プライバシーポリシー

Privacy Policy

2026年7月19日 制定/2026年8月11日 改定(広告の導入)/2026年8月12日 改定(みんなの庭・バックアップの預かり)
Effective July 19, 2026 / revised August 11, 2026 (advertising) / revised August 12, 2026 (shared gardens and server-held backups)

要点

本ポリシーは、メモアプリ「めも庭」(memoniwa.app・以下「本アプリ」)における利用者情報の取り扱いを定めるものです。

1. 基本方針

本アプリはアカウント登録を必要とせず、氏名・メールアドレス・電話番号等の個人情報を取得しません。利用者が本アプリに書いた内容を運営者が収集・閲覧する仕組みはありません。

2. 端末内に保存される情報

以下の情報はすべて利用者の端末内にのみ保存され、外部へ送信されません。

3. 外部への送信が発生する場合

本アプリの外部通信は、以下の6つの場合に限られます。

上記以外の通信はありません。アクセス解析SDKは含まれていません。

広告について — 本アプリは Google AdMob による広告を表示します。表示する場所は次の2か所だけです。

メモを書く・読む・探す画面に広告は表示されません。バナー広告も置きません。広告SDKが利用者の書いた内容(メモの本文・品目・写真・共有した庭の中身)にアクセスすることはありません。

広告の配信にあたり、Google は表示回数の計測や不正防止のために、端末の種類・OSのバージョン・IPアドレスに基づくおおまかな地域等の情報を取得します。本アプリは iOS のトラッキング許可(ATT)を求めません。広告識別子(IDFA)を用いた追跡は行わず、iOS では利用者の趣味嗜好に基づかない広告のみが配信されます。Android では端末の広告設定(Google の広告ID)に応じてパーソナライズ広告が配信される場合があり、端末の設定からオプトアウトできます。欧州経済領域・英国等の利用者には、Google の同意フォームが表示されることがあります。Google のデータの取り扱いは Google のポリシー をご確認ください。

アプリ内購入の「広告を表示しない」(買い切り)をご購入いただくと、上記いずれの広告も表示されなくなります(消えものは広告なしでそのまま届きます)。

4. 共有リンクにおけるデータの取り扱い

共有カードをリンクまたはQRコードで送る際、カードの内容(メモンの姿と、設定に応じてタイトル・本文)は端末内で暗号化されたうえで、中継サーバーに一時保存されます。

共有リンクを作成する操作を行わないかぎり、この通信は発生しません。アプリ画面内に表示されるQRコードは通信を伴わず、端末内で生成されます。

5. 「みんなの庭」におけるデータの取り扱い

「みんなの庭」は、招待リンクを配って複数人が同じ庭を見る機能です。庭を作った人を「共有者」、招待リンクから参加した人を「参加者」と呼びます。この機能を利用したときに限り、以下のデータが中継サーバーに保存されます。

みんなの庭の内容が暗号化されている結果として、運営者は通報を受けてもサーバー上で中身を確認することができません。不適切な書き込みへの対応は、その庭の共有者による削除と、通報に基づく庭そのものの停止・削除によって行います(利用規約第6条)。

6. バックアップの預かりにおけるデータの取り扱い

「サーバーに預ける」は、機種変更や端末の紛失に備えて、庭のバックアップを運営者のサーバーで保管する機能です。既定では無効で、利用者がアプリの「バックアップ」画面で自分で選んだときにだけ有効になります。この機能を使わなくても、端末内の自動保存とファイルの手動書き出しはこれまでどおり利用できます。

7. β版のテレメトリ

βテスト版に限り、アプリの利用状況データ(テレメトリ)の送信について同意をお願いする場合があります。

8. 生成AIの利用について

利用者のメモや画像が生成AIへ送信されることはありません。なお、本アプリの開発工程の一部(イラスト制作等)には生成AIを使用しており、最終的な確認・調整は人間が行っています。

9. 第三者への提供

取得した情報を第三者に提供・販売することはありません(法令に基づく場合を除きます)。

10. 外部サービスの利用

共有カード・みんなの庭の暗号化データおよびβテレメトリの保管には、Cloudflare, Inc. のインフラを利用しています(アクセス権限は運営者のみが保有します。前述のとおり、これらの内容は運営者も読むことができません)。広告の配信には Google LLC(Google AdMob)を利用しています。決済は Apple および Google が、各社のプライバシーポリシーに基づいて行います。

11. 子どものプライバシー

本アプリはアカウント登録がなく、年齢を問わず個人情報の入力を求めません。利用者が書いた内容は端末内にとどまります。

「みんなの庭」に参加するときに入力する名前は、同じ庭の参加者に表示されます。本名である必要はなく、アプリ内でもその旨を案内しています。お子さまが利用する場合は、招待リンクの送り先と書き込む内容について保護者の方のご配慮をお願いします。

12. データの削除

13. 本ポリシーの改定

内容を変更する場合は、本ページで新しい内容と改定日を告知します。新たな情報の取得や送信を伴う重要な変更は、アプリ内でも告知します。

14. お問い合わせ

本ポリシーおよびデータの取り扱いに関するお問い合わせ・削除の申し出は、サポートページの窓口までお寄せください。利用条件については利用規約をご覧ください。

運営者: めも庭 開発者(個人開発)/連絡先: [email protected]

In short

  • Memos, photos, and location stay only on your device.
  • Data leaves your device only when you make a share link, or when you use a shared garden. What is sent is encrypted on your device, and nobody else — us included — can read it.
  • Beta telemetry is sent only by users who explicitly opted in, and it never contains what you wrote.

This Policy sets out how information about users is handled in the memo app “Memolet Garden” (memoniwa.app, “the App”).

1. Our approach

The App needs no account and collects no personal information such as your name, email address, or phone number. There is no mechanism by which we collect or view what you write in the App.

2. Information kept on your device

All of the following is stored only on your device and is not sent anywhere.

  • Memos and lists — stored only on your device.
  • Photos — the photo frame feature displays a photo from your device’s photo library inside the App. Photos are never sent anywhere. They are not part of the shared card data described below, and the photo itself is not part of a backup file.
  • Location — processed on your device only, and only for Where? reminders (a notification when you arrive at or leave a place you chose). Location is never sent anywhere. Using location is optional; every other feature works if you do not allow it.
  • Notifications — reminder notifications are local notifications that stay entirely on your device.
  • Backups — alongside automatic saving on the device, you can manually export a backup file with a passphrase, to a location you choose. By default nothing is sent to our server. Only if you choose “Save to the server” yourself is a copy encrypted on your device and then held on the server (Article 6).

3. When data leaves your device

The App communicates externally in these six cases only.

  • Making or fetching a share link (Article 4)
  • Making, joining, or syncing a shared garden (Article 5)
  • Holding a backup on the server (Article 6 — only if you choose it yourself)
  • In-app purchases — payment is handled by the App Store and Google Play. Payment details such as your name or card number never reach the App. Purchase status is checked on your device.
  • Fetching and showing ads (see “About advertising” below)
  • Beta telemetry, if you opted in (Article 7 — this feature does not exist at all in the public release)

There is no other communication. No analytics SDK is included.

About advertising — the App shows ads from Google AdMob, in these two places only.

  • Video ads (rewarded ads) — play only when you choose “Watch an ad” yourself. When it finishes, a treat, some weather, or fireworks arrives in your garden for that day. Not watching has no effect on how your Memolets grow.
  • Full-screen ads — shown once when you make a new shared garden. They are not shown to people joining, viewing, or answering.

No ads appear on the screens where you write, read, or search your memos, and there are no banner ads. The ad SDK has no access to what you have written — memo text, list items, photos, or the contents of a shared garden.

To deliver ads, Google collects information such as device type, OS version, and an approximate region derived from your IP address, in order to count impressions and prevent fraud. The App does not ask for iOS tracking permission (ATT). We do not track using the advertising identifier (IDFA), and on iOS only ads that are not based on your interests are delivered. On Android, personalised ads may be delivered according to your device’s advertising settings (Google advertising ID), and you can opt out from your device settings. Users in the European Economic Area, the UK, and elsewhere may be shown Google’s consent form. Please see Google’s policies for how Google handles data.

Buying the one-time in-app purchase “Remove ads” turns off both kinds of ad. Consumable extras still arrive as before, without an ad.

4. Data handling for share links

When you send a shared card as a link or a QR code, the contents of the card — how the Memolet looks, plus the title and text depending on your settings — are encrypted on your device and then held temporarily on a relay server.

  • Encryption and the key — the decryption key is in the part of the URL after the “#”. Browsers never send that part to the server, so only someone who has the URL can open the card, and nobody else — us included — can read it.
  • What the server stores — six things only: the card ID, the encrypted data, the time it was created, the time it expires, the maximum number of fetches, and how many times it has been fetched. No access logs such as IP addresses or device information are kept.
  • How long it is kept — when you make the link you choose 24 hours, 7 days, or 30 days. There is no unlimited option. Once past its expiry, a link can no longer be fetched and is deleted from the server automatically.
  • Disappears after one open — a link made with this setting is deleted from the server immediately after it is fetched once. An ordinary link without this setting has no fetch limit and stays valid until the expiry you chose.
  • After deletion — for up to 30 days afterwards, encrypted data only may remain in the infrastructure’s disaster-recovery backups. The decryption key does not exist on the server, so the contents cannot be read from that state.

This communication does not happen unless you actively make a share link. A QR code shown inside the App involves no communication; it is generated on your device.

5. Data handling for shared gardens

A shared garden lets several people see the same garden through an invite link. We call the person who made the garden the owner, and the people who joined from an invite link participants. Only when you use this feature is the following data stored on a relay server.

  • What is encrypted — the garden’s settings (its name, the choices in it, any banned words the owner added), the contents of Memolets (text, list items, calendar dates), the name you entered when joining, how each Memolet looks including fur colour and outfits, and votes. All of this is encrypted on your device with AES-256-GCM before it is sent and stored.
  • The encryption key — the garden key is only in the part of the invite link after the “#”. Browsers and apps never send that part to the server, so only someone who received the invite link can open the contents, and nobody else — us included — can read them.
  • What the server holds unencrypted — only the values needed to enforce limits on people and votes without reading anything: the garden ID, its capacity, the number of Memolets per person, the number of votes per person, whether it is closed, an update sequence number, and the creation and expiry times; plus, for each participant, an internal ID, a hash of a token issued to their device, their role (owner or participant), and when they joined. No access logs such as IP addresses or device information are kept.
  • Passphrases — if a garden has a passphrase, only a value hashed on the device together with the garden ID (SHA-256) is sent and stored. The passphrase itself never reaches the server. A passphrase is a gate that limits who can join; it does not make the encryption stronger.
  • About participants’ names — the name you enter when joining is shown to the other people in that garden. It does not have to be your real name. The name exists only inside the encrypted data, and participants cannot be identified by name on the server.
  • How long it is kept — a garden expires automatically on the day the owner chose when making it (45 days by default, at most 45 days ahead) and is completely deleted from the server. Viewing, writing, or joining does not extend it. The owner can change that day from the App (later than now, at most 45 days ahead; it can also be brought forward). There is no unlimited storage. An expired garden is treated exactly like a garden that does not exist.
  • How to delete it — when the owner ends the sharing, that garden’s data (settings, everyone’s Memolets, votes, and participant records) is deleted from the server immediately. The owner can also delete just one participant’s Memolet. Participants can leave the garden themselves.
  • After deletion — for up to 30 days afterwards, encrypted data only may remain in the infrastructure’s disaster-recovery backups. The decryption key does not exist on the server, so the contents cannot be read from that state.

Because the contents of a shared garden are encrypted, we cannot check them on the server even when we receive a report. Inappropriate posts are handled by deletion by that garden’s owner, and by suspending or deleting the garden itself on the basis of a report (Article 6 of the Terms of Use).

6. Data handling for server-held backups

“Save to the server” keeps a backup of your garden on our server, in case you change devices or lose one. It is off by default, and turns on only when you choose it yourself on the App’s Backup screen. Automatic saving on the device and manual export to a file work as before, whether or not you use this.

  • Encryption and the key — what is held is encrypted on your device. The key that decrypts it is derived on your device from the 16-word passphrase issued when you turn the feature on, and it is never sent to the server. Nobody else — us included — can read what is held. If you lose the passphrase, nobody, including us, can open it.
  • What the server holds unencrypted — only an ID that identifies the backup, a hash of the write key, the size of the data, and when it was stored and when it expires. Both the ID and the write key are derived from the passphrase, and the passphrase itself never reaches the server. No access logs such as IP addresses or device information are kept. No account is needed, and no name or email address is collected.
  • What is held — memos and lists, gardens and Memolets, outfits, and the record of what you bought. Photos in photo frames are not included — photos stay on your device.
  • Generations — the latest copy and the one before it are kept, so that an accidental overwrite can be undone.
  • How long it is kept — it expires and is deleted from the server 12 months after the last time the App stored or read it. It is extended automatically while you keep using the App. There is no unlimited storage.
  • How to delete it — choosing “Stop saving” on the App’s Backup screen deletes what is held on the server immediately. With the passphrase you can also delete it from another device.
  • After deletion — for up to 30 days afterwards, encrypted data only may remain in the infrastructure’s disaster-recovery backups. The decryption key does not exist on the server, so the contents cannot be read from that state.

7. Beta telemetry

In beta test builds only, we may ask you to consent to sending usage data (telemetry).

  • Opt-in — every feature works if you do not consent, and you can withdraw consent at any time from the settings.
  • What is sent — numeric codes representing the kind of action, rounded aggregate values, an anonymous ID that exists only for the beta period, and timestamps.
  • What is not sent — memo text, list item names, names you gave Memolets or gardens, and search terms are not sent. The structure of the transmitted data makes it impossible to include them, and the server checks for this a second time.
  • Storage and deletion — the receiving server keeps no access logs such as IP addresses either. All records are deleted within 30 days of the end of the beta test, and only anonymous aggregates are kept. If you withdraw from the beta, the relevant records are deleted within 30 days of your request.
  • Not in the public release — the public release does not contain the telemetry code at all, and a machine check at build time guarantees this.

8. About generative AI

Your memos and images are never sent to generative AI. Parts of building this App, such as illustration work, did use generative AI, with a human doing the final review and adjustment.

9. Sharing with third parties

We do not provide or sell the information we hold to third parties, except where required by law.

10. External services

Encrypted data for shared cards and shared gardens, and beta telemetry, are held on infrastructure provided by Cloudflare, Inc. (access rights are held by us alone; as described above, we cannot read these contents either). Ads are delivered by Google LLC (Google AdMob). Payment is handled by Apple and Google under their own privacy policies.

11. Children’s privacy

The App has no account registration and never asks anyone, of any age, to enter personal information. What you write stays on your device.

The name entered when joining a shared garden is shown to the other participants in that garden. It does not have to be a real name, and the App says so. If a child uses the App, we ask guardians to pay attention to who the invite link is sent to and what is written there.

12. Deleting data

  • Data on your device — deleting the App removes all data from the device, including memos, gardens, and settings. You can export a backup before deleting it.
  • Share links — manual deletion after creation is not supported, but every link is deleted at the expiry you chose, at most 30 days.
  • Shared gardens — deleted immediately when the owner ends the sharing. Participants can erase their own participation record by leaving (a Memolet placed in the garden can be deleted by the owner). If nobody does either, the garden is deleted automatically on the day it was set to disappear, at most 45 days ahead.
  • Server-held backups — deleted immediately with “Stop saving” on the App’s Backup screen. If you do nothing, it is deleted automatically 12 months after you last used it.
  • Beta telemetry records — deleted within 30 days of a request to support.

13. Changes to this Policy

If we change this Policy, we will post the new text and the revision date on this page. Important changes that involve collecting or sending new information will also be announced in the App.

14. Contact

For questions about this Policy or about how data is handled, and for deletion requests, please write to us through the Support page. For the conditions of use, see the Terms of Use.

Operator: the developer of Memolet Garden (an individual developer) / Contact: [email protected]

This English text is a translation provided for convenience. The Japanese version is the authoritative text, and it governs if the two differ.