Privacy Policy
About this translation. This page is an English translation of maru's Japanese Privacy Policy, provided for reference. The Japanese Privacy Policy is the governing document; in the event of any discrepancy between the two, the Japanese version controls. The Japanese source is also still in draft form pending final legal review, so this translation may change without notice as that review concludes.
maru Privacy Policy v1 (Draft)
1. Business Operator Information
| Item | Details |
|---|---|
| Operator name | Zanmaido K.K. (株式会社三昧堂) |
| Representative | Yuji Kuwamizu |
| Personal Information Protection Manager | Yuji Kuwamizu (concurrent role) |
| Contact | hello@zanmaido.com |
| Registered address | 3914-67 Takachiho, Makizono-cho, Kirishima-shi, Kagoshima, Japan 899-6603 |
2. Personal Information We Collect
2.0 User Roles
The personal information we handle, and our purposes for handling it, differ by user role. As of this writing (Phase 0), only the "Individual User" and "Beta Participant" roles are active. We describe our intended handling of roles planned for future phases below as well.
| Role | Description | Availability |
|---|---|---|
| Individual User | A general user who uses the service to record and view their own health data | Phase 0 onward |
| Beta Participant | An individual user who registered by invitation during the Phase 0 invite-only beta (and separately agreed to an additional consent form) | Phase 0 onward |
| Family Viewer (reserved) | A family member or supporter who, with an individual user's explicit invitation, may view some of that user's health data | Not yet offered (under consideration for later in Phase 1) |
| HCP / Healthcare Professional (reserved) | A physician, dietitian, or similar professional who, with an individual user's explicit sharing consent, views that user's health data for care-guidance purposes | Not yet offered (under consideration for Phase 3b B2B expansion or later) |
Important: The "Family Viewer" and "HCP" roles are not offered as of Phase 0, and no data is collected or processed for them. If and when these roles are introduced, we will revise this Policy in accordance with §13 and obtain advance consent from the affected users.
2.1 Information We Collect From Users
a. Always collected (necessary to provide the service)
- Email address
- Display name (nicknames permitted)
- Password (stored hashed)
- Date of birth (for age verification)
- Sex
b. Optionally collected (to enrich your profile)
- Height, weight, body fat percentage
- Health goals (free text)
- General area of residence (city/town level)
c. Sensitive personal information (only after explicit consent)
- Medical history (optional)
- Current medications
- Allergy information
- Glucose values and spike history from CGM integration
- Meal photos (analyzed for nutritional content)
- Heart rate and sleep data (when connected via HealthKit)
- Health-related consultation history within AI chat
2.2 Information Collected Automatically
- Device information (OS version, app version, device model, language, time zone)
- Login history and app usage logs
- Crash and error information
- IP address (anonymized)
- Cookies and similar technologies (to maintain sessions on our web properties)
2.3 OS Permissions and Their Purposes
Our app uses the following iOS/Android permissions. Each is requested only when you enable the related feature within the app, and you may withdraw any permission at any time from your OS settings.
| OS Permission | Purpose | Data Collected | Effect if Denied | Legal Basis |
|---|---|---|---|---|
| HealthKit (iOS) / Health Connect (Android) | Connect and visualize heart rate, sleep, step count, and similar health data | HealthKit / Health Connect data you choose to share (may include sensitive personal information) | Automatic health-data sync is disabled (manual entry remains available) | Explicit consent, as this involves sensitive personal information (APPI Art. 2(3)) |
| Notifications (push) | Deliver reminders, glucose-anomaly alerts, and AI-generated suggestions | Device token | Push notifications are disabled (in-app display remains available) | Consent |
| Camera | Record meals or body-composition readings by taking a photo | The captured image (only sent if you choose to submit it) | Photo capture is disabled (selecting from your photo library remains available) | Consent |
| Photo Library | Log meals or set a profile photo from existing photos | Only the image(s) you select | Selecting images from your library is disabled | Consent |
| Bluetooth (planned) | Direct communication with CGM devices and wearables | Health-related data obtained from the sensor | Direct device pairing is disabled (OAuth-based integration remains available) | Explicit consent, as this involves sensitive personal information |
| Location (planned) | Bluetooth device scanning (required by OS on Android only) / region-specific content | Approximate device location (city/town level) | Bluetooth scanning is disabled; region-specific features are disabled | Consent |
| Microphone (planned) | Voice-based logging | Only audio you record | Voice input is disabled | Consent |
Important: We request only the minimum OS permissions necessary to provide a given feature. We do not collect data continuously in the background, and we do not request permissions unrelated to a feature you use. Our disclosures in Apple's App Privacy Label and Google Play's Data Safety section are kept consistent with this table.
3. Purposes of Use
| Purpose | Data Involved | Basis under the APPI |
|---|---|---|
| Providing the service (visualizing health data, AI-generated insights) | All categories | Specification and publication of purpose (Arts. 17, 21) + contract performance |
| Improving the service (A/B testing, feature evaluation) | Behavioral logs | Specification and publication of purpose (Arts. 17, 21) |
| Customer support | Inquiry content, usage information | Specification and publication of purpose (Arts. 17, 21) + contract performance |
| Billing (from Phase 1 onward) | Billing information | Specification and publication of purpose (Arts. 17, 21) + contract performance |
| Responding to legal obligations (inquiries, filings, etc.) | All categories, as necessary | As required by law (Art. 18(3)(i)) |
| Detecting and preventing misuse; keeping the service safe | Account information, usage logs | Specification and publication of purpose (Arts. 17, 21) |
| Report quality assurance (pre-delivery checks and post-delivery quality improvement) | Report text and the underlying health data used to generate it (may include sensitive personal information) | Specification and publication of purpose (Arts. 17, 21) + contract performance |
| Research, development, and statistical use | Anonymized data only | Consent (explicit consent where sensitive personal information is involved) |
On the "basis under the APPI" column: Unlike the GDPR, Japan's Act on the Protection of Personal Information (APPI) does not enumerate a list of "legal bases" such as legitimate interest. Instead, the general principle is that we specify and publish our purposes of use in advance (Arts. 17, 21) and handle data within that scope; separate consent is required for collecting sensitive personal information, providing it to third parties, or transferring it abroad. This table shows where each purpose sits within that framework.
We use sensitive personal information only for "providing the service," "customer support," and "report quality assurance" among the purposes above; if we use it for research and development, we obtain separate consent.
On "report quality assurance": because the report itself is our core deliverable, checking it and delivering it are inseparable. Quality assurance includes both (1) pre-delivery review (confirming, before a report reaches you, that the figures match the underlying aggregates and that the wording does not touch on anything prohibited), and (2) post-delivery quality improvement (rereading delivered reports to improve how they are generated). For quality assurance including (2), our default practice is that staff do not review content in a form linked to your name or nickname (our default operating practice is to review only figures and structure, with identifying names withheld). Review linked to your name occurs only with your explicit consent, or where a safety concern arises, and in either case we keep a record of the review.
Behavioral analytics for "service improvement" (data sent to PostHog) is carried out on the basis of the publication of this Policy. If you use a version of our mobile app that includes optional settings (to share "product usage" or "AI operational information"), your choice in those settings governs. Versions without those optional settings, and our web properties (nagaiki.ai), do not show this settings screen (see §6.1).
4. Provision to Third Parties
As a general rule, we do not provide your information to third parties without your consent.
Exceptions:
- Where required by law (e.g., a request from an investigative authority)
- Where necessary to protect a person's life, body, or property (for example, where you wish us to share information with your physician or an emergency medical provider in an emergency)
- Where necessary for public health or child welfare
- Cooperation with a national or local government agency carrying out a function prescribed by law
5. Outsourcing
To the extent necessary to provide the service, we outsource part of our operations to overseas providers. We provide the necessary and appropriate supervision of these providers required under Article 25 of the APPI.
Our principal outsourcing providers (category and location):
| Category | Principal Provider(s) | Provider Location (= transfer destination country) |
|---|---|---|
| AI response generation and meal-photo analysis | Anthropic / OpenAI / Google | United States |
| Backend, database, and storage | Supabase | United States |
| Billing processing (from Phase 1) | Stripe | United States |
| Operational support (behavioral analytics) | PostHog, Inc. | United States |
| Operational support (error monitoring) | Sentry | United States |
| Web hosting | Vercel | United States |
| Email delivery (notifications, inquiries) | Resend | United States |
For PostHog, we have selected the EU region, and data is stored in a data center in Germany (Frankfurt). However, because the contracting entity is the US company PostHog, Inc. (San Francisco), the transfer-destination country under Article 28 of the APPI is the United States (see §6.1).
Our full list of subprocessors is disclosed separately from this Policy, on a page kept continuously up to date. If this list changes, we will notify you within 30 days via an in-app notice and a message to your registered email address.
Public page: https://nagaiki.ai/subprocessors (currently available in Japanese)
Privacy policies of our principal providers:
- Anthropic: https://www.anthropic.com/legal/privacy
- OpenAI: https://openai.com/policies/privacy-policy
- Google (Vertex AI): https://cloud.google.com/terms/cloud-privacy-notice
- Supabase: https://supabase.com/privacy
- Stripe: https://stripe.com/privacy
- PostHog: https://posthog.com/privacy
- Sentry: https://sentry.io/privacy/
- Vercel: https://vercel.com/legal/privacy-policy
- Resend: https://resend.com/legal/privacy-policy
6. Provision to Third Parties Located Abroad
We transfer personal information to the outsourcing providers listed in §5. In every case, the transfer-destination country is the United States.
How we determine the transfer-destination country: whether a recipient qualifies as a "third party located abroad" under Article 28 of the APPI is determined not by where data is physically stored, but by the country where the recipient provider is located. Accordingly, even where we have selected a provider's EU region for data storage, the transfer-destination country remains the United States if that provider is a US legal entity.
The US personal-data-protection framework: the United States has no single comprehensive federal law governing personal information; instead, protection is governed by a patchwork of sector-specific and state laws (e.g., HIPAA, GLBA, CCPA, CPRA). The United States has not been recognized by Japan's Personal Information Protection Commission (PPC) as affording a standard of protection equivalent to Japan's.
Measures we take (our basis under Article 28 of the APPI):
- As a general rule: in accordance with §7, we obtain your consent to providing information to third parties located abroad (Art. 28(1)). When obtaining that consent, we provide you, through this Policy, with information about the destination country's name, that country's personal-data-protection system, and the measures taken by the recipient (APPI Enforcement Rules, Art. 17).
- PostHog (behavioral analytics): the transfer-destination country is the United States (even where we have selected that provider's EU region, the country is determined by the provider's location, so it remains the United States). We cannot rely on any exemption based on the EU's adequacy determination. As described under "As a general rule" above, this transfer is likewise based on your consent under §7 and the information disclosure required by Enforcement Rules Art. 17. We do not currently rely on the "compliant-system" basis defined in Article 16(1) of the APPI Enforcement Rules for this transfer. If we come to rely on that basis in the future, we will revise this Policy to say so explicitly.
- Data including sensitive personal information: for every outsourcing provider, we additionally obtain your explicit consent under §7.
Each outsourcing provider works to protect personal information through its own privacy policy and through appropriate technical and organizational measures (encryption, access controls, audits).
Full details of our subprocessor list, and links to each provider's privacy policy, are disclosed on the public page referenced above.
6.1 About Behavioral Analytics (PostHog)
For accuracy of disclosure, we separately set out the following details regarding PostHog, which we use for behavioral analytics.
| Item | Details |
|---|---|
| Contracting entity (provider) | PostHog, Inc. (United States, San Francisco) |
| Transfer-destination country | United States (determined by provider location; no exemption based on the EU's adequacy determination applies) |
| Data storage location | Germany (Frankfurt). We use PostHog Cloud EU, whose infrastructure runs on AWS's eu-central-1 region |
| Basis under Article 28 | As described under "As a general rule" in §6 (consent under §7 plus the information disclosure required by Enforcement Rules Art. 17). We do not rely on the "compliant-system" basis under Enforcement Rules Art. 16(1) |
| Identifiers we send | See below. None of these are anonymized information |
About the identifiers we send (they are not "anonymous"):
- Mobile app: we send a persistent pseudonymous analytics ID that we issue (not directly tied to your name or contact information, and consistent across your use of the app) together with a session ID. We maintain an internal mapping between this pseudonymous ID and the user it belongs to. Accordingly, this pseudonymous ID qualifies as "personal information" under the APPI, and is neither anonymized information nor a third-party provision of pseudonymously processed information. We delete this mapping once the basis for behavioral analytics ends (for example, if you turn off the relevant optional setting in a version that offers one, if measurement under this Policy ends, or if your account is deleted).
- Web properties (nagaiki.ai): for behavioral analytics after login, we send our own account ID (your Supabase user ID) directly as the identifier. Because this corresponds directly to your account in our database, it is likewise personal information.
- In neither channel do we send your name, email address, photos, meal content, health figures, or chat text.
About training use of data sent to AI providers (Anthropic / OpenAI / Google, etc.): we have opted out, through each provider's API settings, of allowing personal information we send for AI response generation and meal-photo analysis (such as chat history and meal photos) to be used to train that provider's own models. The APIs we use are configured, by default, not to use submitted data to train the provider's own models, and we maintain that setting explicitly. For Google (the Gemini API via Vertex AI), we rely on Google Cloud's service-specific terms, which provide that customer data is not used to train Google's foundation models. If a provider's settings change in a way that alters this protection, we will revise this Policy and notify you in advance in accordance with §13.
By using the service, you are deemed to have consented to these transfers to third parties located abroad, in accordance with §7 ("Obtaining Consent") below.
7. Obtaining Consent
7.1 General Personal Information
We obtain your consent to this Policy when you register your account.
7.2 Sensitive Personal Information
We collect health data (CGM readings, heart rate, sleep, medical history, medications, etc.) only after obtaining your voluntary consent through an explicit in-app consent UI (a checkbox plus a "I agree" button). We record consent logs on our server.
7.3 Cross-Border Transfers
We treat your consent to this Policy as covering the transfers to third parties located abroad described in §6, and we additionally obtain explicit consent through the app's interface.
7.4 Withdrawing Consent
You may withdraw your consent at any time, through any of the following: (a) the "Settings → Privacy & Consent" screen in the app, (b) your OS settings (e.g., withdrawing HealthKit permissions), or (c) written notice to hello@zanmaido.com.
Withdrawing consent may make some features of the service unavailable. The effect of withdrawing each type of consent is as follows:
| Consent Withdrawn | Effect | Handling of Existing Data |
|---|---|---|
| Withdrawal of consent to this Policy as a whole | Treated the same as account deletion; the entire service becomes unavailable | Deleted within 30 days in accordance with §9 |
| Consent to handling sensitive personal information (health data generally) | Glucose visualization, AI analysis, and health-data logging features are disabled | The related data is deleted within 30 days (except anonymized data) |
| Consent to CGM / health-app integration | Automatic syncing stops. Manual entry remains available | Data already synced may be retained or deleted, at your choice, via settings |
| Consent to AI chat use | AI chat is disabled | Chat history may be retained or its deletion requested, in accordance with §9 |
| Consent to cross-border transfers | Features that involve sending data abroad (AI response generation, photo analysis, etc.) are disabled; core logging features remain available | Existing data is generally retained; you may separately request deletion |
| Consent to marketing communications | Promotional messages and newsletters stop | Existing delivery history is retained for one year as an audit log |
| Consent to research, development, and statistical use (secondary use of anonymized data) | You are excluded from future anonymization for this purpose | Data already anonymized cannot be re-identified, and therefore cannot be restored or deleted (see §5, "irreversibility of anonymized information") |
| Consent to participate in our Slack community | You leave the community. Past posts remain, but any identifying information is anonymized | Governed by Slack's own retention policy |
Important: withdrawing consent may affect part or all of the service we can provide to you. Before withdrawing, we recommend reviewing the "Settings → Privacy & Consent → Simulate effect of withdrawal" screen (planned for Phase 1) to see the effect in advance.
8. Security Measures
8.1 Organizational Measures
- Appointment of a Personal Information Protection Manager
- Established internal handling rules
- Supervision of outsourcing providers
8.2 Personnel Measures
- Training for staff (including contracted personnel)
- Confidentiality agreements
8.3 Physical Measures
- Restricted access to data centers and servers (per our providers' standards)
8.4 Technical Measures
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest (AES-256 equivalent)
- Row-level access control via Row Level Security (RLS)
- Log auditing
- Minimization of unnecessary permissions
9. Retention Period
| Data | Retention Period |
|---|---|
| Account information and usage data | For the life of the account |
| After account deletion | Deletion completed within 30 days of your deletion request (to allow for backup-propagation delay and recovery from accidental deletion) |
| Billing information | For the period required by law (7 years, as accounting records) |
| Logs and audit records | For the period required by law (1 year, as a standard) |
10. Requests for Disclosure, Correction, Suspension of Use, and Deletion
You may make any of the following requests:
- Disclosure of the personal data we hold about you
- Correction, addition, or deletion
- Suspension of use or erasure
- Suspension of provision to third parties
- Notice of the procedure for making these requests
How to request: by email to hello@zanmaido.com, or via a dedicated form (planned). We may ask you to provide identifying information to verify your identity.
Response timeline: we aim to respond without undue delay after receiving your request (generally within 14 days, and no later than 30 days, in line with the "without delay" requirement of APPI Art. 33 and its guidelines). We send an initial "request received" reply within 7 days of receipt.
11. Cookies and Similar Technologies
Our web properties (nagaiki.ai) use cookies and similar technologies to maintain your login session and for site analytics. You may disable these through your browser settings.
12. Age Restriction
12.1 Minimum Age
This service is intended for users 18 years of age or older. Users under 18 may not use the service. We confirm age based on the date of birth you self-report at registration.
12.2 If Use by a Minor Is Discovered
If we discover that a user under 18 is using the service, we will suspend that account and delete the associated data in accordance with §9. Requests to delete an account or data, made by the user or a guardian, may be sent to hello@zanmaido.com and will be handled under the procedure in §10.
13. Revisions
If we revise this Policy, we will notify you at least 30 days before the revision takes effect, via an in-app notice and a message to your registered email address. Your continued use of the service after the effective date is deemed acceptance. For material changes (such as adding a new purpose of use or expanding the scope of third-party provision), we will obtain your renewed consent.
14. Contact
| Item | Details |
|---|---|
| Personal information inquiries | hello@zanmaido.com |
| Personal Information Protection Manager | Yuji Kuwamizu |