Privacy Policy

Last updated: 2026-09-04

This page explains how NihonLetter (“the Product” or “we”) collects, uses, shares, and protects your information. Please read this policy in full before using the Product.

Introduction and Scope

NihonLetter is an iOS app for foreign residents in Japan and multilingual families. You can scan or upload Japanese letters, documents, images, PDFs, and screenshots; the Product performs optical character recognition (OCR) and AI analysis to generate “action cards” for you (identifying the document type and extracting information such as deadlines, amounts, and institutions, and offering suggested actions), deadline calendar reminders, and Japanese reply templates. The output language of action cards is determined by your app language setting; currently Simplified Chinese, Traditional Chinese, English, Japanese, and Vietnamese are supported, and action cards default to Simplified Chinese in other language environments.

This policy applies to the collection and processing of information that occurs between you and the Product while you use it; it does not apply to the independent processing carried out by third-party websites, institutions, or services that you access on your own. For the related terms, see our Terms of Service.

Information We Collect

We collect information only to the extent necessary to provide and improve the service, mainly in the following categories:

  • Account and authentication information: the current version primarily uses anonymous accounts, and we collect the internal identifier of the anonymous account. As sign-in methods such as LINE and Apple are rolled out in later versions, we will accordingly collect the user identifier returned by that sign-in method (provider user id), the email address you use to sign in or link, and so on. These sign-in methods are planned and will be rolled out gradually across versions; they may not yet be available in the current version, and what is actually available follows what is shown in your app version. Once the relevant sign-in method is available, you can link multiple identities to the same account. We do not use phone numbers for account registration or sign-in; if a file you upload contains information such as a phone number, it is recognized and processed as part of the uploaded content (see “Content you upload” below).
  • Content you upload: the images and PDFs of the letters, documents, and screenshots you scan or upload, and the text extracted via OCR. This content may contain personal information (such as names, addresses, amounts, institution names, account numbers, etc.). Please upload only content you are entitled to process.
  • Analysis outputs: the action cards, deadline reminders, and reply templates generated from the content you upload.
  • Usage and log information: basic usage records and error logs, used to troubleshoot issues and improve the service.
  • Calendar / reminder integration identifiers: when you use the “Add to Calendar / Reminders” feature, the identifier returned by the system for the created event or reminder is sent back and stored on our servers, used to mark that action as completed and to avoid creating duplicates. We do not obtain any other content from your calendar or reminders.
  • Purchase and subscription information: purchase / subscription status and transaction identifiers. We manage subscriptions through RevenueCat: that service is initialized every time you launch the app, and after each sign-in we submit your account identifier (Supabase user ID) to it as the RevenueCat user identifier (this does not depend on whether you have made a purchase); the actual payment is handled by the Apple App Store, and we do not have access to your bank card or other payment details.
  • Support requests (tickets): when you contact us via “Settings → Support”, the ticket category, subject, language, and message content you submit—this content may contain personal information.
  • Push notification identifiers: when you are signed in and have allowed this app to send notifications in your system settings (whether that permission was granted for deadline reminders, to-do reminders or family notifications), we collect and store your device's push token (issued by Apple and used to deliver notifications to that device), a device identifier (the identifierForVendor provided by iOS, used to recognize repeat registrations of the same device; it changes if you reinstall the app), the platform and push environment, and per-device delivery results (whether delivery succeeded, and failure reason codes). This data is used only to deliver notifications and troubleshoot delivery, and not for advertising or cross-app tracking. When you sign out, the app immediately stops receiving push notifications on that device and sends the server a request to deactivate that token—that request is best-effort, and if it does not reach us (for example because of a network problem) deactivation on the server side may be delayed; when you delete your account, the token record is deleted together with the account.

How Information Is Used

  • To perform OCR recognition and AI analysis on the Japanese content you upload, and to generate action cards, deadline reminders, and Japanese reply templates.
  • To create and maintain your account, and to handle sign-in, identity linking, and session management.
  • To provide, maintain, troubleshoot, and improve the features and stability of the Product.
  • When you authorize it, to write deadline-related events or reminders to your device's calendar or reminders, and to send back the identifier returned by the system to mark completion and avoid duplicates.
  • To manage your subscription and in-app purchase entitlements (through RevenueCat and the Apple App Store).
  • To receive, process, and respond to the requests and tickets you submit through the support feature.
  • When you choose to save a document into a family space, to provide that document and its analysis to the other members of that space so the family can view and handle it together.
  • To assign and track family matters within a family space, and to send family notifications to the members concerned.
  • To record membership and ownership actions within a family space, for our troubleshooting and security auditing.

We do not sell your personal data to third parties.

Third-Party Processing and Sharing

To provide the Product's features, we entrust necessary information to the following types of third parties, to the extent required to deliver the service. We do not sell your personal data.

  • AI analysis service providers: to perform recognition and analysis, the text extracted via OCR from your uploaded content is sent to the third-party AI service provider we use for processing (not the original images—images and PDFs are stored only on our self-hosted infrastructure and are not sent to the AI provider). We currently use Anthropic (the Claude model); depending on configuration we may also use OpenAI or other AI service providers. Such processing is subject to each provider's terms and privacy policy. Model training: your uploaded content will not be used to train AI models—we process data through these providers' commercial APIs, and under their API terms the submitted content is not used to train their models; we also do not use your uploaded content as externally shared quality-assurance (QA) samples.
  • Authentication email delivery: email Magic Link and one-time passcode (OTP) emails are sent through Resend, provided by Plus Five Five, Inc. in the United States. To deliver these emails, Resend processes the email address, email metadata, and message content. We disable email open and link-click tracking.
  • Sign-in identity providers: when you choose the relevant sign-in method, the sign-in process involves LINE and Apple as identity providers.
  • Storage service: your data is stored on our self-hosted infrastructure (Supabase and object storage deployed on a VPS).
  • Subscriptions and in-app purchases: we use RevenueCat to manage subscription and in-app purchase entitlements, which involves syncing purchase / subscription status and account identifiers; the actual payment transaction is handled by the Apple App Store and is subject to Apple's terms and privacy policy.
  • Push notification delivery: family-related push notifications are delivered through the Apple Push Notification service (APNs). We provide Apple with your device's push token and the fixed template text; Apple acts only as the transport channel, and we do not provide it with any document content (the templates contain no document names, institution names, amounts or recognized text—see “Family Shared Spaces” below). Such processing is subject to Apple's terms and privacy policy.

Family Shared Spaces

The Product offers an optional “family space” feature: you can create a family space, invite your family members to join, and share selected documents so that you can handle them together. This section explains the data processing involved. Family features are opened up gradually by app version and by our server-side configuration; even on the latest version some family features may not yet be enabled for you, and what is actually available follows what is shown in the app. If you do not use a family space, this section does not apply to you. Family members are not third-party service providers we entrust with processing (see “Third-Party Processing and Sharing” above); they are other users you actively choose to share with.

  • Only documents you actively choose are shared: every document belongs to one specific space when it is saved—either your personal space or one family space. The default is your personal space (if you have switched to a family space view, that space becomes the default target); you can change the destination on screen before saving. Documents imported through the system “Share / Open with” flow are always saved to your personal space only. Documents in your personal space are never shared automatically because you created or joined a family space, or because family features were launched. The Product also provides no way to move an already saved document between your personal space and a family space—apart from the case described in “Dissolving a family space” below (on dissolution, documents return to the personal space of whoever saved them), the owning space is fixed at save time, so if you no longer want to share a document you need to delete it. These limits are enforced on the server: the app has no permission to change a document's owning space, and the server verifies that you really are a current member of the target family space, otherwise the save is rejected. By design a personal space can contain only you; others cannot be invited into it.
  • Providing personal information to other members: when you save a document containing personal information into a family space, you initiate the provision of that personal information to the other members of that space. In accordance with the rules on providing personal data to third parties under Japan's Act on the Protection of Personal Information, we make the following public: items provided—the original (image or PDF) and thumbnail of that document, the text extracted via OCR, the analysis generated from it (document type, summary, institution name, amount, deadline, risk level, confidence), the related to-dos and suggested actions together with their processing records, the confirmations and corrections you made to extracted fields, and which member uploaded the document; purpose of provision—to let family members jointly view and handle the everyday matters related to that document; scope of recipients—the current (not removed) members of that family space, including members who join after you save the document (they can likewise view every document shared earlier); the number is limited by the member cap we set, and the right to invite new members belongs to the owner of that space; method of provision—through our server, after it verifies membership; how it is triggered—by choosing a family space as the save destination, you choose to share that document within that space. Please note: the documents you upload may contain personal information about people other than yourself (for example family members, children, or individuals connected to a third-party institution). Please upload only content you are entitled to process, and obtain the consent of the individuals concerned (or their legal representatives, where they are minors) after explaining the matter fully—this is your obligation under the Terms of Service, and because we cannot contact those individuals directly we rely on the uploading member having met it. If you are not the uploader but your personal information is contained in a document uploaded by someone else, you may likewise request disclosure, correction, or suspension of use / erasure of that information from us via our Support page; we will handle such requests after verification as required by law.
  • What family members can see: current members of the family space can view the full content of every shared document in that space, including the title, type and source, processing status, the summary, institution name, amount, deadline and risk level, the page-by-page optical character recognition (OCR) results, the AI analysis and its confidence, the to-dos and suggested actions generated from the document (with details, times, locations and links) and their processing records, the field confirmations and corrections, and which member uploaded the document. Members can also view the original images and thumbnails of shared documents: when they do, our server re-verifies their membership and then issues a temporary access link valid for at most 5 minutes (shortened further if less than 5 minutes remain of that original's retention period). The storage holding the originals is not itself open to other members; they can only view via that temporary link.
  • Boundaries between members: members can only view, not modify or delete another member's documents, their analyses, or another member's to-dos. The one exception is an assignment you have accepted—once accepted, you can advance the suggested action for that matter (confirm / execute / mark as completed), which updates the action records and processing status under that document and may create a corresponding to-do under the uploader's account (see “Assignments and activity records” below). Changing a document's original retention period, deleting that document and similar actions are still restricted to the member who uploaded it (and who is still a current member of the space). Inviting and removing members, transferring ownership of the space, and archiving or dissolving the family space are restricted to the owner of that space.
  • What family members cannot see: other members cannot see any document, analysis, to-do or original in your personal space, nor your content in other family spaces. The member list contains only each member's self-set display name, language, role, join time and internal account identifier within that space, and does not contain each other's email or phone number; members also cannot see your sign-in methods or payment details. Support tickets you submit are a private channel between you and us and cannot be viewed by other family members (we only record which family space context a ticket was submitted from, to help us locate the issue).
  • Assignments and activity records: when you use the family assignment feature, all current members of that family can see who a matter was assigned to, whether that person has read it, whether they accepted or declined it, whether they added it to their own reminders or calendar (shown as “scheduled”), and whether and when it was completed. Only the assigned member can mark it read, accept, decline or complete it; cancelling is restricted to the member who created the assignment or to the space owner. Separately, actions within the space (membership changes, creating and renaming labels, ownership changes, and so on) are written to that family's activity record; that record is not open to family members and is used only for our internal operations and security auditing (see “What our staff can see” below). It stores only member identifiers, action types and similar fixed values, and does not store document titles or recognized text.
  • Push notifications: the text of family-related push notifications (for example, a matter assigned to you, a change in its status, or the daily family digest) comes entirely from fixed templates written in advance on our server, selected according to the language you set within that family. The templates are generic prompts such as “A new family task was assigned to you”, and cannot contain document names, institution or school names, amounts, dates, recognized text, or other members' names; the accompanying data is only a set of internal identifiers used to open the corresponding screen. Such notifications therefore do not reveal document content even when shown on the lock screen. Please note that document deadline reminders and to-do reminders are notifications generated locally on your device and do not pass through our servers; so that you can tell what they refer to, a deadline reminder includes that document's name and its deadline date, and a to-do reminder includes the to-do title (depending on the case, that name may be the document type we recognized, a name you set yourself, or an institution name recognized on the document), and these appear on the lock screen and in Notification Center. If you do not want that information on your lock screen, you can turn off the corresponding reminders in the app, or hide notification previews for this app under iOS “Settings → Notifications”.
  • After a member is removed or leaves: we immediately mark that person's membership of the family as “removed” on the server, and their permission to view and act on all content in that space ends at the same time—including documents they themselves previously saved into that space: within the Product they can no longer view those documents' records, analyses or to-dos; those documents remain in the family space for the other members to continue using. To be clear: at the storage layer an original image always belongs to the account that uploaded it, so that person can still retrieve the originals they uploaded themselves, but can no longer obtain originals uploaded by other members. A temporary access link for an original cannot be revoked once issued; links already issued expire naturally within at most 5 minutes, and no new links are issued afterwards. Family originals uploaded by other members that the app kept in memory on that person's device for viewing are cleared the next time the app refreshes family information (for example on returning to the foreground, opening a family screen, or pulling to refresh); those images are never written to device storage. Even after you have left a family space, where content in it contains your own personal information you may still ask us to suspend its use, erase it, or stop providing it to the other members of that space (for example where you consider that continued sharing would harm your rights or legitimate interests) under Japan's Act on the Protection of Personal Information; please raise this via our Support page and we will verify your identity as required by law and decide without delay. A device's push credential is tied only to the account and not to any family space, so removing a member does not unbind that device's push credential; instead we re-check membership immediately before each family notification is sent, and notifications whose recipient has been removed are cancelled and not delivered. We do not remotely delete content you previously exported or saved onto your device yourself. The removal is written to that family's activity record.
  • Family subject labels: within a family space you can create “subject labels” to distinguish which child, school or institution each family document relates to. A label contains only three things: a nickname you type in yourself, a color you pick from a fixed palette (optional), and the label type (which can only be one of “child”, “school”, “organization” or “other”). We do not require a real name, and there is no input field of any kind for a birthday, age or identity document. All current members of the same family space can view, edit and archive that family's labels. Labels are never sent to AI service providers, and their nicknames do not enter our product usage statistics (see “Usage statistics for family features” below). Because the nickname is free text you write yourself, please do not put information in it that you would not want other members of the same family to see.
  • Usage statistics for family features: to measure how well the features work, we record action-type statistical events for family features (for example that a family was created, an invitation was sent or accepted, a member was removed, a matter was assigned or completed, or the family plan page was viewed). Each event carries your account identifier and the internal identifier of the family space the action belongs to, so that usage can be measured per family. These events contain no document titles, institution names, amounts, recognized text, label nicknames or member names; their properties take only preset fixed values, and the statistics are not visible to any user, including other family members. You can turn product usage statistics off at any time in the app's settings, after which our server rejects them; when you delete your account we first clear the family attribution on historical statistical events. In addition, when someone opens or declines a web invitation link we also record an anonymous statistical event that contains no account identifier whatsoever—that event is generated by the web page, and is therefore not governed by the statistics setting inside your app.
  • What our staff can see: to handle support requests, troubleshoot and prevent abuse, our authorized staff can view a family space's metadata in our internal admin console —the family name, the member list (internal account identifiers, roles, status, language, display names, join and change times), the status and timing of invitations, and the family activity record. That console never returns the documents, original images, recognized text or analyses inside a family; where document content genuinely has to be inspected, a restricted break-glass procedure requiring two-person approval and leaving an audit trail must be used. We store only hashes of invitation codes and web link secrets, and the console does not display even those.
  • Family data when accounts are merged: if you sign in with different sign-in methods so that we identify two accounts as the same person and merge them, the merged account's memberships of family spaces are automatically transferred to the account that is kept (where both accounts are in the same family, they become a single membership record). Documents the merged account had saved into a family space remain in that family space and stay visible to the other members, with ownership moved to the account that is kept. This means that after a merge the surviving account gains access to all of the other account's family spaces. If you do not want the family access of two accounts combined, do not link them to the same sign-in identity.
  • AI analysis and cross-border transfer in a family space: the express consent for cross-border transfer is recorded per individual user (see “International and Cross-Border Transfers” below). An analysis runs only if the member who started that particular scan or import has themselves consented; when other members subsequently view, filter, confirm or correct fields, claim or complete to-dos, or use an already generated Japanese reply template, they are only reading results already stored on our servers, and no content is sent to AI service providers again. A family space follows exactly the same processing pipeline as personal use, and the commitments above are unchanged: original images and PDFs are not sent to AI providers, your uploaded content is not used to train AI models, and it is not used as externally shared quality-assurance (QA) samples. Please note that this consent is given by the member who starts the analysis. If the document concerns the personal information of other family members (including minor children), that information is transferred as part of the same analysis. For other people's personal information contained in a document, we rely on the uploading member's representation that they obtained that person's consent (or that of their legal representative, where they are a minor); we cannot contact that person directly and therefore do not separately obtain consent. If you are that person and do not consent to this cross-border transfer, you can ask us via our Support page to stop providing the data to third parties overseas and to delete it.
  • Web invitation page: when the owner of a family space generates a web invitation link to share with a family member who has not installed the app yet, that web page shows only the name of the family space, the display name the inviter set within that space, the language of the invitation, and the link's expiry time; it shows no documents, images or recognized text whatsoever, and no member list, member count, real names, emails or phone numbers. The link's secret is placed in the fragment after “#” in the URL, which by browser rules is not sent to our servers with the request and therefore does not appear in server access logs or referrer information; our server likewise stores only its hash and cannot recover the plain value. A web invitation link is valid for at most 24 hours (an in-app invitation code lasts 7 days by default and at most 30 days); the owner can revoke it at any time, and regenerating it invalidates the old link immediately. The recipient can decline the invitation directly on that page without registering or signing in; accepting an invitation and joining the family space must be completed inside the app after signing in. If the owner shares a “family matter” link instead of an invitation link, the page additionally shows that matter's title, deadline and the display name of the person responsible—still without providing any original document. To prevent bulk guessing of links, we rate-limit large numbers of failed accesses in a short period, and the source IP involved is recorded only as a hash.
  • What happens to family content when you delete your account: whether you are the owner of a family space or an ordinary member, if you have ever saved a document into a family space or created family tasks in one, then when your account deletion is carried out we do not delete that content along with it: we pick a member who is still using that space (its current owner where there is one, otherwise the current member who joined earliest) to take over those documents together with their analyses, to-dos and action records, and those records are re-recorded under that member and kept, so that the current members of that family can continue to view them; the corresponding originals and thumbnails are likewise retained. After the takeover, the ownership identifier on those records is replaced with that member. To be clear: at the storage layer the ownership anchor of an original and its storage path are by design not changed by the takeover, so they still contain your account's internal identifier—it no longer corresponds to any account that can be signed in to, but members of the same family may still see it when they retrieve the original. If no member is left who can take over, that space is archived and frozen and the content under your name is deleted together with your account (content other people left in that space is unaffected). The family's activity record is retained, but the user identifiers pointing to you are cleared; the creator identifier on subject labels is likewise cleared while the labels themselves remain for the other members as shared family data. Content in your personal space continues to be handled as described in “Data Retention and Deletion” below. If you do not want the content you saved into a family space to be retained this way, please delete those documents yourself before deleting your account, or request suspension of use / erasure via our Support page.
  • Additional rules when an owner deletes their account: beyond the general handling described in the previous item, if you are the owner of a family space and that space still has other current members, we will refuse to accept your account deletion request and ask you to first transfer ownership to another member, or first dissolve that family (if you have already requested dissolution and the family is in the waiting period, account deletion can be accepted). When deletion is carried out, the member who takes over as described in the previous item also becomes the new owner of the family space (gaining owner rights such as inviting and removing members, transferring ownership, archiving and dissolving); every invitation that family had sent but that had not yet been accepted is revoked; and if a dissolution had been requested and was still in its waiting period, that dissolution is cancelled (the space stays frozen and the new owner must restore it manually).
  • Dissolving a family space: only the owner of the space can dissolve a family space, and a personal space cannot be dissolved. Once confirmed, the family space is frozen immediately (no new content can be added and existing content can no longer be modified, while members can still view and export what is already there) and a 48-hour waiting period begins; during that period the owner can cancel the dissolution (after cancelling, the space stays frozen and must be restored manually before it can be used again). After the waiting period the dissolution can no longer be cancelled, and a scheduled task carries out the dissolution. The actual execution may be slightly later than 48 hours. What is deleted is the family space itself: memberships, invitations, subject labels, the shared quota and task assignments, together with that family's activity record. Once the family space is deleted it cannot be restored. Documents saved into that family space are not deleted—each document, along with its originals and thumbnails, analyses, to-dos and action records, is returned to the personal space of the member who saved it there (documents the owner saved are likewise returned to the owner's own personal space: it is the family that is being dissolved, and we do not decide on anyone's behalf to delete their own content). Once returned, this content appears in that member's own personal space and the originals remain openable, so please look in your own personal space. Family tasks that are not attached to a particular document likewise return to the personal space of whoever created them. And if the person who originally saved a piece of content has since deleted their account, so that it was reassigned to a succeeding member under “What happens to family content when you delete your account” above, it returns to that succeeding member's personal space. Sharing also ends at that point: from then on each member can see only what is recorded under their own name, and can no longer see other members' documents, so if you want to keep content another member saved, export it yourself before dissolving. For each returned document we record an internal handling record (only the internal identifiers of the document and the account, never the document's contents). Exception: if, at the time of execution, a member does not have a usable personal space, the content they saved into that space has nowhere to be returned to and is deleted along with the family space. In addition, subject labels are family shared data and are deleted along with the family, so labels previously attached to returned documents are cleared. Each member's own personal space, personal documents and account are entirely unaffected—they simply no longer belong to that family.
  • The family boundary in data exports: you can ask us via our Support page to export a copy of your data (there is no self-service export inside the app). The family portion of that export covers only the family spaces you are currently still a member of: the space name and basic settings, the other members' display names, languages, roles and join times (without their email addresses), the basic information of documents in that space (title, type, source, status, workflow status, deadline, institution name, subject label, archived time, creation time) and the list of subject labels. For documents uploaded by other members, their summaries, amounts, recognized text and original images are not written into your export; nor does an export ever contain anything from another person's personal space. Once you leave or are removed from a family, that family no longer appears in your later exports.
  • Family plan: where a family plan is available, whether a family is unlocked depends on whether the owner of that space personally holds a valid paid subscription (we check this in real time and do not build a separate copy of the entitlement, so the answer changes immediately once the owner is refunded, the subscription expires, or ownership is transferred); other members do not need to pay separately, and what members share is that family space's allowance of scan analyses. We use RevenueCat to manage subscriptions: beyond the synchronization of purchase / subscription status and account identifiers already described in “Third-Party Processing and Sharing” above, we do not provide it with your name, email or phone number, nor your family member list, the relationships between members, or any document content. When a member checks whether the family is unlocked, they receive only “whether it is unlocked, the tier, the source, and the member cap”, and never the owner's identity, the product purchased, or the expiry date.

Where Data Is Stored and Security

Your data is stored on our self-hosted infrastructure (Supabase and object storage on a VPS). We take reasonable technical and organizational measures such as access control and encryption in transit to protect the security of your information.

Please note: no method of transmission or storage over the internet can guarantee that no risk will ever occur under all circumstances, and we cannot make an absolute guarantee of security. Please keep your sign-in methods and devices safe.

When you set the originals location to “Keep on this device only” in the app, the original images for that document are not uploaded to the infrastructure described above. They are stored on your own device; we hold no copy and cannot access them. Those originals are included in your device / iCloud backups. Correspondingly, those copies go into Apple's backup service, whose storage region is determined by your Apple ID and system settings and is not controlled by us. If you delete the app and have no usable backup, those originals cannot be recovered. (Documents you import into a family space are an exception — they are still uploaded to our servers so that family members can view them.) (Files brought in by sharing from another app or via “Open in NihonLetter” keep no original — only the analysis result.)

Data Retention and Deletion

We retain your information for as long as needed to provide the service and to meet compliance requirements. For the originals you upload, the Product offers an “original retention” feature: you can choose to keep the originals, or have them deleted automatically after they expire.

The “original retention” feature above applies only to originals uploaded to our servers. For the originals that, per the previous section, are kept only on your device, server-side retention periods and automatic deletion on expiry do not apply — they stay on your device until you delete the file in the app, delete your account in the app, or delete the app.

Important note about anonymous accounts: an anonymous account can be used without registration, and its session is the sole credential for the account. Signing out or losing that session may be equivalent to losing the account and its associated data, and it usually cannot be recovered. If you wish to retain your data long-term, we recommend linking a sign-in method such as LINE, Apple, or email once it becomes available (these sign-in methods are rolled out gradually across versions, subject to what is actually offered in the app).

You can delete your account at any time; once submitted, the deletion request is processed asynchronously in the background and is usually completed within a short time. It removes associated data such as your files, analyses, in-app to-do records, and support content, and cannot be recovered—see “Your Rights” below and Delete Account. Retention exception: to fulfill legal and compliance obligations, we de-identify finance / transaction-related records and retain them for a legally required period, and we keep one deletion audit record containing an account identifier as evidence that the deletion request was carried out; this data is used only for internal compliance purposes and is not provided externally.

If you use a family space: content you saved into a family space is not deleted together with your account. How it is handled, and how it is handled when a family space is dissolved, are described in “Family Shared Spaces” above.

Your Rights

To the extent permitted by applicable law, you may exercise the following rights over your own personal information:

  • Access and correction: to know and update the information we hold about you.
  • Deletion: you can delete your account and its associated privacy content (files, analyses, in-app to-do records) at any time in the app (Settings → Account → Delete Account); deletion cannot be recovered (see also the retention exception under “Data Retention and Deletion” above—to fulfill legal and compliance obligations, we de-identify finance / transaction- related records and retain them for a legally required period, and keep one deletion audit record containing an account identifier as compliance evidence). If you are the owner of a family space that still has other members, you must first transfer ownership or dissolve that family before you can delete your account; content you saved into a family space is not deleted together with your account, as described in “Family Shared Spaces” above. If you cannot do this in the app, you can contact us via our Support page.
  • Withdrawal of consent: for processing carried out based on your consent, you may withdraw your consent; withdrawal does not affect processing already carried out before the withdrawal.
  • APPI disclosure and other requests: if Japan's Act on the Protection of Personal Information (APPI) applies to you, you may make the following requests regarding the personal data we hold: disclosure; correction, addition, or deletion of content; suspension of use or erasure; and disclosure of records of provision to third parties. We will handle these in accordance with applicable law after verifying your identity by reasonable means; the point of contact and the process are described under “Personal Information Handling Business Operator” below.

If you are located in another region (for example, the European Economic Area where the GDPR applies), you may have other rights provided by local law; we will cooperate to the extent applicable.

Device Permissions

The following device permissions of the Product all require your active authorization within the app, and you can revoke them at any time in your system settings:

  • Calendar and Reminders (EventKit): with your authorization, used to write deadline-related events to your device's Calendar, or to write reminders to Reminders. After writing, the identifier returned by the system for that event or reminder is sent back and stored on our servers, used to mark that action as completed and to avoid creating duplicates; we do not upload any other content from your calendar or reminders. Deleting your account only clears the data on our servers and does not automatically remove events or reminders you have already written to your device's Calendar or Reminders; if you want to clear them, please delete them yourself on your device.
  • Camera and Photos: used to scan letters or select files and images for analysis.

Children's Privacy

The Product is intended to be registered for and used by adults (or people of an age at which they can validly contract in your country or region), and we do not collect personal information directly from children. However, the documents you upload and the labels you create in a family space may contain information about your children; such information is treated as provided by you (the guardian), and you should obtain any consent required before providing it. If you believe a child has provided us with personal information without a guardian's consent, please contact us via our Support page, and we will take reasonable measures to delete it.

International and Cross-Border Transfers

To provide the service, some of your information is entrusted to third parties for processing or storage. Regarding the provision of personal data to a foreign third party that must be disclosed under Article 28 of Japan's Act on the Protection of Personal Information (APPI): the AI analysis service providers Anthropic and OpenAI are located in the United States—the text extracted via OCR from your uploaded content is transferred to the United States for their processing, and the personal information protection regime in the United States differs from Japan's; for this we take security measures such as encryption in transit and access control. This cross-border transfer happens only when two conditions are met at the same time: you use the scan / document-analysis feature, and you have yourself given express consent to the current version of this policy. Without that consent our server refuses to run the analysis (this check is enforced on the server side and cannot be bypassed by the app). If you do not want such a cross-border transfer to occur, please do not give that consent, or do not use the relevant analysis feature. The subscription management provider RevenueCat (RevenueCat, Inc., United States)—we use it to manage subscriptions and in-app purchase entitlements; your account identifier (a random ID string) and your purchase / subscription status are transferred to the United States for its processing. Push notification delivery by Apple (Apple Inc., United States)—when we send you a family notification (the individual family notification switches are on by default, and you can turn them off in the app), your device's push token and the fixed template text are transferred to Apple's push notification service (APNs) for delivery; we do not provide it with any document content (the templates contain no document names, institution names, amounts or recognized text). Authentication email provider Resend (Plus Five Five, Inc., United States)—your email address, email metadata, and the message content that contains a Magic Link or OTP are transferred to the United States for storage and processing. We select the Tokyo region for email routing and sending, but that selection does not change the fact that this data is stored in the United States. We engage Resend under its Data Processing Addendum (DPA) and apply safeguards including encryption in transit and access controls. Email open and link-click tracking remain disabled. Our self-hosted infrastructure (VPS, object storage, and the operations admin console) is deployed by the operator within Japan (the AWS Tokyo region). Processing on that self-hosted infrastructure alone does not involve providing personal data to a foreign third party; if its deployment location changes, we will update this policy accordingly and handle the change in accordance with the APPI.

Policy Updates

We may update this Privacy Policy from time to time. Updates will be posted on this page, and the “Last updated” date at the top of the page will be updated. For material changes, we will notify you by appropriate means.

Personal Information Handling Business Operator

The entity handling personal information for this Product (the personal information handling business operator) is the operator of NihonLetter (a sole proprietor in Japan). Under Japan's Act on the Protection of Personal Information, the operator's name and address are matters that can be made known to the individual: if you need them, upon your request we will disclose the operator's name and address without delay in writing or by email. For requests, inquiries, or complaints relating to the handling of personal information and the exercise of the rights above (disclosure, correction, suspension of use, deletion, etc.), please submit them via our Support page (support@nihonletter.app) as the point of contact; we will handle them without delay after verifying your identity in accordance with applicable law. Besides you personally, the legal representative of a minor or of an adult under guardianship, and an agent you have appointed, may also make the requests above; in that case we may separately ask for documents evidencing that authority (for example a document showing parental status, or a power of attorney).

Contact Us

If you have any questions, comments, or requests regarding this Privacy Policy or the handling of personal information, please contact us via our Support page (support@nihonletter.app).