relay
Privacy Policy
We collect the verified e-mail, display name and identifier from your identity provider, the project content you enter, Stripe's customer ID and subscription state (card details never reach us), and GA4 analytics. We use it only to provide, bill, support and improve the Service, never to train models. Deleting your account removes your e-mail and display name at once. Requests: [email protected].
This is a courtesy translation. The Japanese text is the binding version.
TechJapan LLC (the Company) recognises the importance of personal data, complies with the Act on the Protection of Personal Information of Japan and related laws and guidelines, and handles personal data obtained through the services it provides under the Hadano AI Cabinet name (including relay; the Service) as set out below.
1. Basic policy
The Company obtains personal data by lawful and fair means, only to the extent necessary for the stated purposes, and uses it for no other purpose. Personal data is never used to train machine-learning models.
2. Definition
“Personal data” means information about a living individual that can identify that individual by name, e-mail address or other descriptors, including information that can easily be combined with other information to do so.
3. Data we collect
| Category | Items | Source |
|---|---|---|
| Account | Verified e-mail address, display name, the identity provider’s issuer and subject identifiers | Google / GitHub / your organisation’s SSO, within the scope you grant at sign-in |
| Project content | Project name, event records (file names, excerpts of what changed, descriptions of the work; the level of detail is set by the user), e-mail addresses and display names on the allow-list, invitee e-mail addresses | Your input and the development tools (MCP, hook) you configure |
| Payment | Stripe customer ID, subscription ID and state, billed number of people, country/region of the billing address (held by Stripe for tax) | Stripe |
| Device and connection | Device-token issue and revocation times, IP address, user agent, access time | Server logs |
| Analytics | Pages viewed, referrer, device type, approximate region | Google Analytics 4 (cookies) |
| Enquiries | Name, e-mail address, company, message | Your input |
The Company does not collect card numbers, expiry dates or security codes. They are entered on Stripe’s pages and managed by Stripe.
4. Purposes
- Providing the Service, verifying identity, and showing “who did what” to members of the same project only
- Billing and payment, issuing invoices and receipts
- Important notices about the Service (changes to terms or prices, maintenance, incidents, security)
- Responding to enquiries
- Detecting and preventing abuse; keeping the Service secure
- Improving the Service and developing features, in statistical form that identifies no individual
- Compliance with law
5. Third parties and processors
- Except as required by law, the Company does not provide personal data to third parties without consent.
- The Company entrusts processing to the following providers and supervises them appropriately:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud (Google LLC) | Server operation, data storage | USA |
| Cloudflare, Inc. | Traffic relay and protection, website delivery | USA |
| Stripe, Inc. / Stripe Japan K.K. | Payment processing, tax calculation, invoicing | USA, Japan |
| Google LLC (Google Analytics 4) | Website analytics | USA |
| Identity providers (Google LLC, GitHub, Inc., your organisation’s SSO) | Identity verification | USA and others |
- Members of the same project see the e-mail addresses and display names on the allow-list. This is a function of the Service, to which you consent by joining a project. Users of other projects do not see them.
- Personal data may be transferred to a successor in the event of a business transfer or merger, within the scope of the succession.
6. Transfers outside Japan
Some processors above are located in the United States. Under Article 28 of the Act, the Company has reviewed the data-protection regime of that country and the measures each processor takes, and requires by contract that they handle data in line with the Act. Information about those regimes is available from the contact below.
7. Security
- Encryption in transit (TLS). The server exposes no inbound port and is reachable only through Cloudflare.
- Separation of personal data: event records carry only an opaque ID issued by the Service; e-mail addresses and display names live in a separate mapping table. Deleting the mapping preserves the integrity (hash chain) of the records.
- Secrets (API keys, OAuth secrets, payment signing keys) live only in environment variables and never appear in responses, logs or the repository.
- Administrative actions (invitations, revocations, membership changes, deletions) are recorded in a tamper-evident audit log containing no personal data.
- Staff training and least-privilege access.
8. Retention and deletion
| Data | Retention |
|---|---|
| E-mail address and display name (mapping table and identity record) | Deleted (nulled) immediately on account deletion or on request. Deleting a project deletes that project’s mapping table |
| Device tokens | Invalid once revoked; all revoked on account deletion |
| Event records | Contain only Service-issued IDs, no personal data. Deleted with the project |
| Audit log | Contains no personal data. Retained after project deletion to prove the deletion |
| Payment records | 7 years from the transaction, as required by bookkeeping law |
| Access logs | Deleted within 90 days |
9. Cookies and analytics
- The Service uses an HttpOnly cookie to keep you signed in. It is invalidated on sign-out or account deletion.
- Our website and app use Google Analytics 4 to improve the Service. Google Analytics uses cookies to collect browsing information, which we do not combine with information that identifies you. See Google’s Privacy Policy. You can disable collection in your browser or with the Google Analytics opt-out add-on.
10. Access, correction, suspension and deletion requests
You may request disclosure, correction, addition, deletion, suspension of use or erasure of your personal data, or the cessation of third-party provision. Contact us below; after verifying your identity (for example, a message from the e-mail address you sign in with) we respond without delay.
You can also delete your account yourself at any time from the Service, which removes your e-mail address and display name immediately.
11. Changes to this policy
The Company may revise this policy when laws or the Service change. Revisions are posted on this page, and material changes are also sent to the registered e-mail address. A revised policy takes effect when posted here.
12. Contact
| Company | TechJapan LLC (TechJapan合同会社) |
| Address | 1-45 Taishin-cho, Hadano, Kanagawa 257-0034, Japan |
| Contact | [email protected] |
| Personal data protection officer | Managing Member, TechJapan LLC |
Established: 5 September 2026
Frequently asked questions
Can other users see my e-mail address?
Members of the same project see e-mail addresses and display names in the allow-list. Users of other projects cannot. Event records themselves carry only an opaque ID (mbr_…) issued by the Service.
Do you store my card number?
No. Card details are entered on Stripe's pages. We receive only Stripe's customer ID, the subscription state and the billed number of people.
What is removed when I delete my account?
Your e-mail address and display name are removed immediately from every project's mapping table and from your identity record, and all device tokens are revoked. Event records keep only the ID, which no longer links to anyone.