ShutterDNA
Home Privacy Terms JA
Privacy Policy

Privacy Policy

Established: July 4, 2026 / Last revised: July 11, 2026

Sunabalab Inc. (the “Company”) establishes this Privacy Policy (the “Policy”) concerning the handling of User information in the smartphone application “ShutterDNA” (the “App”) provided by the Company and the services related to the App (collectively, the “Service”).

The App is not intended to analyze people, faces, objects, scenery, food, text, or any other image content shown in photos. It does not perform face recognition, face detection, person classification, object recognition, or AI image analysis, and it does not collect, create, store, or share face data. Within the scope authorized by the User, the App uses EXIF Data and other metadata—including capture date and time, location data, camera, lens, focal length, ISO sensitivity, shutter speed, and aperture—to display shooting patterns, photography personality profiles, annual reports, EXIF quests, and similar features.

Article 1 (Scope)

  1. This Policy applies to the handling of User information in the App and Service.
  2. When Users access the App Store, Google Play, operating-system functions, social media, sharing functions, payment services, or other third-party services in connection with the Service, the terms of service, privacy policies, and other conditions established by those third parties may apply.
  3. This Policy does not apply to information handled by third-party services that are not controlled by the Company.

Article 2 (Core App Principles)

The Company places particular importance on the following principles in the App:

  1. The App does not analyze the image content of photos.
  2. The App does not perform face recognition, face detection, person classification, person identification, object recognition, or AI image analysis.
  3. The App does not collect, create, store, or share face data, facial feature data, or face templates.
  4. Under the current specifications, photo images, thumbnails, face data, and image content are not uploaded to Company servers.
  5. Under the current specifications, EXIF Data and Analysis Results are, in principle, processed and stored on the User's device.
  6. Access to the photo library is limited to the scope authorized by the User through the operating system.
  7. Even when location data is used, Share Cards are, in principle, designed not to display coordinates, precise addresses, place names, or similar data directly.
  8. When a User denies or limits photo access, the App provides demo data or limited functions where possible.

Article 3 (Information Obtained or Used)

The Service may obtain or use the following information.

1. EXIF Data and metadata in the photo library

For Photo Data within the scope authorized by the User, the App may read:

  • Photo or media identifiers;
  • File names;
  • Capture date and time;
  • Creation date and time;
  • Image size;
  • Image width and height;
  • Location data stored in a photo;
  • Camera manufacturer;
  • Camera model;
  • Lens information;
  • Focal length;
  • ISO sensitivity;
  • Shutter speed;
  • Aperture;
  • Orientation and rotation information; and
  • Other EXIF Data or metadata contained in a photo file.

The App does not analyze people, faces, objects, scenery, text, food, or any other image content shown in photos. It also does not perform face recognition, face detection, person classification, object recognition, or AI image analysis.

2. Analysis Data

The App may generate the following Analysis Data from EXIF Data and other metadata on the User's device:

  • Shooting-time patterns;
  • Day-of-week, monthly, and seasonal shooting patterns;
  • Camera and lens usage patterns;
  • Focal-length patterns;
  • Patterns in shooting areas based on location data;
  • The Memory Gravity Map;
  • Photography personality profiles;
  • Annual reports;
  • EXIF quests;
  • Profile text for Share Cards; and
  • Other statistics needed to provide App features.

3. Information entered or submitted by Users

When a User contacts the Company, the Company may obtain:

  • Email address;
  • Name or nickname;
  • Inquiry details;
  • Device information, operating-system information, and App version;
  • Details of a defect or malfunction; and
  • Information the User voluntarily attaches or includes.

If a User voluntarily sends photos, screenshots, Profile Results, location data, or other information when making an inquiry, the Company may review that information to respond to the inquiry.

4. Usage and diagnostic information

To improve quality and understand usage, the App uses an analytics service provided by Google LLC and obtains the following information from App startup:

  • Usage events such as App launches, screen views, and button actions;
  • Operational information such as photo-access permission status, processing success or failure, and processing-time ranges;
  • Device and App information such as App version, device type, and operating-system version;
  • App instance IDs and session statistics generated by the analytics service; and
  • Approximate country or region inferred from network information or similar data.

Photo images, thumbnails, file names, asset IDs, coordinates or addresses recorded in photos, raw capture-time or EXIF values, specific profile-type names, and shared content are not sent to the analytics service. The App does not set its own User ID and does not use this information to collect advertising IDs, deliver or personalize ads, or track Users across third-party apps or websites.

5. Purchase information

If paid features, in-app purchases, subscriptions, or similar functions are introduced in the future, the Company may verify purchase status, purchase history, subscription status, receipt information, payment identifiers, and similar information.

Payments themselves are processed through the App Store, Google Play, or another payment provider. Except to the extent permitted by law or payment-provider specifications, the Company does not directly obtain payment information such as credit-card numbers.

6. Demo data

The App may use fictional or sample demo data when photo access has not been granted, when few photos are available, when sufficient EXIF Data cannot be obtained, or to explain App features.

Demo data does not represent the User's own photos, location data, activity history, or shooting patterns.

Face Data

ShutterDNA does not collect, process, store, analyze, or share face data.

The App does not perform face detection, face recognition, biometric identification, facial mapping, facial feature extraction, or image content analysis. The App does not identify whether a person or face appears in a photo.

The App does not obtain, generate, store, analyze, or share face data, facial feature data, face templates, information indicating the presence of a face or person, face-recognition information, face-detection results, or person-identification information.

The App only uses photo metadata available within the scope authorized by the User, such as capture date and time, location metadata, camera model, lens information, focal length, ISO sensitivity, shutter speed, aperture, and image dimensions.

Photos, thumbnails, face data, and image content are not uploaded to Company servers or shared with third parties. Metadata-based analysis is processed on the User's device.

Because ShutterDNA does not collect or generate face data, there is no face-data retention period. Local metadata-based Analysis Data may be stored on the User's device for App functionality, and Users can delete local Analysis Data from the App settings.

Article 4 (Information Not Obtained)

Under the current specifications, the Company does not obtain or analyze the following through the App:

  1. Photo image content;
  2. Facial information of people shown in photos;
  3. Face data, facial feature data, or face templates;
  4. Information indicating the presence of a face or person;
  5. Face-recognition information;
  6. Face-detection results;
  7. Person-identification information;
  8. Object-recognition results;
  9. Text-recognition results from photos;
  10. Photo images themselves;
  11. Photo thumbnails;
  12. Continuously tracked current-location data;
  13. Call history;
  14. Contacts;
  15. Microphone audio;
  16. Camera video;
  17. Health information; or
  18. Advertising tracking IDs.

If a User voluntarily sends the Company photos, screenshots, Profile Results, or other information when making an inquiry, the Company may review that information within the scope necessary to respond.

Article 5 (Purposes of Use)

The Company uses information it obtains or uses for the purposes described below.

1. Providing the Service

  • Reading EXIF Data and metadata;
  • Normalizing photo metadata;
  • Analyzing shooting patterns;
  • Generating photography personality profiles;
  • Generating the Memory Gravity Map;
  • Generating annual reports;
  • Generating EXIF quests;
  • Generating Share Cards;
  • Saving settings; and
  • Analyzing the range of photos selected by the User.

2. Improving the Service

  • Improving features;
  • Improving UI and UX;
  • Investigating defects;
  • Improving performance;
  • Improving profile logic; and
  • Improving demo data and sample displays.

3. User support

  • Responding to inquiries;
  • Verifying identity;
  • Checking the circumstances of a defect;
  • Checking usage circumstances; and
  • Replying and communicating.

4. Security and prevention of misuse

  • Detecting misuse;
  • Detecting failures;
  • Responding to security issues;
  • Responding to violations of the Terms of Service; and
  • Responding to requests under laws or from public authorities.

5. Providing paid features

If paid features are introduced in the future, the Company may use purchase information to:

  • Verify purchase status;
  • Determine access to paid features;
  • Verify subscription status;
  • Handle refunds, cancellations, and inquiries; and
  • Prevent fraudulent purchases.

Article 6 (Photo-Library Access)

  1. The App uses the permission functions provided by the operating system to access the photo library.
  2. Users may allow, deny, or limit photo-library access.
  3. If a User selects limited photo access on iOS, the App analyzes only the photos selected by the User.
  4. If a User uses partial access or a photo-selection function on Android, the App analyzes only the photos authorized by the User.
  5. If photo access is not granted, some Service features may be unavailable.
  6. Even without photo access, the App offers an experience using demo data where possible.
  7. Users may change the scope of photo access at any time through operating-system settings or settings within the App.

Article 7 (Handling of Location Data)

  1. The App may use location data stored in photos to analyze shooting patterns, the Memory Gravity Map, return-visit patterns, shooting areas, and similar features.
  2. The App does not use location data for continuous tracking of a User's current location.
  3. The App is not intended to convert location data into precise addresses.
  4. As a general design principle, Share Cards do not directly display latitude, longitude, precise addresses, place names, station names, or other information that could identify a User's specific location.
  5. When location data is unavailable, the App may still provide analysis based on capture date and time, camera, lens, focal length, or other metadata.
  6. Features such as location blurring, exclusion of specified areas, or a no-location mode may be offered in the future.

Article 8 (On-Device Processing and Local Storage)

  1. Under the current specifications, the App generally processes and stores EXIF Data, Analysis Data, Profile Results, reports, quest completion status, settings, and similar information on the User's device.
  2. Under the current specifications, photo images themselves are not uploaded to Company servers.
  3. Under the current specifications, the App does not offer User accounts, cloud synchronization, or matching with other Users.
  4. Information stored on a device may be deleted by using the App's deletion function, changing operating-system settings, or deleting the App.
  5. Data stored on a device may be lost due to device failure or loss, operating-system malfunction, App deletion, insufficient storage, or other reasons.
  6. The Company cannot inspect, restore, disclose, correct, or delete data that is stored only on a device and has not been obtained by the Company.

Article 9 (Share Cards and External Sharing)

  1. Users may share Share Cards, Profile Results, reports, text, and similar content generated in the App to social media, messaging apps, email, and other external services.
  2. As a general rule, Share Cards are designed not to include coordinates, precise addresses, place names, file names, individual photo images, thumbnails, face data, facial information, or object-recognition results.
  3. If a User adds information through a screenshot, annotation, edit, caption on an external service, or other means, the User is responsible for managing that added information.
  4. Information shared to an external service is governed by that service's terms of service and privacy policy.
  5. Users must review what they share to avoid infringing a third party's privacy, portrait rights, copyright, reputation, credit, or other rights or interests.

Article 10 (Disclosure to Third Parties)

The Company does not provide a User's personal information to a third party except:

  1. With the User's consent;
  2. As required by law;
  3. When necessary to protect a person's life, body, or property and obtaining the User's consent is difficult;
  4. When particularly necessary to improve public health or promote the sound upbringing of children and obtaining the User's consent is difficult;
  5. When cooperation is necessary for a national agency, local government, or its contractor to perform duties prescribed by law, and obtaining the User's consent could impede performance of those duties;
  6. When provided to a contractor within the scope necessary to achieve a purpose of use; or
  7. When provided in connection with a business transfer, merger, company split, or other business succession.

Article 11 (Contractors)

The Company may entrust the handling of User information to third parties within the scope necessary for provision and maintenance of the Service, inquiry support, quality improvement, failure investigation, payment verification, email transmission, data storage, or other operations.

In such cases, the Company provides necessary and appropriate supervision of its contractors.

Under the current specifications, the Company does not expect to send photo images, thumbnails, face data, or image content to contractors.

Article 12 (External Transmission and SDKs)

The App uses the following external services or SDKs:

  • Analytics service (provider: Google LLC; purpose: usage analysis and quality improvement; information transmitted: usage, device, and similar information described in Article 3, Section 4); and
  • Firebase Remote Config (provider: Google LLC; purpose: delivering settings needed to determine whether a mandatory update is required).

Information sent to these services is handled under Google LLC's privacy policy and service terms.

The App does not currently perform advertising tracking, third-party advertising, advertising personalization, or tracking across third-party apps or websites.

Article 13 (Security Measures)

The Company endeavors to implement the following security measures to prevent leakage, loss, damage, unauthorized access, or misuse of User information:

  1. Minimizing the information obtained;
  2. Designing the App not to upload photo images, thumbnails, face data, or image content to servers;
  3. Using on-device processing as the general rule;
  4. Not storing unnecessary data;
  5. Excluding precise location data from Share Cards;
  6. Explaining purposes of use before requesting permissions;
  7. Providing a data-deletion function;
  8. Appropriately implementing access controls, permission management, log management, and similar safeguards; and
  9. If server-side processing is introduced in the future, encrypting communications and implementing other appropriate protective measures.

Article 14 (Retention Periods)

  1. EXIF Data, Analysis Data, Profile Results, reports, quest completion status, settings, and similar information stored on a device may be retained until the User deletes it or deletes the App.
  2. Because the App does not obtain or generate face data, there is no face-data retention period.
  3. Information relating to inquiries is retained for as long as necessary to respond, prevent disputes, improve the Service, and comply with laws.
  4. Usage information from the analytics service is retained in accordance with the retention period configured by the Company in the service's management console and other Google LLC service terms.
  5. After a retention period expires, or information is no longer needed for a purpose of use, the information is deleted or anonymized through an appropriate method unless retention is required by law.

Article 15 (User Controls and Deletion)

Users can manage their information by:

  1. Changing or revoking photo-library permission in operating-system settings;
  2. Limiting which photos are analyzed through limited photo access on iOS or partial access on Android;
  3. Deleting stored data from settings within the App;
  4. Deleting the App from the device;
  5. Reviewing the content of a Share Card or shared text before sharing; and
  6. Contacting the inquiry desk to discuss suspension of use or deletion of information held by the Company, including analytics information.

The Company cannot inspect, disclose, correct, or delete information that is stored only on a device and has not been obtained by the Company.

Article 16 (Requests for Disclosure, Correction, Suspension of Use, Deletion, and Similar Actions)

In accordance with applicable laws, Users may request disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or similar action regarding their own personal information held by the Company.

To make a request, please contact the inquiry desk at the end of this Policy.

After verifying the requester's identity, the Company will respond within a reasonable period in accordance with applicable laws.

The Company cannot disclose, correct, or delete the following information because it does not hold that information:

  • Photo Data stored only on the User's device;
  • EXIF Data stored only on the User's device;
  • Analysis Data stored only on the User's device;
  • Content the User has shared to external social media or similar services; and
  • Information directly managed by a third party such as the App Store or Google Play.

Article 17 (Information Relating to Minors)

  1. A minor must obtain consent from a parent, guardian, or other legal representative before using the Service.
  2. The Service is not directed primarily at children.
  3. When sharing a minor's photos, location data, life patterns, shooting patterns, or similar information, Users must give due consideration to the privacy of the minor and their parent or guardian.
  4. The Company handles minors' personal information appropriately in accordance with applicable laws.

Article 18 (Provision to Third Parties in Foreign Countries)

Under the current specifications, the App is based on on-device processing as a general rule and does not upload photo images themselves to Company servers.

If external services for crash analysis, analytics, inquiry management, payment management, settings delivery, cloud storage, or similar functions are used in the future, information may be sent to or stored by providers in foreign countries.

In that event, the Company will provide required information, obtain consent, implement contractual safeguards, and take other measures in accordance with applicable laws.

Article 19 (Changes to This Privacy Policy)

The Company may amend this Policy as necessary due to changes in laws, Service content, SDKs or external services used, information-handling practices, or other circumstances.

When amending this Policy, the Company will announce the amended content and its effective date in the App, on the Company's website, in the App Store or Google Play, or through other appropriate means.

For material changes, the Company will obtain User consent to the extent required by law.

Article 20 (Contact)

For inquiries about this Policy, the handling of User information in the Service, requests for disclosure, correction, deletion, suspension of use, or other privacy matters, please contact:

Operator: Sunabalab Inc.
Service: ShutterDNA
Support email: support@sunabalab.com

© 2026 ShutterDNA
Home Terms of Service 日本語