プライバシーポリシー
Privacy Policy
要点
- メモ・写真・位置情報は、利用者の端末内にのみ保存されます。
- 外部への送信が発生するのは、利用者が共有リンクを作成した場合と、複数人で使う「みんなの庭」を利用した場合のみです。送信されるデータは端末内で暗号化され、運営者を含む第三者は内容を読むことができません。
- β版のテレメトリ(利用状況データ)の送信は、明示的に同意した利用者のみが対象で、メモの内容を含みません。
本ポリシーは、メモアプリ「めも庭」(memoniwa.app・以下「本アプリ」)における利用者情報の取り扱いを定めるものです。
1. 基本方針
本アプリはアカウント登録を必要とせず、氏名・メールアドレス・電話番号等の個人情報を取得しません。利用者が本アプリに書いた内容を運営者が収集・閲覧する仕組みはありません。
2. 端末内に保存される情報
以下の情報はすべて利用者の端末内にのみ保存され、外部へ送信されません。
- メモ・リストの内容 — 端末内にのみ保存されます。
- 写真 — 「写真たて」機能は、端末のフォトライブラリ内の写真をアプリ内で表示するものです。写真が外部へ送信されることはありません。後述の共有カードのデータに写真は含まれず、バックアップファイルにも写真本体は含まれません。
- 位置情報 — 「どこで?」リマインダー(指定した場所への到着・離脱の通知)のためにのみ、端末内で処理されます。位置情報が外部へ送信されることはありません。位置情報の利用は任意であり、許可しない場合も他の機能はすべて利用できます。
- 通知 — リマインダーの通知は、端末内で完結するローカル通知です。
- バックアップ — 端末内の自動保存に加え、合言葉つきのバックアップファイルを手動で書き出せます。保存先は利用者が選択します。既定では運営者のサーバーへ送信されません。利用者が自分で「サーバーに預ける」を選んだ場合に限り、端末内で暗号化したうえでサーバーに保管されます(第6条)。
3. 外部への送信が発生する場合
本アプリの外部通信は、以下の6つの場合に限られます。
- 共有リンクの作成・取得(第4条)
- 「みんなの庭」の作成・参加・同期(第5条)
- バックアップの預かり(第6条。利用者が自分で選んだ場合のみ)
- アプリ内購入 — 決済は App Store / Google Play が行います。氏名・カード番号等の決済情報が本アプリに渡ることはありません。購入状態の確認も端末内で行います。
- 広告の取得・表示(下記「広告について」)
- β版でテレメトリに同意した場合(第7条。正式版にはこの機能自体が存在しません)
上記以外の通信はありません。アクセス解析SDKは含まれていません。
広告について — 本アプリは Google AdMob による広告を表示します。表示する場所は次の2か所だけです。
- 動画広告(リワード広告) — 利用者が「広告を見る」を自分で選んだときにだけ流れます。見終わると、その日かぎりの おやつ・お天気・花火 が庭に届きます。見なくてもメモンの育ちには影響しません。
- 全画面広告 — 「みんなの庭」を新しく作ったときに1回だけ表示されます。参加する側・見る側・回答する側には表示されません。
メモを書く・読む・探す画面に広告は表示されません。バナー広告も置きません。広告SDKが利用者の書いた内容(メモの本文・品目・写真・共有した庭の中身)にアクセスすることはありません。
広告の配信にあたり、Google は表示回数の計測や不正防止のために、端末の種類・OSのバージョン・IPアドレスに基づくおおまかな地域等の情報を取得します。本アプリは iOS のトラッキング許可(ATT)を求めません。広告識別子(IDFA)を用いた追跡は行わず、iOS では利用者の趣味嗜好に基づかない広告のみが配信されます。Android では端末の広告設定(Google の広告ID)に応じてパーソナライズ広告が配信される場合があり、端末の設定からオプトアウトできます。欧州経済領域・英国等の利用者には、Google の同意フォームが表示されることがあります。Google のデータの取り扱いは Google のポリシー をご確認ください。
アプリ内購入の「広告を表示しない」(買い切り)をご購入いただくと、上記いずれの広告も表示されなくなります(消えものは広告なしでそのまま届きます)。
4. 共有リンクにおけるデータの取り扱い
共有カードをリンクまたはQRコードで送る際、カードの内容(メモンの姿と、設定に応じてタイトル・本文)は端末内で暗号化されたうえで、中継サーバーに一時保存されます。
- 暗号化と復号鍵 — 復号鍵はURLの「#」以降の部分に含まれます。この部分はブラウザの仕様上サーバーへ送信されないため、URLを知る相手だけがカードを開くことができ、運営者を含む第三者は内容を読むことができません。
- サーバーが保存する情報 — カードID・暗号化データ・作成時刻・失効時刻・取得回数の上限・取得された回数の6項目のみです。IPアドレス・端末情報等のアクセスログは保存しません。
- 保存期間 — リンクの有効期限は、作成時に24時間・7日・30日のいずれかを選択します(無期限はありません)。期限を過ぎたリンクは取得できなくなり、サーバーからも自動的に削除されます。
- 1回で消える設定 — 「1回ひらいたら消える」を有効にして作成したリンクは、1回取得された時点でサーバーから即座に削除されます。この設定を使わない通常のリンクに取得回数の制限はなく、選択した期限まで有効です。
- 削除後の残存 — 削除後も、サーバー基盤の障害復旧用バックアップに最大30日間、暗号化データのみが残る場合があります。復号鍵はサーバーに存在しないため、この状態から内容が読まれることはありません。
共有リンクを作成する操作を行わないかぎり、この通信は発生しません。アプリ画面内に表示されるQRコードは通信を伴わず、端末内で生成されます。
5. 「みんなの庭」におけるデータの取り扱い
「みんなの庭」は、招待リンクを配って複数人が同じ庭を見る機能です。庭を作った人を「共有者」、招待リンクから参加した人を「参加者」と呼びます。この機能を利用したときに限り、以下のデータが中継サーバーに保存されます。
- 暗号化される情報 — 庭の設定(庭の名前・選択肢・共有者が追加した禁止語など)、メモンの中身(本文・品目・カレンダーの日付)、参加時に入力した名前、メモンの姿・毛色・着せ替えの見た目、投票先。これらはすべて端末内で AES-256-GCM により暗号化されたうえで送信・保存されます。
- 暗号化の鍵 — 庭の鍵は招待リンクの「#」以降の部分にのみ含まれます。この部分はブラウザ・アプリの仕様上サーバーへ送信されないため、招待リンクを受け取った人だけが内容を開くことができ、運営者を含む第三者は内容を読むことができません。
- サーバーが暗号化せずに持つ情報 — 中身を読まずに人数・票数の上限を守るための値だけです。具体的には、庭のID・定員・一人あたりのメモン数・持ち票数・締め切りの状態・更新の連番・作成時刻・失効時刻、および参加者ごとの内部ID・端末に発行した合言葉的なトークンのハッシュ値・役割(共有者か参加者か)・参加時刻です。IPアドレス・端末情報等のアクセスログは保存しません。
- 合言葉 — 庭に合言葉を設定した場合、端末側で庭IDを混ぜてハッシュ化した値(SHA-256)だけが送信・保存されます。合言葉そのものがサーバーへ渡ることはありません。合言葉は参加を制限するための門であり、暗号化の強度を高めるものではありません。
- 参加者の名前について — 参加時に入力した名前は、同じ庭の他の参加者に表示されます。本名を入力する必要はありません。名前は暗号化されたデータの中にのみ存在し、サーバー上で参加者を名前で識別することはできません。
- 保存期間 — 庭の作成時に共有者が決めた「消える日」(既定は45日後・最大で45日先まで)に自動的に失効し、サーバーから完全に削除されます。閲覧・書き込み・参加によって期限が延びることはありません。共有者はアプリからこの日を変更できます(いまより後・最大45日先。早めることもできます)。無期限の保存はありません。失効した庭は、存在しない庭と同じ扱いになります。
- 削除の方法 — 共有者が「共有を終了」すると、その庭のデータ(設定・全員のメモン・投票・参加者の記録)はサーバーから即座に削除されます。共有者は特定の参加者のメモンだけを削除することもできます。参加者は自分でその庭から退出できます。
- 削除後の残存 — 削除後も、サーバー基盤の障害復旧用バックアップに最大30日間、暗号化データのみが残る場合があります。復号鍵はサーバーに存在しないため、この状態から内容が読まれることはありません。
みんなの庭の内容が暗号化されている結果として、運営者は通報を受けてもサーバー上で中身を確認することができません。不適切な書き込みへの対応は、その庭の共有者による削除と、通報に基づく庭そのものの停止・削除によって行います(利用規約第6条)。
6. バックアップの預かりにおけるデータの取り扱い
「サーバーに預ける」は、機種変更や端末の紛失に備えて、庭のバックアップを運営者のサーバーで保管する機能です。既定では無効で、利用者がアプリの「バックアップ」画面で自分で選んだときにだけ有効になります。この機能を使わなくても、端末内の自動保存とファイルの手動書き出しはこれまでどおり利用できます。
- 暗号化と鍵 — 預けるデータは端末内で暗号化されます。暗号を解く鍵は、有効にしたときに発行される「合言葉」(16語)から利用者の端末で作られ、サーバーへ送信されることはありません。したがって、運営者を含む第三者が預かりの内容を読むことはできません。合言葉を紛失した場合、運営者を含め誰も預かりを開くことができません。
- サーバーが暗号化せずに持つ情報 — 預かりを識別するためのID・書き込み用の鍵のハッシュ値・データの大きさ・預かった日時・失効日時だけです。IDと書き込み用の鍵はいずれも合言葉から作られた値で、合言葉そのものはサーバーへ渡りません。IPアドレス・端末情報等のアクセスログは保存しません。アカウントの登録は不要で、氏名・メールアドレス等は一切取得しません。
- 預かる内容 — メモ・リストの内容、庭とメモン、着せかえ、購入した品の記録が含まれます。写真たての写真は含まれません(写真は端末内にとどまります)。
- 保存の世代 — 最新のものと、その1つ前の2世代を保管します(誤って上書きしたときに戻せるようにするためです)。
- 保存期間 — 最後にアプリから預けた時、または読み出した時から12か月で自動的に失効し、サーバーから削除されます。アプリを使い続けている間は自動的に延長されます。無期限の保存はありません。
- 削除の方法 — アプリの「バックアップ」画面で「やめる」を選ぶと、サーバーの預かりは即座に削除されます。合言葉があれば、別の端末からも削除できます。
- 削除後の残存 — 削除後も、サーバー基盤の障害復旧用バックアップに最大30日間、暗号化データのみが残る場合があります。復号鍵はサーバーに存在しないため、この状態から内容が読まれることはありません。
7. β版のテレメトリ
βテスト版に限り、アプリの利用状況データ(テレメトリ)の送信について同意をお願いする場合があります。
- 任意の同意制 — 同意しない場合もすべての機能を利用できます。同意は設定からいつでも撤回できます。
- 送信される情報 — 操作の種類を表す数値コード・丸められた集計値・β期間限定の匿名ID・タイムスタンプのみです。
- 送信されない情報 — メモの本文・品目名・メモンや庭につけた名前・検索語は送信されません。これらは送信データの構造上含めることができない設計とし、サーバー側でも二重に検査しています。
- 保存と削除 — 送信先のサーバーでもIPアドレス等のアクセスログは保存しません。記録はβテスト終了後30日以内にすべて削除し、匿名の集計結果のみを保持します。β参加を取りやめる場合は、申し出から30日以内に該当の記録を削除します。
- 正式版には存在しません — 正式版のアプリにはテレメトリのコード自体が含まれません(ビルド時の機械検査により保証しています)。
8. 生成AIの利用について
利用者のメモや画像が生成AIへ送信されることはありません。なお、本アプリの開発工程の一部(イラスト制作等)には生成AIを使用しており、最終的な確認・調整は人間が行っています。
9. 第三者への提供
取得した情報を第三者に提供・販売することはありません(法令に基づく場合を除きます)。
10. 外部サービスの利用
共有カード・みんなの庭の暗号化データおよびβテレメトリの保管には、Cloudflare, Inc. のインフラを利用しています(アクセス権限は運営者のみが保有します。前述のとおり、これらの内容は運営者も読むことができません)。広告の配信には Google LLC(Google AdMob)を利用しています。決済は Apple および Google が、各社のプライバシーポリシーに基づいて行います。
11. 子どものプライバシー
本アプリはアカウント登録がなく、年齢を問わず個人情報の入力を求めません。利用者が書いた内容は端末内にとどまります。
「みんなの庭」に参加するときに入力する名前は、同じ庭の参加者に表示されます。本名である必要はなく、アプリ内でもその旨を案内しています。お子さまが利用する場合は、招待リンクの送り先と書き込む内容について保護者の方のご配慮をお願いします。
12. データの削除
- 端末内のデータ — アプリを削除すると、メモ・庭・設定等のすべてのデータが端末から削除されます(削除前に、バックアップの書き出しを利用できます)。
- 共有リンク — 作成後の手動削除には対応していませんが、選択した期限(最長30日)で必ず削除されます。
- みんなの庭 — 共有者による「共有の終了」で即座に削除されます。参加者は退出により自分の参加の記録を消せます(庭に置いたメモンは共有者が削除できます)。いずれの操作もない場合も、作成時に決めた「消える日」(最大45日先)に自動的に削除されます。
- バックアップの預かり — アプリの「バックアップ」画面の「やめる」で即座に削除されます。操作がない場合も、最終利用から12か月で自動的に削除されます。
- βテレメトリの記録 — サポート窓口への申し出により、30日以内に削除します。
13. 本ポリシーの改定
内容を変更する場合は、本ページで新しい内容と改定日を告知します。新たな情報の取得や送信を伴う重要な変更は、アプリ内でも告知します。
14. お問い合わせ
本ポリシーおよびデータの取り扱いに関するお問い合わせ・削除の申し出は、サポートページの窓口までお寄せください。利用条件については利用規約をご覧ください。
運営者: めも庭 開発者(個人開発)/連絡先: [email protected]
In short
- Memos, photos, and location stay only on your device.
- Data leaves your device only when you make a share link, or when you use a shared garden. What is sent is encrypted on your device, and nobody else — us included — can read it.
- Beta telemetry is sent only by users who explicitly opted in, and it never contains what you wrote.
This Policy sets out how information about users is handled in the memo app “Memolet Garden” (memoniwa.app, “the App”).
1. Our approach
The App needs no account and collects no personal information such as your name, email address, or phone number. There is no mechanism by which we collect or view what you write in the App.
2. Information kept on your device
All of the following is stored only on your device and is not sent anywhere.
- Memos and lists — stored only on your device.
- Photos — the photo frame feature displays a photo from your device’s photo library inside the App. Photos are never sent anywhere. They are not part of the shared card data described below, and the photo itself is not part of a backup file.
- Location — processed on your device only, and only for Where? reminders (a notification when you arrive at or leave a place you chose). Location is never sent anywhere. Using location is optional; every other feature works if you do not allow it.
- Notifications — reminder notifications are local notifications that stay entirely on your device.
- Backups — alongside automatic saving on the device, you can manually export a backup file with a passphrase, to a location you choose. By default nothing is sent to our server. Only if you choose “Save to the server” yourself is a copy encrypted on your device and then held on the server (Article 6).
3. When data leaves your device
The App communicates externally in these six cases only.
- Making or fetching a share link (Article 4)
- Making, joining, or syncing a shared garden (Article 5)
- Holding a backup on the server (Article 6 — only if you choose it yourself)
- In-app purchases — payment is handled by the App Store and Google Play. Payment details such as your name or card number never reach the App. Purchase status is checked on your device.
- Fetching and showing ads (see “About advertising” below)
- Beta telemetry, if you opted in (Article 7 — this feature does not exist at all in the public release)
There is no other communication. No analytics SDK is included.
About advertising — the App shows ads from Google AdMob, in these two places only.
- Video ads (rewarded ads) — play only when you choose “Watch an ad” yourself. When it finishes, a treat, some weather, or fireworks arrives in your garden for that day. Not watching has no effect on how your Memolets grow.
- Full-screen ads — shown once when you make a new shared garden. They are not shown to people joining, viewing, or answering.
No ads appear on the screens where you write, read, or search your memos, and there are no banner ads. The ad SDK has no access to what you have written — memo text, list items, photos, or the contents of a shared garden.
To deliver ads, Google collects information such as device type, OS version, and an approximate region derived from your IP address, in order to count impressions and prevent fraud. The App does not ask for iOS tracking permission (ATT). We do not track using the advertising identifier (IDFA), and on iOS only ads that are not based on your interests are delivered. On Android, personalised ads may be delivered according to your device’s advertising settings (Google advertising ID), and you can opt out from your device settings. Users in the European Economic Area, the UK, and elsewhere may be shown Google’s consent form. Please see Google’s policies for how Google handles data.
Buying the one-time in-app purchase “Remove ads” turns off both kinds of ad. Consumable extras still arrive as before, without an ad.
4. Data handling for share links
When you send a shared card as a link or a QR code, the contents of the card — how the Memolet looks, plus the title and text depending on your settings — are encrypted on your device and then held temporarily on a relay server.
- Encryption and the key — the decryption key is in the part of the URL after the “#”. Browsers never send that part to the server, so only someone who has the URL can open the card, and nobody else — us included — can read it.
- What the server stores — six things only: the card ID, the encrypted data, the time it was created, the time it expires, the maximum number of fetches, and how many times it has been fetched. No access logs such as IP addresses or device information are kept.
- How long it is kept — when you make the link you choose 24 hours, 7 days, or 30 days. There is no unlimited option. Once past its expiry, a link can no longer be fetched and is deleted from the server automatically.
- Disappears after one open — a link made with this setting is deleted from the server immediately after it is fetched once. An ordinary link without this setting has no fetch limit and stays valid until the expiry you chose.
- After deletion — for up to 30 days afterwards, encrypted data only may remain in the infrastructure’s disaster-recovery backups. The decryption key does not exist on the server, so the contents cannot be read from that state.
This communication does not happen unless you actively make a share link. A QR code shown inside the App involves no communication; it is generated on your device.
5. Data handling for shared gardens
A shared garden lets several people see the same garden through an invite link. We call the person who made the garden the owner, and the people who joined from an invite link participants. Only when you use this feature is the following data stored on a relay server.
- What is encrypted — the garden’s settings (its name, the choices in it, any banned words the owner added), the contents of Memolets (text, list items, calendar dates), the name you entered when joining, how each Memolet looks including fur colour and outfits, and votes. All of this is encrypted on your device with AES-256-GCM before it is sent and stored.
- The encryption key — the garden key is only in the part of the invite link after the “#”. Browsers and apps never send that part to the server, so only someone who received the invite link can open the contents, and nobody else — us included — can read them.
- What the server holds unencrypted — only the values needed to enforce limits on people and votes without reading anything: the garden ID, its capacity, the number of Memolets per person, the number of votes per person, whether it is closed, an update sequence number, and the creation and expiry times; plus, for each participant, an internal ID, a hash of a token issued to their device, their role (owner or participant), and when they joined. No access logs such as IP addresses or device information are kept.
- Passphrases — if a garden has a passphrase, only a value hashed on the device together with the garden ID (SHA-256) is sent and stored. The passphrase itself never reaches the server. A passphrase is a gate that limits who can join; it does not make the encryption stronger.
- About participants’ names — the name you enter when joining is shown to the other people in that garden. It does not have to be your real name. The name exists only inside the encrypted data, and participants cannot be identified by name on the server.
- How long it is kept — a garden expires automatically on the day the owner chose when making it (45 days by default, at most 45 days ahead) and is completely deleted from the server. Viewing, writing, or joining does not extend it. The owner can change that day from the App (later than now, at most 45 days ahead; it can also be brought forward). There is no unlimited storage. An expired garden is treated exactly like a garden that does not exist.
- How to delete it — when the owner ends the sharing, that garden’s data (settings, everyone’s Memolets, votes, and participant records) is deleted from the server immediately. The owner can also delete just one participant’s Memolet. Participants can leave the garden themselves.
- After deletion — for up to 30 days afterwards, encrypted data only may remain in the infrastructure’s disaster-recovery backups. The decryption key does not exist on the server, so the contents cannot be read from that state.
Because the contents of a shared garden are encrypted, we cannot check them on the server even when we receive a report. Inappropriate posts are handled by deletion by that garden’s owner, and by suspending or deleting the garden itself on the basis of a report (Article 6 of the Terms of Use).
6. Data handling for server-held backups
“Save to the server” keeps a backup of your garden on our server, in case you change devices or lose one. It is off by default, and turns on only when you choose it yourself on the App’s Backup screen. Automatic saving on the device and manual export to a file work as before, whether or not you use this.
- Encryption and the key — what is held is encrypted on your device. The key that decrypts it is derived on your device from the 16-word passphrase issued when you turn the feature on, and it is never sent to the server. Nobody else — us included — can read what is held. If you lose the passphrase, nobody, including us, can open it.
- What the server holds unencrypted — only an ID that identifies the backup, a hash of the write key, the size of the data, and when it was stored and when it expires. Both the ID and the write key are derived from the passphrase, and the passphrase itself never reaches the server. No access logs such as IP addresses or device information are kept. No account is needed, and no name or email address is collected.
- What is held — memos and lists, gardens and Memolets, outfits, and the record of what you bought. Photos in photo frames are not included — photos stay on your device.
- Generations — the latest copy and the one before it are kept, so that an accidental overwrite can be undone.
- How long it is kept — it expires and is deleted from the server 12 months after the last time the App stored or read it. It is extended automatically while you keep using the App. There is no unlimited storage.
- How to delete it — choosing “Stop saving” on the App’s Backup screen deletes what is held on the server immediately. With the passphrase you can also delete it from another device.
- After deletion — for up to 30 days afterwards, encrypted data only may remain in the infrastructure’s disaster-recovery backups. The decryption key does not exist on the server, so the contents cannot be read from that state.
7. Beta telemetry
In beta test builds only, we may ask you to consent to sending usage data (telemetry).
- Opt-in — every feature works if you do not consent, and you can withdraw consent at any time from the settings.
- What is sent — numeric codes representing the kind of action, rounded aggregate values, an anonymous ID that exists only for the beta period, and timestamps.
- What is not sent — memo text, list item names, names you gave Memolets or gardens, and search terms are not sent. The structure of the transmitted data makes it impossible to include them, and the server checks for this a second time.
- Storage and deletion — the receiving server keeps no access logs such as IP addresses either. All records are deleted within 30 days of the end of the beta test, and only anonymous aggregates are kept. If you withdraw from the beta, the relevant records are deleted within 30 days of your request.
- Not in the public release — the public release does not contain the telemetry code at all, and a machine check at build time guarantees this.
8. About generative AI
Your memos and images are never sent to generative AI. Parts of building this App, such as illustration work, did use generative AI, with a human doing the final review and adjustment.
9. Sharing with third parties
We do not provide or sell the information we hold to third parties, except where required by law.
10. External services
Encrypted data for shared cards and shared gardens, and beta telemetry, are held on infrastructure provided by Cloudflare, Inc. (access rights are held by us alone; as described above, we cannot read these contents either). Ads are delivered by Google LLC (Google AdMob). Payment is handled by Apple and Google under their own privacy policies.
11. Children’s privacy
The App has no account registration and never asks anyone, of any age, to enter personal information. What you write stays on your device.
The name entered when joining a shared garden is shown to the other participants in that garden. It does not have to be a real name, and the App says so. If a child uses the App, we ask guardians to pay attention to who the invite link is sent to and what is written there.
12. Deleting data
- Data on your device — deleting the App removes all data from the device, including memos, gardens, and settings. You can export a backup before deleting it.
- Share links — manual deletion after creation is not supported, but every link is deleted at the expiry you chose, at most 30 days.
- Shared gardens — deleted immediately when the owner ends the sharing. Participants can erase their own participation record by leaving (a Memolet placed in the garden can be deleted by the owner). If nobody does either, the garden is deleted automatically on the day it was set to disappear, at most 45 days ahead.
- Server-held backups — deleted immediately with “Stop saving” on the App’s Backup screen. If you do nothing, it is deleted automatically 12 months after you last used it.
- Beta telemetry records — deleted within 30 days of a request to support.
13. Changes to this Policy
If we change this Policy, we will post the new text and the revision date on this page. Important changes that involve collecting or sending new information will also be announced in the App.
14. Contact
For questions about this Policy or about how data is handled, and for deletion requests, please write to us through the Support page. For the conditions of use, see the Terms of Use.
Operator: the developer of Memolet Garden (an individual developer) / Contact: [email protected]
This English text is a translation provided for convenience. The Japanese version is the authoritative text, and it governs if the two differ.