AppExpire Privacy Policy
This Privacy Policy is provided in 8 languages. For users in Korea, the Korean version is the legally controlling text. This English version is a translation provided for convenience; if it conflicts with the Korean version, the Korean version governs.
Last updated: TODO: first effective date | Effective date: TODO: first effective date
AppExpire ("the App") is made by independent developer kukuDev ("the Operator"). The App lets you pick apps you only need temporarily, set a cleanup date, and confirm the uninstall yourself through Android's own system dialog when a local reminder arrives. This Policy explains what the App processes and does not process, what the ad and analytics SDKs handle, and how purchase verification works.
Reading this Policy or installing/running the App does not by itself mean you consent to the optional processing described below (analytics/diagnostics sharing, personalized ads, cross-border transfer tied to those features). Optional processing starts only after you turn it on during onboarding or in Settings. Processing that is necessary to operate the App (e.g., local notifications, the minimal check of your free/Pro status) applies once you agree to this Policy and use the App.
1. How the core flow relates to data processing
- You choose apps installed on your device that you only need for a while, and set a cleanup date and time.
- At that time, the App shows a local notification on your device. No push server is involved.
- Opening the notification shows the cleanup list; for each app you must open and confirm Android's own system uninstall dialog for it to actually be removed.
- The App never uninstalls another app automatically without your confirmation.
- Android battery optimization (Doze), disabled notification permission, device reboot, or your own cancellation can delay or prevent the reminder. We do not guarantee second-precise delivery.
2. Information we collect and store
2.1. Stored only on your device, never sent to the Operator
The following stays only in the App's on-device storage. It is not sent to the Operator's server and is not included in analytics or ad SDK calls.
| Item | Description |
|---|---|
| Reserved app info | Package name and app label of the apps you selected |
| Schedule | The cleanup date and time you set |
| Group name | An optional label you type yourself (e.g. "end of test") |
| Onboarding progress | Whether onboarding is completed or skipped |
| Settings | Theme, language, analytics-sharing choice |
| Cached Pro status | The last-checked purchase status (free/Pro) |
| Ad frequency counter | Internal counter for interstitial spacing |
| Unsaved draft | A reservation you were typing, kept so you can resume |
This data is removed when you uninstall the App or clear its data. You can cancel individual reservations at any time. Your Pro purchase entitlement stays with your Google Play account, separate from this on-device data, and can be restored via "Restore purchase" after reinstalling. Your reservation list and group names are not restored.
2.2. Installed-app list
The App reads the list of launchable installed apps through Android's package-visibility feature, only to (1) show the app picker and (2) check whether a reserved app is still installed. The list, app names, and package names are never sent to analytics SDKs, ad SDKs, or our servers, and are never used for ad targeting.
2.3. Android permissions
| Permission | Purpose |
|---|---|
Notifications (POST_NOTIFICATIONS, Android 13+) | To show the cleanup reminder |
RECEIVE_BOOT_COMPLETED | To re-register scheduled reminders after a reboot |
REQUEST_DELETE_PACKAGES | To open Android's own uninstall-confirmation dialog. The App does not gain uninstall power itself; it invokes the system screen |
INTERNET / ACCESS_NETWORK_STATE | For ad requests, purchase status checks, and optional analytics/diagnostics when enabled |
AD_ID | Required by the Google Mobile Ads SDK; used for ad personalization, frequency capping, and fraud prevention |
3. Optional usage statistics and diagnostics (Firebase Analytics / Crashlytics)
The App may use Firebase Analytics and Firebase Crashlytics. Off by default. You can turn this on or off anytime in Settings. Turning it off stops further collection and deletes unsent crash reports.
When on, we process:
- A Firebase app instance ID (an anonymous identifier for this install)
- Device model, OS version, app version, language, and a country-level location Google derives from IP address
- A limited set of fixed-value events, e.g. onboarding step, reservation saved (count as a bucket, not the exact number), notification permission result, purchase flow state (started/succeeded/canceled/error)
- Crash/error stack traces. Exception message text is not sent.
Never sent: names or package names or lists of your reserved apps, group names, search text, exact reservation times, purchase tokens.
Advertising-ID collection by Analytics is disabled. This analytics consent is separate from the ad consent in Section 4; enabling one does not enable the other.
Firebase project region and GA4 retention period: [TODO to be confirmed; currently planned at 14 months].
4. Advertising: Google AdMob and mediation/bidding partners
Ads are shown only to free users. Pro purchasers see no ads, and no ad is requested until your free/Pro status is confirmed.
4.1. Placements
| Location | Format |
|---|---|
| Reservation list screen | One adaptive banner |
| Occasionally, after a reservation is saved, on the way back to the list | Interstitial ad. Never shown during onboarding, the first reservation, purchase, notification entry, or the uninstall flow |
Only banner and interstitial are currently used. No rewarded ads, and no feature is unlocked by watching an ad.
4.2. Participating partners and bidding
Through Google AdMob mediation/bidding, the App works with Liftoff Monetize, AppLovin, and Unity Ads. When an ad is requested, several participating companies may process data for bidding purposes, including partners that only take part in SDK initialization, the ad request, or bidding, even if they never end up showing the ad.
| Format | Participating partners |
|---|---|
| Banner | Google AdMob + Liftoff Monetize + Unity Ads |
| Interstitial | Google AdMob + Liftoff Monetize + AppLovin + Unity Ads |
4.3. Data processed
Device/app identifiers including the advertising ID, IP address and the country/region-level location derived from it, device model/OS/language/network/screen environment, app identifier/version, ad request/bid/impression/click data, and consent and anti-fraud signals may be processed. Exact items vary by partner, SDK, and your consent settings. This is unrelated to the list of apps you have reserved for cleanup; that list is never shared with ad SDKs.
4.4. Purposes
Ad delivery and selection, bidding, permitted personalized or non-personalized ads, frequency capping, performance/revenue measurement, and fraud prevention. Choosing non-personalized ads does not mean zero processing; a minimum of processing still occurs for frequency capping, fraud prevention, and measurement. This is distinct from the usage analytics in Section 3.
4.5. Per-partner data, international transfer, retention, and contact
Countries and retention periods below are as published by each partner (checked against their official policies on 2026-09-26); an individual request is not guaranteed to always route through those exact countries. The partner's current published policy may be more up to date.
| Partner | Data/purpose | Published processing/transfer countries | Retention | Contact / rights |
|---|---|---|---|---|
| Google AdMob (Google LLC) | Same as 4.3/4.4 | US and other countries where Google publishes server locations | Per Google's service-specific retention/deletion policy | Google Privacy Policy |
| Liftoff Monetize (Liftoff Mobile, Inc.; LMI, Inc.; Vungle SEA Pte. Ltd.) | Same as 4.3/4.4 | US, Singapore, Japan, Germany (primary data centers) | Per its published policy, end-user data is retained pseudonymized in the active database for 30 days, then deleted; backups are kept without a stated end date | Liftoff Privacy Policy |
| AppLovin (AppLovin Corporation) | Same as 4.3/4.4 | US (publishes reliance on EU-U.S., UK, and Swiss Data Privacy Frameworks); other regions per its policy/contact | Per its published policy, typically up to 2 years; device-linked data often shorter, or deleted on request | AppLovin Privacy Policy |
| Unity Ads (Unity Technologies S.F. and affiliates) | Same as 4.3/4.4 | US, Israel (ironSource HQ), and countries of service providers such as Google Cloud Platform | Per its published policy, install-ID-linked app interaction data up to 12 months; transaction records for billing/fraud prevention up to 180 days | Unity Privacy Policy |
These mediation SDKs and adapters are not yet integrated into the App. This section is the first-version policy that applies once integration and activation actually happen; that status is confirmed separately before launch. Processing by a new partner begins only after the required consent flow is in place.
4.6. Consent and choices
In the EEA, UK, Switzerland, and other regions where required, Google's User Messaging Platform (UMP) shows a consent form, and your choice is passed to participating partners. Whether US state-level settings are configured in AdMob: [TODO, confirm in the AdMob console].
You can change your ad consent later from "Ad privacy options" in Settings (shown where applicable), or reset the advertising ID / limit ad tracking in your device's ad settings. Declining personalized ads does not block reservations, reminders, uninstall confirmation, or any other feature of the App.
5. Pro purchase and payment verification
5.1. The product
AppExpire Pro is a non-consumable, one-time purchase through Google Play Billing (product ID appexpire_pro). The price in Korea is KRW 20,000 (including 10% VAT); other countries see the local price Google Play displays. It is not a subscription; there is no recurring charge.
Benefits: removes ads, removes the 10-app reservation limit, removes the 20-day scheduling limit.
5.2. Processing and verification
Google Play processes the payment itself; the Operator does not directly collect your card or payment-method details. To confirm a purchase is genuine, the App sends the product ID, purchase token, and a Firebase App Check token to the Operator's Firebase Cloud Functions endpoint (Google Cloud, Seoul region asia-northeast3). That endpoint queries the Google Play Developer API and returns only a valid/invalid result to the App. The verification server does not store purchase tokens in a database. Google Cloud Logging may still retain request logs (requesting IP, timestamps); retention period [TODO, Google Cloud's default is 30 days].
5.3. Restore
"Restore purchase" works when you are signed into the same Google Play account used to buy Pro, with no separate login. On-device data such as your reservation list is not part of the restore.
6. International data transfer
Servers operated by Google (Firebase, AdMob, Play, Cloud Functions/Logging), Liftoff, AppLovin, and Unity may be located outside Korea, and data described in Sections 3-5 may be transferred to them. Countries and methods, as published by each company, are listed in the table at 4.5. Reading this Policy or installing/using the App does not by itself mean you consent to cross-border transfer. Transfers tied to optional processing (analytics sharing, personalized ads) happen only after you turn on that feature or give consent in the relevant screen. To ask about or object to a transfer, contact us using Section 8's contact details.
7. Retention and deletion
- On-device data (reservations, settings, etc.) stays until you uninstall the App or clear its data; you can cancel any individual reservation at any time.
- Your Pro entitlement stays with your Google Play account, independent of uninstalling the App.
- Analytics/diagnostics retention: see the note at the end of Section 3 (TODO pending confirmation).
- Ad-partner retention: see the table in 4.5.
- Purchase-verification server request-log retention: see 5.2 (TODO pending confirmation).
8. Your rights and how to exercise them
- Delete on-device data: cancel individual reservations, uninstall the App, or clear app data - all take effect immediately.
- Withdraw analytics/diagnostics consent: turn it off anytime in Settings.
- Change ad consent: use "Ad privacy options" in Settings (where shown) or your device's ad settings.
- Access, correction, restriction, or objection to cross-border transfer: email [email protected] (TODO: confirm before launch); we will review and respond. For rights directly against an ad partner, use the policy link for that partner in Section 4.5.
- Purchase questions or refunds: see Section 9 and the Terms of Service.
There is no account, so there is no separate account-deletion procedure.
9. Minors and children's privacy
The App does not target a specific age group; target age is [TODO, to be set after the content rating questionnaire]. We do not knowingly collect personal data from children under 14. For minors' purchase cancellation, see the Terms of Service.
10. Security
On-device data lives in the App's private storage, which other apps cannot normally access. Communication with our server uses TLS/HTTPS. The purchase-verification endpoint uses Firebase App Check to help block abnormal requests. No method of transmission or storage can be guaranteed 100% secure.
11. Privacy officer and contact
- Operator: kukuDev (TODO: confirm before launch - formal business registration status/name)
- Privacy officer: TODO: name and title to be confirmed
- Contact: [email protected] (TODO: confirm before launch)
- Korean users may also contact KISA's Personal Information Infringement Report Center (privacy.kisa.or.kr) or the Personal Information Dispute Mediation Committee (www.kopico.go.kr).
12. Changes to this Policy
We may update this Policy. Material changes unfavorable to you will be announced at least 30 days before they take effect, via an in-app notice or similar, and prior versions will remain accessible. Minor changes may be announced with a shorter notice period.