OwlShot Privacy Policy
misyobun, trading as pawapps (the “Operator,” “we,” “us,” or “our”), describes in this Privacy Policy how information is handled through OwlShot, its extensions, widgets, related APIs, and website (collectively, the “Service”).
1. Information we collect or process
1.1 Saved library information
The following information that you save or generate is processed on your device and in your private Apple CloudKit database:
- URL, title, host name, save date, and read/unread status;
- page description, favicon, Open Graph image, and public metadata;
- category, Stack, classification state, and classification rationale;
- notes you enter;
- detected language, translation language, translated title and description, and processing state; and
- AI summary, summary language and source, cited URLs, search-use state, and error information.
This information may reveal or permit inferences about your interests and reading habits. CloudKit uses your private database. By default, its records are not visible to the Operator through the Apple Developer portal.
1.2 Settings
Translation and summarization preferences, display preferences, advertising consent state, and a cached Premium status may be processed on your device or by the relevant SDK.
1.3 Purchases and subscriptions
Apple and RevenueCat process a randomly generated RevenueCat anonymous App User ID, product identifiers, purchase, renewal, cancellation, refund and billing-issue information, receipts, subscription status and expiry, device type, and operating system. We do not receive your Apple Account password or full payment-card number.
1.4 App Attest and security information
To verify genuine app requests and prevent abuse and replay attacks, we process:
- App Attest key ID, public key, assertion counter, environment, bundle version, and validation category;
- registration and last-use times, single-use challenges, and request identifiers;
- IP address for challenge and registration rate limiting and Cloudflare network processing; and
- error codes, HTTP status, processing time, Gemini token usage, and similar operational data.
The device’s private key remains hardware-protected and is not sent to us.
1.5 Information sent to Cloud AI
When you choose Cloud AI and request a summary, the following is sent to our Cloudflare Worker, RevenueCat, and Google Gemini API as applicable:
- the publicly accessible URL to summarize;
- output language and requested summary length;
- RevenueCat anonymous App User ID; and
- App Attest proof, challenge, and a random request identifier.
Gemini URL Context retrieves the URL content. If retrieval fails, Google Search Grounding may process a search query, search results, citations, and generated output. Our Worker does not persist the URL, page body, note, or summary in a Durable Object, and we do not intentionally include that content in application logs.
Google’s treatment depends on the service tier used by the Operator. For Unpaid Services, Google may use submitted content and generated responses to improve products and machine-learning technology, and human reviewers may process them. For Paid Services, Google states it does not use prompts and responses to improve its products, although limited retention may occur for abuse monitoring. For Google Search Grounding, Google stores prompts, contextual information, and output for 30 days. Do not submit URLs containing credentials, personal data, secrets, or confidential information to Cloud AI.
1.6 On-device processing and direct website requests
The model-processing step for on-device translation, classification, and AI summarization does not send the processed page text to our server or Gemini. Your device nevertheless communicates directly with the selected website to retrieve titles, text, Open Graph images, or other metadata. That website may receive your IP address, User-Agent, access time, and similar request information under its own privacy policy.
1.7 Advertising information
For Free users, Google Mobile Ads SDK and User Messaging Platform may process consent state, IP address, approximate location, device or advertising identifiers where available and permitted, ads viewed, advertising and app interactions, crash logs, performance, and diagnostic information. Where required, we provide a consent message and advertising privacy options.
1.8 Support communications
If you contact us, we process your name or display name, email address, message, attachments, and support history.
2. Purposes of processing
We process information to:
- provide URL saving, search, synchronization, translation, summarization, ad removal, and other features;
- process and restore Premium purchases and verify entitlement;
- prevent abuse, tampering, replay attacks, excessive usage, and security incidents;
- diagnose failures, improve quality and performance, and respond to support requests;
- deliver and measure advertising and manage consent;
- comply with law, court or government requests, and third-party service terms; and
- enforce our Terms and protect users, the Operator, and third parties.
3. Legal bases
Where applicable, we rely on:
- Performance of a contract: providing the Service and Premium features;
- Consent: personalized advertising, advertising identifiers, and other processing requiring consent;
- Legitimate interests: security, fraud prevention, troubleshooting, and service improvement; and
- Legal obligations: accounting, tax, consumer protection, and legal claims.
You may withdraw consent prospectively. Withdrawal does not affect processing lawfully performed before withdrawal.
4. Service providers and recipients
| Recipient | Main purpose and information |
|---|---|
| Apple (App Store, StoreKit, CloudKit, App Attest, Translation, Foundation Models) | Distribution, payment, purchase restoration, private synchronization, device authentication, and on-device processing |
| Cloudflare | Worker/API hosting, transmission protection, rate limiting, storage of public key, counter and last-use time, and operational logs |
| Google (Gemini API, URL Context, Google Search Grounding) | Public URL retrieval, AI summarization, search supplementation, and citations |
| Google (AdMob and UMP) | Advertising, consent management, fraud prevention, and measurement |
| RevenueCat | Anonymous user ID, purchase history, receipt, subscription state, and entitlement management |
| Websites selected by you | Retrieval of metadata, text, Open Graph images, and other page resources |
We may also disclose information where required by law, in a business transfer, to professional advisers, to protect rights, or in response to a lawful public-authority request. We limit processors to information reasonably necessary for their role and seek contractual or other reasonable safeguards.
5. International processing
Apple, Cloudflare, Google, RevenueCat, and other providers may process information in countries outside Japan or your residence. Where required, we use or require appropriate mechanisms such as contractual protections, standard contractual clauses, or adequacy decisions. Consult each provider’s policy for information about processing locations and protections.
6. Retention
| Information | General retention period |
|---|---|
| Saved library on your device | Until you delete it or app data is erased |
| Private CloudKit data | Until deleted through the app or iCloud management; uninstalling the app alone may not delete it |
| App Attest challenge | About five minutes after issuance or until used |
| App Attest public-key record | 365 days after last use; an operational setting may change this within a range of 30–3,650 days |
| URL, page body, and summary result | Not persistently stored by our Worker |
| Worker application logs | Generally no longer than 30 days and designed not to contain URLs, notes, page bodies, or summaries; longer where needed for an incident or legal obligation |
| Google Search Grounding information | 30 days under Google’s terms |
| Apple and RevenueCat purchase information | As needed for subscription management, accounting, tax, refunds, fraud prevention, and legal obligations |
| Support communications | Generally no longer than three years after resolution; longer where needed for a dispute or legal obligation |
Information independently retained by a third party is subject to that party’s retention policy.
7. Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, and withdraw consent.
- You can edit or delete saved URLs, notes, categories, and Stacks in the app.
- You can manage iCloud data through the app and Apple’s iCloud controls.
- Where available, you can revise advertising consent under “Advertising Privacy Settings.”
- You can cancel a subscription in Apple Account subscription settings. Data deletion does not cancel a subscription.
- Premium disables advertising within the Service.
Submit a privacy request using the contact information below. We may request reasonable identity verification and clarification. Because we generally cannot view or identify your private CloudKit records, we may direct you to device or Apple controls for those records.
Residents of jurisdictions such as the EEA, United Kingdom, Switzerland, California, or other U.S. states may have additional rights, including a right to complain to a regulator or opt out of certain sharing or targeted advertising. We will honor applicable rights after verifying the request as legally permitted.
8. Sale, sharing, and targeted advertising
We do not directly sell personal information for money. Personalized advertising or advertising measurement through AdMob may, however, constitute “sharing,” “targeted advertising,” or a similar regulated activity in some jurisdictions. Where applicable, you can exercise available choices through UMP, iOS privacy settings, or by using Premium. We do not discriminate against you for exercising a privacy right, except as permitted where a choice necessarily affects a feature.
9. Security
We use reasonable safeguards such as TLS, Apple App Attest, hardware-protected private keys, Keychain, a private CloudKit database, access controls, rate limits, secret management, and data minimization. No system or transmission method is completely secure.
10. Children
The Service is not directed to persons under 18, and we do not intend to knowingly collect their personal information. If we learn that a person under 18 has used the Service, we may restrict access and delete information to the extent permitted by law.
11. Changes to this Policy
We may revise this Policy to reflect changes to features, law, or third-party services. Material changes will be communicated through the app, website, or another reasonable method. Please review the “Last updated” date above.
12. Third-party policies
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
- Google Privacy Policy: https://policies.google.com/privacy
- Google Advertising Policies and Technologies: https://policies.google.com/technologies/ads
- Gemini API Additional Terms: https://ai.google.dev/gemini-api/terms
- RevenueCat Privacy Policy: https://www.revenuecat.com/privacy
13. Language
The Japanese version is the governing version. This English translation is provided for convenience. If there is a conflict or ambiguity, the Japanese version prevails to the extent permitted by law.