Privacy Policy

Kyohei Takeshita ("we", "us") provides the mobile app おさんぽビンゴ (Walking Bingo) (the "App") and the servers the App communicates with (together, the "Service"). This Privacy Policy (this "Policy") explains how information is handled in the Service.

Fully revised on July 28, 2026

The previous version of this Policy stated that "the information that I request will be retained on your device and is not collected by me in any way." As of version 3.0.0, the App includes features that communicate with our own servers — account linking, cloud storage of custom bingo cards, the public gallery, and the sending of usage data — and that statement no longer holds. This Policy therefore replaces the previous version in its entirety.

1. Provider and Contact

Questions about this Policy, requests for access, correction or deletion of your information, and takedown or rights-infringement notices regarding published cards are all accepted at the email address above.

2. Scope of This Policy

This Policy applies to the Service. Third-party services used by the App (advertising, sign-in, in-app purchases, map data, and so on — see "6. Third Parties and Processors") handle information according to their own privacy policies.

About app versions: This Policy describes the App including features introduced in version 3.0.0. If you are using a version earlier than 3.0.0, the following features are not yet available, and no information relating to them is collected or transmitted.

3. Information Stored Only on Your Device

Most of the App's data is stored on your device rather than on our servers. Except where this Policy states that information is sent to us, the following is not transmitted to our servers.

Photo image data is never sent to our servers. This holds even when you publish a card to the Public Gallery: the photo itself is never seen by anyone else (see section 4.5).

If you save a custom bingo card to the cloud, squares that use a photo or a drawing are represented in the cloud record by a hash value that identifies the image only — the image itself is not included.

Only drawing images are sent to our servers, and only when you submit that card for publication. See section 4.5 for how they are handled.

4. Information We Collect and Why

4.1 Usage Data (In-App Behavior Log)

To improve the quality of the App, the App sends anonymous usage data to our own server (which we operate on infrastructure provided by Cloudflare, Inc.).

What is sent:

What is not sent:

The event types and fields that may be sent are limited to a list defined in advance on the server; anything not on that list is rejected. The anonymous measurement ID is generated and stored separately from your account identifier and from the cloud-sync device identifier, and we do not maintain any mechanism to join them.

Purpose (a continuous improvement loop): we use this data to keep improving the App, as follows.

  1. Measure and record the usage data described above.
  2. Aggregate it daily into statistics from which no individual can be identified (number of users, per-screen drop-off, error rates, and so on).
  3. Generate a weekly analysis report from those statistics using an AI service (the Claude API provided by Anthropic, PBC).
  4. Review the report and feed it into the next round of improvements.

Only the aggregated statistics produced in step 2 are sent to the AI service. Individual interaction records, identifiers, and text you have entered are never sent. The generated report is used internally only and is never published.

Opting out: sending usage data is on by default, but you can turn it off at any time in the App at "設定" (Settings) → "おとなのメニュー" (Adult Menu) → "利用状況データの送信" (Send usage data). Once off, no further data is sent and the anonymous measurement ID is erased from your device.

4.2 Browsing and Importing from the Public Gallery (Happens Even Without Account Linking)

The following is sent to and stored on our servers even when you have not linked a Google or Apple account.

(1) Automatic creation of an anonymous account: the moment you open the public gallery in the App, the App automatically creates an anonymous account on our servers (no account linking is required, and no confirmation screen is shown). What we store at that point is:

This anonymous account contains no name and no email address (we have not received them, because no account has been linked).

(2) Importing a published card: when you import a card from the public gallery as your own, the card title and the text of each of the 25 squares are stored on our servers as a card belonging to your account. This happens whether or not you have linked an account.

(3) Import history: we also record which published card was imported, by which user identifier, and when. We use this to prevent the same card from being imported twice, to count how many times each published card has been imported, and to respond to abuse.

All of the above can be deleted through the account deletion described in section 9. If you have not linked an account, the in-app deletion steps are the same as for a linked account (see Account Deletion Request).

4.3 Account Linking (Optional)

To use cloud storage for your custom bingo cards or to submit a card for publication, you need to link a Google account or an Apple ID. When you link an account, we store the following on our servers.

We use this to synchronize data between your device and the cloud, to establish who is responsible for a publication request, and to respond to abuse. Linking is optional; you can play bingo, use the collection book, and create custom cards stored on your device without linking an account.

4.4 Cloud Storage of Custom Bingo Cards

If you have linked an account, the custom bingo cards you create yourself are stored on our servers. What is stored is the card title, the content of each of the 25 squares (including the literal text you typed), and the state of the card (draft / approved by a guardian / awaiting review, and so on). The purpose is to let you restore your cards after changing or reinstalling on a device, and to synchronize across devices.

Note that cards imported from the public gallery are stored on our servers even if you have not linked an account (see 4.2).

4.5 Public Gallery (User-Generated Content)

The Public Gallery is not yet available. This section describes how it will work once we enable it. We will update the "last updated" date on this page when that happens.
The content of a card you submit for publication becomes visible to the general public.

This section covers the publishing side. For what is stored on our servers when you browse or import from the public gallery, see 4.2.

The terms that govern the public gallery are set out separately in the User-Generated Content (UGC) Terms of Use.

4.6 Reports

When you report a published card, we record the reporter's user identifier, the report category, the free-text description (up to 200 characters), the time of the report, and the card concerned. We use this to act on inappropriate content, to prevent recurrence, and to respond to disputes. Report contents are not disclosed to the author of the reported card.

4.7 Walk Streak Records

If you have linked an account, we store the history of the dates on which you played on our servers. This is synchronized automatically when the home screen is displayed. The purpose is to carry your streak over when you change devices. No information other than the dates (such as where you walked or what you did) is included.

4.8 Device Identifiers

The App generates two identifiers on your device. Both are random values; neither is a hardware identifier nor an advertising identifier.

Both persist on your device until you uninstall the App (the measurement ID is also erased as soon as you turn off the sending of usage data).

4.9 IP Address

Because of how network communication works, our servers receive the source IP address of your requests. We use the IP address solely as the key of a counter that prevents abusive volumes of requests (rate limiting), and it is retained for at most two days (it is erased automatically according to the counter's time window). We do not store or analyze IP addresses as part of usage data, and we do not use them for any other purpose.

4.10 Location

The App includes a "find nearby places" feature that searches for facilities around you.

4.11 In-App Purchases

The App offers the ad-free "おうえんパス" (Support Pass, support_pass) and three "なげ銭" tip items (tip_small / tip_medium / tip_large). Payment and purchase records are handled through Apple's and Google's in-app purchase systems; we do not receive your credit card number or other payment details. Whether you hold the Support Pass is kept on your device, and we do not perform receipt validation on our servers. As noted in 4.1, whether you hold the Support Pass is included in usage data as a boolean value.

4.12 Advertising

Unless you have purchased the Support Pass, the App displays ads from Google AdMob. The advertising SDK may collect information such as your IP address and device attributes in order to deliver ads, prevent fraud, and measure performance. See "6. Third Parties and Processors" and Google's policies for details.

5. Guardian Confirmation Before Certain Actions

Actions that involve a decision or consent — in-app purchases, account linking, account deletion, submitting a card for publication, reporting a card, and switching usage-data sending on or off — are placed behind a simple arithmetic confirmation screen ("おとなのかくにん", the guardian gate). Its purpose is to prevent these actions from being carried out by a child alone. It is not an age-verification mechanism, and we do not collect ages or dates of birth.

6. Third Parties and Processors

We do not sell or otherwise provide the information we collect to third parties, except as required by law. To operate the Service, however, we use the following providers.

Provider / serviceRoleInformation involved
Cloudflare, Inc. Infrastructure for our servers (Workers / D1 / KV / Analytics Engine) and a subprocessor for email delivery All information this Policy describes as being sent to our servers, plus the IP address of the connection
Google LLC (AdMob) Ad delivery IP address, device information, and similar data collected by the advertising SDK
Google LLC (Sign in with Google) / Apple Inc. (Sign in with Apple) Authentication for account linking The information you provide to each company when signing in. We receive the resulting identifier and email address
Apple Inc. / Google LLC In-app purchase processing The information each store requires for payment (we do not receive payment details)
Google LLC (Google Fonts CDN, fonts.gstatic.com) Retrieving the typefaces used in the App The IP address and connection information exposed when the typeface is fetched
OpenStreetMap Foundation (Overpass API / Nominatim) Searching for nearby facilities and resolving addresses when "find nearby places" is used Your approximate latitude and longitude at that moment (rounded to three decimal places, a granularity of roughly 110 metres — see 4.10), and the IP address of the connection (only when you run the feature)
Anthropic, PBC (Claude API) Generating the weekly internal analysis report Aggregated statistics only, from which no individual can be identified (no individual records, identifiers, or entered text)

7. Where Data Is Stored and International Transfers

Our servers run on Cloudflare's global network. Our database (Cloudflare D1) was created with a location hint that prefers the Asia-Pacific region, but we cannot guarantee that data is physically confined to any particular country. In addition, the Anthropic service used to generate the weekly report is provided by a United States company, so the aggregated statistics are transferred to the United States. Data protection regimes in these countries and regions may differ from those in Japan. By using the Service, you acknowledge that these transfers occur.

8. Retention Periods

DataRetention
Individual usage-data records (raw logs)Erased automatically after approximately 92 days, following the retention window of Cloudflare Analytics Engine, which we use
Daily aggregated statistics derived from usage data, and the weekly reportsRetained to support ongoing improvement. We do not currently operate an automatic deletion mechanism for these. No individual can be identified from them
IP address (rate-limiting counters)At most two days
Anonymous account records (user identifier, cloud-sync identifier, session token verification data — see 4.2)Until you delete your account (session token verification data is also erased when it expires or when it is replaced on the next sign-in)
Account link information, cards saved to the cloud, streak records, import historyUntil you delete your account
Snapshots of published cardsWithdrawal or suspension makes the card unavailable to view. Records are retained thereafter only to the extent needed to prevent abuse and to support re-review
Report records, records of consent to the UGC Terms of Use, and the minimal record that an account has been deletedRetained after account deletion (see Account Deletion Request)
Copies contained in disaster-recovery backupsErased as the backup retention period (up to 30 days) elapses
Email correspondenceRemains on the mail server as a record of the inquiry

9. Your Rights

You may request access to, correction of, deletion of, or suspension of use of the information we hold about you.

Note that usage data is associated only with the anonymous measurement ID, and we have no means of linking it to an individual. We therefore cannot locate and disclose or delete specific log entries. Please use the opt-out instead.

10. Children

The Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we discover that a child under 13 has provided us with personal information, we delete it from our servers promptly. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact info+walking_bingo@oysk2.com so that we can take the necessary action.

The App is designed to be used by children together with their family. Actions that involve a decision or consent are placed behind a guardian confirmation screen (section 5), but that screen is not an age-verification mechanism.

11. Security

We take reasonable safeguards to protect the information entrusted to us, including encrypted transport (HTTPS), restricted access, and rate limiting. However, no method of transmission over the internet or of electronic storage is 100% secure, and we cannot guarantee absolute security.

12. Links to Other Sites

The Service may contain links to external sites that we do not operate. We are not responsible for the content, privacy policies, or practices of those sites, and we advise you to review their privacy policies.

13. Changes to This Policy

We may update this Policy from time to time. When we do, we will post the updated text on this page and update the "last updated" date at the bottom. If we make a material change, we will also notify you within the App.

14. Contact

If you have any questions or suggestions about this Policy, please contact info+walking_bingo@oysk2.com.