プライバシーポリシー
最終更新: 2026-08-28
Lovy (以下「本サービス」) は、ユーザーが「好きな場所」を発信・発見するための ソーシャルマップです。本ポリシーは、本サービスが取得する情報、その利用目的、 ユーザーが行使できる権利を説明します。
1. 取得する情報
- アカウント情報: Sign in with Apple、Google、またはメールアドレスで サインインした際のユーザー識別子・メールアドレス・表示名 (任意)・ アバター URL (任意)、およびユーザーがプロフィールに追加した自己紹介・ SNS リンク (任意)。
- 場所の記録: ユーザーが付けた評価 (7 段階)、コメント、 訪問履歴、投稿した写真・キャプション、リスト登録、投稿ごとの公開範囲、 フォロー・友達・マブダチを含むソーシャルグラフ。
- 個別共有: スポット、ログ、リスト等を Lovy 内で共有したときの 送信者・受信者のアカウント識別子、共有対象、および任意で入力したメッセージ。
- 問い合わせ・通報: アプリ内通報、または support@lovy.app / report@lovy.app 宛のメールに含まれる送信者情報、対象コンテンツ、理由、本文、 および任意の添付ファイル。
- スポットのストーリーとログ: 写真付きログは投稿後72時間、地図上の ストーリー欄で新着として強調表示します。ログ、写真、コメント、評価は72時間後も 保管され、投稿者本人と、投稿時に選択した公開範囲の対象ユーザーがスポット、フィード、 投稿者のログ履歴から閲覧できます。投稿者はログと写真を削除でき、他のユーザーは 不適切なコンテンツを通報または投稿者をブロックできます。
- 位置情報: 「使用中のみ」 の許可があった場合のみ、地図上で 現在地を表示し、周辺検索や Lovy 検索の候補を関連性の高い順に表示するために OS の位置情報サービスを利用します。検索時には現在地または表示中の地図範囲を Lovy のサーバへ送信し、スポット候補の取得のため Google Places に送信する場合が あります。座標は PostHog の分析イベントや Lovy の検索履歴には保存しません。
- 検索内容: Lovy 検索で入力した検索文、直前の会話文脈、および 候補スポット情報を、検索意図の解釈と候補の順位付けのため Anthropic、または フォールバックとして OpenAI に送信する場合があります。検索語と位置条件は Google Places にも送信される場合があります。Lovy は検索文を自社データベースや PostHog に検索履歴として保存しませんが、各事業者は自社の契約、設定、法令に従って リクエストを一時的に保持する場合があります。
- 端末・通知情報: プッシュ通知を登録する際に Lovy が発行する インストール識別子、Apple Push Notification service (APNs) のデバイストークン、 アプリ識別子、配信環境、アプリバージョン、言語・タイムゾーン、および登録状態。 通知を有効にしたアカウントに紐づけて管理します。
- 使用状況の分析: ログイン後のアカウント識別子と、検索の成否・ 候補の表示・スポットの閲覧や記録・フォロー・共有などの操作イベントを、 新しい場所との出会いと意思決定体験を改善するために取得します。検索語、座標、 氏名、メールアドレス、コメント・キャプション・メッセージ、URL、共有相手のIDは 分析イベントに含めません。セッションリプレイは使用しません。「マイページ → 右上の歯車 → 設定 → 利用状況の分析」から今後の送信を停止できます。
- 診断情報: 分析が有効な場合、アプリの起動などのライフサイクル情報と、 クラッシュ・エラーおよびその他の診断情報を PostHog が自動取得します。サインイン後は アカウント識別子に紐づく場合があります。正確な位置情報、検索語、投稿内容は診断情報に 含めず、上記の「利用状況の分析」をオフにすると今後の診断情報の送信も停止します。
2. 利用目的
- ユーザー個別の「Lovy マップ」を生成・表示するため
- 位置、検索内容、評価、ログ、信頼関係に基づくおすすめを表示するため
- サインインによる本人確認とアカウント管理のため
- 選択した相手への個別共有と、許可した通知を配信するため
- 問い合わせへの回答、通報の確認、違法・有害コンテンツへの対応のため
- 発見から記録・共有までの体験、継続利用、サービス品質を改善するため
3. 第三者提供
本サービスは、法令に基づく場合または本人の同意がある場合を除き、取得した 個人情報を販売せず、広告目的のクロスアプリ追跡を行いません。サービス提供に必要な 範囲で、主に以下の委託先・プラットフォームが情報を処理します。
- Supabase: 認証、データベース、写真等のストレージ。
- Vercel: API と公開ページのホスティング、リクエスト処理、 セキュリティおよび運用ログ。
- PostHog EU Cloud: 上記の限定した分析イベントと診断情報。
- Google Places: 検索語、現在地または表示中の地図範囲を用いた スポット検索と情報取得。
- Anthropic / OpenAI: 検索文、限定した会話文脈、候補情報を用いた 検索意図の解釈、候補の分類・順位付け。
- Apple Push Notification service: デバイストークンと通知内容を 用いた、ユーザーが許可した通知の配信。
Sign in with Apple は Apple が中継するため、メールを非公開にした場合、本サービスには リレーアドレスのみが共有されます。Google でサインインした場合は、Google から認証に 必要なアカウント情報が共有されます。
4. データの保管
データは Supabase (PostgreSQL) を用いて暗号化された通信で保管されます。 Row Level Security (RLS) により、各ユーザーは自身に許可された範囲のデータ のみアクセスできます。分析イベントは PostHog EU Cloud へ暗号化通信で送信されます。 検索文そのものは Lovy のデータベースや PostHog に検索履歴として保存しませんが、 Google Places、Anthropic、OpenAI、Vercel は、サービス提供、セキュリティ、不正利用防止、 または法令遵守に必要な期間、各社の契約・設定に従ってリクエスト情報を保持する場合があります。 プッシュ通知の登録情報と個別共有メッセージは Supabase に保管されます。 アプリ内通報は Supabase、メールでの問い合わせ・通報は Lovy と送信者が利用する メールサービスで処理され、対応、セキュリティ、法令遵守に必要な期間保持する場合があります。 現在の写真配信には推測困難な公開URLを使用しているため、 URLを取得済みの相手による直接アクセスを公開範囲の変更と同時に無効化できない場合があります。
5. アカウントの削除
アプリ内の「マイページ → 右上の歯車 → 設定 → アカウントを削除」から、いつでも 完全な削除をリクエストできます。削除後、評価・ログ・写真・フォロー関係、プッシュ通知の 端末登録を含む、アカウントに直接紐づくデータは復元不可な形で削除されます。紐づいた PostHog の ユーザー、分析イベント、診断情報、録画データ(録画機能は現在無効)も削除処理の対象です。 ただし、既に他のユーザーへ配信された個別共有・通知のメッセージ、および問い合わせ・通報の 対応記録は、受信者の履歴、サービスの安全性、紛争対応、法令遵守に必要な範囲で残る場合があります。
6. 子どもの個人情報
本サービスは 13 歳未満の利用を想定していません。13 歳未満であることが 判明した場合は、当該アカウントを削除します。
7. 改訂
本ポリシーは予告なく改訂されることがあります。重要な変更がある場合は、 アプリ内通知または本ページの最終更新日で告知します。
8. 問い合わせ
本ポリシーに関するご質問は support@lovy.app までご連絡ください。
Privacy Policy (English)
Last updated: 2026-08-28
Lovy is a social map for sharing and discovering places you love. This policy explains what we collect, how we use it, and your rights.
1. Information we collect
- Account: a unique user id, email address (or Apple relay), optional display name and avatar URL, from your Sign in with Apple, Google, email/password, or email one-time-code sign-in, plus any optional bio or social links you add to your profile.
- Place activity: your 7-tier ratings, comments, visits, uploaded photos and captions, list subscriptions, per-post audience, and your social graph, including follows, friends, and Close Friends (Mabudachi).
- Direct shares: the sender and recipients’ account identifiers, shared item, and any optional message when you share a place, log, list, or other supported content inside Lovy.
- Support and reports: sender information, reported content, reason, message body, and optional attachments submitted through an in-app report or by email to support@lovy.app or report@lovy.app.
- Place Stories and logs: photo logs are highlighted as fresh in the map Story rail for 72 hours after posting. The log, photos, comments, and rating remain stored afterward and can still be viewed from the place, Feed, or author Log history by you and the audience selected when posting. You can delete your logs and photos; other users can report inappropriate content or block its author.
- Location: only when granted “While Using the App”, to draw your current position and rank nearby or Lovy Search results. Your current location or visible map region may be sent to Lovy’s server and to Google Places to retrieve relevant place candidates. Coordinates are not sent to PostHog analytics or stored in Lovy search history.
- Search content: your Lovy Search text, bounded recent conversation context, and candidate-place information may be sent to Anthropic, or to OpenAI as a fallback, to interpret intent and rank results. Search terms and location constraints may also be sent to Google Places. Lovy does not save the search text in its own database or PostHog, but each provider may temporarily retain requests under its contract, settings, and law.
- Device and notification data: when registering for push notifications, a Lovy-generated installation identifier, Apple Push Notification service (APNs) device token, app identifier, delivery environment, app version, language, time zone, and registration status. Registration is linked to the account for which notifications are enabled.
- Usage analytics: after sign-in, an account identifier and bounded events such as search success, recommendation impressions, place opens and saves, follows, and shares. Analytics events exclude exact search text, coordinates, names, email addresses, comments, captions, messages, URLs, and recipient IDs. Session replay is disabled. You can stop future collection under My Page → top-right gear → Settings → Usage analytics.
- Diagnostics: while analytics is enabled, PostHog automatically collects app lifecycle data plus crash, error, and other diagnostic data. After sign-in, it may be linked to your account identifier. Precise location, search text, and post content are excluded. Turning off Usage analytics also stops future diagnostic collection.
2. How we use it
- Render your personal “Lovy Map” and recommendations from people you trust.
- Personalize search and suggestions using location, search content, ratings, logs, and relationships.
- Authenticate you and manage your account.
- Deliver direct shares to selected recipients and notifications you allow.
- Respond to support requests and review illegal or harmful-content reports.
- Improve discovery-to-decision flows, retention, sharing, reliability, and feature quality.
3. Third parties
We do not sell personal information or use cross-app advertising tracking. The following primary processors and platforms handle data only as needed to provide Lovy:
- Supabase: authentication, database, and photo storage.
- Vercel: API and public-page hosting, request processing, security, and operational logs.
- PostHog EU Cloud: the bounded analytics and diagnostics described above.
- Google Places: place lookup using search terms and a current location or visible map region.
- Anthropic / OpenAI: intent interpretation, classification, and ranking using search text, bounded context, and candidate data.
- Apple Push Notification service: delivery of allowed notifications using a device token and notification content.
Sign in with Apple uses Apple’s relay address, so we receive only that relay when you hide your email. Google shares the account information required to authenticate you when you choose Continue with Google.
4. Storage
Data is stored encrypted-in-transit in Supabase (PostgreSQL). Row Level Security ensures each user accesses only what they’re authorized to see. Analytics events are sent over encrypted connections to PostHog EU Cloud. Lovy does not save raw search text in its own database or PostHog, but Google Places, Anthropic, OpenAI, and Vercel may retain request information for service delivery, security, abuse prevention, or legal compliance under their contracts and settings. Push registrations and direct-share messages are stored in Supabase. In-app reports are stored in Supabase; emailed support requests and reports are processed by the sender’s and Lovy’s mail services and may be retained as needed for resolution, security, or legal compliance. Photo delivery currently uses hard-to-guess public URLs, so changing an audience may not immediately revoke direct access by someone who already obtained a media URL.
5. Deleting your account
You can delete your account at any time via My Page → top-right gear → Settings → Delete Account. All related account-linked data (including ratings, logs, photos, follow relationships, and push-device registrations), along with the linked PostHog person, analytics events, diagnostics, and any recordings (recording is currently disabled), is queued for permanent deletion. Messages already delivered through direct shares or notifications, and support or report records, may remain where needed for a recipient’s history, service safety, dispute handling, or legal compliance.
6. Children
Lovy is not intended for users under 13. If we learn of such an account, we will delete it.
7. Changes
We may update this policy. Significant changes will be announced in-app or via the “Last updated” date on this page.
8. Contact
Questions? Email support@lovy.app.