プライバシーポリシー
最終更新: 2026-10-08
Lovy (以下「本サービス」) は、ユーザーが「好きな場所」を発信・発見するための ソーシャルマップです。本ポリシーは、本サービスが取得する情報、その利用目的、 ユーザーが行使できる権利を説明します。
ホームページのアクセス計測
lovy.world のホームページでは、改善のために PostHog(EU)で閲覧と App Store ボタンのクリックを計測します。ブラウザー情報(User-Agent)・端末の種類と参照元のドメインを送信しますが、URL のクエリ・ハッシュ、入力内容、Lovy のアカウント情報、画面録画は送信しません。計測用 Cookie や永続的な訪問者 ID は保存しません。PostHog は通信時の IP アドレスとブラウザー情報等から日ごとに変わる識別値を生成し、イベント保存前に IP アドレスと User-Agent を取り除きます。ホームページの「アクセス計測」でオフにでき、その選択だけをブラウザーに保存します。Do Not Track・Global Privacy Control による拒否も尊重します。
1. 取得する情報
- アカウント情報: Sign in with Apple、Google、またはメールアドレスで サインインした際のユーザー識別子・メールアドレス・表示名 (任意)・ アバター URL (任意)、およびユーザーがプロフィールに追加した自己紹介・ SNS リンク (任意)。
- 場所の記録: ユーザーが付けた評価 (7 段階)、コメント、 訪問履歴、投稿した写真・キャプション、リスト登録、投稿ごとの公開範囲、 フォロー・友達・マブダチを含むソーシャルグラフ。
- ディナー参加: この機能を利用する際に入力する生年月日、性別、国籍、 使ってみたい言語とそのレベル、食事条件と任意の補足、確認済みの連絡先メール、選択した日程、予約・決済・返金状況、 成立したグループ、Lovyが選ぶ会場と本人宛ての案内メッセージ。 入力プロフィールは本人が閲覧・編集でき、Lovyは参加準備のために利用します。 成立したグループの参加者には、 同席者の通常の表示名・ユーザー名・アバター、集合日時・場所と共通言語を表示します。 生年月日・性別・国籍・個人の言語一覧・レベル・食事条件と補足・連絡先メールは同席者に表示しません。 カード番号等の支払い情報は決済サービスの画面で入力し、Lovyでは保管しません。
- 個別共有: スポット、ログ、リスト等を Lovy 内で共有したときの 送信者・受信者のアカウント識別子、共有対象、および任意で入力したメッセージ。
- 友達とのメッセージ: 会話の参加者、本文、共有したスポット・ログの 識別子、送信時刻、および既読の状態を保存します。会話は現在友達である参加者だけが 閲覧でき、ブロックや友達解除後は閲覧・送信できません。通知には本文を載せません。 参加者のアカウントが削除されると、その参加者との会話とメッセージも削除されます。
- 問い合わせ・通報: アプリ内通報、または support@lovy.app / report@lovy.app 宛のメールに含まれる送信者情報、対象コンテンツ、理由、本文、 および任意の添付ファイル。
- スポットのストーリーとログ: 写真付きログは投稿後72時間、地図上の ストーリー欄で新着として強調表示します。ログ、写真、コメント、評価は72時間後も 保管され、投稿者本人と、投稿時に選択した公開範囲の対象ユーザーがスポット、フィード、 投稿者のログ履歴から閲覧できます。投稿者はログと写真を削除でき、他のユーザーは 不適切なコンテンツを通報または投稿者をブロックできます。
- 位置情報: 「使用中のみ」 の許可があった場合のみ、地図上で 現在地を表示し、周辺検索や Lovy 検索の候補を関連性の高い順に表示するために OS の位置情報サービスを利用します。検索時には現在地または表示中の地図範囲を Lovy のサーバへ送信し、スポット候補の取得のため Google Places に送信する場合が あります。座標は PostHog の分析イベントや Lovy の検索履歴には保存しません。
- 検索内容: Lovy 検索で入力した検索文、直前の会話文脈、および 候補スポット情報を、検索意図の解釈と候補の順位付けのため Anthropic、または フォールバックとして OpenAI に送信する場合があります。検索語と位置条件は Google Places にも送信される場合があります。Lovy は検索文を自社データベースや PostHog に検索履歴として保存しませんが、各事業者は自社の契約、設定、法令に従って リクエストを一時的に保持する場合があります。
- 端末・通知情報: プッシュ通知を登録する際に Lovy が発行する インストール識別子、Apple Push Notification service (APNs) のデバイストークン、 アプリ識別子、配信環境、アプリバージョン、言語・タイムゾーン、および登録状態。 通知を有効にしたアカウントに紐づけて管理します。
- 使用状況の分析: ログイン後のアカウント識別子と、検索の成否・ 候補の表示・スポットの閲覧や記録・フォロー・共有などの操作イベントを、 新しい場所との出会いと意思決定体験を改善するために取得します。検索語、座標、 氏名、メールアドレス、コメント・キャプション・メッセージ、URL、共有相手のIDは 分析イベントに含めません。セッションリプレイは使用しません。「マイページ → 右上の歯車 → 設定 → 利用状況の分析」から今後の送信を停止できます。
- 診断情報: 分析が有効な場合、アプリの起動などのライフサイクル情報と、 クラッシュ・エラーおよびその他の診断情報を PostHog が自動取得します。サインイン後は アカウント識別子に紐づく場合があります。正確な位置情報、検索語、投稿内容は診断情報に 含めず、上記の「利用状況の分析」をオフにすると今後の診断情報の送信も停止します。
2. 利用目的
- ユーザー個別の「Lovy マップ」を生成・表示するため
- 位置、検索内容、評価、ログ、信頼関係に基づくおすすめを表示するため
- サインインによる本人確認とアカウント管理のため
- 選択した相手への個別共有と、許可した通知を配信するため
- ディナー参加プロフィールと予約・決済状況を管理し、年齢条件を確認し、選択した日程、国籍と言語に応じて会話できるグループを作り、食事の配慮と会場案内を準備するため
- 問い合わせへの回答、通報の確認、違法・有害コンテンツへの対応のため
- 発見から記録・共有までの体験、継続利用、サービス品質を改善するため
3. 第三者提供
本サービスは、法令に基づく場合または本人の同意がある場合を除き、取得した 個人情報を販売せず、広告目的のクロスアプリ追跡を行いません。サービス提供に必要な 範囲で、主に以下の委託先・プラットフォームが情報を処理します。
- Supabase: 認証、データベース、写真等のストレージ。
- Resend: ディナーの必要な案内メールを本人の確認済み連絡先へ送信します。メールアドレスと開催日・支払い状況・公開時刻以降の会場案内を処理し、生年月日・性別・国籍・言語レベル・食事の補足は送信しません。
- Cloudflare Workers: ディナーの定時処理・再試行を起動します。参加プロフィールを送信しません。
- Stripe: ディナー参加の決済処理。予約識別子、参加日と金額を送信し、生年月日・性別・国籍・言語・食事制限は送信しません。
- Vercel: API と公開ページのホスティング、リクエスト処理、 セキュリティおよび運用ログ。
- PostHog EU Cloud: 上記の限定した分析イベントと診断情報。
- Google Places: 検索語、現在地または表示中の地図範囲を用いた スポット検索と情報取得。
- Anthropic / OpenAI: 検索文、限定した会話文脈、候補情報を用いた 検索意図の解釈、候補の分類・順位付け。
- Apple Push Notification service: デバイストークンと通知内容を 用いた、ユーザーが許可した通知の配信。
Sign in with Apple は Apple が中継するため、メールを非公開にした場合、本サービスには リレーアドレスのみが共有されます。Google でサインインした場合は、Google から認証に 必要なアカウント情報が共有されます。
4. データの保管
データは Supabase (PostgreSQL) を用いて暗号化された通信で保管されます。 Row Level Security (RLS) により、各ユーザーは自身に許可された範囲のデータ のみアクセスできます。分析イベントは PostHog EU Cloud へ暗号化通信で送信されます。 検索文そのものは Lovy のデータベースや PostHog に検索履歴として保存しませんが、 Google Places、Anthropic、OpenAI、Vercel は、サービス提供、セキュリティ、不正利用防止、 または法令遵守に必要な期間、各社の契約・設定に従ってリクエスト情報を保持する場合があります。 プッシュ通知の登録情報と個別共有メッセージは Supabase に保管されます。 ディナー参加プロフィール、予約・決済状況、本人宛ての案内も Supabase に保管し、 生年月日・性別・国籍・話せる言語・食事制限と補足を分析イベントや外部AIサービスへ送信しません。 アプリ内通報は Supabase、メールでの問い合わせ・通報は Lovy と送信者が利用する メールサービスで処理され、対応、セキュリティ、法令遵守に必要な期間保持する場合があります。 現在の写真配信には推測困難な公開URLを使用しているため、 URLを取得済みの相手による直接アクセスを公開範囲の変更と同時に無効化できない場合があります。
5. アカウントの削除
アプリ内の「マイページ → 右上の歯車 → 設定 → アカウントを削除」から、いつでも 削除をリクエストできます。削除後、ディナー参加プロフィール・参加希望・Lovyからの案内メッセージ、評価・ログ・写真・フォロー関係、プッシュ通知の 端末登録を含む、アカウントに直接紐づくデータは復元不可な形で削除されます。紐づいた PostHog の ユーザー、分析イベント、診断情報、録画データ(録画機能は現在無効)も削除処理の対象です。 決済の照合と返金対応に必要な予約識別子・決済事業者の識別子・参加日・金額・決済状態は、 アカウントとの紐づけを外して必要な範囲で保持します。生年月日・性別・国籍・言語・食事制限は保持しません。 ただし、既に他のユーザーへ配信された個別共有・通知のメッセージ、および問い合わせ・通報の 対応記録は、受信者の履歴、サービスの安全性、紛争対応、法令遵守に必要な範囲で残る場合があります。
6. 子どもの個人情報
本サービスは 13 歳未満の利用を想定していません。13 歳未満であることが 判明した場合は、当該アカウントを削除します。
7. 改訂
本ポリシーは予告なく改訂されることがあります。重要な変更がある場合は、 アプリ内通知または本ページの最終更新日で告知します。
8. 問い合わせ
本ポリシーに関するご質問は support@lovy.app までご連絡ください。
Privacy Policy (English)
Last updated: 2026-10-08
Lovy is a social map for sharing and discovering places you love. This policy explains what we collect, how we use it, and your rights.
Homepage analytics
On the lovy.world homepage, we use PostHog (EU) to measure page views and App Store button clicks to improve the website. We send browser information (User-Agent), device categories and the referring domain, but no URL query/hash, form contents, Lovy account information or screen recordings. We store no analytics cookies or persistent visitor IDs. PostHog processes the connection IP address and browser information to generate a daily rotating identifier, and removes the IP address and User-Agent before storing cookieless events. You can turn this off using the homepage analytics control; only that preference is saved in your browser. We also respect Do Not Track and Global Privacy Control.
1. Information we collect
- Account: a unique user id, email address (or Apple relay), optional display name and avatar URL, from your Sign in with Apple, Google, email/password, or email one-time-code sign-in, plus any optional bio or social links you add to your profile.
- Place activity: your 7-tier ratings, comments, visits, uploaded photos and captions, list subscriptions, per-post audience, and your social graph, including follows, friends, and Close Friends (Mabudachi).
- Dinner participation: your date of birth, gender, nationality, languages you are willing to speak and their levels, dietary requirements and optional notes, verified contact email, selected date, booking, payment and refund status, matched group, Lovy-selected venue and private guide messages. You can view and edit your dinner profile; Lovy uses it to prepare your participation. Matched participants see each other’s ordinary display names, usernames and avatars, plus the meeting time, venue and common languages. They do not receive your date of birth, gender, nationality, individual language list or levels, dietary requirements or notes, or contact email. Payment-card information is entered with the payment provider and is not stored by Lovy.
- Direct shares: the sender and recipients’ account identifiers, shared item, and any optional message when you share a place, log, list, or other supported content inside Lovy.
- Messages between friends: we store conversation participants, message text, identifiers of shared places or Logs, send times, and read positions. Only participants who are currently friends can read the conversation. Blocking or ending the friendship prevents reading and sending. Push notifications omit message text. Deleting either participant’s account also deletes the conversation and its messages.
- Support and reports: sender information, reported content, reason, message body, and optional attachments submitted through an in-app report or by email to support@lovy.app or report@lovy.app.
- Place Stories and logs: photo logs are highlighted as fresh in the map Story rail for 72 hours after posting. The log, photos, comments, and rating remain stored afterward and can still be viewed from the place, Feed, or author Log history by you and the audience selected when posting. You can delete your logs and photos; other users can report inappropriate content or block its author.
- Location: only when granted “While Using the App”, to draw your current position and rank nearby or Lovy Search results. Your current location or visible map region may be sent to Lovy’s server and to Google Places to retrieve relevant place candidates. Coordinates are not sent to PostHog analytics or stored in Lovy search history.
- Search content: your Lovy Search text, bounded recent conversation context, and candidate-place information may be sent to Anthropic, or to OpenAI as a fallback, to interpret intent and rank results. Search terms and location constraints may also be sent to Google Places. Lovy does not save the search text in its own database or PostHog, but each provider may temporarily retain requests under its contract, settings, and law.
- Device and notification data: when registering for push notifications, a Lovy-generated installation identifier, Apple Push Notification service (APNs) device token, app identifier, delivery environment, app version, language, time zone, and registration status. Registration is linked to the account for which notifications are enabled.
- Usage analytics: after sign-in, an account identifier and bounded events such as search success, recommendation impressions, place opens and saves, follows, and shares. Analytics events exclude exact search text, coordinates, names, email addresses, comments, captions, messages, URLs, and recipient IDs. Session replay is disabled. You can stop future collection under My Page → top-right gear → Settings → Usage analytics.
- Diagnostics: while analytics is enabled, PostHog automatically collects app lifecycle data plus crash, error, and other diagnostic data. After sign-in, it may be linked to your account identifier. Precise location, search text, and post content are excluded. Turning off Usage analytics also stops future diagnostic collection.
2. How we use it
- Render your personal “Lovy Map” and recommendations from people you trust.
- Personalize search and suggestions using location, search content, ratings, logs, and relationships.
- Authenticate you and manage your account.
- Deliver direct shares to selected recipients and notifications you allow.
- Manage dinner profiles, bookings and payment status, check age eligibility, form groups sharing a language on your selected date, and prepare dietary arrangements and venue guidance.
- Respond to support requests and review illegal or harmful-content reports.
- Improve discovery-to-decision flows, retention, sharing, reliability, and feature quality.
3. Third parties
We do not sell personal information or use cross-app advertising tracking. The following primary processors and platforms handle data only as needed to provide Lovy:
- Supabase: authentication, database, and photo storage.
- Resend: necessary dinner updates sent to your verified contact email, including the dinner date, payment status and venue after its reveal time. We do not send birth dates, gender, nationality, language levels or dietary notes.
- Cloudflare Workers: triggers scheduled dinner operations and retries; participant profiles are not sent.
- Stripe: dinner participation payments. We send booking identifiers, the participation date and amount; we do not send your date of birth, gender, nationality, languages or dietary requirements.
- Vercel: API and public-page hosting, request processing, security, and operational logs.
- PostHog EU Cloud: the bounded analytics and diagnostics described above.
- Google Places: place lookup using search terms and a current location or visible map region.
- Anthropic / OpenAI: intent interpretation, classification, and ranking using search text, bounded context, and candidate data.
- Apple Push Notification service: delivery of allowed notifications using a device token and notification content.
Sign in with Apple uses Apple’s relay address, so we receive only that relay when you hide your email. Google shares the account information required to authenticate you when you choose Continue with Google.
4. Storage
Data is stored encrypted-in-transit in Supabase (PostgreSQL). Row Level Security ensures each user accesses only what they’re authorized to see. Analytics events are sent over encrypted connections to PostHog EU Cloud. Lovy does not save raw search text in its own database or PostHog, but Google Places, Anthropic, OpenAI, and Vercel may retain request information for service delivery, security, abuse prevention, or legal compliance under their contracts and settings. Push registrations and direct-share messages are stored in Supabase. Dinner profiles, bookings, payment status and private guide messages are also stored in Supabase. Dates of birth, gender, nationality, spoken languages and dietary requirements or notes are not sent to analytics or external AI services. In-app reports are stored in Supabase; emailed support requests and reports are processed by the sender’s and Lovy’s mail services and may be retained as needed for resolution, security, or legal compliance. Photo delivery currently uses hard-to-guess public URLs, so changing an audience may not immediately revoke direct access by someone who already obtained a media URL.
5. Deleting your account
You can delete your account at any time via My Page → top-right gear → Settings → Delete Account. All related account-linked data (including dinner profiles, participation requests and guide messages, ratings, logs, photos, follow relationships, and push-device registrations), along with the linked PostHog person, analytics events, diagnostics, and any recordings (recording is currently disabled), is queued for permanent deletion. Minimal booking and provider identifiers, participation dates, amounts and payment statuses may remain without an account link where needed for payment reconciliation and refunds. Birth dates, gender, nationality, languages and dietary requirements are not retained in those records. Messages already delivered through direct shares or notifications, and support or report records, may remain where needed for a recipient’s history, service safety, dispute handling, or legal compliance.
6. Children
Lovy is not intended for users under 13. If we learn of such an account, we will delete it.
7. Changes
We may update this policy. Significant changes will be announced in-app or via the “Last updated” date on this page.
8. Contact
Questions? Email support@lovy.app.