The provider of PHRAZE (the “App”), Takuma Okuyama (the “Provider”), handles personal information obtained from users in connection with the use of the App in accordance with this Privacy Policy (the “Policy”). By using the App, users are deemed to have agreed to this Policy.
Article 1 (Scope)
This Policy applies to the handling of personal information acquired and used by the Provider when users use the App.
Article 2 (Information We Collect)
In providing the App, the Provider collects the following information.
- Account identification information: identifiers issued through external authentication services, email addresses optionally provided, and a display name obtained from the external authentication service (based on the user’s name; provided by Apple only at the time of initial authentication).
- Learning and operation data: learning behavior, feature usage, screen navigation, error occurrences, and other usage statistics within the App.
- Billing information: type of subscription purchased, purchase price and currency, timestamps of purchase and cancellation, validity period, and the success/failure status of billing events (payment information itself is not collected).
- Device and network information: OS version, App version, language setting, time zone, country, region, and city-level location inferred from the IP address, and pseudonymized device identifiers (irreversibly transformed using cryptographic hashing).
- User-input text: text entered by the user in the course of using features such as phrase generation, editing, and chat.
- Usage records: the type, count, and timing of feature usage, as well as cost information associated with the use of each feature.
Payment processing is performed by Apple’s App Store, and the Provider does not directly obtain credit card numbers or other payment information.
Article 3 (Purpose of Use)
The Provider uses the collected personal information for the following purposes.
- To provide the App’s core features, including account authentication, learning progress storage, and subscription management.
- To send user-input text to external AI providers to the extent necessary for generating learning content and chat responses through AI.
- To improve learning experience and to enhance the accuracy of learning-pace optimization algorithms through statistical analysis.
- To aggregate and analyze usage data for feature improvement, defect detection, and quality enhancement.
- To confirm the proper completion of billing transactions and to detect and respond to unauthorized use and violations of the Terms.
- To respond to inquiries and to send necessary notices to users (important announcements, notification of changes to the Terms, etc.).
- To respond to requirements based on applicable laws and regulations.
If the Provider changes the purpose of use, and such change exceeds the scope reasonably regarded as related to the original purpose of use, the Provider shall obtain the user’s consent anew.
Article 4 (Restrictions on Third-Party Provision)
Except in the following cases, the Provider does not provide personal information to third parties without the user’s consent.
- When disclosure is required by law.
- When necessary for the protection of life, body, or property and it is difficult to obtain the consent of the individual.
- When particularly necessary for improving public health or promoting the sound upbringing of children.
- When cooperation with national or local government agencies in performing duties prescribed by law is required.
Article 5 (Use of External Services)
In providing the App, the Provider uses services offered by external providers for functions such as AI content generation based on user-input text, authentication, database and server infrastructure, subscription management, speech synthesis, and usage analytics. As a result, the user’s personal information may be transmitted to such external services.
The transmission of information to these external providers is limited to the extent necessary for the provision of the App’s features, and constitutes the entrustment of handling of personal data as set forth in Article 27, Paragraph 5, Item 1 of the Act on the Protection of Personal Information. In selecting external providers, the Provider confirms that each provider has established a privacy policy and security measures and is operated in accordance therewith.
The primary destination countries of the external providers used as of the date of this Policy are listed below. The provider of AI processing and speech synthesis is Google LLC (Gemini / Vertex AI), which is expressly named in the body of this Policy. For the other categories of use, because the specific external providers and their countries of location may change as service offerings evolve, the names of individual providers are not enumerated; users who wish to obtain the most recent list of providers (including the latest service names) may request disclosure via the contact in Article 9.
| Category of use | Primary provider | Primary destination country |
|---|---|---|
| AI-based learning content generation and chat responses | Google LLC (Gemini / Vertex AI) | United States |
| Subscription management | — (disclosed upon request) | United States |
| Usage analytics | — (disclosed upon request) | United States |
| Database and server infrastructure | — (disclosed upon request) | United States, Singapore, etc. |
| Speech synthesis | Google LLC (Gemini / Vertex AI) | United States |
| Authentication | — (disclosed upon request) | United States |
The user data transmitted to Google LLC (Gemini / Vertex AI) for AI processing is, for each feature, as follows.
- Phrase generation: The text the user types (source sentences and refinement instructions), and the text of candidates rejected when regenerating. Transmitted to generate, refine, and explain the user’s personalized phrases.
- Explore (conversations): Conversation messages (the most recent exchanges). Transmitted to produce conversational responses and to extract phrase candidates.
- Speech synthesis: The text of saved phrases and audio settings (voice and speaking rate). Transmitted to create spoken audio for phrases.
The transmitted text is used solely for the purposes described above and, in accordance with the terms and contracts governing the external AI processing infrastructure, is not used for additional training of machine learning models. Note that it may be temporarily logged by the processing infrastructure for purposes such as abuse monitoring. Transmission to AI in connection with phrase generation and Explore conversations can be turned off at any time from the in-app settings (AI Generation); learning and reviewing saved phrases, and speech synthesis, are not affected by this setting.
The provision of personal data to those of the above external providers that are located in foreign countries constitutes the provision of personal data to a third party in a foreign country as set forth in Article 28 of the Act on the Protection of Personal Information. In effecting such transfers, the Provider takes necessary and appropriate measures for the protection of personal data at the transfer destination, either by confirming that the recipient has established a system for continuously taking protective measures equivalent in standard to those required under Japan’s Act on the Protection of Personal Information, or by entering into a contract with the recipient providing for the proper handling of personal data. The principal countries in which the recipients are located are as set forth in the table above; note that the United States has no comprehensive legal framework equivalent to Japan’s Act on the Protection of Personal Information, and is instead regulated by sector-specific federal and state laws.
The legal frameworks for personal information protection in destination countries depend on the laws of the respective country or region. Users wishing to obtain detailed information regarding the personal information protection systems of each country may refer to the materials published by the Personal Information Protection Commission (https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/), or may receive information individually via the contact in Article 9.
Article 6 (Disclosure, Correction, Suspension of Use, and Account Deletion)
Users may request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, and cessation of third-party provision regarding their own personal information held by the Provider. The Provider offers the following two channels for such requests.
- In-app account deletion: By selecting “Delete Account” on the App’s settings screen, the user can immediately delete their account after identity confirmation (two-step confirmation). Upon completion of deletion, the user is returned to the onboarding screen and can no longer log in to the App from that device.
- Via the email contact: Requests made by a third party (a legal representative, the guardian of a user under 16, a bereaved family member, etc.), requests concerning users under the age of 13, and requests for complete erasure including the pseudonymized identifiers retained by third-party analytics services, are accepted via the contact in Article 9 and addressed without undue delay in accordance with applicable laws after identity verification.
The scope of data erasure and the retention periods upon account deletion are as follows.
| Target | Method of deletion | Retention period |
|---|---|---|
| Learning data (phrases / learning history / audio) | Immediately erased from the device | 0 |
| Billing principal ID / subscription status / monthly usage | Immediately erased from the server (hard delete) | 0 |
| Usage event logs / webhook receipt logs | Retained with identifiers pseudonymized (HMAC) | 13 months |
| Account deletion requests / audit logs | Retained for legal compliance (identifying information pseudonymized) | 1 year |
| Identifiers to prevent fraudulent account revival (pseudonymized HMAC) | Retained to prevent fraudulent revival by the same user (cannot identify the individual) | Indefinite |
| Duplicate-registration lock during deletion processing | Released after deletion processing completes, retained only briefly for audit and then erased | 24 hours after deletion processing completes |
| Deletion-failure analysis logs (dead letter) | Retained to prevent recurrence of failures (pseudonymized; contains no raw identifying data) | 5 years |
| Third-party analytics service identifiers | Retained in pseudonymized form (identifying attributes such as name and email address are released immediately) | Retained while pseudonymized |
Note that, in the in-app account deletion, the pseudonymized identifiers already transmitted to third-party analytics services and past usage events are retained as statistical data that cannot identify the individual. If you wish to have these completely erased as well, please contact the email contact in 2. above.
Users who log in using Apple Sign In will, in principle, have Apple’s authorization automatically revoked upon account deletion. In some cases, manual revocation may be required after deletion is complete, by stopping the use of “Sign in with Apple” for the App from your Apple Account settings within the iOS “Settings” app (the exact menu names vary by iOS version).
If you wish only to stop usage analytics (without deleting your account), you may contact the contact in Article 9 by email, and the Provider will take measures to cease transmission of analytics data from your device. Where the App provides an in-app setting for stopping analytics, you can also do so from that setting.
Article 7 (Changes to This Policy)
The Provider may modify this Policy in response to changes in laws and regulations, modifications to the App’s features, operational necessity, or similar reasons.
- Minor changes to this Policy (correction of typographical errors, clarification of expressions, updates to external links, etc.) will take effect from the time they are published within the App or on the Provider’s official website.
- Changes that materially disadvantage users will be notified to users at least 30 days prior to the effective date through in-App notification or other appropriate means, and the modified Policy will apply from the effective date of such change.
- If the Provider changes the purpose of use, and such change exceeds the scope reasonably regarded as related to the original purpose of use, the Provider shall obtain the user’s consent anew.
Article 8 (Use by Minors)
The App is designed for use by persons aged approximately 13 years or older. Users under the age of 16 shall obtain the prior consent of their parent or legal guardian regarding the use of the App and agreement to this Policy. If the Provider receives any communication concerning the use of the App from a user under 16 years of age, the Provider may, as necessary, take steps to confirm parental consent.
Article 9 (Contact and Public Disclosure Items)
For inquiries regarding this Policy, requests for disclosure, or any other matters concerning the handling of personal information, please contact the following.
- Name of personal information handling business operator (Provider): Takuma Okuyama
- Address: Disclosed without delay upon request (please use the contact below).
- Contact: [email protected]
- Procedures for requesting notification of purpose of use, disclosure, and other rights: see Article 6 of this Policy.
- Authorized personal information protection organization: None.
- Where to file complaints: please use the contact above. Complaints regarding the handling of personal information may also be filed with the Personal Information Protection Commission (https://www.ppc.go.jp/personalinfo/).
Article 10 (Security Control Measures)
The Provider takes necessary and appropriate measures, including the following, to prevent the leakage, loss, or damage of acquired personal information and otherwise to manage its security.
- Organizational and human security control measures: clarifying responsibility for the handling of personal information, establishing rules for such handling, and exercising necessary supervision over persons involved in the development and operation of the App.
- Technical security control measures: encryption of communications (HTTPS), management of access privileges to stored data, access control through authentication, and measures against unauthorized access.
- Understanding of the external environment: the Provider stores part of the personal data on the servers of providers located in foreign countries (primarily the United States and Singapore). Having understood the systems for the protection of personal information in such foreign countries, the Provider takes necessary and appropriate measures for security control, together with the supervision of contractors and the confirmation of protective measures at transfer destinations set forth in Article 5.
Article 11 (Response in the Event of a Leakage)
In the event that a leakage, loss, damage, or other incident involving acquired personal data occurs or is likely to have occurred, the Provider will, in accordance with applicable laws, promptly investigate the facts and take measures necessary to prevent recurrence, and, where required under the Act on the Protection of Personal Information, will report to the Personal Information Protection Commission, notify the affected individuals, and take other necessary responses.
Article 12 (Information Not Collected)
The Provider does not collect the following information in the App.
- Address, telephone number, or date of birth (the App does not request input of any of these).
- Credit card numbers or other payment method information (in-app purchases are processed by Apple, and the Provider does not obtain card information).
- The Advertising Identifier (IDFA). The Provider does not engage in cross-device user tracking based on App Tracking Transparency (ATT) or in advertising delivery based on such tracking, and does not display third-party advertisements in the App.
- Precise location information via GPS or the like (the location information the Provider obtains is limited to the coarse country, region, and city level based on the IP address as described in Article 2, Item 4).
- Audio data captured by the microphone and the results of its speech recognition (in the voice answer feature on study cards, microphone audio is processed only on the device using Apple’s speech recognition; it is never transmitted to or stored on the Provider’s servers. The recognized text is used solely for on-device answer checking and is not collected by the Provider).
Effective Date: June 3, 2026 Last Updated: July 9, 2026