プライバシーポリシー
最終更新日: 2026年10月5日
Torevo 運営者(以下「運営者」)は、アプリ「Torevo」(以下「本アプリ」)における利用者の情報の取り扱いについて、次のとおり定めます。
1. 運営者
本アプリは Torevo 運営者が提供します。
2. 取得する情報
本アプリは、次の情報を取得することがあります。
- 利用者が入力するトレーニング・体組成・食事の記録、目標、設定
- 体の写真(利用者が保存した場合)
- 端末ごとに発行する匿名の識別子(サーバーへの保存と同期に用います)
- 位置情報(ジム判定を有効にした場合、本アプリの使用中のみ)
- ヘルスデータ(Android で Health Connect との連携を有効にした場合は、歩数・消費カロリー・距離・ワークアウト・体重・体脂肪率の読み取り、およびワークアウト・消費カロリーの書き込み。iOS で Apple ヘルスケアとの連携を有効にした場合は、体重・体脂肪率・消費カロリー・歩数・距離・Apple エクササイズ時間の読み取り、およびワークアウト・消費カロリーの書き込み)
- アカウント情報(メールアドレスを登録した場合のメールアドレス)
- ジムを検索した場合の検索語と、「現在地を使う」を選んだ場合の現在地
- 招待コードを引き換えた場合、そのコード
- 種目のデモ動画(GIF)を運営者のサーバーから読み込む場合、その通信の送信元 IP アドレス(過剰なアクセスを防ぐための判定に 5 分間だけ使い、期限を過ぎたものはその後のアクセスに合わせて順次削除します)
- プッシュ通知用のトークン(お知らせ通知を有効にした場合)
- フィードバックを送信した場合、その内容と、任意で入力した返信用メールアドレス。送信時に診断情報を付ける設定にしている場合は、あわせてアプリのバージョン・OS の種別とバージョン・言語設定
3. 保存場所
記録と設定は利用者の端末内に保存するとともに、端末ごとに発行する匿名の識別子に紐づけて運営者のサーバー(Supabase)にも保存(同期)します。メールアドレスの登録は、別の端末で記録を引き継ぐための任意の操作です。登録すると、この識別子はそのメールアドレスに結びつき、同じメールアドレスでサインインした別の端末からも同じ記録にアクセスできるようになります。
「体型の記録」として保存した体の写真は端末内にのみ暗号化して保存し、表示するたびに Face ID・Touch ID または端末のパスコードで確認します。端末のバックアップには含めません。これらの写真をサーバーへ送ることはありません(目標の解釈に添付した参考写真は第4項のとおり送信されます)。
検索から登録したジムでチェックした器具・設備・マシンの種類は、「器具を匿名で共有」がオンの間(初期設定はオン)、どのジム(検索で選んだ施設)についての情報かとあわせて匿名の識別子に紐づけてサーバーに保存し、同じジムを登録する他の利用者に初期値として示します。他の利用者に示すのは、異なる3人以上、かつそのジムについて共有した人の6割以上が共有している項目だけで、誰が共有したかや人数は示しません。現在地、利用者が付けたジム名、トレーニングの記録は含みません。オフにすると、共有した分はサーバーから削除されます。
4. AI 機能における第三者への送信
食事の推定や目標の解釈といった AI 機能を利用者が有効にした場合、または器具の判別で送信を選んだ場合に限り、次の内容を運営者のサーバーを経由して AI 提供事業者へ送信します。
- 食事の推定: 送信した食事の写真またはテキスト(あわせて言語と単位の設定)
- 目標の解釈: 目標のテキスト、添付した参考写真、設定した性別・身長、最新の体組成の記録(体重・体脂肪率・骨格筋量。ヘルス連携で取り込んだ値を含みます)
- 器具の判別: 種目を写真で探すときに、端末内で器具の名前を読み取れず、利用者が AI で調べることを選んだ器具の写真(その都度確認します)
現在の提供事業者は Anthropic PBC および OpenAI, L.L.C. です。提供事業者は変更されることがあります。
運営者が、氏名やメールアドレス、アカウントの識別子などを送信内容に付け加えることはありません。ただし、利用者が入力したテキストや写真に含まれる情報(写真に写った顔など)は、そのまま送信されます。AI 機能の有効化は、設定からいつでも取り消せます。
5. 利用者がつないだ AI アシスタント
利用者が ChatGPT や Claude などの AI アシスタントを本アプリにつないだ場合(接続 URL を作成した場合、またはアシスタント側の「接続」から本アプリで許可した場合)、そのアシスタントは、利用者が会話で求めたときに、運営者のサーバーに保存されたトレーニング・体組成・食事の記録を読み取り、食事の記録の提案を送ることができます。体の写真、食事の写真、AI 推定の詳細は読み取れません。提案された食事は、利用者が本アプリで確認して保存するまで記録には加わりません。
アシスタントが読み取った内容の取り扱いには、そのアシスタントの提供事業者(OpenAI, L.L.C.、Anthropic PBC など)の規約とプライバシーポリシーが適用されます。運営者は、接続を識別するための鍵とトークンを、元に戻せない形(ハッシュ)でのみ保存します。接続は、本アプリの設定からいつでも切ることができ、切るとすぐに読み取れなくなります。
6. 位置情報
ジム判定は、本アプリの使用中にのみ現在地を取得し、登録済みのジムとの距離を端末内で計算します。判定に使った現在地そのものをサーバーへ送信することはありません。
ジムの検索で「現在地を使う」を選んだ場合は、近くのジムを探すために現在地の座標を運営者のサーバーへ送信します。この座標は検索にのみ使い、保存しません。
ジムの「ここを記録」で保存したジムの位置は、ジムの記録の一部として、他の記録と同様にサーバーに保存(同期)されます。
7. ヘルスデータ
連携を有効にした場合、上記の範囲でヘルスデータを読み書きします。連携で取り込んだ体重・体脂肪率・歩数などは、記録の一部として運営者のサーバーに保存(同期)されます。利用者が目標の解釈(第4項)を有効にした場合に、最新の体組成として AI 提供事業者へ送信されることがあるほかは、第三者へ送信することはありません。
8. 通知
お知らせ通知を有効にした場合、プッシュ通知用のトークンを運営者のサーバーに保存します。通知を無効にすると、登録を解除します。
9. 利用目的
取得した情報は、次の目的で利用します。
- 本アプリの機能の提供と、端末間の同期
- フィードバック(不具合の報告、種目の追加やジム情報の誤りなどのご要望、機能のリクエスト、使い方の質問)への対応。返信用メールアドレスは、そのフィードバックへの返信にのみ使います
- 有料機能や招待による利用権の確認
- お知らせの配信
広告の配信や行動分析には利用しません。本アプリに解析 SDK や広告 SDK は組み込んでいません。
10. 保存期間と削除
- 端末内のデータは、本アプリを削除するか、本アプリ内で個別に削除するまで保持します。
- 記録と設定は、設定の「データを書き出す」から手元に取り出せます。写真や動画(体型の記録の写真、食事の写真、トレーニングに添付したメディア)は書き出しに含まれません。
- サーバー上のアカウントと同期データの削除は、設定の「お問い合わせ・不具合の報告」から依頼できます。依頼を受けたのち、相当な期間内に削除します。
11. 利用者の権利
利用者は、運営者が保有する自身の個人情報について、開示・訂正・削除・利用停止を求めることができます。設定の「お問い合わせ・不具合の報告」からご連絡ください。
12. 安全管理
本アプリとサーバーの間の通信は暗号化します。サーバー上のデータは、他の利用者からアクセスできないよう制限します。
13. 変更
運営者は、必要に応じて本ポリシーを変更することがあります。変更後のポリシーは、本アプリ内に掲示した時点で効力を生じます。重要な変更は本アプリ内でお知らせします。
14. お問い合わせ
本ポリシーに関するお問い合わせは、設定の「お問い合わせ・不具合の報告」からお送りください。
設定に「お問い合わせ・不具合の報告」が表示されない構成の本アプリをお使いの場合は、本アプリを入手した配布元(ストアのページなど)に記載の連絡先へお送りください。
Privacy Policy
Last updated: October 5, 2026
This policy describes how the Torevo operator (the "Operator") handles your information in the Torevo app (the "App").
1. Operator
The App is provided by the Torevo operator.
2. Information we collect
The App may collect:
- workout, body measurement, and meal logs, goals, and settings you enter;
- body photos, if you save them;
- an anonymous identifier issued per device, used to store and sync your data on the server;
- your location, if you enable gym detection, and only while the App is in use;
- health data, if you enable Health Connect on Android (reading steps, active calories, distance, workouts, weight, and body fat; writing workouts and active calories), or Apple Health on iOS (reading weight, body fat, active energy, steps, distance, and Apple Exercise Time; writing workouts and active energy);
- account information (your email address, if you register one);
- the search term when you search for a gym, and your current location if you choose "Use current location";
- an invitation code, if you redeem one;
- the IP address of the request when an exercise demo (GIF) is loaded from the Operator's server (used for 5 minutes to prevent excessive access; expired entries are then deleted progressively as later requests arrive);
- a push notification token, if you enable news notifications;
- if you send feedback, its content and any reply email address you enter; if diagnostics are attached, also the App version, OS name and version, and language setting.
3. Where data is stored
Logs and settings are stored on your device and are also stored (synced) on the Operator's server (Supabase), linked to an anonymous identifier issued per device. Registering an email address is optional and exists so you can carry your logs over to another device. Once registered, that identifier is linked to your email address, and any other device signed in with the same email address accesses the same records.
Body photos saved as body-progress records are stored encrypted on your device only, and Face ID, Touch ID, or your device passcode is required each time they are shown. They are excluded from device backups. Those photos are never sent to a server (a reference photo attached for goal interpretation is sent as described in section 4).
For gyms you added from search, the equipment, fixtures, and machine types you tick are stored on the server, together with which gym (the facility you chose from search) they are for, under your anonymous identifier while "Share equipment anonymously" is on (it is on by default), and are offered as starting values to other users who add the same gym. Other users see only items shared by at least three different people and by at least 60% of the people who shared anything for that gym, never who shared them or how many. Your location, the names you gave your gyms, and workout records are not included. Turning it off deletes what you shared from the server.
4. Sharing with AI providers
Only if you enable an AI feature, such as meal estimation or goal interpretation, or choose to send a photo for equipment identification, is the following sent through the Operator's server to an AI provider:
- Meal estimation: the meal photo or text you submit (together with your language and unit settings).
- Goal interpretation: the goal text, any reference photo you attach, your configured gender and height, and your latest body measurements (weight, body fat, and skeletal muscle, including values imported through the health integration).
- Equipment identification: when you search for exercises with a photo, the App cannot read the equipment's name on the device, and you choose to ask the AI, that photo of the equipment (you are asked each time).
The current providers are Anthropic PBC and OpenAI, L.L.C. Providers may change.
The Operator does not add your name, email address, account identifier, or similar to what is sent. Whatever is contained in the text or photos you submit (such as a face visible in a photo) is, however, sent as is. You can withdraw AI features at any time in Settings.
5. AI assistants you connect
If you connect an AI assistant such as ChatGPT or Claude to the App (by creating a connection URL, or by allowing it in the App after choosing "Connect" in the assistant), the assistant can, when you ask it in a conversation, read the workout, body and meal logs stored on our server and send a suggested meal entry. It cannot read body photos, meal photos or AI estimation details. A suggested meal is not added to your logs until you review and save it in the App.
What the assistant reads is handled under the terms and privacy policy of its provider (such as OpenAI, L.L.C. or Anthropic PBC). We store the keys and tokens that identify a connection only in a form that cannot be reversed (a hash). You can disconnect at any time in the App's settings, and the assistant loses access immediately.
6. Location
Gym detection reads your location only while the App is in use and computes the distance to your registered gyms on the device. The location used for detection is never sent to a server.
If you choose "Use current location" when searching for a gym, your current coordinates are sent to the Operator's server to find gyms nearby. They are used only for that search and are not stored.
A gym's position saved with "Save this spot" is stored (synced) on the server as part of that gym's record, like your other records.
7. Health data
If you enable the integration, the App reads and writes health data within the scope listed above. Weight, body fat, steps, and other values imported through the integration are stored (synced) on the Operator's server as part of your records. They are not sent to third parties, except that your latest body measurements may be sent to the AI provider if you enable goal interpretation (section 4).
8. Notifications
If you enable news notifications, a push notification token is stored on the Operator's server. Turning notifications off removes the registration.
9. How we use information
Information is used to:
- provide the App's features and sync between your devices;
- handle your feedback (bug reports, requests such as adding an exercise or correcting gym information, feature requests, and usage questions); a reply email address is used only to reply to that feedback;
- check your access to paid or invitation-based features;
- deliver news.
It is not used for advertising or behavioural analytics. The App contains no analytics or advertising SDKs.
10. Retention and deletion
- Data on your device is kept until you delete the App or delete items within it.
- You can take a copy of your logs and settings with "Export my data" in Settings. Photos and videos (body-progress photos, meal photos, and media attached to workouts) are not included in the export.
- To delete your account and synced data on the server, ask through "Contact us / report a bug" in Settings. Deletion is carried out within a reasonable period after the request.
11. Your rights
You may ask the Operator to disclose, correct, delete, or stop using your personal information. Contact us through "Contact us / report a bug" in Settings.
12. Security
Communication between the App and the server is encrypted. Data on the server is restricted so that other users cannot access it.
13. Changes
The Operator may revise this policy as needed. The revised policy takes effect when posted in the App. Significant changes will be announced in the App.
14. Contact
Send questions about this policy through "Contact us / report a bug" in Settings.
If "Contact us / report a bug" does not appear in Settings in your configuration of the App, direct inquiries to the contact listed where you obtained the App (such as its store page).