1. Operator and Scope
In this policy, the “Operator” or “we” means the entity operating the Service (an individual business operator). The operator's name and full address are disclosed without delay by email upon the data subject's request under Article 32(1) of the Act on the Protection of Personal Information (ryugakujinja@gmail.com). Personal information protection manager: the operator (same contact desk). This policy applies to all processing of your personal information when you access, register for and use the Service.
2. Information We Collect
Information you provide
- Account information: email address, display name, password (stored only as a hash, never in plain text), language preference.
- Google sign-in information: the stable account identifier (sub) supplied by Google, verified email address, display name and locale information within the granted scope. We do not persist Google access tokens, refresh tokens or ID tokens, and do not use a Google email address as the identity key.
- Profile (all voluntary): nationality/region, native language, education stage and current school/major, scores (GPA, JLPT / TOEFL / IELTS / EJU, etc.), target stage, year, schools, majors and professors, residence status, research and career intentions. You decide how much to fill in.
- User content: text you submit to tools (research plans, statements, ES, email drafts), uploaded files (PDFs, screenshots, résumés), voice-input audio and its transcripts, and generated results you save (drafts, reviews, experience cards, mistake notebooks, timelines).
- Inquiry and booking information: display name and contact details (email or WeChat ID) submitted through inquiry/booking forms.
- Payment-related information: subscription and entitlement status, Hatsuho balance and consumption records. Card details are processed directly by the payment provider shown at checkout; we do not store your full card number.
Information collected automatically
- Authentication and security data: IP address and device information (User-Agent) at sign-in. One-time verification codes are stored as single-use, attempt-limited HMAC hashes. During Google sign-in, we briefly retain hashed OAuth state, browser-binding and nonce values together with PKCE verification data, and invalidate them after use. We do not retain these as reusable plaintext credentials.
- Session data: server-side session tokens with creation/activity/expiry times and associated IP and device information.
- Access and usage logs: access times, page paths, feature-usage events, and AI usage and cost records (for quota management and billing).
- Analytics data (on by default once you are signed in; you can turn it off at any time): we record minimized page paths, feature events, coarse device/browser classes and delivery delay first-party, and store a random pseudonymous identifier (anon_id) and session identifier in the browser. Analytics events do not store raw IP addresses, full User-Agent strings, search terms, user-entered content or business-object IDs. Identifiers rotate on sign-out or account switching. This production version does not enable browser-direct third-party product analytics (Section 7).
3. Purposes of Use
We use personal information to the extent necessary for the following purposes:
- Providing, maintaining and personalizing the Service's features (search, matching, generation, review, practice, timelines);
- Running AI features: sending your inputs to third-party AI providers to generate results (Section 4);
- Authentication, session management, abuse prevention and security;
- Processing subscriptions, Hatsuho and billing (through the payment provider shown at checkout) and making communications required under commerce law;
- Responding to inquiries and sending important service notices;
- Analyzing usage in aggregated/statistical form to improve features and develop new ones;
- Complying with legal obligations, handling disputes and protecting legitimate rights.
We will obtain your prior consent before using personal information beyond these purposes, except where permitted by law.
4. AI Processing and Third-Party Model Providers
Generation, review, matching, parsing and transcription rely on third-party AI providers (currently including DeepSeek and Google (Gemini), as actually enabled). Text you submit to AI tools, uploaded files and voice data are sent to these providers to the extent necessary to generate results.
- We do not use your user content to train our own models; transmission to third parties is solely to generate the results you request;
- Generated results are stored in your account as run history and saved content, and you can delete them yourself;
- Please avoid submitting highly sensitive information you do not want processed by third parties (Section 12).
5. Voice Input
When you use voice input, processing follows one of two paths depending on your browser:
- In-browser speech recognition: where the browser's speech feature (e.g. Web Speech API) is used, your audio is processed by the browser vendor (e.g. Google) under its own terms, and we receive only the resulting text;
- Server-side transcription: where the browser lacks support or the feature is enabled, recordings are uploaded to our servers and sent to a speech-to-text provider for transcription; audio is used solely to produce the transcript.
6. Cookies and Local Storage
We use cookies and browser local storage to keep you signed in, remember your language and save UI state. Before you choose, we create a strictly necessary random consent-coordination identifier so tabs and the server apply one privacy preference. It is never written to analytics events or used to link behavior, and is retained for no more than one year. Analytics pseudonymous/session identifiers and the retry queue are created only while analytics is on, and when you are not signed in they are not created before you explicitly opt in. You can turn analytics off or withdraw at any time from Analytics settings in the footer; that immediately clears local analytics identifiers and queued events without affecting core features. Global Privacy Control (GPC) and Do Not Track (DNT) override any stored grant. We use no third-party advertising cookies and do not track you for advertising.
You can manage or clear cookies and local storage in your browser; disabling some items may break sign-in and related features.
7. Product Analytics
This production version uses only first-party product analytics gated by our server and does not enable browser-direct delivery to PostHog or another analytics vendor. To find faults and keep improving the service, the server accepts minimized page paths and allow-listed feature events by default once you are signed in; when you are not signed in, it collects them only after you explicitly opt in. You can turn analytics off at any time in Analytics settings in the footer; turning it off, GPC and DNT stop subsequent collection at the server boundary. We do not use autocapture, input capture, session recording, heatmaps, performance tracking or automatic exception capture.
8. Sharing and Entrustment
We do not sell your personal information, and do not share it without consent except in the following cases:
- Entrustment: within the scope necessary for the purposes of use, we entrust processing to providers in these categories, with necessary and appropriate supervision — identity authentication (Google sign-in, when enabled), AI model providers (DeepSeek, Google, etc.), payment processing (the provider shown at checkout), email delivery (e.g. Resend), SMS delivery (when enabled), cloud infrastructure/hosting (Google Cloud), product analytics (PostHog, when enabled);
- Legal grounds: where required by law, or where necessary to protect life, body or property and consent is difficult to obtain, and other cases permitted by law;
- Business succession: transfers accompanying mergers or business transfers (the successor is bound by this policy).
9. Transfers to Third Parties Outside Japan
Some of the above providers are located outside Japan. Google sign-in authentication and some AI model services are provided by Google in the United States, while other AI model providers include DeepSeek in China. The payment provider may be Stripe or Creem depending on deployment and region; its location and cross-border processing terms are described at checkout and in that provider's privacy policy. Email delivery (Resend) and analytics (PostHog) are mainly located in the United States. Cloud infrastructure and hosting for this service are provided by Google Cloud, with servers located in the United States. Your personal information may therefore be provided to third parties abroad to the extent necessary for entrusted processing.
- Information on each country's data-protection regime is available in the surveys published by Japan's Personal Information Protection Commission (PPC);
- We require overseas recipients, by contract, to implement protections equivalent to Japanese law and monitor their implementation;
- Where the law requires consent, we obtain it through this policy and on-screen notices before you use the relevant features (AI generation, payment, etc.).
10. Security Measures
- Organizational and personnel measures: designated responsibility for data handling, restricted access to personal data, and necessary training and supervision;
- Technical measures: encrypted transport (TLS); hashed password storage; HMAC-hashed, attempt- and time-limited one-time codes; access control and operation logging;
- Session protection: sessions are revoked immediately when you sign out, change your password, or your account is suspended;
- Awareness of the external environment: some entrusted providers handle personal data in the United States, China and other countries; we implement security measures with knowledge of those countries' data protection regimes (Section 9).
No transmission or storage method is absolutely secure; please safeguard your password. In the event of a reportable breach, we will report to the PPC and notify affected individuals as required by law.
11. Retention and Deletion
- While your account exists, we retain your account information, profile and user content to provide the Service;
- You can delete saved content and run history within the Service at any time;
- Analytics event detail that can be linked to a browser, session or account is retained for no more than 90 days. Before expiry, we may create anonymous daily aggregates containing no user, browser, session, network or event identifiers for longer-term trend analysis;
- Withdrawing analytics consent stops future collection and clears local identifiers and the retry queue. When an account is deleted, we delete analytics events linked to it and sever the link between its former pseudonymous identifiers and any remaining anonymous events;
- When you delete your account, we delete personal information tied to it except records needed for security, preventing repeat-registration abuse of new-account benefits or free quotas, dispute handling, or legal obligations. We normalize email addresses and phone numbers and process them using HMAC-SHA256 protected by a server-side secret. We retain only the identifier type (email or phone) and an irreversible digest, not the original email address or phone number. For Google sign-in, we erase the identity's optional profile and retain its stable account identifier (sub) as a deletion tombstone for the same purpose. We use these records only for account security and preventing repeat-registration abuse, not for marketing, advertising targeting, or general profiling. We retain them only for the period necessary for those purposes and then delete them. Other security logs and transaction records are deleted after the statutory or necessary period.
12. Sensitive Personal Information
We do not actively request “special care-required personal information” under Japanese law (health and medical history, disabilities, beliefs, criminal history, etc.). If you include such information in free-text fields or uploads, you are deemed to consent to its handling under this policy, including AI processing under Section 4. Please avoid submitting unnecessary sensitive information; you can delete submitted content at any time or request deletion via Section 15.
13. Minors
Users under 18 should use the Service with the consent of a legal guardian. The Service is not offered to children under 13; if we learn we have collected a minor's personal information without guardian consent, we will delete it promptly.
14. Your Rights (Disclosure and Related Requests)
Regarding retained personal data, you may request under law: notification of purposes of use; disclosure (including records of third-party provision); correction, addition or deletion; and suspension of use or of third-party provision.
- Most account information, profile data and saved content can be viewed, corrected or deleted directly within the Service;
- For other requests, contact the desk in Section 15. After verifying that the requester is the data subject or their legal representative, we will respond within a reasonable period;
- We charge no fee for such requests in principle; where actual costs (e.g. postage) arise, we will explain them in advance.
15. Contact; Changes to This Policy
For inquiries, complaints and disclosure requests concerning personal information, contact: personal information desk ryugakujinja@gmail.com. We will respond sincerely and promptly. If you are dissatisfied with our response, you may also consult or complain to Japan's Personal Information Protection Commission (PPC).
This policy may be updated as laws or the Service change. We will revise the date at the top of this page, and announce material changes separately by posting on the Service or by email.