Emopi

Privacy Policy

Effective date: August 1, 2026

This is an English translation provided for convenience. The Japanese version (プライバシーポリシー) is the official text; if there is any conflict between the two, the Japanese version prevails.

1. Introduction

Pluralworks LLC ("we," "us," or "our") provides Emopi, an AI-powered app for self-care and communication with the people you care about (the "Service"). We treat the protection of our users' personal information and privacy as one of our highest priorities.

By its nature, the Service holds highly sensitive information about your feelings and your physical and mental state. This Privacy Policy (this "Policy") explains what information we collect, how we use it, and what we do not share. Please read this Policy carefully before using the Service.

We comply with Japan's Act on the Protection of Personal Information (APPI), the Telecommunications Business Act and other Japanese laws, and, where applicable, the GDPR (EU General Data Protection Regulation), the CCPA (California Consumer Privacy Act), and other privacy laws.

2. Business Operator Information

In accordance with the APPI, we disclose the following information about our company.

  • Name: Pluralworks LLC
  • Address: 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
  • Managing Member: Takahiro Ikeuchi

3. Definitions

The following terms are used in this Policy.

  • Pair: the relationship between two users connected by mutual consent through the Service's invitation feature.
  • Content: any data you enter into the Service, including journal entries, messages, and inputs about your feelings and state.
  • AI-Generated Information: information the Service's AI features generate from Content and other data, such as summaries, condition indicators, suggestions on how to phrase things, and hints.
  • Sharing Settings: the settings by which you choose which of your mood, energy, and care hints are shared with the other member of your Pair.

4. Information We Collect

4.1 Information you provide directly

  • Account information: email address, nickname, password hash, profile image, date of birth, gender, language, time zone, display preferences, and similar information. If you choose Sign in with Apple or Google, this also includes the provider-issued identifier, email address, name, and other information you authorize the provider to share.
  • Content: journal entries, conversations with the AI, messages, and inputs about your feelings and state. Because these are free-form, Content may include information about your medical history, hospital visits, medication, or other health conditions, which qualifies as special care-required personal information under the APPI. We design and operate the Service on the assumption that such information may be included. We disclose this through this Policy and other in-app notices and collect information you voluntarily enter with your consent. We do not provide data that may contain special care-required personal information to third parties on an opt-out basis.
  • Inquiry information: the reply-to email address and content of messages you submit through our website or app to support, and your feedback. For support handling, we send this information to our support mailbox through an external email delivery service.
  • Connection and safety information: invitations, connections, Sharing Settings, blocks, reports, optional safety comments, and the status of our response.

4.2 Information generated in the course of providing the Service

  • AI-Generated Information (derived data): condition indicators, summaries, phrasing suggestions, hints, and similar information the AI generates from your Content.

4.3 Information collected automatically

  • Device and log information: IP address, OS type and version, device information, app version, and access timestamps.
  • Behavioral logs: to improve service quality, we may record screen transitions and interaction events using tools such as PostHog. What you write — journal entries, messages, and other inputs — is excluded from behavioral log collection or masked (redacted).
  • Identifiers: we use cookies or similar technologies and identifiers issued by us for users and devices to keep you signed in, store consent state, and analyze usage.
  • Notification and device-protection information: push notification tokens, notification settings, device platform, and public keys, device names, and other technical information required to encrypt Talk and manage authorized devices.

4.4 Payment information

Payments for paid plans are processed through App Store or Google Play in-app purchases. We do not directly collect or store your credit card information. From the Stores and RevenueCat, we receive and use product IDs, purchase, renewal, cancellation, and refund status, expiration, trials, billing issues, the originating Store, Store transaction identifiers, and similar information associated with the user ID we issue to confirm and manage access.

5. Purposes of Use

We use the personal information we collect for the following purposes.

5.1 Providing and operating the Service

  • User authentication and account management
  • Providing features such as the journal, condition indicators, and messages
  • Generating AI-Generated Information (see Section 6)
  • Sharing information with the other member of your Pair according to your Sharing Settings
  • Managing paid-plan purchases, access, trials, and purchase restoration
  • Providing push notifications, real-time updates, and app updates

5.2 Service improvement and development

  • Analyzing usage (such as improving the UI based on interaction logs)
  • Planning and developing new features, and fixing bugs

5.3 User support

  • Responding to inquiries, communicating about incidents, and sending important notices

5.4 Security

  • Detecting and preventing unauthorized access, spam, and violations of the Terms of Service, responding to reports, and conducting audits

5.5 Marketing

  • Sending information about our services (only with your consent)

5.6 Limitation to the stated purposes

We use personal information only within the scope of the purposes above. If we need to use it in a way incompatible with these purposes, we will obtain your prior consent or follow applicable law.

6. AI Processing and Handling of Content

Before we begin sending information to an external AI service, we display the recipient, the information sent, the purpose, and other material details, and obtain your explicit consent. Consent to external AI processing is required to use the Service. If you do not consent or withdraw consent, you cannot use the Service and can only sign out or delete your account. Withdrawing consent alone does not delete records already stored. You can withdraw consent at any time in the app's settings.

  • What the AI processes: we process Content with AI to generate AI-Generated Information such as summaries, condition indicators, and phrasing suggestions.
  • Use of external AI services: for AI processing, we may send all or part of your Content, relevant conversation context, and processing metadata to OpenAI's API to generate AI-Generated Information and perform safety checks. We treat this processing as an entrustment within the scope necessary to achieve the purposes of use and appropriately supervise the provider.
  • Model training and retention: we use OpenAI's API under terms that do not allow data we submit to be used to train or improve OpenAI's AI models, including large language models (LLMs), unless we explicitly opt in, and we do not make that opt-in for Content. Under OpenAI's standard API data practices, inputs and outputs included in abuse-monitoring logs may be retained for up to 30 days. This may differ based on the feature, our contract and settings, or legal requirements.
  • Limits on sharing with your Pair: journal entries and conversations with the AI are not shared with the other member of your Pair through the Service. The information shared with them is limited to the mood, energy, and care hints you select in your Sharing Settings.
  • No advertising use: we do not use your Content or AI-Generated Information for advertising, and we do not sell it to third parties.
  • Limits on human access: our staff do not read the body of your Content except for security investigations, report or support handling, legal compliance, or with your explicit consent. Limited access by an external provider is governed by that provider's contract and privacy policy.

7. Disclosure Regarding External Transmission

In accordance with the Telecommunications Business Act, we disclose the principal information transmitted from your device to external providers, the recipients, and our purposes. Each recipient may also handle information to provide and secure its service, prevent abuse, and comply with law under its own terms and privacy policy.

  • PostHog (PostHog Inc.): a non-guessable user ID issued by us; IP address; OS, device, and app information; app lifecycle; screen names consisting only of route categories without dynamic dates or IDs; and event type, character counts, source, and similar metadata, for product analytics and UX improvement. We do not send the body of journals, Talk, drafts, AI-Generated Information, or other Content. We do not use session recording.
  • Google Fonts (Google LLC): only when you visit our website at www.emopi.app, your IP address, the requested font URL, browser and OS information, referring page, and similar request information are transmitted to display text and provide font delivery and security. Google Fonts is not used in the mobile app.
  • RevenueCat (RevenueCat, Inc.): a non-guessable user ID issued by us; device and OS information; product information; Store receipts or purchase tokens; and purchase, renewal, cancellation, refund, trial, and similar transaction data, to display products, process and restore purchases, and manage access.
  • Supabase (Supabase, Inc.): a user ID issued by us, information identifying real-time subscription topics, connection metadata, IP address, and similar information, to provide Pair updates and other real-time features.
  • Expo (650 Industries, Inc.): if you allow notifications, the push token; OS; project ID; a random installation identifier used to check for app updates; fixed notification copy; and internal identifiers used to open the destination screen, to deliver push notifications and EAS Update app updates. We do not include journal or Talk text in notifications.
  • Apple Inc. / Google LLC: if you choose the provider's sign-in, authentication requests, device and app information, and required account information; if you use in-app purchases, product and transaction information; and if you allow push notifications, information required for delivery, for authentication, payment, purchase management, and notification delivery.

Product analytics through PostHog may be disabled depending on the app environment and our configuration. You can disable notifications in your device settings and withdraw consent to external AI processing in the app. If you disable communications essential to the Service, the corresponding feature may not work. We update and publish this Policy when there is a material change to a recipient or transmitted information.

8. Provision to Third Parties, Entrustment, and Joint Use

8.1 Restrictions on provision to third parties

Except as permitted by law, we do not provide personal data to third parties (including selling or lending it) without your prior consent.

8.2 Entrustment

Within the scope necessary to achieve the purposes of use, we may entrust all or part of the handling of personal data to external parties (such as cloud service providers, AI service providers, email delivery service providers, and analytics tool providers). In such cases, we exercise necessary and appropriate supervision over these parties.

Our principal current external services are listed below.

  • OpenAI (OpenAI, L.L.C.): AI generation and safety checks. It handles Content, relevant context, and processing metadata.Privacy Policy
  • Supabase (Supabase, Inc.): database, file storage, and real-time communications. It handles account information, Content, AI-Generated Information, connection and Sharing Settings, reports, inquiries, purchase status, and other Service data.Privacy Policy
  • Render (Render Services, Inc.): hosting for APIs, background processing, job queues, caches, and operational logs. It processes information sent to the Service as needed to provide it.Privacy Policy
  • Cloudflare (Cloudflare, Inc.): delivery of the website, API, and links; DNS; communications security; and protection against unauthorized access. It handles IP addresses, communications headers, access logs, and requests and responses passing through it for delivery.Privacy Policy
  • PostHog (PostHog Inc.): product analytics. It handles the user ID, device and app information, screen categories, and interaction events described in Section 7.Privacy Policy
  • Google Fonts (Google LLC): web-font delivery on www.emopi.app (not used in the mobile app). It handles the IP address, requested URL, browser and OS information, referring page, and similar request information described in Section 7.Privacy and data collection
  • RevenueCat (RevenueCat, Inc.): in-app purchases and access management. It handles user ID, device information, and product, transaction, and subscription information.Privacy Policy
  • Resend (Plus Five Five, Inc.): delivery of authentication codes and support notifications. It handles recipient email addresses, authentication codes, support reply-to addresses and message text, and device information you choose to attach. Safety-report notifications contain only the report ID and no report text.Privacy Policy
  • Expo (650 Industries, Inc.): app builds and updates and push delivery. It handles the push tokens, fixed notifications, OS, project ID, update-check identifiers, and similar information described in Section 7. Notifications are delivered through Apple Push Notification service or Firebase Cloud Messaging.Privacy Policy
  • Apple Inc. / Google LLC: the social sign-in you choose, distribution, billing, refunds, and purchase management through App Store or Google Play, and OS push delivery. We do not collect credit card information.Apple Privacy Policy/Google Privacy Policy
  • Slack (Slack Technologies, LLC): operational status and incident notifications. We send only limited operational information, such as service, environment, event category, and time. We do not send user IDs, email addresses, names, Content, inquiry text, transaction identifiers, or other user data.Privacy Policy

8.3 Sharing through the Pair feature

The mood, energy, and care hints you select in your Sharing Settings are shared with the other member of your Pair. Journal entries and conversations with the AI are not shared with the other member of your Pair through the Service.

8.4 Provision to third parties in foreign countries

We may entrust personal data to providers in the United States and other countries, or process personal data on servers in foreign countries. In those cases, in accordance with Article 28 of the APPI and other applicable law, we obtain consent where legally required or confirm an arrangement that continuously implements equivalent safeguards through provider agreements, data processing agreements, standard contractual clauses, or other means. To request information about a foreign legal system, safeguards implemented by a provider, or other information required by law, contact us under Section 14.

8.5 Where data is stored

Your data may be stored and processed in cloud regions we select and on servers operated in the United States or other countries by external providers or their subprocessors. Locations may change based on service configuration, resilience, support, and provider subprocessors.

9. Your Rights

Subject to the requirements and procedures of the APPI and other applicable law, you may make the following requests concerning personal data we hold about you.

  • Disclosure, correction, and deletion: the right to request disclosure of your personal data (including electromagnetic records) and correction, addition, or deletion of its content.
  • Suspension of use and erasure: the right to request suspension of use, erasure, and suspension of provision to third parties.
  • Data portability: the right to receive your personal information in a structured, machine-readable format where the GDPR, CCPA, or another applicable law grants that right.
  • Withdrawal of consent: the right to withdraw consent at any time for processing based on consent.
  • Account deletion: the right to delete your account and data from the in-app settings or by contacting us. For the steps and the scope of deletion, seeAccount Deletion.
  • No detrimental treatment: we do not treat you in an unjustly discriminatory manner for exercising your rights.
  • Rights of residents of Europe and the United States:where the GDPR, CCPA, or another regional law applies to us or to you, you may exercise rights granted by that law, such as access, correction, deletion, restriction, objection, opt-out, or lodging a complaint with a supervisory authority. We do not sell personal information for money or "share" it for cross-context behavioral advertising as defined by the CCPA.

To exercise your rights, please contact us using the contact information in Section 14. We verify the identity of the requester or authorized agent and respond in accordance with law. Where permitted by law, we may be unable to satisfy all or part of a request; if so, we explain the reason where possible.

10. Security Measures

We take the following measures to prevent the leakage, loss, or damage of personal information.

  • Encryption of communications (SSL/TLS).
  • For journal entries, conversations with the AI, certain prose-form derived information, safety reports, push tokens, and database copies of in-app support requests, application-layer encryption at rest (AES-256-GCM) in addition to encryption in transit.
  • For Talk messages sent after the connection's E2E keys are available on supported devices, end-to-end encryption between devices, with ciphertext stored on our servers that we cannot decrypt. Messages sent before E2E keys are ready, and messages using the earlier method, are protected at rest with AES-256-GCM application-layer encryption and can be decrypted by our systems where necessary to provide and operate the Service.
  • Password hashing with Argon2id and encryption of stored OAuth tokens.
  • Role-based access controls, separation of credentials and production environments, and monitoring of access logs.
  • Exclusion and masking of user input in behavioral log collection.
  • Restricted support-mailbox access, vendor selection and review, contractual controls, and incident-response procedures.
  • Security training for development and operations staff.

11. Account Deletion and Retention Period

11.1 Deleting your account

You can delete your account at any time from the in-app settings. If you can no longer access the app, you can request deletion by the method described on theAccount Deletion page.

11.2 Scope of deletion

When you delete your account, the following data is deleted from our Service database.

  • Account information (email address, nickname, profile image, and similar data)
  • Journal entries and the full text of conversations with the AI
  • Derived data such as AI-Generated Information (condition indicators, summaries, care hints, and similar data)
  • Sharing Settings, Pair connections, and Talk within connections
  • External AI processing consent history and safety reports submitted by the User
  • Push notification tokens
  • In-app support requests stored in our database

After account deletion, the analytics identity on the device is reset. However, content-free events previously sent to PostHog, Store and RevenueCat transaction records, and records retained for legal or security reasons may remain under each provider's retention period or Section 11.3.

11.3 Retention period and limited retention

We retain personal information for the period needed to achieve its purpose or for the period required by law. We determine retention by the information type, purpose, sensitivity, legal and contractual requirements, the need to respond to misuse or disputes, and provider settings. When an account is deleted, we delete personal information used for ordinary service delivery, and copies in backups are removed over the normal backup rotation.

Copies of website or in-app support requests already delivered to our support mailbox are not automatically deleted at the same time as the account. We retain them only as long as needed to provide support and delete them when they are no longer needed.

We may retain the minimum information necessary to comply with law, preserve transaction records, prevent misuse, investigate security, exercise rights, or resolve disputes—such as purchase and refund records, and access and operational logs—only for as long as needed for that purpose. API inputs and outputs sent to OpenAI may be retained for up to 30 days under its standard practices.

11.4 Information on devices, Stores, and external accounts

Deleting an account and canceling an App Store or Google Play subscription are separate procedures. Deleting an account does not automatically cancel a subscription; cancel it from the management screen of the Store where you purchased it. Apple or Google accounts, Store purchase history, and information in device backups are not deleted as part of deleting an Emopi account.

12. Our Promises

Because the Service holds records of your feelings, we make the following promises about how we handle its data.

  • Your journal is yours alone. Journal entries are not read by the other member of your Pair, nor by our staff (except where operationally necessary). We send them to AI only to generate AI-Generated Information and perform safety checks, and they are not used to train or improve AI models, including LLMs.
  • We never use data about your feelings for advertising. We never sell it.
  • Privacy and safety are never paywalled. The free plan includes the same privacy protections and safety features.
  • AI never speaks for you. You decide everything that is shared or sent. AI only makes suggestions.
  • Emopi is not a tool for surveillance. You can quietly stop sharing at any time, and the other member of your Pair is not notified that you stopped.
  • The Service is not a medical service. It does not diagnose or treat any condition. If you continue to feel unwell, we encourage you to consult a doctor or other professional.

13. Changes to This Policy

We may change this Policy in response to changes in law, the Service, or the external providers we use. We post the changed terms and effective date in the Service or on our website. For a material change, we provide notice before it takes effect through an in-app notice, email, or another appropriate method. If law requires new consent, we obtain it before beginning the changed processing.

14. Contact

For questions about this Policy, or complaints and consultations about the handling of personal information, please contact us at:

Pluralworks LLC
Personal Information Protection Manager
Email: support@emopi.app

The official text of this Privacy Policy is the Japanese version. If there is any conflict between a translated version and the Japanese version, the Japanese version prevails.

← Back to home