App Foret ("we", "us" or "the Operator") sets out below how we handle personal information in the mobile application "Nadge" (the "App") and its related website (together, the "Service"). Please read this policy before using the Service.
- 1. Definition of personal information
- 2. Information we collect
- 3. Information we do not collect / keep only on your device
- 4. Where information is stored
- 5. Purposes of use
- 6. Disclosure to third parties
- 7. Service providers and external services
- 8. International transfers
- 9. Cookies and similar technologies
- 10. Retention and deletion
- 11. Your rights
- 12. Contact
- 13. Users under 13
- 14. Security measures
- 15. Changes to this policy
1. Definition of personal information
"Personal information" in this policy means personal information as defined in the Act on the Protection of Personal Information of Japan: information about a living individual that can identify that individual by name, date of birth or other descriptions, or that contains an individual identification code. Other terms used here have the meanings given in that Act.
2. Information we collect
We may collect the following information in providing the Service.
- Authentication: a user identifier (uid) issued through Firebase Authentication. The App signs in anonymously on first launch, so you do not need to register a name, email address or password for normal use
- Profile: the display name you optionally register to use the Friends feature, the avatar you choose, the epithet you compose from titles, and the name and note you give your crystal (island)
- Usage: mission completion, points, level, the state of your crystal and island (buildings), titles earned, collection progress, missions marked as habits, and login days
- Friends: if you use the Friends feature, your friend code, friend requests and approvals, friendships, timeline posts (titles earned, level-ups), Likes, and friend points
- Transfer: the transfer code used to move to a new device (stored hashed) and records of its issuance and use
- Notifications: your device push-notification token, if you turn on notifications for friend activity
- Purchases: receipts, purchase history and the state of purchased features issued by the App Store / Google Play if you make an in-app purchase. Payment details such as card numbers are processed by the store and never reach us
- Device and connection: OS type and version, device model, app version, language setting, IP address, timestamps, crash reports and usage statistics
- Inquiries: the email address and message you send when you contact us
3. Information we do not collect / keep only on your device
The Service is designed to collect no more than it needs. The following is never sent to our servers or shared with third parties.
- Exclusion settings: the conditions you set as "things I can't do" (for example, "strenuous exercise is difficult", "long reading sessions are difficult") and individual missions you have set aside may relate to your health or circumstances. They are stored only on your device and are never sent to our servers or shown in the profile visible to friends
- Advertising identifiers: the App shows no ads and does not collect the IDFA (iOS) or GAID (Android). It never asks for App Tracking Transparency permission
- Location, contacts, photos: the App does not access your location, contacts or photo library. Mission completion is self-reported; we never ask for proof
4. Where information is stored
- Our servers (Cloud Firestore): authentication, profile, usage, friends, transfer, notification, purchase and inquiry information listed in section 2. Data is processed in Google's Tokyo region (asia-northeast1)
- Your device only: exclusion settings, mission difficulty setting, display language, tutorial progress, the display state of the achievements screen, a cache of purchased features, and caches of the mission and title master data
5. Purposes of use
- To provide, operate, maintain and improve the Service
- To present missions and manage completion, points, level, the growth of your crystal and island, titles and the collection
- To provide the Friends feature (preventing duplicate names and codes, requests and approvals, timeline and Likes, optional notifications)
- To transfer your data when you change devices
- To process in-app purchases, verify receipts and restore purchased features
- To send important notices about the Service, such as maintenance and changes to these terms
- To investigate and respond to misuse or violations of the Terms, and to resolve disputes
- To measure quality, analyze usage statistics and consider improvements
- To respond to your inquiries
- To comply with the law
6. Disclosure to third parties
We do not disclose personal information to third parties without your prior consent, except:
- where required by law;
- where necessary to protect a person's life, body or property and it is difficult to obtain your consent;
- where especially necessary for public health or the sound upbringing of children and it is difficult to obtain your consent;
- where necessary to cooperate with a national or local government body, or a party entrusted by one, in carrying out duties prescribed by law.
We may entrust the handling of personal information to the service providers listed in section 7 to the extent necessary to provide the Service. Information shown to other users through the Friends feature (see the note in section 3) is shared as a result of your own actions: registering a name, approving a request, or setting your timeline to public.
7. Service providers and external services
We use the following external services to operate the Service. Each is limited to what the Service requires and is governed by that company's privacy policy.
- Google LLC (Firebase): Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging (push notifications), Crashlytics, Analytics, App Check, Cloud Storage (image delivery)
- Apple Inc. (App Store) / Google LLC (Google Play): app distribution, in-app purchase payment processing and receipt issuance
The Service uses no advertising networks and never sends your input to generative AI services.
8. International transfers
Firebase (Google LLC) data is processed in Japan (asia-northeast1, Tokyo) as a rule, but some features (Analytics, Crashlytics, Cloud Messaging and others) may route through other Google regions. We use these services after confirming the personal-data protection regime of the destination and the safeguards the company applies.
9. Cookies and similar technologies
The App does not use browser cookies, but may use device-specific identifiers to provide features and collect usage statistics. If we introduce analytics on this website (nadge.appforet.com), we will add the information collected and how to opt out to this section before doing so.
10. Retention and deletion
We keep personal information only as long as needed for the purposes above. If you ask us to delete your data, we will delete it within a reasonable period, except for records we are legally required to keep (for example, accounting records). See "Data Deletion" for the procedure and scope, and contact us as described in section 12.
After deletion, data may remain in automatic disaster-recovery backups for up to 14 days. We never restore or reuse backup data during that period, and it is erased automatically afterwards.
11. Your rights
You have the following rights regarding the personal information we hold about you. Contact us as described in section 12 to exercise them.
- To request disclosure
- To request correction, addition or deletion where the information is inaccurate
- To request suspension of use or erasure
- To request that disclosure to third parties be stopped
12. Contact
For questions about this policy, or to request disclosure, correction or deletion of your personal information:
| Operator | App Foret |
|---|---|
| Personal information manager | The person responsible for operating the Service |
| Contact | nadge@appforet.com |
13. Users under 13
To protect children's privacy, the Service is intended for users aged 13 and over, and we do not handle personal information of anyone under 13. If we learn that someone under 13 has provided personal information, we will delete it promptly. Users aged 13 to 17 should use the Service with a parent's or guardian's consent.
14. Security measures
We take organizational, personnel, physical and technical measures to prevent leakage, loss or damage of personal information. Main technical measures include TLS encryption in transit, Firebase App Check against unauthorized access, Cloud Firestore security rules for access control, and server-side verification of in-app purchase receipts.
15. Changes to this policy
We may change this policy in response to changes in the law or the Service. The revised policy takes effect when posted in the Service or on this website. We will notify you of important changes in the App or by email.
Revision history
- September 4, 2026: sections 2, 4, 5, 7 and 10 revised for the Friends, transfer, notification and in-app purchase features
- August 3, 2026: established
End