Privacy Policy

About this translation. This page is an English translation of maru's Japanese Privacy Policy, provided for reference. The Japanese Privacy Policy is the governing document; in the event of any discrepancy between the two, the Japanese version controls. The Japanese source is also still in draft form pending final legal review, so this translation may change without notice as that review concludes.

maru Privacy Policy v1 (Draft)

1. Business Operator Information

ItemDetails
Operator nameZanmaido K.K. (株式会社三昧堂)
RepresentativeYuji Kuwamizu
Personal Information Protection ManagerYuji Kuwamizu (concurrent role)
Contacthello@zanmaido.com
Registered address3914-67 Takachiho, Makizono-cho, Kirishima-shi, Kagoshima, Japan 899-6603

2. Personal Information We Collect

2.0 User Roles

The personal information we handle, and our purposes for handling it, differ by user role. As of this writing (Phase 0), only the "Individual User" and "Beta Participant" roles are active. We describe our intended handling of roles planned for future phases below as well.

RoleDescriptionAvailability
Individual UserA general user who uses the service to record and view their own health dataPhase 0 onward
Beta ParticipantAn individual user who registered by invitation during the Phase 0 invite-only beta (and separately agreed to an additional consent form)Phase 0 onward
Family Viewer (reserved)A family member or supporter who, with an individual user's explicit invitation, may view some of that user's health dataNot yet offered (under consideration for later in Phase 1)
HCP / Healthcare Professional (reserved)A physician, dietitian, or similar professional who, with an individual user's explicit sharing consent, views that user's health data for care-guidance purposesNot yet offered (under consideration for Phase 3b B2B expansion or later)

Important: The "Family Viewer" and "HCP" roles are not offered as of Phase 0, and no data is collected or processed for them. If and when these roles are introduced, we will revise this Policy in accordance with §13 and obtain advance consent from the affected users.

2.1 Information We Collect From Users

a. Always collected (necessary to provide the service)

  • Email address
  • Display name (nicknames permitted)
  • Password (stored hashed)
  • Date of birth (for age verification)
  • Sex

b. Optionally collected (to enrich your profile)

  • Height, weight, body fat percentage
  • Health goals (free text)
  • General area of residence (city/town level)

c. Sensitive personal information (only after explicit consent)

  • Medical history (optional)
  • Current medications
  • Allergy information
  • Glucose values and spike history from CGM integration
  • Meal photos (analyzed for nutritional content)
  • Heart rate and sleep data (when connected via HealthKit)
  • Health-related consultation history within AI chat

2.2 Information Collected Automatically

  • Device information (OS version, app version, device model, language, time zone)
  • Login history and app usage logs
  • Crash and error information
  • IP address (anonymized)
  • Cookies and similar technologies (to maintain sessions on our web properties)

2.3 OS Permissions and Their Purposes

Our app uses the following iOS/Android permissions. Each is requested only when you enable the related feature within the app, and you may withdraw any permission at any time from your OS settings.

OS PermissionPurposeData CollectedEffect if DeniedLegal Basis
HealthKit (iOS) / Health Connect (Android)Connect and visualize heart rate, sleep, step count, and similar health dataHealthKit / Health Connect data you choose to share (may include sensitive personal information)Automatic health-data sync is disabled (manual entry remains available)Explicit consent, as this involves sensitive personal information (APPI Art. 2(3))
Notifications (push)Deliver reminders, glucose-anomaly alerts, and AI-generated suggestionsDevice tokenPush notifications are disabled (in-app display remains available)Consent
CameraRecord meals or body-composition readings by taking a photoThe captured image (only sent if you choose to submit it)Photo capture is disabled (selecting from your photo library remains available)Consent
Photo LibraryLog meals or set a profile photo from existing photosOnly the image(s) you selectSelecting images from your library is disabledConsent
Bluetooth (planned)Direct communication with CGM devices and wearablesHealth-related data obtained from the sensorDirect device pairing is disabled (OAuth-based integration remains available)Explicit consent, as this involves sensitive personal information
Location (planned)Bluetooth device scanning (required by OS on Android only) / region-specific contentApproximate device location (city/town level)Bluetooth scanning is disabled; region-specific features are disabledConsent
Microphone (planned)Voice-based loggingOnly audio you recordVoice input is disabledConsent

Important: We request only the minimum OS permissions necessary to provide a given feature. We do not collect data continuously in the background, and we do not request permissions unrelated to a feature you use. Our disclosures in Apple's App Privacy Label and Google Play's Data Safety section are kept consistent with this table.


3. Purposes of Use

PurposeData InvolvedBasis under the APPI
Providing the service (visualizing health data, AI-generated insights)All categoriesSpecification and publication of purpose (Arts. 17, 21) + contract performance
Improving the service (A/B testing, feature evaluation)Behavioral logsSpecification and publication of purpose (Arts. 17, 21)
Customer supportInquiry content, usage informationSpecification and publication of purpose (Arts. 17, 21) + contract performance
Billing (from Phase 1 onward)Billing informationSpecification and publication of purpose (Arts. 17, 21) + contract performance
Responding to legal obligations (inquiries, filings, etc.)All categories, as necessaryAs required by law (Art. 18(3)(i))
Detecting and preventing misuse; keeping the service safeAccount information, usage logsSpecification and publication of purpose (Arts. 17, 21)
Report quality assurance (pre-delivery checks and post-delivery quality improvement)Report text and the underlying health data used to generate it (may include sensitive personal information)Specification and publication of purpose (Arts. 17, 21) + contract performance
Research, development, and statistical useAnonymized data onlyConsent (explicit consent where sensitive personal information is involved)

On the "basis under the APPI" column: Unlike the GDPR, Japan's Act on the Protection of Personal Information (APPI) does not enumerate a list of "legal bases" such as legitimate interest. Instead, the general principle is that we specify and publish our purposes of use in advance (Arts. 17, 21) and handle data within that scope; separate consent is required for collecting sensitive personal information, providing it to third parties, or transferring it abroad. This table shows where each purpose sits within that framework.

We use sensitive personal information only for "providing the service," "customer support," and "report quality assurance" among the purposes above; if we use it for research and development, we obtain separate consent.

On "report quality assurance": because the report itself is our core deliverable, checking it and delivering it are inseparable. Quality assurance includes both (1) pre-delivery review (confirming, before a report reaches you, that the figures match the underlying aggregates and that the wording does not touch on anything prohibited), and (2) post-delivery quality improvement (rereading delivered reports to improve how they are generated). For quality assurance including (2), our default practice is that staff do not review content in a form linked to your name or nickname (our default operating practice is to review only figures and structure, with identifying names withheld). Review linked to your name occurs only with your explicit consent, or where a safety concern arises, and in either case we keep a record of the review.

Behavioral analytics for "service improvement" (data sent to PostHog) is carried out on the basis of the publication of this Policy. If you use a version of our mobile app that includes optional settings (to share "product usage" or "AI operational information"), your choice in those settings governs. Versions without those optional settings, and our web properties (nagaiki.ai), do not show this settings screen (see §6.1).


4. Provision to Third Parties

As a general rule, we do not provide your information to third parties without your consent.

Exceptions:

  • Where required by law (e.g., a request from an investigative authority)
  • Where necessary to protect a person's life, body, or property (for example, where you wish us to share information with your physician or an emergency medical provider in an emergency)
  • Where necessary for public health or child welfare
  • Cooperation with a national or local government agency carrying out a function prescribed by law

5. Outsourcing

To the extent necessary to provide the service, we outsource part of our operations to overseas providers. We provide the necessary and appropriate supervision of these providers required under Article 25 of the APPI.

Our principal outsourcing providers (category and location):

CategoryPrincipal Provider(s)Provider Location (= transfer destination country)
AI response generation and meal-photo analysisAnthropic / OpenAI / GoogleUnited States
Backend, database, and storageSupabaseUnited States
Billing processing (from Phase 1)StripeUnited States
Operational support (behavioral analytics)PostHog, Inc.United States
Operational support (error monitoring)SentryUnited States
Web hostingVercelUnited States
Email delivery (notifications, inquiries)ResendUnited States

For PostHog, we have selected the EU region, and data is stored in a data center in Germany (Frankfurt). However, because the contracting entity is the US company PostHog, Inc. (San Francisco), the transfer-destination country under Article 28 of the APPI is the United States (see §6.1).

Our full list of subprocessors is disclosed separately from this Policy, on a page kept continuously up to date. If this list changes, we will notify you within 30 days via an in-app notice and a message to your registered email address.

Public page: https://nagaiki.ai/subprocessors (currently available in Japanese)

Privacy policies of our principal providers:


6. Provision to Third Parties Located Abroad

We transfer personal information to the outsourcing providers listed in §5. In every case, the transfer-destination country is the United States.

How we determine the transfer-destination country: whether a recipient qualifies as a "third party located abroad" under Article 28 of the APPI is determined not by where data is physically stored, but by the country where the recipient provider is located. Accordingly, even where we have selected a provider's EU region for data storage, the transfer-destination country remains the United States if that provider is a US legal entity.

The US personal-data-protection framework: the United States has no single comprehensive federal law governing personal information; instead, protection is governed by a patchwork of sector-specific and state laws (e.g., HIPAA, GLBA, CCPA, CPRA). The United States has not been recognized by Japan's Personal Information Protection Commission (PPC) as affording a standard of protection equivalent to Japan's.

Measures we take (our basis under Article 28 of the APPI):

  • As a general rule: in accordance with §7, we obtain your consent to providing information to third parties located abroad (Art. 28(1)). When obtaining that consent, we provide you, through this Policy, with information about the destination country's name, that country's personal-data-protection system, and the measures taken by the recipient (APPI Enforcement Rules, Art. 17).
  • PostHog (behavioral analytics): the transfer-destination country is the United States (even where we have selected that provider's EU region, the country is determined by the provider's location, so it remains the United States). We cannot rely on any exemption based on the EU's adequacy determination. As described under "As a general rule" above, this transfer is likewise based on your consent under §7 and the information disclosure required by Enforcement Rules Art. 17. We do not currently rely on the "compliant-system" basis defined in Article 16(1) of the APPI Enforcement Rules for this transfer. If we come to rely on that basis in the future, we will revise this Policy to say so explicitly.
  • Data including sensitive personal information: for every outsourcing provider, we additionally obtain your explicit consent under §7.

Each outsourcing provider works to protect personal information through its own privacy policy and through appropriate technical and organizational measures (encryption, access controls, audits).

Full details of our subprocessor list, and links to each provider's privacy policy, are disclosed on the public page referenced above.

6.1 About Behavioral Analytics (PostHog)

For accuracy of disclosure, we separately set out the following details regarding PostHog, which we use for behavioral analytics.

ItemDetails
Contracting entity (provider)PostHog, Inc. (United States, San Francisco)
Transfer-destination countryUnited States (determined by provider location; no exemption based on the EU's adequacy determination applies)
Data storage locationGermany (Frankfurt). We use PostHog Cloud EU, whose infrastructure runs on AWS's eu-central-1 region
Basis under Article 28As described under "As a general rule" in §6 (consent under §7 plus the information disclosure required by Enforcement Rules Art. 17). We do not rely on the "compliant-system" basis under Enforcement Rules Art. 16(1)
Identifiers we sendSee below. None of these are anonymized information

About the identifiers we send (they are not "anonymous"):

  • Mobile app: we send a persistent pseudonymous analytics ID that we issue (not directly tied to your name or contact information, and consistent across your use of the app) together with a session ID. We maintain an internal mapping between this pseudonymous ID and the user it belongs to. Accordingly, this pseudonymous ID qualifies as "personal information" under the APPI, and is neither anonymized information nor a third-party provision of pseudonymously processed information. We delete this mapping once the basis for behavioral analytics ends (for example, if you turn off the relevant optional setting in a version that offers one, if measurement under this Policy ends, or if your account is deleted).
  • Web properties (nagaiki.ai): for behavioral analytics after login, we send our own account ID (your Supabase user ID) directly as the identifier. Because this corresponds directly to your account in our database, it is likewise personal information.
  • In neither channel do we send your name, email address, photos, meal content, health figures, or chat text.

About training use of data sent to AI providers (Anthropic / OpenAI / Google, etc.): we have opted out, through each provider's API settings, of allowing personal information we send for AI response generation and meal-photo analysis (such as chat history and meal photos) to be used to train that provider's own models. The APIs we use are configured, by default, not to use submitted data to train the provider's own models, and we maintain that setting explicitly. For Google (the Gemini API via Vertex AI), we rely on Google Cloud's service-specific terms, which provide that customer data is not used to train Google's foundation models. If a provider's settings change in a way that alters this protection, we will revise this Policy and notify you in advance in accordance with §13.

By using the service, you are deemed to have consented to these transfers to third parties located abroad, in accordance with §7 ("Obtaining Consent") below.


7. Obtaining Consent

7.1 General Personal Information

We obtain your consent to this Policy when you register your account.

7.2 Sensitive Personal Information

We collect health data (CGM readings, heart rate, sleep, medical history, medications, etc.) only after obtaining your voluntary consent through an explicit in-app consent UI (a checkbox plus a "I agree" button). We record consent logs on our server.

7.3 Cross-Border Transfers

We treat your consent to this Policy as covering the transfers to third parties located abroad described in §6, and we additionally obtain explicit consent through the app's interface.

7.4 Withdrawing Consent

You may withdraw your consent at any time, through any of the following: (a) the "Settings → Privacy & Consent" screen in the app, (b) your OS settings (e.g., withdrawing HealthKit permissions), or (c) written notice to hello@zanmaido.com.

Withdrawing consent may make some features of the service unavailable. The effect of withdrawing each type of consent is as follows:

Consent WithdrawnEffectHandling of Existing Data
Withdrawal of consent to this Policy as a wholeTreated the same as account deletion; the entire service becomes unavailableDeleted within 30 days in accordance with §9
Consent to handling sensitive personal information (health data generally)Glucose visualization, AI analysis, and health-data logging features are disabledThe related data is deleted within 30 days (except anonymized data)
Consent to CGM / health-app integrationAutomatic syncing stops. Manual entry remains availableData already synced may be retained or deleted, at your choice, via settings
Consent to AI chat useAI chat is disabledChat history may be retained or its deletion requested, in accordance with §9
Consent to cross-border transfersFeatures that involve sending data abroad (AI response generation, photo analysis, etc.) are disabled; core logging features remain availableExisting data is generally retained; you may separately request deletion
Consent to marketing communicationsPromotional messages and newsletters stopExisting delivery history is retained for one year as an audit log
Consent to research, development, and statistical use (secondary use of anonymized data)You are excluded from future anonymization for this purposeData already anonymized cannot be re-identified, and therefore cannot be restored or deleted (see §5, "irreversibility of anonymized information")
Consent to participate in our Slack communityYou leave the community. Past posts remain, but any identifying information is anonymizedGoverned by Slack's own retention policy

Important: withdrawing consent may affect part or all of the service we can provide to you. Before withdrawing, we recommend reviewing the "Settings → Privacy & Consent → Simulate effect of withdrawal" screen (planned for Phase 1) to see the effect in advance.


8. Security Measures

8.1 Organizational Measures

  • Appointment of a Personal Information Protection Manager
  • Established internal handling rules
  • Supervision of outsourcing providers

8.2 Personnel Measures

  • Training for staff (including contracted personnel)
  • Confidentiality agreements

8.3 Physical Measures

  • Restricted access to data centers and servers (per our providers' standards)

8.4 Technical Measures

  • Encryption in transit (TLS 1.2 or higher)
  • Encryption at rest (AES-256 equivalent)
  • Row-level access control via Row Level Security (RLS)
  • Log auditing
  • Minimization of unnecessary permissions

9. Retention Period

DataRetention Period
Account information and usage dataFor the life of the account
After account deletionDeletion completed within 30 days of your deletion request (to allow for backup-propagation delay and recovery from accidental deletion)
Billing informationFor the period required by law (7 years, as accounting records)
Logs and audit recordsFor the period required by law (1 year, as a standard)

10. Requests for Disclosure, Correction, Suspension of Use, and Deletion

You may make any of the following requests:

  • Disclosure of the personal data we hold about you
  • Correction, addition, or deletion
  • Suspension of use or erasure
  • Suspension of provision to third parties
  • Notice of the procedure for making these requests

How to request: by email to hello@zanmaido.com, or via a dedicated form (planned). We may ask you to provide identifying information to verify your identity.

Response timeline: we aim to respond without undue delay after receiving your request (generally within 14 days, and no later than 30 days, in line with the "without delay" requirement of APPI Art. 33 and its guidelines). We send an initial "request received" reply within 7 days of receipt.


11. Cookies and Similar Technologies

Our web properties (nagaiki.ai) use cookies and similar technologies to maintain your login session and for site analytics. You may disable these through your browser settings.


12. Age Restriction

12.1 Minimum Age

This service is intended for users 18 years of age or older. Users under 18 may not use the service. We confirm age based on the date of birth you self-report at registration.

12.2 If Use by a Minor Is Discovered

If we discover that a user under 18 is using the service, we will suspend that account and delete the associated data in accordance with §9. Requests to delete an account or data, made by the user or a guardian, may be sent to hello@zanmaido.com and will be handled under the procedure in §10.


13. Revisions

If we revise this Policy, we will notify you at least 30 days before the revision takes effect, via an in-app notice and a message to your registered email address. Your continued use of the service after the effective date is deemed acceptance. For material changes (such as adding a new purpose of use or expanding the scope of third-party provision), we will obtain your renewed consent.


14. Contact

ItemDetails
Personal information inquirieshello@zanmaido.com
Personal Information Protection ManagerYuji Kuwamizu