시행일 2026년 9월 29일
Roster Privacy Policy
This policy explains how Roster's native mobile and Apps-in-Toss editions handle your information.
Controller and Contact
Magsmi, a sole proprietor in the Republic of Korea, provides Roster. The Magsmi Privacy Desk handles privacy matters and related complaints. Send privacy requests to support@magsmi.com.
What Roster Stores
The native app stores the people you add and what you record about them in a database on your device. This includes names, pronunciations, relationships, birthdays, profile facts such as reminders, allergies, dietary needs, sizes, or accessibility needs, and notes, meetings, and plans with their dates, places, activities, and participants. Settings such as language, haptics, and appearance are stored on the device too. Magsmi has no Roster account or cloud sync and cannot see these records. Android cloud backup is off. Other device backups follow your platform settings.
The Apps-in-Toss edition stores the following in Toss Storage: the same kinds of people records and settings, and a cached Roster Plus status. Toss manages that storage under its own policy.
How Information Is Used
Roster uses your records only to show them to you. Purchase information is used to provide and restore Roster Plus, and support email is used to answer your request. Magsmi does not sell your information or use it for advertising.
Retention and Deletion
Records stay until you delete them. Deleting a person removes their facts and any entry recorded only with them. Deleting an entry removes it for every participant. Clearing app data or uninstalling the native app removes its records. In the Apps-in-Toss edition, Delete all Roster data in Settings removes your people, profile details, and entries from Toss Storage and keeps your settings and cached Roster Plus status.
If you email support@magsmi.com, Magsmi receives your email address, message, and any attachments. Magsmi keeps support messages only as long as needed to answer and follow up, and deletes them on request unless the law requires keeping them.
When a record is no longer needed and no law requires keeping it, Magsmi deletes the electronic copy it controls.
Service Providers and International Processing
Apple and Google run the app stores and take payment for the native app. Toss runs the Apps-in-Toss platform and Toss Storage. Each acts under its own policy.
Magsmi shares personal information only with the providers named in this policy and only for the purposes stated here. The recipients below receive personal information outside Korea.
Recipient: RevenueCat, Inc. Destination: the United States, on Amazon Web Services. Items: an anonymous app user ID, product, transaction, and entitlement state, and routine device and network data. When and how: over an encrypted connection when a native store build opens and when you buy or restore Roster Plus. Purpose: offering, verifying, and restoring purchases. Retention: RevenueCat keeps purchase records for as long as it needs them to provide and restore purchases, prevent fraud, resolve disputes, and meet legal obligations. You can ask Magsmi to have your records deleted. Deleting them does not remove your purchase, and restoring it later from the App Store or Google Play creates a new record. Privacy contact: 1032 E Brandon Blvd #3003, Brandon, FL 33511, United States, compliance@revenuecat.com. Refusing: do not use the native app, which starts RevenueCat when it opens. The Apps-in-Toss edition does not use RevenueCat.
Recipient: Cloudflare, Inc. Destination: primarily the United States and the European Economic Area, with access from other countries where Cloudflare operates. Items: request data such as your IP address and the addresses, headers, message, and attachments of support email it forwards. When and how: over an encrypted connection when the native app checks the magsmi.com release file or you open Magsmi's legal or support pages, and through Email Routing when you email support. Purpose: delivering the release file, delivering Magsmi's legal and support pages, and forwarding support email. Retention: Cloudflare keeps routine request and security records for as long as the purposes in its privacy policy and its legal obligations require. Privacy contact: dpo@cloudflare.com. Refusing: do not use the native app, which checks the release file, do not open Magsmi's legal or support pages, and do not email support. You can still use the Apps-in-Toss edition. Magsmi cannot answer a request it does not receive.
Recipient: Google LLC. Destination: the United States and Google servers around the world. Items: the sender and recipient addresses, headers, message, and attachments of support email. When and how: when you email support, Cloudflare Email Routing forwards the message to Magsmi's consumer Gmail mailbox. Support email uses standard encrypted email transport where your email provider supports it. Purpose: receiving, reading, and answering support requests. Retention: Gmail keeps the message until Magsmi deletes it under this policy. Google says its complete deletion process generally takes about two months and encrypted backups can retain data for up to six months. Privacy contact: the options at https://support.google.com/policies/answer/9581826. Google's privacy policy is at https://policies.google.com/privacy. Refusing: do not email support. Magsmi cannot answer a request it does not receive.
Recipient: 650 Industries, Inc. (Expo). Destination: the United States. Items: a random installation ID, the platform and app and update versions, routine network data such as your IP address, and, after a failed start, up to 1,024 characters of the error message. Update requests do not include what you record in the app. When and how: over an encrypted connection when the native app checks for or downloads an update. Purpose: delivering app updates. Retention: Expo keeps this information only as long as reasonably necessary for the purposes in its privacy policy, under applicable law. Privacy contact: https://expo.dev/contact. Refusing: do not use the native app, which checks for updates. The Apps-in-Toss edition does not use Expo.
Your Rights, Security, and Changes
Depending on applicable law, you can ask Magsmi to access, correct, delete, or stop processing information it controls, or withdraw consent, by emailing support@magsmi.com. Records the law requires Magsmi to keep stay until their period ends. In Korea, you can also contact the Privacy Infringement Report Center at 118 or the Personal Information Dispute Mediation Committee at 1833-6972.
The app's network requests use HTTPS.
Magsmi posts changes to this policy here with a new effective date and gives additional notice where the law requires it.