Privacy Policy

Last Updated: September 11, 2026

MimiSeka is an iOS app that uses AI to interpret scenes from photos and videos, generating literary narratives and summary text. The generated text can be embedded as photo captions (ALT text) or read aloud.

This policy describes how data is handled in this app.

1. Data We Collect, Transmit, and How We Use It

Photo Data

To generate summaries and narratives for your photo captions, photos you take or select are sent to external generative AI services. How data is handled after transmission is governed by each service's privacy policy.

Conversation, Diary, and Note Text (Scia)

The text you type or speak while talking about a photo, any note you attach to a photo, and the material used to write a diary entry are sent to third-party generative AI services in order to produce the writing. Once transmitted, that data is handled according to each service's own privacy policy.

The conversation record itself is kept on your device (see 3. Data Stored on Your Device).

Initial Survey

On first launch, the app asks for the following information:

This information is used to optimize app settings and is also stored in anonymized form on our servers to improve the service. It is never used to identify any individual.

Device Identifier

To maintain stable service operation (daily request rate limiting), a device-specific identifier assigned by Apple (identifierForVendor) is sent to our server. This identifier changes when the app is reinstalled and is not used for cross-app tracking or advertising purposes.

Location Data (Optional)

Location data is only collected when you grant the app location access through your device's iOS system settings. When enabled, location data is used for:

Precise location data (latitude and longitude) is sent to our servers only if you use the "leave a story at this place" feature described below. Otherwise, a coarse location name (city or municipality level) may be sent to generative AI services as contextual information for narrative generation. Place names, venue names, and weather are retrieved through Apple's services and do not pass through our servers.

Content You Publish as a "Listenable Photo" (Optional)

MimiSeka Scia lets you turn a story or diary entry into a link or QR code so that people without the app can listen to it. Only when you use this feature, the following is stored on our servers (AWS Tokyo region) and becomes accessible to anyone who has the link:

Publication is time-limited, and you choose the period when you publish. Expired content becomes unreadable and is deleted automatically. Before expiry, you can revoke publication at any time from "Disable QR" in the app; once revoked, the link no longer opens.

Our servers count how many times published content has been played or viewed and report that count back to you. We do not record who viewed it.

"Leave a Story at This Place" (Optional)

MimiSeka Scia lets you leave a story at the place where the photo was taken. If you use this feature, your story (text, narration audio, capture date, and capture coordinates) is stored on our servers and shown anonymously to other users who visit that place, as "a story someone left here." The publication period is one year.

Your name and display name are never shown alongside a story you leave. You can withdraw it at any time from within the app. Withdrawing stops new deliveries, though it may remain on devices that already received it.

When you place a story, its text is sent once to an automated content check (OpenAI's Moderation API) before it is published. Text judged inappropriate is neither stored nor published. Photos are never stored on our servers by this feature (what is stored is the text, the narration audio, the capture date, and the capture coordinates).

Stories left at a place can be reported. A reported story stops being delivered immediately, and we then review it and decide whether to restore or delete it. The reason selected by the reporter, and any note they choose to write, are stored on our servers for up to 400 days for audit purposes.

For this feature only, we store a pseudonymised identifier for the author and for the reporter. It is derived from the publishing identifier held on your device (a value unrelated to your name or email address) by a salted, irreversible hash, and it is used for two purposes only:

This identifier is never displayed, and never passed to other users or apps. Authors and reporters are hashed with separate domains, so the two cannot be matched against each other. Block records (who does not want to receive from whom) are likewise stored as a relation between pseudonymised identifiers.

Push Notifications (Optional)

If you use "letters from MimiSeka," we deliver notifications through Apple's Push Notification service (APNs). You can revoke notification permission at any time in iOS Settings.

iCloud (CloudKit) Storage and Sync

The story text and titles, capture notes, emotion tags, and narration audio collected on your shelf are stored and synced in your own iCloud. The photo images themselves are not sent — they stay in your device's photo library, and only an identifier for each photo is stored in iCloud. This happens entirely within Apple's services and does not pass through our servers. Data held in iCloud is governed by Apple's privacy policy.

In-App Purchases

If you buy a subscription or a ticket pack, we verify the signed purchase receipt issued by Apple on our servers and record the resulting allowance against your device identifier. We never receive your payment details, such as credit card numbers.

Usage Data

To improve the app, the following usage data is recorded on your device:

This data is anonymized and stored on our servers solely for the purpose of service improvement. It is never used to identify any individual.

Data Retention

Content published as a "listenable photo" is retained until the period you chose when publishing (30 days by default), after which it is deleted automatically. A story left at a place is retained for one year. Report records are retained for up to 400 days, and block records until they are removed. In both cases, revoking publication in the app makes the content unreadable from then on. Usage data and device identifiers are retained for the duration of service operation and deleted when the service is discontinued. Initial survey data is retained as anonymized statistical information for the duration of service operation.

2. Third-Party Services

Generative AI Services

The following generative AI services are used for photo analysis and narrative generation. All communications are routed through our server over encrypted connections (HTTPS).

How data is handled after transmission is governed by each service's privacy policy:

Text-to-Speech Services

The following services may be used to convert generated text to audio. Only text generated within the app is sent; no photos or user-identifying information is included.

X (formerly Twitter)

Posting to X is optional. If you choose to use this feature, you connect your account via X's secure account authorisation. The app only requests posting (write) permission; it does not access your timeline, followers, or any other read permissions. Authentication credentials are securely stored in the device's secure credential storage (Keychain) and deleted upon logout.

3. Data Stored on Your Device

Scia

Generated summary and narrative text can be embedded as a description field stored inside the photo file (IPTC caption) and saved to the "MimiSeka" album in your device's photo library. This feature can be toggled on or off in Settings. Saved photos may include the following embedded data:

We also store, on your device, the record of your conversations about photos and the profile notes distilled from them (how you speak and what you tend to care about). These are never synced to iCloud and never leave your device. You can review and delete them from the app's settings.

Voice Recordings Attached to Photos

In Scia you can record your own voice and attach it to a photo (before or after taking it, or later from the chapter screen). Recording your voice is the only feature that uses the microphone.

Recorded audio files are stored in the app's own storage on your device. They are never transmitted to our servers, and they are never transcribed or analyzed. Audio is not included when you publish a story as a QR code or link, when you share it with someone, or when you leave a story at a place.

Because these recordings are part of your device backup (such as an iCloud backup), they carry over when you move to a new device. You can remove the audio from an individual chapter inside the app, and "Erase all data" in Settings deletes all of them.

4. Data Security

5. Sharing with Third Parties

Except for the external services described above, we do not sell, rent, or otherwise provide your data to third parties. We do not sell or share your personal information as defined under the California Consumer Privacy Act (CCPA/CPRA).

6. International Data Transfers

Your data may be processed by third-party generative AI and speech synthesis services in countries outside your country of residence. All transfers are conducted over encrypted connections (HTTPS) via our server. By using the app, you acknowledge that your data may be transferred to and processed in countries that may have different data protection standards from your own.

7. Children's Privacy

This app is not directed at children under the age of 13, but it may be used by children with visual impairments. In compliance with the Children's Online Privacy Protection Act (COPPA), all survey responses and usage data are collected exclusively as anonymous, non-personally identifiable information for all users regardless of age. Device identifiers are sent to our server solely for request rate limiting and are not linked to any personal information. Core app features (photo analysis, narrative generation, and read-aloud) remain fully available regardless of age.

That said, publishing a "listenable photo" and leaving a story at a place are features where what you write can be seen by other people. If a child uses the app, a parent or guardian should review these features first. Any publication can be revoked.

If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete such information promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@mimiseka.jp.

8. Your Rights and Choices

You can control your data through the following means:

For California Residents

Under the California Consumer Privacy Act (CCPA/CPRA), California residents have the right to:

To exercise these rights, please contact us at privacy@mimiseka.jp. We will respond to verifiable requests within 45 days.

9. Do Not Track

This app does not track users across third-party websites or services. We do not respond to Do Not Track (DNT) signals because the app does not engage in such tracking.

10. Changes to This Policy

If we make changes to this policy, we will notify you through the app or our website. For significant changes, a notification will be displayed when the app launches.

11. Contact Us

If you have any questions or requests regarding privacy, please contact us:

Operator: MimiSeka Project
Privacy enquiries: privacy@mimiseka.jp
Reports, problems, and general enquiries: support@mimiseka.jp (also reachable from Settings → About This App → Contact us in the app)