Atoyomu Privacy Policy

Effective date: September 3, 2026 · Version 1.0

The short version

  • Your bookmarks, summaries, categories and tags are stored on your device and, on Apple platforms, in your own iCloud account. We cannot read them.
  • Summaries are generated entirely on your device with Apple Intelligence or Gemini Nano. Page text is never sent to us or to any cloud AI service.
  • The app shows no ads and does not track you across apps or websites.
  • Crash and usage reports are off until you turn them on. They never contain URLs, page titles, page text or your identity, and you can turn them off at any time in Settings.
  1. Who we are
  2. Data you save in the app
  3. How the app processes web pages
  4. Optional crash and usage reports
  5. How we use the reports
  6. How long data is kept
  7. Who we share data with
  8. International transfers
  9. Your choices and rights
  10. Children
  11. Security
  12. Changes to this policy
  13. Contact

1. Who we are

Atoyomu ("the app") is developed and operated by Minato Digital ("we", "us"). This policy explains what information the app handles on iPhone, iPad, Mac and Android, and the choices you have. It applies to the app and to this website.

2. Data you save in the app

When you share a web page to Atoyomu, the app creates a bookmark that may contain:

Where it lives. On iPhone, iPad and Mac, bookmarks are stored in the app's local database and, if you are signed in to iCloud with iCloud Drive enabled, in the private database of your own iCloud account so that they sync between your devices. That data is protected by your Apple Account and Apple's privacy policy. We have no server of our own, no access to your iCloud data, and no way to see what you have saved. On Android, bookmarks are stored only on the device and are not synced anywhere.

If iCloud is unavailable, the app keeps working with the local copy and does not sync.

3. How the app processes web pages

After you save a page, the main app downloads that page directly from your device to the website, exactly as a browser would. The website therefore sees your IP address and standard request headers; we do not act as a proxy and do not see the request. The Share Extension may also download the page's cover image from the same website.

The app then extracts the readable article text on your device using an open-source readability engine, keeps at most 8,000 characters of it temporarily, and passes that excerpt to the on-device model:

Once a summary is produced, or if the page has too little readable text, the temporary excerpt is discarded. Page text, HTML, titles and URLs are never sent to us, to Google's or Apple's cloud AI services, or to any other third party for summarization. Devices without on-device AI keep the bookmark in a "pending" state; nothing is uploaded instead.

In-app browser. When you open a saved page inside the app, it is displayed by the system browser view (Safari View Controller on Apple platforms, Chrome Custom Tabs or your default browser on Android). The website's own cookies and privacy practices apply to that visit.

Local diagnostics log. The app keeps a small processing log on your device (which phase succeeded or failed and a technical error category, for up to 200 bookmarks). It does not contain page text or HTML. You can view, copy or export it from Settings; nothing in it leaves the device unless you share it yourself.

4. Optional crash and usage reports

On iPhone, iPad and Mac, the app can send anonymous crash and usage reports to help us fix bugs and understand which parts of the app are used. This is opt-in: after the first-run walkthrough the app asks "Send crashes and usage?", and nothing is collected until you choose Send. You can change your answer at any time in Settings › Send crashes and usage. Turning it off stops both crash and usage collection. The Android app does not include this feature.

Reports are processed by Firebase Crashlytics and Firebase Analytics, services of Google LLC. When enabled, the following is sent:

CategoryWhat is included
Crash reportsStack trace, the app version and build, OS version, device model, memory and disk state at the time of the crash, and the time of the crash.
Usage eventsWhich tab you switched to; that a bookmark detail was opened and from which screen (for example "read later" or "search results"), whether it was already read, and its processing state; how the first-run walkthrough was completed; and when you turned reports on or off.
Processing failure reportsA normalized, fixed-vocabulary description of why fetching, extraction or summarization failed (an error category, size buckets, a set of feature flags, and a 64-character fingerprint that groups identical failures).
SDK metadataA random app-instance identifier generated by the Firebase SDK, app language and region, platform (iOS or macOS), and the approximate country derived by Google from the IP address of the request. We do not store IP addresses.

The following are never included in any report: page URLs, domains, titles, page text, summaries, category names, tags, search queries, bookmark identifiers, your name, e-mail address, Apple Account or Google Account, contacts, precise location, or the advertising identifier. The app does not request App Tracking Transparency permission and does not use the IDFA. Reports are not linked to your identity, and we do not attempt to identify you from them.

5. How we use the reports

We use crash and usage reports only to diagnose crashes, find and prioritize processing failures, and understand how the app's screens are used so we can improve it. We may copy the normalized failure reports into our own analytics environment on Google Cloud (BigQuery) and analyze them with automated tools, including Google's Gemini models running in Google Cloud. Those tools only ever see the normalized fields listed above; the excluded fields are never present in the reports to begin with. We do not use the reports for advertising, profiling or any automated decision that affects you.

6. How long data is kept

7. Who we share data with

We do not sell personal information and do not share it for advertising. The only third parties that handle data on our behalf are:

We may also disclose information if required by law or to protect the rights, safety or property of users, the public or ourselves, and in connection with a merger, acquisition or sale of assets, in which case this policy will continue to apply to the transferred data.

8. International transfers

We are based in Japan. Google may process the optional reports on servers in the United States and other countries. Where required, transfers rely on the safeguards in Google's data processing terms, including standard contractual clauses, and on the fact that the reports contain no directly identifying information.

9. Your choices and rights

Because your bookmarks are held only on your devices and in your own iCloud account, and because crash and usage reports are not linked to your identity, we are generally unable to locate data belonging to a specific person. If you contact us with a request, we will explain what we can and cannot do and act on it within the time required by applicable law. We will not discriminate against you for exercising your rights.

Legal bases (EU/UK). We process bookmark data on your device to provide the app (performance of a contract). We process optional crash and usage reports on the basis of your consent, which you may withdraw at any time. We process data to comply with legal obligations where required.

California. We do not sell or share personal information as defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information.

10. Children

Atoyomu is not directed to children under 13, or under the higher minimum age that applies in your country. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it.

11. Security

Bookmarks are protected by your device's operating system security and, in iCloud, by Apple's encryption. All network connections made by the app use HTTPS. The app only downloads pages from public web addresses and refuses private or local network addresses. Optional reports are limited to a fixed vocabulary that excludes free-form text, which is verified automatically before each release.

12. Changes to this policy

We may update this policy when the app changes. The effective date at the top shows when it was last revised. If a change materially affects how your information is used, we will notify you in the app or on this website before it takes effect.

13. Contact

Questions and requests about this policy can be sent to Minato Digital at [SUPPORT_EMAIL].

This policy is provided in English and Japanese. If the two versions differ, the Japanese version prevails.