Shikishi.app

Privacy Policy

The operator of Shikishi.app (hereinafter referred to as the "Company") establishes this Privacy Policy (hereinafter referred to as "this Policy") regarding the handling of Users' personal information in this Service, as follows.

Last Updated: July 30, 2026
01

Article 1 (Personal Information)

"Personal Information" refers to "personal information" as defined in the Act on the Protection of Personal Information of Japan, meaning information about a living individual that can identify a specific individual by name, date of birth, address, phone number, email address, or other descriptions contained in such information (including information that can be readily collated with other information, thereby enabling the identification of a specific individual), and information containing individual identification codes.

For Users residing outside Japan, references to "Personal Information" in this Policy shall be read to also include "personal data" as defined in the EU General Data Protection Regulation (GDPR) and the UK GDPR, and "personal information" as defined in the California Consumer Privacy Act (CCPA), in each case to the extent those laws apply to the User. See Article 12 for region-specific disclosures.

02

Article 2 (Methods of Collecting Personal Information)

The Company may ask for personal information such as name and email address when a User registers to use the Service. Users may also optionally register their date of birth and gender. In addition, when Users place an order for delivery of postcards or similar items (available in Japan only), we will ask for the recipient's name, address, and phone number. Purchases of digital content (digital shikishi templates, coins, etc.) are processed through the billing system of the Apple App Store (Apple Inc.) or Google Play (Google LLC). Payment for products involving physical delivery, such as postcards, is processed through a payment service provider (Stripe, Inc.). In either case, information related to payment methods, such as credit card information, is acquired and managed by each payment provider, and the Company does not retain credit card numbers. The Company may collect records of transactions and payment-related information conducted between Users and the Company's business partners, from such partners.

In addition to the above, the Company may acquire the following information in providing this Service.

  • Identifiers issued for Guest Use (use without registration) — For guest users, the Company does not collect registration information such as name or email address; however, in order to provide the Service, the Company issues an anonymous user identifier (user ID) and handles it in association with the other information described in this Article and with the content created or posted by the user. If a guest user subsequently registers, that identifier and the associated data are carried over to the registered account.
  • Device tokens / push notification tokens (Firebase Cloud Messaging) — for delivering push notifications
  • Information stored in cookies and local storage (localStorage) — to maintain login sessions, improve the convenience of the Service, and understand usage conditions
  • Device information, device identifiers (used for managing push notifications across multiple devices, etc.), browser type, IP address, access logs, etc.
  • Text entered by Users when using the AI generation feature (including selections and free-text answers to questions, message body text, and revision instructions) — for AI generation processing, this is sent, depending on the model selected by the User, to Google LLC (Gemini), Anthropic PBC (Claude), or OpenAI, L.L.C. (GPT) (hereinafter collectively referred to as the "AI Providers"; all located in the United States).
  • Meta information such as the dimensions and file size of image, video, and audio materials used in the AI generation feature — this is sent to the AI Providers via the same route as above. The actual image, video, and audio files (binary data) are not sent to the AI Providers for AI generation processing, and are stored on storage managed by the Company (Firebase Storage, provided by Google LLC).
  • The HTML/CSS/JavaScript most recently generated by the AI, used during the revision phase of the AI generation feature — this is sent to the AI Providers via the same route as above, as context for revision instructions.
  • Information for preventing unauthorized use — through the use of Firebase App Check (App Attest / DeviceCheck on iOS, Play Integrity on Android), information for verifying the legitimacy of the app and device, as well as IP addresses, etc., is sent to Google LLC. The handling of this information is governed by Google LLC's Privacy Policy.
  • Usage data — to understand, analyze, and improve how the Service is used, we use Google Analytics for Firebase (Google LLC), and information such as app usage (screen views, interaction events, etc.), app version, device type, OS version, and app instance identifiers is sent to Google LLC.
  • Crash information — to improve the stability of the app and fix defects, we use Firebase Crashlytics (Google LLC), and information such as the device model, OS version, app version, and stack traces at the time of a crash is sent to Google LLC.
  • Safety review of posted images — to detect inappropriate content, images posted by Users may be reviewed using the Google Cloud Vision API provided by Google LLC. In connection with this review, the image data concerned is sent to Google LLC (this is a separate process from the AI generation processing described above).
  • Information relating to the cloud sync feature — if you use the cloud sync feature, which backs up saved shikishi to your own cloud storage, the data concerned is encrypted on your device and then stored in your own account area: iCloud Drive (Apple Inc.) on iOS, or the app-specific folder of Google Drive (Google LLC) on Android. This data does not pass through the Company's servers, and the Company does not access its contents. On Android, use of this feature requires your Google account credentials and permission to access the app-specific folder (drive.appdata). The Company retains the status of this feature (enabled/disabled and the time of the last sync) on your device.

Users may refuse to accept cookies or delete stored data through their browser settings; however, in such cases, some functions of the Service (such as maintaining login status) may become unavailable.

03

Article 3 (Purposes of Collecting and Using Personal Information)

The purposes for which the Company collects and uses personal information are as follows.

  1. To provide and operate the Company's services
  2. To respond to inquiries from Users (including identity verification)
  3. To send emails regarding new features, updates, campaigns, etc. of the services being used by Users, and to provide information about other services offered by the Company
  4. To provide necessary communications such as maintenance and important notices
  5. To identify Users who have violated the Terms of Service or who attempt to use the Service for fraudulent or improper purposes, and to refuse their use of the Service
  6. To allow Users to view, change, or delete their own registered information, and to view their usage status
  7. To bill Users for usage fees in paid services
  8. To manage transaction history for the purchase, use, and transfer of coins, and to accurately track coin balances
  9. To prevent fraudulent use of coins and to provide a safe service
  10. To generate content such as digital shikishi in HTML format through the AI generation feature
  11. To improve and analyze the Service and to provide services appropriate to age, etc., based on attribute information (date of birth and gender) that Users have voluntarily registered
  12. To back up and restore saved shikishi to and from the User's own cloud storage through the cloud sync feature
  13. To introduce and promote the Service (including using content posted by Users to the extent necessary to introduce the Service, pursuant to Article 7-2, Paragraph 2 of the Terms of Service)
  14. For purposes incidental to the above purposes of use
04

Article 4 (Change of Purpose of Use)

  1. The Company shall change the purpose of use of personal information only in cases where it is reasonably recognized that the changed purpose is related to the purpose before the change.
  2. In the event of a change in the purpose of use, the Company shall notify Users of the changed purpose by a method prescribed by the Company, or publish it on this website.
05

Article 5 (Provision of Personal Information to Third Parties)

  1. Except in the following cases, the Company will not provide personal information to third parties without obtaining the User's prior consent. However, this excludes cases permitted under the Act on the Protection of Personal Information or other laws and regulations.
    • When necessary for the protection of a person's life, body, or property, and it is difficult to obtain the consent of the individual
    • When particularly necessary for improving public health or promoting the sound development of children, and it is difficult to obtain the consent of the individual
    • When it is necessary to cooperate with a national government organ, a local government, or a person entrusted by them in executing affairs prescribed by laws and regulations
  2. Notwithstanding the preceding paragraph, in the following cases, the recipient of such information shall not be considered a third party.
    • When the Company outsources all or part of the handling of personal information within the scope necessary to achieve the purpose of use
    • When personal information is provided in connection with the succession of business due to a merger or other reasons
  3. Notwithstanding the preceding paragraphs, the Company may provide personal information to the extent necessary to achieve the purpose in the following cases.
    • When a User orders delivery of postcards or similar items, providing the recipient's name, address, phone number, and other information necessary for delivery to the delivery company
    • Providing payment-related information to a payment service provider (Stripe, Inc., located in the United States), or to the billing system of the Apple App Store (Apple Inc., located in the United States) or Google Play (Google LLC, located in the United States), for payment processing
    • In connection with the use of the AI generation feature, providing text entered by Users, meta information of image, video, and audio materials, and the AI's most recent output during the revision phase, for AI processing, to the following AI Providers depending on the model selected by the User. The actual image, video, and audio files are not provided to the AI Providers for AI processing. In the manner in which the Company uses these services (the enterprise APIs provided by each company), the information provided is not used to train the AI Providers' generative AI models. However, the AI Providers may retain such information for a certain period for purposes such as detecting fraudulent use and ensuring safety.
      • Google LLC (model provided: Gemini, located in the United States)
      • Anthropic PBC (model provided: Claude, located in the United States)
      • OpenAI, L.L.C. (model provided: GPT, located in the United States)
    • For the purpose of preventing unauthorized use of the Service, providing app and device legitimacy verification information, IP addresses, etc., acquired through the use of Firebase App Check (App Attest / DeviceCheck on iOS, Play Integrity on Android), to Google LLC (located in the United States).
    • For the purpose of analyzing how the Service is used and improving the stability of the app, providing usage data and crash information to Google LLC (services provided: Google Analytics for Firebase / Firebase Crashlytics; located in the United States).
    • For the purpose of detecting inappropriate content, providing images posted by Users to Google LLC (service provided: Google Cloud Vision API; located in the United States).
  4. Each of the recipients listed in the preceding paragraph is a third party located in a foreign country (the United States). In accordance with Japan's Act on the Protection of Personal Information, the Company will provide, through the contact point stated in Article 11, information on the personal information protection regime of that country and on the measures taken by such third parties to protect personal information.
06

Article 6 (Disclosure of Personal Information)

  1. When requested by the individual to disclose personal information, the Company will disclose it to the individual without delay. However, the Company may not disclose all or part of the information if disclosure falls under any of the following.
    • When there is a risk of harming the life, body, property, or other rights and interests of the individual or a third party
    • When there is a risk of significantly hindering the proper execution of the Company's operations
    • When it would otherwise violate laws and regulations
  2. Notwithstanding the preceding paragraph, information other than personal information, such as history information and characteristic information, will not be disclosed as a general rule.
07

Article 7 (Correction and Deletion of Personal Information)

  1. If personal information held by the Company about a User is incorrect, the User may request the Company to correct, add, or delete such personal information, in accordance with the procedures prescribed by the Company.
  2. When the Company receives a request under the preceding paragraph from a User and determines that it is necessary to comply with the request, the Company shall correct, etc. the personal information without delay.
  3. When the Company has made a correction, etc. based on the provisions of the preceding paragraph, or has decided not to make a correction, etc., the Company shall notify the User of this without delay.
08

Article 8 (Suspension of Use of Personal Information, etc.)

  1. When requested by the individual to suspend the use or erase personal information on the grounds that it is being handled beyond the scope of the purpose of use, the Company will conduct the necessary investigation without delay.
  2. Based on the results of the investigation in the preceding paragraph, if it is determined that it is necessary to comply with the request, the Company will suspend the use, etc. of the personal information without delay.
  3. When the Company has suspended use, etc. based on the provisions of the preceding paragraph, or has decided not to suspend use, etc., the Company shall notify the User of this without delay.
  4. Notwithstanding the preceding two paragraphs, in cases where suspension of use, etc. would require a large expense or is otherwise difficult to carry out, and where alternative measures necessary to protect the rights and interests of the User can be taken in place of suspension of use, etc., the Company shall take such alternative measures.
09

Article 9 (Data Retention Period)

  1. The Company stores data for digital shikishi purchased by Users on its servers for 90 days from the date of purchase. Digital shikishi that are being created (not yet purchased), including drafts generated by the AI generation feature, are stored for 60 days from the date of creation and are automatically deleted after this period elapses.
  2. After the retention period ends, the Company automatically deletes the digital shikishi data.
  3. Users must download data as necessary within the retention period. Data cannot be recovered after deletion.
  4. Data stored temporarily on the Company's servers to deliver the results of the AI generation feature is automatically deleted seven (7) days after generation.
  5. Data stored in the User's own cloud storage through the cloud sync feature is outside the scope of the retention periods in this Article and remains in that cloud storage until the User deletes it.
  6. Other personal information is retained for the period necessary for the use of the Service or for the period prescribed by laws and regulations.
09-2

Article 9-2 (Security Control Measures)

The Company implements the following measures to prevent the leakage, loss, or damage of the personal data it handles and otherwise to manage such data securely.

  1. Establishment of a basic policy: To ensure the proper handling of personal data, the Company has established this Policy and complies with applicable laws, regulations, and guidelines.
  2. Organizational measures: The Company limits the persons who handle personal data to the minimum necessary and maintains a system for recording and reviewing how such data is handled. The Company also maintains reporting and communication procedures in preparation for any incident such as a data leak.
  3. Personnel measures: The Company informs those who handle personal data of the points to note in handling it and enforces confidentiality obligations.
  4. Physical measures: Personal data is managed in the data centers of the cloud services provided by Google LLC (Firebase / Google Cloud Platform), and the Company manages the equipment and devices used to handle such data.
  5. Technical measures: The Company encrypts communications in transit (TLS), identifies and authenticates users through an authentication platform (Firebase Authentication), restricts the scope of data accessible according to permissions through access controls (Firebase Security Rules), and verifies the integrity of the app and device through Firebase App Check. Data saved to the User's own cloud storage through the cloud sync feature is encrypted on the device before being stored.
  6. Understanding the external environment: The Company handles personal data using services of providers located in a foreign country (the United States). The Company implements necessary and appropriate measures for security control after ascertaining the personal information protection regime of that country. The providers used are as set out in Articles 2 and 5.
10

Article 10 (Changes to the Privacy Policy)

  1. The Company may change the contents of this Policy, except for matters otherwise provided for by laws and regulations or by this Policy.
  2. When making a material change to this Policy, the Company will inform Users in advance, or notify Users, by posting on this website or in the Service or by another appropriate method. Where the User's consent to a change is required by applicable law (including the GDPR / UK GDPR), the Company will obtain such consent in accordance with that law.
  3. Except as otherwise provided by the Company, the revised Privacy Policy shall take effect from the time it is posted on this website.
11

Article 11 (Operator Information and Contact)

For inquiries regarding this Policy, and for requests to disclose, correct, or suspend the use of retained personal data, please contact us at the following.

  • Operator: The operator of Shikishi.app (person in charge: Rikuto Horie)
  • Address: BIG Office Plaza Ikebukuro 1206, 2-62-8 Higashi-Ikebukuro, Toshima-ku, Tokyo 170-0013, Japan
  • Service Name: Shikishi.app
  • Email Address: support@shikishi.app
  • Contact Form: Contact Page
12

Article 12 (Disclosures for Users Outside Japan)

This Article applies to Users who use the Service from outside Japan. In the event of any conflict between this Article and the other provisions of this Policy, this Article shall prevail to the extent required by the laws applicable to the User.

1. Data Controller

The data controller (the business operator responsible for the handling of Personal Information) for the Service is the operator of Shikishi.app (Person Responsible for Operations: Rikuto Horie), as identified in our Legal Notice. Contact: support@shikishi.app.

2. Children's Privacy (Including COPPA)

The Service is not directed to children under 13 years of age, and persons under 13 may not use the Service. The Company does not knowingly collect Personal Information from children under 13. If the Company learns that it has collected Personal Information from a child under 13 without the consent required by applicable law (including the U.S. Children's Online Privacy Protection Act (COPPA)), the Company will delete such information and the related account without delay. If you believe that a child under 13 has provided Personal Information to the Service, please contact us at support@shikishi.app. Minors aged 13 or older must obtain the consent of a parent or legal guardian before using the Service. For Users residing in the European Economic Area (EEA) or the United Kingdom, under Article 8 of the GDPR and the national laws implementing it, the Company processes the personal data of persons under the age of 16 (or such lower age between 13 and 16 as the law of the User's country of residence may specify) only with the consent of a parent or legal guardian.

3. Users in the EEA and the United Kingdom (GDPR / UK GDPR)

Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies to the processing of your personal data, the following applies.

  • Legal bases: The Company processes personal data on the following legal bases: (i) performance of our contract with you (e.g., providing and operating the Service, responding to inquiries, billing, and managing coins); (ii) our legitimate interests (e.g., preventing fraudulent use, ensuring security, and improving the Service); (iii) your consent (e.g., the optional registration of date of birth and gender, and emails about new features and campaigns); and (iv) compliance with legal obligations. Where processing is based on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Your rights: You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including objection to direct marketing) as provided in the GDPR / UK GDPR. You may exercise these rights through the contact coins set out in Article 11, and the procedures in Articles 6 through 8 will be applied consistently with the GDPR / UK GDPR where it applies.
  • International transfers: Personal data is processed on servers located in Japan and by the service providers located in the United States identified in Articles 2 and 5 (Google LLC, Apple Inc., Stripe, Inc., Anthropic PBC, and OpenAI, L.L.C.). Japan has been recognized by both the European Commission and the United Kingdom as providing an adequate level of data protection (adequacy decisions). Transfers to service providers in the United States are protected by safeguards such as those providers' certification under the EU-U.S. Data Privacy Framework (and its UK Extension) and/or standard contractual clauses.
  • Retention: Personal data is retained for the periods described in Article 9.
  • Complaints: You have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner's Office (ICO)).

4. Users in California, USA (CCPA/CPRA)

Where the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies, the following applies.

  • The categories of Personal Information the Company collects, the sources of that information, and the purposes of collection and use are as described in Articles 2 and 3 (identifiers such as name, email address, device identifiers, and IP address; commercial information such as purchase and coin history; internet activity information such as access logs; user content; and, where voluntarily registered, date of birth and gender).
  • The Company does not sell Personal Information, and does not share Personal Information for cross-context behavioral advertising. The Company has no actual knowledge of selling or sharing the Personal Information of consumers under 16 years of age.
  • California residents have the right to know (access), the right to delete, and the right to correct their Personal Information, as well as the right not to receive discriminatory treatment for exercising these rights.
  • To exercise these rights, please contact us through the contact coins set out in Article 11. You may also designate an authorized agent to submit a request on your behalf. The Company may verify your identity (e.g., through the email address registered to your account) before responding to a request.