Privacy Policy
The Japanese-language version is the authoritative text (see Section 15). The enactment date and the date of the most recent revision are not yet determined.
This document is a draft that has not yet undergone legal review.
This document is a draft prepared by the development team based on the app's specifications and technical design, and does not constitute legal advice. Before publication and submission to the App Store, it is planned to be reviewed by a professional (such as an attorney) with expertise in data protection law. Items that have not yet been determined are marked "TBD."
Table of Contents
- Summary
- 1. Introduction
- 2. Information We Collect
- 3. How Information Is Collected
- 4. Purposes of Use
- 5. Disclosure to and Entrustment with Third Parties
- 6. International Transfers
- 7. Retention Period and Deletion
- 8. User Rights
- 9. Security
- 10. Use by Minors
- 11. Cookies and Tracking
- 12. Contact
- 13. Changes to This Policy
- 14. Notes on AI-Generated Content
- 15. Governing Law
Summary (the formal provisions begin at Section 1)
| Service name | Watagumo |
|---|---|
| Provider | Kento Ito (no trade name) |
| What the app does | An iOS app that creates an AI character based on the user's own exported past conversation history, or on information entered by the user, and lets the user talk with that character |
| Main information collected | Apple user identifier, feature data extracted from conversation history, AI chat content, purchase information, device and usage information |
| Information not collected | Name, email address, phone number, address, location data, contacts, entire photo library, advertising ID |
| Disclosure to third parties | A portion of conversation data is sent to OpenAI, L.L.C. to generate AI responses (Section 5) |
| Storage location | Cloudflare, Inc.'s global infrastructure (including locations outside Japan) (Section 6) |
| Retention period | Until deleted by the user. Deletion requests are processed asynchronously after being received, and "Deleted" is not shown until completion has been confirmed (Section 7) |
| User rights | Data deletion and account deletion are available at any time from within the app (Section 8) |
| Minimum age | 17 or older |
| Regions served | Initial release: 8 regions — Japan, Taiwan, South Korea, the United States, Canada, Australia, New Zealand, and Singapore. Not currently offered in the EU/EEA or the UK (Section 6) |
| Contact | spw2jo2@gmail.com (Section 12) |
1. Introduction
Kento Ito ("we," "us," or "our") establishes this Privacy Policy ("this Policy") to govern the handling of personal information and other privacy-related information of users ("Users") of the iOS application "Watagumo" (the "App").
The App handles records of Users' extremely private conversations. We recognize that this information requires special care, and we design and operate the App giving priority to privacy and safety over adding new features.
Users are asked to agree to this Policy when they first start using the App. If you do not agree, you will not be able to use the App.
2. Information We Collect
2.1 Account information
| Information | Description | How it is obtained |
|---|---|---|
| Apple user identifier | A user identifier specific to this app, provided by Apple through "Sign in with Apple" | Obtained from Apple at sign-in |
| Internal user ID | A random identifier we automatically generate for each user | Generated by us |
The App's only authentication method is "Sign in with Apple." No password is ever set or stored.
We do not store the Apple user identifier in its original form; we convert it into a form that cannot be reversed (a hash value) before storing it. We do not collect names or email addresses. Even if you choose to share or not share your email address through "Sign in with Apple," we do not store that value.
2.2 Information related to imported conversation history
Users can load conversation history files that they have exported themselves from LINE, WhatsApp, KakaoTalk, and similar services into the App.
The original conversation history file (the file itself) is processed on the user's device and is never sent to or stored on our servers. After analysis on the device, only the following is sent to our servers.
| Information sent to the server | Example |
|---|---|
| Portions (samples) of the conversation extracted to analyze the characteristics of the AI character | Excerpts of representative exchanges |
| Conversation statistics | Average characters per message, emoji usage tendencies, reply intervals, etc. |
| Display name and icon set for the AI by the user | e.g. "○○" |
| AI profile generated from the analysis (characteristic data such as tone, sentence endings, and frequently used words) | — |
The extracted portion (sample) of the conversation includes statements made by third parties who appear in the conversation. After import, any temporary working files created on the device are deleted regardless of whether processing succeeds or fails. Original files remaining in the source app (such as LINE) or in the Files app are the user's own responsibility to manage and delete.
2.3 Information about AIs created from user input
Instead of using conversation history, users can also create an AI by entering text describing the other person's name, way of speaking, relationship, and topics of conversation. In this case, the content entered by the user is sent to and stored on our servers.
2.4 Chat information
| Information | Stored? |
|---|---|
| Text of messages the user sends to the AI | Stored |
| Text of responses generated by the AI | Stored |
| Date and time sent/received | Stored |
Chat content is stored on our servers so that conversation history can be viewed again later. It is also retained as a cache on the device for a certain period to allow offline viewing.
2.5 Purchase and billing information
| Information | Description |
|---|---|
| App Store purchase transaction information | Proof of purchase issued by Apple, product ID, purchase date and time (obtained via RevenueCat, Inc.) |
| Ticket balance and usage history | Records of grants and consumption |
| Subscription status | Active/expiration |
Payment method information such as credit card numbers is processed by Apple. Neither we nor RevenueCat ever collect it.
About purchase data being passed to RevenueCat (a third party). The App's billing infrastructure (purchase UI and receipt processing) uses RevenueCat, Inc. When you purchase tickets or subscribe, purchase transaction information issued by the Apple App Store (product ID, purchase date and time, transaction ID, auto-renewal status, etc.) reaches our servers via RevenueCat, Inc. (through a RevenueCat webhook notification). RevenueCat's role is limited to notifying us that a purchase has occurred based on this information; the granting, consumption, and balance management of tickets continues to be handled by our own servers (the balance itself is never entrusted to RevenueCat). Payment method information such as credit card numbers is processed by Apple and is never passed to us or to RevenueCat. Please refer to RevenueCat's own website for its privacy policy.
2.6 Device and usage information
| Information | Purpose |
|---|---|
| IP address | Preventing unauthorized use and excessive access (recorded in our application logs only after conversion into a form that cannot be reversed) |
| OS version, app version, language setting | Investigating issues, determining display language |
| Error type, API status code, processing time, request identifier | Incident response, quality improvement |
Our application logs never record the content of conversations, AI display names, entered profile text, file names, or similar content. However, Cloudflare's platform-level access logs record IP addresses and similar information for a certain period, in accordance with their own specifications.
2.7 Information we do not collect
For clarity, we state here what we do not collect.
- Name, date of birth, gender, address, phone number
- Email address (except when you contact us)
- Location data, contacts (address book), calendar, entire photo library
- Advertising identifier (IDFA), and tracking for advertising purposes
- Continuous access to the device microphone or camera
3. How Information Is Collected
- Direct input and actions by the user (sign-in, file selection, AI creation, sending chat messages)
- Automatic collection incidental to use of the App (IP address, app version, error information)
- Provided by Apple (user identifier at sign-in, purchase transaction verification results)
The App does not use cookies or tracking technologies for advertising purposes. Nor do we purchase or obtain information from third-party data brokers or similar sources.
4. Purposes of Use
We use the information we collect only for the following purposes.
| # | Purpose | Information involved |
|---|---|---|
| 1 | Authenticating users and separating data by user | Apple user identifier, internal user ID |
| 2 | Creating AI characters through analysis of conversation history, and storing the AI profile | Information extracted from imports, entered profile text |
| 3 | Providing the AI conversation feature (generating responses, displaying conversation history) | Chat content, AI profile |
| 4 | Managing ticket balances, and providing and verifying billing/subscriptions | Purchase information |
| 5 | Preventing unauthorized use, fraudulent billing, and excessive access | Converted IP address values, usage counts, converted purchase transaction identifier values |
| 6 | Incident response, investigating issues, improving service quality | Error type, processing time, request identifier |
| 7 | Responding to user inquiries | Information you provide when contacting us |
| 8 | Compliance with laws, and responding to violations of the Terms of Service | The necessary portion of the above |
We do not do the following.
- Sell the information we collect
- Use the content of conversations for advertising targeting
- Read the content of conversations ourselves for our own enjoyment, or show it to third parties (except at a user's explicit request for the purpose of investigating an issue)
- Use conversation content we have collected to train our own AI models
5. Disclosure to and Entrustment with Third Parties
5.1 Business operators we use to provide the service
| Operator | Role | Information disclosed/stored | Location |
|---|---|---|---|
| OpenAI, L.L.C. | AI analysis of conversation history, and generation of AI responses | See 5.2 | United States |
| Cloudflare, Inc. | Application runtime environment, database, file storage | All information described in this Policy as being stored, and the connecting IP address | United States (global network) |
| Apple Inc. | Sign-in, billing through the App Store, app distribution | User identifier, purchase information | United States and elsewhere |
| RevenueCat, Inc. | Mediation of App Store purchase processing (purchase UI, receipt processing, purchase notifications) | Purchase transaction information (product ID, purchase date and time, transaction ID, auto-renewal status), anonymous ID for purchases | United States |
The above are business operators to whom we entrust the handling of information under conditions we set.
5.2 About sending conversation data to OpenAI
To provide the App's core features — "creating an AI" and "talking with an AI" — we send a portion of the user's conversation data to an API provided by OpenAI, L.L.C.
| Situation | Content sent |
|---|---|
| AI creation (from conversation history) | Portions (samples) and statistics extracted from the imported conversation history. Not the full text of the conversation history |
| AI creation (from entered text) | Text entered by the user describing the other person's characteristics, way of speaking, relationship, etc. |
| Conversation with the AI | The text of messages sent by the user, a portion of the most recent exchange, and the AI profile (characteristic data such as tone) |
Information not sent: The original file or full text of imported conversation history files; account-identifying information such as the Apple user identifier or internal user ID; purchase information; IP address.
Data sent is handled in accordance with OpenAI's privacy policy and API terms of use. We use OpenAI's API under settings and conditions under which our API usage is not used to train OpenAI's models. OpenAI may retain sent data for a certain period for purposes such as monitoring for misuse; the retention period and conditions are as determined by OpenAI. There are limits to our ability to have data stored on OpenAI's side deleted, and deletion of data on our own servers (Sections 7 and 8) does not automatically extend to records on OpenAI's side.
As described above, the content of your conversations with the AI through the App is sent to OpenAI. Please keep this in mind, and avoid entering information you would not want sent.
5.3 Disclosure required by law
We may disclose information to the extent necessary, only where required by law, or where necessary to protect a person's life, body, or property and it is difficult to obtain the user's consent.
5.4 Business transfer
Information may be transferred in connection with a business transfer, merger, or similar event. In that case, the transferee will be required to handle the information in a manner equivalent to this Policy.
6. International Transfers
Data for the App is stored and processed on servers located outside Japan.
| Transfer | Operator | Country |
|---|---|---|
| Application runtime environment, database, file storage | Cloudflare, Inc. | United States (and a globally distributed network) |
| AI analysis and response generation | OpenAI, L.L.C. | United States |
| Authentication and billing | Apple Inc. | United States and elsewhere |
| Purchase processing mediation | RevenueCat, Inc. | United States |
By using the App, users are deemed to consent to these international transfers. Personal information protection systems in other countries may differ from those in Japan. For an overview of the protective measures taken by each operator, please refer to the information published by each company.
6.1 Regions where the App is offered
The App is currently offered only in the following 8 regions: Japan / Taiwan / South Korea / United States / Canada / Australia / New Zealand / Singapore.
The App is not currently offered in the EU (European Union), the EEA (European Economic Area), or the UK. This is because the App's coverage is geographically aligned with the regions supported by the provider of the AI API the App relies on, and use outside that provider's supported regions may result in the service being suspended under that provider's terms. The regions offered may change in the future. Please check the App Store listing for the most current information on regions offered.
7. Retention Period and Deletion
7.1 Retention period
| Information | Retention period |
|---|---|
| Account information, AI profiles, AI analysis data, chat history | Until deleted by the user (for as long as the account exists) |
| Original imported conversation history files | Not stored (deleted after processing on the device) |
| Session information (login state) | Up to 90 days. Deleted 7 days after expiration |
| Counters for preventing excessive access | 1 day |
| Job progress records | 7 days after completion |
| Converted purchase transaction identifier values | Retained even after account deletion |
| Our application logs | A short period following Cloudflare's default retention period. Not retained long-term |
7.2 How to delete data
Users can perform the following actions at any time from within the app.
| Action | Location | What is deleted | Ticket balance / purchase history |
|---|---|---|---|
| Delete an individual AI | AI list → AI settings | That AI's profile, analysis data, chat history, and icon image | Not affected |
| Delete all data | Settings → Data Management → Delete Data | All AIs and chat history (account remains) | Remains (purchased assets are not deleted, to avoid refund-related issues) |
| Delete account | Settings → Data Management → Delete Account | All of the above, plus account information and login information | Is erased |
A confirmation screen is shown before any of these actions is carried out. Deletion is processed asynchronously. When you perform an in-app action, we first complete acceptance of the deletion request; the actual deletion processing then proceeds in the background afterward. While processing is underway, the app shows "Deleting…" After deletion processing is complete, we automatically verify that nothing subject to deletion actually remains. The app will not show "Deleted" until this verification is complete. If verification reveals that something subject to deletion still remains, deletion processing is automatically retried.
The on-device cache is also discarded upon account deletion or logout. Deleting your account does not automatically cancel your App Store subscription. You must cancel separately through iOS Settings. This is also indicated on the account deletion confirmation screen.
7.3 Information that remains even after deletion
| Information that remains | Reason | Can it identify an individual? |
|---|---|---|
| A value obtained by converting the purchase transaction identifier into a form that cannot be reversed | To prevent fraudulent ticket acquisition through repeated reuse of the same purchase record. Retained without being linked to a user ID | No |
| Aggregated values not linked to any individual (such as total daily requests) | Operational monitoring of the service | No |
| Cloudflare's platform-level access logs | Per Cloudflare's specifications | May include IP addresses |
| Records retained by OpenAI and Apple | As determined by each company | As determined by each company |
7.4 Removal from backups
For disaster recovery purposes, our database has a mechanism that allows restoration to a point within a certain past period. Because of this, it may take a certain number of days after a deletion is carried out before the corresponding record on backups is removed. During this period, the data in question is never used to provide the service in the ordinary course.
8. User Rights
Users have the following rights regarding their own information.
| Right | How to exercise it |
|---|---|
| Right to request deletion | The in-app deletion feature (Section 7), or the contact address in Section 12 |
| Right to request disclosure (access) | Contact us at the address in Section 12. After confirming your identity, we will provide the information we hold about you in electronic form |
| Right to request correction | The AI's display name, etc. can be changed within the app. For anything else, contact us at the address in Section 12 |
| Right to request suspension of use | Contact us at the address in Section 12. This is generally handled by deleting your account |
| Right to withdraw consent | You may withdraw consent by stopping use of the App and deleting your account |
We generally respond to requests within a reasonable period. For identity verification, we plan to use methods such as presenting information displayed on the in-app settings screen. Users residing in the EU, the UK, and similar jurisdictions may separately be entitled to rights such as data portability, restriction of processing, and lodging a complaint with a supervisory authority.
9. Security
We take the following measures to protect the information we collect.
- All communications are encrypted (HTTPS)
- To ensure that only the authenticated user can access their own data, the user's identity is enforced server-side for every data operation
- Sensitive information such as the OpenAI API key is never included in the app itself (it is all managed server-side)
- Login information (tokens) is stored in the device's Keychain and is not synced to other devices or backups
- Our server-side logs are designed not to record the text of conversations or personally identifiable information
- We have implemented limits to prevent excessive access and misuse
That said, we cannot guarantee complete security for communications over the internet or for electronic storage.
9.1 About managing your device (an important request)
The App also retains conversation content on the user's device for a certain period. We ask that you protect the device itself, for example by setting a passcode or enabling Face ID. If your device is lent to a third party, the content of the App may be viewed by that person. Also, due to how iOS works, the App cannot prevent screenshots from being taken.
10. Use by Minors
- The App is intended for users 17 years of age or older.
- We do not intentionally collect information from anyone under the age of 13.
- If a minor uses the App, they should do so only with parental consent.
- If we discover that we have collected information from someone under 13, we will promptly delete that information. If you believe this may apply, please contact us at the address in Section 12.
11. Cookies and Tracking
- The App is a native app and does not use cookies for advertising purposes.
- We do not perform cross-app or cross-website tracking that would be subject to App Tracking Transparency (ATT). Accordingly, no tracking permission dialog is shown.
- Only information used to maintain login state and improve display speed is stored on the device.
12. Contact
For inquiries regarding this Policy and the handling of personal information, please contact us at the following.
| Operator name | Kento Ito (no trade name) |
|---|---|
| Email address | spw2jo2@gmail.com |
| Address | Disclosed by email without delay upon request (the same practice used for the Commercial Transactions Act disclosure; our target response time is within 3 business days of receipt) |
13. Changes to This Policy
We may revise this Policy in response to changes in law or in the App's content. If we make a change that has a material effect on users' rights, we will provide notice, such as through an in-app notification, before the change takes effect. If you continue using the App after a change takes effect, you are deemed to have agreed to the revised content. If you do not agree, please delete your account and discontinue use.
14. Notes on AI-Generated Content
The following is outside the scope of this Policy but is noted here as an important matter.
- The AI created through the App is a character generated from conversation history or user input, and is not the actual specific person.
- What the AI says does not represent the intentions, statements, or views of any real person.
- Content generated by the AI may include information that differs from fact.
15. Governing Law
The interpretation and application of this Policy are governed by the laws of Japan.
This page does not include internal-use documents such as a list of legal-review items or an implementation
checklist intended for the development team; those are managed separately as internal documents. The content
of this page is a public-facing rendering of Sections 0 through 15 of
privacy-policy-draft-ja.md (a draft that has not yet undergone legal review), and does not change
the meaning of any provision.