Effective August 7, 2026
Converter Plus for Toss Privacy Policy
This policy applies only to the Converter Plus mini-app provided through Apps-in-Toss. The native iOS and Android app has a separate policy on magsmi.com.
Controller and Contact
Magsmi, represented by Magne Saetran, operates the mini-app from the Republic of Korea. Business registration number: 482-28-02053. Privacy requests may be sent to support@magsmi.com or by post to 2F, 214-S128, 46 Apgujeong-ro 2-gil, Gangnam-gu, Seoul 06034, Republic of Korea.
Data stored on your device
Converter amounts, selected currencies and units, saved and recent conversions, pinned currencies, tax, card-fee and tip settings, themes, onboarding state, cached rates, size profiles, and Convert Board data are stored locally in the Toss WebView using browser storage such as local storage and IndexedDB.
Magsmi does not upload or cloud-sync those converter records. You can remove them with the mini-app's reset controls, by clearing Toss app data, or by uninstalling Toss, subject to platform behavior.
Exchange-Rate Requests
For current and historical reference rates, the mini-app requests data from the Frankfurter public API. The request includes selected currency codes, but not the amount being converted, saved-pair list, tax, card-fee, tip, unit, clothing-size, or search input.
Frankfurter and its delivery provider may receive routine network information such as an IP address, request time, requested currency codes, and network headers.
Toss Login and account identifiers
The free converter does not require login. Converter Plus asks you to use Toss Login when you buy, restore, or use an account-linked Pro entitlement. Magsmi requests only the app-scoped Toss userKey needed to recognize the same user across supported devices. Magsmi does not request your name, email address, phone number, birthday, gender, nationality, Connection Information (CI), or advertising identifier through Toss Login.
The mini-app sends the one-time authorization code to Magsmi's server. The server exchanges it with Toss over mutual Transport Layer Security (mTLS). Access tokens, refresh tokens, and session credentials remain on the server and are not stored in the WebView. Magsmi uses them only to authenticate the account, verify purchase status, restore access, prevent abuse, and respond to account-link changes.
Purchases, entitlements, and ads
The mini-app uses Apps-in-Toss in-app purchase APIs for a permanent non-consumable product. Magsmi's Cloudflare Worker verifies order status with Toss and stores the app-scoped userKey, order ID, product identifier, order and entitlement status, grant and refund timestamps, and limited idempotency and audit metadata in Cloudflare D1. This record lets Magsmi deliver the purchase, restore it on another supported device, prevent duplicate grants, reconcile refunds, and meet transaction-record obligations.
Toss and the applicable Apple or Google marketplace process the technical, device, marketplace, product, order, purchase, restoration, refund, and fraud-prevention information needed to provide Apps-in-Toss purchases. Magsmi does not receive your full payment-card or bank-account details.
The free version may show banner ads supplied through Toss. Toss may process device, app, ad-delivery, interaction, fraud-prevention, and routine network information under its policies. Magsmi does not embed RevenueCat, PostHog, session replay, or a separate cross-app advertising SDK in this mini-app.
Service providers and international processing
Magsmi uses Toss for login, purchase, marketplace, refund, and ad services; Cloudflare Workers and D1 for the entitlement service, security, and legal-site hosting; Frankfurter and its delivery providers for exchange rates; and an email provider for support. These providers may process routine network and service information under their own policies or agreements.
Cloudflare may process and store account, entitlement, security, and request data outside Korea, including in the United States and other locations where its services operate. Data is transferred over encrypted network connections when you log in, buy or restore Converter Plus, use the entitlement service, or visit toss.magsmi.com. The transferred items and purposes are limited to those described in this policy.
Retention, disconnection, and deletion
Magsmi keeps account sessions and Toss Login tokens only while needed to maintain the connection and entitlement service. When Toss reports an unlink, terms withdrawal, or Toss-account withdrawal, Magsmi revokes the session and deletes login tokens without undue delay. Magsmi deletes the userKey when it is no longer needed, unless a purchase, fraud-prevention, dispute, accounting, or legal-retention duty requires a limited record.
Magsmi retains records of contracts, payment, and supply for five years and consumer complaints or dispute handling for three years where Korean electronic-commerce law applies. Security and fraud-prevention records are kept only for the period reasonably needed for those purposes, unless another law requires longer retention. When no legal or operational purpose remains, Magsmi deletes or de-identifies records under its control using methods intended to prevent recovery. Toss, Apple, Google, Cloudflare, Frankfurter, and the email provider apply their own retention duties and policies to records they control.
Disconnecting Toss Login stops account-linked access until you sign in again. It does not automatically refund a purchase or delete transaction records that law requires Magsmi or the marketplace to retain. It also does not remove converter data stored locally in the WebView.
Support, your rights, and your choice
If you email support@magsmi.com, Magsmi receives your email address, message, and attachments you choose to send. Do not send passwords or full payment details. Support records are kept only as needed to answer the request, protect legal rights, and meet legal obligations.
Cloudflare hosts and secures toss.magsmi.com and may process routine request information. Cloudflare Web Analytics measures aggregate page use and performance without analytics cookies or individual visitor profiles. It excludes query strings from measured paths.
You may refuse Toss Login and continue using the free converter, but you cannot buy, restore, or use account-linked Converter Plus access without the app-scoped userKey. Depending on applicable law, you may request access, correction, deletion, restriction, portability, suspension, or information about Magsmi-controlled data by contacting support. Magsmi may ask for limited information needed to identify the correct account or transaction.
Security and changes
Magsmi minimizes collected data, uses HTTPS, protects server secrets, validates Toss callbacks, rate-limits sensitive endpoints, and uses mTLS for required partner-server calls to Toss. No storage or transmission method can be guaranteed completely secure. This page and its effective date will be updated when the mini-app's practices change.