eipet is a Japan-only service for adult, primarily Japanese-speaking English learners. This policy explains the information handled by the operator, its purposes, storage, external transmission, and user rights.
1. Operator and contact
The personal-information handling business operator and service operator is sole proprietor Albert Sebastian Sokol, located in Tokyo, Japan. Contact for privacy, complaints, rights requests, and other matters: hello@eipet.app.
The business address will be disclosed without delay upon request to the email address above, after procedures reasonably necessary to confirm the request and the requester's relationship to the relevant information.
2. Information collected and processed
Account information: Google or Apple authentication identifier, email address when provided, display name, sign-in time, and authentication-provider information. Apple Hide My Email may provide a relay address.
Eligibility and acceptance records: acceptance of the Terms, which require users to be at least 18; acknowledgment of this Policy; versions and choices for AI processing; and the server-recorded time. We do not collect a full date of birth.
Learning and usage information: profile, learning history, answers, corrections, chat and translation history, vocabulary and SRS state, English Ability estimates, statistics, streak and Momentum data, rewards, pets, inventory, beta access, and feature usage.
Product analytics information: account-linked screen names, approximate time the app runs in the foreground, app version, build number, OS category, and release channel. We do not collect keystrokes, taps, scrolling, screen recordings, or continuous heartbeats. Product analytics events do not contain learning text, answers, chat or translation text, audio, or AI reasoning.
Support information: subject, message, optional reproduction steps, reply email, and limited diagnostics such as app version, build, OS, route, and correlation ID.
Operational information: pseudonymous user IDs; operation, feature, chat, and session identifiers; timing; outcome and error categories; AI model and token counts; evaluation outcomes; and other metadata required to operate the service.
Purchase and access information: Apple-issued transaction and original-transaction identifiers; product; purchase, renewal, and expiry dates; free-trial and auto-renewal state; billing-grace, expiry, and revocation state; storefront; a pseudonymous identifier that safely associates an App Store account with an eipet account; and verification records. We do not receive card numbers or Apple ID passwords.
3. Purposes
Creating, authenticating, and protecting accounts and managing eligibility and acceptance state.
Providing chat, translation, vocabulary, SRS, progress, reward, and other learning features.
AI response generation, transcription, translation, correction, evaluation, and speech.
Answering support requests, investigating failures, maintaining quality and safety, and preventing abuse.
Aggregating usage, improving features, complying with law, and handling disputes.
Verifying and restoring monthly-plan purchases, granting access, reflecting renewal, cancellation, and refund status, preventing conflicting use, and meeting accounting and tax obligations.
4. AI processing, OpenAI, and audio
Chat text, translation prompts and answers, correction and evaluation material, AI instructions, and necessary chat context are sent to OpenAI for response generation, evaluation, translation, transcription, or speech generation. This processing is necessary for the AI features, and onboarding asks for a separate express confirmation before use.
The operator configures OpenAI Responses API requests not to store application state. Data sent through the OpenAI API is not used to train OpenAI models unless the operator expressly opts in, and the operator does not opt in. OpenAI may nevertheless retain inputs and outputs for abuse monitoring, ordinarily for up to 30 days under its applicable policy, and the operator may not be able to delete those provider records immediately.
For voice input, a recording is created in temporary device storage for transmission and the app automatically deletes it when processing finishes, whether the request succeeds or fails. Recordings are not stored in the eipet database. OpenAI provides transcription and AI chat speech; lessons and reviews use native device speech services.
5. Information stored on the device
The device may store audio-autoplay and notification preferences, notification schedules, operation identifiers needed for retries, display-only chat correction state, dictionary data, and a local reflection of vocabulary and SRS state. Account-linked corrections, retry information, schedules, local SRS state, and badges are removed on logout or account switch. Installation-wide audio and notification preferences remain after logout. Uninstalling the app ordinarily removes local data, although device OS backup settings may affect this.
6. Support information
Support information is used to respond, investigate failures, prevent abuse, retain handling history, address disputes, and comply with law. Reply addresses are used only for support, not marketing. We do not automatically attach files, advertising identifiers, screenshots, chat history, audio, Firestore contents, or device logs. Do not send passwords, authentication codes, payment information, or another person's confidential information.
7. Processors, storage location, and foreign processing
Primary application data is stored in Google Firebase Firestore in the asia-northeast1 Tokyo region. We also use Firebase Authentication, Cloud Functions, Cloud Logging and other Google/Firebase services, Apple sign-in, App Store payment, and subscription-management services, and OpenAI AI, transcription, and speech-generation services. Apple's privacy policy and applicable terms also govern App Store payments.
Even for users in Japan, authentication information, learning content sent to AI, and technical metadata may be processed in the United States and other locations where a provider operates infrastructure. Foreign privacy systems may differ from Japan's. The operator applies reasonable safeguards including purpose limitation, access controls, data minimization, and review of provider contracts and security measures.
We do not sell personal information or use it for third-party behavioral advertising. We do not provide personal information to third parties other than the processors above, except where required by law, necessary to protect life or safety, involved in a business transfer, or authorized by the user.
8. Operational logs
We record the operational and product analytics metadata described in Section 2 for reliability, cost control, incident investigation, abuse prevention, and product improvement. These records may include pseudonymous user and chat or session identifiers, screen names, and foreground duration, but are designed not to intentionally record learning text, answers, prompts, audio, or support-message content. Unexpected errors are converted to content-free categories before logging.
9. Retention
Account, acceptance, and learning information: while the account exists and the data remains necessary to provide or secure the service or respond to a user request.
Support information: after the last response, for as long as reasonably needed for handling history, abuse prevention, disputes, and legal compliance. Information no longer needed is subject to periodic review.
Operational logs: for as long as needed for incident investigation, abuse prevention, and security. Necessity is reviewed periodically, except for audit records Google Cloud must retain longer.
Detailed product analytics events such as screen views and foreground duration: ordinarily no more than 90 days. If the account is deleted earlier, they are included in account deletion. Aggregated or anonymized statistics may be retained longer when they no longer identify a person.
Purchase and accounting records: only as needed for refunds, fraud prevention, accounting, tax, and legal obligations, potentially for the statutory period (ordinarily up to seven years). After account deletion, links to learning data and contact information are removed and only the minimum necessary transaction record is retained.
Temporary device audio: automatically deleted after transmission processing. OpenAI abuse-monitoring records: ordinarily up to 30 days under its applicable policy.
Information no longer needed: deleted or anonymized unless retention is required for law, security, or disputes.
10. Security measures
We use measures proportionate to the information and risks, including authentication, least-privilege access controls, restrictions on direct client writes, server-side validation, encrypted transport, separation of secrets, content-free logging, deletion processes, and processor review. Further information is available on request to the extent disclosure would not undermine security. No system can guarantee absolute security.
11. Requests and complaints
Under applicable law, users may request notice of purposes, disclosure of retained personal data or third-party provision records, correction, addition, deletion, cessation of use, erasure, or cessation of third-party provision. In-app account deletion is also available.
Send requests or complaints to hello@eipet.app with the requested action, relevant account, and desired response. Depending on the request, we may verify identity through the registered email, reauthentication, or another reasonable method; the specific method will be explained individually. We ordinarily charge no fee. If special costs require a lawful fee, we will provide advance notice. If the law permits us to refuse a request, we will explain the reason and respond without delay.
12. AI choice and account deletion
AI-processing permission can be withdrawn from this Policy screen. Because AI processing is a core part of eipet's learning features, withdrawal signs you out and prevents use of those features until permission is granted again.
Account deletion is irreversible. After identity verification, we immediately begin deleting the Firebase Authentication identity and account-related profile, learning, support, and other Firestore data. Deleting the account does not cancel an Apple monthly plan; cancel it separately in the device subscription-management screen. Completion may take time. Legally required purchase and accounting records, security logs, ordinary backups, and records independently retained by Apple or another provider may remain until their respective retention periods expire.
13. Age and territory
The service is for users aged 18 or older. Anyone under 18 may not use it. When you accept the Terms, we record your representation that you meet the Terms' 18+ eligibility requirement and the time of acceptance, but we do not collect a full date of birth. This beta is intended for Japan. If underage use or use outside the intended territory becomes known, we may suspend access or delete information as appropriate.
14. Changes and language
We will give advance notice through the app or another appropriate method according to the significance of a change and update the version and effective date. We will request renewed confirmation or consent where appropriate for a material change. If the Japanese and English versions conflict, the Japanese version controls.