app-aozora — Privacy Policy
DRAFT — not legal advice; counsel review required.
Governing law: Japan
- Effective date: 2026-07-02
- Last updated: 2026-07-28
- Data controller / operator (APPI "business handling personal information"): AWAI Network, L.L.C., a Delaware limited liability company (Delaware file number 10704996). Gftd Japan 株式会社 is an infrastructure and software supplier, not the controller. Full operator record:
legal/company.md. - Service: app-aozora (
aozora.app)
This policy explains how we handle personal information. Our primary regime is Japan's Act on the Protection of Personal Information (APPI). Where they apply, the EU/UK GDPR and California CCPA/CPRA also apply.
1. Information we collect
- Account & identity data: decentralized identifier (DID), handle, and authentication data: primarily CACAO self-sovereign DID/key-proof sign-in, plus an optional WebAuthn/passkey credential you can add to bind a device to that identity. A password-based sign-in exists only in a developer/testing mode explicitly for external-PDS testing, not offered to end users in production. We do not use third-party social login (e.g. Google) and do not use third-party passwords for account access.
- Profile data: display name, description, avatar/banner images, and other profile fields you provide.
- Posts and records: posts, replies, likes, follows, and other atproto records you create. These are public by design when published.
- Blobs (media): images and video you upload, stored content-addressed (by CID) in a Cloudflare R2 bucket (
aozora-pds-blobs), served R2-first with an IPFS-gateway fallback for reads. - Usage & device data: log data, IP address, approximate location, device/ browser information, and interaction events (for abuse prevention).
[DECISION NEEDED: no third-party analytics SDK is integrated today; there is an in-house, read-only telemetry module that computes an aggregate "organism vs. human" engagement ratio purely from already-public post/like/ repost/follow records, with no session or per-user activity log. Confirm whether this in-house telemetry should be disclosed here as-is, and confirm a retention period for raw log/IP data, which is not yet defined.] - Advertising data:
[DECISION NEEDED: ad-tech (Google AdSense, ExoClick, Media.net) has been REMOVED from the live app-aozora UI — the ad-rendering component is currently a no-op per an internal policy decision ("removed: ad-tech (adsense, exoclick, medianet)"). This bullet, the "Advertising" section below, and the "Cookies and advertising" section (§8) describe an active ad program that does not currently exist in the shipped product. Confirm whether to remove these sections, or keep them as forward-looking language for a not-yet-relaunched ad program — see the flag in §8.] - Browser-inference telemetry (optional feature): performance statistics and GPU/device capabilities, per the separate Browser Inference Terms.
2. How and why we use it, and legal bases
| Purpose | APPI basis (utilization purpose) | GDPR legal basis |
|---|---|---|
| Provide the Service (accounts, posting, feeds, federation) | Service provision | Contract (Art. 6(1)(b)) |
| Security, abuse prevention, moderation | Service provision / legal compliance | Legitimate interests / legal obligation |
| Analytics and product improvement | Service improvement | Legitimate interests / consent |
| Advertising | With consent where required | Consent / legitimate interests |
| Legal compliance and responding to lawful requests | Legal compliance | Legal obligation |
We specify utilization purposes as required by APPI and do not use data beyond them without a new basis.
3. Public and federated nature of the network
app-aozora is built on the AT Protocol. Content and records you publish publicly are broadcast to the atproto network (relays, other AppViews, the firehose) and can be copied and re-served by independent third parties outside our control. Do not post anything you need to keep private as public content.
4. Sharing and subprocessors
We do not sell personal information for money. We share data with:
- Infrastructure / subprocessors:
- Cloudflare — Workers (hosting/SSR), D1 (repository/records), R2 (blobs). Cloudflare operates a global edge network; we do not currently pin processing to a specific region.
[DECISION NEEDED: confirm whether a Cloudflare Data Processing Addendum is in place and cite it here.] - Backblaze B2 is not used as a subprocessor for app-aozora's own blobs (confirmed: R2 + IPFS-gateway only, see §1).
- Upstream atproto data sources: the browser client makes some proxied reads directly against
atproto.etzhayyim.com. Separately, this service's own AppView can ingest from Bluesky's public Jetstream firehose (jetstream2.us-east.bsky.network) as an upstream relay source; that ingest path is currently disabled.[DECISION NEEDED: this is a genuinely transitional/dual architecture — confirm which upstream relationship(s) should be disclosed as currently active.]
- Cloudflare — Workers (hosting/SSR), D1 (repository/records), R2 (blobs). Cloudflare operates a global edge network; we do not currently pin processing to a specific region.
- Advertising networks: none currently active.
[DECISION NEEDED: see the ad-tech-removed flag in §1 — this bullet and the "Cookies and advertising" section (§8) need a decision on whether to delete or keep as forward- looking language.] - The atproto network: public records, as described above.
- Legal / safety: authorities and third parties where required by law or to protect rights and safety.
[DECISION NEEDED: with ad-tech and Backblaze B2 both ruled out, Cloudflare is the sole current infrastructure subprocessor. Confirm DPA status and whether a full formal subprocessor list/registry should be maintained and linked here (a live list is a more common pattern than enumerating them in the policy text).]
5. International transfers
Our infrastructure (Cloudflare, a US-headquartered global CDN/edge platform) processes data outside Japan, including in the United States. For APPI we provide the required information about cross-border transfers; for GDPR we rely on adequacy decisions or Standard Contractual Clauses as applicable. [DECISION NEEDED: the specific legal transfer mechanism (SCCs vs. adequacy) and the APPI-required transfer disclosure are legal determinations, not code-derivable facts — needs counsel input. Ad-partner transfers no longer apply since no ad network is currently integrated, see §1/§4.]
6. Retention
We retain personal information for as long as needed to provide the Service and for legitimate/legal purposes. Public atproto records persist until you delete them (and may persist on independent participants thereafter). Backups persist for a limited period. [DECISION NEEDED: concrete retention periods per data category — a business policy decision, not determinable from the codebase.]
7. Security
We use technical and organizational measures including encryption in transit, access controls, and secret management (signing keys held as Worker secrets with backup in a managed vault). No system is perfectly secure. [DECISION NEEDED: a formal security program description and breach-notification process/SLA are organizational commitments, not code-derivable facts.]
8. Cookies and advertising
[DECISION NEEDED: no ad network is currently integrated (see §1/§4) — the ad-rendering UI component is an explicit no-op today. This section as originally drafted describes an active ad-tech/cookie program that does not currently exist. Options: (a) remove this section and any auth/session-only cookie disclosure elsewhere covers it, (b) keep as forward-looking language for a possible future ad program, (c) something else. Needs your decision before this section is finalized.]
9. Your rights
Depending on where you live:
- APPI (Japan): request disclosure, correction, addition/deletion, cessation of use, and cessation of third-party provision of your retained personal data, and disclosure of third-party provision records.
- GDPR (EU/UK): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent; right to lodge a complaint with a supervisory authority.
- CCPA/CPRA (California): know, access, delete, correct, and opt out of "sale"/"sharing" of personal information and limit use of sensitive personal information; non-discrimination for exercising rights.
To exercise rights, contact us (Section 11). We will verify your identity via your account/DID (verification method confirmed). [DECISION NEEDED: a concrete response-timeline SLA is a business/legal commitment, not code-derivable.]
10. Children
[DECISION NEEDED: minimum age and children's-data handling. Confirmed from the codebase: there is no age gate anywhere in account creation/sign-up — the general account minimum age is genuinely undocumented and unenforced today. The unrelated optional browser-inference feature separately requires 18+ but that has no bearing on general account eligibility. This is a business/legal decision (and, once decided, an engineering follow-up to actually enforce it) — needs COPPA (US) and GDPR Art. 8 age-of-consent handling to be decided.]
11. Contact and representatives
- Controller: AWAI Network, L.L.C., a Delaware limited liability company (Delaware file number 10704996)
- Privacy contact: hello@gftd.co.jp (a temporary operational address; an AWAI-controlled address will replace it)
- Registered agent and registered office: Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States — statutory service-of-process address only, not a principal place of business or customer-support office
- Infrastructure and software supplier (not the controller): Gftd Japan 株式会社, GranTokyo South Tower 11F, 1-9-2 Marunouchi, Chiyoda-ku, Tokyo 100-6611, Japan (Corporate Number 1011101086505)
- APPI applicability: as a foreign business handling the personal information of individuals in Japan in connection with providing this Service to them, the controller is directly bound by APPI under its extraterritorial application (Art. 171).
[CONFIRM: whether the APPI sections of this policy fully cover a foreign-organized controller has not been reviewed by counsel — seelegal/company.md.] - APPI complaints handling / consultation desk:
[DECISION NEEDED: an organizational process/contact, not code-derivable.] - EU/UK GDPR representative (Art. 27): 該当なし (not designated). The controller was outside the EU/UK before and after the 2026-07-28 operator change, so this obligation is unchanged and remains open.
- Data Protection Officer: 該当なし (not designated)
12. Changes
We may update this policy and will post the updated version with a new "last updated" date; material changes will be notified through the Service.