picmi
picmi Privacy Policy
This is a reference translation. The Japanese version is authoritative; if any discrepancy exists, the Japanese version prevails.
Last updated: July 2, 2026
VAULT LLC (合同会社VAULT; "we") establishes this Privacy Policy ("Policy") regarding the handling of users' personal information and data in "picmi" ("the Service").
1. Business operator
- Operator: VAULT LLC (合同会社VAULT)
- Representative: Representative Member, Takumi Kawamori
- Address: 〒153-0064 Konotora Bldg. 7F, 1-1-14 Shimo-Meguro, Meguro-ku, Tokyo, Japan
2. Information we collect
- Account identifier / display name / icon: an identifier for providing the Service, and the display name and icon image you set.
- Sign-in info: if you sign in with Apple or Google, we collect an authentication identifier, email address, and name (if provided). With Apple's Hide My Email, we receive the relay address Apple provides.
- Photos, posted content, and metadata: photos you shoot/import, doodles, and accompanying information such as creation timestamps.
- Location (optional): if you permit it, we obtain location to add a current-location stamp (shooting place) to a photo.
- Device info: device type, OS version, app version, device identifier.
- Usage: operation logs, feature usage history, crash/defect info.
- Push notification token: an identifier for sending notifications (if permitted).
- Billing info: purchase/subscription status. Payment information such as card numbers is processed by payment providers (Apple, etc.) and not held by us.
3. Purposes of use
- To provide the photo creation, saving, and sharing features. 2. To provide collaborative album editing and real-time sync. 3. To provide the AI doodle feature. 4. To send push notifications. 5. To process billing/payments. 6. To investigate defects, provide support, and respond to inquiries. 7. To improve quality and analyze usage. 8. To prevent misuse and respond to Terms violations.
4. Handling of photos and content
Photos and doodles you upload are in principle stored so that only members of the relevant album can access them (via row-level access control and signed URLs). On the free tier, original source photos of an album with no activity for a certain period after the last edit (currently 45 days) may be deleted (completed/exported images are retained).
5. Handling of images in AI doodles
When you use the AI doodle feature, the target photos are sent to external generative-AI services (Google Gemini API, and OpenAI API as a fallback if generation fails) for image generation. They are used only to generate output and used under a setting that does not use them for model training. API keys are managed server-side (Edge Function) and never exposed to the client.
6. About location
Location is used only to add a current-location stamp to a photo when you permit it. You can change the location permission anytime in device settings.
7. Third-party provision / outsourcing
We outsource data processing to the following providers within the scope necessary to provide the Service. Some place servers overseas.
- Supabase — account authentication / storage of photos and data
- Apple (Sign in with Apple) — sign-in authentication
- Google (Google Sign-In) — sign-in authentication
- Google (Gemini API) — image generation for AI doodles (target images are sent; used only to generate output, under a setting that does not use them for training)
- OpenAI (OpenAI API) — fallback for AI doodle image generation (target images are sent; used only to generate output, under a setting that does not use them for training)
- RevenueCat — billing/subscription management
- Expo (Apple APNs / Google FCM) — sending push notifications
Other than the above, we do not provide personal data to third parties without prior consent, except as required by law or to protect a person's life, body, or property. These providers are required, under our agreements or their data-processing terms, to handle the data only for the outsourced purposes and to apply protection equivalent to or exceeding our own.
8. Retention / deletion
- We retain data for the period necessary to achieve the purposes. 2. When you delete your account, related data including photos and doodles is cascade-deleted from servers. Information legally required to be retained, or data in backups, may remain for a certain period. In shared albums with other members, doodles added by other members may remain.
9. Minors' personal information
We do not intentionally collect personal information from those under 13. We handle the information of users under 18 with particular care, limited to the minimum necessary.
10. Security measures
We take necessary and appropriate measures to prevent leakage, loss, or damage of personal data and to otherwise manage it safely.
11. Overseas privacy laws
As the Service is intended for Japan, it does not comply with overseas privacy laws (GDPR, CCPA, etc.).
12. Disclosure / correction / suspension requests
You may request disclosure, correction, suspension of use, or deletion of your personal data under applicable law. Requests are accepted via the "Contact" desk.
13. Changes to this Policy
We may change this Policy in response to changes in law or the Service. Material changes are announced in the Service.
14. Contact
Questions/requests about this Policy: picmi@vault-tec.jp
VAULT LLC