Head-Light プライバシーポリシー

最終更新日: 2026年9月6日

基本方針

Head-Light(以下「本アプリ」)は、あなたの記録を広告の材料や商品にしません。本アプリにはアカウント登録がなく、第三者広告、広告目的の追跡、個人データの販売を行いません。

記録の保存場所

入力した言葉、写真、録音、コレクション、チェック記録などは、基本的にお使いの端末内に保存されます。開発者がこれらを一覧したり、独自の記録用サーバーへ保存したりすることはありません。ただし、ユーザーが明示的に作成したコレクション共有リンクに必要な情報は、下記のとおり保存されます。

ユーザーが「Head-Light保管庫」やバックアップを設定した場合に限り、選択したiCloud Drive、NAS、またはファイル保存先へ記録が書き出されます。その保存先におけるデータの取り扱いは、ユーザーが選択したサービスの規約とプライバシーポリシーに従います。

AI機能

対応端末では、言葉の整理などをAppleの端末内AIで処理できます。この処理では記録は端末の外へ送信されません。

クラウドAIを使う機能では、その機能の実行に必要なテキスト、画像、関連する文脈が、暗号化された通信でHead-Lightの中継サーバー(Cloudflare Workers)を経由してAnthropic APIへ送信されます。中継サーバーはAIへの転送と利用上限の管理だけを行い、送信した本文や画像を保存しません。

利用上限の管理には、氏名やメールアドレスと結びつかないランダムな識別子と推定利用額を使用します。購入者の月次利用記録は最長60日、一度きりの無料体験の利用記録は最長365日で自動的に削除されます。

クラウドAIの送信先はこの経路だけです。ユーザーが自分のAnthropic APIキーを設定して直接送信する機能は提供していません。Anthropic APIの入力・出力は通常30日以内に削除されます。ただし、安全対策や法令遵守のためAnthropicが定める例外があります。データは米国で保存され、米国、欧州、アジア、オーストラリアのAnthropic運用地域で処理される場合があります。

送信の前に、必ずアプリ内で同意を求めます。何を送るか、どこへ送るか、何を送らないかを画面で説明し、同意されるまでクラウドAIへは一切送信しません。同意しない場合も、言葉・手帳・予定・道具・棚・保存済みの記録の閲覧といったHead-Lightの機能は引き続き利用でき、保存済みの記録は失われません。同意はいつでも設定画面から取り消せます。取り消した後は、次に使うときにあらためて同意を求めます。

Anthropicおよび中継サーバーの提供元であるCloudflareは、本ポリシーおよびApp Store Reviewガイドラインが定める水準と同等以上のユーザーデータ保護を提供することを、それぞれの利用規約およびプライバシーポリシーにおいて約束しています。Head-Lightは、これらの事業者へ送信したデータを広告や第三者への販売、他社アプリをまたぐ追跡に利用しません。

アプリ内購入(RevenueCat)

本アプリは、アプリ内購入の提供、購入状態の確認、購入の復元のためにRevenueCatを使用します。RevenueCatへは、ランダムに生成された匿名のユーザー識別子、購入した商品、購入履歴、サブスクリプションの状態などが送信されます。氏名、メールアドレス、アプリ内に保存した言葉・写真・録音はRevenueCatへ送りません。

これらの情報は、購入済み機能を正しく利用できるようにすることと、購入機能の運用状況を把握することにのみ使用します。広告への利用や、他社アプリをまたぐ追跡には使用しません。決済そのものはAppleが処理します。

リンク・書籍などの情報取得

ユーザーがリンク、書籍、音楽などをコレクションへ追加するとき、本アプリは表紙、サムネイル、題名などを取得するため、リンク先のサイトや公開情報サービスへ通信することがあります。送信先では、一般的なウェブアクセスと同様にIPアドレスなどが処理される場合があります。取得した内容はコレクション作成のために使用します。

マイク、写真、カレンダーなど

マイク、音声認識、カメラ、写真、ミュージックライブラリ、カレンダー、通知、位置情報(天気表示)へのアクセスは、該当する機能を使うときにOSの許可を得て行います。許可はiPhoneやiPadの設定からいつでも変更できます。

外部サービスへの共有

「AIに渡す」機能や共有ボタンは、ユーザー自身の操作で内容をコピーまたは共有するものです。共有後の取り扱いは、ChatGPT、Claude、Geminiなど、選択したサービスのプライバシーポリシーに従います。

コレクションの短い共有リンクを作成すると、ユーザーが選んだコレクション名、リンクカードの題名・URL・並び順と、代替用の共有表紙画像がCloudflare KVに保存されます。YouTubeの公式サムネイルとSpotifyのアルバムジャケットは、元リンクとサービス名を保ち、切り抜かず表紙へ使用します。Apple Musicだけの共有では、SNSプレビューと共有ページがAppleの公式CDNにあるジャケットURLを直接参照します。Head-LightはApple Musicのジャケットを共有表紙へコピー・合成・保存しません。TikTok・Instagram投稿画像と一般Webの画像は表紙へ書き出しません。共有ページは、元サイトが公開するOG画像などのURLを取得して元サイトから直接表示する場合があります。画像カードを含むコレクションでは、元の写真ファイルや位置情報ではなく、端末上で縮小・合成した棚全体の表紙だけを保存します。個人的なメモ、録音、端末固有のApple Music IDは保存されません。リンクを知る人は内容と表紙を閲覧できます。現時点では、送信後にリンクを無効化できません。

Threadsの投稿取り込み

ユーザーがThreadsの公式認証画面で許可した場合、本アプリはThreads APIから、そのユーザーのプロフィール情報(ユーザーID、ユーザー名、表示名、プロフィール画像)と本人の投稿(本文、投稿時刻、投稿ID、投稿URL)を取得します。取得した情報とアクセストークンは端末内に保存され、投稿はユーザーが選んだ機能として手帳と専用フォルダへ追加されます。Head-Lightは投稿、プロフィール、アクセストークンを独自のサーバーへ保存しません。

認証コードはアクセストークンへ交換するために限り、暗号化された通信でHead-LightのCloudflare Workers中継サーバーを通過します。Threads App Secretは中継サーバー内だけで使用されます。連携は設定からいつでも停止または解除でき、解除すると端末内のアクセストークンと連携アカウント情報を削除します。すでに手帳へ取り込んだ投稿は通常の記録として残り、ユーザーがアプリ内で削除できます。

Xの投稿取り込み

ユーザーがXの公式認証画面で許可した場合、本アプリはX APIから、そのユーザーのプロフィール情報(ユーザーID、ユーザー名、表示名、プロフィール画像)と本人の投稿(本文、投稿時刻、投稿ID、投稿URL)を取得します。返信とリポストは取得しません。取得した情報とアクセストークンは端末内に保存され、投稿はユーザーが選んだ機能として手帳と専用フォルダへ追加されます。Head-Lightは投稿、プロフィール、アクセストークンを独自のサーバーへ保存しません。

認証にはOAuth 2.0 PKCEを使い、認証コードはXからアプリへ直接返されます。アクセストークンへの交換もアプリからXへ直接行います。Head-Lightの中継サーバーは公開情報であるClient IDをアプリへ渡すだけで、認証コードやアクセストークンを受け取らず、保存しません。連携は設定からいつでも停止または解除でき、解除すると端末内のアクセストークンと連携アカウント情報を削除します。すでに手帳へ取り込んだ投稿は通常の記録として残り、ユーザーがアプリ内で削除できます。

YouTubeプレイヤー

ユーザーがYouTubeの連続再生を選び、初回の案内に同意した場合、YouTubeの公式埋め込みプレイヤーを読み込みます。動画の表示・再生、再生可否の確認、不正利用の防止などのため、IPアドレス、端末・ブラウザ情報、再生操作などがGoogleおよびYouTubeへ送信される場合があります。Head-LightはYouTube動画をダウンロードせず、音声を分離せず、バックグラウンド再生を提供しません。

削除とお問い合わせ

アプリ内の記録は各画面から削除できます。アプリを削除すると端末内のデータも削除されますが、ユーザーが別途作成したバックアップや外部保管庫のデータは自動では削除されません。

プライバシーに関するご質問や、サービス側に保存された情報についてのご相談は、headlight.app.jp@gmail.com までご連絡ください。

Head-Lightは、あなたの言葉や「好き」を広告のために利用しません。必要な外部通信は、あなたが選んだ機能を動かすために限定します。

利用する外部サービスの方針

Head-Light Privacy Policy

Last updated: September 6, 2026

Our approach

Head-Light (the “App”) does not turn your records into advertising data or a product. The App requires no account, contains no third-party advertising, does not track you for advertising, and does not sell personal data.

Where your records are stored

Words, photos, recordings, collections, check-ins, and other records are stored primarily on your device. The developer cannot browse them and does not store them on a proprietary record-storage server, except for information required for a Collection sharing link that you explicitly create, as described below.

Only when you choose to configure a Head-Light Vault or create a backup are records written to your selected iCloud Drive, NAS, or file location. Data stored there is governed by the terms and privacy policy of the service you select.

AI features

On supported devices, features such as word organization can run using Apple's on-device AI. On-device processing does not send your records off the device.

When you use a cloud AI feature, the text, images, and relevant context required for that feature are sent over an encrypted connection to the Anthropic API through Head-Light's relay hosted on Cloudflare Workers. The relay only forwards requests and enforces usage limits; it does not store the submitted text or images.

To enforce usage limits, the relay uses a random identifier that is not linked to your name or email address and an estimated usage amount. Monthly usage records for subscribers expire after no more than 60 days. The one-time free-taste usage record expires after no more than 365 days.

This is the only path by which cloud AI requests leave the device. Head-Light does not offer a way to supply your own Anthropic API key and send requests directly. Anthropic normally deletes API inputs and outputs within 30 days, subject to its safety and legal-retention exceptions. Data is stored in the United States and may be processed in Anthropic operating regions in the United States, Europe, Asia, and Australia.

Head-Light asks for your permission in the app before anything is sent. A screen explains what is sent, who receives it, and what is never sent. Nothing goes to the cloud AI until you agree. If you decline, Head-Light keeps working — words, journal, plans, tools, shelves, and reading everything you have saved — and nothing you have saved is removed. You can withdraw your consent at any time in Settings; after that, Head-Light asks again the next time a cloud AI feature is used.

Anthropic and Cloudflare, which hosts the relay, each commit in their terms of service and privacy policies to providing protection of user data equal to or greater than that described in this policy and required by the App Store Review Guidelines. Head-Light does not use data sent to these providers for advertising, does not sell it, and does not use it to track you across other companies' apps.

In-app purchases (RevenueCat)

Head-Light uses RevenueCat to offer in-app purchases, verify entitlements, and restore purchases. RevenueCat receives a randomly generated anonymous user identifier, purchased products, purchase history, and subscription status. Head-Light does not send your name, email address, words, photos, or recordings to RevenueCat.

This information is used only to provide purchased features and understand the operation of the purchase system. It is not used for advertising or cross-app tracking. Apple processes the payment itself.

Link and catalog metadata

When you add a link, book, music release, or similar item to a Collection, the App may contact the linked website or public metadata services to retrieve artwork, thumbnails, titles, or related details. Those services may process information normally associated with a web request, such as an IP address. Retrieved data is used to create your Collection item.

Microphone, photos, calendar, and other permissions

The App requests access to the microphone, speech recognition, camera, photos, music library, calendar, notifications, or location (for weather) only when a feature needs it and only after receiving operating-system permission. You can change permissions at any time in device Settings.

Sharing with external services

The “Send to AI” feature and system share buttons copy or share content only when you choose to do so. After sharing, the privacy policy of the selected service—such as ChatGPT, Claude, or Gemini—applies.

When you create a short Collection sharing link, the Collection name, link-card titles, URLs and order that you chose to share, together with a fallback cover image, are stored in Cloudflare KV. Official YouTube thumbnails and Spotify album artwork appear uncropped with the original link and service name. For Apple Music-only shares, the social preview and shared page directly reference artwork URLs on Apple’s official CDN. Head-Light does not copy, composite, or store Apple Music artwork in the sharing cover. TikTok, Instagram, and general-web images are not exported into the cover. The shared page may retrieve URLs for OG images or similar previews published by the source site and display them directly from that site. For Collections containing image cards, only the whole-shelf cover downscaled and composited on the device is stored, not original photo files or location data. Personal notes, recordings, and device-specific Apple Music IDs are not stored. Anyone who knows the link can view its content and cover. A sent link cannot currently be revoked.

Importing Threads posts

If you grant access on the official Threads authorization screen, the App retrieves your Threads profile information (user ID, username, display name, and profile image) and your own posts (text, posting time, post ID, and permalink) from the Threads API. The retrieved information and access token are stored on your device, and posts are added to your journal and a dedicated folder as a feature you chose to use. Head-Light does not store posts, profile information, or access tokens on its own server.

The authorization code passes over an encrypted connection through Head-Light’s Cloudflare Workers relay only to exchange it for an access token. The Threads App Secret is used only inside the relay. You can pause or disconnect the integration from Settings at any time. Disconnecting deletes the on-device access token and linked-account information. Posts already imported remain as ordinary records until you delete them in the App.

Importing X posts

If you grant access on the official X authorization screen, the App retrieves your X profile information (user ID, username, display name, and profile image) and your own posts (text, posting time, post ID, and permalink) from the X API. Replies and reposts are excluded. The retrieved information and access token are stored on your device, and posts are added to your journal and a dedicated folder as a feature you chose to use. Head-Light does not store posts, profile information, or access tokens on its own server.

Authorization uses OAuth 2.0 with PKCE. X returns the authorization code directly to the App, and the App exchanges it directly with X for an access token. Head-Light’s relay provides only the public Client ID to the App; it does not receive or store authorization codes or access tokens. You can pause or disconnect the integration from Settings at any time. Disconnecting deletes the on-device access token and linked-account information. Posts already imported remain as ordinary records until you delete them in the App.

YouTube player

When you choose continuous YouTube playback and accept the first-use notice, Head-Light loads the official embedded YouTube player. Google and YouTube may receive information such as your IP address, device and browser information, and playback interactions to display and play videos, determine playability, and prevent abuse. Head-Light does not download YouTube videos, separate their audio, or provide background playback.

Deletion and contact

You can delete records from within the App. Deleting the App removes on-device data, but does not automatically delete backups or files you separately stored in an external vault.

For privacy questions or requests concerning information held by the services described above, contact headlight.app.jp@gmail.com.

Head-Light does not use your words or the things you love for advertising. External communication is limited to operating the features you choose to use.

Third-party privacy policies

Head-Light 개인정보 처리방침

최종 업데이트: 2026년 9월 6일

기본 방침

Head-Light(이하 “앱”)는 이용자의 기록을 광고 데이터나 판매 상품으로 사용하지 않습니다. 계정 가입이 필요 없으며, 제3자 광고, 광고 목적 추적 및 개인정보 판매를 하지 않습니다.

기록의 저장 위치

입력한 글, 사진, 녹음, 컬렉션 및 체크 기록은 원칙적으로 이용자의 기기에 저장됩니다. 개발자는 이를 열람하거나 자체 기록 서버에 저장하지 않습니다. 이용자가 직접 공유 링크를 만들거나 Head-Light 보관함·백업을 설정한 경우에만 선택한 정보가 Cloudflare KV, iCloud Drive, NAS 또는 지정한 파일 위치에 저장될 수 있습니다.

AI 기능

지원되는 기기에서는 Apple의 온디바이스 AI로 일부 정리 기능을 처리할 수 있으며, 이 경우 기록은 기기 밖으로 전송되지 않습니다.

클라우드 AI 기능을 사용하면 해당 기능에 필요한 글, 사진 및 관련 문맥이 암호화된 통신으로 Head-Light의 Cloudflare Workers 중계 서버를 거쳐 Anthropic API로 전송됩니다. 중계 서버는 요청 전달과 이용 한도 관리만 하며 전송된 본문이나 사진을 의도적으로 저장하지 않습니다.

이용 한도 관리를 위해 이름·이메일과 연결되지 않은 무작위 식별자와 추정 이용량을 사용합니다. 구독자의 월별 이용 기록은 최대 60일, 일회성 무료 체험 이용 기록은 최대 365일 후 자동 삭제됩니다.

앱은 클라우드 AI로 정보를 보내기 전에 별도 동의를 받습니다. 동의하지 않아도 글, 수첩, 일정, 도구, 컬렉션 및 저장한 기록을 계속 이용할 수 있습니다. 동의는 설정에서 언제든 철회할 수 있으며, 철회 후에는 클라우드 AI 전송이 중단됩니다.

개인정보 국외 이전

개인정보 보호법 제28조의8 제1항 제1호에 따라 아래 국외 이전에 대한 별도 동의를 받습니다.

이전 시기·방법이용자가 동의한 뒤 클라우드 AI 기능을 사용할 때마다 암호화된 HTTPS 통신으로 이전
이전 항목이용자가 해당 AI 기능에 사용한 글, 선택한 사진, 필요한 관련 문맥, 무작위 사용자 식별자, 구독 권한·추정 이용량, 요청 처리에 필요한 일반 통신 메타데이터
Cloudflare받는 자: Cloudflare, Inc.
국가: 미국 및 유럽경제지역을 포함한 Cloudflare 운영 지역
목적: 암호화 중계, 보안, 남용 방지, 이용 한도 관리
보유 기간: AI 본문·사진은 Head-Light가 중계 서버에 저장하지 않음. 구독 이용 기록은 최대 60일, 무료 체험 이용 기록은 최대 365일
연락처: dpo@cloudflare.com
Anthropic받는 자: Anthropic, PBC
국가: 미국에 저장되며 미국·유럽·아시아·오스트레일리아의 운영 지역에서 처리될 수 있음
목적: 이용자가 요청한 AI 응답 생성, 안전 및 부정 이용 방지
보유 기간: API 입력·출력은 원칙적으로 30일 이내 삭제. 안전 또는 법적 의무에 따른 예외가 있을 수 있음
연락처: Anthropic Privacy Center
동의 거부·철회동의를 거부하거나 설정에서 철회할 수 있습니다. 이 경우 클라우드 AI 기능은 이용할 수 없지만, 기기에 저장된 기록과 클라우드 AI가 필요하지 않은 기능은 유지됩니다.

앱 내 구입

앱 내 구입 제공, 권한 확인 및 복원을 위해 RevenueCat을 사용합니다. RevenueCat에는 무작위 익명 식별자, 구입 상품, 구입 이력 및 구독 상태가 전송됩니다. 이름, 이메일, 앱에 저장한 글·사진·녹음은 전송하지 않으며 결제는 Apple이 처리합니다.

권한 및 외부 서비스

마이크, 음성 인식, 카메라, 사진, 음악 보관함, 캘린더, 알림 및 위치(날씨)에 대한 접근은 해당 기능을 사용할 때 운영체제의 허가를 받은 뒤 이루어집니다. 링크·도서·음악의 제목과 이미지를 가져오거나 YouTube 공식 플레이어를 사용할 때에는 해당 사이트와 서비스가 일반적인 웹 요청 정보(IP 주소 등)를 처리할 수 있습니다.

“AI로 보내기”와 공유 버튼은 이용자가 직접 선택한 경우에만 내용을 복사하거나 외부 서비스로 보냅니다. 전송 후에는 이용자가 선택한 서비스의 개인정보 처리방침이 적용됩니다.

Threads 게시물 가져오기

이용자가 Threads 공식 인증 화면에서 허용하면 앱은 Threads API에서 이용자의 프로필 정보(사용자 ID, 사용자 이름, 표시 이름, 프로필 이미지)와 본인 게시물(본문, 게시 시각, 게시물 ID, 게시물 링크)을 가져옵니다. 가져온 정보와 액세스 토큰은 기기에 저장되며, 게시물은 이용자가 선택한 기능에 따라 수첩과 전용 폴더에 추가됩니다. Head-Light는 게시물, 프로필 정보 또는 액세스 토큰을 자체 서버에 저장하지 않습니다.

인증 코드는 액세스 토큰으로 교환하기 위한 경우에만 암호화된 통신으로 Head-Light의 Cloudflare Workers 중계 서버를 통과합니다. Threads App Secret은 중계 서버 안에서만 사용됩니다. 설정에서 언제든 연동을 일시 중지하거나 해제할 수 있습니다. 연동을 해제하면 기기의 액세스 토큰과 연결 계정 정보가 삭제됩니다. 이미 가져온 게시물은 일반 기록으로 남으며 앱 안에서 삭제할 수 있습니다.

X 게시물 가져오기

이용자가 X 공식 인증 화면에서 허용하면 앱은 X API에서 이용자의 프로필 정보(사용자 ID, 사용자 이름, 표시 이름, 프로필 이미지)와 본인 게시물(본문, 게시 시각, 게시물 ID, 게시물 링크)을 가져옵니다. 답글과 재게시물은 제외합니다. 가져온 정보와 액세스 토큰은 기기에 저장되며, 게시물은 이용자가 선택한 기능에 따라 수첩과 전용 폴더에 추가됩니다. Head-Light는 게시물, 프로필 정보 또는 액세스 토큰을 자체 서버에 저장하지 않습니다.

인증에는 OAuth 2.0 PKCE를 사용합니다. X가 인증 코드를 앱으로 직접 반환하며, 앱이 X와 직접 액세스 토큰으로 교환합니다. Head-Light 중계 서버는 공개 정보인 Client ID만 앱에 제공하며 인증 코드나 액세스 토큰을 받거나 저장하지 않습니다. 설정에서 언제든 연동을 일시 중지하거나 해제할 수 있습니다. 연동을 해제하면 기기의 액세스 토큰과 연결 계정 정보가 삭제됩니다. 이미 가져온 게시물은 일반 기록으로 남으며 앱 안에서 삭제할 수 있습니다.

삭제 및 문의

앱 안의 기록은 각 화면에서 삭제할 수 있습니다. 앱 삭제 시 기기 내 데이터도 삭제되지만, 별도로 만든 백업·외부 보관함·공유 링크의 데이터는 자동 삭제되지 않을 수 있습니다.

개인정보 문의, 동의 철회 지원 또는 서비스에 저장된 정보의 삭제 요청은 headlight.app.jp@gmail.com으로 연락해 주세요.

외부 서비스 개인정보 처리방침

サポートページへ戻るBack to support지원 페이지로 돌아가기利用規約Terms이용약관 ・ © 2026 Ani-Q