1. Scope and definitions
- This Policy applies to information we collect, use, store, or transmit through the Service.
- "Personal data" includes information treated as personal information or personal data under applicable law.
2. Controller
- Company: CLOViZ Inc.
- Address: 4-13-7 Akatsutsumi, Setagaya-ku, Tokyo 156-0044, Japan
- Representative: Sotaro Masaki, Representative Director
- Personal information protection manager: Representative Director
- Privacy contact: info@cloviz.co.jp
- Reception hours: Weekdays 9:00–18:00 (inquiries received during the year-end and New Year holidays, Golden Week, or summer holidays will be handled from the next business day)
3. Information we collect
We may collect the following information as needed to provide the Service.
| Category | Examples |
|---|---|
| Account and contact information | Name or display name, email address, profile image, language, country or region, and authentication-provider information |
| Identifiers and device information | Our user ID, session information, push token, IP address, operating system, browser, and device settings |
| Usage and analytics information | Pages viewed, clicks, session duration, referral source, advertising campaign, approximate country or region, cookies, and similar technologies |
| Learning and gameplay information | Quiz answers and results, learning history, game records, tile-play actions, game results, matches, rankings, weakness analysis, and other study or gameplay records |
| AI and user content | AI chat prompts, game-record reviews, conversation history, AI responses, feedback, voice input or transcription data, and content submitted through support or surveys |
| Purchase and subscription information | Products, subscriptions, price, currency, purchase, renewal and expiration dates, refunds, transaction IDs, entitlements, and coin or credit balances and usage |
| Diagnostics and security information | Crash, error, performance, network, audit, and fraud-prevention information |
Payment card details and other payment information are handled directly by our payment provider, Paddle, and are not collected by us. We receive from Paddle the transaction information needed to verify purchases and provide entitlements.
4. How we collect information
We collect information:
- when you register, submit content, make a purchase, or contact us;
- automatically through the website, cookies, SDKs, and logs when you use the Service;
- from Paddle, authentication providers, advertising and measurement providers, and other partners; and
- from external services when you choose to connect or share through them.
5. How we use information
We use information to:
- create accounts, authenticate users, and maintain security;
- provide quizzes, lessons, exercises, learning tools, gameplay, rankings, AI chat, and other Service features;
- verify purchases, grant coins and entitlements, manage renewals, cancellations and refunds, and prevent purchase fraud;
- analyze learning progress, personalize the Service, provide recommendations, and improve our products;
- send push notifications, service communications, campaigns, and other permitted messages;
- measure advertising and analyze acquisition and purchase journeys;
- diagnose failures, improve quality and performance, and prevent misuse;
- respond to support, privacy requests, disputes, and legal obligations; and
- create and use aggregated or de-identified statistics and learning or gameplay information, including for academic research at universities and other research institutions.
6. Service providers and external transmissions
We use third-party services including those below. The information sent depends on your device, settings, features used, and consent choices.
| Category and representative providers | Information | Purpose |
|---|---|---|
| Google Analytics | IP address, device and browser information, page and interaction data, approximate location | Analytics and product improvement |
| AppsFlyer | Campaign and referral codes, link-use information, and device and browser information | Advertising attribution, fraud prevention |
| Google, Apple, X, and LINE | Identifiers, display name, and email address of the account used to sign in (depending on each provider and your settings) | Sign-in and authentication |
| Firebase Messaging | Device and push-token information | Notifications |
| Cloudflare, Vercel, and Microsoft Azure | IP address, network logs, account information, and Service data stored on our behalf | Delivery, security, hosting, and storage |
| Anthropic, DeepSeek, or OpenAI | AI prompts, conversation context, game-record information, and identifiers or pseudonymous information needed to provide a feature | AI responses, analysis, transcription, and related AI functionality |
| Paddle (Paddle.com Inc., Paddle.com (Canada) Ltd., or Paddle.com Market Limited, depending on the buyer's location) | Name, email address, billing country or region and postal code, payment information, our user ID, products, transactions, amounts, currencies, subscriptions, and refund information | Web payment processing, subscription management, refunds, fraud prevention, tax compliance |
For web payments, Paddle.com Inc. (United States), Paddle.com (Canada) Ltd. (Canada), or Paddle.com Market Limited (United Kingdom), depending on the buyer's location (collectively, "Paddle"), processes payments as the Merchant of Record (the authorized reseller). The name, email address, billing country or region, payment information, and other details you enter at checkout are collected directly by Paddle and handled under Paddle's privacy policy for payment processing, fraud prevention, tax compliance, and Paddle's other business purposes. We provide Paddle with identifiers, such as our user ID, needed to link a purchase to your Service account, and we receive from Paddle information such as transaction IDs, subscription IDs, customer IDs, purchased products, amounts, currencies, subscription status, and billing country or region. We do not receive credit card numbers or other payment details.
We review service providers as appropriate and use contracts or other measures to supervise their handling of information. A provider's own privacy policy and terms may also apply.
7. Advertising, tracking, and cookies
- The Service may use cookies, local storage, other similar technologies, and SDKs for analytics, advertising measurement, and fraud prevention.
- You can manage available choices through browser cookie settings, notification settings, and settings provided in the Service.
- We do not use Google Signals (association with Google account information) in Google Analytics.
For instructions and data requests, contact us using the details in Section 2.
8. AI features
- Content submitted to AI features may be sent to us and an AI provider to generate responses, maintain conversation history, manage usage, protect safety, and improve service quality.
- Do not submit sensitive personal data, confidential information, or third-party information you are not authorized to provide in a free-form AI field.
- Provider retention, data use, and processing locations may vary according to the provider, our contract and settings, and the feature used.
9. Disclosure to third parties
We do not disclose personal data to third parties without consent except:
- as required or permitted by law;
- to protect life, health, safety, or property where consent is impracticable;
- for public-health or child-protection purposes where obtaining consent is impracticable;
- to cooperate with a lawful government request where obtaining consent could impede the relevant official duties;
- to service providers acting within the purposes described in this Policy;
- in connection with a merger, reorganization, financing, or transfer of all or part of our business; or
- through another arrangement, such as joint use or an opt-out disclosure, where permitted and properly notified under applicable law.
10. International processing
Information may be processed by providers or on servers located outside Japan. The main destination countries and the providers that process information there are:
| Country | Main providers and purposes |
|---|---|
| United States | Google (analytics, authentication, notifications), Apple and X (authentication), Vercel and Cloudflare (delivery, security), Anthropic and OpenAI (AI features), Paddle.com Inc. (web payments by buyers in the United States) |
| China | DeepSeek (AI chat) |
| United Kingdom | Paddle.com Market Limited (web payments by buyers outside the United States and Canada) |
| Canada | Paddle.com (Canada) Ltd. (web payments by buyers in Canada) |
These are the main destinations. Other providers listed in Section 6 (such as AppsFlyer) may also process information in the countries where their facilities are located.
Information on the personal data protection systems of each country is available in the surveys published by Japan's Personal Information Protection Commission. China has laws, such as the National Intelligence Law, that require businesses to cooperate with government information collection. We send DeepSeek the information needed for AI responses, such as your AI chat input, conversation history, game records, display name, and learning progress. We do not send your email address or payment information. Please do not enter sensitive information into free-text AI fields (see Section 8).
We take measures required by applicable law, including reviewing each provider's security measures and contract terms and entering into service agreements.
11. Retention and account deletion
- We retain information for as long as needed for the purposes in this Policy, our contracts, legal obligations, dispute resolution, fraud prevention, and security.
- We handle account deletion and other deletion requests after verifying identity, in accordance with applicable law and the procedures specified for the Service.
- Purchase, refund, accounting, audit and fraud-prevention records, learning or gameplay history, and records required to preserve Service integrity may be retained after removing or pseudonymizing direct identifiers where legally and operationally necessary.
- Deletion from backups and service-provider systems may take a reasonable period.
12. Security
We take the following measures to prevent leakage, loss, or damage of personal data:
- Organizational measures: we assign responsibility for handling personal data and review handling regularly. If a data breach occurs, we report it to the Personal Information Protection Commission and notify affected individuals as required by law.
- Personnel measures: we bind personnel who handle personal data to confidentiality and provide necessary training.
- Physical measures: we protect devices that handle personal data against theft and loss, and delete personal data in a way that cannot be recovered.
- Technical measures: we use access control, authentication, encryption in transit and at rest, access-log monitoring, and protection against unauthorized access.
- Understanding foreign environments: when personal data is handled in another country, we take security measures based on our understanding of that country's personal data protection system, as described in Section 10.
13. Access, correction, restriction, and deletion
Subject to applicable law, you or an authorized representative may request notice of purposes, access, correction, addition, deletion, restriction, erasure, cessation of third-party disclosure, or disclosure of third-party disclosure records. We may request information needed to verify identity or authority.
For instructions, contact us using the details in Section 2.
14. Minors
Minors must obtain consent from a parent or legal guardian before using the Service. The Service does not offer wagering of real money.
15. Residents of the EEA and the United Kingdom
If you live in the European Economic Area (EEA) or the United Kingdom, the following applies under the EU General Data Protection Regulation (GDPR) and the UK GDPR:
- We process personal data on the basis of performing our contract with you (accounts, learning features, purchases), our legitimate interests (improving the Service, fraud prevention, security), compliance with legal obligations, and your consent (optional analytics, notifications, and other consent-based processing).
- You may request access to, correction or erasure of, restriction of processing of, and portability of your personal data, and may object to processing. Where processing is based on consent, you may withdraw consent at any time; this does not affect the lawfulness of processing before withdrawal.
- You may lodge a complaint with the data protection supervisory authority in your country of residence.
- Transfers from the EEA and the United Kingdom to Japan rely on the adequacy decisions for Japan by the European Commission and the UK government. Onward transfers from Japan to other countries are described in Section 10.
- To make a request, contact us using the details in Section 2.
16. Changes to this Policy
We may update this Policy to reflect changes in law, platform requirements, providers, or Service features. We will provide reasonable notice of material changes through the Service, website, email, or another appropriate method. Unless otherwise stated, an updated Policy takes effect when posted.


