
Legal
Cookie and External Transmission Policy
Page Summary
- Audience
- readers who want to know how cookies and on-device storage are used, and what is sent from their device and to whom.
- Important Point
- no cookies are used for advertising or behavioural targeting. Performance measurement (30 July 2026) and network error reporting (31 July 2026) have both been stopped.
- Required Action
- check the effect on functionality before changing your browser settings.
Contents (14)
- 1Scope
- 2Cookies and Other On-Device Storage
- 3When On-Device Data Remains
- 4Understanding Usage
- 5Outside the Scope of Measurement
- 6Transmission to External Parties
- 7Transmissions That Have Been Stopped
- 8If External Transmission Is Introduced in Future
- 9Where You Move to a Payment Screen
- 10Handling of Information on Payment Screens
- 11Regarding Consent
- 12Refusing Cookies and the Consequences
- 13Handling Outside Japan
- 14Revisions
1Scope
This Policy applies to the website and app of the service (sumlia.com).
Handling on external providers’ pages reached from the service (such as payment screens) is governed by those providers’ own terms. The providers to which transmission occurs after such a transition are listed under "Transmission to External Parties".
This Policy supplements the Privacy Policy. Matters not provided for in this Policy are governed by the Privacy Policy.
2Cookies and Other On-Device Storage
The operator uses cookies, browser local storage, session storage, IndexedDB, and cache storage. So that learning is possible offline, some of the data needed for learning is stored on the user’s device.
| Purpose | Content | Retention |
|---|---|---|
| Maintaining authentication | Cookies that keep you signed in (two kinds). They are issued with settings that prevent anyone other than the operator from reading them (HttpOnly, Secure) | Up to 90 days from your last use. The expiry is extended each time you use the service, so no re-login is needed while you continue to use it. The cookie used to check the sign-in state is refreshed hourly |
| Display language (NEXT_LOCALE) | Keeps the Japanese/English display setting | Until the browser is closed |
| Display mode (app-mode) | Keeps whether the learning screen or the guardian screen opens | 30 days |
| Display settings (sumlia_text_register) | Keeps the child-facing script setting (mainly hiragana, or standard). Because the display differs per user, it contains a string generated from the user’s identifier (a one-way conversion value from which the original identifier cannot be recovered) | 1 year |
| Continuing an invite | When you register from an invite link, a cookie that keeps the invite information from being lost partway through registration. It is issued with settings that prevent anyone other than the operator from reading it (HttpOnly, Secure) and is sent only to the processing that applies the invite (it is not sent to any other screen or feature) | Up to 30 minutes. It is deleted once the invite has been applied, and on sign-out, sign-in, and account deletion |
| Fraud prevention | Cookies automatically set by the service’s delivery infrastructure (Cloudflare) may be issued | Per that company’s settings |
| Storage | What is stored |
|---|---|
| Local storage | The user’s profile, history of learning messages, information about the school year, display mode, display language, last use date, and the analytics consent setting. While a registration or account deletion procedure is in progress, temporary information needed to complete it (the display name being entered, the confirmation code, and information used to confirm the deletion) is also stored |
| Session storage | Information about the signed-in account (including the email address) and temporary screen-transition state. Cleared when the browser tab is closed |
| IndexedDB | Problems presented, answers, correctness, time taken, learning sessions, levels, daily learning status, display settings |
| Cache storage | Display data such as screens, images, audio, and styles |
| Trigger | What is deleted |
|---|---|
| Pressing the sign-out button on screen | Authentication cookies, the display-settings cookie, the profile, message history, information about the school year, signed-in account information, and cached API responses |
| Pressing the sign-out button on screen (learning records) | Those learning records that have already been saved (synchronized) to the server |
| Deleting the account | The above, plus on-device learning data including learning records that have not been synchronized |
| What remains on the device | What it is, and how to remove it |
|---|---|
| Display mode, display language, and the analytics consent setting | These are all device settings and contain no information identifying the individual user. They can be removed from the browser’s settings |
3When On-Device Data Remains
Learning records that have not been synchronized remain on the device even after signing out. This is by design, so that learning records are not lost when, for example, the connection drops. If you use a shared device, please consider deleting the account or clearing site data from the browser’s settings.
If you finish using the service without pressing the sign-out button (connection loss, closing the tab, the app terminating abnormally), on-device data is not deleted. It is deleted the next time you sign out from the screen.
The tables above describe the device on which the operation is performed. If you use the service on several devices, information stored on devices where you did not perform the deletion remains even after you delete the account. Because you cannot sign in again after deletion, that information cannot be erased from within the service. Please clear site data and cookies from the browser settings on each device you use.
4Understanding Usage
To understand usage of public pages (the top page, articles, and similar), the operator sends the following information to its own servers and aggregates it. No third-party analytics tool is used.
| Item sent | Content |
|---|---|
| Event type | Page view, section view, button press, completion of registration |
| Identification of the target (section views and button presses only) | The name of the section displayed and the type of button pressed. Both are fixed strings identifying an element on the page and contain no information identifying an individual |
| Path of the page viewed | The path of the public page. It contains no information identifying an individual |
| Display language | ja or en |
| View identifier | A random value newly generated each time a page is opened. It is stored neither in a cookie nor on the device, and becomes a different value when the page is reloaded. It cannot be linked to the same user on a return visit |
| Referrer host name, campaign information | The referrer where the user came from an external site. The full URL is not included |
| Device category | Whether a smartphone or not (determined by the operator’s server from the information in the request) |
| Method | Effect |
|---|---|
| Enable "Do Not Track" in your browser | The transmission above is not performed |
| Enable Global Privacy Control (GPC) in your browser or an extension | The same |
5Outside the Scope of Measurement
Learning screens after sign-in and payment screens are outside the scope of this measurement. IP addresses, user identifiers, and browser identification information as such are not stored.
Neither of the methods above affects the functionality of the service. No transmission occurs while offline either.
6Transmission to External Parties
No cookies or similar technologies are used for advertising delivery or behavioural targeting. Google Analytics and other Google measurement tags are not used either.
| Recipient | Information sent | The operator’s purpose | The recipient’s purpose |
|---|---|---|---|
| Cloudflare, Inc. (United States) — delivery infrastructure | All communications to the service (including IP address, request headers, URLs viewed, and cookies) | Delivering the service, protecting communications, fraud prevention | Provision of that company’s services |
| Supabase (Singapore) and others | Not sent directly from the user’s device. Transmission goes via the operator’s servers | — | — |
7Transmissions That Have Been Stopped
The operator has stopped the following two transmissions. Both have been disabled in configuration, and the absence of transmission has been confirmed.
- Transmission of performance data to Cloudflare for measuring display performance (stopped on 30 July 2026)
- The setting that had browsers report network errors to Cloudflare when communication failed (stopped on 31 July 2026)
8If External Transmission Is Introduced in Future
If in future the operator introduces a mechanism that sends information from the user’s device to an external party — for measuring display performance or for any other purpose — we will update this policy before introducing it, and will state the recipient, the information sent, the purpose of use, and how to stop it.
9Where You Move to a Payment Screen
Payment for the service takes place on Stripe’s own pages. Communications after moving to those pages occur on Stripe’s site, not on the operator’s site.
| Provider | Content |
|---|---|
| Stripe | Display of the payment screens, and measurement of usage by that company |
| A fraud-prevention mechanism Stripe uses on its own payment screens | Transmission of device and communication information to detect automated fraudulent operations. This mechanism is built into Stripe’s payment functions and cannot be switched off by us |
10Handling of Information on Payment Screens
Handling of information on those screens is governed by each company’s own terms. The operator does not obtain card numbers or similar details entered on those screens.
11Regarding Consent
The operator does not display a consent banner, because it does not use cookies or similar technologies for advertising delivery or behavioural targeting.
The measurement described under "Understanding Usage" does not use cookies or on-device storage, and is carried out by a method that cannot link a user across return visits or across devices.
If in future the operator introduces cookies or similar technologies that require prior consent, or if consent or opt-out means become necessary for the handling described in this Policy, the operator will revise this Policy and provide the necessary means.
12Refusing Cookies and the Consequences
You can refuse or delete cookies through your browser settings.
- If cookies are disabled, sign-in cannot be maintained, and some functions — including saving and synchronizing learning records — cannot be used.
- If you share a device, we recommend periodically reviewing cookies and information stored in the browser.
13Handling Outside Japan
The recipients described in this Policy include providers outside Japan. Handling outside Japan is governed by the Privacy Policy.
14Revisions
Where the operator revises this Policy, it will post the revised content and the date of last update within the service.
Related Legal Pages

Cookie Questions
For questions about cookies or external transmission, please contact the legal channel.
- Operator
- Kentaro Ishida (石田憲太朗)
- Legal contact email
- support@sumlia.com