DRAFT — This is not legal advice. Review by qualified counsel is required before publication.
Last updated: 2026-08-14
Governing law: Japan
This Privacy Policy explains how Gftd Japan 株式会社 (Gftd Japan K.K.), GranTokyo South Tower 11F, 1-9-2 Marunouchi, Chiyoda-ku, Tokyo 100-6611, Japan (Corporate Number 1011101086505) (the "Operator", "we") handles personal information in connection with the kotobase.net Service (the "Service").
Our primary framework is the Japanese Act on the Protection of Personal Information (APPI, 個人情報保護法). Where applicable we also address the EU/EEA General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
For much of the Customer Data you ingest, you act as the controller/business and we act as your processor/service provider; in that case your own privacy notice governs your end users, and we handle that data under our agreement with you.
https://auth.kotobase.net — the identifiers associated with your bearer token. Email address is collected when you sign in with email OTP (and would be collected from an identity provider if Google/GitHub OAuth were enabled; both are disabled in production). A display name is not required by the apex Worker. Accounts may also be keyed by a hash of email in the same-origin session path (kotobase_session).pin_id, name, cid, target, status, timestamps, size, content type, archived object keys, error strings), and optional archive payloads (IPLD CARs or raw bytes) that you ingest or pin. This content may contain personal data that you choose to include; you are responsible for its lawful provision.x-kotobase-request-id), Cloudflare cf-ray, edge/version identifiers, storage-mode signals, sanitized error summaries, and smoke/health output.We do not intentionally collect special-category / sensitive data, and you must not submit secrets or sensitive personal data into fields, logs, or public metadata contrary to docs/DATA-HANDLING.md.
We process personal information to:
APPI: we identify and use personal information within the scope of the utilization purposes above (APPI Arts. 17–18) and do not use it beyond them without consent, except as permitted by law.
GDPR legal bases (for EU/EEA users, where applicable): performance of a contract (Art. 6(1)(b)); legitimate interests in operating and securing the Service (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)); and consent (Art. 6(1)(a)) where relied upon (e.g. certain cookies).
CCPA/CPRA: we process personal information for the business purposes above. The kotobase.net marketing and API surfaces do not load advertising pixels or cross-context behavioural advertising scripts. Unauthenticated GET / and GET /signup set no cookies. We do not disclose personal information for monetary consideration. [CONFIRM: counsel must still confirm this meets CCPA/CPRA "sale" / "share" definitions before that characterisation is treated as a customer-facing representation.]
We share personal information only with service providers ("subprocessors") that process it on our behalf to deliver the Service, and as required by law. Current subprocessors:
| Subprocessor | Function | Data involved |
|---|---|---|
| Cloudflare, Inc. | Edge/Worker control plane, Durable Objects (tenant locks), TLS, DNS | Request metadata, tenant identifiers, edge diagnostics |
| Backblaze, Inc. (B2) | Object storage for pin metadata, replay markers, and optional CAR/raw archives | Pin metadata, archive payloads |
| Stripe, Inc. | Payment processing and subscription billing | Payment/billing data, tenant DID reference |
| Plus Five Five, Inc. (Resend) | Transactional email delivery when mail is sent | Email address, headers, message content and delivery events |
| auth.kotobase.net | Session verification and tenant identity controls | Account identity, session data, tenant metadata |
The machine-readable source register is legal/subprocessors.json. Counsel must still verify the complete hosting chain, account entities, processing regions, contract acceptance and transfer safeguards before publication. Do not treat this table as an approved or exhaustive contractual list until that review is recorded.
Content stored as CIDs may also be retrievable by third parties through the public IPFS network, gateways, and caches; this is inherent to content addressing and is not limited to our subprocessors.
The Operator is based in Japan and uses subprocessors that may process data outside your country, including the United States. The configured production register (legal/subprocessors.json, version 2026-08-03) records Cloudflare as distributed including the United States, Stripe as international including the United States, Resend as United States, and Backblaze as a configured-account region that must still be exported from the provider dashboard.
AUDIT_RETENTION_DAYS; the deployed default is 365 days. Existing records keep the TTL assigned when written, so changing the setting is not legal hold.DELETE /pins/:id is marked as deleted; this does not guarantee cryptographic erasure of previously archived content-addressed bytes.legal/retention-schedule.json. Customer-specific pin/archive periods and the effective account, billing, transactional-email, diagnostics and tombstone periods remain unqualified until the applicable contract, provider settings and counsel-approved schedule record them.nosniff and frame denial./_app/meta), logs, and error responses by design.Subject to applicable law and to verification of your identity, you may request:
To exercise rights, contact us at hello@gftd.co.jp. Because deletion of content-addressed data cannot be fully guaranteed, we will explain the limits of any erasure request.
Unauthenticated GET https://kotobase.net/ and GET /signup set no cookies (measured 2026-08-14). After sign-in, session cookies may be set:
gftd_session — issued by auth.kotobase.net, used to authenticate browser navigations to kotobase.net (HttpOnly / Secure / SameSite as configured by the authentication service);kotobase_session — same-origin Worker session (HttpOnly; Secure; SameSite=Lax; Max-Age=2592000).Both are strictly necessary for an authenticated session. The marketing pages do not load analytics or advertising scripts. Visit telemetry (kaiyu) is recorded server-side from the request Referer and does not set a cookie. The API surface is token/CACAO-authenticated and does not rely on cookies.
The Service is not directed to children. You must be at least 18 years of age (owner commercial decision, run 0006). If we learn we have collected account records of a person under 16, we will delete the identity/control-plane records we control; content-addressed Customer Data cannot be guaranteed erased. [CONFIRM: APPI 2026-amendment under-16 handling if any residual processing remains after account deletion.]
We may update this Policy; material changes are indicated by updating the "Last updated" date and, where appropriate, by additional notice.
Email: hello@gftd.co.jp. The Operator's registered address is GranTokyo South Tower 11F, 1-9-2 Marunouchi, Chiyoda-ku, Tokyo 100-6611, Japan (Corporate Number 1011101086505). No DPO or EU-UK GDPR Art. 27 representative is designated at this time.