ニャ識 Privacy Policy
Last updated: August 31, 2026
This translation is provided for convenience. If it differs from the Japanese version, the Japanese version prevails: https://nyashiki.erzhiqian.cc/legal/privacy-policy-ja/
This Privacy Policy describes how ニャ識 (Nyashiki, the "App") handles user information and personal information. Users should review and understand this Policy before using the App.
1. Basic Policy
The App is designed to run entirely on the device (Local-First). The operator does not run a server for the App and does not receive the receipt images, household records, learning data, or any other information the user enters into the App.
The App has no account registration and no sign-in. The operator does not issue an identifier for the user and does not track how the App is used.
The operator complies with the Act on the Protection of Personal Information of Japan and other applicable laws, regulations, rules, and guidelines.
2. Information Stored on the Device
The App creates or stores the following information in an on-device database and in storage reserved for the App. This information stays on the user's device.
- Receipt information: receipt images, store name, purchase date and time, item names, quantities, amounts, tax amounts, payment method, processing state, review state, notes
- Household and budget information: expenses, categories, monthly budgets, balances, currency, totals, display settings
- Learning information: words, readings, meanings, parts of speech, examples, source of registration, review history, learning progress, mastery state, answer results, favorites
- Image information: images taken from the photo library or camera, text and word candidates extracted from them, and word images the App generates
- Settings: display language, learning settings, audio settings, screen state
- AI settings: the AI provider API key and connection settings the user registers (the API key is stored in the device Keychain)
- Diagnostic information: records kept for troubleshooting. They stay on the device and are not sent to the operator automatically
The operator does not collect the information listed above.
3. Information the Operator Receives
The only information the operator receives is what a user sends to the support contact themselves: the message body, the reply address, and anything the user attaches.
The operator uses it solely to answer the inquiry, investigate defects, and improve the App.
4. Device Permissions
The App uses the following device permissions in response to user actions.
| Permission | Purpose |
|---|---|
| Camera | To photograph receipts or printed text the user wants to study |
| Photo library (read) | To read receipt images or photos the user selects |
| Photo library (add) | To save word images to the photo library, only when the user chooses to |
The App does not use the microphone, location, contacts, calendar, notifications, or health data. The read-aloud feature plays device speech synthesis and does not record audio.
Users can change permissions in the OS settings. Some features may be unavailable when a permission is disabled.
5. AI Features and External Transmission
The App's core features work without AI. Receipts are read with on-device text recognition and parsing, and word meanings are shown from a dictionary bundled with the App.
AI features work only when the user registers their own AI provider API key in the settings screen. The App does not include an API key belonging to the operator.
- The providers a user can select are OpenAI, Google (Gemini), and, on supported devices, Apple's on-device model.
- When Apple's on-device model is selected, processing completes on the device and nothing is transmitted externally.
- When OpenAI or Google (Gemini) is selected, the receipt image, extracted text, item names, words, and other data required by the feature the user invoked are sent from the user's device directly to that provider. The transmission does not pass through any server of the operator, and the operator does not receive its contents.
- The handling of transmitted data is governed by the agreement and privacy policy between the user and that provider. Users should confirm each provider's terms themselves, including whether data may be used for training.
- The API key is stored in the device Keychain and is not transmitted anywhere other than the endpoint of the provider the user selected.
The App does not embed advertising SDKs, behavioral analytics SDKs, or crash reporting SDKs. Apart from the AI features described above, the App has no mechanism that sends information from the user's device to an external server.
6. Disclosure to Third Parties
The operator does not hold users' personal information and therefore does not disclose it to third parties.
Inquiry content is not disclosed to third parties except in the following cases.
- With the user's consent
- Where required by law
- Where necessary to protect a person's life, body, or property and obtaining consent is difficult
7. Cross-Border Transfer
The operator does not transfer users' personal data outside Japan.
When a user uses the AI features described in Article 5, data may be sent from the user's device directly to a provider located outside Japan, based on the user's own settings. That transmission occurs in the relationship between the user and that provider.
8. Backup and Export
The App can write the data on the device out as a backup file. Backups are encrypted with a key derived from a passphrase the user sets.
Users are responsible for where the exported file is stored, with whom it is shared, and how it is managed. If the passphrase is lost, no one, including the operator, can decrypt the backup.
9. Security Measures
App data is stored in storage reserved for the App and in the Keychain, managed under the protections provided by iOS.
Users should manage the device itself, including setting a passcode, keeping the OS updated, and responding if the device is lost. The operator cannot access the data on a user's device.
10. Retention and Deletion
Information on the device is retained until the user deletes it. Users can delete receipts, household data, learning data, images, and AI settings individually through the deletion features in the App.
Deleting the App from the device removes the information stored in the App's reserved storage. Images saved to the photo library and backup files the user exported are not removed by deleting the App.
Inquiry content is deleted after the response is complete and the necessary retention period has passed.
11. Requests for Disclosure, Correction, and Suspension of Use
The operator does not retain users' retained personal data. For information on the device, users can review, correct, delete, and export it themselves within the App.
Requests for disclosure, correction, or deletion regarding inquiry content should be sent to the contact in Article 14. The operator may request information necessary to verify identity.
12. Response to Data Breaches
If a leak, loss, or damage of information held by the operator occurs or is suspected, the operator will investigate the facts, prevent the damage from spreading, prevent recurrence, notify the parties concerned, report to the Personal Information Protection Commission, notify the individuals concerned, and take any other action required by law.
13. Use by Minors
Minors should use the App with the consent of a parent or other legal representative. When using the AI features described in Article 5, the provider's terms and costs should also be reviewed by the legal representative.
14. Business Operator and Contact
- Personal information handling business operator: disclosed without delay upon request
- Address: disclosed without delay upon request
- Representative: disclosed without delay upon request
- Personal information protection manager: disclosed without delay upon request
- Contact: [email protected]
Pursuant to Article 32, Paragraph 1 of the Act on the Protection of Personal Information, the operator's name, address, representative, and personal information protection manager will be provided without delay upon request to the contact above.
Inquiries about this Policy and about the handling of personal information should also be sent to the contact above. Replies are normally sent within three business days.
Please do not send passwords, authentication codes, credit card numbers, AI provider API keys, or other confidential information in an inquiry.
15. Changes to This Policy
The operator may revise this Policy in response to changes in the service, laws, guidelines, or operating structure.
For significant changes, the operator will publish the content of the change and its effective date through in-app notices, the official website, or another appropriate method.