Goshuin Ledger

Privacy Policy (app)

The Japanese version of this page is the authoritative text. What follows is a reference translation. Read the Japanese version

Goshuin Ledger (“the app”) saves your records and photos only on the device you use, and does not send them to any outside server.

Business
友田 陽大
Effective date
Last revised

Basic policy

The app has no server and asks for no account registration. It embeds no usage-analytics SDK, no advertising SDK and no tracking mechanism. Your goshuin records, photos, notes and the names of shrines and temples do not leave the device, whatever the setting below is.

There is one exception. From version 1.3, you can choose in the app’s “Settings → Privacy → Send crash reports” whether a record of where the app stopped (a crash report) is sent to the developer. It starts out as “do not send”, and until you turn it on the mechanism does not even start. What is sent, and to whom, is written in the “Crash reports” section.

What this policy governs is the app itself. The website that introduces the app (goshuinbako.com, including the page you are reading) uses web analytics to improve how it reads. For how the website handles information, see Privacy Policy (website).The app itself carries no mechanism for analysing usage (which screens you looked at and for how long). The only traffic the app sends out is the map display, purchases on the App Store, and the crash report described above once you have turned that setting on.

Information the app collects

The app collects no personal information such as your name, email address, location or device identifiers. The visit dates, shrine and temple names, notes and photos you enter are saved in a database on the device, and no third party — the developer included — can read them. That does not change when “Send crash reports” is on.

Photos

The app only receives the photos you chose in the iOS system picker, and saves a scaled-down copy of them on the device. It does not ask for permission to read your whole photo library. A photo taken with “Take photo” inside the app is likewise saved only as a scaled-down copy on the device, and is not written to your photo library; permission to use the camera is asked for the first time you press that button. A photo sent to “Goshuin Ledger” from the share menu of the Photos app or another app is placed, as a file, in a location on the device that only this app and its share extension can use (an App Group), and the next time you open the app it is imported as a scaled-down copy and the original file is deleted. While you keep this app’s widget on the Home Screen, the name of the shrine or temple and the date of a goshuin you received on this day in an earlier year are written to that same location (when you remove the widget they are deleted the next time you open and close the app), and only when you choose “Show photos in the widget” in Settings is a scaled-down copy of the photo it shows placed there as well (a photo it no longer shows is deleted). Dates written on a photo are read on the device by text recognition (iOS Vision) as candidates for the visit date; the recognised text is not saved and is not sent off the device. The capture date and time contained in a photo is used as the starting value for the visit date. When a photo contains the location where it was taken, that is read on the device as a candidate for placing a pin on the map of the shrine or temple. It is not used on the map until you choose the candidate; only then is a pin placed and the map around it shown (the traffic with Apple that comes with showing a map is as described under “Location”). In a record you are still writing (a draft), the place a photo was taken also stays on the device until you save or discard it. If you choose not to include location information under “Options” in the iOS photo picker, the place a photo was taken is not read at all.

Location

The app does not ask for permission to use your location. A pin on the map is only the point you tapped yourself, the point you chose from a photo’s capture location, or the position of a shrine or temple you chose from the list bundled with the app (data from Wikidata); nothing else is saved on the device, and the app performs no address search and no reverse geocoding.

Maps are shown with Apple’s MapKit, which communicates with Apple’s servers to fetch map tiles. Information that accompanies that traffic, such as the area being shown, is handled under Apple’s privacy policy, and the app does not save it.

Backups

The data on the device is included in the standard iOS backup (iCloud Backup and Quick Start). The ZIP file the app exports is encrypted with the passphrase you set, and the passphrase is neither saved nor sent anywhere. If you forget the passphrase, not even the developer can decrypt the file.

Purchase information

The in-app purchase is processed by Apple’s App Store. The app receives only whether the purchase is active, and does not collect or save payment information such as your name or means of payment.

Crash reports (only when you turn them on in Settings)

When you turn on “Settings → Privacy → Send crash reports” in the app, the following is sent, and only when the app stops. While it is off, and before you turn it on, not a single report is sent.

  • Where it stopped (the position in the program) and the kind and wording of the error
  • The device model and OS version, and the app’s version and build number

Your goshuin records, photos, notes, the names and positions of shrines and temples, the name of your device and your IP address are not included. What may be sent is written in the code as an allow-list, and anything not on it is stripped before sending, whatever kind of value it is. Because there is no account, what is sent is never tied to you as a person. As for launches, moving between screens and the like — usage itself is not sent even when this is on.

The processor is Functional Software, Inc. (“Sentry”, in the United States; the data is stored in the United States as well). For how they handle it, see the Sentry Privacy Policy. When you turn the setting back off, sending stops at that moment and anything not yet sent is discarded on the device.

Provision to third parties

Your records, photos and notes are never provided to a third party. The outside parties the app communicates with are Apple (App Store payments and MapKit maps) and, when you have turned on “Crash reports” above, Sentry. In neither case are your goshuin records, photos or notes sent.

Retention and deletion

Your records (visit dates, shrine and temple names, notes) and the copies of your photos are saved only on the device and stay there until you delete them. The developer has no server and never receives this data, so there is nothing held, and no retention period, on the developer’s side. What is sent when “Crash reports” is on is deleted by Sentry after 30 days.

  • Deleting a goshuin also deletes the copy of its photo from the device. A photo lined up in “Imported photos” is deleted, copy and all, when you remove it from that list (the original in your photo library stays).
  • An exported backup (.goshuin) can be deleted under “Settings → Backup and phone change → Export history”. A CSV or PDF is created in a temporary area on the device each time you export, and handed to whichever destination you choose in the Share sheet.
  • A copy you saved elsewhere through the Share sheet — the Files app, iCloud Drive, email — is under your control. Delete it there when you no longer need it.
  • When you delete the app, iOS deletes the database on the device, the copies of your photos and any export files still inside the app along with it.
  • Data taken into the standard iOS backup is under Apple’s control. If you do not want it, delete the iCloud backup from the iOS Settings.
  • The record of your purchase is held by Apple and remains after you delete the app. After reinstalling, “Settings → Restore purchase” brings the purchase back. All the device holds is a note of whether you have purchased, and that goes when the app is deleted.

Withdrawing consent and requesting deletion

Because the app collects no personal information and neither your records nor your photos leave the device, there is no data in the developer’s hands to delete. If you had turned on “Crash reports”, you can withdraw your consent by turning the setting back off (sending stops at that moment). If you would like what has already been sent to be deleted, please contact us at the address below. To withdraw your consent to the handling described in this policy, delete the data on the device as described above and delete the app. Photos are received only as the ones you point at in the iOS system picker each time, so no continuing permission to your photo library is left behind.

Questions about how to delete, and requests to withdraw consent or delete data, are taken at the contact address below. We answer without delay once you write to us.

How to have the email address you registered on the website’s waiting list (which is now closed) deleted, and how to stop the website’s web analytics, are described in Privacy Policy (website).

Revisions

If this policy is revised, the revision is published on this page and the last-revised date is updated.

Contact

Questions about this policy: tomodahinata@gmail.com