Pochi and Moji — Privacy Policy
Last updated: 16 September 2026 Effective: 16 September 2026
Daiju Ishikawa ("we", "us", "our") sets out below how we handle user information in the iOS app "Pochi and Moji" (Japanese name ポチッと文字; the "App").
1. Principles
The App is built on three principles.
- Audio never leaves your device. Transcription runs on your iPhone. The App has no mechanism for sending recorded audio files to our servers or anywhere else.
- The cloud is a waypoint, not a store. The transcript and the generated result that are sent to our servers for document generation are deleted once your device has received the result. If receipt cannot be confirmed, they are deleted automatically on or after the day following creation.
- Your transcripts and documents are not used to train AI models. Neither we nor the generative AI provider we use will use your transcripts or generated results to train models.
The App contains no advertising SDKs and no third-party behavioural tracking SDKs. We do not collect user behaviour for analytics purposes.
In this policy, "our servers" means the system we build and manage on Amazon Web Services. We do not own or operate physical servers ourselves; we combine AWS managed services (a serverless architecture). The individual providers and their locations are listed in section 4.
2. Information we collect, and where it is held
| Information | When it is collected | Where it is held | Retention |
|---|---|---|---|
| Audio | When you record | Your device only | The period you set per project (7 days by default). Recordings that are still processing or have failed are not deleted even after the period elapses |
| Transcript | When transcription runs | Your device | The period you set per project (90 days by default) |
| Same | When you run document generation | Our servers (AWS) | Deleted once your device has received the generated result. If receipt cannot be confirmed, deleted automatically on or after the day following creation (at most about 48 hours later) |
| Same | Same | The generative AI provider (Anthropic) | → section 5 |
| Generated documents | On document generation | Our servers (AWS) / the generative AI provider | Same as the transcript |
| Same | On filing | Your device, your Obsidian Vault (iCloud Drive), and Notion if you have configured it | Under your control. We do not delete them |
| Recording date, duration and project name | On document generation | Our servers (AWS) | Used only for generation. Deleted from the server when processing completes |
| Authentication identifier | At sign-in (immediately before document generation) | Our servers (AWS) and our billing provider (RevenueCat) | The identifier issued by Apple, converted into a one-way hash. We do not collect your name or email address. Held until you delete your account |
| Usage records | On document generation | Our servers (AWS) | Character count, token count, document type, AI model used, success or failure, error category, timestamp, and credits spent or returned. They do not include the body text, the title, the project name, the recording date or the duration. 400 days |
| Technical logs | During server processing | Our servers (AWS) | Character counts, processing IDs and error categories only. Body text is never written to logs. 14 days |
| Purchase information | When you buy credits | Apple and RevenueCat | The product purchased, the timestamp and the transaction identifier. We do not receive your credit card details |
| Notion token (optional) | When you configure it | Your device only (Keychain) | Never sent to our servers |
| Output folder access rights | When you select a folder | Your device only | — |
| Settings backup file (optional) | When you export it | Under your control | Project settings only. Tokens, connection details and folder access rights are excluded |
In addition, only if you use the contact form on the support page, we collect the information described in section 8. That is collected by a web form, not by the App itself.
3. Purposes of use
| Information | Purpose |
|---|---|
| Transcript, recording date, duration and project name | To generate a document and return it to you. The date is used so that phrases such as "next Monday" can be read as a calendar date |
| Authentication identifier | To associate your credit balance with you and to manage spending and returns. To prevent misuse |
| Usage records | To keep a record of credits spent and returned. To understand and improve the cost and quality of the service. To manage the daily usage limit. To total unused balances as required by law |
| Technical logs | To detect faults and investigate their causes |
| Purchase information | To grant credits and to respond to enquiries about purchases |
4. Disclosure to, and processing by, third parties
We do not sell or disclose your information to third parties except where required by law. In providing the App we entrust processing to, or use the services of, the following providers.
| Provider | Role | Information they receive | Location |
|---|---|---|---|
| Apple Inc. | Sign in with Apple, In-App Purchase, iCloud Drive | Sign-in and purchase information. The contents of a Vault held in iCloud Drive are governed by your agreement with Apple | United States |
| Amazon Web Services, Inc. | The platform for our servers (file storage, processing, records, detection of malicious instructions) | Transcripts and generated results (temporarily), usage records, technical logs | Japan (Tokyo region ap-northeast-1) |
| Anthropic, PBC | Document generation by generative AI (Claude) | Transcript, recording date, duration, project name, generated result | United States (→ section 5) |
| RevenueCat, Inc. | Credit purchases and balance management | The hashed authentication identifier, purchase information, credits spent and returned | United States |
| Notion Labs, Inc. (optional) | Destination for document output | Generated documents, only if you enable Notion output. Sent directly from your device; they do not pass through our servers | United States |
| Cloudflare, Inc. | Bot protection for the contact form | → section 8 | United States |
Please refer to each provider's own privacy policy for how they handle personal information.
- Apple: https://www.apple.com/legal/privacy/en-ww/
- Amazon Web Services: https://aws.amazon.com/privacy/
- Anthropic: https://www.anthropic.com/legal/privacy
- RevenueCat: https://www.revenuecat.com/privacy/
- Notion: https://www.notion.so/privacy
- Cloudflare: https://www.cloudflare.com/privacypolicy/
5. Handling by the generative AI provider (Anthropic)
Document generation is performed using the Claude API provided by Anthropic, PBC. The following applies to that processing.
| Item | Detail |
|---|---|
| Where processing occurs | United States |
| Use for training | Not used |
| Retention | Anthropic deletes inputs (transcripts) and outputs (generated results) within 30 days of receiving them |
| Batch processing | To keep costs down, generation may be run as a batch. Batch inputs and outputs are retained for up to 29 days by design, but we delete the batch immediately after receiving the result (usually within a few minutes) |
| Exception | Where content is automatically flagged as violating Anthropic's usage policies, Anthropic may retain the relevant inputs and outputs for up to two years |
We design the App so that a transcript is treated as material to be processed rather than as instructions to the model. If the transcript contains something that reads like an instruction, the model does not follow it; it records it as something that was said.
We may also evaluate transcripts using an AWS security inspection feature (Amazon Bedrock Guardrails, Tokyo region) in order to detect injected malicious instructions. The inspection exists to create a record, not to block generation. The only thing we record from it is the classification of the verdict; we do not record the body text or the passage concerned.
6. Provision to third parties located abroad
Of the providers listed in section 4, Apple Inc., Anthropic, PBC, RevenueCat, Inc., Notion Labs, Inc. and Cloudflare, Inc. are located in the United States. We provide the following information in accordance with the Act on the Protection of Personal Information of Japan.
| Item | Detail |
|---|---|
| Country | United States of America |
| The data protection regime of that country | Please refer to the survey of foreign personal data protection regimes published by the Personal Information Protection Commission of Japan ( https://www.ppc.go.jp/ ) |
| Measures taken by each provider | Each provider applies security measures to the information it receives under its own privacy policy and its contract with us. See the privacy policies listed in section 4 |
7. Security measures
- All communication with our servers, and with each provider, is encrypted (TLS).
- Transcripts and generated results held temporarily on our servers are stored encrypted.
- The body of transcripts and generated results is never written to server logs.
- Each server process runs with the minimum privileges it needs.
- The credentials used to reach the generative AI provider are held only in an encrypted store on our servers and are not embedded in the App.
- Daily caps on processing volume and spend limit the damage from misuse or faults.
- The authentication identifier is held as a one-way hash that cannot be reversed.
8. Information collected by the contact form
If you use the contact form on the support page ( https://da-leca.click/en/app/pochimoji/support ), we collect the following. None of it is collected by the App itself.
| Item | Purpose | Sent to AI analysis |
|---|---|---|
| Reply email address (required) | To reply to your enquiry | No |
| Name (optional) | To address our reply | No |
| Subject and message (required) | To understand and handle your enquiry | Yes (summarisation, categorisation, draft reply) |
| Source IP address and User-Agent | To detect abusive submissions and to investigate faults | No |
This information is processed and stored using the following AWS services (Tokyo region ap-northeast-1).
- Amazon API Gateway / AWS Lambda: receiving the form submission
- Cloudflare Turnstile: preventing automated (bot) submissions
- Amazon Bedrock (Anthropic Claude): summarising, categorising and drafting a reply
- Amazon S3: storing the enquiry history
- Amazon SES: sending the developer digest email and the automatic acknowledgement
Retention
| Item | Retention |
|---|---|
| The enquiry as submitted (name, email address, message) | Deleted automatically 365 days after receipt |
| AI analysis results (summary, category, urgency) | Retained indefinitely, in a form that contains no personal information, for product improvement and FAQ planning |
| Automatic acknowledgement send logs | Deleted automatically 365 days after receipt |
Transmission to third parties
- Enquiry content is passed to Anthropic's Claude model via Amazon Bedrock. This is processing inside AWS and is governed by the AWS data handling policies (AWS Customer Agreement / AWS Service Terms). Input sent via Bedrock is not used to train models.
- Nothing is sent to external AI services other than AWS and Cloudflare.
9. Deleting information held on your device
Audio and transcripts on your device are deleted automatically once the retention period you set per project has elapsed. You may delete a recording session manually at any time.
If you delete the App from your device, the audio, transcripts, settings and Notion token held on that device are all removed. Documents already filed in your Obsidian Vault or in Notion are under your control and are not removed by deleting the App.
10. Account deletion and your rights
10.1 Deleting your account
You may delete your account at any time from the settings screen in the App. Doing so releases the link between the hashed authentication identifier we hold and your credit balance. Unused credits become unusable (→ Terms of Service 3.13).
Usage records (statistics containing no body text) are separated from the identifier and retained until the end of their retention period, so that we can keep the records the law requires.
10.2 Requests for disclosure, correction or suspension of use
You may request disclosure, correction, addition, deletion or suspension of use of the information we hold about you. Requests are received at the contact point in section 13.
⚠️ We hold the authentication identifier only as a hash, and cannot identify a user from a name or email address. When making a request, please therefore include something that identifies the account concerned — the date you purchased credits, or the order ID shown on your App Store receipt, for example. Where we cannot identify the account, we may be unable to act on the request.
11. A request about recording
The App records conversations. Whether you need the consent of the people you are recording depends on the country, region and circumstances. Please obtain any consent required before you record. We do not review or monitor what you record.
12. Children
We do not knowingly collect personal information from children under 13. A minor should use the App only with the consent of a parent or guardian.
13. Contact
For enquiries about this policy or about how we handle your information, and for requests for disclosure, please contact us here.
| Item | Detail |
|---|---|
| Operator | Daiju Ishikawa |
| Address and telephone number | Disclosed without delay on request. Please contact us at the email address or through the contact form below |
| Email address | info@da-leca.click |
| Contact form | https://da-leca.click/en/app/pochimoji/support |
14. Changes to this policy
We may change this policy in response to changes in the law or in the service. When we do, we will publish the revised policy on this page and update the "Last updated" date at the top. We will announce significant changes in advance in the App or on the support page ( https://da-leca.click/en/app/pochimoji/support ).
The revised policy applies from the time it is published, or from the effective date stated in the announcement.
15. Governing law and jurisdiction
The interpretation of this policy and any dispute arising in connection with the App are governed by Japanese law, and the Tokyo District Court shall have exclusive jurisdiction in the first instance.
16. Language
This policy is drawn up in Japanese. Translations into English, Spanish or any other language are provided for reference only; if there is any discrepancy, the Japanese version prevails.