FLARE / LEGAL / PRIVACY

Privacy Policy

LAST UPDATED

EFFECTIVE DATE

Article 1 General Provisions

Siremo Inc. (Head Office: Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo; Representative: Yuki Kaneda; hereinafter referred to as the “Company”) establishes this Privacy Policy (hereinafter referred to as the “Policy”) regarding the handling of personal information and other data of users of “Flare” (hereinafter referred to as the “Service”), a service provided by the Company, and persons who begin the account-registration process. The Company complies with the Act on the Protection of Personal Information of Japan and other applicable laws, regulations, and guidelines, and endeavors to protect their privacy.

Article 2 Information We Collect

The Company collects the following information when a person uses the Service or begins the account-registration process:

  1. Account registration information
    • Identifiers and email addresses provided through authentication using an Apple or Google account
    • A name or other initial display name provided by Apple or Google
    • The birth year and birth month entered by the user (the Company does not collect the day of birth)
    • The user's preference concerning receipt of news and special offers by email
    • A display name and icon selected by the user (from combinations of designs and colors provided by the Company or an image uploaded by the user)
  2. Service usage information
    • Image data and capture dates and times for photos taken by the user
    • Information concerning Rolls (the units in which photos are shared), including their names, creation dates and times, unlock dates and times, participating members, and invitations
  3. Device and application information
    • Device type, operating system, application version, language settings, network environment, and similar information
    • App-instance IDs, identifiers for vendors, and other identifiers used to distinguish an application installation
    • Approximate location at the country or regional level based on IP addresses and similar information
  4. Analytics information concerning use of the Service
    • Information concerning first launch or first launch after reinstallation, session starts, engagement time, screens displayed, and similar activity
    • Authentication method and result; whether and how features are used, including creation, joining, and unlocking of Rolls; opening, sharing, and processing of invitations; taking photos; updating statuses; and updating profiles
    • Analytics events configured by the Company do not include Firebase Authentication user IDs, email addresses, display names, birth years or months, Roll names or IDs, invitation codes, tokens or URLs, photo data or photo URLs, status emoji or text, or the contents of error messages
  5. Crash and issue diagnostic information
    • Stack traces and application state at the time of a crash; device, operating-system, and application-version information; and identifiers used to distinguish a crash report or application installation
    • The processing area, processing stage, classified error type, and numeric code for issues arising in authentication, push-notification registration, photo upload or download, Roll synchronization, and similar operations
    • Non-fatal diagnostic information configured by the Company does not include Firebase Authentication user IDs, email addresses, display names, birth years or months, Roll names or IDs, invitation codes, tokens or URLs, status emoji or text, photo data, photo URLs or storage references, authentication tokens, push-notification device identifiers, or the contents of error messages
  6. Report and moderation information
    • Identifiers of the reporting and reported users; the reported photo or other User Content; the Roll identifier; the reason, details, and date and time of the report
    • Review findings, response status, measures taken, and other information created by the Company when handling a report or investigating a violation of the Terms
  7. Technical information generated when viewing the Company’s website
    • Browser information, cookies, and other information transmitted through use of the website
  8. Payment information (when using paid services)
    • Information concerning subscriptions and use of paid services

Article 3 Purposes of Use

The Company uses the information it collects for the following purposes:

  • To provide and operate the Service and manage user accounts
  • To verify whether a new registrant meets the minimum registration age and prevent registration by persons under 13
  • To determine whether an account may be registered and delete authentication information when registration is not permitted
  • To improve the Service, develop new features, and enhance quality
  • To aggregate and analyze use of the Service, retention, and usage trends for key features and user flows
  • To detect and analyze crashes and issues and improve the stability and quality of the Service
  • To prevent unauthorized use and maintain security
  • To respond to inquiries and provide support
  • To send news and special offers by email only when requested by the user
  • To receive and review reports, investigate violations of the Terms, protect children, and prevent harm
  • To disable access to, isolate, or remove violating content; restrict use; suspend accounts; and take other necessary measures
  • To deliver advertising and promotions and conduct marketing research
  • To investigate breaches of contracts or terms and comply with legal requirements
  • To preserve necessary evidence and report to or cooperate with law enforcement and other appropriate authorities
  • To exercise rights and perform obligations under applicable laws

The Company uses birth years and months to verify the minimum age at new registration and does not use them for advertising, marketing analytics, feature recommendations, or display to other users.

Article 4 Special Provisions Concerning Photos and Sharing

The Service is designed to allow users to share photos they take with other members participating in the same Roll.

  1. Photos taken by a user are sent to the Company’s servers immediately after capture and stored by the Company until the unlock time.
  2. Before the unlock time, users cannot view any photos in the Roll, including photos they have taken themselves.
  3. After the unlock time, all members participating in the same Roll can view every photo in that Roll together with the display name and icon of the user who took each photo.
  4. The Company does not use users’ photos for advertising or other promotional purposes and does not provide them to third parties for machine learning or other purposes.
  5. Notwithstanding the preceding paragraphs, authorized Company personnel may review a reported photo or other information when necessary to handle a report, investigate a violation of the Terms, protect children, respond to a security issue, or comply with applicable law.

Article 5 Analytics, Advertising, and External Services

  1. The Company may display advertisements for the Company or third parties within the Service.
  2. The Company uses Google Analytics and Google Analytics for Firebase (Firebase Analytics), provided by Google LLC, to understand use of the Service, analyze retention and key features and user flows, and improve the Service.
  3. Information transmitted to Google Analytics from the Company’s website includes cookies and other online identifiers, browser and device information, traffic sources, pages viewed, approximate location at the country or regional level, session information, and interaction events such as link clicks.
  4. The Company loads the Google Analytics tag and transmits the information described above only when a website visitor allows analytics. Declining analytics does not affect use of the Service or the Company’s website.
  5. The analytics choice is stored for up to 12 months in a first-party cookie shared by the Company’s website and invitation links. Visitors may change or withdraw their choice at any time through “Analytics preferences” in the website footer.
  6. Information transmitted to Firebase Analytics includes app-instance IDs, device and application information, approximate location at the country or regional level, session information, and interaction events within the Service. This includes information automatically collected by Firebase Analytics and events configured by the Company within the scope of Article 2.4.
  7. As of the date this Policy was last updated, the Company does not configure Firebase Analytics in the iOS version of the Service to collect or transmit Apple’s Identifier for Advertisers (IDFA).
  8. The Company uses Firebase Crashlytics, provided by Google LLC, to detect and analyze crashes and issues and improve the stability and quality of the Service.
  9. Firebase Crashlytics automatically receives stack traces and application state at the time of a crash, device, operating-system, and application-version information, Crashlytics installation identifiers, Firebase installation IDs, and similar information. It also receives non-fatal diagnostic information configured by the Company within the scope of Article 2.5.
  10. The Company does not set a user ID in Firebase Crashlytics and limits diagnostic information configured by the Company to the fixed classification data described in Article 2.5.
  11. Crash reports and related information stored in Firebase Crashlytics are retained in accordance with the retention policy published by Google LLC. As of the date this Policy was last updated, the standard retention period is 90 days.
  12. Please refer to Google LLC’s privacy policy and other published materials for information about how Google LLC handles data.

Article 6 Provision of Information to Third Parties

The Company does not provide collected information to third parties except in the following cases:

  • With the user’s consent
  • When required by law
  • When necessary to protect a person’s life, body, or property and it is difficult to obtain the user’s consent
  • When the handling of information is entrusted to a contractor specified in the following Article to the extent necessary to provide the Service

Sharing photos, display names, and icons with members participating in the same Roll is an essential function of the Service and does not constitute provision of information to a third party.

When necessary to protect children, prevent harm, or comply with applicable law, the Company may provide report information, User Content, and other necessary information to law enforcement or other appropriate authorities in accordance with applicable law.

Article 7 Use of External Services

The Company uses the following external services to provide the Service and entrusts the handling of information to them to the extent necessary:

  • Google LLC (Google Analytics, Firebase Authentication, Cloud Firestore, Cloud Storage, Firebase Cloud Messaging, Firebase Analytics, Firebase Crashlytics, and Google Cloud Platform) — authentication, storage of data and photos, delivery of notifications, measurement and analysis of Service usage, and diagnosis of crashes and issues
  • Apple Inc. (Sign in with Apple) — authentication

Please refer to each provider’s privacy policy for information about how that provider handles data.

Article 8 Retention and Deletion of Information

  1. The Company retains collected information for as long as necessary to provide the Service.
  2. Users may delete their accounts at any time from the account screen in the Service.
  3. When an account is deleted, the Company deletes the user’s authentication information, email address, display name, icon, birth year and month, and email-delivery preference. Photos that the user shared with a Roll before account deletion will remain in that Roll without the photographer’s display name or icon because those photos also form part of the record shared by the Roll’s other members.
  4. If a new registrant does not meet the minimum registration age, the Company does not create a Flare account and promptly deletes the Firebase Authentication information created on Flare’s behalf for the registration process. This does not delete the person’s Apple account or Google account.
  5. If the deletion described in the preceding paragraph cannot be completed immediately because of a network failure or another reason, the Company will retry the deletion and take necessary measures to avoid retaining the authentication information beyond the period required for the registration process.
  6. The Company retains information that must be preserved by law only for the required period.
  7. The Company retains information necessary to handle reports, prevent harm, preserve evidence, or cooperate with the appropriate authorities only for as long as necessary to fulfill those purposes or comply with applicable law.

Article 9 User Rights

Users may make the following requests regarding their personal information held by the Company:

  • Disclosure
  • Correction, addition, or deletion
  • Suspension of use or erasure
  • Suspension of provision to third parties

Requests must be submitted using the method prescribed by the Company.

The Company may charge a fee of JPY 1,000 per request for disclosure or a related procedure.

Article 10 Security Measures

The Company implements necessary and appropriate security measures, including encryption of communications and management of access permissions, to prevent unauthorized access to, loss, destruction, alteration, or leakage of collected information.

Article 11 Changes to This Policy

The Company may amend this Policy in response to changes in applicable laws or the Service. The Company will provide advance notice of material changes within the Service or on the Company’s website.

Article 12 Contact Information

For inquiries concerning this Policy, please contact:

Siremo Inc.

Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo, Japan
flare-support@siremo.co.jp
Flare Support