PRIVACY
Privacy Policy
Effective: 19 July 2026 / Last updated: 25 August 2026
This policy explains how information is handled by the MichiLoop iPhone app and official website.
In this policy, the “Provider” means the person or entity displayed as the seller on MichiLoop’s App Store product page. Contact: info@tkgshoyu.jp.
1. Information stored by the app
MichiLoop stores the profile, vehicles, trip plans, journal entries, locations, photos, videos, voice notes, travelled routes, distances, per-journey budgets, trip expenses (amount, currency, date and time, category, merchant, memo, purchase items, fuel details, and a confirmed merchant and location), and receipt images the user chooses to keep. A journal entry may include weather and attribution returned by Apple Weather for its recorded time and place.
This information is stored on the user’s device in SQLite and Application Support. When iCloud is available, it is synced to the user’s private MichiLoop CloudKit database. Per-journey budgets, trip expenses, and receipt images remain on this device until the staged rollout of a compatible app version is complete. Journal data and media are not stored on a server operated by the Provider.
When the user explicitly selects walking as the travel mode for a recorded segment, MichiLoop may obtain step count, distance, pace, and floors ascended or descended measured by Apple Core Motion. These measurements are used only for the journey’s walking record, not for health goals or automatic activity classification. They are stored only in Application Support within the current storage scope and are not automatically sent to iCloud, the widget, the Provider, or a third party.
Receipt text recognition uses Apple Vision and runs on the device. MichiLoop does not send the image or recognised text to a third-party AI or external OCR service. The user reviews the result before saving. Full recognised text, text positions, confidence values, and candidate history are not stored, synced, exported, or logged. When finding nearby stores from a trip location, the merchant-name suggestion and search location are sent to Apple Maps; the receipt image and full recognised text are not sent. A receipt image is attached only when the user chooses to keep it.
The main app stores the next plan, preparation progress, ride statistics, the latest journal title, date, distance and duration, up to 40 trip-plan coordinates, and up to 120 points from a simplified travelled route in an App Group. Only the app and its widget use this information on the same device; it is not sent to the Provider or a third party. It is removed when the user chooses Delete Data or switches the Apple Account whose data is displayed.
2. Accounts, advertising and analytics
No MichiLoop account is required. The Provider cannot access the email address or credentials for the user’s Apple Account.
The current App Store version does not show advertising and does not include third-party advertising SDKs, independent analytics SDKs, tracking SDKs, or third-party crash-reporting SDKs. MichiLoop does not request App Tracking Transparency permission and does not use precise location, travelled routes, search terms, journals, profile or vehicle information, photos, videos, or audio for advertising, independent analytics, or third-party profiling.
3. Permissions
When selecting existing photos or videos, MichiLoop uses the iOS system photo picker and receives only the items selected by the user. MichiLoop requests photo access so it can read when and where the selected photos and videos were taken and fill in the date and place of the entry. It reads only the items the user selected; it does not read or enumerate the rest of the photo library. Refusing this permission still allows attaching photos and filling in the capture date. MichiLoop requests add-only Photos permission to save a trip cover or share card the user creates. The camera is used for journal and saved-spot photos and for receipt scanning started by the user; expenses can still be entered manually when camera access is refused. MichiLoop requests access to the microphone, location, Motion & Fitness, and notifications only when the user uses a related feature. Motion & Fitness is used only to obtain measurements for recorded segments where the user selected walking. After the user starts a ride log, location is recorded until the user ends it, including while the screen is locked or another app is in use. Location is not continuously collected outside an active ride session.
Permissions can be changed at any time in iOS Settings. Refusing a permission prevents the related feature but does not prevent use of unrelated features.
4. Apple services
MichiLoop uses Apple MapKit for place search and routes, Apple WeatherKit for weather, and Apple iCloud for synchronisation. Search terms, places, routes, times, and other information necessary to provide these features may be sent to Apple. Apple’s privacy policy applies to Apple’s handling of that information.
MichiLoop uses Apple StoreKit to purchase Creator Pack and MichiLoop Plus, check subscription status, and restore purchases. Apple handles the purchase process, reconciliation with the Apple Account, and payment information; the Provider does not receive full payment-card numbers. The app checks StoreKit entitlements and subscription status on the device to unlock features. It does not send entitlements, subscription status, or app data to a third-party purchase-management SDK. Apple’s terms and privacy policy apply to sales and transaction information Apple makes available to the Provider.
The App Store version does not include transmission to a third-party AI service or a feature for registering an external API key. If WeatherKit is unavailable, MichiLoop does not send location to a substitute weather provider.
5. Sharing and files
Travel Circle is invitation-only private sharing through Apple CloudKit Sharing. After the recipient accepts one invitation, MichiLoop uses a private control share that contains no journey or plan content to prepare independent read-only content shares so either person can explicitly send an item. Becoming connected publishes nothing. MichiLoop provides no public profiles, people search, public feed, follows, comments, reactions, collaborative editing, or live-location sharing.
An ordinary Travel Circle summary may contain only the title, day-level date range, category, selected distance and vehicle summary, sharing display name, and a plan’s start and destination display names and day count reviewed in the sharing screen. Only when the sender explicitly selects Plan-ready places and route settings may it also contain the names and precise coordinates of the start, destination, and up to 40 checkpoints, plus checkpoint day, category and stay, route type, and toll or highway avoidance settings. It excludes current location, travelled routes, route geometry, exact times, addresses, journal text, private notes, photos, videos, audio, expenses, receipts, source internal identifiers, and Apple Account email addresses or credentials. A plan saved by the recipient receives new internal identifiers and is an independent copy that does not automatically follow later edits or deletion of the source.
If both people review journeys they already explicitly shared and separately propose and accept a Journey Association, MichiLoop shares only an association identifier, state, revision, and each journey’s title, day-level date range, and shared-content version. If they then separately propose and accept a shared checklist, MichiLoop shares up to 20 short item labels, each item’s open or completed state, creator, and revision. Associations and checklists are pairwise. They do not co-edit either person’s journey, plan, private preparation items, or notes and add no location, route, exact time, expense, photo, or other private record.
Trip images, GPX files, and other data are passed to a destination only after the user reviews the content, starts an export or share action, and chooses the destination. The selected service’s terms and privacy policy apply.
A GPX exported from a recorded journey contains precise locations within the scope selected by the user and timestamps only for GPS points whose observed timestamps were saved. Checkpoints are excluded by default; when the user adds them, only their name, coordinates, and record time are included. Journal text, addresses, photos, videos, audio, notes, and vehicle IDs are excluded. An exported file is an independent copy and does not automatically follow later edits or deletion of the source record.
A GPX file is imported only after the user selects it on the device. MichiLoop does not automatically send GPX files to a server operated by the Provider.
Data Management in Settings can export rider data in the current storage scope, including per-journey budgets, confirmed trip expenses, active or unsaved rides, and walking measurements stored on this device. The export contains rider records and settings but excludes internal sync history, deletion metadata, and CloudKit bookkeeping. Readable attached media, including receipt images the user chose to keep, is included in a TAR file created in protected temporary storage. It is never sent automatically and leaves the app only after the user chooses a destination. Expired temporary exports are deleted automatically.
6. Support and the official website
If a user contacts support by email, the Provider handles the email address, message, and any app version, device details, or attachments the user chooses to provide to answer the request, investigate a problem, and prevent abuse. Do not send unnecessary location data, photos, GPX files, or credentials.
The hosting provider may process request information such as IP address, browser information, and access time to deliver and secure the official website. The Provider does not add independent analytics, advertising, tracking cookies, or a contact form to the website.
7. Retention and deletion
Content received through Travel Circle may remain in an on-device cache scoped to the Apple Account currently displayed. Revocation, source deletion, blocking, and disconnection take effect after CloudKit synchronisation and may be delayed while offline. After ordinary shared content is removed, MichiLoop may temporarily retain only payload-free identifiers needed to finish remote cleanup. MichiLoop cannot retrieve a copy the other person saved or captured outside the app.
Journal entries, plans, trip expenses, profile, and vehicle information can be deleted in the app. Deleting a ride log also deletes its corresponding on-device walking measurements. Delete Data in Settings removes data, walking measurements, attached media including receipt images, current-scope recovery backups, unsaved rides, notifications, and widget content in the currently displayed Apple Account or on-device storage scope. When iCloud is in use, deletions of CloudKit-enabled items are synchronised to the same Apple Account’s other devices, including iCloud media in the current scope.
Data from an older app version whose storage environment cannot be identified is separated as Protected Legacy Data and is not removed by Delete Data. Each protected source can be explicitly deleted from its detail screen after the user exports it or confirms deletion without exporting.
Original photos and videos in Photos are not deleted. Media captured in MichiLoop and not saved to Photos will not remain after its MichiLoop data is deleted. On-device data is removed when the app is deleted. iCloud data can be deleted in the app or through iOS storage management.
Support information is kept only as long as necessary to answer the request, recheck a problem, comply with law, or handle a dispute, and is deleted when no longer needed. To request deletion of support information, contact us from the same email address. The hosting provider’s retention policy applies to its logs.
8. Security
The Provider takes reasonable measures to protect support information against unauthorised access, loss, alteration, or disclosure. App data is managed through Apple-provided device storage and the user’s private iCloud area.
9. Changes
This policy may be updated when features, practices, or applicable law change. Material changes will be identified by the updated date on the official website and, where appropriate, in the app.
10. Contact
Questions about this policy or information handling: info@tkgshoyu.jp