Privacy Policy
Japanese version prevails
This document is provided in Japanese and English. In case of any discrepancy between the Japanese and English versions, the Japanese version shall prevail.
Article 1 Information Collected and Used
The Service collects and uses the following information. This includes personal information as defined in Article 2, Paragraph 1 of the Act on the Protection of Personal Information and personally linkable information as defined in Article 2, Paragraph 2 of the same Act, as well as information that does not constitute personal information.
The Service stores the following information on the device (in @react-native-async-storage/async-storage and in the app’s dedicated file area). The items in this table are not sent to any server (if any information is sent for advertising or similar purposes, it will be described in Article 8).
| Type of information stored |
Purpose |
| Onboarding completion status |
Controls first-launch tutorial display |
| Consent status for the Terms of Use and Privacy Policy (consent timestamp, accepted revision, display language, app version, OS type) |
Re-consent control when documents are revised |
| App settings (theme, session composition, volume, playback settings, display language, etc.) |
Cross-session restoration of user preferences |
| Custom Word Sets created by the User (names and word lists) |
Persistence of the Custom Word Sets feature |
| Management information for downloaded Premium audio (target, file count, size, completion timestamp, version) and the audio files themselves |
Offline playback of downloaded content |
In connection with use of the Service, the following information is transmitted to external providers. All such transmissions are encrypted via HTTPS.
| Recipient |
Information transmitted |
Purpose of transmission |
| RevenueCat, Inc. (United States) |
Anonymous customer ID (auto-generated by RevenueCat), purchase history and subscription status, billing provider identifier (Apple / Google) |
Determining subscription status and restoring purchases |
The Operator’s delivery server (assets.toapps.dev, operated on infrastructure of Cloudflare, Inc.) |
Anonymous customer ID (issued by RevenueCat) |
Verifying entitlement to download Premium audio. The Operator does not store this ID |
| Apple Inc. / Google LLC (United States) |
Information required for the purchase process (collected and managed by each store’s billing platform) |
Processing in-app purchases and restoring purchases |
| Expo, Inc. (United States / various) |
Technical information accompanying OTA update checks (OS type, app / runtime version, request timestamp) |
Delivery of OTA updates |
| GitHub, Inc. (United States) |
Ordinary web access information generated when a public URL (this Policy, the Terms of Use, etc.) is opened in the device browser |
Display of public pages |
Please also note the following.
- The Operator does not maintain a continuous database that accumulates User information. The delivery server above uses the anonymous customer ID it receives solely to verify download entitlement, and does not store it.
- Device and app information read by
expo-device (device manufacturer detection) and expo-constants (app version display) is used only on the device and is not transmitted externally.
- Notifications from the Service (such as detection of session interruptions) are generated only on the device; no information is transmitted externally for notification purposes (no push notification tokens are obtained).
The following information is used during sessions or temporarily, but is not persisted on the device or any server.
- Audio playback logs during sessions (held in memory only during playback, discarded when the session ends)
The Service does not collect the following information.
- Location data (GPS, etc.)
- Microphone or camera (
expo-audio is used for audio playback only; recording permissions are disabled)
- Contacts or photo library
- Advertising identifiers (IDFA / AAID) — not collected at this time. If they are introduced, this Policy will be revised and OS-level permission will be requested where required (
expo-tracking-transparency is not implemented as of the version of this Policy)
- Biometric data or HealthKit data
- User names, email addresses, or other personally identifiable information (Apple ID / Google Play account information is not obtained on the Service side)
Article 2 Purpose of Use
Information collected will be used only within the scope of the following purposes. The information will not be used beyond these purposes.
- Service provision and maintenance: Enabling and disabling features based on subscription status, subscription management, identifying the active plan (monthly / annual), and verifying entitlement to download Premium audio
- Persistence of user settings: Cross-session restoration of audio settings, theme settings, session settings, Custom Word Sets, and other preferences
- Customer support: Querying and verifying the RevenueCat customer ID for purchase restoration troubleshooting
- App improvement: Verifying behavior by OS version and confirming OTA update distribution status (crash analysis tools are not integrated as of the version of this Policy; only basic EAS Update logs are available at this time)
- Consent management: Re-consent control when the Terms of Use or Privacy Policy are revised
- Delivery and measurement of advertising (if introduced): If advertising is introduced, delivery of advertisements, understanding of impressions and responses, and measurement of effectiveness
Article 3 Provision to Third Parties / Joint Use
- Except where disclosure is required by law, Personal Data will not be provided to third parties without the individual User’s consent.
- Statistical information processed in a form that does not identify individuals may be used and published for the purpose of app improvement.
- If the business relating to the Service is succeeded to as a result of a merger, company split, business transfer, or other cause, the information collected may be transferred to the successor. Such provision does not constitute provision to a third party pursuant to Article 27, Paragraph 5, Item 2 of the Act on the Protection of Personal Information.
Article 4 Service Providers
The Service entrusts part of its operations to the following entities and delegates the handling of Personal Data to them as necessary.
| Service Provider |
Delegated Operations |
Location |
| RevenueCat, Inc. |
Purchase information management, subscription processing |
United States |
| Apple Inc. |
iOS app distribution, billing processing |
United States |
| Google LLC |
Android app distribution, billing processing (advertising delivery if advertising is introduced) |
United States |
| Cloudflare, Inc. |
Premium audio delivery and download entitlement verification, DNS, and inquiry email relay |
United States |
| Expo, Inc. |
OTA update distribution |
United States / Various |
| GitHub, Inc. |
Public URL hosting (GitHub Pages) |
United States |
Article 5 Cross-Border Transfer
- Some of the service providers listed in the preceding article are located outside Japan, and Personal Data may be transferred outside Japan as a result.
- All transfer destinations are located in the United States, and Personal Data is handled under safeguards based on the privacy policies and data processing terms published by each provider. Information regarding the personal information protection regimes of the destination countries will be provided upon request made to the contact listed in Article 14.
- As this Service is operated by an individual developer, large-scale ISMS certification has not been obtained; however, communications are encrypted via HTTPS, and the service providers comply with their respective privacy policies and security standards.
Article 6 Security Safeguards
- The following security safeguards are implemented to prevent leakage, loss, or damage of Personal Data.
- Data is stored in AsyncStorage and similar storage on the device; sensitive information (passwords, authentication tokens, payment information, etc.) is not stored
- Payment-related information is managed by the App Store / Google Play / RevenueCat and is not retained on the app side
- Communications use HTTPS (public URLs / RevenueCat API / Expo Updates / the Operator’s delivery server and the source from which Premium audio is delivered)
- This Service is operated by an individual developer and does not hold certification for a large-scale Information Security Management System (ISMS).
Article 7 Requests for Disclosure, Correction, or Cessation of Use
- Users may request disclosure, correction, or cessation of use of retained Personal Data.
- Requests should be sent to the contact email address listed in Article 14. For identity verification purposes, Users may be asked to provide information such as their RevenueCat customer ID.
- Upon receiving a request, a response will be provided within 30 days in principle. If the investigation requires additional time, the User will be notified of that fact and of the expected timing of the response.
- Information stored on the device is completely erased by uninstalling the app. Selecting “Settings” > “Reset to Defaults” within the app only initializes setting values; Custom Word Sets and the onboarding completion status are not deleted. Downloaded Premium audio can be deleted individually from the download management screen.
Article 8 Cookies / Tracking / Advertising
- The Service is a native app and does not use cookies (if equivalent identifiers are used for advertising or similar purposes, this Article will be revised).
- No advertising SDKs or tracking SDKs are integrated as of the version of this Policy.
- No analytics tools (such as Google Analytics / Firebase Analytics) are integrated as of the version of this Policy. If they are introduced, the service provider table in Article 4 and this Article will be revised.
Article 9 Use by Minors
- The Service is not directed to children under the age of 13, and the Service does not knowingly collect personal information from children under 13. If the Service learns that it has collected personal information from a child under 13, such information will be deleted promptly.
- Minors should use the Service with the consent of a parent or guardian.
- The Service does not provide a UI for age verification (soft consent model). Use under parental supervision is expected.
Article 10 Breach Notification
- In the event of leakage, loss, or damage of Personal Data, where the requirements prescribed by law are met, a report will be made to the Personal Information Protection Commission, and notification will be sent to Users who may be affected.
- Notification methods include in-Service announcements, email, or other appropriate means.
Article 11 Revision
- This Policy may be revised in response to changes in laws and regulations or changes in the Service.
- Revisions will be published via in-Service notifications and at a public URL.
- For material revisions (such as additions to the items collected or changes to the scope of third-party provision),
legalManifest.json’s minRequiredRevision will be updated, and Users may be required to re-consent.
Article 12 Notice for Users Residing in the United States and Canada
- The Operator does not sell or share personal information.
- The person responsible for the protection of personal information is the Operator himself/herself (the representative listed in Article 13). Contact details are as set out in Article 14.
- Users residing in Canada may request access to and correction of the personal information held by the Operator through the procedure set out in Article 7.
Article 13 Operator Information
| Item |
Content |
| Name (business name) |
<Operator’s name / business name> |
| Address |
<Operator’s business address> |
| Representative |
The same individual as the name above |
Article 14 Contact Information
For inquiries regarding this Policy, please contact the following.
- Email: <Operator’s contact email address>