Effective date: May 30, 2026 · Last revised: September 16, 2026
This Privacy Policy explains how the mobile app “Jann” (잔) (the “Service”) collects, uses, entrusts, and retains users’ personal information. It is an English translation of the Korean version, which prevails if the two differ.
Summary
Your fridge ingredient list, expiry dates, saved recipes, and ingredient photos are stored only on your device.
AI features work only if you agree to “Use AI features”; when you use them, ingredient names and photos are sent to OpenAI.
Usage statistics (Firebase Analytics) are collected only if you agree to “Send usage statistics”.
We serve only non-personalized ads and do not track you across apps.
1. Personal Information We Collect
a. Required (when you sign in): email address, user name, profile photo URL, authentication identifier (provided by Apple/Google/Kakao)
If you use the app via “Browse without signing in”, none of this is collected.
b. Collected automatically (always): device information, crash logs, and device information needed to display ads (only non-personalized ads are served, and there is no cross-app tracking)
c. Collected automatically (only with consent): screen and feature usage events, anonymous app instance identifier — collected only if you agree to “Send usage statistics”.
d. User input: ingredient names, photos (camera/photo library)
Information stored only on your device
Your fridge ingredient list (name, expiry date, category), saved recipes, ingredient photos, and AI usage counts are stored only on your device and are not sent to the operator’s servers, whether or not you are signed in.
Receipt recognition, expiry-date text recognition, and basic ingredient recognition run on your device (Apple Vision and Core ML); photos do not leave your device during this processing.
2. Purposes of Collection and Use
a. Identifying members and keeping you signed in
b. Providing AI-based ingredient recognition and recipe recommendations
c. Managing free AI usage (monthly counts) — currently 15 AI recipe generations and 30 AI photo recognitions per month are free; usage counts are stored on your device.
d. Service improvement and statistical analysis — only if you agree to “Send usage statistics”.
e. Diagnosing app errors and improving stability
f. Displaying ads
g. Expiry reminders and weekly summary notifications — these are local notifications scheduled on your device; no push server is used. You can turn them off at any time in iOS Settings.
3. Third-Party Provision and Entrusted Processing
We do not sell personal information. The Service entrusts the processing of personal information to the following third parties.
a. OpenAI (United States)
Data: images you capture or select, ingredient names
Purpose: GPT-4o-based ingredient recognition and recipe generation
When sent: when you generate an AI recipe (ingredient names), and when on-device recognition finds no ingredients and AI photo recognition is used (photo)
Retention: kept for up to 30 days under OpenAI’s API policy, then deleted automatically; not used for model training.
Legal basis: your consent (Me → Settings “Use AI features”) — all basic features remain available without it.
b. Firebase Authentication (Google LLC, United States)
Data: authentication identifier, email
Purpose: sign-in authentication and session management
Legal basis: performance of contract (required to provide member services)
c. Firebase Crashlytics (Google LLC, United States)
Data: crash and error logs, device/OS/app version information (no personal information such as photos or ingredient names)
Purpose: diagnosing app errors and improving stability
Legal basis: performance of the service contract (the minimum information needed to fix errors and keep the app stable) — names, emails, photos, and ingredient names are not included.
d. Firebase Analytics (Google LLC, United States)
Data: screen and feature usage events (e.g., adding an ingredient, opening a recipe), device and app version, anonymous app instance identifier (no photos, ingredient names, or personal information)
Purpose: analyzing and improving how the Service is used
Retention: per the Google Analytics data retention setting
Legal basis: your consent (Me → Settings “Send usage statistics”) — nothing is collected without consent, and you can turn it off at any time in Me → Settings even after agreeing.
e. Cloudflare (United States)
Data: data passed through temporarily when OpenAI is called
Purpose: API proxy and security relay (not stored)
f. Kakao (Republic of Korea)
Data: Kakao login identifier
Purpose: Kakao account authentication
g. Google AdMob (Google LLC, United States)
Data: device and app information needed for ad requests
Purpose: displaying in-app banner and interstitial ads
Only non-personalized ads are requested. We do not request App Tracking Transparency (ATT) permission and do not use the advertising identifier (IDFA) for cross-app tracking. Where consent is legally required (e.g., the EU), Google’s consent screen is shown.
h. Firebase App Check (Google LLC, United States)
Data: app and device integrity tokens (based on Apple DeviceCheck/App Attest; no personal information)
Purpose: confirming that AI requests come from the genuine app, to prevent abuse
External shopping links
When you tap a Coupang or Kurly search link for a missing ingredient, that external site (or app) opens with the ingredient name as the search term. Any further processing is governed by that site’s privacy policy.
4. Retention and Destruction
a. When you delete your account, all personal information is destroyed immediately. Your sign-in account is deleted (for Kakao, the connection is unlinked), and the fridge ingredients, saved recipes, photos, consent settings, and AI usage counts stored on your device are deleted as well.
b. However, information that must be kept under applicable law is kept for the required period and then destroyed.
c. Signing out also deletes the fridge ingredients, saved recipes, photos, AI consent setting, and AI usage counts stored on your device.
d. Data created via “Browse without signing in” exists only on your device and is deleted when you delete the app. The operator does not back up on-device data.
e. Information held by entrusted processors follows each processor’s retention period described in Section 3.
5. Your Rights
a. You may access, correct, or delete your personal information at any time.
b. You can delete your account immediately in the Me tab → Delete account.
c. You can turn AI feature consent and usage statistics consent on or off independently at any time in Me → Settings.
d. For any other request, email the privacy officer below and we will handle it without delay. Depending on where you live (e.g., the EU/UK or California), you may have additional rights under local law, which you can exercise through the same email.
6. Security Measures
a. Authentication tokens are stored in a secure system area.
b. All external communication is encrypted with HTTPS.
c. Account information such as email or name is not sent with AI requests.
7. Children Under 14
The Service does not collect personal information from children under 14.