About this policy
Goji is provided by CHOU BORUEI. This policy covers the Goji iOS app, services supporting its features, and this website. Contact privacy@ohsakura.com with privacy questions.
This is a draft, not an effective policy. It describes data flows found in the current source code. Production retention settings, backups, and data request procedures still require confirmation.
Location, routing and navigation
With your location permission, the app uses location for nearby information, route planning and navigation. Selected origins, destinations, times and journey preferences are used for route requests and sent to the services supporting those features.
During active navigation, the app can send precise coordinates, timestamps, altitude, speed, heading, accuracy, floor and location status to Goji services. Depending on the route configuration, it can also send region-monitoring events, beacon identifiers, distance estimates and signal strength to determine journey progress and provide guidance. Navigation includes background-operation settings; this does not mean that location is collected at all times.
Unsent navigation observations may be stored temporarily on the device for retries. Disabling location limits features that depend on it. Ending navigation or stopping location access does not delete previously transmitted data.
Device identity and security
The app creates a random device identifier, stores it in the device keychain, and registers the iOS platform, app version and build version with the service. This identifier is not your name, but should not be treated as fully anonymous.
The app uses Apple App Attest to verify requests. Verification identifiers, challenges, attestations and session information help prevent unauthorized access. Removing the app does not mean that all keychain or server records are deleted.
Saved places, recent places and Apple services
Favourites and recently viewed places can contain names, addresses, coordinates, place identifiers and viewing times, stored using SwiftData. The current code limits recently viewed places to 30 entries.
The app is configured for iCloud and CloudKit. Depending on your iCloud sign-in and system settings, relevant data may sync through Apple services. Maps and place searches also use Apple MapKit. Apple services operate under the Apple privacy policy. These records should not all be described as staying on a single device.
Live Activities and push delivery
To update Live Activities, the app sends push tokens, activity identifiers and related journey or stop information to Goji services. Updates are delivered through Apple Push Notification service. A push token addresses an app or activity; it is not a phone number or email address.
Advertising and privacy choices
The app integrates Google AdMob and the User Messaging Platform (UMP). It uses the SDK’s consent state to determine whether ads may be requested. Where applicable, use Settings → Advertising privacy options in the app to manage your choices. The entry appears according to UMP status and is not necessarily shown in every region.
Google’s disclosures describe processing of IP addresses, device identifiers, interactions with ads, and diagnostic and performance information for purposes including advertising, analytics and fraud prevention. IP addresses may also be used to estimate a general location. Actual processing depends on the SDK, consent, system restrictions and advertising configuration. Navigation location processing and advertising SDK behaviour are distinct; integrating AdMob does not establish that navigation locations are sent to Google.
See Google’s SDK data disclosure, Google’s privacy policy and how Google uses information from partners. This policy does not claim that all ads are non-personalized or that every user will receive a tracking authorization prompt.
Recipients and purposes
Data is processed by Goji service infrastructure and, where needed for the features used, Apple, Google or other third-party services. Purposes include answering queries, navigation, place synchronization, activity updates, request verification and advertising. Providers may process data in different regions. Production hosting regions and the provider inventory still require operational confirmation.
If you email us, we receive the contact details and message you provide to handle your inquiry. Please do not send passwords, push tokens or complete location histories.
Retention and cleanup
Current code defaults are not a promise about production retention:
- General navigation location and other observations become eligible for cleanup 24 hours after receipt. Related records also have cleanup rules 24 hours after navigation ends.
- Some navigation decision audits and delivery attempts have a seven-day cleanup threshold. Other rules may make them eligible sooner after navigation ends.
- The code also contains storage and cleanup capability for beacon-resolution telemetry, with a default threshold of 90 days after navigation ends. Static inspection did not find a caller of its write method. Activation and actual retention remain unconfirmed.
Cleanup runs in scheduled batches. Failures, dependent records and production settings can affect completion. Retention of device registrations, verification identifiers, non-navigation push records, backups, logs and support emails remains to be confirmed. The thresholds above do not imply that all data is deleted together.
Your choices and data requests
You can manage location permissions, delete manageable favourites and recent places in the app, adjust iCloud and Live Activity settings, and manage advertising consent where applicable. See Privacy choices for guidance.
For questions about access, correction or deletion, contact privacy@ohsakura.com. We may need to establish which data and identity a request concerns. There are no website accounts or website self-service deletion tools. The production request procedure and applicable limits still require confirmation; immediate deletion of all data is not promised.
This website
This website does not include an advertising SDK or analytics tracking scripts. Appearance and manually selected language preferences may be stored in your browser. Website code does not upload them. Clear site data in your browser to remove them.
Visiting the site still requires the hosting service to process connection information such as IP addresses and requests. This website is hosted on Cloudflare Pages. Hosting log and retention details still require confirmation. External links are subject to their destination’s policies.
Policy changes
Changes will be published here with an updated date. A draft’s revision date is not an effective date. The effective date and data practices will be confirmed before publication.