MAKASETE, Inc. (hereinafter the "Operator") establishes this privacy policy (hereinafter this "Policy") regarding the handling of user information in Repitta and its related services (hereinafter collectively the "Service").
1. The business operator handling personal information and, where applicable, the controller for the Service is:
Name: MAKASETE, Inc. (株式会社マカセテ)
Address: 23-17-408 Sakuragaoka-cho, Shibuya-ku, Tokyo 150-0031, Japan
Contact: hello@repitta.com
2. Please use the contact details above for questions concerning this Policy, the handling of User Information, or the exercise of your rights.
The Operator collects the following information through the Service. Depending on its relationship to an individual, personal information or personal data may include not only an email address, but also online identifiers, usage records, and content entered by a user.
(1) Account and authentication information
Email address provided through a Google or Apple account, the authentication provider's identifier, the user's internal Service identifier, and account creation and sign-in records. The Service may also be used with anonymous authentication without linking a Google or Apple account.
(2) Data created or shared by users
Recipes, ingredients, images, notes, meal plans, shopping lists, group participation information, and other content registered with the Service. Data used in a group is shared with members of that group.
(3) Device and technical information
Device identifiers, OS type and version, device model, app version, time zone, language settings, IP address, push notification tokens, access times, activity records, and error and crash information.
(4) Health and nutrition information
Ingredient information from recipes and meal plans registered by users and nutrition information generated from it, including calories, protein, fat, carbohydrates, vitamins, and minerals. Depending on its content and use, this information may constitute health-related data.
(5) Subscription and purchase information
Plan type, expiry date, purchase, renewal and cancellation status, store transaction identifiers, and similar information. Payment instruments such as credit card numbers are generally managed by Apple App Store, Google Play Store, or another payment provider and are not collected directly by the Operator.
(6) Inquiries and usage information
The content of inquiries, reply contact details, survey responses, advertising consent status, in-app usage, logs required for incident response, and other information provided to the Operator.
1. The Operator uses User Information for the following purposes:
(1) Providing recipe management, meal plan creation, shopping list creation, group sharing, nutrition balance checks, and other Service features
(2) Authentication, account management, synchronization between devices, and retention of user settings
(3) Billing, subscription management, and prevention of fraudulent purchases
(4) Security, prevention of improper or unauthorized use, incident response, and defect correction
(5) Analysis of usage, improvement of Service quality, and consideration of new features
(6) Responding to inquiries, providing necessary Service communications, and handling legal claims
(7) Displaying advertisements to free users and managing advertising consent
(8) Keeping data shared within a group available to other group members
2. Where the laws of the EEA, the United Kingdom, Switzerland, or a similar jurisdiction apply, the Operator relies, as appropriate to the processing, on performance of a contract; the legitimate interests of operating and improving the Service securely and preserving collaboration with other group members; compliance with legal obligations; or consent. Advertising and other processing that requires consent under applicable law is performed after the required consent has been obtained. A user may withdraw consent to future processing at any time.
3. Nutrition information is used to provide and improve the nutrition balance check feature and is not sold to advertising businesses. Where applicable law treats such information as a special category of personal data and requires consent or another condition, the Operator will process it only after confirming the required legal basis. The Service is not intended to provide medical diagnosis or treatment.
1. The Operator does not disclose User Information to a third party except:
(1) With the user's consent
(2) To a service provider to the extent necessary to provide the Service
(3) As required by law or by a court, supervisory authority, or competent public authority
(4) Where necessary to protect a person's life, body, or property and obtaining consent is difficult
(5) Where necessary to respond to misuse or protect the rights of the Operator, users, or a third party
(6) In connection with a merger, corporate split, business transfer, or other business succession
2. The Operator primarily uses the following providers and services. The information sent to a provider varies depending on the feature used and the user's settings.
- Google LLC (including Firebase and Google Cloud): authentication, databases, storage, analytics, crash reporting, push notifications, infrastructure, and AI features
- Google AdMob and advertising mediation partners (including Pangle): in-app advertising, consent management, and advertising measurement
- Apple Inc. and Google LLC: app distribution, in-app purchases, and payments
- RevenueCat, Inc.: subscription and entitlement management
- Stripe, Inc.: web-based subscriptions and payments
- OpenAI, L.L.C. and Google Vertex AI: AI features based on recipes or ingredients
- Cloudflare, Inc.: content delivery and storage
- Slack Technologies, LLC: inquiries and operational communications
3. The Operator requires providers, through provider selection, contracts, and other appropriate means, to process information consistently with the relevant purposes and security requirements. Where an advertising provider or another provider processes information independently, that provider's privacy policy may also apply.
The Operator may process User Information in Japan, the United States, and other countries in which its providers or their servers are located. When personal data is transferred from the EEA, the United Kingdom, Switzerland, or a similar jurisdiction to another country, the Operator uses an adequacy decision, standard contractual clauses, a data protection agreement with the provider, or another safeguard permitted by applicable law, as appropriate to the destination and processing. Information about the applicable safeguards may be requested using the contact details in Article 1.
1. When a user deletes an account, the Operator deletes the authentication account from Firebase Authentication. This removes the association in the authentication service between that account and the email address obtained from the linked Google or Apple account, and the user can no longer sign in to that account.
2. Recipes, meal plans, shopping lists, and similar data are collaborative data that other group members may create, edit, or access. Accordingly, after a user deletes an account, such data may be retained to the extent necessary for continued use by other group members, data integrity, and operation of the Service. The Operator does not use this shared data to contact or authenticate the former user.
3. Shared data may retain an internal Service identifier to preserve relationships between data, creation or update history, or access controls. After deletion of the authentication account, the Operator does not use that identifier for the purpose of re-associating the former user's email address. However, information that may relate to an individual when combined with other information is handled in accordance with applicable law.
4. Account information is generally retained until account deletion; shared data is retained while other group members use it or as necessary to provide the Service; and purchase records, inquiry records, and security logs are retained as necessary for legal obligations, dispute resolution, fraud prevention, and system operation. Information in backups is overwritten or deleted according to the applicable backup cycle. When information is no longer required, the Operator deletes it or disassociates it from the individual, unless retention is required by law.
5. A user may request deletion of, or disassociation from, particular shared data relating to the user by using the contact details in Article 1. The Operator will consider the request in accordance with applicable law, taking into account the requester's rights, the rights of other group members, legal obligations, and the nature of the data. The right to erasure may be subject to exceptions under applicable law.
1. Subject to applicable law, a user may request access to, correction or completion of, deletion or erasure of, restriction or suspension of processing of, objection to the processing of, and portability of the user's personal information or personal data. The Operator will verify the requester's identity and respond within the period and by the method required by applicable law.
2. Where processing is based on consent, a user may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
3. A user in the EEA, the United Kingdom, Switzerland, or a similar jurisdiction may lodge a complaint with the data protection supervisory authority having jurisdiction over the user's habitual residence, place of work, or the place of the alleged infringement.
4. Where processing is based on legitimate interests, a user may object on grounds relating to the user's particular situation. If direct marketing is conducted, the user may object to processing for that purpose at any time.
1. Providing User Information is generally optional. However, if information required for authentication, synchronization, payment, or another feature is not provided, the relevant feature may be unavailable.
2. The Service may use AI to generate nutrition information or other suggestions, but it does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on a user.
The Operator takes necessary and appropriate measures to prevent leakage, loss, or damage of User Information and otherwise protect it, including access controls, protection of communications, and management of service providers.
1. The Operator may update this Policy in response to changes in law, Service features, or the handling of User Information. Material changes will be notified in the Service or by another method the Operator considers appropriate. Where consent is required by law, the Operator will obtain the required consent.
2. This Policy is effective as of August 12, 2026.