Privacy Policy
English
Summary
- The iOS app works without an account. Locally saved recipes, settings and notes stay on your device. Apple and Google services used by the app are described below.
- An account is optional. If you sign in on the web (app.hoparoma.com) or in the app, your phone number is verified by Google's Firebase Authentication. Our server stores only a keyed hash of the number, never the number itself.
- Recipes you save to your account are stored on our server so you can reach them from the web and the app.
- Pro billing goes through Stripe (web) or Apple (app). We never see card details.
- This website uses Google Analytics 4 to count page views, as described under Website.
1. Who we are
Hoparoma is operated by Art Factory Co., Ltd., 1-32-3 Hongo, Bunkyo-ku, Tokyo 113-0033, Japan. We are the controller of the data described here. Contact: support@hoparoma.com.
2. The iOS app without an account
Until you sign in, the app sends nothing about you to Hoparoma. Versions with account support initialise Google Firebase at launch and register with Apple's push notification service (the resulting device token is shared with Firebase, which uses it only to verify phone sign-ins), and load product information from the App Store; none of this involves your recipes. The following stays in local storage on your device and never leaves it unless you actively share it through iOS's share sheet:
- Saved recipe definitions (hops, malts, water chemistry, yeast, mash settings) and results
- App preferences (language, default batch volume, warning toggles)
- Recipe history, tastings and personal corrections you create
The app shows no advertising and does not collect names, email addresses or location. Firebase Authentication and the reCAPTCHA Enterprise SDK process identifiers and diagnostic data for phone sign-in and abuse prevention, as described in section 3.
3. Your account (web service and signed-in app)
An account lets you use Hoparoma in a browser, keep recipes across the web and the app, and share one Pro subscription between them. When you sign in, we process:
- Phone number. Google's Firebase Authentication sends you a one-time SMS code and confirms the number to us. Our server keeps a keyed hash (HMAC) of the number and a random account identifier; it does not store the number. The hash lets us keep one account per number and apply monthly allowances. Firebase processes the number under Google's privacy policy; SMS delivery is enabled for Japan, the United States, Canada, the United Kingdom and Australia.
- Sign-in session. A session token, valid for up to 90 days, stored in a cookie on the web or in the device Keychain in the app; it stays there until you sign out or it is replaced. In the app, the Firebase sign-in component also keeps your sign-in state (including the phone number) in the device Keychain until you sign out.
- Recipes and results you save to the account (hop additions, brewing settings, yeast, the aroma estimate and comparison history), together with the calculation history behind them. Deleting a recipe hides it and frees a saved slot; the underlying data is removed when you delete the account (see section 6).
- Brewing journal (web service). When you mark a saved recipe version as brewed, we store a copy of that version and its aroma estimate together with the brew date and your batch notes. Each tasting you log against a brew stores the tasting date, an optional liking score (1–5), your notes and any aroma observations you choose to record. These records stay in your journal even if you later change or delete the recipe, until you delete the record or the account. The journal is kept on our server and is not synchronised with the app's tasting log.
- Usage counters: how many recipes, comparisons, saves and calculations you have used in the current month, to apply the Free or Pro allowances.
- Security signals. Sign-in is protected by Google reCAPTCHA, which evaluates browser and device signals to block automated SMS abuse. In iOS versions with reCAPTCHA Enterprise phone sign-in, the SDK may collect device identifiers, crash data, performance data and app interaction information (such as taps, clicks and scrolling) for app functionality and abuse prevention. Its privacy manifest declares these data as linked to the user and not used for tracking. Firebase Authentication also collects diagnostic information about its SDK, device and platform to diagnose issues and improve the service. See Google’s reCAPTCHA Apple privacy details and Firebase data disclosures; Google's Privacy Policy and Terms of Service apply. Cloudflare and our hosting provider record IP addresses and request metadata for rate limiting and troubleshooting; our own application log records status codes, paths, timings and internal identifiers, not phone numbers or recipe contents.
- Abuse detection. We analyse patterns in submitted recipes (for example a run of near-identical variations) to detect automated probing of the model. Nobody reads your recipes unless you ask us to look at them in a support request.
We do not use your recipes to train models or for advertising, and we do not sell or share personal data.
4. Pro subscription and payments
- Web (Stripe). Checkout and the customer portal are provided by Stripe. Stripe collects your card details, email and billing address and sends receipts; we receive a customer identifier, subscription identifier, status and billing period dates. Card numbers never reach our server. See Stripe's privacy policy.
- App (Apple). Apple handles payment. To count the subscription for your account, the app sends us Apple's signed transaction record (transaction identifiers, product, dates, environment) together with your account identifier. See Apple's privacy policy.
- Pro status on your device. The app caches your account's Pro status for up to 30 days so it keeps working offline.
- Stripe and Apple keep the transaction records, including amounts. We keep the identifiers and status described above for as long as tax, accounting and dispute-handling obligations require (in Japan, up to seven years).
5. Where your data is processed
Our server and database run on Fly.io in San Jose, California, USA, behind Cloudflare. Firebase Authentication and reCAPTCHA are operated by Google, payments by Stripe and Apple. These providers process data in the United States and other countries and act on our instructions as processors. Art Factory Co., Ltd. is established in Japan; for users in the EU/EEA, the UK and Switzerland, transfers rely on the providers' standard contractual clauses or equivalent safeguards. Fly.io keeps five daily volume snapshots, and we copy the database daily to Cloudflare R2 (encrypted at rest), keeping the newest 30 copies.
6. How long we keep data
- Recipes and results: while the account exists. A deleted recipe is hidden at once; its data is removed together with the account.
- Brewing journal (brews and tastings): until you delete the record or the account. Deleting a brew erases its recipe copy, notes, brewing date and all its tastings at once, while deleting a tasting erases only that tasting's notes, ratings, aroma observations and date; record and request identifiers, version numbers where applicable, creation times and hashes of the original creation requests remain, without those contents, until account deletion, so that a repeated request cannot recreate the record.
- Sessions: until sign-out or expiry (90 days).
- Usage counters and abuse-detection flags: for the life of the account and about 90 days after deletion.
- Account deletion: recipes, calculation history, the brewing journal, sessions and abuse-detection data are deleted immediately. Any Stripe subscription is first set to end at the close of the paid period (an incomplete one is cancelled at once). The hashed phone identifier, usage counters and abuse flags are kept for about 90 days so that deleting and re-creating an account cannot reset monthly allowances; the clean-up runs daily rather than at an exact moment. Apple subscriptions must be cancelled with Apple.
- Billing records: if the account ever had a subscription, we keep the Stripe customer and subscription identifiers, the Apple transaction identifiers and their status after deletion, together with the hashed phone identifier they are linked to, for as long as tax, accounting and dispute-handling obligations require (in Japan, up to seven years), and then delete them.
- Server logs: our application log is kept by the hosting provider for a short period (days); Cloudflare keeps its own request logs under its policy.
- Backups: the newest 30 daily copies plus five Fly.io snapshots. Deleted data leaves the backups as they rotate.
7. Your choices and rights
- You can use the iOS app without any account.
- You can delete your account yourself, in the web app (Account → Delete account) or in the app (Settings → Account). Deletion of your Hoparoma account is immediate and cannot be undone; if removing the sign-in record from Firebase fails, you are asked to sign in again to finish.
- You can see your saved recipes in the web app and the app at any time, and your brewing journal in the web app; the app can export a recipe as text through the share sheet. For a copy of any other data we hold about your account, email us.
- Depending on where you live (for example under the GDPR, the UK GDPR or Japan's APPI) you may have rights to access, correct, delete, restrict or port your data and to object to processing, and to complain to a supervisory authority. Write to support@hoparoma.com; we answer within 30 days.
- California residents: we do not sell or share personal information and do not use it for targeted advertising.
8. Children
Hoparoma is a brewing-planning tool and is not directed to children. Accounts require you to be at least 18 years old. We do not knowingly collect data from anyone under 13; if we learn that we have, we delete it.
9. Security
All traffic is encrypted in transit (TLS). Phone numbers are stored only as keyed hashes, secrets are kept in the hosting provider's secret store, card data is handled only by Stripe and Apple, and sign-in is rate-limited and protected against automated abuse. If a breach affecting your data occurs, we will notify you and the authorities as the law requires.
10. Website (hoparoma.com)
This website uses Google Analytics 4 to count page views and clicks on links to the App Store and to the web app (which link was clicked and where on the page it sits), so we can see which reference pages are useful. Google Analytics sets cookies for that purpose and processes your IP address and browser details on Google's servers. We have not enabled advertising features, and we do not sell or share the data. If you would rather not be counted, use the Google Analytics opt-out browser add-on or block cookies for this site. The email sign-up form is provided by Buttondown and receives only the address you submit. The web app at app.hoparoma.com does not use Google Analytics.
11. Changes
When we change this policy we update the date above. If a change materially affects how account data is used, we announce it in the web app and the app before it takes effect.
12. Contact
Email support@hoparoma.com, or open an issue at the project repository linked from the App Store description. Seller details: 特定商取引法に基づく表記.
日本語
要旨
- iOS アプリはアカウントなしで使えます。端末に保存したレシピ・設定・メモは端末内にとどまります。アプリが利用する Apple と Google のサービスについては以下に説明します。
- アカウントは任意です。ウェブ版(app.hoparoma.com)またはアプリでサインインすると、電話番号は Google の Firebase Authentication が確認します。当社サーバーが保存するのは番号の鍵付きハッシュだけで、番号そのものは保存しません。
- アカウントに保存したレシピは、ウェブとアプリの両方から使えるように当社サーバーに保存されます。
- Pro の決済は Stripe(ウェブ)または Apple(アプリ)が行い、当社はカード情報を見ません。
- このウェブサイトは Google Analytics 4 でページ閲覧数を計測しています(「ウェブサイト」参照)。
1. 事業者
Hoparoma の運営者および個人情報取扱事業者は、株式会社アート・ファクトリー(〒113-0033 東京都文京区本郷一丁目32番3号)です。連絡先: support@hoparoma.com
2. アカウントなしの iOS アプリ
サインインするまで、アプリがあなたに関する情報を Hoparoma に送ることはありません。アカウント対応版のアプリは起動時に Google Firebase を初期化し、Apple のプッシュ通知サービスに登録し(得られた端末トークンは Firebase に渡り、電話番号サインインの確認だけに使われます)、App Store から商品情報を読み込みますが、いずれもレシピには関わりません。以下は端末内にローカル保存され、あなたが iOS の共有シートで能動的に共有しない限り、端末の外には出ません:
- 保存レシピ(ホップ、モルト、水化学、酵母、マッシュ設定)と予測結果
- アプリ設定(言語、デフォルトバッチ量、警告トグル)
- 作成したレシピ履歴、試飲ログ、個人補正
アプリは広告を表示せず、氏名・メールアドレス・位置情報を収集しません。電話番号サインインと不正利用防止のため、Firebase Authentication と reCAPTCHA Enterprise SDK が識別子や診断データを処理します(第3節)。
3. アカウント(ウェブ版とサインイン済みアプリ)
アカウントを作ると、ブラウザで Hoparoma を使い、ウェブとアプリでレシピを共有し、1 つの Pro を両方で使えます。サインインすると、次を取り扱います:
- 電話番号。Google の Firebase Authentication がワンタイムコードを SMS で送り、確認済みの番号を当社に伝えます。当社サーバーは番号の鍵付きハッシュ(HMAC)と無作為のアカウント識別子だけを保存し、番号そのものは保存しません。ハッシュは「1 番号 1 アカウント」と月間枠の適用に使います。番号の処理は Google のプライバシーポリシーに従います。SMS の送信対象は日本・アメリカ・カナダ・イギリス・オーストラリアです。
- サインインのセッション。有効期間最長 90 日のセッショントークンを、ウェブでは Cookie、アプリでは端末のキーチェーンに置きます。トークンはサインアウトするか新しいものに置き換わるまで残ります。アプリでは Firebase のサインイン部品も、サインアウトまで電話番号を含むサインイン状態を端末のキーチェーンに保持します。
- アカウントに保存したレシピと結果(ホップ投入、醸造設定、酵母、香りの見積もり、比較履歴)と、その元になった計算履歴。レシピを削除すると一覧から消えて保存枠が空きますが、データ自体はアカウントを削除したときに消去されます(第 6 条参照)。
- 醸造記録(ウェブ版)。保存したレシピの版を「醸造した」と記録すると、その版と香りの見積もりの写し、醸造日、仕込みのメモを保存します。その醸造記録に付けた試飲については、試飲日、任意の好みの点数(1〜5)、メモ、任意で記録した香りの観察を保存します。これらの記録は、後でレシピを変更・削除しても、記録またはアカウントを削除するまで日誌に残ります。記録は当社サーバーに保存され、アプリの試飲ログとは同期しません。
- 利用回数。当月に使ったレシピ作成・比較・保存・計算の回数。無料枠 / Pro 枠の適用に使います。
- セキュリティ信号。サインインは Google reCAPTCHA で保護され、ブラウザや端末の信号から SMS の自動送信悪用を判定します。reCAPTCHA Enterprise による電話番号サインインに対応する iOS 版では、アプリの機能提供と不正利用防止のため、SDK が端末識別子、クラッシュデータ、パフォーマンスデータ、タップ・クリック・スクロールなどのアプリ操作情報を収集する場合があります。SDK のプライバシーマニフェストでは、これらを利用者に関連付けるデータ、トラッキング目的ではないデータとして申告しています。Firebase Authentication も、障害の診断とサービス改善のために SDK・端末・プラットフォームに関する診断情報を収集します。Google のreCAPTCHA の Apple 向けプライバシー情報とFirebase のデータ開示情報をご覧ください。Google のプライバシーポリシーと利用規約が適用されます。Cloudflare とホスティング事業者は、レート制限と障害対応のために IP アドレスとリクエスト情報を記録します。当社自身のアプリケーションログには応答コード・経路・処理時間・内部識別子を記録し、電話番号やレシピの内容は含めません。
- 不正利用の検知。モデルの自動探索を検知するため、送信されたレシピの傾向(ほぼ同一な変種の連続など)を機械的に分析します。サポートで依頼された場合を除き、人がレシピを閲覧することはありません。
レシピをモデルの学習や広告に使うことはなく、個人情報を販売・共有することもありません。
4. Pro サブスクリプションと決済
- ウェブ(Stripe)。決済画面とカスタマーポータルは Stripe が提供します。Stripe がカード情報・メールアドレス・請求先住所を取り扱い、領収書を送ります。当社は顧客識別子・サブスクリプション識別子・状態・課金期間を受け取ります。カード番号が当社サーバーに届くことはありません。Stripe のプライバシーポリシーをご覧ください。
- アプリ(Apple)。決済は Apple が行います。サブスクリプションをアカウントに反映するため、アプリは Apple の署名付き取引記録(取引識別子、商品、日付、環境)をアカウント識別子とともに当社へ送ります。Apple のプライバシーポリシーをご覧ください。
- 端末上の Pro 状態。オフラインでも使えるよう、アプリはアカウントの Pro 状態を最長 30 日間キャッシュします。
- 金額を含む取引記録は Stripe と Apple が保持します。当社は上記の識別子と状態を、税務・会計・紛争対応の義務が求める期間(日本では最長 7 年)保持します。
5. データの処理場所
サーバーとデータベースは Cloudflare を経由した Fly.io(米国カリフォルニア州サンノゼ)で動いています。Firebase Authentication と reCAPTCHA は Google、決済は Stripe と Apple が運営します。これらの事業者は米国その他の国でデータを処理し、当社の委託先として当社の指示に従います。当社は日本の事業者です。EU/EEA・英国・スイスの利用者については、各事業者の標準契約条項または同等の保護措置により移転します。Fly.io はボリュームの日次スナップショットを 5 世代保持し、当社はデータベースを毎日 Cloudflare R2(保存時に暗号化)へ複製して新しい 30 世代を保持します。
6. 保持期間
- レシピと結果: アカウントが存続する間。削除したレシピは直ちに一覧から消え、データはアカウント削除とともに消去されます。
- 醸造記録(醸造と試飲): 記録またはアカウントを削除するまで。醸造記録を削除するとレシピの写し・メモ・醸造日と配下の全試飲を、試飲だけを削除するとその試飲のメモ・評価・香りの観察・試飲日を直ちに消去します。再送による復元を防ぐため、記録と要求の識別子・該当する版番号・作成日時・元の作成要求のハッシュは、それらの内容を含めずにアカウント削除まで保持します。
- セッション: サインアウトまたは失効(90 日)まで。
- 利用回数と不正検知のフラグ: アカウントが存続する間と、削除後およそ 90 日間。
- アカウント削除: レシピ・計算履歴・醸造記録・セッション・不正検知のデータは直ちに削除します。Stripe のサブスクリプションは先に支払済み期間の末日での終了を予約します(未完了のものは直ちに解約)。番号のハッシュ・利用回数・不正検知のフラグは、削除と再登録による月間枠のリセットを防ぐためおよそ 90 日間保持し、その後削除します(清掃は日次で、厳密な時刻ではありません)。Apple のサブスクリプションは Apple で解約してください。
- 決済の記録: サブスクリプションを契約したことのあるアカウントについては、削除後も Stripe の顧客・サブスクリプション識別子、Apple の取引識別子とその状態を、紐づく番号のハッシュとともに、税務・会計・紛争対応の義務が求める期間(日本では最長 7 年)保持し、その後削除します。
- サーバーのログ: 当社のアプリケーションログはホスティング事業者が短期間(数日)保持します。Cloudflare は自社の方針でリクエストログを保持します。
- バックアップ: 新しい 30 世代の日次コピーと Fly.io のスナップショット 5 世代。削除したデータは世代の入れ替わりとともにバックアップからも消えます。
7. 選択肢と権利
- iOS アプリはアカウントなしで使えます。
- アカウントは、ウェブ版(Account → Delete account)またはアプリ(設定 → アカウント)から自分で削除できます。Hoparoma アカウントの削除は即時で、元に戻せません。Firebase 側のサインイン記録の削除に失敗した場合は、再度サインインして完了するよう案内します。
- 保存レシピはウェブ版とアプリでいつでも閲覧でき、醸造記録はウェブ版で閲覧できます。アプリでは共有シートからレシピをテキストとして書き出せます。それ以外の保有データの写しが必要な場合はメールでご連絡ください。
- お住まいの地域の法令(個人情報保護法、GDPR、UK GDPR など)に基づき、開示・訂正・削除・利用停止・データポータビリティ・異議申立て、および監督機関への申立ての権利があります。support@hoparoma.com までご連絡ください。30 日以内に回答します。
- 個人情報を販売・共有せず、ターゲティング広告にも使いません。
8. 子ども
Hoparoma は醸造計画のツールであり、子ども向けではありません。アカウントの作成は 18 歳以上に限ります。13 歳未満の方の情報を故意に収集することはなく、判明した場合は削除します。
9. 安全管理
通信はすべて TLS で暗号化します。電話番号は鍵付きハッシュのみを保存し、秘密情報はホスティング事業者のシークレットストアで管理し、カード情報は Stripe と Apple のみが扱い、サインインはレート制限と自動化対策で保護しています。あなたのデータに影響する漏えいが起きた場合は、法令に従って本人と当局に通知します。
10. ウェブサイト(hoparoma.com)
このウェブサイトでは Google Analytics 4 を使ってページ閲覧数と、App Store およびウェブ版アプリへのリンクのクリック数(どのリンクが、ページ内のどの位置で押されたか)を計測しています。どの参照ページが役に立っているかを知るためです。Google Analytics はそのために Cookie を設定し、IP アドレスやブラウザ情報を Google のサーバーで処理します。広告機能は有効にしておらず、データを販売・共有することもありません。計測を望まない場合は Google Analytics オプトアウト アドオン を使うか、このサイトの Cookie をブロックしてください。メール登録フォームは Buttondown が提供し、送信したアドレスのみを受け取ります。ウェブ版アプリ(app.hoparoma.com)では Google Analytics を使っていません。
11. 変更
本方針を変更する場合は上部の日付を更新します。アカウントのデータの扱いに重要な変更がある場合は、施行前にウェブ版とアプリで告知します。
12. お問い合わせ
support@hoparoma.com までメールするか、App Store 説明文記載のリポジトリで Issue を立ててください。事業者情報は特定商取引法に基づく表記をご覧ください。