Skip to content
magsmi
SupportLegal한국어
Legal

Effective September 29, 2026

Converter Plus for Toss Privacy Policy

This policy explains how the Converter Plus mini-app in Apps-in-Toss handles your information. The native iOS and Android app has a separate policy.

LanguagesThis document is available in Korean and English. If the versions differ or wording is unclear, the interpretation more favorable to the user applies where required by law.

Controller and Contact

Magsmi, a sole proprietor in the Republic of Korea, provides Converter Plus for Toss. The Magsmi Privacy Desk handles privacy matters and related complaints. Send privacy requests to support@magsmi.com.

What the Mini-App Stores

The Apps-in-Toss edition stores the following in Toss Storage: converter amounts, selected currencies and units, saved, recent, and pinned conversions, tax, card-fee, and tip settings, themes, onboarding state, cached rates, size profiles, Convert Board data, and, after you sign in, a Magsmi session token, a cached Converter Plus status, and the last verified order ID and product ID. Toss manages that storage under its own policy.

Magsmi does not upload or sync your converter records. A cached Converter Plus status works offline for up to seven days. The order ID and product ID stay until Toss Storage is cleared.

Toss Login and Purchases

The free converter needs no sign-in. Buying or restoring Converter Plus opens Toss Login. The mini-app sends the resulting authorization code to Magsmi's purchase service at api.toss.magsmi.com, which runs on Cloudflare. The service exchanges it with Toss for an app-scoped Toss user key and uses the Toss access tokens only on the server. It stores a pseudonymous subject derived from the user key, sessions that hold the user key in encrypted form, and order, order event, and entitlement records in Cloudflare D1.

Free users see banner and full-screen ads, which Toss serves under its own policy.

How Information Is Used

The mini-app uses your records only to convert currencies, units, and sizes and to show rates. Purchase information is used to provide and restore Converter Plus, and support email is used to answer your request. Magsmi does not sell your information or use it for targeted advertising.

Retention and Deletion

When Toss reports that you unlinked the mini-app, Magsmi deletes the purchase service's user record with its sessions, orders, order events, and entitlements. A pseudonymous unlink marker stays for up to two hours so that a sign-in that started earlier cannot recreate the record. Unlinking does not clear your records in Toss Storage.

Korea's Act on Consumer Protection in Electronic Commerce requires contract, payment, and supply records to be kept for five years. Magsmi keeps a separate record of each verified Toss order for five years from the order's latest status date and deletes it when that period ends. It holds the order and product identifiers, the pseudonymous subject, and the purchase, grant, and refund status and dates. It remains after unlinking. Under the same Act, Magsmi keeps records of consumer complaints and disputes about these purchases, such as support emails, for three years.

If you email support@magsmi.com, Magsmi receives your email address, message, and any attachments. Magsmi keeps support messages only as long as needed to answer and follow up, and deletes them on request unless the law requires keeping them.

When a record is no longer needed and no law requires keeping it, Magsmi deletes the electronic copy it controls. A deleted record leaves the live database right away. Cloudflare D1's point-in-time recovery can restore it for up to 30 days, after which it is gone.

Service Providers and International Processing

Toss runs the Apps-in-Toss platform, Toss Login, payment, Toss Storage, and ads, and Apple or Google processes the underlying store payment. Each acts under its own policy.

Magsmi shares personal information only with the providers named in this policy and only for the purposes stated here. The recipients below receive personal information outside Korea.

Recipient: Cloudflare, Inc. Destination: primarily the United States and the European Economic Area, with access from other countries where Cloudflare operates. Items: request data such as your IP address, the account, entitlement, purchase-record, and security data of the Apps-in-Toss purchase service, and the addresses, headers, message, and attachments of support email it forwards. When and how: over an encrypted connection when you open Magsmi's legal or support pages or you sign in, buy, or restore a purchase in the Apps-in-Toss edition, and through Email Routing when you email support. Purpose: delivering Magsmi's legal and support pages, running the Toss purchase service, and forwarding support email. Retention: Magsmi keeps the records it stores there for the periods in the retention section above. Cloudflare keeps routine request and security records for as long as the purposes in its privacy policy and its legal obligations require. Privacy contact: dpo@cloudflare.com. Refusing: do not open Magsmi's legal or support pages, do not sign in, buy, or restore a purchase in the Apps-in-Toss edition, and do not email support. The Apps-in-Toss edition's free features keep working, but you cannot buy or restore a purchase there. Magsmi cannot answer a request it does not receive.

Recipient: Google LLC. Destination: the United States and Google servers around the world. Items: the sender and recipient addresses, headers, message, and attachments of support email. When and how: when you email support, Cloudflare Email Routing forwards the message to Magsmi's consumer Gmail mailbox. Support email uses standard encrypted email transport where your email provider supports it. Purpose: receiving, reading, and answering support requests. Retention: Gmail keeps the message until Magsmi deletes it under this policy. Google says its complete deletion process generally takes about two months and encrypted backups can retain data for up to six months. Privacy contact: the options at https://support.google.com/policies/answer/9581826. Google's privacy policy is at https://policies.google.com/privacy. Refusing: do not email support. Magsmi cannot answer a request it does not receive.

Recipient: Frankfurter public API (https://frankfurter.dev), delivered through Cloudflare, Inc. Destination: Frankfurter does not publish where its servers are. Requests pass through Cloudflare's network and may be processed outside Korea. Items: the selected currency codes and dates, your IP address, the request time, and network headers. Amounts are not sent. When and how: over an encrypted connection whenever a currency screen or the Convert Board is open. Currency conversion is the default screen, so this starts on first launch. Purpose: providing current and historical reference rates. Retention: Magsmi does not receive or store these requests. Frankfurter says its API does not log personal data, IP addresses, or request URLs. Privacy contact: Frankfurter does not publish a privacy contact. Its source code and issue tracker are at https://github.com/lineofflight/frankfurter. Refusing: switch to unit or size conversion, which makes no rate requests. The mini-app reopens in the last mode you used. To avoid the requests entirely, do not open the mini-app. Without them it cannot show rates.

Your Rights, Security, and Changes

Depending on applicable law, you can ask Magsmi to access, correct, delete, or stop processing information it controls, or withdraw consent, by emailing support@magsmi.com. Records the law requires Magsmi to keep stay until their period ends. In Korea, you can also contact the Privacy Infringement Report Center at 118 or the Personal Information Dispute Mediation Committee at 1833-6972.

The app's network requests use HTTPS. The Toss purchase service also uses mutual TLS (mTLS) for calls to Toss, stores sessions only as hashes that expire after one hour, encrypts the Toss user key, limits sign-in attempts by IP address, and checks each order with Toss before granting access.

Magsmi posts changes to this policy here with a new effective date and gives additional notice where the law requires it.