← Back to KOLi
Privacy Policy
Last updated: June 3, 2026
KOLi ("we", "our", "the app") is a work management and financial tracking app for migrant workers in South Korea. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Account Information
- Phone number — used for authentication via SMS OTP
- Email address — used for authentication (Google, Apple, or email sign-in)
- Name — displayed on your profile and in community posts
- Profile photo — optional, uploaded by you
Work & Financial Data
- Work sessions — clock in/out times, break durations, stored locally on your device and synced to our server
- Job details — job name, hourly rate, shift settings
- Income and expenses — amounts, categories, notes you enter
- Pay calculations — derived from your work sessions and job settings
Location Data
- Coarse location — used only when you access the "Around Me" feature to show nearby services. Location is accessed only while the app is in use and is never stored on our servers.
Community Data
- Posts, comments, and polls — content you create in the community section
- Bookmarks — posts you save
Technical Data
- Device type and OS version — for crash reporting and compatibility
- Push notification token — to deliver notifications you opt into
2. How We Use Your Data
- Provide the service — clock in/out, pay calculation, financial tracking, community features
- Authentication — verify your identity when you sign in
- Notifications — send work reminders and community updates you opt into
- Improve the app — aggregate, anonymized usage patterns to fix bugs and improve features
3. How We Store Your Data
- Server: Your account data, community posts, and synced work sessions are stored on Supabase, hosted on AWS infrastructure with encryption at rest and in transit.
- On-device: Work sessions, jobs, and financial data are also stored locally on your device for offline access. On iOS, sensitive credentials are stored in the Keychain. On Android, sensitive data is stored in encrypted storage.
- Backups: You can create encrypted local backups (.koli files) protected by a passphrase you choose. We cannot access your backup passphrase.
4. Data Sharing
We do not sell your data to anyone.
We share data only in these cases:
- Supabase — our backend infrastructure provider (data processing)
- Firebase — phone number authentication (Google)
- Kakao — if you choose Kakao sign-in
- Apple / Google — if you choose Apple or Google sign-in
- Legal requirements — if required by Korean or international law
5. Your Rights
Access & Export
You can export your work session and financial data as CSV from the app's Settings.
Account Deletion
You can delete your account from Settings > Account Security > Delete Account. Deletion includes a 30-day grace period during which you can restore your account by signing back in. After 30 days, all your data is permanently deleted from our servers.
Data Correction
You can edit your profile, work sessions, and financial entries at any time within the app.
6. Children's Privacy
KOLi is not intended for use by anyone under the age of 17. We do not knowingly collect data from children.
7. Security
We use industry-standard security measures:
- All network communication uses HTTPS/TLS encryption
- Server-side Row Level Security (RLS) ensures users can only access their own data
- Passwords and tokens are stored using secure platform mechanisms (iOS Keychain, Android EncryptedSharedPreferences)
- In-app purchase verification uses Apple's signed JWS with certificate chain validation
8. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last updated" date at the top.
9. Contact Us
If you have questions about this Privacy Policy or your data:
This privacy policy is available in English. Korean and Khmer translations will be provided in a future update.