Stored on your device
Your events, images, and settings are stored primarily on your iPhone. There are no accounts and no cloud sync.
Sent only with your consent
Data is sent to external AI services only after you review what will be sent and explicitly agree. You can withdraw consent at any time.
No tracking, no selling
We do not use the information we receive for advertising tracking or data sales.
TOSHIAKI NAKAO (the "Operator") handles information processed in Mr. Fixture (the "App") in accordance with the Act on the Protection of Personal Information of Japan, other applicable laws, and this Policy. This is an English translation of the Japanese Privacy Policy; if there is any inconsistency, the Japanese version prevails.
1. Information stored on your device
The App stores the events you register, team and artist names, URLs, notes, images, settings, import history, usage counts, and a random device ID generated by the App on your device. The App currently provides no accounts, no cloud sync, no advertising, and no in-app purchases.
2. Information sent when you use AI analysis
Only when you run AI analysis and explicitly consent to the transmission, the App sends the following to the Mr. Fixture Cloudflare Worker:
- Text you enter or paste
- The URL you specify and the webpage content fetched from it
- Images you select for AI analysis
- The random device ID generated by the App
- The App version, client date, and time zone
- Your connection IP address, which Cloudflare receives during communication
The AI providers receive the text, webpage content, or images being analyzed, together with the client date and time zone needed to interpret dates. Mr. Fixture does not forward the random device ID, the App version, or your connection IP address to the AI providers.
This data is processed to extract schedule candidates, manage usage counts, prevent abuse and excessive use, and investigate failures. It is not used for advertising tracking or data sales.
3. External providers and international processing
| Provider | Location | Data | Purpose / notes |
|---|---|---|---|
| Cloudflare, Inc. | United States | AI analysis requests, IP address, technical logs | Running the Worker, protecting communication, rate limiting |
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | China | Text, webpage content | Primary extraction of schedule candidates |
| OpenAI, L.L.C. | United States | Text, webpage content, images | Fallback analysis when DeepSeek fails, and image analysis |
China has a comprehensive personal information protection law. It also has rules requiring certain data to be stored within the country, and rules that can oblige businesses to cooperate with the government for national security or criminal investigations. The United States has no comprehensive federal law governing the private sector; sector-specific federal laws and state laws apply instead. Because both legal frameworks differ from Japan's, the same rights and protections available in Japan are not always guaranteed.
DeepSeek's public Open Platform Terms state that DeepSeek processes input from end users of downstream apps and that developers must disclose the processing to their users and obtain consent. However, those terms do not specify the retention period for downstream end-user input, whether it is used for model training, or the specific safeguards DeepSeek itself applies, so these points remain unconfirmed. DeepSeek's general Privacy Policy expressly states that it does not apply to the processing of end users of downstream apps.
Content sent to the OpenAI API is not used to train models by default, but may be retained in abuse-monitoring logs for up to 30 days. Mr. Fixture encrypts traffic, keeps API keys on the server, and limits input size and request counts. OpenAI states that it uses AES-256 encryption at rest and TLS 1.2 or later in transit, limits personnel access, and undergoes SOC 2 Type 2 audits. Cloudflare's Data Processing Addendum specifies security measures aligned with the ISO/IEC 27000 series, including encryption, access controls, monitoring, business continuity, and independent audits. Complete security cannot be guaranteed.
- DeepSeek Open Platform Terms
- DeepSeek Privacy Policy (does not cover end users of downstream apps)
- OpenAI API Data Controls
- OpenAI Enterprise Privacy
- OpenAI Privacy Policy
- Cloudflare Data Processing Addendum
- Cloudflare Privacy Policy
- Personal Information Protection Commission of Japan: surveys of foreign legal systems (Japanese)
- Personal Information Protection Commission of Japan: report on China (Japanese)
4. Retention on the Mr. Fixture side
The Worker does not store the text, webpage content, or images being analyzed in the App's database. Rate-limit keys derived from the device ID and IP address are kept for about 65 minutes, and the service-wide request counter for up to about 25 hours. Cloudflare may retain technical logs for incident and security response in accordance with its contracts and settings.
Data on your device is kept until you delete it in the App or delete the App itself.
5. Consent, refusal, and withdrawal
Before your first AI analysis, the App shows the recipients, the data to be sent, the purposes, and the international processing involved, and obtains your explicit consent. The consent record is stored on your device together with the version of the consent text, the date and time, the display language, and the providers covered.
If you decline, you can still use manual entry and CSV/iCal import. You can withdraw consent in Settings under "AI data sharing"; after withdrawal, no new AI transmissions occur until you consent again. Withdrawal does not automatically delete information already processed or retained by the external providers.
6. What to keep out of AI analysis
Do not include personal information, confidential information, ticket QR codes, or third-party information you are not authorized to send. If you send information about other people, confirm that you have the necessary rights or their consent.
7. Other external integrations
When you explicitly choose to do so, the App may pass event information to the OS calendar, Google Calendar, share-sheet destinations, and similar services. Those services are governed by their own providers' terms and policies.
8. Security
The Operator takes reasonable security measures, including encrypted communication, server-side management of API keys, input and size limits, and access restrictions. Complete security cannot be guaranteed.
9. Requests for deletion and disclosure
You can delete on-device data with the App's data-deletion features or by deleting the App. Requests for disclosure, correction, suspension of use, or deletion recognized under applicable law are accepted at the contact below. Whether information retained by external providers can be deleted is governed by each provider's contracts and policies.
10. Minors
Minors who cannot appropriately judge the external transmission of information should use the App with the confirmation and consent of a parent or legal guardian.
11. Changes
If the collected items, purposes, or recipients change in a material way, the Operator will give notice in the App or by similar means before the effective date. If the targets, purposes, or providers of AI transmission change, explicit consent will be obtained again as necessary.
12. Contact
- Operator
- TOSHIAKI NAKAO
- wonderfooty@gmail.com
- Support
- Support page (Japanese)