Hitaru
Privacy Policy (Draft)
Last updated: 2026-08-07
This Privacy Policy explains how the individual operator of Hitaru (the "Service", operated by the "Operator") collects, uses, stores, and protects your personal information. By using the Service, you are deemed to have agreed to this Policy.
1. Who Operates This Service
- The Service is operated by an individual sole proprietor based in Japan (as of July 2026, the Operator has not incorporated a company). If the Operator incorporates in the future, this Policy will be revised and the change of operating entity will be announced.
- For privacy-related inquiries, contact privacy@hitaru.dev (handled directly by the Operator; no dedicated Data Protection Officer has been appointed).
2. Information We Collect
- Account information: email address, display name (optional), learning level (optional), password (hashed and managed by Supabase Auth), and OAuth provider information (e.g. Google, optional).
- Payment information: your Stripe customer ID and billing history. Your credit card number itself is held only by Stripe; the Operator does not store it.
- Learning data: saved expression cards (a one-way hash of the subtitle line plus commentary text — the subtitle text itself is not stored), known-word markers, and review progress (FSRS state).
- Audio clip data: when you tap the star (save) button to create a card, a short audio clip corresponding to the sentence you save. It is transmitted only as end-to-end encrypted (E2EE) data through the temporary relay described in Section 4 — the Operator cannot decrypt or view its content, and it is not retained long-term.
- Device information: your pairing public key and device install ID.
- Behavioral data: anonymized event logs via PostHog (collected only after you consent; your user ID is one-way hashed).
- Technical information: IP address (masked or hashed before storage), User-Agent, and Cloudflare access logs (retained 90 days).
- Error information: error logs and crash reports via Sentry (these do not include directly identifying information such as your email address).
3. Information We Do Not Collect
- Your credit card number itself (Stripe tokenizes and holds it)
- Your Netflix login credentials or password
- The text of Netflix's subtitles (we do not collect or store this, except for the narrow exception described in Section 4)
- Phone numbers, precise location data, or device identifiers such as advertising IDs
4. Handling of Subtitles, Translation, Images, and Audio
- The Service reads and displays Netflix's subtitles (both English and Japanese) locally in your browser only; it does not transmit or store the subtitle text on our servers.
- The "commentary" the Service provides consists of our own explanations of meaning, grammar, and nuance — it is not a full translation of the dialogue.
- As a narrow exception, for titles that lack an official Japanese subtitle track, or where a mislabeled or mixed-language subtitle track is detected, the Service may temporarily store machine-translated text in an internal cache. This storage occurs only under the conditions that (a) it is keyed solely by a one-way hash of the source line, (b) it is never linked to your account, and (c) it is automatically deleted after at most 30 or 90 days depending on the case. This mirrors the kind of translation caching common among similar learning services, operated here under stricter implementation constraints (hashing, no account linkage, automatic expiry, and a takedown process).
- Screenshots and similar images pass through our servers only temporarily, for at most 5 minutes, while end-to-end encrypted and undecryptable by us, and are deleted immediately once transfer to the mobile app completes.
- When you tap the star (save) button to create a card, a short audio clip corresponding to the sentence you save is transmitted through the same kind of temporary, end-to-end encrypted relay — undecryptable by us — and is automatically deleted after a short period rather than being retained long-term (see Section 8).
5. How We Use Information
- Providing the Service: generating commentary, scheduling reviews (SRS), and transferring cards between devices (E2EE relay)
- Billing: managing your subscription through Stripe
- Quality improvement: usage analytics (PostHog, only after consent) and understanding malfunctions (Sentry)
- Anti-abuse: detecting abuse (rate limiting, detection of anomalous usage patterns)
- Legal compliance: complying with copyright law, Japan's Act on the Protection of Personal Information, GDPR, and similar laws, and responding to takedown requests
6. Cookies and Tracking
- Essential cookies: authentication session (Supabase Auth), language preference (hitaru-lang), theme preference (hitaru-theme), and cookie consent state.
- Analytics cookies: an anonymized PostHog identifier (active only after you consent; you can opt out from the settings screen).
- Marketing cookies: we do not use any (we do not use Google Ads, Facebook Pixel, or similar).
- For users in Japan, we do not currently display a cookie consent banner; disclosure in this Policy serves this purpose for now. We will consider implementing a consent banner as our service expands.
7. Third-Party Recipients and Processors
- Stripe: email address, payment information → billing
- Supabase: account information, learning data, etc. → authentication and database
- Cloudflare: access logs, encrypted temporary relay data → CDN, API infrastructure, and relay
- Upstash: rate-limit counters (hashed user/IP tokens only — we never send raw IP addresses or email addresses) → rate limiting
- PostHog: anonymized behavioral events → analytics (client-side events from the web app and browser extension are processed in the EU region; server-side events from our API and batch systems are processed in the US region)
- Sentry: error information → error monitoring
- Resend: email address, notification content → sending email
- A third-party push notification service: push notification token → delivering notifications
- OpenAI, Anthropic, and Google: only title metadata and short quotations (we never send information that identifies you personally) → generating commentary
- We do not sell or otherwise provide your personal data to any third party beyond those listed above. We respond to legally mandated disclosure requests (from courts, law enforcement, etc.) within the scope required by applicable law.
8. Retention and Deletion
- For 14 days after you request account deletion, your account is deactivated and your personal information is masked (a soft delete); you may cancel the request during this period.
- 180 days after that, your data is permanently deleted, including from backups.
- Payment records are retained for 7 years as required by tax law. Audit logs (records of significant account actions) are retained for 1 year.
- Temporary relay data used to transfer cards, screenshots, and audio clips between devices is automatically deleted from Cloudflare R2 after a short retention window; the exact window varies by data type, but relay data is never kept for long-term storage.
- Using the in-app "data export" feature, you can obtain your data in JSON format within 24 hours. You can request account deletion using the in-app "account deletion" feature.
9. International Data Transfers
- Cloudflare, Stripe, and similar providers operate global infrastructure that includes the United States. Supabase primarily uses the Tokyo region. PostHog processing is split by source: client-side analytics events (web app, browser extension) are processed in the EU region (eu.i.posthog.com), while server-side analytics events (API, batch backend) are processed in the US region (us.i.posthog.com).
- In line with Article 28 of Japan's Act on the Protection of Personal Information, this Policy discloses the destination countries and an outline of protective measures. If the Service expands substantially into the EU, we will confirm additional safeguards such as Standard Contractual Clauses (SCCs).
10. Your Rights
- Right of access: you may request disclosure of your data through the data export feature.
- Right of correction: you can change your display name and similar information from in-app settings.
- Right of deletion: deleting your account removes your data in accordance with the timeline and process set out in Section 8.
- Data portability: JSON export helps you move your data to another service.
- Withdrawing consent: you can opt out of PostHog analytics and marketing emails from the settings screen or the email footer.
- For requests related to the above, contact privacy@hitaru.dev. We aim to respond within 30 days.
11. Children's Privacy
- The Service is not primarily directed at children under 13. If a user under 13 uses the Service, consent from a parent or legal guardian is required.
- If the Operator becomes aware that it has collected personal information from a user under 13 without parental or guardian consent, it will promptly delete that information.
12. Security Measures
- Temporary relay data is end-to-end encrypted (E2EE), so no one — including the Operator — can decrypt or view its content.
- Stored data is protected by Supabase's encryption at rest, and communications are encrypted using TLS 1.3.
- In the event of a data breach, we will comply with applicable law, including a preliminary report to Japan's Personal Information Protection Commission (within 3–5 business days) and notification to affected users (within 7 days).
13. Anti-Abuse and Automated Decisions
- To detect abuse, we score signals such as device fingerprints, IP addresses, and behavioral patterns, and may make automated decisions such as restricting an account when a threshold is exceeded.
- If you disagree with such an automated decision, you may request human review by contacting support@hitaru.dev (we aim to acknowledge within 48 hours and decide within 7 days).
- The categories of signals used are as summarized in this Section; detailed internal weighting is kept confidential to prevent circumvention.
14. Region-Specific Rights (GDPR and Japan's APPI)
- If you are in Japan: you may make requests for disclosure, correction, and suspension of use under Japan's Act on the Protection of Personal Information (Article 32 et seq.).
- If you are in the EU: you may exercise the rights under Articles 15–22 of the GDPR, including the rights of access, erasure, restriction of processing, and objection.
- The Service is not currently substantially operating within the EU, and no EU representative has been appointed. This will be addressed separately if the Service expands into the EU.
15. Changes to This Policy
- This Policy may be revised from time to time. For material changes, we will provide at least 30 days' advance notice before the changes take effect, by updating this page and notifying you at your registered email address.
16. Contact
- Privacy-related inquiries: privacy@hitaru.dev
- Copyright infringement claims (DMCA / Japan's Information Distribution Platform Act): /legal/takedown
- The Japanese version of this Policy is the controlling version. The English version is provided for your convenience.