隱私權政策
最後更新:2026 年 10 月
走路工(Salary Walker,以下簡稱「本服務」)重視您的隱私。本政策說明我們如何收集、使用及保護您的個人資料。使用本服務即表示您同意本政策之內容。
一、收集的資料
- 本機資料與存檔同步:薪資設定、遊戲進度等首先儲存於您裝置上的 localStorage。在您登入帳號之後,這份存檔(含您填入的薪資設定與遊戲內的金幣、資產等數值)會自動同步至我們的伺服器,以便跨裝置接續遊玩。其中自選股清單與持股資料在伺服器端以 AES-256-GCM 加密儲存(每位使用者獨立金鑰);薪資設定則作為一般存檔內容儲存,傳輸過程全程 HTTPS 加密,但未另行加密於資料庫中。未登入時(訪客模式)資料僅留在您的裝置上。您可在 設定 →「雲端同步」最下方刪除帳號與所有雲端資料。
- Google 登入資料:若您選擇 Google 帳號登入,我們會取得您的姓名、電子郵件及頭像,僅用於帳號識別與跨裝置同步。
- 使用統計:本站使用 Google Analytics 收集匿名瀏覽統計(頁面瀏覽次數、裝置類型等),不含個人識別資訊。
- 產品行為分析:本站使用 PostHog 收集產品行為分析事件(功能使用次數、流程完成率等)。此項會與您的身分關聯:您登入後,這些事件會與您的帳號識別資訊關聯,包含公開 ID、電子郵件、暱稱、英雄等級與訂閱狀態。PostHog 的畫面錄影功能(session replay)已於 2026 年 8 月 6 日起完全停用,我們不會錄製您的畫面操作。
- 錯誤報告與效能指標(2026 年 8 月 25 日起):為了找出當機與卡頓,本站透過 PostHog 收集未被處理的 JavaScript 錯誤(錯誤訊息、錯誤發生的程式位置與呼叫堆疊)以及網頁效能指標(最大內容繪製 LCP、互動延遲 INP、版面位移 CLS、首次內容繪製 FCP)。我們不會刻意蒐集您輸入的內容,也不會擷取畫面;瀏覽器主控台(console)的訊息不在收集範圍內。錯誤訊息由瀏覽器與程式在出錯當下即時產生,因此可能夾帶到您輸入過的文字。為此,錯誤訊息在離開您的裝置前會先經過自動遮蔽:電子郵件、權杖與金鑰、網址參數、長串識別碼與數字、引號內的長字串,以及連續的中文/日文文字,都會被替換成佔位符(例如
[email]、[text]),並截短長度。但這是盡力而為的過濾,我們無法保證百分之百排除。效能指標則只有時間與數值,不含任何文字內容。與上一項相同,您登入後這些事件會與您的帳號識別資訊關聯。
- 位置與天氣資料:當您在 設定 →「天氣特效」選擇「所在地」模式時,本服務會呼叫第三方天氣服務 WeatherAPI(api.weatherapi.com)取得當地天氣,用於在遊戲畫面顯示對應的天氣效果。傳送給 WeatherAPI 的內容為依您的連線推估、並降低精度至小數點後兩位(約 1.1 公里)的概略座標;一般情況下不會傳送您的 IP 位址,但在少數取不到概略座標的情況下,仍可能改以您的 IP 位址向該服務查詢。天氣結果僅在邊緣節點快取 15 分鐘,不會寫入資料庫、不與您的遊戲帳號關聯,也不用於廣告用途;推估出的地名僅用於在設定頁「目前天氣」旁顯示地點。若您將天氣特效切換為「關閉」「自選」或「隨機」,本服務即不會發出此請求。
- 待認養動物配對的位置使用:當您在寵物頁展開「現實中的同伴」區塊時,本服務會依您的連線推估概略位置,用來把離您較近的收容所排在前面。此處的位置完全不會傳送給任何第三方(待認養資料是本服務每日自行向農業部開放平台取得,與個別玩家無關),也不會回傳到您的瀏覽器——回應中沒有任何座標或距離數字,只有收容所名稱。此位置不寫入資料庫、不與您的遊戲帳號關聯。您可在 設定 →「現實中的同伴」關閉此區塊,關閉後不會發出任何相關請求。
- Apple 登入資料:若您使用「透過 Apple 登入」,我們會取得 Apple 提供的使用者識別碼與電子郵件(若您選擇「隱藏我的電子郵件」,取得的是 Apple 的私密轉寄地址),僅用於帳號識別與跨裝置同步。姓名僅在第一次授權時由 Apple 提供。
- 當機與錯誤診斷(Sentry):本站使用 Sentry 收集未被處理的錯誤與例外(錯誤訊息、程式位置、呼叫堆疊、瀏覽器版本與發生錯誤時的網址)。錯誤訊息在離開您的裝置前會先經過遮蔽處理,且我們已關閉主控台記錄的上傳,避免夾帶遊戲存檔內容。
- 頭像圖片:若您自訂角色或寵物頭像,您選擇的圖片會在您的裝置上被裁切與像素化後上傳,儲存於您的帳號並顯示給您的好友。
- 問題回報:您透過遊戲內「問題回報」送出的內容(描述文字、您自願填寫的聯絡方式、瀏覽器版本資訊)會被儲存並轉寄至我們的聯絡信箱。
- 您輸入的遊戲內容:暱稱、角色留言、寵物名稱、公會名稱與簡介,以及「討厭的人」清單等由您自行輸入的文字,會隨遊戲存檔同步至伺服器。請勿填入他人的真實個人資料。
- 聊天室(僅網頁版):網頁版的公開聊天室由 Google Firebase Realtime Database 提供,您送出的訊息、暱稱與頭像會被儲存並顯示給其他玩家。iOS App 不含聊天功能。
- 付款資料:目前所有購買都在 iOS App 內進行(網頁版已不提供付款功能);先前在網頁版購買的訂閱,付款由 Polar.sh(授權經銷商)處理。本服務不會接觸或儲存您的卡片資訊;但會保留訂單編號、交易金額、付款狀態與退款狀態等交易記錄,供訂閱管理與客服使用。若您在 iOS App 內購買,付款由 Apple 處理,我們收到與保存的交易資料請見第五節。
二、Cookie 的使用
- 必要性 Cookie:維持登入狀態與基本功能運作。
- 分析 Cookie(Google Analytics):收集匿名使用統計。
- 分析 Cookie(PostHog):用於產品行為分析,登入後會與您的帳號識別資訊(電子郵件、暱稱)關聯,但不進行畫面錄影。
三、第三方服務
本服務不投放任何廣告,也不與廣告商或資料仲介分享您的資料。我們使用下列第三方服務,各自的用途與資料如下:
- Google Analytics(分析)/PostHog(產品行為分析,登入後與帳號關聯)
- Sentry(當機與錯誤診斷;錯誤訊息經遮蔽,不上傳主控台記錄)
- Google/Apple 登入(帳號識別)
- WeatherAPI(僅在您開啟「所在地」天氣特效時,傳送降精度後的概略座標)
- Google Firebase Realtime Database(僅網頁版聊天室;iOS App 不含此功能)
- YouTube(Google)(僅網頁版:遊戲封面與遊戲內「說明」面板的預告片縮圖由本站提供;您按下播放後才會載入內嵌的 YouTube 播放器(隱私強化模式 youtube-nocookie.com),此後的資料處理適用 Google 隱私權政策;iOS App 不含此功能)
- Polar.sh(網頁版訂閱付款的授權經銷商;本服務不接觸卡片資訊)
- Apple App Store(僅在您於 iOS App 內購買時:處理付款、訂閱續訂與退款;本服務不接觸您的付款資訊)
四、您的選擇
- 天氣定位:在 設定 →「天氣特效」改選「所在地」以外的模式,即不再傳送概略座標。
- 待認養配對:收合寵物頁的「現實中的同伴」區塊即停止使用概略位置。
- 分析 Cookie:可在瀏覽器設定中管理或封鎖第三方 Cookie。
- 刪除帳號:可在 設定 →「雲端同步」最下方自行刪除。我們會刪除您的帳號、所有遊戲資料(存檔、進度、股票與投資設定)、社交資料(好友、好友邀請、公會關聯、封鎖名單)與雲端備份;財務與法遵紀錄(金流交易、訂閱事件、問題回報與檢舉紀錄)依法保留,但其中的使用者識別碼會替換成不可逆的雜湊值,無法再對應到您本人。此操作無法復原(見第八節)。
五、付款資料處理
網頁版付款(Polar.sh)
- 網頁版的付款交易由 Polar.sh(授權經銷商)處理,符合 PCI-DSS 標準。
- 本服務不會接觸或儲存任何信用卡資訊,卡片資料全部由 Polar.sh 管理。
- 本服務會保留交易記錄(訂單編號、交易金額、付款狀態、退款狀態),用於訂閱管理與客服查詢。您刪除帳號後,這些記錄仍會保留,但其中的使用者識別碼會去識別化(替換為不可逆的雜湊值)。
- Polar.sh 之隱私政策請參閱其官方網站。
iOS App 內購買(Apple)
- 若您在 iOS App 內購買鑽石或訂閱 Pro,付款由 Apple 透過您的 Apple 帳號處理。本服務不會接觸或取得您的信用卡或其他付款資訊,也不會取得您的 Apple 帳號密碼。
- 購買完成後,Apple 會提供一份經 Apple 簽章的交易紀錄。我們會驗證這份紀錄,並將下列資料與您的遊戲帳號關聯後儲存:交易編號與原始交易編號、商品編號、商品類型、購買日期、訂閱到期日、撤銷(退款)日期、交易環境(正式或測試),以及 Apple 簽章的交易紀錄原文(其中可能包含 Apple 提供的其他交易欄位)。訂閱另會保存 Apple 回報的訂閱狀態、到期日與是否自動續訂。
- 我們使用這些資料的目的是:把鑽石或 Pro 發給正確的遊戲帳號、避免同一筆交易重複發放、依 Apple 回報的狀態更新訂閱(續訂、到期、退款),以及客服查詢。為此,我們會以交易編號向 Apple 的伺服器查詢訂閱狀態,並接收 Apple 傳送的交易狀態通知。
- App 內購買的退款由 Apple 依其政策受理與處理(見退款政策)。
六、資料的保護
- 所有雲端同步資料透過 HTTPS 加密傳輸
- 財務資料(資產快照、股票庫存等)採 AES-256-GCM 加密儲存於伺服器
- 本服務不會將您的個人資料出售給第三方
- Session 權杖採隨機 48 位元組生成,定期自動過期
七、未成年人保護
本服務不針對 13 歲以下兒童收集個人資料。若您是未成年人,請在父母或監護人同意下使用本服務。
八、您的權利
依《個人資料保護法》,您享有以下權利:
- 查詢或閱覽您的個人資料
- 製給複製本
- 補充或更正
- 停止蒐集、處理或利用
- 刪除您的個人資料
如需行使上述權利,請聯絡:hnigel@gmail.com
九、政策變更
本政策如有重大變更,我們將於本頁面公告,並更新頁面頂端的修訂日期。繼續使用本服務即表示您接受更新後的政策。
十、聯絡我們
如有隱私相關問題,請聯絡:hnigel@gmail.com
Privacy Policy
Last updated: October 2026
Salary Walker ("the Service") values your privacy. This policy explains how we collect, use, and protect your personal information. By using the Service, you agree to the terms of this policy.
1. Information We Collect
- Local Data and Save Sync: Salary settings, game progress, and other data are first stored in your device's localStorage. Once you sign in, this save file — including the salary settings you enter and in-game values such as coins and assets — is automatically synced to our servers so you can continue on another device. Your stock watchlist and holdings are stored encrypted at rest with AES-256-GCM using a per-user key; your salary settings are stored as ordinary save data — transmitted over HTTPS, but not separately encrypted in the database. While signed out (guest mode), the data stays on your device only. You can delete your account and all cloud data at the bottom of Settings → "Cloud Sync".
- Google Sign-in Data: If you choose to sign in with Google, we obtain your name, email address, and profile picture, used solely for account identification and cross-device sync.
- Analytics: We use Google Analytics to collect anonymous browsing statistics (page views, device types, etc.) that contain no personally identifiable information.
- Product Behavior Analytics: We use PostHog to collect product behavior events (feature usage counts, flow completion rates, etc.). These events are linked to your identity: once you sign in, these events are linked to your account identity, including your public ID, email address, display name, hero level, and subscription status. PostHog's session replay has been fully disabled since August 6, 2026 — we do not record your screen.
- Error Reports and Performance Metrics (since August 25, 2026): To find crashes and slowdowns, we collect unhandled JavaScript errors (error message, source location, and stack trace) and web performance metrics (LCP, INP, CLS, FCP) through PostHog. We do not intentionally collect anything you type, and no screen content is captured; browser console messages are not collected. Because error messages are produced by the browser and the code at the moment of failure, they may incidentally include text you entered. To limit this, error messages are automatically redacted before leaving your device: email addresses, tokens and keys, URL parameters, long identifiers and number strings, long quoted strings, and runs of Chinese/Japanese text are replaced with placeholders (e.g.
[email], [text]) and the message is truncated. This is a best-effort filter and we cannot guarantee complete removal. Performance metrics contain only timings and numeric values, never text. As with the item above, these events are linked to your account identity once you sign in.
- Location and Weather Data: When you set Settings → "Weather FX" to the "Local" mode, the Service calls the third-party weather provider WeatherAPI (api.weatherapi.com) to retrieve local conditions so that the game can display matching weather effects. What we send is an approximate location estimated from your connection and reduced in precision to two decimal places (roughly 1.1 km). Under normal operation we do not send your IP address; however, in the rare cases where no approximate location is available, we may query the service using your IP address instead. Weather responses are cached at the edge for 15 minutes only, are never written to our database, are not linked to your game account, and are not used for advertising. The estimated place name is used solely to show your location next to "Current" weather on the settings page. Switching Weather FX to "Off", "Pick", or "Random" stops this request from being made at all.
- Location Use for Adoptable-Animal Matching: When you expand the "Companions in Real Life" section on the pet page, the Service estimates your approximate location from your connection in order to rank nearby shelters first. This location is never sent to any third party (the adoptable-animal data is fetched by us once a day from the Ministry of Agriculture's open data platform, independently of any individual player) and is never returned to your browser — the response contains no coordinates and no distance figures, only shelter names. It is not written to our database and is not linked to your game account. You can turn this section off under Settings → "Companions in Real Life"; no such request is made while it is off.
- Sign in with Apple Data: If you use Sign in with Apple, we receive the Apple user identifier and an email address (a private relay address if you chose "Hide My Email"), used only for account identification and cross-device sync. Your name is provided by Apple on first authorization only.
- Crash and Error Diagnostics (Sentry): We use Sentry to collect unhandled errors and exceptions (error message, code location, stack trace, browser version, and the URL where the error occurred). Error messages are redacted before leaving your device, and console log capture is disabled so game save content is not included.
- Avatar Images: If you set a custom character or pet avatar, the image you choose is cropped and pixelated on your device, then uploaded, stored with your account, and shown to your friends.
- Bug Reports: Content you submit through the in-game bug report form (description, optional contact details you provide, browser version) is stored and forwarded to our contact mailbox.
- Game Content You Enter: Display name, character remarks, pet names, guild name and description, and your "annoying people" list are synced to our servers with your save data. Please do not enter other people's real personal information.
- Chat (Web Only): The public chat room on the web version is powered by Google Firebase Realtime Database; messages, display name and avatar you send are stored and shown to other players. The iOS app does not include chat.
- Payment Data: All purchases are now made in the iOS app (the web version no longer offers payments); subscription payments previously made on the web version were processed by Polar.sh, our authorized Merchant of Record. We never handle or store your card details; we do retain transaction records (order number, transaction amount, payment status, and refund status) for subscription management and customer support. If you purchase in the iOS app, payment is processed by Apple; see Section 5 for the transaction data we receive and store.
2. Cookie Usage
- Essential Cookies: Required to maintain login sessions and basic functionality.
- Analytics Cookies (Google Analytics): Used to collect anonymous usage statistics.
- Analytics Cookies (PostHog): Used for product behavior analytics, linked to your account identity (email address, display name) once you sign in, but never including session replay.
3. Third-Party Services
This Service does not serve any advertising and does not share your data with advertisers or data brokers. We use the following third-party services:
- Google Analytics (analytics) / PostHog (product analytics, linked to your account once signed in)
- Sentry (crash and error diagnostics; error messages are redacted and console logs are not uploaded)
- Google / Apple Sign-In (account identification)
- WeatherAPI (only when you enable "Current location" weather effects; receives coarsened coordinates)
- Google Firebase Realtime Database (web chat room only; not included in the iOS app)
- YouTube (Google) (web only: the trailer thumbnail on the game's cover screen and in the in-game Help panel is served by this site; the embedded YouTube player (privacy-enhanced mode, youtube-nocookie.com) loads only after you tap play, and from then on is subject to the Google Privacy Policy; not included in the iOS app)
- Polar.sh (Merchant of Record for web subscriptions; we never handle card data)
- Apple App Store (only when you purchase in the iOS app: processes payment, subscription renewals and refunds; we never handle your payment details)
4. Your Choices
- Weather location: Choose any weather mode other than "Current location" in Settings to stop sending coarse coordinates.
- Adoption matching: Collapse the "Real-world companions" section on the pet page to stop using coarse location.
- Analytics cookies: Manage or block third-party cookies in your browser settings.
- Delete your account: You can do this yourself at the bottom of Settings → Cloud Sync. We delete your account, all game data (saves, progress, stock and investment settings), social data (friends, friend requests, guild membership, blocked list) and cloud backups. Financial and compliance records (payment transactions, subscription events, bug reports and content reports) are retained as required by law, but the user identifier in them is replaced with an irreversible hash so they can no longer be traced back to you. This cannot be undone (see Section 8).
5. Payment Data Handling
Web payments (Polar.sh)
- Payment transactions on the web version are processed by Polar.sh, our authorized Merchant of Record, which is PCI-DSS compliant.
- We never handle or store any credit card information. All card data is managed by Polar.sh.
- We do retain transaction records (order number, transaction amount, payment status, refund status) for subscription management and customer support enquiries. These records survive account deletion, but the user identifier in them is de-identified (replaced with an irreversible hash).
- Please refer to Polar.sh's official website for their privacy policy.
In-app purchases on iOS (Apple)
- If you buy diamonds or subscribe to Pro in the iOS app, payment is processed by Apple through your Apple Account. We never see or receive your credit card or other payment details, or your Apple Account password.
- After a purchase, Apple provides a transaction record signed by Apple. We verify it and store the following linked to your game account: transaction ID and original transaction ID, product ID, product type, purchase date, subscription expiry date, revocation (refund) date, environment (production or test), and the Apple-signed transaction record itself (which may contain other transaction fields supplied by Apple). For subscriptions we also store the subscription status, expiry date and auto-renew setting reported by Apple.
- We use this data to deliver diamonds or Pro to the correct game account, to prevent the same transaction from being delivered twice, to keep your subscription in sync with the status Apple reports (renewal, expiry, refund), and for customer support. To do so, we query Apple's servers for subscription status using the transaction ID and receive transaction status notifications sent by Apple.
- Refunds for in-app purchases are handled by Apple under Apple's policies (see our Refund Policy).
6. Data Protection
- All cloud-synced data is transmitted via HTTPS encryption
- Financial data (asset snapshots, stock holdings, etc.) is encrypted with AES-256-GCM on our servers
- We will never sell your personal data to third parties
- Session tokens are generated with 48 random bytes and automatically expire on a regular basis
7. Children's Privacy
The Service does not knowingly collect personal information from children under the age of 13. If you are a minor, please use the Service with the consent of a parent or guardian.
8. Your Data Rights
Under Taiwan's Personal Data Protection Act (PDPA), you have the following rights:
- Access and review your personal data
- Request a copy of your data
- Supplement or correct your data
- Request cessation of collection, processing, or use
- Request deletion of your personal data
To exercise any of the above rights, please contact: hnigel@gmail.com
Note: These rights are provided under Taiwan's PDPA. Users in other jurisdictions may have additional or different rights under their local laws.
9. Policy Changes
If significant changes are made to this policy, we will post a notice on this page and update the revision date at the top. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related questions, please contact: hnigel@gmail.com
プライバシーポリシー
最終更新:2026年10月
ウォーカー(Salary Walker、以下「本サービス」)は、お客様のプライバシーを大切にしています。本ポリシーでは、個人情報の収集・利用・保護について説明します。本サービスのご利用により、本ポリシーの内容に同意したものとみなされます。
1. 収集する情報
- ローカルデータとセーブ同期:給与設定やゲームの進行状況などは、まずお客様の端末の localStorage に保存されます。ログイン後は、このセーブデータ(お客様が入力された給与設定や、ゲーム内のコイン・資産などの数値を含みます)が自動的に当社のサーバーへ同期され、別の端末でも続きから遊べるようになります。このうちウォッチリストと保有銘柄はサーバー側で AES-256-GCM により暗号化して保存されます(利用者ごとに個別の鍵)。給与設定は通常のセーブデータとして保存され、通信はすべて HTTPS で暗号化されますが、データベース内での個別の暗号化は行っていません。未ログイン時(ゲストモード)はデータが端末内にのみ保持されます。アカウントとすべてのクラウドデータは、設定 →「クラウド同期」の最下部から削除できます。
- Google ログインデータ:Google アカウントでログインを選択された場合、お名前・メールアドレス・プロフィール画像を取得し、アカウント識別とデバイス間の同期にのみ使用します。
- 利用統計:Google Analytics を使用して匿名の閲覧統計(ページビュー数、デバイスの種類など)を収集しています。個人を特定する情報は含まれません。
- プロダクト行動分析:PostHog を使用してプロダクト行動分析イベント(機能の利用回数、フローの完了率など)を収集しています。これらは個人と紐づく情報です:ログイン後は、これらのイベントがお客様のアカウント識別情報(公開 ID、メールアドレス、ニックネーム、ヒーローレベル、サブスクリプション状態)と紐づけられます。PostHog のセッションリプレイ(画面録画)機能は 2026 年 8 月 6 日より完全に無効化しており、お客様の画面操作を録画することはありません。
- エラーレポートと性能指標(2026 年 8 月 25 日より):クラッシュや動作の重さを特定するため、PostHog を通じて未処理の JavaScript エラー(エラーメッセージ、発生箇所、スタックトレース)とウェブ性能指標(LCP・INP・CLS・FCP)を収集しています。お客様が入力された内容を意図的に収集することはありません。画面の取得も行わず、ブラウザのコンソール出力も収集しません。ただしエラーメッセージはブラウザやプログラムが発生時に生成するため、お客様が入力された文字が混入する可能性があります。そのため、エラーメッセージは端末を離れる前に自動的にマスキングされます(メールアドレス、トークンや鍵、URL パラメータ、長い識別子や数字列、引用符内の長い文字列、連続する日本語・中国語の文字をプレースホルダー(例:
[email]、[text])に置換し、長さも切り詰めます)。ただしこれは best-effort のフィルタであり、完全な除去を保証するものではありません。性能指標には時間と数値のみが含まれ、文字情報は含まれません。上記と同様に、ログイン後はアカウント識別情報と紐づけられます。
- 位置情報と天気データ:設定 →「天気エフェクト」で「現在地」モードを選択されている場合、本サービスはサードパーティの天気サービス WeatherAPI(api.weatherapi.com)を呼び出し、画面に対応する天気エフェクトを表示するために現地の天気を取得します。WeatherAPI に送信されるのは、お客様の接続情報から推定し、小数点以下 2 桁(約 1.1 km)まで精度を下げたおおよその座標です。通常の動作ではお客様の IP アドレスを送信することはありませんが、おおよその位置が取得できない一部のケースでは、代わりに IP アドレスを用いて同サービスに問い合わせる場合があります。取得した天気はエッジで 15 分間のみキャッシュされ、データベースに保存されることも、ゲームアカウントと紐づけられることも、広告に利用されることもありません。推定された地名は、設定ページの「現在の天気」の横に地点を表示する目的にのみ使用します。天気エフェクトを「オフ」「手動選択」「ランダム」に切り替えた場合、このリクエストは行われません。
- 里親募集動物のマッチングにおける位置情報の利用:ペットページで「現実の仲間たち」セクションを展開された場合、本サービスは接続情報からおおよその現在地を推定し、お近くの保護施設を上位に表示するためにのみ使用します。この位置情報はいかなる第三者にも送信されません(里親募集データは、個々のプレイヤーとは無関係に、本サービスが毎日農業部のオープンデータから取得しています)。またブラウザに返されることもありません——応答に座標や距離の数値は含まれず、施設名のみです。データベースへの保存やゲームアカウントとの紐付けも行いません。設定 →「現実の仲間たち」でこのセクションをオフにでき、オフの間は関連するリクエストは一切行われません。
- Apple サインイン情報:「Appleでサインイン」をご利用の場合、Apple から提供されるユーザー識別子とメールアドレス(「メールを非公開」を選択された場合は Apple のプライベートリレーアドレス)を取得し、アカウント識別とデバイス間同期にのみ使用します。氏名は初回認証時のみ Apple から提供されます。
- クラッシュ・エラー診断(Sentry):未処理のエラーや例外(エラーメッセージ、コード位置、スタックトレース、ブラウザのバージョン、発生時の URL)を Sentry で収集します。エラーメッセージは端末を離れる前にマスキング処理され、コンソールログの送信は無効化しているため、ゲームのセーブ内容が含まれることはありません。
- アバター画像:キャラクターやペットのアバターをカスタマイズした場合、選択した画像は端末上で切り抜き・ピクセル化されたのちアップロードされ、アカウントに保存されてフレンドに表示されます。
- 不具合報告:ゲーム内の「不具合報告」から送信された内容(説明文、任意でご記入の連絡先、ブラウザのバージョン情報)は保存され、当方の連絡先メールに転送されます。
- お客様が入力したゲーム内コンテンツ:ニックネーム、キャラクターのひとこと、ペット名、ギルド名と説明、「嫌いな人」リストなどの入力テキストは、セーブデータとともにサーバーへ同期されます。他人の実在する個人情報は入力しないでください。
- チャット(ウェブ版のみ):ウェブ版の公開チャットは Google Firebase Realtime Database を利用しており、送信したメッセージ・ニックネーム・アバターは保存され他のプレイヤーに表示されます。iOS アプリにチャット機能はありません。
- 決済データ:現在、購入はすべて iOS アプリ内で行われます(ウェブ版には決済機能はありません)。以前ウェブ版で購入されたサブスクリプションの支払いは、認定販売代理店(Merchant of Record)である Polar.sh が処理しました。本サービスがお客様のカード情報を取り扱ったり保存したりすることはありません。ただし、サブスクリプション管理およびカスタマーサポートのため、取引記録(注文番号、取引金額、支払い状況、返金状況)は保持します。iOS アプリ内で購入された場合、決済は Apple が処理します。当方が受け取り保存する取引データについては第 5 条をご覧ください。
2. Cookie の使用について
- 必須 Cookie:ログイン状態の維持と基本機能の動作に必要です。
- 分析 Cookie(Google Analytics):匿名の利用統計の収集に使用します。
- 分析 Cookie(PostHog):プロダクト行動分析に使用します。ログイン後はお客様のアカウント識別情報(メールアドレス、ニックネーム)と紐づけられますが、画面録画は行いません。
3. サードパーティサービス
本サービスは広告を一切配信しておらず、広告事業者やデータブローカーへの情報提供も行いません。利用しているサードパーティサービスは以下のとおりです。
- Google Analytics(分析)/PostHog(プロダクト行動分析。ログイン後はアカウントと紐づけ)
- Sentry(クラッシュ・エラー診断。エラーメッセージはマスキングされ、コンソールログは送信しません)
- Google/Apple サインイン(アカウント識別)
- WeatherAPI(「現在地」天候エフェクトを有効にした場合のみ、精度を落とした座標を送信)
- Google Firebase Realtime Database(ウェブ版チャットのみ。iOS アプリには含まれません)
- YouTube(Google)(ウェブ版のみ。ゲームのカバー画面とゲーム内「ヘルプ」パネルのトレーラーのサムネイルは本サイトから配信します。埋め込みの YouTube プレーヤー(プライバシー強化モード youtube-nocookie.com)は再生ボタンを押した後にのみ読み込まれ、以降のデータの取り扱いには Google プライバシーポリシーが適用されます。iOS アプリには含まれません)
- Polar.sh(ウェブ版サブスクリプションの認定販売代理店。カード情報は当方で扱いません)
- Apple App Store(iOS アプリ内で購入された場合のみ。決済・サブスクリプションの更新・返金を処理します。お支払い情報は当方で扱いません)
4. お客様の選択
- 天候の位置情報:設定の「天候エフェクト」で「現在地」以外を選ぶと、概略座標の送信は停止します。
- 里親マッチング:ペットページの「現実の相棒」セクションを閉じると概略位置の利用は停止します。
- 分析 Cookie:ブラウザ設定でサードパーティ Cookie を管理・ブロックできます。
- アカウント削除:設定 →「クラウド同期」の最下部からご自身で削除できます。アカウント、すべてのゲームデータ(セーブ、進行状況、株式・投資設定)、ソーシャルデータ(フレンド、フレンド申請、ギルド所属、ブロックリスト)、クラウドバックアップを削除します。財務・法令遵守の記録(決済取引、サブスクリプション履歴、不具合報告・通報記録)は法令に基づき保持しますが、含まれる利用者識別子は不可逆のハッシュ値に置き換えられ、お客様と紐付けられなくなります。この操作は取り消せません(第 8 条参照)。
5. 決済情報の取り扱い
ウェブ版の決済(Polar.sh)
- ウェブ版の決済取引は、PCI-DSS 準拠の認定販売代理店(Merchant of Record)である Polar.sh が処理します。
- 本サービスがクレジットカード情報を取り扱ったり保存したりすることは一切ありません。カード情報はすべて Polar.sh が管理します。
- 本サービスは、サブスクリプション管理およびカスタマーサポートのお問い合わせ対応のため、取引記録(注文番号、取引金額、支払い状況、返金状況)を保持します。アカウント削除後もこれらの記録は保持されますが、含まれる利用者識別子は匿名化(不可逆のハッシュ値に置換)されます。
- Polar.sh のプライバシーポリシーについては、同社の公式サイトをご参照ください。
iOS アプリ内課金(Apple)
- iOS アプリ内でダイヤモンドを購入、または Pro を購読された場合、決済はお客様の Apple アカウントを通じて Apple が処理します。本サービスがお客様のクレジットカードその他のお支払い情報や Apple アカウントのパスワードを取得することはありません。
- 購入が完了すると、Apple が署名した取引記録が提供されます。当方はこれを検証し、以下の情報をお客様のゲームアカウントに紐づけて保存します:取引 ID と元の取引 ID、商品 ID、商品の種類、購入日、サブスクリプションの有効期限、取り消し(返金)日、取引環境(本番またはテスト)、および Apple が署名した取引記録そのもの(Apple が提供するその他の取引項目が含まれる場合があります)。サブスクリプションについては、Apple から通知される購読状態、有効期限、自動更新の設定も保存します。
- これらの情報は、ダイヤモンドや Pro を正しいゲームアカウントに付与するため、同じ取引の二重付与を防ぐため、Apple から通知される状態(更新・期限切れ・返金)に合わせて購読状態を更新するため、およびカスタマーサポートのために使用します。そのため、取引 ID を用いて Apple のサーバーに購読状態を問い合わせ、Apple から送信される取引状態の通知を受信します。
- アプリ内課金の返金は、Apple のポリシーに基づき Apple が受け付け・処理します(返金ポリシーをご覧ください)。
6. データ保護措置
- クラウド同期データはすべて HTTPS 暗号化で送信されます
- 金融データ(資産スナップショット、株式保有など)は AES-256-GCM 暗号化でサーバーに保存されます
- お客様の個人データを第三者に販売することは一切ありません
- セッショントークンは48バイトのランダム値で生成され、定期的に自動失効します
7. 児童のプライバシー
本サービスは、13歳未満のお子様から意図的に個人情報を収集することはありません。未成年の方は、保護者の同意のもとで本サービスをご利用ください。
8. あなたのデータに関する権利
台湾の個人情報保護法に基づき、以下の権利があります:
- 個人データの照会・閲覧
- 個人データの複製の請求
- 個人データの補正・修正
- 収集・処理・利用の停止の請求
- 個人データの削除の請求
上記の権利を行使するには、こちらまでご連絡ください:hnigel@gmail.com
注:これらの権利は台湾の個人情報保護法に基づくものです。他の法域のユーザーは、現地の法律に基づき追加的または異なる権利を有する場合があります。
9. ポリシーの変更
本ポリシーに重要な変更がある場合、本ページで告知し、ページ上部の改訂日を更新します。変更後も本サービスを継続してご利用いただくことで、更新されたポリシーに同意したものとみなされます。
10. お問い合わせ
プライバシーに関するご質問は、こちらまでご連絡ください:hnigel@gmail.com