Privacy Policy
📅 Last updated: July 15, 2026 · Version 4.0
1. Who we are
The Moshibary app and the website moshibary.com (together, the “Service”) are operated by:
- Operator: Shinobasa (a sole proprietor in Japan)
- Representative: Shimba Saruta
- Address: Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
- Email: moshibary@gmail.com
For the purposes of data protection laws such as the EU/UK General Data Protection Regulation (GDPR), Shimba Saruta, operating under the trade name Shinobasa, is the data controller of the personal data described in this policy.
2. What this policy covers
This policy explains what data we process through the Moshibary mobile app and this website, why we process it, how it is protected, and the choices and rights you may have. Privacy rights and obligations vary by jurisdiction. We apply the laws that are applicable to our activities, the relevant user, and the particular processing. A reference to a regional law does not mean that every provision of that law applies to every user or every processing activity.
The data practices described below apply only to features that are enabled in the production release you use. If a listed feature or provider is not enabled, the related processing does not occur. We update this policy before materially changing production data practices.
3. Data we collect
Guest mode does not require an account. Your learning records such as progress, decks, settings, and custom words are designed to remain on your device unless you choose a feature that requires a network request, such as downloading content or audio. Our hosting and content-delivery providers may process limited technical data, including IP address and request metadata, to deliver and protect the Service.
If you choose to create an account or use an optional connected feature, the data processed may include the following, depending on the production version you use:
| Category | What exactly | When | Where it lives |
|---|---|---|---|
| Account data | Email address; or the sign-in identity provided by Apple or Google (name/email as you authorize); password (stored only as a secure hash by our authentication provider) | When you sign up or sign in | Supabase (database & authentication) |
| Profile & preferences | App language, learning goal, daily goal minutes, onboarding completion time | During onboarding / in settings | Supabase |
| Consent records | Timestamps of your acceptance of the Terms and this policy; your age confirmation | During onboarding | Supabase |
| Learning data (sync) | Study progress, statistics, decks, review schedule, display settings, collection/garden state, app version, last sync time, and text you type yourself: your word notes and the names of your custom lists | While signed in, as you study | Supabase (and a copy on your device) |
| Crash reports (when enabled) | Technical diagnostics such as a stack trace, device model, OS version, app version, and error context. We configure the service to minimize unnecessary personal data and to avoid sending passwords, authentication tokens, and full message content. The provider may process network-level data, including an IP address, to receive and secure the report. | When an error occurs and crash reporting is enabled in the production build | Sentry |
| Support messages | Whatever you write to us by email, plus the app version, OS and language that the contact template pre-fills | Only when you contact us | Our email inbox |
Search queries you type inside the app's dictionary search are sent to our database to return results; they are not used to profile you.
If you purchase the optional Premium subscription, Apple or Google processes the payment. Through RevenueCat, we receive an app user identifier and purchase or subscription information so the app can validate and unlock Premium. Depending on the store and event, this may include product, transaction, subscription, renewal, refund, and entitlement status. The app user identifier may be generated for the app or linked to your Moshibary account, depending on how the production app is configured and how you use it. We do not receive your full payment-card details.
4. Data-use limits and current permissions
We limit collection and use to what is described in this policy. In particular:
- We do not sell personal data. Service providers may process data on our behalf only for the functions described in this policy.
- Moshibary may offer optional rewarded ads through Google AdMob. A rewarded ad is shown only after you actively choose to watch it. We do not use banner ads or automatically displayed interstitial ads. Google AdMob may process device and network information needed to request and display the ad, prevent fraud, measure delivery, and confirm the reward, as described in Section 6. We provide consent and privacy controls where required for the user’s region and age treatment.
- Current device permissions. As of the date above, the app is not designed to request precise location, contacts, photos, microphone recordings, or health data. If a future feature changes this, we will update this policy and request any permission required by the operating system or applicable law before collection.
5. How and why we use data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the Service: account access, syncing your progress across devices | Account, profile, learning data | Performance of a contract (Art. 6(1)(b)) |
| Remember your consent and age confirmation | Consent records | Legal obligation / legitimate interests (Art. 6(1)(c), (f)) |
| Verify Premium purchases and unlock the features you paid for | App user identifier and purchase/subscription information | Performance of a contract (Art. 6(1)(b)) |
| Show an optional rewarded ad and confirm its reward, only after you choose to watch it | Device and ad-delivery data processed through Google AdMob | Consent where required (Art. 6(1)(a)); legitimate interests for limited security and fraud prevention where permitted (Art. 6(1)(f)) |
| Diagnose crashes and improve stability | Technical crash diagnostics, when enabled | Consent where reporting is optional; otherwise legitimate interests where permitted (Art. 6(1)(a), (f)) |
| Answer your questions | Support messages | Legitimate interests (Art. 6(1)(f)) |
We do not use learning data, account information, or other user data under our control to build advertising profiles. Processing performed by Google AdMob for ad delivery is limited by the purposes described in Section 6 and by the user’s consent and regional settings. We do not use automated decision-making that produces legal or similarly significant effects.
6. Service providers and third parties
We use a limited number of companies to operate the Service. Depending on the service and applicable law, a company may act as our processor, service provider, or an independent controller under its own terms and privacy policy:
| Provider | Role | What it processes |
|---|---|---|
| Supabase | Database, authentication and hosting for account data | The account, profile, consent and learning data listed in Section 3 |
| Sentry | Crash reporting, when enabled | Technical crash diagnostics configured to minimize unnecessary personal data; network-level data may be processed when receiving and securing a report |
| RevenueCat | Subscription validation and entitlement management | An app user identifier and store-supplied purchase information, such as product, transaction, subscription, renewal, refund, and entitlement status. The identifier may be app-generated or linked to your Moshibary account. Full payment-card details do not reach us; Apple or Google processes the payment. |
| Google AdMob | Optional rewarded advertising | Device and network data needed to request and display an ad, prevent fraud, measure delivery, and confirm the reward, such as IP address, device information, and advertising or app identifiers where permitted. The feature operates only when enabled in the production build. Consent, privacy messaging, non-personalized or limited-ad settings, and age treatment are applied where required. |
| Cloudflare | Content delivery for audio files (Cloudflare R2) and this website | No account data. Like any web server, the CDN processes IP addresses at the network level to deliver content and prevent abuse |
| Apple / Google | Optional sign-in and app-store billing | Authentication tokens and profile fields you authorize for sign-in. For purchases, the store provides transaction and subscription information to the app or RevenueCat, while Apple or Google processes payment and related store data under its own terms and privacy policy. |
| Google (Gmail) | Support email | The content and metadata of messages you send to our support address |
We do not disclose personal data for unrelated purposes. We may disclose data to the companies listed above, professional advisers where necessary, a successor in a lawful business transfer, or authorities and other parties when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service.
7. Where data is processed & international transfers
We are based in Japan, and our providers may process data in other countries. Depending on the transfer route and applicable law, safeguards may include an adequacy decision, contractual transfer clauses, a UK transfer addendum or agreement, or another lawful transfer mechanism. The provider, infrastructure region, account configuration, and contract in use determine the countries and safeguards for a particular transfer.
8. How long we keep data
- Account and synced learning data: kept while your account remains active. After a verified deletion request, we aim to delete or de-identify this data within 30 days, except for limited information that must be retained for legal, security, fraud-prevention, or billing reasons. Backup copies expire according to the applicable backup cycle.
- Crash reports: kept for the retention period configured in the crash-reporting service and deleted when no longer reasonably necessary for diagnosis, security, or legal obligations.
- Support emails: kept as long as reasonably necessary to resolve the request, maintain an appropriate support record, and meet legal obligations.
- Guest data: stored locally on the device. Removing the app normally removes local guest data, although operating-system or device backups may retain a copy until those backups expire or are deleted.
9. Security
- We use HTTPS/TLS for supported network communications.
- We use access controls, secure authentication practices, data minimization, and provider security features appropriate to the production configuration.
- Access to account data is restricted to authorized systems and personnel with a legitimate operational need.
- Security controls are reviewed as the Service changes.
No online service can be guaranteed completely secure. If we become aware of a personal-data breach, we will investigate, mitigate it, and notify affected users and authorities when required by applicable law.
10. Your rights
Depending on where you live, you have some or all of the following rights regarding your personal data:
- Access — ask for a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Deletion — request deletion in the app (Settings → Account → Delete account) or through the account-deletion page.
- Portability — receive your data in a machine-readable format.
- Objection & restriction — object to or restrict certain processing.
- Withdraw consent — change available privacy choices in the app or contact us. Withdrawal does not affect processing that was lawful before withdrawal.
To exercise any right, use the in-app options or email us at moshibary@gmail.com. We respond within the time required by the law that applies to the request. We may need to verify your identity and may retain a limited record of the request. We will not discriminate against you for exercising an applicable privacy right.
If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
11. California residents (CCPA/CPRA)
For users to whom California privacy law applies, the categories of personal information we process and the business purposes are described in Sections 3 and 5.
- We do not sell personal information for money.
- Ad-related disclosures may be treated as “sharing” or targeted advertising under some laws. Where such a right applies, we provide the required consent or opt-out control and use non-personalized or limited ads when required by the user’s choice, age treatment, or region.
- We do not use or disclose sensitive personal information for purposes requiring a right to limit, based on the data practices described in this policy.
- You may exercise applicable rights to know, access, correct, delete, and non-discrimination as described in Section 10.
12. Other regions
Your rights and our obligations vary by location. We handle requests under the law that applies to the relevant user and processing activity. Our commitment not to sell personal data applies regardless of location. Contact us if you want to exercise a privacy right or ask how a regional rule applies.
13. Children
Moshibary is intended for users aged 13 and over. If local law requires a higher age to consent independently to data processing or contract terms, permission from a parent or legal guardian, or another lawful basis, is required. We do not knowingly create accounts for children below the applicable minimum age. If you believe such an account exists, contact us so we can investigate and delete it where required.
14. This website
As of the date above, the public pages of moshibary.com are configured as follows:
- They do not intentionally set application analytics or advertising cookies or use browser local storage.
- Fonts, images, and styles are served from moshibary.com. The pages use no executable application JavaScript; the only script element is non-executable structured metadata. They do not embed third-party analytics or advertising resources.
- The hosting/CDN provider processes IP addresses, request metadata, user-agent information, and network-security logs to deliver the site and prevent abuse. Cloudflare may set strictly necessary security cookies if an enabled protection feature requires them.
- External links, if selected, take you to the relevant third-party website, which is governed by that website's own privacy practices.
15. Changes to this policy
When we change this policy in a meaningful way, we update the date and version at the top. For changes that materially affect your rights or how we use personal data, we provide additional notice in the app, by email, or by another appropriate method before the change takes effect where required. Earlier versions are available on request.
16. Contact
Questions, requests or complaints about privacy:
- Email: moshibary@gmail.com
- Post: Shinobasa, Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
We usually reply within a few business days.