Privacy Policy
PIS Japan LLC ("we" or "us") sets forth the following regarding the handling of personal information in Qlinx.
1. Information We Collect (where applicable)
- Firebase Authentication identifiers (UID) and authentication information such as email address
- If you sign in with Google, we may process provider identifiers, email address, and other authentication information provided by Google through Firebase Authentication
- If you use Sign in with Apple, we may process Apple authentication identifiers, email address provided by Apple (which may include a private relay address), and other authentication information required through Firebase Authentication. Authentication credentials processed temporarily for sign-in, reauthentication, or unlinking are not retained long-term
- If you use LINE Login, we may verify the ID token issued by LINE on the server side and process the verified LINE user identifier (subject), its mapping to a Firebase UID, and authentication metadata. Display name, profile photo, email address, and similar fields are not auto-copied into the Qlinx profile
- If you sign in with Facebook, we may process provider identifiers required for authentication through Firebase Authentication (providerId: facebook.com), and authentication metadata such as email address only when Firebase provides it (email may be unavailable). Social profile fields such as display name or profile photo are not auto-copied into the Qlinx profile
- Profile information (e.g., romanized name, date of birth, nationality, residence or planned residence, optional phone number, industry, work history, exam-related information, profile photo, and other user-entered content)
- Learning progress, favorites, settings, and referral-related information
- QP balance, ledger, entitlements, and Store purchase sync status (in-app identifiers; purchase tokens are not displayed on public web pages)
- In-app Important Inbox items and read state, and related records
- When the user enables Important Push and also grants OS notification permission, device identification tokens used for push delivery may be processed (default OFF; tokens are not collected from all users at all times). Delivery uses Firebase Cloud Messaging
- Device and app diagnostics, crash reports (Crashlytics), usage and error logs
- Technical information required for App Check and fraud prevention
- Admin console (CMS / admin) operation audit information (for administrators)
- Information provided by users when contacting us
- If you use Qurio AI, user input needed to generate answers, necessary conversation context, and provider usage metadata (including input, output, and total token counts, model identifiers, request identifiers, measurements related to normalized quotas, and incident/safety diagnostics). Internal yen-conversion policy is not displayed to users
Continuous location tracking and ad SDK targeting are not part of the current implementation. Static web pages (landing / Legal / auth action) do not use tracking cookies.
2. Purposes of Use
Service provision, authentication, session management, storage and sync of learning data, QP grant/consumption/unlock/referral processing, purchase verification, refunds, fraud prevention, audit, incident response, inquiry handling, Important notices (in-app Inbox and optional Important Push), Qurio AI answer generation, management of usage quotas and Premium use, security and safety, fraud prevention, maintaining service quality, and legal compliance.
3. External Services (in use)
- Google Firebase / Google Cloud (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Hosting, Firebase App Check, Firebase Cloud Messaging, etc.)
- Firebase Crashlytics
- RevenueCat
- Apple App Store / Google Play
- Google Gemini API (answer generation for Qurio AI; Gemini Developer API; model identifiers sent follow the configuration at implementation time)
Processing may occur outside Japan. We do not sell data to third parties (except as required by law). We may entrust processing to service providers. Whether Google uses data for product improvement, retention periods, and details of overseas processing locations are matters that depend on Google's terms and our contractual status. We do not currently represent that Google does not store inputs or that Google does not use them for product improvement. Limited processing for safety, policy, legal, or regulatory response may occur.
4. Retention & Account Deletion
Retention periods depend on purpose, law, and security needs; we do not specify a single fixed number of days. On account deletion, profile, progress, settings, favorites, QP, entitlements, user-facing referral display, Important Inbox, notification settings, deviceTokens, etc. are deleted or anonymized. Purchase, refund, ledger, webhook, and audit records may be retained for legal, fraud prevention, or audit purposes but are not used to restore data after re-registration. We do not represent that all user data is physically deleted immediately. Qlinx quota and request ledgers do not additionally store user question text or answer body for ratio or cost management. This does not mean we represent that Qlinx never stores questions or answers at all. For Facebook Login users, see also Facebook User Data Deletion.
5. Security
We strive to prevent leakage and unauthorized access through access controls, communication protection, security rules, App Check, and similar measures.
6. Disclosure, Correction, Deletion, etc.
We respond to requests for disclosure, correction, deletion, etc. from the data subject in accordance with applicable law.
7. Minors
If a minor uses the service, please do so with consent from a parent or legal guardian.
8. Contact
Personal information inquiries: support@qlinx.jp / Phone: 090-8520-4217 (same as general contact)
Operator: PIS Japan LLC
