Privacy Policy

Updated: September 29, 2026

Yoshifumi Kanno (the “Operator”) explains below how SyncFlow and its related services (the “Service”) handle information. Reviewing this Policy is separate from agreeing to the Terms.

For additional disclosures and rights concerning Washington and Nevada consumer health data, see the separate Consumer Health Data Privacy Policy (Washington and Nevada).

1. Information handled on the device

SyncFlow applies iOS Data Protection and backup exclusion to Sync History and Widget storage, but cannot promise exclusion under every OS or environment condition. Currently, the Operator provides no Sync History cloud restore, cross-device transfer, iCloud/CloudKit History storage, or backup service. Uninstalling the app, replacing or losing a device, corruption, or deletion may permanently remove that history. Whether Apple Health samples sync through or remain in iCloud follows Apple's services and your device settings.

2. Information received from the Google Health API (Google user data)

This section explains how SyncFlow accesses, uses, stores, shares, retains, and deletes information it receives through the Google Health API when you connect SyncFlow to Google Health (“Google user data”).

2.1 Data accessed and permissions

SyncFlow requests read-only permissions and never writes data to Google Health. It requests only the permissions needed for the categories you enable for sync.

When you sign in, Google Sign-In for iOS may return basic Google Account information (such as name, email address, and profile picture) to the device. SyncFlow does not currently use, store, or transmit it.

A Google permission can cover a broader family of data types than the categories you enable. SyncFlow reads only the data types that correspond to the categories you enable. You may grant only some permissions on the consent screen; categories whose permission is not granted are not synced.

2.2 Use

Google user data is used only to provide and improve user-facing SyncFlow features, such as writing the categories you select into Apple Health (HealthKit) on the same device during a manual sync you start or an automatic sync you enable, and, for that purpose, verifying the account and determining the sync start date. It is not used to serve, target, or measure advertising, for usage analytics, for marketing, for sale, for credit-worthiness or lending decisions, for medical decisions, or to develop, improve, or train generalized artificial intelligence or machine learning models.

2.3 Processing and storage

2.4 Sharing

Google user data is not sold. Any transfer to a third party is made only as permitted by the Limited Use requirements. Currently, SyncFlow passes Google user data only to Apple Health on the same device as the result of a sync you request.

2.5 Retention, disconnection, and deletion

2.6 Limited Use

The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.

SyncFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Information handled by the Operator's server

Currently, the Operator's server does not store Fitbit tokens, Google authorization data or access tokens, Google Health user identifiers, HealthKit samples, data received from Google Health, health measurements, Sync History categories/ranges/outcomes/counts, or arbitrary provider error text.

4. Analytics, ads, purchases, and diagnostics

5. Support, surveys, and feedback

For a bug report, the email or Google Forms destination may visibly prefill information such as the request type, app and build, platform and OS, device family, locale, entry surface, fixed diagnostic context, and a recent Sentry Event ID only when one already exists. For a question or feature request, a minimal set of app and device context may be prefilled. You can review and edit destination content before sending. Health or sync detail, run keys, credentials, raw errors, and provider payloads are not prefilled. Google, email providers, and the Operator may process the content and attachments you choose to send, plus ordinary web information such as IP address and browser data, to provide support.

The Operator may conduct optional surveys, feedback requests, requests for opinions or suggestions, and other research to improve the Service, develop features, understand usage, or make other operational decisions. These activities may collect usage information, purposes of use, requests, ratings, free-form responses, and other information identified in the relevant survey, and may use external services such as Google Forms to collect and manage responses.

6. Purposes

Information is used for purposes such as performing sync, showing local History and Widgets, making an additional Auto Sync attempt, sending announcements, showing subscription offers and verifying purchases, preserving settings, operating, measuring, and improving the Service and feature use (Product Measurement, regardless of the Usage Analytics setting), analyzing general use with Firebase Analytics while the Usage Analytics setting is enabled, serving ads, preventing failures and abuse, answering support, managing legal versions, and meeting legal or platform requirements. Health measurements, HealthKit or Fitbit samples, data received from Google Health, health categories, sync ranges/counts, run IDs, and credentials are not sold or used for ad targeting, general analytics, or marketing. General screen, ad-placement, paywall, purchase-flow, and post-sync ad-surface events disclosed above may be processed.

The Operator may create and use statistical or aggregated information that does not identify individuals. Google user data is used for this purpose only in aggregated and anonymized form as permitted by the Limited Use requirements.

7. Providers and international processing

The Service uses providers such as Apple Health / HealthKit, Fitbit, Google Health API, Google Sign-In, Firebase Authentication / App Check / Analytics / Remote Config, Google Cloud, Expo Push Service, RevenueCat, Sentry, Google AdMob / UMP, Google Forms, email providers, and other service providers that help operate the Service. They may process information outside your country under their terms, policies, and applicable transfer safeguards.

The Operator selects and uses external providers that implement safeguards required by applicable law and platform rules.

The Operator may disclose information when required by law or by a valid request from a public authority, or to protect the rights, property, or safety of users, the Operator, or others, or the Service, as permitted by law. Google user data is disclosed for these reasons only as permitted by the Limited Use requirements.

8. Retention

9. Deletion, choices, and rights

“Delete Synced Data and History” deletes local Sync History, Widget data, cursors, and SyncFlow-authored HealthKit data, but not the Fitbit connection, Apple purchase, legal confirmation, or account. “Delete Account” attempts deletion of the Operator-controlled user aggregate, push registration, legal confirmations, local installation ID, local history and credentials, and SyncFlow-authored HealthKit data. It also asks Google to revoke SyncFlow's Google Health access. Revoking Fitbit access, deleting Apple's transaction records, and canceling an Apple subscription are separate actions. See Section 2.5 for disconnecting Google Health and revoking Google access.

Usage Analytics may be disabled under About SyncFlow > Usage at any time, which stops future collection and resets the app analytics identifier. You may use the Service while Analytics is disabled.

If you do not confirm a new Terms or Policy version, or the documents cannot be retrieved, the app may still offer basic functions such as Delete Account on a limited screen. Firebase may still process data to retrieve legal documents, resolve an existing account, or enforce an analytics-disabled boundary.

Depending on your location, you may request access, correction, deletion, restriction, objection, withdrawal, portability, or complain to an authority. Identity verification and lawful exceptions may apply.

10. Security and incidents

The Operator uses reasonable safeguards such as encrypted transport, authentication, App Check, least privilege, device protection, backup exclusion, validation, minimized diagnostics, and deletion controls. No system is perfectly secure. Incidents will be investigated and notified where applicable law requires.

11. Children, business transfers, changes, and contact

The Service is not directed to children. Do not use it unless you have reached the minimum age to consent independently under the laws, platform, and health services applicable to you.

In a merger, acquisition, business transfer, or similar transaction, information may be transferred to the successor. Google user data is transferred in such a transaction only after the Operator obtains your explicit prior consent, as required by the Google API Services User Data Policy, including the Limited Use requirements.

The Operator may update this Policy. Unless applicable law requires otherwise, an update takes effect when it is posted on this page. For material changes, the Operator will give notice in the app or on this page and will obtain your consent where applicable law requires it. Before using Google user data in a new way or for a purpose not described in this Policy, the Operator will notify you and ask for your consent to the updated Policy, as required by the Google API Services User Data Policy.

Operator: Yoshifumi Kanno
Email: sync.health.app@gmail.com
Address and phone number will be disclosed without delay upon a legally valid request.

プライバシーポリシー

更新日:2026年9月29日

Yoshifumi Kanno(以下「運営者」)は、SyncFlowアプリおよび関連サービス(以下「本サービス」)における情報の取扱いを、次のとおり説明します。本ポリシーの確認は、利用規約への同意とは別の行為です。

Washington州およびNevada州の消費者健康データに関する追加開示と権利は、英語のConsumer Health Data Privacy Policy (Washington and Nevada)をご確認ください。

1. 端末内で取り扱う情報

Sync HistoryとWidget領域にはiOSのData Protectionおよびバックアップ除外を適用します。ただし、OSや利用環境を含む全ての状況で除外を絶対に保証するものではありません。現在、運営者はSync History用のiCloud・CloudKit、クラウド復元、端末間移行またはバックアップサービスを提供しません。アンインストール、端末交換、故障、データ破損または削除により履歴を失う場合があります。Apple Health内のサンプルがiCloud等で同期・保持されるかは、Appleのサービスと利用者の端末設定に従います。

2. Google Health APIから受け取る情報(Googleユーザーデータ)

本項は、利用者がSyncFlowをGoogle Healthに接続した場合に、Google Health APIを通じて受け取る情報(以下「Googleユーザーデータ」)の取得、利用、保存、共有、保持および削除を説明します。

2.1 取得する情報と権限

SyncFlowは読み取り専用の権限だけを要求し、Google Healthへデータを書き込みません。権限は、利用者が同期対象として有効にしたカテゴリに必要なものだけを要求します。

Google Sign-In for iOSは、ログイン時にGoogleアカウントの基本情報(氏名、メールアドレス、プロフィール画像等)を端末へ返す場合があります。SyncFlowは現在、これらを使用、保存または送信していません。

Googleの権限は、有効にしたカテゴリより広いデータ種類をまとめて対象とする場合があります。その場合でも、SyncFlowは有効にしたカテゴリに対応するデータ種類だけを読み取ります。利用者は同意画面で一部の権限だけを許可でき、許可されなかった権限のカテゴリは同期されません。

2.2 利用目的

Googleユーザーデータは、利用者に提供するSyncFlowの機能の提供と改善にだけ使用します。例えば、手動同期または利用者が有効にした自動同期の実行時に、選択したカテゴリを同じ端末のApple Health(HealthKit)へ書き込むこと、およびそのためのアカウント確認と同期開始日の決定です。Googleユーザーデータを広告の表示・ターゲティング・効果測定、利用状況分析、マーケティング、データの販売、信用力の判断・融資、医療上の判断、または汎用的なAI・機械学習モデルの開発・改善・学習には使用しません。

2.3 処理と保存の場所

2.4 共有

Googleユーザーデータを販売しません。第三者への移転は、Limited Use要件が認める範囲に限ります。現在、SyncFlowがGoogleユーザーデータを渡す先は、利用者が要求した同期による同じ端末のApple Healthだけです。

2.5 保持、接続解除および削除

2.6 Limited Use

The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.

SyncFlowによるGoogle APIから受け取った情報の利用および他のアプリへの移転は、Limited Use要件を含むGoogle API Services User Data Policyに従います。

3. 運営者のサーバーで取り扱う情報

現在、運営者のサーバーへ、Fitbitトークン、Googleの認可情報・アクセストークン、Google Healthのユーザー識別子、HealthKitサンプル、Google Healthから受け取ったデータ、健康測定値、Sync Historyのカテゴリ・期間・結果・件数、または任意のプロバイダーエラー本文を保存していません。

4. 分析、広告、購入および障害診断

5. 問い合わせ・アンケート等

不具合報告では、メールまたはGoogle Formsの送信内容に、利用者が確認・編集できる状態で、問い合わせ種別、アプリ版・ビルド、プラットフォーム・OS、端末ファミリー、言語、開始画面、固定された診断コンテキスト、既に存在する場合に限る直近のSentry Event ID等を事前入力する場合があります。質問・機能要望では、最小限のアプリ・端末情報を事前入力する場合があります。健康・同期の詳細、Run Key、資格情報、生エラーまたはプロバイダーのPayloadを事前入力しません。問い合わせ本文、利用者が選んだ添付、IPアドレスやブラウザ情報等はGoogle、メール事業者および運営者がサポート対応のため処理する場合があります。

運営者は、本サービスの改善、機能開発、利用状況の把握その他の運営上の判断のため、任意のアンケート、フィードバック、意見・要望の募集その他の調査を実施する場合があります。これらでは、利用状況、利用目的、要望、評価、自由記述その他各調査で案内する情報を取得し、Google Forms等の外部サービスを通じて収集・管理する場合があります。

6. 利用目的

同期の実行、ローカル履歴・Widget表示、自動同期の追加試行、お知らせの配信、サブスクリプションの案内と購入権利確認、設定維持、本サービスと機能利用の運営・計測・改善(利用状況分析の設定にかかわらないProduct Measurement)、利用状況分析の設定が有効な間のFirebase Analyticsによる一般的な利用状況の分析、広告、障害・不正利用の防止、問い合わせ対応、法的文書の版管理、法令・プラットフォーム要件への対応等の目的に利用します。健康測定値、HealthKit・Fitbitサンプル、Google Healthから受け取ったデータ、健康カテゴリ、同期範囲・件数、Run IDまたは資格情報を販売せず、広告ターゲティング・一般分析・マーケティングに利用しません。前項で開示した一般的な画面、広告配置、ペイウォール、購入フローおよび同期完了後の広告面に関するイベントは処理される場合があります。

運営者は、個人を識別できない統計情報・集計情報を作成し、利用する場合があります。Googleユーザーデータをこの目的に利用するのは、Limited Use要件が認める範囲で集計・匿名化された形式の場合に限ります。

7. 外部事業者と国外処理

本サービスはApple Health / HealthKit、Fitbit、Google Health API、Google Sign-In、Firebase Authentication / App Check / Analytics / Remote Config、Google Cloud、Expo Push Service、RevenueCat、Sentry、Google AdMob / UMP、Google Forms、メール事業者、その他本サービスの運営を支援する事業者等を利用します。これらの事業者は日本国外を含む地域で、各社の規約、ポリシーおよび法的保護措置に基づき情報を処理する場合があります。

運営者は、利用者の情報を取り扱う外部事業者として、適用法令およびプラットフォーム規則が求める保護措置を講じる事業者を選定して利用します。

運営者は、法令に基づく場合、公的機関からの有効な要請がある場合、または利用者、運営者その他の者もしくは本サービスの権利、財産もしくは安全を保護するため、法令が認める範囲で情報を開示する場合があります。Googleユーザーデータをこれらの理由で開示するのは、Limited Use要件が認める範囲に限ります。

8. 保存期間

9. 削除、選択および権利

「同期済みデータと履歴を削除」は、ローカルSync History、Widget、同期カーソルおよびSyncFlowが書き込んだHealthKitデータを削除しますが、Fitbit接続、Appleの購入、法的確認またはアカウント自体を削除しません。「アカウントを削除」は、運営者のユーザー集約、Push登録、法的確認、端末のインストール識別子、ローカル履歴・認証情報、およびSyncFlowが書き込んだHealthKitデータの削除を試みます。また、SyncFlowのGoogle Healthへのアクセス許可の取消しを要求します。Fitbit側の許可取消し、Appleの取引記録削除およびサブスクリプション解約は別の手続です。Google Healthの接続解除とアクセス許可の取消しは第2.5項をご確認ください。

利用状況分析は「このアプリについて > 利用状況」でいつでも無効にでき、無効化時に将来の収集を停止してアプリ分析識別子をリセットします。無効にしても本サービスを利用できます。

新しい規約・ポリシーを確認しない場合または文書を取得できない場合でも、限定画面からアカウント削除等の基本的な機能を利用できる場合があります。Firebaseは、法的文書の取得、既存アカウントの判定または分析収集を停止する境界の適用のため処理する場合があります。

居住地域に応じて、アクセス、訂正、削除、処理制限、異議申立て、同意撤回、データ移転または監督機関への申立てを行える場合があります。本人確認および法令上許される例外を適用することがあります。

10. 安全管理とインシデント

通信暗号化、認証、App Check、最小権限、端末保護、バックアップ除外、入力検証、診断最小化、削除手段等の合理的な対策を講じます。完全な安全性は保証できません。適用法令上必要な場合、インシデントを調査し、利用者または当局へ通知します。

11. 子ども・事業承継・改定・連絡先

本サービスは子ども向けではありません。居住地域および利用するプラットフォーム・健康サービスについて有効な同意を単独で行える最低年齢に達していない方は利用しないでください。

合併、買収、事業譲渡その他これらに類する取引に伴い、情報を承継者へ移転する場合があります。この場合でも、Googleユーザーデータは、Limited Use要件を含むGoogle API Services User Data Policyが求めるとおり、利用者の明示的な事前の同意を得た後にだけ移転します。

運営者は本ポリシーを改定することがあります。法令上別段の定めがある場合を除き、改定は本ページへの掲載時に効力を生じます。重要な変更については、アプリ内または本ページで通知し、法令上必要な場合は利用者の同意を得ます。Googleユーザーデータを新しい方法で、または本ポリシーに記載のない目的で利用する前には、Google API Services User Data Policyが求めるとおり、利用者に通知し、改定後のポリシーへの同意を求めます。

運営者:Yoshifumi Kanno
メール:sync.health.app@gmail.com
住所・電話番号は、法令に基づく請求があった場合に遅滞なく開示します。