Restry プライバシーポリシー
1. 基本方針
Restry(以下「本アプリ」)は、利用者の記録のうち最も機微なもの——水分摂取と排尿の記録、切迫度、予測の学習状態、自宅として登録した位置——を利用者の端末内にのみ保存し、当社のサーバーへ送信しません。最寄りのトイレの計算結果(座標・取得時刻・徒歩の所要分数)も端末内の App Group の共有領域に保存します。予測の計算と学習も、すべて端末内で行います。
2. 端末内にのみ保存する情報
以下は端末内に保存され、当社サーバーへ送信されません。
- 水分摂取の記録、排尿の記録および切迫度
- 予測の学習状態
- 自宅として登録した位置
- 最寄りのトイレの計算結果(座標・取得時刻・徒歩の所要分数)
地図に表示するトイレ情報も端末内にキャッシュされます。キャッシュの内容自体を当社サーバーへ送信することはありませんが、レビュー集計を取得するため、読み込んだトイレの識別子は当社サーバーへ送信されます(第 3 項・第 4 項)。
これらは、利用者が iCloud バックアップを有効にしている場合、Apple の iCloud を通じてバックアップされることがあります。当社はその内容にアクセスできません。本アプリを削除すると、SwiftData に保存された記録、地図のトイレ情報キャッシュ、App Group に保存した設定値は端末から削除されます。ただし、匿名認証セッションは端末のキーチェーンに残ります。
3. 当社サーバーに保存する情報
利用者が投稿・評価・通報を行った場合、以下を当社のサーバー(Supabase)に保存します。
- 投稿されたトイレの位置・設備 — 他の利用者への地図情報の提供のため
- 設備に関する評価 — 情報の正確性の改善のため
- 通報の対象と理由 — 不適切な投稿への対応のため
- 匿名の利用者識別子 — 投稿の重複防止と不正利用への対応のため
匿名の利用者識別子は、投稿時に自動的に生成されます。氏名、メールアドレス、電話番号その他の連絡先は求めず、保存しません。
サーバーの所在地: 日本
投稿していない利用者を含め、地図の読み込みが成功するたびに、可視範囲のトイレ ID をレビュー集計を取得するため当社サーバーへ最大 200 件ずつ送信します。
匿名アカウントと投稿データは、アプリ内からいつでも削除できます(7. 保存期間と削除を参照)。
4. 第三者に送信される情報
本アプリの機能上、以下の情報が第三者のサービスへ送信されます。
- 地図の表示範囲の座標、および最寄りのトイレを探すときは現在地を中心とする約 1.5 km の範囲の座標 — トイレ情報を取得するため、OpenStreetMap の Overpass API に送信されます
- 検索中心の緯度経度と検索半径 — 周辺のトイレ情報を取得するため、Supabase に送信されます。地図表示、アプリが active のときの再計算、ログ保存、外出モード開始が送信の契機です
- 可視範囲のトイレ ID — 地図の読み込み成功のたびに、レビュー集計を取得するため当社サーバーへ最大 200 件ずつ送信されます。投稿していない利用者も対象です
- 現在地および目的地の座標 — 徒歩ルートと所要時間を計算するため、Apple の地図サービスに送信されます
- RevenueCat の Privacy Manifest が宣言する購入履歴 — 購読の管理のため RevenueCat に送信されます。この宣言では Linked = false、Tracking = false であり、Diagnostics は宣言されていません
- 購入処理に必要な情報 — Apple の App Store に送信されます
これらの事業者による取り扱いは、各事業者のプライバシーポリシーに従います。当社の処理委託先である Supabase および RevenueCat については、各社が提供するデータ処理契約(DPA)により、本ポリシーと同等以上の保護 — GDPR への準拠、国際移転に関する標準契約条項、暗号化を含む安全管理措置、および再委託先への同等の保護の要求 — が適用されることを確認しています。OpenStreetMap の Overpass API への問い合わせは公共の地図データベースへの検索であり、問い合わせの内容(検索範囲の座標)に氏名やアカウント識別子を含めません。ただし、通信に伴い、IP アドレスなどの接続情報が同 API の提供元によって処理されることがあります。同 API の主要な提供元(overpass-api.de)は、EU 一般データ保護規則(GDPR)の適用を受けるドイツの非営利団体FOSSGIS e.V. が運営しています。同団体は、公表しているプライバシーポリシーにおいて、サーバーログとして自動収集される情報を特定の個人に結び付けず、他のデータソースと結合しないことを示しています。
5. 端末の機能の利用
利用者の許可を得た場合に限り、以下を利用します。許可はいつでも端末の設定から取り消せます。
- ヘルスケア — 水分摂取量の読み取りと書き込み。歩数は読み取りません
- カレンダー — 予定の開始時刻・終了時刻・終日フラグ・カレンダーイベント識別子を読み取ります。予定別の通知設定を保存した場合、予定の識別子を端末内の予定ごとの通知設定に保存します。カレンダーデータは当社サーバーへ送信しません
- 位置情報 — 地図の表示、最寄りのトイレの検索、および利用者が有効にした場合の滞在の自動検知に使用します。自宅として登録した位置の周囲 300 メートル以内では、位置の記録と自動検知を行いません
- 通知 — 先回りの通知および予定前の通知の送信
6. 広告・アクセス解析
本アプリは、広告および利用者の行動を追跡するアクセス解析を使用していません。
7. 保存期間と削除
- 端末内のデータ: 本アプリを削除すると、SwiftData に保存された記録、地図のトイレ情報キャッシュ、App Group に保存した設定値は端末から削除されます。ただし、匿名認証セッションは端末のキーチェーンに残ります
- 端末内の記録: 設定画面の「データの削除」から、この端末の水分摂取・排尿の記録、予測の学習状態、予定ごとの調整をいつでも削除できます。ヘルスケアに書き出した水分の記録は、本アプリにヘルスケアへの書き込み権限がある場合に、あわせて削除するかどうかを選べます。権限がない場合は、ヘルスケア App の「ソース」から削除できます
- 投稿されたデータ: 設定画面の「データの削除」から、匿名アカウントと、匿名の利用者識別子に紐づく投稿をいつでも削除できます。削除後に投稿すると、新しい匿名アカウントが作成されます。上記のお問い合わせ先へ削除を依頼することもできます
- 購読情報: RevenueCat および Apple の定めに従います。アカウントの削除は購読の解約とは別であり、購読の解約は App Store の設定から行う必要があります。アカウントを削除しても、RevenueCat が処理・保持する購入関連データは削除されません
8. 子どもの利用
本アプリは子ども向けに設計されたアプリではありません。
9. 本ポリシーの改定
本ポリシーを改定する場合は、本ページに改定後の内容と改定日を掲示します。
10. 準拠法
本アプリは全世界に配信されます。本ポリシーは日本法に準拠します。
11. 欧州経済領域および英国の利用者の権利
欧州経済領域(EEA)または英国にお住まいの利用者には、本条が追加で適用されます。
取扱いの法的根拠
- 購読の提供と管理 — 契約の履行
- 投稿・評価・通報の受付と表示 — 契約の履行
- 不適切な投稿への対応、重複投稿の防止 — 正当な利益(サービスの健全性の維持)
- ヘルスケア・カレンダー・位置情報・通知の利用 — 同意(端末の設定からいつでも撤回できます)
利用者の権利
アクセス、訂正、削除、取扱いの制限、取扱いへの異議、データポータビリティ、および同意の撤回を求めることができます。行使を希望される場合は、上記のお問い合わせ先へご連絡ください。
ただし本アプリは、投稿に匿名の識別子しか結び付けておらず、氏名・メールアドレス等を保存していません。そのため、ご本人と保存データを結び付けられない場合には、権利の行使にあたって識別に必要な情報(投稿時の識別子など)の提供をお願いすることがあります。ご提供いただけない場合、当社はご本人を特定できないため、権利の行使に応じられないことがあります。
国外への移転
当社サーバーは日本にあります。日本は、欧州委員会により個人データの十分な保護水準を確保していると認定されています。
苦情の申立て
お住まいの国の個人データ保護監督機関へ苦情を申し立てることができます。
Restry Privacy Policy
1. Our approach
Restry (the "App") keeps your most sensitive records — drink and bathroom logs, urgency levels, prediction learning state, and your registered home location — on your device only. They are never sent to our servers. The nearest-toilet calculation result (coordinates, capture time, and walking minutes) is also stored in the device's shared App Group storage. All prediction and learning happens on your device.
2. Stored on your device only
The following stay on your device and are not sent to our servers:
- Drink logs, bathroom logs, and urgency levels
- Prediction learning state
- Your registered home location
- Nearest-toilet calculation result (coordinates, capture time, and walking minutes)
Toilet information shown on the map is also cached on your device. We do not send the contents of that cache to our servers, but the identifiers of the toilets you loaded are sent to our server to retrieve review summaries (sections 3 and 4).
If you have iCloud Backup enabled, these may be backed up through Apple's iCloud; we cannot access their contents. Deleting the App removes the records stored in SwiftData, cached toilet information shown on the map, and settings stored in the App Group from your device. However, the anonymous auth session remains in the device's keychain.
3. Stored on our servers
When you contribute, rate, or report, we store the following on our servers (Supabase):
- Location and facilities of a toilet you submit — to provide map information to other users
- Your facility ratings — to improve the accuracy of the information
- The target and reason of a report — to act on inappropriate contributions
- An anonymous user identifier — to prevent duplicate submissions and handle abuse
The anonymous identifier is generated automatically when you contribute. We do not ask for or store your name, email address, phone number, or any other contact details.
Server location: Japan
Even for users who have not submitted anything, each successful map load sends visible toilet IDs to our server in batches of up to 200 to retrieve review summaries.
You can delete your anonymous account and contributed data at any time from within the App (see 7. Retention and deletion).
4. Information sent to third parties
The App's features send the following to third-party services:
- The coordinates of the visible map area, and — when finding the nearest toilet — the coordinates of an area about 1.5 km around your current position — sent to the OpenStreetMap Overpass API to retrieve toilet information
- The search center's latitude and longitude and search radius — sent to Supabase to retrieve nearby toilet information. This occurs for map display, recalculation while the app is active, log saving, and outing-mode start
- Visible toilet IDs — sent to our server in batches of up to 200 on each successful map load to retrieve review summaries, including for users who have not submitted anything
- Your current location and destination coordinates — sent to Apple's mapping services to calculate walking routes and times
- Purchase History declared in RevenueCat's Privacy Manifest — sent to RevenueCat to manage subscriptions. The declaration has Linked = false and Tracking = false; it does not declare Diagnostics
- Information required to process purchases — sent to Apple's App Store
Their handling of this information is governed by each company's own privacy policy. For our processors Supabase and RevenueCat, we have confirmed through each company's Data Processing Agreement (DPA) that protections equal to or stronger than this policy apply — GDPR compliance, Standard Contractual Clauses for international transfers, security measures including encryption, and a requirement that their own sub-processors provide equivalent protection. Queries to the OpenStreetMap Overpass API are searches against a public map database; the query itself (the coordinates of the search area) contains no name or account identifier. However, connection information such as your IP address may be processed by the API's provider as part of the communication. The main provider of that API (overpass-api.de) is operated by FOSSGIS e.V., a German non-profit subject to the EU General Data Protection Regulation (GDPR). Its published privacy policy states that the information automatically collected in server logs is not attributed to specific individuals and is not combined with other data sources.
5. Device capabilities
We use the following only with your permission, which you can withdraw at any time in your device settings:
- Health — reading and writing water intake. We do not read step count
- Calendar — reading the start time, end time, all-day flag, and calendar event identifier. If you save per-event notification settings, we store the identifier on the device as part of that event's notification settings. We do not send calendar data to our servers
- Location — showing the map, finding nearby toilets, and, if you enable it, automatic stay detection. Within 300 metres of your registered home location, we do not record location or run automatic detection
- Notifications — sending ahead-of-time and pre-event notifications
6. Advertising and analytics
The App does not use advertising or behavioural analytics.
7. Retention and deletion
- Data on your device: deleting the App removes the records stored in SwiftData, cached toilet information shown on the map, and settings stored in the App Group from your device. However, the anonymous auth session remains in the device's keychain
- Records on your device: you can delete drink and bathroom records, the learned prediction state, and per-event adjustments on this device at any time from "Delete data" in Settings. If the App has write access to Health, you can choose whether to also remove the water records saved to the Health app; without that access, you can remove them in the Health app under Sources
- Contributed data: you can delete your anonymous account and the contributions linked to your anonymous identifier at any time from "Delete data" in Settings. A new anonymous account is created if you contribute again. You can also request deletion at the contact address above
- Subscription information: governed by RevenueCat's and Apple's terms. Deleting your account is separate from cancelling your subscription — cancellation must be done in your App Store settings. Deleting your account does not delete the purchase-related data processed and retained by RevenueCat
8. Children
The App is not designed for children.
9. Changes to this policy
If we revise this policy, we will post the revised text and its date on this page.
10. Governing law
The App is distributed worldwide. This policy is governed by the laws of Japan.
11. Your rights in the European Economic Area and the United Kingdom
This section applies in addition if you live in the European Economic Area (EEA) or the United Kingdom.
Lawful basis for processing
- Providing and managing subscriptions — performance of a contract
- Accepting and displaying contributions, ratings, and reports — performance of a contract
- Acting on inappropriate contributions and preventing duplicates — legitimate interests (keeping the service sound)
- Use of Health, Calendar, Location, and Notifications — consent (withdrawable at any time in your device settings)
Your rights
You may request access, rectification, erasure, restriction of processing, objection to processing, data portability, and withdrawal of consent. To exercise them, contact us at the address above.
Note that the App links contributions only to an anonymous identifier and stores no name, email address, or similar details. Where we cannot link you to the stored data, we may ask you to supply the information needed to identify it (such as the identifier used when you contributed). If you cannot provide it, we may be unable to act on your request because we cannot identify you.
International transfers
Our servers are in Japan. The European Commission has recognised Japan as providing an adequate level of protection for personal data.
Complaints
You may lodge a complaint with the data protection supervisory authority in your country of residence.