Skip to main content
PasoPaso
About Plans Privacy Policy Terms of Service Contact
  • 日本語
  • English

Privacy

Privacy Policy

Last updated: 2026-07-10

This English translation is provided for convenience only. In the event of any conflict or discrepancy between this translation and the Japanese original, the Japanese version shall prevail.


PasoPaso ("we" or "us") regards the protection of users' personal and usage information as an important responsibility in providing this service, and handles such information appropriately in accordance with the following policy.

1. Information We Collect

  • Account information: email address, identifiers used to identify your account, etc.
  • User content: content you enter, such as goals (Goal), milestones (Milestone), tasks (Todo), and their descriptions, deadlines, etc.
  • Usage and technical information: error logs, basic operation history, device/browser information (kept to the minimum necessary).
  • Usage analytics information: in-app operation events and usage-status categories collected for service improvement (see Section 5 for details).
  • Information handled by AI features: goals, milestones, descriptions, deadlines, and other information you enter into or specify for AI features such as automatic task generation.
  • Billing and subscription information: subscription status for the paid plan (Plus) (plan type, status, expiration date, etc.) and information used to identify store purchases. Payment details themselves, such as credit card numbers, are handled by the respective stores and the payment management provider, and are not retained by us.

2. How We Collect Information

  • Through your input (submissions from the app UI).
  • When you create an account or sign in (authenticate), through identifiers provided by external ID providers (Apple, Google, X, GitHub, etc.) and our authentication platform (Supabase) to identify your account.
  • When you use AI features, the goals, milestones, descriptions, deadlines, and other information you enter or specify may be sent to the OpenAI API.
  • When you purchase or subscribe to the paid plan, we receive subscription status and related information from the App Store / Google Play and the payment management provider (RevenueCat).
  • While you use the app, error information and technical information about your device and runtime environment may be collected automatically for defect monitoring and quality improvement (Sentry).
  • While you use the app, usage information such as operation events is collected automatically for service improvement, only after you have agreed to the Terms of Service and Privacy Policy (PostHog; see Section 5 for details).

3. Purposes of Use

  • Providing the service, including storage, synchronization, authentication, and security.
  • Providing features such as AI task generation.
  • Providing the paid plan (subscription), managing and synchronizing subscription status, and determining entitlements.
  • Quality improvement, feature development, usage analysis, defect response, and support inquiries.
  • Preventing unauthorized use and complying with laws and the Terms of Service.

4. Third-Party Provision and Outsourcing

  • Supabase: database, authentication, Edge Functions (with access control via RLS). Reference: Supabase Privacy Policy
  • Apple / Google / X / GitHub, etc. (sign-in): used for authentication when creating an account or signing in. Each external ID provider may supply identifiers, email addresses, and other information necessary for authentication. When signing in with an Apple ID, a private (private relay) email address may be provided depending on your Apple settings. Reference: Apple Privacy Policy / Google Privacy Policy / X Privacy Policy / GitHub General Privacy Statement
  • OpenAI: for AI task generation, the goals, milestones, descriptions, deadlines, and other information you enter into or specify for AI features may be sent. Reference: OpenAI Privacy Policy
  • Sentry: sends error information and technical information about your device and runtime environment for monitoring app defects and crashes and improving quality. We take reasonable measures to remove or suppress email addresses, credentials, user-entered content, and similar data from what is sent. Reference: Sentry Privacy Policy
  • PostHog: used to analyze usage for service improvement. Analytics data such as operation events collected after consent is processed and stored on the cloud infrastructure of PostHog, Inc. (US region). See Section 5 for details of what is collected. Reference: PostHog Privacy Policy
  • Google (Forms): used to provide our contact form. Content entered into the form may be processed and stored by Google. Reference: Google Privacy Policy
  • Apple App Store / Google Play: used to sell the paid plan (in-app purchases / subscriptions) and process payments. Payment information is managed by each store, and we do not retain credit card details or similar information. Reference: Apple Privacy Policy / Google Privacy Policy
  • RevenueCat: used to manage and synchronize the subscription status of the paid plan. Handles subscription identifiers, subscription status, expiration dates, and similar information. Reference: RevenueCat Privacy Policy

5. Usage Analytics

For the purpose of improving the service, we use the analytics tool "PostHog" (provided by PostHog, Inc.; data storage region: United States) to collect and analyze app usage.

Information we collect

  • In-app operation events (for example: app launches; the fact that goals, milestones, or to-dos were created, edited, deleted, or completed, or that their input screens were displayed; the fact that recurring to-dos were created in bulk and the approximate count bracket; the start, success, or failure of AI task generation; reaching creation limits; the fact that the plan information screen or sign-in screen was displayed; starting guest use or transitioning to sign-in; and the status of purchase and purchase-restore operations)
  • Usage-status categories (guest / free plan / Plus plan, and sign-in status)
  • Environment information such as app version and language settings
  • For signed-in users, our app's internal user ID

Information we do not collect

The following information is not collected or sent for analytics purposes:

  • Entered content such as the titles or descriptions of goals, milestones, or to-dos
  • Input to AI features and content generated by AI
  • Contact and profile information such as email addresses and display names
  • Authentication tokens and payment-related identifiers (transaction IDs, purchased product information, etc.)

Timing of collection and consent

Usage data is collected only after you have agreed to the Terms of Service and Privacy Policy. No analytics data is sent before consent.

Handling of guest usage data

Operation events during guest use are collected anonymously. If you transition from guest use to sign-in on the same device, the anonymous operation events from before sign-in may be linked to your post-sign-in user ID for service improvement (analyzing transitions from guest use).

6. Cookies and On-Device Storage

We may use cookies and similar technologies for purposes such as session management, in order to provide the service and ensure security.

During guest use, goals, milestones, tasks, your consent status for the Terms of Service and Privacy Policy, onboarding completion status, and similar data are stored on your device. Guest-use data is device-dependent and is not automatically migrated to the cloud upon account creation or sign-in.

7. Security Measures

  • We implement reasonable technical and organizational security measures, including access control (such as RLS).
  • Communications are protected by TLS as a rule.

8. Retention and Deletion

  • User data is retained for as long as necessary for providing the service, ensuring safety, improving quality, preventing fraud, supporting audits, and complying with laws.
  • Data is not necessarily deleted immediately upon account closure. Your account becomes unusable, and data is deleted or anonymized progressively after a certain period (except where retention is required for legal obligations, fraud prevention, dispute resolution, or similar reasons).
  • If you wish to have your data deleted, please submit a request via the contact form. We will respond to the extent possible. Data may remain in backups and similar systems for a certain period.

9. Your Rights

  • You may request access to, correction of, suspension of use of, or deletion of your data.
  • Closing your account alone does not immediately delete your data. If you wish to have it deleted, please submit a request via the contact form.
  • For specific procedures, please see the contact information at the end of this page.

10. International Transfers

Depending on the countries in which the contractors and partners listed in Section 4 (cloud infrastructure, authentication, AI, defect monitoring, usage analytics, payment and subscription management, forms, etc.) are located, data may be transferred to and stored outside Japan. We handle such data appropriately in accordance with applicable laws.

11. Changes to This Policy

This policy may be revised in response to changes in laws or the service. If there are material changes, we will announce them by appropriate means.

12. Contact

For inquiries, please contact us via the contact form or by email (pasopaso.app@gmail.com).

PasoPaso

Turn big goals into steps you can take today.

© PasoPaso

PasoPaso

Home About PasoPaso Plans

Support

Terms of Service Privacy Policy Contact