Privacy Policy
Effective date: August 7, 2026
1. Data We Collect
- Account data: your email address, hashed password, verification status, and subscription plan status.
- Usage and security data: IP address, API endpoint called, response status, and timestamp. These records are stored in the
api_logstable and are scheduled for automatic deletion after 7 days. - Cookies: an essential JWT session cookie configured as HTTP-only, Secure, and SameSite=Lax. It is used to keep you signed in and is not used for advertising.
2. Data We Do Not Collect
We do not collect your browsing history outside our service. We do not collect your precise location unless you deliberately provide or select a location when using a map or address-search feature.
3. Service Providers
We use a limited number of service providers to operate the service:
- Stripe processes subscription payments. Payment-card details are handled by Stripe, not stored by us. See the Stripe Privacy Policy.
- Lolipop SMTP currently delivers account and service emails. SendGrid may be added as an email-delivery provider in the future.
- Google Maps Platform may process an address or map query when you use address search or geocoding features. See the Google Privacy Policy.
- Cloudflare may be used in the future for content delivery and service security.
4. Cross-Border Data Transfers
Our primary service is operated from Japan. When you use the service, relevant account, payment, email, map-search, device, and security data may be transferred to these recipients:
- Stripe — United States: subscription payment processing.
- SendGrid — United States: email delivery, if this planned additional provider is introduced.
- Google Maps Platform — United States: maps, geocoding, and address search.
- Cloudflare — United States / global network: content delivery and security, if this planned provider is introduced.
These transfers support payment processing, essential service communications, map and address-search functions, and secure service delivery. Each provider processes and retains data under its applicable terms and privacy policy. Where required by the Korean PIPA, the GDPR, the Chinese PIPL, or other applicable law, we request consent before the transfer. You may decline or withdraw consent by contacting us, but features that require an international transfer may then be unavailable.
5. Data Retention
- Account data is retained until you request deletion, subject to records we must retain for legal, tax, fraud-prevention, or dispute-resolution purposes.
- Cross-border consent records are retained while needed to demonstrate your choice and meet applicable legal obligations.
- API logs are retained for 7 days.
- Rate-limit ban records are retained for up to 30 days.
6. Your Rights
You may request access to, correction of, or deletion of your personal data, or withdraw your cross-border transfer consent, by emailing minpaku@kago.me. We may ask you to verify your identity before completing a request. Depending on your jurisdiction, you may also have the right to object to or restrict processing and to lodge a complaint with a supervisory authority.
7. International Users
Our service is operated from Japan and our primary servers are located in Japan. If you access the service from another country, your information may be transferred to and processed in Japan and at the recipient locations listed above. We accept requests made under the PIPA, GDPR, PIPL, and other applicable privacy laws.
8. Contact
For privacy questions or requests, email minpaku@kago.me.