プライバシーポリシー — okoma

最終更新日:2026年7月4日

1. 事業者情報

Volker Haigis(個人開発者)
住所:Hoheluftchaussee 39, 20253 Hamburg, ドイツ
お問い合わせ:support@okoma.app

2. okomaについて — 医療機器ではありません

okomaは、つながった二人の間の純粋に情報伝達のためのコミュニケーション手段です。okomaは医療機器ではなく、健康管理アプリでもありません。健康データの分析・診断・表示は一切行いません。Apple Watchから読み取られる心拍数の値は、パートナーの端末上でのハートのアニメーションと触覚信号のリズムとしてのみ使用されます。脈拍数は表示されず、履歴も保存されません。

3. 取り扱う情報

情報利用目的保存場所
Appleサインイン識別子(匿名化されたユーザーID)ログイン・アカウント管理Firebase Authentication
パートナー連携情報(partnerUid・役割・技術的なペアリング用シークレット)二つのアカウントをつなぐ中核機能・信号伝送の保護Cloud Firestore
配信設定(一時停止・一日の始まり・タイムゾーン)ご希望のときにのみ信号をお届けするためCloud Firestore
瞬間的な心拍数の値パートナーへの伝達信号。次の信号で上書きされ、履歴は残りませんHealthKit(Watch内ローカル)→ Cloud Firestore(最新値のみ)
プッシュトークン(FCM)信号通知の配信Cloud Firestore / Firebase Cloud Messaging
購入・サブスクリプション状況サブスクリプションの処理RevenueCat・Apple App Store

HealthKitのデータを広告・マーケティング・データマイニングに使用することはなく、第三者に販売することもありません。

4. 委託先・提供先

5. 個人情報保護法(APPI)に基づく取り扱い

当方は、個人情報保護法に従い、利用目的の範囲内でのみ個人データを取り扱い、安全管理措置(通信の暗号化、アクセス制限)を講じます。外国にある第三者(米国のGoogle・RevenueCat・Apple)への提供は、本ポリシーへの同意をもって行われます。各社は各国の制度に基づく適切な保護措置を講じています。

6. 保存期間

瞬間的な心拍数の値は新しい信号のたびに上書きされ、履歴は存在しません。アカウントおよび連携データは、アカウント削除まで保持されます。アカウント削除はアプリ内から直接行うことができ、FirestoreとFirebase Authenticationからデータが削除されます。

7. ご本人の権利

保有個人データの開示・訂正・利用停止・削除を請求することができます。support@okoma.app までご連絡ください。

8. 未成年の方について

okomaは16歳未満のお子様を対象としていません。保護者がお子様にWatchを装着させる場合(しるしの受け取りなど)は、保護者ご自身のアカウントの範囲内で、その責任において行われるものとします。お子様のアカウントが作成されることはありません。

9. 改定について

本ポリシーは必要に応じて改定されます。最新版は okoma.app/privacy にてご確認いただけます。

Datenschutzerklärung — okoma

Stand: 4. Juli 2026

1. Verantwortlicher

Volker Haigis (Einzelentwickler)
Hoheluftchaussee 39, 20253 Hamburg, Deutschland
Kontakt: support@okoma.app

2. Was okoma ist — und was nicht

okoma ist ein rein informatives Kommunikationsmittel zwischen zwei verbundenen Personen. okoma ist kein Medizinprodukt und keine Gesundheits-App: Es findet keine Auswertung, Diagnose oder Anzeige von Gesundheitsdaten statt. Der von der Apple Watch gelesene Herzfrequenz-Wert dient ausschließlich als Taktgeber für eine Herz-Animation und ein haptisches Signal beim verbundenen Partner. Es wird keine Pulszahl angezeigt und kein Verlauf gespeichert.

3. Welche Daten wir verarbeiten

DatumZweckSpeicherort
Apple-Sign-in-Kennung (anonymisierte User-ID)Anmeldung, KontoverwaltungFirebase Authentication
Partner-Verknüpfung (partnerUid, Rolle, technisches Kopplungsgeheimnis)Kernfunktion: Verbindung zweier Konten, Absicherung der SignalübertragungCloud Firestore
Zustell-Einstellungen (Signal-Pause, Tagesbeginn, Zeitzone)Signale nur dann zustellen, wenn Du sie empfangen möchtestCloud Firestore
Herzfrequenz-MomentanwertÜbertragungssignal an den Partner; wird beim nächsten Signal überschrieben, kein VerlaufHealthKit (lokal auf der Watch) → Cloud Firestore (nur letzter Wert)
Push-Token (FCM)Zustellung der Signal-BenachrichtigungCloud Firestore / Firebase Cloud Messaging
Kauf-/Abo-StatusAbwicklung des AbonnementsRevenueCat, Apple App Store

HealthKit-Daten werden niemals für Werbung, Marketing oder Data-Mining verwendet und nicht an Dritte verkauft.

4. Empfänger und Auftragsverarbeiter

Mit Blick auf Nutzer in der EU erfolgt die Übermittlung in Drittländer (Japan, USA) auf Grundlage von Angemessenheitsbeschlüssen der EU-Kommission (Japan) bzw. EU-Standardvertragsklauseln und dem EU-US Data Privacy Framework.

5. Rechtsgrundlagen (DSGVO)

6. Speicherdauer

Der Herzfrequenz-Momentanwert wird bei jedem neuen Signal überschrieben; es existiert kein Verlauf. Konto- und Pairing-Daten bestehen bis zur Löschung deines Kontos. Die Kontolöschung ist direkt in der App möglich und entfernt deine Daten aus Firestore und Firebase Authentication.

7. Deine Rechte

Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch (Art. 15–21 DSGVO) sowie auf Beschwerde bei einer Datenschutz-Aufsichtsbehörde. Wende dich dazu an support@okoma.app.

8. Kinder

okoma richtet sich nicht an Kinder unter 16 Jahren. Legt ein Erziehungsberechtigter die Watch einem Kind an (z. B. als Empfänger eines Zeichens), geschieht dies in seiner Verantwortung innerhalb seines eigenen Kontos; ein eigenes Konto für das Kind entsteht dabei nicht.

9. Änderungen

Wir aktualisieren diese Erklärung bei Bedarf; die jeweils aktuelle Fassung findest du unter okoma.app/privacy.

Privacy Policy — okoma

Last updated: July 4, 2026

1. Controller

Volker Haigis (independent developer)
Hoheluftchaussee 39, 20253 Hamburg, Germany
Contact: support@okoma.app

2. What okoma is — and is not

okoma is a purely informational means of communication between two connected people. okoma is not a medical device and not a health app: it does not evaluate, diagnose, or display health data. The heart-rate value read from Apple Watch serves solely as the rhythm source for a heart animation and a haptic signal on the connected partner's device. No pulse number is displayed and no history is stored.

3. Data we process

DataPurposeStorage
Apple Sign-in identifier (anonymized user ID)Sign-in, account managementFirebase Authentication
Partner link (partnerUid, role, technical pairing secret)Core feature: connecting two accounts, securing the signal transmissionCloud Firestore
Delivery settings (signal pause, start of day, time zone)Delivering signals only when you want to receive themCloud Firestore
Momentary heart-rate valueTransmission signal to the partner; overwritten by the next signal, no historyHealthKit (local on Watch) → Cloud Firestore (latest value only)
Push token (FCM)Delivery of the signal notificationCloud Firestore / Firebase Cloud Messaging
Purchase/subscription statusSubscription processingRevenueCat, Apple App Store

HealthKit data is never used for advertising, marketing, or data mining, and is never sold to third parties.

4. Recipients and processors

For users in the EU, transfers to third countries (Japan, USA) rely on EU adequacy decisions (Japan) and EU Standard Contractual Clauses / the EU-US Data Privacy Framework respectively.

5. Legal bases (GDPR)

6. Retention

The momentary heart-rate value is overwritten with every new signal; no history exists. Account and pairing data persist until you delete your account. Account deletion is available directly in the app and removes your data from Firestore and Firebase Authentication.

7. Your rights

You have the right to access, rectification, erasure, restriction, data portability, and objection (Art. 15–21 GDPR), and to lodge a complaint with a supervisory authority. Contact support@okoma.app.

8. Children

okoma is not directed at children under 16. If a parent or guardian places the Watch on a child (e.g. as the receiver of a sign), this happens under their responsibility within their own account; no separate account is created for the child.

9. Changes

We update this policy as needed; the current version is available at okoma.app/privacy.