プライバシーポリシー
Privacy Policy
KiraKiran
このアプリについて
KiraKiran はネイル技術者(サロンオーナー)ご本人が使う顧客管理(CRM)アプリです。アプリに登録するユーザーはご本人(技術者)のみで、メールアドレスによるワンタイムコード(OTP)でサインインします。パスワードは使用しません。
技術者がアプリ内に入力する情報の多くは、技術者自身のものではなくお客様(第三者)に関する情報です。この点をご理解のうえ、必要な範囲でお客様の同意を得たうえでご利用ください。
収集・保存する情報
- 技術者ご本人の情報:サインインに使うメールアドレスと、認証用のセッション情報。
- 顧客情報:氏名・ふりがな・電話番号・誕生日・メモ(自由記述)。
- 健康・アレルギーに関する情報(要配慮個人情報):アレルギーや体質に関するフラグとメモを、専用の項目として保存します。これは日本の個人情報保護法(APPI)上「要配慮個人情報」に該当し、記録には事前にお客様ご本人の同意が必要です。同意の取得は技術者の責任で行ってください。
- SNS掲載の同意フラグ:初期値はオフで、お客様ごとに個別に設定します。
- 施術記録:予約日時、メニュー内容、料金、ステータス、メモ。
- 写真:参考デザイン写真と仕上がり写真。非公開のストレージに保存され、アプリ内でのみ、期限付きの署名付きURLを通じて表示されます。
アプリの利用状況を計測する解析(アナリティクス)・広告・トラッキングSDKは一切組み込まれていません。
データの保存場所と通信
データは Supabase(東京リージョン)にHTTPS通信でのみ保存・送信されます。サインイン用のワンタイムコードは Resend 経由でメール送信されますが、これはサーバー側の設定のみで行われ、アプリから直接 Resend と通信することはありません。SupabaseおよびResendは、データの委託処理者であり、データを第三者に販売・提供することはありません。
デバイスの権限
カメラおよび写真ライブラリへのアクセスは、参考デザイン写真・仕上がり写真を撮影・選択する目的でのみ使用します。
データの保持と削除
- 個々の顧客データ:アプリ内から個別の顧客を完全に削除する機能は現在ありません(アーカイブ扱いとなり、データは保持されます)。
- アカウントの削除:設定画面から「アカウントを削除」を行うと、確認手順のうえで、あなたのアカウントに紐づくすべてのデータ(顧客情報、施術記録、写真、写真ストレージ、アカウント本体)がサーバー側で完全に削除されます。この操作は取り消せません。
お問い合わせ
開発者: Ciaran Fontein
連絡先: ciaranfontein@gmail.com
本ポリシーの変更
新しい機能の追加やデータ取り扱いの変更があった場合、本ポリシーを改定し、施行日を更新します。
施行日: 2026-07-13
About this app
KiraKiran is a client-management (CRM) app used by an independent nail technician (salon owner). The only registered user is the technician herself, who signs in with an emailed one-time code (OTP). There are no passwords.
Most of the information the technician enters in the app is not about her. It's abouther clients (a third party). She is responsible for obtaining any consent required from her clients before recording it.
What's collected and stored
- The technician's own data: her sign-in email address and session tokens.
- Client data: name, name reading (furigana), phone number, birthday, and free-text notes.
- Health / allergy information: a dedicated allergy/health flag and note field. This qualifies under Japan's Act on the Protection of Personal Information (APPI) as "special-care-required personal information," which requires the client's prior consent to record. Obtaining that consent is the technician's responsibility.
- SNS-publication consent: off by default, set per client.
- Appointment records: date/time, menu, price, status, notes.
- Photos: design-reference and result photos, stored in a private bucket and shown in-app only via short-lived signed URLs.
No analytics, advertising, or tracking SDK is included in the app.
Where data lives and how it travels
Data is stored with Supabase (Tokyo region) and transmitted over HTTPS only. Sign-in codes are delivered by email via Resend, configured server-side. The app itself never talks to Resend directly. Supabase and Resend act only as processors; neither sells nor shares data with third parties.
Device permissions
Camera and photo-library access are used only to capture or pick design-reference and result photos.
Retention and deletion
- Individual client records: the app does not currently offer a way to fully delete a single client. They can be archived, and the underlying data is retained.
- Account deletion: from Settings, "Delete account" (after a confirmation step) permanently deletes all data tied to the technician's account on the server: clients, appointments, photos, photo storage, and the account itself. This cannot be undone.
Contact
Developer: Ciaran Fontein
Contact: ciaranfontein@gmail.com
Changes to this policy
This policy will be revised, with an updated effective date, if new features or data handling change.
Effective date: 2026-07-13