Privacy Policy
Effective Date: April 2026
Override ("we", "us", "the app") is committed to protecting your privacy. This privacy policy explains how we collect, use, and safeguard your information.
Key Principle: Override is designed with a privacy-first architecture. Your sensitive data stays on your device, encrypted and under your control. We do not sell your data. We do not use it for advertising.
1. Information We Collect
1.1 Data Stored Locally on Your Device
The following data is stored only on your device using local encrypted storage. It is never transmitted to our servers:
- Streak and recovery progress data
- Onboarding quiz answers (dependency history, triggers, goals)
- Pledge person name and relationship
- Journal entries
- Notification preferences
- Badge and achievement data
Sensitive data (triggers, pledge person information, dependency history) is encrypted with AES-256 encryption before storage. Encryption keys are stored in the iOS Keychain or Android Keystore, managed by your device's operating system.
1.2 Data Processed by Third Parties
- Subscription status: Managed by RevenueCat. RevenueCat processes your purchase through Apple App Store or Google Play. We receive only your subscription status (active/inactive) and anonymous user ID. See RevenueCat's Privacy Policy.
- Anonymous analytics: In future versions, we may use Firebase Analytics to understand app usage patterns. All analytics data is anonymized and cannot be linked to your identity.
1.3 Data We Do NOT Collect
- Browsing history
- Photos or camera data (camera is used only in real-time for the self-confrontation exercise; no images are saved or transmitted)
- Location data
- Contacts
- Personal identification information (name, email, phone number)
- Content blocker activity logs
2. How We Use Your Information
- To provide recovery tracking features within the app
- To verify your subscription status
- To send local notifications based on your preferences
- To improve the app experience through anonymized analytics (future)
3. Data Sharing
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. Data is shared only with:
- RevenueCat: For subscription management (anonymous transaction data only)
- Apple / Google: For processing in-app purchases through their respective app stores
4. Data Security
- Sensitive data is encrypted with AES-256-CBC before local storage
- Encryption keys are stored in the OS-level secure enclave (iOS Keychain / Android Keystore)
- No sensitive data is transmitted over the network
- The Content Blocker extension runs entirely on-device using Safari's built-in content blocking framework
5. Data Deletion
You can delete all your data at any time from Settings > Delete All Data within the app. This will:
- Erase all local data from your device
- Delete encryption keys from secure storage
- Reset the app to its initial state
To cancel your subscription, use the standard Apple App Store or Google Play subscription management.
6. Children's Privacy
Override is intended for users aged 18 and older. We do not knowingly collect data from users under 18. The app includes an age verification step during onboarding that prevents minors from using the app.
7. GDPR and APPI Compliance
Under the EU General Data Protection Regulation (GDPR) and the Japanese Act on Protection of Personal Information (APPI), you have the right to:
- Access your data (all data is viewable within the app)
- Delete your data (via Settings > Delete All Data)
- Data portability (data is stored locally on your device)
8. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes through an in-app notification. Continued use of the app after changes constitutes acceptance of the updated policy.
9. Contact
If you have questions about this privacy policy, contact us at: dorelist00@gmail.com
プライバシーポリシー
施行日:2026年4月
Override(以下「当アプリ」「私たち」)は、ユーザーのプライバシー保護に取り組んでいます。本プライバシーポリシーでは、情報の収集、利用、保護の方法について説明します。
基本方針: Overrideはプライバシーファーストの設計思想で開発されています。機密データはお使いの端末内に暗号化された状態で保存され、ユーザーご自身の管理下に置かれます。データの販売や広告目的での利用は一切行いません。
1. 収集する情報
1.1 端末にローカル保存されるデータ
以下のデータは、暗号化されたローカルストレージを使用してお使いの端末にのみ保存されます。当社のサーバーに送信されることはありません:
- ストリーク(連続記録)および回復の進捗データ
- オンボーディングの回答内容(依存履歴、トリガー、目標)
- 誓約相手の名前と関係性
- ジャーナル(日記)エントリー
- 通知設定
- バッジおよび実績データ
機密データ(トリガー、誓約相手の情報、依存履歴)は保存前にAES-256暗号化が施されます。暗号化キーはiOS KeychainまたはAndroid Keystoreに保存され、端末のOSによって管理されます。
1.2 第三者が処理するデータ
- サブスクリプション状況: RevenueCatによって管理されます。RevenueCatはApple App StoreまたはGoogle Play経由で購入処理を行います。当社が受け取るのは、サブスクリプションの状態(有効/無効)と匿名ユーザーIDのみです。詳細はRevenueCatのプライバシーポリシーをご覧ください。
- 匿名分析: 将来のバージョンでは、アプリの利用パターンを把握するためにFirebase Analyticsを使用する場合があります。分析データはすべて匿名化され、個人を特定することはできません。
1.3 収集しないデータ
- 閲覧履歴
- 写真またはカメラデータ(カメラは自己直視エクササイズのリアルタイム表示にのみ使用され、画像の保存・送信は行いません)
- 位置情報
- 連絡先
- 個人識別情報(氏名、メールアドレス、電話番号)
- コンテンツブロッカーの活動ログ
2. 情報の利用目的
- アプリ内の回復トラッキング機能の提供
- サブスクリプション状態の確認
- ユーザーの設定に基づいたローカル通知の送信
- 匿名化された分析によるアプリ体験の改善(将来)
3. データの共有
広告やマーケティング目的で第三者にユーザーの個人データを販売、貸与、共有することは一切ありません。データが共有されるのは以下の場合のみです:
- RevenueCat: サブスクリプション管理のため(匿名の取引データのみ)
- Apple / Google: 各アプリストアを通じたアプリ内課金の処理のため
4. データセキュリティ
- 機密データはローカル保存前にAES-256-CBCで暗号化
- 暗号化キーはOSレベルのセキュアエンクレーブ(iOS Keychain / Android Keystore)に保存
- 機密データのネットワーク経由での送信なし
- コンテンツブロッカー拡張機能はSafariの組み込みコンテンツブロッキングフレームワークを使用して完全に端末上で動作
5. データの削除
アプリ内の設定 > すべてのデータを削除から、いつでもすべてのデータを削除できます。削除により:
- 端末上のすべてのローカルデータが消去されます
- セキュアストレージから暗号化キーが削除されます
- アプリが初期状態にリセットされます
サブスクリプションのキャンセルは、Apple App StoreまたはGoogle Playの標準的なサブスクリプション管理をご利用ください。
6. 児童のプライバシー
Overrideは18歳以上のユーザーを対象としています。18歳未満のユーザーからデータを故意に収集することはありません。アプリにはオンボーディング時に年齢確認ステップがあり、未成年者のアプリ利用を防止しています。
7. GDPR および個人情報保護法への準拠
EU一般データ保護規則(GDPR)および日本の個人情報保護法(APPI)に基づき、ユーザーには以下の権利があります:
- データへのアクセス(すべてのデータはアプリ内で閲覧可能)
- データの削除(設定 > すべてのデータを削除から実行)
- データポータビリティ(データは端末にローカル保存)
8. 本ポリシーの変更
本プライバシーポリシーは随時更新される場合があります。重要な変更がある場合は、アプリ内通知でお知らせします。変更後もアプリを継続してご利用いただくことで、更新されたポリシーに同意したものとみなします。
9. お問い合わせ
本プライバシーポリシーに関するご質問は、以下までお問い合わせください:dorelist00@gmail.com