Privacy Policy

Friendly Dictionary app · Friendly Store (다정한상점)
Effective date: September 4, 2026 · Last updated: September 4, 2026
Questions: friendlystore.korea@gmail.com · Account deletion: How to delete your account

Friendly Dictionary ("the app") is a seasonal food dictionary for the United States, published by Friendly Store (다정한상점), Hadong-gun, Gyeongsangnam-do, Republic of Korea ("we", "us"). This policy explains what information the app collects, why, where it goes, and what you can do about it. We wrote it to match what the app actually does. The app shows no ads, uses no advertising or analytics trackers, and we do not sell personal information.

1. What we collect and why
2. AI Chef and OpenAI
3. Food Album stays on your device
4. Crash reports
5. Security, abuse prevention, app integrity
6. "Forgot email?" hint
7. Retention and deletion
8. Service providers
9. Your choices and rights
10. Children
11. Where data is processed
12. Changes and contact

1. What we collect and why

You use the app with an account created from an 8-digit PIN code printed on the Friendly Dictionary calendar. The account exists so that your pass (the period the calendar entitles you to use the app) and the things you save can follow you across devices.

InformationWhy we keep it
Email address and passwordTo sign you in and to send password-reset email. The password is stored only by Firebase Authentication in hashed form; we never see or store the password itself. We do not send verification or marketing email.
NicknameShown in the app and used to keep nicknames unique. It is also used for the "Forgot email?" hint (section 6) and the secondary password reset (nickname + most recently used PIN).
Pass records: the PIN codes you have redeemed, the calendar edition they belong to, the date your pass expires, and the dates you registered and renewedTo know whether your pass is active and until when. A redeemed PIN is marked as used so it cannot be used again.
Things you save: favorites (liked ingredients), Yummy records (ingredients you marked as eaten, with the date), your grocery list, and AI Chef recipes you chose to saveTo show them back to you on any device where you sign in.
Crash reports (see section 4)To find and fix bugs.
Hashed IP address and attempt counters (see section 5)To limit repeated PIN or password-reset attempts.

We do not collect your name, phone number, precise location, contacts, or payment information. The app has no camera, microphone, or location permission. There is no in-app purchase; the calendar is bought separately, outside the app.

2. AI Chef and OpenAI

AI Chef suggests a recipe from ingredients you type. When you use it, the ingredient text you entered is sent from our server to OpenAI, L.L.C. (United States) to generate the recipe. We send only that text. Your email, nickname, account ID and device identifiers are not included, and the prompt around your text is written by our server. OpenAI processes API requests under its API data privacy commitments. The recipe that comes back is shown to you and is stored in your account only if you tap to save it; otherwise we do not keep it. AI Chef is available only while your pass is active.

3. Food Album stays on your device

Food Album finds food photos in your phone's photo library and arranges them by month. To do this the app asks for read access to your photos (on iOS you can grant access to selected photos only). All scanning and indexing happens on your device. Your photos, the index the app builds, and the food records you add are stored only on your phone and are never uploaded to our servers or to any third party. If you use the Share button, the photo goes directly from your phone to the app you choose through the operating system's share sheet; it does not pass through us. Deleting the app deletes this local data.

4. Crash reports

The app uses Firebase Crashlytics (Google) to collect reports when the app crashes or hits an unexpected error. A report contains the technical stack trace, your device model and operating system version, the app version, and a Crashlytics installation identifier that is specific to the app on your device. Reports are not linked to your email, nickname or account, and we do not add custom identifiers. Crashlytics is active only in the released app, not in test builds. Google retains crash data for 90 days. Firebase's own terms are described in Privacy and Security in Firebase.

5. Security, abuse prevention and app integrity

All traffic between the app and our servers is encrypted (HTTPS). Server rules prevent any account from reading or writing another account's data; PIN inventories and configuration are never readable from the app. To stop automated guessing of PIN codes and reset requests, our server keeps a short-lived counter keyed to a one-way hash of the requesting IP address (the IP itself is not stored; IPv6 addresses are bucketed before hashing). These counters delete themselves within two days. The app also uses Firebase App Check (Google Play Integrity on Android, Apple App Attest or DeviceCheck on iOS) so that our servers can tell requests from the genuine app apart from tampered or automated clients; App Check tokens are handled by Google and Apple and are not stored by us.

6. "Forgot email?" hint

If you forget which email you signed up with, the sign-in screen lets you enter your nickname and shows a masked version of the email on that account, for example c*****s@g****.com (first and last letter of the local part, first letter of the domain, and the top-level domain). Please be aware that anyone who knows your nickname can see this masked form. To limit misuse, the feature requires a valid App Check token, allows five attempts per nickname and per network address every ten minutes, and returns a similar-looking but meaningless value for nicknames that do not exist, so it does not reveal whether an account exists. The full email address never leaves our server.

7. Retention and deletion

8. Service providers

We use the following providers to run the app. We do not sell personal information and we do not share it with advertisers or data brokers.

ProviderPurpose
Google Firebase (Google LLC, United States)Authentication, database and file storage for account data, Cloud Functions (our server code), Crashlytics, App Check.
OpenAI, L.L.C. (United States)Generating AI Chef recipes from the ingredient text you enter (section 2).
Apple and GoogleApp distribution, App Attest / Play Integrity.

We may also disclose information if required by law or to protect the rights and safety of users and the service.

9. Your choices and rights

Contact for all requests: friendlystore.korea@gmail.com. You can also reach us on Instagram at @friendlystore.korea.

10. Children

The app is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, email us and we will delete it.

11. Where data is processed

We are located in the Republic of Korea. Account data is stored on Google Firebase servers in the United States, and AI Chef requests are processed by OpenAI in the United States. By using the app you understand that your information is processed in these locations.

12. Changes and contact

If we change this policy in a way that matters, we will update the date at the top of this page and, for significant changes, show a notice in the app. Continued use after the effective date means you accept the updated policy.

Friendly Store (다정한상점)
Hadong-gun, Gyeongsangnam-do, Republic of Korea
Email: friendlystore.korea@gmail.com
Instagram: @friendlystore.korea