Privacy Policy
Effective date: August 19, 2026
This is a reference translation. The Japanese version is the authoritative text; in the event of any discrepancy, the Japanese version prevails. See the
Japanese version.
Bearcode Co. ("we," "us," or "the Company") sets forth this Privacy Policy (this "Policy") regarding the handling of users' information in connection with the iPhone application "Unfurl" (the "App").
1. Basic Approach
The App lets you keep a photo diary and care records for your houseplants. The records you keep in the App (plant information, journal entries, photos, and care logs) are stored on your iPhone and, if you have enabled sync, in iCloud associated with your Apple Account. These records are not sent to any server operated by us.
No account registration is required to use the App. We receive information on our servers only when you submit an inquiry from within the App, or in the form of information used to improve the quality of the App (crash information and usage data).
2. Information We Collect
2-1. Information stored on your device and in your iCloud (not sent to our servers)
- Plant information (name, date adopted, etc.)
- Journal entries (photos and notes)
- Care logs (watering, etc.)
- App settings
This information is stored in an on-device database (an app-private storage area) and, for photos, in an app-private folder on your device; none of it is sent to any server we operate. Thumbnail images used for list views are held only in the device's memory and are never saved as files. However, in the following cases this information is stored in iCloud, provided by Apple Inc.:
- iCloud sync: When iCloud sync for the App is enabled (it is enabled by default; you can turn it off at any time from Settings > Backup & Sync), the records above are stored in an area of iCloud (a private database) associated with your Apple Account. This area is under the control of your Apple Account, and we cannot view its contents.
- iCloud backup: If you have enabled iCloud Backup for iOS, the App's database and photos are included in the device backup Apple creates (the App does not exclude them from backup). In this case as well, the backup is stored in iCloud associated with your Apple Account, and we cannot view its contents.
The handling of information within iCloud is governed by Apple's own Terms of Service and Privacy Policy.
2-2. Information Collected Automatically
- Crash information: To identify and fix defects in the App, we use Firebase Crashlytics (provided by Google LLC) to collect the location of crashes and errors together with technical information at the time (device model, OS version, App version, device state at the time of the crash, etc.), as well as installation-level identifiers (Firebase Installation ID and Crashlytics Installation UUID). This does not include personally identifying information such as your name or email address, nor the content of any photos or notes you have recorded.
- Usage data: To improve the App, we use Firebase Analytics (provided by Google LLC) to collect the following:
- Screen views and interaction events (limited to predetermined event names and numeric counts; this does not include content you entered, such as photos, notes, or plant names)
- App version, OS version, device model, and language setting
- Installation-level identifiers (Firebase Installation ID), an app-vendor identifier (IDFV), and a session identifier marking discrete usage sessions
- IP address (used at the time of transmission and used to estimate an approximate country/region)
- Settings values describing App usage: display language, whether reminders are enabled, and a banded count of the number of plants recorded
We do not incorporate any feature that handles an advertising identifier (IDFA), and we do not collect one. We also never set your name, email address, or a user ID as a parameter for usage analysis.
- About stopping collection: The crash information and usage data described above are collected at all times, solely for the purpose of improving your experience with the App, and the App does not provide a setting to stop this collection. Collection is limited to the items listed above and never includes content you have recorded (photos, notes, plant names), personally identifying information (name, email address, etc.), or an advertising identifier (IDFA). We also do not use the collected information for advertising or for tracking users. If you do not wish this information to be collected, please stop using the App (delete it).
- Server access logs: When our servers (an API running on Cloudflare) are accessed — for example, when you submit an inquiry — the IP address, access date and time, the destination accessed (the content of the request), and the response result or error information are recorded as technical records (access logs). These are used solely for detecting unauthorized access, limiting excessive access, and responding to incidents. The IP address is used to determine whether access is excessive and is not retained in the operational records we output.
2-3. Information Collected When You Submit an Inquiry
When you submit the in-app inquiry form, we collect the following:
- The type of inquiry (bug report, feature request, or general inquiry)
- The body of the inquiry (up to 2,000 characters)
- Your email address (required only for the "general inquiry" type, where a reply is expected; optional for bug reports and feature requests, and you may submit without providing one)
- App version, OS version, and device model name
This information is stored on our server (database). To notify us that an inquiry has arrived, we send a notification to our internal business chat, but that notification contains only the inquiry type — not the body, email address, App or OS version, or device model name.
In addition, if you contact us by email at support@unfurl.garden, we collect that email address, the message body, any information you attach (such as screenshots), and the record of our response.
3. Purposes of Use
We use the information we collect for the following purposes:
- Providing and maintaining the App
- Identifying and fixing defects, and improving quality and usability
- Detecting and preventing unauthorized access and misuse
- Responding to inquiries
- Notifying you of important information, such as changes to our terms and policies
4. Disclosure to Third Parties
We do not disclose the information we collect to third parties, except in the following cases:
- Where you have given your consent
- Where required by law
- Where necessary to protect a person's life, body, or property, and it is difficult to obtain the individual's consent
5. Service Providers and Cross-Border Transfers
In providing the App's server-side and analytics functions, we entrust the processing of information to the following external services. These providers' servers may be located outside Japan, and the information we collect may accordingly be stored and processed outside Japan.
The handling of information by each service is governed by that provider's own privacy policy. We use each provider after reviewing its terms of service and privacy policy.
Note that iCloud (Apple Inc.), described in Section 2-1, is a service you use under your own agreement with Apple and is not one of our service providers.
6. Retention Periods
- Records on your device and in iCloud: Retained until you delete them or delete the App (if iCloud sync is enabled, data in iCloud may remain until deleted through the procedure Apple provides).
- Inquiries: The content, email address, and response history are retained in our database for as long as necessary to respond to the inquiry and prevent recurrence, and are deleted once no longer needed.
- Crash information: Under Firebase Crashlytics's own policy, this is retained for 90 days from collection, after which deletion begins.
- Usage data: In Firebase Analytics, user- and device-level data is retained for up to 14 months (it is automatically deleted after this period); aggregated reports are unaffected by this period. We also export this data to Google BigQuery, where it is retained until we delete it.
- Access logs: Server operational records are retained for 7 days under Cloudflare's own policy.
7. Your Rights (Means of Disclosure, Deletion, etc.)
- Deleting records on your device: You can delete plants, journal entries, and care records within the App at any time. Deleting the App also deletes the records on your device (if iCloud sync is enabled, deletion of data in iCloud follows the procedure Apple provides).
- Stopping collection of usage data and crash information: As described in Section 2-2, the App does not provide a setting to stop this collection. If you do not wish this information to be collected, please stop using the App (delete it).
- Requests regarding disclosure, etc.: If you wish to request notification of the purpose of use, disclosure, correction, addition, or deletion, suspension of use or erasure, or suspension of provision to third parties, of your retained personal data, please contact us by email at the address given in Section 9. We handle such requests as follows:
- Identity verification: We verify your identity by matching the email address from which the request was sent against our records of inquiries. If we are unable to make this match, or if there is a risk of impersonation, we may ask you to confirm details that only you would know, such as the content of a prior inquiry.
- Method of response: We will respond, without undue delay and in accordance with applicable law, to the email address from which the request was sent.
- Fee: Free of charge.
Note that, in the App as of v1.0, the personal data we retain on our servers is, in practice, limited to records of inquiries (plant, journal, photo, and care records reside on your device and in your iCloud, and we do not hold them).
8. Security Measures
To prevent the leakage, loss, or damage of the information we collect, we implement the following measures:
- Organizational security measures: We limit personnel handling personal data to the Company's representative and maintain a structure through which the handling of such data can be reviewed. We have established a reporting and communication structure for use in the event of a data leak or similar incident.
- Personnel security measures: We ensure that personnel are aware of the relevant considerations for handling personal data and that such data is handled appropriately.
- Physical security measures: Devices used to handle personal data are kept in lockable locations and protected by screen locks and disk encryption to prevent information from being read in the event of theft or loss.
- Technical security measures: Communications are encrypted using TLS. Access to our servers, databases, and the administrative consoles of external services is limited to the minimum privileges necessary, and two-factor authentication is set on administrative accounts. Access to our servers is retained as a technical record and used to detect unauthorized access.
- Oversight of service providers: For the service providers described in Section 5, we select providers after reviewing their terms of service and privacy policies, and we manage them appropriately under contract.
- Awareness of the external environment: As described in Section 5, our service providers' servers may be located outside Japan. We implement security measures after confirming the location and applicable legal frameworks each provider publishes.
9. Company Information and Contact
Please direct inquiries, complaints, and requests regarding disclosure, etc. concerning this Policy and the handling of personal information to:
10. Amendments
We may amend this Policy in response to changes in law or the addition of new features. When we do so, we will set an effective date, and for significant changes we will provide advance notice through a clear method such as an in-app display.