MolVanilla プライバシーポリシー
本ポリシーは、化学構造式の作図・解析アプリ(以下「本アプリ」)における情報の取扱いを説明します。
端末内に保存される情報
キャンバス、構造式、設定、ローカル保存データおよび再表示を速くするための分析結果キャッシュは、原則として利用者の端末内に保存されます。運営者はこれらのローカル保存データへアクセスしません。保存データはアプリ内から、キャッシュは設定から削除でき、アプリとそのデータを削除すると端末内の情報をまとめて削除できます。
サーバー解析時に送信される情報
NMR予測、軽量物性、MS/MS候補および3D配座のサーバー計算を利用した場合、入力した分子構造と計算条件がHTTPSで解析サーバーへ送信されます。送信された構造は回答を生成するためにのみ処理され、データベースへ保存せず、広告、追跡、販売または機械学習モデルの訓練には使用しません。
正規のアプリからの要求であることの確認、不正利用防止、再送攻撃の防止および利用回数制限のため、Apple App Attestが生成するアプリインストール単位の鍵識別子、公開鍵、カウンタおよび確認日時を保存します。氏名、メールアドレス、広告IDまたは端末のシリアル番号は取得せず、広告や利用者追跡には使用しません。
任意の計算クレジットを購入・同期した場合、または旧買い切りプランを復元した場合、Appleが署名した購入証明を解析サーバーへ送信します。残高または旧プランの計算回数を確認するため、StoreKitトランザクション識別子の鍵付きハッシュ、商品情報および利用回数を保存します。Apple Accountの氏名やメールアドレスは取得せず、広告や利用者追跡には使用しません。
需要、混雑時間、性能および障害率を把握するため、利用した計算機能、成否およびサーバー処理時間を1時間単位の件数へ集計し、最大180日保持します。この集計には分子構造、IPアドレス、App Attest鍵識別子その他の利用者識別子を保存せず、広告や利用者追跡には使用しません。
購入後のクレジット反映や認証の不具合を調べるため、サーバーでの処理日時、処理段階、エラー分類、応答状態、処理時間および要求ごとに生成するランダムな照合番号を記録します。直近10,000件を上限とし、新しい記録を追加する際に14日より古いものを削除します。購入証明、取引ID、認証キー、IPアドレス、氏名、メールアドレスおよび分子構造を含めず、アカウントへの紐付け、広告または追跡には使用しません。
不正利用の防止と障害調査のため、IPアドレス、アクセス日時、要求先および応答状態などの技術的ログがホスティング事業者により最大7日程度保持される場合があります。要求本文の分子構造はアクセスログへ記録しません。
第三者サービス
解析サーバーの運用基盤としてFly.ioを利用します。広告SDK、行動分析SDKおよび第三者トラッカーは組み込んでいません。
保持・削除・安全管理
分子構造は計算に必要な間だけメモリ上で処理します。App Attestの記録はセキュリティと利用回数管理に必要な期間保持します。アカウントやクラウド保存機能は提供していないため、運営者が保持する構造データの削除依頼は通常必要ありません。App Attestの記録または技術的ログについて確認が必要な場合は、下記連絡先へお問い合わせください。
お問い合わせ
MolVanilla Privacy Policy
This policy explains how the chemical structure drawing and analysis app (the “App”) handles information.
Information stored on your device
Canvases, structures, settings, locally saved documents, and cached analysis results used for faster reuse normally remain on your device. The operator cannot access this local content. Saved documents can be deleted in the App, analysis cache can be cleared in Settings, and deleting the App and its data removes all local content.
Information sent for server analysis
When you request server-based NMR estimation, lightweight properties, MS/MS candidates, or 3D conformer calculation, the molecular structure and calculation options are sent to the analysis server over HTTPS. Structures are processed only to return the requested result. They are not stored in a database or used for advertising, tracking, sale, or model training.
To authenticate genuine app requests, prevent abuse and replay attacks, and enforce usage limits, we store the per-installation key identifier, public key, assertion counter, and verification timestamps generated through Apple App Attest. We do not receive your name, email address, advertising identifier, or device serial number, and these records are not used for advertising or user tracking.
If you purchase or synchronize optional calculation credits, or restore a legacy one-time plan, Apple-signed purchase evidence is sent to the analysis server. To verify the credit balance or legacy plan allowance, we store keyed hashes of StoreKit transaction identifiers, product evidence, and usage counts. We do not receive your Apple Account name or email address, and these records are not used for advertising or user tracking.
To understand demand, busy periods, performance, and failure rates, we aggregate the calculation feature used, outcome, and server processing duration into hourly counts retained for up to 180 days. These aggregates do not store molecular structures, IP addresses, App Attest key identifiers, or other user identifiers, and are not used for advertising or user tracking.
To troubleshoot credit delivery and authentication, we record server processing time, stage, error category, response status, duration, and a random reference generated for each request. We keep at most the latest 10,000 records and delete records older than 14 days when adding a new record. These records exclude purchase evidence, transaction IDs, authentication keys, IP addresses, names, email addresses, and molecular structures. They are not linked to an account or used for advertising or tracking.
For abuse prevention and troubleshooting, the hosting provider may retain technical logs such as IP address, access time, endpoint, and response status for approximately seven days. Molecular structures in request bodies are not written to access logs.
Service providers
Fly.io provides the analysis hosting infrastructure. The App contains no advertising SDK, behavioral analytics SDK, or third-party tracker.
Retention, deletion, and security
Molecular structures are handled in memory only as long as needed to perform the calculation. App Attest records are retained while needed for security and usage-limit enforcement. Because the App provides no account or cloud document storage, the operator normally has no stored structure to delete. Contact us below with questions about App Attest records or technical logs.