Privacy Policy
This is an English translation provided for convenience. The Japanese version is the legally binding text.
Kazoku Nikki ("the app") lets an invited family share a diary, photo album, plans, tasks, a wish list and childcare records among themselves. This policy sets out what information the operator of the app and its API (api.familynikki.com) ("we") handle and how we use it, under Japan's Act on the Protection of Personal Information and other applicable law.
1. Information we collect
- Account information: email address, display name, password (stored hashed with PBKDF2-SHA256; never in plain text)
- What your family enters: childcare records (feeds, sleep, nappies, temperature, growth and so on), diary entries, comments, reactions, the wish list, calendar plans, chores and tasks
- Photos and videos: those uploaded to attach to your family's album, diary entries or records
- Device tokens: the Apple Push Notification service (APNs) tokens needed to deliver push notifications, and the display language of that device (so notifications arrive in the right language)
- Activity logs: audit logs kept for detecting unauthorised access and for safety (creation, editing, deletion, invitations, permission changes and the like). We do not log tokens or other secrets.
2. How we use it
We use the information we collect to provide the app: sharing records, photos and plans within a family, sending notifications, managing accounts and preventing misuse. We never sell data to third parties. The contents of photos, videos and diary entries are encrypted on your device and cannot be read by us.
3. Storage and third parties
- Data is stored on Cloudflare, Inc. infrastructure (D1 / R2 / Workers). Photos and videos live in a private bucket; viewing and uploading go through short-lived signed URLs issued only after authorisation is verified
- We use Apple Inc. (APNs) to deliver push notifications
- Apart from these processors, we do not provide information to third parties except where required by law
Processors located outside Japan
Cloudflare, Inc. and Apple Inc. are both headquartered in the United States. For information about the protection of personal information under the US regime, please see the material published by Japan's Personal Information Protection Commission. We work to ensure our processors handle personal data appropriately through our contracts with them and through technical measures such as access control and encryption.
4. Advertising
As of 31 July 2026 the app shows no advertising and contains no advertising SDK. In future, in order to keep the app free to use, we may show advertising. If we do, we will first add to this policy what information is provided to advertising providers and why, and give notice in the app or on this website beforehand.
Because photos, videos and diary entries are encrypted on your device and cannot be read by us, their contents can never be used as material for advertising — it isn't possible by design.
5. Location data in photos (EXIF)
For uploaded JPEG photos, EXIF data (including GPS location) is removed both by re-encoding on the device and again on the server. It is kept only if you explicitly choose to keep it.
6. Children's information
Information about children recorded in the app (name, birthday, childcare records, photos and so on) can be entered and viewed only by a parent or by family members they have invited. Joining a family group requires an invite code, and nothing is made public outside the family group.
7. Managing and deleting data
- You can delete your account from the settings in the app. We also provide a family data export
- Deleted photos and videos are erased from storage for good after a 30-day recovery window
- For requests or questions, please contact us at the address below
8. Security
To prevent leakage, loss or damage to the personal data we handle, we take the following measures.
- All communication is encrypted with TLS
- Access tokens are short-lived. Refresh tokens, invite codes and verification codes are stored only as hashes. Passwords are hashed with PBKDF2-SHA256 and never stored in plain text
- Photos and videos are protected by end-to-end encryption — encrypted inside your family's devices before being stored — and no decryption key is kept on our servers
- Every API enforces access control at the family-group level, verified continuously by automated tests
- We keep audit logs of creation, editing, deletion, invitations and permission changes, and use them to detect unauthorised access
9. Disclosure, correction and suspension of use
Under Japan's Act on the Protection of Personal Information, you may ask us to disclose your retained personal data, to correct, add to or delete its contents, to suspend its use or erase it, or to stop providing it to third parties. Please contact us from your registered email address at the address below. After verifying your identity we will respond within a reasonable period, as required by law. Note that much of this information can be checked, corrected and deleted directly by you through the app itself — viewing and editing records and photos, exporting your data, and deleting your account.
10. Changes to this policy
If we change this policy we will announce it on this page. For significant changes we will also notify you in the app. Where the law requires your consent for a change, we will obtain it again.
11. Operator and contact
This app is operated by an individual developer. Questions about how personal information is handled, and the requests described in section 9, are received at the address below. We will notify the operator's name and address without delay, as required by law, to anyone who requests them.
Email: [email protected]
Established: 24 July 2026
Last revised: 31 July 2026 (added the section on advertising)