KAWARIMI Privacy Policy

Last updated: 2026-09-26

This Policy sets forth the handling of personal information and photos obtained by the provider of the photo transformation app "KAWARIMI" (hereinafter referred to as the "Service"; the provider is hereinafter referred to as the "Operator," and business operator information is set forth in Article 19) in the course of providing the Service.

The Operator complies with the Act on the Protection of Personal Information of Japan and other relevant laws, regulations, and guidelines, and handles personal information in accordance with this Policy.

Article 1 (Scope of Application)

This Policy applies to all personal information handled by the Operator in the course of providing the Service (including the application and the web version). The handling of personal information in third-party services accessed from the Service is governed by the rules of such third parties.

Article 2 (Information Obtained)

The Operator obtains the following information in the course of providing the Service.
(1) Account information: identifiers obtained upon authentication through Apple or Google. The Operator does not obtain the User's password.
(2) Information relating to generation: the photo selected by the User for generation (hereinafter referred to as the "Subject Photo"), the mask image used to specify the generation, and the Generated Output.
(3) Avatar Image: the image, only if registered by the User.
(4) Information relating to notifications: the token identifying the notification destination, the type of operating system, and the application version.
(5) Information relating to billing: whether purchases have been made, and records of Credits granted and consumed. Payment-related processing is performed by the payment processor.
(6) Technical records: access logs and error logs necessary for the operation of the Service, the investigation of failures, and the prevention of unauthorized use.

Article 3 (Information Not Obtained)

The Operator does not obtain the following information.
(1) The User's password.
(2) Credit card numbers and other payment method details (handled by the payment processor).
(3) Photos on the device other than the photo selected by the User for generation, and any listing of the photo library.
(4) Location information, contacts, and call history.
(5) Behavioral history using advertising identifiers.

Article 4 (Purpose of Use)

The Operator uses the information obtained for the following purposes.
(1) Provision of the Service, execution of generation, and display of Generated Output.
(2) Authentication and management of accounts.
(3) Storage and display of generation history and registered Avatar Images.
(4) Management of the granting, consumption, and purchase of Credits.
(5) Sending of notifications.
(6) Detection and prevention of unauthorized use, and ensuring the safety of the Service.
(7) Investigation of the causes of failures and improvement of the quality of the Service (including statistical processing in a form that does not identify individuals).
(8) Responding to inquiries.
(9) Compliance with laws and regulations.

Article 5 (Processing and Deletion of Subject Photos)

1. Detection of persons appearing in photos is performed within the User's device. At this stage, no photo is transmitted to the Operator's server.
2. Only when the User instructs the execution of generation is one selected photo transmitted to the Operator's server (infrastructure provided by Cloudflare, Inc.).
3. The Operator provides the Subject Photo to the external image generation services set forth in Article 6 for the execution of generation.
4. After the completion of the generation process (regardless of whether generation succeeds or fails), the Operator deletes the Subject Photo from the Operator's server. Subject Photos are not made available for viewing or retrieval by the User.

Article 6 (Provision to External Image Generation Services and Prohibition on Use for Training)

1. For the execution of generation, the Operator transmits Subject Photos to image generation services provided by the following businesses.
(1) The image generation API of OpenAI, L.L.C. (the normal generation route).
(2) The Grok image generation API of xAI Corp. (an alternative route used when generation cannot be performed via (1) due to a safety determination or other reasons). Photos are not always sent to both.
2. Subject Photos are not used for the training of artificial intelligence models by the Operator, OpenAI, L.L.C., or xAI Corp. OpenAI, L.L.C. provides that input received through the API is not used for training by default, and the Operator has disabled the setting relating to provision for training. xAI Corp. also provides that API input and output are not used for training without permission.
3. The retention of transmitted data is as follows.
(1) OpenAI, L.L.C.: may retain transmitted data for up to 30 days for purposes such as monitoring for abuse, after which it is deleted.
(2) xAI Corp.: the Operator applies a Zero Data Retention setting, under which API requests and responses (including input and generated images) are not stored long-term by that company.
(3) The Operator's server: the Subject Photo is promptly deleted after the completion of the generation process.
4. Except as set forth in the preceding paragraphs, handling by each business is governed by the privacy policies and terms of use established by that business.

Article 7 (Outsourcing of Operations)

To the extent necessary for the provision of the Service, the Operator outsources operations to the following businesses and causes them to handle personal data. The Operator exercises necessary and appropriate supervision over the recipients.
(1) Cloudflare, Inc.: provision of servers, databases, and object storage.
(2) Clerk, Inc.: provision of the user authentication infrastructure.
(3) RevenueCat, Inc.: management of paid plans, purchases, and subscription status.
(4) Stripe, Inc.: payment processing.
(5) OneSignal, Inc.: delivery of push notifications.
(6) The businesses listed in Article 6: execution of image generation.

Article 8 (Provision to Third Parties in Foreign Countries)

1. The provision and outsourcing set forth in Articles 6 and 7 constitute the provision of personal data to third parties in foreign countries. The recipients, the countries in which they are located, and the measures taken are as follows.
(1) OpenAI, L.L.C. (United States of America): execution of image generation. In addition to handling based on that company's terms of use and privacy policy, the Operator has disabled the setting relating to provision for training.
(2) xAI Corp. (United States of America): execution of image generation via the alternative route. The Operator applies a Zero Data Retention setting.
(3) Cloudflare, Inc. (United States of America): servers and storage. Data may be processed in facilities located in multiple countries or regions operated by that company.
(4) Clerk, Inc. (United States of America): authentication.
(5) RevenueCat, Inc. (United States of America): management of paid plans, purchases, and subscription status.
(6) Stripe, Inc. (United States of America): payment processing.
(7) OneSignal, Inc. (United States of America): delivery of push notifications. It handles the token identifying the notification destination, the type of operating system, the application version, and records of notification delivery and opening.
2. Information on the system for the protection of personal information in the United States of America may be found in the survey results on foreign systems published by the Personal Information Protection Commission of Japan (https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/ ).
3. Each recipient has established a policy on the secure management of personal data, and the Operator makes such provision in accordance with those policies and the terms applicable between the Operator and each company.
4. By commencing use of the Service, the User consents to the provision to third parties in foreign countries set forth in this Article.

Article 9 (Provision to Third Parties)

Except in the cases set forth in Articles 6 through 8, the Operator will not provide personal data to any third party without the User's consent. However, this does not apply where required by law, where necessary for the protection of the life, body, or property of a person, or in other cases permitted by the Act on the Protection of Personal Information of Japan. The Operator does not sell personal data.

Article 10 (Payment Information)

1. Purchases and subscription management for paid plans and one-time packs are provided through RevenueCat Billing by RevenueCat, Inc., and payments are processed by Stripe, Inc. Credit card numbers are never stored on the Operator's server.
2. The Operator retains records of purchases, amounts, subscription status, and Credit balances.
3. Handling by RevenueCat, Inc. and Stripe, Inc. is governed by each company's privacy policy.

Article 11 (Cookies and Behavioral Analysis)

1. The Operator has not introduced identifiers for behavioral targeting advertising or third-party behavioral analysis mechanisms into the Service.
2. The Operator may handle the minimum technical records necessary for the operation of the Service and the prevention of unauthorized use (including cookies, local storage, and access logs).

Article 12 (Retention Period)

The Operator retains the information obtained for the following periods, after which it is deleted.
(1) Subject Photos: deleted after the completion of the generation process (regardless of whether generation succeeds or fails).
(2) Generated Output and mask images: until deleted by the User or until the account is deleted.
(3) Avatar Images: until deleted by the User or until the account is deleted.
(4) Account information and notification information: until the account is deleted.
(5) Records relating to purchases and Credits: for the period required by law.
(6) Technical records: for the period necessary to respond to failures and prevent unauthorized use.

Article 13 (Security Management Measures)

The Operator takes the following measures to prevent the leakage, loss, or damage of personal data and to otherwise manage security.
(1) Encryption of communications (TLS).
(2) Access control using an authentication infrastructure, and a design that limits access to a User's data to that User.
(3) Limitation of authority to handle personal data.
(4) Minimization of retained data through the operational practice of deleting Subject Photos after the completion of the generation process.
(5) Monitoring through access logs and error logs.

Article 14 (Requests for Disclosure, Correction, Suspension of Use, etc.)

1. The User may request of the Operator notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, and suspension of provision to third parties, with respect to retained personal data.
2. Requests under the preceding paragraph shall be made by email to the contact point set forth in Article 19.
3. The Operator will respond after confirming that the person making the request is the individual concerned, by cross-checking information associated with the account or by other methods.
4. After receiving a request, the Operator will, in principle, respond by email within two weeks.
5. No fee is charged for requests under the preceding paragraphs.

Article 15 (Deletion of Data and Accounts)

1. The User may delete registered Avatar Images and generation history through in-app operations.
2. The User may request deletion of the account. Upon deletion of the account, the Operator deletes the associated data. However, minimal records may be retained to the extent necessary for the prevention of unauthorized use and as required by law.

Article 16 (Personal Information of Minors)

1. Persons under the age of 13 may not use the Service.
2. Persons under the age of 18 shall use the Service only with the consent of a parent or other legal representative.
3. If the Operator becomes aware that it has obtained personal information of a person under the age of 13, the Operator will promptly delete such information.

Article 17 (Response in the Event of Leakage, etc.)

In the event of a leakage, loss, or damage of personal data, or any other situation likely to harm the rights and interests of individuals, the Operator will, in accordance with laws and regulations, report to the Personal Information Protection Commission of Japan and notify the individuals concerned.

Article 18 (Revision of This Policy)

1. The Operator may revise this Policy in response to amendments to laws and regulations or changes to the content of the Service.
2. If the Operator revises this Policy, the Operator will make known the revised content and the time at which it takes effect by display within the app or by any other method the Operator deems appropriate.
3. For revisions that have a material impact on the User, the Operator may obtain consent in advance.

Article 19 (Business Operator Information and Contact for Complaints)

Inquiries regarding this Policy, requests under Article 14, and complaints are accepted at the following contact point.

Business operator: 垣花 恵祐
Person responsible for the management of personal information: 垣花 恵祐
Contact: eightbeat8b@gmail.com