CrystalEngine Privacy Policy
General Provisions
The Company collects nothing from users directly.
(1) BS Planet (hereinafter the "Company") establishes and publishes this Privacy Policy (hereinafter this "Policy") with respect to the processing of personal information in CrystalEngine (hereinafter the "App").
(2) The App is a completely private app that finds and opens the files, photos, music, and records on the device. All processing happens on the user's device, and the contents of the user's files are never sent to a server.
(3) The Company does not collect even device information directly. There is no account or login in the App, and accordingly the Company holds no user information.
(4) Provided that, where a user watches an ad for a "one-day ad pass," Google AdMob may collect an advertising identifier. The boundary between the Company's direct collection and such collection shall be set out in Article 4.
Definitions
For the purposes of this Policy, the following terms shall have the meanings set out below.
1. "Company" means BS Planet, the developer that develops and distributes the App.
2. "App" means CrystalEngine, which the Company distributes.
3. "User" means a person who installs and uses the App.
4. "Device" means the terminal on which the user has installed the App.
5. "Index" means the database that the App creates within the device for unified search.
6. "Optional feature" means a feature that operates only where the user has turned it on. Its principal examples shall be as set out in Article 3 (1).
7. "Trail" means the record of the user's activity that the App leaves within the device and shows on the activity timeline, the composition of which shall be as provided in Article 7.
Article 1 (Information the Company Collects Directly)
(1) There is no information that the Company collects directly from users. The Company collects no information from users directly.
(2) The Company does not collect device information, and it does not collect information that could identify a user.
(3) There is no sign-up or login in the App.
(4) Google's collection through ads shall be set out separately in Article 4.
Article 2 (Processing Carried Out Only on the Device)
(1) The information set out in each of the following subparagraphs is stored only in an index on the user's device and is not sent to any server. Provided that, where the user has turned on an optional feature under Article 3, the artist and album name in subparagraph 2 and a photo's location coordinates are sent to the relevant provider to the extent that feature requires, and Article 3 sets out that extent and who receives them.
1. The file and document contents read for search
2. The metadata of photos and music
3. Contacts, calendar, messages, and health records, only when the user turns them on
(2) The index database is encrypted on the device (SQLCipher).
(3) Provided that, where the App fails to open the encrypted index, the index may be stored unencrypted. That happens where the device keystore (Android Keystore) cannot supply the encryption key, where the encryption library cannot be loaded, where storage is unavailable, or where the cause cannot be determined. The App tells the user when that happens.
(4) The network is off by default. Provided that, in the Google Play edition that carries ads, the ad consent check and the advance ad request are not subject to this switch; they take place at the time set out in Article 4, paragraph (5). The App's network status notice says so as well.
Article 3 (Optional Features the User Turns On)
(1) Optional features include those set out in the following subparagraphs. This enumeration is given by way of example and does not limit the optional features in their entirety.
1. Album image lookup
2. Converting a photo's location to an address
3. Voice recognition
4. Maps
5. On-device model downloads
6. Cast and DLNA output
(2) Only when the user turns on and uses an optional feature is the minimum query needed for that feature sent to the relevant provider. Album image lookup sends the artist and album name read from the file's tags to Apple Inc.'s iTunes Search API, and the cover image found is fetched from Apple's image servers. Converting a photo's location to an address sends the location coordinates to the device's system geocoding service, and maps send the tile coordinates of the map area being viewed to the OpenStreetMap tile server. On-device model downloads fetch model files from the Hugging Face and Google repositories when the user requests them. Cast and DLNA output discovers devices on the same network by multicast and opens a temporary server on the device to deliver the file being cast to the device the user chose; the file does not leave the user's network. Voice search uses the on-device recognizer first, but on devices where it is unavailable it falls back to the system recognizer, and the voice the user spoke then leaves the device through the device's system.
(3) Even in that case the contents of the user's files are not sent to any server, and the Company neither receives nor stores those queries. Files served by the temporary on-device server during casting go only to the device the user chose within the user's own network.
(4) These features are off by default.
(5) The user may turn off "Network use" in Settings. Turning it off stops any communication the app makes on its own. Communication by the voice-recognition fallback, which the device's system recognizer performs on the app's behalf, follows the device settings rather than the app's switch.
Article 4 (Advertising, Payment, Updates, License)
(1) With respect to advertising, payment, updates and license as well, the Company still collects nothing from users directly.
(2) The user may run the app free for the first 5 times. Where, after using the first 5 free app runs, the user chooses a "one-day ad pass" to keep using the app, a rewarded ad is shown at that point, and that ad is served by Google AdMob.
(3) AdMob may collect and use the advertising identifier (AD_ID), the IP address, device and app information, and ad-interaction data for ad delivery and measurement, and it may process them outside the country. This collection does not happen only while the user is watching an ad; it happens from the point at which the ad consent check and advance ad request under paragraph (5) take place. This is processing that Google performs under its own privacy policy.
(4) The Company neither receives nor stores that information, and the user's file contents, search terms, and index are not used for advertising nor passed to the ad provider.
(5) Ads do not appear automatically and play only when the user chooses to watch them. Users who purchase the lifetime edition are not shown ads. The ad consent check and the advance ad request take place when the App is opened in the Google Play edition after the user has agreed to the Terms on the first-run screen and while no lifetime purchase has been confirmed; on a device where a lifetime purchase has been confirmed they do not take place. On the first launch right after a purchase, before the App has reflected it, they may take place once.
(6) Where consent is required (such as in the EEA), personalized-ad consent is obtained before the first ad, and the user can change or withdraw it at any time under "Ad privacy options" in Settings.
(7) The conditions of use shall be as set out in the following subparagraphs.
1. The user may run the app free for the first 5 times (each cold launch and each return to the app from the background counts as one run).
2. After that the user can keep using it with a one-day pass earned by watching an ad, or with a lifetime purchase (a one-time purchase).
3. There is no separate per-use limit on document viewing, search, music, photos, or video.
4. There is no subscription and no license key.
(8) Payment is handled by Google Play and made anonymously, so the Company cannot know who paid; all the Company can see is a purchase identifier (purchase token and product ID).
(9) Updates are handled by Google Play.
(10) The ad SDK of the Google Play edition also declares Android's ad-services permissions (ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_TOPICS, ACCESS_ADSERVICES_ATTRIBUTION). The latter two belong to Android Privacy Sandbox, which handles interest topics and ad conversion measurement on the device instead of the advertising identifier; they work only on devices where Google has enabled that feature, and the user can turn them off under Privacy in the device settings. When requesting ads the App does not tag them as child-directed and limits the ad content rating to PG.
Article 5 (Permissions and Their Purposes)
(1) The permissions the Company uses and their purposes are set out in the table below, and nothing read with any permission is used for advertising, analytics, or profiling.
(2) The table lists every permission the user has to grant. Normal permissions granted automatically at installation, such as internet access and network state, are not listed, and where communication actually happens is set out in Article 3 and Article 4.
(3) Some permissions differ depending on where the user obtained the app, and the table says so for those.
| Permission | Purpose |
|---|---|
| All files access | Searching and managing all files (the core feature) |
| Photos, videos, music | Media listing and playback |
| Photo location | Reading where a photo was taken (when address conversion is on) |
| Contacts, calendar | Unified search index |
| SMS messages | Adding the sender, body and time of messages to the unified search index on the device. Requested only when you turn the messages source on. Present only in the "full" edition distributed by the developer; the app obtained from Google Play does not have this permission |
| App usage history | The activity timeline |
| Location (current location) | Recording the route on the activity timeline - your current location is sampled only while you are using the app (no background collection). Requested only when you turn on "location history" in the timeline; the app obtained from Google Play does not have this permission. Sampled coordinates are stored only in the activity records on the device |
| Health (steps, sleep) | Reading daily step counts and sleep records from Health Connect, read-only, to show them on the activity timeline. Health Connect permission is requested only when you turn the "health" source on. What is read is stored only in the activity records on the device, is not sent to any server, and is not used for advertising, analytics or profiling nor provided to third parties |
| Microphone | Voice search and spectrum display |
| Camera | Taking a photo to find similar images |
| Notifications | Showing indexing progress and music playback controls |
| Biometric authentication | Unlocking with a fingerprint or similar when app lock is on. Biometric data is verified by the device's system, and the App receives only whether it succeeded |
| Wi-Fi multicast | Discovering devices on the same network when Cast or DLNA output is started |
| Installing apps | Opening the system installer screen when you tap an installation file (.apk) in the file list. Whether to install is decided by you on the system screen |
(4) The app works even if the user does not grant a permission; only that feature is unavailable.
Article 6 (Children Under 14)
(1) The Company does not knowingly collect the personal information of children under 14, and there is no path by which it collects personal information from children.
(2) The application market's target age is 13 and older.
Article 7 (Retention and Deletion)
(1) The Company holds no user data.
(2) The on-device index, settings, and records are deleted together when the user deletes the app. The user can also erase them from inside the app. Provided that a backup file created with "Export backup" in Settings (search history, saved searches, file paths of collections, favorites, and settings) is saved in plain text at the location the user chose and remains after the app is deleted, so the user deletes it when it is no longer needed. The backup does not include the trail.
(3) The ways of erasing them from inside the app shall be as set out in the following subparagraphs.
1. The file index is handled from Settings > Storage scan: Clean up removes files deleted or changed by other apps from the index, and Full rescan deletes the index and rebuilds it from scratch. Delete index removes the index and leaves it empty; an emptied index is rebuilt when the user scans again or automatic scanning runs.
2. The trail (location, calls, messages, app usage, and health records; location and messages exist only in the edition the developer distributes directly) is erased from Settings > Trail (Delete permanently).
3. Search history can be deleted in full from the search history sheet on the home screen, and Settings > Auto-delete history can automatically delete entries older than 7 or 30 days. Auto-delete is off by default.
(4) Cleaning up or rebuilding the index does not erase the trail. In that case the trail has to be deleted separately with the permanent deletion under subparagraph 2 of paragraph (3).
(5) In the case of either deletion, no separate deletion request is needed.
(6) The only thing the Company holds is the email the user sends of their own accord when contacting it, together with the reply. The Company keeps it as a consumer complaint handling record for 3 years from the day the reply was completed and then deletes it (the period set by Article 6(1) of the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce of the Republic of Korea), and the user may request its deletion earlier through the contact set out in Article 8.
(7) If the app closes unexpectedly, a record of it remains in the app's storage on the device. That record leaves the device only when the user sends it themselves with Share log under Settings > Diagnostics, and file names are masked in it.
Article 8 (Inquiries and Amendment of the Policy)
(1) Inquiries about personal information and the exercise of rights under Article 9 are received by email (support@bsplanet.app).
(2) If this Policy changes, it is reflected in both "Settings > Privacy Policy" in the app and the public URL above.
- Developer: BS Planet
- Email: support@bsplanet.app
Article 9 (Rights of Data Subjects and How to Exercise Them)
(1) The user may at any time demand access to, correction or deletion of, or suspension of processing of the personal information the Company holds about them. Since the only thing the Company holds is the inquiry email under Article 7, paragraph (6), such demands concern that email and its reply.
(2) Demands are received by the email set out in Article 8, and the Company gives notice of the result within 10 days of receipt in accordance with article 41 of the Enforcement Decree of the Personal Information Protection Act of the Republic of Korea. Where a demand is refused, the reason and the way to object are given together.
(3) The legal representative of a child under 14 may exercise these rights on the child's behalf in the same way.
(4) The index, settings, and records on the device are not held by the Company and are therefore not the subject of demands under this Article; the user erases them directly by the methods in Article 7. Google holds the originals of Google Play orders and reviews, so demands about them are best made through the user's Google account, and the advertising identifier can be reset or deleted in the device settings.
Article 10 (Destruction of Personal Information)
(1) When the retention period of an inquiry email (Article 7, paragraph (6)) has passed, the Company deletes the email and its reply in a way that cannot be recovered.
(2) Data on the device is deleted when the user deletes the app or erases it by the methods in Article 7; the Company holds no copy, so there is nothing further for the Company to destroy.
Article 11 (Measures to Ensure Security)
(1) The Company operates no server that stores users' personal information. Only the representative has access to the inquiry email account and the Google Play Console.
(2) The on-device index is encrypted with SQLCipher (Article 2, paragraph (2)), and the app uses HTTPS when it communicates with external servers. Casting, however, delivers files to the device the user chose within the user's own network, so that leg is plain HTTP.
(3) The user can require device lock or biometric authentication when opening the app with App lock in Settings.
Article 12 (Personal Information Protection Officer)
The Company is a small business run by a single representative and, under the small-business exception in article 32 of the Enforcement Decree of the Personal Information Protection Act of the Republic of Korea, does not designate a separate personal information protection officer; in that case the representative acts as the protection officer and handles personal information protection and related grievances. The contact is the email set out in Article 8 (support@bsplanet.app).
Article 13 (Remedies for Infringement of Rights)
The user may seek advice on or report infringements of personal information to the following bodies. All are institutions of the Republic of Korea; users residing outside Korea may also report to the supervisory authority of their country of residence.
| Body | Contact |
|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972, https://www.kopico.go.kr |
| Personal Information Infringement Report Center (KISA) | 118, https://privacy.kisa.or.kr |
| Supreme Prosecutors' Office, Cyber Investigation Division | 1301, https://www.spo.go.kr |
| Korean National Police Agency, Cybercrime Reporting System | 182, https://ecrm.police.go.kr |
Article 14 (Transfer of Personal Information Abroad)
While the app is in use, the information in the following table may be sent to businesses outside the country. The Company does not receive this information; each recipient processes and retains it under its own privacy policy.
| Recipient (country) | Information transferred | When and how | Purpose |
|---|---|---|---|
| Google LLC (United States) | Advertising identifier, IP address, device and app information, ad interactions | The ad consent check and advance request when the App is opened in the Google Play edition after agreeing to the Terms, and the ad SDK's network transmission while an ad is watched | Ad delivery, measurement, fraud prevention (https://policies.google.com/privacy) |
| Apple Inc. (United States) | Artist name, album name, IP address | Cover lookup and image download when album image lookup is on | Displaying album covers |
| Hugging Face, Inc. (United States), Google LLC (United States) | IP address, name of the requested model file | When the user requests a model download | Downloading the speech recognition and image embedding models |
| OpenStreetMap Foundation (United Kingdom) | Tile coordinates of the map area being viewed, app package name, IP address | When maps are turned on and viewed | Displaying map tiles |
| Provider of the device's system services (usually Google LLC, United States) | Photo location coordinates; voice during the voice-recognition fallback | When address conversion is turned on and used; when voice search is used on a device without an on-device recognizer | Address conversion, voice recognition |
Addendum
(1) This Policy takes effect from 2026-09-01.
(2) The last revision date of this Policy is 2026-09-09.