Settly Privacy Policy
- Effective Date: 2026-09-21
- Last Updated: 2026-09-21
- Controller/operator: Solidsoft
- Address: 4F, Room 498, 60 Dunji-ro (Dunsan-dong), Seo-gu, Daejeon, Republic of Korea
- Privacy contact: corp@solidsoft.team · +82-10-2615-3559
- 한국어: 개인정보처리방침
This Policy covers the Settly Android app, shared-table viewer, and privacy and terms website. Settly calculates how to split expenses; it does not transfer money, track completed transfers, or provide a financial account. Subscription conditions appear in the Terms of Use.
Japanese notices are available in the Japanese policy, and Taiwan notices in the Traditional Chinese policy. These language options do not waive mandatory rights applicable to you.
The U.S. disclosures below address the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable state privacy laws. A law and its rights apply when its jurisdictional, business, and processing requirements are met.
1. Scope and key privacy facts
In versions supporting cloud collaboration, after the cloud-storage disclosure in the service notice is acknowledged, all settlements, participants, items, notes and attached photos sync to the operator's Firebase servers, whether or not a link has been shared. If you have created a table, your full category list and its order also sync, including unused categories. Offline changes are stored locally and uploaded after reconnection. Settlement content is not included in advertising, diagnostics, usage analytics or subscription-verification data.
Each table has a hard-to-guess sharing code. Anyone with its link can view it on the web or edit together in the app. Only its original creator can delete the whole server table. Reinstalling or resetting app data can lose owner access; reopening a link does not restore that ownership. See Sections 4 and 8.
Usage analytics is optional. Firebase Analytics collection and delivery are permitted only after both [Optional] Analytics collection and use and [Optional] International data transfer have been saved as agreed. Declining either choice does not prevent settlements, image sharing, subscriptions, or restoration. Free-version limits and Pro benefits are independent of analytics consent.
Before the initial notice is acknowledged, Settly does not start UMP, AdMob, remote Firebase diagnostics, or RevenueCat. Afterwards, configured release builds automatically collect crash and performance diagnostics. RevenueCat also checks the current entitlement for free users, not only after someone taps a purchase button. Notice acknowledgement and Google's ad choices are not treated as optional analytics consent.
Settly has no user-facing signup or login. Cloud sync uses a Firebase anonymous authentication ID linked to RevenueCat to check the creator's subscription limits. Installation, authentication and purchase identifiers can be associated with usage or purchases; they are not fully anonymous merely because they lack a name. A support ID generated for each app installation links support requests, server operation logs, subscription information and Crashlytics errors. With analytics consent, it is also used as the Firebase Analytics user ID.
The support ID is a UUID generated for each app installation. It survives app updates and restarts but is regenerated after reinstallation, clearing app storage or switching devices, and is excluded from backups. It can be viewed and copied in App information and is included in editable support email drafts. Deleting settlement data does not reset the installation ID. It is not an authentication credential and is not included in settlement content or advertising requests. Local storage lasts until app storage is cleared; copies sent to external services follow the respective retention and deletion rules below.
2. Categories of personal information
The following describes current processing, including testing before public launch. Over the preceding 12 months, or since processing began if shorter, disclosures are limited to the functions and recipients described in this Policy. A provider may process information that the operator does not directly receive.
| Category | Examples and sources | Purpose | Retention period or criterion |
|---|---|---|---|
| User-provided content, including photos | From you or a collaborator: settlement title, currency/rounding, participant names/order, item names, expense currencies, original/converted amounts, conversion methods and applied rates, expense dates, payers, split participants and ratio/percentage allocations, assigned category names, notes and selected photos | Calculation, offline editing, synchronization, collaborative editing and shared web viewing | Local database/files and the operator's Firestore/Cloud Storage in Seoul, Republic of Korea. Section 8 explains table, attachment and deletion retention |
| Creator category catalog | All category IDs, names, order, deletion markers and catalog revision managed by the creator, including unused categories | A consistent selection list across every table the creator makes and its app collaborators | Local Room database and the operator's Firestore. Deleting the creator's last server table removes the server catalog; local settings remain |
| Sync and access metadata | Table/item/photo IDs, hashed sharing codes, creator authentication ID and table count, revisions, operation IDs/digests/editor IDs, actual view/edit times, attestation materials and tokens, hashed IP/ID rate counters, request types/error codes | Link access, owner deletion, creator limits, conflict handling, retry deduplication and service security | Firebase/Google Cloud and local sync queues. Polling is not recorded as a new visit. Rate counters expire after 24 hours and are then removed through the provider's automatic deletion process; other criteria are in Section 8 |
| Server operational logs | Installation support ID, verified requester/creator Firebase authentication IDs, table/item/photo resource paths, request IDs/types, success/error codes, duration, app version and sync/quota state | Investigate server faults, verify access and processing outcomes, service security | Google Cloud Logging; separate from 24-hour rate counters and two-month Analytics details. See Section 11 for verified retention and processing details |
| Identifiers | From the device, Google SDKs and store: IP address, user agent, advertising/app set IDs, Firebase authentication/installation/session and Analytics app-instance IDs; RevenueCat app user ID, installation support ID and Play transaction identifiers. From a requester: email and necessary verification information | Authentication, ads and privacy choices, diagnostics, consented analytics, subscription verification, website delivery, support | Provider-specific periods below. Only necessary authentication identifiers are linked to cloud table metadata; ads/Analytics IDs and purchase tokens are not stored as settlement content. Support messages remain while needed for the request or applicable duties |
| Commercial information | Play/RevenueCat product, base plan, purchase token, transaction and entitlement state, renewal, expiry, refund, subscription price/currency and period; displayed subscription prices in consented analytics | Purchase validation, acknowledgement, restoration, entitlement updates, subscription operations and consented purchase-flow analysis | Store and RevenueCat records and device caches. Subscription expiry or uninstall does not itself delete server records; see Section 8 |
| Internet or other electronic network activity | App/ad interactions; crashes and technical state; performance timings and network URLs without queries or bodies; the consented screen, settlement, expense, result, sharing, joining, exchange-rate, sync-error and subscription events detailed below; SDK automatic events such as first opens and sessions | Ads, fraud prevention, troubleshooting and performance; with both consents, improving settlement, sharing, exchange-rate and subscription usability and analyzing save, purchase and sync errors experienced by users | Ad data follows provider policies and choices. Crashlytics starts deletion after 90 days; Performance after 30 days for IP-linked events and 60 days for installation-linked/deidentified performance data. Analytics detail retention is set to two months |
| Approximate geolocation and device information | IP-derived approximate location or country, model, app/OS/SDK version, language, network and technical device state | Ad delivery, fraud prevention, diagnostics and consented usage analysis | Relevant service retention. Hosting visitor IPs are retained for a few months. Settly does not request precise location permission |
| Support communications | Email address, message and necessary request or purchase verification information supplied by a user | Answer questions, exercise rights, resolve disputes | Until no longer needed for the request, compliance or dispute; applicable legal records may be retained separately |
App-defined analytics events contain whether tables exist when measurement starts; predefined screen types and visits; table creation, duplication and opening; expense-save outcomes and validation categories; conversion modes; whether notes, photos, categories and expense dates are used; result-screen and calculation states; link/image share-launch results; join sources and results; exchange-rate lookup outcomes; visible sync-error categories and manual retries; owner/invitee status; free-limit events; subscription and price views; purchase starts and results; entry points, limit type, free/Pro verification state, product, monthly/annual plan, offer, trial duration and displayed store subscription price/currency.
Optional expense fields are recorded only as used or not used, not their contents or actual dates. Owner/invitee status describes the installation's relationship to a table, not a participant's identity. A successful save means local device storage, and a share launch means opening Android sharing, not confirmed delivery or a money transfer. Subscription prices are not the expense amounts in settlement tables, and purchase-attempt results are not a definitive revenue ledger.
App-defined events exclude settlement, expense, participant and category names; note contents, photos and actual expense dates; expense and settlement amounts and exchange-rate values; sharing links and codes; table and expense IDs; Firebase authentication user IDs; order numbers, purchase tokens, RevenueCat customer IDs, and raw errors. A separate installation support ID is set as the Analytics user ID to correlate server operation logs, RevenueCat customer attributes and Crashlytics errors. This Analytics linkage requires both current analytics collection and international-transfer consents. Firebase authentication UIDs and RevenueCat purchase IDs themselves are not sent to Analytics. SDK automatic screen reporting is disabled; the app explicitly records only predefined types of screens actually shown. Analytics advertising-ID collection, ad storage, ad-user-data use and ad personalization are disabled. These settings do not eliminate installation identifiers or all SDK automatic events, which can vary with installed SDKs and integrations.
Settly does not set names, emails or phone numbers as RevenueCat customer attributes. Additional automatic device-identifier collection and RevenueCat SDK diagnostics are disabled; necessary purchase verification still occurs. Custom diagnostic records exclude settlement content and raw purchase tokens.
3. Your optional analytics choices
- In the service notice, Agree to all saves both analytics choices as agreed. With one selected, Agree to selected saves that choice without starting analytics. Agree to required only declines both analytics choices and continues into the app. These buttons also accept the required Terms of Use and acknowledge service/cloud disclosures; those records are separate from optional analytics consent.
- Apps supporting support ID correlation request a new choice at consent version 7. Earlier consent is not automatically applied to the expanded scope. Both optional items start unselected and must be agreed before expanded measurement starts. Older apps remain subject to the scope disclosed and agreed in those versions.
- Either declined choice prevents usage analytics collection and delivery. Manual app events from before consent are discarded, not saved for later replay. SDK automatic-event timing and generation can differ from manual events.
- Open Settings → Usage analytics consent, deselect either or both choices, and save to withdraw. Withdrawal stops subsequent analytics collection and delivery and resets local Analytics data. Retry if a save error appears so the choice persists on the next launch.
- Local reset is not confirmation that previously uploaded server data has been deleted. Use Section 10 for a server-data request.
- Analytics consent applies only to usage analytics. It does not control Google UMP ad choices, operational diagnostics, or subscription verification. Refusal or withdrawal does not change subscription prices or access to otherwise available functions.
4. Local data, cloud sync, backup and sharing
The local Room database and photo files contain the settlement content listed in Section 2. DataStore contains preferences, notice version, the two analytics choices, consent version and save time. Cloud sync uploads existing and new tables after the cloud-storage disclosure is acknowledged. A creator's full category list and its order also sync, including unused categories, and apply across all tables they create. Other general settings are not synced.
App users with a sharing link receive the creator's full category list for item selection. It is not automatically merged into their personal settings. Only the creator can manage that list in Settings; the web displays only category names assigned to that table's items. Deleting a category leaves its linked items uncategorized without deleting their other contents. A deletion marker prevents old input from restoring that classification. Do not include information you do not want to share in category names. Deleting the creator's last server table also removes the server category list; local category settings remain.
Every table has a code, including a table whose link you have not sent. There is no public directory of tables. Anyone who obtains or receives the link can view names, notes, photos and calculated results. In the app they can also add, edit or delete items and participants. There is currently no per-invitee approval, permission tier or link rotation. Share links only with trusted recipients and ensure you may include other people's information.
Actual table opens and edits update service timestamps. Background sync, polling and retries of the same operation do not count as new activity. There is currently no inactivity-based automatic table deletion. Any future retention change will be separately communicated. These service records are separate from optional usage analytics.
Unsaved or failed input is held in memory and cleared on successful save, cancellation, related-data deletion or process end. A shared PNG is cached until the next image share, deletion of all settlement data or Android cache cleanup. PDF/XLSX exports and preparation-photo/shared-copy caches are also local: the next file-export preparation removes copies older than seven days; deletion of all settlement data and Android cache cleanup can remove them too. This is not a guaranteed deletion exactly seven days after creation. Files saved elsewhere and recipients’ copies follow their own retention.
Android system backup or device transfer may include the settlement database, sharing links and ordinary settings when enabled. Purchase-entitlement/RevenueCat caches and anonymous authentication credentials are excluded by Settly's backup allowlist. A backup or link does not guarantee restoration of original owner access. Backup retention and deletion follow Android and the user's account settings; local deletion need not immediately remove older backup copies.
A shared link displays current server content. PNG, PDF and Excel (XLSX) results are created from the device’s content at export time, without guaranteeing completed server sync. Detailed documents can include expense dates, categories, notes and photos according to the selected options. Review included fields and recipients before sharing or saving. The result files are not separately stored on the operator’s server, although existing attached photos may be downloaded to create them. Later edits or deletion cannot recall files saved externally or recipients’ copies. Automatic rate lookup sends the currency pair to the operator’s server; that server retrieves a fixed ECB reference-rate dataset without sending settlement content, participants or photos to the ECB. The app uses Android's sandbox but does not add separate database encryption or an app lock. Protect the device with access controls and security updates. The operator cannot access content that has not left your device, but authorized operational access to synced server content is possible.
5. Providers and disclosures
| Recipient | Information and function | When processing occurs |
|---|---|---|
| Google Cloud/Firebase — Firestore, Cloud Storage, Cloud Functions and deletion retry jobs | Settlement content, sync metadata and access-protection information for storage, collaboration, viewing, deletion and security | After the cloud notice, during creation, editing, sync, link opening and deletion; settlement storage and functions are configured in Seoul |
| Google Cloud — Cloud Logging | Server operational logs in Section 2, fault investigation, access/outcome verification and security | During server request processing; verified location/retention and legal bases are in Section 11 |
| Google LLC — Firebase Authentication/App Check and Google Play Integrity | Anonymous authentication IDs, connection information, attestation materials and tokens for authentication and app-integrity checks | After the cloud notice, during authentication, token issuance/validation and server requests |
| Google LLC — AdMob, UMP and applicable ad partners | Identifiers, ad/app activity, approximate location and technical diagnostics for privacy choices, advertising, measurement and fraud prevention | After initial notice acknowledgement; ad requests only when UMP permits them |
| Google LLC — Firebase Crashlytics and Performance Monitoring | Installation/session identifiers, crashes, device/app state and network/performance data for troubleshooting | Automatically after notice acknowledgement in configured release builds |
| Google LLC — Google Analytics for Firebase | The consented manual and automatic analytics information in Section 2 | Collection is enabled only after both consents; events are sent over encrypted connections, possibly later because of connectivity |
| RevenueCat, Inc. | Subscription identifiers, transactions, technical connection information, entitlement status and the linked Firebase anonymous authentication ID for purchase and creator-limit verification | After initial notice acknowledgement for free-user initialization, customer/product queries, purchases, restoration and Play notifications; after the cloud notice for identity linking and server-side creator-limit checks |
| Google Play | Payment and subscription information for purchases, renewals, cancellation, refunds and verification | Through Play services, payment screens, verification and server notifications |
| Google LLC — Firebase Hosting | Visitor IP for page delivery, abuse prevention and hosting usage analysis | When shared-table, privacy or terms pages are opened |
| Google Workspace (Gmail) — Google Asia Pacific Pte. Ltd. / Google LLC | Support email, replies and necessary verification information | When a user contacts support and the operator responds |
| Link holders and user-selected backup/sharing recipients | Shared table content, including notes/photos; local data/settings or requested PNG/PDF/XLSX | When a link holder opens the table, through enabled Android backup or an intentional result-file share or save |
RevenueCat and providers performing diagnostics, analytics and hosting process information under their applicable service and data-processing terms. Store payments and advertising-party processing may also be governed by those parties' independent terms. Settly does not disclose settlement content to the advertising, analytics, diagnostics or purchase-verification providers.
6. Sale, sharing and advertising choices
Settly does not sell personal information for money. Conditional AdMob disclosures of identifiers, app/ad activity and approximate location for advertising across unaffiliated services may constitute sharing for cross-context behavioral advertising or targeted advertising under applicable state law. For this notice, Settly treats these advertising disclosures as sharing and provides opt-out methods.
Exercise the Right to Opt-Out through Google's Ad privacy choices entry in Settings when available, the Do Not Sell or Share My Personal Information page, or the privacy contact. Google messages govern personalization and applicable regional consent or opt-out signals. Non-personalized ads can still process data for delivery, measurement and fraud prevention.
A verified Pro entitlement stops ad requests but does not disable diagnostics or separately consented analytics. Changing the Android advertising ID or an ad choice is not an analytics withdrawal or a RevenueCat deletion request.
Shared-table, policy and terms pages install no advertising or analytics tracking scripts or cookies. They do not sell or share browser data for advertising regardless of a Global Privacy Control (GPC) signal. Shared-table opens update the service's last-viewed timestamp separately. A signal on this website does not automatically change every Android-app setting; use the applicable in-app control or contact us.
7. Sensitive Personal Information, children and automated decisions
Settly does not request government identifiers, financial account credentials, precise location, biometric, genetic or neural data, health information, or other Sensitive Personal Information for profiling. Do not include such information in free-text fields, attached photos or support emails. Only user-selected photos are imported as app-specific JPEG copies; Settly does not perform OCR or face identification. The app does not request contacts, precise location, camera, microphone, health or biometric permissions.
Settly does not use Sensitive Personal Information for purposes requiring a Right to Limit Use control. If that practice changes, the required notice and controls will be provided. Local expense amounts are not financial-account credentials.
Settly is not designed or directed to children, including children under 13, and does not knowingly sell or share information of anyone under 16. If inappropriate child-data processing is identified, the operator will take applicable steps to stop it and delete information it controls. A parent or guardian can contact us.
Settly does not use Automated Decision-Making Technology to make legally or similarly significant decisions about employment, credit, insurance, housing or similar opportunities. Settlement results use arithmetic on user input, not significant profiling.
8. Retention, deletion and destruction
Analytics event- and user-level detail retention is set to two months, with extension on new user activity off. Expired detail is removed through Google's monthly deletion process; setting changes can take 24 hours to apply. The setting does not uniformly limit standard aggregated reports, separately retained copies, or subscription records. Analytics retention
RevenueCat data is retained under the operator's service agreement, applicable deletion requests and legal exceptions, not simply until a user's Pro subscription expires. Contract termination, return/deletion and backup exceptions follow the RevenueCat DPA. Google Play retains transaction information under its policies and legal duties.
Deleting a table you created blocks link access and further edits once the server receives the request, then deletes its content, photos and child operation records. Failed cleanup is retried. Whole-table deletion cannot be undone in the app. Offline deletion waits on the device until reconnection; others can still see the server copy until then. Uninstalling or clearing app data before transmission can lose the queued deletion.
Removing an invited table removes only that device’s table and pending changes, not the server copy. Settings → Delete all settlement data requests permanent server deletion of tables you created and removes invited tables only from this device. Once applied on the server, other participants also lose access. Offline deletions remain queued until reconnection; uninstalling or resetting before delivery can leave server content behind. Local tables, related photos and result-file caches are cleaned up, while personal settings/categories, notice acknowledgement, analytics consent and purchase entitlement remain. This does not cancel renewal, withdraw analytics consent, or delete unrelated Firebase authentication, Analytics or RevenueCat records.
While a table exists, its synced content, item/participant undo state and retry-deduplication records are retained. Photos removed from an item can remain on the server until whole-table deletion. Afterwards, only a minimal deletion marker containing the table ID and sharing-code hash remains, without settlement content, names or authentication IDs, for as long as the sync service needs to prevent old offline requests from recreating that table.
Cloud Storage photos currently have a seven-day provider soft-delete period. They are inaccessible through the app/link during this period and then follow the provider's final deletion process. This is not a user-facing table restoration or undo service. Cloud Storage deletion
Reinstallation or data reset can lose the original anonymous identity; joining again through a link does not restore owner access. There is currently no account linking, ownership recovery or inactivity-based automatic table deletion. Losing ownership does not immediately delete server content. Use Section 10 to request deletion or restriction of remaining information.
Authentication identifiers and creator counts remain while needed for authentication, permissions and limits. Firebase retains other authentication information until the associated user is deleted and then applies its system-deletion process; authentication IP logs are kept for a few weeks. App Check materials/tokens follow the applicable provider and feature rules and are not placed in settlement content or custom logs. Firebase privacy information
Support information is deleted when no longer needed for the request, applicable compliance or disputes. Where Korean e-commerce recordkeeping applies to the operator's records, contract/withdrawal and payment/service-supply records are kept for five years, complaint/dispute records for three years and advertising records for six months. These duties are not a basis for retaining entire settlement tables as statutory transaction records.
Support email retention is separate from the two-month Analytics setting. Under the Google Cloud Data Processing Addendum, deletion that is no longer recoverable by the operator instructs Google to erase the data from its systems as soon as reasonably practicable, within 180 days, subject to legally required retention. Trash/recovery stages are not confirmation of completed system deletion.
Unneeded electronic records are deleted through the relevant storage/provider tools. Required records are retained separately for the permitted purpose. Server and backup deletion can follow a provider's schedule; neither local reset nor a submitted request means all remote copies have already been erased. Restoring or syncing an active purchase can recreate a RevenueCat record; deletion is distinct from cancelling renewal.
9. U.S. privacy rights
Depending on applicable law and exceptions, you may have the Right to Know or access information about collection and disclosures, Right to Delete, Right to Correct, Right to Opt-Out of sale/sharing, targeted advertising or qualifying profiling, Right to Limit Use of Sensitive Personal Information, and Data Portability. Non-Discrimination means no unlawful retaliation for exercising these rights. Where applicable, you may appeal a denied request.
Settly provides no discount or financial incentive in exchange for analytics consent or sale/sharing of data. Pro is an optional subscription for its stated benefits, not an analytics-consent incentive.
10. Requests, verification and appeals
Contact corp@solidsoft.team · +82-10-2615-3559 with Settly privacy request, your requested action, the type of record (table/photo, analytics, purchase or support), and a reply address. Tell us whether you can still use the device and whether the request concerns a table you created or your information entered by someone else. We explain the minimum information needed to identify the record and verify authority, process the relevant systems/providers, and report the result or applicable limitation/extension within the required deadline. Settly is online-only and does not require an app account to submit a request. Requests are free unless applicable law permits a fee.
For access, correction or deletion, we may ask for minimal information to identify the relevant record and verify authority. Authorized agent requests are accepted through the same contact, with authorization checks where permitted. An advertising opt-out does not require creation of an account or identity verification, though information to identify the affected device or record may be needed.
Email is not used as the app's authentication, Analytics or RevenueCat identifier. Email alone may therefore be insufficient to locate a table or an installation's records, or establish ownership. We explain the minimal information needed and use provider tools or support channels. If a record cannot be matched or a legal exception applies, we explain the limitation and available alternatives. Do not send passwords, full card numbers, raw purchase tokens or participant lists.
When CCPA deadlines apply, we acknowledge requests within 10 business days, respond within 45 days, and explain any permitted 45-day extension. Advertising opt-outs are addressed as soon as feasible and within 15 business days where required. Other applicable deadlines take precedence. To appeal, reply with Privacy request appeal; we respond under the relevant state procedure.
11. International processing
Solidsoft operates in the Republic of Korea. Google LLC processes data in the United States and may use distributed facilities and subprocessors elsewhere. Google LLC's address is 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States; contact its privacy inquiry channel.
Settlement storage and server functions are configured in Seoul, Republic of Korea. Firebase Authentication operates in the United States; other Google services and support may use distributed facilities under their applicable terms. For Google Cloud agreements with Korean customers, Google's entity guide identifies Google Cloud Korea LLC unless otherwise agreed, at Gangnam Finance Center 20fl., 152 Teheran-ro, Gangnam-gu, Seoul, and describes the role of Google Asia Pacific Pte. Ltd. and affiliates. See the contracting-entity guide.
For locations and provider scope, see Google data centers, Firebase processing locations, Firebase subprocessors and Google advertising/analytics subprocessors. These are provider-wide lists of possible facilities and recipients, not a claim that every listed recipient receives each user's data or that all information stays only in the U.S.
RevenueCat, Inc. is a U.S. provider at 1032 E Brandon Blvd #3003, Brandon, FL 33511. Contact compliance@revenuecat.com. Its DPA identifies U.S. infrastructure/operations subprocessors and support for Korean customers.
Support email: Google Workspace (Gmail) — Google Asia Pacific Pte. Ltd. / Google LLC. Processing may occur in Singapore, the United States and other countries in Google's published Workspace facilities/subprocessor lists below. Support messages are kept while needed for the request or applicable legal records, then removed through Google's recovery and system-deletion procedures.
Google's contracting-entity information identifies Google Asia Pacific Pte. Ltd. for Korean Workspace customers, at 70 Pasir Panjang Road, #03-71, Mapletree Business City II, Singapore 117371. See the Workspace subprocessor list for entities, activities and countries, and service-specific terms for the scope of data-location commitments. No single-country storage guarantee is made. The operator can escalate requests through Google's Workspace privacy support, which requires an administrator account.
Transfers occur through encrypted connections for the functions and at the times in Section 5. Optional usage analytics requires both consents and may be withdrawn in Section 3. Operational diagnostics and purchase verification are separate processes, not covered by analytics consent.
Acknowledging the service notice or consenting to optional analytics is not blanket consent for operational diagnostics, advertising or all international processing. Verified server-log retention settings follow:
The operating configuration checked on September 21, 2026 retains ordinary server logs (_Default) for 30 days and separate audit logs, including administrator activity, system events and access transparency (_Required), for 400 days. Both buckets use the global location, which does not specify a single country. No additional project log-export destination is configured. These periods are separate from the 24-hour expiry for rate-limit records and the two-month Analytics detailed-data setting.
Firebase service data is technical operating information Google collects or generates while providing its services, distinct from settlement content entrusted to the service. We have disabled optional use to improve other Google services in project settings. This does not stop processing for Firebase operations and improvement or products we directly connect.
Provider contracts differ by product: Google Cloud data processing terms cover services such as Auth, Firestore, Storage, Functions and App Check; Firebase data processing and security terms cover Crashlytics, Performance and Hosting; Ads processor terms cover Analytics; ordinary AdMob uses controller terms. RevenueCat and Workspace have separate contracts. A single provider contract does not establish the legal basis for every product or country. Google advertising SDKs directly collect advertising information under Google’s advertising privacy terms. Settly does not supply settlement content or Firebase authentication IDs for advertising. UMP operates the published regional messages; permission to request an ad is not proof of consent under every country’s law. Ads may include banner, native and, in supporting app versions, return-to-app placements.
12. Security
Settly uses the Android sandbox, limited app permissions, encrypted SDK transport, delayed external-service startup and consent-based analytics controls. Custom logs exclude settlement content. Business and provider account access is limited to operational needs. No method guarantees complete security; protect the device and accounts.
The sync service uses authentication, app verification, hard-to-guess codes, private storage, blocked direct database/file access and request limits. It is not an end-to-end encrypted service. Possessing a link is enough to access its table; it does not establish a recipient's identity. Do not publicly post links, and contact us about leaks or inappropriate sharing.
13. Changes and contact
This revision adds installation support ID correlation with renewed analytics consent and clarifies server deletion, PDF/Excel exports, conversion/allocation/expense-date data, operational logs, request procedures and multilingual notices. Revising this document does not itself expand analytics collection or grant consent. Expanded analytics continues to require the current version and both choices described in Section 3. Material changes to purposes, fields, SDKs, recipients or retention will be disclosed with any consent required by applicable law.
- Previous policy — September 21, 2026, before support ID correlation
- Previous policy — 2026-09-17
- Previous policy — September 10, 2026, with the shared category catalog
- Previous policy — September 10, 2026, before the shared category catalog
- Previous policy — September 7, 2026
- Previous policy — September 6, 2026
- Privacy officer and requests: 장효원 / Representative
- Operator: Solidsoft
- Address: 4F, Room 498, 60 Dunji-ro (Dunsan-dong), Seo-gu, Daejeon, Republic of Korea
- Contact: corp@solidsoft.team · +82-10-2615-3559
You may also contact the California Privacy Protection Agency or the relevant state attorney general/privacy regulator.