← トップページへ戻る
Rakutoon Privacy Policy
1. Introduction
Welcome to Rakutoon ("the App"). Rakutoon is a fitness and health management application that helps you easily track your daily training and diet. This Privacy Policy explains how we collect, use, store, and protect your personal information.
We are committed to protecting your privacy and ensuring the security of your personal data. This policy describes our practices regarding data collection and usage in accordance with applicable privacy laws.
2. Information We Collect
2.1 Authentication Data
- Email address and password (when using email/password authentication)
- Google account information (email, name, ID token, access token) when using Google Sign-In
- Apple account information (email, name) when using Apple Sign-In
- Firebase User ID (UID) assigned to your account
2.2 Profile Information
- Display name and avatar image
- Gender and date of birth
- Height (cm) and weight (kg)
2.3 Health and Fitness Data
- Workout logs (exercise name, category, reps, weight, notes, date and time)
- Cardio logs (exercise type, duration, distance, average heart rate, calories burned, notes, date and time)
- Custom exercise definitions
- Workout templates and usage history
2.4 HealthKit Data (iOS only, with explicit permission)
- Heart rate, active energy burned, walking/running distance
- Workout sessions, respiratory rate, height, weight, biological sex, date of birth
2.5 App Settings and Preferences (stored locally)
- Weight unit preference, theme mode, onboarding completion status
- HealthKit integration status, summary display settings
2.6 Device Information
- Platform (iOS, Android, etc.), app version
- Device identifiers for error tracking and analytics
2.7 Usage Data
- App usage patterns and feature interactions (via Firebase Analytics)
- Crash reports and error logs (via Firebase Crashlytics and Sentry)
2.8 Advertising Data
- Advertising identifiers (e.g., IDFA on iOS) when you allow tracking
- Ad impressions, clicks, and other interaction data related to ads
- Device information and IP address that may be used for ad delivery and fraud prevention
- Tracking permission status (e.g., App Tracking Transparency choice)
3. How We Use Your Information
We use the collected information for the following purposes:
- App Functionality: To provide core features such as workout tracking, cardio logging, and profile management
- Cloud Backup and Sync: To store your data in Firebase Firestore and sync across devices
- Error Tracking: To identify and fix bugs using Firebase Crashlytics and Sentry
- Performance Analysis: To understand app usage patterns and improve user experience via Firebase Analytics
- Personalization: To customize your app experience based on your preferences and settings
- Advertising: To display ads, measure their performance, and (if permitted) provide personalized ads
- Security: To verify the authenticity of requests using Firebase App Check
4. Data Storage and Security
4.1 Storage Locations
Firebase Services (Google Cloud - asia-northeast1, Tokyo):
- Firebase Firestore: User profiles, workout logs, cardio logs, custom exercises, and templates
- Firebase Storage: Avatar images (max 5MB, formats: jpg/jpeg/png/gif/webp)
- Firebase Authentication: Authentication credentials and user identity
Local Device Storage (SharedPreferences):
- App settings, preferences, and HealthKit integration status
4.2 Security Measures
- Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest in Firebase services
- Firebase App Check: iOS devices use App Attest (iOS 14.0+) with DeviceCheck fallback to verify app authenticity
- User Data Isolation: Firestore Security Rules ensure users can only access their own data
- File Upload Restrictions: Avatar images are limited to 5MB and specific file formats
- Access Controls: Only authenticated users can read/write their own data
5. Third-Party Services
We use the following third-party services to provide and improve our app:
5.1 Firebase (Google)
- Firebase Authentication: User authentication and identity management
- Firebase Firestore: Cloud database for storing user data
- Firebase Storage: Cloud storage for avatar images
- Firebase Crashlytics: Crash reporting (disabled in debug mode)
- Firebase Analytics: Usage analytics and app performance monitoring
- Firebase App Check: App authenticity verification
Privacy Policy: https://firebase.google.com/support/privacy
5.2 Sentry
- Purpose: Error tracking and performance monitoring
- Data Collected: Error logs, stack traces, breadcrumbs (up to 100), device information
- Sampling: 70% transaction sampling in production
- Session Tracking: Automatic session tracking enabled
Privacy Policy: https://sentry.io/privacy/
5.3 microCMS
- Purpose: Content management for exercise definitions (read-only)
- Data Sent: No personal data is sent to microCMS
5.4 Google Sign-In / Apple Sign-In
- Purpose: OAuth2 authentication flow
- Data Received: Email, name, and authentication tokens
5.5 HealthKit (iOS only)
- Purpose: Access health and fitness data with explicit user permission
- Data Processing: HealthKit data is processed locally on your device and is NOT sent to external servers
Privacy Policy: https://www.apple.com/legal/privacy/
5.6 Google AdMob (Google Mobile Ads)
- Purpose: Serving banner ads and measuring ad performance
- Data Collected: Advertising identifiers, ad interaction data, device information, and IP address (as required for ad delivery and fraud prevention)
Privacy Policy: https://policies.google.com/privacy
Ads Information: https://policies.google.com/technologies/ads
6. HealthKit-Specific Disclosures
Important: HealthKit integration is optional and requires explicit user permission.
6.1 Data Types Accessed
- Heart Rate, Active Energy Burned, Walking/Running Distance
- Workout Sessions, Respiratory Rate
- Height, Weight, Biological Sex, Date of Birth
6.2 How HealthKit Data is Used
- To display health metrics alongside your workout logs
- To calculate workout intensity and effectiveness
- All HealthKit data is processed locally on your device only
- HealthKit data is NOT uploaded to Firebase or any external servers
6.3 Managing HealthKit Permissions
You can manage HealthKit permissions at any time:
- Go to iOS Settings → Health → Data Access & Devices → Rakutoon
- Toggle individual data types on or off
- Revoking permissions will stop the app from accessing HealthKit data
6.4 No Use of Health Data for Advertising
We do NOT use your health data for advertising or marketing purposes. HealthKit data is used solely to provide app functionality.
7. Data Retention and Deletion
7.1 Data Retention Period
- Active Accounts: Data is retained as long as your account is active
- Inactive Accounts: Data may be retained for up to 12 months after your last login
- Deleted Accounts: Data is deleted within 30 days of account deletion
7.2 Deleting Your Data
You can delete your data in the following ways:
- Individual Records: Delete workout logs, cardio logs, or custom exercises within the app
- Profile Data: Edit or delete profile information in the app settings
- Account Deletion: Currently, account deletion must be requested via email (see Contact Information below). We are working on implementing an in-app account deletion feature.
7.3 Data Deletion Process
When you delete your account:
- All personal data is permanently deleted from Firebase Firestore and Storage
- Authentication credentials are removed from Firebase Authentication
- Anonymized analytics data may be retained for statistical purposes
- HealthKit data is automatically removed from the app (but remains in Apple Health)
8. Your Rights
Depending on your location, you may have the following rights:
8.1 Access and Portability
- You can view and access all your data within the app
- Data export functionality is not currently available but is planned for future releases
8.2 Correction
- You can edit your profile information, workout logs, and settings within the app
8.3 Deletion
- You can delete individual records within the app
- For account deletion, please contact us at the email address below
8.4 Opt-Out
- Analytics: Analytics data collection is enabled by default. To opt out, please contact us.
- Advertising: You can disable personalized ads by denying tracking permission (iOS: Settings → Privacy & Security → Tracking). You may still see non-personalized ads.
- HealthKit: You can revoke HealthKit permissions in iOS Settings at any time
8.5 Region-Specific Rights
- GDPR (EU/EEA): Right to access, rectification, erasure, restriction, portability, and objection
- CCPA (California): Right to know, delete, and opt-out of sale (we do NOT sell personal data)
9. International Data Transfers
Your data may be transferred to and processed in locations outside your country of residence:
- Firebase Services: Hosted in Google Cloud (asia-northeast1, Tokyo, Japan)
- Sentry: Headquartered in the United States
- Data Protection: We use standard contractual clauses and other safeguards to ensure data protection
10. Children's Privacy
Rakutoon is intended for users aged 13 and above. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use this app or provide any personal information.
If we discover that we have collected personal information from a child under 13, we will delete that information immediately. If you believe we have collected information from a child under 13, please contact us.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
We will respond to your inquiry within 30 days.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:
- The "Last Updated" date at the top of this policy will be revised
- Significant changes will be communicated through in-app notifications or email
- Continued use of the app after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically.
13. Developer Information
This Privacy Policy is effective as of February 3, 2026.