Privacy Policy
Kifu: Trading Journal
Last updated: 2026-08-17
한국어
Kifu is built local-first: your trading data stays on your device
and is never sent to our servers. The only exceptions are optional
features that you switch on and point at a destination you
choose (see "Optional features" below). None of them are on by default.
Your trading data
- Imported trade history (CSV/XLSX files or exchange API fills), review
notes, trading plans, playbook, tags, attached chart photos, and
statistics are stored only on your device, in a local
database and local files.
- There are no accounts and no login. We do not operate a
server that receives your trading data.
- Deleting the app, or using Settings → Delete all data,
permanently removes everything stored by the app on that device.
What the app sends over the network (always)
Kifu makes a small number of outbound requests, none of which include your
trading data or any personal identifiers we control:
- Market chart data. To draw candlestick charts, the app
requests public price data (symbol and timeframe only) from public
exchange APIs (e.g. OKX, Upbit, Binance).
- Parser definitions. The app periodically fetches
updated CSV-format definitions from our GitHub repository so new
exchange formats work without an app update. No data about you is
sent.
Optional features (off by default — you decide)
Each feature below is disabled until you set it up. When enabled, data goes
directly from your device to the destination you configured
— it does not pass through, and is not stored on, any server operated by
us.
Exchange API connection (read-only)
- You may connect a read-only API key for a supported
exchange (Binance, Bybit, OKX) so the app can download your own fills
instead of a CSV export.
- The API key, secret, and passphrase are stored only in your
device's secure storage (Android Keystore / iOS Keychain). They
are never written to the app database, backups, sync files, or logs, and
are never sent to us.
- Requests go directly from your device to the exchange's
servers. We do not proxy, see, or store them. The exchange's
own privacy policy governs how it handles those requests.
- Disconnecting deletes the stored key from the device.
Sync between your devices (self-hosted)
- If you want the same data on more than one device, you can enter the
address and credentials of a WebDAV server that you own or
control. Kifu then uploads an encrypted-in-transit (HTTPS, if
your server uses it) backup file and attached photos to that server and
merges them back on your other devices.
- We do not operate a sync server and do not receive any
of this data. If the server field is empty (the default), the feature is
completely inactive.
- The sync credentials you enter are stored on the device. The optional
"settings code" you can copy to move the configuration to another device
contains those credentials — treat it like a password.
AI review partner (bring your own key)
- You may enter your own API key for an AI provider you
choose (Anthropic, or any OpenAI-compatible endpoint). The key is stored
only in your device's secure storage and is never sent
to us.
- Nothing is sent to an AI provider automatically. Only when you
press the send button does the app transmit a weekly
summary consisting of aggregate statistics (e.g. trade counts,
win rate, net P&L for the period, adherence rate, R distribution) and
the review texts you wrote (mistakes, "next time", daily
summaries). Symbols, prices, timestamps, and individual fills
are not included.
- The exact payload is shown to you in full before
sending, and the request goes directly from your device
to the provider you selected. We do not see, relay, or store the
request or the response. The provider's privacy policy and terms govern
how it handles the data.
- The AI response is stored locally on your device with your other review
data.
Chart photo attachments
- Photos you attach to a trade are copied into the app's local storage on
the device. Kifu never uploads them, except to your own sync server if
you set one up (above). Photo-library access is used only to let you
pick an image.
Advertising (free tier only)
The free tier shows ads served by Google AdMob. AdMob may
collect device identifiers (such as the advertising ID), IP address, and
coarse usage information to serve and measure ads, as described in
Google's Privacy Policy and
how Google
uses information from partner apps. Subscribing to Pro removes all
advertising.
Purchases
Subscriptions are processed by Google Play Billing
(Android) or Apple In-App Purchase (iOS). To validate
purchases and restore subscriptions across reinstalls, we use
RevenueCat, which receives a random app-generated user ID and
purchase receipt data (never your name, email, or payment details — the app
stores do not share those with us). See the
RevenueCat Privacy Policy.
Children
Kifu is a finance utility intended for adults and is not directed at
children.
Changes
If this policy changes, the updated version will be posted at this URL with
a new date.
Contact
Questions: garage96@gmail.com
개인정보처리방침
Kifu: 매매일지·복기
시행일: 2026-08-17
English
Kifu는 로컬 우선으로 만들어졌습니다. 매매 데이터는 기기 안에만
있으며 당사 서버로 전송하지 않습니다. 예외는 사용자가 직접
켜고, 사용자가 직접 지정한 목적지로만 보내는 선택 기능뿐입니다(아래
"선택 기능" 참고). 어떤 것도 기본으로 켜져 있지 않습니다.
매매 데이터
- 가져온 체결 내역(CSV/XLSX 파일 또는 거래소 API 체결), 복기 노트, 매매
계획, 플레이북, 태그, 첨부한 차트 사진, 통계는 기기 안의 로컬
데이터베이스와 로컬 파일에만 저장됩니다.
- 계정도 로그인도 없습니다. 당사는 매매 데이터를 수신하는
서버를 운영하지 않습니다.
- 앱을 삭제하거나 설정 → 모든 데이터 삭제를 실행하면 해당
기기에 앱이 저장한 모든 것이 영구 삭제됩니다.
앱이 항상 네트워크로 보내는 것
Kifu는 소수의 외부 요청만 보내며, 어느 것에도 매매 데이터나 당사가 관리하는
개인 식별자는 포함되지 않습니다.
- 시세 차트 데이터. 캔들차트를 그리기 위해 공개 거래소
API(OKX·업비트·바이낸스 등)에 공개 시세(심볼·시간 단위만)를 요청합니다.
- 파서 정의. 새 거래소 양식을 앱 업데이트 없이 지원하기
위해 당사 GitHub 저장소에서 CSV 형식 정의를 주기적으로 받아옵니다.
사용자에 관한 데이터는 보내지 않습니다.
선택 기능 (기본 꺼짐 — 사용자가 결정)
아래 기능은 사용자가 설정하기 전까지 비활성입니다. 켜면 데이터는
기기에서 사용자가 지정한 목적지로 직접 갑니다 — 당사가
운영하는 서버를 경유하거나 거기에 저장되지 않습니다.
거래소 API 연결(읽기 전용)
- 지원 거래소(바이낸스·바이빗·OKX)의 읽기 전용 API 키를
연결하면 CSV 대신 본인의 체결을 앱이 직접 내려받습니다.
- API 키·시크릿·패스프레이즈는 기기의 보안 저장소(Android Keystore /
iOS Keychain)에만 저장됩니다. 앱 데이터베이스·백업·동기화
파일·로그에 기록되지 않으며 당사로 전송되지 않습니다.
- 요청은 기기에서 거래소 서버로 직접 갑니다. 당사는
중계·열람·저장하지 않습니다. 해당 요청의 처리는 거래소의
개인정보처리방침을 따릅니다.
- 연결을 해제하면 저장된 키가 기기에서 삭제됩니다.
기기 간 동기화(자체 서버)
- 여러 기기에서 같은 데이터를 쓰고 싶으면 사용자가 소유·관리하는
WebDAV 서버의 주소와 인증정보를 입력할 수 있습니다. Kifu는 백업
파일과 첨부 사진을 그 서버에 올리고 다른 기기에서 병합합니다(서버가
HTTPS를 쓰면 전송 구간 암호화).
- 당사는 동기화 서버를 운영하지 않으며 이 데이터를 받지
않습니다. 서버 주소가 비어 있으면(기본값) 기능 전체가 비활성입니다.
- 입력한 동기화 인증정보는 기기에 저장됩니다. 설정을 다른 기기로 옮기기
위해 복사할 수 있는 "설정 코드"에는 그 인증정보가 포함되므로 비밀번호처럼
다루세요.
AI 복기 파트너(본인 키 사용)
- 사용자가 선택한 AI 제공자(Anthropic 또는 OpenAI 호환 엔드포인트)의
본인 API 키를 입력할 수 있습니다. 키는 기기의
보안 저장소에만 저장되며 당사로 전송되지 않습니다.
- AI 제공자로 자동 전송되는 것은 없습니다. 사용자가 전송 버튼을
누를 때만 집계 통계(기간 매매 건수·승률·순손익·준수율·R 분포
등)와 사용자가 쓴 복기 텍스트(실수·다음엔·하루 총평)로
이루어진 주간 요약을 전송합니다.
심볼·가격·시각·개별 체결은 포함되지 않습니다.
- 전송될 내용은 보내기 전에 전문이 미리보기로 표시되며,
요청은 기기에서 선택한 제공자로 직접 갑니다. 당사는
요청·응답을 열람·중계·저장하지 않습니다. 데이터 처리는 해당 제공자의
개인정보처리방침과 약관을 따릅니다.
- AI 응답은 다른 복기 데이터와 함께 기기에 로컬로 저장됩니다.
차트 사진 첨부
- 매매에 첨부한 사진은 기기 안 앱 로컬 저장소로 복사됩니다. Kifu는 사진을
업로드하지 않습니다(위의 자체 동기화 서버를 설정한 경우 그 서버로만
전송). 사진 라이브러리 접근은 이미지를 고르는 용도로만 사용됩니다.
광고(무료 이용 시)
무료 이용 시 Google AdMob 광고가 표시됩니다. AdMob은 광고
게재·측정을 위해 기기 식별자(광고 ID 등)·IP 주소·대략적 사용 정보를 수집할 수
있으며, 자세한 내용은
Google 개인정보처리방침과
Google이
파트너 앱에서 정보를 사용하는 방식을 참고하세요. Pro 구독 시 모든 광고가
제거됩니다.
결제
구독은 Google Play 결제(Android) 또는 Apple 인앱
결제(iOS)로 처리됩니다. 구매 검증과 재설치 시 구독 복원을 위해
RevenueCat을 사용하며, RevenueCat은 앱이 생성한 무작위 사용자
ID와 구매 영수증 데이터만 받습니다(이름·이메일·결제 정보는 받지 않습니다 —
앱 스토어가 당사에 제공하지 않습니다).
RevenueCat 개인정보처리방침을
참고하세요.
아동
Kifu는 성인을 대상으로 한 금융 유틸리티이며 아동을 대상으로 하지 않습니다.
변경
방침이 변경되면 새 날짜와 함께 이 URL에 게시합니다.
문의
garage96@gmail.com