Last Updated: July 20, 2026
About Us #
| Item | Details |
|---|---|
| Business Name | ottava |
| Operator | Hiroya Onoe |
| Address | (Available upon request) |
| Contact | contact@ottava.dev |
Introduction #
ottava (“we”, “us”, or “our”) operates mobile applications and related services (collectively, the “Service”). This Privacy Policy describes how we collect, use, and share your personal information when you use our Service.
1. Information We Collect #
1.1 Information You Provide #
- Account Information: Name and email address (obtained through Apple Sign In)
- Profile Information: Classroom name, student names, and other information you enter in the App
- Chat Content: Messages sent through the in-app chat feature
1.2 Information Collected Automatically #
- Device Information: Device tokens (used for push notifications)
- Usage Data: Anonymized statistics about App usage
We currently do not use cookies or tracking technologies for advertising purposes. If we introduce tracking in the future, such as for advertising measurement, we will request your permission in advance in accordance with Apple’s App Tracking Transparency framework.
1.3 Information from Third-Party Services #
- Apple Sign In: Authentication information associated with your Apple ID
2. How We Use Your Information #
We use the collected information for the following purposes:
- Creating and authenticating your account and managing login sessions
- Displaying lesson schedules, processing absence notifications, and automatically matching and confirming rescheduled lessons
- Sending push notifications such as lesson reminders and rescheduling results
- Sending chat messages to Anthropic, PBC’s AI service for schedule adjustments and response generation
- Fixing bugs and improving usability of the App
- Responding to inquiries
- Addressing violations of our Terms of Service
3. Sharing of Information #
We do not share your personal information with third parties except in the following cases:
- With your consent
- When required by law
- With service providers (subprocessors) necessary for Service operation
The current list of our service providers (provider, purpose, location, and safeguards) is published on the Subprocessors page. Each service provider maintains data protection measures at a level equivalent to or higher than this Policy.
4. International Data Transfers #
The primary store of your personal information (Supabase) is located in Japan (Tokyo region). Separately, to provide the Service, some information is transferred to third parties located outside Japan (the United States, the EU, etc.) (pursuant to Article 28 of Japan’s Act on the Protection of Personal Information). The location of each provider is listed on the Subprocessors page.
4.1 Data Protection Regimes in the Provider Locations #
The United States does not have a comprehensive federal data protection law comparable to the EU’s GDPR or Japan’s APPI. Protection is provided through sector-specific laws (HIPAA, COPPA, etc.) and state laws such as California’s CCPA/CPRA. U.S. government agencies may access data held by U.S. companies under certain conditions pursuant to FISA Section 702 and the CLOUD Act.
The EU (Germany, Ireland, etc.) is subject to the EU General Data Protection Regulation (GDPR), a comprehensive data protection regime regarded as providing a level of protection equivalent to or higher than Japan’s APPI.
4.2 Protection Measures by Service Providers #
The protection measures taken by each service provider (certifications, encryption, data isolation, etc.) are described on the Subprocessors page.
5. Data Storage #
- Data is stored on Supabase cloud servers (Japan / Tokyo region).
- After you request account deletion, a 14-day grace period applies. If you wish to cancel the deletion (restore your account) during this period, please contact us at contact@ottava.dev. After the grace period, the deletion is carried out, and your personal information is deleted within 30 days of your request.
- When a guardian withdraws, their chat content is deleted in full after the grace period. Student information is retained under the teacher’s management as a classroom record.
- Backup data is automatically deleted after a set retention period (currently within 90 days).
- To verify that deletions are carried out properly, deletion activity is retained as an audit record containing only identifiers and processing counts, with no names or chat content.
6. Your Rights #
You have the following rights:
- Right of Access: Request disclosure of your personal information
- Right of Rectification: Request correction, addition, or deletion of inaccurate personal information
- Right to Restrict Processing: Request restriction or erasure of your personal information
- Data Portability: You can export your own data through an in-app feature
- Account Deletion: You can delete your account at any time through the in-app account deletion feature
Data exports are limited to information within your own scope of access. When a teacher exports data, it includes students’ enrollment and lesson history and chat content, but does not include guardians’ direct identifiers (such as email address or Apple ID). Guardians may separately request disclosure of their own information, including their email address, by contacting us directly.
To exercise these rights, please contact us at contact@ottava.dev. We will respond within a reasonable time after verifying your identity.
7. Children’s Privacy #
The Service handles student information, but students do not create accounts themselves. Student information is managed by teachers or guardians (adult users). Children under 13 cannot create accounts directly.
Student (child) data is registered by the teacher (an adult user) for classroom management. Teachers consent, when they register for the Service, to the handling of information across the purposes set out in Sections 2 and 3 of this policy (including AI processing by Anthropic, PBC, and push notification delivery). When a guardian links their child’s information under their own account (upon invitation acceptance), we obtain the guardian’s prior consent, as the child’s legal representative, to the handling of the child’s personal data and to the purposes set out in Sections 2 and 3 of this policy (including AI-assisted scheduling and push notification delivery). These consents are recorded as separate items by type.
8. Security #
We implement reasonable security measures to prevent unauthorized access, loss, or alteration of personal information, including:
- Encrypted communications (TLS)
- Row-Level Security (RLS) on database
- Secure management of authentication tokens
9. Changes to This Policy #
We may update this Privacy Policy from time to time. We will notify you of significant changes through in-app notifications or email. The updated policy becomes effective when posted on this page. Note that notice under this section does not substitute for the consent required under Article 28 of the Act on the Protection of Personal Information when personal data is newly transferred to a third party located outside Japan.
10. Contact Us #
If you have questions about this Privacy Policy, please contact us at:
- Email: contact@ottava.dev