Privacy Policy

This policy explains how Hatara Kiroku (はたらきろく, "the app") handles personal and location data.

Last updated: 6 September 2026

Effective date: the day the app becomes available on the App Store

Scope of this policy

This policy describes the iOS version of the app as it is currently implemented. The app has not yet been released. This policy will be revised as the implementation changes.

This is an English translation provided for convenience. The Japanese version is the original text.

1. Our approach

Hatara Kiroku exists so that working people can keep a record of their own working hours. Because that record belongs to the person who made it, the app is built on the following principles.

  • Recorded data is stored only on the user's device.
  • The app does not transmit recorded data to any server.
  • There are no user accounts, and the app does not collect names or contact details.
  • At present, no advertisements are displayed in the app.
  • We will not use third-party advertising or tracking SDKs, and we will not track users through their behavioural histories.
  • We will not provide your work records, workplace location data, or wage settings to any third party, including advertisers.
  • Only for managing in-app purchases do we use an external service (RevenueCat). See "6. Transmission and disclosure to third parties".
  • Location data is not collected beyond what is needed to measure working hours.

2. What the app collects

2-1. Location data

The app collects and stores the following location data on the device.

Location data collected and stored
Data When it is read Whether it is stored
Latitude and longitude of a registered workplace When you register a workplace, either from your current location or by choosing a point on a map Stored, together with the 100-metre radius used for detection
Latitude, longitude, and accuracy at the moment you enter or leave a workplace When iOS detects that you have crossed the boundary of a registered workplace Stored
Latitude, longitude, and accuracy of your current location when the workplace registration map is shown When the registration screen displays the map (obtained automatically, to centre the map on your current location) and when you tap "Current location" Not stored (used to display the map and to determine whether you are at the workplace immediately after registering it)
Latitude, longitude, and accuracy of your current location when the app opens Each time the app comes to the foreground; the location is read once Stored only as a correcting entry when it conflicts with the existing record. If there is no conflict, it is not stored

If no location is available at the moment a boundary crossing is detected, the app records the stored coordinates of the workplace instead. In that case, no accuracy value is recorded.

2-2. Information you enter

  • A name for the workplace (optional; assigned automatically as "勤務先1" and so on if you leave it blank. It appears on the home and settings screens, and in the exported CSV and its filename)
  • Session notes (optional free text you can attach to a work session)
  • Wage settings (hourly or monthly wage, standard monthly hours, contracted weekly hours, which weekday counts as the statutory day off, and how public holidays are treated)

These are stored on the device exactly as you enter them. The app does not look them up against any external service or transmit them anywhere.

Text you entered as a "workplace note" in an earlier version may still be stored on your device. The current version no longer offers that field.

2-3. Arrival and departure records

The app stores each event — that you entered or left a given workplace — along with the time it occurred, the time it was recorded, and how it was detected (automatic detection, a check performed when the app opened, or a manual entry).

Working hours themselves are not stored. They are calculated from these events each time they are displayed.

2-4. Session notes

You can attach free text to each work session. The app stores the text, the time you wrote it, and the time you last edited it.

2-5. Day classifications and the pay closing day

The app stores the classification you set for each day on the schedule screen (regular working day, contractual day off, statutory day off) and the pay closing day you chose in the wage settings.

2-6. Tamper-detection seals

So that you can verify your records have not been altered afterwards, the app stores a chained hash value for each arrival and departure record.

2-7. Diagnostic log

For troubleshooting purposes, the app keeps a diagnostic log on the device. Each entry contains a timestamp, a severity level, a category, and a message.

Message text may include latitude and longitude (to five decimal places), part of the internal identifier of a workplace, the workplace radius, and positioning accuracy. The log is also stored only on the device, and the app never transmits it automatically.

2-8. Other

The following information is stored in the device's app settings:

  • Whether you have completed initial setup.
  • When you accept the terms of use and this privacy policy, the version identifier of the accepted documents and the date and time of acceptance.

This information is stored only on the device and is never transmitted externally.

3. What the app does not collect

The app does not collect any of the following. There is no screen or mechanism in the app to do so.

  • Name, email address, phone number, postal address, or date of birth
  • Account credentials or passwords — the app has no registration or sign-in
  • The name of your employer or details about them, except where you have typed them yourself as a workplace name or note
  • Contacts, photos, calendars, microphone, camera, or health data
  • The Advertising Identifier (IDFA). The current version contains no code that collects the IDFA, and the app does not ask for tracking permission. For purchase management, however, the app does send the device's vendor identifier (IDFV), which is a different identifier and is shared only among apps from the same vendor (see "6. Transmission and disclosure to third parties")
  • Routes, travel history, or a record of places you passed through
  • Analysis of which screens you view or which buttons you tap, and crash reports sent to anyone. Communication for purchase management does occur, at app launch and when you purchase or restore (see "6. Transmission and disclosure to third parties")

4. How location data is used

4-1. Purpose

Location data is used solely to detect when you enter or leave a registered workplace and to calculate your working hours. It is not used for any other purpose.

4-2. How it is obtained

The app uses the geofencing (region monitoring) feature of iOS. It registers a circular region centred on each workplace with iOS, and iOS notifies the app when you cross the boundary.

The app does not track your location continuously. It reads your location only in these cases:

  • When you tap to capture your current location while registering a workplace
  • When iOS detects that you have crossed the boundary of a registered workplace
  • When the app comes to the foreground and checks your position against the existing record

4-3. Background use

The app does use location data in the background. This is necessary to record arrivals and departures while the app is closed, which is why it asks for location access set to "Always".

What happens in the background is limited to detecting and recording boundary crossings at your workplace. The app does not follow your movements.

If location access is set to anything other than "Always", the app's behaviour is limited and its measurement of working hours becomes unreliable.

5. Where data is stored

All of the data described above is stored only on the user's device. The app has no server of its own, and it is not configured to store data in any cloud service. It does not sync via iCloud.

Note that if you have device backups enabled (iCloud Backup, or a backup to a computer), the operating system may include the app's data in that backup. This is a function of iOS, not data being transmitted by the app. Backup settings can be changed in the iOS Settings app.

6. Transmission and disclosure to third parties

6-1. Your work records

The app does not transmit location data, workplace information, arrival and departure records, session notes, wage settings, or diagnostic logs to anywhere outside your device. The operator does not receive any of it.

We do not provide them to any third party, including advertisers.

6-2. In-app purchase management

The app uses RevenueCat, a service operated in the United States, to check purchase status and to process purchases and restorations.

To check purchase status, the app communicates with RevenueCat at launch. This happens whether or not you have made a purchase, and also before you accept the terms of use. What is sent is an anonymous identifier used for purchase management, the device's vendor identifier (IDFV) where it is available, and technical information about the device, OS, and app (OS version, device model identifier, app version and build number, bundle ID, preferred language, and the state of the purchase environment). When you purchase or restore, purchase-related information is sent in addition.

The app contains no code that sends your work records, workplace location data, session notes, or wage settings to RevenueCat.

For how RevenueCat handles information, please see that company's privacy policy.

6-3. Map display

Displaying a map relies on the operating system's map feature, which involves communication with Apple's services. See "7. Map display" for details.

6-4. Sharing that you initiate

If you export a CSV file or a diagnostic log and share it with someone or with another service, that sharing is at your own discretion. The app neither chooses the destination nor sends anything automatically.

7. Map display

When a map is shown — for example while registering a workplace — the app uses the standard iOS map framework (Apple's MapKit). The communication required to display the map takes place with Apple's services.

The app does not transmit data to any server of its own. It has no backend service.

For what information Apple handles in connection with MapKit, please refer to Apple's privacy policy.

8. Exporting your data

8-1. Work records as CSV

From "Settings > Export and delete records" you can choose a workplace and a date range and export your work records as a CSV file. The file contains:

  • the export time, the workplace name and coordinates, the detection radius, the date range, the pay closing day, and the tamper-detection result;
  • the date, arrival and departure times, hours worked, status, how each was recorded, the latitude and longitude of each, the event identifiers, and the chained hash values;
  • the text of session notes, when they were written, and when they were last edited;
  • if wages are configured, regular hours, overtime hours, overtime pay, an indicative gross amount, and the derived hourly rate.

A work session that overlaps the range you chose is included with its actual times, even if it began or ended outside that range.

8-2. Diagnostic log

From "Settings > App log" you can export the diagnostic log as a text file. The log contains workplace names, coordinates, and times.

8-3. Sharing and temporary files

Exporting happens only when you choose to do it, and where the exported file goes — or whether it goes anywhere at all — is your decision. The app never sends it automatically.

An exported file contains location coordinates. Please review the contents before sharing it with anyone.

Exported files are written to a temporary area on the device and, in the current version, are not deleted automatically. A copy you save elsewhere is governed by wherever you saved it.

9. How long data is kept

Retention by data type
Data Retention
Workplace information (coordinates, radius, name) Not deleted automatically. Kept on the device until you delete the app
Arrival and departure records, tamper-detection seals, and session notes Not deleted automatically. Kept on the device until you delete them or delete the app (see "10. How to delete your data")
Wage settings Not deleted automatically. Kept on the device until you delete the app
Diagnostic log Around 2,000 entries are kept as a guideline, with older ones removed periodically. Because tidying does not happen on every write, the count can temporarily exceed that figure

Because work records exist precisely so that you can look back on them, the app does not erase them on its own.

10. How to delete your data

10-1. What you can delete from within the app

Data you can delete in the app
Data How to delete it
Arrival and departure records, tamper-detection seals, and session notes From "Settings > Export and delete records > Delete all work records", for every workplace at once. This cannot be undone
A single session note Open the session on the home screen and delete its note
Diagnostic log From "Settings > App log", all at once
Day classifications On the schedule screen, reset a day to its default classification

10-2. What you cannot delete from within the app

Workplace information, wage settings, the pay closing day, and purchase-management information cannot be deleted from within the current version. To remove them, delete the app from the iOS home screen.

Deleting the app from the iOS home screen removes the app's data stored on the device. Deleted data cannot be recovered.

10-3. What remains after deletion

Exported CSV files and log files, and any copies you saved elsewhere, are not removed by the deletions above.

After deleting your records

"Delete all work records" does not stop workplace monitoring. If you enter or leave a workplace afterwards, new records are created. To stop monitoring, delete the app.

11. Changing or withdrawing location permission

You can change or withdraw location permission at any time from the iOS Settings app.

Go to Settings > はたらきろく > Location to change the permission state.

If permission is set to anything other than "Always", or if it is denied, the app can no longer record arrivals and departures automatically, and measurement of working hours becomes unreliable. Records made before the change are not deleted.

12. Requests for access, correction, or deletion

Work records, workplace information, session notes, wage settings, and diagnostic logs are stored only on your device; the operator does not hold them. The operator therefore cannot disclose, correct, or delete them. Please delete them yourself, following "10. How to delete your data".

Information sent to RevenueCat for purchase management is governed by that company's terms. For enquiries, please use the contact details in "16. Contact and operator information".

You can review the contents of your records yourself, on your own device.

13. Use by children

The app is not designed for any particular age group and does not collect information about age. If a child uses the app, guardians are encouraged to review the location permission settings.

14. The Android version

This policy covers the Hatara Kiroku service as a whole. However, the iOS version is still in development and has not yet been released. The specifics described here reflect that iOS implementation.

An Android version is planned but is not available at this time. When one is released, this policy will be revised to reflect its implementation.

15. Changes to this policy

This policy may change as features are added or the implementation changes. Any revised version will be published on this page together with its last-updated date.

Changes to this policy are also subject to the notice and consent requirements set out in Article 13 of the Terms of Use.

16. Contact and operator information

For enquiries about this policy, or about how the app handles personal and location data, please use the contact below.

Operator information
Operator Tadashi Sugie
Location Hachioji, Tokyo, Japan
Contact hatarakiroku@sapp.sakura.ne.jp

The app is developed and operated by an individual.

For questions about using the app, please also see the support page.