sukiba
/Privacy Policy

Legal

Privacy Policy

Last updated: September 27, 2026

1. Introduction

sukiba (“Service”) is a map application for saving places you want to visit or have visited, recording your travel trails, and sharing them with friends and family. This Privacy Policy explains how the Service collects, uses, and protects your personal information. By using this Service, you agree to this Policy.

2. Information We Collect

We collect the following information.

  • Account information: Email address (collected at registration via email/password, Sign in with Apple, or Google Sign-In), display name, and country of origin if you choose to set one
  • Location information: Your current location and the coordinates of places you save, rate, or visit. When you start the trip recording feature, location is collected in the background, including while the app is closed, in order to record your travel trail. Recording only occurs while a trip is actively started and stops when you end it
  • Photos: Photos you attach to places or groups
  • Photo shooting data (EXIF): When you attach a photo, we read the camera make and model, aperture, shutter speed, ISO, focal length, and the compass direction the device was facing, and store them alongside that photo. These are provided so you can review how a shot was taken. If the photo contains no EXIF data, nothing is read
  • Photo feature vectors: A numeric representation of a photo’s visual characteristics, computed on your device. See Section 4
  • Weather at time of recording: When you start a trip, the weather at that moment and location is obtained once and stored with the trip record
  • User content: Ratings, reviews, comments, custom list names, itinerary times, group names, crowd-sourced condition posts, and other content you create within the Service
  • Reports: If you report a public review or photo, the report and the reported item are recorded
  • Purchase records: When you unlock the group feature via Apple In-App Purchase, we record that the purchase was completed for your account, together with the App Store transaction identifier. Payment details (card numbers, etc.) are handled entirely by Apple and never reach our servers
  • Usage logs: Access timestamps and similar technical information (for service improvement and security purposes)

3. How We Use Your Information

  • Account creation, management, and authentication
  • Displaying your current location on the map and recording places you save or visit
  • Recording, replaying, and displaying your travel trail (trip recording feature)
  • Showing weather, sunrise and sunset, and golden-hour guidance for a place
  • Providing the group feature, allowing members to share saved and visited places with each other
  • Storing and displaying photos you attach to places, and finding places that look similar
  • Showing the elapsed time and distance of an active recording on the Lock Screen and Dynamic Island (Live Activity)
  • Detecting and preventing unauthorized use, and handling reports
  • Service improvement and new feature development

4. Analysis Performed On Your Device

The following analysis runs entirely on your device using Apple frameworks. The photograph itself is never sent anywhere for these purposes.

  • Feature vector (Vision): A list of numbers describing a photo’s visual characteristics is computed on your device. Only this list of numbers is stored on our servers, so that the “places with a similar feel” search can compare photos. The original image cannot be reconstructed from it
  • Attention area (Vision): Where the subject sits within a photo, used to crop cover images well. Never leaves your device
  • Subject classification (Vision): A guess at what a photo depicts (beach, mountain, shrine, and so on), used to build search terms. Never leaves your device
  • Search term generation (Apple Foundation Models): On devices that support Apple Intelligence running iOS 26 or later, the on-device language model turns the classification above into Japanese search terms. Never leaves your device. On other devices a fixed lookup table is used instead

5. What Is Sent To External Services

The Service sends the following to the following recipients, and nothing more. No recipient below receives your account information unless stated.

  • Apple — Maps and place names: Coordinates, to draw the map, search for places, and resolve addresses and city names (reverse geocoding)
  • Apple — WeatherKit: Coordinates, to obtain current weather and forecasts. Weather data is provided by Weather (legal attribution)
  • Apple — Look Around: Coordinates, to show street-level imagery of a place
  • Apple — App Store Server API: The transaction identifier of an in-app purchase, sent from our server to Apple to verify that the purchase is genuine
  • Pexels / Unsplash — borrowed photographs: Only an English place or area name (for example “Minato City Tokyo”) or a generic category word (“cafe”). Coordinates, street addresses, your photographs and your account information are never sent. Used to borrow a representative photograph for a place or trip that has no photograph of its own
  • Hot Pepper Gourmet (Recruit Co., Ltd.): A restaurant name and a coordinate range, to obtain opening hours, budget, payment options, and coupons. The request is made through our own server, so the API key is never present on your device
  • Infrastructure providers: Cloud database and authentication (Supabase), photo storage (Cloudflare R2 and Supabase Storage), hosting (Vercel)
  • Sign-in providers: When you sign in with Apple or Google, those providers process your authentication. Please refer to Apple's and Google's own privacy policies
  • Payment processing: In-app purchases are processed entirely by Apple Inc. through the App Store. We do not receive or store any payment card information

6. Information Sharing

We do not sell your personal information. We share it only in the following cases.

  • With people you choose: Each place, list, and trip carries a visibility setting of private, group, or public. Private is the default. Group content is visible to members of that group; public content is visible to all users of the Service through the Discover tab
  • Recipients listed in Section 5, limited to what Section 5 describes
  • Legal requests: When required by applicable law or regulation

7. Leaving the Service for Another Site

Some features open another company’s app or website. Once you leave, that company’s own privacy policy governs what happens, and we have no access to what you do there.

  • Asking an assistant about a place: If you choose this, the app opens the service you selected (ChatGPT, Gemini, Claude, Perplexity, or Copilot) and passes a question that contains the name of the place. The same text is also copied to your clipboard, so that it can be pasted if the service does not accept a pre-filled question. Nothing else about you is sent
  • External place links: Tabelog, Hot Pepper Gourmet, Yelp, TheFork, Instagram, and Apple Maps can be opened from a place. Only the place name or a standard link is used
  • Searching the web for a similar place: Opens a browser view. The Service cannot read what is shown or what you do there

8. Data Storage and Deletion

  • Photos, location records, and user content are stored on the infrastructure listed in Section 5
  • Deleted trips and photos go to a trash area and are recoverable for 7 days, after which they are permanently removed
  • Crowd-sourced condition posts expire automatically 2 hours after posting
  • You can delete your sukiba data at any time from Settings → Account → Delete Account within the app. This permanently deletes all sukiba data associated with your account, including saved places, trip records, photos, feature vectors, custom lists, and group memberships
  • sukiba shares its underlying account system with our other product, Tokitage. Deleting your sukiba data does not delete your shared sign-in account itself; it only removes the data created within sukiba

9. Security

The Service implements the following security measures.

  • HTTPS encryption for all communications
  • Row-level security (RLS) for data access control, ensuring users can only access their own data or data explicitly shared with them
  • Location and content visibility follow the sharing scope you set (private, group, or public) for each place or list
  • API keys for external services are held only as server-side secrets and are never embedded in the app
  • In-app purchases are verified server to server against Apple before any entitlement is granted

10. Locally Stored Data

The Service stores the following information only on your device, and does not transmit it externally.

  • Language setting: Your selected display language
  • Recent search history: Recent place searches, to help you search faster next time
  • Album layout: If you drag photos to rearrange them in the My Page album view, their positions and stacking order are saved on your device only, so the layout stays the way you left it
  • Reminder notification settings: If you enable the “Want to go” reminder in Account Settings, we store your on/off preference and which places have already been notified, and schedule a local notification via iOS. This all happens on your device; no data is sent to our servers, and no notification content is visible to anyone else
  • Active recording journal: While a trip is being recorded, the distance so far and any points not yet uploaded are written to a file on your device, so that nothing is lost if the app is closed or terminated unexpectedly. It is deleted once the trip has been closed
  • Widget data: If you place the golden-hour widget on your Home Screen, the coordinates of your most recently saved “want to go” places are shared with the widget through a private container on your device. The widget performs its calculation offline and has no network access
  • Cover image notes: Which image was chosen as the cover for a place, so it does not have to be looked up again

11. Your Rights

You have the following rights.

  • Request disclosure, correction, or deletion of personal information we hold
  • View and change your saved places, trips, and content within the app
  • Change the visibility of any place, list, or trip at any time
  • Delete your sukiba account data (Settings → Account → Delete Account)

12. Contact

For questions about this Policy or requests regarding your personal information, please contact us at:

work@craphtguys.jp

13. Changes to This Policy

This Policy may be updated without prior notice. In the event of significant changes, we will notify you within the Service. Continued use of the Service after changes constitutes acceptance of the revised Policy.