送信する回答
無料フローは選択したスタイルと買い物に関する回答、任意のメモを処理します。結果を要求したときだけRingMatcherサーバーへ送信され、結果の作成と検証に使われます。
任意画像とAI処理
写真は任意で、顔写真は不要です。最大3枚がブラウザで縮小され、そのリクエスト用に設定されたAI提供者へRingMatcherサーバー経由で送られる場合があります。RingMatcherはアップロード画像を意図的に保存しません。ゼロ保持と収集拒否の設定を要求しますが、提供者の基盤、規約、法的義務は適用されます。
画像指示は視覚的デザイン要素だけを許可し、個人特定やセンシティブ属性の推測を禁止します。画像内の文字や指示は無視されます。
共有リンク
共有リンクのURLフラグメントには、表示結果、選択したダイヤモンド経路、予算帯、コンテンツ言語が含まれます。アップロード画像は含まれません。リンクを持つ人は情報を読めるため、送信前に確認してください。
限定されたフラグメントで、表示中のブリーフ項目を小売店検索へ渡せます。ページのHTTPリクエストには送信されず、取り込み後にアドレスバーから削除されますが、未取り込みのリンクを持つ人は読めます。
Native app data, purchases, and recovery (authoritative English disclosure)
This native-app section is the authoritative English disclosure. The surrounding translated text may not yet describe every native-app behavior.
A questions-only Ringprint in the native app is created on the device, so those answers do not leave the device for matching. If you add up to three photos, the app re-encodes them and sends the device-resized images, their context labels, the questionnaire answers, the content locale, and a random installation identifier through RingMatcher for that request. Cookies are omitted. RingMatcher then sends the answers and images to OpenRouter, the configured AI gateway, with zero-data-retention and data-collection-denial settings requested. RingMatcher does not intentionally persist the match request body or uploaded image files, and saved Ringprints never contain a photo file or image payload. OpenRouter, any routed model provider, and their infrastructure, terms, and legal obligations still apply.
The app stores saved Ringprints in AsyncStorage, including the questionnaire answers, optional note, generated result, locale, source, timestamps, and image-analysis counts. Paid-plan snapshots, generated guidance, setup inputs, and tool activity are also stored in AsyncStorage; source snapshots omit the free-form Ringprint note. These records are app-local but are not encrypted by AsyncStorage. Photo files are excluded. A random installation UUID and purchase capabilities—including draft and access tokens, obfuscated purchase-binding identifiers, and a Google Play purchase token after billing—are stored separately with device-only SecureStore settings.
On Android, RingMatcher disables app backup and excludes its app files, databases, preferences, and device-to-device transfer domains from backup rules. This is intended to keep local Ringprints, plans, and purchase capabilities off Android backup and migration services. Other operating-system, device-administration, forensic, or user-initiated copying behavior is outside RingMatcher's control.
If you choose Report this result, the app sends RingMatcher the result identifier, visible result title, summary and rationale, the selected report reason, an optional note, the content locale, and the random installation identifier in a request header. The service uses the installation identifier and network address to enforce an hourly report limit. It writes the report content, reason, optional note, locale, a generated report identifier, and the receipt time to structured deployment logs so the report can be reviewed. Those report logs do not intentionally include the raw installation identifier or network address; their retention follows the deployment logging configuration. Reporting is optional and does not affect saved Ringprints or paid access.
Starting a Google Play checkout sends RingMatcher the selected pack, random installation UUID, local Ringprint identifier, and a SHA-256 digest of the Ringprint—not the questionnaire answers, uploaded photos, or generated plan. The server persists a digest of the installation identifier, the Ringprint identifier and digest, generated draft/access identifiers, product and pack identifiers, obfuscated Google Play binding identifiers, capability hashes, and timestamps. Claiming a purchase sends the raw Google Play purchase token to RingMatcher so it can be verified with Google Play. The server persists a digest of that token, and may persist an order-ID digest and purchase-completion timestamp; it does not write the raw purchase or order token to its purchase-state file.
The protected Google Play app-review path sends the reviewer access code and random installation UUID to RingMatcher. The server compares a one-way code digest, enforces network and installation limits, and persists only the code digest, installation digest, synthetic draft/claim/access identifiers, pack and product identifiers, and timestamps—not the plaintext review code. It returns signed, expiring plan capabilities to device-only SecureStore. This review path does not open billing or create a charge.
An unclaimed purchase draft expires after 7 days. After a successful claim, its draft and replay-claim record become eligible for pruning when that same 7-day draft capability expires. Paid access expires after 30 days for Shortlist or Complete Plan and after 90 days for Together Plan. Expired eligible rows are pruned atomically during later purchase-state maintenance, such as a subsequent draft creation or purchase grant; there is no background deletion timer. Unexpired drafts and access records are not evicted to make room for newer records.
Saved Ringprints and completed paid plans remain on the device until you remove them, the bounded local history replaces older Ringprints, app storage is cleared, or the operating system removes the app data. Removing a completed paid plan also asks SecureStore to delete its associated capability. A plan with an unfinished purchase is protected from ordinary removal because the local draft may still be needed for Google Play recovery. RingMatcher has no user account or cross-device plan library: clearing local app data, removing protected credentials, changing devices, or uninstalling can make a consumed one-time purchase or its generated plan impossible to recover. Contact contact@ringmatcher.com for privacy or server-record deletion questions.
リクエスト制限、ファーストパーティ計測、技術ログ
サーバーはネットワークアドレスから、メモリ内だけに保持する一時的なリクエスト制限キーを生成する場合があります。RingMatcherは、ランディングページ、Ringprintの作成、共有とダウンロード、任意の決済と有料パックのフロー、販売店検索におけるファーストパーティの到達点を記録します。イベント仕様で許可されるのは、イベント名、固定された参照元・チャネル・パック・状態・CTAの移動先・CTAの配置・ロケールの値、真偽値、上限付きの件数またはスコアだけです。質問への回答、予算、メモ、生成された方向性の文章、任意のURLやページパス、自由入力の移動先、決済識別子、エラーメッセージやスタック、個人情報、自由入力文は含まれません。
販売店検索のイベントには、固定された購入種別と、RingMatcherが確認したカタログ内の販売店IDが含まれる場合もあります。
ガイドからクイズへ移動するリンクをクリックした後、ブラウザーのセッションストレージには、許可リストにあるガイドのスラッグ、ロケール、CTAの配置という帰属値だけが、技術的なバージョンおよび有効期限のメタデータとともに保持される場合があります。帰属情報が受け付けられるのは最長30分で、参照元を関連付けたRingprintリクエストで一度だけ使用されます。期限切れの記録は無視され、次回アクセス時に削除されます。セッションストレージもブラウザーのタブまたはセッションとともに終了します。質問への回答、予算、写真、連絡先情報、アカウントまたはユーザーの識別子は含まれません。
受け付けたイベントは、構造化されたサーバーのデプロイログにのみ書き込まれます。RingMatcherは第三者の分析サービスへ送信せず、専用の分析データベースにも保存しません。保持期間はデプロイ先のログ設定によります。イベントにアカウントまたはユーザー識別子は含まれません。技術的なAI利用状況は、質問への回答やアップロード画像を含めずに記録される場合があります。
有料パックとStripe
任意の有料パックの1回払いはStripeが処理します。RingMatcherは、領収書用メールアドレス、選択したパック、サーバーが設定した金額と通貨、生成されたリクエストIDとPaymentIntent IDをStripeへ送信します。支払い情報はStripeのPayment Elementが収集し、RingMatcherが完全なカード番号やセキュリティコードを受信または保存することはありません。
Stripeのメタデータに含まれるのは、生成されたID、支払いと提供処理の状態、ブラウザーのアクセスに結び付く一方向ハッシュのみで、質問への回答、写真、個人的なメモ、レポート内容は含まれません。パックごとのHttpOnly・SameSite Cookieは最長100日、保留中の支払い記録はそのブラウザーのローカルストレージに最長30日保存される場合があります。Stripeの規約とプライバシーポリシーが適用されます。
本番サイトでは、有料レポートのセッションを保護されたサーバーボリュームに保存し、通常の再起動やデプロイ後に復元します。Shortlist と Complete Plan のセッションは30日後、Couple’s Edition は90日後に期限切れとなります。RingMatcherは削除依頼を完了した時点で、セッションをそれ以前に削除する場合があります。
RingMatcherが販売しないもの
RingMatcherは指輪も個人データも販売しません。アカウント、決済、分析、保存、モデル提供者が変わる場合は、変更後のサービス公開前にこのページを見直します。プライバシーに関する質問はcontact@ringmatcher.comへお送りください。