Settly Privacy Policy
- Effective Date: 2026-09-06
- Last Updated: 2026-09-06
- Controller/operator: Solidsoft
- Address: 4F, Room 498, 60 Dunji-ro (Dunsan-dong), Seo-gu, Daejeon, Republic of Korea
- Privacy contact: corp@solidsoft.team · 010-2615-3559
Settly is an Android settlement calculator. It calculates who owes whom from information entered by the user; it does not transfer money, confirm whether anyone paid, or offer a financial account.
This Privacy Policy explains how Settly handles personal information in the United States. It is designed around the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and common requirements of comprehensive U.S. state privacy laws. A particular state law and its rights apply only when its territorial, entity, and processing thresholds are met.
1. Scope and key privacy facts
This Policy applies to the Settly Android app and the Settly privacy-policy website. It does not govern an app that a user selects through the Android share sheet, Google Play, Android system backup, or Google services acting under their own notices and terms.
Settly does not send settlement titles, participant names, item descriptions, or amounts to an operator-run server. That content remains in the app's local storage and any Android system backup enabled by the user. It leaves the device only when the user intentionally shares a result or when the user's Android backup configuration transfers it.
Settly has no user accounts and does not include Firebase Analytics, operator-defined behavioral analytics events, or contacts access. On first launch, Settly presents a notice about automatic advertising and diagnostics processing. Advertising and remote diagnostics SDKs do not start until the user acknowledges that notice. Afterwards, the free version requests ads only when UMP permits them, and configured release builds automatically collect technical diagnostics through Firebase Crashlytics and Performance Monitoring. Google privacy messages control personalization and applicable regional advertising choices.
2. Categories of personal information
During the preceding 12 months, or since launch if shorter, Settly and the providers identified below may have processed the following categories. The table uses the categories in the California Consumer Privacy Act. Settly does not necessarily receive or have access to information processed by a provider.
| CCPA category | Examples | Sources | Business or commercial purposes | Retention period or criterion |
|---|---|---|---|---|
| Identifiers | IP address; Android advertising ID; app set ID; Firebase installation ID; Crashlytics installation UUID; Google Play purchase token; email address and verification details sent with a privacy request | Device, network connection, Google services, or directly from the requester | Privacy choices, ad delivery and measurement, fraud prevention, diagnostics, purchases, policy hosting, and rights requests | Settly does not independently persist advertising, Firebase, or purchase identifiers in its settlement database or custom logs. Providers retain them under the periods and criteria below. Privacy correspondence is kept while needed to resolve the request, document compliance, or handle a dispute, then deleted when no longer needed |
| Commercial information | Ad-removal product ID, purchase state, acknowledgement state, and entitlement status | User's Google Play purchase and Google Play | Process, acknowledge, restore, and verify the ad-removal purchase | The app caches only the entitlement until app data is cleared or the app is uninstalled. Google retains transaction records under its policies and legal duties |
| Internet or other electronic network activity | App launches, taps, ad impressions or video views; SDK and app diagnostics; crash stack and technical app state; performance timing; network URL without query strings or request bodies | Device and Google SDKs | Ad delivery and measurement, fraud prevention, crash diagnosis, and performance monitoring | Ad data follows Google's settings and retention policies. Crashlytics data enters deletion after 90 days; Performance data linked to IP after 30 days and installation-linked or deidentified performance data after 60 days |
| Geolocation data | Approximate location inferred from IP address; Performance Monitoring's IP-derived country | Network connection and Google SDKs | Ad delivery, fraud prevention, performance analysis, policy delivery, and abuse detection | Settly does not request precise location permission. Performance IP-linked events are kept for 30 days; Firebase Hosting keeps visitor IP data for a few months; other ad data follows Google's policies |
Settly does not knowingly collect protected-class characteristics, biometric information, sensory data, professional or employment information, education information, or profiles and inferences created by Settly about a user.
3. Information kept locally or shared only at the user's direction
| Information | What happens | Retention and control |
|---|---|---|
| Settlement content | Settlement title and currency; participant names and order; item description, amount, payer, and split participants remain in the Room database on the device | Until the user deletes a settlement, uses Delete all settlement data, clears app data, or uninstalls the app, subject to an older Android backup copy |
| Preferences | Default currency, last settlement, and the acknowledged data-collection notice version remain in DataStore on the device | Until changed, app data is cleared, or the app is uninstalled, subject to Android backup |
| Shared result | The app creates a selected summary or detailed table PNG only when the user asks to share | Cached until the next image share, Delete all settlement data, or Android cache cleanup; the chosen receiving app controls its copy |
Android system backup may include the local settlement database and ordinary preferences when backup is enabled. Android and the user's Google account govern the backup transport, retention, and deletion. Deleting data in Settly may not immediately remove an older backup copy. The cached ad-removal entitlement is excluded from Settly's Android backup rules.
4. Sources and purposes
Settly receives personal information from these sources:
- Directly from a user who sends a privacy request or intentionally shares a result.
- Automatically from the device or network after the first-run data-collection notice is acknowledged and, for advertising, only when UMP permits an ad request, except for the IP address necessarily processed when the user opens the hosted policy page or uses Google Play.
- From Google Play when the user purchases or restores ad removal.
Settly uses the information only to calculate and restore settlements locally, remember user settings, create a user-requested share image, manage privacy notices and ads, process ad removal, diagnose technical failures, improve reliability and performance, secure and operate the services, respond to privacy requests, and comply with law.
5. Service providers, contractors, and third-party disclosures
During the preceding 12 months, or since launch if shorter, the categories below may have been disclosed for the stated purposes. Whether a recipient is legally a service provider, contractor, or third party depends on the governing agreement and how it uses the information.
| Recipient category and provider | Personal information | Purpose and condition |
|---|---|---|
| Advertising and consent-management providers: Google LLC, AdMob, UMP, and configured ad partners | Identifiers, Internet or network activity, approximate geolocation, and SDK diagnostics | Privacy-choice management, ad delivery and measurement, and fraud prevention after notice acknowledgement, subject to applicable UMP choices and permission to request ads |
| Diagnostics providers: Google Firebase Crashlytics and Performance Monitoring | Installation identifiers, crash and app or device diagnostics, network performance information, and IP-derived country | Automatically diagnose crashes, ANRs, and performance after notice acknowledgement in a release build configured for Firebase |
| Hosting provider: Google Firebase Hosting | Visitor IP address | Deliver this policy page, detect abuse, and provide hosting usage analysis when the page is opened |
| App store and payment provider: Google Play | Identifiers and commercial purchase information | Process, acknowledge, restore, and verify the user-requested ad-removal purchase |
| Android backup provider selected through the user's device and account | Local settlement content and ordinary preferences | User-controlled cloud backup or device transfer when Android backup is enabled |
| App selected by the user in the Android share sheet | The result PNG selected by the user | Complete the user's requested share; the recipient acts under its own privacy practices |
| Operator's email provider | Requester's email address, message, and necessary verification details | Receive and respond to privacy and rights requests |
Settly does not disclose local settlement content to advertising or diagnostics providers and does not put participant names, item text, amounts, purchase tokens, or an app-defined user ID into custom Crashlytics logs or keys.
6. Sale, sharing, targeted advertising, and opt-out choices
Settly does not sell personal information for money.
When applicable Google privacy choices permit personalized advertising, Google or configured advertising partners may use identifiers, Internet or network activity, and approximate geolocation for advertising based on activity across nonaffiliated apps or services. That disclosure may be considered sharing for cross-context behavioral advertising under the CCPA or processing for targeted advertising under another state law. Settly does not share local settlement content for these purposes.
For purposes of this notice, Settly treats those conditional AdMob disclosures as sharing and provides the opt-out methods below. In the preceding 12 months, any sale, sharing, or targeted-advertising disclosure by Settly was limited to the categories, recipients, purposes, and user-controlled conditions described in this section.
Users can exercise the Right to Opt-Out in any of these ways:
- When available, open
Ad privacy choicesin Settly Settings and submit the choice in Google's U.S. state regulations message. - Visit Do Not Sell or Share My Personal Information.
- Send a request to the privacy contact listed above.
The release configuration requires Google's U.S. state regulations message to cover all current and future U.S. states supported by Google. Applicable Google consent, opt-out, restricted-data-processing, or GPC signals control ad treatment. Once an ad-removal entitlement is confirmed, Settly stops requesting banner ads. Changing a control affects future processing; information already transferred remains subject to the provider's retention rules.
Global Privacy Control (GPC). The Settly policy website does not load advertising, analytics, or tracking scripts, so it does not sell or share browser data regardless of whether a GPC signal is present. For supported app ad requests and states, Google states that it receives recognized GPC signals and applies restricted data processing.
7. Sensitive Personal Information
Settly does not knowingly collect Sensitive Personal Information as defined by the CPRA, such as government identifiers, financial account credentials, precise geolocation, private communications, genetic or neural data, biometric identifiers, health information, racial or ethnic origin, religious beliefs, union membership, or information about sex life or sexual orientation.
Amounts entered into a settlement are not financial account credentials and remain local. Settly does not request contacts, precise location, camera, microphone, health, or biometric permissions.
Because Settly does not collect or use Sensitive Personal Information for a purpose that may be limited, the Right to Limit Use of Sensitive Personal Information does not currently apply. If this practice changes, Settly will provide the required notice and control before the new processing begins.
8. Retention, deletion, and destruction
Retention periods or criteria appear in Sections 2 and 3. Settly keeps personal information only for as long as reasonably necessary for the disclosed purpose, legal compliance, security, or dispute resolution.
Delete all settlement data removes every settlement, participant, item, and cached shared image from the device. It keeps the default currency, data-collection notice acknowledgement, and ad-removal entitlement. Clearing Android app data or uninstalling the app removes all local Settly data. The operator cannot retrieve, correct, or delete settlement content it never receives. Provider-held information and older Android backups follow the applicable provider's controls and retention schedule.
9. U.S. privacy rights
Subject to applicable law and exceptions, residents of California, Virginia, Colorado, Connecticut, Utah, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws may exercise these rights:
- Right to Know or access the categories and specific pieces of personal information processed, the sources, purposes, and recipient categories.
- Right to Delete personal information, subject to legal and operational exceptions.
- Right to Correct inaccurate personal information.
- Right to Opt-Out of sale, sharing, targeted advertising, and certain profiling where applicable.
- Right to Limit Use of Sensitive Personal Information where applicable. Settly does not currently process such information in a manner subject to this right.
- Data Portability to obtain eligible personal information in a portable and readily usable format.
- Non-Discrimination so that exercising a privacy right does not result in unlawful retaliation, denial of service, or a different price or quality of service.
- The right to appeal a refusal to act on a request when applicable state law provides an appeal process.
These rights do not require Settly to obtain or retain information it otherwise would not keep. Because the operator has no account system and cannot access local settlement content, some requests may result in confirmation that no operator-held record can be matched to the requester.
10. How to exercise U.S. privacy rights
Settly is an online-only service that has a direct relationship with its users. Rights requests may be submitted by email through the privacy contact, while sale, sharing, and targeted-advertising choices can also be exercised through Google's in-app privacy form when available and the online opt-out page described in Section 6.
To make a rights or external-service deletion request, email corp@solidsoft.team · 010-2615-3559 with the subject Settly privacy request, the requested action, and a reply address. The operator may request the minimum additional information needed to verify the requester, then respond using applicable law and the service provider's available tools.
Requests are free unless applicable law permits a reasonable fee for manifestly unfounded, excessive, or repetitive requests. Settly does not require a user to create an account to exercise a privacy right. The scope of each right and any exception depend on the law that applies to the requester and the operator.
Settly will confirm receipt within 10 business days and respond within 45 days when the CCPA requires those periods. If reasonably necessary and permitted by law, Settly may extend the response by another 45 days after giving notice and a reason. Other state-law deadlines apply where they differ. Opt-out requests are handled as soon as technically feasible and no later than 15 business days when the CCPA applies.
Settly may request only information reasonably necessary to verify a request and will use verification information only for that purpose. An opt-out submitted through Google's in-app privacy form does not require a Settly account.
An Authorized agent may submit a request on a consumer's behalf by using the same privacy contact. Settly may ask for signed permission, proof of the agent's authority, or direct confirmation from the consumer as permitted by law. A consumer may appeal a denied request by replying to the decision with the subject Privacy request appeal; Settly will respond within the period required by the applicable state law.
11. Children and teenagers
Settly is not designed or directed to children, and the operator does not intentionally request children's personal information.
Settly does not knowingly sell or share personal information of anyone under 16. If the operator learns that information from a child was processed contrary to this Policy, the operator will take reasonable steps to stop the processing and delete information it controls. A parent or guardian may contact the privacy address above.
12. Automated Decision-Making Technology
Settly does not use personal information in Automated Decision-Making Technology (ADMT) to make decisions that produce legal or similarly significant effects, and it does not use personal information for significant profiling.
The app calculates settlement results from amounts, payers, and participants using fixed arithmetic rules. This calculation does not decide access to employment, credit, insurance, education, healthcare, housing, or another significant service. Advertising technology may select ads, but Settly does not use that selection to make a significant decision about a user.
13. Security
Settly uses the Android app sandbox, limited permissions, encrypted network transport provided by the listed Google SDKs, delayed advertising and diagnostics initialization until the first-run notice is acknowledged, UMP gating before ad requests, and diagnostics designed not to include settlement content. No method of storage or transmission is completely secure, and users should protect their device and accounts with current security updates and access controls.
14. Financial incentives
Settly does not offer a financial incentive, loyalty program, price difference, or service difference in exchange for collecting, selling, or sharing personal information. The optional one-time ad-removal purchase buys an ad-free app experience and is not conditioned on providing personal information for sale or sharing.
15. International processing
Google LLC and its disclosed subprocessors may process the information described in this Policy in the United States and other countries where they operate facilities. Google LLC is located at 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States. Information is transferred over encrypted connections when UMP or AdMob makes an allowed request, a crash or performance event is recorded, Google Play processes a purchase, or a visitor opens the hosted policy page.
Advertising and remote diagnostics do not start until the user acknowledges Settly's first-run data-collection notice. After acknowledgement, configured release builds automatically collect Firebase Crashlytics and Performance Monitoring diagnostics. The free version requests ads only when UMP reports that ads may be requested. Google privacy messages control personalization and applicable regional consent or opt-out choices. Confirmed ad removal stops banner requests but does not disable operational diagnostics. Information already transferred remains subject to the retention periods above.
The operator does not transfer local settlement content to Google. Where applicable law requires a transfer mechanism or additional consent, Settly relies on Google privacy messages, provider terms, and other legally recognized safeguards. Users may contact Google through its privacy inquiry form.
16. Changes to this Policy
Settly reviews this Policy at least every 12 months and when its data practices, SDKs, or legal obligations materially change. The new Last Updated date will appear at the top. Material changes will also be presented in the app or by another reasonably prominent method before they take effect when required by law.
17. Contact and complaints
- Privacy responsibility and access requests: Solidsoft
- Address: 4F, Room 498, 60 Dunji-ro (Dunsan-dong), Seo-gu, Daejeon, Republic of Korea
- Contact: corp@solidsoft.team · 010-2615-3559
Consumers may also submit a complaint to the California Privacy Protection Agency or the attorney general or privacy regulator in their state. Government agencies do not act as Settly's customer service representatives and may not provide personal legal advice.
Official references
- California Privacy Protection Agency — CCPA regulations effective January 1, 2026
- California Attorney General — California Consumer Privacy Act
- California Privacy Protection Agency — updated monetary thresholds
- Colorado Attorney General — Colorado Privacy Act and universal opt-out
- Connecticut Attorney General — Connecticut Data Privacy Act
- Virginia Attorney General — Virginia Consumer Data Protection Act summary
- Rhode Island General Laws — Data Transparency and Privacy Protection Act
- Google Mobile Ads SDK data disclosure
- Google Mobile Ads ad personalization settings
- Google AdMob — U.S. state regulations messages
- Privacy and Security in Firebase