Privacy Policy

Effective: October 3, 2026 · 한국어 · Terms

DailySmile Studio provides this policy to explain how Big smile, Good fortune handles personal information and photos.

1. Information we process

The app itself does not collect GPS or precise location. Google Mobile Ads SDK may process an IP address and infer approximate location from it. The app does not collect contacts, payment information, health information, or microphone audio.

2. How photos are handled

Personal smile-record photos and GIFs are stored locally on your device by default and are not automatically backed up to a server.

Smile dates and score summaries may be stored on the server so your total score and streak can be restored when you sign in to the same app account on another device. These records do not include personal smile-photo originals or local file paths.

Face and smile detection is performed on-device to provide the app feature. It is not used to verify identity or identify a person. Smile probability and face count are used only for the personal smile record.

Only funny photos you choose to send to a friend and reaction photos you choose to send may be stored in Firebase Storage. Access through the app is limited to the relevant sender and recipient. DailySmile Studio does not routinely view these photos. An authorized operator may access them only to the minimum extent necessary to handle a report, respond to a security incident, resolve a service failure, or comply with a legal obligation, and does not use them for unrelated purposes. These files become eligible for automatic deletion seven days after upload; completion may be delayed by server processing.

Before first opening a friend's photo, the app separately explains and obtains consent for about five seconds of on-device front-camera smile analysis. The photo, camera, and countdown do not start before consent. After analysis, the app shows the result and smile score first. The result, score, and any selected reaction photo are sent to the sender only when the user chooses whether to include the photo and taps Send.

3. Why we use information

4. Server storage

Firebase Authentication stores the user ID, sign-in provider, an email address supplied by the provider, and a Google display name. Firestore may store the nickname, invite code, friend data and private friend names, friend requests, notification setting, per-device push token, platform and language code, smile-score sharing setting, smile dates and score summaries, daily send usage, ad-session and send-access state, and AdMob transaction identifiers used to prevent duplicate rewards. Firebase Storage may store friend-feature photos described above. Safety-related server data may include photo-sharing rules consent, block lists, safety concerns submitted to customer support, short-lived rate-limit records, and App Check verification data. Personal smile-photo originals, GIFs, local file paths, and scheduled Today's Smile alarms are not automatically stored on the server.

5. Third-party services

The app uses Google Firebase for authentication, data storage, and notifications. If you choose Apple sign-in, Apple processes the authentication request as the identity provider under the Apple Privacy Policy. The app uses Google AdMob and Google Mobile Ads SDK for rewarded ads. The SDK may automatically collect and share IP address, app interactions, diagnostics, advertising ID, app set ID, and other device or account identifiers with Google for ad delivery, analytics, and fraud prevention.

If you enable friend activity notifications on iOS, Expo Push Service relays the device's Expo push token, notification title and body, and the minimum navigation data (screen and section) to Apple Push Notification service (APNs). Notifications do not contain photos. Expo processes this data under the Expo Privacy Policy.

Where advertising privacy choices are required, including in the EEA, United Kingdom, and Switzerland, Google User Messaging Platform provides a consent or choice screen. Eligible users can revisit their choices under Settings > Ad privacy settings. Google's processing is governed by the Google Privacy Policy.

Firebase user IDs are not sent to AdMob to verify ad completion. Only a random ad-session identifier that does not directly identify the user is sent as server-side verification custom data. If you use the share feature, the selected file or text is provided to the external app or service you choose, and its privacy policy applies.

6. Retention and deletion

Account profiles, friendships, private friend names, consent records, and block lists are kept while the account is active and deleted with the account. If a safety concern is submitted to customer support, that record may be retained for up to one year for safety and dispute handling, or longer where legally required or necessary for an active dispute. Rate-limit records expire after a short security-review period.

In-app photo reports follow the same safety-record retention criteria and may be retained on that limited basis after account deletion. Reporting does not extend the original photo's retention period. On the photo viewing screen, open ⋯ > Report and select a reason to submit a report. Blocking the sender is a separate, optional choice.

Per-friend send access becomes eligible for deletion after the relevant Korean calendar day ends. Daily usage and SSV ad-session links become eligible seven days after that day ends. AdMob transaction identifiers used to prevent duplicate rewards become eligible 30 days after verification. Firestore TTL deletion may take approximately 24 hours after expiration.

After identity verification with the current sign-in method, Settings > Account management > Delete account deletes the app's Firebase account and associated profile, invite code, friend relationships and requests, private friend names, notification settings and tokens, smile dates and score summaries, score sharing setting, daily usage, ad-session and transaction records, and retained friend-feature photos. For Apple sign-in, the app first requests revocation of the Apple authorization using the code issued during in-app identity verification. It does not delete your Google Account or Apple Account itself.

In-app deletion also removes this device's app-specific smile records, personal smile photos, generated GIFs, and settings. Files exported to the phone's photo library, files shared with other apps, and local files on other offline devices cannot be deleted remotely.

If you cannot use the app, request deletion through the account and data deletion page. External requests are normally processed within 30 days after identity verification.

7. Security

DailySmile Studio uses Firebase Authentication and Firestore and Storage Security Rules to restrict access to user data. Firebase App Check is configured to use Android Play Integrity and iOS App Attest with DeviceCheck fallback as supplementary app-integrity signals. App Check supplements but does not replace authentication and authorization. Operator access is limited to the purposes and minimum scope described above.

8. Children's privacy

You must be at least 14 years old to use the app. Before sign-in, users confirm that they are at least 14 years old. The app does not ask for or collect a date of birth. A parent or guardian who believes information from a child under 14 was collected may request deletion.

9. Changes

We may update this policy when features, laws, or operating practices change. Material changes will be announced in the app or on the distribution page.

10. Contact

Privacy and service contact: Operator of DailySmile Studio

Email: dailysmile.help@gmail.com

Terms and Community Rules