Privacy Policy
Last updated: January 9, 2026
1. Introduction and Scope
Welcome to Docchi ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our mobile application and related services (the "Service").
This policy applies globally and complies with applicable data protection laws including:
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- European Union General Data Protection Regulation (GDPR)
- Japan's Personal Information Protection Act (PIPA - 個人情報保護法)
- Other applicable state and federal privacy laws
By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Service.
2. Information We Collect
2.1 Personal Information You Provide
- Account Registration: Email address, username, securely encrypted password
- Profile Information: Optional demographic data including birth date, gender, location (country, state/prefecture, city)
- Authentication Data: Third-party login credentials (Google, Apple ID) when you choose social login
- Communication: Messages, feedback, and support requests you send us
2.2 Content and Activity Data
- Poll Creation: Questions, answer options, images, categories, and poll settings
- Voting Activity: Your votes, poll interactions, and engagement patterns
- User-Generated Content: Any content you create, share, or comment on within the Service
- Usage Patterns: How you navigate and interact with polls and features
2.3 Automatically Collected Information
- Device Information: Device type, operating system, app version, unique device identifiers (IDFA/AAID)
- Authentication Data: Session tokens and authentication tokens for API access
- Technical Data: IP address, HTTP headers, connection information, timestamps
- Content Metadata: Timestamps of poll creation, voting timestamps, aggregate poll statistics
3. How We Use Your Information
We use your information for the following purposes:
3.1 Service Operations
- Provide, maintain, and improve our Service functionality
- Process your votes and display poll results
- Authenticate your identity and secure your account
- Enable social features like poll sharing and discussions
3.2 Communication and Support
- Send important account and service notifications
- Respond to your questions and provide customer support
- Notify you about Service changes, updates, or new features
- Send marketing communications (with your consent where required)
3.3 Information Sharing and Disclosure
We Do NOT Sell Your Personal Data. Docchi will never sell your personal information to third parties.
When We May Share Information:
- Public Poll Results: Poll results and aggregate statistics are publicly available
- Legal Requirements: When required by law, court order, or to protect safety
- Service Providers: With trusted cloud infrastructure providers who help us operate our service (under strict data processing agreements)
- Push Notifications: With notification services for push notification delivery (with minimal user data)
- Business Transfers: In the event of a merger or acquisition (with advance notice)
4. Your Privacy Rights
4.1 All Users
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and associated data
- Portability: Receive your data in a portable format
4.2 California Residents (CCPA/CPRA Rights)
- Right to know what personal information we collect and how it's used
- Right to delete personal information (with certain exceptions)
- Right to opt-out of the sale of personal information (we don't sell data)
- Right to non-discrimination for exercising privacy rights
4.3 Japan Residents (PIPA Rights - 個人情報保護法)
- Right to disclosure of personal information usage purposes (利用目的の開示)
- Right to request suspension of usage or provision to third parties (利用停止・第三者提供停止)
- Right to correction or deletion of personal information (訂正・削除)
- Right to file complaints with the Personal Information Protection Commission
4.4 Data Retention
- Account data: Retained while your account is active
- Poll data: Retained to maintain service functionality
- Deleted accounts: Most data deleted within 30 days (some aggregate analytics may be retained)
5. Data Security and International Transfers
5.1 Security Measures
We implement industry-standard security measures including:
- Encryption for all data in transit
- Secure password protection using cryptographic hashing
- Database encryption at rest via secure cloud infrastructure
- Token-based authentication with secure generation
- Rate limiting and abuse prevention systems
- Regular security updates and ongoing maintenance
- Limited employee access to production data
5.2 International Data Transfers
Your information may be transferred to and processed in the United States and Japan. We ensure appropriate safeguards are in place for these transfers.
6. Tracking, Analytics, and Error Monitoring
Docchi uses the following tracking and monitoring services:
- Session authentication tokens (essential for app functionality)
- Local app preferences (stored on your device only)
- Google Analytics on our website for understanding visitor patterns (anonymized, no personal data)
- No invasive tracking pixels or behavioral analytics in the app
- Error tracking service (Sentry) for quality monitoring - collects minimal data (device type, OS version, error details) to help us fix bugs and improve stability
On the web, we use standard HTTP server logs for performance monitoring only. See our Cookie Policy for details.
7. Children's Privacy
Docchi is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately.
8. Changes to This Policy
We may update this Privacy Policy occasionally. We will notify you of significant changes via email or in-app notification. Continued use of Docchi after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or your data:
Response Time: We will respond to your privacy requests within 30 days (or as required by applicable law).