プライバシーポリシー

クリエイトム合同会社(以下「当社」といいます。)は、当社が提供するアプリケーション、Webサイト、Webサービス、AI関連機能、広告を含むサービス、有料機能、サブスクリプションその他当社が提供する一切のサービス(以下総称して「本サービス」といいます。)における、ユーザーに関する情報の取扱いについて、以下のとおりプライバシーポリシー(以下「本ポリシー」といいます。)を定めます。

第1条(事業者情報)

事業者名:クリエイトム合同会社
代表者:中川雄斗
所在地:〒150-0043 東京都渋谷区道玄坂1丁目10番8号 渋谷道玄坂東急ビル2F-C
お問い合わせ先:app@creatom.jp

第2条(適用範囲)

  1. 本ポリシーは、本サービスに共通して適用されます。
  2. 本サービスには、当社が現在または将来提供する、アプリ、Webサイト、Webアプリ、AI関連機能、有料機能、サブスクリプション、広告を含むサービス、その他これらに付随または関連するサービスが含まれます。
  3. 本サービスからリンクされる第三者のサービス、Webサイト、アプリ、広告その他の外部サービスについては、当該第三者が定めるプライバシーポリシー、利用規約その他の定めが適用されます。
  4. 当社が特定のサービスについて、本ポリシーとは別に個別のプライバシーポリシーその他の定めを設けた場合、当該サービスについては、その個別の定めが本ポリシーに優先して適用されます。

第3条(定義)

本ポリシーにおいて使用する用語は、個人情報の保護に関する法律その他関係法令の定めに従います。

本ポリシーにおいて「ユーザーに関する情報」とは、個人情報、個人データ、保有個人データ、個人関連情報、Cookie、広告識別子、端末情報、利用履歴、ログ情報、入力内容、生成内容その他ユーザーに関連して取得または生成される情報を含みます。

第4条(取得する情報)

当社は、本サービスの提供にあたり、以下の情報を取得することがあります。取得する情報は、ユーザーが利用するサービス、機能、端末、設定、利用状況により異なります。

1. ユーザーが入力または提供する情報

当社は、Googleその他の外部認証サービスを利用して認証を行う場合があり、ユーザーのパスワードを当社が取得または保存することはありません。ただし、認証状態の管理、ログイン管理、本人確認、セキュリティ確保のため、ユーザーID、認証ID、メールアドレス、認証に関連する識別情報その他必要な情報を取得することがあります。

2. 本サービスの利用に伴い取得または生成される情報

3. 課金・決済に関連する情報

当社は、有料プラン、サブスクリプション、有料機能、アプリ内課金その他有償サービスの提供にあたり、購入状況、購読状態、レシート情報、購入復元に必要な情報、利用権限、プラン情報その他課金管理に必要な情報を取得することがあります。

なお、クレジットカード番号その他の決済手段に関する情報は、Apple、Googleその他の決済事業者が管理し、当社が直接取得または保存しない場合があります。

4. 広告配信に関連する情報

当社は、広告を含むサービスにおいて、広告識別子、Cookie、端末情報、IPアドレス、広告の表示・閲覧・クリックに関する情報、アプリまたはWebサイトの利用状況、広告効果測定に必要な情報を取得または外部の広告関連事業者へ送信することがあります。

5. AI関連機能に関する情報

当社は、AI関連機能を含むサービスにおいて、ユーザーが入力したテキスト、画像、音声、ファイル、プロンプト、指示内容、利用状況、生成結果、AI機能の提供に必要な設定情報、ログ情報その他AI関連機能の提供、品質維持、不具合調査、安全性確保に必要な情報を取得または外部のAI関連サービス提供事業者へ送信することがあります。

6. Health Connect等の健康・フィットネスデータに関する情報

当社は、健康管理、運動記録、コンディション分析その他健康・フィットネス関連機能を含むサービスにおいて、ユーザーが当該機能を利用し、Health Connectその他の連携機能へのアクセスを許可した場合に限り、運動データ、距離データ、睡眠データ、運動または睡眠の日時、平均ペースその他当該機能の提供に必要な健康・フィットネスデータにアクセスし、取得することがあります。

7. 外部サービスを通じて取得する情報

当社は、認証、データ保存、アクセス解析、障害解析、通知配信、広告配信、広告効果測定、決済、サブスクリプション管理、AI関連機能、Health Connect等の連携機能、その他本サービスの提供に必要な外部サービスを利用する場合があり、これらの外部サービスを通じて、必要な範囲で情報を取得することがあります。

8. 要配慮個人情報等

当社は、法令上特別な配慮を要する個人情報の提供を原則として求めません。ユーザーが自由入力欄、問い合わせ、AI関連機能、アップロード機能その他の機能を通じて、要配慮個人情報または機微な情報を提供する場合は、必要最小限の範囲で行うものとし、当社は法令に従い当該情報を取り扱います。

第5条(取得方法)

当社は、以下の方法によりユーザーに関する情報を取得します。

  1. ユーザーが本サービスに登録、ログイン、ゲスト利用、外部サービス連携その他の方法により本サービスの利用を開始したとき
  2. ユーザーが本サービスの各種機能、設定機能、投稿機能、保存機能、問い合わせ機能、問題報告機能、AI関連機能、有料機能、広告を含む機能その他の機能を利用したとき
  3. ユーザーが有料プランの申込み、購入、更新、解約、購入復元その他課金に関する操作を行ったとき
  4. ユーザーが本サービス上で情報を入力、送信、保存、投稿、アップロード、共有したとき
  5. 本サービスまたは外部サービスを通じて、端末情報、ログ情報、利用状況、解析情報、クラッシュ情報、広告関連情報等が自動的に送信されたとき
  6. ユーザーから電子メール、フォーム、アプリ内問い合わせ、その他の方法により連絡を受けたとき

第6条(利用目的)

当社は、取得したユーザーに関する情報を、以下の目的のために利用します。

  1. 本サービスの提供、運営、維持、保護および改善のため
  2. 本人確認、認証、ログイン管理、アカウント管理のため
  3. ゲスト利用、利用状態、設定、履歴、進捗、成果、コンテンツその他本サービス上の情報を記録、表示、同期、管理するため
  4. 本サービスの各種機能、AI関連機能、生成機能、分析機能、通知機能、共有機能、広告を含む機能その他ユーザーが利用する機能を提供するため
  5. ユーザーの利用状況に応じた表示、機能提供、利便性向上、パーソナライズのため
  6. お問い合わせ対応、本人確認、サポート、問題報告への対応のため
  7. 不具合の調査、障害対応、品質改善、セキュリティ確保、技術上または運営上の問題解決のため
  8. 利用状況の分析、統計情報の作成、機能改善、サービス改善、新サービスまたは新機能の企画、開発および検証のため
  9. 重要なお知らせ、メンテナンス情報、アップデート情報、規約・ポリシー変更その他本サービスの運営上必要な連絡を行うため
  10. ユーザーが希望または同意した場合、または法令上認められる範囲で、キャンペーン、アンケート、新サービス、追加機能、広告、マーケティングその他関連情報を案内するため
  11. 有料プラン、有料機能、サブスクリプション、アプリ内課金その他決済に関する購入確認、課金管理、購入復元、利用権限の確認、不正購入防止のため
  12. 広告を含むサービスにおいて、広告の表示、配信、効果測定、不正広告対策、広告品質の向上のため
  13. AI関連機能を含むサービスにおいて、入力内容に基づく応答、生成、要約、分類、解析、その他AI関連機能の提供のため
  14. Health Connect等の健康・フィットネスデータを利用するサービスにおいて、ランニング記録の日付、距離、平均ペース、睡眠時間等の自動入力、運動・睡眠の記録管理、コンディション分析その他ユーザー向け健康・フィットネス関連機能の提供のため
  15. 不正利用、不正アクセス、スパム、詐欺、権利侵害、利用規約違反その他不適切な利用の防止、調査および対応のため
  16. 法令、ガイドライン、行政機関・裁判所等の命令または要請への対応のため
  17. 上記各目的に付随または関連する目的のため

当社が、ユーザーの入力内容、投稿内容、アップロード内容その他の情報を、当社または第三者のAIモデルの学習・改善目的で利用する場合は、サービス内表示、同意取得画面、設定画面その他適切な方法により、その内容、範囲、選択手段等を明示します。

第7条(AI関連機能の取扱い)

  1. 本サービスの一部では、AI関連機能を提供する場合があります。
  2. AI関連機能を利用する場合、ユーザーが入力したテキスト、画像、音声、ファイル、指示内容、利用状況、生成結果その他AI関連機能の提供に必要な情報が、当社または当社が利用する外部サービス提供事業者に送信されることがあります。
  3. ユーザーは、AI関連機能に、法令上特別な配慮を要する情報、第三者の個人情報、秘密情報、業務上の機密情報、その他入力すべきでない情報を入力する場合、その必要性、権限、公開範囲、送信先等を十分に確認するものとします。
  4. AI関連機能の性質上、生成結果には不正確、不完全または不適切な内容が含まれる場合があります。当社は、ユーザーに関する情報を、本ポリシーおよび法令に従い、AI関連機能の提供、品質維持、安全性確保、不具合調査その他必要な目的の範囲で取り扱います。

第8条(広告、Cookie、解析ツール等の利用)

  1. 当社は、本サービスの提供、ログイン状態の維持、セキュリティ確保、利用状況の分析、サービス改善、広告配信、広告効果測定等のため、Cookie、広告識別子、端末識別子、類似技術を利用します。
  2. 広告を含むサービスでは、ユーザーの利用状況、端末情報、広告識別子、Cookie等に基づき、広告の表示、広告配信、広告効果測定、不正広告対策を行うことがあります。
  3. ユーザーは、ブラウザ、端末、OS、アプリ、広告事業者その他の設定により、Cookie、広告識別子、通知、解析、広告配信等に関する設定を変更できる場合があります。ただし、これらを制限した場合、本サービスの一部機能を利用できないことがあります。
  4. 当社は、アクセス解析、障害解析、広告配信、広告効果測定その他の目的で、外部サービスを利用することがあります。この場合、送信される情報、送信先、利用目的等については、本ポリシーに定めるほか、必要に応じて本サービス内、当社Webサイト、アプリストア上の表示その他ユーザーが確認できる方法により表示します。

第9条(利用する外部サービス)

当社は、本サービスの提供にあたり、以下の外部サービスを利用することがあります。利用する外部サービスは、サービス、機能、端末、提供形態、時期により異なります。

これらの外部サービス提供事業者は、それぞれのプライバシーポリシー、利用規約、データ処理条件その他の定めに基づいて情報を取り扱う場合があります。

第10条(外部送信)

  1. 当社は、本サービスの機能提供、認証、データ保存、アクセス解析、障害解析、通知配信、広告配信、広告効果測定、課金管理、AI関連機能の提供、セキュリティ確保その他本サービスの提供に必要な目的のため、ユーザーの端末またはブラウザから、ユーザーに関する情報を当社または外部事業者に送信することがあります。
  2. 主な外部送信先、送信される可能性のある情報、利用目的は、以下のとおりです。実際に送信される情報は、利用するサービス、機能、端末、設定、利用状況により異なります。
外部サービス・送信先 主な利用目的 送信される可能性のある情報
Google LLC等(Firebase Authentication) 認証、ログイン管理、アカウント管理 メールアドレス、ユーザーID、認証に関連する識別情報、端末情報、ログ情報等
Google LLC等(Cloud Firestore) データ保存、データ同期、本サービスの機能提供 アカウント情報、ユーザーが入力・保存した情報、利用履歴、設定情報、各サービスの機能利用に伴い生成される情報等
Google LLC等(Firebase Analytics) 利用状況分析、機能改善、サービス改善 アプリ情報、端末情報、イベント情報、利用状況、広告識別子、IPアドレスその他解析に必要な情報等
Google LLC等(Firebase Crashlytics) 障害解析、不具合調査、品質改善 クラッシュ情報、エラー情報、診断情報、端末情報、OS情報、アプリ情報、ログ情報等
Google LLC等(Firebase Cloud Messaging) プッシュ通知、通知配信管理 プッシュ通知トークン、端末情報、通知設定、配信に必要な情報等
RevenueCat, Inc. サブスクリプション管理、購入確認、購入復元 ユーザーID、購入状況、購読状態、レシート情報、アプリ情報、端末情報等
Apple Inc. アプリ配信、アプリ内課金、決済処理、購入履歴管理 Apple IDに紐づく情報、購入情報、決済情報、端末情報その他Appleが定める情報
Google LLC等(Google Play) アプリ配信、アプリ内課金、決済処理、購入履歴管理 Googleアカウントに紐づく情報、購入情報、決済情報、端末情報その他Googleが定める情報
Android Health Connect 健康・フィットネス関連機能の提供、ランニング記録の日付・距離・平均ペース・睡眠時間等の自動入力、運動・睡眠の記録管理、コンディション分析 ユーザーが許可した範囲の運動データ、距離データ、睡眠データ、運動または睡眠の日時、平均ペースその他健康・フィットネス関連機能に必要な情報
広告配信・広告効果測定サービス 広告表示、広告配信、広告効果測定、不正広告対策 広告識別子、Cookie、端末情報、IPアドレス、広告の表示・閲覧・クリックに関する情報、利用状況等
AI関連サービス AI関連機能の提供、応答生成、要約、分類、解析、品質維持、安全性確保 ユーザーが入力したテキスト、画像、音声、ファイル、プロンプト、生成に必要な設定情報、ログ情報等
その他当社が利用する外部サービス提供事業者 本サービスの提供、運営、改善、保護、サポート、セキュリティ確保その他必要な目的 本サービスの提供に必要な範囲のユーザーに関する情報、端末情報、ログ情報、利用状況、エラー情報等
  1. 外部送信の停止、Cookieの無効化、広告識別子の制限、通知の停止その他の設定が可能な場合、ユーザーは、端末、OS、ブラウザ、アプリ、広告事業者その他の設定によりこれらを変更できる場合があります。ただし、外部送信を停止または制限した場合、本サービスの全部または一部を利用できないことがあります。
  2. 当社は、外部サービスの追加、変更、停止、仕様変更等に応じて、上記内容を変更することがあります。重要な変更がある場合には、本サービス内、当社Webサイトその他適切な方法により周知します。

第10条の2(Health Connect等の健康・フィットネスデータの取扱い)

  1. 当社は、健康管理、運動記録、コンディション分析その他健康・フィットネス関連機能を含むサービスにおいて、ユーザーが当該機能を利用し、Health Connectその他の連携機能へのアクセスを許可した場合に限り、Health Connect等から健康・フィットネスデータにアクセスし、取得します。
  2. 当社が取得する健康・フィットネスデータには、運動データ、距離データ、睡眠データ、運動または睡眠の日時、平均ペースその他当該機能の提供に必要な情報が含まれる場合があります。
  3. 当社は、健康・フィットネスデータを、ランニング記録の日付、距離、平均ペース、睡眠時間等の自動入力、運動・睡眠の記録管理、コンディション分析、ユーザーの利便性向上その他ユーザー向け健康・フィットネス関連機能の提供のために利用します。
  4. 健康・フィットネスデータへのアクセスおよび取得は、ユーザーがHealth Connect連携、記録の読み込み、自動入力その他該当する操作を行った場合に限り実行されます。
  5. 当社は、Health Connect等から取得した健康・フィットネスデータを、ユーザーが記録を保存した場合に限り、本サービス上で保存します。ユーザーが保存操作を行わない場合、当社は当該データを継続的に保存しません。
  6. 当社は、健康・フィットネスデータを、第三者への販売、広告配信または広告効果測定、信用判断、保険の引受・料率判断、雇用判断、医療診断その他これらに類する目的のために利用しません。また、法令により認められる場合またはユーザーの明示的な同意がある場合を除き、健康・フィットネスデータを第三者に提供しません。
  7. 健康・フィットネスデータに基づき保存された履歴または記録は、履歴画面から個別に削除できます。また、プロフィール画面その他本サービス内の所定の画面からアカウント削除を行うことにより、アカウントに紐づくデータの削除を請求または実行できます。
  8. 本サービスは、健康・フィットネスデータを用いてコンディション分析等を行う場合がありますが、医療行為、医療診断、治療、疾病の予防、医学的助言またはこれらに類する目的で提供されるものではありません。

第11条(第三者提供)

  1. 当社は、法令により認められる場合を除き、あらかじめ本人の同意を得ることなく、ユーザーの個人データを第三者に提供しません。
  2. 前項にかかわらず、以下の場合には、法令に従い、ユーザーの個人データを第三者に提供することがあります。
    1. 法令に基づく場合
    2. 人の生命、身体または財産の保護のために必要がある場合であって、本人の同意を得ることが困難であるとき
    3. 公衆衛生の向上または児童の健全な育成の推進のために特に必要がある場合であって、本人の同意を得ることが困難であるとき
    4. 国の機関、地方公共団体またはその委託を受けた者が法令の定める事務を遂行することに対して協力する必要がある場合であって、本人の同意を得ることにより当該事務の遂行に支障を及ぼすおそれがあるとき
    5. 合併、会社分割、事業譲渡その他の事業承継に伴って個人データが提供される場合
    6. その他、個人情報保護法その他法令により認められる場合
  3. 当社が、共同利用を行う場合は、共同して利用される個人データの項目、共同して利用する者の範囲、利用する者の利用目的、当該個人データの管理について責任を有する者の氏名または名称および住所ならびに法人にあってはその代表者の氏名その他法令で必要とされる事項を、あらかじめ公表または本人が容易に知り得る状態に置きます。

第12条(委託)

当社は、利用目的の達成に必要な範囲で、個人データその他ユーザーに関する情報の取扱いの全部または一部を、外部サービス提供事業者、クラウドサービス事業者、決済事業者、開発・運用・保守事業者、サポート事業者、広告・解析事業者、AI関連サービス提供事業者その他の委託先に委託することがあります。この場合、当社は、委託先に対し、必要かつ適切な監督を行います。

第13条(外国にある第三者への提供等)

当社は、外国にある事業者が提供するクラウドサービス、認証サービス、解析サービス、障害解析サービス、通知配信サービス、広告関連サービス、決済関連サービス、サブスクリプション管理サービス、AI関連サービスその他の外部サービスを利用することがあります。

当社が、外国にある第三者へ個人データを提供する場合には、個人情報保護法その他の法令に従い、必要な情報提供、本人同意の取得、基準適合体制の確認その他必要な措置を講じます。

第14条(ゲスト利用)

  1. 当社は、サービスによって、アカウント登録を行わずに利用できるゲスト利用機能を提供する場合があります。
  2. ゲスト利用においても、利用履歴、設定情報、進捗状況、端末情報その他の情報が保存される場合があります。
  3. ゲスト利用において保存された情報は、端末変更、アプリ削除、ブラウザデータ削除、認証状態の消失、その他の事情により、引き継ぎ、復元または削除の手続ができない場合があります。

第15条(通知および連絡)

  1. 当社は、プッシュ通知、アプリ内通知、電子メール、Webサイト上の表示その他の方法により、重要なお知らせ、メンテナンス情報、アップデート情報、利用状況に関する通知、サービス改善に関する案内、キャンペーン情報その他本サービスに関する情報を配信することがあります。
  2. ユーザーは、端末、アプリ、メール、ブラウザその他の設定により、通知または案内の受信可否を変更できる場合があります。ただし、サービス運営上重要な通知については、設定にかかわらず配信する場合があります。

第16条(ユーザー投稿・公開情報)

  1. 本サービスにおいて、ユーザーがプロフィール、投稿、コメント、ランキング、共有機能、公開ページその他の機能を利用する場合、ユーザーが入力または設定した情報が、他のユーザーまたは第三者に表示されることがあります。
  2. ユーザーは、公開範囲、共有先、投稿内容を確認したうえで、本サービスを利用するものとします。

第17条(未成年者の利用)

  1. 未成年者が本サービスを利用する場合は、必要に応じて、親権者その他の法定代理人の同意を得たうえで利用するものとします。
  2. 当社は、サービスの内容、対象年齢、利用態様に応じて、保護者の同意、保護者向けの説明、年齢確認、利用制限その他必要な措置を講じる場合があります。

第18条(アカウント削除およびデータ削除)

  1. ユーザーは、アプリ内またはサービス内のプロフィール画面その他所定の画面から、アカウント削除を行うことができます。
  2. Health Connect等から取得した健康・フィットネスデータに基づく履歴または記録は、履歴画面から個別に削除できます。
  3. アカウント削除により、アカウント情報、保存データ、利用履歴、設定情報、投稿内容その他本サービス上の情報の全部または一部が削除され、復元できなくなる場合があります。
  4. アカウント削除後であっても、法令上保存が必要な情報、課金・決済に関する記録、不正利用防止または紛争対応に必要な情報、バックアップに含まれる情報その他直ちに削除できない情報については、必要な範囲で保存される場合があります。
  5. アプリ内またはサービス内で削除できない情報、削除状況の確認、その他データ削除に関するお問い合わせについては、第24条のお問い合わせ先までご連絡ください。

第19条(保存期間)

  1. 当社は、取得したユーザーに関する情報を、利用目的の達成に必要な期間、または法令、会計、税務、紛争対応、不正利用防止、セキュリティ確保その他正当な目的のために必要な期間、保存します。
  2. 保存の必要がなくなった情報については、法令および当社所定の手続に従い、適切な方法により削除、消去、匿名化その他必要な措置を講じます。

第20条(安全管理措置)

当社は、取得した個人データその他ユーザーに関する情報について、漏えい、滅失、毀損、不正アクセス、不正利用その他のリスクを防止するため、当社の規模、事業内容、取り扱う情報の性質およびリスクに応じて、必要かつ適切な安全管理措置を講じます。安全管理措置の概要は以下のとおりです。

  1. 組織的安全管理措置:個人データの取扱いに関する責任者または担当者の設置、取扱状況の確認、事故発生時の報告・対応体制の整備等
  2. 人的安全管理措置:個人データを取り扱う者に対する秘密保持、社内ルールの周知、必要な教育・注意喚起等
  3. 物理的安全管理措置:端末、書類、記録媒体等の盗難、紛失、不正持出しを防止するための管理等
  4. 技術的安全管理措置:アクセス制御、認証管理、通信の暗号化、ログ管理、不正アクセス対策、脆弱性対策等
  5. 委託先管理:委託先の選定、契約、取扱状況の確認その他委託先に対する必要かつ適切な監督等
  6. 外的環境の把握:外国にある事業者または外国において個人データを取り扱う可能性のあるサービスを利用する場合における、当該外国の制度、外部サービス提供事業者の安全管理措置その他必要な事項の確認等

なお、安全管理に支障を及ぼすおそれがある情報については、具体的な内容の開示を控える場合があります。

第21条(開示、訂正、利用停止、削除等)

  1. ユーザーは、当社に対し、個人情報保護法その他の法令の定めに従い、保有個人データの利用目的の通知、開示、訂正、追加、削除、利用停止、消去、第三者提供の停止、第三者提供記録の開示を求めることができます。
  2. 前項の請求を希望する場合は、第24条のお問い合わせ先までご連絡ください。当社は、本人確認を行ったうえで、法令に従い、合理的な期間および範囲で対応します。
  3. 当社は、請求者が本人または正当な代理人であることを確認するため、登録メールアドレス、本人確認書類、代理権を確認できる書類その他必要な情報の提供を求めることがあります。
  4. 当社は、法令により対応を要しない場合、本人または第三者の権利利益を害するおそれがある場合、本サービスの適正な運営に著しい支障を及ぼすおそれがある場合、その他法令により認められる場合には、請求の全部または一部に応じないことがあります。この場合、当社は法令に従い、その旨を通知します。
  5. 開示等の請求に関する手数料は、原則として無料とします。ただし、郵送、記録媒体、特別な対応その他実費が発生する場合には、合理的な範囲で実費相当額を請求することがあります。その場合は、あらかじめ案内します。

第22条(匿名加工情報・統計情報等)

当社は、取得した情報を、特定の個人を識別できないように加工した統計情報、集計情報、匿名加工情報その他個人を識別できない情報として、本サービスの改善、新サービスの開発、分析、研究、広報、広告、その他正当な目的のために利用することがあります。

匿名加工情報を作成し、第三者に提供する場合には、個人情報保護法その他の法令に従い、必要な事項を公表します。

第23条(本ポリシーの変更)

  1. 当社は、法令の改正、本サービスの内容変更、利用する外部サービスの変更、運営上の必要その他の理由により、本ポリシーを変更することがあります。
  2. 本ポリシーを変更する場合、当社は、変更後の内容および効力発生日を、当社Webサイト、本サービス内表示、電子メールその他当社が適切と判断する方法により周知します。
  3. 法令上ユーザーの同意が必要となる変更を行う場合、当社は、法令に従い、必要な同意取得その他の手続を行います。

第24条(お問い合わせ・苦情窓口)

本ポリシー、本サービスにおけるユーザーに関する情報の取扱い、開示等の請求、苦情、相談に関するお問い合わせは、以下の窓口までご連絡ください。

クリエイトム合同会社
個人情報お問い合わせ窓口
メールアドレス:app@creatom.jp

第25条(日本語版と翻訳版)

当社が本ポリシーの翻訳版を作成する場合、翻訳版は参考のために提供されるものとします。日本語版と翻訳版との間に矛盾または相違がある場合、日本語版が優先して適用されます。

第26条(制定日・改定日)

制定日:2026年3月11日
改定日:2026年5月27日

以上

Privacy Policy

Creatom LLC (hereinafter referred to as the "Company") establishes this Privacy Policy (hereinafter referred to as this "Policy") regarding the handling of information related to users in all services provided by the Company, including applications, websites, web services, AI-related features, services including advertisements, paid features, subscriptions, and any other services provided by the Company (collectively, the "Services").

Note on Translation: This English version is provided for reference. In the event of any conflict or discrepancy between the Japanese version and any translated version, the Japanese version shall prevail.

Article 1 (Business Information)

Business Name: Creatom LLC
Representative: Yuto Nakagawa
Address: Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
Contact: app@creatom.jp

Article 2 (Scope of Application)

  1. This Policy applies commonly to the Services.
  2. The Services include applications, websites, web applications, AI-related features, paid features, subscriptions, services including advertisements, and any services incidental or related to the foregoing, whether currently or in the future provided by the Company.
  3. Third-party services, websites, applications, advertisements, and other external services linked from the Services are governed by the privacy policies, terms of use, and other rules established by such third parties.
  4. If the Company separately establishes an individual privacy policy or other rules for a specific service, such individual rules shall prevail over this Policy with respect to that service.

Article 3 (Definitions)

Terms used in this Policy shall have the meanings prescribed by the Act on the Protection of Personal Information and other applicable laws and regulations.

In this Policy, "Information Related to Users" includes personal information, personal data, retained personal data, personally referable information, cookies, advertising identifiers, device information, usage history, log information, input content, generated content, and other information acquired or generated in relation to users.

Article 4 (Information Collected)

The Company may collect the following information in providing the Services. The information collected may vary depending on the service, features, device, settings, and usage conditions.

1. Information entered or provided by users

The Company may use Google or other external authentication services for authentication, and the Company does not acquire or store user passwords. However, the Company may collect user IDs, authentication IDs, email addresses, authentication-related identifiers, and other information necessary for managing authentication status, login management, identity verification, and security.

2. Information acquired or generated through use of the Services

3. Information related to billing and payments

In providing paid plans, subscriptions, paid features, in-app purchases, and other paid services, the Company may collect purchase status, subscription status, receipt information, information necessary for purchase restoration, usage entitlements, plan information, and other information necessary for billing management.

Credit card numbers and other payment method information may be managed by Apple, Google, and other payment service providers, and may not be directly acquired or stored by the Company.

4. Information related to advertising

In services that include advertisements, the Company may acquire or transmit to external advertising-related business operators advertising identifiers, cookies, device information, IP addresses, information regarding advertisement displays, views, and clicks, usage status of applications or websites, and information necessary for measuring advertising effectiveness.

5. Information related to AI-related features

In services that include AI-related features, the Company may acquire or transmit to external AI-related service providers texts, images, audio, files, prompts, instructions, usage status, generated results, setting information necessary to provide AI features, log information, and other information necessary for providing AI-related features, maintaining quality, investigating defects, and ensuring safety.

6. Health and fitness data related to Health Connect, etc.

In Services that include health management, activity tracking, condition analysis, or other health and fitness-related features, the Company may access and collect exercise data, distance data, sleep data, dates and times of exercise or sleep, average pace, and other health and fitness data necessary to provide such features only when the user uses the relevant feature and grants access to Health Connect or other linked functions.

7. Information acquired through external services

The Company may use external services necessary for providing the Services, including authentication, data storage, access analytics, error analysis, notification delivery, advertising, advertising effectiveness measurement, payment processing, subscription management, AI-related features, linked functions such as Health Connect, and other purposes, and may acquire information through such external services to the extent necessary.

8. Sensitive personal information and similar information

The Company does not, in principle, request users to provide personal information requiring special care under applicable laws. If a user provides such information or other sensitive information through free-entry fields, inquiries, AI-related features, upload features, or other functions, the user shall do so only to the minimum extent necessary, and the Company will handle such information in accordance with applicable laws.

Article 5 (Collection Methods)

The Company collects Information Related to Users by the following methods.

  1. When users start using the Services through registration, login, guest use, external service integration, or other methods
  2. When users use various features of the Services, including settings, posting, saving, inquiries, problem reporting, AI-related features, paid features, advertising-related features, and other features
  3. When users apply for, purchase, renew, cancel, or restore purchases for paid plans or otherwise perform billing-related operations
  4. When users enter, send, save, post, upload, or share information on the Services
  5. When device information, log information, usage status, analytics information, crash information, advertising-related information, and similar information are automatically transmitted through the Services or external services
  6. When the Company receives communications from users by email, forms, in-app inquiries, or other methods

Article 6 (Purposes of Use)

The Company uses Information Related to Users for the following purposes.

  1. To provide, operate, maintain, protect, and improve the Services
  2. For identity verification, authentication, login management, and account management
  3. To record, display, synchronize, and manage guest use, usage status, settings, history, progress, results, content, and other information on the Services
  4. To provide various features of the Services, including AI-related features, generation features, analysis features, notification features, sharing features, and advertising-related features
  5. To provide displays, functions, convenience improvements, and personalization according to users' usage status
  6. To respond to inquiries, verify identity, provide support, and respond to problem reports
  7. To investigate defects, respond to failures, improve quality, ensure security, and resolve technical or operational issues
  8. To analyze usage, create statistical information, improve features and services, and plan, develop, and verify new services or features
  9. To provide important notices, maintenance information, update information, changes to terms or policies, and other operationally necessary communications
  10. To provide information about campaigns, surveys, new services, additional features, advertisements, marketing, and related matters where requested or consented to by users or where permitted by law
  11. To confirm purchases, manage billing, restore purchases, confirm usage entitlements, and prevent fraudulent purchases related to paid plans, paid features, subscriptions, in-app purchases, and other payments
  12. To display and deliver advertisements, measure advertising effectiveness, prevent advertising fraud, and improve advertising quality in services including advertisements
  13. To provide responses, generation, summaries, classification, analysis, and other AI-related features based on input content in services including AI-related features
  14. In Services that use health and fitness data from Health Connect or similar functions, to automatically enter running record dates, distances, average pace, sleep duration, and similar information, to manage exercise and sleep records, to analyze condition, and to provide other user-facing health and fitness-related features
  15. To prevent, investigate, and respond to unauthorized use, unauthorized access, spam, fraud, infringement of rights, violations of terms of use, and other improper use
  16. To respond to laws, regulations, guidelines, and orders or requests from administrative agencies, courts, and similar bodies
  17. For purposes incidental or related to the foregoing

If the Company uses user input content, posted content, uploaded content, or other information for the purpose of training or improving AI models of the Company or a third party, the Company will clearly indicate the details, scope, available choices, and other relevant matters by in-service display, consent screen, settings screen, or other appropriate methods.

Article 7 (Handling of AI-Related Features)

  1. Some Services may provide AI-related features.
  2. When using AI-related features, texts, images, audio, files, instructions, usage status, generated results, and other information necessary to provide AI-related features may be transmitted to the Company or external service providers used by the Company.
  3. When entering information requiring special care under laws, third-party personal information, confidential information, business secrets, or other information that should not be entered into AI-related features, users shall sufficiently confirm the necessity, authority, scope of disclosure, transmission destination, and other relevant matters.
  4. Due to the nature of AI-related features, generated results may include inaccurate, incomplete, or inappropriate content. The Company handles Information Related to Users in accordance with this Policy and applicable laws within the scope necessary for providing AI-related features, maintaining quality, ensuring safety, investigating defects, and other necessary purposes.

Article 8 (Advertising, Cookies, Analytics Tools, etc.)

  1. The Company uses cookies, advertising identifiers, device identifiers, and similar technologies for providing the Services, maintaining login status, ensuring security, analyzing usage, improving the Services, delivering advertisements, and measuring advertising effectiveness.
  2. In services that include advertisements, the Company may display and deliver advertisements, measure advertising effectiveness, and prevent advertising fraud based on users' usage status, device information, advertising identifiers, cookies, and similar information.
  3. Users may be able to change settings related to cookies, advertising identifiers, notifications, analytics, and advertisement delivery through their browser, device, OS, application, advertising operator, or other settings. However, restricting such settings may make some or all features of the Services unavailable.
  4. The Company may use external services for access analytics, error analysis, advertising delivery, advertising effectiveness measurement, and other purposes. In such cases, information transmitted, transmission destinations, purposes of use, and other relevant matters shall be described in this Policy and, where necessary, displayed in the Services, on the Company's website, on app store pages, or by other methods accessible to users.

Article 9 (External Services Used)

The Company may use the following external services in providing the Services. External services used may vary depending on the service, features, device, form of provision, and timing.

These external service providers may handle information in accordance with their respective privacy policies, terms of use, data processing terms, and other rules.

Article 10 (External Transmission)

  1. The Company may transmit Information Related to Users from users' devices or browsers to the Company or external business operators for purposes necessary for the Services, including feature provision, authentication, data storage, access analytics, error analysis, notification delivery, advertising, advertising effectiveness measurement, billing management, AI-related features, and security.
  2. The main external transmission destinations, information that may be transmitted, and purposes of use are as follows. Information actually transmitted may vary depending on the service, features, device, settings, and usage status.
External Service / Destination Main Purposes of Use Information That May Be Transmitted
Google LLC, etc. (Firebase Authentication) Authentication, login management, account management Email address, user ID, authentication-related identifiers, device information, log information, etc.
Google LLC, etc. (Cloud Firestore) Data storage, data synchronization, provision of service features Account information, information entered or saved by users, usage history, settings, information generated through use of service features, etc.
Google LLC, etc. (Firebase Analytics) Usage analysis, feature improvement, service improvement App information, device information, event information, usage status, advertising identifiers, IP address, and other information necessary for analytics, etc.
Google LLC, etc. (Firebase Crashlytics) Error analysis, defect investigation, quality improvement Crash information, error information, diagnostic information, device information, OS information, app information, log information, etc.
Google LLC, etc. (Firebase Cloud Messaging) Push notifications, notification delivery management Push notification tokens, device information, notification settings, information necessary for delivery, etc.
RevenueCat, Inc. Subscription management, purchase confirmation, purchase restoration User ID, purchase status, subscription status, receipt information, app information, device information, etc.
Apple Inc. App distribution, in-app purchases, payment processing, purchase history management Information associated with Apple ID, purchase information, payment information, device information, and other information determined by Apple
Google LLC, etc. (Google Play) App distribution, in-app purchases, payment processing, purchase history management Information associated with Google accounts, purchase information, payment information, device information, and other information determined by Google
Android Health Connect Providing health and fitness-related features, automatically entering running record dates, distances, average pace, sleep duration, managing exercise and sleep records, and condition analysis Exercise data, distance data, sleep data, dates and times of exercise or sleep, average pace, and other information necessary for health and fitness-related features, to the extent permitted by the user
Advertisement delivery and advertising effectiveness measurement services Advertisement display and delivery, advertising effectiveness measurement, advertising fraud prevention Advertising identifiers, cookies, device information, IP address, information regarding ad displays, views, and clicks, usage status, etc.
AI-related services Provision of AI-related features, response generation, summarization, classification, analysis, quality maintenance, safety assurance Texts, images, audio, files, prompts entered by users, setting information necessary for generation, log information, etc.
Other external service providers used by the Company Provision, operation, improvement, protection, support, and security of the Services and other necessary purposes Information Related to Users necessary for providing the Services, device information, log information, usage status, error information, etc.
  1. Where settings are available to stop external transmission, disable cookies, restrict advertising identifiers, stop notifications, or take similar measures, users may be able to change such settings through their device, OS, browser, application, advertising operator, or other settings. However, if external transmission is stopped or restricted, some or all of the Services may become unavailable.
  2. The Company may change the above details due to additions, changes, suspension, specification changes, or similar changes to external services. In the event of material changes, the Company will provide notice in the Services, on the Company's website, or by other appropriate methods.

Article 10-2 (Handling of Health and Fitness Data such as Health Connect Data)

  1. In Services that include health management, activity tracking, condition analysis, or other health and fitness-related features, the Company accesses and collects health and fitness data from Health Connect or similar functions only when the user uses the relevant feature and grants access to Health Connect or such linked functions.
  2. The health and fitness data collected by the Company may include exercise data, distance data, sleep data, dates and times of exercise or sleep, average pace, and other information necessary to provide the relevant features.
  3. The Company uses health and fitness data to automatically enter running record dates, distances, average pace, sleep duration, and similar information, to manage exercise and sleep records, to analyze condition, to improve user convenience, and to provide other user-facing health and fitness-related features.
  4. Access to and collection of health and fitness data is performed only when the user performs an applicable action, such as linking Health Connect, reading records, or using automatic entry.
  5. The Company stores health and fitness data obtained from Health Connect or similar functions in the Services only when the user saves a record. If the user does not perform a save action, the Company does not continuously store such data.
  6. The Company does not use health and fitness data for sale to third parties, ad delivery or ad measurement, credit decisions, insurance underwriting or rate decisions, employment decisions, medical diagnosis, or similar purposes. Except where permitted by law or with the user's explicit consent, the Company does not provide health and fitness data to third parties.
  7. History or records saved based on health and fitness data can be deleted individually from the history screen. Users may also request or perform deletion of data linked to their account by deleting their account from the profile screen or other designated screens within the Services.
  8. The Services may perform condition analysis using health and fitness data, but the Services are not provided for medical practice, medical diagnosis, treatment, disease prevention, medical advice, or similar purposes.

Article 11 (Provision to Third Parties)

  1. Except as permitted by law, the Company will not provide users' personal data to third parties without obtaining the user's prior consent.
  2. Notwithstanding the preceding paragraph, the Company may provide users' personal data to third parties in accordance with laws in the following cases:
    1. When based on laws and regulations
    2. When necessary to protect a person's life, body, or property, and it is difficult to obtain the person's consent
    3. When especially necessary to improve public health or promote the sound development of children, and it is difficult to obtain the person's consent
    4. When it is necessary to cooperate with a national government agency, local government, or a person entrusted by them in performing affairs prescribed by laws and regulations, and obtaining the person's consent may impede the performance of such affairs
    5. When personal data is provided in connection with a merger, company split, business transfer, or other business succession
    6. Other cases permitted by the Act on the Protection of Personal Information or other laws and regulations
  3. If the Company jointly uses personal data, the Company will make public or place in a state readily accessible to users the items of personal data jointly used, the scope of joint users, the purposes of use by joint users, the name and address of the person responsible for managing such personal data, the representative's name in the case of a corporation, and other matters required by law.

Article 12 (Entrustment)

The Company may entrust all or part of the handling of personal data and other Information Related to Users to external service providers, cloud service providers, payment providers, development, operation, and maintenance contractors, support providers, advertising and analytics providers, AI-related service providers, and other contractors to the extent necessary to achieve the purposes of use. In such cases, the Company will exercise necessary and appropriate supervision over such contractors.

Article 13 (Provision to Third Parties Located in Foreign Countries, etc.)

The Company may use cloud services, authentication services, analytics services, error analysis services, notification delivery services, advertising-related services, payment-related services, subscription management services, AI-related services, and other external services provided by business operators located in foreign countries.

When the Company provides personal data to a third party located in a foreign country, the Company will take necessary measures, such as providing required information, obtaining consent, confirming systems conforming to applicable standards, and other measures in accordance with the Act on the Protection of Personal Information and other applicable laws.

Article 14 (Guest Use)

  1. Some Services may provide guest-use features that allow use without account registration.
  2. Even during guest use, usage history, settings, progress status, device information, and other information may be stored.
  3. Information stored during guest use may not be transferred, restored, or deleted due to device changes, app deletion, browser data deletion, loss of authentication status, or other circumstances.

Article 15 (Notifications and Communications)

  1. The Company may deliver important notices, maintenance information, update information, notifications related to usage status, information regarding service improvements, campaign information, and other information related to the Services by push notifications, in-app notifications, email, website displays, or other methods.
  2. Users may be able to change whether to receive notifications or information through device, application, email, browser, or other settings. However, operationally important notices may be delivered regardless of such settings.

Article 16 (User Posts and Public Information)

  1. If users use profile, posting, commenting, ranking, sharing, public page, or other features in the Services, information entered or set by users may be displayed to other users or third parties.
  2. Users shall use the Services after confirming the scope of disclosure, sharing destinations, and posted content.

Article 17 (Use by Minors)

  1. If minors use the Services, they shall use the Services with the consent of a parent or other legal representative as necessary.
  2. The Company may take necessary measures, such as obtaining parental consent, providing explanations to parents, age verification, and usage restrictions, according to the content, target age, and usage mode of the Services.

Article 18 (Account Deletion and Data Deletion)

  1. Users may delete their accounts from the profile screen or other designated screens within the application or service.
  2. History or records based on health and fitness data obtained from Health Connect or similar functions can be deleted individually from the history screen.
  3. Account deletion may delete all or part of account information, saved data, usage history, settings, posted content, and other information on the Services, and such information may become unrecoverable.
  4. Even after account deletion, information required to be retained by law, records related to billing and payments, information necessary for preventing unauthorized use or handling disputes, information included in backups, and other information that cannot be immediately deleted may be retained to the extent necessary.
  5. For information that cannot be deleted within the application or service, confirmation of deletion status, or other inquiries regarding data deletion, please contact the inquiry desk specified in Article 24.

Article 19 (Retention Period)

  1. The Company retains Information Related to Users for the period necessary to achieve the purposes of use or for the period necessary for legitimate purposes such as legal, accounting, tax, dispute handling, prevention of unauthorized use, and security purposes.
  2. When information no longer needs to be retained, the Company will delete, erase, anonymize, or otherwise take necessary measures by appropriate methods in accordance with laws and the Company's prescribed procedures.

Article 20 (Security Management Measures)

The Company takes necessary and appropriate security management measures to prevent leakage, loss, damage, unauthorized access, unauthorized use, and other risks concerning personal data and other Information Related to Users, according to the Company's size, business content, nature of information handled, and risks. The outline of security management measures is as follows.

  1. Organizational security management measures: Appointment of a person or staff responsible for handling personal data, confirmation of handling status, and establishment of reporting and response systems in the event of incidents
  2. Human security management measures: Confidentiality obligations, dissemination of internal rules, and necessary education and reminders for persons handling personal data
  3. Physical security management measures: Management to prevent theft, loss, and unauthorized removal of devices, documents, recording media, and similar items
  4. Technical security management measures: Access control, authentication management, encryption of communications, log management, measures against unauthorized access, vulnerability measures, and similar measures
  5. Contractor management: Selection of contractors, contracts, confirmation of handling status, and other necessary and appropriate supervision of contractors
  6. Understanding of external environments: Where services provided by foreign business operators or services that may handle personal data in foreign countries are used, confirmation of the systems of such foreign countries, security management measures of external service providers, and other necessary matters

The Company may refrain from disclosing specific details that could interfere with security management.

Article 21 (Disclosure, Correction, Suspension of Use, Deletion, etc.)

  1. Users may request the Company to notify the purpose of use, disclose, correct, add, delete, suspend use, erase, suspend provision to third parties, and disclose third-party provision records regarding retained personal data in accordance with the Act on the Protection of Personal Information and other applicable laws.
  2. If users wish to make such requests, please contact the inquiry desk specified in Article 24. The Company will respond within a reasonable period and scope in accordance with laws after verifying identity.
  3. The Company may request registered email addresses, identification documents, documents confirming authority of representation, and other necessary information to confirm that the requester is the user or a legitimate representative.
  4. The Company may refuse all or part of a request where the Company is not required to respond under laws, where responding may harm the rights and interests of the user or a third party, where responding may significantly impede the proper operation of the Services, or where otherwise permitted by laws. In such cases, the Company will notify the requester in accordance with laws.
  5. Fees for requests such as disclosure are generally free of charge. However, if postage, recording media, special handling, or other actual costs arise, the Company may charge a reasonable amount equivalent to such actual costs. In such cases, the Company will provide prior notice.

Article 22 (Anonymously Processed Information, Statistical Information, etc.)

The Company may use acquired information as statistical information, aggregated information, anonymously processed information, or other information that cannot identify specific individuals, after processing it so that specific individuals cannot be identified, for legitimate purposes such as improving the Services, developing new services, analysis, research, public relations, and advertising.

If the Company creates anonymously processed information and provides it to third parties, the Company will disclose necessary matters in accordance with the Act on the Protection of Personal Information and other applicable laws.

Article 23 (Changes to this Policy)

  1. The Company may change this Policy due to changes in laws, changes in the content of the Services, changes in external services used, operational necessity, or other reasons.
  2. When changing this Policy, the Company will notify users of the changed content and effective date through the Company's website, in-service displays, email, or other methods deemed appropriate by the Company.
  3. If consent is required by law for a change, the Company will obtain necessary consent and take other procedures in accordance with laws.

Article 24 (Inquiry and Complaint Desk)

For inquiries regarding this Policy, handling of Information Related to Users in the Services, requests such as disclosure, complaints, or consultations, please contact the following desk.

Creatom LLC
Personal Information Inquiry Desk
Email: app@creatom.jp

Article 25 (Japanese Version and Translations)

If the Company prepares a translated version of this Policy, the translated version is provided for reference purposes. In the event of any conflict or discrepancy between the Japanese version and any translated version, the Japanese version shall prevail.

Article 26 (Date of Establishment and Revision)

Established: March 11, 2026
Revised: May 27, 2026

End of Policy