Privacy Policy
This policy describes how personal information is handled in miggy (the "Service").
1. Information We Collect
| Category | Examples | How collected |
|---|---|---|
| Profile information | Display name, handle (optional), selected avatar number | Entered by the user |
| Device identifiers | Public key generated by the device (identifier for authentication), device ID for sync | Generated automatically |
| Notification token | Device token for push notifications | Obtained from the device |
| Messages (DMs) | End-to-end encrypted ciphertext (the server cannot decrypt the contents) | Upon sending/receiving |
| Shared content | Photos/videos shared in shared albums and rooms, and associated information | User actions |
| Friends and inbox | Friend relationships; friend requests, approvals, room invitations | User actions |
| Network/device information | IP address at communication time, device/OS information, access timestamps | Automatic |
| Advertising-related information | Information collected by advertising providers for ad delivery (see Section 5 and the annex) | Ad SDK |
The Service does not collect your name, address, phone number, date of birth, gender, or location.
2. Purposes of Use
- Identity verification/authentication and prevention of impersonation (device public key)
- Providing features such as friends, messages (DMs), voice calls, and shared albums
- Delivering push notifications
- Preventing abuse and nuisance behavior, handling reports and blocks, ensuring safety
- Troubleshooting and responding to inquiries
- Displaying advertisements (Section 5)
3. Retention Periods
- DM ciphertext: deleted upon successful delivery; automatically deleted after 14 days if undelivered.
- Decrypted message history: stored only on the user's device (not retained on the server).
- Profile, friends, shared albums, etc.: until deleted by the user or until the Service ends.
- Communication logs: within the scope and period necessary for operations and abuse prevention.
4. Third-Party Provision, Outsourcing, and Transfers to Foreign Third Parties
The Service uses services of the following external providers (all foreign (U.S.) corporations). These constitute "provision to third parties in foreign countries" or "outsourcing" under the Act on the Protection of Personal Information of Japan.
| Provider (country) | Role | Main information handled | Storage location |
|---|---|---|---|
| Backend infrastructure contractor (U.S. corporation) | Contractor for servers, storage, and communication relay | Profile, identifiers, notification tokens, DM ciphertext, shared media, network information | The company's global edge network; may span multiple countries including Japan, and the storage country may not be identifiable |
| Push notification infrastructure provider (U.S. corporation) | Delivery of push notifications | Notification tokens, delivery information | The company's global infrastructure |
| Advertising provider (U.S. corporation) | Ad delivery | See the annex "Disclosure on External Transmission" | The company's global infrastructure |
- About storage locations: because the backend is an edge computing platform, data may be processed and stored around the world. While the contractor is incorporated in the U.S., the actual storage locations may span multiple countries including Japan and may not be identifiable.
- The names of external providers to which information is transmitted from the user's device are listed in the annex "Disclosure on External Transmission".
- For information about data protection systems in these countries, refer to materials published by the Personal Information Protection Commission of Japan.
- Except as required by law, we do not provide personal information to third parties without prior consent.
5. Advertising (External Transmission)
The Service uses third-party advertising services. Information is transmitted from the user's device to the advertising provider for this purpose. Details are in the annex "Disclosure on External Transmission".
6. Security Measures
- DMs are end-to-end encrypted; only ciphertext is stored on the server (the contents cannot be decrypted).
- Voice calls are encrypted with DTLS-SRTP.
- Communication with the server is encrypted with TLS (HTTPS/WSS).
- Device private keys and authentication tokens are stored in the iOS Keychain.
- We monitor the environment of contractors (including those abroad) and supervise them as necessary.
7. Requests Regarding Retained Personal Data
Users may request notification of purposes of use, disclosure, correction, addition, deletion, suspension of use, or suspension of third-party provision of their personal data. Please contact the office below; we respond in accordance with the law after verifying identity.
8. Use by Minors
Persons under 13 may not use the Service. Minors should use the Service with the consent of a parent or guardian.
9. Contact for Inquiries and Complaints
Operator: {{事業者名}} / Contact: {{連絡先メール}}
10. Revisions
This policy may be revised in response to changes in laws or the Service. Important changes will be announced in the app or by other means.