Privacy Policy

Japanese version prevails

This document is provided in Japanese and English. In case of any discrepancy between the Japanese and English versions, the Japanese version shall prevail.

Article 1 Information Collected and Used

The Service collects and uses the following information. This includes personal information as defined in Article 2, Paragraph 1 of the Act on the Protection of Personal Information and personally linkable information as defined in Article 2, Paragraph 2 of the same Act, as well as information that does not constitute personal information.

1.1 Information Stored on the Device

The Service stores the following information on the device (in @react-native-async-storage/async-storage and in the app’s dedicated file area). The items in this table are not sent to any server (if any information is sent for advertising or similar purposes, it will be described in Article 8).

Type of information stored Purpose
Onboarding completion status Controls first-launch tutorial display
Consent status for the Terms of Use and Privacy Policy (consent timestamp, accepted revision, display language, app version, OS type) Re-consent control when documents are revised
App settings (theme, session composition, volume, playback settings, display language, etc.) Cross-session restoration of user preferences
Custom Word Sets created by the User (names and word lists) Persistence of the Custom Word Sets feature
Management information for downloaded Premium audio (target, file count, size, completion timestamp, version) and the audio files themselves Offline playback of downloaded content

1.2 List of Information Transmitted Externally

In connection with use of the Service, the following information is transmitted to external providers. All such transmissions are encrypted via HTTPS.

Recipient Information transmitted Purpose of transmission
RevenueCat, Inc. (United States) Anonymous customer ID (auto-generated by RevenueCat), purchase history and subscription status, billing provider identifier (Apple / Google) Determining subscription status and restoring purchases
The Operator’s delivery server (assets.toapps.dev, operated on infrastructure of Cloudflare, Inc.) Anonymous customer ID (issued by RevenueCat) Verifying entitlement to download Premium audio. The Operator does not store this ID
Apple Inc. / Google LLC (United States) Information required for the purchase process (collected and managed by each store’s billing platform) Processing in-app purchases and restoring purchases
Expo, Inc. (United States / various) Technical information accompanying OTA update checks (OS type, app / runtime version, request timestamp) Delivery of OTA updates
GitHub, Inc. (United States) Ordinary web access information generated when a public URL (this Policy, the Terms of Use, etc.) is opened in the device browser Display of public pages

Please also note the following.

1.3 Information Generated and Used In-App but Not Stored

The following information is used during sessions or temporarily, but is not persisted on the device or any server.

1.4 Information Not Collected (Explicit Statement)

The Service does not collect the following information.

Article 2 Purpose of Use

Information collected will be used only within the scope of the following purposes. The information will not be used beyond these purposes.

  1. Service provision and maintenance: Enabling and disabling features based on subscription status, subscription management, identifying the active plan (monthly / annual), and verifying entitlement to download Premium audio
  2. Persistence of user settings: Cross-session restoration of audio settings, theme settings, session settings, Custom Word Sets, and other preferences
  3. Customer support: Querying and verifying the RevenueCat customer ID for purchase restoration troubleshooting
  4. App improvement: Verifying behavior by OS version and confirming OTA update distribution status (crash analysis tools are not integrated as of the version of this Policy; only basic EAS Update logs are available at this time)
  5. Consent management: Re-consent control when the Terms of Use or Privacy Policy are revised
  6. Delivery and measurement of advertising (if introduced): If advertising is introduced, delivery of advertisements, understanding of impressions and responses, and measurement of effectiveness

Article 3 Provision to Third Parties / Joint Use

  1. Except where disclosure is required by law, Personal Data will not be provided to third parties without the individual User’s consent.
  2. Statistical information processed in a form that does not identify individuals may be used and published for the purpose of app improvement.
  3. If the business relating to the Service is succeeded to as a result of a merger, company split, business transfer, or other cause, the information collected may be transferred to the successor. Such provision does not constitute provision to a third party pursuant to Article 27, Paragraph 5, Item 2 of the Act on the Protection of Personal Information.

Article 4 Service Providers

The Service entrusts part of its operations to the following entities and delegates the handling of Personal Data to them as necessary.

Service Provider Delegated Operations Location
RevenueCat, Inc. Purchase information management, subscription processing United States
Apple Inc. iOS app distribution, billing processing United States
Google LLC Android app distribution, billing processing (advertising delivery if advertising is introduced) United States
Cloudflare, Inc. Premium audio delivery and download entitlement verification, DNS, and inquiry email relay United States
Expo, Inc. OTA update distribution United States / Various
GitHub, Inc. Public URL hosting (GitHub Pages) United States

Article 5 Cross-Border Transfer

  1. Some of the service providers listed in the preceding article are located outside Japan, and Personal Data may be transferred outside Japan as a result.
  2. All transfer destinations are located in the United States, and Personal Data is handled under safeguards based on the privacy policies and data processing terms published by each provider. Information regarding the personal information protection regimes of the destination countries will be provided upon request made to the contact listed in Article 14.
  3. As this Service is operated by an individual developer, large-scale ISMS certification has not been obtained; however, communications are encrypted via HTTPS, and the service providers comply with their respective privacy policies and security standards.

Article 6 Security Safeguards

  1. The following security safeguards are implemented to prevent leakage, loss, or damage of Personal Data.
    • Data is stored in AsyncStorage and similar storage on the device; sensitive information (passwords, authentication tokens, payment information, etc.) is not stored
    • Payment-related information is managed by the App Store / Google Play / RevenueCat and is not retained on the app side
    • Communications use HTTPS (public URLs / RevenueCat API / Expo Updates / the Operator’s delivery server and the source from which Premium audio is delivered)
  2. This Service is operated by an individual developer and does not hold certification for a large-scale Information Security Management System (ISMS).

Article 7 Requests for Disclosure, Correction, or Cessation of Use

  1. Users may request disclosure, correction, or cessation of use of retained Personal Data.
  2. Requests should be sent to the contact email address listed in Article 14. For identity verification purposes, Users may be asked to provide information such as their RevenueCat customer ID.
  3. Upon receiving a request, a response will be provided within 30 days in principle. If the investigation requires additional time, the User will be notified of that fact and of the expected timing of the response.
  4. Information stored on the device is completely erased by uninstalling the app. Selecting “Settings” > “Reset to Defaults” within the app only initializes setting values; Custom Word Sets and the onboarding completion status are not deleted. Downloaded Premium audio can be deleted individually from the download management screen.

Article 8 Cookies / Tracking / Advertising

  1. The Service is a native app and does not use cookies (if equivalent identifiers are used for advertising or similar purposes, this Article will be revised).
  2. No advertising SDKs or tracking SDKs are integrated as of the version of this Policy.
  3. No analytics tools (such as Google Analytics / Firebase Analytics) are integrated as of the version of this Policy. If they are introduced, the service provider table in Article 4 and this Article will be revised.

Article 9 Use by Minors

  1. The Service is not directed to children under the age of 13, and the Service does not knowingly collect personal information from children under 13. If the Service learns that it has collected personal information from a child under 13, such information will be deleted promptly.
  2. Minors should use the Service with the consent of a parent or guardian.
  3. The Service does not provide a UI for age verification (soft consent model). Use under parental supervision is expected.

Article 10 Breach Notification

  1. In the event of leakage, loss, or damage of Personal Data, where the requirements prescribed by law are met, a report will be made to the Personal Information Protection Commission, and notification will be sent to Users who may be affected.
  2. Notification methods include in-Service announcements, email, or other appropriate means.

Article 11 Revision

  1. This Policy may be revised in response to changes in laws and regulations or changes in the Service.
  2. Revisions will be published via in-Service notifications and at a public URL.
  3. For material revisions (such as additions to the items collected or changes to the scope of third-party provision), legalManifest.json’s minRequiredRevision will be updated, and Users may be required to re-consent.

Article 12 Notice for Users Residing in the United States and Canada

  1. The Operator does not sell or share personal information.
  2. The person responsible for the protection of personal information is the Operator himself/herself (the representative listed in Article 13). Contact details are as set out in Article 14.
  3. Users residing in Canada may request access to and correction of the personal information held by the Operator through the procedure set out in Article 7.

Article 13 Operator Information

Item Content
Name (business name) <Operator’s name / business name>
Address <Operator’s business address>
Representative The same individual as the name above

Article 14 Contact Information

For inquiries regarding this Policy, please contact the following.