| 🇯🇵 日本語 | 🇺🇸 English |
Privacy Policy
The operator of Whimo (“we”, “us”, or the “Operator”) establishes this Privacy Policy (this “Policy”) regarding the handling of users’ personal information in the mobile application “Whimo” (formerly “Dokoiko”) (the “App”).
Last updated: 2026-07-12
This Policy is prepared in Japanese and translated into English. In the event of any inconsistency between the two versions, the Japanese version shall prevail to the extent permitted by applicable law.
1. Information We Collect
We collect the following information in the course of your use of the App.
| Category | Items | How it is collected |
|---|---|---|
| Account information | Email address, display name | Entered by you at sign-up; obtained from the OAuth provider when you sign in with Google / Apple |
| Authentication identifiers | User ID (UUID), Google / Apple linking IDs | Sign-in process |
| Location information | Approximate device location (latitude / longitude) | OS location services (only if you grant permission) |
| User content | Saved spots, notes, planned dates, visit dates, lists, groups you belong to, group member lists | Your actions in the App |
| Usage logs | Screen transitions, in-app events (saving spots, recording visits, creating groups, sending invites, filtering, etc.), device model / OS version, app launch and session information automatically collected by Firebase Analytics | Firebase Analytics |
| User properties | Number of saved spots (spot_count), number of groups (group_count) |
Firebase Analytics |
| Purchase information | Subscription status, plan type, purchase / renewal / expiration dates for the paid plan (Premium), and the anonymous purchase identifier issued by the App Store | In-app purchases (App Store) and our subscription management service (RevenueCat) |
The App does not collect your name, postal address, phone number, credit card information, contacts, photo library, or camera content. Payments for the paid plan are processed by Apple (App Store), and we do not receive your credit card number or other payment details.
2. How We Use Your Information
We use the collected information for the following purposes:
- Authentication and account management for the App
- Verifying and managing the subscription status of the paid plan (Premium) and providing paid features
- Storing the spots, lists, and group information you register, and syncing them to your other devices signed in to the same account
- Displaying and sorting spots by distance from your current location
- Investigating defects and performing statistical analysis to improve service quality
- Responding to violations of the Terms of Service and other misuse
- Delivering important notices
3. Legal Bases for Processing (for users in the United Kingdom)
Where the UK GDPR applies, we process your personal data on the following legal bases:
- Performance of a contract: account management, storing and syncing your content, and providing paid-plan features
- Legitimate interests: usage analytics, service improvement, security, and prevention of misuse
- Consent: use of device location (you may withdraw consent at any time in iOS Settings)
- Legal obligation: where we are required to retain or disclose information by law
4. Disclosure to Third Parties
We do not provide your personal information to third parties except in the following cases:
- With your consent
- When required by law
- When necessary to protect a person’s life, body, or property and it is difficult to obtain your consent
- When cooperation with a government agency or local authority carrying out duties prescribed by law is necessary
We do not sell your personal information, and we do not “sell” or “share” personal information as those terms are defined in the California Consumer Privacy Act (CCPA/CPRA). We have not done so in the preceding 12 months.
5. Service Providers
We use the following services to operate the App. Each provider handles data in accordance with its own privacy policy.
| Provider | Purpose | Privacy policy |
|---|---|---|
| Supabase Inc. (US) | Account authentication, database, file storage | https://supabase.com/privacy |
| Google LLC (US) | Google Sign-In, Google Maps SDK for iOS, Google Places API | https://policies.google.com/privacy |
| Apple Inc. (US) | Sign in with Apple | https://www.apple.com/legal/privacy/ |
| Google LLC / Firebase (US) | Firebase Analytics (usage statistics) | https://firebase.google.com/support/privacy |
| RevenueCat, Inc. (US) | Managing and validating paid subscription status | https://www.revenuecat.com/privacy |
6. International Data Transfers
Your data may be stored and processed on servers located outside your country of residence, primarily in the United States and Japan. Where required by applicable law (including the UK GDPR), transfers are protected by appropriate safeguards, such as the providers’ standard contractual clauses, the UK International Data Transfer Addendum, or certification under applicable data privacy frameworks.
7. Tracking
The App does not track users within the meaning of Apple’s guidelines. Specifically, we do not collect the advertising identifier (IDFA) for advertising or ad-measurement purposes, and we do not share user or device data with third-party advertising networks or data brokers (our privacy manifest declares NSPrivacyTracking as false). Firebase Analytics is used solely to collect anonymous usage statistics (events, screen transitions, device model, etc.) without the IDFA.
8. Location Information
Location information is used only to display nearby spots and to sort spots by distance from your current location. Location data is processed on your device and is not stored on our servers. You can revoke location permission at any time in the iOS Settings app.
9. Data Retention
We retain your information for as long as your account exists. When you use the “Delete Account” feature in the App, your account information and user content (spots, lists, notes, group memberships, etc.) are promptly deleted. Anonymized usage logs collected by Firebase Analytics are retained in accordance with Google’s retention periods.
10. Security
- All communications are encrypted with HTTPS / TLS.
- The database is protected by Supabase Row Level Security so that each user can access only their own data.
- Credentials (passwords, OAuth tokens) are managed by Supabase Auth using industry-standard methods; we do not hold them in plain text.
11. Your Rights and Choices
You have the following rights, subject to applicable law:
- The right to request access to, correction of, restriction of use of, or deletion of your personal information
- The right to completely delete your account and related data at any time using the “Delete Account” feature in the App
To exercise these rights or to ask questions about this Policy, please contact us at the address in Section 15. We will not discriminate against you for exercising any of your rights.
Depending on where you live, you may have additional rights:
- United States (California): Under the CCPA/CPRA, you have the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to non-discrimination. The categories of personal information we collect are described in Section 1 (identifiers, approximate geolocation, commercial information, and internet or other electronic network activity). We do not sell or share personal information.
- United Kingdom: Under the UK GDPR, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO, https://ico.org.uk/).
- Canada: Under PIPEDA, you have the right to access and correct your personal information and to withdraw consent subject to legal or contractual restrictions. You may file a complaint with the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca/).
- Australia: Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to access and correct your personal information. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC, https://www.oaic.gov.au/).
12. Cookies and Similar Technologies
The App is a mobile application and does not use web browser cookies. Session tokens issued by OAuth providers at sign-in are stored in secure storage on your device.
13. Children’s Privacy
The App is rated 4+ (suitable for all ages, though not specifically directed at children). The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 13, please use the App only with the consent of a parent or guardian. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
14. Changes to This Policy
We may amend this Policy in response to changes in law or in the App. The amended Policy takes effect when published on this page. We will announce material changes through in-app notices or other means.
15. Contact
Whimo Operator Email: tomokazu.kozuma@gmail.com