このプライバシーポリシー(以下「本ポリシー」といいます。)は、Geneura株式会社(以下「当社」といいます。)が提供する iOS アプリ「PastPort」および関連するバックエンドサービス(Firebase、Cloud Functions 等を含みます。以下「本サービス」といいます。)における利用者の個人情報の取り扱いについて定めるものです。本サービスをご利用になる前に、本ポリシーをよくお読みいただき、ご同意の上ご利用ください。
第1条(個人情報の定義)
本ポリシーにおいて「個人情報」とは、生存する個人に関する情報であって、氏名、メールアドレスその他の記述により特定の個人を識別できる情報、または個人識別符号が含まれる情報をいいます。他の情報と照合することにより特定の個人を識別できる情報も個人情報に含まれます。
第2条(取得する情報及び取得方法)
当社は本サービスの提供に際し、以下の情報を利用者から取得します。取得は適正な手段により行い、偽りその他不正の手段により取得しません。
・アカウント情報
- 外部アカウント連携情報(Apple でサインイン、Google サインインの識別子)
- Apple / Google から提供される氏名およびメールアドレス(利用者が共有を選択した場合)
・プロフィール情報
- 表示名、ユーザーID(ハンドル)
- プロフィール画像・カバー画像・自署画像のファイル保存先
- カード記載項目(利用者が任意に入力した項目)
- 旅券の配色設定、登録順(serial)、発行国コード(端末の地域設定に基づく2文字コード)
- 公開範囲設定(非公開設定、フォロー承認設定等)
・投稿・コミュニケーション・行動履歴
- 投稿データ(画像ファイルの保存先、キャプション、お題情報、TRANSFER の系譜関係等)
- いいね、コメントの履歴
- フォロー、フォローリクエスト等の関係情報
- ブロックしているユーザーおよびブロックされているユーザーの情報
- ミュート(非表示)設定
・端末・アプリ情報および通知関連情報
- Firebase Cloud Messaging トークン
- 端末識別子(installation ID 等)
- OS情報、OSバージョン、アプリバージョン、言語設定
- プッシュ通知許可状態
・通報・サポート対応に関する情報
- 通報対象(対象の種類やID)、通報理由、通報内容の詳細、通報者の識別情報
・その他
- 本サービスの利用過程で当社が合理的に必要と判断する情報(IPアドレス、アクセスログ等)
第3条(利用目的)
当社は取得した個人情報を、以下の目的の範囲内で利用します。利用目的を変更する場合は、関連性を有すると合理的に認められる範囲を超えないものとし、変更内容を公表します。
- 本サービスの提供・運営およびユーザー認証のため
- 投稿、コメント、いいね、フォロー、TRANSFER 等のSNS機能提供のため
- プッシュ通知の配信(いいね・コメント・フォロー等の通知、運営からの連絡等)のため
- モデレーション、不正利用防止、スパム検知など安全性確保のため
- 通報対応、投稿やアカウントの審査、利用規約違反への対応のため
- 不具合対応や利用状況の把握、機能改善・品質向上のため
- マーケティング調査、新サービス・新機能の開発のため統計データを作成するため
- 個人情報の取扱いに関する各種法令・ガイドラインへの対応のため
第4条(第三者提供)
当社は以下の場合を除き、利用者の個人情報を第三者に提供しません。
- 利用者本人の同意がある場合
- 法令に基づく場合
- 人の生命・身体・財産の保護のために必要で、本人の同意を得ることが困難な場合
- 公衆衛生の向上や児童の健全育成の推進のために特に必要であり、本人の同意を得ることが困難な場合
- 国の機関、地方公共団体またはその委託を受けた者が法令の定める事務を遂行することに協力する必要がある場合で、本人の同意を得ることにより当該事務の遂行に支障を及ぼすおそれがあるとき
- 業務委託に伴い必要な範囲で個人情報の取扱いを委託する場合(第5条参照)
なお、本サービスはSNSであるため、表示名・ハンドル・プロフィール・公開設定の投稿等は、機能の性質上、他の利用者に公開されます。
第5条(外部サービスの利用・委託先への提供)
当社は、本サービスの運営に必要な範囲で以下の外部サービスを利用し、個人情報を送信する場合があります。各サービスとは必要な契約を締結し、適切な監督を行います。
Firebase(Google LLC)
- 利用目的:認証、データベース(Firestore)、ファイル保存(Storage)、バックエンド処理(Cloud Functions)、ホスティング、プッシュ通知等
- 送信される情報:アカウント情報、プロフィール情報、投稿データ、端末情報、通知トークン
- データ保管先:主に米国および東京リージョンを利用。国外移転に際しては個人情報保護法に従い、適切な措置を講じます。
- Firebase のプライバシーとセキュリティ:https://firebase.google.com/support/privacy?hl=ja
- Google プライバシーポリシー:https://policies.google.com/privacy?hl=ja
Apple でサインイン
- 利用目的:Apple アカウントを利用した認証およびログイン
- 送信される情報:Apple が当社に提供する識別子、利用者が共有を選択した氏名およびメールアドレス
- プライバシーに関する情報:https://www.apple.com/legal/privacy/data/en/sign-in-with-apple/
Google サインイン
- 利用目的:Google アカウントを利用した認証およびログイン
- 送信される情報:Google が当社に提供する識別子、氏名、メールアドレス
- Google プライバシーポリシー:https://policies.google.com/privacy?hl=ja
外部サービスへの情報提供は上記の利用目的に限定し、厳格な管理のもと行われます。各外部サービスにおける個人情報の取扱いの詳細については、上記リンク先の各社プライバシーポリシー等もあわせてご確認ください。
第6条(保存期間・削除)
当社は、利用目的の達成に必要な期間、個人情報を保管し、その後は速やかに削除または匿名化します。主な保存期間の目安は以下のとおりです。
- アプリ内通知:作成から約30日経過後、順次削除
- アカウント退会時:当社所定の削除手続きにより投稿・画像・関連データを削除(非同期処理のため一定期間を要する場合があります)
- 利用停止や更新により不要となったFCMトークン等:適宜削除
第7条(ユーザーの権利)
利用者は当社に対して、自己の個人情報の開示、訂正、追加、削除、利用停止または第三者提供の停止を求めることができます。請求の際は、本人確認のうえ合理的な範囲で対応いたします。詳細は第13条記載の窓口までお問い合わせください。アカウントの削除は、アプリ内の設定からいつでも行うことができます。
第8条(未成年の利用)
本サービスは原則として13歳以上の方を対象とします。未成年の利用者は、必要に応じて親権者等の同意を得たうえでご利用ください。13歳未満の児童から意図的に個人情報を収集しません。
第9条(端末権限)
本サービスは以下の端末権限を利用する場合があります。利用者は端末設定によりいつでも許可を変更できます。
- 写真ライブラリ:投稿用の画像選択、およびスタンプ入り画像の保存のため
- 通知:プッシュ通知の受信のため
許可を与えない場合でも、一部機能を除いて本サービスの利用は可能です。
第10条(広告識別子・トラッキング)
本サービスは現在、広告を配信しておらず、広告識別子(IDFA等)によるトラッキングも行っていません。将来これらを行う場合には、iOS の App Tracking Transparency(ATT)に基づき事前に利用者の許可を得るとともに、本ポリシーを改定して周知します。
第11条(安全管理措置)
当社は、個人情報の漏えい、滅失又は毀損を防止するため、アクセス権限管理や暗号化、不正アクセス対策、従業員・委託先への教育など、必要かつ適切な安全管理措置を講じます。個人情報の取扱いに関する事故が発生した場合には、法令に従い速やかに報告・公表し、被害拡大防止に努めます。
第12条(本ポリシーの変更)
当社は、法令やサービス内容の変更に応じて、本ポリシーを改定することがあります。改定後の本ポリシーは、当社ウェブサイト上の本ポリシーページの更新その他当社が適切と判断する方法により周知した時点から効力を生じます。なお、重要な変更を行う場合には、本サービス内またはウェブサイト上で分かりやすく周知し、必要に応じて利用者の同意を得ます。
第13条(お問い合わせ・個人情報取扱い窓口)
本ポリシーに関するお問い合わせ、開示等のお申し出、その他個人情報の取扱いに関するご質問・ご相談は、以下の窓口にて受け付けます。
お問い合わせ窓口:support@geneura.co.jp
第14条(事業者情報)
事業者名:Geneura株式会社
所在地:〒344-0067 埼玉県春日部市中央一丁目1番地5 小島ビル2階
This Privacy Policy ("Policy") describes how Geneura, Inc. ("Company," "we," "our," or "us") collects, uses, discloses, and otherwise processes personal data when you use our iOS app, PastPort, and associated backend services (including Firebase and Cloud Functions; collectively, the "Service"). By using PastPort, you agree to the practices described in this Policy.
1. Personal Data We Collect
Personal data means any information relating to an identified or identifiable natural person. We collect the following types of data through lawful and appropriate means:
Account Information: external login identifiers (Sign in with Apple, Google Sign-In); name and email address provided by Apple or Google where you choose to share them.
Profile Information: display name; user ID (handle); file paths for profile, cover and signature images; optional card fields; passport colour setting; registration serial number; issuing-country code (a two-letter code based on your device region); privacy settings (private account, follow-approval setting).
Posting, Communication and Activity History: post data (image file paths, captions, daily-theme information and TRANSFER lineage relationships); like and comment history; following/follower relationships and follow requests; information about blocked and blocking users; mute (hide) settings.
Device, App and Notification Information: Firebase Cloud Messaging tokens; device identifiers (installation ID, etc.); OS version, app version and language settings; push-notification permission status.
Reports and Support: reported target (type and ID), reason, details and the reporter's identifier.
Other: information we reasonably require in the course of operating the Service (IP addresses, access logs, etc.).
2. Purposes of Use
We use the collected data to:
- provide and operate the Service and authenticate users;
- provide social features such as posting, comments, likes, follows and TRANSFER;
- deliver push notifications (likes, comments, follows and service announcements);
- ensure safety, including moderation, fraud prevention and spam detection;
- handle reports, review content and accounts, and respond to violations of the Terms of Service;
- fix defects, understand usage and improve features and quality;
- create statistical data for research and development of new features; and
- comply with applicable laws and guidelines.
3. Third-Party Disclosure
We do not provide personal data to third parties except: with your consent; where required by law; where necessary to protect life, health or property and consent is difficult to obtain; where particularly necessary for public health or the sound development of children and consent is difficult to obtain; where cooperation with government agencies is required; or where processing is entrusted to service providers within the necessary scope (see Section 4).
Because the Service is a social network, your display name, handle, profile and public posts are visible to other users by design.
4. External Services and Processors
We use the following external services and may transmit personal data to them within the scope necessary to operate the Service:
Firebase (Google LLC)
- Purposes: authentication, database (Firestore), file storage (Storage), backend processing (Cloud Functions), hosting and push notifications.
- Data sent: account information, profile information, post data, device information and notification tokens.
- Storage locations: primarily the United States and Tokyo regions. Cross-border transfers are handled in accordance with applicable data-protection laws.
- Firebase Privacy and Security: https://firebase.google.com/support/privacy
- Google Privacy Policy: https://policies.google.com/privacy
Sign in with Apple
- Purposes: authentication using your Apple account.
- Data sent: identifiers provided by Apple, plus name and email address where you choose to share them.
- Details: https://www.apple.com/legal/privacy/data/en/sign-in-with-apple/
Google Sign-In
- Purposes: authentication using your Google account.
- Data sent: identifiers, name and email address provided by Google.
- Google Privacy Policy: https://policies.google.com/privacy
5. Retention and Deletion
We retain personal data only as long as necessary for the purposes above, then delete or anonymise it. Typical retention periods:
- In-app notifications: deleted progressively about 30 days after creation.
- Account deletion: posts, images and related data are deleted through our prescribed procedure (asynchronous processing may take some time).
- Expired FCM tokens and similar data: deleted as appropriate.
6. Your Rights
You may request disclosure, correction, addition, deletion, suspension of use or suspension of third-party provision of your personal data. We will respond within a reasonable scope after verifying your identity. You can delete your account at any time from the in-app settings. For requests, contact us at the address in Section 9.
7. Children
The Service is intended for users aged 13 or older. We do not knowingly collect personal data from children under 13. Minors should obtain consent from a parent or guardian where required.
8. Device Permissions, Advertising and Tracking
The Service may request the following device permissions, which you can change at any time in your device settings: Photo Library (to select images for posting and to save stamped images) and Notifications (to receive push notifications).
The Service currently displays no advertising and does not track users via advertising identifiers (such as IDFA). If this changes in the future, we will obtain prior permission through Apple's App Tracking Transparency (ATT) framework and update this Policy.
9. Security and Contact
We implement necessary and appropriate safeguards — access control, encryption, protection against unauthorised access and staff training — to prevent leakage, loss or damage of personal data. In the event of an incident, we will promptly report and disclose it in accordance with applicable laws.
We may revise this Policy in response to legal or service changes. Material changes will be announced clearly within the Service or on our website.
Contact: support@geneura.co.jp
Company: Geneura, Inc.
Address: Kojima Bldg. 2F, 1-1-5 Chuo, Kasukabe-shi, Saitama 344-0067, Japan
PASTPORT