LABEL TO LABEL for iOS
LABEL TO LABEL for iOS Privacy Policy
This Privacy Policy describes how LABEL TO LABEL K.K. collects, uses, shares, and protects information when you use the LABEL TO LABEL native iOS app shown on device as “LILA”.
- Effective
- May 21, 2026
- Last updated
- September 10, 2026
Contents01 · Language and controlling version
Language and controlling version
This Policy is available in English and Japanese.
The two versions are intended to have the same meaning. If they differ, the English version takes precedence only to the extent permitted by applicable law. This does not limit rights or protections that cannot lawfully be excluded.
Introduction
This Privacy Policy explains how LABEL TO LABEL K.K. ("LABEL TO LABEL", "we", "us" or "our") collects, uses, discloses and protects information in the LABEL TO LABEL iOS app, shown on the device as "LILA". It covers LILA AI interactions, Messages with people, Project Rooms and collaboration, voice messages and files, company information, updates, meeting requests, Access and invitations, private saved places and place sharing, profiles, notifications, reports, Capture, permitted business tools, Benefits and physical-product Shop checkout when available, Apple system integrations, TestFlight testing and support (the "Service").
The app provides public company information alongside personal and restricted features. Availability depends on the feature, your account, your permissions and whether the feature has been made available. Personal saved places are private unless you choose to share them. Partner, brand, retailer and project areas are available only to authorized users. The app is not a substitute for medical, legal, financial or other regulated professional services and must not be used for safety-critical decisions.
Submit only information that you have the right to use and that is appropriate for the selected feature. Information requested through designated account, checkout or support fields may be provided for those purposes. The prohibited-content rules in the iOS Terms apply to other submissions.
Information We Collect
We collect information you provide, information created when you use the Service, and technical information needed to operate, secure, support, and improve the Service.
LILA, Messages, Reports, Meeting Requests, and App Interaction
LILA chat may be available after acceptance of this Privacy Policy and the Terms. When you use LILA, we may collect prompts, messages, AI responses, timestamps, app version, language settings, and related operational metadata needed to provide, secure, debug, and improve the requested experience.
LILA is designed to help users understand Label to Label, its services, partner opportunities, office access context, and related company information. It is not designed for sensitive personal data or regulated professional advice.
The Service may also include human Messages between you and Label to Label. Messages may include message text, voice/audio messages, attachments, replies, sender identity, delivery and read state, timestamps, notification metadata, archive status, and related conversation information needed to provide and manage the conversation.
Messages may be direct conversations with Label to Label or shared conversations created by Label to Label with selected signed-in users. Content, attachments, voice messages, shared files, delivery/read information, participant information, and related conversation metadata in a shared conversation may be visible to the participants in that conversation and authorized Label to Label team members. If you leave a shared conversation, you stop seeing the conversation and receiving future notifications for it, but messages, files, and other content you already sent may remain visible to the remaining participants and Label to Label where needed for conversation continuity, safety, legal compliance, or business records.
Projects and Business Collaboration
If Label to Label creates or manages a project with you, we may process the project name and summary, membership and roles, steps, assignments, planned dates, status and completion records, activity history, related Project Room messages and files, and notification preferences. These records support business collaboration; they do not by themselves constitute an electronic signature, binding approval, contract, or guarantee.
Project information is available only to current authorized project members. A person added later may see the current project structure, current and completed steps, and project files, while Project Room message and activity history is limited to that person's latest join time. A person who leaves or is removed loses project access. Contributions made while authorized may remain visible to current members for business continuity, security, legal compliance, or business records.
If you choose to send a voice message, we may collect the audio recording, file type, file size, duration, waveform or playback metadata, speech-recognition transcript text where available, transcript status, timestamps, sender information, and related message metadata needed to send, store, preview, transcribe, play back, and manage the message. Speech recognition is requested only to provide transcript text for the audio message.
Meeting requests are handled as a simple Messages workflow. When you request a meeting topic, we may collect the selected subject, any note you add, your account/contact information, and the resulting conversation so an authorized Label to Label team member can respond and organize the next step.
Account, Authentication, and Profile Information
If you sign in, request protected access, or use private features, we may collect account identifiers, sign-in status, email address, phone number where provided or required for supported workflows, display name, full name if provided through Sign in with Apple or profile settings, access status, membership status, language setting, notification preference, legal acceptance version, and related session information.
Partner, Meeting, and Access Records
Private partner or business features may collect or store meeting details, partner notices, office arrival records, QR/access pass identifiers, pass status, expiration times, access permissions, contact phone numbers for supported access or event workflows, app updates, service content, timestamps, and related records needed to manage secure access and relationship continuity.
Shop purchases and Benefits
The app may include Shop functionality for tangible products. The Shop or checkout may be hidden, unavailable, or disabled until Label to Label chooses to publish products. When Shop checkout is not visible or enabled, we do not collect checkout shipping, order, or payment-status information through app checkout.
If Shop checkout is enabled and you choose to buy a tangible product, we may collect the selected product, variant, quantity, order identifier, customer name, email address, phone number, Japan shipping address, price, tax, shipping, payment status, payment provider, Stripe payment or order identifiers, fulfillment status, return or refund status, timestamps, and related support or operational information needed to process the order.
We do not collect or store full payment card numbers or card security codes. Payment card details are processed by payment providers such as Stripe, Apple Pay where enabled, card networks, issuing banks, or other payment providers according to their own terms and privacy practices.
If you participate in Benefits, we process the account and verified purchase or reversal records needed to calculate eligibility, Season Value, continuity and level, together with invitations, reservation and guest counts, Event Pass and check-in records, Travel Courtesy assignment or use status, notification preferences and related support records. These records administer Benefits under its separate Terms. Benefits does not give unrelated users access to your purchase history or private reservations.
Images, Audio, Attachments, and Uploaded Assets
If you, Label to Label, or authorized users upload images, videos, audio recordings, documents, QR images, or other attachments for chat, reports, LILA, app updates, service content, notices, access passes, support, Capture, or meeting-related records, we may collect file content, file name, file type, file size, creation time, and related metadata. If you grant location permission and capture media in LILA Capture, captured photos or videos may include location metadata.
Camera and photo-library access are used only when you choose to capture, attach, or save media. QR/access-pass images are stored only when they are uploaded or assigned as part of an access workflow; ordinary user-location map use does not require storing camera images. The app saves captured media to Photos only when you choose Save to Photos.
Authorized business tools may also process product photographs, reference files, product information, instructions, marked areas, corrections and generated drafts that you submit or request. Where Product Studio is available, its submission confirmation identifies the material being sent to OpenAI. Prepared or generated material remains subject to that feature's access and export controls; it is not automatically public.
Saved Places and Location Sharing
If you save a place, we collect its name, precise latitude and longitude, any optional address or cover image you add, timestamps, and related account information. We use this information to keep the place private in your account, sync it across your signed-in devices, display it in the app, and share it only when you choose. Location access for this feature occurs while you use the app; My Places does not provide continuous or background location sharing.
Saved places are private unless you share them in Messages. A shared private place is available only to authorized recipients in that conversation. People added later cannot access an earlier place share, and a removed participant loses access. A recipient may save the shared place within the conversation or create a separate private copy in their own account. A separate recipient copy is controlled by that recipient and is not removed when the sender edits or deletes the original place or account. Official Label to Label locations remain subject to the recipient's current access permissions.
Notifications
If you allow notifications, the app may use Apple notification services to notify you about important app updates, partner notices, meeting changes, access pass updates, protected-access notices, or other permitted events. We may process device notification identifiers, account identifiers, notification delivery metadata, and notification preferences needed to send and manage notifications. You can manage notification permissions in iOS settings.
Notifications and widgets may display names, message previews or other selected app content outside the app, depending on device settings and the feature. App lock does not by itself hide all such previews. Review iOS notification-preview and widget settings when using a shared or visible device.
Device, Usage, and Service Information
We may collect device and app information, such as platform, app version, build number, operating system version, language or region settings, notification device identifiers, request timestamps, IP address, error reports, diagnostic information, security events, read/unread state, delivery state, and feature usage events where enabled. We use this information to operate, secure, debug, support, and improve the Service.
The app may use Apple-native system features such as Spotlight, App Intents, Sign in with Apple, Apple Maps, Calendar, notifications, local haptics, Keychain, and device location services. Content indexed for Spotlight is app content such as published news, services, and office locations. Device location used only to center the map or open Apple Maps is processed on device or by Apple platform services. We store precise location when you expressly save a My Place, share a place in Messages, include location in a support request, or save captured media with location metadata as described in this Policy. If you choose to synchronize an access appointment, event invitation, project, or step schedule with Calendar, the app uses Calendar access to create, find, display, and update that linked item. The app does not import, upload, or disclose unrelated calendar events. Calendar synchronization choices are private to your signed-in account and device; other app users cannot see them. Changes to an available linked app item may update its Calendar event, but Calendar edits do not change the shared record in the app.
Reports, Support, and Privacy Requests
If you contact us through Messages, email, a privacy request, an account deletion request, an issue report, content report, or other support communication, we may collect your name, company name, email address, message contents, voice messages, attachments, screenshots, reported content, report reason, report status, admin/user response messages, account identifiers, diagnostic details, and any other information you choose to provide.
How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Service. - Provide LILA chat and company/service information. - Authenticate users and protect access to Messages, protected business, meeting, profile, and access-pass features. - Save legal acceptance status, profile settings, app update records, partner notices, meeting details, access records, and related business content. - Generate LILA-assisted responses and other AI-assisted outputs requested by you. - Prepare, process, fulfill, support, return, refund, or audit tangible-product Shop orders when Shop checkout is enabled. - Store and retrieve uploaded images, audio, documents, report attachments, and other assets where needed for app functionality. - Manage authorized project membership, steps, schedules, status, activity, files, and related collaboration records. - Create, sync, display, edit, delete, and recipient-scope My Places and place shares that you expressly save or send. - Send requested or permitted notifications. - Provide customer support, respond to inquiries, process privacy requests, and handle account deletion requests. - Review reports, investigate abuse, enforce our Terms, protect users, and prevent prohibited content or misuse. - Improve app reliability, security, usability, and performance. - Prevent unauthorized access, fraud, spam, security incidents, or misuse. - Comply with legal obligations and enforce our terms and policies.
AI Processing
LILA uses OpenAI to process requests and generate responses or other requested outputs. The information sent may include your prompt, relevant conversation history, files or images you submit, app or business context made available for the request, and necessary technical metadata. Authorized image tools may send reference photographs, instructions and corrections to produce and review a draft.
We retain AI requests and responses, including records held by OpenAI, for conversation functionality, quality and security monitoring, troubleshooting, abuse prevention and other purposes described in this Policy. Authorized personnel may review these records for those purposes. Retention depends on the type of record, the feature and the applicable provider arrangements; deleting an item in the app does not mean that every provider, security or legally required record is deleted immediately. We do not use Service data for third-party targeted advertising.
Optional personal memory is separate from ordinary conversation history. Where available, its settings control the supported memory feature; disabling memory does not mean a request is no longer sent to OpenAI or that previous conversation records are erased. You can stop submitting AI requests and contact us about access or deletion. Where a particular transfer requires separate permission, the required permission must be obtained; accepting this Policy does not replace it.
Review AI outputs before using or sharing them. They may be inaccurate, incomplete, outdated, biased or unsuitable for the intended purpose.
How We Share Information
We do not sell personal information and we do not use Service data for third-party targeted advertising.
We may share information with:
- Service providers, including Google/Firebase for cloud infrastructure and OpenAI for AI processing, that help host, store, secure, troubleshoot, support and operate the Service. - AI service providers used to process chat content and requested LILA responses. - Payment, commerce, fulfillment, and shipping providers, such as Stripe, Apple Pay where enabled, card networks, banks, logistics providers, and related support partners, when Shop checkout or product fulfillment is enabled. - Apple, as needed for App Store distribution, TestFlight, Sign in with Apple, notifications, platform services, and app review. - Authorized organization members, partner users, and collaborators when private access features are used. - Professional advisors, authorities, courts, regulators, or other parties when required by law, legal process, security needs, abuse prevention, or protection of rights. - Successors or affiliates in connection with a merger, acquisition, reorganization, financing, or transfer of business assets, subject to appropriate protections.
Service providers are permitted to use information only as needed to provide services to us or as otherwise allowed by applicable law and their agreements with us.
Private saved-place information is shared only with the authorized recipients of the conversation in which you choose to send it. Official Label to Label locations are shared only with people who currently have access to them. Project information is shared only with current authorized project members, subject to the history limits described above.
These descriptions do not authorize unrestricted disclosure. Where Japanese law requires prior consent for providing personal data to a third party, we obtain it unless a statutory exception applies. Outsourcing, business succession and overseas transfers are handled under the conditions applicable to those activities.
Your Responsibility for Shared Content
Submit, save or share only content you have the right and authority to use. Confidential business materials may be used only with the necessary authorization and in an appropriate permitted feature. Do not send prohibited sensitive, unlawful, exploitative or infringing content; the iOS Terms explain these restrictions. Information requested in designated account, checkout or support fields may be supplied for those purposes.
Save or share a place only when you are entitled to use its location, name, address and cover image. Do not disclose another person's current or precise location without their knowledge and lawful authority, or use places or location data for stalking, surveillance, harassment or harm.
International Transfers
LABEL TO LABEL is based in Japan. Providers, including Google/Firebase and OpenAI, may process information in Japan, the United States, the European Economic Area or other locations used to provide the relevant service. Storing some information in Japan does not mean all processing remains in Japan.
When personal data is provided to a third party outside Japan, we follow the applicable requirements of Japan's Act on the Protection of Personal Information. Where we rely on consent, we provide the information required for that consent, including information about the destination country's system and the recipient's safeguards. Where we rely on an equivalent protection system or a recipient's continuing equivalent safeguards, the applicable legal conditions and required ongoing measures apply. Contact us for information about the arrangement relevant to your data and information we must provide under applicable law.
Retention
We retain information for the purposes described in this Policy and for as long as reasonably necessary to provide the relevant feature, maintain an account or business relationship, fulfil an order, handle a request or dispute, prevent abuse, and meet legal obligations. The period depends on the record and its purpose; it is not one fixed period for all app data.
LILA history, files and provider-held AI records support conversation continuity and the quality, security and other purposes explained under “AI Processing”. Personal memory, conversation history and uploaded files are distinct records; changing one setting or deleting one item does not necessarily remove the others.
Messages, project contributions, saved places, invitations, access and Benefits records are retained for the relevant account, relationship or shared business activity, subject to supported deletion and applicable law. Shop order, payment-status, fulfilment, return and refund records may need to remain for accounting, tax, fraud prevention, disputes and legal obligations. Support, report and privacy-request records are retained as needed to resolve the matter, document the response and meet those purposes.
At the date of this update, ordinary logs in our Google Cloud default logging bucket are retained for 30 days, while Google's required audit-log bucket retains records for 400 days. These periods concern those cloud logs, not every database record, support case or AI provider record. Other records follow the purposes above and the applicable provider arrangements or legal requirements.
Supported deletion removes information from active use through the relevant deletion process. Completion can take time, including when a provider request must be retried. Recovery copies, legally required records and provider security or audit records may remain under their applicable retention rules. We do not promise that every provider or backup copy disappears immediately or within a single universal period.
The in-app account-deletion process deletes the user profile, sessions, notification-device registrations, access and event passes, personal saved places and associated stored media. It also removes project membership and processes deletion of the user's Messages and LILA conversation records and files, including deletion requests for associated OpenAI conversation records. Shared project contributions and business records may remain available to authorized current members where needed for the purposes above. A place or file separately copied by another recipient is controlled by that recipient. Copies saved to Photos, exported outside the app or retained on another device may require separate removal. Minimal deletion, legal, security or dispute records may be retained where necessary. Contact us if you need help identifying or deleting retained information; the statutory rights described below remain available.
Your Choices and Rights
Under Japan's Act on the Protection of Personal Information, you may request notification of the purposes of use, disclosure of retained personal data and applicable third-party provision records, correction, addition or deletion of inaccurate data, and suspension of use, erasure or cessation of third-party provision where the statutory conditions are met. Where another applicable law provides additional rights, those rights also apply. You may withdraw consent for processing based on consent; this does not change the lawfulness of earlier processing.
Contact us with the request and the information concerned. We may ask for information reasonably needed to verify your identity or an agent's authority. We will respond as required by applicable law and explain a refusal or partial refusal where required. Any legally permitted fee and its basis will be explained before the charged procedure. You may also raise a concern with the Personal Information Protection Commission or another competent authority. These rights are subject to the limits and exceptions in applicable law.
You can manage notification permissions in iOS settings, edit supported profile and language settings, manage or delete saved places, choose whether to share them, and request account deletion in the app. AI requests and optional memory have the choices described in “AI Processing”.
For Sign in with Apple accounts, the deletion flow requests Apple confirmation and revocation of the app's Sign in with Apple access as part of deletion.
Security
We use access controls, authentication, encrypted communications, Apple's device security features and other administrative, technical and organizational safeguards appropriate to the Service. Access to personal information is limited according to responsibilities and operational need. These measures do not mean that all content is end-to-end encrypted or inaccessible to authorized administrators or the providers needed to process it. You can request information about applicable safeguards, except details whose disclosure would undermine security. No method of transmission or storage is completely secure.
Children
The Service is intended for business and professional users. It is not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact us so we can take appropriate action.
Third-Party Services and Content
The Service may link to websites, Apple Maps, Apple platform services, payment processors, shipping providers, partner services, or other third-party resources. We are not responsible for the privacy practices, content, terms, accuracy, security, or availability of third-party services or content. Your use of third-party services and content is governed by their own policies and terms.
Changes to This Policy
We may update this Policy to reflect changes in the Service, our information handling or applicable law. We will identify the revised version by its updated date and give notice of material changes as required by law. We will obtain separate consent where a new purpose, disclosure or other change requires it. Continued use alone does not replace consent required by law.
Contact
LABEL TO LABEL K.K. (レーベルトゥレーベル株式会社)
Representative Director: Alberto Nomura
Floor 26, Kyobashi Edogrand, 2-2-1 Kyobashi, Chuo-ku, Tokyo 104-0031, Japan
Email: connect@label-to-label.com