Privacy Policy
Friendly Dictionary ("the app") is a seasonal food dictionary for the United States, published by Friendly Store (다정한상점), Hadong-gun, Gyeongsangnam-do, Republic of Korea ("we", "us"). This policy explains what information the app collects, why, where it goes, and what you can do about it. We wrote it to match what the app actually does. The app shows no ads, uses no advertising or analytics trackers, and we do not sell personal information.
2. AI Chef and OpenAI
3. Food Album stays on your device
4. Crash reports
5. Security, abuse prevention, app integrity
6. "Forgot email?" hint
7. Retention and deletion
8. Service providers
9. Your choices and rights
10. Children
11. Where data is processed
12. Changes and contact
1. What we collect and why
You use the app with an account created from an 8-digit PIN code printed on the Friendly Dictionary calendar. The account exists so that your pass (the period the calendar entitles you to use the app) and the things you save can follow you across devices.
| Information | Why we keep it |
|---|---|
| Email address and password | To sign you in and to send password-reset email. The password is stored only by Firebase Authentication in hashed form; we never see or store the password itself. We do not send verification or marketing email. |
| Nickname | Shown in the app and used to keep nicknames unique. It is also used for the "Forgot email?" hint (section 6) and the secondary password reset (nickname + most recently used PIN). |
| Pass records: the PIN codes you have redeemed, the calendar edition they belong to, the date your pass expires, and the dates you registered and renewed | To know whether your pass is active and until when. A redeemed PIN is marked as used so it cannot be used again. |
| Things you save: favorites (liked ingredients), Yummy records (ingredients you marked as eaten, with the date), your grocery list, and AI Chef recipes you chose to save | To show them back to you on any device where you sign in. |
| Crash reports (see section 4) | To find and fix bugs. |
| Hashed IP address and attempt counters (see section 5) | To limit repeated PIN or password-reset attempts. |
We do not collect your name, phone number, precise location, contacts, or payment information. The app has no camera, microphone, or location permission. There is no in-app purchase; the calendar is bought separately, outside the app.
2. AI Chef and OpenAI
AI Chef suggests a recipe from ingredients you type. When you use it, the ingredient text you entered is sent from our server to OpenAI, L.L.C. (United States) to generate the recipe. We send only that text. Your email, nickname, account ID and device identifiers are not included, and the prompt around your text is written by our server. OpenAI processes API requests under its API data privacy commitments. The recipe that comes back is shown to you and is stored in your account only if you tap to save it; otherwise we do not keep it. AI Chef is available only while your pass is active.
3. Food Album stays on your device
Food Album finds food photos in your phone's photo library and arranges them by month. To do this the app asks for read access to your photos (on iOS you can grant access to selected photos only). All scanning and indexing happens on your device. Your photos, the index the app builds, and the food records you add are stored only on your phone and are never uploaded to our servers or to any third party. If you use the Share button, the photo goes directly from your phone to the app you choose through the operating system's share sheet; it does not pass through us. Deleting the app deletes this local data.
4. Crash reports
The app uses Firebase Crashlytics (Google) to collect reports when the app crashes or hits an unexpected error. A report contains the technical stack trace, your device model and operating system version, the app version, and a Crashlytics installation identifier that is specific to the app on your device. Reports are not linked to your email, nickname or account, and we do not add custom identifiers. Crashlytics is active only in the released app, not in test builds. Google retains crash data for 90 days. Firebase's own terms are described in Privacy and Security in Firebase.
5. Security, abuse prevention and app integrity
All traffic between the app and our servers is encrypted (HTTPS). Server rules prevent any account from reading or writing another account's data; PIN inventories and configuration are never readable from the app. To stop automated guessing of PIN codes and reset requests, our server keeps a short-lived counter keyed to a one-way hash of the requesting IP address (the IP itself is not stored; IPv6 addresses are bucketed before hashing). These counters delete themselves within two days. The app also uses Firebase App Check (Google Play Integrity on Android, Apple App Attest or DeviceCheck on iOS) so that our servers can tell requests from the genuine app apart from tampered or automated clients; App Check tokens are handled by Google and Apple and are not stored by us.
6. "Forgot email?" hint
If you forget which email you signed up with, the sign-in screen lets you enter your nickname and shows a masked version of the email on that account, for example c*****s@g****.com (first and last letter of the local part, first letter of the domain, and the top-level domain). Please be aware that anyone who knows your nickname can see this masked form. To limit misuse, the feature requires a valid App Check token, allows five attempts per nickname and per network address every ten minutes, and returns a similar-looking but meaningless value for nicknames that do not exist, so it does not reveal whether an account exists. The full email address never leaves our server.
7. Retention and deletion
- Account data (email, nickname, pass records, favorites, Yummy records, grocery list, saved recipes) is kept while your account exists and is deleted when you delete your account — immediately in the app, or within 7 days when you ask us by email. See How to delete your account.
- Redeemed PIN codes remain marked as used after account deletion so that a code cannot be reused; the record no longer points to any account.
- Abuse-prevention counters expire automatically within 2 days.
- Crash reports are retained by Google for 90 days and cannot be linked back to you.
- Backups: deleted data may persist in encrypted backups for a limited period before being overwritten.
- Food Album data lives only on your phone; uninstalling the app removes it.
8. Service providers
We use the following providers to run the app. We do not sell personal information and we do not share it with advertisers or data brokers.
| Provider | Purpose |
|---|---|
| Google Firebase (Google LLC, United States) | Authentication, database and file storage for account data, Cloud Functions (our server code), Crashlytics, App Check. |
| OpenAI, L.L.C. (United States) | Generating AI Chef recipes from the ingredient text you enter (section 2). |
| Apple and Google | App distribution, App Attest / Play Integrity. |
We may also disclose information if required by law or to protect the rights and safety of users and the service.
9. Your choices and rights
- Access and correction: your email, nickname, pass expiration and saved items are visible in the app. Nicknames cannot be changed after sign-up; the email on the account is fixed to the one you registered with. For anything else, email us.
- Deletion: use Delete account in the app (Likes page) or email us from the address on the account. Details: How to delete your account.
- Photos permission: you can revoke or limit photo access at any time in your phone's settings; Food Album will simply show fewer or no photos.
- AI Chef: nothing is sent to OpenAI unless you use the feature.
- California residents: you have the right to know what personal information we collect, to request its deletion, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise a right, email us; we may ask you to confirm the request from the email address on the account.
- Other regions: if your local law gives you additional rights (for example access, portability or objection), you may exercise them by email and we will respond within the period your law requires.
Contact for all requests: friendlystore.korea@gmail.com. You can also reach us on Instagram at @friendlystore.korea.
10. Children
The app is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, email us and we will delete it.
11. Where data is processed
We are located in the Republic of Korea. Account data is stored on Google Firebase servers in the United States, and AI Chef requests are processed by OpenAI in the United States. By using the app you understand that your information is processed in these locations.
12. Changes and contact
If we change this policy in a way that matters, we will update the date at the top of this page and, for significant changes, show a notice in the app. Continued use after the effective date means you accept the updated policy.
Hadong-gun, Gyeongsangnam-do, Republic of Korea
Email: friendlystore.korea@gmail.com
Instagram: @friendlystore.korea