← くもたん トップへ

プライバシーポリシー

くもたん(以下「本アプリ」といいます)の運営者(以下「運営者」といいます)は、本アプリにおけるユーザーの個人情報の取扱いについて、以下のとおりプライバシーポリシー(以下「本ポリシー」といいます)を定めます。

第1条(個人情報の定義)

「個人情報」とは、個人情報保護法にいう「個人情報」を指すものとし、生存する個人に関する情報であって、当該情報に含まれる氏名、生年月日、住所、電話番号、連絡先その他の記述等により特定の個人を識別できる情報(個人識別符号となるものを含む)を指します。

第2条(収集する情報)

本アプリは、以下の情報を取得する場合があります。

【1. Blueskyアカウント情報】

Bluesky OAuth認証を通じて以下の情報を取得します。

【2. 端末内に保存されるデータ】

以下のデータはユーザーの端末内に保存され、運営者のサーバーに送信されることはありません(単語データは【3】のとおり、ユーザー自身のPDSにも同期されます)。

【3. PDSに同期されるデータ】

AT Protocolの仕組みに基づき、以下のデータがユーザー自身のPDS(Personal Data Server)に同期されます。

PDSに保存されたデータは、AT Protocolの仕組み上、公開され、誰でも読むことができます。そのため、登録元の投稿の本文は同期しません。

【4. 外部サービスに送信されるデータ】

本アプリの機能を提供するため、以下のデータが外部サービスに送信されます。

【5. プッシュ通知トークン】

ユーザーがプッシュ通知を有効にした場合、以下の情報が運営者管理サーバー(Railway)に送信・保存されます。

これらの情報はプッシュ通知の送信目的にのみ使用します。プッシュ通知を無効にしたとき、またはログアウトしたときは、サーバーから削除します。アンインストールした場合は、通知の配信サービスがその端末に届けられないと報告した時点で削除します。

【6. フィードバック情報】

ユーザーがアプリ内のフィードバック機能を利用した場合、以下の情報がGoogle Apps Script経由で運営者に送信されます。

送信された内容は、運営者の非公開のGitHubリポジトリにIssueとして記録されます。

第3条(情報の利用目的)

運営者が情報を利用する目的は、以下のとおりです。

1. 本アプリの提供・運営のため

2. ユーザー認証およびBlueskyアカウントとの連携のため

3. 単語データの保存・復元機能を提供するため

4. 辞書検索、翻訳、テキスト解析等の学習支援機能を提供するため

5. ユーザーからのフィードバックに対応し、本アプリを改善するため

6. 本アプリの不具合の修正および機能改善のため

7. プッシュ通知(Blueskyのソーシャルアクション通知・学習リマインダー)の送信のため

第4条(個人情報の第三者提供)

1. 運営者は、次に掲げる場合を除いて、あらかじめユーザーの同意を得ることなく、第三者に個人情報を提供することはありません。

2. 本アプリは、ユーザーがAPIキーを設定した場合に、第2条【4】に記載した内容をGoogle AI Studio(Gemma)に送信します。これはユーザーが自ら設定したAPIキーに基づく送信であり、運営者による第三者提供には該当しません。

第5条(外部送信規律への対応)

電気通信事業法第27条の12(外部送信規律)に基づき、本アプリが利用者の情報を外部に送信する場合の詳細を以下のとおり開示します。

【Bluesky / AT Protocol(bsky.social)】

送信情報: タイムラインリクエスト、投稿内容、画像データ

運営者の目的: タイムライン表示・投稿機能の提供

送信先の目的: AT Protocolネットワークのサービス提供

【ユーザー自身のPDS】

送信情報: 単語データ(投稿の本文は含みません)

運営者の目的: クロスデバイス同期・復元機能の提供

送信先の目的: ユーザー自身のデータ管理

備考: PDSのデータは、AT Protocolの仕組み上、公開されます。

【cardyb API(bsky.app)】

送信情報: 投稿に含まれるURL

運営者の目的: リンクプレビュー(OGPカード)の取得

送信先の目的: URLのメタデータ抽出サービス提供

【Blueskyのモデレーションサービス】

送信情報: 通報した投稿またはアカウント、通報の理由

運営者の目的: 不適切な投稿の通報機能の提供

送信先の目的: Blueskyのモデレーション

【Google AI Studio — Gemma API(Google LLC)】

送信情報: 解説を求めた英単語、英作文モードで書いた英文と出題の例文、校正を求めた投稿の下書き(ユーザーがAPIキーを設定した場合のみ)

運営者の目的: AI機能(単語の解説・英作文の採点・投稿の校正)の提供

送信先の目的: AIテキスト生成サービスの提供

備考: Gemini APIの追加利用規約(2026年4月28日更新)では、無料枠で送信された内容と生成された応答は、Googleの製品の改善やモデルの学習に使われ、人が読むこともあると定められています。有料枠では、製品の改善には使われません。個人情報や機密情報は送信しないでください。

【Appleの音声認識(Apple Inc.)】

送信情報: クイズの音声入力を使ったときの音声

運営者の目的: クイズに音声で回答する機能の提供

送信先の目的: 音声認識サービスの提供

備考: 音声は端末内またはAppleのサーバーで文字に変換されます。

【Google Apps Script(運営者管理)】

送信情報: フィードバック内容

運営者の目的: フィードバック収集・サービス改善

送信先の目的: GitHub Issueへの転送

【Railway(運営者管理サーバー)】

送信情報: Bluesky DID、Expo Push Token、通知設定

運営者の目的: プッシュ通知の配信管理

送信先の目的: プッシュ通知サーバーの運営

【Expo Push Notification Service】

送信情報: Expo Push Token、通知タイトル・本文

運営者の目的: プッシュ通知のデバイス配信

送信先の目的: Expo通知配信サービスの提供

【GitHub(GitHub Pages・GitHub API)】

送信情報: なし(更新の確認とダウンロードのリクエストのみ)

運営者の目的: アプリと辞書の更新の確認、辞書データ(JMdict等)の取得

送信先の目的: ソフトウェアの配布・静的ファイルのホスティング

※ Google AI Studio(Gemma API)への送信は、ユーザーが自身のAPIキーを設定した場合にのみ発生します。運営者はこのAPIキーにアクセスできません。

※ 本アプリはアクセス解析・広告・トラッキングSDKを使用していません。

第6条(安全管理措置)

運営者は、個人情報の漏えい、滅失またはき損の防止その他の個人情報の安全管理のために、以下の措置を講じています。

第7条(アナリティクス・トラッキング)

本アプリは、アクセス解析ツール、広告配信SDK、トラッキングツール等を使用しておりません。ユーザーの行動データを収集・分析する機能は搭載していません。

第8条(端末のアクセス権限)

本アプリは、以下の端末機能へのアクセス許可を求める場合があります。

これらの権限は、ユーザーが該当する機能を利用する際にのみ求められ、許可しなくても本アプリの基本機能は利用できます。

第9条(データの削除)

1. ユーザーは、本アプリの設定画面から「すべてのデータを削除」を実行することにより、端末内に保存されたすべての学習データを削除できます。

2. ログアウトを行うことにより、端末内に保存された認証情報は削除されます。

3. PDSに同期されたデータの削除については、ユーザー自身のPDS管理に委ねられます。

4. 本アプリをアンインストールすることにより、端末内のすべてのデータが削除されます。

5. 削除されたデータは復元できません。ユーザーは、削除前に必要に応じてデータエクスポート機能を利用し、バックアップを行ってください。

第10条(未成年者の利用)

本アプリは、特に未成年者を対象としたサービスではありませんが、未成年者が利用する場合は、保護者の同意のもとで利用することを推奨します。

第11条(プライバシーポリシーの変更)

1. 運営者は、必要に応じて本ポリシーを変更することがあります。

2. 本ポリシーの変更は、本アプリ内または運営者のウェブサイト上で通知するものとします。

3. 変更後に本アプリの利用を継続した場合、ユーザーは変更後のポリシーに同意したものとみなします。

第12条(お問い合わせ窓口)

本ポリシーに関するお問い合わせは、下記の窓口までお願いいたします。

Privacy Policy

The operator (hereinafter the "Operator") of Kumotan (hereinafter "this App") establishes this Privacy Policy (hereinafter "this Policy") regarding the handling of users' personal information in this App.

Article 1 (Definition of Personal Information)

"Personal information" refers to "personal information" as defined in the Act on the Protection of Personal Information, meaning information about a living individual that can identify a specific individual by name, date of birth, address, telephone number, contact information, or other descriptions contained in the information (including personal identification codes).

Article 2 (Information We Collect)

This App may collect the following information:

[1. Bluesky Account Information]

The following information is obtained through Bluesky OAuth authentication:

[2. Data Stored on Device]

The following data is stored on the User's device and is not sent to the Operator's servers (word data is also synced to the User's own PDS, as described in [3]):

[3. Data Synced to PDS]

Based on the AT Protocol framework, the following data is synced to the User's own PDS (Personal Data Server):

Data stored in a PDS is public by design of the AT Protocol and can be read by anyone. For this reason, the text of the source post is not synced.

[4. Data Sent to External Services]

To provide this App's features, the following data is sent to external services:

[5. Push Notification Tokens]

When Users enable push notifications, the following information is sent to and stored on the Operator's server (Railway):

This information is used solely for push notification delivery. It is deleted from the server when the User disables push notifications or logs out. If the User uninstalls the App, it is deleted once the delivery service reports that the device can no longer receive notifications.

[6. Feedback Information]

When Users use the in-app feedback feature, the following information is sent to the Operator via Google Apps Script:

Submitted feedback is recorded as an issue in the Operator's private GitHub repository.

Article 3 (Purpose of Information Use)

The purposes for which the Operator uses information are as follows:

1. To provide and operate this App

2. For user authentication and linking with Bluesky accounts

3. To provide word data storage and restoration functions

4. To provide learning support functions such as dictionary search, translation, and text analysis

5. To respond to user feedback and improve this App

6. To fix bugs and improve features of this App

7. To send push notifications (Bluesky social action notifications and learning reminders)

Article 4 (Provision of Personal Information to Third Parties)

1. The Operator will not provide personal information to third parties without prior consent of the User, except in the following cases:

2. When the User has set their API key, this App sends the data listed in Article 2 [4] to Google AI Studio (Gemma). This transmission is based on the API key set by the User and does not constitute third-party provision by the Operator.

Article 5 (External Transmission Disclosure)

Pursuant to Article 27-12 of the Telecommunications Business Act (external transmission regulations), the Operator discloses the following details regarding cases where this App transmits user information externally.

[Bluesky / AT Protocol (bsky.social)]

Information sent: Timeline requests, post content, image data

Operator's purpose: Providing timeline display and posting features

Recipient's purpose: Providing AT Protocol network services

[User's own PDS]

Information sent: Word data (not including post text)

Operator's purpose: Providing cross-device sync and restoration

Recipient's purpose: User's own data management

Note: Data in a PDS is public by design of the AT Protocol.

[cardyb API (bsky.app)]

Information sent: URLs contained in posts

Operator's purpose: Fetching link previews (OGP cards)

Recipient's purpose: URL metadata extraction service

[Bluesky's moderation service]

Information sent: The reported post or account, and the reason

Operator's purpose: Providing the feature to report inappropriate posts

Recipient's purpose: Bluesky moderation

[Google AI Studio — Gemma API (Google LLC)]

Information sent: English words the User asks to have explained, sentences written in the sentence-writing quiz with the example sentence, and post drafts sent for proofreading (only when the User has set their API key)

Operator's purpose: Providing AI features (word explanations, sentence grading, post proofreading)

Recipient's purpose: AI text generation service

Note: Under the Gemini API Additional Terms of Service (updated April 28, 2026), content submitted through the unpaid tier and the generated responses are used to improve Google products and train models, and may be read by human reviewers. Content submitted through the paid tier is not used to improve products. Do not submit personal or confidential information.

[Apple's speech recognition (Apple Inc.)]

Information sent: The User's voice when using voice input in quizzes

Operator's purpose: Providing voice answers in quizzes

Recipient's purpose: Speech recognition service

Note: Voice is converted to text on the device or on Apple's servers.

[Google Apps Script (Operator-managed)]

Information sent: Feedback content

Operator's purpose: Feedback collection and service improvement

Recipient's purpose: Forwarding to GitHub Issues

[Railway (Operator-managed server)]

Information sent: Bluesky DID, Expo Push Token, notification settings

Operator's purpose: Managing push notification delivery

Recipient's purpose: Operating push notification server

[Expo Push Notification Service]

Information sent: Expo Push Token, notification title and body

Operator's purpose: Delivering push notifications to devices

Recipient's purpose: Expo notification delivery service

[GitHub (GitHub Pages, GitHub API)]

Information sent: None (update checks and download requests only)

Operator's purpose: Checking for app and dictionary updates, fetching dictionary data (JMdict, etc.)

Recipient's purpose: Software distribution and static file hosting

* Transmission to Google AI Studio (Gemma API) occurs only when the User has set their own API key. The Operator cannot access this key.

* This App does not use analytics, advertising, or tracking SDKs.

Article 6 (Security Measures)

The Operator takes the following measures for the security management of personal information to prevent leakage, loss, or damage:

Article 7 (Analytics and Tracking)

This App does not use analytics tools, advertising SDKs, or tracking tools. No features for collecting or analyzing user behavioral data are included.

Article 8 (Device Access Permissions)

This App may request access permissions to the following device features:

These permissions are only requested when the User uses the corresponding features, and the basic features of this App can be used without granting them.

Article 9 (Data Deletion)

1. Users can delete all learning data stored on the device by executing "Delete All Data" from the Settings screen of this App.

2. Logging out will delete authentication information stored on the device.

3. Deletion of data synced to PDS is left to the User's own PDS management.

4. Uninstalling this App will delete all data on the device.

5. Deleted data cannot be recovered. Users should use the data export function to create backups before deletion as needed.

Article 10 (Use by Minors)

This App is not specifically targeted at minors, but it is recommended that minors use it with parental consent.

Article 11 (Changes to Privacy Policy)

1. The Operator may change this Policy as needed.

2. Changes to this Policy will be notified within this App or on the Operator's website.

3. If a User continues to use this App after changes, the User shall be deemed to have agreed to the revised Policy.

Article 12 (Contact)

For inquiries regarding this Policy, please contact us through the following: