Tooru
Privacy Policy
What we hold, who processes it on our behalf, how long we keep it, and how you get it out or have it deleted.
Draft. This document has not yet been reviewed by counsel and its effective date is not set.
What we hold
We hold only what the service needs to run. We never hold card details — payment happens on Stripe’s own page and only a customer reference and subscription state come back to us.
- Your account
- Name, email address, whether the address is confirmed, and a hash of your password. We never store the password itself.
- Signing in
- Your IP address and browser user agent against each session, and one-time values for email confirmation and password resets. Sessions expire after 7 days.
- Abuse prevention
- A counter keyed on your IP address and the path you called, so that sign-up and email endpoints cannot be flooded. Deleted after 1 hour.
- Your organisation
- Organisation name, language, time zone, billing currency, and the reference to your Stripe customer record.
- Your diagnoses
- The URLs you asked us to diagnose, the scores and findings, and a digest of each page (see “What we send to AI”). We keep these for the life of your account because tracking change over time is the point of the service.
- Billing
- An append-only ledger of credit grants and consumption, and your subscription state.
- Records
- Consent records (what you agreed to, which version, with IP address and user agent), an audit log of actions taken in your account, and any data export or deletion requests you make.
What we send to AI
When you generate an AI analysis, we send a digest of the diagnosed page to Anthropic: the title and meta description, up to 1,500 characters of the main body, up to 12 headings, up to 12 navigation labels, and the list of structured-data types. We do not send your account details, other customers’ data, or the full HTML.
If you ask us to diagnose a page that is behind a login, the content of that page is included in the digest. Only submit pages you are willing to have processed this way.
Who processes data on our behalf
These are the only services we transmit data to. Where a provider is outside Japan, your data leaves Japan.
| Provider | Purpose | Where the data sits |
|---|---|---|
| Supabase | Database | Tokyo, Japan |
| Vercel | Hosting and running the application | Functions run in Tokyo; logs are held by Vercel (United States) |
| Resend | Sending confirmation and password-reset email | United States |
| Anthropic | AI analysis and AI reading | United States |
| Stripe | Payments and subscriptions | United States and Ireland |
How long we keep it
Sessions expire after 7 days. Abuse-prevention counters are deleted after 1 hour. Application logs are kept for 7 days. Diagnoses, reports and the billing ledger are kept for the life of your account.
We have not yet fixed how long we keep data after an account is closed. We will state a period here before general availability, and we will not state one we cannot carry out.
Getting your data out, or deleted
You can request an export of your data, or its deletion, from Settings. Both are recorded so you can see the status of a request.
You can also write to contact@untype.jp. If you are in the EU or the UK you have the rights the GDPR gives you, including access, rectification, erasure, restriction, portability and objection.
Cookies
One cookie, for keeping you signed in. It is HttpOnly, SameSite=Lax, and Secure in production, and it is scoped to this host only, so it is never sent to tooru.ai.
We use no analytics or advertising cookies. If that changes, this page changes first.
Changes to this policy
We record the version of this document you agreed to. If we change it in a way that affects you, we will tell you before the change takes effect.