Privacy Policy
Effective date: July 20, 2026 / Last updated: August 24, 2026
Poppin Studio ("we", "us", "our") operates the Android application "Poppin" (the "App") and the website poppin-studio.com (the "Site"; together with the App, the "Service"). This Privacy Policy (this "Policy") explains how information relating to users of the Service is handled, and reflects our commitment to compliance with the Japanese Act on the Protection of Personal Information (the "APPI") and other applicable laws.
1. Definitions
In this Policy, the following terms have the meanings set out below.
- "Personal Information" means personal information as defined in Article 2, Paragraph 1 of the APPI.
- "User" means any person who uses the Service.
- "On-Device Data" means any information a User creates, enters, or stores through the App, and any information the App holds solely on the device during operation — including decks and card content (text, images, audio), study progress and spaced-repetition state, user settings, monitored-application usage state, and media-playback state.
- "Advertising ID" means the advertising identifier assigned to an Android device.
2. Information We Handle
2.1 On-Device Data
On-Device Data is processed on the User's device solely to operate the App's features. It is stored only in Android's SharedPreferences and internal storage, and is never transmitted to servers operated by us or to any third party. We do not obtain, view, copy, or retain On-Device Data.
2.2 Information handled by third-party services
The App integrates the third-party services listed below. Each such service handles information in accordance with its own privacy policy, which the User is encouraged to consult.
- Google AdMob (provider: Google LLC) — for ad delivery. May receive the Advertising ID, coarse location, and technical device information (Google Ads Policies).
2.3 Data-handling summary
Consistent with the approach used in Google Play's Data safety section, a summary of the information described above:
| Data type | Recipient | Transmitted off-device? | Purpose |
|---|---|---|---|
| On-Device Data (decks, cards, study progress, etc.) | None | Not transmitted | App functionality (processed on-device only) |
| Advertising ID | Google AdMob | Transmitted | Ad delivery |
3. Purposes of Use
Information described in Section 2 is used only for the following purposes:
- providing and operating the App's core features (flashcard study, spaced-repetition scheduling, and Pop Quiz);
- determining when to display the study prompt based on the User's activity in monitored applications;
- automatically toggling Pop Quiz on/off according to the day-of-week and time schedule the User has configured;
- improving the quality of the Service, diagnosing defects, and developing future functionality;
- delivering advertisements.
4. Android Permissions Used by the App
To implement its core features, the App requests the following Android permissions from the User. Each is used only within the scope required by its stated purpose and is not used for any other purpose, consistent with Google Play's policy that sensitive permissions be limited to what is necessary for an app's core functionality.
- Usage Access (PACKAGE_USAGE_STATS): used to detect the foreground application. Only the package name and the timestamp of foreground transitions are read, over a short rolling window kept on-device. This information is not stored as a persistent log or usage history, and is never transmitted off-device.
- Accessibility Service: used solely to detect the URL string currently displayed within applications (such as browsers) the User has designated as Pop Quiz targets. The detected URL is held only transiently in memory to compare it against the User's configured target URL patterns; it is not stored or accumulated as browsing history, and it is never transmitted off-device. The App does not capture on-screen content (screenshots, form input, passwords, etc.), and does not monitor activity in applications the User has not designated as targets.
- Display over other apps (SYSTEM_ALERT_WINDOW): used solely to present the study prompt in front of the monitored application.
- Foreground Service (FOREGROUND_SERVICE_SPECIAL_USE): used to run the resident service that detects the currently foregrounded application while Pop Quiz is on, so a flashcard can be triggered the moment the User opens a monitored app. A persistent status-bar notification is shown while the service is running so the User can see that it is active.
- KILL_BACKGROUND_PROCESSES: used, at the moment a study prompt fires, to stop playback only in the specific application the User has designated as a monitoring target. It is never used to terminate processes of unrelated third-party applications.
- Alarms & reminders (SCHEDULE_EXACT_ALARM): used solely to fire the User-configured Pop Quiz auto on/off schedule at the specified weekday and time. If this permission is not granted, the schedule still works but the fire time may drift by a few minutes.
- Post notifications (POST_NOTIFICATIONS): used solely to notify the User when Pop Quiz is automatically toggled on or off by the schedule. It is never used for promotional notifications.
- Receive boot completed (RECEIVE_BOOT_COMPLETED): used solely to re-arm the schedule alarms after the device reboots, so the schedule continues to fire.
5. Sharing with Third Parties
Except as set out below, we will not disclose Personal Information to any third party without the User's prior consent:
- where required by law;
- where necessary to protect the life, body, or property of an individual, and obtaining consent is impracticable;
- where specifically necessary to improve public health or promote the sound upbringing of children, and obtaining consent is impracticable;
- where necessary to cooperate with a governmental authority or its delegate performing statutory duties, and obtaining consent might interfere with those duties.
6. Safeguards
We implement reasonable and appropriate safeguards to prevent the leakage, loss, or corruption of information handled in connection with the Service. Because On-Device Data is not stored on any server operated by us, the responsibility for safeguarding that data rests with the User; each User should take appropriate measures against device loss, theft, and unauthorized access.
7. Advertising ID and Opt-Out
The App uses the Advertising ID for ad delivery through Google AdMob. You may reset or delete your Advertising ID, and opt out of personalized ads, at any time from your Android device's ads settings (Settings > Google > Ads), or via Google Ads Settings. Non-personalized ads may continue to be shown after opting out.
8. Data Breach Response
Because On-Device Data is never stored on any server we operate, a breach originating from us is not structurally possible for that data. However, if we become aware of an actual or suspected leak, loss, or corruption of personal information in connection with the Site's hosting infrastructure or our integration with third-party advertising services, we will promptly investigate the facts and, as applicable law requires, report to the Personal Information Protection Commission and notify affected individuals, to the extent reasonably practicable.
9. Access, Correction, and Deletion
- On-Device Data can be deleted in its entirety by uninstalling the App. Because we do not hold this data, requests to us for access, correction, or deletion of it do not apply.
- For information handled by third-party services (such as the Advertising ID), please use the reset or deletion controls in Android's ads settings, or the opt-out and support channels provided by each service.
- In addition, if you wish to request disclosure, correction, or suspension of use of information we handle under Articles 32 through 34 of the APPI, please contact us using the details in Section 13, stating the type and substance of your request together with information sufficient to confirm your identity. We will respond within a reasonable period once your identity has been confirmed, as required by law.
10. International Users
The Service is primarily intended for users in Japan. If you access the Service from outside Japan, you may have rights under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), or other applicable local law, including rights of access, deletion, and objection to processing. We will address requests to exercise such rights through the contact channel in Section 13, to the extent reasonably practicable.
11. About the Site
The Site consists of static web pages only. It does not set cookies, collect personal information through forms or other means, or use analytics tools. If any of these are introduced in the future, this Policy will be updated in advance and notice given on the Site.
12. Changes to this Policy
We may revise this Policy as needed to reflect changes in applicable law, changes to the Service, or otherwise. Any revised Policy takes effect when posted on the Site. Material changes will be announced separately in the App or on the Site.
13. Contact
Questions about this Policy, and requests under Sections 9 and 10, may be directed to:
Poppin StudioEmail: contact@poppin-studio.com