Japanese version is here
Privacy Policy of TwitPane, ZonePane, BluePane, TaiPane and related apps
Last updated: October 1, 2026
TwitPane, ZonePane, BluePane, TaiPane, TwitPaneResearch and their related apps (hereinafter "the App"), provided by Panecraft, Inc. (hereinafter "we" or "the Operator"), handle user information in accordance with this policy. We comply with the laws and regulations on the protection of personal information, including the Act on the Protection of Personal Information of Japan and, for users in the European Economic Area (EEA), the United Kingdom and Switzerland, the GDPR and equivalent laws.
Data Controller
- Name: Panecraft, Inc.
- Contact: info@panecraft.net
Information the App collects and how it is used
The App collects information through the tools and services listed below. None of them is used by us to identify you by name, and we do not collect or retain personally identifying information outside of these tools.
1. Crash reports (Firebase Crashlytics)
- Information collected: stack traces at the time of a crash, device information (model, OS version, memory, etc.), app version, the Crashlytics installation ID and the Firebase installation ID. Your IP address is processed temporarily by Google when the report is sent. No personally identifying information such as account names is sent.
- Purpose: investigating and fixing bugs
- Legal basis: legitimate interests (keeping the App stable)
- Retention: retained by Google for 90 days
- How to opt out: turn off "Settings → Advanced settings → Send crash reports" in the App
- Details: Privacy and Security in Firebase
2. Usage analytics (Google Analytics for Firebase)
- Information collected: how screens and features are used (screens viewed, types of API calls, login method, whether posts succeeded, ad impressions and errors), the number of signed-in accounts, network type, device model, OS and language, the app instance ID, and the advertising ID where available. Post contents and account names are not sent.
- Purpose: improving the App and analyzing usage statistics
- Legal basis: consent for users in the EEA, the UK and Switzerland (see the consent form below); legitimate interests for other regions
- Retention: event-level data for 2 months and user-level data for 14 months
- How to opt out: users in the EEA, the UK and Switzerland can decline in the consent form or change their choice at any time under "Settings → Ads and subscription settings → Ad privacy settings". Users in any region can reset or delete the advertising ID in the device settings.
- Details: How Google uses information from sites or apps that use our services
3. Advertising (free version / without a subscription only)
The free version of the App (when no subscription is active) uses the following third-party advertising services.
- Google AdMob (Google LLC): Google advertising policies
- Ad Generation (Supership Inc.): Informative Data Policy / Opt-out. Ads from Unity Ads (Unity Technologies) and maio (i-mobile Co., Ltd.) may be shown through Ad Generation mediation.
- Information collected: advertising ID, device model, OS and language, IP address (and the approximate location derived from it), and information about ad impressions and clicks
- Purpose: serving and measuring ads, and showing ads according to your interests
- Legal basis: consent for users in the EEA, the UK and Switzerland (the App uses a Google-certified consent management platform and shows a consent form on first launch); legitimate interests for other regions
- Retention: according to each advertising provider's policy
- How to opt out: users in the EEA, the UK and Switzerland can change or withdraw their consent at any time under "Settings → Ads and subscription settings → Ad privacy settings". If you do not consent, the App does not show ads. In other regions you can reset the advertising ID or opt out of personalized ads in the device settings. No ads are shown while a subscription is active.
4. Push notifications (Mastodon notifications in ZonePane)
- Information collected: the device token for push notifications (Firebase Cloud Messaging or Apple Push Notification service)
- Handling: when you enable notifications, the subscription information including the device token is sent to the Mastodon server you are connected to and to our relay server (push.zonepane.com). The relay server only forwards notifications to the App and does not store tokens or notification contents. Notification contents are relayed in encrypted form and decrypted on your device.
- Purpose: delivering new notifications
- Legal basis: consent (given when you enable notifications). Disabling notifications cancels the subscription.
5. Remote configuration (Firebase Remote Config)
The Firebase installation ID is sent to Google in order to deliver configuration settings for the App. This is the minimum information required to provide the App's functionality.
6. In-app purchases
Subscriptions and other purchases are processed through Google Play and the App Store, and purchase information is handled by Google and Apple under their respective privacy policies. We only handle the information needed to verify purchase status (such as purchase tokens and the store country code) and never receive payment details such as credit card numbers.
7. Social network account information
The App is a client for social networks such as X, Bluesky, Mastodon, Misskey and Taittsuu. Access tokens, timelines, posts and other information of each service are stored only on your device and are not sent to our servers (except for the notification relay described in section 4). The authentication pages on our websites (twitpane.com / zonepane.com) used during login only hand the received authentication data over to the App and do not store it. The handling of your information on each social network is governed by that service's own privacy policy.
Sharing with third parties and processors
We manage user information appropriately and do not provide it to third parties except in the following cases.
- When you have given your consent
- When processing is entrusted to the service providers listed above (Google, Supership, etc.) to the extent necessary to provide the App's functionality
- When disclosure is required by law
International transfers
The service providers listed above process data outside Japan, mainly in the United States. Information of users in the EEA, the UK and Switzerland is transferred to Google on the basis of appropriate safeguards such as the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
Your rights (EEA, UK and Switzerland)
If the GDPR or an equivalent law applies to you, you have the right to request access to, rectification or erasure of, or restriction of processing of your personal data that we handle, the right to data portability, the right to object to processing, and the right to withdraw your consent at any time (without affecting the lawfulness of processing before the withdrawal). You also have the right to lodge a complaint with the supervisory authority in your country of residence.
To exercise your rights, please contact us at the address under "Contact Us" below. Because we do not hold data that identifies you by name, we may ask you to provide information needed to locate your data, such as the advertising ID or the Firebase installation ID of your device. If we are technically unable to locate your data, we will let you know. You can withdraw your consent for advertising and analytics at any time in the App's settings.
Children
The App is provided in accordance with the age rating shown on each app store. We do not knowingly collect personal information from children.
Safety measures for personal information
We take all possible security measures to ensure the accuracy and safety of personal information.
Child Sexual Abuse and Exploitation (CSAE) Policy
1. Prohibition of inappropriate content
The App is a third-party client for social networks such as X, Bluesky, Mastodon, Misskey and Taittsuu. Content and behavior related to child sexual abuse and exploitation (CSAE) are strictly prohibited on these services. The App strongly supports this policy and works to prevent the following.
- Posting or sharing images, videos, text or other media related to CSAE
- Behavior that violates the operating policies or community guidelines of each server; the App supports monitoring of such behavior
2. Cooperation with servers (instances)
Operating policies may differ depending on the server (instance) you connect to. We expect connected servers to comply with CSAE-related policies, and the App:
- provides means to report inappropriate content directly to the server operator, and
- respects the guidelines and policies of the server you choose.
3. Content moderation
The App supplements the content moderation policies of the social networks it connects to by:
- making the existing reporting and blocking functions of each platform available in its interface, and
- providing a UI that makes inappropriate content and accounts easy to find.
4. Protection of minors
To provide an environment where all users, including minors, can use the App safely, the App:
- supports appropriate reporting and settings functions so that minors are protected on each platform, and
- applies an age rating to prevent use by users below the target age.
5. Data sharing
If CSAE-related behavior is discovered, we will report it to the appropriate law enforcement agencies or server operators. Where necessary, we will cooperate with third-party organizations (such as experts or non-profit organizations) to resolve the issue.
6. User responsibilities
Users must:
- report inappropriate content using the platform's reporting functions, and
- take care not to infringe the rights of others through the App.
7. Compliance with legal obligations
In connection with the use of social networks including X, Bluesky, Mastodon, Misskey and Taittsuu, the App fully complies with international and regional laws on the protection of children (for example, the Children's Online Privacy Protection Act and child abuse prevention laws).
Operation and monitoring
To keep providing a safe environment, we:
- strengthen cooperation with platforms and server operators, and
- regularly review and improve the App's policies.
Compliance with laws and review of this policy
We comply with Japanese laws, regulations and other norms applicable to the personal information we hold, and review this policy from time to time to improve it. This policy may be changed due to changes in our business, amendments to laws and regulations, etc. Changes will be published on this page, and the "Last updated" date at the top will be revised.
Contact Us
For inquiries about this policy and requests to exercise your rights regarding your personal data, please contact us at the following.
- X: @twitpane
- Email: info@panecraft.net