1. Operator and scope
WatchMemory is provided by Nihon Kanun K.K. (“we,” “us,” or “our”). This policy applies to the WatchMemory iPhone and iPad app, related cloud processing, and support.
- Operator: Nihon Kanun K.K. (日本冠雲株式会社)
- Address: Sunrise Building 1026, 2-4-11 Kitahorie, Nishi-ku, Osaka 550-0014, Japan
- Contact: [email protected]
2. Data and purposes
When you start a recording, the app handles audio files, recording times, device information, transcripts, anonymous speaker labels, per-segment summaries, events and action items, links from each result to its source text and audio, settings, and deletion state. The app uses this data to save recordings, transcribe speech, distinguish speakers, present a daily view, play the original audio for each segment, search, send local notifications, synchronize paired devices, and perform the AI processing you select.
The app has no account registration, advertising SDK, advertising identifier, or behavioral tracking. We do not sell recording content for advertising.
3. On-device storage, transcription, and paired-device transfer
- Recordings and processing results are kept in protected app storage. WatchMemory storage directories are excluded from system backups.
- Transcription uses Apple Speech resources installed on the device. Speaker separation uses FluidAudio/Core ML models on the device. Required model assets are downloaded from Apple or Hugging Face, but those download requests do not include your audio or transcript.
- Apple Watch support is paused in the current iPhone/iPad app. Existing Watch recordings and pending transfers are preserved; the current app does not initiate paired-device synchronization.
A recording may include another person’s voice. You are responsible for confirming any notice, consent, or other authority required where you record.
4. Core Spotlight search
The app adds transcript text, record titles, dates, and internal source identifiers to the iPhone Core Spotlight index. This supports in-app search and, depending on device settings, system Spotlight results. The index stays on the device and uses a protection class that makes it available after the first device unlock. Deleting a record also schedules its index entries for deletion, although paired-device transfer and system indexing may take time.
5. Privacy Mode and Apple Private Cloud Compute
Privacy Mode prioritizes conversation privacy. After you consent, only the transcript text, timestamps, speaker numbers, and source references needed for a summary are processed by Apple Private Cloud Compute (PCC). Raw audio is not sent to AI services, and this route does not pass through our relay. Search runs on the device: neither search terms nor matching content is sent to an AI service, and search does not generate AI answers.
Apple states that PCC request data is used only to fulfill the request and is not retained after the response. See Apple’s PCC technical overview and Privacy Policy.
6. Power Mode, Cloudflare, and OpenAI
Power Mode offers more precise analysis with encrypted data transfer. After explicit consent and verification of an active Plus monthly or annual subscription, the transcript text, timestamps, speaker numbers, and source references needed for a summary pass through our Cloudflare-hosted relay to OpenAI. Text may itself contain personal information. Raw audio, local voiceprints, person names stored in the speaker library, and contact mappings are not sent as separate data. Essential supports recording and Privacy Mode summaries; Plus also supports Power Mode. Viewing, local search, export, and deletion of existing content remain available after a subscription expires.
- The relay processes an Apple-signed transaction, current subscription status, a subscription-derived identifier, usage count, concurrent work state, and an IP address for abuse prevention and rate limiting.
- Our relay does not persist request or response bodies and does not write those bodies or upstream exception details to application logs. Session tokens expire after 15 minutes. Usage counts and temporary work state are deleted approximately 30 days after the last use.
- Requests to OpenAI disable storage. OpenAI states that API data is not used for model training by default. Standard abuse-monitoring logs may be retained for up to 30 days, prompt caching may retain data for up to 24 hours depending on configuration, and legal or safety exceptions may apply.
See the Cloudflare Privacy Policy and OpenAI API data controls.
7. Service providers and international processing
- Apple: Speech assets, Core Spotlight/PCC, StoreKit, APNs, and transaction-status verification
- Cloudflare: Power Mode relay hosting, transport protection, and rate limiting
- OpenAI: Power Mode summary generation
- Hugging Face: distribution of public model files used for on-device speaker separation; no recording or transcript is included
Depending on each provider’s infrastructure, network information and the data described above may be processed outside Japan.
8. Retention, deletion, and withdrawal
- On-device recordings, transcripts, summaries, and Spotlight entries remain until you delete the record or remove WatchMemory from the relevant device. Deleted items move to Recently Deleted until restored or permanently removed. Shared audio is removed only after its final reference is permanently deleted. The app shows a retry state if cleanup fails.
- You can change your mode or withdraw Power Mode consent in Settings. After withdrawal or a switch to Privacy Mode, the app stops new Power requests and attempts to cancel current work. Data already sent remains subject to the recipient’s retention rules.
- Changing modes does not by itself resend past recordings. You can stop subscription renewal in Apple’s subscription management screen.
9. Permissions and choices
The app explains and requests microphone access, notifications, and AI-processing consent when needed. It will not start recording without microphone access. Declining notifications does not prevent saving or viewing recordings. Declining AI processing does not prevent recording and on-device storage.
10. Security
We use on-device file protection, HTTPS, short-lived session tokens, Apple signature and current-subscription checks, request-size limits, rate limiting, and error handling that excludes content. No storage or transmission method can guarantee absolute security.
11. Contact and requests
Most app content stays on your device. If we do not hold a recording body, we cannot search for or delete it on our side; use the app’s deletion controls for on-device data. To request access, correction, restriction, or deletion of support information, subscription-usage information, or other personal data we hold, contact [email protected]. We may verify your identity where required by law.
Daily reminders and automatic summaries
Automatic processing applies to new recordings after activation and checks your current consent and subscription before processing. It does not automatically reprocess historical recordings. Background processing is best effort; Privacy Mode summary generation requires the app to stay open. A daily reminder, at 21:00 local time by default or your chosen time, helps you open the app and continue.
The Cloudflare reminder service receives an Apple-signed transaction for subscription verification, a random installation identifier, an APNs token, the reminder time and UTC offset. It receives no recordings, transcripts, summaries, search terms or recording identifiers. Signed transactions are not persisted. Registrations expire within seven days and may be renewed while work is pending; completion, withdrawal, an invalid subscription or an invalid token triggers removal. Apple delivers the notification through APNs.
Speaker voiceprints, person names, contact mappings and selected contact thumbnails stay on the device. Existing contact photos are read only with existing permission; showing an avatar does not request new contact access.
12. Updates
If we materially change the data types, purposes, recipients, or retention described here, we will update this page and notify you in the app when appropriate. Changes that require new consent will not take effect for that processing until consent is obtained.
Effective and last updated: September 20, 2026