Last updated: September 7, 2026
1. Introduction
This Privacy Policy describes how Dobizi (Rikuta Ishigaki) ("we," "us," or "our") handles the personal information of users ("you") in connection with the data cleansing tool "ZeroTrace" (the "Service").
The Service is designed to process the content of uploaded data solely within volatile memory (RAM) and does not store it in persistent storage. This Privacy Policy does not concern the content of the data you upload; it concerns the personal information we collect to the extent necessary to manage your account and operate the Service. For the handling of uploaded data, please refer to Section 10 (In-Memory Processing) of our Terms of Service.
2. Personal Information We Collect
In providing the Service, we collect the following personal information.
(1) Account Information. Collected when you register or log in via a single sign-on (SSO) authentication provider (Apple, Google, Microsoft):
- Your verified email address
- The type of SSO provider used for authentication, and the user identifier assigned by the authentication infrastructure
- Usage information, such as your plan, number of sessions used, registration date, and last login date
We do not collect your name or other profile information during SSO authentication.
(2) Consent Logs and Security Logs. To record the fact of your consent, the following information is collected at the point at which single sign-on (SSO) authentication is completed and your verified email address is established:
- The verified email address established through SSO authentication, used to associate the consent with the consenting account
- A transient session token
- The type of action consented to, and the version of the policy to which consent was given
- The system timestamp of the action
We do not record the originating IP address in our consent logs. The verified email address recorded here is the same identifier already collected under Section 2-(1), and is not used to collect any additional category of personal information beyond what is disclosed in this Policy.
(3) Operational Logs and Diagnostic Information. For the purposes of service delivery, error diagnosis, abuse prevention, and infrastructure protection, limited information — such as file names, file formats, metadata regarding data structure, and technical error information — may be recorded in transient operational logs or diagnostic records. This information does not constitute the content of the uploaded data itself. You are responsible for ensuring that file names and similar fields do not contain confidential information.
3. Purposes of Use
We use the personal information we collect for the following purposes:
- To authenticate you and enforce access control
- To manage plans, subscriptions, licenses, billing, and session usage
- To prevent abuse and maintain platform security
- To record the fact and content of your consent
- To operate, maintain, improve, and troubleshoot the Service
- To respond to your inquiries
The term "session" has the meaning given in Section 11A (Plans, Sessions, and Usage Allowances) of our Terms of Service. Information such as session counts is used for the billing and usage-management purposes described above.
4. Use of Cookies and Similar Technologies
The Service uses cookies and other session-management technologies to the extent necessary to provide the Service, in order to maintain your authentication state and ensure security. These are necessary for the Service to function properly.
5. Third-Party Disclosure and Use of External Services
We use the following external services to provide the Service. Accordingly, personal information may be handled by these providers to the extent necessary.
- SSO authentication: Apple, Google, Microsoft (for login authentication)
- Payment processing: Stripe (for processing subscription and license payments; payments are processed through Stripe, and we do not retain payment information such as credit card numbers)
- Cloud infrastructure: Amazon Web Services (AWS) (for the operating platform of the Service and data storage)
These providers handle personal information in accordance with their respective privacy policies. We do not provide personal information to third parties without your consent, except as required by law.
6. Data Storage Location and Cross-Border Transfer
The account information and consent logs we collect are stored in the AWS Tokyo Region (within Japan, ap-northeast-1).
However, the SSO authentication providers (Apple, Google, Microsoft) and the payment provider (Stripe) are entities with operations outside Japan, and in the course of using these services, personal information may be handled by providers located outside Japan. By using the Service, you are deemed to have consented to the handling of personal information associated with the use of these external services.
7. Data Retention Period
We retain account information for the period during which your account is active. If you close your account, we will, in principle, delete the personal information associated with that account within ninety (90) days after closure. However, where retention is required by law, or is necessary for the investigation of abuse, the resolution of disputes, or similar purposes, we may retain such information beyond that period to the extent necessary.
Consent logs and security logs are retained for a reasonable period for the purposes of abuse prevention and compliance recordkeeping.
8. Security of Personal Information
We implement reasonable security measures to prevent the leakage, loss, or damage of the personal information we collect. We use standard TLS encryption for network transmission, and we handle administrative information and logs strictly separated from user-uploaded data payloads.
However, we cannot guarantee the absolute security of personal information in circumstances beyond our reasonable control (such as hardware failure, cyberattacks, or cloud-provider failures).
9. Your Rights (Requests for Disclosure, Correction, Deletion, etc.)
Under applicable law, you may request the disclosure, correction, addition, deletion, or suspension of use of your personal information that we hold. To make such a request, please contact us via the contact channel described in Section 11. We will respond within a reasonable period in accordance with applicable law, after verifying your identity.
Users in the EU/EEA, the United Kingdom, or other regions where the GDPR or similar laws apply may have rights under applicable law, including the right to access, correct, or delete data, to restrict processing, to data portability, and to object to processing.
10. Changes to This Privacy Policy
We may revise this Privacy Policy from time to time in response to changes in law or changes to the Service. Where we make a change that has a material effect on you, we will provide notice on our website (https://www.dobizi.tech). Other changes become effective when posted on our website.
11. Contact
For inquiries regarding this Privacy Policy or the handling of personal information, and for requests for disclosure, correction, or deletion, please contact us via the contact form on our website (https://www.dobizi.tech).
12. Language
This Privacy Policy may be provided in Japanese and English. In the event of any discrepancy or inconsistency between the Japanese and English versions, the Japanese version shall prevail.
---
ZeroTrace — Privacy Policy — All rights reserved.