PRIVACY
Privacy Policy
Effective and last updated: August 9, 2026
This Privacy Policy explains how Lockeigo handles information. It is intended to satisfy applicable requirements of Japan’s Act on the Protection of Personal Information (“APPI”) and to provide a clear account of the app’s current data flows.
1. Controller and contact
The person responsible for Lockeigo and for personal data under this Policy is Yohei Ueda, Japan. Privacy questions, complaints, and rights requests are accepted at englishhub0001@gmail.com. A mailing address will be provided without undue delay after a verified request where required under the APPI. Seller address and telephone requests are handled separately under Seller Information.
2. Information stored only on your device
- English cards, meanings, optional examples, decks, and folder names
- Bookmarks, “Again” and “Got it” review history, spaced-repetition state, daily plans, and on-device insights
- Theme, custom color, font, text size, Widget, notification, audio, and presentation settings
This information is stored in the app’s Apple App Group container so that the app and its Widgets can share it. There is no Lockeigo account or cloud synchronization. Deleting the app or using the in-app deletion command may permanently remove local data. Apple may include app data in device backups according to your Apple settings.
3. Optional automatic Live Activity display
Only after you explicitly start Lock Screen display, Lockeigo sends the minimum information needed to start, replace, update, and end Live Activities: a pseudonymous installation hash; ActivityKit push-to-start and activity update tokens; an activity ID, consent ID, generation and delivery state; iOS major version and time zone; selected card text, meaning and optional example; and presentation settings including theme, custom color, text color, font, size, and layout.
This data is processed in Microsoft Azure Japan East using Azure Container Apps, Cosmos DB, Key Vault, Container Registry, Application Insights, and Log Analytics. The delivery service attempts a safe replacement approximately every 7 hours and sends Live Activity notifications directly to Apple Push Notification service (“APNs”). Signed device contact and a strictly matching replacement confirmation may renew the enabled delivery registration, selected content, and ActivityKit tokens for up to 30 days. App Attest evidence and a pseudonymous deletion tombstone may be retained for up to 90 days to reject replay and delayed requests. In-app stop or disabling Live Activities immediately removes delivery payloads, tokens, Activities, and pending intents; the deletion tombstone remains for that bounded safety period. APNs and iOS remain best effort, so exact timing and continuous display are not guaranteed. The service does not associate this data with your name, email address, Apple Account, RevenueCat customer identifier, or advertising identifier.
Apple App Attest verifies that registration requests come from a genuine app installation. The service processes the App Attest public key, attestation receipt and evidence, assertion counter, validation category, and app build number. The private App Attest key remains protected by Apple on your device and is not uploaded.
Use the in-app stop button to withdraw consent and request deletion of the Azure delivery registration. Disabling Live Activities for Lockeigo in iOS Settings also stops automatic delivery. A Lock Screen-only dismissal can be indistinguishable from a system or replacement ending and may be recovered automatically; use the in-app stop button when you intend to stop.
4. Analytics
Lockeigo uses Firebase Analytics for product improvement. Events are limited to outcomes such as onboarding completion, card creation count, review completion count, theme application, and Live Activity start or stop. Firebase may process a pseudonymous app-instance identifier, app and OS version, device characteristics, and a general region derived from a masked IP address.
Card text, meanings, examples, folder names, card IDs, purchase identifiers, names, and email addresses are not included in analytics events. Analytics advertising personalization, Google Signals, User-ID, user-provided data collection, Analytics IDFA collection, and Analytics IDFV collection are disabled. You can stop future Analytics collection with the “Share Anonymous Usage Data” setting.
5. Advertising
The Free plan may request and display Google Mobile Ads in a dedicated footer area of the four main app tabs and may show an interstitial after eligible review sessions. Google and its advertising partners may process IP address, device and app information, advertising identifiers where lawfully available, consent choices, ad interactions, and fraud-prevention signals under their policies and applicable consent rules.
Lockeigo Plus does not request or display ads. No ad request or ad UI is used on the iPhone Lock Screen, in Live Activities, Dynamic Island, Widgets, notifications, review cards themselves, or the Plus purchase and subscription-management screen. Where required, Google’s consent form is shown and ad privacy choices can be reopened from app Settings.
6. Purchases
Apple processes payment and Apple Account purchase history. RevenueCat is used to display offerings, verify entitlements, restore purchases, and prevent purchase abuse. RevenueCat processes a pseudonymous app user identifier, product and offering information, subscription status, transaction information received from Apple, app version, and related technical data. Lockeigo does not send learning content to RevenueCat.
7. Optional update checks
Lockeigo may contact Apple’s public App Store Lookup service no more than once every 24 hours to check whether a newer public version is available. The request contains the public App Store app identifier and storefront country code. Lockeigo does not include card content, learning history, an account identifier, an advertising identifier, or an installation identifier in this request. Apple may process ordinary network request information, such as an IP address, under Apple’s policies.
If a newer version is available, the app shows an optional notice. You may open the App Store or choose “Later” and continue using the installed version. Choosing “Later” stores the postponed version and date on the device and suppresses the same notice for seven days. This is not a forced-update mechanism.
8. Support form and email
The support form is hosted by Google Forms. If you submit it, Google and the operator process the category and text you enter for support and product improvement. The form does not request your Google Account email address. If you email the operator, your email address, message, and attachments are used to answer the request, establish necessary records, prevent abuse, and comply with law.
9. Website hosting
This static website is hosted on Cloudflare Pages. Cloudflare may process IP address, request headers, user agent, timestamps, and security or performance logs as a website infrastructure provider. Cloudflare is not used for Live Activity registration, notification scheduling, APNs delivery, or storage of ActivityKit tokens or learning content. The former Cloudflare Live Activity Worker, APNs secret, and D1 database were deleted on August 2, 2026.
10. Purposes of use
- Provide local learning, Widgets, Live Activities, reminders, speech, and Plus functionality
- Authenticate app installations, schedule best-effort Live Activity delivery, prevent replay and abuse, and troubleshoot fixed error categories
- Check for and optionally present newer App Store versions
- Process purchases and restore entitlements
- Provide advertising to eligible Free users in accordance with consent choices
- Measure limited product outcomes and improve reliability
- Respond to support, privacy, legal, and seller-information requests
- Protect users, the service, and legal rights; comply with lawful requests and applicable law
11. Service providers and international processing
Depending on the feature you use, information is entrusted to Microsoft, Apple, Google, RevenueCat, and Cloudflare for the purposes described above. Azure Live Activity state is configured in Japan East. Other providers may process data in Japan, the United States, or other locations under their contractual safeguards and privacy policies. The operator reviews provider roles and applies data minimization, access controls, and contractual or equivalent safeguards appropriate to the data and service.
12. Retention and deletion
- Azure display payload and enabled delivery registration: retained for up to 30 days after signed device contact or a strictly matching replacement confirmation; explicit stop requests immediate deletion from active state.
- Activity tokens: expire after their useful Activity lifetime, normally no more than 8 hours from registration.
- App Attest evidence: retained for up to 90 days for authentication and abuse prevention.
- Azure operational logs: retained for 30 days. Application logs are designed not to contain card text, tokens, assertions, or installation hashes.
- Azure Cosmos DB backups: encrypted periodic backups may retain a previous state for up to 8 hours. Restores are followed by reapplication of deletion controls.
- Firebase Analytics: event and user data retention is configured to 2 months without resetting retention on new activity.
- Support email or form content: retained only as reasonably needed to resolve the request, maintain necessary records, prevent abuse, or comply with law.
- Purchase, advertising, website, and provider records: retained by Apple, RevenueCat, Google, or Cloudflare under their applicable policies and legal obligations.
13. Security safeguards
Safeguards include data minimization; TLS; production App Attest and signed requests; replay counters; strict payload validation; short TTLs; Azure managed identities and least-privilege role assignments; Key Vault for the APNs private key; encryption at rest by the cloud provider; bounded delivery and kill switches; restricted logs; source and app-bundle secret scans; dependency audits; deletion controls; incident investigation procedures; and periodic review of providers and the countries where processing may occur. Details that would weaken security may be withheld where permitted by law.
14. Your rights under Japanese law
Subject to the APPI and other applicable law, you may request notice of purpose of use, disclosure of retained personal data or applicable third-party provision records, correction, addition, deletion, suspension of use, erasure, or cessation of third-party provision.
Send a request to englishhub0001@gmail.com with the subject “Lockeigo Privacy Rights Request.” Describe the right requested, the relevant feature and approximate date, and the minimum information needed to identify the record. Because Lockeigo has no account, some pseudonymous data may not be reasonably linkable to you. The operator may request proportionate proof of identity or authority, preferably using app-generated or transaction information rather than a government ID. Do not send a My Number or an unredacted government ID unless specifically and lawfully requested.
Electronic requests are normally handled without charge. If exceptional actual costs are lawfully chargeable, the amount and method will be explained in advance. The operator will respond without undue delay, explain a refusal or alternative measure where required, and use the verification material only for the request.
15. Children
Lockeigo does not require an account and does not ask users to provide age, name, address, or contact details in the app. A parent or legal guardian may contact the operator regarding a child’s information. Users should not place sensitive personal information in learning cards that they choose to send for optional Live Activity display.
16. Security incidents and legal disclosures
If a reportable leak or similar incident occurs, the operator will investigate, contain the incident, take corrective measures, and report to Japan’s Personal Information Protection Commission and notify affected individuals where required. If direct notice is difficult because the service has no account contact information, an appropriate public notice or inquiry channel may be used as permitted by law.
17. Changes
Material changes will be published here with a new effective date and, where required, presented in the app or submitted for consent before the new processing begins.