EPOKE Privacy Policy
Established: July 16, 2026 / Revised: October 1, 2026
Morito Ishizaki (the “Operator”) establishes this Privacy Policy (the “Policy”) for handling user information in EPOKE, an app for iOS and Android (the “App”).
1. Scope
This Policy applies to information handled by the Operator through the App. Information collected by Apple, Google, or other third parties through their own services is governed by their respective privacy policies.
2. Information handled by the App
2.1 Information stored on your device
The App stores the following on your device:
- Display language.
- XP, level, titles, consecutive days of use, and other progress information.
- Reflection responses, dates, and counts.
- Lantern of Awareness practice status.
- Reading viewing and completion status.
- Notification preferences and scheduled notification time.
- Birthday month and day (not the year).
- Onboarding and similar display status.
- Identifiers for the self-critical words you select.
- Self-critical words you enter yourself (up to three).
This information is used locally to provide the App’s features. Through the App’s normal features, the Operator does not transmit these contents to a server or view them.
Depending on your operating system and settings, this information may be included in device backups provided by Apple or Google. Their terms and privacy policies apply to such backups.
2.2 Information transmitted for usage analytics
To improve the service, the App uses PostHog and sends 43 types of usage events to PostHog EU Cloud. These are fixed events limited to the following scope, not a record of every tap or screen content:
- Randomly generated anonymous analytics identifiers and session identifiers.
- App launches, major screen views represented by fixed IDs, and the preceding screen.
- Step views, completion, abandonment, and overall flow completion for onboarding, daily reflection, and the Lantern of Awareness, represented by fixed IDs.
- Reading list views, reading views, completion, abandonment, locked content displays, and purchase prompts.
- XP awards, level changes, and updates to consecutive days of use.
- Purchase screen views, plan selections, purchase and restoration starts and results, and opening subscription management.
- Settings views, language changes, notification permission results, notification preference changes, opening legal pages, and analytics consent.
- Fixed
reading_idvalues identifying published readings, required level, free/paid classification, and the originating screen. - A temporary
attempt_idgenerated for each flow, not used as a persistent user identifier. - Duration buckets such as “under 30 seconds,” “30 seconds to under one minute,” “one to under three minutes,” and “three minutes or more,” and buckets for consecutive days of use—not exact seconds or day counts.
- Level, XP awarded, result category, end reason, language, distribution channel, and analytics schema version required by fixed event definitions.
- App name, version, build number, and package name.
- Device type, manufacturer, and model.
- Operating system name and version.
- Device language, region, and time zone.
- Network information such as IP addresses technically processed during communication.
Purchase events contain only fixed product categories (monthly, Lifetime, or Super Support), fixed result categories (such as success, cancellation, or failure), and fixed failure classifications (such as network, store unavailable, payment pending, purchase not allowed, or unknown). Prices, currencies, and raw store error messages are not sent to PostHog.
The App does not send the following to PostHog:
- Your selected self-critical words, their internal IDs, or selection counts.
- Custom self-critical words you enter.
- The contents of reflection answers or values from which those answers can be inferred.
- Other input or search contents.
- Reading titles or body text.
- Birthday information.
- Names, email addresses, or telephone numbers.
- Prices or currencies.
- Purchase receipts or StoreKit/Google Play purchase tokens.
- Full customer information received from RevenueCat.
- Raw error messages or stack traces.
- Screen screenshots.
- Advertising identifiers.
- Location information.
The App also does not use session replay, screen recording, automatic input capture, automatic error/exception or crash capture, Feature Flags, GeoIP location enrichment, Person Properties, automatic lifecycle capture, or advertising tracking.
2.3 Information transmitted for purchases and entitlement verification
The App uses RevenueCat to provide in-app purchases, verify purchased entitlements, and restore purchases. When you open the purchase screen, purchase or restore, or when the App checks purchase status, RevenueCat, Apple, or Google may process:
- An anonymous App User ID generated by RevenueCat.
- App, operating system, store, and other operating environment information.
- Product IDs, purchase/restoration status, purchase dates, subscription validity, renewal and expiration status, and in-app entitlements.
- Transaction information issued by Apple or Google, which may include receipts or purchase tokens.
Apple or Google handles credit card numbers and other payment credentials; the Operator does not obtain them directly. Purchase information sent to RevenueCat is not forwarded to PostHog for usage analytics.
3. How information is collected
Locally stored information comes from your input, selections, and use of the App. Analytics information is collected and transmitted through the PostHog SDK; purchase and entitlement information through the RevenueCat SDK and Apple or Google store features.
On iOS, the PostHog client is created only after you consent to usage analytics in the App. Pre-consent events are not saved or transmitted later. Turning analytics off in iOS Settings stops new events and discards the unsent analytics queue. On Android, analytics within this Policy’s scope is enabled from the start of use, without an additional consent screen or analytics toggle. On both operating systems, analytics transmission pauses while developer mode is active and resumes according to each operating system’s analytics settings when developer mode ends.
4. Purposes of use
The Operator uses information to:
- Provide App features and retain your progress and preferences locally.
- Provide features you choose, such as notifications.
- Statistically understand usage and improve onboarding, daily reflection, the Lantern of Awareness, readings, purchase flows, screen structure, and features.
- Provide in-app purchases and verify and restore purchased entitlements.
- Investigate problems, maintain security, and prevent misuse.
- Respond to user inquiries.
Analytics information is not used for third-party advertising, tracking across other companies’ apps or websites, data sales, credit scoring, or automated decisions adversely affecting users.
5. External service providers
5.1 PostHog
The Operator uses PostHog as a service provider processing usage analytics.
- Service: PostHog.
- Environment: PostHog EU Cloud.
- Provider: PostHog, Inc.
- Purpose: Usage analysis and improvement of the App.
- Privacy information: PostHog Privacy Policy.
PostHog processes analytics information based on the Operator’s instructions.
5.2 RevenueCat
The Operator uses RevenueCat to manage in-app purchases and entitlements.
- Service: RevenueCat.
- Provider: RevenueCat, Inc.
- Purpose: Product information retrieval, purchase and restoration processing, and subscription status and entitlement verification.
- Privacy information: RevenueCat Privacy Policy.
5.3 Apple and Google
iOS purchases are processed through Apple’s App Store, and Android purchases through Google Play. Their respective terms and privacy policies govern payments, store accounts, purchase history, refunds, and subscription management.
The Operator does not provide user information to third parties except where required by law, necessary to protect life, bodily safety, or property, consented to by the user, or entrusted within the necessary scope to the service providers described in this Policy.
6. Retention and deletion
6.1 Information on your device
Progress and input information are stored on your device and can be removed by uninstalling the App. Manage information remaining in operating system backups through Apple or Google backup settings. For purchase history and entitlements, see section 6.3.
6.2 Analytics information
Analytics information sent to PostHog is retained as needed for its purposes, according to the retention period set by the Operator and PostHog’s service conditions. Turning analytics off on iOS stops new transmission and discards the local unsent queue, but does not automatically delete information already sent. The Operator does not offer a routine service for individual deletion requests concerning analytics information already transmitted. For requests to cease use or erase information under applicable law, contact the address in section 12. The Operator will handle such requests in accordance with applicable law.
6.3 Purchase and entitlement information
Purchase and entitlement information processed by RevenueCat, Apple, and Google is retained according to entitlement provision, transaction records, legal obligations, and each service’s conditions. Uninstalling the App does not necessarily delete store purchase history or RevenueCat entitlement information. For the handling of store purchase history and other information managed by Apple or Google, refer to the relevant service’s contact point. For requests under applicable law concerning information handled by the Operator, contact the address in section 12. The Operator will handle such requests in accordance with applicable law.
7. Analytics and device permissions
Consent to usage analytics on iOS is optional. The App’s main features remain available if you decline. You can withdraw iOS consent at any time by turning analytics off in Settings. On Android, usage analytics within this Policy’s scope is enabled from the start of use, without an additional consent screen or analytics toggle. Withdrawing iOS consent stops subsequent transmission, but does not automatically delete previously transmitted information; see section 6 for the handling of information already transmitted. Analytics preferences do not affect access to paid features.
The App requests operating system notification permission if you use notifications. Declining notifications does not prevent other main features from working. You can change notification permission in device settings at any time.
8. Security
The Operator takes reasonable security measures—including encrypted communication, access restrictions, and data minimization—to prevent unauthorized access, disclosure, loss, or damage. However, complete information and communication security is not guaranteed.
9. Use by minors
The App is not primarily intended for children under 13. Minors should consult a parent or guardian as appropriate before use.
10. Processing outside Japan
Analytics information may be processed outside Japan through PostHog EU Cloud, and purchase and entitlement information through RevenueCat, Apple, or Google infrastructure. The Operator checks service provider security measures and conditions in accordance with applicable law.
11. Policy changes
The Operator may change this Policy when laws, services, or information handling change. Significant changes will be clearly announced in the App or on its public pages, and consent will be obtained again where required by law.
12. Contact
- Operator: Morito Ishizaki (石崎森人).
- Privacy contact: [email protected].