プライバシーポリシー
制定日: 2026年9月28日・最終更新日: 2026年9月29日
1. 基本方針
Block & Relayは一般ユーザーのアカウントを作成せず、受動的な閲覧タイムライン、ページのパス、検索語を収集しない設計です。利用者が匿名報告に同意して自ら登録した正規化ドメインは、Appleの分類上「閲覧履歴」に該当し得るデータとして保守的に開示します。
2. 端末とiCloudに保存する情報
BLOCK設定、個人ブラックリスト、許可リスト、進行中の申請を端末内に保存します。PlusのiCloud保護バックアップは初期状態で無効です。設定で利用者が有効にした場合に限り、同じ情報を利用者のCloudKit private databaseへ保存します。未送信の匿名報告キューは端末内にのみ保存し、CloudKitへ同期しません。
3. 匿名報告
利用者が初回同意した場合に限り、正規化した登録可能ドメインとランダムな重複防止キーを審査基盤へ送信します。完全なURL、ページパス、閲覧時刻、Apple IDは報告データへ含めません。匿名報告は設定から停止できます。
4. 購入と共有フィルタ
購入はAppleのStoreKitを利用します。共有フィルタ資格の確認時にApple署名付き取引情報を検証し、取引識別子の一方向ハッシュと有効期限を資格管理のため保存します。この購入情報はPlus利用資格に紐づきますが、匿名報告とは分離して扱い、APIログにはStoreKit識別子を記録しません。共有フィルタ照会はAppleのURL FilterおよびPIRの仕組みを利用します。
5. 不正利用対策
API保護のためGoogle提供のFirebase App Checkと、Apple提供のApp AttestまたはDeviceCheckを利用します。これらの処理者が端末・通信に関する技術情報を、それぞれのプライバシー条件に基づいて処理する場合があります。当社は委託先に対して、契約その他の合理的な措置により本ポリシーと同等水準の保護を求めます。
6. 保存期間
匿名報告、異議申立て、審査結果および監査記録は、共有リストの品質維持、不正利用防止、障害調査に必要な期間保存します。不要になった情報は、法令上の保存義務がある場合を除き、安全な方法で削除または匿名化します。
7. 第三者提供と削除
法令上必要な場合を除き、取得情報を広告目的で販売しません。iCloudデータは利用者のiCloud設定から管理できます。報告・申立てに関する削除または問い合わせはサポート窓口へご連絡ください。本人または対象データを合理的に特定できない匿名データは、削除のご要望に対応できない場合があります。
8. 事業者・お問い合わせ
運営者: Eunois
Privacy Policy
Effective: September 28, 2026. Last updated: September 29, 2026.
1. Overview
Block & Relay does not create end-user accounts and is designed not to passively collect page paths, search terms, or a browsing timeline. A normalized domain that a user explicitly opts to report may conservatively be disclosed as Browsing History under Apple’s data categories.
2. On-device and iCloud data
BLOCK settings, personal blocklist and allowlist entries, and pending requests are stored on-device. Plus iCloud protection backup is off by default and stores the same data in the user’s private CloudKit database only after the user enables it in Settings. Unsent report queues remain device-local.
3. Anonymous reports
Only after opt-in, Block & Relay sends the normalized registrable domain and a random deduplication key for review. Full URLs, page paths, access times, and Apple IDs are not included. Reporting can be disabled in Settings.
4. Purchases and shared filtering
Purchases use Apple StoreKit. We verify Apple-signed transaction data and retain a one-way hash of the transaction identifier and its expiration date to manage entitlement. This purchase information is linked to Plus access but kept separate from anonymous reports, and StoreKit identifiers are not written to API logs. Shared lookups use Apple URL Filter and PIR technology.
5. Security services
Google Firebase App Check and Apple App Attest or DeviceCheck protect the API. These processors may handle technical device and connection information under their privacy terms. We require service providers, through contractual or other reasonable measures, to maintain protections consistent with this policy.
6. Retention and disclosure
Reports, appeals, review outcomes, and audit records are retained only as needed for list quality, abuse prevention, incident investigation, or legal obligations, then deleted or anonymized. We do not sell collected data for advertising. Anonymous data that cannot reasonably identify a person or submission may not be individually removable.
7. Operator and contact
Operator: Eunois — support@eunois.com