Privacy Policy
Ryoichi Sasaki ("Operator") sets out this Privacy Policy for KAYA ("Service"), an app for nurturing relationships through personalized readings grounded in classical Eastern systems, to explain how user information is handled.
1. Operator
| Operator | Ryoichi Sasaki |
|---|---|
| Address | 3F Mitsuhashi Building, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan |
| Contact | [email protected] |
2. Information We Collect
| Type | Details |
|---|---|
| Date of birth and gender | Entered by the user and normally stored locally on the device. It is stored in a confirmed-email Web account only if you explicitly choose the record backup described below. |
| Birth time | Optional entry normally stored locally on the device. It is stored in a Web account only if you explicitly choose record backup. |
| Mood records | Optional emoji-based records stored locally on the device. |
| Anonymous authentication ID | Automatically issued when the Service starts. No name or email address is required for normal use. |
| AI text cache | Generated readings may be cached on the server to reduce regeneration costs. |
| Letters message and reply | The structured consultation you send as an individual Premium consultation (including any free text you add) and the reply you receive the next morning. The reply is generated by AI and then checked by the operator before it is delivered. Stored on the server linked to your anonymous authentication ID, and erased when a deletion request is processed. Your date of birth itself is not sent or stored. |
| Device information and logs | Crash reports or similar information may be collected to improve the Service. |
| Purchase and billing information | Purchase and restore status of the Premium subscription (subscription expiry, store used, etc.). Collected to manage in-app purchases and processed linked to the anonymous authentication ID. Payment details such as credit card numbers are not collected (handled by each store). |
| Push notification token | If you opt in to notifications such as Peach Blossom alerts, the device's push notification token (device identifier) is collected and used solely to send notifications. If notifications are turned off, the token is neither collected nor sent. |
| Reply email address (optional) | Collected only when you enter it in in-app feedback because you would like a reply. Used for a receipt email and any needed reply, and stored in email delivery audit records. |
| Record backup (optional) | Bundles the record at the time you explicitly save it and stores only the latest saved bundle in your confirmed-email Web account. It includes birth information such as date of birth, birth time, gender, and time zone; your call name; partner information; and daily letters and notes (up to 60 for each language). It is not saved automatically or kept in ongoing sync. |
Information we do not collect: During normal use, we do not collect direct identifiers such as your name or phone number. We collect an email address only if you optionally enter it because you would like a reply or to register or confirm an account for carrying over purchase status and opted-in saved records. Birth information is normally stored on your device, and the server receives only anonymized chart features for readings. The record-backup exception is described above.
3. Purposes of Use
- Calculating charts from classical Eastern systems and generating AI explanations (including next-morning replies in Letters).
- Managing daily quotas and preventing abuse.
- Improving quality and fixing bugs.
- Sending receipt emails and replies for inquiries or feedback.
- Saving the record you choose and explicitly restoring it on another device after email sign-in.
- Responding to legal requirements.
4. Sharing with Third Parties
We do not provide collected information to third parties except where disclosure is required by law or necessary to protect life, body, or property.
5. Service Providers
| Provider | Purpose and data |
|---|---|
| Supabase, Inc. | Authentication and database infrastructure. Processes anonymous authentication IDs, reading caches, usage data, data needed to operate purchases, notifications, and deletion processing, and records you choose to save. |
| Anthropic, PBC | Generation of AI readings and Letters replies. For readings, only anonymized chart results are sent. For Letters, the structured content of your consultation is sent. Raw birth dates are not sent. Generation logs may be retained on Anthropic servers for up to 7 days. |
| Cloudflare, Inc. | Website delivery and security. |
| RevenueCat, Inc. | Purchase status and entitlement management for in-app purchases (Premium subscription). Processes anonymous authentication IDs and purchase information. |
| Sentry (Functional Software, Inc.) | Service quality improvement through crash reporting and error diagnostics. Not used to identify individuals. |
| Apple Inc. / Google LLC | Push notification delivery (APNs / FCM). Push notification tokens are used solely for notification delivery. |
| Resend, Inc. | Sending receipt emails and replies for in-app feedback. Processes only the email address you optionally provide. |
Each service provider implements appropriate data protection measures.
6. Storage and Deletion
Data such as date of birth and mood records is stored primarily on your device. Some usage, purchase, notification, and operational data is stored on the server and linked to an anonymous account. If you do not choose record backup, your date of birth, call name, partner information, and daily letters and notes remain only on your device. If you choose it, your confirmed-email Web account stores only the latest snapshot you explicitly save; this is not ongoing sync. After signing in by email on another device, you can explicitly restore it only when those device records are empty. Letters consultation history, purchase or plan information, authentication information, and analytics data are not included in this backup or restore. After the app accepts a request through Settings → Erase KAYA records, KAYA clears records from your device where possible and without unnecessary delay. KAYA's operational target is to complete deletion of eligible server data linked to the anonymous account within 14 days of accepting the request. Incomplete requests and any risk of missing the target are monitored, with manual follow-up as needed.
You can explicitly delete a saved record in Settings. Deleting your Web account also deletes the records saved in that account.
Uninstalling the app by itself is not treated as a deletion request. What happens to on-device data after uninstalling may vary with the operating system and backup or restore settings, so use the in-app deletion feature before uninstalling when possible. If you cannot access the app, contact support for guidance; contacting support alone does not start deletion. This action does not cancel an App Store or Google Play subscription. Cancel it separately through the applicable store.
The shared cache used by other users, aggregate data that does not identify you, and audit records for deletion, payment, delivery, and operations may be retained according to their separate purposes and retention periods.
To delete your data, please use the in-app deletion feature. For questions about this policy or how your data is handled, contact [email protected].
7. Cookies and Tracking
The mobile app does not use cookies. The website uses only minimal functional cookies and does not perform advertising tracking.
8. Children
You must be at least 14 years old to use the Service. Users under 14 may not use the Service. If a distribution platform or country or region imposes a higher minimum age, that requirement takes precedence. Users aged 14 through 17 may use the Service only with consent from a parent or legal guardian.
9. User Rights and Cross-Border Processing
Depending on applicable law, you may request access, correction, suspension of use, or deletion of your personal data. Some service providers may process data outside your country or region. We use them only for the purposes described in this policy.
10. Changes
This policy may be updated due to legal or service changes. Important changes will be announced on this page and in the app.
11. The One-Time Reading Sold on Coconala ("KAYA ふたりの相性鑑定書")
If you order the one-time service "KAYA ふたりの相性鑑定書," sold through the external platform Coconala, we receive the date of birth, birth time (if known), and birthplace of both you and your partner through the Coconala chat room or similar. Handling of this information is separate from Sections 1–10 above, and is as follows.
- Purpose of use: The information you provide is used only to create the report for that order. It is not linked to other orders or to your data in the in-app Service.
- Third-party sharing and AI processing: We use tools including AI to calculate and generate the report, but only structural information derived from the birth data (such as chart and stem/branch results) is sent to those tools. The raw date of birth itself is never sent externally.
- Storage: The birth data you provide is encrypted before storage.
- Retention and deletion: After the report is delivered, the encrypted birth data and the report content (including charts, drafts, and deliverables) are deleted once the defined retention period has elapsed. The retention period follows the retention policy set by the operator for each order. We also honor deletion requests from the purchaser.
- About your partner's information: Before sending your partner's date of birth, please tell your partner and obtain their consent. If your partner contacts us directly to request access to or deletion of their data, we will confirm your relationship to them and respond within the scope of applicable law.
- Transaction terms: Purchase, cancellation, and refund terms follow Coconala's terms of use and the relevant section of our Legal Notice.
12. Contact
For requests or questions about privacy, contact [email protected].