CC31 Calendar
Privacy Policy
CC31 (the "Operator") establishes this policy for information handled by CC31 Calendar (the "App") and pages related to the App (collectively, the "Service"). The App does not create login accounts. The Operator does not store calendar events or the contents of in-App memos on servers managed by the Operator.
1. Information handled on the device
The App processes the following information on the user's device to provide its features and does not send it to servers managed by the Operator. Google Calendar sync means that the App reads and writes calendars already configured on the device through iOS Calendar (EventKit); the App does not use a separate Google login or the Google Calendar API. However, events stored in the device calendar may be synchronized by iCloud, Google, or another calendar provider configured by the user. The applicable provider's terms and privacy policy govern that processing.
- Calendar events (title, date and time, location, attendees, notes, and similar fields)
- Memos created in the App
- On-device cached images attached to events
- On-device shared data used by widgets
- Notification settings
2. Information handled through external services
The App handles the following information through external services for in-app purchases, advertising, and usage analysis. The Operator does not collect credit-card numbers or other payment-instrument details. Apple App Store processes payments.
- Purchase history, transaction information, anonymous app user IDs, device and operating-system technical information, and identifiers associated with enabled integrations, as processed by RevenueCat
- Usage data processed by Firebase Analytics, including app launches, interaction events, app instance IDs, and device and app information. The App controls collection according to the permission status described in section 4
- Advertising identifiers when their use is authorized, device information, approximate location inferred from IP addresses, ad interaction data, and identifiers used to deliver ads, as processed by Google AdMob
3. Purposes of use
- To provide and operate the App and related services
- To display and edit calendars and memos on the device
- To manage in-app purchases, restore purchase status, and prevent fraud
- To understand usage and improve the App when tracking is authorized
- To deliver advertising and measure ad performance
- To handle feedback and inquiries
4. App Tracking Transparency (ATT)
On iOS 14.5 and later, the App requests permission under App Tracking Transparency (ATT) before tracking by linking information from the App with information from other companies' apps or websites, or accessing the advertising identifier (IDFA). ATT permission does not replace any separate consent for advertising or analytics required by applicable law or in a particular region.
- If you allow tracking, the advertising identifier may be used for personalized ads, ad measurement, and, depending on configuration, Firebase Analytics
- If you do not allow tracking, you can still use the App. The App displays non-personalized or limited ads and disables Firebase Analytics collection. Google AdMob may still process IP addresses, device information, and information other than the IDFA as necessary to deliver ads, prevent fraud, maintain security, or perform basic measurement
- You can change this later in iOS Settings > Privacy & Security > Tracking
5. External services and international processing
The Operator uses the external services listed below. These providers may process information in the United States or other countries outside Japan. The Operator reviews their contractual terms and privacy safeguards and requires protections necessary under applicable law and this policy. Except where required by law, the Operator does not provide information to third parties beyond what is necessary for the stated purposes. You may request information about international processing and relevant safeguards through the contact channel in section 12.
- Apple App Store: payment and purchase processing (https://www.apple.com/legal/privacy/)
- RevenueCat: purchase-status management and fraud prevention (https://www.revenuecat.com/privacy-policy/)
- Google (Firebase Analytics, Google AdMob, and inquiry email): usage analytics, ad delivery, ad measurement, and inquiry handling (https://policies.google.com/privacy)
- Cloudflare (Pages, Workers, D1, and Turnstile): delivery of related pages, feedback storage, and automated-submission protection (https://www.cloudflare.com/privacypolicy/)
- Slack: new-feedback notifications (https://slack.com/privacy-policy)
6. Feedback that does not request direct identifiers
The official website's feedback form does not request a name, address, phone number, or email address as an input field, but it receives the information listed below. If you enter personal information about yourself or another person in the free-text field, the Operator, Cloudflare, and Slack as the notification provider will also process that information. Do not enter personal information.
- Feedback category and message
- A public app ID identifying the applicable App
- A submission ID used to prevent duplicate submissions
- Time received and handling status
7. In-app contact
The in-App contact form may collect a name and email address if the user chooses to enter them. The Operator uses that information to handle the inquiry, contact the user, and maintain a response history. Quick feedback sent from the rating prompt does not ask for a name or email address.
8. Feedback storage, automated-submission protection, and retention
Feedback is stored in Cloudflare D1. Submission information, including the message, is sent to Slack to notify the Operator of a new submission. The Operator uses Cloudflare Turnstile to prevent automated submissions. Turnstile processes browser-environment and other signals necessary for fraud detection, and its verification token is sent to Cloudflare's Siteverify API. The Operator does not send the feedback message or other form fields to the Siteverify API and does not store Turnstile tokens or verification results in its database.
Information held in D1, Slack, or inquiry-response records is retained only for as long as necessary to review and address the submission, prevent abuse, maintain security, or respond to legal claims. Once the purpose has been fulfilled and retention is no longer required by law or for dispute handling, the Operator periodically reviews the information and deletes it or makes it unavailable for use. Information retained independently by an external provider is also subject to that provider's retention and deletion policy.
9. Children
The Service is not directed to children under 13. If the Operator learns that it has obtained personal information from a child under 13, the Operator will promptly delete information that it can identify, unless retention is required by law. A parent or guardian may contact the Operator using the channel in section 12.
10. Security, user rights, and request procedure
The Operator applies access controls, permission management, and other necessary and appropriate safeguards. Subject to applicable law, users may request access to, correction of, restriction of, deletion of, or cessation of third-party disclosure of information about themselves. Submit a request through the channel in section 12 and provide information necessary to identify the relevant data. The Operator will verify the requester's identity and respond in accordance with applicable law. If the Operator cannot fulfill the request, it will explain the reason. The Operator will give advance notice of any applicable fee.
In-App memos, image caches, widget data, and settings can be deleted through available in-App controls, device settings, or by deleting the App. Events written to a device calendar are not deleted when the App is deleted; delete those events using iOS Calendar or the applicable calendar provider's service. Because the feedback form does not request direct identifiers, the Operator may be unable to identify the requester or locate the relevant submission.
11. Changes to this policy
The Operator may update this policy when the Service, external services, or applicable law changes. Material changes will be announced in the App or on the official website with reasonable advance notice. The Operator will obtain consent where applicable law requires it.
12. Operator information and contact
CC31 is the entity responsible for handling personal information. For questions or requests concerning this policy, international processing, safeguards, or user rights, use the official contact channel or email isajiappdev@gmail.com. The Operator will, upon a data subject's request and without undue delay, provide the Operator's legal name and address and, if the Operator is a corporation, the name of its representative, to the extent disclosure is required by law.