Oshily プライバシーポリシー
カタラボ(以下「当社」)は、アプリ「Oshily」(以下「本アプリ」)における利用者の情報の取り扱いを、次のとおり定めます。
1. 基本方針 ── 端末を主な保存先に
本アプリは、アカウント登録なしで利用できます。法的な氏名・メールアドレス・電話番号の登録は求めません。アプリ内で呼ばれたい名前は任意で入力できます。
会話・記憶・生成した画像・音声・プロフィール設定の主な保存先は、利用者の端末です。当社の Cloud Functions/Firestore には通常、内容を保存しません。生成機能を使うときは、必要な内容が下記のAI提供元へ送信されます。ただし、利用者が明示的に報告したAI生成メッセージは安全確認のため保存します。
そのかわり、アプリの削除や機種変更でデータは失われます。この点は利用規約にも明記しています。
2. 取得する情報
(1) 端末を主な保存先とする情報
- 会話の履歴・記憶・関係性などの設定
- 生成された画像・音声のキャッシュ
- 表示設定・言語設定・プラン利用状況のカウント
(2) 機能の提供のために外部へ送信される情報
| 情報 | 送信先 | 目的 | 保存 |
|---|---|---|---|
| 会話、記憶、プロフィール、キャラクター・場面設定のうち生成に必要な文章 | OpenAI(当社のCloud Functions経由) | 返答・記憶・画像用説明文の生成 | 当社サーバーには保存しない。OpenAI側の取扱いは下記参照 |
| 画像生成用の説明文(会話・容姿・場面の要約を含む) | OpenAI(同上) | 画像の生成 | 同上 |
| 読み上げるキャラクターのセリフ | xAI(同上) | 音声の生成 | 当社サーバーには保存しない。xAI側の取扱いは下記参照 |
| 利用者が選択したプロフィール写真・会話で見せる写真 | OpenAI(同上) | 内容を文章に変換する一度きりの解析 | 当社サーバーには保存しない。端末には写真と説明文を保存 |
| 匿名ID | Google Firebase | 端末の識別・不正利用の防止 | Firebaseの認証基盤に保存 |
| 端末が正規のアプリであることの証明(App Check:iOSはApp Attest、AndroidはPlay Integrity) | Apple/Google/Google Firebase | 本アプリ以外からの不正な呼び出しの遮断 | 検証用のトークンのみ。会話の内容や利用者を特定する情報は含まない |
| IPアドレス、リクエスト日時、認証・App Check情報、エラー等の技術ログ | Google Firebase / Cloud Functions | セキュリティ、障害調査、不正防止 | Googleの基準および運用上必要な期間 |
| 匿名IDごとの1日あたりの生成回数(会話・画像・音声・写真解析の件数のみ) | 当社のCloud Functions/Firestore | 不正利用を止めるための上限の判定 | 日付と回数の数値だけを保存。会話の内容は含まない |
| 利用者が報告操作をしたAI生成メッセージ、生成物の種類、言語、匿名IDのハッシュ | 当社のCloud Functions/Firestore | 不適切な生成物の調査、安全性の改善 | 報告時のみ保存。原則90日。会話全体・写真は送信しない |
| 購入情報(トランザクション) | Apple/RevenueCat | 課金の処理・プランの判定 | 各社の基準に従う |
| IPアドレス、広告識別子、端末・広告操作・診断情報、IP等から推定されるおおまかな地域 | Google AdMob | 広告の表示、効果測定、不正防止(無料プランのみ) | Googleの基準に従う |
| お問い合わせフォームに入力した内容およびGoogleが自動取得する情報 | Google Forms | お問い合わせへの対応 | Googleの基準および対応に必要な期間 |
- 写真について:画像から起こした「見た目のことば(テキスト)」だけがその後の生成に使われます。写真そのものが繰り返し送信されることはありません。
- OpenAI APIとxAI企業向けAPIでは、送信内容は既定でモデル学習に使用されません。一方、入力・出力等は通常最大30日保持される場合があります。法令、安全・不正利用調査、契約または設定による例外があります。詳細は各社の規約・データ処理条件に従います。
(3) 取得しない情報
- GPS等による正確な位置情報(AdMobがIP等からおおまかな地域を推定する場合はあります)
- 連絡先・通話履歴
- マイク音声(本アプリは録音機能を持ちません)
- カメラ・写真ライブラリへの常時アクセス(利用者が写真を選んだときのみ、その写真だけを読み取ります)
3. 利用目的
- 本アプリの機能(会話・画像・音声の生成、プランの管理)の提供
- 課金の処理と復元
- 広告の表示(無料プランのみ)
- 不正利用の防止
- 利用者から報告されたAI生成物の安全確認と再発防止
- お問い合わせへの対応
4. 第三者提供・委託
当社は、次の場合を除き、利用者の情報を第三者に提供しません。
- 上記 2.(2) に記載した、機能の提供に必要な外部サービスへの送信
- 法令に基づく開示請求があった場合
- 人の生命・身体・財産の保護のために必要で、本人の同意を得ることが困難な場合
主な外部サービスと各社のプライバシーポリシー:
- Google Firebase / AdMob:policies.google.com/privacy
- Google Forms:policies.google.com/privacy
- OpenAI(企業・API向けデータ取扱い):openai.com/enterprise-privacy
- xAI(企業向け利用規約):x.ai/legal/terms-of-service-enterprise
- xAI(データ処理契約):x.ai/legal/data-processing-addendum
- Apple:apple.com/legal/privacy
- RevenueCat:revenuecat.com/privacy
5. 広告とトラッキング
- 無料プランでは、Google AdMob による広告を表示します。
- 広告SDKの初期化前に、適用地域ではGoogleのUser Messaging Platform(UMP)を用いて必要な同意を取得します。必要な地域では設定画面から選択を変更できます。
- iOSでは、オンボーディング完了後、無料プランの利用者に限り App Tracking Transparency(ATT)の許可を一度だけ求めます。許可した場合に限り、AdMobへパーソナライズ広告を要求します。拒否・未決定の場合は非パーソナライズ広告を要求し、機能は制限しません。会話や写真を広告のターゲティングには使いません。
- iOSのSame App Keyは無効化しています。広告の最大コンテンツレーティングはTeenに設定しています。
- 有料プラン(Lite以上)では広告を表示せず、広告目的のデータ送信も行いません。
6. 通知
本アプリの通知は端末内で完結するローカル通知のみで、既定はオフです。プッシュ通知の配信基盤は使用していません。
7. データの保存期間と削除
- 端末内の会話・キャラクター・プロフィール・画像:対応するアプリ内の削除操作、またはアプリのアンインストールで消去されます。参照されなくなった画像も削除します。
- 生成音声のキャッシュ:端末内に最大300件保持し、古いものから自動削除されます。アプリのアンインストールでも消去されます。
- 生成時に送信した内容:当社サーバーには保存しません。AI提供元での保持・削除は各社の規約、契約および設定に従います。
- 匿名IDごとの1日あたりの生成回数:翌日以降の最初の利用時に同じ記録を上書きし、日ごとの履歴は作成しません。
- 報告したAI生成メッセージ:安全確認後、原則90日以内に削除します。Firestoreの有効期限(TTL)を使用します。
- 設定の「すべてのデータを削除」:端末内データ、Firebaseの匿名認証ID、当社の匿名利用回数および当該匿名IDから送られた報告を削除します。
- Apple/Google/RevenueCatの購入記録:法令、決済、返金、契約状態の管理に必要な期間、各社の基準で保持されます。全削除ではサブスクリプションは解約されません。RevenueCat等に残る情報の削除依頼はお問い合わせフォームから受け付けます。
8. 安全管理
- 外部との通信はすべて暗号化(HTTPS)されています。
- AI提供元へのアクセスに用いるAPIキーは当社のサーバー側で管理し、アプリ内には保持していません。
9. 子どものプライバシー
本アプリは18歳未満の方は利用できません。18歳未満の方の情報を取得していることが判明した場合、速やかに削除します。
10. ポリシーの変更
誤記の修正、表現の調整、法令対応その他の軽微な変更は、個別の通知なく行えるものとし、変更後のポリシーを掲示した時点から効力を生じます。取得する情報や利用目的の追加など、利用者に重要な影響を与える変更を行う場合は、アプリ内での表示その他の適切な方法で、事前にお知らせします。
11. お問い合わせ
本ポリシーに関するお問い合わせは、アプリ内「設定 > お問い合わせ」のフォーム、またはメール(info@cata-labs.jp)にて受け付けています。
以上
Oshily Privacy Policy
Cata Labs ("we," "us," or "our") sets out below how information is handled in the app "Oshily" (the "App").
This English version is provided for convenience. If there is any inconsistency between the Japanese version and this English version, the Japanese version prevails.
Contents
1. Our approach — your device is the primary storage
The App works without account registration. We do not require a legal name, email address, or phone number. You may optionally enter a name you want characters to call you.
Your device is the primary storage for conversations, memories, generated images and voice files, and profile settings. We ordinarily do not persist their contents in our Cloud Functions or Firestore. When you use a generation feature, the necessary content is sent to the AI providers listed below. As an exception, an AI-generated message you explicitly report is stored for safety review.
The trade-off is that deleting the App or changing devices erases your data. This is stated in our Terms of Service as well.
2. Information we handle
(1) Information primarily stored on your device
- Conversation history, memories, and relationship settings
- Cached generated images and voice files
- Display settings, language settings, and plan usage counts
(2) Information sent externally to provide features
| Information | Sent to | Purpose | Retention |
|---|---|---|---|
| Conversation, memory, profile, character, and scene text needed for a generation | OpenAI (via our Cloud Functions) | Generating replies, memories, and image descriptions | Not stored on our servers; see the provider terms below |
| Image-generation prompts, including summaries of conversation, appearance, and scenes | OpenAI (same route) | Generating images | Same as above |
| Character dialogue selected for playback | xAI (same route) | Generating voice audio | Not stored on our servers; see the provider terms below |
| Profile photos and photos shown in a conversation | OpenAI (same route) | One-time conversion into a text description | Not stored on our servers; the photo and description are stored on the device |
| Anonymous ID | Google Firebase | Identifying the device, preventing abuse | Stored in Firebase Authentication |
| Proof that the request comes from a genuine App instance (App Check: App Attest on iOS, Play Integrity on Android) | Apple / Google / Google Firebase | Blocking unauthorized API calls | Verification tokens only; they do not contain conversation content |
| IP address, request time, authentication and App Check information, errors, and similar technical logs | Google Firebase / Cloud Functions | Security, troubleshooting, and abuse prevention | Per Google's standards and as long as operationally necessary |
| Daily generation counts per anonymous ID (number of chat, image, voice, and photo-analysis requests only) | Our Cloud Functions / Firestore | Enforcing an abuse ceiling | Only the date and the counts are stored; no conversation content |
| AI-generated message you choose to report, content type, language, and a hash of the anonymous ID | Our Cloud Functions / Firestore | Investigating inappropriate output and improving safety | Only when you report; normally 90 days; the rest of the conversation and photos are not sent |
| Purchase transactions | Apple / RevenueCat | Processing purchases, determining your plan | Per each provider's standards |
| IP address, advertising identifiers, device, ad interaction and diagnostic data, and coarse region inferred from IP or similar signals | Google AdMob | Serving and measuring ads and preventing fraud (free plan only) | Per Google's standards |
| Information entered in the contact form and information automatically handled by Google | Google Forms | Responding to your inquiry | Per Google's standards and as long as needed to respond |
- About photos: only the text description derived from the image is used for later generation. The photo itself is not sent repeatedly.
- OpenAI API and xAI enterprise API data are not used for model training by default. Inputs and outputs may ordinarily be retained for up to 30 days, subject to exceptions for law, safety, abuse investigations, agreements, or account settings. Details follow each provider's applicable terms and data-processing conditions.
(3) Information we do not collect
- Precise GPS-based location (AdMob may infer a coarse region from IP or similar signals)
- Contacts or call history
- Microphone audio (the App has no recording feature)
- Ongoing access to your camera or photo library (we read only the single photo you select, at the moment you select it)
3. Purposes of use
- Providing the App's features (generating conversation, images, and voice; managing plans)
- Processing and restoring purchases
- Serving ads (free plan only)
- Preventing abuse
- Reviewing reported AI-generated content and preventing recurrence
- Responding to inquiries
4. Sharing and processors
We do not provide your information to third parties except:
- Transmission to the external services listed in 2.(2) above, as needed to provide features
- Where disclosure is required by law
- Where necessary to protect a person's life, body, or property and it is difficult to obtain consent
Privacy policies of the main external services:
- Google Firebase / AdMob: policies.google.com/privacy
- Google Forms: policies.google.com/privacy
- OpenAI (enterprise and API data): openai.com/enterprise-privacy
- xAI enterprise terms: x.ai/legal/terms-of-service-enterprise
- xAI data processing agreement: x.ai/legal/data-processing-addendum
- Apple: apple.com/legal/privacy
- RevenueCat: revenuecat.com/privacy
5. Advertising and tracking
- On the free plan, we display ads through Google AdMob.
- Before initializing the advertising SDK, the App uses Google's User Messaging Platform (UMP) to obtain consent where required. Where required, you can revisit those choices from Settings.
- On iOS, after onboarding, the App asks free-plan users once for App Tracking Transparency permission. It requests personalized ads from AdMob only when permission is granted. If permission is denied or undecided, it requests non-personalized ads and does not restrict features. Conversations and photos are not used for ad targeting.
- On iOS, the Same App Key is disabled. The maximum ad content rating is set to Teen.
- On paid plans (Lite and above), we display no ads and send no data for advertising purposes.
6. Notifications
The App uses only local notifications that stay on your device, and they are off by default. We do not use any push notification infrastructure.
7. Retention and deletion
- On-device conversations, characters, profiles, and images: erased through the corresponding deletion controls in the App or by uninstalling the App. Images that are no longer referenced are also removed.
- Generated voice cache: up to 300 files are kept on device; older entries are removed automatically. Uninstalling the App also removes them.
- Content sent for generation: not stored on our servers. Provider retention and deletion follow each provider's terms, agreement, and settings.
- Daily generation counts per anonymous ID: overwritten on the first use of a later day; no day-by-day history is created.
- Reported AI-generated messages: deleted after safety review, normally within 90 days, using Firestore time-to-live (TTL).
- Settings > Delete all data deletes on-device data, the Firebase anonymous authentication ID, our anonymous usage counters, and reports sent from that ID.
- Purchase records held by Apple, Google, or RevenueCat are retained under each provider's standards as needed for law, payments, refunds, and subscription status. Delete all data does not cancel a subscription. Use the contact form to request deletion of information that remains with RevenueCat or another provider.
8. Security
- All external communication is encrypted (HTTPS).
- API keys used to reach AI providers are held on our server side and are never stored in the app.
9. Children's privacy
The App may be used only by people aged 18 or older. If we learn that we hold information from anyone under 18, we will delete it promptly.
10. Changes to this policy
Minor changes — corrections, adjustments of wording, and updates for legal compliance — may be made without individual notice and take effect when the revised policy is posted. For changes that materially affect you, such as adding new categories of information or new purposes of use, we will give advance notice in the App or by other appropriate means.
11. Contact
For questions about this policy, use the form under Settings > Contact us in the App, or email info@cata-labs.jp.
End of Policy