AppExpire Privacy Policy

Draft - needs review before publishing. Items marked TODO below are not yet finalized.

This Privacy Policy is provided in 8 languages. For users in Korea, the Korean version is the legally controlling text. This English version is a translation provided for convenience; if it conflicts with the Korean version, the Korean version governs.

Last updated: TODO: first effective date | Effective date: TODO: first effective date

AppExpire ("the App") is made by independent developer kukuDev ("the Operator"). The App lets you pick apps you only need temporarily, set a cleanup date, and confirm the uninstall yourself through Android's own system dialog when a local reminder arrives. This Policy explains what the App processes and does not process, what the ad and analytics SDKs handle, and how purchase verification works.

Reading this Policy or installing/running the App does not by itself mean you consent to the optional processing described below (analytics/diagnostics sharing, personalized ads, cross-border transfer tied to those features). Optional processing starts only after you turn it on during onboarding or in Settings. Processing that is necessary to operate the App (e.g., local notifications, the minimal check of your free/Pro status) applies once you agree to this Policy and use the App.

1. How the core flow relates to data processing

2. Information we collect and store

2.1. Stored only on your device, never sent to the Operator

The following stays only in the App's on-device storage. It is not sent to the Operator's server and is not included in analytics or ad SDK calls.

ItemDescription
Reserved app infoPackage name and app label of the apps you selected
ScheduleThe cleanup date and time you set
Group nameAn optional label you type yourself (e.g. "end of test")
Onboarding progressWhether onboarding is completed or skipped
SettingsTheme, language, analytics-sharing choice
Cached Pro statusThe last-checked purchase status (free/Pro)
Ad frequency counterInternal counter for interstitial spacing
Unsaved draftA reservation you were typing, kept so you can resume

This data is removed when you uninstall the App or clear its data. You can cancel individual reservations at any time. Your Pro purchase entitlement stays with your Google Play account, separate from this on-device data, and can be restored via "Restore purchase" after reinstalling. Your reservation list and group names are not restored.

2.2. Installed-app list

The App reads the list of launchable installed apps through Android's package-visibility feature, only to (1) show the app picker and (2) check whether a reserved app is still installed. The list, app names, and package names are never sent to analytics SDKs, ad SDKs, or our servers, and are never used for ad targeting.

2.3. Android permissions

PermissionPurpose
Notifications (POST_NOTIFICATIONS, Android 13+)To show the cleanup reminder
RECEIVE_BOOT_COMPLETEDTo re-register scheduled reminders after a reboot
REQUEST_DELETE_PACKAGESTo open Android's own uninstall-confirmation dialog. The App does not gain uninstall power itself; it invokes the system screen
INTERNET / ACCESS_NETWORK_STATEFor ad requests, purchase status checks, and optional analytics/diagnostics when enabled
AD_IDRequired by the Google Mobile Ads SDK; used for ad personalization, frequency capping, and fraud prevention

3. Optional usage statistics and diagnostics (Firebase Analytics / Crashlytics)

The App may use Firebase Analytics and Firebase Crashlytics. Off by default. You can turn this on or off anytime in Settings. Turning it off stops further collection and deletes unsent crash reports.

When on, we process:

Never sent: names or package names or lists of your reserved apps, group names, search text, exact reservation times, purchase tokens.

Advertising-ID collection by Analytics is disabled. This analytics consent is separate from the ad consent in Section 4; enabling one does not enable the other.

Firebase project region and GA4 retention period: [TODO to be confirmed; currently planned at 14 months].

4. Advertising: Google AdMob and mediation/bidding partners

Ads are shown only to free users. Pro purchasers see no ads, and no ad is requested until your free/Pro status is confirmed.

4.1. Placements

LocationFormat
Reservation list screenOne adaptive banner
Occasionally, after a reservation is saved, on the way back to the listInterstitial ad. Never shown during onboarding, the first reservation, purchase, notification entry, or the uninstall flow

Only banner and interstitial are currently used. No rewarded ads, and no feature is unlocked by watching an ad.

4.2. Participating partners and bidding

Through Google AdMob mediation/bidding, the App works with Liftoff Monetize, AppLovin, and Unity Ads. When an ad is requested, several participating companies may process data for bidding purposes, including partners that only take part in SDK initialization, the ad request, or bidding, even if they never end up showing the ad.

FormatParticipating partners
BannerGoogle AdMob + Liftoff Monetize + Unity Ads
InterstitialGoogle AdMob + Liftoff Monetize + AppLovin + Unity Ads

4.3. Data processed

Device/app identifiers including the advertising ID, IP address and the country/region-level location derived from it, device model/OS/language/network/screen environment, app identifier/version, ad request/bid/impression/click data, and consent and anti-fraud signals may be processed. Exact items vary by partner, SDK, and your consent settings. This is unrelated to the list of apps you have reserved for cleanup; that list is never shared with ad SDKs.

4.4. Purposes

Ad delivery and selection, bidding, permitted personalized or non-personalized ads, frequency capping, performance/revenue measurement, and fraud prevention. Choosing non-personalized ads does not mean zero processing; a minimum of processing still occurs for frequency capping, fraud prevention, and measurement. This is distinct from the usage analytics in Section 3.

4.5. Per-partner data, international transfer, retention, and contact

Countries and retention periods below are as published by each partner (checked against their official policies on 2026-09-26); an individual request is not guaranteed to always route through those exact countries. The partner's current published policy may be more up to date.

PartnerData/purposePublished processing/transfer countriesRetentionContact / rights
Google AdMob (Google LLC)Same as 4.3/4.4US and other countries where Google publishes server locationsPer Google's service-specific retention/deletion policyGoogle Privacy Policy
Liftoff Monetize (Liftoff Mobile, Inc.; LMI, Inc.; Vungle SEA Pte. Ltd.)Same as 4.3/4.4US, Singapore, Japan, Germany (primary data centers)Per its published policy, end-user data is retained pseudonymized in the active database for 30 days, then deleted; backups are kept without a stated end dateLiftoff Privacy Policy
AppLovin (AppLovin Corporation)Same as 4.3/4.4US (publishes reliance on EU-U.S., UK, and Swiss Data Privacy Frameworks); other regions per its policy/contactPer its published policy, typically up to 2 years; device-linked data often shorter, or deleted on requestAppLovin Privacy Policy
Unity Ads (Unity Technologies S.F. and affiliates)Same as 4.3/4.4US, Israel (ironSource HQ), and countries of service providers such as Google Cloud PlatformPer its published policy, install-ID-linked app interaction data up to 12 months; transaction records for billing/fraud prevention up to 180 daysUnity Privacy Policy

These mediation SDKs and adapters are not yet integrated into the App. This section is the first-version policy that applies once integration and activation actually happen; that status is confirmed separately before launch. Processing by a new partner begins only after the required consent flow is in place.

4.6. Consent and choices

In the EEA, UK, Switzerland, and other regions where required, Google's User Messaging Platform (UMP) shows a consent form, and your choice is passed to participating partners. Whether US state-level settings are configured in AdMob: [TODO, confirm in the AdMob console].

You can change your ad consent later from "Ad privacy options" in Settings (shown where applicable), or reset the advertising ID / limit ad tracking in your device's ad settings. Declining personalized ads does not block reservations, reminders, uninstall confirmation, or any other feature of the App.

5. Pro purchase and payment verification

5.1. The product

AppExpire Pro is a non-consumable, one-time purchase through Google Play Billing (product ID appexpire_pro). The price in Korea is KRW 20,000 (including 10% VAT); other countries see the local price Google Play displays. It is not a subscription; there is no recurring charge.

Benefits: removes ads, removes the 10-app reservation limit, removes the 20-day scheduling limit.

5.2. Processing and verification

Google Play processes the payment itself; the Operator does not directly collect your card or payment-method details. To confirm a purchase is genuine, the App sends the product ID, purchase token, and a Firebase App Check token to the Operator's Firebase Cloud Functions endpoint (Google Cloud, Seoul region asia-northeast3). That endpoint queries the Google Play Developer API and returns only a valid/invalid result to the App. The verification server does not store purchase tokens in a database. Google Cloud Logging may still retain request logs (requesting IP, timestamps); retention period [TODO, Google Cloud's default is 30 days].

5.3. Restore

"Restore purchase" works when you are signed into the same Google Play account used to buy Pro, with no separate login. On-device data such as your reservation list is not part of the restore.

6. International data transfer

Servers operated by Google (Firebase, AdMob, Play, Cloud Functions/Logging), Liftoff, AppLovin, and Unity may be located outside Korea, and data described in Sections 3-5 may be transferred to them. Countries and methods, as published by each company, are listed in the table at 4.5. Reading this Policy or installing/using the App does not by itself mean you consent to cross-border transfer. Transfers tied to optional processing (analytics sharing, personalized ads) happen only after you turn on that feature or give consent in the relevant screen. To ask about or object to a transfer, contact us using Section 8's contact details.

7. Retention and deletion

8. Your rights and how to exercise them

There is no account, so there is no separate account-deletion procedure.

9. Minors and children's privacy

The App does not target a specific age group; target age is [TODO, to be set after the content rating questionnaire]. We do not knowingly collect personal data from children under 14. For minors' purchase cancellation, see the Terms of Service.

10. Security

On-device data lives in the App's private storage, which other apps cannot normally access. Communication with our server uses TLS/HTTPS. The purchase-verification endpoint uses Firebase App Check to help block abnormal requests. No method of transmission or storage can be guaranteed 100% secure.

11. Privacy officer and contact

12. Changes to this Policy

We may update this Policy. Material changes unfavorable to you will be announced at least 30 days before they take effect, via an in-app notice or similar, and prior versions will remain accessible. Minor changes may be announced with a shorter notice period.