
Legal
Privacy Policy
Page Summary
- Audience
- the contracting guardian, the registered child, and anyone who contacts us.
- Important Point
- covers what we collect, why, which providers are involved, handling outside Japan, retention, and deletion.
- Required Action
- contact us from your registered email address for disclosure, correction, or suspension of use.
Contents (24)
- 1The Operator and Who This Covers
- 2Information Collected
- 3Card Details
- 4How Information Is Collected
- 5Purposes of Use
- 6Changes to Purposes of Use
- 7Children’s Information
- 8External Providers
- 9Authentication Emails and Passwords
- 10External Involvement on Payment Screens
- 11Provision to Third Parties
- 12Handling Outside Japan
- 13Cookies, On-Device Storage, and External Transmission
- 14Retention Periods
- 15Account Deletion and Deletion Requests
- 16Statistical Information
- 17Security Control Measures
- 18Understanding the External Environment for Handling Personal Data Abroad
- 19Notes on the External Environment
- 20Disclosure, Correction, and Suspension of Use
- 21How to Make a Request
- 22Interviews and Marketing
- 23If a Leak or Similar Incident Occurs
- 24Changes to This Policy
1The Operator and Who This Covers
The personal information handling business operator is Kentaro Ishida. The address and contact details are given at the end of this page.
This English text is provided for reference only. The Japanese version is the authoritative text and prevails in the event of any discrepancy.
This Policy applies to information about the guardian who contracts for the service and manages the registered email address, the child registered by that guardian, and anyone who contacts the operator through inquiries, applications to invitations, or applications for interviews.
One guardian is the contracting party and account administrator, and one child is registered per account. Guardians other than the contracting guardian may watch over the child’s learning but have no independent account administration rights.
2Information Collected
The operator collects the following information to the extent necessary to provide the service. Depending on the features used, not all of it is collected.
- Guardian and account: registered email address; user ID, authentication identifier, and authentication status; display name and other registration details; registration date and time, language, and the type, version, and timing of presentation of and consent to the terms; guardian onboarding answers; records of changes to registration details, identity confirmation, and account management
- Child: nickname or display name; school year; the initial assessment, learning methods, display settings, and other onboarding entries; internal identifiers linking the child to the guardian’s account
- Learning and usage: problems presented, answers, correctness, answer times and time taken; learning sessions, learning days, continuity, levels, achievement, and history; assessment results, use of hints, learning support displayed, and feature usage; optional feedback; records of screen display, operations, errors, and synchronization state
- Contract and payment: plan selected, version of the fee conditions, contract status; identifiers issued by the payment provider; amounts billed, currency, billing dates, payment status, scheduled cancellation, contract periods; transaction information notified by Stripe; refund requests, decisions, reasons, amounts, and refund IDs
- Device, communication, and logs: IP address, access date and time, referrer, URL, HTTP headers; browser, OS, device type, language, time zone; information recorded in on-device storage for authentication, settings, learning, and synchronization; logs for errors, security, authentication, API use, and system operation; usage of public pages including a randomly generated view identifier
- Inquiries, invitations, and interviews: name or display name, email address, content of inquiries and handling history; invitation applications and sending history; interview applications, scheduling, guardian consent, responses, and any honorarium; marketing email sign-ups, delivery, opt-outs, and the minimum information needed to keep an opt-out in force
3Card Details
Full card numbers, card security codes, and other information entered directly into Stripe’s payment screens are handled by Stripe; the operator does not, in principle, collect or store them.
4How Information Is Collected
The operator collects information through entry into the service by the contracting guardian or the child, automatic recording in the course of use, receipt from Stripe and other external providers of information necessary for contracts, payments, authentication, security, or system operation, and receipt through inquiries, invitations, interviews, and other communications.
Where the operator collects personal information directly through a web form or similar, it states the purpose of use in advance in accordance with law, except where the purpose is clear from the circumstances or another statutory exception applies.
5Purposes of Use
The operator uses the information it collects for the following purposes.
- Providing the service: creating, authenticating, and maintaining accounts; providing problems, learning screens, hints, and feedback suited to the child; recording and displaying learning history and progress; synchronizing on-device learning records with the server
- Contracts, billing, and support: receiving and accepting subscriptions and recording contract details; billing, managing payment status, retries, cancellation, plan changes, and refunds; identity confirmation, changes to registration details, and account deletion; responding to inquiries and giving important notices
- Safe operation: preventing, detecting, investigating, and responding to unauthorized access, fraudulent payments, breaches, and misuse; investigating and recovering from failures and security incidents; access control, auditing, backups, and other security control measures
- Improvement and analysis: understanding usage, learning trends, and the effectiveness of features; improving the service, learning materials, and learning support; creating and analyzing statistical information from which individuals cannot reasonably be re-identified
- Optional communications: interview requests and marketing messages to those who have individually consented (consent is obtained separately for each and can be opted out of at any time)
- Legal compliance and protection of rights: responding to lawful requests; creating and retaining records necessary for tax, accounting, contractual, and dispute purposes; protecting the rights, property, or safety of the operator, users, or third parties
6Changes to Purposes of Use
Where the operator changes a purpose of use, it does so within a scope reasonably related to the purpose before the change, and notifies or announces it in accordance with law. Changes requiring individual consent are not made by notice alone.
7Children’s Information
The contracting guardian registers the child after reviewing this Policy and the Children’s Privacy Notice.
Explanation to the child about the handling of information is given by the contracting guardian, in a manner suited to the child’s level of understanding. On screens used by the child, the operator uses expressions appropriate to the child’s age and level of understanding.
The operator limits the child’s information to what is necessary to provide the service and takes the best interests of the child into account. The child does not independently contract, make payments, change the registered email address, or delete the account. Interviews with a child require the guardian’s individual consent and presence.
8External Providers
The operator uses the following external providers to the extent necessary to provide the service.
| Provider | The operator’s position | Main purpose | Information mainly handled |
|---|---|---|---|
| Stripe (payment processing) | Entrustment | Payments, billing, subscriptions, refunds | Guardian information, payment information, transaction information |
| Stripe (its own handling) | Provision to a third party | Prevention of fraudulent use, legal compliance, analysis and improvement of its services | Payment-related information, device and communication information |
| Supabase | Entrustment | Database, authentication, data storage, and related system functions | Account information, passwords, children’s information, learning information, contract status, consent records, logs |
| Cloudflare | Entrustment | Web delivery, communications, security, the application execution environment, and system operation | Information handled by the service generally (it passes through the communication relay and the execution environment), IP addresses, device and communication information, requests, and logs |
| Resend | Entrustment | Sending email for authentication and communications | Email address, subject and body of the email |
9Authentication Emails and Passwords
Confirmation codes at account registration and other authentication emails are sent through the email provider above. The operator does not include in those emails any information about an individual other than the confirmation code or link and the destination email address.
Passwords entered at authentication are sent over encrypted communications to the authentication service provider and handled temporarily for authentication processing. When stored, they are stored as salted hash values rather than the original password.
Where the operator entrusts the handling of personal data, it supervises the entrusted party as necessary and appropriate. Where an external provider handles information as a personal information handling business operator in its own right, that provider’s own privacy notice also applies.
10External Involvement on Payment Screens
Payment screens are provided by Stripe on its own pages. On those screens, an external provider engaged by Stripe is involved in order to prevent automated fraudulent operations, and device and communication information is sent to that provider. This mechanism is built into Stripe’s payment functions and cannot be switched off by us.
Handling of that information is governed by the terms of Stripe and of that provider. The operator does not obtain card numbers or similar details entered on those screens.
11Provision to Third Parties
Except where based on law; where necessary to protect a person’s life, body, or property and obtaining consent is difficult; where specially necessary to improve public health or promote the sound upbringing of children and obtaining consent is difficult; where cooperation with statutory duties of a public body is necessary and obtaining consent risks impeding them; in connection with a business succession; or where the provision otherwise does not constitute provision to a third party under the Act on the Protection of Personal Information or may be made without consent, the operator does not provide personal data to third parties without prior consent.
Where the operator entrusts handling, it does not allow handling beyond the scope of the purpose of entrustment.
The payment provider also handles information to prevent fraudulent use and to meet its own legal obligations in connection with providing payment services. These are integral to the payment service and cannot be switched off by us. That company also follows the policies it has set for such handling.
12Handling Outside Japan
In connection with the use of Stripe, Supabase, Cloudflare, and Resend, information is handled on servers or at sites located outside Japan. Personal data is handled in the following countries: for Supabase, Singapore for the database and countries including the United States for platform logs, monitoring, and operational support; for Stripe, the United States and other countries; for Cloudflare, countries worldwide; and for Resend, the United States. For Stripe and Cloudflare, the structure of their services means the countries of handling cannot be identified as a single country.
Provision to providers located outside Japan is subject to Article 28 of the Act on the Protection of Personal Information even where it is entrustment. This does not apply to provision to a provider located in a country or region designated under that Act as having a system recognized as equivalent to Japan’s. The counterparty to the payment contract is a company located in Ireland, which is within that designation.
For provision to Supabase, Cloudflare, Resend, and the United States Stripe entity, the operator provides information after confirming that these providers have established systems for continuously taking measures equivalent to those required of personal information handling business operators under Japanese law. The operator checks the state of implementation and the systems of those countries on a regular basis, takes necessary measures if problems arise, and if continuation becomes difficult we stop providing data.
On request from the person or their statutory representative, the operator will answer regarding how those systems are established, an outline of the equivalent measures, the frequency and method of checking, the countries where the recipients are located, the systems of those countries, whether any problems have arisen, and the measures taken.
If in future the operator makes a provision that cannot rely on these methods, it will provide the country or region of the recipient, that country’s personal information protection system, the recipient’s protective measures, and other information required by law, and will obtain individual consent for that processing.
13Cookies, On-Device Storage, and External Transmission
The service uses cookies, local storage, session storage, IndexedDB, caches, and other technologies for maintaining sign-in, security, language and display settings, offline use, synchronizing learning records, investigating failures, and improving quality.
The service does not use Google Analytics 4 or other third-party advertising measurement tools. Usage of public pages may be aggregated through a mechanism managed by the operator.
When you use Stripe’s payment screens, Supabase’s authentication and data functions, and Cloudflare’s delivery and security functions, the necessary communication information is sent to each provider. Details of recipients, items sent, purposes, and how to stop transmission are set out in the Cookie and External Transmission Policy.
If you disable essential storage or communications, you may be unable to use functions such as sign-in, learning records, or payment.
14Retention Periods
The operator retains personal information only for the period necessary to achieve the purposes of use, perform the contract, comply with law, maintain security, or handle disputes.
Account information and learning information linked to individuals is retained while the contract or account exists, and for the period necessary afterwards to handle deletion, inquiries, and resumption. Information relating to billing, payments, refunds, contracts, consents, tax, and accounting is retained for the period necessary under applicable law or for billing and dispute handling.
Information relating to security, fraudulent use, inquiries, and disputes is retained for the period necessary for investigation, prevention of recurrence, protection of rights, or legal compliance. Information in backups is overwritten or deleted within a reasonable period in accordance with safe rotation and restoration procedures.
For those who have opted out, the minimum information needed to avoid sending again may be retained. Information no longer needing retention is deleted securely or processed into information from which individuals cannot reasonably be re-identified.
15Account Deletion and Deletion Requests
The contracting guardian may request deletion of account information and learning information linked to individuals, by the method the operator indicates. After confirming identity, the operator deletes the email address, account information, and learning information linked to individuals that are no longer necessary.
Where deletion is requested during a paid contract period, the operator immediately cancels that subscription and then carries out the deletion. No charge for the service arises after deletion is complete. Where a payment is completed through processing already in progress before the request, the operator cancels the subscription and refunds that payment in full.
Records of billing, payments and refunds; contracts and consents; vouchers necessary for tax and accounting; records of fraudulent use and security incidents; records of inquiries and dispute handling; grounds for decisions on breaches and suspension; and the minimum records needed to keep an opt-out in force may be retained separately after deletion, limited to the scope and period necessary. "Retained separately" means keeping the record after severing its correspondence with names, email addresses, and other directly identifying information. The operator does not describe this severance as making the record anonymized.
Identifiers assigned by the payment provider and the operator’s internal management IDs are retained within those records in order to stop billing and identify the contract. The operator does not carry out deletion only after a waiting period, and does not separately retain deleted personal data solely for account restoration.
Transaction records held by the payment provider are vouchers for tax and accounting purposes and are not deleted on that provider’s side. After deletion, the operator does not use those records in connection with names or email addresses, except solely to confirm that no billing has occurred for a deleted contract, to cancel and refund if any does occur, and to reconcile the results of the deletion.
Information stored only on the device and technically inaccessible to the operator must be deleted by the contracting guardian on that device or browser. For the device from which the request is made, the operator erases such information to the extent technically possible. Because signing in again is not possible after deletion, information on other devices should be removed by clearing this site’s site data and cookies from that device’s browser settings.
Information remaining in backups is deleted or overwritten in accordance with ordinary rotation, and is managed so that deleted data is not permanently restored to the production environment.
16Statistical Information
The operator may create statistical information from the information it collects, for purposes such as improving the service and analyzing learning trends. Statistical information severed from any correspondence with individuals and placed in a state where individuals cannot reasonably be re-identified may be retained and used for the necessary period.
Information that remains reasonably re-identifiable from internal IDs, detailed histories, or other information merely because the email address or name has been removed is not treated as statistical information under this section.
17Security Control Measures
The operator implements security control measures such as the following, according to the nature of the information handled and the risks involved.
- Establishing responsibilities and procedures for handling information
- Restricting access rights to the minimum necessary personnel
- Authentication, encryption of communications, and countermeasures against unauthorized access
- Restricting the scope of access per user and otherwise separating data between users
- Reviewing logs, addressing vulnerabilities, and responding to security incidents
- Selecting, contracting with, and appropriately supervising external providers
- Where personal data is handled in a foreign country, understanding that country’s personal information protection system and implementing necessary measures
18Understanding the External Environment for Handling Personal Data Abroad
The operator uses the following external providers, and personal data is also handled outside Japan.
| Provider | Countries where personal data is handled |
|---|---|
| Supabase (database) | Singapore |
| Supabase (platform logs, monitoring, and operational support) | Countries including the United States |
| Stripe | The United States and other countries |
| Cloudflare | Countries worldwide |
| Resend | The United States |
19Notes on the External Environment
For Supabase, the operator has selected a Singapore region for database storage. Logs, monitoring, and operational support arising from running the service may, through that company and the sub-processors it publishes, be handled in countries including the United States.
Stripe and Cloudflare provide their services on infrastructure spanning multiple countries and regions, and the countries of handling cannot be identified as a single country. For Cloudflare, communications are processed via the nearest of its network locations worldwide, so the country of processing is not fixed.
Based on information published by each provider, the operator understands the personal information protection systems of these countries and implements the security control measures above. It also selects providers after confirming the protective measures they take for international data transfers.
The operator will answer requests regarding an outline of its security control measures in accordance with law. For security reasons, it may withhold specific configuration values or information that could be used for attacks.
20Disclosure, Correction, and Suspension of Use
The person or their statutory representative may request notification of the purpose of use, disclosure of retained personal data or of third-party provision records, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties.
Requests concerning a child’s information are in principle accepted from the contracting guardian. Where the child makes a request, the operator responds taking into account age, content, and applicable law, liaising with the guardian as necessary. Where a guardian other than the contracting guardian makes a request, the operator responds after confirming statutory representative or other legitimate authority.
The operator investigates without delay in accordance with law and notifies the outcome or the reason for not responding. It may decline all or part of a request where it is not subject to a request under law, where there is a risk of harming rights or interests, where there is a risk of significantly impeding the proper conduct of business, or where refusal is otherwise permitted under law.
21How to Make a Request
Requests are accepted through the following procedure.
- How to submit: contact the email address at the end of this page from your registered email address. There is no prescribed form.
- What to include: the type of request (notification of purpose of use, disclosure, disclosure of third-party provision records, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties) and its subject matter.
- Identity confirmation: confirmed by the fact that the contact arrives from the registered email address. Where that address cannot be used, the operator confirms identity using the minimum necessary contract information. To prevent impersonation, the operator does not publish the combination of items used for confirmation or any other specific criteria. Where confirmation is not possible or insufficient, the operator may decline the request.
- Requests by a representative: the operator may ask for materials evidencing the authority of representation.
- How the operator responds: in principle by reply to the registered email address. Where the volume of disclosure is large, it may be provided by electromagnetic record.
- Fees: none.
22Interviews and Marketing
Interview requests and marketing emails are not required in order to contract for or use the service. The operator obtains separate, voluntary consent for each, and records the date and time of consent, the subject, the version, and any opt-out.
Consent can be withdrawn at any time with prospective effect. Even after opting out, the operator may send communications necessary for use of the service, including those relating to contracts, billing, security, failures, and changes to the terms.
Interviews with a child are conditional on the guardian’s individual consent and presence.
23If a Leak or Similar Incident Occurs
If a leak, loss, or damage of personal data or any other incident occurs, or there is a risk of one, the operator confirms the scope of impact, prevents expansion, investigates the cause, prevents recurrence, and takes other necessary action. Where required by law, it reports to the Personal Information Protection Commission and notifies the persons concerned.
24Changes to This Policy
The operator may revise this Policy in response to changes in law, the content of the service, or the handling of information, and announces the content and date of application within the service.
For changes that materially affect the information collected, the purposes of use, provision to third parties, handling outside Japan, children’s information, or the rights of the person, the operator allows a reasonable notice period and gives notice, including by sending it to the registered email address.
The operator does not implement changes requiring individual consent under law merely by posting this Policy or on the basis of blanket consent.
The Japanese version of this Policy is the authoritative text. Where a translation is provided, the operator endeavours to keep the content consistent, but to the extent permitted by law the Japanese version prevails in the event of any discrepancy.
Related Legal Pages

Contact
For questions about the handling of personal information, requests such as disclosure, or account deletion, please use the following desk.
- Operator
- Kentaro Ishida (石田憲太朗)
- Address
- 〒530-0001 大阪府大阪市北区梅田1丁目2番2号 大阪駅前第2ビル12-12
- Legal contact email
- support@sumlia.com