Privacy Policy

Last update: 2026-10-03. This policy covers the iOS app Mogyu (もぎゅ).

Your photos stay on your iPhone, unless you turn on AI lines

Optional Tidy photos lets you choose accessible originals, review the exact selection, and request deletion through Apple Photos with a system confirmation. Feeding never deletes your originals. Deleting an original does not remove its separate diary copy. Cleanup selections stay on your device and are not sent to our servers. Pet appearance choices and the latest broad fed-photo category used for local keepsakes also stay on your device.

The app reads a photo on your iPhone. Apple's Vision framework names what is in the photo, and the pet picks a line. On an iPhone with Apple Intelligence, Apple's on-device model can write the line, also on the iPhone. Unless you turn on AI lines (see the next section), the app sends no photo, no part of a photo, and no result of the photo analysis to a server. The food diary keeps a small copy of each photo in the app's own storage on your iPhone. Delete a page of the diary, or delete the app, and that copy is gone.

AI lines (optional, off by default)

The first time that a photo can use this feature, the app asks you. If you select "Allow", an AI service writes a line about the photo that you feed. If you select "Keep it on this iPhone", nothing changes and no photo leaves your iPhone. You can change the answer at any time in the app: Settings, "AI lines".

For each meal the app sends a small copy of that one photo, 512 pixels on the long side. The copy holds no location, no date and no other metadata. Text in the photo (a receipt, a note, a screenshot) goes as taken, so the pet can react to what it says, unless you turn on Settings, "Hide text in photos from the AI". With that setting on, the app covers the text before upload, and a photo that is mostly text does not go at all. In every case the AI hosts process the request with zero data retention (see below), and our server tells the AI model never to repeat a name, an address or a number from the photo. With it go the words from the on-device analysis (for example "cake"), a few simple tags that the app sets on the iPhone (for example "taken late at night" or "an old photo"), the types of your last 5 meals and the last 3 lines of the pet. No tag holds a place or a date. Up to 3 short notes about what the pet ate lately go too, for example "Ramen: 4 times in the last 7 days". The app makes them on the iPhone from the pet's diary. They never hold a photo with a face, a sensitive subject, or your answers to the pet's questions. You can delete each note in Settings, on the page about what the pet knows. A few short facts about the pet go too: its mood, the days since its first meal, its favorite food, an open craving and the last line it said from its own memory. The app makes these on the iPhone. They hold no words of yours and no answer to a question of the pet. The app language, the app version and a random id go too. The id only limits the number of requests for each day. It is not the id of the usage data, and it holds no name and no device id.

The app never sends a photo with a face or a photo of a sensitive subject (for example medicine, alcohol, a passport or a license plate). It never sends a photo that you did not feed.

Where it goes: to our server on Cloudflare Workers, and from there through the router OpenRouter to the main model, the open-weight model DeepSeek V4.1 Flash. The hosts that run it are Together AI, DeepInfra and Fireworks AI, tried in this order, all in the United States. When the main model gives no answer in time, our server sends the same request once more to the backup model, the open-weight model Gemma 3 27B from Google. The hosts that run it are DeepInfra and Parasail, tried in this order, both in the United States. OpenRouter may not send the request to any other host. Each request carries the flags "zero data retention" and "no data collection". No party keeps the photo or the line after the answer. No party uses them to train a model.

The weights of DeepSeek V4.1 Flash come from DeepSeek, a company in China. No data goes to DeepSeek and no data goes to China. The hosts above only run the open weights on their own machines.

Our server keeps no photo and no line. It keeps salted hashes of the random install id and your IPv4 address or IPv6 network prefix. It does not store the raw IP address in these counters. These 2 values count the requests of each day. Our server deletes them after 2 days. Cloudflare AI Gateway keeps the model name, the token counts, the cost and the status of each request. Payload logging is off, so it keeps no photo and no line. The app sends 30 photos a day at most.

Photo library access

With your permission the app shows your recent photos on the home screen, so you can feed the pet with one tap. You can refuse. The app then uses the system photo picker, which gives the app only the photo that you select. You can change the access at any time in the Settings app.

Photo places are optional and off until you enable Settings, "Use photo places". With your agreement, the app reads photo location metadata and keeps a rough area of about 1 kilometre in the diary, never the exact position or a place name. Places stay on your iPhone. Turning this off stops new reads and place reactions; existing diary places remain until you delete those diary pages.

Usage data (optional, off until you agree)

The app sends anonymous usage events to our database at Supabase. No usage events are collected or sent until you choose to share them during onboarding or enable Settings, "Usage data". You can turn this off at any time in Settings. Off stops the events at once and deletes the events that the app has not sent yet. The events are, for example, "app opened", "photo fed" with a category such as "food", "paywall seen", and "purchase". When you tap an answer to a question of the pet, the event holds the code of the question and the code of your choice (for example "sea_or_mountain" and "sea"), not the words. When the pet comes back from a night trip, the event holds the code of the destination. Each event holds a random install id, the app version, the iOS version, the device model and the language. It holds no name, no email address, no photo, no photo label, no line from the AI service and no advertising id. We do not link the events to you and we do not track you across apps. Crash and hang reports from Apple's MetricKit use the same channel and the same switch. We delete events after 365 days.

Purchases

Apple processes each purchase. The app sees only whether the Friends Pack is active.

Children

The app has no accounts, no chat, no ads and no links to social networks inside the app.

Third parties and your choices

We share data only with the services named above: Cloudflare (our server), OpenRouter and the AI hosts for AI lines, and Supabase for usage data. Each of them processes the data only for us, under terms that protect it at least as well as this policy.

To stop AI lines, turn off Settings, "AI lines". To stop usage data, turn off Settings, "Usage data". To stop photo access, use the Settings app. To delete the diary and all data on your iPhone, delete the app. Our server keeps no photo and deletes its counters after 2 days. To ask us to delete the usage events of your install, write to the contact address below. We answer within 30 days.

Contact

support@kazukiminami.com


プライバシーポリシー

最終更新日: 2026年10月3日。このポリシーは iOS アプリ「もぎゅ」(Mogyu) に適用されます。

「AIのひとこと」をオンにしないかぎり、写真はiPhoneの外に出ません

任意の「写真を整理」では、アクセスできる元の写真から自分で選び、選択した写真を確認してから、Appleの写真アプリの確認画面を通じて削除を依頼できます。ペットに食べさせても元の写真は削除されません。元の写真を削除しても、日記に保存された別のコピーは残ります。整理する写真の選択は端末内だけに保存され、サーバーには送られません。ペットの見た目の設定や、その見た目に使う直近の写真のおおまかなカテゴリも、端末内だけに保存されます。

写真の解析は、お使いのiPhoneの中で行います。AppleのVisionフレームワークが写真の内容を判定し、ペットがセリフを選びます。Apple Intelligenceに対応したiPhoneでは、Appleのオンデバイスモデルが、同じくiPhoneの中でセリフを考えることがあります。「AIのひとこと」(次の項目)をオンにしないかぎり、写真そのもの、写真の一部、解析結果をサーバーに送信することはありません。ごはん日記には、写真の小さなコピーをアプリ内の保存領域に保存します。日記のページを削除するか、アプリを削除すると、そのコピーも消えます。

AIのひとこと(任意・初期設定はオフ)

この機能を使える写真をはじめてあげたときに、アプリが確認の画面を出します。「許可する」を選ぶと、あげた写真についてのひとことをAIサービスが考えます。「このiPhoneの中だけにする」を選ぶと、これまでどおりで、写真がiPhoneの外に出ることはありません。この設定は、アプリの「設定」→「AIのひとこと」でいつでも変更できます。

1回のごはんで送信するもの: あげた写真1枚の小さなコピー(長辺512ピクセル。位置情報、撮影日時、その他のメタデータはすべて取りのぞきます。写真の中の文字(レシート、メモ、スクリーンショットなど)は、レシートやメモの内容にペットが反応できるよう、そのまま送ります。アプリの「設定」→「写真の文字をAIに見せない」をオンにすると、送る前に文字をぬりつぶし、文字がほとんどの写真は送りません。どの場合も、AI事業者はデータを保持しません(後述)。また、写真の中の名前、住所、数字をくり返さないように、当方のサーバーがAIモデルに指示しています)、端末内の解析で得られた言葉(例:「ケーキ」)、アプリがiPhoneの中で付ける簡単なタグ(例:「夜おそくに撮った」「むかしの写真」。場所や日時は含みません)、直近5回のごはんの種類、ペットの直近3つのセリフ、ペットが最近食べたものについての短いメモ(最大3つ。例:「ラーメン を この7日で 4回」)、ペット自身についての短い情報(いまの気分、はじめてのごはんからの日数、いちばん好きな食べもの、いま食べたいもの、ペットが最後に言った思い出のセリフ)、アプリの言語、アプリのバージョン、ランダムなID。このIDは1日あたりの送信回数を制限するためだけに使います。利用状況データのIDとは別のもので、氏名や端末のIDは含みません。短いメモは、ペットの日記をもとにiPhoneの中で作ります。顔が写っている写真やデリケートな写真のこと、ペットの質問へのあなたの答えは、メモに入りません。メモは、設定の「ペットが覚えていること」のページで1つずつ消せます。ペット自身の情報も、日記からその場で作ります。あなたが書いた文章や、ペットの質問への答えは含みません。

送信しないもの: 顔が写っている写真、デリケートな内容の写真(例: 薬、お酒、パスポート、ナンバープレート)、あげていない写真。

送信先: 当方のサーバー(Cloudflare Workers)から、ルーターのOpenRouterを通じて、メインのモデルであるオープンウェイトのモデル「DeepSeek V4.1 Flash」に送信します。実行するのは、アメリカ合衆国のTogether AI、DeepInfra、Fireworks AIのいずれかで、この順に試します。メインのモデルが時間内に答えなかったときは、当方のサーバーが同じリクエストを1回だけ、予備のモデルであるGoogleのオープンウェイトモデル「Gemma 3 27B」に送ります。実行するのは、アメリカ合衆国のDeepInfra、Parasailのいずれかで、この順に試します。OpenRouterがほかの事業者にリクエストを回すことはありません。各リクエストには「zero data retention(データ保持なし)」と「no data collection(データ収集なし)」を指定しています。応答が返ったあと、写真もセリフも、どの事業者も保持しません。学習に使うこともありません。

「DeepSeek V4.1 Flash」の重みは、中国の企業であるDeepSeek社が公開したものです。ただし、DeepSeek社や中国にデータが送られることはありません。上記の事業者は、公開された重みを自社の設備で動かしているだけです。

当方のサーバーは写真もセリフも保存しません。1日の送信回数を数えるために、ランダムなインストールIDと、IPv4アドレスまたはIPv6アドレスのネットワーク部分を、ソルトを付けたハッシュに変換して保持します。この回数カウンターに元のIPアドレスは保存しません。2日が過ぎたら削除します。Cloudflare AI Gatewayには、モデル名、トークン数、料金、ステータスが記録されます。ペイロードの記録はオフにしているため、写真もセリフも記録されません。送信は1日30枚までです。

写真ライブラリへのアクセス

許可をいただいた場合、最近の写真をホーム画面にならべ、ワンタップでペットにあげられるようにします。許可しなくてもアプリは使えます。その場合はシステムの写真ピッカーを使い、アプリには選んだ写真だけが渡されます。アクセスの設定は「設定」アプリでいつでも変更できます。

写真の場所の利用は任意です。「設定」→「写真の場所を使う」で同意するまでオフです。同意した場合、写真の位置情報を読み、日記には約1キロメートルのおおまかな範囲だけを保存します。正確な位置や地名は保存せず、iPhoneの外には送りません。オフにすると新しい読み取りと場所の反応を止めます。保存済みの場所は、その日記のページを削除するまで残ります。

利用状況データ(任意・同意するまでオフ)

アプリは匿名の利用イベントを、当方の分析用データベース(Supabase)に送信します。はじめて起動したときの画面、または「設定」→「利用状況データ」で送信を選ぶまで、利用イベントを収集・送信しません。アプリの「設定」→「利用状況データ」で、いつでもオフにできます。オフにすると送信はすぐに止まり、まだ送っていないイベントも削除します。イベントの例:「アプリを開いた」「写真をあげた(カテゴリ: 食べもの など)」「購入画面を見た」「購入した」。ペットの質問に答えたときのイベントには、質問と選んだ答えのコード(例:「sea_or_mountain」と「sea」)が含まれます。文章は含まれません。ペットが夜の旅から帰ったときのイベントには、行き先のコードが含まれます。各イベントには、ランダムなインストールID、アプリのバージョン、iOSのバージョン、機種名、言語が含まれます。氏名、メールアドレス、写真、写真のラベル、AIサービスが考えたセリフ、広告IDは含まれません。イベントをお客様個人と結びつけることはなく、他社アプリをまたいだ追跡も行いません。AppleのMetricKitによるクラッシュ・フリーズのレポートも、同じ経路で送信し、同じスイッチで止まります。イベントは365日後に削除します。

購入

購入の処理はAppleが行います。アプリが知るのは「なかまパック」が有効かどうかだけです。

お子さまについて

アカウント、チャット、広告、アプリ内からSNSへのリンクはありません。

第三者への提供と、あなたが選べること

データを渡すのは、上に書いた事業者だけです。当方のサーバー(Cloudflare)、「AIのひとこと」のためのOpenRouterとAI事業者、利用状況データのためのSupabaseです。どの事業者も当方のためだけにデータを扱い、このポリシーと同等以上の保護を約束しています。

「AIのひとこと」をやめるには、アプリの「設定」→「AIのひとこと」をオフにしてください。利用状況データの送信をやめるには、「設定」→「利用状況データ」をオフにしてください。写真へのアクセスは「設定」アプリで止められます。日記など、iPhoneの中のデータをすべて消すには、アプリを削除してください。当方のサーバーは写真を保存せず、回数のカウントは2日で削除します。利用状況データの削除をご希望の場合は、下のお問い合わせ先までご連絡ください。30日以内にお返事します。

お問い合わせ

support@kazukiminami.com