directly collect or store credit card numbers or payment credentials. Only minimal receipt metadata — such as transaction ID, product ID, purchase and expiration timestamps, and receipt validation results — is collected and retained for subscription verification and refund handling. Cardholder details and billing addresses are stored by Apple/Google. The Service collects only the minimum information necessary to provide the Service.
The Service collects and uses personal information for the following purposes: 1. Service provision: user identification, login, subscription and delivery of email reports 2. Service improvement: usage analytics, service enhancement, and new feature development 3. Security: prevention of abuse, dispute resolution, and customer support 4. Legal compliance: fulfillment of legal obligations and protection of rights and interests Personal information is not used beyond the stated purposes and is not provided to third parties without user consent, except where required by law.
Personal information is retained until the collection purpose is achieved or the retention period expires, and is then promptly destroyed. Record retention periods: 1. Account registration information: until withdrawal or account deletion 2. Access logs: 3 months from collection (as required by the Protection of Communications Secrets Act) 3. In-app purchase receipt metadata (transaction ID, product ID, purchase/expiration timestamps): 5 years from the transaction date (as required by the Act on Consumer Protection in Electronic Commerce) 4. Consumer complaints or dispute records: 3 years after dispute resolution Payment instrument information (card numbers, billing addresses, etc.) is not retained by the Company; it is retained by the platform operators (Apple, Google) under their respective policies. Where laws require longer retention, information is retained for the legally required period.
The Service does not provide users' personal information to third parties except in the following cases: 1. Where the user has given prior consent 2. Where required by law, or requested by investigative authorities for investigative purposes 3. Where necessary for service provision and the recipient/purpose has been disclosed 4. Where urgent to protect rights, property, or safety of users or third parties and obtaining prior consent is impracticable For smooth operation, the Service entrusts the processing of certain personal information to the following external providers: - Supabase Inc.: account authentication and session management (email address, social login identifiers) - Zoho Corporation (ZeptoMail): delivery of email reports and service emails (email address) - Mailgun Technologies, Inc. (a Sinch company): delivery of real-time trade alert (whale alert) emails (email address) - Apple Inc. / Google LLC: in-app purchase processing for the mobile app (receipt metadata) Each processor may only handle personal information for the entrusted purpose, and the Company manages and supervises secure processing through written agreements.
To provide the Service, the Company transfers personal information overseas (for processing entrustment/storage) as set out below, and discloses these matters through this Policy. [1] Supabase Inc. (United States) - Items: email address, social login identifiers, authentication/session data - Time & method: transmitted with encryption over the network at the time of use - Purpose: account authentication and session management - Retention: until withdrawal or termination of the processing agreement - Contact: privacy@supabase.com [2] Zoho Corporation (ZeptoMail) (United States, zeptomail.zoho.com) - Items: email address - Time & method: transmitted with encryption over the network when emails are sent - Purpose: delivery of email reports and service emails - Retention: until withdrawal or termination of the processing agreement - Contact: dpo@zohocorp.com (Zoho Corporation, 4141 Hacienda Drive, Pleasanton, CA 94588, USA) [3] Mailgun Technologies, Inc. (a Sinch company) (United States) - Items: email address - Time & method: transmitted with encryption over the network when alert emails are sent - Purpose: delivery of real-time trade alert (whale alert) emails - Retention: until withdrawal or termination of the processing agreement - Contact: privacy@mailgun.com (Mailgun Technologies, Inc., 112 E Pecan St #1135, San Antonio, TX 78205, USA) [4] Apple Inc. (United States) - Items: in-app purchase receipt metadata - Time & method: transmitted with encryption over the network at payment/validation - Purpose: in-app purchase processing and subscription verification - Retention: 5 years from the transaction date - Contact: privacy.apple.com [5] Google LLC (United States) - Items: in-app purchase receipt metadata - Time & method: transmitted with encryption over the network at payment/validation - Purpose: in-app purchase processing and subscription verification - Retention: 5 years from the transaction date - Contact: https://policies.google.com/privacy (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) Users may refuse the international transfer of their personal information. However, because these transfers are essential to core functions of the Service — including authentication, email delivery, and payment processing — refusal may restrict account registration and use of those functions.
Users may exercise the following rights regarding their personal information at any time: 1. Right to request access 2. Right to request correction of errors 3. Right to request deletion 4. Right to request suspension of processing 5. Right to withdraw consent Users may exercise these rights by contacting the Privacy Officer via email or through the Service settings page. The Service will take action without undue delay upon such request.
The Service is not directed to children under the age of 14, and the Company does not knowingly collect personal information from children under 14. If the Company becomes aware that personal information of a child under 14 has been collected, it will destroy such information without undue delay.
On its web service, the Company may use cookies and similar automatic-collection technologies for usage analytics and service improvement. Cookies are small pieces of information stored in the user's browser; users may refuse or delete cookies through their browser settings. However, refusing cookies may limit the use of certain parts of the web service.
The Service takes the following technical and administrative measures to prevent loss, theft, leakage, alteration, or damage of personal information: 1. Encryption: user passwords are stored in encrypted form, and sensitive data is transmitted using encryption 2. Access control: only authorized personnel can access personal information, and access logs are regularly reviewed 3. Security software: security tools are installed and regularly updated to prevent hacking and malware 4. Regular inspections: regular security checks are performed to identify and remediate vulnerabilities 5. Physical security: physical access to data storage facilities is controlled and restricted
The Service designates a Privacy Officer to handle complaints related to personal information processing. Contact information: - Email: biz@mymoneywood.com - Phone: +82-10-8969-1994 Users may contact the Privacy Officer for all privacy-related inquiries, complaints, and requests for relief. The Service will verify identity and respond without undue delay.
For any privacy concern, you can first contact our Privacy Officer by email (see Article 12); we respond to all users regardless of location. You may also request dispute resolution or consultation from the following authorities in the Republic of Korea, where the Company is established and whose laws govern this Policy: - Personal Information Dispute Mediation Committee (Korea): +82-1833-6972 (www.kopico.go.kr) - Privacy Infringement Report Center, KISA (Korea): 118 (privacy.kisa.or.kr) - Cybercrime Investigation Dept., Supreme Prosecutors' Office (Korea): 1301 (www.spo.go.kr) - Cyber Bureau, National Police Agency (Korea): 182 (ecrm.police.go.kr)
This Policy may be revised in line with changes to applicable laws, government policy, or the Service. When the Policy is changed, the Company will announce the changes, the effective date, and the reason through in-app notices or the website at least 7 days before the effective date. For changes that are unfavorable to users, notice will be given at least 30 days in advance.