Leto

Mobile App Privacy Policy

Effective and last updated:

This Privacy Policy explains how Ryosuke Yokota (the "Developer," "we," or "us") handles information in connection with the Leto mobile application (the "App"). It applies to the mobile App and is separate from the policy for the public Leto website.

1. Information processed by the App

  • Account and sign-in data: the App creates a Firebase anonymous account so learning data can be stored securely. This includes a Firebase user ID, sign-in type, device platform, creation time, selected books, and, if you provide it, install source. If you link or use Google or Apple sign-in, Firebase may also receive the email address, display name, profile image, and other basic profile information supplied by that provider.
  • Cloud learning data and user content: selected books, vocabulary and section status, answers and answer history, study sessions, learning statistics, streaks, bookmarks, word notes, exam dates, goals, visible study formats and ranges, language and theme preferences, reminder settings, and vocabulary correction requests are stored in Google Firebase.
  • Local App data: cached learning content, audio, settings, one-time feature receipts, and locally scheduled reminder information may be stored on your device.
  • Notification data: if notification permission is granted, the App processes notification preferences and may store a Firebase Cloud Messaging token, device platform, and token creation time under your account to deliver reminders and service messages.
  • Analytics and diagnostics: Firebase Analytics processes screen views, sign-in and onboarding steps, study activity, feature use, purchase-flow events, App version, device and platform information, installation identifiers, and the Firebase user ID included with App events. Firebase Crashlytics and related Firebase diagnostic services may process crash logs, performance information, device state, and technical identifiers to diagnose reliability problems.
  • Purchase data: Apple App Store or Google Play and RevenueCat process product identifiers, price and currency, transaction and subscription status, entitlement status, store receipt information, and an App user identifier to complete, validate, restore, and manage purchases. We do not receive your full payment-card details.
  • Support communications: if you contact us, we receive your email address and any information you choose to include so we can respond.
  • Advertising and consent data: Google Mobile Ads and Google's User Messaging Platform ("UMP") may process IP address and approximate location derived from it, App and device information, SDK or installation identifiers, consent signals, and advertisement requests, impressions, clicks, reward completion, and other interactions. This data is used to deliver and measure ads, limit repetition, and prevent fraud and abuse.

2. How we use information

We process the information above to:

  • authenticate users and sync learning data across supported sessions;
  • provide study, note, statistics, reminder, and personalization features;
  • send notifications that you enable;
  • measure use, diagnose problems, maintain security, and improve the App;
  • complete, validate, restore, and support purchases;
  • deliver, measure, secure, and manage advertisements;
  • respond to support, correction, and privacy requests; and
  • comply with law and protect users, the Developer, and others.

3. Leto's advertising configuration

The App may display anchored banner ads, interstitial ads at study-session boundaries, and user-initiated rewarded ads that temporarily unlock a feature. Ad placements are hidden from users whose Premium entitlement has been recognized. The Mobile Ads SDK and an advertisement preload may nevertheless initialize before or independently of an entitlement check, so the technical advertising data described above may be processed even when no ad is displayed.

Every Leto ad request is configured as non-personalized, and ad content is limited to Google's G rating. Leto is configured as a general-audience App, so Google's child-directed and under-age-of-consent request tags are set to false. Non-personalized ads can still use contextual information and limited device or SDK identifiers for delivery, frequency control, measurement, security, and fraud prevention.

On iOS, Leto does not request App Tracking Transparency ("ATT") permission and does not request access to the IDFA. On Android, Google may process identifiers permitted by Android and your advertising privacy settings. The App requests updated UMP consent information and attempts to show a Google-provided consent form when required before initializing Mobile Ads.

4. Advertising consent and choices

If UMP displays a consent or privacy form in your region, you can use the controls in that form to make the available choices. You can also use the advertising privacy controls in iOS or Android and, where applicable, your Google account. Because Leto does not request ATT permission, there is no Leto ATT choice to change. You may contact us if you want help identifying the controls available to you. Changes apply prospectively and do not necessarily remove information already retained for security, accounting, or legal purposes.

5. Service providers and disclosure

We do not sell personal information. The following providers process information only as needed to provide their respective services:

  • Google LLC: Firebase Authentication, Firestore, Analytics, Crashlytics, Performance Monitoring, Cloud Functions, Cloud Messaging, Google Sign-In, Google Play billing, Google Mobile Ads, and UMP. See the Google Privacy Policy and information about Google advertising technologies.
  • Apple Inc.: Sign in with Apple, App Store billing, and platform notification services on iOS. See the Apple Privacy Policy.
  • RevenueCat, Inc.: purchase validation, entitlement management, and purchase analytics. See the RevenueCat Privacy Policy.

We may also disclose information when required by law, to protect legal rights or safety, or in connection with a business transfer. We do not intentionally copy raw advertising identifiers into a Developer-operated database.

6. International data processing

Google, Apple, and RevenueCat may process information in Japan, the United States, and other countries where they or their subprocessors operate. Those countries may have data-protection laws different from those in your country. Processing is subject to the providers' contractual, organizational, and technical safeguards and applicable law.

7. Retention, deletion, and your choices

  • Cloud account and learning data is retained while your account remains active. The App's Settings screen provides account deletion, which deletes the active Firebase user record and current user-data collections. Provider backups, security logs, aggregated records, and records required by law may remain for a limited period.
  • You can separately reset study data while keeping the account, or remove local data by clearing App data or uninstalling the App.
  • You can disable notifications in the App or device settings. The App attempts to keep the current device's messaging token up to date, and account deletion removes stored messaging-token records under that account.
  • Firebase analytics and diagnostic data, RevenueCat purchase records, store transactions, advertising data, and consent records are retained under our service configuration, provider policies, fraud-prevention needs, and legal obligations. In-App account deletion may not delete information already aggregated or retained independently by those providers.
  • Support communications are retained only as long as reasonably needed to respond, maintain support records, resolve disputes, and meet legal duties.

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal information. Contact us to make a request. We may need limited information to verify and complete it.

8. Security

We use reasonable technical and organizational safeguards appropriate to the nature of the information, including authenticated database access rules and encrypted network connections provided by the operating system and service providers. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

9. Children's privacy

Leto is a general-audience vocabulary-learning App and is not directed specifically to children under 13. It does not use child-directed or under-age-of-consent ad request tags, although all ads are non-personalized and limited to the G content rating. If you are below the age at which you can consent to data processing in your country, please use the App only with a parent or guardian's involvement. If you believe a child provided personal information without appropriate authorization, contact us so we can review and delete it where appropriate.

10. Changes to this policy

We may update this Privacy Policy when the App, our providers, or legal requirements change. We will post the revised policy at this URL and update the date above. Material changes may also be communicated in the App or store listing.

11. Developer and privacy contact

Developer: Ryosuke Yokota
Email: yokopi521@gmail.com