Kivori プライバシーポリシー
最終更新: 2026-08-22
Kivori は、あなたが会った人を思い出すためのプライベート CRM です。本ポリシーでは、当社がどのデータを保持し、なぜ保持し、どのように削除できるかを説明します。
問い合わせ先: privacy@kazuki-jo.com
1. 保存するデータ
Kivori をご利用いただくと、Supabase のサーバー(データベース所在地: カナダ / AWS ca-central-1・モントリオール)上に以下のデータを保存します。
- 識別子: 初回起動時は匿名ユーザー ID。Apple / Google のサインインを行うと、OAuth 連携された ID に昇格します。
- 記録した人物: 入力した名前、会った場所、日付、短い「関係メモ」、および音声メモから AI 抽出した「メモリ」「次に聞くこと」の各行が含まれます。
- 音声メモの文字起こし: テキストのみ。音声そのものは端末上で文字起こしされ、外部には送信されません。
以下のデータは保存しません。
- 音声録音そのもの
- 連絡先、カレンダー、その他の端末内データ
- 端末の広告 ID
2. 第三者に関する情報
Kivori はあなたが会った人を思い出すためのアプリなので、保存する情報の多くはあなた以外の人物に関するものです。これをあなたのアカウントに閉じた情報として扱います。
- アクセス: あなたのみが自分の行を読み取れます。Supabase の行レベルセキュリティ (RLS) で強制されます。
- 通信の暗号化: すべての読み書きは HTTPS を利用します。
- AI 処理: 文字起こしは Supabase から言語モデル (Google Vertex AI / Gemini) に送信され、構造化された「メモリ」「次に聞くこと」を抽出します。モデルの学習には利用されません。
- 削除: アプリ内から人物を削除できます。ソフト削除が即時に反映され、30 日以内に完全に削除されます。
- 処理の根拠: 記録された第三者の情報は、あなたがご自身の人間関係を思い出すという目的のため、当社の正当な利益に基づいて処理します(GDPR 第6条1項(f))。
- 保存場所と国外への送信: データベースは Supabase のカナダ リージョン(AWS ca-central-1・モントリオール)にあります。AI 処理を行う Google Vertex AI は米国(アイオワ / us-central1)にあるため、文字起こしテキストは米国へ送信されます。米国の個人情報保護制度は日本や EU と同一ではないため、Google Cloud の Cloud Data Processing Addendum に基づく保護措置を講じています。
- 記録された方からのご請求: Kivori にご自身の情報が記録されているとお考えの方は privacy@kazuki-jo.com までご連絡ください。開示および削除のご請求に対応します。
3. 分析とクラッシュレポート
アプリが役に立っているかを把握するため、PostHog により PII を含まない少数のイベントを収集します。
- アプリ起動 (
session_started)
- サインイン完了 (
sign_in_completed) — プロバイダ名のみ
- 人物を記録した (
person_recorded) — 内部 ID、文字起こしを取得したかの真偽値、ソース (voice / manual)
- 人物カードを再度開いた (
person_opened) — 内部 ID、前回の開封が 24 時間以上前かの真偽値、前回開封からの経過秒数
人物の名前、文字起こし、メモ、プロフィールリンクなどが PostHog に送信されることは一切ありません。
クラッシュレポートには Sentry を利用します。Sentry には例外の型・メッセージ・スタックトレースのみが送信されます。アプリ内のスクラバーが、メモ本文・文字起こし・人物名を含む可能性のあるログ行やブレッドクラムを事前に除去します。
4. あなたの権利
以下を行えます。
EU 域内のお客様に対する処理の法的根拠は、アカウント作成時のご同意、および当社によるサービス運営の正当な利益です。
5. 年齢制限
Kivori は子ども向けのアプリではありません。一般的なオンラインサービスの慣行にあわせ、13 歳以上でのご利用を推奨しています。13 歳未満の方のデータを収集していることが判明した場合は、当該データを削除します。デジタル同意年齢がこれより高く定められている法域 (例: GDPR の 16 歳など) では、その年齢に満たない方は保護者の同意のうえでご利用ください。
6. 変更
本ポリシーは随時更新されます。重要な変更は、施行前にアプリ内でご案内します。
← Back
Kivori Privacy Policy
Last updated: 2026-08-22
Kivori is a private CRM: a place to remember the people you meet. This policy describes what data we hold, why, and how you can remove it.
Contact: privacy@kazuki-jo.com
1. What we store
When you use Kivori, we store the following on Supabase servers located in Canada (AWS ca-central-1, Montréal):
- Your identifiers: an anonymous user id at first launch, upgraded (via Sign in with Apple or Google) to an OAuth-linked identity if you choose.
- The people you record: each row contains the name you typed, the place you met, the date of the meeting, a short "connection note", and any memories or follow-up questions that the AI extraction produced from your voice memo.
- Your voice-memo transcript: text-only. The audio itself is transcribed on your device and never leaves it.
We do not store:
- your voice recordings,
- your contacts, calendar, or other on-device data,
- your device's advertising id.
2. Third-party notes
Kivori helps you remember other people, so much of what it stores is about someone other than you. We treat that data as private to your account:
- Access: only you can read your rows; row-level security policies on Supabase enforce this.
- Encryption in transit: all reads and writes use HTTPS.
- AI processing: the transcript is sent from Supabase to a language model (Google Vertex AI / Gemini) to extract structured memories and follow-up questions. It is not used to train the model.
- Deletion: you can delete a person from the app; the record is soft-deleted immediately and removed permanently within 30 days.
- Legal basis: information about third parties is processed on the basis of our legitimate interest in helping you remember your own relationships (GDPR Art. 6(1)(f)).
- Where the data is held, and transfers abroad: the database is hosted in Canada (AWS ca-central-1, Montréal). The AI processing runs on Google Vertex AI in the United States (Iowa / us-central1), so transcripts are transferred to the US. US data protection law is not identical to that of Japan or the EU, so the transfer is covered by the Google Cloud Data Processing Addendum.
- If you are one of the people recorded: contact privacy@kazuki-jo.com and we will handle your access or deletion request.
3. Analytics and crash reporting
To understand whether the app is useful, we track a small, PII-free set of events with PostHog:
- app opens (
session_started),
- sign-in completes (
sign_in_completed) — with the provider name only,
- a person was recorded (
person_recorded) — with the person's internal id, a boolean for whether a transcript was captured, and a source ("voice" or "manual"),
- a person's card was opened again (
person_opened) — with the internal id, a boolean for whether the previous open was more than 24 hours ago, and the elapsed seconds since the previous open.
None of the person's name, transcript, notes, or profile links are ever sent to PostHog.
We use Sentry to collect crash reports. Sentry receives only the exception type, message, and stack trace; a scrubber inside the app strips any log line or breadcrumb whose text or field name could carry a note body, transcript, or person name.
4. Your rights
You can:
- Export your data by emailing privacy@kazuki-jo.com; we return a JSON archive within 30 days.
- Delete your account and all associated data from Settings → Delete account, or by emailing privacy@kazuki-jo.com.
- Withdraw consent for analytics collection by contacting us.
For EU residents, the legal basis for processing is your consent when you create an account, and our legitimate interest in operating the service.
5. Age requirement
Kivori is not intended for children. We recommend a minimum age of 13, in line with common online services. If we learn that we have collected data from a child under 13, we will delete it. In jurisdictions where the digital consent age is higher (for example, 16 under GDPR), users below that age should have a parent or guardian's consent to use Kivori.
6. Changes
We will update this policy from time to time. Material changes are announced in-app before they take effect.
← Back