Legal & trust
Money Luck Privacy Policy
Summary
This Privacy Policy explains how Jaeyoung Kim, operating as Kkum ("we," "us," or "our"), handles information in connection with the Money Luck iPhone application (the "App") and the Money Luck pages of our website (together, the "Service").
Money Luck is an entertainment and personal-reflection app. It does not provide financial or other professional advice and does not predict financial outcomes.
- Money Luck does not require a Money Luck account in this version.
- The App stores its state locally. A limited copy of the derived profile, assigned calendar, and reveal history synchronizes through the user's private CloudKit database when iCloud is available.
- Date of birth and calibration answers are used on-device to create derived profile values; the raw birth date and raw answers are removed from the App's saved profile after creation.
- The App sends limited product-usage events to PostHog using an SDK-generated identifier. Superwall receives a persistent Money Luck profile identifier, device information, subscription information, and paywall activity to provide subscription screens, manage access, and measure their use. We do not intentionally send names, birth dates, answer text, derived profile vectors, or fortune text to either provider.
- Apple processes purchases and subscription management.
- The App has no advertising, bank connection, brokerage connection, or custom personal-data backend. Private CloudKit is used only for app-data restoration and cross-device reconciliation.
Delete Profile & Calendarremoves Money Luck's local and private CloudKit profile data and resets PostHog and Superwall identifiers on the device. This does not automatically delete records already sent to those providers or cancel a subscription managed by Apple.
Information handled by the App
A. Information you provide
The App may ask for:
- an optional display name;
- date of birth;
- answers to calibration questions;
- a selected reflection intention;
- a preferred reminder time; and
- settings choices, such as notifications, reduced-motion behavior, and share card style.
The App uses date of birth and calibration answers on-device to create derived values used for the Money Luck experience. After profile creation, the saved profile retains a one-way birth-derived seed and an answer-derived profile vector rather than the raw birth date and raw answer text.
B. Information created and stored locally
The App stores or may store on the device:
- a randomly generated private profile identifier in the iOS Keychain;
- optional display name;
- birth-derived seed and answer-derived profile values;
- home time-zone identifier and locale;
- preferred reminder time and App settings;
- a dated calendar of candidate fortune-line identifiers;
- reveal status, revealed line identifiers, timestamps, and history;
- local time-integrity observations used to preserve one reveal per home day;
- subscription product, entitlement, transaction, trial, renewal, and expiration metadata received from StoreKit;
- a bounded queue of analytics event names, approved categorical properties, event identifiers, and timestamps awaiting delivery; and
- signed remote-configuration cache data if remote configuration is enabled in a future production configuration.
The main App-state and analytics-queue files use iOS complete file protection. The private profile identifier is stored in the Keychain with a device-restricted accessibility class.
C. Private iCloud synchronization
When the user is signed in to iCloud, the App stores a restoration record in the user's private CloudKit database. That record can contain the optional display name, birth-derived seed, answer-derived profile values, selected intention, home time zone and locale, assigned candidate-line identifiers, reveal identifiers and timestamps, and local time-integrity observations.
The CloudKit record does not include the raw birth date, raw calibration answers, StoreKit transaction or entitlement data, notification authorization or schedule, reduced-motion setting, or share-card preference. Apple operates CloudKit and handles that data under Apple's terms and privacy disclosures. Offline changes remain local until synchronization succeeds, so another device may temporarily show older state.
D. Purchases and subscriptions
Purchases are processed by Apple through the App Store. The App receives transaction and entitlement information needed to unlock access, restore purchases, determine trial/renewal state, and show subscription status. We do not receive your full payment-card details.
Apple handles information under its own privacy terms. Subscription management and refund decisions are handled through Apple unless applicable law requires otherwise.
E. Notifications
If you grant notification permission, the App schedules a daily reminder at the time you choose and may schedule a reminder before an annual introductory trial renews. These are local iOS notifications in the current implementation. You can disable them in the App or iOS Settings.
F. Share cards
If you choose to create a share card, the App renders an image containing the fortune line, date, Money Luck branding, and—if you choose—your display name. The App presents the iOS share sheet. The destination service you select handles the shared image under its own terms and privacy policy.
Analytics and technical information
A. PostHog product analytics
Money Luck uses PostHog to understand product flow and reliability. The current production configuration:
- sends only explicitly coded events relating to onboarding, subscription interactions, daily reveals, sharing outcome category, notifications, archive use, review prompts, and deletion;
- disables automatic application-lifecycle capture, screen capture, element capture, rage-click capture, session replay, surveys, feature-flag preload and exposure events, method swizzling, and identified person profiles;
- uses an SDK-generated analytics identifier rather than the private Money Luck profile identifier; and
- filters event properties through an explicit allowlist.
PostHog analytics fields can include:
- event name and event time;
- random event identifier;
- SDK-generated identifier;
- limited categorical properties such as question number, selected intention category, plan identifier, eligibility boolean, source screen, engine/content version, share outcome/channel category, or notification source; and
- technical metadata added by the SDK or network service, which may include App version, SDK version, device/operating-system information, locale, network/IP information, and coarse location inferred by the provider from an IP address.
Money Luck's App code intentionally excludes the following from PostHog analytics:
- name;
- birth date;
- answer or choice text;
- derived profile vectors and seeds;
- fortune text;
- private Money Luck profile identifier;
- precise reminder time; and
- StoreKit transaction identifiers.
Analytics is hosted in PostHog's United States region in the current release configuration. Analytics is retained for up to 2,555 days (seven years) under the current production PostHog Product Analytics entitlement. This period may be shortened if the project configuration or service plan changes.
PostHog acts as a service provider/processor for us. Learn more from PostHog's privacy information.
B. Superwall subscription screens and analytics
Money Luck uses Superwall to deliver subscription screens, associate subscription access with an app profile, and understand paywall performance. Before a profile is created, Superwall uses its own generated identifier. Once a profile exists, the App sends its random, persistent Keychain profile UUID to Superwall, which associates it with its SDK identifier. These are pseudonymous identifiers: associated records can be linked to the same app profile or device even though we do not send a name or email address.
The information sent to Superwall can include the profile UUID and SDK aliases; device/vendor identifiers; app and SDK versions; device model, operating system, locale, and network information; approximate city, region, or country inferred from the IP address; paywall views, placement events, button interactions, and timestamps; and purchase, trial, plan, and subscription-access information. App-defined attributes are limited to whether a profile exists, the plan identifier, and whether subscription access is active.
Names, birth dates, calibration answer text, derived profile vectors and seeds, fortune content, and precise reminder times are not intentionally sent to Superwall. The current paywall does not ask for contact or payment-card details. Apple processes App Store payments. Superwall events are not forwarded to PostHog by the current integration.
We use these records for app functionality and analytics. We do not use this integration for cross-company targeted advertising, advertising measurement, or sharing with data brokers. Superwall acts as our service provider/processor.
Learn more from Superwall’s privacy policy and data-processing terms.
Website information
The Money Luck landing, Privacy, Terms, and Support pages are static pages hosted by Vercel. The current Kkum website does not add analytics scripts, advertising trackers, email-capture forms, or application cookies. Vercel may process request information such as IP address, browser and device metadata, requested URL, timestamps, and security or diagnostic logs to deliver and protect the website under Vercel's Privacy Policy.
If Kkum later adds website analytics, cookies, forms, or another provider, this Policy will be updated before those practices are introduced on the Money Luck pages.
How we use information
We use information to:
- create and maintain the private Money Luck experience;
- shape a safe eligible pool, select the final line at reveal, and preserve one revealed result per eligible home day;
- restore the derived profile, calendar, and revealed history through private iCloud and reconcile compatible cross-device changes;
- remember device-local settings;
- verify subscription access and restore purchases;
- schedule reminders you request;
- produce share cards you request;
- understand aggregate onboarding, subscription, and product-use patterns;
- diagnose failures, prevent abuse, and protect service integrity;
- respond to support, privacy, and accessibility requests; and
- comply with legal obligations.
We do not use Money Luck information to provide investment, credit, insurance, employment, housing, debt, tax, legal, or gambling decisions.
Sharing and service providers
We do not sell personal information. We do not use Money Luck onboarding data for targeted advertising.
Information may be handled by:
- Apple, for App distribution, StoreKit purchases, subscriptions, refunds, review prompts, private CloudKit synchronization, and operating-system services;
- PostHog, for limited product analytics;
- Superwall, for subscription screens, access-related functionality, and paywall analytics linked to app/profile and device identifiers;
- website hosting and infrastructure providers, as documented by the developer website's final production privacy disclosures;
- professional advisers under confidentiality obligations; and
- authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or complete a business transaction subject to appropriate safeguards.
Retention
- Local App data remains on the device until you use
Delete Profile & Calendar, the operating system removes it, or the App is uninstalled. - The private CloudKit restoration record remains until
Delete Profile & Calendarremoves it or the user removes it through Apple's iCloud controls. If iCloud is unavailable during in-App deletion, the App retains a deletion marker and retries without restoring the cloud record. - A Keychain item may not be removed merely by uninstalling the App. Use the in-App deletion control before uninstalling if you want the private profile identifier removed.
- Raw date of birth and calibration answers are removed from the saved App state after profile creation and are never included in the CloudKit record; derived values remain until local and CloudKit deletion.
- The analytics delivery queue is bounded to 500 events and drops events after repeated delivery failure. Successfully sent analytics follow the verified production PostHog retention period stated above.
- Superwall server records follow our service agreement and its data-processing terms, separately from the PostHog retention period above. The App's identity reset does not request server-side deletion. On termination of the service, we can request return or deletion under those terms, subject to backup/archival practices and applicable retention obligations. Contact privacy@kkumapps.com to request deletion of provider-held records associated with your use of Money Luck.
- Apple retains purchase and subscription information under Apple's policies.
- We may retain records required for legal, fraud-prevention, security, or dispute purposes for the period reasonably necessary.
Your choices and rights
You can:
- decline the optional name;
- decline or disable notifications;
- use
Delete Profile & Calendarin Settings to remove the local profile, assigned calendar, settings, reveal history, analytics queue, Keychain profile identifier, and private CloudKit restoration record, and reset PostHog and Superwall identifiers on the device; - manage or cancel subscriptions through Apple's subscription settings; and
- contact us about privacy rights available in your jurisdiction.
Deleting the Money Luck profile does not cancel the Apple subscription. To manage the subscription, use Apple's subscription settings.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to appeal or complain to a data-protection authority. The App's deletion control resets local provider identities but does not automatically erase historical records already received by PostHog or Superwall. Contact us for provider-held data requests. We assess requests, verify the relevant identifiers where possible, and work with the provider to fulfill applicable requests. Because Money Luck has no sign-in account and private CloudKit records are controlled by your Apple Account, we may need additional information to locate records and will explain any limitations.
Send privacy requests to privacy@kkumapps.com.
International processing
Service providers may process information outside your country, including in the United States. Where required, we use legally recognized safeguards for cross-border transfers and require providers to protect information consistent with applicable law.
Security
We use safeguards designed for the nature of the information, including local iOS data protection, Keychain storage for the private profile identifier, Apple private-database access controls for CloudKit restoration data, HTTPS for configured network services, limited analytics fields, bounded local queues, and deletion controls. No storage or transmission method is completely secure, and we cannot guarantee absolute security.
Children
Money Luck is designed for adults aged 18 and older. We do not knowingly collect personal information from children through the Service. If you believe a child has provided information, contact privacy@kkumapps.com.
Changes to this Policy
We may update this Policy to reflect changes to the App, website, providers, or law. We will update the date above and provide additional notice when required.
Contact
Jaeyoung Kim
Doing business as Kkum
103-103, 148 Edu city-ro, Seogwipo-si, Jeju-do 63644, Republic of Korea
Privacy: privacy@kkumapps.com
Support: support@kkumapps.com