Privacy Policy
Mikata+ (ミカタ; "we", "us") is a coaching app for fitness beginners. This policy explains, in plain language, what information the app handles, where it is stored, and what does — and does not — leave your device. We aim to comply with Japan's Act on the Protection of Personal Information (APPI), and we describe your rights honestly regardless of where you live.
This policy describes how the app handles data today. If future features change how data is handled, we will update this policy before those changes take effect and announce it in the app or on the store page (Section 14).
The short version
- Sign-in uses your Apple or Google account (we never handle passwords). We never receive or store your password. You can use Apple "Hide My Email" (a private relay) if you prefer. Sign-in is optional — the whole app works without it (Section 1).
- To generate meal and workout plans, we send your profile (goal, date of birth / age, height, weight, activity level, dietary preference, allergies, gender, place, available equipment) to our recommendation server. This happens for all users — whether signed in or not, and whether cloud sync is on or off — every time we build a recommendation, because it is the input to the plan engine. The transmission is encrypted (TLS) (Section 2).
- When you sign in, we back up and sync your profile and day history to a cloud (storage & sync) provider, on by default. This carries your data over after a reinstall or new phone. You can stop syncing and request deletion at any time (Section 3).
- Your step / health-sensor data never leaves your device. It is used on-device only to show your activity — never sent to our server or to analytics (Section 4).
- We keep each kind of data only as long as it is needed, then delete it. Deleting your account permanently deletes the data tied to it after a 6-month grace period, and the profile sent for recommendations is never stored on our server (Section 12).
- Product analytics is anonymous events only — no email, no user id, no body/health values, no free text — and is not used to identify you or to track you (Section 5).
- No ads for your first 7 days — except a video you choose to play yourself to receive a shield, which is available during that period too. From day 8 ads appear in the app (Google AdMob). We never send your health information — weight, meals, workouts, steps, goals — to any ad provider (Section 15).
- You get 3 streak shields free each month, plus up to 3 more in the same month by watching a video ad (6 in total). There are no in-app purchases.
The above describes our current practices. If we ever change or add to them, we will tell you in advance and update this policy.
1. Sign-in (Apple / Google, optional)
- The app supports sign-in with your Apple or Google account. Sign-in is optional — you can use every feature of the app without it.
- We never handle passwords. Authentication is performed by Apple / Google; the app never receives or stores your password.
- At sign-in, we may receive an email address from the provider to identify your account and contact you. If you choose Apple "Hide My Email" (a private relay), it will be a relay address, and in some cases no email is provided (it may be empty).
- The purpose of sign-in is to verify you and to enable the cloud sync in Section 3 (backup, multiple devices, and carry-over after reinstall).
| Item | Details |
|---|---|
| Data received | An account identifier issued by the provider (Apple / Google) and an email address (may be a private relay, or empty) |
| Purpose | Verifying you via sign-in, necessary account-related contact, enabling cloud sync |
| Processing | Authentication is handled by the service providers (Apple / Google). We do not store your password |
| In transit | Encrypted with TLS |
2. Profile sent for recommendations — important
The core of the app is personalized meal and workout plans. To build them, the app sends the following profile to our recommendation server.
| Data sent | Classification |
|---|---|
| Goal / date of birth (or age) / height / weight / activity level / dietary preference / allergies / gender / place / available equipment | Health & fitness information (handled as sensitive data) |
- This transmission happens whether or not you are signed in, and regardless of the cloud-sync setting (Section 3). It is a separate mechanism from cloud sync: the profile is sent as request input to the recommendation API, per request. Even signed out, and even with sync off, this transmission occurs whenever recommendations are shown.
- Purpose: to generate and display meal and workout plans suited to you.
- In transit: the connection is encrypted (TLS).
- Storage: your backup is kept with a trusted cloud service. We handle it appropriately in line with Japan's Act on the Protection of Personal Information (APPI).
The step count read from device sensors is not included here (as in Section 4, it never leaves your device).
3. Cloud backup and sync (when signed in, on by default)
When you sign in, we safely back up the items below so your data is restored after a reinstall or a new phone. Your data is saved on your device first, and a copy is synced to the cloud. The app works fine offline and syncs automatically once you're back online.
- Profile: the body data from Section 2, your fridge contents (ingredients you enter), your saved workout steps, your favorites (the names of the items you star and when you saved them), and your store display order.
- Day history: check-ins (including your daily weight log), meal and workout commits (including a per-meal nutrition snapshot — calories, protein, fat, carbs), and the streaks, XP, and badges derived from them.
- Meal-choice events: picking, swapping, and removing items, along with the mood selected at the time.
- Consent record: the revision of the Terms of Use and Privacy Policy you agreed to (we do not record the date and time of your consent). While you are signed out it is kept on your device only, and it is recorded against your account once you sign in.
| Item | Details |
|---|---|
| Purpose | Backup, use across multiple devices, and carry-over after reinstall |
| Default | On by default when signed in. We explain what is synced |
| Processing | We entrust data storage to a trusted cloud service provider. The provider handles the data only as needed to operate the app, and is required by contract to keep it secure. |
| Storage | The cloud service provider's servers. We handle it appropriately in line with the law (Japan's APPI). |
| In transit | Encrypted with TLS |
Step / health-sensor data is never part of this sync (Section 4).
4. Health data (step count) — never leaves your device
- Only with your explicit permission, the app reads your step count from Apple HealthKit (iOS) or Health Connect (Android).
- Steps are processed on your device only, to display your daily activity. They are never transmitted off your device — not to our recommendation server, not to cloud sync, not to any analytics service, not to anyone.
- You can revoke this permission at any time in your OS settings (iOS: Settings > Privacy & Security > Health; Android: Health Connect settings). The app keeps working fully without it — you just won't see your step count.
- The app reads only; it never writes any health data.
5. Product analytics
To improve the product, the app collects anonymous usage events via an analytics service.
- For example: quest completed, recipe viewed, mood selected — anonymous usage events only (just numbers and fixed options).
- Not included: email address, user id, body/health values, or free-text. It is not used to identify you.
- It is not linked to your identity (account).
| Item | Details |
|---|---|
| Purpose | Understanding usage trends and improving features |
| Storage | The analytics provider's servers. We handle it appropriately in line with the law (Japan's APPI). |
6. Crash diagnostics
- In release builds only, the app collects crash diagnostics via a crash-diagnostics service.
- What is sent is technical logs — the error, stack traces, and device / OS information. No personal identifiers are included.
- The purpose is to identify and fix bugs.
7. Push notifications
- To deliver reminders, when you enable notifications via the in-app prompt, the device's push token is uploaded to our server. The token is tied to your account and is gated on your consent to cloud sync.
- Notification permission is requested only via an in-app prompt. You can turn notifications off at any time in your OS settings.
- Local on-device reminders may also be used, but push notifications are used for delivery as well.
8. Feedback form
When you submit in-app feedback, the following is sent to our server:
- the message body, an optional free-text contact / reply address, your locale, the app version, and the platform (iOS / Android).
- The purpose is to respond to issues and requests and to improve the product.
9. Third parties and where data is stored
The app uses the following providers:
| Provider | Role |
|---|---|
| Apple / Google | Sign-in providers |
| An analytics, crash-diagnostics & push-notification service provider | Analytics / diagnostics / notification delivery |
| A cloud service provider | Authentication, data storage and sync, and recommendation processing |
For in-app ads, the following information is also provided (Section 15):
| Recipient | Information provided | Purpose |
|---|---|---|
| Google (AdMob / Google Ireland Ltd. and affiliates) | Device, OS, language, approximate region, ad impressions and taps and similar interactions, rewarded-video completion, and on Android the advertising ID (the IDFA is not sent on iOS) | Serving, measuring and protecting in-app ads against abuse |
| Our server | Contained in the rewarded-video completion callback: a transaction id issued by Google, an identifier this app generates per install, and (only when signed in) your account id | Granting streak shields and enforcing the monthly cap of 3 |
10. Children
Mikata+ is for users aged 13 and over. The birth date picker in onboarding does not allow users under 13 to proceed. We do not knowingly collect information from children under 13.
11. Your rights and account deletion
- In-app data: You can view and edit the data you enter in the app at any time. Deleting the app deletes the on-device data.
- Account deletion and reactivation: Account deletion is scheduled with a 6-month grace period, after which the account is permanently deleted. Within the grace period you can reactivate it. This is available in-app and via the contact below.
- Access, correction, suspension, etc.: For requests under APPI, please contact us below. We will respond in good faith within our means. Note that anonymous analytics events cannot be matched to a specific individual, so there are technical limits.
12. Data retention
We keep each kind of data only as long as it is needed for the purpose it was collected for, and delete it once that period ends or when you ask us to. Our retention periods are as follows.
| Data | How long we keep it | How it is deleted |
|---|---|---|
| On-device data (profile, day history, fridge contents, step display) | For as long as the app is installed | Deleting the app deletes the on-device data |
| Account record (the identifier and email address received from Apple / Google — Section 1) | For as long as your account exists | When you request deletion, it is permanently deleted after a 6-month grace period (you can reactivate within the grace period — Section 11) |
| Cloud backup of your profile, day history and meal-choice events (Section 3) | For as long as your account exists (so it can be restored on a new phone or after a reinstall). It is not deleted on a fixed timer | Deleting your account permanently deletes all data tied to it. Turning sync off stops any further upload |
| The profile sent for recommendations (Section 2) | Not retained — it is used only to compute that response and is never written to our database | Discarded as soon as the request finishes. Operational request logs (timestamp, endpoint and similar technical fields — never the profile itself) are kept by our cloud provider for a short period (a few days) and then deleted automatically |
| Push token (Section 7) | For as long as your account exists (replaced whenever the OS issues a new token) | Deleted together with your account. Turning notifications off in your OS settings stops delivery; if you want the token itself removed, ask us via the contact below |
| Anonymous usage events (Section 5) | Automatically deleted by the analytics provider under its retention setting, within 14 months at most | Auto-deleted by the provider once the period ends. Because they cannot be matched to an individual, we cannot honour per-person deletion requests for them |
| Crash diagnostics (Section 6) | Automatically deleted after 90 days under the crash-diagnostics provider's retention policy | Auto-deleted by the provider once the period ends |
| Feedback content and the optional contact address (Section 8) | Until we have finished handling your report or request | Deleted promptly once handling is complete. You can also ask us to delete it sooner via the contact below |
| Consent record (the revision of the Terms and Privacy Policy you agreed to, plus the date we received it — not the time you consented; Section 3) | For as long as the account exists (it is the record of which revision you accepted, so it is not auto-deleted after a period) | When you request deletion, it is permanently deleted together with your account after a 6-month grace period (you can reactivate within that period, so the consent record remains during it — Section 11) |
| Rewarded-video records (transaction id, per-install identifier, the month granted — Section 15) | Kept for 13 months for abuse prevention and the monthly cap, then deleted | Deleting your account unlinks the record from the account only; the record itself is kept so the cap still works |
- Where the law requires us to keep records, or where data is needed to handle a dispute, we may keep it for that purpose only, and only for as long as needed.
- If we ever need to keep data longer than stated above, we will tell you before the change takes effect, following Section 14.
13. Security
We take reasonable measures appropriate to the nature of the data. Recommendation requests, authentication, cloud sync, and notification-token uploads are all encrypted in transit (TLS). We require our service providers to apply appropriate safeguards by contract. An important safeguard remains the design itself: your step / health-sensor data simply does not leave your device.
14. Changes to this policy
If future features change how data is handled, we will update this policy before those changes take effect and announce it in the app or on the store page. For significant changes we may ask for your consent again.
15. Ads
The app shows ads inside the app so the features can stay free to use.
- When they appear: No ads for the first 7 days after you start using the app. From day 8, ads appear in the app. The one exception is the rewarded video below: a video you choose to play yourself to receive a shield is available during that period too. If you play one in that first week, a consent prompt (see "Your choices" below) may be shown then, right before the video, for people in the EU/UK and similar regions.
- Ad provider: We use Google's ad-serving service (Google AdMob). Every ad is clearly labelled as an ad.
- What is sent to the ad provider: your device type, OS, language and approximate region, and interaction history such as ad impressions and taps. These go to Google and are used to serve ads, measure impressions, and prevent click fraud. On iOS the advertising identifier (IDFA) is not sent, because this app never asks for tracking permission. On Android the device's advertising ID is used (you can reset or switch it off in your device settings, below).
- What is never sent (important): your weight, height, age, gender, meal contents, calories, workout history, step count, goals, allergies, fridge contents and mood are never sent to any ad provider. None of it is used to target the ads you see, either.
- Rewarded video (extra streak shields): A video ad plays only when you choose to play one, to receive extra streak shields. When you watch it to the end, Google notifies our server that the view completed, and that notification contains only a transaction id issued by Google, an identifier this app generates per install, and (only when signed in) your account id — no health information. Every feature of the app remains available whether or not you watch a video.
- Your choices:
- iOS: this app never asks for tracking permission. Nothing you do here is linked to your activity in other companies' apps or sites, and your ads are always non-personalised.
- Android: you can reset your advertising ID or opt out of personalisation in Settings → Google → Ads on your device.
- EU / UK and similar regions: we show a consent screen the first time. You can change your choices at any time from Settings → Ad settings in the app.
- About this external transmission: As described above, the app sends information from your device to Google in order to serve ads. The information sent, its recipient, and the purpose are exactly as stated in this section.
16. Contact
For questions or requests about your data:
- Operator: Mikata+
- Email: mikataapp@gmail.com