Privacy Policy

'TickKit' (the "Service") values the personal information of its users and complies with the Personal Information Protection Act of Korea (「개인정보 보호법」) and other applicable laws and regulations. This Privacy Policy explains how the personal information you provide is used, for what purposes and by what means, and what measures are taken to protect it.

Article 1 (Items of Personal Information Collected and Methods of Collection)

The Service collects the following personal information for purposes of account registration, customer support, and the provision of the Service.

CategoryItems CollectedMethod of Collection
Account registration (required)Social account identifier (Apple ID or Google account), email address, social account name (initial display name), device language settingCollected upon Apple/Google social sign-in
Profile (optional)Profile photo (an image taken with the camera or selected from the photo library)Registered directly by the user
Child profileChild's display name, role designation, and (optionally) the child's profile photoEntered and registered directly by the parent (legal guardian)
To-do and reward icons (optional)Images used as to-do and reward icons (taken with the camera or selected from the photo library)Registered directly by the parent
In the course of using the Service (automatic)To-do and reward usage records (to-do content, completion records, coin earning/spending history, reward request history), push notification token (FCM), device type, last access date, app usage events (screen views, feature usage, etc.) and user identifiers, error (crash) logs, access logsAutomatically generated and collected in the course of using the Service
Upon paid subscriptionPayment event information such as subscription product, payment amount and currency, and store transaction identifierCollected upon payment through the store (Apple/Google)
Upon customer inquirySender's email address, inquiry content, user identifier, app version, device model, and OS version (automatically included in the body of the inquiry email)When the user sends an inquiry email
When visiting the website (tickkit.app)Cookies, access records, and other web usage recordsAutomatically collected via Google Analytics
  1. The Service does not collect date of birth, gender, or phone number, and does not collect payment instrument information such as credit card numbers (payments are processed by the Apple and Google stores).
  2. Profile photos and to-do/reward icon images registered by users are stored in the Service's storage in a manner that is accessible to anyone who knows the unique link (URL). Registering images is entirely optional.

Article 2 (Purposes of Collection and Use of Personal Information)

The Service uses the collected personal information for the following purposes.

  1. Member management: Identifying users, confirming intent to register, connecting family members (invitation codes), preventing fraudulent use, and confirming intent to withdraw membership
  2. Provision of the Service: Providing to-do, reward, and coin management features; sending push notifications (notifications such as to-do completions, reminders, and weekly reports may include the child's display name); integrating subscription payments and verifying subscription status
  3. Service improvement: Analyzing app usage statistics, diagnosing errors (crashes), and improving quality
  4. Customer support: Receiving and handling inquiries and communicating the results
  5. The Service does not serve personalized advertising and does not process personal information for advertising purposes.

Article 3 (Retention and Use Period of Personal Information)

  1. As a rule, when a user requests to withdraw membership or withdraws consent to the collection and use of personal information, the Service destroys that user's personal information without delay.
  2. However, where retention is required under applicable laws and regulations, the Service retains personal information for the periods prescribed by law, as follows.
    • Records concerning contracts or withdrawal of offers: 5 years (Act on the Consumer Protection in Electronic Commerce of Korea)
    • Records concerning payments and the supply of goods, etc.: 5 years (Act on the Consumer Protection in Electronic Commerce of Korea)
    • Records concerning consumer complaints or dispute resolution: 3 years (Act on the Consumer Protection in Electronic Commerce of Korea)
    • Service access records (logs): Retained in accordance with the retention settings of the infrastructure processor and then destroyed
  3. Data processed by processors (Article 6), such as app usage statistics and error logs, is retained and then destroyed in accordance with each processor's retention settings and privacy policy.

Article 4 (Procedures and Methods for Destruction of Personal Information)

  1. Procedures upon membership withdrawal:
    • Immediately upon withdrawal, identifying information such as the account's email address is anonymized in an irreversible manner, the social sign-in link is deleted, and the account is permanently blocked from signing in again.
    • When a family owner (parent) account withdraws, the family's data (member profiles, to-dos, completion records, push notification tokens, etc.) is deleted. When a child account withdraws, that child's profile is deleted.
    • When a parent deletes a child profile within the app, related data such as that child's to-do completion records, coin history, and reward request history is deleted together with the profile.
    • Information falling under Article 3, Paragraph 2 (such as payment records) is retained in a form with restricted access for the statutory period and then destroyed.
    • Certain system operation records, such as notification delivery logs, may take some time to be destroyed for technical reasons, and image files in storage are destroyed upon the user's deletion request (using the method set out in Article 10).
  2. Method of destruction: Personal information stored in electronic file format is permanently deleted using technical methods that render the records unrecoverable.

Article 5 (Provision of Personal Information to Third Parties)

  1. As a rule, the Service does not provide users' personal information to external parties.
  2. However, when in-app payments are made through the Apple and Google platforms, payment-related information may be provided to the respective store platforms (Apple Inc. and Google LLC) for payment processing.
  3. Exceptions also apply where required by law, or where a request is made by a law enforcement agency for investigative purposes in accordance with the procedures and methods prescribed by law.

Article 6 (Outsourcing of Personal Information Processing)

To provide the Service smoothly, the Service outsources personal information processing tasks as set forth below, and when entering into outsourcing agreements, stipulates the matters necessary to ensure that personal information is managed securely.

ProcessorOutsourced TaskItems Processed
Supabase, Inc.Operation of database, member authentication, and file storage infrastructureMember information (email address, social account identifier), profile (display name, profile photo), to-do/reward icon images, to-do/reward/coin usage records, push notification tokens, payment event records
Google LLC (Firebase)Push notification delivery (FCM), error collection and analysis (Crashlytics), app usage statistics (Analytics)Push notification tokens and notification content, error (crash) logs, app usage events and user identifiers
Google LLC (Google Analytics)Website visit statistics analysisCookies, web usage records
RevenueCat, Inc.Subscription payment management and subscription status verificationUser identifier (limited to the purchasing account), subscription and payment event information
Zoho CorporationReceipt and storage of customer inquiry emailsSender's email address, inquiry content, and information included in the email body
Slack Technologies, LLCInternal operational notifications regarding subscription statusSubscription event information (event type, plan, amount, currency, store), de-identified user reference value (truncated identifier)

Article 7 (Cross-Border Transfer of Personal Information)

To operate the infrastructure essential to providing the Service, the Service transfers (stores and processes) personal information overseas as set forth below. Transfers occur on an ongoing basis via information and communications networks at the time the Service is used.

Recipient (Contact)Country of TransferItems TransferredPurpose of TransferRetention and Use Period
Supabase, Inc. (supabase.com/privacy)Australia (Sydney region)All Supabase processing items listed in Article 6Operation of database, authentication, and storage infrastructureUntil membership withdrawal or termination of the outsourcing agreement
Google LLC (policies.google.com/privacy)United StatesPush notification tokens and notification content, error logs, app usage events, web cookies and usage recordsPush delivery, error analysis, usage statisticsUntil the outsourced purpose is fulfilled or per Google's retention settings
RevenueCat, Inc. (revenuecat.com/privacy)United StatesUser identifier, subscription and payment eventsSubscription payment managementUntil membership withdrawal or termination of the outsourcing agreement
Zoho Corporation (zoho.com/privacy.html)United States and other countriesInquiry emails and information contained thereinReceipt and handling of customer inquiriesUntil the inquiry is resolved and any statutory retention period expires
Slack Technologies, LLC (slack.com/trust/privacy/privacy-policy)United StatesSubscription event information, de-identified user reference valueOperational notifications regarding subscription statusUntil the outsourced purpose is fulfilled

Users who do not wish their personal information to be transferred overseas may refuse the transfer by withdrawing their membership; however, in that case, use of the Service will not be possible.

Article 8 (Processing of Children's Personal Information)

The Service is a family service used by parents (legal guardians) together with their children, and processes children's personal information in accordance with the following principles.

  1. Child profiles are created and managed directly by the parent (legal guardian). Creating a child profile uses only the display name entered by the parent (and, optionally, a profile photo); the child's own email address or social account information is not requested.
  2. Even when a child uses the Service on a separate device, the child can be connected to the family only through an invitation code issued by the parent, and a sign-in account may be created in this process for the purpose of linking the device.
  3. Personal information of children under the age of 14 (display name, profile photo, to-do completion records, coin history, etc.) is processed on the basis of consent given by the parent, as legal guardian, through the act of creating the profile or issuing the invitation.
  4. Parents may view, correct, and delete child profiles and related data at any time within the app, and rights concerning a child may be exercised by the legal guardian using the method set out in Article 10.

Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

  1. Website (tickkit.app): The Service uses Google Analytics to analyze visit statistics, and in this process cookies may be stored in the user's browser. Users may opt out by the following methods.
    • Blocking or deleting cookies in the browser settings (e.g., Chrome — Settings > Privacy and security > Cookies)
    • Installing the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout)
  2. App: The Service collects app usage events via Firebase Analytics to improve the Service. On Android devices, the advertising ID (ADID) may be collected in accordance with the default behavior of the analytics tool, and users can control this in their device settings.
    • Android: Settings > Privacy > Ads > "Delete advertising ID" or reset
  3. The Service does not collect the iOS advertising identifier (IDFA) and does not engage in tracking subject to App Tracking Transparency (ATT).

Article 10 (Rights and Obligations of Users and Legal Guardians, and How to Exercise Them)

  1. Users may at any time request access to, correction of, deletion of, or suspension of the processing of their personal information (or, in the case of a child profile, their child's personal information, in their capacity as legal guardian).
  2. Rights may be exercised through the in-app settings menu (edit profile, manage members, withdraw membership) or by email (support@tickkit.app), and the Service will take action without delay within the periods prescribed by applicable laws and regulations.
  3. If a user requests the correction of an error in their personal information, the Service will not use or provide that personal information until the correction has been completed.
  4. Rights may also be exercised through the user's legal guardian or an authorized agent. In such cases, a power of attorney as required by applicable laws and regulations must be submitted.

Article 11 (Technical and Administrative Safeguards for Personal Information)

In handling personal information, the Service implements the following technical and administrative measures to ensure security and to prevent loss, theft, leakage, alteration, or damage.

  1. Protection of data in transit through encrypted communications (HTTPS)
  2. Database access controls that block access to data by anyone other than family members
  3. Encrypted storage of authentication information such as passwords

Article 12 (Privacy Officer and Remedies for Infringement of Rights)

  1. To protect users' personal information and handle related complaints, the Service has designated a responsible officer as follows.
  • Business name: Appskit (앱스키트)
  • Privacy Officer (Chief Privacy Officer): Young-Hee Jang (CEO)
  • Email: support@tickkit.app
  • Receipt and handling of requests for access to personal information: Same as the Privacy Officer
  1. Users who need to report or seek counseling regarding a personal information infringement may contact the following organizations (Korean supervisory and law enforcement authorities).
    • Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회): 1833-6972 (no area code, within Korea) / www.kopico.go.kr
    • Personal Information Infringement Report Center (개인정보침해신고센터, operated by KISA): 118 (no area code, within Korea) / privacy.kisa.or.kr
    • Supreme Prosecutors' Office of Korea (대검찰청): 1301 (no area code, within Korea) / www.spo.go.kr
    • Korean National Police Agency (경찰청): 182 (no area code, within Korea) / ecrm.police.go.kr

Article 13 (Changes to this Privacy Policy)

If the contents of this Privacy Policy are added to, deleted, or amended, notice will be given through in-Service announcements or the website at least 7 days before the effective date (or at least 30 days in the case of significant changes affecting users' rights).

(Initial Effective Date: February 1, 2026)

Date of Announcement: July 22, 2026
Effective Date: July 29, 2026