Last updated: 2026-08-03
This English version is provided for reference only. The Japanese version is the authoritative text, and it prevails in the event of any discrepancy.
Privacy Policy
Shiiman Works ("we", "us") sets out below how user information is handled in Bucket List Commit (the "App").
1. Our approach
We collect only the minimum information needed to provide the features of the App. The lists you create are stored on your device by default, and only the items whose visibility you choose are saved to our server (Google Firebase).
2. What we collect and why
| Information | Purpose | Stored in |
|---|---|---|
| Account identifier (Firebase UID), display name, profile image | Identifying your account; display in friends features and public lists | Firebase |
| Contents of lists you set to "Public" or "Friends only" (title, category, completion status, images and so on) | Showing public lists, sharing with friends, likes | Firebase |
| Friend relationships, likes, participation in shared lists | Providing social features | Firebase |
| Birth decade (in ten-year bands) and gender (optional, only if you enter them) | Display on your public profile | Firebase |
| Push notification device token | Delivering urgent or time-limited announcements | Firebase |
| Crash reports and usage statistics (can be turned off) | Identifying defects and improving quality | Firebase |
| Contents of lists set to "Private", your date of birth, tokens for external services | Providing app features | On your device only (we do not collect these) |
← Scroll horizontally
The default visibility for a list is "Friends only". You can change visibility per item.
3. Email addresses
You sign in to the App with an Apple or Google account. We receive an email address during authentication, but itstays within the authentication service (Firebase Authentication) and is not stored in our database. We do not read email addresses in order to contact you.
4. Date of birth and gender
Both are optional, and every feature works without them. Even if you enter a date of birth, only theten-year band is sent to the server; the exact date stays on your device. If gender is not set, it is not sent to the server at all.
5. Diagnostics (you can turn these off)
We collect crash reports and usage statistics to identify defects. They are on by default and can be turned off with a single toggle in the App's settings. We do not send your name, email address, or the contents of your lists. We do not use the advertising identifier (IDFA), so no tracking permission is requested.
6. Linking external services (optional)
- GitHub — syncs your list to a repository you own. That repository belongs to you and the contents are stored as plain, unencrypted Markdown. We do not read its contents.
- Google Calendar / Google Sheets — used to export completion dates or your list in spreadsheet form. Linking happens only when you explicitly authorise it.
- Apple iCloud — syncs your lists between devices on the same Apple account (iOS).
The credentials used for these links are stored in a secure area on your device and are not sent to our server.
7. Notifications
Local notifications such as due-date reminders are scheduled and delivered entirely on your device, so their contents never pass through an external service. Receiving them is optional and can be configured per type.
Separately, we have the ability to send urgent or time-limited announcements, and we store a push notification device token for that purpose. We do not send push notifications for everyday events such as likes or friend requests.
8. Information you send through the feedback form
What you send through the feedback form on this website is recorded in a private development repository (GitHub) that we manage. We receive:
- The text you write
- The type, device and area you select (all optional)
- The user ID and app version you enter (both optional)
We do not record your name, email address or IP address. The form has no field for contact details, so we cannot reply individually to what you send.
If you enter a user ID, we look at the data for that accountsolely to investigate the issue you reported, and for no other purpose.
We may publish selected submissions on this website under "Requests we have received".Only the text and the selected options are shown; we never publish a user ID. If you would prefer not to be quoted, please say so in your message.
To prevent abuse, the form uses Cloudflare Turnstile. That check is performed by Cloudflare and we receive only its result.
9. Sharing with third parties
We do not sell or provide the information we collect to third parties. As described above, we do use the following providers to the extent needed to run the service.
- Google LLC (Firebase: authentication, database, file storage, crash reports, statistics)
- Apple Inc. (sign-in, iCloud sync, billing)
- GitHub, Inc. (only if you authorise linking)
- Cloudflare, Inc. (delivery of this website)
We will comply with a legally valid request for disclosure.
10. Retention and deletion
When you delete your account, we delete the information about you stored on our server. SeeDeleting your account for the steps and exactly what is removed.
11. Age
The App is intended for people who meet the age rating shown in the stores. Please do not use it without the consent of a parent or guardian.
12. Changes to this Policy
If we revise this Policy we will post the revised text and its date on this page. We will announce significant changes in the App as well.
13. Contact
Requests concerning your retained personal data — notification of the purpose of use, disclosure, correction, deletion, or suspension of use — can be sent to[email protected]. To verify your identity, please include the user ID shown in the App.
For anything else — feedback, requests, or bug reports — please use the feedback form. Apart from statutory requests, we may not be able to respond individually.