Atoyomu Privacy Policy
The short version
- Your library stays on each device. Optional Mac requests and results use your own iCloud private database; libraries are not synced. We cannot read them.
- Summaries are generated entirely on your device with Apple Intelligence or Gemini Nano. Page text is never sent to us or to any cloud AI service.
- The app shows no ads and does not track you across apps or websites.
- Optional diagnostic reports have region-dependent defaults: they stay off until you turn them on in the EU/EEA, the United Kingdom and Switzerland, and are on by default elsewhere. They never contain page URLs, titles or text, and you can turn them off at any time in Settings.
- Who we are
- Data you save in the app
- How the app processes web pages
- Optional crash, usage and performance reports
- How we use the reports
- How long data is kept
- Who we share data with
- International transfers
- Your choices and rights
- Children
- Security
- Changes to this policy
- Contact
1. Who we are
Atoyomu ("the app") is developed and operated by Minato Digital ("we", "us"). This policy explains what information the app handles on iPhone, iPad, Mac and Android, and the choices you have. It applies to the app and to this website.
2. Data you save in the app
When you share a web page to Atoyomu, the app creates a bookmark that may contain:
- the page URL, title, description, site name and cover image URL;
- the summary, category and tags generated on your device, and any category you assign by hand;
- read/unread state, processing state, and the dates the bookmark was saved, processed and read.
- passages you choose to save, their source URLs, comments you write, and the dates these notes were saved and edited.
Where it lives. Bookmarks, saved summaries, notes, categories, tags, read state and activity are stored in a local library on each device and are not synced between devices. We have no backend that can read them. An update preserves data already on the device and does not delete old iCloud library data or retrieve articles that have not reached that device. Use export and import to move articles between devices.
Optional Mac companion. Each iPhone or iPad separately registers a Mac using the same Apple Account. Through your iCloud private database, it sends the source device’s app-generated ID and display name, language, category candidates, and the URL, captured page information or text needed to process the request (up to 8,000 characters of article text). The Mac processes the request locally and returns the result only to the requesting device. Automatic requests and disconnect are set per device. This is not library sync. Apple protects this data under your Apple Account and its privacy policy; we cannot access it. Local saving and reading remain available without iCloud.
3. How the app processes web pages
After you save a page, the main app downloads that page directly from your device to the website, exactly as a browser would. The website therefore sees your IP address and standard request headers; we do not act as a proxy and do not see the request. The Share Extension may also download the page's cover image from the same website.
The app then extracts the readable article text on your device using an open-source readability engine, keeps at most 8,000 characters of it temporarily, and passes that excerpt to the on-device model:
- iPhone and iPad: Apple Intelligence (Foundation Models framework). Optional Mac requests use Apple Intelligence or the additional model selected on your Mac; generation happens on the Mac.
- Android: Gemini Nano through the ML Kit GenAI APIs. Processing happens on the device.
Once a summary is produced, or if the page has too little readable text, the temporary excerpt is discarded. Page text, HTML, titles and URLs are never sent to us, to Google's or Apple's cloud AI services, or to an external AI service for summarization. Devices without on-device AI keep the bookmark in a "pending" state unless you request processing on your registered Mac.
Saved quotations and notes. Passages you choose to save on iPhone or iPad and comments you add are separate from the temporarily retained article text. They remain after summarization until you delete the note or its article. They are stored in the same local database on that device and are included in library search and backups. Quotations and comments are not included in AI summarization input, diagnostic logs, or crash, usage and performance reports.
In-app browser. On iPhone and iPad, pages are displayed using WebKit (WKWebView), and the app reads your selected passage when you tap “Save as note.” Android uses Chrome Custom Tabs or your default browser. The website's own cookies and privacy practices apply to that visit. The iPhone and iPad in-app browser stores cookies and website data on your device; you can clear them in Settings without deleting saved articles or notes.
Local diagnostics log. The app keeps a small processing log on your device (which phase succeeded or failed and a technical error category, for up to 200 bookmarks). It does not contain page text or HTML. You can view, copy or export it from Settings; nothing in it leaves the device unless you share it yourself.
4. Optional crash, usage and performance reports
On iPhone, iPad and Mac, the app sends anonymous crash and usage reports to help us fix bugs and understand which parts of the app are used. This is on by default, except for users in the EU/EEA, the United Kingdom and Switzerland, where it is off by default and nothing is sent until you turn it on. In every region you can change it at any time in Settings › Send diagnostics. On iPhone and iPad, performance reports follow the same setting. Turning it off stops new crash, usage and performance collection. The Android app does not include this feature.
Reports are processed by Firebase Crashlytics, Firebase Analytics and, on iPhone and iPad, Firebase Performance Monitoring, services of Google LLC. When enabled, the following is sent:
| Category | What is included |
|---|---|
| Crash reports | Stack trace, the app version and build, OS version, device model, memory and disk state at the time of the crash, and the time of the crash. |
| Usage events | Which tab you switched to; that a bookmark detail was opened and from which screen (for example "read later" or "search results"), whether it was already read, and its processing state; how the first-run walkthrough was completed; and when you turned reports on or off. |
| Processing failure reports | A normalized, fixed-vocabulary description of why fetching, extraction or summarization failed (an error category, size buckets, a set of feature flags, and a 64-character fingerprint that groups identical failures). |
| Performance reports (iPhone and iPad) | App launch time, time in the foreground and background, and durations for article fetching, text extraction and on-device summarization. Standard SDK information also includes timestamps, device/OS/app information and performance information such as memory and CPU usage. App-defined trace names are fixed; automatic network and screen instrumentation is disabled. |
| SDK metadata | Random app-instance, installation and session identifiers generated by the Firebase SDK, app language and region, platform (iOS or macOS), and the approximate country derived by Google from the IP address of the request. We do not store IP addresses. |
The following are never included in any report: page URLs, domains, titles, page text, summaries, category names, tags, search queries, bookmark identifiers, your name, e-mail address, Apple Account or Google Account, contacts, precise location, or the advertising identifier. The app does not request App Tracking Transparency permission and does not use the IDFA. Reports are not linked to your identity, and we do not attempt to identify you from them.
5. How we use the reports
We use crash, usage and performance reports only to diagnose crashes, find and prioritize processing failures, understand screen usage, and improve processing speed and stability. We may copy the normalized failure reports into our own analytics environment on Google Cloud (BigQuery) and analyze them with automated tools, including Google's Gemini models running in Google Cloud. Those tools only ever see the normalized fields listed above; the excluded fields are never present in the reports to begin with. We do not use the reports for advertising, profiling or any automated decision that affects you.
6. How long data is kept
- Bookmarks and saved summaries: on each device until you delete them. Old iCloud library data is kept separately until you remove it (see section 9).
- Local diagnostics log: on your device only; oldest entries are dropped automatically.
- Crash reports: kept by Firebase Crashlytics for 90 days.
- Performance reports: Firebase Performance Monitoring keeps IP-associated events for 30 days and installation-associated and de-identified performance data for 60 days before starting removal from live and backup systems.
- Usage events: kept by Firebase Analytics for up to 14 months.
- Exported failure analysis dataset: up to 12 months in our Google Cloud environment, after which partitions expire automatically.
- Mac requests and results: stored in your iCloud private database for processing and return. Unfinished request inputs expire after seven days; completed results and content-free completion/cancellation records may remain. Remove retained iCloud data separately as described in section 9.
7. Who we share data with
We do not sell personal information and do not share it for advertising. The only third parties that handle data on our behalf are:
- Apple Inc. – iCloud/CloudKit delivery and storage of your optional Mac requests and results, and retained old library data, under your Apple Account. Apple acts as your service provider, not ours.
- Google LLC – Firebase Crashlytics, Firebase Analytics, Firebase Performance Monitoring and Google Cloud, for the optional reports described in section 4, under Google's data processing terms.
We may also disclose information if required by law or to protect the rights, safety or property of users, the public or ourselves, and in connection with a merger, acquisition or sale of assets, in which case this policy will continue to apply to the transferred data.
8. International transfers
We are based in Japan. Google may process the optional reports on servers in the United States and other countries. Where required, transfers rely on the safeguards in Google's data processing terms, including standard contractual clauses, and on the fact that the reports contain no directly identifying information.
9. Your choices and rights
- Turn reports off: Settings › Send diagnostics. Reports already sent cannot be recalled, but no further data is collected.
- Delete your bookmarks: delete individual bookmarks in the app, or delete the app to remove its local data. To remove old library data and companion data retained in iCloud, open the Settings app on your iPhone or iPad, tap your name › iCloud › Manage Account Storage (or See All) › Atoyomu › Delete Data. On Android, clear the app's storage or uninstall it.
- Access, correction, deletion, portability and objection: depending on where you live (including the EU/EEA, the United Kingdom, Switzerland, Brazil, California and other U.S. states, and Japan), you may have the right to request access to, correction or deletion of personal information we hold, to receive a copy, to object to or restrict processing, and to withdraw consent. You also have the right to lodge a complaint with your data protection authority.
Because your libraries are held on your devices and optional companion data and old library data are held in your own iCloud account, and because crash, usage and performance reports are not linked to your identity, we are generally unable to locate data belonging to a specific person. If you contact us with a request, we will explain what we can and cannot do and act on it within the time required by applicable law. We will not discriminate against you for exercising your rights.
Legal bases (EU/UK). We process bookmark data on your device to provide the app (performance of a contract). For users in the EU/EEA and the United Kingdom, crash, usage and performance reports are off by default and are processed only on the basis of your consent, given by turning them on in Settings; you may withdraw that consent at any time in the same place. We process data to comply with legal obligations where required.
California. We do not sell or share personal information as defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information.
10. Children
Atoyomu is not directed to children under 13, or under the higher minimum age that applies in your country. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it.
11. Security
Local libraries are protected by your device's operating system security; companion data in iCloud is protected by Apple's encryption. All network connections made by the app use HTTPS. The app only downloads pages from public web addresses and refuses private or local network addresses. Optional reports are limited to a fixed vocabulary that excludes free-form text, which is verified automatically before each release.
12. Changes to this policy
We may update this policy when the app changes. The effective date at the top shows when it was last revised. If a change materially affects how your information is used, we will notify you in the app or on this website before it takes effect.
13. Contact
Questions and requests about this policy can be sent to Minato Digital at support@atoyomu.com.
This policy is provided in English and Japanese. If the two versions differ, the Japanese version prevails.