Nulvo (the "App") respects users' privacy and strives to protect personal information. This Policy explains the information the App collects and how it is handled.
The Version 3.1 revision (the addition of "Introducing the App" to the purposes of use) takes effect on August 18, 2026. Until then, the previous version of this Policy applies.
1. Information We Collect
The App is designed to be used anonymously, and we never ask for an email address, name, or phone number to create an account. To provide the Service, however, we collect and store the information listed below. While this information does not by itself directly identify you, some of it consists of identifiers that are treated as personal data (personal information) under the laws of certain jurisdictions. Please also avoid writing information that could identify you or anyone else in your posts or inquiries (see Section 3 of the Terms of Service).
User ID — A random ID used to identify a user within the App
Post content — The text you post, the feeling opener you select (in Japanese posts, the corresponding sentence ending), the emotion category (sadness, emptiness, loneliness), the language of the post, and the wording our AI identifies as sensitive (the wording to be masked on other users' screens)
Post translations — Translations generated by AI, including the words subject to sensitive-content masking, are stored on our servers so that posts can be shown to users reading in another language
Reactions and bookmarks — Records of empathy reactions and bookmarks
Report and block information — Records kept to maintain a safe community
Subscription status — Distinction between the free and paid plans
Notification settings — Whether to include a post preview in the notification body
Push notification token — A device identifier token (Expo Push Token) used to send push notifications. Collected only if you enable notifications
Apple ID information — If you link your account with your Apple ID, we obtain the user identifier provided by Apple. We do not obtain your email address or name
Inquiry content — The category, message body, app version, OS type and version, and plan type submitted through the in-app inquiry feature
Language setting — We store the language you are using in the App (Japanese/English — the language selected on the settings screen, or your device language if none is selected) in order to switch the language of notification text
Advertising identifier (IDFA) — Only if you consent to tracking (App Tracking Transparency), this is used by Google AdMob to personalize advertising. If you do not consent, non-personalized advertisements are displayed (advertisements are shown on the free plan only)
Access logs and technical information — When your device connects to our servers, technical information such as your IP address, the date and time of the request, the request itself, and the user agent is automatically recorded by the infrastructure of the cloud services the App uses (for example, Supabase). We use this information to detect unauthorized access and misuse, to investigate faults, and to keep the Service running reliably; we do not use it to personalize advertising or for behavioral analytics. These records are deleted after a period of time in accordance with each service provider's retention policy
Because of the nature of the App, a post may also contain information about your own health or similar matters that may qualify as "special care-required personal information" (要配慮個人情報) under Japan's Act on the Protection of Personal Information. Where you write and send such information yourself, we treat that act as your consent to our obtaining it.
2. Purposes of Use
Delivering the timeline and providing the empathy feature
Checking the safety of post content (AI review)
Generating and storing automatic translations of posts (Japanese ⇔ English)
Preventing misuse and maintaining community safety
Introducing the App (displaying post content — the body of a post together with its ending word — on external media, without any information identifying the author; see Section 5 of the Terms of Service for the applicable conditions and how to opt out)
AI review and automatic translation are also applied progressively to posts made before these features launched. Only the post text and the selected feeling opener are sent; no information identifying the poster is sent.
3. Sharing Information with Third-Party Services
The App uses the following third-party services. We share with each service only the information necessary for the stated purpose. We have confirmed that each of these providers affords the same or equal protection of user information as stated in this Policy, under its own published privacy policy and the applicable data processing terms.
The safety review and automatic translation of post content (OpenAI) are entrusted processing carried out within the scope necessary to achieve the purposes of use, and do not constitute provision of personal data to a third party under Japan's Act on the Protection of Personal Information.
Supabase — Database and authentication infrastructure. Stores and manages app data such as user IDs, post content, and reactions. Technical information such as your IP address is also recorded in Supabase's logs when your device connects to the server (Privacy Policy)
OpenAI — Safety review of post content (GPT-4o) and automatic translation of posts (GPT-4o mini). Only the post text and the selected feeling opener are sent; no information identifying the poster is sent (Privacy Policy)
Google AdMob — Ad delivery (free plan only). The advertising identifier (only when tracking is permitted), approximate location based on IP address, and device information are sent to Google (Privacy Policy)
RevenueCat — Management of in-app purchases. Shares your user ID and subscription status (Privacy Policy)
Expo — Push notification delivery infrastructure. In addition to the push notification token, the title and body of each notification pass through Expo's servers and are delivered to your device via the Apple Push Notification service (APNs). When the "Show content in notifications" setting is on (the default), the body of empathy notifications includes a preview of your own post. When it is off, only a generic message is sent. Text identified as sensitive is masked before sending, and if it cannot be masked, no preview is included (Privacy Policy)
Sentry — Collection and aggregation of crash reports, error logs, and app performance data (EU region). In addition to the stack trace, OS version, device model, and Nulvo's internal anonymous ID sent when a crash occurs, we send performance measurements such as startup time and screen transition duration for a sample of sessions (approximately 10%). We do not send post text, Apple ID, email address, or IP address (Privacy Policy)
Apple — Authentication via "Sign in with Apple", payment processing for in-app purchases through the App Store, and the push notification delivery infrastructure (APNs). When you sign in, Apple issues a user identifier and the App receives only that identifier. Apple collects payment for in-app purchases on our behalf; the App does not receive payment details such as credit card numbers. Push notifications are delivered to your device via Apple's servers (APNs) (Privacy Policy)
4. Information Used Only on the Device
The following information is used only on your device and is not sent to our servers or those of third-party services.
Motion and fitness data — Used for the character animation on the archive screen (effects that respond to tilting and shaking). The data is read from the device sensors and immediately discarded.
Home screen widget — Displays the posts you have marked with empathy and the posts you have bookmarked in the device's home screen widget. These are mainly posts written by other users, not your own. Which post is shown, and the rotation between posts, are decided on the device; for posts flagged as sensitive, the flagged parts are replaced with ■ before being written to the widget, and any post that cannot be fully masked is excluded from the widget entirely.
Device-local settings — Stores information such as onboarding completion status, announcement read timestamps, the agreed Terms of Service version, and the language you selected in the App on the device.
5. About AI Review Logs
At the time of posting, AI reviews the content (checking whether it fits the themes, whether it contains self-harm or aggressive expression and the like, and whether it contains wording that should be masked on other users' screens), and we retain the result of that determination on the server for up to 60 days. This applies to posts that were blocked and never published as well as to posts that were approved.
Information retained:
The post text
The emotion category (sadness, emptiness, loneliness)
The AI's determination (approved / rejected)
If rejected, the category of the reason (off-theme, self-harm expression, aggressive expression, and so on)
The sensitive-content determination and the wording it identified
The date and time of determination
Nulvo's internal user ID
Purposes of use:
Improving the accuracy of AI review (detecting and improving posts that were wrongly rejected)
Adjusting service quality
We do not provide this to third parties. Only the operator accesses it for aggregation and review. Logs are automatically deleted 60 days after the date of determination. Once adjustments to the AI review logic are complete, the operator may manually delete them before then.
We do not attach your Apple ID, email address, device information, real name, or contact details to these logs. However, the post text is retained exactly as you wrote it, together with Nulvo's internal user ID, regardless of the outcome, which means the logs are not anonymous: a log entry can be traced back to the account that created it. The text of a post that was rejected for containing personal information is likewise retained as written. We therefore treat AI review logs as personal data — access is restricted to the operator, and the logs are deleted on the schedule described above. As set out in the Terms of Service, please do not include personal information in your posts.
6. About Crash Reports and Performance Data
We anonymously collect crashes and unexpected errors that occur in the App, as well as app performance data, and use them to improve quality. Collection is performed through Sentry, and the data is stored in the EU region.
Information collected:
The location of the crash or error (stack trace)
Technical metadata such as OS version and device model
Nulvo's internal anonymous user ID
The screen navigation history just before the crash (breadcrumbs)
App performance measurements (startup time, screen transition duration, and rendering delays), sampled from approximately 10% of all sessions
Information not collected:
Apple ID, email address, real name, or contact details
Post text, reactions, or bookmark content
IP address (removed on transmission)
Data sent to Sentry is managed by the company that operates Sentry, and only Nulvo's operator accesses it to improve quality.
7. Where Data Is Stored and Cross-Border Transfers
App data is stored and processed on the servers of the providers listed below. The region shown in parentheses is the primary location of storage and processing.
Supabase (Japan, Tokyo region) — Storage of app data such as posts and reactions, and authentication. The operating company is in the United States
OpenAI (United States) — Safety review and automatic translation of posts
Google (AdMob) (United States and other countries; the destination country cannot be specified) — Ad delivery (free plan only)
RevenueCat (United States) — Management of in-app purchases and subscription status
Expo (United States) — Delivery of push notifications
Sentry (EU) — Storage of crash reports and related data. The operating company is in the United States
Apple (United States and other countries; the destination country cannot be specified) — Sign-in, payment processing for in-app purchases, and push notification delivery
Because some of these providers are located outside Japan, the information above may be transferred outside Japan.
For Google (AdMob) and Apple, we cannot specify the destination country, because both companies process data across data centers distributed worldwide and the country in which processing takes place varies from time to time. As reference information, the primary processing locations of both companies include the United States; for details, please see each company's published privacy policy. The locations of the other providers are as listed above.
For information on the personal data protection regimes of the destination countries, please refer to the survey of foreign personal data protection systems published by Japan's Personal Information Protection Commission.
Each of the providers listed above states, in its own published privacy policy and applicable data processing terms (which in most cases include the EU Standard Contractual Clauses as the framework for international transfers), that it applies safeguards such as encryption in transit, encryption of stored data, and access controls. We reviewed those terms before engaging each provider.
By starting to use the App, or by agreeing to a revision of this Policy, you are treated as having consented to the provision of personal data to the providers located in the countries listed above.
8. Data Retention and Deletion
User data is retained for as long as the account exists. When you delete your account from the settings screen within the App, the data held in the App's database — posts, empathy reactions, bookmarks, notifications, push notification tokens, inquiry history, reporting and blocking records, and subscription status — is deleted immediately and cannot be restored.
However, the following data remains for a limited period after account deletion.
AI review logs — When you delete your account, Nulvo's internal user ID is detached from these logs (anonymized), leaving only the recorded text and the assessment result. Those are retained for up to 60 days from the date of determination, for the purpose of preventing misuse, and are then deleted automatically.
Purchase and billing records — Retained by Apple and by RevenueCat for payment processing and to prevent repeated use of the free trial (RevenueCat retains a customer record linked to your in-App user ID, together with your purchase and trial history). Their handling and deletion follow each company's own policy.
Crash reports — Retained for up to 90 days and then automatically deleted in accordance with Sentry's retention policy.
For content already saved on other users' devices before the deletion (home screen widgets, in-app caches, and the like) and for push notifications that have already been delivered, please see Section 5 of the Terms of Service.
9. Data Security
Data is transmitted over encrypted communication (HTTPS) and managed under appropriate access controls. However, complete security cannot be guaranteed for communications over the internet.
Understanding the external environment — Part of the personal data handled through the App is handled by providers outside Japan (the providers and their locations are listed in Section 7, "Where Data Is Stored and Cross-Border Transfers"; this includes providers whose servers are in Japan but whose operating company is located outside Japan). We have informed ourselves of the personal data protection regimes of those countries, using sources such as the surveys of foreign systems published by Japan's Personal Information Protection Commission, and on that basis we apply security measures such as encryption in transit and minimization of access privileges.
10. Your Rights
Under Japan's Act on the Protection of Personal Information, which governs the operator's handling of personal information, you have the following rights regarding your own data.
Access to and review of your data
Requesting correction or deletion of your data
Requesting suspension of the use of your data
To exercise these rights, please contact us using the details below. We respond to such requests to the extent we can verify that you are the person concerned. You can also delete your account at any time from the settings screen within the App.
11. Children's Privacy
The App is not primarily intended for people under the age rating shown on the App Store. We do not knowingly collect information from children. Where appropriate — for example, at the request of a parent or guardian — we will delete an account and its associated data (you can also delete your account at any time from the in-app settings).
12. Changes to This Policy
This Policy may be updated as necessary. When there is a material change, we may display a re-consent dialog when the App launches, and users will be asked to agree to the new Policy in order to continue using the App.
13. Contact and Complaints
For questions about this Policy or about how we handle personal information, to request disclosure, correction, or suspension of use of your data, or to make a complaint, you can reach us through either of the following two channels.
The purposes for which we use retained personal data are set out in Section 2, and the procedure for requesting disclosure, correction, or suspension of use is set out in Section 10. We respond to such requests to the extent we can verify that you are the person concerned.
The operator's name and address are not published on this page, but we will provide them without undue delay upon request through the contact channels above.
14. Revision History
This Policy and the Terms of Service share a single version number. When we make a material change, we ask you to agree again inside the App, and the version you agreed to is recorded on your device. We began publishing this revision history with the version below.
Version 3.1 (August 18, 2026) — Added "Introducing the App" (displaying post content on external media without any information identifying the author) to the purposes of use. See Section 5 of the Terms of Service for details.
Version 3.0 (July 25, 2026) — Added disclosures on the advertising identifier (IDFA) and App Tracking Transparency following the introduction of advertising on the free plan (Google AdMob); added disclosures on the information sent for automatic translation of posts (OpenAI GPT-4o mini) and on the storage of the resulting translations; added storage of your language setting used to localize notification text; added disclosures on the information submitted through in-app contact, on access logs and technical information, on Apple, and on app performance measurement; clarified the disclosures on AI review logs and on data retention and deletion; listed the storage locations and cross-border transfers by provider and added the information provided where a destination country cannot be specified; added confirmation that third-party providers afford the same or equal protection and clarified which processing is entrusted rather than provided to a third party; added a disclosure on obtaining special care-required personal information; added a disclosure on security measures including understanding of the external environment; added a statement that the operator's name and address are provided on request.
Version 1.3 and earlier — The contents of those versions are not published on this page. Please contact us at the addresses above with any questions.