Privacy Policy / プライバシーポリシー — Theoretical Height Max (理論身長マックス)
- Operator / 運営者: SHIRO KAWAI(川井志朗)
- Contact / 連絡先: shiro.kawai@icloud.com
- Governing jurisdiction / 準拠法・管轄: 日本法・東京地方裁判所 / Laws of Japan, Tokyo District Court
- Effective date / 施行日: 2026-08-12
English
1. What this app is
Theoretical Height Max is a family wellness and record-keeping app operated by SHIRO KAWAI(川井志朗). A parent or guardian records a child's growth (height, weight) and sees a clearly labeled estimated range for adult height. It is not a medical device and does not provide medical advice or diagnosis.
2. Data we handle
We practice data minimization. The app asks only for what its features need:
- Child profile: nickname (not legal name), birth date, the sex category used by growth references, country/region for reference selection.
- Growth records: dated heights and weights, entered manually or derived on device from the optional Growth Scan; measurement source, quality notes, and revision history.
- Biological parent heights (optional, may be marked unknown), used only for the published mid-parental target-height calculation.
- Scan-derived metadata: body-segment proportions/lengths, confidence, method, and quality flags. Raw camera frames are processed on device and are not stored by default and never uploaded. Optional photo retention is a separate explicit opt-in and stays on the device.
- Habit data: routines the guardian approves and their completion.
- Account data (cloud mode only): your email address, a salted password hash, and session records.
- Subscription state: Apple-signed transaction information needed to verify an active subscription.
We do NOT collect legal names, addresses, schools, precise location, contacts, advertising identifiers, or face-recognition data. The scan detects bodies and faces only for framing/privacy-masking; it never identifies anyone or creates biometric templates.
3. Local-only mode vs. cloud mode
- Local-only mode (no account): all data stays on the device. Nothing is transmitted to our servers. Deleting the app deletes the data.
- Cloud mode (optional email/password account): the data categories above, minus photos, sync to our backend (Cloudflare Workers/D1) so a guardian can restore or use a second device. Transport is encrypted (HTTPS). Photos and raw camera data never sync.
You can switch a local-only account to a cloud account later; you will be shown what will be synced before it happens.
4. Children's data and guardian consent
The account holder must be an adult parent or guardian. The app requires explicit, versioned guardian confirmation before any child information is entered, and again before cloud sync is enabled. Guardians can review, edit, export, and delete each child's data at any time (Family tab). Where local law requires additional consent for processing children's data, the guardian provides that consent as the child's legal representative. adapt this section to COPPA/GDPR-K/APPI or other applicable regimes.
5. What we never do
- No advertising and no third-party ad SDKs.
- No sale, rental, or brokerage of data.
- No tracking across apps/websites and no device fingerprinting.
- No third-party analytics SDKs; the app's analytics interface is a no-op.
- No use of child or health data for profiling or unrelated purposes.
- No AI training on your data.
6. Processors
Cloud-mode data is stored with Cloudflare, Inc. (Workers/D1) as our hosting processor. Subscriptions are processed by Apple; we receive Apple-signed subscription state, never your payment details. list any additional processors and applicable transfer mechanisms.
7. Your rights: export and deletion
- Export: Family tab → Privacy → Export data produces a complete machine-readable copy (JSON; measurements also as CSV).
- Delete a child profile: removes that child's records everywhere (device, and server in cloud mode).
- Delete account: Family tab → Privacy → Delete Account immediately and permanently deletes all server data (children, measurements, scans, habits, entitlement records, sessions). We do not claim deletion before it has completed.
- Depending on your jurisdiction you may have additional rights (access, rectification, portability, complaint to a supervisory authority). Contact shiro.kawai@icloud.com.
8. Retention and security
Cloud data is retained while the account exists and deleted on account deletion. Access tokens are short-lived; credentials are stored in the device Keychain. Server logs contain request metadata only — never health values, tokens, or child data. See the project's published security policy (SECURITY.md) for vulnerability reporting.
9. Subscriptions
Premium features are unlocked by an auto-renewable subscription billed through your Apple account. Price and terms are shown before purchase; manage or cancel in iOS Settings → Apple Account → Subscriptions. See the Terms of Service for details.
10. Changes
We will announce material changes in-app before they take effect and update the effective date above. Continued use after the effective date constitutes acceptance where permitted by law.
日本語
1. 本アプリについて
「理論身長マックス」は、運営者名 が運営する、家族向けの ウェルネス・記録アプリです。保護者がお子さまの身長・体重を記録し、 成人身長の推定レンジ(はば) を確認できます。本アプリは医療機器では なく、診断・医学的助言を行うものではありません。
2. 取り扱うデータ
必要最小限のデータのみを取り扱います。
- お子さまのプロフィール: ニックネーム(本名は不要)、生年月日、 成長基準の計算に用いる性別区分、基準データ選択のための国・地域
- 成長記録: 日付つきの身長・体重(手入力または端末上で処理される 任意の「成長スキャン」由来)、測定方法・品質メモ・修正履歴
- 生物学的親の身長(任意・「わからない」選択可): 公表されている ミッドパレンタル法の計算のみに使用
- スキャン由来のメタデータ: 体の部位の比率・長さ、信頼度、方式、 品質フラグ。カメラの生フレームは端末内で処理され、既定では保存 されず、アップロードもされません。 写真の保持は別途の明示的な オプトインで、端末内にのみ保存されます。
- 習慣データ: 保護者が承認したルーティンとその達成記録
- アカウントデータ(クラウドモードのみ): ハッシュ化された メールアドレス・ソルト付きパスワードハッシュ・セッション記録
- サブスクリプション状態: 購読の有効性確認に必要な Apple 署名済み トランザクション情報
本名・住所・学校名・正確な位置情報・連絡先・広告識別子・顔認識データは 収集しません。スキャンにおける人体・顔の検出はフレーミングと プライバシーマスクのためだけに行い、個人の識別や生体テンプレートの 作成は行いません。
3. ローカルのみモードとクラウドモード
- ローカルのみモード(アカウント不要): すべてのデータは端末内に 保存され、当社サーバーには一切送信されません。アプリを削除すると データも削除されます。
- クラウドモード(任意のメールアドレス/パスワードアカウント): 上記データ(写真を 除く)が当社バックエンド(Cloudflare Workers/D1)に同期され、復元や 複数端末での利用が可能になります。通信は暗号化(HTTPS)されます。 写真とカメラの生データは同期されません。
ローカルのみモードは後からクラウドモードへ移行できます。移行前に、 同期される内容が表示されます。
4. お子さまのデータと保護者の同意
アカウント保有者は成人の保護者に限ります。お子さまの情報の入力前、 およびクラウド同期の有効化前に、明示的でバージョン管理された保護者の 確認を求めます。保護者はいつでも各お子さまのデータを閲覧・編集・ 書き出し・削除できます(ファミリータブ)。 個人情報保護法その他適用法令に応じて本節を調整してください。
5. 当社が行わないこと
- 広告表示・広告SDKの組み込みは行いません。
- データの販売・貸与・仲介は行いません。
- アプリ・サイト横断のトラッキング、端末フィンガープリンティングは 行いません。
- サードパーティ解析SDKは使用しません。
- お子さま・健康関連データをプロファイリングや無関係な目的に使用 しません。
- お客様のデータでAIの学習を行いません。
6. 委託先
クラウドモードのデータは Cloudflare, Inc.(Workers/D1)に保管されます。 サブスクリプションの決済は Apple が行い、当社が受け取るのは Apple 署名 済みの購読状態のみで、支払い情報は受け取りません。 その他の委託先・越境移転の枠組みがあれば記載してください。
7. 書き出しと削除の権利
- 書き出し: ファミリータブ → プライバシー → データを書き出す (JSON、測定値はCSVも可)
- お子さまプロフィールの削除: 端末および(クラウドモードでは) サーバーから該当データを削除します。
- アカウント削除: ファミリータブ → プライバシー → アカウントを削除。 サーバー上の全データ(お子さま情報・測定・スキャン・習慣・購読記録・ セッション)を直ちに完全削除します。削除完了前に完了と表示することは ありません。
- 法令に基づく開示・訂正等のご請求は 連絡先 までご連絡 ください。
8. 保存期間とセキュリティ
クラウドデータはアカウント存続中のみ保持し、アカウント削除時に削除 します。アクセストークンは短寿命で、認証情報は端末のキーチェーンに 保存されます。サーバーログにはリクエストのメタデータのみが記録され、 健康数値・トークン・お子さまのデータは記録されません。
9. サブスクリプション
プレミアム機能は Apple アカウントに課金される自動更新サブスクリプション で提供されます。価格と条件は購入前に表示されます。解約・管理は iOS の 「設定」→ Apple Account →「サブスクリプション」から行えます。詳細は 利用規約をご覧ください。
10. 変更
重要な変更は施行前にアプリ内で告知し、冒頭の施行日を更新します。