レシポケ / ReceiptPocket プライバシーポリシー 最終更新: 2026年9月22日 保存するデータ 領収書の元画像、スキャン画像、OCRの文字、店名、日付、金額、明細、タグ、フォルダ、申請状態は端末内に保存します。アプリ独自のアカウントはありません。保存領域はOSバックアップ対象外です。必要な資料はZIPで書き出してください。アプリへの復元は未対応です。 任意の写真への保存 スキャン画像の写真アプリへの自動保存は初期状態でオフです。オンにした場合、または詳細画面から写真に保存を選んだ場合だけ、写真への追加権限を使って画像を追加します。写真ライブラリの閲覧権限は求めません。アプリ内で削除しても写真アプリ側の複製は残ります。iCloud写真の同期は端末の設定に従います。 任意のGoogle Drive同期 設定で明示的に有効にした場合、選択したフォルダの提出用画像、領収書CSV、明細CSVを、接続したユーザー自身のGoogle DriveへHTTPSで直接送信します。元画像、OCR全文、クラウド解析の生レスポンスはDriveへ送りません。Googleアカウントのメールアドレスは接続中のアカウント表示にだけ使い、運営側へ送りません。レシポケのサーバーはDriveのファイルや認証トークンを受信・保存しません。同期を無効化またはアプリ内の領収書を削除しても、誤消去を防ぐためDrive上の複製は自動削除しません。Drive上のファイルはGoogle Driveで管理してください。 任意のクラウド解析 画像解析対応版では、送信内容と送信先を表示し、明示的な同意を得てからクラウド解析を有効にします。画像送信への同意がない場合は、画像もOCRの文字も新たに送信しません。設定の「クラウド解析を使う」をオフにすると、その後の解析を端末内だけで行います。画像解析対応版では、有効時は毎回縮小した領収書画像とOCRの文字をHTTPSでCloudflare Workers / Workers AI(必要に応じてAI Gatewayを経由)へ送り、店名、日付、金額、明細、タグなどを抽出します。AI自動仕分けを実行した場合は、選択した対象フォルダの名前・説明・識別子も送信して振り分け先を判断します。旧版はOCRの文字のみ送信します。領収書の内容には店舗、購入履歴などの個人情報が含まれることがあります。アプリ運営側のサーバーには領収書画像・本文・解析結果を保存せず、利用回数・モデル別のトークン使用量と内容を含まない診断ログ(ランダムなリクエストID、処理時間、モデル名、エラー・検証分類)を記録します。診断ログにOCR本文・画像・抽出金額・認証トークンは含めません。AI Gatewayを使用する場合も、画像・本文・解析結果のログ保存とキャッシュを無効にします。通信事業者の処理には各社のポリシーが適用されます。送信開始済みの処理は設定変更で取り消せない場合があります。 広告 一覧のバナー広告にはGoogle AdMobとUser Messaging Platformを使用します。広告配信、不正防止、同意管理、測定のため、Googleや広告パートナーがIPアドレス(おおよその地域)、端末・広告識別子、広告の表示や操作、診断・性能情報などを扱う場合があります。レシポケは領収書の画像、OCR、金額、タグ、検索語を広告SDKへ渡しません。 ユーザーの選択 iOSのApp Tracking Transparency(ATT)で許可した場合のみ、広告SDKが広告識別子を利用できます。拒否した場合はパーソナライズされていない広告をリクエストします。拒否してもスキャン、検索、仕分け、書き出しなどの機能は制限しません。許可はiOSの設定から変更できます。地域に応じた広告の同意画面が必要な場合は表示し、アプリの「広告とプライバシー」から必要な同意設定を変更できます。クラウド解析をオフにしても広告通信は別に行われます。広告の読み込みに失敗しても領収書の機能は使えます。 共有・削除 ZIPなどの書き出しはユーザーが選択した共有先に送ります。共有先やGoogle Driveに渡した複製は各サービスで管理してください。領収書はアプリ内で削除できます。アプリを削除すると端末内のアプリデータは削除されますが、OSのバックアップ、Drive同期、書き出した複製は別に管理してください。 外部サービス Google: https://policies.google.com/privacy?hl=ja Cloudflare: https://www.cloudflare.com/privacypolicy/ 変更 機能や利用するサービスを変更した場合は、このページを更新します。 プラン・購入と利用枠 無料プランはAI解析を月30枚、Proは月300枚まで利用できます。同じApp Storeのアプリ購入識別情報に対して利用枠を管理します。本人確認と購入検証のためApp Storeの署名付きアプリ購入・サブスクリプション情報をCloudflareへ送信します。サーバーは派生した識別子、契約の有効期限・失効情報、月の利用件数、同じ画像を二重に数えないためのハッシュを保存します。氏名やApple Accountのメールアドレス、カード番号は取得しません。レシートの画像や文字は保存しません。前月の利用ハッシュは次月の解析時に置き換えます。購入状態は購入復元・不正利用防止のため保持します。Proでは広告を表示しません。 --- English --- ReceiptPocket Privacy Policy Updated: September 23, 2026 Plans and usage: Free includes 30 AI-analyzed receipts per calendar month; Pro includes 300. App Store-signed app acquisition and subscription data is sent to Cloudflare to authenticate access and verify purchases. We retain a derived account identifier, entitlement expiry/revocation, usage counts, and hashes to avoid counting the same image twice. Previous-month hashes are replaced on the next month's analysis. Purchase state is retained for restoration and fraud prevention. We do not receive your name, Apple Account email, or payment-card details. Pro does not display ads. Receipt data is stored on your device: original and scanned images, OCR text, extracted receipt fields, tags, folders, and submission status. The app has no proprietary user account. The receipt storage directory is excluded from operating-system backups. Export important records as ZIP files. Importing these archives back into the app is not currently supported. Saving scans to Photos is optional and off by default. When enabled, or when you choose Save to Photos, the app requests add-only permission and adds the scan image. It does not request permission to read your photo library. Deleting a receipt in the app does not delete the Photos copy. iCloud Photos sync follows device settings. Google Drive sync is optional and must be explicitly enabled. When enabled, the processed submission image, receipt CSV, and line-item CSV for selected folders are sent directly over HTTPS to the connected user's own Google Drive. Original images, full OCR text, and raw cloud-analysis responses are not sent to Drive. The Google account email address is used only to identify the connected account on device and is not sent to us. Our server never receives or stores Drive files or Google authorization tokens. Disabling sync or deleting a receipt in the app does not automatically delete its Drive copy; manage those copies in Google Drive. Cloud analysis is optional. Image-analysis versions disclose the data and recipient and obtain explicit permission before enabling cloud analysis. Without image-analysis consent, neither images nor OCR text are newly transmitted. In image-analysis versions, a resized receipt image and OCR text are sent together for each analysis over HTTPS to Cloudflare Workers and Workers AI, through AI Gateway where configured, to extract receipt fields. When you run AI folder sorting, selected folder names, descriptions, and identifiers are also sent to determine a destination. Older versions send OCR text only. OCR text may contain personal purchase information. Our application server does not persist receipt images, text, or analysis results; it stores usage counters, per-model token usage, and content-free diagnostic logs (random request IDs, processing times, model names, and error/validation categories). Diagnostic logs do not include OCR text, images, extracted amounts, or authorization tokens. Disable cloud analysis in the app to process future receipts on device. Already transmitted requests may complete. When AI Gateway is used, payload logging and response caching are disabled. Providers process network requests under their own policies. The library uses Google AdMob banner ads and User Messaging Platform. Google and advertising partners may process IP-derived approximate location, device and advertising identifiers, advertising interactions, diagnostic and performance information for advertising, consent management, measurement, and fraud prevention. ReceiptPocket does not pass receipt images, OCR text, amounts, tags, or search queries to the advertising SDK. The advertising identifier is available only with iOS ATT authorization. If tracking is not authorized, the app requests non-personalized ads. Receipt features remain available regardless of your choice. Change ATT permission in iOS Settings. Where required, the app presents regional consent messages and provides an advertising privacy options entry point. Disabling cloud analysis does not disable advertising network requests. Exports are shared only with destinations you choose. Delete receipts in the app to remove their local records. Removing the app removes its local data; separately manage backups, Drive copies, and exported copies. Google and Cloudflare privacy policies are linked above. This page will be updated when the app's data practices change.