Privacy Policy

Last updated: 2025-06-01

1. Introduction

Studio Hedera (“we”, “us”, “our”) operates GuideQR (the “Service”). This Privacy Policy explains how we collect, use, and protect your personal information when you use the Service.

2. Information We Collect

2.1 Account Information (Facility Operators)

  • Email address (for authentication)
  • Display name (optional)
  • Authentication data provided through Google Sign-In or email/password

2.2 Facility & Spot Content

  • Facility names, descriptions, and addresses
  • Spot titles, descriptions, and photos
  • AI-generated guide text and audio files
  • Translated content in multiple languages

2.3 Visitor Information

When visitors access audio guides via QR codes, we do not collect personal information. Visitors are not required to create accounts or provide any personal data. Standard web server logs (IP addresses, browser type, access time) may be collected by our hosting provider (Firebase/Google Cloud) for operational purposes.

2.4 Automatically Collected Data

  • Browser language preference (for UI localization)
  • Device type and browser information (for compatibility)

3. How We Use Your Information

  • To provide and maintain the Service
  • To authenticate your identity and manage your account
  • To generate AI-powered guide text and audio content
  • To display your facility and spot information to visitors
  • To improve the Service and fix issues
  • To communicate important updates about the Service or your account

4. Third-Party Services

We use the following third-party services to operate GuideQR:

ServicePurposeData Shared
Firebase AuthenticationUser sign-inEmail, auth tokens
Cloud FirestoreData storageFacility & spot data
Firebase StorageFile storageImages, audio files
Google Gemini APIAI text generationSpot descriptions, images
Google Cloud TTSAudio synthesisGuide text
Firebase HostingWeb hostingStandard access logs

These services are operated by Google LLC and are subject to Google's Privacy Policy.

5. Data Storage & Security

  • Your data is stored on Google Cloud infrastructure in the Asia-Northeast1 (Tokyo) region.
  • All data is transmitted over HTTPS with TLS encryption.
  • Access to your data is restricted through Firebase Authentication and Firestore security rules.
  • While we implement reasonable security measures, no method of transmission or storage is 100% secure.

6. Data Retention

  • Account data is retained as long as your account is active.
  • Upon account deletion, your data (including facility data, spots, images, and audio files) will be deleted within 30 days.
  • We may retain anonymized, aggregated data for analytics purposes.

7. Your Rights

You have the right to:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Update or correct your personal data through the Service.
  • Deletion — Request deletion of your account and associated data.
  • Export — Request an export of your data in a portable format.

To exercise these rights, please contact us at the email address below.

8. Cookies & Local Storage

The Service uses browser local storage to save your preferred admin UI language. We do not use advertising cookies or third-party tracking cookies. Firebase Authentication may use cookies or local storage for session management.

9. Children's Privacy

The Service is not intended for use by children under the age of 18 without parental consent. We do not knowingly collect personal information from children under 18. Visitor-facing audio guides do not collect any personal data and can be accessed by anyone.

10. International Data Transfers

Your data is primarily processed and stored in Japan (Google Cloud Asia-Northeast1 region). Some processing by third-party services (such as AI text generation) may occur in other regions as determined by Google's infrastructure. By using the Service, you consent to such transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or through the Service. The updated policy will be effective upon posting with a new “Last updated” date.

12. Contact

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: info@studio-hedera.com