隐私政策
最后更新:2026 年 8 月 3 日
本政策适用于 SWTLOVE 品牌在 swtlove.com 提供的「由纪的闺房」及其相关账号、游戏、支付和客服功能(以下称“本服务”)。“SWTLOVE”“我们”指本服务的运营方和数据控制方。我们通过第 10 节列明的专用业务渠道处理隐私事项,不要求用户向开发者个人邮箱、住址或私人账号发送资料。
本政策按本服务当前实际数据流编写,说明我们处理哪些信息、处理目的、共享对象、跨境传输、保存方式,以及你可提出的请求。第三方服务商也会依其自身条款和隐私政策处理其直接取得的信息。
面向成年人的服务。本服务包含面向成年人的剧情与亲密向内容,仅供 18 周岁及以上人士使用。我们不面向儿童提供服务,也不会有意收集未满 18 周岁者的个人信息。详见《服务条款》。
1. 我们收集哪些信息
1.1 账号信息
- 电子邮箱地址。这是注册时主动要求的唯一直接联系标识,用于注册和登录。本服务不设置密码。
- 一次性登录验证码。6 位数字。我们不保存验证码明文,数据库中只保存不可直接使用的校验值;验证码 10 分钟后失效,验证成功即删除,连续输错会被锁定并触发限流。
- 登录会话。登录成功后我们在你的浏览器写入会话 Cookie;服务器只保存令牌校验值与过期时间,默认最多有效 30 天。
1.2 你在游戏中产生的内容
- 聊天与剧情消息:你输入的每一条消息以及 AI 的回复,会按“账号 + 剧本”存入我们的数据库,用于让角色记住上下文、恢复进度与修复记忆。单条消息最长保存 24,000 个字符。
- 剧情记忆与人物关系:由对话自动提炼的摘要、记忆节点与关系图、角色好感度与亲密度事件记录。
- 角色与偏好设定:你为自己设定的称呼、性别、扮演身份、当前剧本、界面语言、主题与音频开关等。
虚构的成人剧情本身不一定是关于你的敏感信息;但你主动输入的内容可能披露或使人推断你的性生活、性取向、健康状况或其他受特别保护的信息。提供游戏服务不要求你披露这些资料,请避免把现实中的敏感信息写入剧情。本服务目前没有单独的敏感信息明确同意闸门;在完成适用地区的合规确认前,不应把聊天框当作提交现实敏感信息的渠道。
1.3 经济与交易信息
- 钱包余额(金币、钻石、代金券、抽卡券)、探索值余额与每日免费额度、已购买的服装与技能、已装备项、每日领取记录。
- 充值订单:订单号、商品档位(SKU)、钻石数量、金额(以“分”为单位的整数)、币种(AUD)、支付渠道、渠道单号、订单状态与时间戳。
- 退款与冲正流水、首充奖励记录,以及封禁记录(如发生)。
1.4 支付信息
我们不通过本服务收集、查看或存储完整银行卡号、CVV 或网上银行凭据。银行卡付款由 Stripe 的托管结账页处理;在 USDT 入口启用时,加密货币付款由 NOWPayments 的托管页面处理。我们会保存履约、退款、对账与反欺诈所需的订单号、商品档位、金额、币种、支付渠道、支付会话或发票引用、客户引用(如由渠道创建)、付款/退款/争议状态、渠道事件 ID 与时间戳。
1.5 技术与使用信息
- 网络与安全信息:应用数据库不保存原始 IP,而是即时生成带密钥的哈希桶,用于限流、验证码防滥用与安全控制。作为网络和托管服务商,Cloudflare 仍可能在网络层处理原始 IP、请求头和请求日志。
- 使用量统计:按账号按天记录请求次数、输入与输出字符数,用于额度控制与容量规划。
- 第一方产品分析:我们会向同源接口记录页面打开、登录流程、剧情使用、额度消耗、商城和结账漏斗等事件,以及事件时间、随机设备/会话标识、内部账号 ID(登录时)、界面语言、粗略时区、有限的功能属性和首触广告归因参数(如 UTM、gclid、fbclid、ttclid)。该事件系统会过滤邮箱、聊天正文、昵称、令牌和验证码;它不是第三方广告像素,并会尊重浏览器的 Do Not Track 设置。
- 服务器与网络日志:Cloudflare 作为我们的托管与网络服务商,会按其自身政策处理网络层日志。
1.6 保存在你自己设备上的数据
浏览器的 Cookie、localStorage 与 sessionStorage 用于登录会话、界面语言与主题、游客设备标识、试玩计数、本地聊天备份与部分存档、分析事件缓冲、会话标识和首触归因。部分内容仅保留在设备上;为登录、同步、恢复进度或第一方分析所需的部分会发送到本服务。清除浏览器数据会删除设备副本,但不会自动删除已经同步至服务器的记录。
2. 我们不收集什么
注册和游戏功能不要求真实姓名、住址、电话号码、政府签发的身份证件、精确定位或生物识别信息;请不要主动在聊天或普通客服邮件中提供这些资料。支付服务商可能为履行其法律或风控义务直接向你收集额外信息,该等信息由服务商依其政策处理。本服务目前不部署 Google Analytics、Meta Pixel 等第三方广告追踪器,也不出售或出租个人信息;但会运行第 1.5 节所述的第一方产品分析。
3. 我们为什么使用这些信息
- 提供服务本身:登录、维持会话、生成剧情回复、保存进度与角色记忆。
- 履行合同:交付你购买的虚拟货币与虚拟物品。
- 运营与改进:衡量功能和结账漏斗、排查故障、规划容量并改进用户体验。
- 安全与合法利益:反滥用、反刷号、限流、反欺诈、争议处理与系统防护。
- 法定义务:保存交易与账务记录,以满足澳大利亚税务与对账要求。
在适用法律要求说明处理依据的地区,我们会根据具体场景依赖履行与你的合同、遵守法律义务、我们或第三方的合法利益,以及在法律要求时取得的同意。你可以撤回基于同意的处理,但不影响撤回前处理的合法性。
4. 我们与谁共享(第三方与跨境传输)
我们不出售你的个人信息。我们只在提供服务所必需的范围内与下列服务商共享:
DeepSeek(深度求索)
共享内容:你输入的聊天内容、剧情上下文、角色设定与系统提示词
目的:生成 AI 剧情回复
处理地区:中国大陆
角色说明:我们决定从本服务收集哪些终端用户数据以及为何传输,并对本政策中的披露负责。DeepSeek 面向其自有服务用户的一般隐私政策不适用于我们在本应用内收集的终端用户数据。
Stripe
共享内容:邮箱、订单金额、币种、商品描述、本地订单引用及防欺诈所需的技术信息
目的:处理银行卡付款、退款、争议与收据
处理地区:Stripe 及其关联方和分包商运营所在的国家或地区
NOWPayments
我们发送:订单标识、金额、币种与回跳/通知所需的技术引用
目的:在该付款方式启用并由你选择时,处理 USDT-TRC20 加密货币付款
处理地区:NOWPayments 及其服务商运营所在的国家或地区
渠道直接收集:付款与钱包地址、交易资料、IP/设备/使用信息;遇到风险或法律要求时,还可能直接要求 KYC/AML 身份资料。此类资料不等于由我们取得,适用结账页显示的实体及其隐私通知。
Cloudflare
共享内容:网络请求、静态资源、数据库(D1)内容、登录验证码邮件
目的:网站托管、CDN、数据库存储、发送验证码邮件
处理地区:全球边缘节点
我们也可能在法律要求、保护用户或本服务安全、处理欺诈或支付争议,或发生受保密义务约束的业务重组时披露必要信息。我们不会为第三方的独立营销目的出售聊天内容或账号资料。
关于 AI 处理的重要提示:你使用聊天功能时,我们会把你提交的文字、生成回复所必需的相关对话上下文、角色设定和提示发送给位于中国大陆的 DeepSeek 开放平台。供应商可能为提供、保护和排查 API 进行短期缓存或日志处理;具体期限受技术机制及合同安排约束,我们不承诺供应商即时删除或不留存。
请不要在聊天中输入你的真实姓名、住址、银行卡号、身份证件号或其他敏感个人信息。如果你不接受这一跨境传输,请不要使用本服务的聊天功能。
5. 我们保存多久
- 登录验证码:10 分钟后不可再使用;验证成功时删除,新验证码请求会覆盖旧记录。过期校验记录可能保留到后续覆盖或维护清理,但不包含可直接使用的明文验证码。
- 会话:默认最多有效 30 天;退出时撤销当前会话,过期记录会在会话维护时清理。
- 聊天、记忆、存档、钱包与已购物品:账号有效期间通常持续保存,以提供恢复和跨设备功能;之后按删除请求、运营需要和适用法律处理。
- 第一方分析事件:按衡量产品表现、安全调查与对账所需的期限保存,并在不再需要时删除或汇总去标识化。
- 交易、安全与账务记录:在税务、会计、反欺诈、退款、拒付或其他法律义务所需期间保存。删除账号不会要求我们删除法律要求保留或为建立、行使、抗辩法律请求所必需的记录。
没有单一保存期适用于所有数据。我们会考虑账号是否仍在使用、数据的敏感性、处理目的、争议期限、技术备份周期与法定义务;期限届满后删除、汇总或去标识化。
6. 你的权利与如何删除账号
视你所在地区及相关法律是否适用,你可以请求访问、更正或删除个人信息,限制或反对某些处理,取得可携带副本,撤回同意,或向监管机构投诉。部分权利可能受身份核验、法律例外、他人权利及必要记录保留限制。
自助删除账号:在应用内进入「程序设置 → 个人账号 → 删除账号」,按提示确认。系统会:
- 立即注销你所有的登录会话;
- 以不可用于登录的别名替换账号邮箱,并记录删除请求;
- 停止通过该账号继续访问游戏资料。
删除范围说明:自助删除不会在同一时刻抹除每一条内部记录。聊天、记忆、存档、钱包、风控和交易记录可能在删除处理、备份轮换、系统完整性检查、欺诈调查或法定保留期间继续以内部账号 ID 保存。我们目前不承诺固定的最终技术清理天数。你可以通过第 10 节要求确认处理范围。
提交请求时,请使用账号邮箱并说明请求类型;不要发送密码、登录验证码、完整卡号、政府证件或聊天全文。我们会先用最少必要信息核验账号控制权,再调查并在适用法律规定的期限内回复。若你对结果不满意,可要求内部复核;在澳大利亚隐私法适用时,也可以向澳大利亚信息专员办公室(OAIC,oaic.gov.au)投诉。
7. 安全
我们采用与风险相称的技术与组织措施,包括传输加密、受保护的会话与登录凭据、访问控制、滥用与欺诈防护、支付通知验证、敏感分析字段过滤以及必要的监测和故障响应。我们会限制有业务需要的系统和服务商访问个人信息。
没有任何系统能保证绝对安全。请妥善保管你的邮箱账户——任何能收到你邮箱验证码的人都能登录你的账号。
8. 儿童
本服务不面向未满 18 周岁者,也不有意收集其个人信息。若我们有合理理由认为未成年人使用了本服务,我们会限制或终止账号,并在法律允许及技术可行的范围内删除或隔离相关信息。举报时请不要发送未成年人的证件、住址或其他不必要资料。
9. 本政策的变更
我们可能不时更新本政策。更新会在本页发布,并同时更新顶部的“最后更新”日期。涉及重大变更时,我们会在应用内提示。
10. 隐私请求与投诉
联系角色:SWTLOVE 隐私与支持团队
业务邮箱:support@swtlove.com
该地址用于隐私权请求、账号与数据问题、未成年人举报及正式投诉。请在主题中注明“隐私请求 / Privacy Request”。为保护你和开发者的隐私,请勿发送密码、登录验证码、完整支付卡资料、政府证件、住址或不必要的敏感聊天内容。
Privacy Policy
Last updated: 3 August 2026
This policy applies to Yuki’s Room and the related account, game, payment and support functions offered under the SWTLOVE brand at swtlove.com (the "Service"). "SWTLOVE", "we" and "us" mean the operator of the Service and controller of Service data. Privacy matters are handled through the dedicated business channel in section 10; users are not asked to send information to a developer's personal email, home address or private account.
This policy describes the Service's current data flows: what we process, why, who receives it, international transfers, retention, and the requests you may make. Service providers also process information they receive directly under the terms and privacy notices applicable to them.
Adults only. The Service contains adult-oriented story and intimate content and is intended solely for people aged 18 or over. We do not offer the Service to children and do not knowingly collect personal information from anyone under 18. See our Terms of Service.
1. What we collect
1.1 Account information
- Email address. This is the only direct contact identifier requested at registration and is used to register and sign in. The Service does not use passwords.
- One-time sign-in code. A 6-digit code. We do not store the code in plain text; the database holds only a verification value that cannot itself be used to sign in. The code becomes invalid after 10 minutes and is deleted when successfully used. Repeated wrong entries lock it and trigger rate limiting.
- Session. After sign-in we set a session cookie in your browser. Our server stores only a token-verification value and expiry. The default maximum validity is 30 days.
1.2 Content you create in the game
- Chat and story messages. Every message you send and every AI reply is stored in our database, keyed to your account and the script you are playing, so characters can remember context, so you can resume, and so memory can be repaired. Each message is stored up to 24,000 characters.
- Story memory and relationships. Summaries automatically distilled from your conversations, memory nodes and relationship graphs, affection and intimacy event records.
- Character and preference settings. The name you choose for yourself, your gender, the role you play, the current script, interface language, theme, and audio toggles.
Fictional adult storytelling is not necessarily sensitive information about you. However, what you volunteer may reveal or permit inferences about your sex life, sexual orientation, health, or other specially protected information. The Service does not require those real-world details. Avoid putting them into the story. The Service does not currently present a separate explicit-consent gate for sensitive information; until the relevant compliance design is completed, do not treat the chat box as a channel for submitting real-world sensitive information.
1.3 Economy and transaction information
- Wallet balances (coins, diamonds, vouchers, gacha tickets), exploration-point balance and daily free allowance, outfits and skills you own, what you have equipped, daily claim records.
- Top-up orders: order ID, SKU, diamond quantity, amount (stored as an integer number of cents), currency (AUD), payment provider, provider reference, order status and timestamps.
- Refund and reversal ledgers, first-top-up bonus records, and ban records if any.
1.4 Payment information
We do not use the Service to collect, view or store full card numbers, CVVs or online-banking credentials. Card payments are handled on Stripe-hosted checkout pages. Where the USDT option is enabled, cryptocurrency payments are handled on NOWPayments-hosted pages. For fulfilment, refunds, reconciliation and fraud prevention, we retain order IDs, SKU, amount, currency, provider, checkout-session or invoice references, customer references where created, payment/refund/dispute status, provider event IDs and timestamps.
1.5 Technical and usage information
- Network and security information. Our application database does not store raw IP addresses; it derives keyed-hash buckets for rate limiting, sign-in-code abuse prevention and security controls. Cloudflare, as network and hosting provider, may still process raw IP addresses, request headers and network logs at the network layer.
- Usage counters. Per account, per day: number of requests and input/output character counts, used for quota control and capacity planning.
- First-party product analytics. We record events about page opens, sign-in flow, story usage, quota consumption, store activity and the checkout funnel through a same-origin endpoint. Records may include event time, random device/session identifiers, internal account ID when signed in, interface language, coarse time-zone offset, limited feature properties, and first-touch advertising attribution parameters such as UTM values, gclid, fbclid and ttclid. The event pipeline filters email addresses, chat text, nicknames, tokens and sign-in codes; it is not a third-party advertising pixel and respects the browser's Do Not Track setting.
- Server and network logs. Cloudflare, our hosting and network provider, processes network-layer logs under its own policies.
1.6 Data kept on your own device
Cookies, localStorage and sessionStorage are used for sign-in sessions, language and theme preferences, guest device identifiers, trial counters, local chat backups and some saves, analytics buffering, session identifiers and first-touch attribution. Some data remains on the device only; the parts needed for sign-in, syncing, progress restoration or first-party analytics are sent to the Service. Clearing browser data removes device copies but does not delete records already synced to our servers.
2. What we do not collect
Registration and gameplay do not require a legal name, home address, phone number, government-issued identity document, precise location or biometric data. Do not volunteer those details in chats or ordinary support email. A payment provider may collect additional information directly from you to meet its legal or risk obligations, under its own notice. We do not currently deploy third-party advertising trackers such as Google Analytics or Meta Pixel, and we do not sell or rent personal information; we do operate the first-party analytics described in section 1.5.
3. Why we use this information
- To provide the Service: sign-in, session maintenance, generating story replies, saving progress and character memory.
- To perform our contract: delivering the virtual currency and virtual items you purchase.
- To operate and improve: measuring features and checkout funnels, troubleshooting, capacity planning and improving the user experience.
- Security and legitimate interests: anti-abuse, anti-farming, rate limiting, fraud prevention, dispute handling and system protection.
- Legal obligations: retaining transaction and accounting records to meet Australian tax and reconciliation requirements.
Where applicable law requires a legal basis, the basis depends on the activity and may be performance of our contract with you, compliance with law, our or another person's legitimate interests, or consent where required. You may withdraw consent-based processing, without affecting processing that occurred before withdrawal.
4. Who we share with (third parties and cross-border transfers)
We do not sell your personal information. We share it only as necessary to run the Service, with the providers below.
DeepSeek
Shared: the chat text you write, story context, character settings and system prompts
Purpose: generating AI story replies
Processed in: mainland China
Role: we decide what end-user data the Service collects and why it is sent, and we are responsible for the disclosures in this policy. DeepSeek's general privacy policy for users of its own services does not cover end-user data collected through our application.
Stripe
Shared: email, order amount, currency, product description, local order reference and technical information needed for fraud prevention
Purpose: card payments, refunds, disputes and receipts
Processed in: countries where Stripe, its affiliates and subprocessors operate
NOWPayments
Sent by us: order identifiers, amount, currency, and technical references needed for redirects and payment notifications
Purpose: USDT-TRC20 cryptocurrency payments where that option is enabled and selected
Processed in: countries where NOWPayments and its service providers operate
Collected directly by the provider: payment and wallet addresses, transaction details, IP/device/usage information and, where risk or law requires it, KYC/AML identity information. This is not necessarily information we receive; the entity and privacy notice displayed at checkout apply.
Cloudflare
Shared: network requests, static assets, database (D1) contents, sign-in code emails
Purpose: hosting, CDN, database storage, sending verification emails
Processed in: Cloudflare's global edge network
We may also disclose information where required by law, to protect users or the Service, to investigate fraud or payment disputes, or as part of a business reorganisation subject to confidentiality protections. We do not sell chats or account information for a third party's independent marketing.
Important note about AI processing: when you use chat, we send the text you submit, relevant conversation context needed to generate a reply, character settings and prompts to the DeepSeek Open Platform in mainland China. The provider may use short-term caching or logs needed to deliver, secure and troubleshoot the API. The exact period depends on technical mechanisms and contractual arrangements; we do not promise immediate provider-side deletion or zero retention.
Please do not type your real name, home address, card number, government ID number, or other sensitive personal information into the chat. If you do not accept this cross-border transfer, please do not use the chat features of the Service.
5. How long we keep it
- Sign-in codes: unusable after 10 minutes; deleted on successful use, and an old record is replaced when a new code is requested. An expired verification record may remain until replacement or maintenance cleanup, but it does not contain a usable plain-text code.
- Sessions: valid for no more than 30 days by default; the current session is revoked on sign-out, and expired records are removed during session maintenance.
- Chats, memory, saves, wallet and owned items: generally kept while the account is active to provide restoration and cross-device features, then handled according to deletion requests, operational needs and applicable law.
- First-party analytics events: kept for as long as needed to measure product performance, investigate security issues and reconcile funnels, then deleted or aggregated and de-identified.
- Transaction, security and accounting records: kept for the period required for tax, accounting, fraud prevention, refunds, chargebacks or other legal obligations. Account deletion does not require deletion of records we must retain by law or need to establish, exercise or defend legal claims.
There is no single retention period for every data type. We consider whether an account remains active, the sensitivity and purpose of the data, dispute windows, backup cycles and legal duties, then delete, aggregate or de-identify information when it is no longer needed.
6. Your rights and how to delete your account
Depending on your location and which laws apply, you may request access, correction or deletion, restriction of or objection to certain processing, a portable copy, withdrawal of consent, or review by a regulator. Rights may be limited by identity verification, legal exceptions, the rights of others, and necessary record retention.
Self-service deletion: in the app, go to Program Settings → Account → Delete account and confirm. The system will:
- immediately revoke all of your sign-in sessions;
- replace the account email with an alias that cannot be used to sign in, and record the deletion request;
- stop further access to game data through that account.
Scope of deletion: self-service deletion does not erase every internal row at the same moment. Chats, memory, saves, wallet, risk and transaction records may remain under an internal account ID while deletion processing, backup rotation, integrity checks, fraud investigations or legal retention continue. We do not currently promise a fixed final technical-purge period. You may ask us to confirm the scope through section 10.
Use the account email and identify the type of request. Do not send passwords, sign-in codes, full card details, identity documents or whole chat transcripts. We will verify account control using the minimum information needed, investigate, and respond within the period required by applicable law. If you are dissatisfied, you may request an internal review; where Australian privacy law applies, you may also complain to the Office of the Australian Information Commissioner (OAIC, oaic.gov.au).
7. Security
We use technical and organisational safeguards proportionate to the risk, including encryption in transit, protected sessions and sign-in credentials, access controls, abuse and fraud prevention, payment-notification verification, filtering of sensitive analytics properties, and appropriate monitoring and incident response. Access by systems and providers is limited to a business need.
No system can be guaranteed absolutely secure. Please protect your email account — anyone who can read your sign-in code email can sign in to your account.
8. Children
The Service is not directed at anyone under 18, and we do not knowingly collect their personal information. If we reasonably believe a minor has used the Service, we will restrict or terminate the account and delete or isolate related information to the extent permitted by law and technically feasible. A report should not include the minor's identity document, home address or other unnecessary information.
9. Changes to this policy
We may update this policy from time to time. Updates are published on this page and the "Last updated" date at the top is revised. We will notify you in the app of material changes.
10. Privacy requests and complaints
Contact role: SWTLOVE Privacy & Support
Business email: support@swtlove.com
This channel is for privacy-rights requests, account and data issues, reports concerning minors, and formal complaints. Use "Privacy Request" in the subject line. To protect both you and the developer, do not email passwords, sign-in codes, complete payment-card details, government identity documents, home addresses or unnecessary sensitive chat content.
プライバシーポリシー
最終更新日:2026年8月3日
本ポリシーは、SWTLOVE ブランドが swtlove.com で提供する「由紀の閨房」ならびに関連するアカウント、ゲーム、決済およびサポート機能(以下「本サービス」)に適用されます。「SWTLOVE」「当方」とは、本サービスの運営者および本サービス上のデータ管理者を指します。プライバシーに関する連絡は第10条の専用業務窓口で受け付け、開発者個人のメール、住所または私的アカウントへの送付を求めません。
本ポリシーは、現在の実際のデータフローに基づき、処理する情報、目的、共有先、国外移転、保存およびお客様が行える請求を説明します。各サービス事業者は、直接取得した情報を、自らに適用される規約および通知に従って処理します。
成人向けサービスです。本サービスには成人向けのストーリーおよび親密な内容が含まれ、18歳以上の方のみご利用いただけます。当方は児童に向けてサービスを提供せず、18歳未満の方の個人情報を故意に収集することもありません。詳細は「利用規約」をご覧ください。
1. 収集する情報
1.1 アカウント情報
- メールアドレス。登録時に求める唯一の直接連絡先識別子であり、登録およびログインに使用します。本サービスにパスワードはありません。
- ワンタイム認証コード。6桁の数字です。当方はコードを平文で保存しません。データベースには、それ自体ではログインに使えない検証値のみを保存します。コードは10分で失効し、認証成功時に削除されます。連続して誤入力するとロックされ、レート制限がかかります。
- ログインセッション。ログイン後、ブラウザにセッション Cookie を設定します。サーバー側にはトークン検証値と有効期限のみを保存し、既定の最長有効期間は30日です。
1.2 ゲーム内で生成される内容
- チャット・ストーリーのメッセージ:お客様が入力した各メッセージと AI の返答は、「アカウント+シナリオ」単位で当方のデータベースに保存されます。キャラクターが文脈を記憶し、進行を再開し、記憶を修復するために使用します。1メッセージあたり最大24,000文字まで保存されます。
- ストーリー記憶と人物関係:会話から自動抽出された要約、記憶ノードと関係グラフ、好感度・親密度イベントの記録。
- キャラクターおよび設定情報:呼び名、性別、演じる役柄、現在のシナリオ、表示言語、テーマ、音声のオン/オフなど。
架空の成人向けストーリーが常にお客様本人の機微情報となるわけではありません。しかし、お客様が自ら入力した内容から、性生活、性的指向、健康状態その他特別に保護される情報が明らかになり、または推測される可能性があります。本サービスの利用に現実のこれらの情報は必要ありません。ストーリーへ入力しないでください。現在、本サービスには機微情報のための独立した明示的同意画面がありません。該当する法域向けの設計が完了するまで、チャット欄を現実の機微情報を提出する窓口として使用しないでください。
1.3 経済・取引情報
- ウォレット残高(コイン、ダイヤ、クーポン、ガチャチケット)、探索値残高と1日の無料枠、購入済みの衣装・スキル、装備中の項目、デイリー受取記録。
- チャージ注文:注文ID、商品区分(SKU)、ダイヤ数、金額(セント単位の整数)、通貨(AUD)、決済チャネル、チャネル参照番号、注文ステータス、タイムスタンプ。
- 返金・戻し入れ台帳、初回チャージ特典の記録、および(発生した場合)アカウント停止記録。
1.4 決済情報
当方は本サービスを通じて、完全なカード番号、CVV またはオンラインバンキングの認証情報を収集・閲覧・保存しません。カード決済は Stripe のホスト型チェックアウトで処理され、USDT の選択肢が有効な場合は NOWPayments のホスト型ページで処理されます。履行、返金、照合および不正防止のため、注文 ID、SKU、金額、通貨、決済事業者、チェックアウトセッションまたは請求書の参照、作成された場合の顧客参照、支払・返金・紛争の状態、事業者イベント ID およびタイムスタンプを保存します。
1.5 技術情報・利用状況
- ネットワーク・セキュリティ情報:アプリケーションのデータベースには生の IP アドレスを保存せず、レート制限、認証コードの悪用防止およびセキュリティ制御のため、鍵付きハッシュのバケットを生成します。ネットワークおよびホスティング事業者である Cloudflare は、ネットワーク層で生の IP、リクエストヘッダーおよびネットワークログを処理する場合があります。
- 利用量の集計:アカウント単位・日単位でリクエスト回数、入出力文字数を記録し、利用枠の管理と容量計画に用います。
- ファーストパーティのプロダクト分析:同一オリジンのエンドポイントを通じて、ページ表示、ログインフロー、ストーリー利用、利用枠の消費、ストアおよびチェックアウトファネルのイベントを記録します。イベント時刻、ランダムな端末・セッション識別子、ログイン時の内部アカウント ID、表示言語、おおまかなタイムゾーン、限定的な機能属性、UTM、gclid、fbclid、ttclid 等の初回広告流入パラメータが含まれる場合があります。メールアドレス、チャット本文、ニックネーム、トークンおよび認証コードはイベント処理で除外されます。第三者広告ピクセルではなく、ブラウザの Do Not Track 設定を尊重します。
- サーバー・ネットワークログ:ホスティングおよびネットワーク事業者である Cloudflare が、自社のポリシーに従いネットワーク層のログを処理します。
1.6 お客様の端末に保存されるデータ
Cookie、localStorage および sessionStorage は、ログインセッション、言語とテーマの設定、ゲスト端末識別子、体験回数、ローカルのチャットバックアップと一部のセーブ、分析イベントのバッファ、セッション識別子および初回流入情報に使用されます。端末にのみ残る情報もありますが、ログイン、同期、進行復元またはファーストパーティ分析に必要な部分は本サービスへ送信されます。ブラウザデータを消去すると端末上のコピーは削除されますが、サーバーへ同期済みの記録は削除されません。
2. 収集しない情報
登録およびゲーム利用に、法的氏名、住所、電話番号、政府発行の身分証、正確な位置情報または生体情報は必要ありません。チャットや通常のサポートメールに自ら入力しないでください。決済事業者は法令またはリスク管理上の義務を果たすため、お客様から追加情報を直接収集する場合があり、その取扱いには当該事業者の通知が適用されます。本サービスは現在 Google Analytics や Meta Pixel 等の第三者広告トラッカーを導入せず、個人情報を販売・賃貸しませんが、第1.5条のファーストパーティ分析は行います。
3. 利用目的
- サービスの提供:ログイン、セッション維持、ストーリー応答の生成、進行状況とキャラクター記憶の保存。
- 契約の履行:購入されたゲーム内通貨・仮想アイテムの提供。
- 運営・改善:機能とチェックアウトファネルの測定、障害調査、容量計画およびユーザー体験の改善。
- セキュリティおよび正当な利益:不正利用・アカウント量産対策、レート制限、不正決済防止、紛争対応およびシステム保護。
- 法的義務:オーストラリアの税務・照合要件を満たすための取引および会計記録の保持。
適用法が処理の法的根拠を求める場合、具体的な処理に応じて、お客様との契約の履行、法的義務の遵守、当方または第三者の正当な利益、または必要な場合の同意に依拠します。同意は撤回できますが、撤回前に行われた処理の適法性には影響しません。
4. 共有先(第三者および越境移転)
当方はお客様の個人情報を販売しません。サービス提供に必要な範囲でのみ、以下の事業者と共有します。
DeepSeek(深度求索)
共有内容:お客様が入力したチャット内容、ストーリーの文脈、キャラクター設定、システムプロンプト
目的:AI によるストーリー応答の生成
処理地域:中国本土
役割:本サービスが収集する終端ユーザーデータと送信目的は当方が決定し、本ポリシーの説明に責任を負います。DeepSeek が自社サービスのユーザー向けに掲示する一般的なプライバシーポリシーは、当方のアプリケーションを通じて収集される終端ユーザーデータを対象としません。
Stripe
共有内容:メールアドレス、注文金額、通貨、商品説明、ローカル注文参照および不正防止に必要な技術情報
目的:カード決済、返金、紛争および領収書の処理
処理地域:Stripe、その関連会社および再委託先が事業を行う国・地域
NOWPayments
当方から送信:注文識別子、金額、通貨、リダイレクトおよび決済通知に必要な技術参照
目的:当該選択肢が有効で、お客様が選択した場合の USDT-TRC20 暗号資産決済
処理地域:NOWPayments およびそのサービス事業者が事業を行う国・地域
事業者が直接収集:決済・ウォレットアドレス、取引情報、IP・端末・利用情報、ならびにリスクまたは法令上必要な場合の KYC/AML 本人確認情報。当方がこれらすべてを受領するとは限らず、チェックアウト画面に表示される事業体およびプライバシー通知が適用されます。
Cloudflare
共有内容:ネットワークリクエスト、静的アセット、データベース(D1)の内容、認証コードメール
目的:ホスティング、CDN、データベース保存、認証メールの送信
処理地域:Cloudflare のグローバルエッジネットワーク
また、法令上必要な場合、ユーザーまたは本サービスの保護、不正・決済紛争の調査、または秘密保持義務を伴う事業再編に必要な範囲で情報を開示することがあります。第三者独自のマーケティング目的でチャットやアカウント情報を販売しません。
AI 処理に関する重要なお知らせ:チャット利用時、お客様が送信した文章、返答生成に必要な関連会話の文脈、キャラクター設定およびプロンプトを、中国本土の DeepSeek Open Platform へ送信します。同事業者は API の提供、保護および障害調査に必要な短期キャッシュまたはログ処理を行う場合があります。具体的な期間は技術的仕組みおよび契約に左右され、当方は同事業者側での即時削除または保存ゼロを約束しません。
チャットに実名、住所、カード番号、身分証番号、その他の機微な個人情報を入力しないでください。この越境移転に同意されない場合は、本サービスのチャット機能をご利用にならないでください。
5. 保存期間
- 認証コード:10分後は利用できません。認証成功時に削除され、新しいコードを要求すると旧記録が置換されます。期限切れの検証記録は置換または保守作業による削除まで残る場合がありますが、利用可能な平文コードは含みません。
- セッション:既定で最長30日有効です。ログアウト時に現在のセッションを無効化し、期限切れ記録はセッション保守時に削除します。
- チャット、記憶、セーブ、ウォレットおよび購入済みアイテム:復元・端末間機能を提供するため、アカウントが有効な間は通常保存し、その後は削除請求、運営上の必要および適用法に従って処理します。
- ファーストパーティ分析イベント:製品性能の測定、セキュリティ調査およびファネル照合に必要な期間保存し、その後削除または集計・非識別化します。
- 取引、セキュリティおよび会計記録:税務、会計、不正防止、返金、チャージバックその他の法的義務に必要な期間保存します。アカウント削除は、法令上保存すべき記録または法的請求の確立・行使・防御に必要な記録の削除を意味しません。
すべての情報に一律の保存期間があるわけではありません。アカウントの利用状況、データの機微性と目的、紛争期間、バックアップ周期および法的義務を考慮し、不要になった情報を削除、集計または非識別化します。
6. お客様の権利とアカウント削除の方法
お客様の所在地および適用法に応じ、アクセス、訂正、削除、特定の処理の制限・異議、ポータブルな写し、同意の撤回、または監督機関への申立てを請求できる場合があります。本人確認、法的例外、第三者の権利および必要な記録保持により制限されることがあります。
セルフサービスでの削除:アプリ内の「プログラム設定 → 個人アカウント → アカウント削除」から、案内に従って確認してください。システムは次を実行します:
- すべてのログインセッションを直ちに無効化する;
- アカウントのメールアドレスをログインに利用できない別名へ置換し、削除リクエストを記録する;
- そのアカウントからゲームデータへの以後のアクセスを停止する。
削除の範囲:セルフサービス削除によって、すべての内部レコードが同時に消去されるわけではありません。チャット、記憶、セーブ、ウォレット、リスクおよび取引記録は、削除処理、バックアップの更新、整合性確認、不正調査または法定保存が続く間、内部アカウント ID に紐づいて残る場合があります。現時点で最終的な技術パージの固定日数は約束していません。第10条の窓口から処理範囲の確認を求めることができます。
アカウントのメールアドレスから請求の種類を明記してご連絡ください。パスワード、認証コード、完全なカード情報、身分証、チャット全文を送らないでください。当方は必要最小限の情報でアカウント管理権限を確認し、調査のうえ適用法の期限内に回答します。結果にご納得いただけない場合は内部再審査を請求できます。オーストラリアのプライバシー法が適用される場合、オーストラリア情報コミッショナー事務局(OAIC、oaic.gov.au)へ申し立てることもできます。
7. セキュリティ
当方は、通信時の暗号化、保護されたセッションとログイン認証情報、アクセス制御、不正利用・不正決済対策、決済通知の検証、分析用属性からの機微情報の除外、必要な監視および障害対応など、リスクに応じた技術的・組織的安全管理措置を講じます。システムおよびサービス事業者によるアクセスは、業務上必要な範囲に限定します。
絶対に安全なシステムは存在しません。メールアカウントは厳重に管理してください——認証コードのメールを読める人は誰でもお客様のアカウントにログインできます。
8. 児童について
本サービスは18歳未満の方を対象とせず、その個人情報を故意に収集しません。未成年者が利用したと合理的に判断した場合、アカウントを制限または終了し、法令上許され技術的に可能な範囲で関連情報を削除または隔離します。報告の際、未成年者の身分証、住所その他不要な情報を送らないでください。
9. 本ポリシーの変更
本ポリシーは随時更新されることがあります。更新は本ページに掲載し、上部の「最終更新日」を改訂します。重要な変更についてはアプリ内でお知らせします。
10. プライバシー請求・苦情
担当窓口:SWTLOVE Privacy & Support
業務用メール:support@swtlove.com
プライバシー権の請求、アカウント・データに関する問題、未成年者に関する報告、正式な苦情を受け付けます。件名に「Privacy Request」と記載してください。お客様と開発者双方のプライバシー保護のため、パスワード、認証コード、完全なカード情報、政府発行の身分証、住所または不要な機微性の高いチャット内容をメールで送らないでください。