プライバシーポリシー
Yoshifumi Kanno(以下「運営者」)は、SyncFlowアプリおよび関連サービス(以下「本サービス」)における情報の取扱いを、次のとおり説明します。本ポリシーの確認は、利用規約への同意とは別の行為です。
Washington州およびNevada州の消費者健康データに関する追加開示と権利は、英語のConsumer Health Data Privacy Policy (Washington and Nevada)をご確認ください。
1. 端末内で取り扱う情報
- Fitbitの認証情報、利用者が選択した健康・フィットネスデータ、同期設定および同期範囲。
- Apple Healthへの読書き権限、SyncFlowが書き込むHealthKitサンプル、およびサンプルに付す同期識別情報。
- 同期実行ID、同期元・同期先、実行契機、実行・開始・完了時刻、端末実行であること、実行状態・結果、カテゴリ、確認期間、集計単位・件数、書込件数および限定されたエラーコードからなるSync History。健康測定値そのものはSync HistoryのSQLiteデータベースへ複製しません。
- Widget表示用の日付、最終完了時刻、カテゴリ、書込件数、表示状態およびプラン表示区分の限定されたスナップショット、ならびに利用者が有効にした自動同期完了通知の結果・カテゴリ数・書込件数。通知のロック画面等への表示はiOSの通知設定に従います。
- 選択した設定・範囲、自動同期・通知の状態、端末内のインストール識別子・重複防止枠、法的文書の版と確認状態、任意の利用状況分析の選択、購入権利・運用設定の限定されたキャッシュ、お知らせ・表示設定等、本サービスを端末上で動作させるためのアプリ状態。
Sync HistoryとWidget領域にはiOSのData Protectionおよびバックアップ除外を適用します。ただし、OSや利用環境を含む全ての状況で除外を絶対に保証するものではありません。運営者はSync History用のiCloud・CloudKit、クラウド復元、端末間移行またはバックアップサービスを提供しません。アンインストール、端末交換、故障、データ破損または削除により履歴を失う場合があります。Apple Health内のサンプルがiCloud等で同期・保持されるかは、Appleのサービスと利用者の端末設定に従います。
2. 運営者のサーバーで取り扱う情報
- Firebaseの仮名ユーザーIDならびにアカウント作成・更新時刻。
- 自動同期のためのインストール識別子、プラットフォーム、タイムゾーン、Expo Push Token、利用者の有効設定、実際のリモート起動可否、限定された実行不能理由、Background App Refresh・APNs登録の状態、次回試行時刻、重複防止枠および最新の配信結果。Silent Pushのデータ部には、トリガー種別、時刻枠、および診断機能が有効な場合の診断相関用識別子が含まれます。この識別子は、端末・サーバー・Sentry上の同じ処理を関連付けて障害を調査するために使用します。健康値、健康カテゴリ、同期範囲、件数またはユーザーIDは含みません。
- 利用状況分析の有効・無効・未決定の状態と更新時刻、アプリ版およびビルド番号。
- 利用状況分析の設定にかかわらず、サービス提供、稼働状況およびバックグラウンド機能の価値の把握のため、インストール単位で日付、前面での端末確認・バックグラウンドサービス応答の有無、手動・Widget・Silent Push・Background Taskの各同期経路を利用したか、および同期の大まかな結果(正常完了・部分失敗・失敗・スキップ)を日単位の有無として保存します。アプリ版・ビルド番号、利用状況分析の設定状態および計測仕様版も含みます。健康値、健康カテゴリ、同期範囲・件数、Push Token、GA4識別子または正確な同期時刻は、この日単位記録へ保存しません。日単位記録は仮名インストール識別子を通じて、運営者サーバー上のFirebase仮名ユーザーIDに関連付けられます。
- 確認した利用規約・本ポリシーの版、確認時刻、アプリ版、ビルド番号および言語。
- 配信、安全管理、不正利用防止および障害調査のため、IPアドレス、User-Agent、日時、経路、応答状態・所要時間等の接続・技術ログ。健康データ本文、認証トークンまたはSync Historyをアプリのサーバーログへ意図的に記録しません。
運営者のサーバーへ、Fitbitトークン、HealthKitサンプル、健康測定値、Sync Historyのカテゴリ・期間・結果・件数、または任意のプロバイダーエラー本文を保存しません。
3. 分析、広告、購入および障害診断
- Firebase Analytics:法的文書の確認後、限定された利用状況分析を有効にします。閲覧画面と一般操作、手動・Widget・Silent Push・その他のバックグラウンド同期という実行経路と大まかな成否、設定済みWidgetの種類、セッション・利用状況、アプリ版、OS・端末機種、概算地域、アプリ内購入イベントおよびアプリインスタンスIDを処理する場合があります。この設定は端末に保存され、「このアプリについて > 利用状況」でいつでも無効にできます。無効化すると将来の収集を停止し、アプリ分析識別子をリセットします。健康測定値、HealthKit・Fitbitサンプル、健康カテゴリ、同期範囲・件数、Run ID、氏名、メール、ログイン情報、認証情報またはFirebaseユーザーIDをカスタムイベントやユーザープロパティとして送りません。Widgetの表示回数・閲覧回数は取得しません。
- Firebaseの運用機能:Authentication、App Check、Remote Config、HostingおよびCloud Runは、Firebase Installation ID、認証・端末証明情報、IPアドレス、国・言語・タイムゾーン、端末・OS・アプリ・通信情報、リクエスト経路・URL、応答状態・サイズ・所要時間等を、認証、不正防止、設定配信およびサービス提供のため処理する場合があります。API本文は第2項で開示した限定情報に限り、アプリケーションログへ認証トークンや健康データ本文を意図的に記録しません。Firebase Performance SDKはv2.4へ組み込みません。これらは運営者のSync Historyデータベースへ保存する情報とは別の、第三者サービスによる処理です。
- AdMob / UMP:広告表示・配置、同意選択、端末・広告識別子、広告操作および概算地域等を処理する場合があります。健康測定値、HealthKit・Fitbitサンプル、健康カテゴリ、同期範囲・件数、Run IDまたは資格情報を広告ターゲティング、広告リクエストのキーワードまたは広告効果測定へ使用しません。
- Apple / RevenueCat:購入、レシート、権利状態、端末・アプリ情報、仮名ユーザーID、ならびに同期完了後の広告面を含む広告の配置・配信・ネットワーク・収益・通貨・エラー等の広告実績イベントを処理します。運営者はカード番号を取得しません。健康測定値、HealthKit・Fitbitサンプル、健康カテゴリ、同期範囲・件数、Run IDまたは資格情報はRevenueCatへ送りません。
- Sentry:法的文書の確認後に、Event ID、シンボル化されたスタック、例外種別・発生機構とNative Thread、Release・Build・環境、OS・端末ファミリー・機種・言語・アプリ状態、固定された診断コンテキスト、画面名のみのナビゲーション・ライフサイクル・固定フェーズ・一部の固定広告動作のBreadcrumb、およびCrash-free Session情報を障害調査のため処理する場合があります。健康値・記録日時・睡眠区間・同期カテゴリ・範囲・件数、Run・サンプル・同期元の識別子、Firebase UID、氏名・メール・IPアドレス、資格情報、プロバイダーや通信の生データ、Console Log、Tap表示名、Screenshot、Replay、View Hierarchy、Profiling、Tracingおよび任意添付は送らないよう制限します。
4. 問い合わせ・アンケート等
不具合報告では、メールまたはGoogle Formsの送信内容に、利用者が確認・編集できる状態で、問い合わせ種別、アプリ版・ビルド、プラットフォーム・OS、端末ファミリー、言語、開始画面、固定された診断コンテキスト、および既に存在する場合に限る直近のSentry Event IDを事前入力する場合があります。質問・機能要望では問い合わせ種別だけを事前入力します。健康・同期の詳細、Run Key、資格情報、生エラーまたはプロバイダーのPayloadを事前入力しません。問い合わせ本文、利用者が選んだ添付、IPアドレスやブラウザ情報等はGoogle、メール事業者および運営者がサポート対応のため処理する場合があります。
運営者は、本サービスの改善、機能開発、利用状況の把握その他の運営上の判断のため、任意のアンケート、フィードバック、意見・要望の募集その他の調査を実施する場合があります。これらでは、利用状況、利用目的、要望、評価、自由記述その他各調査で案内する情報を取得し、Google Forms等の外部サービスを通じて収集・管理する場合があります。
5. 利用目的
同期の実行、ローカル履歴・Widget表示、自動同期の追加試行、購入権利確認、設定維持、有効な設定下での一般的な利用状況の分析、広告、障害・不正利用の防止、問い合わせ対応、法的文書の版管理、および法令・プラットフォーム要件への対応に利用します。健康測定値、HealthKit・Fitbitサンプル、健康カテゴリ、同期範囲・件数、Run IDまたは資格情報を販売せず、広告ターゲティング・一般分析・マーケティングに利用しません。前項で開示した一般的な画面、広告配置および同期完了後の広告面に関するイベントは処理される場合があります。
6. 外部事業者と国外処理
本サービスはApple Health / HealthKit、Fitbit、Firebase Authentication / App Check / Analytics / Remote Config、Google Cloud、Expo Push Service、RevenueCat、Sentry、Google AdMob / UMP、Google Formsおよびメール事業者を利用します。これらの事業者は日本国外を含む地域で、各社の規約、ポリシーおよび法的保護措置に基づき情報を処理する場合があります。
運営者は、利用者の情報を取り扱う外部事業者について、本ポリシーおよび適用されるプラットフォーム要件と同等以上の保護を提供するサービスを選定して利用します。
7. 保存期間
- 端末内のSync Historyは、利用者が削除するか、アプリのデータが失われるまで保存されます。
- Fitbit資格情報および接続状態は、切断、置換、アカウント削除、アンインストールその他の端末・OS処理まで、端末設定・カーソル・Widget・通知状態は更新、無効化、Delete All、アカウント削除またはアンインストール等まで保持されます。
- SyncFlowが書き込んだHealthKitサンプルは、利用者・SyncFlowによる削除またはApple側の処理までApple Health内に残り得ます。Apple Health/iCloud側の保存・同期はAppleおよび利用者設定に従います。
- サーバーのユーザーおよび法的文書確認記録は、原則としてアカウント削除まで保存します。法令、紛争対応または不正防止に必要な記録は必要な範囲で保持する場合があります。
- アカウント削除が成功すると対象記録を稼働中データベースから削除します。ただし、災害復旧・セキュリティ用のアクセス制限されたバックアップには通常のローテーションが完了するまで残る場合があります。現在の本番構成は7世代の定期バックアップを保持します。バックアップは復旧、法令またはセキュリティ上必要な場合を除き利用せず、復元した場合は適用可能な削除を稼働系へ再適用します。
- 自動同期が有効で配送先が有効な間、インストール情報とPush Tokenをサービス提供のため保持します。自動同期の無効化、Tokenの置換、配信事業者による無効判定、Delete Allまたはアカウント削除等により、該当する配送情報を無効化または削除します。前面でアプリを開いていない期間だけを理由に、有効な自動同期の配送情報を削除しません。
- 日単位のインストール活動記録は、利用状況の長期推移、継続利用およびバックグラウンド機能の価値を把握するため、経過日数による自動削除を行わず、アカウント削除、適法な削除要求または処理目的の終了等の削除理由が生じるまで保持します。
- 問い合わせ情報は、回答、調査、再発防止、フォローアップ、法令・安全上の義務または紛争対応に合理的に必要な期間だけ保持し、不要になった後に削除または匿名化します。第三者のバックアップ・法定保存は各社方針に従います。
- 利用状況分析の選択は、撤回、アカウント削除、アンインストールその他の端末・OS処理まで端末に保存されます。分析を有効にした後のデータ、広告、購入および診断の保存期間は各事業者の設定・方針にも従います。
- Cloud Run等の接続・技術ログは、運営者が確認したGoogle Cloudの保存設定に従い、原則30日を基準として保持します。法令、セキュリティ調査または正当な紛争対応に必要な場合は、許される範囲で別途保全することがあります。
8. 削除、選択および権利
「同期済みデータと履歴を削除」は、ローカルSync History、Widget、同期カーソルおよびSyncFlowが書き込んだHealthKitデータを削除しますが、Fitbit接続、Appleの購入、法的確認またはアカウント自体を削除しません。「アカウントを削除」は、運営者のユーザー集約、Push登録、法的確認、端末のインストール識別子、ローカル履歴・認証情報、およびSyncFlowが書き込んだHealthKitデータの削除を試みます。Fitbit側の許可取消し、Appleの取引記録削除およびサブスクリプション解約は別の手続です。
利用状況分析は「このアプリについて > 利用状況」でいつでも無効にでき、無効化時に将来の収集を停止してアプリ分析識別子をリセットします。無効にしても本サービスを利用できます。
新しい規約・ポリシーを確認しない場合または文書を取得できない場合でも、限定画面から購入の復元、Appleのサブスクリプション管理およびアカウント削除を選べます。限定画面への移動だけでRevenueCatへの購入処理または一般分析の収集を開始せず、選択した操作に必要な追加通信だけを行います。Firebaseは、法的文書の取得、既存アカウントの判定または分析収集を停止する境界の適用のため処理する場合があります。アカウントが存在しない場合、削除のために新しいFirebaseまたはRevenueCat識別子を作成しません。
居住地域に応じて、アクセス、訂正、削除、処理制限、異議申立て、同意撤回、データ移転または監督機関への申立てを行える場合があります。本人確認および法令上許される例外を適用することがあります。
9. 安全管理とインシデント
通信暗号化、認証、App Check、最小権限、端末保護、バックアップ除外、入力検証、診断最小化および削除手段等の合理的な対策を講じます。完全な安全性は保証できません。適用法令上必要な場合、インシデントを調査し、利用者または当局へ通知します。
10. 子ども・改定・連絡先
本サービスは子ども向けではありません。居住地域および利用するプラットフォーム・健康サービスについて有効な同意を単独で行える最低年齢に達していない方は利用しないでください。重要な変更では新しい版の確認を求めます。
運営者:Yoshifumi Kanno
メール:sync.health.app@gmail.com
住所・電話番号は、法令に基づく請求があった場合に遅滞なく開示します。
Privacy Policy
Yoshifumi Kanno (the “Operator”) explains below how SyncFlow and its related services (the “Service”) handle information. Reviewing this Policy is separate from agreeing to the Terms.
For additional disclosures and rights concerning Washington and Nevada consumer health data, see the separate Consumer Health Data Privacy Policy (Washington and Nevada).
1. Information handled on the device
- Fitbit credentials, the health and fitness data you select, sync settings, and sync ranges.
- Apple Health permissions, HealthKit samples written by SyncFlow, and sync identifiers attached to those samples.
- Sync History containing a run ID, source and destination, trigger, run/start/completion times, on-device execution owner, execution state and outcome, category, inspected range, summary unit and count, write count, and a bounded error code. Health measurements are not copied into the Sync History SQLite database.
- A limited Widget snapshot containing local date, latest completion time, category, write count, display status, and plan-view state, plus outcome/category/write counts in an Auto Sync completion notification if you enable it. Lock Screen and Notification Center visibility follows your iOS notification settings.
- App state needed to operate the Service on the device, such as selected settings and ranges, Auto Sync and notification state, an installation ID and deduplication slot, cached legal-document versions and confirmation state, the optional analytics choice, limited entitlement/runtime snapshots, and announcement or display preferences.
SyncFlow applies iOS Data Protection and backup exclusion to Sync History and Widget storage, but cannot promise exclusion under every OS or environment condition. The Operator provides no Sync History cloud restore, cross-device transfer, iCloud/CloudKit History storage, or backup service. Uninstalling the app, replacing or losing a device, corruption, or deletion may permanently remove that history. Whether Apple Health samples sync through or remain in iCloud follows Apple's services and your device settings.
2. Information handled by the Operator's server
- A pseudonymous Firebase user ID and account timestamps.
- For Auto Sync: an installation ID, platform, time zone, Expo push token, the user's enabled preference, effective remote-trigger eligibility, a finite ineligibility reason, Background App Refresh and APNs registration status, next attempt, deduplication slot, and latest delivery status. The Silent Push data payload contains the trigger type, time slot, and, when diagnostics are enabled, a diagnostic correlation identifier used to connect the same operation across the device, server, and Sentry for troubleshooting. It does not contain health values, health categories, ranges, counts, or a user ID.
- The Usage Analytics state (enabled, disabled, or undecided), its update time, and app/build version.
- Regardless of the Usage Analytics setting, the server records per-installation daily operational activity to provide and monitor the service and understand the value of background features: the date; whether a foreground reconciliation or background-service response was observed; whether manual, Widget, Silent Push, or Background Task sync paths were used; and broad outcomes (success, partial failure, failure, or skipped), each as a daily presence flag. App/build version, Usage Analytics state, and measurement-spec version are also included. These daily records do not contain health values, health categories, sync ranges or counts, Push tokens, GA4 identifiers, or exact sync times. They are associated with the server-side pseudonymous Firebase user ID through a pseudonymous installation identifier.
- The exact Terms and Policy versions reviewed, confirmation time, app/build version, and locale.
- Connection and technical logs such as IP address, User-Agent, timestamp, route, response status, and timing for delivery, security, abuse prevention, and incident investigation. The app does not intentionally write health payloads, authentication tokens, or Sync History into its server application logs.
The Operator's server does not store Fitbit tokens, HealthKit samples, health measurements, Sync History categories/ranges/outcomes/counts, or arbitrary provider error text.
3. Analytics, ads, purchases, and diagnostics
- Firebase Analytics: after the legal documents are confirmed, bounded Usage Analytics is enabled. Firebase may process viewed screens and general operations; whether a sync starts manually, from a Widget, Silent Push, or another background path and its broad outcome; configured Widget families; session and usage information; app version; OS and device model; approximate region; in-app purchase events; and an app-instance identifier. The setting is stored on your device and may be disabled under About SyncFlow > Usage at any time. Disabling stops future collection and resets the app analytics identifier; the Service remains usable. SyncFlow does not send health measurements, HealthKit or Fitbit samples, health categories, sync ranges or counts, run IDs, name, email, login or authentication data, or Firebase user ID as custom events or user properties. It does not collect Widget impression or view counts.
- Firebase operational services: Authentication, App Check, Remote Config, Hosting, and Cloud Run may process a Firebase Installation ID, authentication and attestation material, IP address, country, language, time zone, device/OS/app and network information, request routes or URLs, and response status, size, and timing for authentication, abuse prevention, configuration, and service delivery. API bodies are limited to the information disclosed in Section 2, and application logs intentionally exclude authentication tokens and health payloads. The Firebase Performance SDK is not packaged in v2.4. This provider processing is separate from information stored in the Operator's Sync History database.
- AdMob / UMP: may process ad delivery, choices, device or advertising identifiers, ad interactions, and approximate location. Health measurements, HealthKit or Fitbit samples, health categories, sync ranges/counts, run IDs, and credentials are not used for ad targeting, request keywords, or ad measurement.
- Apple / RevenueCat: process purchases, receipts, entitlement state, device/app information, a pseudonymous user ID, and advertising-performance events such as the post-sync ad surface, placement, delivery, network, revenue, currency, and errors. The Operator does not receive payment-card numbers. Health measurements, HealthKit or Fitbit samples, health categories, sync ranges/counts, run IDs, and credentials are not sent to RevenueCat.
- Sentry: after the legal documents are confirmed, may process an event ID, symbolicated stack, exception type and mechanism, native threads, release/build/environment, OS and device family/model, locale, app state, fixed diagnostic context, route-name-only navigation/lifecycle/fixed-phase/selected fixed ad-action breadcrumbs, and crash-free session information. Health values, record dates, sleep intervals, sync categories/ranges/counts, run/sample/source identifiers, Firebase UID, name/email/IP address, credentials, raw provider or network data, console logs, tap labels, screenshots, replay, view hierarchy, profiling, tracing, and arbitrary attachments are restricted from reports.
4. Support, surveys, and feedback
For a bug report, the email or Google Forms destination may visibly prefill the request type, app and build, platform and OS, device family, locale, entry surface, fixed diagnostic context, and a recent Sentry Event ID only when one already exists. For a question or feature request, only the request type is prefilled. You can review and edit destination content before sending. Health or sync detail, run keys, credentials, raw errors, and provider payloads are never prefilled. Google, email providers, and the Operator may process the content and attachments you choose to send, plus ordinary web information such as IP address and browser data, to provide support.
The Operator may conduct optional surveys, feedback requests, requests for opinions or suggestions, and other research to improve the Service, develop features, understand usage, or make other operational decisions. These activities may collect usage information, purposes of use, requests, ratings, free-form responses, and other information identified in the relevant survey, and may use external services such as Google Forms to collect and manage responses.
5. Purposes
Information is used to perform sync, show local History and Widgets, make an additional Auto Sync attempt, verify purchases, preserve settings, analyze general use while the setting is enabled, serve ads, prevent failures and abuse, answer support, manage legal versions, and meet legal or platform requirements. Health measurements, HealthKit or Fitbit samples, health categories, sync ranges/counts, run IDs, and credentials are not sold or used for ad targeting, general analytics, or marketing. General screen, ad-placement, and post-sync ad-surface events disclosed above may be processed.
6. Providers and international processing
The Service uses Apple Health / HealthKit, Fitbit, Firebase Authentication / App Check / Analytics / Remote Config, Google Cloud, Expo Push Service, RevenueCat, Sentry, Google AdMob / UMP, Google Forms, and email providers. They may process information outside your country under their terms, policies, and applicable transfer safeguards.
The Operator selects and uses external providers that provide the same or equal protection for user information as described in this Policy and required by applicable platform rules.
7. Retention
- On-device Sync History remains until you delete it or the app data is lost.
- Fitbit credentials and connection state remain until disconnection, replacement, account deletion, uninstall, or other device/OS handling. Settings, cursors, Widget, and notification state remain until update, disablement, Delete All, account deletion, uninstall, or similar handling.
- HealthKit samples written by SyncFlow may remain in Apple Health until deleted by you or SyncFlow, or otherwise handled by Apple. Apple Health/iCloud retention and sync follow Apple and your settings.
- Server user and legal-confirmation records generally remain until account deletion. Records reasonably needed for law, disputes, or abuse prevention may be retained where permitted.
- Successful account deletion removes the relevant records from the active database. Restricted disaster recovery and security backups may retain residual copies until ordinary rotation completes; the current production configuration retains seven scheduled backup generations. Backups are not used except for recovery, legal, or security needs, and applicable deletions are reapplied to active systems after a restore.
- Installation information and its Push token are retained while Auto Sync and the delivery route remain valid. Delivery information is disabled or deleted when Auto Sync is disabled, the token is replaced or reported invalid by the provider, Delete All applies, or the account is deleted. A valid Auto Sync route is not deleted merely because the app has not been opened in the foreground.
- Daily installation-activity records are retained without automatic elapsed-time deletion to measure long-term usage trends, retention, and the value of background features. They remain until account deletion, an applicable deletion request, or another reason ending the processing purpose applies.
- Support information is retained only as reasonably needed to answer, investigate, prevent recurrence, follow up, meet legal or security duties, or resolve a dispute, then deleted or anonymized. Provider backups or legally required retention follow provider rules.
- The Usage Analytics setting remains on the device until withdrawal, account deletion, uninstall, or other device/OS handling. Data processed while enabled, advertising, purchase, and diagnostic retention also follows provider settings and policies.
- Connection and technical logs for services such as Cloud Run follow the verified Google Cloud retention configuration, generally using 30 days as the baseline. Records may be preserved longer where permitted for law, security investigations, or legitimate dispute handling.
8. Deletion, choices, and rights
“Delete Synced Data and History” deletes local Sync History, Widget data, cursors, and SyncFlow-authored HealthKit data, but not the Fitbit connection, Apple purchase, legal confirmation, or account. “Delete Account” attempts deletion of the Operator-controlled user aggregate, push registration, legal confirmations, local installation ID, local history and credentials, and SyncFlow-authored HealthKit data. Revoking Fitbit access, deleting Apple's transaction records, and canceling an Apple subscription are separate actions.
Usage Analytics may be disabled under About SyncFlow > Usage at any time, which stops future collection and resets the app analytics identifier. You may use the Service while Analytics is disabled.
If you do not confirm a new Terms or Policy version, or the documents cannot be retrieved, a limited screen still offers Restore Purchases, Apple subscription management, and Delete Account. Entering that screen does not itself start RevenueCat purchase processing or general analytics collection; only additional communications needed for an action you select occur. Firebase may still process data to retrieve legal documents, resolve an existing account, or enforce an analytics-disabled boundary. If no account exists, deletion does not create a new Firebase or RevenueCat identifier.
Depending on your location, you may request access, correction, deletion, restriction, objection, withdrawal, portability, or complain to an authority. Identity verification and lawful exceptions may apply.
9. Security and incidents
The Operator uses reasonable safeguards including encrypted transport, authentication, App Check, least privilege, device protection, backup exclusion, validation, minimized diagnostics, and deletion controls. No system is perfectly secure. Incidents will be investigated and notified where applicable law requires.
10. Children, changes, and contact
The Service is not directed to children. Do not use it unless you have reached the minimum age to consent independently under the laws, platform, and health services applicable to you. Material changes may require review of a new version.
Operator: Yoshifumi Kanno
Email: sync.health.app@gmail.com
Address and phone number will be disclosed without delay upon a legally valid request.