Privacy Policy
Effective: July 24, 2026 · Last updated: August 17, 2026
This policy applies to the iOS app "Peekino / 間違い探し工房" (the "App"), provided by GARLAND Inc. ("we", "us").
What we collect and send
Only when you edit an image with AI, the following is sent through our server (Google Cloud, Tokyo region) to an AI provider (such as Google Gemini):
- The image you are editing (only the photo you selected — we never read your photo library as a whole)
- Your editing instruction (the text you typed, e.g. "change this to a balloon")
In addition, only when you send a puzzle to someone as a link, that puzzle (two images and the locations of the differences) is kept on our servers for a limited time — see "Sharing your puzzles" below. Sharing is your choice. If you do not share, we never keep a copy of your puzzle. (The image and instruction you submit while creating still pass through for AI processing, as described above — keeping a copy of the finished puzzle is a separate matter.)
Storage and use
- The images and instructions you send for AI editing are not stored — they only pass through for processing.
- A safety check also applies while you are creating. To keep Peekino safe for everyone, the image and instruction you submit pass through the safety checks of our AI providers (such as Google). If a check stops the request, nothing is created.
- Only puzzles you share as a link are kept, so that the person you sent it to can open it (see "Sharing your puzzles" below).
- Your data is not used to train AI models (per the providers' terms for their paid APIs).
- For operations and troubleshooting, our server records metadata only: when, which device, how many times, estimated cost, and which processing route. We do not record the image, the instruction text, or hashes of them.
Sharing your puzzles (sending a link)
- We check your photo once, just before it is shared. To keep Peekino safe for everyone, the photo is sent — before encryption — through our server to Google's content-safety service (Cloud Vision SafeSearch), which tells us only whether it is suitable for sharing. It is passed through for that check only; neither we nor Google store it. If it does not pass, the puzzle cannot be shared (it stays on your device).
- When you create a link, the puzzle is encrypted on your device before it is uploaded. The key that unlocks it exists only inside the link and never reaches us. As a result, we cannot see the contents of the puzzles we hold — this applies to our staff and developers as well.
- We keep a shared puzzle for 30 days, after which it is deleted automatically. If you choose to stop sharing before then, it is deleted at that moment.
- The recipient's copy is also deleted automatically after 30 days (the App always shows the days remaining). Please note that the two countdowns start at different moments: the copy we hold expires 30 days after the link was created, while the recipient's copy expires 30 days after they received it. So the later someone opens a link, the later their copy disappears — it can still be on their device after our copy is gone.
- The puzzle on your own device is never deleted. Only the shared copies go away.
- Anyone who has the link can open the puzzle. We cannot prevent a recipient from forwarding the link to someone else, so please be careful who you send it to.
- When someone solves your puzzle, you are told how long they took and how many differences they found. We tell the player about this before they play.
- If a player prefers not to send that, they can turn it off. It can be switched off in Settings under "Puzzles you received", and also declined for a single result on the finish screen. When it is off, no record is sent to our servers (the preference itself stays on the device and never reaches us).
- A player's name is "anonymous" by default. After finishing, we ask whether they would like to attach a name — it is entirely optional, and staying anonymous is perfectly fine. It can be changed or cleared in Settings under "Puzzles you received" — that applies to solves you send from then on; a name already attached to a record you sent stays as it was. We ask players not to use their real name.
- A nickname is shown only to the person who made that puzzle. There is no public gallery of other people's puzzles or names anywhere in the App.
- If you receive a puzzle you find inappropriate, please report it from within the App. Only when you report, the contents of the puzzles from that link that are still on your device are decrypted on your device and sent to us. If that link contained several puzzles, all of the ones you still have are included (two images, the locations of the differences, and the time limit for each); any you deleted earlier are not. We normally cannot read them, so without this we would have no way to check what you reported. We review the contents and delete the puzzle if there is a problem. The reported contents we receive are deleted automatically after 30 days, just like shared puzzles. If you do not report, the contents never reach us in readable form (what we hold for a shared link stays encrypted, and we cannot unlock it).
- Reporting also blocks that author on your device, so nothing else they send will reach you. You can also block without reporting, from the screen of a puzzle you received. The block is stored on our servers and you can remove it at any time from Settings → "Puzzles you received" → "Blocked people". The other person is not told that you blocked them.
Device verification (App Attest)
To prevent abuse and impersonation, we use Apple's App Attest to verify that requests come from the genuine App on a real device. This verifies the device and the App only — it does not collect your name or any personal details.
Account
No account or sign-up is required (we do not collect your name or email address). To manage the ink available to you, the App stores a random, anonymous identifier that we issue in your device's secure storage (Keychain), and our server associates a record of how many times you have used the App with it. We do not store a balance — the ink available to you is calculated each time from your subscription and your usage count. This identifier is not linked to your name or any personal information. It is used to carry your usage record and subscription over when you reinstall the App or move to a new device.
When you use the sharing feature, we also store your solving records (which puzzle, how long it took, and how many differences you found) against this anonymous identifier, together with a nickname if you chose to enter one (optional — anonymous by default). These are likewise not linked to your name. You can stop sending them at any time (turn off "Tell the person who made it" in Settings under "Puzzles you received", or change or clear your nickname there). Records you have already sent, and the nickname attached to them, can also be deleted from within the App at any time (Settings → “Puzzles you received” → “Delete my play records”). Deleting removes your row entirely from the maker’s list, so no trace that you played remains. Please note that this cannot be undone, that notifications already delivered cannot be taken back, and that content kept as part of a report is not removed by this action, for safety reasons. If something doesn’t work, please contact us at the address below.
To tell you when someone solves a puzzle you made, we also store the push notification token issued by Apple for your device, associated with the same anonymous identifier. It is used only to deliver those notifications and is not linked to your name. If you turn notifications off in your device settings, they stop arriving.
Purchases
Monthly ink plans are purchased through Apple In-App Purchase; payment details are handled by Apple (we never receive your credit card number).
To check whether you currently have an active plan, which plan it is, and when it renews, we use RevenueCat, an external purchase-management service. We pass it the purchase and subscription information we receive from Apple (transaction and product identifiers, period dates — no name or payment details) along with the anonymous identifier our App issued on your device. The ink available to you is calculated each time from that subscription information and how many times you have used the App; we do not store a balance ourselves.
Third parties (processors)
- Google (Gemini API / Vertex AI — image processing; Google Cloud Storage — temporary storage of shared puzzles; Cloud Vision — the pre-share photo check)
- OpenAI (backup image processing)
- Apple (In-App Purchase, App Attest, push notification delivery)
- RevenueCat (purchase and subscription management)
These providers act only for image processing, storing shared puzzles, purchases, subscription management, device verification, and notification delivery. We do not share your data for any other purpose.
Shared puzzles are stored encrypted, so the storage provider cannot see their contents either. There are two exceptions:
- The pre-share check passes the photo through once before encryption (it is not stored).
- A reported set is decrypted on the reporting person's device and kept so that we can review it (all puzzles in that set are included; automatically deleted after 30 days).
Children
The App is suitable for all ages and requires no account or personal information. When a puzzle is shared, the only things the other person learns are (and only if that setting is on) how long it took to solve and how many differences were found, plus a nickname if the player chose to enter one (anonymous by default, entirely optional). We ask players not to use their real name. There is no messaging and no way to send free-form text to each other. There is no public gallery of other people's puzzles or names inside the App — only someone who receives a link can open that puzzle. If your child uses the App, please check with them who they are sending links to.
Changes
If we make material changes to this policy, the App will ask for your consent again (managed by a policy version number).
Contact
GARLAND Inc.
Email: contact+peekino@garland-i.com