Back to home

Privacy Policy

Mikata+ (ミカタ; "we", "us") is a coaching app for fitness beginners. This policy explains, in plain language, what information the app handles, where it is stored, and what does — and does not — leave your device. We aim to comply with Japan's Act on the Protection of Personal Information (APPI), and we describe your rights honestly regardless of where you live.

This policy describes how the app handles data today. If future features change how data is handled, we will update this policy before those changes take effect and announce it in the app or on the store page (Section 14).

1. Sign-in (Apple / Google, optional)

ItemDetails
Data receivedAn account identifier issued by the provider (Apple / Google) and an email address (may be a private relay, or empty)
PurposeVerifying you via sign-in, necessary account-related contact, enabling cloud sync
ProcessingAuthentication is handled by the service providers (Apple / Google). We do not store your password
In transitEncrypted with TLS

2. Profile sent for recommendations — important

The core of the app is personalized meal and workout plans. To build them, the app sends the following profile to our recommendation server.

Data sentClassification
Goal / date of birth (or age) / height / weight / activity level / dietary preference / allergies / gender / place / available equipmentHealth & fitness information (handled as sensitive data)

The step count read from device sensors is not included here (as in Section 4, it never leaves your device).

3. Cloud backup and sync (when signed in, on by default)

When you sign in, we safely back up the items below so your data is restored after a reinstall or a new phone. Your data is saved on your device first, and a copy is synced to the cloud. The app works fine offline and syncs automatically once you're back online.

ItemDetails
PurposeBackup, use across multiple devices, and carry-over after reinstall
DefaultOn by default when signed in. We explain what is synced
ProcessingWe entrust data storage to a trusted cloud service provider. The provider handles the data only as needed to operate the app, and is required by contract to keep it secure.
StorageThe cloud service provider's servers. We handle it appropriately in line with the law (Japan's APPI).
In transitEncrypted with TLS

Step / health-sensor data is never part of this sync (Section 4).

4. Health data (step count) — never leaves your device

5. Product analytics

To improve the product, the app collects anonymous usage events via an analytics service.

ItemDetails
PurposeUnderstanding usage trends and improving features
StorageThe analytics provider's servers. We handle it appropriately in line with the law (Japan's APPI).

6. Crash diagnostics

7. Push notifications

8. Feedback form

When you submit in-app feedback, the following is sent to our server:

9. Third parties and where data is stored

The app uses the following providers:

ProviderRole
Apple / GoogleSign-in providers
An analytics, crash-diagnostics & push-notification service providerAnalytics / diagnostics / notification delivery
A cloud service providerAuthentication, data storage and sync, and recommendation processing

For in-app ads, the following information is also provided (Section 15):

RecipientInformation providedPurpose
Google (AdMob / Google Ireland Ltd. and affiliates)Device, OS, language, approximate region, ad impressions and taps and similar interactions, rewarded-video completion, and on Android the advertising ID (the IDFA is not sent on iOS)Serving, measuring and protecting in-app ads against abuse
Our serverContained in the rewarded-video completion callback: a transaction id issued by Google, an identifier this app generates per install, and (only when signed in) your account idGranting streak shields and enforcing the monthly cap of 3

10. Children

Mikata+ is for users aged 13 and over. The birth date picker in onboarding does not allow users under 13 to proceed. We do not knowingly collect information from children under 13.

11. Your rights and account deletion

12. Data retention

We keep each kind of data only as long as it is needed for the purpose it was collected for, and delete it once that period ends or when you ask us to. Our retention periods are as follows.

DataHow long we keep itHow it is deleted
On-device data (profile, day history, fridge contents, step display)For as long as the app is installedDeleting the app deletes the on-device data
Account record (the identifier and email address received from Apple / Google — Section 1)For as long as your account existsWhen you request deletion, it is permanently deleted after a 6-month grace period (you can reactivate within the grace period — Section 11)
Cloud backup of your profile, day history and meal-choice events (Section 3)For as long as your account exists (so it can be restored on a new phone or after a reinstall). It is not deleted on a fixed timerDeleting your account permanently deletes all data tied to it. Turning sync off stops any further upload
The profile sent for recommendations (Section 2)Not retained — it is used only to compute that response and is never written to our databaseDiscarded as soon as the request finishes. Operational request logs (timestamp, endpoint and similar technical fields — never the profile itself) are kept by our cloud provider for a short period (a few days) and then deleted automatically
Push token (Section 7)For as long as your account exists (replaced whenever the OS issues a new token)Deleted together with your account. Turning notifications off in your OS settings stops delivery; if you want the token itself removed, ask us via the contact below
Anonymous usage events (Section 5)Automatically deleted by the analytics provider under its retention setting, within 14 months at mostAuto-deleted by the provider once the period ends. Because they cannot be matched to an individual, we cannot honour per-person deletion requests for them
Crash diagnostics (Section 6)Automatically deleted after 90 days under the crash-diagnostics provider's retention policyAuto-deleted by the provider once the period ends
Feedback content and the optional contact address (Section 8)Until we have finished handling your report or requestDeleted promptly once handling is complete. You can also ask us to delete it sooner via the contact below
Consent record (the revision of the Terms and Privacy Policy you agreed to, plus the date we received it — not the time you consented; Section 3)For as long as the account exists (it is the record of which revision you accepted, so it is not auto-deleted after a period)When you request deletion, it is permanently deleted together with your account after a 6-month grace period (you can reactivate within that period, so the consent record remains during it — Section 11)
Rewarded-video records (transaction id, per-install identifier, the month granted — Section 15)Kept for 13 months for abuse prevention and the monthly cap, then deletedDeleting your account unlinks the record from the account only; the record itself is kept so the cap still works

13. Security

We take reasonable measures appropriate to the nature of the data. Recommendation requests, authentication, cloud sync, and notification-token uploads are all encrypted in transit (TLS). We require our service providers to apply appropriate safeguards by contract. An important safeguard remains the design itself: your step / health-sensor data simply does not leave your device.

14. Changes to this policy

If future features change how data is handled, we will update this policy before those changes take effect and announce it in the app or on the store page. For significant changes we may ask for your consent again.

15. Ads

The app shows ads inside the app so the features can stay free to use.

16. Contact

For questions or requests about your data: