プライバシーポリシー
制定日:2026年9月19日 最終改定日:2026年9月19日
合同会社The Good Managers(以下「当社」)は、アプリ「Circles」および関連するウェブサイト(以下あわせて「本サービス」)で取得する利用者の個人情報を、個人情報の保護に関する法律(以下「個人情報保護法」)その他の法令に従い、以下のとおり取り扱います。
本サービスは、社会人のバスケットボールサークルが、練習試合の相手やメンバーを見つけるためのサービスです。そのため、あなたが入力した情報の多くは、ほかの利用者に表示されます。どの情報が誰に表示されるかは「4. 他の利用者に表示される情報」にまとめています。本サービスを使う前に、この章だけは必ずお読みください。
1. 事業者とお問い合わせ窓口
- 名称
- 合同会社The Good Managers
- 代表社員
- Pellan Aymeric
- 所在地
- 〒359-1117 埼玉県所沢市有楽町15-8
- お問い合わせ窓口
- 合同会社The Good Managers 個人情報お問い合わせ窓口
info@thegoodmanagers.com
開示・訂正・利用停止などのご請求、アカウントの削除の代行、その他個人情報の取扱いに関するお問い合わせは、すべてこの窓口で受け付けます。
2. 取得する情報
| 区分 | 内容 | 取得するとき |
|---|---|---|
| アカウント | メールアドレス。メールアドレスで登録した場合は、設定したパスワードのハッシュ化した値(元の文字列は当社も確認できません)。Googleでログインした場合は、Googleから受け取る情報(Googleアカウントの識別子、氏名、メールアドレスとその確認状況、プロフィール画像のURL、Google Workspaceをお使いの場合はその組織のドメイン) | 登録時、ログイン時 |
| プロフィール | 表示名(必須)、プロフィール写真、ポジション、身長、レベル、3x3/5x5の希望(表示名以外は任意)。アプリの表示言語 | 登録時、プロフィールの作成・編集時 |
| チームと所属 | チーム名、ロゴ、バナー、活動地域(都道府県・市区町村)、区分、レベル、チーム紹介、活動メモ、招待コード、メンバーの役割(管理者/メンバー)、背番号、参加した日 | チームの作成・編集時、参加・招待時 |
| 募集と申し込み | 練習試合の募集(日時、活動地域、会場名、メモ)、申し込みと直接の対戦申し込み、両チームの管理者のあいだでやりとりするメッセージ(2,000字まで) | 募集・申し込み・返信のとき |
| 試合と練習の予定 | 日付、開始・終了時刻、都道府県・市区町村、会場名、メモ、中止したことと中止の理由 | 試合・練習の作成・変更時 |
| 出欠 | 行く/行かない/未定の回答と、100字までのコメント、回答した日時 | 出欠を回答したとき |
| スコアと成績 | 試合中の得点の記録(誰がいつ入力し、取り消したか)、スコアを担当した人、試合結果、結果の訂正の記録、選手ごとのスタッツ(得点、アシスト、リバウンド、シュートの内訳)と、それを入力した人 | スコアの入力時、結果の確定・訂正時 |
| 記録とバッジ | XP、レベル、出場した試合数、勝敗、主催した回数、通算のスタッツ、獲得したバッジとその日時、ショーケースに選んだバッジ、設立したチーム。チームのレベルと特典 | 試合結果が確定したとき(自動で計算します) |
| チーム内のやりとり | チームチャットの本文(2,000字まで)、既読の時刻とチャットを開いているかどうか、練習の予定と出欠、動画リンク(YouTubeのURL、動画ID、タイトル)と追加した人 | チャット・練習・動画の利用時 |
| フィード | 投稿の本文(500字まで)と、一覧に表示するために投稿した時点で保存する内容(チーム名、試合結果、募集の概要など)、コメント(500字まで)、リアクション、フォローしているチーム、フィードで選んだ都道府県 | 投稿・コメント・リアクションのとき |
| メンバー募集 | 「チームを探しています」の投稿(都道府県・市区町村、希望ポジション、レベル、300字までのメモ)、チームのメンバー募集(募集ポジション、人数、レベル、300字までのメモ)、参加申請と招待(300字までのメッセージ、誰が招待したか)、練習へのビジター参加(100字までのメモ)、試合の助っ人の募集と応募(300字までのメッセージ)、チームがブロックした相手の記録 | 投稿・申請・招待・応募のとき |
| 通報とブロック | 通報した人、通報の対象、理由、500字までの詳細、通報された時点の内容の写し(本文や動画リンクと、コメント・チャットの場合は書いた人の識別子を含みます)。個人単位のブロックの記録 | 通報・ブロックのとき |
| 端末とプッシュ通知 | プッシュ通知用のトークン、インストールごとに生成する識別子、OSの種類、アプリのバージョン、トークンを登録したログインセッションの識別子、最後に確認した日時、受け取る通知の設定 | 通知を許可したとき、アプリの起動時 |
| お知らせの記録 | 本サービス上のお知らせ。表示のために、相手の表示名、チーム名、日時、会場名、メッセージ・コメント・投稿の冒頭100字までの抜粋を含みます。プッシュ通知を送った日時と、失敗した場合はその理由 | お知らせが発生したとき |
| 障害の記録 | 定期実行の処理が失敗したときの、処理の名前、対象の行の識別子、エラーの内容 | 処理が失敗したとき |
| お問い合わせ | メールアドレス、お問い合わせの内容 | お問い合わせ時 |
| 公開のお知らせの登録 | メールアドレス、ご登録のときのウェブサイトの表示言語、ご登録の日時 | このウェブサイトで公開のお知らせにご登録いただいたとき |
アプリの表示言語は、端末に保存するほか、プッシュ通知を送る言語を決めるためにアカウントにも保存します。
取得していない情報。本サービスは、生年月日、年齢、性別、国籍、電話番号、住所、決済情報を取得する項目を設けていません。端末の位置情報の権限は求めず、端末から位置情報を取得する仕組みはありません。活動地域は、あなたが一覧から選んだ都道府県・市区町村と、会場名として入力された文字列だけです。解析、広告、クラッシュレポートの仕組みは組み込んでいません。写真は、端末内でメタデータ(Exif。撮影場所や撮影日時を含むことがあります)を取り除いてから送信しますので、撮影場所はアップロードされません(「8.」)。
アクセスの記録について。本サービスのデータベースには、IPアドレス、ブラウザや端末の識別情報(ユーザーエージェント)、アクセスした日時を保存する項目はありません。一方、委託先であるSupabaseの基盤側では、認証やサーバーへのアクセスの記録(IPアドレスを含みます)が保存され、データベースのバックアップも取得されます。その内容と保存期間を決めているのは当社ではなくSupabaseであり、同社の提供するプランに応じて定められ、同社が公開する文書に記載されています。
3. 利用目的
- アカウントの作成と本人確認、ログイン状態の維持
- プロフィール、チームのページ、メンバー名簿の表示(利用者どうしが相手を確認できるようにするため)
- 練習試合の募集・申し込み・対戦相手との日程調整と、両チームの管理者のあいだのメッセージのやりとり
- 試合と練習の予定、出欠、当日の参加者の管理
- スコアの記録、試合結果の確定と訂正、選手ごとのスタッツの集計
- XP、レベル、バッジ、チームのレベルと特典の計算と表示
- チームのレーティングと全国ランキングの計算と公開
- メンバー、練習のビジター、試合の助っ人の募集と、申請・招待・承認のやりとり
- アプリ内のお知らせとプッシュ通知の送信(種類ごとに受け取るかどうかを設定できます)
- 通報への対応、ブロックの実行、規約違反や迷惑行為への対応、利用者の安全の確保
- お問い合わせへの対応
- 本サービスの公開のお知らせ(ウェブサイトでご登録いただいた方に、1回だけお送りします)
- 障害の調査と復旧、不具合の修正
- 規約やポリシーの変更など、重要なお知らせの連絡
- 法令に基づく対応
上記以外の目的には利用しません。とくに、宣伝のために利用することはありません。利用者の写真、表示名、投稿の内容を、広告、ストアの掲載情報、宣伝用のウェブサイトなどに使うことはしません。
4. 他の利用者に表示される情報
本サービスは、チームや選手どうしがお互いを見つけるためのサービスです。次の情報は、あなた以外の利用者に表示されます。メールアドレスそのものは、どの画面でも他の利用者に表示しません。ただし、メールアドレスで登録した直後の表示名には、メールアドレスの「@」より前の部分が使われます(下の「表示名の初期値について」をご覧ください)。
| 情報 | 見られる範囲 |
|---|---|
| プロフィール(表示名、写真、ポジション、身長、レベル、3x3/5x5の希望、アプリの表示言語、登録日) | ログインしているすべての利用者。相手との関係は問いません |
| 選手の記録(レベル、XP、通算の試合数と勝敗、通算のスタッツ、バッジの数、ショーケースのバッジ、設立したチームの数) | ログインしているすべての利用者。ただし、設立したチームの名前は、同じチームに所属している人にだけ表示します。バッジを獲得した日付は、ご本人にしか表示しません |
| プロフィール写真、チームのロゴ、チームのバナーの画像ファイル | URLを知っている人なら誰でも。ログインしていない人も開けます |
| チームのページ(チーム名、ロゴ、バナー、活動地域、区分、レベル、紹介文、活動メモ、メンバー数、レーティングとランキング、チームを作成した人) | ログインしているすべての利用者。解散したチームは、元メンバーにだけ表示されます |
| メンバー名簿(誰が所属しているか、役割、背番号、参加した日) | そのチームのメンバーだけ。ただし、チームを作成した人は上のチームのページから分かります |
| 練習試合の募集(日時、活動地域、会場名、メモ) | ログインしているすべての利用者 |
| 申し込みと、そのやりとりのメッセージ | 申し込んだチームと申し込まれたチームの管理者だけ。どちらのチームの一般メンバーにも表示しません |
| 試合の予定、出欠の回答とコメント、選手ごとのスタッツ | 対戦する両チームのメンバー。相手チームにも、あなたの出欠・コメント・スタッツが表示されます。承認した助っ人が見られるのは、試合の予定、スコアの記録、自分が入るチーム側の出欠の3つだけです(相手チームの出欠と、選手ごとのスタッツは見られません) |
| 試合結果、チームのレーティングと全国ランキング | ログインしているすべての利用者(チーム単位の情報として表示します) |
| 練習の予定と出欠、チームチャット | そのチームのメンバーだけ。チャットは、あなたが参加した時点より前の発言は表示されません。チャットを開いているあいだは、同じチームのメンバーにオンラインであることが表示されます |
| 動画リンク(YouTubeのURL、タイトル、キャプション) | 試合・練習の画面では、追加したチームのメンバーだけ(対戦相手にも表示しません)。フィードに投稿するときに「全体公開」を選ぶと、ログインしているすべての利用者に表示されます。「メンバーのみ」を選んだ場合はそのチームのメンバーだけです |
| フィードの「全体公開」の投稿 | ログインしているすべての利用者。チームの活動として表示し、投稿した個人の名前は表示しません |
| フィードのコメントとリアクション | その投稿を見られる人。コメントは、書いた人の表示名とともに表示されます |
| フィードの「メンバーのみ」の投稿 | そのチームのメンバーだけ |
| 「チームを探しています」の投稿 | Circlesでチームを運営している人(全国。次の項で詳しく説明します) |
| チームのメンバー募集 | ログインしているすべての利用者。フィードにも自動的に投稿されます |
| 練習のビジター枠 | ログインしているすべての利用者に、日付、時間、活動地域、会場名、参加費、残りの枠を表示します。チームの練習メモは表示しません |
| ビジターとして申し込んだこと(表示名、プロフィール、100字までのメモ) | 主催するチームのメンバー全員(管理者だけではありません) |
| 試合の助っ人の募集 | ログインしているすべての利用者に、日付、時間、活動地域、対戦相手、募集人数、希望ポジション、残りの枠を表示します。会場名とチームのメモは、承認した助っ人だけが見られます |
| 助っ人への応募(表示名、プロフィール、300字までのメッセージ) | 募集しているチームの管理者だけ。対戦相手にも、ほかの応募者にも表示しません |
| フォローしているチーム、個人単位のブロック | あなただけ。相手にも、そのチームにも表示しません |
「チームを探しています」の投稿について
この投稿を公開すると、表示名、プロフィール(写真、ポジション、身長、レベル)、選んだ活動エリア(都道府県・市区町村)、希望ポジション、レベル、300字までのメモが、Circlesでチームを運営している管理者であれば、地域を問わず全国の誰にでも表示されます。チームは誰でも作れるため、この範囲は「近くのチーム」よりも広いものです。所属しているチームは表示しません。
投稿は掲載開始から60日で掲載が終わり、アプリからいつでも取り下げられます。掲載が終わったあとも、投稿の記録自体はアカウントを削除するまで残ります(「11. 保存期間」)。
写真とURLについて
プロフィール写真、チームのロゴ、チームのバナーの画像は、CDNから誰でも開けるURLで配信しています。URLを知っていれば、Circlesにログインしていない人も画像を開けます。URLには、あなたのアカウントの識別子またはチームの識別子が含まれます。顔写真を登録するかどうかは、この点をふまえてお決めください。写真を差し替えたときの古い画像が残る場合があります。
表示名の初期値について
登録した直後の表示名は、Googleでログインした場合はGoogleアカウントの氏名、メールアドレスで登録した場合はメールアドレスの「@」より前の部分を自動的に使います。表示名はログインしているすべての利用者に表示されるため、本名やメールアドレスの一部を見せたくない場合は、プロフィールから表示名を変更してください。
ブロックについて
- 個人のブロック:あなたの画面から相手のフィードのコメントが表示されなくなり、そのコメントやリアクションのお知らせも届かなくなります。チームチャットの相手の発言は、折りたたんだ状態で表示され、「表示する」を押すと読めます。チャットや試合の申し込みのメッセージと、そのお知らせは止まりません。相手には通知されません。表示を止めるだけで、相手の投稿そのものが消えるわけではありません。
- チームのブロック:チームの管理者が行います。ブロックされた人は、そのチームの練習のビジター、試合の助っ人、参加申請に申し込めなくなり、予定していた参加は取り消されます。ブロックされたことは本人に通知されず、本人はブロックの記録を見ることもできません(すでに承認していた練習や試合の参加が取り消される場合は、当日の行き違いを防ぐため、取り消された事実だけをお知らせします)。ブロックは一方向で、チーム側からその人を招待することはできます。また、その人の「チームを探しています」の投稿は、ブロックしたチームにも引き続き表示されます。
通報された内容の確認
通報があったときは、当社の運用者が、通報の内容と、通報された投稿・メッセージの写し(コメント・チャットの場合は、それを書いた人の識別子を含みます)を確認します。通報によって自動的に何かが削除されることはありません。
5. 自由記述欄と要配慮個人情報
本サービスには、自由に文章を入力できる欄があります(出欠のコメント、チームチャット、申し込みのメッセージ、フィードの投稿とコメント、募集のメモ、通報の詳細など)。
当社は、人種、信条、社会的身分、病歴、犯罪の経歴、犯罪により害を被った事実といった、個人情報保護法にいう要配慮個人情報を取得するための項目を設けていません。
ただし、自由記述欄に入力された内容は、入力されたとおりに保存され、「4.」の範囲で表示されます。欠席の理由など、健康やプライバシーに関わることは書かないようお願いします。通報の詳細についても、対応に必要な範囲を超える情報は書かないでください。
自由記述欄にご自身の要配慮個人情報を入力された場合は、ご本人の同意に基づいて取得したものとして取り扱います。他方、通報の詳細欄などに第三者の要配慮個人情報が入力されていることを当社が認識した場合は、その方の同意を得ずに取得したことになるため、通報への対応その他必要な範囲を超える部分を速やかに削除します。
6. 第三者への提供
当社は、次の場合を除き、あらかじめ本人の同意を得ることなく個人データを第三者に提供しません。
- 法令に基づく場合
- 人の生命、身体または財産の保護のために必要であり、本人の同意を得ることが困難な場合
- その他、個人情報保護法で認められている場合
- 次の「7. 外部サービスの利用」に記載する委託に伴って提供する場合(外国にある第三者への提供については、「7.」のとおり第28条の要件を満たす必要があります)
なお、「4.」のとおり本サービス上で他の利用者に表示される情報も、個人情報保護法にいう第三者提供に当たります。これは、利用者ご自身が公開することを選んだ情報であり、当社はご本人の同意に基づき、「4.」に記載した範囲で他の利用者に提供します。公開の範囲は、プロフィールの編集や投稿の取り下げによりご自身で変更できます。
ほかの利用者の投稿によって権利を侵害された方は、「1.」の窓口に、送信防止措置(削除)の申出と、情報流通プラットフォーム対処法に基づく発信者情報の開示請求ができます。お申出には、問題のある投稿の内容、それがどこにあるか、どの権利がどのように侵害されているかをお書きください。開示請求または裁判所の開示命令を受けた場合は、上記の「法令に基づく場合」として、当社が保有する情報を法令に従って開示することがあります。なお、当社はIPアドレスを保存していないため、保有しているのはご登録のメールアドレスと投稿の記録です。
7. 外部サービスの利用(委託先・外国にある第三者への提供)
当社は、本サービスの運営に次の外部サービスを利用し、必要な範囲で個人データの取扱いを委託します。提供先は、シンガポールの法人であるSupabase Pte. Ltd.と、アメリカ合衆国の法人であるGoogle LLCおよびCloudflare, Inc.です。いずれも個人情報保護法にいう「外国にある第三者」に当たります。
委託先への提供そのものは、個人情報保護法第27条第5項第1号により本人の同意を要しないとされています。ただし、この例外は、外国にある第三者への提供を定めた第28条には及びません。そこで当社は、あらかじめ本人の同意を得たうえで提供する方法(第28条第1項)をとっています。
もうひとつの方法(提供先が同法施行規則第16条の基準に適合する体制を整えていることを確認して提供する方法。第28条第3項)はとりません。この方法は、提供先の社内の体制を当社が確認し、その後も定期的に確認し直すことを求めています(同規則第18条)。本サービスは代表社員一人で運営しており、その確認を正確に行えるとは言えないためです。
同意をいただくとき。アプリの登録画面に「続行すると、利用規約と、外国にある事業者への個人データの提供を含むプライバシーポリシーに同意したものとみなされます。」と表示し、登録を続ける操作をもって同意をいただきます。ウェブサイトの公開のお知らせの登録欄でも、送信ボタンのそばに同じ趣旨を表示し、送信する操作をもって同意をいただきます。同意をいただく前にお知らせすべき3つの事項(提供先の所在国、その国の個人情報の保護に関する制度、提供先が講ずる措置。第28条第2項)は、この章に記載しています。
| 委託先 | 所在国 | 用途 | 取り扱う情報 |
|---|---|---|---|
| Supabase Pte. Ltd. | シンガポール | データベース、認証、画像の保存、リアルタイム通信、サーバー上の処理の実行、認証メールの送信 | 「2. 取得する情報」のうち、お問い合わせを除くすべて |
| Google LLC Firebase Cloud Messaging |
アメリカ合衆国 | プッシュ通知の配信 | プッシュ通知用のトークン、通知の件名・本文、および画面を開くための識別子(次の項をご覧ください)。また、トークンを取得する際に、Firebaseのライブラリが端末とアプリの情報をGoogleに送信します |
| Google LLC Googleでログイン |
アメリカ合衆国 | Googleアカウントでのログイン | Googleアカウントの識別子、氏名、メールアドレスとその確認状況、プロフィール画像のURLなど |
| Cloudflare, Inc. Cloudflare Workers Assets |
アメリカ合衆国 | このウェブサイトの配信 | ページを開いたブラウザのIPアドレス、ユーザーエージェントなど。当社のサーバーを経由せず、Cloudflareが同社の記録として保存します(「9.」) |
データベースと画像の保存領域は、アジア北東(東京)リージョン(ap-northeast-1)に置いています。ただし、サーバーが日本国内にあっても、提供先が外国の法人である以上、第28条は適用されます。東京リージョンであることを理由に、同条の手続を省くことはしていません。また、保守などの目的で、日本国外から取り扱われることがあります。認証コードなどのメールは、現在Supabaseの標準のメール送信機能で送信しています。独自のメール送信事業者を使うことになった場合は、本ポリシーにその事業者名を追記します。
提供先の国の制度と、提供先が講ずる措置
- 提供先の所在国:シンガポール(Supabase Pte. Ltd.)と、アメリカ合衆国(Google LLC、Cloudflare, Inc.)の2か国です。どちらも、日本の個人情報保護委員会が同法施行規則第15条に基づき日本と同等の水準にあると認めた国(欧州連合と英国)には含まれていません。そのため、いずれについても第28条が適用されます。
- シンガポールの個人情報の保護に関する制度(Supabase Pte. Ltd.):個人情報の保護を包括的に定める法律として2012年個人情報保護法(Personal Data Protection Act 2012)があり、個人情報保護委員会(Personal Data Protection Commission)が監督しています。日本の個人情報保護委員会が日本と同等の水準にあると認めた国には含まれていません。
- アメリカ合衆国の個人情報の保護に関する制度(Google LLC、Cloudflare, Inc.):個人情報の保護を包括的に定める連邦法はなく、分野ごとの連邦法(医療・金融・児童など)と州法(カリフォルニア州など)によります。日本の個人情報保護委員会に相当する独立した監督機関は、連邦レベルには置かれていません。外国情報監視法(FISA)第702条や大統領令12333号に基づき、政府機関が情報を取得する可能性があります。この記載はGoogle LLCとCloudflare, Inc.についてのもので、Supabaseには当てはまりません。
- 提供先が講ずる措置:各社とは、個人データの取扱いに関する条件(データ処理に関する契約条項)に基づいて取り扱います。各社が公表している範囲では、次のとおりです。
- Supabase Pte. Ltd.:SOC 2 Type 2の報告とISO 27001の認証を取得しています。同社のデータ処理に関する契約条項では、データは顧客が選んだリージョンに保存され、主にそのリージョンで処理されると定めています。東京リージョンを選んでいることが単なる設定にとどまらないのは、このためです。また、同社は自社の再委託先を利用しており、その一覧を公表し、変更するときは30日前に通知します。再委託先は入れ替わるため、本ポリシーでは個々の名前は記載しません。
- Google LLC:ISO/IEC 27001の認証と、SOC 2・SOC 3の報告を取得しています。
- Cloudflare, Inc.:このウェブサイトの配信のみで、当社から個人データを提供する場面はありません。
端末から直接送信される情報
次の情報は、当社のサーバーを経由せず、あなたの端末から直接、送信先の事業者に送信されます。当社はこれらの情報を取得しておらず、取扱いを委託してもいないため、上の表とは別に記載します。
| 送信される情報 | 送信先 | 送信されるときと、送信先での用途 |
|---|---|---|
| 動画の識別子、端末のIPアドレス、ユーザーエージェント | Google LLC(米国) YouTube |
動画リンクのサムネイルを表示するときと、動画を再生するとき。アプリ内に動画を埋め込んではいません |
| ブラウザのIPアドレス、ユーザーエージェントなど | Google LLC(米国) Google Fonts |
このウェブサイトのページを開いたとき、書体を配信するため。アプリ内の書体はアプリに同梱しており、送信は発生しません |
プッシュ通知で送信される内容
プッシュ通知は、Googleのサーバー(Firebase Cloud Messaging)を経由して端末に届きます。当社がGoogleに渡すのは、端末のトークン、通知の件名・本文、および画面を開くための識別子(お知らせの種類、お知らせ自体の識別子、対象となるチーム・試合・スレッドなどの識別子)です。識別子には、表示名も本文も含みません。件名と本文には、お知らせの種類に応じて、相手の表示名、チーム名、試合や練習の日時と会場名、メッセージ・コメント・投稿の冒頭100字までの抜粋が含まれることがあります。
通知は、ロック画面に本文を表示しない設定を付けて送信しています。ただし、端末やOSの設定によっては表示されることがあります。プッシュ通知は、アプリの「設定」から種類ごとにオフにできます。オフにしても、アプリ内のお知らせ一覧には届きます。すでに送信したプッシュ通知を取り消すことはできません。
8. 端末に保存する情報
アプリは、端末に次の情報を保存します。
- ログイン状態を保つための認証トークン(アクセストークンとリフレッシュトークン)
- インストールごとに1回だけ作るランダムな識別子。プッシュ通知の登録に使います。アプリを削除するか、アプリのデータを消すとなくなります
- 表示言語の設定、通知の説明を表示したかどうか、最後に選んだチーム、フィードで選んだ都道府県
- 表示した画像(プロフィール写真、ロゴ、バナー、YouTubeのサムネイル)の一時的なキャッシュ
ログアウトやアカウントの削除を行っても、これらの端末内のデータは自動では消えません。端末から完全に消すには、OSの設定からアプリのデータを削除してください。
アプリが実行時に許可を求める権限は、通知の許可だけです。このほかに、通信のためのインターネット接続など、動作に必要な権限をアプリに含んでいます(ストアの権限一覧にはこれらも表示されます)。カメラや写真ライブラリへのアクセス権限は求めません(写真は、Androidの写真選択画面であなたが選んだ1枚だけを受け取り、端末内で512×512に縮小してから送信します)。位置情報の権限は求めません。
写真は、端末内で512×512に縮小して再エンコードしたあと、撮影情報(Exif)、XMP、ICCプロファイル、コメントといったメタデータの領域を取り除いてから送信します。そのため、写真に含まれていた撮影場所(GPS)や撮影日時はアップロードされません。ただし、写真に写っているもの(背景の建物や看板など)から場所が分かることはあります。プロフィール写真、チームのロゴ、バナーは、URLを知っていれば誰でも開ける保存領域に置かれますので(「4.」)、この点をふまえてお決めください。
9. このウェブサイトについて
- このウェブサイトは、Cookieやアクセス解析ツールを使用していません。
- 表示言語の選択だけを、ブラウザのlocalStorageに保存します。この値は当社には送信されません。
- 文字の表示にGoogle Fontsを使用しています。ページを開くと、ブラウザからGoogleのサーバー(fonts.googleapis.com、fonts.gstatic.com)にIPアドレスなどが送信されます。
- このウェブサイトは、Cloudflare, Inc.のCloudflare Workers Assets(アメリカ合衆国)で配信しています。当社はアクセスの記録を取得していませんが、ページを配信するCloudflareは、同社のプラットフォームの運営者として自社のアクセスの記録を保存します(「7.」)。
- 公開のお知らせの登録欄に入力されたメールアドレスは、委託先であるSupabase Pte. Ltd.(シンガポール)のプラットフォームを経由して、当社が受け取って保存します(次の項をご覧ください)。ページを配信するCloudflareと同じように、同社もプラットフォームの運営者として、送信元のIPアドレスを含む通信の記録を保存します(「7.」)。これは通信の記録であり、アクセス解析や行動の追跡のためのものではありません。このほかに、このウェブサイトから外部に送信される情報はありません。
公開のお知らせの登録について
このウェブサイトには、本サービスの公開をお知らせするためにメールアドレスをご登録いただく欄があります。お預かりするのは、メールアドレス、ご登録のときのウェブサイトの表示言語、ご登録の日時の3つだけです。お名前もアカウントも必要ありません。Cookieも使いません。
ご登録いただいたメールアドレスは、本サービスを公開したときに1回だけお知らせをお送りするために使います。メールマガジンや宣伝をお送りすることはなく、ほかの目的にも使いません(「3. 利用目的」)。ご登録は、アプリのアカウントとは別のもので、アカウントの作成にはなりません。
ご登録の内容は、本サービスのほかの情報と同じく、シンガポールの法人であるSupabase Pte. Ltd.のデータベース(東京リージョン)に保存します。提供先が増えるわけではありません(「7.」)。
保存するのは、公開のお知らせをお送りするまで、またはご本人から削除のお申し出をいただくまでの、いずれか早いときまでです(「11.」)。削除のお申し出は「1.」の窓口で受け付けます。ご登録のメールアドレスからお送りいただくことをもって本人確認とします(「13.」)。
10. 安全管理のために講じている措置
基本方針の策定
個人データの適正な取扱いに関する基本方針として本ポリシーを策定し、本サービス上で公表しています。
個人データの取扱いに係る規律の整備
どの情報を誰が読み書きできるかを、データベース自体に定めています(行単位のアクセス制御と、列ごとの権限)。これが取扱いの規律そのものです。規律を変更するときは、プロジェクトのレビューと自動テストを通します。
組織的安全管理措置
個人データを取り扱うのは、「1.」に記載する代表社員だけです。個人データの漏えい、滅失または毀損が起きた場合は、個人情報保護法第26条に従い、個人情報保護委員会へ報告し、対象となる方にご連絡します。
人的安全管理措置
代表社員以外の者に個人データを取り扱わせる場合は、その前に、本ポリシーと取扱いのルールを周知し、秘密保持の取決めを結びます。
物理的安全管理措置
本サービスの運用に使う端末には、画面ロックとディスク全体の暗号化を設定しています。端末は、他の人が触れられる場所に置いたままにしません。端末を廃棄するときは、記憶装置のデータを消去します。
技術的安全管理措置
- 通信の暗号化(TLS)
- データベースの行単位のアクセス制御(RLS)。すべての表は既定で権限を取り消したうえで、書き込みは必要な列にだけ許可しています。読み取りの範囲は、表ごとに設定した行単位のアクセス制御で制限しています。ログインしていない人は、「4.」に記載した公開の画像を除き、データを読み取れません
- 複数の表にまたがる更新は、原則としてサーバー側の関数に限定しています(プロフィールの編集、出欠の回答、チームの解散など一部は、書き込みを許可した列に限って直接更新します)
- 誰が何を見られるかを、自動テストで検証しています(部外者、一般メンバー、管理者、ブロックされた人それぞれの立場から確認します)
- プッシュ通知の配信要求は、署名を検証したうえで処理します
- プッシュ通知は、ロック画面に本文を表示しない設定で送信します
- アカウントの削除の前に、直近10分以内にログインしていることを確認します
- 管理用の鍵の厳重な管理と、アクセス権限の最小化。サーバー用の鍵はアプリに組み込みません
- メールアドレスは、他の利用者が読み取れる領域に複製しない設計にしています
委託先の監督
委託先を選定し、個人情報保護法第25条に基づき必要かつ適切な監督を行います(「7.」)。委託先の基盤側に保存される記録やバックアップの内容と保存期間は委託先が定めており、当社は同社が公開する文書で確認しています(「2.」)。
外的環境の把握
当社は、シンガポールの法人であるSupabase Pte. Ltd.と、アメリカ合衆国の法人であるGoogle LLCおよびCloudflare, Inc.のサービスを利用しています(データベースと画像は、東京リージョンに保存しています)。両国の個人情報の保護に関する制度は「7.」に記載したとおりで、これを把握したうえで上記の措置を講じています。
11. 保存期間
自動的に削除されるものと、そうでないものがあります。
| 情報 | 保存期間 |
|---|---|
| アプリ内のお知らせ(メッセージの抜粋を含みます) | 最後の出来事から90日で自動的に削除 |
| プッシュ通知用のトークン | 月1回の定期処理で、270日使われていないトークンと、ログインセッションがなくなったトークンを削除。ログアウトすると、アプリがその場で登録の削除を試みますが、通信できないときなどは削除できません。その場合も、次にあなたへ通知を送ろうとした時点か、次の定期処理で削除します |
| 通報の記録(通報された内容の写しを含みます) | 作成から180日で自動的に削除 |
| 障害の記録 | 30日。定期実行の履歴は14日 |
| スタッツの保存操作の記録 | 1日 |
| ランキングの月ごとの履歴 | 24か月 |
| 「チームを探しています」の投稿、チームのメンバー募集 | 60日で掲載終了(更新すると、そこから60日)。掲載が終わってもデータは残ります |
| チームからの招待 | 14日で期限切れ。データは残ります |
| 参加申請 | 30日で期限切れ。データは残ります |
| 公開のお知らせの登録(メールアドレス) | 公開のお知らせをお送りするまで、またはご本人から削除のお申し出をいただくまでの、いずれか早いときまで。お送りしたあとに削除します |
| 上記以外(プロフィール、チーム、試合と練習、出欠、募集と申し込みのメッセージ、チャット、フィード、スタッツ、XPとバッジ、募集の記録など) | 自動的に削除される仕組みはありません。アカウントを削除すると多くは消えますが、申し込みのメッセージの本文、フィードの投稿の本文、あなたが作成した募集・試合・練習・スコアやスタッツの記録などは、名前を伏せたまま期限を定めずに残ります(「12. アカウントの削除」) |
チームを解散すると、そのチームの情報は他の利用者には表示されなくなりますが、元メンバーには引き続き表示されます。解散を取り消すことはできません。
バックアップとサーバーの記録(ログ)は、委託先であるSupabaseが同社の基盤で取得・保存しています。その内容と保存期間は、当社ではなく同社が、提供するプランに応じて定めています(「2.」)。
本サービスの提供を終了する場合は、終了日の30日前までに本サービス上とウェブサイトでお知らせし、終了日以降にデータを削除します。データをまとめて書き出す機能はありませんので、必要な内容は終了日までにご自身で控えてください。
法令で保存が義務付けられている情報や、不正利用への対応に必要な記録は、必要な期間保存することがあります。
12. アカウントの削除
アプリの「設定」から「アカウントを削除」を選ぶと、いつでもご自身で削除できます。安全のため、削除の直前にもう一度ログインしていただきます。削除は取り消せません。アプリを使えない場合は、「1.」の窓口までご連絡ください。本人確認のうえで削除します。
チームへの影響
削除の前に、アプリの画面で次のどれに当たるかを確認できます。
- ほかに管理者がいる場合、またはあなたが一般メンバーの場合:そのチームから抜けます
- あなたが唯一の管理者の場合:いちばん早く参加したメンバーが管理者を引き継ぎ、その方にお知らせが届きます
- あなたが唯一のメンバーの場合:そのチームは解散し、予定していた試合は中止になります
削除されるもの
プロフィールと写真、チームへの所属、出欠の回答、通知の設定、プッシュ通知用のトークン、あなた宛のお知らせ、あなたが個人として行ったブロックとフォロー、フィードのリアクションとコメント、選手ごとのスタッツ、XP・レベル・バッジ・ショーケース、「チームを探しています」の投稿、参加申請、招待、ビジター参加、助っ人の応募。チームチャットの発言は、本文と動画リンクを消去します。ほかの利用者に届いたお知らせからも、あなたの表示名と、チャットの抜粋を取り除きます。
なお、あなたがチームの管理者として行ったブロックは、ブロック自体はそのチームに残ります。消えるのは、誰が行ったかの記録だけです。ブロックされた方は、そのチームに引き続きブロックされたままになります。
残るもの
次のものは、退会後もデータとして残ります。お名前とともに表示されることはありません。チームチャットとお知らせでは「退会したメンバー」と表示され、試合の申し込みのやりとりやフィードの投稿では、書いた人の名前が表示されなくなります。
ただし、当社の記録上は名前と結びつかない識別子が残るため、これらは引き続き個人データとして本ポリシーに従って取り扱います。これらについても、個人情報保護法第35条に基づく利用停止・消去のご請求は「1.」の窓口で受け付け、法令に従って対応します。
- 試合の申し込みでやりとりしたメッセージの本文
- フィードの投稿の本文(動画のキャプションや募集のメモ)
- あなたが作成した募集、試合、練習、スコアの入力記録、スタッツの保存記録、追加した動画リンク
- 通報の記録に含まれる、あなたの投稿・メッセージの写し。また、あなたが行った通報の理由・詳細と、通報した内容の写し(いずれも通報から180日のあいだ)
- ほかの利用者のお知らせに残る、あなたが送った申し込みメッセージやコメントの抜粋(最大90日)
- 試合の集計に使う内部の記録に残る、名前と結びつかない識別子
- あなたが作成し、ほかの方が管理者を引き継いだチーム
写真について
プロフィール写真は、アカウントの削除の処理のあとに保存領域から消します。この処理は順番待ちで実行するため、アカウントの削除と同時ではありません。失敗した場合は、次に同じ処理が動いたときに再試行します(定期的に実行する仕組みはありません)。CDNのキャッシュにしばらく残ることがあります。
13. 開示・訂正・利用停止などの請求
利用者は、個人情報保護法に基づき、保有個人データについて、利用目的の通知、開示(第三者提供記録の開示を含みます)、内容の訂正・追加・削除、利用の停止・消去、第三者への提供の停止を請求できます。本人確認のうえ、法令に従って遅滞なく対応します。
ご請求の手続
- 請求先:「1.」の窓口のメールアドレス宛にお送りください。所定の書式はありません。
- 記載していただくこと:ご請求の趣旨(利用目的の通知、開示、訂正・追加・削除、利用停止・消去、第三者提供の停止のいずれか)と、対象となる情報。
- 本人確認の方法:ご登録のメールアドレスからお送りいただくことをもって本人確認とします。当社は、住所も電話番号も取得しておらず、利用者を特定できる連絡先はご登録のメールアドレスだけだからです。必要に応じて、そのアドレス宛に確認のご連絡をすることがあります。
- 代理人によるご請求:法定代理人または委任による代理人からもご請求いただけます。委任による代理人の場合は委任状など代理権を確認できる書類を、法定代理人の場合はその資格を確認できる書類を、それぞれ代理人ご本人を確認できる書類の写しとあわせてご提出ください。
- 手数料:無料です。利用目的の通知および開示のご請求を含め、手数料はいただきません。
- ご回答の方法と期限:ご登録のメールアドレス宛に、電磁的記録の提供によりご回答します。ご請求を受けてから2週間以内にご回答します。調査に時間がかかる場合は、その2週間以内に、どのくらいかかる見込みかと、その理由をご連絡します。
アプリからできること、できないこと
プロフィール、チームの情報(管理者の場合)、募集、出欠、チームチャットの発言、フィードのコメントは、アプリで確認し、編集または削除できます。一方、フィードの投稿そのものは、アプリから削除できません(動画リンクを削除すると、その投稿も表示されなくなります)。削除をご希望の場合は窓口までご連絡ください。データをまとめて書き出す機能はありません。開示のご請求は、窓口で個別に対応します。
ご自身では見られない情報もあります。チームがあなたをブロックした記録は、アプリの画面には表示しません。この記録について開示のご請求があった場合、当社は、開示することで他の利用者の権利利益を害するおそれがあるとき、または本サービスの業務の適正な実施に著しい支障を及ぼすおそれがあるときは、個人情報保護法第33条第2項に基づき、その全部または一部を開示しないことがあります。その場合は、開示しない旨とその理由をご通知します。
また、スタッツは、あなたのチームの管理者が全員分をまとめて入力します。誤りがある場合は、まずそのチームの管理者に訂正を依頼し、解決しない場合は窓口までご連絡ください。
14. 苦情の申出先
本サービスにおける個人情報の取扱いについてのご意見・苦情は、まず「1.」の窓口へお寄せください。あわせて、監督官庁である個人情報保護委員会に申し出ることもできます。
個人情報保護委員会:https://www.ppc.go.jp/
15. 未成年者の利用
本サービスは、18歳以上の方を対象としています。利用規約でも同じ年齢を定めています。18歳未満の方は、本サービスをご利用いただけません。
18歳以上としているのには、2つの理由があります。ひとつは、本サービスに年齢を確認する仕組みがなく、生年月日も年齢も取得していないことです。もうひとつは、「チームを探しています」の投稿が、写真、身長、活動地域(都道府県・市区町村)を、Circlesでチームを運営している大人であれば全国の誰にでも表示することです(「4.」)。保護者の同意を取得したり記録したりする仕組みもないため、対象年齢を18歳以上としました。
18歳未満の方が利用していることが分かった場合は、利用規約に基づき、アカウントを停止または削除することがあります。ご本人または法定代理人からの開示・削除などのご請求は、「1.」の窓口で受け付けます(「13.」)。
16. 本ポリシーの変更
法令や本サービスの内容の変更に合わせて、本ポリシーを変更することがあります。重要な変更は、本サービス上でお知らせします。
17. データの出典
本サービスで使用している都道府県・市区町村のデータは、次の資料をもとに作成しています(団体コードの検査数字を除くなどの加工をしています)。ローマ字表記は当社が独自に作成したもので、出典元によるものではありません。
出典:総務省「全国地方公共団体コード」(https://www.soumu.go.jp/denshijiti/code.html)
18. 言語
本ポリシーは日本語版を正本とします。英語版は参考のための翻訳であり、内容に相違がある場合は日本語版が優先します。
制定日:2026年9月19日 最終改定日:2026年9月19日
以上
The Good Managers LLC (“we” or “us”) handles the personal information of users of the Circles app and its related website (together, the “Service”) in line with the Act on the Protection of Personal Information (the “APPI”) and other applicable law, as set out below.
Circles exists so that adult basketball circles can find opponents and players. That means much of what you enter is shown to other users. Section 4, What other users can see, sets out exactly who sees what. Please read that section before you use the Service.
1. Operator and contact
- Name
- The Good Managers LLC
- Representative Partner
- Pellan Aymeric
- Address
- 15-8 Yurakucho, Tokorozawa, Saitama 359-1117, Japan
- Contact
- The Good Managers LLC personal information enquiries
info@thegoodmanagers.com
Requests for disclosure, correction or suspension of use, requests to delete an account on your behalf, and any other question about how we handle personal information all go to this address.
2. Information we collect
| Category | What | When |
|---|---|---|
| Account | Email address. If you registered by email, the hashed value of the password you set (we cannot see the original). If you sign in with Google, what Google gives us: your Google account identifier, name, email address and whether it is verified, profile picture URL, and — for Google Workspace accounts — your organisation’s domain | Sign-up and sign-in |
| Profile | Display name (required), profile photo, position, height, level, 3x3/5x5 preference (everything except the display name is optional). The app’s interface language | Sign-up, creating or editing your profile |
| Teams and membership | Team name, logo, banner, area (prefecture and municipality), category, level, team description, activity note, invite code, each member’s role (admin or member), jersey number and the date they joined | Creating or editing a team, joining, inviting |
| Listings and requests | Game listings (date, time, area, venue name, notes), applications and direct challenges, and the messages exchanged between the admins of the two teams (up to 2,000 characters) | Posting, applying and replying |
| Games and practices | Date, start and end time, prefecture and municipality, venue name, notes, and whether and why it was cancelled | Creating or changing a game or practice |
| Attendance | Going / not going / undecided, a comment of up to 100 characters, and when you answered | Answering an RSVP |
| Scores and results | Every scoring action with who entered it, when, and whether it was undone; who kept score; the result; records of corrections; per-player statistics (points, assists, rebounds, shooting splits) and who entered them | Keeping score, finishing or correcting a result |
| Progress and badges | XP, level, games played, wins and losses, games hosted, career statistics, badges earned and when, the badges you put in your showcase, teams you founded. Team level and perks | When a result is finalised (calculated automatically) |
| Inside a team | Team chat messages (up to 2,000 characters), when you last read the chat and whether you have it open, practice schedules and practice attendance, film links (YouTube URL, video id, title) and who added them | Using chat, practices and film |
| Feed | Post bodies (up to 500 characters) and the details saved at the time of posting so the card can be listed (team names, the result, a summary of the listing), comments (up to 500 characters), reactions, the teams you follow, and the prefecture you chose in the feed | Posting, commenting, reacting |
| Recruiting | “Looking for a team” posts (prefecture and municipality, positions, level, a note of up to 300 characters); team openings (positions, how many players, level, a note of up to 300 characters); join requests and invites (messages up to 300 characters, and who invited you); guest places at a practice (a note of up to 100 characters); helper requests and offers for a game (messages up to 300 characters); records of players a team has blocked | Posting, applying, inviting, offering |
| Reports and blocks | Who reported, what was reported, the reason, up to 500 characters of detail, and a copy of the reported content as it stood (including its text, film links and — for a comment or a chat message — the identifier of the person who wrote it). Records of personal blocks | Reporting or blocking |
| Device and push | Push notification token, an identifier generated once per installation, operating system, app version, the identifier of the sign-in session the token was registered under, when it was last seen, and your notification preferences | Allowing notifications, opening the app |
| Notification records | In-app notifications. To display them they include the other person’s display name, team names, dates and times, venue names, and the first 100 characters of a message, comment or post. When a push was sent, and why it failed if it did | When a notification event happens |
| Fault records | When a scheduled job fails: the job name, the identifier of the row involved, and the error | When a job fails |
| Enquiries | Email address and the content of your enquiry | Contacting us |
| Launch notice sign-up | Email address, the website’s interface language when you signed up, and the date and time | Signing up on this website to be told when the Service launches |
The app’s interface language is stored on your device and also on your account, so that push notifications are sent in the right language.
What we do not collect. There is no field anywhere in the Service for date of birth, age, gender, nationality, phone number, postal address or payment details. The app does not ask for location permission and has no mechanism for reading location from your device. An “area” is only the prefecture and municipality you picked from a list, plus whatever you typed as a venue name. There is no analytics, advertising or crash-reporting software anywhere in the Service. Photographs have their metadata — Exif, which can include where the photo was taken — removed on your device before they are uploaded, so the location is not uploaded (see section 8).
Access logs. Our database has no field for IP addresses, for browser or device identifiers (user agents), or for the time of a request. Supabase, our provider, does keep records of authentication and of requests to its servers on its own platform, and those include IP addresses; it also takes backups of the database. What those contain and how long they are kept is set by Supabase, not by us, according to the plan it provides, and is described in its own published documentation.
3. Why we use it
- To create accounts, confirm identity and keep you signed in.
- To show profiles, team pages and rosters, so that users can see who they are dealing with.
- To post and apply to game listings, arrange games with the other team, and carry the messages between the two teams’ admins.
- To manage game and practice schedules, attendance and who is turning up.
- To keep score, finalise and correct results, and total up per-player statistics.
- To calculate and show XP, levels, badges, team levels and perks.
- To calculate and publish team ratings and the national ranking.
- To run recruiting: members, guests at a practice and helpers for a game, and the requests, invites and approvals that go with them.
- To send in-app notifications and push notifications (you can choose which kinds you receive).
- To act on reports, carry out blocks, deal with breaches of the Terms and nuisance behaviour, and keep users safe.
- To answer enquiries.
- To tell the people who signed up on the website, once, when the Service launches.
- To investigate and fix faults.
- To tell you about important changes, such as changes to the Terms or this policy.
- To comply with the law.
We use it for nothing else. In particular, we do not use it to promote the Service: your photos, your display name and what you post are never used in advertising, in store listings or on a marketing website.
4. What other users can see
The Service exists so that teams and players can find each other, so the following is shown to other users. Your email address itself is never shown to another user anywhere in the Service. If you signed up by email, though, your first display name is the part of your email address before the “@” — see “Your first display name” below.
| Information | Who can see it |
|---|---|
| Your profile (display name, photo, position, height, level, 3x3/5x5 preference, the app’s interface language, when you signed up) | Every signed-in user. No relationship with you is required |
| Your player record (level, XP, games played, wins and losses, career statistics, how many badges you have, your showcase badges, how many teams you founded) | Every signed-in user. The names of teams you founded are shown only to people in a team with you, and the dates you earned your badges are shown only to you |
| Profile photos, team logos and team banners, as image files | Anyone who has the URL, including people who are not signed in |
| Team pages (name, logo, banner, area, category, level, description, activity note, member count, rating and ranking, and who created the team) | Every signed-in user. A disbanded team is shown only to its former members |
| The roster (who is in the team, their role, jersey number and join date) | Members of that team only — except that the person who created the team is visible from the team page above |
| Game listings (date, time, area, venue name, notes) | Every signed-in user |
| Applications and the messages in a request thread | The admins of the two teams involved only. Not shown to ordinary members of either team |
| Game details, attendance answers and comments, per-player statistics | Members of both teams in the game. The opposing team sees your attendance, your comment and your statistics. An accepted helper sees exactly three things: the game itself, the scoring record, and the attendance answers of the side they are filling in for — not the other team’s attendance, and not per-player statistics |
| Results, team ratings and the national ranking | Every signed-in user (shown as team-level information) |
| Practices and practice attendance, team chat | Members of that team only. Chat sent before you joined is never shown to you. While you have the chat open, your teammates can see that you are online |
| Film links (YouTube URL, title, caption) | On a game or practice screen, members of the team that added it only — not the opposing team. If it is posted to the feed as “Everyone”, every signed-in user can see it; if it is posted as “Members”, only that team’s members can |
| Feed posts set to “Everyone” | Every signed-in user. They are shown as the team’s activity and never name the individual who posted |
| Feed comments and reactions | Anyone who can see that post. Comments are shown with the display name of whoever wrote them |
| Feed posts set to “Members” | Members of that team only |
| “Looking for a team” posts | Anyone who runs a team on Circles, anywhere in Japan (see below) |
| Team openings | Every signed-in user. They are also posted to the feed automatically |
| Guest places at a practice | Every signed-in user sees the date, time, area, venue name, guest fee and how many places are left. The team’s own practice notes are not shown |
| Signing up as a guest (display name, profile, a note of up to 100 characters) | Every member of the host team, not only its admins |
| Helper requests for a game | Every signed-in user sees the date, time, area, the opposing team, how many helpers are wanted, the positions and how many places are left. The venue name and the team’s note are shown only to helpers the team has accepted |
| Offering to help (display name, profile, a message of up to 300 characters) | The admins of the team asking, only. Not the opposing team, and not other volunteers |
| The teams you follow, and the people you have blocked | You only. Neither the person nor the team is told |
About “Looking for a team” posts
When you publish one of these posts, your display name, profile (photo, position, height, level), the area you chose (prefecture and municipality), the positions you want to play, your level and a note of up to 300 characters become visible to anyone who runs a team on Circles, anywhere in Japan — not only teams near you. Anyone can create a team, so this audience is wider than it may sound. The teams you already belong to are not shown.
A post stops being listed 60 days after it is posted, and you can take it down at any time in the app. After it stops being listed, the record itself is kept until you delete your account (see 11. How long we keep it).
Photos and their URLs
Profile photos, team logos and team banners are served from a CDN at URLs anyone can open. Anyone who has the URL can view the image, including people who are not signed in to Circles. The URL contains your account identifier or the team identifier. Please bear that in mind when deciding whether to upload a photograph of your face. An older photo may remain after you replace it.
Your first display name
When you sign up, your display name is set automatically: to the name on your Google account if you signed in with Google, or to the part of your email address before the “@” if you signed up by email. Your display name is visible to every signed-in user, so if you do not want your real name or part of your email address shown, change it in your profile.
Blocking
- Blocking a person hides their feed comments from you and stops their comments and reactions notifying you. Their team chat messages are folded away rather than hidden: tapping “Show” reveals one. Chat messages and game request messages, and the notifications for them, are not stopped. They are not told. It only stops you seeing their content; it does not remove it.
- A team block is applied by a team’s admins. Someone a team has blocked can no longer take a guest place at its practices, help in its games or ask to join, and any upcoming place they held is cancelled. They are not told they have been blocked, and they cannot see the record of it (if a place they had already been accepted for is cancelled, they are told that much, so that nobody travels to a court for nothing). A block works one way only: the team can still invite that person, and their “Looking for a team” post is still shown to the team that blocked them.
Reviewing reported content
When something is reported, we review the report and the copy of the reported post or message, including — for a comment or a chat message — the identifier of whoever wrote it. A report never removes anything automatically.
5. Free-text fields and special-care personal information
The Service has fields you can type freely into: attendance comments, team chat, request messages, feed posts and comments, recruiting notes, and the detail box on a report.
We have no field anywhere designed to collect the special-care personal information defined by the APPI — race, creed, social status, medical history, criminal record, or the fact of having been the victim of a crime.
What you type into a free-text field is stored as you typed it and shown to the audiences set out in section 4. Please do not write health or other sensitive details there, such as the reason you cannot make a game. When reporting content, please do not include more than is needed to deal with it.
If you enter your own special-care personal information in a free-text field, we treat it as having been collected with your consent. If we become aware that a free-text field — the detail box on a report, for example — contains someone else’s special-care personal information, it was collected without that person’s consent, so we promptly delete whatever goes beyond what is needed to deal with the report.
6. Sharing with third parties
We do not give personal data to third parties without your prior consent, except:
- where required by law;
- where needed to protect someone’s life, body or property and consent is difficult to obtain;
- in other cases permitted by the APPI;
- when entrusting processing to the providers listed in section 7 (provision to a third party outside Japan must additionally satisfy Article 28, as section 7 explains).
Information shown to other users inside the Service, as described in section 4, is also provision to a third party under the APPI. It is information you chose to publish, and we provide it to other users, to the extent set out in section 4, on the basis of your consent. You can change how much is published by editing your profile or taking a post down.
If something another user posted infringes your rights, you can ask us at the contact address in section 1 to take it down, and you can request disclosure of sender information under the Act on Countermeasures against Distribution of Information on Platforms. Please tell us what the content is, where it is, and which right it infringes and how. If we receive such a request, or a court order to disclose, we may disclose what we hold as required by law — that is the “where required by law” case above. We hold no IP addresses, so what we hold is your registered email address and the record of the post.
7. Service providers (entrusted processing and third parties outside Japan)
We use the following providers to run the Service and entrust them with personal data to the extent needed. The recipients are Supabase Pte. Ltd., a company of Singapore, and Google LLC and Cloudflare, Inc., companies of the United States. All of them are “third parties located outside Japan” under the APPI.
Entrusting processing to a provider is itself exempt from the consent requirement under APPI Article 27(5)(i). That exemption does not reach Article 28, which governs provision to a third party outside Japan. We therefore rely on obtaining your prior consent before providing it (Article 28(1)).
We do not use the other route (confirming, before providing it, that the recipient has systems meeting the standards in Article 16 of the APPI Enforcement Rules — Article 28(3)). That route requires us to verify the recipient’s internal arrangements and to re-verify them periodically (Rule 18), and the Service is run by its representative partner alone, who cannot honestly claim to do that properly.
When we ask for consent. The app’s sign-up screen says that by continuing you are treated as agreeing to the Terms of Service and to this Privacy Policy, “including the provision of personal data to businesses located in foreign countries”; continuing with sign-up is how consent is given. The launch-notice sign-up on this website says the same thing beside its submit button, and submitting the form is how consent is given there. The three things Article 28(2) requires us to tell you before that — where the recipient is, the personal-information regime in that country, and the measures the recipient takes — are set out in this section.
| Provider | Country | Purpose | Data |
|---|---|---|---|
| Supabase Pte. Ltd. | Singapore | Database, authentication, image storage, realtime messaging, server-side processing, and sending authentication emails | Everything in section 2 except enquiries |
| Google LLC Firebase Cloud Messaging |
United States | Delivering push notifications | The push token, the title and body of the notification, and the identifiers used to open the right screen (see below). Obtaining the token also sends device and app information to Google from the Firebase library |
| Google LLC Sign in with Google |
United States | Signing in with a Google account | Google account identifier, name, email address and whether it is verified, profile picture URL and similar |
| Cloudflare, Inc. Cloudflare Workers Assets |
United States | Serving this website | The IP address and user agent of the browser opening the page, and similar. It does not pass through our servers; Cloudflare keeps it as its own record (see section 9) |
The database and the image storage sit in the Asia Northeast (Tokyo) region (ap-northeast-1). Even with the servers in Japan, Article 28 still applies, because the recipient is a company of a foreign country. We do not treat the Tokyo region as a reason to skip anything Article 28 requires. Data may also be handled from outside Japan for maintenance and similar purposes. Authentication emails, such as sign-in codes, are currently sent using Supabase’s built-in mail sender. If we move to a separate mail provider, we will name it here.
The regime in each recipient’s country, and the measures each recipient takes
- Where the recipients are: two countries — Singapore (Supabase Pte. Ltd.) and the United States (Google LLC, Cloudflare, Inc.). Neither is among the countries the Personal Information Protection Commission has recognised, under Article 15 of the APPI Enforcement Rules, as having standards equivalent to Japan’s (the European Union and the United Kingdom). Article 28 therefore applies to both.
- The personal-information regime in Singapore (Supabase Pte. Ltd.): personal data is protected comprehensively by the Personal Data Protection Act 2012, supervised by the Personal Data Protection Commission. Singapore is not among the countries recognised by Japan’s Personal Information Protection Commission as having standards equivalent to Japan’s.
- The personal-information regime in the United States (Google LLC, Cloudflare, Inc.): there is no comprehensive federal law protecting personal information. Instead there are sector-specific federal laws (health, finance, children and so on) and state laws (California, for example). There is no independent supervisory authority at federal level equivalent to Japan’s Personal Information Protection Commission. Government agencies may obtain information under Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333. This describes Google LLC and Cloudflare, Inc.; it does not describe Supabase.
- The measures each recipient takes: each handles personal data under its data processing terms with us. So far as each publishes:
- Supabase Pte. Ltd. holds a SOC 2 Type 2 report and ISO 27001 certification. Its data processing terms undertake that data is stored, and primarily processed, in the region the customer chooses — which is what makes our choice of the Tokyo region more than a setting. It also engages sub-processors of its own, publishes the list of them, and gives 30 days’ notice of changes to it. That list changes, so we do not reproduce it here.
- Google LLC holds ISO/IEC 27001 certification and SOC 2 and SOC 3 reports.
- Cloudflare, Inc. only serves this website; we provide it with no personal data.
Information sent straight from your device
The following goes directly from your device to the recipient without passing through our servers. We neither collect it nor entrust anyone with it, so it is listed separately from the table above.
| What is sent | To whom | When, and what it is used for |
|---|---|---|
| The video id, your device’s IP address and its user agent | Google LLC (USA) YouTube |
When a film thumbnail is shown and when film is played. No video is embedded in the app |
| The browser’s IP address, its user agent and similar | Google LLC (USA) Google Fonts |
When a page of this website is opened, to serve the typefaces. The app’s own fonts are bundled with the app and send nothing |
What a push notification sends
Push notifications reach your phone through Google’s servers (Firebase Cloud Messaging). What we give Google is the device token, the title and body of the notification, and the identifiers the app needs to open the right screen (the kind of notification, the notification’s own identifier, and the identifier of the team, game or thread it is about). Those identifiers carry no names and no message text. Depending on the kind of notification, the title and body can contain another user’s display name, team names, the date, time and venue of a game or practice, and the first 100 characters of a message, comment or post.
We send notifications marked not to show their text on the lock screen, although your phone or its settings may still show it. You can turn each kind of push notification off in the app’s settings. Turning them off does not stop the notification appearing in the in-app list. A push notification that has already been sent cannot be recalled.
8. What the app stores on your device
The app stores the following on your phone:
- the tokens that keep you signed in (an access token and a refresh token);
- a random identifier created once per installation, used to register for push notifications. It is gone if you uninstall the app or clear its data;
- your interface language, whether the notification explainer has been shown, the team you last selected, and the prefecture you chose in the feed;
- a temporary cache of images it has shown you (profile photos, logos, banners and YouTube thumbnails).
Signing out or deleting your account does not clear any of this from the device automatically. To remove it completely, clear the app’s data in your phone’s settings.
The only permission the app asks for at runtime is permission to send notifications. It also declares the permissions it needs to work, such as internet access — those appear in the store’s permission list too. It does not ask for camera or photo-library access: it receives the single image you pick in Android’s photo picker, and scales it down to 512×512 on the device before uploading. It does not ask for location permission.
After scaling the photo to 512×512 and re-encoding it on your device, the app removes the metadata segments — Exif, XMP, the ICC profile and comments — before the file is uploaded. The location (GPS) and the date the photo was taken are therefore never uploaded. What is visible in the picture itself, such as a building or a sign in the background, can of course still show where it was. Profile photos, team logos and banners are stored where anyone with the URL can open them (see section 4), so please bear that in mind when choosing one.
9. This website
- This website does not use cookies or analytics tools.
- It saves only your language choice in your browser’s localStorage. That value is never sent to us.
- It uses Google Fonts to display text. Opening a page sends your IP address and similar information from your browser to Google’s servers (fonts.googleapis.com and fonts.gstatic.com).
- This website is served by Cloudflare Workers Assets (Cloudflare, Inc., United States). We keep no access logs of our own, but Cloudflare, as the operator of that platform, keeps its own (see section 7).
- An email address typed into the launch-notice field reaches us through the platform of Supabase Pte. Ltd. (Singapore), our processor, and we store it (see below). Like Cloudflare, which serves the page, Supabase keeps its own record of that request as the operator of its platform, including the IP address it came from (see section 7). That is a request log, not analytics and not tracking. Nothing else on this website is sent anywhere.
The launch-notice sign-up
This website has a field where you can leave your email address to be told when the Service launches. We take three things and nothing else: your email address, the website’s interface language at the time, and the date and time. No name, no account. No cookie.
We use the address to send one notification, when the Service is published. We send no newsletter and no advertising, and we use it for nothing else (see section 3, Why we use it). Signing up is separate from an app account and does not create one.
Like the rest of the Service, the sign-up is stored in the database of Supabase Pte. Ltd., a company of Singapore, in the Tokyo region. It adds no new recipient (see section 7).
We keep it until the launch notice has been sent, or until you ask us to delete it, whichever comes first (see section 11). To have it deleted, write to the contact address in section 1; sending the request from the address you signed up with is how we confirm it is yours (see section 13).
10. Security measures
Our basic policy
This policy is our basic policy on the proper handling of personal data, and it is published in the Service.
Rules for handling personal data
Who may read and who may write each kind of data is defined in the database itself — row-level security and per-column grants. Those definitions are the rules. Changing them goes through the project’s review and its automated tests.
Organisational measures
Personal data is handled only by the representative partner named in section 1. If personal data is leaked, lost or damaged, we report it to the Personal Information Protection Commission and tell the people affected, as APPI Article 26 requires.
Personnel measures
If anyone other than the representative partner is ever given access to personal data, they are briefed on this policy and on the handling rules, and bound to confidentiality, before they get it.
Physical measures
The devices used to run the Service have a screen lock and full-disk encryption. They are not left where other people can reach them, and their storage is erased before they are disposed of.
Technical measures
- Encryption in transit (TLS).
- Row-level security in the database. Every table starts with all privileges revoked, and writes are granted only on the columns that need them. What can be read is limited by the row-level policies set on each table. Someone who is not signed in can read no data at all, apart from the public images described in section 4.
- Writes that span several tables go through a server-side function as a rule. Some — editing a profile, answering an RSVP, disbanding a team — are direct updates limited to the columns granted for writing.
- Automated tests check who can see what, from the point of view of an outsider, an ordinary member, an admin and someone who has been blocked.
- Requests to send a push notification are processed only after their signature has been verified.
- Push notifications are sent marked not to show their text on the lock screen.
- Deleting an account requires a sign-in within the last 10 minutes.
- Careful handling of administrative keys and least-privilege access. The server key is never built into the app.
- Email addresses are by design never copied into any area other users can read.
Supervising our providers
We select our providers and supervise them as APPI Article 25 requires (see section 7). What the provider’s own platform records and backs up, and for how long, is set by the provider; we have checked its published documentation for it (see section 2).
Understanding the external environment
We use services from Supabase Pte. Ltd., a company of Singapore, and from Google LLC and Cloudflare, Inc., companies of the United States (the database and the images are stored in the Tokyo region). The personal-information regimes of both countries are described in section 7, and the measures above are taken in the light of them.
11. How long we keep it
Some things are deleted automatically; others are not.
| Information | Retention |
|---|---|
| In-app notifications (including message extracts) | Deleted automatically 90 days after the last event |
| Push notification tokens | A monthly job deletes tokens unused for 270 days and tokens whose sign-in session has ended. Signing out makes the app try to remove its registration there and then, but that can fail — with no network, for instance. If it does, the token is removed the next time we try to send you a notification, or at the next monthly job |
| Reports (including the copy of the reported content) | Deleted automatically 180 days after they are made |
| Fault records | 30 days. Scheduled-job history, 14 days |
| Records of saving a stat sheet | 1 day |
| Monthly ranking history | 24 months |
| “Looking for a team” posts and team openings | Listed for 60 days (refreshing starts the 60 days again). The record remains after it stops being listed |
| Invites from a team | Expire after 14 days. The record remains |
| Requests to join a team | Expire after 30 days. The record remains |
| Launch notice sign-ups (email address) | Until the launch notice has been sent, or until you ask us to delete it, whichever comes first. We delete it once the notice has gone out |
| Everything else — profiles, teams, games and practices, attendance, listings and request messages, chat, feed, statistics, XP and badges, recruiting records | There is no automatic deletion. Deleting your account removes much of it, but request message bodies, feed post bodies, and the listings, games, practices, scoring and statistics records you created stay indefinitely with your name removed (see 12. Deleting your account) |
When a team is disbanded its details stop being shown to other users, but former members still see them. Disbanding cannot be undone.
Backups and server logs are taken and kept by Supabase, our provider, on its own platform. What they contain and how long they are kept is set by Supabase rather than by us, according to the plan it provides (see section 2).
If we end the Service, we will announce it in the Service and on this website at least 30 days before the closing date, and delete the data after that date. There is no feature for exporting your data in bulk, so please keep your own copy of anything you need before the closing date.
We may keep information the law requires us to keep, and records needed to deal with misuse, for as long as necessary.
12. Deleting your account
You can delete your account yourself at any time from Settings → Delete account in the app. For safety you are asked to sign in again immediately beforehand. Deletion cannot be undone. If you cannot use the app, contact us using the details in section 1 and we will delete it after confirming your identity.
What it does to your teams
Before you confirm, the app shows you which of these applies:
- if the team has another admin, or you are an ordinary member: you leave the team;
- if you are its only admin: the member who joined earliest becomes admin and is notified;
- if you are its only member: the team is disbanded and its upcoming games are cancelled.
What is deleted
Your profile and photo, your team memberships, attendance answers, notification preferences, push tokens, the notifications addressed to you, the blocks and follows you made as an individual, feed reactions and comments, per-player statistics, XP, level, badges and showcase, your “Looking for a team” post, join requests, invites, guest places and helper offers. Your team chat messages have their text and film links erased. Your display name, and extracts of your chat messages, are also stripped from notifications already delivered to other users.
A block you applied as a team’s admin is different: the block itself stays with the team. All that goes is the record of who applied it. The person blocked remains blocked by that team.
What remains
The following stays as data after you leave. It is never shown next to your name: team chat and notifications show “a former member”, while a game request thread and a feed post simply stop showing who wrote it.
Our own records do keep an identifier with no name attached, so we continue to treat all of this as personal data under this policy. A request under APPI Article 35 to stop using or erase it can be made to the contact in section 1, and we will deal with it as the law requires.
- the messages you sent in a game request thread;
- feed post bodies (film captions and recruiting notes);
- listings, games, practices, scoring actions, saved stat sheets and film links you created;
- copies of your posts or messages held inside a report; and the reason, detail and content copy of any report you made — both for up to 180 days after the report;
- extracts of your request messages and comments inside other users’ notifications, for up to 90 days;
- an identifier with no name attached, inside the internal records used to total up games;
- any team you created that someone else now administers.
Photos
Your profile photo is removed from storage after the deletion itself. That step is queued rather than immediate. If it fails, it is retried the next time that clean-up runs; there is no scheduled job that retries it on its own. A copy may remain in the CDN’s cache for a while.
13. Access, correction and other requests
Under the APPI you can ask us to tell you the purposes of use of your retained personal data, disclose it (including records of provision to third parties), correct, add to or delete it, stop using or erase it, or stop providing it to third parties. We will confirm your identity and respond without delay as the law requires.
How to make a request
- Where to send it: to the email address in section 1. There is no set form.
- What to say: which request you are making (notification of purpose, disclosure, correction, addition or deletion, suspension of use or erasure, or suspension of provision to third parties), and which information it concerns.
- How we confirm your identity: by the request coming from your registered email address. We hold no postal address and no phone number for you, so that address is the only identifier we have for you. We may write back to it to confirm the request.
- Requests through an agent: an appointed agent or a statutory representative may make a request. For an appointed agent, please send written authority such as a power of attorney; for a statutory representative, evidence of that status. In either case, please include a copy of identification for the agent.
- Fee: free. We charge nothing, including for notification of purpose and for disclosure.
- How and when we reply: electronically, to your registered email address, within two weeks of the request. If it will take longer to look into, we will tell you within those two weeks how much longer we expect to need and why.
What you can and cannot do in the app
You can view, edit or delete your profile, your team’s details (if you are an admin), listings, attendance answers, team chat messages and feed comments directly in the app. Feed posts themselves cannot be deleted from the app — removing a film link does stop its post being shown. If you want one removed, contact us. There is no feature for exporting your data in bulk; we handle disclosure requests individually through the contact address.
Some information is not visible to you. If a team has blocked you, that record is not shown on any screen. If you ask us to disclose it, we may withhold it in whole or in part under APPI Article 33(2) where disclosure would risk harming the rights or interests of another user, or would seriously hinder the proper conduct of the Service. If we do, we will tell you so and give our reason.
Stat sheets are entered for the whole side by one of your team’s admins. If a figure is wrong, ask that admin to correct it, and contact us if that does not resolve it.
14. Complaints
If you have a concern or complaint about how the Service handles personal information, please contact us first using the details in section 1. You may also raise it with the Personal Information Protection Commission, the supervisory authority.
Personal Information Protection Commission: https://www.ppc.go.jp/en/
15. Minors
The Service is for people aged 18 or over. The Terms of Service set the same age. If you are under 18, you may not use the Service.
There are two reasons for that age. The first is that the Service has no age check of any kind: we collect neither a date of birth nor an age. The second is that a “Looking for a team” post shows your photo, your height and your area (prefecture and municipality) to any adult who runs a team on Circles, anywhere in Japan (see section 4). There is also no mechanism for obtaining or recording a guardian’s consent, so we set the minimum age at 18.
If we learn that someone under 18 is using the Service, we may suspend or delete the account under the Terms of Service. A request from the person, or from their statutory representative, to disclose or delete their information goes to the contact address in section 1 (see section 13).
16. Changes to this policy
We may change this policy to reflect changes in the law or the Service. We will announce important changes in the Service.
17. Data sources
The prefecture and municipality data in the Service is based on the following source, adapted (for example, the check digit is removed from each local government code). The romanised readings are our own and do not come from the source.
出典:総務省「全国地方公共団体コード」 (Source: Ministry of Internal Affairs and Communications, “Local Government Codes”, https://www.soumu.go.jp/denshijiti/code.html)
18. Language
The Japanese version of this policy is the authoritative text. This English version is a translation for reference; if the two differ, the Japanese version prevails.
Enacted: September 19, 2026 · Last updated: September 19, 2026
End of policy.