hinoto logohinoto

Privacy Policy

Last updated: October 23, 2025

YONAGI Co., Ltd. (hereinafter "the Company") establishes the following policy regarding the handling of personal information in connection with the AI journaling app "hinoto" and related websites and support (hereinafter "the Service").


Article 1 (Information We Collect)

The Company collects the following information:

  • Account information: email address, authentication provider identifiers, etc.
  • Journal and other content: text, attachments, and metadata (timestamps, etc.) entered and saved by the user. This data is stored in encrypted form, and Company employees do not access plaintext content directly.
  • Transaction information: subscription status, purchase history, transaction IDs, payment dates, amounts, tax information, refunds/chargebacks, etc.
    • (iOS) Payments are processed by Apple; the Company does not acquire or store card information.
    • (Web) Payments are processed by Stripe; the Company does not acquire or store full card numbers or security codes. Where necessary, the Company may reference tokenized payment identifiers and masked information (last 4 digits, brand, expiry) provided by Stripe.
  • Device and log information: app version, device info, IP address, crash logs, and event data from analytics tools such as Firebase.
  • Inquiry information: content of support inquiries, contact details, etc.

* User inputs may contain sensitive personal information such as health or mental health data. The Company collects such information based on the user's voluntary input and handles it appropriately in accordance with applicable law and this Policy.


Article 2 (Collection Methods)

  • Direct input and submission by users
  • Automatic collection through use of the app (logs, analytics events, etc.)
  • Receipt of subscription and transaction information from payment processors (Apple/Stripe)

Article 3 (Purposes of Use)

  • Providing and operating the Service, authentication, billing and subscription management
  • Responding to inquiries, handling incidents, and delivering important notices
  • Quality improvement, fraud prevention, and safety measures (including aggregation and anonymization)
  • Responding to violations of law or the Terms of Service
  • Personalized suggestions and improving the accuracy of AI-based reflection support

Article 4 (Use of Generative AI)

  • To provide AI-based reflection support, the Company may transmit journal text and similar content to AI model providers (such as Google/OpenAI) for inference purposes (communications are encrypted via TLS).
  • Data is not used for secondary purposes such as model training.
  • Even if data is stored in encrypted form on the device, the decrypted content is transmitted to inference providers at the time of processing.

Article 5 (Third-Party Disclosure and International Transfers)

  • The Company will not provide personal information to third parties except as permitted by law or with the user's consent.
  • When providing data to overseas cloud or AI providers (e.g., in the United States), the Company will provide information about the data protection regime of the destination country, the recipient's practices, and the Company's protective measures (contracts, access controls, encryption, etc.), and will obtain consent where required.

Article 6 (Outsourcing)

The Company may outsource tasks such as cloud hosting, analytics, notification delivery, and support operations, and will exercise appropriate oversight of such contractors.


Article 7 (Use of Analytics Tools)

The Company uses analytics tools such as Firebase and Crashlytics to collect app usage data and crash reports. This information is used to provide the Service, improve quality, and prevent fraud — not for advertising purposes. Collected information may include device information and event logs. Users may control some data collection through device settings (e.g., limiting ad tracking).


Article 8 (Retention Period and Deletion)

  • Personal data on our servers will be deleted within 30 days of a request to delete an account.
  • Note on key loss: Since decryption keys are stored in the iOS Keychain on the user's device, data may not be recoverable if the key is lost due to device loss, reset, or reinstallation. Where recovery methods (e.g., iCloud Keychain sync or recovery codes) are available, setup instructions will be provided in the Help section.

Article 9 (Security Measures)

To prevent leakage, loss, or damage of personal information, the Company takes the following measures:

  • Organizational: role-based and least-privilege access management, periodic access reviews, and access log recording and auditing
  • Technical (transmission): encryption of communications (TLS)
  • Technical (storage): application-level encryption (e.g., AES-256-GCM) for sensitive data such as journal entries
  • Key management: decryption keys are stored in the user's iOS Keychain and not on Company servers (if cloud KMS is used in the future, keys will be managed separately with strict access controls and auditing)
  • Backup: server-side backups are also stored in encrypted form
  • Contractor management: confidentiality agreements and security compliance checks
  • Incident response: established procedures for detection, reporting, impact assessment, and recurrence prevention

Article 10 (Requests for Disclosure, etc.)

You may request disclosure, correction, addition, deletion, suspension of use, or cessation of third-party provision of personal data held by the Company. We will respond promptly after verifying your identity. There is generally no fee, but actual costs may apply for extensive disclosures. Please contact the office listed in Article 12.


Article 11 (Amendments)

When amending this Policy, the Company will notify users via in-app announcements or other means. Where changes materially affect users' rights — such as a substantial change to the purposes of use — the Company will take appropriate steps, including re-obtaining consent.


Article 12 (Business Operator, Controller, and Contact)

For inquiries regarding this Policy, please contact:

Business Name: YONAGI Co., Ltd.

Representative Director: Shuichi Ikehara

Address: 3-6-14 Kamishakujii, Nakano-ku, Tokyo

Department: hinoto Customer Support

Email: hello@hinoto.ai


Article 13 (For EU Residents)

This article provides supplementary information for residents of the EU/EEA to whom the EU General Data Protection Regulation (GDPR) applies.

  • Legal basis for processing: The primary legal bases are performance of a contract (GDPR Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). Processing of sensitive data (Art. 9), such as journal entries, is based on the user's explicit consent (Art. 9(2)(a)).
  • Rights of EU residents: You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), data portability (Art. 20), restriction of processing (Art. 18), and the right to object (Art. 21). To exercise these rights, please contact us at the email address in Article 12. We will respond within 30 days.
  • Data transfers outside the EEA: Transfers of data to Google (Firebase / Gemini), OpenAI, and Stripe are made under EU Standard Contractual Clauses (SCCs) with appropriate safeguards.
  • Right to lodge a complaint: EU residents have the right to lodge a complaint with their local data protection authority (DPA).

— End —