Bucket List Commit日本語

Last updated: 2026-08-03

This English version is provided for reference only. The Japanese version is the authoritative text, and it prevails in the event of any discrepancy.

Privacy Policy

Shiiman Works ("we", "us") sets out below how user information is handled in Bucket List Commit (the "App").

1. Our approach

We collect only the minimum information needed to provide the features of the App. The lists you create are stored on your device by default, and only the items whose visibility you choose are saved to our server (Google Firebase).

2. What we collect and why

InformationPurposeStored in
Account identifier (Firebase UID), display name, profile imageIdentifying your account; display in friends features and public listsFirebase
Contents of lists you set to "Public" or "Friends only" (title, category, completion status, images and so on)Showing public lists, sharing with friends, likesFirebase
Friend relationships, likes, participation in shared listsProviding social featuresFirebase
Birth decade (in ten-year bands) and gender (optional, only if you enter them)Display on your public profileFirebase
Push notification device tokenDelivering urgent or time-limited announcementsFirebase
Crash reports and usage statistics (can be turned off)Identifying defects and improving qualityFirebase
The exact date of your date of birth, tokens for external servicesProviding app featuresOn your device only (we do not collect these)
Your list contents (including lists set to "Private")Restoring your data when you change devices or reinstallStored encrypted (see "5. Backups and changing devices")

← Scroll horizontally

The default visibility for a list is "Friends only". You can change visibility per item.

3. Email addresses

You sign in to the App with an Apple or Google account. We receive an email address during authentication, but itstays within the authentication service (Firebase Authentication) and is not stored in our database. We do not read email addresses in order to contact you.

4. Date of birth and gender

Both are optional, and every feature works without them. Even if you enter a date of birth, only theten-year band is sent to the server; the exact date stays on your device. If gender is not set, it is not sent to the server at all.

5. Backups and changing devices

So that you can carry your lists over when you change devices or reinstall the app, we store your list contents (including lists set to "Private") encrypted on our servers (Cloud Storage). We keep the most recent copy and the one immediately before it.

This encryption is a defence-in-depth measure, not end-to-end encryption that would make the contents unreadable to us. The substantive protection is server-side access control that limits access to your own account.

Your date of birth and gender are not included in this backup; they stay on your device.

Deleting your account also deletes this backup.

6. Diagnostics (you can turn these off)

We collect crash reports and usage statistics to identify defects. They are on by default and can be turned off with a single toggle in the App's settings. We do not send your name, email address, or the contents of your lists. We do not use the advertising identifier (IDFA), so no tracking permission is requested.

7. Linking external services (optional)

  • GitHub — syncs your list to a repository you own. That repository belongs to you and the contents are stored as plain, unencrypted Markdown. We do not read its contents.
  • Google Calendar / Google Sheets — used to export completion dates or your list in spreadsheet form. Linking happens only when you explicitly authorise it.
  • Apple iCloud — syncs your lists between devices on the same Apple account (iOS).

The credentials used for these links are stored in a secure area on your device and are not sent to our server.

8. Notifications

Local notifications such as due-date reminders are scheduled and delivered entirely on your device, so their contents never pass through an external service. Receiving them is optional and can be configured per type.

Separately, we have the ability to send urgent or time-limited announcements, and we store a push notification device token for that purpose. We do not send push notifications for everyday events such as likes or friend requests.

9. Information you send through the feedback form

What you send through the feedback form on this website is recorded in a private development repository (GitHub) that we manage. We receive:

  • The text you write
  • The type, device and area you select (all optional)
  • The user ID and app version you enter (both optional)

We do not record your name, email address or IP address. The form has no field for contact details, so we cannot reply individually to what you send.

If you enter a user ID, we look at the data for that accountsolely to investigate the issue you reported, and for no other purpose.

We may publish selected submissions on this website under "Requests we have received".Only the text and the selected options are shown; we never publish a user ID. If you would prefer not to be quoted, please say so in your message.

To prevent abuse, the form uses Cloudflare Turnstile. That check is performed by Cloudflare and we receive only its result.

10. Sharing with third parties

We do not sell or provide the information we collect to third parties. As described above, we do use the following providers to the extent needed to run the service.

  • Google LLC (Firebase: authentication, database, file storage, crash reports, statistics)
  • Apple Inc. (sign-in, iCloud sync, billing)
  • GitHub, Inc. (only if you authorise linking)
  • Cloudflare, Inc. (delivery of this website)

We will comply with a legally valid request for disclosure.

11. How we share, transfer, or disclose Google user data

This section applies specifically to information we obtain through Google APIs when you choose to link your Google Account (“Google user data”), as required by the Google API Services User Data Policy. It covers information from Google Calendar and Google Sheets / Drive.

We do not share, transfer, disclose, or sell Google user data to any third party.We do not use or provide it for advertising, ad targeting, credit assessment, or any similar purpose. We do not allow humans to read it, except when required by law or when you explicitly ask us to investigate a problem on your behalf.

Google user data flows as follows:

  • It travels directly between your device and Google. Calendar events and spreadsheet contents never pass through our servers (Google Firebase) and are never stored on them.
  • The linked account’s email address, display name, and the identifier of the calendar you selected are stored only on your device. They are not sent to our servers.
  • No provider other than Google receives it. Of the providers listed in Section 10, only Google LLC (the service you linked) receives Google user data. Apple Inc., GitHub, Inc., and Cloudflare, Inc. do not.
  • We never use it to train machine learning or AI models. We do not develop, improve, or train any model using Google user data, and we do not provide it to third parties for that purpose.

You can unlink at any time from Settings → Google in the app. Unlinking discards the credentials and linked-account information stored on your device. You can also revoke access fromThird-party apps & services in your Google Account.

12. How we protect Google user data

We apply the following safeguards to sensitive information (Google user data and credentials such as access tokens).

  • Encryption in transit — all communication with Google APIs uses HTTPS (TLS). We do not use any unencrypted transport.
  • Credential storage — on iOS, access tokens and ID tokens are stored in theKeychain provided by the operating system. On Android we do not persist the access token: it is obtained from the authorization state managed by Google Play services when needed and held only in a short-lived in-memory cache. In neither case are credentials sent to our servers.
  • Least privilege — we request only the scopes a feature needs. Spreadsheet export uses aper-file scope limited to files this app creates (drive.file) rather than full Drive access, and listing calendars uses a read-only scope.
  • Data minimization — we do not store Google user data itself (event or sheet contents) on our servers. What we keep on the device is limited to identifiers used to avoid creating duplicates and a flag indicating that the link is active.
  • Access control — information stored on our servers (Google Firebase) is protected by security rules that allow only the owner to read and write it. Our operators do not routinely access other people’s data.
  • Handling revoked access — if access is revoked or a required scope is found to be missing, we discard the credentials remaining on the device and treat the link as incomplete.

13. Retention and deletion

When you delete your account, we delete the information about you stored on our server. SeeDeleting your account for the steps and exactly what is removed.

14. Age

The App is intended for people who meet the age rating shown in the stores. Please do not use it without the consent of a parent or guardian.

15. Changes to this Policy

If we revise this Policy we will post the revised text and its date on this page. We will announce significant changes in the App as well.

16. Contact

Requests concerning your retained personal data — notification of the purpose of use, disclosure, correction, deletion, or suspension of use — can be sent to[email protected]. To verify your identity, please include the user ID shown in the App.

For anything else — feedback, requests, or bug reports — please use the feedback form. Apart from statutory requests, we may not be able to respond individually.