ないしょメモ(BunNote) プライバシーポリシー
個人開発者BunDev(以下「当方」)は、本アプリケーション「ないしょメモ(BunNote)」(以下「本アプリ」)におけるユーザーの情報の取り扱いについて、以下の通りプライバシーポリシーを定めます。
1. 基本方針
当方は、ユーザーのプライバシー保護を最優先事項とします。本アプリはユーザーが入力した情報を当方が収集することは一切なく、データは原則としてユーザー自身のデバイス内にのみ保存されます。唯一の例外は、ユーザーが自ら有効にした場合に限り、暗号化したバックアップをユーザー本人のGoogleドライブに保存する機能です(第4条)。このバックアップは当方のサーバーを経由せず、当方を含む第三者が内容を読むことはできません。当方は分析SDK・広告SDK・クラッシュレポートサービスを一切使用していません。
2. データの保存と暗号化
本アプリに入力したメモの内容は、AES-256暗号化(SQLCipher)によりマスターパスワードから派生した鍵で暗号化され、デバイス内に保存されます(ユーザーが第4条のバックアップを利用した場合は、暗号化されたままの複製がユーザー本人のGoogleドライブにも保存されます)。マスターパスワードは当方のサーバーにも端末にも平文で保存されません。開発者を含む第三者がこれらのデータにアクセスすることは技術的に不可能です。
3. 端末内に保存される情報と利用目的
以下はユーザーの端末内に保存され、当方のサーバーに送信されることはありません。
- メモデータ:アプリ内で入力された口座情報・パスワード・証明書情報・予定等は、暗号化された状態で端末内(SQLCipher暗号化Roomデータベース)にのみ保存されます。
- 設定データ:テーマカラー・表示設定・リマインダー設定等は端末内(DataStore)に保存されます。
- 通知の予定:端末の再起動後にマスターパスワードなしで通知を登録し直すため、通知を設定したメモのタイトルと通知日時は、暗号化されていない状態で端末内の本アプリ専用領域に保存されます。他のアプリから参照されることはなく、外部に送信されることもありません。通知を解除するかメモを削除すると、この情報も削除されます。なお、通知そのものにはメモのタイトルが表示されます。
- ウィジェット表示用データ:ホーム画面ウィジェットにカレンダーの印を表示するため、予定の日付と種別のみを端末内に保存します。メモのタイトルや本文など、内容にあたる情報は保存しません。この情報はウィジェットの描画にのみ使用され、外部に送信されることはありません。
- 壁紙画像:透かし壁紙に設定した画像は、端末内の本アプリ専用領域にコピーして保存されます。他のアプリから参照されることはなく、外部に送信されることもありません。
- 添付画像:メモに添付した画像(ギャラリーから選んだもの・カメラで撮影したもの)は、容量を抑えるため一定の大きさ(400万画素)を超える場合に縮小したうえで、サムネイルとともに暗号化して端末内の本アプリ専用領域に保存されます。暗号化の鍵は乱数で作られ、暗号化されたメモのデータベースの中に保管されます。他のアプリから参照されることはなく、外部に送信されることもありません(第4条のバックアップを除く)。カメラで撮影した写真は、取り込みのために一時的に本アプリ専用の一時領域に置かれ、取り込み後すぐに削除されます。なお、撮影には端末のカメラアプリを使用するため、カメラアプリの設定によっては、カメラアプリ側に写真の控えが残る場合があります。
- バックアップデータ(ファイルへの書き出し):ファイルへの書き出しはユーザーが任意で実行するものです。書き出されるファイルは暗号化されたままの状態であり、保存先はユーザー自身が選択します。当方のサーバーには一切送信されません。復元には、そのバックアップを作成した時点のマスターパスワードが必要です。Googleドライブへのバックアップについては第4条をご覧ください。
4. Googleドライブへのバックアップ
本アプリは、機種変更やスマートフォンの故障に備えて、データをユーザー本人のGoogleドライブにバックアップする機能を備えています。この機能はユーザーが自ら操作した場合にのみ動作し、初期状態では何も送信しません。
- 保存する内容:メモのデータベース・設定・壁紙画像・添付画像を1つのファイルにまとめたものです。中身はすべて暗号化してから送信します(データベース・設定・壁紙画像はマスターパスワードから派生した鍵で、添付画像はデータベースの中に保管された鍵で暗号化されています)。当方のサーバーを経由することはなく、当方・Google社を含む第三者が内容を読むことはできません。
- 保存先:ユーザー本人のGoogleドライブ内の「ないしょメモ」フォルダです。手動で保存したバックアップ(機種変更用)は常に最新の1つだけを保管し、保存するたびに置き換えます。
- 毎日のじどう保存:ユーザーがオンにした場合に限り、アプリのロックを解除したときに1日1回自動で保存します。モバイル通信量を使わないよう、Wi-Fiに接続しているときだけ実行します(手動の保存は接続の種類を問わず行えます)。保管するのは最新の3つまでで、古いものから削除します。初期状態はオフです。
- Googleアカウントへのアクセス:Googleの認可画面でユーザーが許可した場合に限り、Googleドライブの
drive.file 権限(本アプリが作成したファイルにのみアクセスできる権限)を使用します。本アプリはユーザーのほかのファイル、メールアドレス、氏名、連絡先等にアクセスせず、取得もしません。アクセスのための鍵(アクセストークン)は端末内で一時的に使用するのみで、保存も外部への送信も行いません。
- 用途の限定:Google APIから受け取った情報は、バックアップの保存・一覧・復元・古いバックアップの削除にのみ使用し、それ以外の目的には使用せず、第三者に提供することもありません。本アプリによるGoogle APIから受け取った情報の使用および他のアプリへの転送は、Google API サービスのユーザーデータに関するポリシー(限定使用の要件を含む)に準拠します。
- 削除とアクセスの取り消し:バックアップはユーザー本人のGoogleドライブにあるため、ユーザーはいつでもGoogleドライブから削除できます。本アプリを削除してもGoogleドライブ上のバックアップは自動的には削除されません。本アプリへのアクセス許可は、Googleアカウントの「サードパーティ製のアプリとサービス」からいつでも取り消せます。
- 復元に必要なもの:バックアップを作成したときと同じGoogleアカウント、およびバックアップを作成した時点のマスターパスワードが必要です。
5. 権限の使用について
本アプリは機能提供のため、以下の権限を使用します。取得した情報を第三者に提供することはありません。
- インターネット (INTERNET):Proプランの購入・復元のためのGoogle Play Billingとの通信、およびユーザーが利用した場合のGoogleドライブへのバックアップ・復元(第4条)にのみ使用します。当方がユーザーの個人情報を収集することはありません。
- アプリ内課金 (com.android.vending.BILLING):Google Play を通じたProプランの購入・復元のため。
- 生体認証 (USE_BIOMETRIC / USE_FINGERPRINT):指紋・顔認証によるアプリのロック解除機能のため。生体情報そのものはAndroid OSが管理し、本アプリが取得・保存することはありません。
- 通知 (POST_NOTIFICATIONS):リマインダー通知の送信のため。
- 正確なアラーム (SCHEDULE_EXACT_ALARM):指定した時刻に正確にリマインダーを作動させるため。
- 起動完了受信 (RECEIVE_BOOT_COMPLETED):端末の再起動後にリマインダーのスケジュールとウィジェットの表示を自動復元するため。
- ネットワーク状態の確認 (ACCESS_NETWORK_STATE):毎日のじどう保存をWi-Fi接続時に限るため、現在の接続が従量制(モバイル通信等)かどうかのみを確認します。
なお、壁紙画像と添付画像の選択にはAndroid標準のフォトピッカーを使用しているため、写真ライブラリ全体へのアクセス権限は要求しません。本アプリが扱えるのはユーザーがその場で選択した画像のみです。また、写真の撮影には端末のカメラアプリを呼び出すため、本アプリはカメラの権限を持ちません。
6. 不具合報告
本アプリはFirebase Crashlytics等のクラッシュレポートサービスを使用していません。アプリが予期せず終了した場合、原因調査のための記録(例外の種類・発生箇所のクラス名・メソッド名・行番号)を端末内にのみ保存します。この記録にはメモの内容・マスターパスワード・ファイルパスは含まれません。
アプリ内の「不具合を報告する」機能は、ユーザーがその記録の内容を画面上で確認した上で、任意でメールを送信するものです。自動的な送信は一切行いません。
7. 第三者サービスによるデータ収集
Google Play Billing(決済)
Proプランの提供に「Google Play Billing」を利用しています。決済情報はGoogle社によって管理され、当方が決済詳細情報にアクセスすることはありません。当方が受け取るのは「購入が完了したかどうか」の情報のみです。
Google ドライブ/Google Play 開発者サービス(バックアップ)
第4条のバックアップのために、GoogleドライブのAPIと、Google Play 開発者サービスによる認可の仕組みを利用しています。送信するバックアップは暗号化済みであり、Google社がその内容を読むことはできません。Googleアカウントおよびドライブの取り扱いについては、Google社のプライバシーポリシーが適用されます。
上記以外の広告SDK・分析SDK・クラッシュレポートサービス等の外部SDKは一切使用していません。
8. お子様の利用について
本アプリは特定の年齢層を対象として設計されたものではなく、いかなる年齢のユーザーからも個人情報を収集しません。
9. プライバシーポリシーの変更
当方は、本ポリシーを変更することがあります。重要な変更を行う場合は、本ページに変更後の内容を掲載します。
10. お問い合わせ窓口
BunDev
住所:〒105-0013 東京都港区浜松町2丁目2番15号 浜松町ダイヤビル2F
メール:support.bun.apps@gmail.com
BunNote Privacy Policy
BunDev ("we" or "us"), an independent developer, has established this Privacy Policy regarding the handling of user information in the application "BunNote" ("the App").
1. Basic Policy
We place the highest priority on protecting user privacy. We never collect any information entered by users, and data is, as a rule, stored only on the user's own device. The single exception is a feature that, only when you turn it on yourself, saves an encrypted backup to your own Google Drive (Section 4). That backup never passes through our servers, and no third party — including us — can read its contents. We use no analytics SDKs, no advertising SDKs, and no crash reporting services.
2. Data Storage and Encryption
The content of your notes is encrypted using AES-256 (SQLCipher) with a key derived from your master password, and stored on your device (if you use the backup described in Section 4, an encrypted copy is also stored in your own Google Drive). Your master password is never stored in plain text, neither on our servers nor on your device. It is technically impossible for us or any third party — including the developer — to access this data.
3. Information Stored on Your Device
The following is stored on your device and is never transmitted to our servers.
- Memo Data: Bank account details, passwords, identification information, schedules, etc. entered in the App are stored in encrypted form on your device only (SQLCipher-encrypted Room database).
- Settings Data: Theme color, display settings, reminder settings, etc. are stored on your device (DataStore).
- Scheduled Notifications: So that reminders can be re-registered after a device restart without your master password, the title and time of each note that has a reminder are stored unencrypted in the App's private storage area on your device. They are not accessible to other apps and are never transmitted externally. They are deleted when you turn the reminder off or delete the note. Note that the notification itself displays the note's title.
- Widget Display Data: To show calendar markers on the home screen widget, the App stores only the dates and categories of your scheduled items on your device. No titles or note content are stored. This information is used solely to draw the widget and is never transmitted externally.
- Wallpaper Images: An image set as a watermark wallpaper is copied into the App's private storage area on your device. It is not accessible to other apps and is never transmitted externally.
- Attached Images: Images you attach to a note (chosen from your gallery or taken with the camera) are reduced in size when they exceed a set limit (4 megapixels) to save space, and are then stored encrypted, together with their thumbnails, in the App's private storage area on your device. The encryption key is generated randomly and kept inside the encrypted note database. They are not accessible to other apps and are never transmitted externally (except in the backup described in Section 4). A photo taken with the camera is placed in the App's private temporary area only while it is being taken in, and is deleted immediately afterwards. Because photos are taken with your device's camera app, that camera app may keep its own copy depending on its settings.
- Backup Data (Export to File): Exporting to a file is entirely user-initiated. The exported file remains encrypted, and you choose where it is saved. It is never sent to our servers. Restoring a backup requires the master password that was in use when the backup was created. For backups to Google Drive, see Section 4.
4. Backup to Google Drive
To prepare for a new phone or a broken one, the App can back up your data to your own Google Drive. This feature works only when you use it yourself; by default nothing is sent.
- What is saved: A single file containing the note database, settings, wallpaper images and attached images. Everything in it is encrypted before it is sent (the database, settings and wallpapers with a key derived from your master password; attached images with the key kept inside the database). It never passes through our servers, and no third party — including us and Google — can read its contents.
- Where it is saved: A folder named "ないしょメモ" in your own Google Drive. A backup you save manually (for moving to a new phone) is kept as a single, latest file and is replaced each time you save.
- Daily automatic backup: Only if you turn it on, the App saves a backup once a day when you unlock it. To avoid using mobile data, it runs only while you are connected to Wi-Fi (a manual save works on any connection). Up to the three most recent are kept; older ones are deleted. It is off by default.
- Access to your Google Account: Only after you grant permission on Google's authorization screen, the App uses the Google Drive
drive.file scope, which allows access only to files the App itself has created. The App does not access or obtain your other files, email address, name, contacts or any other account information. The access token is used only temporarily on your device and is neither stored nor sent anywhere else.
- Limited use: Information received from Google APIs is used only to save, list and restore backups and to delete older backups. It is not used for any other purpose and is never shared with third parties. The App's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Deletion and revoking access: Because backups are in your own Google Drive, you can delete them from Google Drive at any time. Uninstalling the App does not automatically delete backups in Google Drive. You can revoke the App's access at any time from "Third-party apps & services" in your Google Account.
- What you need to restore: The same Google Account used to create the backup, and the master password that was in use when the backup was created.
5. Permissions
The App uses the following permissions to provide its features. Information obtained is never shared with third parties.
- Internet (INTERNET): Used solely for communication with Google Play Billing to purchase and restore the Pro Plan, and, if you use it, for backing up to and restoring from Google Drive (Section 4). We never collect any personal user data.
- In-app Billing (com.android.vending.BILLING): To purchase and restore the Pro Plan through Google Play.
- Biometric (USE_BIOMETRIC / USE_FINGERPRINT): For unlocking the App using fingerprint or face authentication. Biometric data itself is managed by the Android OS and is never accessed or stored by the App.
- Notifications (POST_NOTIFICATIONS): To send reminder notifications.
- Exact Alarm (SCHEDULE_EXACT_ALARM): To trigger reminders at the exact scheduled time.
- Boot Completed (RECEIVE_BOOT_COMPLETED): To automatically restore reminder schedules and widget display after a device restart.
- Network State (ACCESS_NETWORK_STATE): To limit the daily automatic backup to Wi-Fi, the App checks only whether the current connection is metered (such as mobile data).
Choosing wallpapers and attached images uses the Android system photo picker, so the App does not request access to your photo library. It can only handle the images you explicitly select. Photos are taken with your device's camera app, so the App does not hold the camera permission.
6. Crash Records and Bug Reports
We do not use Firebase Crashlytics or any other crash reporting service. If the App terminates unexpectedly, a diagnostic record (exception type, class name, method name and line number) is saved on your device only. This record contains no note content, no master password and no file paths.
The in-app "Report a Bug" feature sends an email only after you review that record on screen and choose to send it. No automatic transmission ever occurs.
7. Third-Party Services
Google Play Billing (Payments)
The App uses Google Play Billing for the Pro Plan. Payment information is managed by Google, and we do not have access to payment details. We only receive whether a purchase has been completed.
Google Drive / Google Play services (Backup)
For the backup described in Section 4, the App uses the Google Drive API and the authorization provided by Google Play services. Backups are encrypted before they are sent, so Google cannot read their contents. Google's Privacy Policy applies to your Google Account and Google Drive.
We do not use any advertising SDKs, analytics SDKs, crash reporting services, or any other third-party SDKs beyond the above.
8. Children
The App is not directed at any particular age group and does not collect personal information from users of any age.
9. Changes to This Policy
We may update this Policy. Any significant changes will be posted on this page.
10. Contact
BunDev
Email: support.bun.apps@gmail.com