CocoMemo Privacy Policy
QuickServe Inc. ("we", "us") sets out below how user information is handled in CocoMemo (the "App"), our location-based to-do reminder app (this "Policy").
1. Company information (data controller)
- Name: QuickServe Inc.
- Address: Sakurai Bldg. 2F, 2-8-19 Fukagawa, Koto-ku, Tokyo 135-0033, Japan
- Contact: info@91932.com / Tel. +81-3-6450-5141 (weekdays 10:00–19:00 JST)
- Personal data protection manager: Manager, Systems Development Department
Where the GDPR or similar laws apply, QuickServe Inc. is the data controller for the App.
2. Scope and authoritative version
This Policy applies only to the App. Our other apps are covered by our common app privacy policy. This document is independent of the privacy policy on our corporate website. The Japanese version of this Policy is authoritative; if there is any discrepancy with a translation, the Japanese version prevails.
3. Information the App stores on your device
The App can be used without registering your name, email address or similar information, and we do not directly collect such information from you. The data below is stored on your device and is never sent to our servers (except for the sharing features in Section 4 and the backups in Section 6). We cannot access this data.
| Data | Source | Purpose |
|---|---|---|
| Location (GPS) including background collection | Your device's location services | Detecting when you approach a saved place and notifying you; showing your current position on the map; the initial position when saving a place |
| Saved places (coordinates, place name, radius) | Your actions on the map, and place names obtained from coordinates (Section 5) | Linking memos to places, proximity detection, map display. Places attached to shared memos are also synced to the people you share with (Section 4) |
| My memos (title, note, due date, completion status, history) | Entered by you and generated in the App | Displaying memos, notifications and history |
| Recovery code (plain text) | Generated in the App | Transferring to a new device (Section 4). Stored in your device's secure storage |
| App settings | Your actions in the App | Storing notification and display preferences |
You can delete this data from within the App, and uninstalling the App removes it from your device (except for the backups described in Section 6).
4. Information stored on our servers (Firebase)
To provide the App's sharing, device-transfer and premium features, we store the information below in Google's Firebase (Cloud Firestore / Firebase Authentication / Cloud Functions), which we use as our backend. Your current location and your location history are never sent to our servers. However, the place you attach to a shared memo (coordinates, place name, address and notification radius) is stored on our servers as part of that memo and shown to the group members, so that their devices can notify them at the same place.
| Data | Details | Purpose | Who can see it |
|---|---|---|---|
| Anonymous account | A user identifier issued by Firebase (contains no name or email address) | Identifying the owner and participants of shared data | Us only |
| Profile | Nickname, a hash of your recovery code (the code itself is not stored), push notification tokens, premium plan status / expiry / product ID | Display within groups, device transfer, delivering comment notifications, providing premium features | You and us only |
| Groups | Group name, identifiers of the creator and members | Managing who you share with | Group members |
| Friend memos (shared memos) | Title, note, due date, completion status, the attached place (coordinates, place name, address, notification radius), creator identifier, last-updated time | Sharing and syncing with group members | The people you share with (group members) |
| Comments | Text, author identifier, timestamp | Conversation on a shared memo; push notifications to participants | Participants of that shared memo |
| Invitations | Target group, inviter identifier, expiry, whether used | Joining a group via QR code or link | The person who issued the invitation |
| Deletion marker | A record containing only your user identifier and the time of deletion, created when you delete your account | Prevents data from being re-created with the old account's credentials immediately after deletion. Automatically removed 2 hours after creation | Us only |
Shared memos, comments and your nickname are visible to the people you invite (group members). The place attached to a shared memo (coordinates, place name, address) is also visible to them. Please do not put any content or place in a shared memo that you do not want them to see. We do not view or use this information for any purpose other than providing and maintaining the service and the purposes set out in this Policy.
The recovery code lets you carry over the same anonymous account (groups and premium status) by entering it on a new device. Because only a hash of the code is stored on our servers, we cannot recover or reissue a lost code.
You can delete your anonymous account and the data in this section at any time from "Settings > Account > Delete account" in the App. See CocoMemo Account and Data Deletion for the list of what is deleted and what is retained.
5. How location data is handled
The core function of the App is to notify you when you approach a saved place, which requires background location access ("Always") so that notifications work while the App is closed. Location is only collected if you grant permission in your operating system's dialog, and you can change or revoke it at any time in your device settings.
Proximity to a place is determined on your device using the OS geofencing feature. Your current location and location history are never sent to our servers, and location data is never used for advertising or ad targeting, nor provided to third parties for any other purpose (for places you attach to shared memos, see Section 4).
However, coordinates are passed to the following OS / platform features for map and place-name display.
- Google Maps SDK: To display the map, information about the visible area and your current position is sent to Google's servers (Google Privacy Policy).
- Reverse geocoding (obtaining place names): When you save a place, coordinates are sent to the standard OS geocoder (Apple on iOS, Google on Android) to obtain a place name. We never receive these coordinates.
6. How backups are handled
If your device's OS backup (iCloud Backup / Google Backup) is enabled, a copy of the App's on-device data may be kept on that OS provider's servers and restored when you reinstall. These copies remain even after you delete the App, so please remove them from your OS backup settings if you no longer need them.
7. Information collected by third-party SDKs
The App uses the following third-party SDKs for advertising, quality improvement and abuse prevention. These SDKs automatically collect the information below and send it to servers operated by Google LLC and its affiliates ("Google").
| SDK | Main information collected | Purpose |
|---|---|---|
| Google AdMob (ad delivery) | Advertising ID (IDFA on iOS / Advertising ID on Android — collected only where permitted by OS settings, applicable law and your consent), ad impression and interaction events, IP address (including inference of approximate location), device information (model, OS version, etc.) | Delivering ads, measuring their performance, preventing fraud (no ads are shown on the premium plan) |
| Firebase Crashlytics (crash reporting) | Crash logs, diagnostic and performance information, installation UUID, device and OS information | Diagnosing defects, improving quality |
| Firebase Cloud Messaging (push notifications) | Push notification token, device and OS information | Notifying you of comments on shared memos |
| Firebase App Check (abuse prevention) | Attestation tokens proving the integrity of the device and App (Apple DeviceCheck / Google Play Integrity) | Preventing unauthorized access to our servers |
The App does not use Firebase Analytics or any other usage-analytics SDK. Furthermore, the location data and memo contents described in Section 3 are never passed to these SDKs. The "approximate location" inferred by AdMob is derived from your IP address and is separate from the GPS location the App collects.
If you contact us, we collect your contact details (such as name and email address), the content of your enquiry and, where necessary, device and OS information, for the purpose of responding. We delete this information after a reasonable period once your enquiry has been resolved.
8. Premium plan (in-app purchases)
Premium plan purchases are made through the App Store (Apple) or Google Play (Google), and payment details (such as credit card numbers) are handled by Apple / Google. We never receive your payment details. We store the plan status, expiry and product ID in your profile (Section 4) and use them to provide premium features.
9. Disclosure to third parties and external transmission
We do not provide collected information to third parties, except as required by law and for transmission to the external service providers (such as Google and Apple) described in this Policy. Shared memos and similar data becoming visible to the people you invite through the sharing features in Section 4 is sharing at your own instruction and does not constitute disclosure to third parties by us.
Information sent through the SDKs and platform features in Sections 5 and 7 is handled by Google or Apple under their respective privacy policies. Depending on the processing, Google may act as an independent controller. Personalized advertising and cross-app tracking are carried out in accordance with applicable law and your consent status.
- Google Privacy Policy
- How Google uses information from sites or apps that use its services
- Privacy and Security in Firebase
- Apple Privacy Policy
10. International data transfers
Firebase (Section 4) and the SDKs in Section 7 transmit data to Google servers located in the United States and other countries outside Japan. Google applies appropriate safeguards, including compliance with the EU Standard Contractual Clauses. Details of the destinations and safeguards are available in "Privacy and Security in Firebase" and the other references above.
11. Managing consent and opting out
- Location, notifications and camera: You can change or revoke each permission at any time in your device settings. If you revoke them, the corresponding features (proximity notifications, scanning invitation QR codes, etc.) become unavailable.
- Stopping sharing: You can leave a group or delete a shared memo from within the App.
- Advertising: No ads are shown if you subscribe to the premium plan. On iOS you can manage tracking under Settings > Privacy & Security > Tracking; on Android you can reset or delete your advertising ID and opt out of personalized ads in the OS settings.
- Deleting data on our servers: You can delete your anonymous account and the data in Section 4 at any time from "Settings > Account > Delete account" in the App (shared memos will no longer be visible to the people you shared them with). If you can no longer use the App, contact us at the contact point in Section 15 and we will delete it within a reasonable period. See CocoMemo Account and Data Deletion for the steps and what is deleted.
12. Additional information for users in the EEA and the UK (GDPR / UK GDPR)
The legal bases for processing are as follows.
| Processing | Legal basis |
|---|---|
| Collecting location and detecting proximity on your device (on-device processing only) | Consent (OS permission grant) |
| Storing the anonymous account, profile, shared memos, comments and invitations on our servers (Section 4) | Performance of a contract (providing the sharing, device-transfer and premium features you request) |
| Delivering push notifications (comment notifications) | Performance of a contract (providing the sharing features). You can stop them in your OS notification settings |
| Storing and reading identifiers on your device (advertising ID, etc.) | Consent |
| Delivering personalized ads | Consent |
| Delivering ads without consent (limited ads) and preventing abuse (including App Check) | Legitimate interests (sustaining the free App, security) |
| Crash reporting (Crashlytics) | Legitimate interests (maintaining quality on a data-minimizing basis) |
| Complying with legal obligations | Legal obligation |
- Retention: Data on your device is retained until you delete it. Data on our servers (Section 4) is retained until you delete your account in the App or we receive a deletion request under Section 11 (the deletion marker is removed automatically 2 hours after creation). For data collected by Google, see Privacy and Security in Firebase and the Google advertising policies. Retention of enquiry information is described in Section 7.
- Your rights: You have the rights of access, rectification, erasure, restriction of processing, objection and data portability. Requests are accepted at the contact point in Section 15. For data held on your device and shared memos, you can view, edit and delete them directly in the App.
- Complaints: You have the right to lodge a complaint with the supervisory authority in your country.
- Voluntary provision: Providing information is not a statutory requirement. If you do not grant location access, proximity notifications will not work; if you do not use the sharing features, nothing is stored on our servers; the rest of the App remains usable.
- Automated decision-making: We do not carry out automated decision-making, including profiling, that produces legal effects.
13. Users in other regions
Depending on the laws of your region, you may have rights such as access, deletion and opt-out. Requests to exercise these rights are accepted at the contact point in Section 15.
14. Children
The App is not designed for children.
15. Requests for disclosure and contact point
Requests for disclosure, correction, suspension of use or deletion of retained personal data, and enquiries about this Policy, are accepted at the contact point below. For requests concerning an anonymous account, we may ask you to provide your recovery code or the user identifier shown in the App to verify that the account is yours. There is no fee.
QuickServe Inc. — Personal Data Enquiries
Email: info@91932.com
Tel: +81-3-6450-5141 (weekdays 10:00–19:00 JST)
Address: Sakurai Bldg. 2F, 2-8-19 Fukagawa, Koto-ku, Tokyo 135-0033, Japan
16. Changes to this Policy
We may revise this Policy in response to changes in law or in the App's functionality. For material changes (such as adding a new SDK, purpose or recipient, or changing how consent is handled), we will post a notice on this page and, where necessary, notify you in the App or obtain your consent again. A revised Policy takes effect when it is posted on this page.