プライバシーポリシー

Octa Share / 第14版 ・ 発効日: 2026年9月5日

日本語 English 利用規約

Octa Share(以下「本アプリ」)は、待ち合わせや迎えのために、期限つきで現在地を共有するためのアプリです。本ポリシーは、本アプリが取得する情報と、その扱いについて説明します。

1. 事業者

本アプリは 合同会社Octa Air(以下「当方」)が提供しています。個人情報保護法上の個人情報取扱事業者は次のとおりです。

名称合同会社Octa Air
住所〒651-0084 兵庫県神戸市中央区磯辺通2丁目10-1006
代表者代表社員 種村 圭依人
お問い合わせ・苦情の申出先support@octa-air.co.jp

名称・住所・代表者の氏名は、保有個人データに関して公表が求められる事項です(個人情報保護法 第32条1項1号)。本ポリシーおよび個人情報の取扱いに関するお問い合わせ、ならびに苦情の申出は、上記の窓口で受け付けます。

2. 取得する情報

2-1. 位置情報

あなたが共有しているとき

他の人の共有を見ているとき

ざっくり共有のとき

共有していない間、かつ受信画面を開いていない間に、本アプリが位置情報を継続的に取得することはありません。共有中は、画面を消したり、ほかのアプリを使っている間も送信を続けます。ただし、iOS でアプリをスワイプ終了した場合、OS が大きな移動を検知して本アプリを再起動するまで更新が遅れることがあります。精密共有の期限後もシステム側の監視登録が次の大きな移動まで残る場合がありますが、そのとき最初に届く位置は監視を解除する判定だけに使い、サーバーへ送信・保存しません。Android の端末設定で本アプリを強制停止した場合は、利用者が再びアプリを開くまで更新できません。共有中であることは、アプリを開いている間は画面全体の枠と上部の表示で常時お知らせします(精密共有はピンク、ざっくり共有は青)。加えて精密共有は Android のフォアグラウンドサービスとして動作し、システムの「実行中のアプリ」に表示されます。通知を許可している場合は通知領域にも「共有中」の継続通知が表示されますが、Android 13 以降で通知を拒否した場合は通知領域には出ず、「実行中のアプリ」から確認できます。ざっくり共有は端末の省電力な位置更新のしくみを使うため、通知領域の常時表示や iOS の画面上部インジケータは出ません。実行中のざっくり共有は、アプリのホーム画面と上記の表示でいつでも確認・停止できます。

ざっくり共有は、終了予定時刻を過ぎたとき、または一定時間(6時間)サーバーに確認していないときに、位置が更新されたタイミングでサーバーに問い合わせ、共有が終了・削除されていれば端末側の監視を停止します。停止の判定は位置の更新に伴って行われるため、実際に止まるまでに多少の間があります。

ざっくり共有の「自動継続」について。有料プランでは、ざっくり共有に「自動継続」を設定できます。この場合もサーバーに記録される終了予定時刻は常に24時間以内で、有料プランが有効である限り、サーバーが24時間ごとにこれを先へ延ばします。つまり共有は「期限のない共有」として保存されるのではなく、24時間ごとに更新され続けている共有です。利用者が停止した場合、有料プランが終了した場合、または当方のサーバー側処理が止まった場合には、いずれも更新が行われなくなり、最後に記録された終了予定時刻(最長24時間後)で共有は終わります。有料プランの終了を検知した時点で1回だけ猶予(24時間)を設け、停止予定時刻をプッシュ通知でお知らせします。

2-2. アカウントとプロフィール

2-3. 通知とその他

3. 利用目的

取得した位置情報を、広告配信やプロファイリングに利用することはありません。また、位置情報を第三者に販売することはありません。

利用者が個別に ON にしたときだけ動く機能。次の機能は既定で OFF であり、利用者が明示的に有効にしたときにのみ、上記の目的の範囲で動作します。いずれもアプリ内の同じスイッチを OFF にすることで、いつでも停止できます。

位置情報・通知・Bluetoothといった端末の権限は、OS の許可ダイアログで与えられるものであり、OS の設定からいつでも取り消せます(§13)。初回公開版は写真へのアクセスを求めません。

4. 共有される範囲

位置情報を閲覧できるのは次のいずれかに限られます。

共有は必ず有効期限を持ち、期限を過ぎると自動的に停止して閲覧できなくなります。また、共有者と閲覧者のどちらかが相手をブロックすると、期限前でも両者間の既存の閲覧権限と関連する位置・近接確認データを削除し、以後のアクセスを拒否します。

5. 保存期間

データ保存期間
共有中の位置情報(正確な位置)共有の有効期限(5〜60分)で閲覧できなくなります。サーバー上の記録は、その24時間後を過ぎたものから順次自動削除します(削除処理は1分ごとに動きますが、障害等で遅れることがあります)。
ざっくり共有の位置情報利用者が指定した期間(1回あたり最長30日)で閲覧できなくなり、以後は上と同じ扱いです。「自動継続」を設定した場合は、サーバーに記録される終了予定時刻は常に24時間以内で、有料プランが有効な間はこれが24時間ごとに更新されます。停止・解約・サーバー側処理の停止のいずれかにより更新が止まれば、最後に記録された終了予定時刻(最長24時間後)で閲覧できなくなり、以後は上と同じ扱いです(§2-1)。
ざっくり共有の「けいろ」(通過した地域名の並び。履歴表示をONにした共有にのみ残ります)共有本体と同じで、共有の削除時に一緒に消えます(上の行を超えて残ることはありません)。加えて、共有中も古いものから順次削除しています —— 現在のビルドでは新しい方から100件を残し、有料プランの提供を開始した後は、無料プランでは直近7日分を残します。有料プランでは共有が続いている間は削除しないため、「自動継続」の共有では、その共有を止めるまで残ります。地域名だけで、座標も日時も記録していません。
ざっくり共有が開かれた回数その共有と同じ(共有の削除時に一緒に消えます)
待ち合わせピンの座標共有本体と同じ(共有の削除時に一緒に消えます)
BLE許可のやり取り共有の削除時、または利用者がデータ削除を行うまで
検査済み表示名、現行版への同意記録、友だちのバックアップ利用者がデータ削除を行うまで
ブロックの記録ブロックした利用者が解除するか、いずれかの利用者がデータ削除を行うまで。解除しても以前の友だち関係や閲覧権限は復元しません
不適切な利用者の報告(匿名ID、選択理由、対象者の検査済み表示名、日時、状態)作成から最長90日。原則24時間以内に一次確認し、期限を過ぎた行は定期処理で削除します。アカウント削除後も、安全対応および削除による調査回避の防止のため、この期間内に限り保持します
友だち解除の合図(解除した側の匿名ID、解除日時、配信期限)対象の友だち端末が受信した時点で直ちに削除。受信されない場合も作成から最長30日
プッシュ通知トークン利用者がデータ削除を行うまで(端末側でトークンが更新された場合は上書き)
回数制限のカウンタ計測期間の開始から24時間を過ぎたものから順次削除
アプリの利用記録(閲覧できるようになった共有の一覧)その共有が終了・削除された時点、または利用者がデータ削除を行うまでの、いずれか早い方
クラッシュ・診断情報各サービスの保持期間(Firebase Crashlytics: 最長90日、Sentry: 最長90日)

友だちリストは原則として端末内にのみ保存されます。Android 版で Google アカウントを連携している場合に限り、機種変更に備えたバックアップがサーバーに保存されます。

6. 第三者サービス

本アプリは以下のサービスを利用しており、その範囲で情報が各社に取り扱われます。いずれも、当方が定めた目的の範囲で個人データの取扱いを委託しているものであり、個人情報保護法 第27条5項1号の「委託」に当たります。当方が個人データを第三者に販売・提供して、その第三者が独自の目的で利用することはありません。委託先に対しては、同法 第25条に基づき必要かつ適切な監督を行います。

サービス提供者用途
Firebase(Authentication / Realtime Database / Cloud Functions / Cloud Messaging / Crashlytics / App Check / Remote Config)Google LLC認証、位置情報の中継、通知配信、不具合検知、端末の正当性確認(App Check)、アップデート告知の配信設定(Remote Config)
SentryFunctional Software, Inc.不具合の検知、性能計測
RevenueCatRevenueCat, Inc.購入状態の管理。購入用の鍵を設定してビルドしたアプリの場合のみ
App Store / Google PlayApple Inc. / Google LLC決済処理、プッシュ通知の配送
OpenFreeMapOpenFreeMap地図スタイル、タイル、画像、スプライトおよびグリフの配信。地図データは © OpenStreetMap contributors
unpkgCloudflare, Inc.ブラウザで共有を閲覧した場合のみ、地図ライブラリの配信

インストール済みアプリの書体は、端末に入っているシステムフォントだけを使います。フォントを表示するために外部のフォント配信サービスへ接続することはありません。

地図の表示にあたっては、表示中の地図タイルを取得するためのリクエストが地図提供者に送信されます。

また、ざっくり共有で「通知先」を設定した場合に限り、現在の地域および地域が変わったことのお知らせが、利用者自身の指定した Slack / Discord / Microsoft Teams の Webhook 宛に送信されます(設定直後に1回、以降は地域が変わるたび)。指定した Webhook の URL は共有データの一部としてサーバーに保存されます。送信先を決めるのは利用者であり、設定しなければ送信は行われません。

7. データの保管場所と、外国にある第三者への提供

位置情報を含むデータベースはシンガポール(asia-southeast1)に、サーバー処理は日本・東京(asia-northeast1)に配置されています。§6 のサービスを利用するため、情報の一部は日本国外で取り扱われます。

具体的には、不具合と性能の診断は米国(Sentry)、認証・データベース・通知配信・クラッシュ検知は Google の設備(米国を含む)、地図タイルは各提供者の設備(欧州を含む)で処理されます。

7-1. 提供先の外国と、講じている措置(個人情報保護法 第28条)

外国にある第三者へ個人データを提供している範囲と、その保護のために講じている措置は次のとおりです。

国該当する提供先取扱い
シンガポールGoogle LLC(Realtime Database。位置情報はここに置かれます)個人情報保護委員会規則で定める基準に適合する体制を整備している者への提供として取り扱っています(同法 第28条1項、規則第16条)。根拠は同社の標準データ処理条項です
米国Google LLC(認証・通知配信・Crashlytics・App Check・Remote Config)、Functional Software, Inc.(Sentry)、RevenueCat, Inc.(購入用の鍵を設定してビルドしたアプリの場合のみ)同上。各社の標準データ処理条項(欧州標準契約条項を含む)により、当方は相当措置の継続的な実施を確保しています
欧州その他OpenFreeMap(地図配信)、Cloudflare, Inc.(ブラウザで閲覧した場合のみ、unpkg の地図ライブラリ配信)送信されるのは、表示中の地図の範囲および接続元の IP アドレスです。OpenStreetMap Foundationは地図データの帰属先であり、本アプリからタイル要求を送る提供先ではありません
利用者が指定した国Slack / Discord / Microsoft Teams(ざっくり共有の Webhook 通知先)送信先を決めるのは利用者自身です。設定しなければ送信は行われません

これらの外国における個人情報の保護に関する制度の概要、および各提供先が講じている措置の内容は、§15 の窓口にご請求いただければご提供します(同法 第28条3項)。

8. 安全管理のために講じている措置

保有個人データの安全管理のために、次の措置を講じています(個人情報保護法 第32条1項4号、同法施行令 第10条1号)。

9. 利用者による削除

アプリの「設定 → データ削除」から、アカウントとサーバー上のデータを削除できます。この操作により、次のものがすべて削除されます。

削除は取り消せません。Android 版では、削除後に同じ Google アカウントでサインインしても以前のデータは復元されません。端末内に保存された友だちリストや設定(iOS の Siri 用に控えている友だち名と共有待ちの情報を含む)も同時に消去されます。端末内の消去に失敗した場合はその旨を画面に表示します。

なお、アプリの「設定 → データ削除」では、アプリ内に作られた地図タイルのキャッシュと、アップデート告知を再表示しないための記録は残ります。アプリ版のキャッシュはアプリを削除すると消えます。ブラウザ版では、受信画面の「このブラウザの受信データを削除」により、Firebase の匿名アカウント、保存済みのPIN・受信設定・端末識別子と同時に、このページが管理する地図タイルと静的アセットのキャッシュも削除します。サーバー上またはブラウザ内の消去を完了したと確認できない場合は、その旨と再試行方法を画面に表示します。ただし、ブラウザ自身が管理する一般のHTTPキャッシュと、すでに別の履歴項目として残ったURLはページから完全には消去できません。削除に成功した現在の履歴項目からは共有リンクとPINを取り除きます。地図タイルの画像とリクエストURLには表示していた地図の範囲を推測できる情報が含まれますが、氏名、匿名ID、共有ID、リンクまたはPINとは結び付けて保存しません。明示的に削除するまで、ブラウザ版は通常500件を目安に古いタイルから削除し、保存から30日を過ぎたタイルは次に表示するときにオンラインであれば再取得します。ただし、同時に多数のタイルを取得したときやブラウザが処理を中断したときは一時的に500件を超えることがあります。また、30日を過ぎてもオフライン等で再取得できなければ古いタイルを表示するため、500件または30日は厳密な保存上限ではありません。

ただし、最小限の記録は次の範囲で残します。アカウントが削除済みであること自体の記録(内部的な識別子と削除日時)と、課金状態の欄に立てる「削除済み」の目印は、定期課金の通知などが後から届いてアカウントが復活してしまうのを防ぐために必要です。将来、有料プランを有効にした版で有効なストア購入があった場合に限り、再インストール後の新しい匿名IDへその購入を移すため、購入が有効であること、有効期限(買い切りの場合は期限なし)および RevenueCat 由来であることだけを同じ削除済み記録に残します。商品ID、購入通知のIDおよび更新時刻は削除し、移行が成功するとこの証明も直ちに消して「移行済み」の目印だけにします。加えて、信頼済みだった友だちの端末からあなたを消すため、あなたの匿名ID、削除日時および配信期限だけを含む解除の合図を、その友だちごとに最長30日残します。合図は相手端末が受信すると直ちに削除されます。あなたが送信した、またはあなたを対象とする安全上の報告は、調査回避を防ぎ、必要な対応を完了するため、§5に記載した作成から最長90日の範囲で残る場合があります。報告には位置情報・共有リンク・PIN・自由記述を含めません。

有料プランを購入されていた場合、決済事業者(RevenueCat、App Store / Google Play)側に残る購入履歴は当方では削除できません。当方が保持していた購入状態の記録は、直前の段落に記載した購入移行のための最小限の証明を除いて削除します。

削除処理は、消し残しが出ないよう完了まで繰り返し確認したうえで終了します。それでも通信障害などで一部が残った場合に備え、サーバー側に記録を残して追跡できるようにしています。

10. 保有個人データの開示・訂正・利用停止等のご請求

利用者ご本人は、当方が保有する自身の個人データについて、利用目的の通知、開示(電磁的記録の提供による方法を含みます)、訂正・追加・削除、利用の停止・消去、第三者への提供の停止を請求できます(個人情報保護法 第32条〜第35条)。

当方は、利用者に法的効果または同等の重大な影響を及ぼす自動化された意思決定・プロファイリングを行っていません。また、要配慮個人情報(同法 第2条3項)は取り扱いません。

本ポリシーおよび保有個人データの取扱いに関する苦情の申出先は §1 の窓口です。当方への申出で解決しない場合は、個人情報保護委員会に申し出ることができます。

11. 配信地域と、日本国外でのご利用について

本アプリは日本国内でのみ配信しています。App Store および Google Play の配信対象地域は日本に限定しており、EU / EEA・英国その他の地域のストアには掲載していません。当方はこれらの地域の利用者に向けてサービスを提供する意図を持たないため、EU 一般データ保護規則(GDPR)第3条2項の適用対象になるとは考えておらず、同規則 第27条の EU 域内代理人および英国代理人はいずれも選任していません。当方の取扱いに適用されるのは、日本の個人情報の保護に関する法律(個人情報保護法)です。

もっとも、日本の利用者が旅行や出張で日本国外に滞在している間も、本アプリはそのまま動作します。滞在先の国がどこであっても、本ポリシーに書かれた取扱い — 取得する情報(§2)、利用目的(§3)、保存期間(§5)、安全管理措置(§8)、削除(§9)、外国にある第三者への提供(§7)— はすべて同じように適用されます。

また、§10 のご請求は、ご請求時にどの国にいらっしゃるかを問わず、同じ窓口・同じ手続・無料で受け付けます。GDPR が定めるアクセス・訂正・消去・処理の制限・異議・データポータビリティに相当する内容についても、日本の個人情報保護法のもとで §10 の手続により対応します。

将来 EEA・英国での配信を開始する場合は、配信を開始する前に本ポリシーを改版し、GDPR 上の法的根拠(第6条)、データ主体の権利、越境移転の根拠(第44条以下)、および第27条に基づく代理人の選任について記載します。あわせて、EU デジタルサービス法 第30条に基づく「トレーダー(事業者)ステータス」の申告も必要になります。

12. お子さまの利用

本アプリは13歳未満の方による利用を想定していません。13歳未満の方の情報を取得していることが判明した場合、速やかに削除します。

13. 権限について

14. 本ポリシーの変更

本ポリシーを変更する場合は、本ページに変更後の内容と版数・発効日を掲示します。重要な変更を行う場合は、アプリ内でお知らせします。

15. お問い合わせ

本ポリシーに関するお問い合わせ、および保有個人データの開示・訂正・利用停止等のご請求は support@octa-air.co.jp までご連絡ください。手続の詳細は §10 のとおりです。

Privacy Policy (English)

Octa Share — version 14, effective 5 September 2026. The Japanese text above is the authoritative version; this translation is provided for convenience.

1. Who we are

Octa Share is provided by Octa Air LLC (合同会社Octa Air), the business operator handling personal information under Japan's Act on the Protection of Personal Information (APPI).

NameOcta Air LLC (合同会社Octa Air)
Registered address2-10-1006 Isobedori, Chuo-ku, Kobe, Hyogo 651-0084, Japan
(〒651-0084 兵庫県神戸市中央区磯辺通2丁目10-1006)
RepresentativeKeito Tanemura (種村 圭依人), Representative Member
Contact and complaintssupport@octa-air.co.jp

APPI Art. 32(1)(i) requires the name, address and representative of the operator to be published for retained personal data, which is why they are here rather than only in a company registry.

2. What we collect

We do not continuously collect location when you are neither sharing nor watching a share. While a share is active, updates continue with the screen off or while you use another app. On iOS, swiping the app away can delay updates until the operating system detects significant movement and relaunches it. For a precise share, system monitoring may also remain registered after expiry until that next significant movement; the first post-expiry location delivered for that retirement check is not sent to our server or stored. On Android, using Force stop in system settings prevents updates until you reopen the app. A precise share runs as a foreground service and appears in Android's Active apps display. If notifications are allowed, an ongoing sharing notification also remains in the notification drawer; on Android 13 or later, denying notification permission hides it from the drawer but not from Active apps. Fuzzy sharing uses the platform's low-power location mechanism and has no persistent notification or iOS status indicator; it remains visible and stoppable in the app. We do not use location for advertising or profiling, and we do not sell it.

3. Who can see your location

Someone holding both your share link and its PIN; anyone holding the link alone if you chose to create the share without a PIN (the link then carries one for them); or a friend you picked from your friend list and notified, since that grants access in advance. Every share carries an expiry; once it passes, sharing stops and the link no longer resolves.

4. How long we keep it

A precise share stops being readable the moment it expires (5–60 minutes). Its records are then deleted once they are more than 24 hours old — a job runs every minute, so in practice shortly after that, though an outage can delay it. Fuzzy shares work the same way over the period you choose, up to 30 days per share; a fuzzy share set to auto-continue on a paid plan is never stored with an expiry more than 24 hours away — the server moves that expiry forward every 24 hours for as long as the plan is active, and the share ends at the last recorded expiry if you stop it, if the plan ends, or if our server-side job stops running. The region trail inside a fuzzy share (region names only — no coordinates and no timestamps, and only if you turned the trail on) never outlives its share, and is trimmed as it goes: today we keep the newest 100 entries; once paid plans start, the free plan keeps the last 7 days and a paid plan keeps the whole trail for as long as that share runs — including an auto-continuing one, until you stop it. The open count for a fuzzy share is deleted with the share. Meetup pins go with the share; BLE handshake records go with the share or with your account deletion. Your moderated display name, current-version acceptance record, friend backup and push token are kept until you delete your data. A block remains until the blocker unblocks or either account is deleted. A safety report is triaged within 24 hours as a rule and retained for no more than 90 days from creation, including after account deletion where needed to complete safety handling and prevent deletion from evading review. A friend-removal signal is deleted as soon as the affected friend's device consumes it, and in every case within 30 days. Rate-limit counters follow the same 24-hour rule. Crash reports follow each provider's retention (up to 90 days). The app usage records are kept until you delete your data, except the list of shares you were granted access to, which goes when that share ends or is deleted, whichever comes first.

5. Third parties

Firebase (Google LLC) for authentication, data relay, notifications, crash reporting, device attestation and update configuration; Sentry (Functional Software, Inc.) for error and performance monitoring; RevenueCat, Inc. for purchase state (only in a build compiled with the purchase key); Apple and Google for payments and push delivery; and OpenFreeMap for map styles, tiles, images, sprites and glyphs. The map data is credited to © OpenStreetMap contributors, but the shipping app does not request tiles from the OpenStreetMap Foundation endpoint. Viewing a share in a browser also loads the map library from unpkg. Both the browser receiver and the installed app use fonts already available on the device and do not contact a font CDN. The initial public build does not send meetup search terms to an external geocoder.

If — and only if — you configure a notification endpoint for a fuzzy share, region-change notices are posted to the Slack, Discord or Microsoft Teams webhook you chose.

All of these providers process the data on our instructions and for our purposes — entrustment under APPI Art. 27(5)(i), not provision to a third party who then uses it for their own ends — and we supervise them as Art. 25 requires. We do not sell personal data.

6. Where data is stored, and transfers outside Japan

The database holding location data is hosted in Singapore (asia-southeast1); server-side processing runs in Tokyo, Japan (asia-northeast1). Because we use the services in section 5, some data is handled outside Japan: error and performance diagnostics in the United States (Sentry); authentication, database, push delivery, crash reporting and attestation on Google's infrastructure (including the United States); and map tiles on each provider's own infrastructure (including Europe). If you configure a Slack, Discord or Microsoft Teams webhook for a fuzzy share, the destination country follows from your own choice of endpoint.

APPI Art. 28 governs providing personal data to a third party located in a foreign country. We rely on the route for recipients maintaining a system that conforms to the standards set by the Personal Information Protection Commission (Art. 28(1); Rules Art. 16): each provider's standard data processing terms — which include the EU Standard Contractual Clauses — bind them to equivalent protection, and we take the measures needed to ensure that protection keeps being applied. On request, at the address in section 13, we will supply information on the data protection regime of each of those countries and on the measures each recipient takes (Art. 28(3)).

7. How we protect it

Measures taken to safeguard retained personal data (APPI Art. 32(1)(iv)): per-share access rules, so that nobody outside the conditions in section 3 can read a share, and the list of shares you were granted access to sits where no app — including your own — can read it; either person's block immediately denying both directions and removing pair-specific grants, viewer rows and proximity material; server-side moderation and explicit current-version acceptance before user-created content crosses accounts; a private report queue and block store that clients cannot read or write directly; a mandatory expiry on every share, backed by the automatic deletion windows in section 4; encryption in transit for everything the app and the browser receiver send; Firebase App Check tokens sent by both the app and browser receiver, whose verification results we monitor; and data minimisation — nothing is collected while you are neither sharing nor watching, fuzzy shares send only coordinates already rounded on your device, and the initial release does not collect profile photos. At the initial launch App Check is in monitoring mode, so an unverified request is not rejected solely because of App Check. We will switch to enforcement, which rejects unverified requests, only after the shipping clients have maintained more than 99% verified legitimate traffic for at least 48 hours. The foreign countries where data is handled are the ones listed in section 6.

8. Deleting your data

Settings → Delete data removes your shares and their related records, your moderated display name and current-version acceptance record, your outgoing blocks and the reverse block entries about you, your friend backup, your push token, purchase records (except the minimal transfer evidence described below), rate-limit counters and the app usage records described above (the list of shares you were granted access to), the entries about you left in other people's friend lists, and your authentication account itself. On Android, this also unlinks Google sign-in. This cannot be undone; signing back in with the same Google account on Android will not restore anything.

Local app data — friends, settings, and on iOS the copies kept for Siri — is erased at the same time, and you are told if that part fails. The app's cached map tiles and a flag remembering that you dismissed an update notice remain; uninstalling the app clears its app-side cache. In the browser receiver, “Delete this browser's receiver data” deletes the Firebase anonymous account, saved PINs, receiver settings and device identifier together with the map-tile and static-asset caches managed by this page. If either the server-side or browser-side erasure cannot be confirmed, the page says that deletion did not fully complete and explains how to retry. The page cannot completely erase the browser's ordinary HTTP cache or a capability URL already stored as a separate history entry. On success it does remove the share link and PIN from the current history entry. Tile images and request URLs can reveal the area of the map that was displayed, but we do not store them linked to a name, anonymous ID, share ID, link or PIN. Until explicitly deleted, the browser receiver normally targets 500 tiles and evicts the oldest first. Once a tile has been cached for 30 days, the receiver tries to fetch it again the next time it is displayed while online. Concurrent requests or an interrupted browser task can temporarily leave more than 500 tiles, and when a refresh fails offline the receiver may retain and display an older tile. Neither 500 tiles nor 30 days is therefore a strict storage limit.

A few minimal records are deliberately kept. A record that the account was deleted (an internal identifier and a timestamp), plus a "deleted" marker where its purchase state used to be, stop a late subscription webhook from bringing the account back. If a future paid-plan build had a currently valid store purchase, we also keep only the fact that it is active, its expiry (or lifetime status), and that RevenueCat supplied it, so the store purchase can transfer to the new anonymous ID after reinstall. Product ids, purchase-event ids and update times are erased; once the transfer succeeds, that evidence is erased too and only a "transferred" marker remains. In addition, each formerly trusted friend's device receives a removal signal containing only your anonymous ID, the deletion time and its delivery expiry; it is deleted as soon as that device consumes it and otherwise within 30 days. A safety report you submitted or that concerns you may remain within its 90-day-from-creation limit so review cannot be evaded by deleting an account; reports contain no location, share link, PIN or free text. Purchase history held by RevenueCat and the app stores is outside our control. The deletion runs until repeated checks come back empty; if a network failure still leaves something behind, we record that so it can be chased.

9. Requesting disclosure, correction or suspension of use

You may ask us to notify you of the purpose of use, to disclose the personal data we hold about you (including by electronic record), to correct, add to or delete it, and to suspend its use, erase it, or stop providing it to third parties (APPI Arts. 32–35).

Erasure you can perform yourself, at any time, from Settings → Delete data (section 8 lists what goes); you can correct your display name in the same screen. For anything else, write to support@octa-air.co.jp, in any form. There is no charge (APPI Art. 38). We answer within one month as a rule, and tell you why if a complex request needs longer.

Identifying you. Accounts here are anonymous by default: we hold no name, address or phone number. To find the data a request concerns, we need either the identifier shown in the app's settings screen or a message from the Google address you linked. If we still cannot identify you and the data, we may be unable to act on the request.

We carry out no automated decision-making or profiling producing legal or similarly significant effects, and we handle no special care-required personal information (APPI Art. 2(3)). Complaints go to the contact in section 1; if we cannot resolve one, you may take it to Japan's Personal Information Protection Commission.

10. Where the app is distributed, and using it abroad

Octa Share is distributed in Japan only. Availability on the App Store and Google Play is limited to Japan, and the app is not listed in the EU/EEA, the UK or elsewhere. We therefore do not intend to offer the service to users in those regions, and do not consider ourselves to fall within Art. 3(2) of the EU General Data Protection Regulation; we have designated no EU or UK representative under Art. 27. The law that applies to our handling of personal data is Japan's Act on the Protection of Personal Information (APPI).

The app does keep working when a user based in Japan travels abroad. Wherever you are, everything in this policy applies unchanged — what is collected (section 2), how long it is kept (section 4), how it is protected (section 7), how it is deleted (section 8), and which foreign countries it reaches (section 6).

Requests under section 9 are accepted whatever country you are in when you make them, through the same contact, by the same procedure, free of charge. What the GDPR calls access, rectification, erasure, restriction, objection and portability, we handle under the APPI procedure in section 9.

If we ever open distribution in the EEA or the UK, we will revise this policy before doing so — to state the GDPR lawful bases (Art. 6), the data subject rights, the basis for international transfers (Art. 44 et seq.) and the representative designated under Art. 27 — and we would additionally have to file trader status under Art. 30 of the EU Digital Services Act.

11. Children

Octa Share is not intended for children under 13. If we learn we hold such information, we will delete it promptly.

12. Changes

Any change to this policy will be posted on this page with a new version number and effective date, and significant changes will be announced in the app.

13. Contact

support@octa-air.co.jp — including for the requests described in section 9.