AI English Lover
AI English Loverプライバシーポリシー / Privacy Policy
AI English Loverに適用されるプライバシーポリシーを、 日本語版、English versionの順に掲載します。
Japanese / 日本語
プライバシーポリシー
最終更新: 2026-09-05 JST
プライバシーポリシー
Emmaは、英語練習のためのAIロールプレイパートナーです。本アプリは、AI音声会話、 Direct Chat、関係性の継続、英語力向上機能、ローカル通知およびサブスクリプション アクセスを提供します。本ポリシーはリリース候補版の実装について説明するものであり、 本製品が提供していないアカウント同期や復元を約束するものではありません。
この端末に保存される情報
本アプリは、アプリが管理する次のような製品状態を端末内に保存します。
- ユーザーが18歳以上であると自己確認したかどうか、および適用される年齢ポリシーの バージョン。本アプリは生年月日を収集または保存しません。
- 表示名、および上限を設けたオンボーディング・設定情報。
- Emma Chatのメッセージ、および上限を設けたCall(通話)の履歴・振り返り。
- RelationshipおよびScenario・Continuationの進行状態。
- Memory、Shared HistoryおよびShared Milestoneの表示状態。
- Natural Expression History、および会話内容を含まないEnglish Progress Evidence。
- 初回無料Callの状態、通知スケジュール、および購入フロー上の位置。
- 上限を設けた、内容を含まないローカル分析データ(FIFO方式で最大500件)。
- 音声リクエストが処理中または再試行可能な間の一時音声。
初回リリースでは、これらのEmmaの状態は端末内にのみ保存されます。製品アカウントや、 サーバーによる同期・復元サービスはありません。本アプリを再インストールした場合や端末を 変更した場合、Relationship、Memory、Shared History、Chat履歴、会話の進行状態、 Natural Expression Historyおよび英語力の進捗は、永久に失われる可能性があります。
AI会話の処理
音声の文字起こし、Emmaからの返信およびCall後の分析を提供するため、本アプリは、 マイク音声、ユーザーが入力したテキスト、確定した字幕、および関連するローカル情報のうち 上限を設けた一部を、製品バックエンドを経由してOpenAIへ送信することがあります。 この情報には、プロフィール・設定、Relationship policy、最近のMemoryまたはShared History、 および選択されたNatural Expressionが含まれる場合があります。バックエンドアプリケーションは、 音声、文字起こし、Memoryのテキスト、Shared HistoryのテキストまたはExpressionのテキストを、 永続的なauthority storeへ保存しません。
処理中のリクエストとしてすでに送信された情報は、ローカルデータを削除しても処理が完了する 場合があり、送信後に取り戻すことはできません。本アプリは、削除後にそのリクエストを 再試行しません。
運営者は、本番Projectについて、OpenAIのmodel feedbackの共有、evaluation・fine-tuningの 共有およびinput/outputの共有を無効にしています。本アプリは、これらのAPI callについて、 OpenAI側でのアプリケーション保存を明示的に要求しません。特別な 保持期間短縮設定が適用されていることを前提としておらず、Zero Data Retentionを保証 しません。このリリース候補版について確認したOpenAI APIの標準データ管理では、 Chat CompletionsおよびRealtimeの内容が、不正利用監視用ログに最大30日間保持される 場合があります。Audio Transcriptionsについて示されている標準の不正利用監視目的の 保持期間は「なし」です。Realtime sessionの一部として処理される音声には、Realtimeの 境界が適用されます。OpenAIは、顧客が明示的に同意しない限りAPIデータをモデルの 学習に使用しないと説明しており、本番Projectの共有設定は無効です。
サブスクリプションとRevenueCat
本アプリは、製品の表示、購入または購入の復元、およびサブスクリプションアクセスが 有効かどうかの判定のため、AppleのApp StoreサブスクリプションシステムとRevenueCatを 使用します。アカウントがない場合、RevenueCatはanonymous App User IDを使用します。 バックエンドは、premium entitlementを検証するためにそのIDを一時的に 受け取る場合がありますが、raw RevenueCat App User IDを永続的なauthority storeへ保存しません。
RevenueCatは、anonymous App User ID、Offering・package・product identifier、購入履歴、 App Storeのreceiptおよびtransaction情報、entitlementの状態、Restore request、ならびに 標準的なSDK技術情報を処理します。技術情報には、アプリ、SDK、プラットフォーム、OS、 端末、言語・地域設定、storefront、networkおよびrequestの詳細が含まれる場合があります。 現在のRevenueCat iOS SDKは、利用可能な場合、Identifier for Vendor(IDFV)も標準的な request metadataとして送信します。Emmaは、custom App User ID、プロフィール名、 メールアドレス、電話番号、年齢確認、会話内容、custom Customer Attributesまたは アプリレベルの広告identifierをRevenueCatへ提供しません。
本番RevenueCat Projectには、webhook、scheduled data export、analytics、attribution、広告、 marketingまたはsupport integrationは設定されていません。本アプリはApp Tracking Transparencyの許可を要求せず、広告SDKまたはattribution SDKを含みません。RevenueCatは、 それ自身のサービス管理方針に基づき、購入・顧客recordおよび技術recordを保持する場合が あります。
Restore Purchasesで復元されるのは、対象となるサブスクリプションアクセスのみです。EmmaのRelationship、Memory、Shared History、Chat履歴、ScenarioまたはContinuationの 進行状態、Natural Expression History、English Progress Evidenceは復元されません。 Projectは、必要に応じてpurchaseを新しいApp User IDへtransferするよう設定されており、 sandboxに別のrestore behaviorは設定されていません。anonymous identityは再インストールや ローカルデータ削除後に変わることがあるため、RestoreによってApp Store transactionが 新しいRevenueCatのanonymous customer identityと関連付けられる場合があります。
会話内容を含まないbackend authority data
Callの認可、Day 0の不正利用防止、信頼性、rate limitingおよびbudget operationのため、 本番バックエンドは、次のような会話内容を含まない運用metadataを永続的に保存します。
- opaqueなauthority subjectおよびhashed identity binding。
- Callのauthority・ownership、experience、state、expiryおよびattempt metadata。
- idempotencyおよびcompletion identity。
- Day 0のreservation・consumptionおよびprovider-attempt state。
- rate-window、およびbudgetのreservation・commit state。
このstoreには、文字起こし、音声、Memory・Shared History・Expressionのテキスト、raw prompt、 raw RevenueCat App User ID、authorization token、provider secretまたはRevenueCat secretは 含まれません。この運用上のauthority dataはEmmaのアカウント同期ではなく、削除された ローカルのEmmaの状態を復元することはできません。
期限切れのgrantおよびrequest windowは、短いreplay余裕期間の後に物理的にcompactされます。 idempotency、completion、Call、rateおよびrealtime-minute recordは、active・recovery windowに 限って保持され、該当する場合の上限を設けた物理cleanupの余裕期間を加えても、通常は 24時間を超えて保持されません。前日のbudget identityはUTCの日付変更時に削除されます。 消費済みDay 0の詳細stateは、24時間後に、subjectごとに1件のminimal pseudonymous consumed markerへ縮小されます。同じsubjectへのintroductory free accessの繰り返しを防止するため、 このmarkerは最終的な消費時刻から最大365日間保持されます。markerに含まれるのは、 pseudonymous subject binding、consumed statusおよび消費時刻だけであり、会話recordや 購入recordではありません。このmarkerは、同じpseudonymous installation-derived identityに のみ適用されます。この期間について1人につき無料Callが1回だけであることを保証するもの ではありません。再インストールまたはDelete Allによって新しいidentityが作成され、backendが 以前のmarkerと確実に関連付けられない場合があります。
分析、crash reportingおよび広告
製品分析データは現在、上限を設けた、内容を含まないイベントとして端末内にのみ保存されます。 イベントのmetadataには、上限を設けたproduct phase、result category、Call engine、milestone kind またはerror categoryが含まれる場合があります。transcript、Chat・Memory・Shared History・ Expression text、raw prompt、access tokenまたはraw installation・RevenueCat user identifierは 含まれません。
このリリース候補版には、外部analytics SDK、外部crash-reporting SDK、広告SDK、 attribution SDKまたはcross-app tracking SDKはありません。IDFAまたはApp Tracking Transparencyの許可を要求しません。RevenueCatの広告、analytics、attributionまたはmarketing integrationは設定されていません。本アプリおよびその処理事業者は、アプリデータを第三者広告 またはアプリ横断広告の測定に使用しません。最上位のerror screenは、例外messageまたは stack traceを長期的な分析データとして保存しません。
通知
許可が付与された場合、本アプリはEmma Callのローカル通知をスケジュールします。 通知文はアプリが管理するtemplateから選ばれ、Memoryまたは会話テキストをlock screenに 表示しません。Delete All Local Dataは、スケジュール済みおよび配信済みのEmmaアプリ通知の identifierを削除します。
Delete All Local Data
本アプリのPrivacy & dataを開き、Delete All Local Dataを選択してください。本アプリは、その端末から、 ローカルの年齢確認、プロフィール、Chat・Call履歴、Relationship、Memory、 Shared History、Natural Expression History、English Progress Evidence、進行状態、local analytics、通知、一時録音、およびアプリが管理するローカルアクセスデータを削除します。 モバイルbackend clientのprocess内に保持されているproduction access grant、Call scope、 pending Call-start identityおよびraw RevenueCat App User IDは、上限を設けたactive Callの cleanup後に消去されます。プロフィールまたはprovider処理を再開するには、年齢gateで 再確認する必要があります。
Delete All Local Dataでは、次の処理は行われません。
- App Storeサブスクリプションの解約。
- Appleのtransaction recordまたはRevenueCatのcustomer・purchase recordの削除。
- Restore PurchasesによるEmma stateの復元。
- 認可、重複防止、Day 0の消費および上限を設けたoperationのために維持される、backendの 会話内容を含まないauthority・safety ledgerの削除。
サブスクリプションの管理または解約には、Appleのサブスクリプション管理機能を使用して ください。適用されるprivacy requestについては、NextProLabが継続監視するprivacy・support 問い合わせ窓口であるcontact@nextprolab.comへご連絡ください。RevenueCatのcustomer・provider recordに関するリクエストは、 Delete All Local DataおよびAppleのサブスクリプション解約とは別に取り扱われます。 RevenueCat customer recordの削除はAppleのサブスクリプションを解約するものではなく、 その後のRestoreによってApp Store transactionがRevenueCatへ再送信される場合があります。
初回リリースには、ユーザー単位でbackend authorityを削除するtoolはありません。永続的な authority storeは、設計上raw installation IDまたはraw RevenueCat App User IDを保持しないため、 ローカルidentityの削除後は、運営者がpseudonymous authority recordを申請者と安全に 関連付けられない場合があります。運営者は、その時点で安全に利用可能なidentifierとproviderの 機能に基づいてリクエストを検討します。本ポリシーは、確実に特定できないrecordの削除、または 文書化された保護期間中維持する必要がある、上限を設けたsecurity・access recordの削除を 約束するものではありません。
外部処理事業者と保持期間
実装済みの外部処理事業者は、AI・文字起こし処理を行うOpenAIと、サブスクリプションアクセスを 処理するRevenueCatです。AppleはApp Storeでの購入を処理します。外部analytics providerまたは crash providerは追加されていません。
本番hostはruntime logを7日間、service metricを7日間保持します。Application logは、 会話content、raw RevenueCat・installation identifierおよびcredentialを除外するよう設計されて いますが、hostingのrequest metadataには、IP address、route、status、timestampおよびrequest ID などのnetwork・technical identifierが含まれる場合があります。アクセスは本番運用者に 制限されています。securityおよびreliability対応に必要な最小限のtechnicalまたはpseudonymous 証拠のみを含むredacted incident recordは、適用される保全措置により異なる対応が必要な場合を 除き、180日間保持される場合があります。Service metricは集約された運用測定値であり、 行動profilingには使用されません。
上記の外部controlに関する記述は、このリリース候補版について確認したproduction設定および provider documentationを反映しています。API endpoint、SDK、integration、Project controlまたは providerの条件が変更された場合は、再確認する必要があります。
年齢と安全性
この初回リリースは、18歳以上の方のみを対象としています。プロフィール入力、マイクへのアクセス、 AI処理またはサブスクリプション提供事業者の初期化の前に、本アプリはユーザーへ18歳以上である ことの自己確認を求めます。生年月日を要求または保存しません。18歳未満であると回答した ユーザーは先へ進めません。この年齢制限は、想定する成人ユーザー層および初回リリースの データ・プライバシー範囲を反映するものであり、露骨な性的contentを意味するものではありません。 Emmaの振る舞いは引き続きPG-13であり、性的contentおよび依存を誘導する感情操作を禁止します。
変更とお問い合わせ
重要な変更は、発効日および公開済みポリシーを更新することで反映します。
公開ポリシーURL: https://nextprolab.com/privacy/ai-english-lover
プライバシー窓口:contact@nextprolab.com
公開チェックリスト
- Completed: 運営者名を確認済み。
- Not completed: 発効日および法務確認を確認済み。
- Completed: 継続監視するプライバシー・support窓口を確認済み。
- Completed: Day 0 minimal tombstoneの保持期間を365日と定め、文書化済み。
- Not completed: 実在する公開HTTPSのPrivacy Policy URLを公開し、設定済み。
- Completed: 本番hosting、logging、accessおよびretentionを確認済み。
- Completed: OpenAIおよびRevenueCatの本番controlとstandard retention basisを、 このリリース候補版について確認済み。
- Not completed: App Store App Privacyの回答を
docs/PHASE7_PRIVACY_DATA_MAP.mdおよびdocs/APP_PRIVACY_OWNER_CHECKLIST.mdと照合済み。 - Not completed: Delete、Restore、subscription cancellation、再インストールおよび端末変更に関する 説明を、出荷するbuildと照合済み。
English version
Privacy Policy
Last updated: 2026-09-05 JST
Privacy Policy
Emma is an AI roleplay partner for English practice. The app provides AI voice conversations, Direct Chat, relationship continuity, English-progress features, local notifications, and subscription access. This policy describes the release-candidate implementation; it does not promise account sync or recovery that the product does not provide.
Information stored on this device
The app stores app-owned product state locally, including:
- whether the user self-confirmed that they are 18 or older and the applicable age-policy version; the app does not collect or store a date of birth;
- display name and bounded onboarding/preferences;
- Emma Chat messages and bounded Call history/recaps;
- Relationship and Scenario/Continuation progression;
- Memory, Shared History, and Shared Milestone presentation state;
- Natural Expression History and content-free English Progress Evidence;
- first-free-Call state, notification schedule, and purchase-flow position;
- bounded, content-free local analytics (up to 500 FIFO events); and
- temporary audio while a voice request is active or retryable.
This Emma state is local-only for the first release. There is no product account or server-sync/recovery service for it. Reinstalling the app or changing devices may permanently lose Relationship, Memory, Shared History, Chat history, conversation progression, Natural Expression History, and English progress.
AI conversation processing
To provide voice transcription, Emma's replies, and post-Call analysis, the app may send microphone audio, user text, final captions, and a bounded subset of relevant local context through the product backend to OpenAI. Context can include profile/preferences, Relationship policy, recent Memory or Shared History, and a selected Natural Expression. The backend application does not persist audio, transcript, Memory text, Shared History text, or Expression text in its durable authority store.
Information already submitted for an active request may finish processing and cannot be recalled by deleting local data. The app does not retry that request after deletion.
The operator has disabled OpenAI model-feedback sharing, evaluation and fine-tuning sharing, and input/output sharing for the production Project. The app does not explicitly request provider-side application storage for these API calls. No special reduced-retention configuration is assumed. Under the standard OpenAI API data controls verified for this release candidate, Chat Completions and Realtime content may be kept in abuse-monitoring logs for up to 30 days. The standard abuse-monitoring retention listed for Audio Transcriptions is none; audio processed as part of a Realtime session remains subject to the Realtime boundary. OpenAI states that API data is not used to train its models unless the customer explicitly opts in, and the production Project's sharing options are disabled.
Subscription and RevenueCat
The app uses Apple's App Store subscription system and RevenueCat to present products, complete or restore a purchase, and determine whether subscription access is active. RevenueCat uses an anonymous App User ID when no account is available. The backend may receive that ID transiently to verify the premium entitlement, but does not persist the raw RevenueCat App User ID in its durable authority store.
RevenueCat processes the anonymous App User ID, Offering/package/product identifiers, purchase history, App Store receipt and transaction information, entitlement state, Restore requests, and standard SDK technical information. Technical information can include app, SDK, platform, operating-system, device, locale, storefront, network, and request details; the current RevenueCat iOS SDK also sends the Identifier for Vendor (IDFV) as standard request metadata when it is available. Emma does not provide RevenueCat with a custom App User ID, profile name, email address, phone number, age confirmation, conversation content, custom Customer Attributes, or app-level advertising identifiers.
The production RevenueCat Project has no configured webhook, scheduled data export, analytics, attribution, advertising, marketing, or support integration. The app does not request App Tracking Transparency permission and contains no advertising or attribution SDK. RevenueCat may still retain purchase/customer and technical records under its own service controls.
Restore Purchases restores eligible subscription access only. It does not restore Emma's Relationship, Memory, Shared History, Chat history, Scenario or Continuation progress, Natural Expression History, or English Progress Evidence. The Project is configured to transfer purchases to the new App User ID when needed, with no separate sandbox restore behavior. Because anonymous identity can change after reinstall or local deletion, a Restore may associate the App Store transaction with a new RevenueCat anonymous customer identity.
Content-free backend authority data
For Call authorization, Day 0 abuse protection, reliability, rate limiting, and budget operations, the production backend durably stores content-free operational metadata such as:
- an opaque authority subject and hashed identity bindings;
- Call authority/ownership, experience, state, expiry, and attempt metadata;
- idempotency and completion identities;
- Day 0 reservation/consumption and provider-attempt state; and
- rate-window and budget reservation/commit state.
This store excludes transcript, audio, Memory/Shared History/Expression text, raw prompts, raw RevenueCat App User ID, authorization tokens, and provider or RevenueCat secrets. This operational authority data is not Emma account sync and cannot reconstruct deleted local Emma state.
Expired grants and request windows are physically compacted after their short replay margins. Idempotency, completion, Call, rate, and realtime-minute records are retained only for their active/recovery window and normally no longer than 24 hours, plus a bounded physical-cleanup margin where applicable. Prior-day budget identities are removed at UTC day rollover. Detailed consumed Day 0 state is reduced after 24 hours to one minimal pseudonymous consumed marker per subject. To prevent repeated introductory free access for the same subject, that marker has a maximum retention period of 365 days from the final consumption time. It contains only the pseudonymous subject binding, consumed status, and consumption time; it is not a conversation or purchase record. The marker applies only to the same pseudonymous installation-derived identity. It does not guarantee one free Call per person over that period: a reinstall or Delete All can create a new identity that the backend cannot reliably link to the prior marker.
Analytics, crash reporting, and advertising
Product analytics are currently stored only on the device as bounded, content-free events. Event metadata may describe a bounded product phase, result category, Call engine, milestone kind, or error category. It does not contain transcript, Chat/Memory/Shared History/Expression text, raw prompts, access tokens, or raw installation/RevenueCat user identifiers.
The release candidate has no external analytics SDK, external crash-reporting SDK, advertising SDK, attribution SDK, or cross-app tracking SDK. It does not request IDFA or App Tracking Transparency permission. No RevenueCat advertising, analytics, attribution, or marketing integration is configured. The app and its processors do not use app data for third-party advertising or cross-app advertising measurement. The root error screen does not persist exception messages or stack traces as long-term analytics.
Notifications
If permission is granted, the app schedules local notifications for Emma Calls. Notification copy is selected from app-owned templates and does not place Memory or conversation text on the lock screen. Delete All Local Data removes Emma's scheduled and delivered app notification identities.
Delete All Local Data
Open Privacy & data in the app and choose Delete All Local Data. The app removes its local age confirmation, profile, Chat/Call history, Relationship, Memory, Shared History, Natural Expression History, English Progress Evidence, progression, local analytics, notifications, temporary recordings, and app-owned local access data from that device. In-process production access grants, Call scopes, pending Call-start identities, and the raw RevenueCat App User ID held by the mobile backend client are cleared after bounded active-Call cleanup. The age gate is shown again before profile or provider processing can resume.
Delete All Local Data:
- does not cancel an App Store subscription;
- does not erase Apple's transaction record or RevenueCat's customer/purchase record;
- does not turn Restore Purchases into Emma-state recovery; and
- does not delete the backend's content-free authority/safety ledger, which is maintained for authorization, duplicate prevention, Day 0 consumption, and bounded operations.
Manage or cancel a subscription using Apple's subscription controls. Contact contact@nextprolab.com, NextProLab's monitored privacy and support inquiry address, for an applicable privacy request. A request concerning RevenueCat customer/provider records is handled separately from Delete All Local Data and separately from Apple subscription cancellation. Deleting a RevenueCat customer record does not cancel an Apple subscription, and a later Restore can send the App Store transaction to RevenueCat again.
The first release has no per-user backend-authority deletion tool. Its durable authority store intentionally keeps no raw installation ID or raw RevenueCat App User ID, so after local identity is deleted the operator may not be able to safely associate a pseudonymous authority record with a requester. The operator will assess a request using the identifiers and provider capabilities that are then safely available; this policy does not promise deletion of a record that cannot be reliably identified or deletion of bounded security/access records that must remain for their documented protection period.
External processors and retention
The implemented external processors are OpenAI for AI/transcription processing and RevenueCat for subscription access. Apple processes App Store purchases. No external analytics or crash provider has been added.
The production host retains runtime logs for 7 days and service metrics for 7 days. Application logs are designed to exclude conversation content, raw RevenueCat/installation identifiers, and credentials, but hosting request metadata can include network and technical identifiers such as IP address, route, status, timestamp, and request ID. Access is restricted to the production operator. A redacted incident record containing only the minimum technical or pseudonymous evidence needed for security and reliability response may be kept for 180 days, unless an applicable hold requires different handling. Service metrics are aggregate operational measurements and are not used for behavioral profiling.
The external-control statements above reflect the production settings and provider documentation verified for this release candidate. They must be reviewed again if an API endpoint, SDK, integration, Project control, or provider term changes.
Children and safety
This first release is intended only for people who are 18 years of age or older. Before profile entry, microphone access, AI processing, or subscription-provider initialization, the app asks the user to self-confirm that they are at least 18. It does not request or store a date of birth. A user who indicates that they are under 18 cannot proceed. This age boundary reflects the intended adult audience and the first-release data/privacy scope; it does not indicate explicit sexual content. Emma's behavior remains PG-13 and prohibits sexual content and manipulative emotional dependency.
Changes and contact
Material changes will be reflected by updating the effective date and the published policy.
Public policy URL: https://nextprolab.com/privacy/ai-english-lover
Privacy contact: contact@nextprolab.com
Publication checklist
- Completed: operator name confirmed;
- Not completed: effective date and legal review confirmed;
- Completed: monitored privacy/support contact confirmed;
- Completed: Day 0 minimal-tombstone retention set to 365 days and documented;
- Not completed: real public HTTPS Privacy Policy URL published and configured;
- Completed: production hosting/logging/access/retention verified;
- Completed: OpenAI and RevenueCat production controls and standard retention basis verified for the release candidate;
- Not completed: App Store App Privacy answers reconciled with
docs/PHASE7_PRIVACY_DATA_MAP.mdanddocs/APP_PRIVACY_OWNER_CHECKLIST.md; and - Not completed: Delete, Restore, subscription cancellation, reinstall, and device-change copy reviewed against the shipped build.