Haruki プライバシーポリシー
最終更新: 2026年9月23日
Harukiは、走行記録、日記、写真、添付ファイル、音楽情報を原則として端末内に保存し、Haruki独自のサーバーへ送信しません。
外部サービス
地図表示ではOpenStreetMapタイルを取得します。表示範囲周辺の公園・緑道・河川・街灯のある道・公衆トイレを取得するため、表示中の地図中心をOverpass APIへ送信します。天気取得では位置情報、ユーザーが明示的に選んだGoogle Drive書き出しでは選択データが各サービスへ送信されます。Health Connectは許可された提供元と項目だけを読み取ります。通知アクセスでは再生中の曲名・アーティスト等のメディア情報だけを利用し、通知本文を保存しません。
健康データ(Health Connect)
Harukiはランニングの日記です。他のアプリやスマートウォッチで走った日が日記から欠けないように、利用者が明示的に連携を許可した場合にかぎり、Android の Health Connect から走った記録を読み取ります。連携は任意で、つながなくても GPS 計測と日記はそのまま使えます。
読み取る種類と、それぞれの用途(これ以外の健康データは読み取りません):
- 運動セッション — その日に走ったことと、開始・終了の時刻。日記の1ページを作るために使います。
- 距離 — 走った距離。日記の記録値と積み重ねの集計に使います。
- 速度 — 1kmごとの平均ペースの算出に使います。スマートフォンのGPSより精度が高いため、ある場合はこちらを優先します。
- 心拍 — 取り込んだその走りの時間範囲だけの心拍を読み、1kmごとの平均にして、同じ区間のペースと並べてグラフに表示します。一日を通した心拍・安静時心拍・睡眠中の心拍は読みません。
- 総消費カロリー — 記録の補足として日記に表示します。
- 記録された軌跡(ルート) — Haruki 側に軌跡が1点も無い時にかぎり、地図へ描くために使います。Haruki 自身が測った軌跡を上書きすることはありません。
速度・心拍・総消費カロリー・軌跡は任意です。 許可しなくても取り込みは通常どおり動き、その項目が日記に出ないだけです。必須なのは運動セッションと距離の2つで、これが無いと「いつ走ったか」が分からず取り込み自体が成立しません。
書き込みはしません。 Haruki から Health Connect へデータを書き出すことはなく、書き込み権限も要求しません。読み取る提供元(Garmin 等)は利用者が選び、いつでも変更できます。
保存場所:取り込んだ内容は端末内のデータベースに保存します。Haruki が運営するサーバーはなく、健康データを Haruki へ送信することはありません。利用者が自分で Google ドライブへの書き出しを選んだ場合にかぎり、その書き出しファイルに含まれます(送信先は利用者自身の Google ドライブです)。
バックグラウンドでの読み取り:設定の「自動更新」をオンにした場合にかぎり、アプリを使っていない間も Health Connect を読み取ります(新しく走った記録を取りに行くためだけに使います)。オフのままなら、読み取りはアプリを開いている時だけです。
保持と削除:取り込んだ記録は、利用者が消すまで端末内に残ります。記録ごとの削除、アプリのストレージ消去、アンインストールのいずれでも削除できます。権限の取り消しと、保存済みデータの削除は別の操作です——Health Connect 側で権限を取り消しても、それまでに取り込んで端末内にある記録は消えません。消したい場合はアプリ側で記録を削除してください。
権限の取り消し:Health Connect アプリ、または端末の設定からいつでも取り消せます。Haruki の設定画面からも連携を解除できます。
位置情報
アプリを開いている間:地図に現在地を表示するためと、その日の天気を記録に添えるために使います。天気の取得では座標が天気サービスへ、地図の表示ではタイル配信元へ送られます。
計測中:走った距離とルートを記録するために使います。画面を消していても計測は続きます。記録は端末内に保存します。
「自動でランを検知」をオンにしている場合:走り出しに気付くために、アプリを閉じている・使っていない間もこの端末の位置情報と身体活動を読み取ります(登録した場所の周辺が対象)。この機能は任意で、オフにすれば読み取りはアプリを開いている間と計測中だけになります。
位置情報を Haruki のサーバーへ送ることはありません(Haruki が運営するサーバーはありません)。
書き出し・Google Drive へのバックアップ:走行ルートに加え、「プロフィールと設定」を含めた場合は自動計測のために登録した場所(Start Point の位置と住所)も、あなたが選んだ保存先(端末のフォルダ、またはあなた自身の Google Drive)へ書き出します。含めたくない場合は「記録を書き出す」で外せます。
利用状況の匿名計測
Harukiが実際に使われているかを確認するため、匿名の行動データをPostHog(EUリージョン)へ送信します。個人を識別せず、氏名・メールアドレス等の個人情報とは一切結び付けません。
利用目的:収集した情報は、次の目的にのみ使用します。
- アプリの画面と使い勝手の改善(どの機能が実際に使われているかを把握し、使われていない導線や分かりにくい画面を見直すため)
- 不具合の発見と修正(特定の機種やOSバージョンでのみ問題が起きていないか、記録の途中で操作が止まっていないかを把握するため)
- 対応機種・対応環境の判断(どの端末での動作確認を優先すべきかを決めるため)
広告の配信、利用者のプロファイリング、第三者への販売・提供には一切使用しません。
送信する行動は、次の4種類だけです。
- アプリを起動したこと(日単位の継続率の算出に使います)
- 走行を1件記録したこと(記録の有無のみ。距離・時間・ルートは含みません)
- 日記本文を書いたこと(書いたという事実のみ。本文・タイトル・文字数は含みません)
- 開いたタブの種別(リスト/カレンダー/曲/写真のいずれか。中身は含みません)
これらに付随して、端末とアプリの基本情報が一緒に送られます。内訳は次のとおりです。
- 端末のメーカー・機種名・OS名とバージョン(例: Google / Pixel 9a / Android 17)
- 画面の幅・高さ・解像度、表示言語、タイムゾーン
- アプリの名称・バージョン・ビルド番号
- ネットワークの種別(Wi-Fi/モバイル回線などの別)、エミュレータかどうか
これらは対応機種の把握、表示崩れの確認、継続率を計算する際の日付の区切りに使います。特定の個人を識別する目的では使用しません。
送信しないもの: 日記の本文・タイトル、写真、走行ルート、位置情報、曲名、氏名、メールアドレス、連絡先、広告ID、IPアドレス、通信事業者名、詳細な端末識別文字列。広告IDは取得も要求もしません。IPアドレスは送信前に取り除き、IPからの地域推定もサーバー側で無効化しています。
識別にはアプリ内部で生成した匿名IDのみを用います。このIDは端末のアプリ領域にのみ存在し、アプリの再インストールまたはデータ消去で切断され、以後は別の利用者として扱われます。人物単位のプロファイルは作成しません。
この計測は設定画面の「利用状況の共有」からいつでも停止できます。また、端末側で広告トラッキングの制限が有効な場合は、設定に関わらず送信しません。
クラッシュ情報
アプリが予期せず終了した場合に、原因を特定するための技術情報をFirebase Crashlytics(Google LLC)へ送信します。目的は不具合の発見と修正のみで、利用状況の分析や広告には使用しません。
送信する内容: エラーの種類とエラーメッセージ、プログラムのどの箇所で停止したかを示す技術的な記録(スタックトレース)、および端末のメーカー・機種名・OSバージョン・アプリのバージョン・空きメモリ量などの状態です。
送信しないもの: 日記の本文・タイトル、写真、走行ルート、位置情報、曲名、氏名、メールアドレス、連絡先。アプリの側からこれらを付け加えることはありません。また、画面の遷移履歴(どの画面をどの順に開いたか)も収集しません。
技術的な限界について: エラーメッセージはアプリが受け取った文面がそのまま含まれます。そのため、たとえば写真の読み込みに失敗した場合に、端末内の写真ファイルの保存場所を示す文字列が含まれる可能性があります。日記の本文が含まれる経路は確認されていませんが、この記録は自動的に生成されるため、内容を事前に完全に取り除くことはできません。
保存先: Crashlyticsのデータは米国のGoogleのサーバーに保存されます(保存先の国を選ぶことはできません)。前述の利用状況の匿名計測はEUリージョンを選択していますが、クラッシュ情報については選択の余地がないため、この点を明記します。保存期間はGoogleの定めにより最長90日間です。
識別子: Crashlyticsは、同一端末からの複数のクラッシュをまとめるために、インストールごとの匿名IDを自動的に生成します。これは氏名やメールアドレス等とは結び付かず、アプリの再インストールまたはデータ消去で切断されます。アプリの側から利用者を識別する情報を設定することはありません。
クラッシュ情報の送信は、利用状況の匿名計測と同じく設定画面の「利用状況の共有」で停止できます。停止した場合、端末内にまだ送信されていないクラッシュ記録があれば、それも削除されます。
選択と削除
連携と利用状況の共有は任意で、設定からいつでも解除・停止できます。端末内データはエクスポートでき、個別記録の削除、端末設定からのストレージ消去、またはアンインストールで削除できます。
問い合わせ
Haruki Privacy Policy
Last updated: September 23, 2026
Haruki keeps your run records, journal entries, photos, attachments, and music information on your device. None of it is sent to a Haruki-operated server.
External Services
Map display requests OpenStreetMap tiles. To retrieve parks, greenways, waterways, lit roads, and public toilets around the visible area, the displayed map center is sent to the Overpass API. Weather lookup uses your location. A Google Drive export sends only the data you explicitly select. Health Connect reads only the sources and fields you have authorized. Notification access is used solely for media information such as the currently playing title and artist; notification bodies are never stored.
Health data (Health Connect)
Haruki is a running journal. So that days you ran with another app or a smartwatch are not missing from it, Haruki reads your running records from Android's Health Connect — only if you explicitly connect it. Connecting is optional; GPS recording and the journal work without it.
What is read, and what each is for (no other health data is read):
- Exercise sessions — that you ran that day, and when it started and ended. Used to create the journal page.
- Distance — how far you ran. Used for the record and for your cumulative totals.
- Speed — used to work out your average pace per kilometre. It is more accurate than a phone's GPS, so it is preferred when present.
- Heart rate — read only for the span of the imported run, averaged per kilometre and drawn beside the pace for the same segments. All-day, resting and sleeping heart rate are not read.
- Total calories burned — shown on the journal page as supplementary information.
- The recorded route — used to draw the map, and only when Haruki has no route of its own for that run. It never overwrites a route Haruki recorded itself.
Speed, heart rate, calories and the route are optional. Decline them and importing still works — that detail is simply absent from the journal. Only exercise sessions and distance are required; without them there is no way to know a run happened at all.
Nothing is written. Haruki never writes to Health Connect and does not request write permission. You choose which sources (Garmin and so on) it reads, and can change that at any time.
Where it is stored: what is imported is saved in a database on your device. There is no Haruki-operated server, and health data is never sent to one. It is included in a Google Drive export only if you choose to make one — and that goes to your own Google Drive.
Reading in the background: only if you turn on "Automatic updates" does Haruki read Health Connect while you are not using the app, and only to pick up newly recorded runs. Left off, it reads only while the app is open.
Retention and deletion: imported records stay on your device until you delete them — by deleting individual records, clearing the app's storage, or uninstalling. Revoking permission and deleting stored data are two separate actions: revoking access in Health Connect does not remove records already imported onto your device. To remove those, delete the records in the app.
Revoking access: you can revoke it at any time from the Health Connect app or your device settings. You can also disconnect from Haruki's own settings screen.
Location
While the app is open: to show where you are on the map and to note the day's weather on the record. Looking up weather sends your coordinates to the weather service; showing the map sends them to the map tile provider.
During a run: to record the run's distance and route. Recording continues with the screen off. The record is saved on your device.
If "Auto-detect" is on: to notice when you start running, Haruki reads this device's location and physical activity while the app is closed and not in use, around places you registered. This feature is optional; with it off, location is read only while the app is open or a run is in progress.
Location is never sent to a Haruki server (there is no Haruki-operated server).
Exports and Google Drive backup: besides your routes, if you include "Profile and Settings", the places you registered for automatic recording (Start Point locations and addresses) are also written to the destination you choose (a folder on your device, or your own Google Drive). You can leave them out under "Export Records".
Anonymous Usage Measurement
To confirm that Haruki is actually being used, anonymous usage signals are sent to PostHog (EU region). You are not identified, and this data is never linked to personal information such as your name or email address.
Purpose. The collected information is used only for the following:
- Improving the app's screens and usability — understanding which features are actually used, so that unused paths and confusing screens can be reworked.
- Finding and fixing defects — detecting problems that occur only on particular devices or OS versions, or places where recording stops partway through.
- Deciding which devices and environments to support — determining where to prioritise testing.
It is never used for advertising, user profiling, or sale or provision to third parties.
Only four kinds of action are sent.
- That the app was opened (used to calculate day-level retention)
- That one run was recorded (whether or not, only — never distance, duration, or route)
- That journal text was written (the fact alone — never the text, title, or character count)
- Which tab was opened (list / calendar / songs / photos — never their contents)
Alongside these, basic device and app information is included:
- Device make, model, OS name and version (for example: Google / Pixel 9a / Android 17)
- Screen width, height and density; display language; time zone
- App name, version and build number
- Network type (Wi-Fi, mobile, and so on) and whether the device is an emulator
These are used to know which devices to support, to catch broken layouts, and to set the day boundary when calculating retention. They are not used to identify any individual.
Never sent: journal text and titles, photos, run routes, location, song names, your name, email address, contacts, advertising IDs, IP addresses, carrier names, and detailed device identifier strings. Advertising IDs are neither collected nor requested. IP addresses are stripped before transmission, and IP-based location inference is disabled on the server side.
Identification uses only an anonymous ID generated inside the app. That ID exists solely in the app's storage on your device; reinstalling the app or clearing its data severs it, and you are afterwards treated as a different user. No person-level profile is created.
You can stop this measurement at any time from "Usage sharing" in Settings. In addition, when your device has ad tracking limited, nothing is sent regardless of that setting.
Crash Reports
When the app terminates unexpectedly, technical information needed to identify the cause is sent to Firebase Crashlytics (Google LLC). It is used only to find and fix defects — never for usage analysis or advertising.
What is sent: the error type and message, a technical record of where in the program execution stopped (a stack trace), and device state such as make, model, OS version, app version and available memory.
Never sent: journal text and titles, photos, run routes, location, song names, your name, email address, or contacts. The app never attaches any of these. Screen navigation history (which screens you opened, and in what order) is not collected either.
A technical limitation: an error message is included exactly as the app received it. So if, for example, loading a photo fails, the message may contain the file path of that photo on your device. No path has been found by which journal text would be included, but because these records are generated automatically, their contents cannot be fully stripped in advance.
Where it is stored: Crashlytics data is stored on Google servers in the United States; the storage region cannot be chosen. The anonymous usage measurement described above uses the EU region, but for crash reports there is no such choice, so it is stated here explicitly. Google retains this data for up to 90 days.
Identifier: to group multiple crashes from the same device, Crashlytics automatically generates an anonymous per-installation ID. It is not linked to your name, email address or similar, and is severed when you reinstall the app or clear its data. The app never sets any information that would identify you.
Crash reporting can be stopped from "Usage sharing" in Settings, the same switch as the anonymous usage measurement. If you stop it, any crash records still waiting on your device are deleted as well.
Your Choices and Deletion
Connections and usage sharing are optional and can be revoked or stopped in Settings at any time. Local data can be exported, and deleted by removing individual records, clearing app storage in device settings, or uninstalling the app.