AI駆動開発で、作る・確かめる・運用する。

受託開発 / 導入支援 / 検証・商用化 / 技術顧問

株式会社ロク株式会社ロクRoku Inc. / AI-Native Engineering

Privacy Policy

BlurEXIF Privacy Policy / プライバシーポリシー

最終更新日 / Last updated: 2026年8月15日 / August 15, 2026

日本語

1. 適用範囲

本プライバシーポリシーは、株式会社ロク(以下「当社」)が提供する写真プライバシー加工アプリ「BlurEXIF」(以下「本アプリ」)に適用されます。

2. 顔データと端末内の写真処理

本アプリは、利用者が明示的に選択または共有した写真だけを処理します。顔・文字の検出、マスクの描画、画像の加工、および位置情報、EXIFその他のメタデータ除去は、利用者の端末内で行います。

当社は、顔データを端末外で受領または収集せず、本アプリは顔データを端末外へ送信しません。顔を隠す候補を提示するため、本アプリは顔を含む可能性のある写真の画素を一時的に処理し、Apple Visionを使用して顔の矩形座標と信頼度を端末内で生成します。同じ処理セッションで選択された写真だけを対象とする任意の同一人物候補比較では、一時的な顔の切り抜き画像、画像特徴量(feature print)および類似距離をメモリ内で生成することがあります。これらは、利用者が確認し、ぼかし、モザイクまたは黒塗りを適用する候補領域の提示にだけ使用します。

本アプリは、人物の実世界での身元を判定または保存せず、顔データを氏名やアカウントと関連付けません。顔データを認証、顔データベースまたは利用者プロファイルの作成、モデル学習、解析、広告、マーケティングに使用しません。

顔データを当社または第三者のAI、解析、広告その他のサービスへアップロードせず、当社は顔データを販売、開示または共有しません。Apple Visionによる処理は端末内で行われます。iCloud写真を利用している場合、Appleの「写真」およびiCloudが、利用者が選択した元写真のダウンロードまたは利用者が保存した保護済みコピーの同期を行うことがあります。この通信はAppleのサービスを通じて行われ、当社が運営するサーバーを経由しません。

顔の矩形座標、信頼度、メモリ内の切り抜き画像、画像特徴量、類似距離およびマスク等の派生した顔データは、処理セッション中だけ揮発性メモリに保持します。永続ストレージへ書き込まず、処理状態のリセットもしくは置換時、または本アプリのプロセス終了時に破棄します。選択した写真の作業用コピーは、編集に必要な間だけiOSが管理する本アプリの一時領域に保持します。利用者が処理を完了するか、新しい写真を取り込むと本アプリが削除します。処理が中断された場合、一時ファイルはiOSによって削除されることがあり、本アプリを削除すると消去されます。

共有拡張の引き渡しデータは、取り込みまたは破棄された時点で削除します。取り込まれなかった引き渡しデータは24時間後に失効し、次に本アプリまたは共有拡張が期限切れデータを整理するときに削除します。保護済みコピーは、利用者の指示がある場合だけ「写真」、「ファイル」またはiCloudへ保存され、利用者が削除するまで各サービスに残ります。当社はこれらのコピーへアクセスせず、保持しません。

顔処理は、利用者が「写真を選ぶ」、「ファイルを選ぶ」または「共有」を開始し、写真を明示的に選択または共有した後にだけ開始します。利用者はいつでも処理を中止でき、iOSの設定から写真へのアクセス権を取り消すことができます。

3. 写真ライブラリとファイルへのアクセス

  • 写真ライブラリの読み取りは、利用者が選んだ写真を端末内で加工するために使用します。
  • 写真ライブラリへの追加は、保護済みコピーを保存するために使用します。
  • 「ファイル」への書き出しは、利用者がAppleの書類選択画面で明示的に保存先を選んだ場合にだけ行います。
  • 本アプリは元写真を変更または削除せず、新しい保護済みコピーを作成します。

4. 端末内に保存する情報

本アプリは、利用者が選んだ設定、購入権利の状態、および直近の書き出し履歴を端末内に保存します。書き出し履歴には、処理枚数、成功・失敗件数、完了日時、出力形式、メタデータ設定、保存先の種類だけが含まれ、写真、ファイル名、ファイルパスは含まれません。

共有拡張から送った写真は、アプリへ引き渡すためにアプリグループ領域へ一時的にコピーされます。取り込みまたは破棄された一時データは削除され、処理されなかった一時データは24時間後に失効します。

5. 購入情報

Lifetime Proの購入はAppleのApp StoreおよびStoreKitを通じて処理されます。当社はクレジットカード番号等の決済情報を本アプリから取得しません。本アプリは、購入権利を確認・復元するためにAppleが提供する検証済み取引情報を端末上で参照します。

6. 広告、解析、追跡およびデータ収集

本アプリは、広告SDK、第三者解析SDK、独自アカウント、利用者追跡、当社運営のネットワークサービスを使用しません。本アプリの現行バージョンは、App StoreのApp Privacy上「データを収集しない」設計です。

7. サポートへの連絡

利用者が当社のお問い合わせフォームから任意に送信した氏名、連絡先、問い合わせ内容等は、回答および必要な調査のために取り扱います。これは本アプリによる自動的なデータ収集ではありません。初回のお問い合わせには、私的な写真、位置情報、その他の機微な情報を添付しないでください。

8. データの削除

本アプリの設定、履歴および一時データは、アプリの削除により削除できます。写真ライブラリ、「ファイル」またはiCloudへ保存・同期された保護済みコピーは、利用者自身で各Appleサービスから削除してください。

9. Appleのサービス

写真、iCloud、App Store、StoreKit等のAppleサービスには、Appleの利用規約およびプライバシーポリシーが適用されます。当社はAppleのサービス提供状況や保持方針を管理しません。

10. お問い合わせと改定

本ポリシーに関するお問い合わせは、お問い合わせフォームよりご連絡ください。本ポリシーを改定した場合は、本ページで告知します。

English

1. Scope

This Privacy Policy applies to BlurEXIF (the “App”), a photo privacy app provided by Roku Inc. (“we,” “us,” or “our”).

2. Face Data and On-Device Photo Processing

The App processes only photos that the user explicitly selects or shares. Face and text detection, masking, rendering, and removal of location, EXIF, and other metadata are performed on the user’s device.

Roku Inc. does not receive or collect Face Data off the device, and the App does not transmit Face Data off the device. For face masking, the App temporarily processes photo pixels that may contain faces and uses Apple Vision on the device to derive face bounding rectangles and confidence scores. For an optional same-person-candidate comparison limited to photos selected in the same processing session, the App may also create temporary in-memory face crops, image feature prints, and similarity distances. This data is used only to suggest areas for the user to review and mask with blur, mosaic, or a black bar.

The App does not determine or store a person’s real-world identity, associate Face Data with a name or account, authenticate a person, build a face database or user profile, train models, or use Face Data for analytics, advertising, or marketing.

Face Data is not uploaded to or received by Roku Inc. or any third-party AI, analytics, advertising, or other service, and we do not sell, disclose, or share it. Apple Vision processing occurs locally. If iCloud Photos is enabled, Apple Photos and iCloud may download a user-selected source photo or synchronize a user-saved protected copy under Apple’s terms; this traffic does not pass through a server operated by us.

Derived Face Data, including face rectangles, confidence scores, in-memory crops, feature prints, similarity distances, and masks, is kept only in volatile memory during the processing session. It is not written to persistent storage and is discarded when the processing state is reset or replaced, or when the App process ends. A working copy of a selected photo is kept only in the App’s iOS-managed temporary sandbox while needed for editing. The App removes it when the user completes the flow or starts a new import. If a session is interrupted, iOS may purge the temporary files, and uninstalling the App removes them.

A Share Extension handoff is removed when claimed or discarded. An unclaimed handoff expires after 24 hours and is deleted the next time the App or Share Extension purges expired handoffs. A protected copy is saved to Photos, Files, or iCloud only at the user’s direction and remains there until the user deletes it. Roku Inc. has no access to or retention of those copies.

Face processing begins only after the user initiates Choose Photos, Choose Files, or Share and affirmatively selects or shares a photo. The user may cancel processing at any time and may revoke Photos access in iOS Settings.

3. Photos and Files Access

  • Photo Library read access is used to process photos selected by the user on the device.
  • Photo Library add access is used to save protected copies.
  • Files export occurs only after the user explicitly chooses a destination in Apple’s document picker.
  • The App does not modify or delete originals; it creates new protected copies.

4. Information Stored on the Device

The App stores selected preferences, purchase-entitlement state, and recent aggregate export history on the device. History includes counts, completion time, output format, metadata policy, and destination type, but not photos, filenames, or file paths.

Photos sent through the share extension are temporarily copied to the App Group container for handoff to the App. Claimed or discarded temporary data is removed, and unclaimed handoffs expire after 24 hours.

5. Purchases

Lifetime Pro purchases are processed by Apple through the App Store and StoreKit. We do not receive payment-card details from the App. The App reads Apple-verified transaction information on the device to determine and restore entitlement.

6. Advertising, Analytics, Tracking, and Collection

The App does not use advertising SDKs, third-party analytics SDKs, proprietary accounts, user tracking, or developer-operated network services. The current version is designed to report “Data Not Collected” in App Store App Privacy.

7. Support Contact

Information that a user voluntarily submits through our contact form, such as contact details and the support message, is used to respond and investigate as needed. This is separate from automatic collection by the App. Do not attach private photos, location data, or other sensitive information to your first message.

8. Deletion

App preferences, history, and temporary App data can be removed by uninstalling the App. Protected copies saved or synchronized to Photos, Files, or iCloud must be deleted by the user from the applicable Apple service.

9. Apple Services

Apple’s terms and privacy policy apply to Photos, iCloud, the App Store, StoreKit, and other Apple services. We do not control the availability or retention policies of Apple services.

10. Contact and Changes

For questions about this policy, use our contact form. We will post revisions to this policy on this page.