PRIVACY POLICY

CaloriesBunny (モグダイエット)

Effective Date: April 12, 2025

Last Updated: April 12, 2025

This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the CaloriesBunny application (also marketed under the Japanese name モグダイエット, "Mogudaietto") and all associated services (the "Application"). This Privacy Policy has been prepared in compliance with the Act on the Protection of Personal Information (個人情報の保護に関する法律, "APPI"), the guidelines issued by the Personal Information Protection Commission (個人情報保護委員会, "PPC"), and other applicable Japanese laws and regulations.

By using the Application, you consent to the collection and processing of your personal information as described in this Privacy Policy. If you do not consent, please do not use the Application.

1. WHO WE ARE AND HOW TO CONTACT US

CaloriesBunny / モグダイエット is operated by Calorie note ("we", "us", "our"), a business entity engaged in the development and operation of mobile software applications. We are committed to protecting your privacy and handling your personal data with transparency and in accordance with applicable law.

Personal Information Protection Manager (個人情報保護管理者): Dongsu Kim Founder

Contact for Privacy Enquiries: caloriesbunnysupport@gmail.com

Response Time: We will endeavor to respond to all privacy-related enquiries within 14 days of receipt and will in all cases comply with response timelines required under APPI.

2. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to all personal information collected from users of the Application, whether collected through the Application itself, through account registration, through in-app interactions, through third-party service integrations, or through any other means in connection with your use of the Application.

This Policy does not apply to third-party websites, services, or applications that may be linked from the Application. We encourage you to review the privacy policies of any third-party services you access in connection with or through the Application.

3. CATEGORIES OF PERSONAL INFORMATION COLLECTED

We collect the following categories of personal information from users of the Application:

3.1 Registration and Account Information:

3.2 Health and Biometric Profile Data:

Under the APPI, health-related personal information is treated as requiring heightened protection. We apply additional security and access controls to this category of data. We collect this information only with your explicit consent and solely for the purpose of providing personalized nutritional analysis and progress tracking within the Application.

3.3 Food and Nutritional Data:

3.4 Technical and Device Data:

3.5 Usage and Analytics Data:

We do not collect precise geolocation data. We do not knowingly collect sensitive personal information beyond Health Data as described above.

4. HOW WE COLLECT PERSONAL INFORMATION

We collect personal information through the following means:

We do not collect personal information from third-party data brokers or social media platforms.

5. LEGAL BASIS AND PURPOSE OF DATA PROCESSING

Under the APPI and applicable PPC guidelines, we process your personal information on the following bases and for the following purposes:

We do not use your personal information for automated individual decision-making that produces legal or similarly significant effects without human review.

6. USE OF FOOD PHOTOGRAPHS AND AI PROCESSING

When you submit a food photograph or text description through the Application for nutritional analysis, the data is transmitted to the Google Gemini API for AI-powered processing. We wish to be fully transparent about the following:

We do not use your food photographs to train AI models without your explicit consent. We do not share your food photographs with third parties other than Google (via the Gemini API) in the course of providing the nutritional analysis service.

7. SHARING OF PERSONAL INFORMATION

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We share your personal information only in the following circumstances:

7.1 Service Providers and Data Processors:

All third-party service providers are engaged under appropriate contractual arrangements requiring them to protect your personal information in accordance with applicable law and to use it only for the purposes for which it was disclosed.

7.2 Legal Requirements:

We may disclose your personal information where required to do so by law, court order, or in response to a legitimate request by a Japanese governmental or regulatory authority, including the PPC, or as otherwise required under applicable law.

7.3 Business Transfers:

In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, your personal information may be transferred to the acquiring entity as part of that transaction. We will provide notice of any such transfer and the opportunity to exercise your rights under the APPI.

8. INTERNATIONAL DATA TRANSFERS

The Application integrates with services operated by companies located outside Japan, including Supabase (United States), Google LLC (United States), Sentry (United States), and Upstash (United States). When your personal information is transferred to these providers, it may be processed and stored outside Japan.

Such cross-border transfers of personal data are conducted in accordance with Article 24 of the APPI and the PPC's guidelines on the provision of personal information to third parties in foreign countries. We take the following measures to ensure appropriate protection:

You may request information about the safeguards in place for cross-border transfers by contacting us using the contact details provided in Section 1.

9. DATA RETENTION

We retain your personal information for the periods necessary to fulfill the purposes described in this Privacy Policy, subject to any longer retention periods required by applicable law.

Upon expiry of the applicable retention period, personal information will be securely deleted or anonymized in accordance with our data destruction procedures.

10. SECURITY MEASURES

We implement technical and organizational security measures to protect your personal information against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures include:

However, no security system is impenetrable. We cannot guarantee the absolute security of your personal information and cannot be responsible for unauthorized access resulting from circumstances beyond our reasonable control. We encourage you to use strong, unique passwords and to safeguard your account credentials.

11. YOUR RIGHTS UNDER THE APPI

Under the Act on the Protection of Personal Information (APPI), as amended by the 2022 reforms which took effect on April 1, 2022, you have the following rights with respect to your personal information held by us:

To exercise any of these rights, please contact us using the details in Section 1, clearly identifying yourself and describing your request. We will verify your identity before processing any request. We will respond within the timeframes required by the APPI.

If you are dissatisfied with our response to any privacy-related request or complaint, you have the right to lodge a complaint with the Personal Information Protection Commission (個人情報保護委員会) at https://www.ppc.go.jp/.

12. CONSENT AND WITHDRAWAL OF CONSENT

Where we process your personal information on the basis of consent, including the processing of Health Data, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

You may withdraw consent by: (i) deleting your account through the Application settings, which will trigger deletion of your Health Data; (ii) contacting us directly to request cessation of specific processing activities; or (iii) disabling specific data collection features within the Application settings where such options are available.

13. CHILDREN'S PRIVACY

The Application is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If we become aware that we have inadvertently collected personal information from a child under 13, we will take prompt steps to delete such information.

If you are a parent or guardian and believe that your child under the age of 13 has provided personal information to us without your consent, please contact us immediately at the contact details provided in Section 1 so that we may take appropriate action.

14. THIRD-PARTY LINKS AND SERVICES

The Application may contain links to third-party websites or services or may integrate with third-party platforms. We are not responsible for the privacy practices of third parties, and their collection and use of your information is not governed by this Privacy Policy. We encourage you to review the privacy policies of all third-party services before providing personal information to them.

In particular, in-app purchase transactions are processed by Apple Inc. or Google LLC through their respective platform stores. The collection and processing of payment information in connection with in-app purchases is governed by the applicable platform's privacy policy, not this Privacy Policy.

15. COOKIES AND TRACKING TECHNOLOGIES

The Application and its associated backend services use certain tracking and identification technologies, including session tokens, device identifiers, and server-side logging. The use of these technologies is described in our Cookie Policy, which forms part of this Privacy Policy. Please refer to our Cookie Policy for detailed information about the technologies used, their purpose, and your management options.

16. IN-APP PURCHASES AND PAYMENT DATA

We do not collect, store, or process your payment card information or financial account details. All payment transactions for in-app purchases are processed exclusively by Apple Inc. (for iOS users) or Google LLC (for Android users) through their secure payment platforms. We receive only confirmation of successful or failed transactions and a transaction reference number for account management purposes.

For information about how your payment data is handled in connection with in-app purchases, please refer to Apple's or Google's applicable privacy policies.

17. AUTOMATED DECISION-MAKING

The Application uses automated AI processing (via the Google Gemini API) to generate nutritional estimates from food photographs and text descriptions. This automated processing is used to provide the core functionality of the Application. The nutritional analysis generated is an estimate based on pattern recognition and does not constitute a clinical or medical assessment.

We do not use automated processing to make decisions about you that produce significant legal or similarly significant effects. All outputs of the AI nutritional analysis feature are informational only and are not used to make automated decisions about your eligibility for services, your health status, or any other matter affecting your rights or interests.

18. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our data practices, changes in applicable law, or changes in the Application's functionality. When we make material changes to this Privacy Policy, we will notify you through the Application, by email to the address associated with your account, or by any other appropriate means.

The updated Privacy Policy will be effective from the date stated at the top of this document. Your continued use of the Application following notification of changes constitutes your acceptance of the updated Privacy Policy. If you do not accept the updated Privacy Policy, you must cease use of the Application and delete your account.

19. CALIFORNIA AND INTERNATIONAL USERS

This Application is operated primarily for users in Japan and is governed by Japanese data protection law. However, we acknowledge that users may access the Application from other jurisdictions. To the extent applicable:

20. CONTACT US AND COMPLAINTS

If you have any questions, concerns, or complaints about this Privacy Policy, our privacy practices, or the handling of your personal information, please contact us at:

Email: caloriesbunnysupport@gmail.com

Subject Line: Privacy Enquiry — CaloriesBunny

We will acknowledge receipt of your enquiry within 3 business days and will provide a substantive response within 14 days, or within such other period as required by applicable law.

If you are not satisfied with our response, you have the right to escalate your complaint to the Personal Information Protection Commission (PPC) of Japan:

Personal Information Protection Commission (個人情報保護委員会)

Website: https://www.ppc.go.jp/

This Privacy Policy was drafted and last reviewed by legal counsel on April 12, 2025.