How Kotoba Labs Inc handles personal information for kotobase.net.
Last updated: 2026-08-30
Applicable privacy law depends on the user, processing activity, and operating location.
This Privacy Policy explains how Kotoba Labs Inc (the "Operator", "we") handles personal information in connection with the kotobase.net Service (the "Service"). Sales contact: Ryo Awai.
Our primary framework is the Japanese Act on the Protection of Personal Information (APPI, 個人情報保護法). Where applicable we also address the EU/EEA General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
For much of the Customer Data you ingest, you act as the controller/business and we act as your processor/service provider; in that case your own privacy notice governs your end users, and we handle that data under our agreement with you.
https://auth.kotobase.net — the identifiers associated with your bearer token. Email address is collected when you sign in with email OTP (and would be collected from an identity provider if Google/GitHub OAuth were enabled; both are disabled in production). A display name is not required by the apex Worker. Accounts may also be keyed by a hash of email in the same-origin session path (kotobase_session).pin_id, name, cid, target, status, timestamps, size, content type, archived object keys, error strings), and optional archive payloads (IPLD CARs or raw bytes) that you ingest or pin. This content may contain personal data that you choose to include; you are responsible for its lawful provision.x-kotobase-request-id), Cloudflare cf-ray, edge/version identifiers, storage-mode signals, sanitized error summaries, and smoke/health output.We do not intentionally collect special-category / sensitive data, and you must not submit secrets or sensitive personal data into fields, logs, or public metadata contrary to docs/DATA-HANDLING.md.
We process personal information to:
APPI: we identify and use personal information within the scope of the utilization purposes above (APPI Arts. 17–18) and do not use it beyond them without consent, except as permitted by law.
GDPR legal bases (for EU/EEA users, where applicable): performance of a contract (Art. 6(1)(b)); legitimate interests in operating and securing the Service (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)); and consent (Art. 6(1)(a)) where relied upon (e.g. certain cookies).
CCPA/CPRA: we process personal information for the business purposes above. The kotobase.net marketing and API surfaces do not load advertising pixels or cross-context behavioural advertising scripts. Unauthenticated GET / and GET /signup set no cookies. We do not disclose personal information for monetary consideration.
We share personal information only with service providers ("subprocessors") that process it on our behalf to deliver the Service, and as required by law. Current subprocessors:
| Subprocessor | Function | Data involved |
|---|---|---|
| Cloudflare, Inc. | Edge/Worker control plane, Durable Objects (tenant locks), TLS, DNS | Request metadata, tenant identifiers, edge diagnostics |
| Backblaze, Inc. (B2) | Object storage for pin metadata, replay markers, and optional CAR/raw archives | Pin metadata, archive payloads |
| Stripe, Inc. | Payment processing and subscription billing | Payment/billing data, tenant DID reference |
| Plus Five Five, Inc. (Resend) | Transactional email delivery when mail is sent | Email address, headers, message content and delivery events |
| auth.kotobase.net | Session verification and tenant identity controls | Account identity, session data, tenant metadata |
A public machine-readable subprocessor register is not published. The table above is the current public list.
Content stored as CIDs may also be retrievable by third parties through the public IPFS network, gateways, and caches; this is inherent to content addressing and is not limited to our subprocessors.
The Operator is organized in Delaware, United States, and uses subprocessors that may process data outside your country, including the United States. Cloudflare may process data in a distributed network including the United States; Stripe may process internationally including the United States; Resend processes in the United States. Backblaze processing region is the region configured on the operator account and is not published as a fixed public region.
AUDIT_RETENTION_DAYS; the deployed default is 365 days. Existing records keep the TTL assigned when written, so changing the setting is not legal hold.DELETE /pins/:id is marked as deleted; this does not guarantee cryptographic erasure of previously archived content-addressed bytes.legal/retention-schedule.json. Customer-specific pin/archive periods and the effective account, billing, transactional-email, diagnostics and tombstone periods remain unqualified until the applicable contract, provider settings and counsel-approved schedule record them.nosniff and frame denial./_app/meta), logs, and error responses by design.Subject to applicable law and to verification of your identity, you may request:
To exercise rights, contact us at support@kotobase.net. Because deletion of content-addressed data cannot be fully guaranteed, we will explain the limits of any erasure request.
Unauthenticated GET https://kotobase.net/ and GET /signup set no cookies (measured 2026-08-14). After sign-in, session cookies may be set:
gftd_session — issued by auth.kotobase.net, used to authenticate browser navigations to kotobase.net (HttpOnly / Secure / SameSite as configured by the authentication service);kotobase_session — same-origin Worker session (HttpOnly; Secure; SameSite=Lax; Max-Age=2592000).Both are strictly necessary for an authenticated session. The marketing pages do not load analytics or advertising scripts. Visit telemetry (kaiyu) is recorded server-side from the request Referer and does not set a cookie. The API surface is token/CACAO-authenticated and does not rely on cookies.
The Service is not directed to children. You must be at least 18 years of age and capable of forming a binding contract. If we learn we have collected account records of a person under 16, we will delete the identity/control-plane records we control, stop processing those records except where retention is required by law, and provide notice of any content-addressed Customer Data that cannot be guaranteed erased.
We may update this Policy; material changes are indicated by updating the "Last updated" date and, where appropriate, by additional notice.
Email: support@kotobase.net. Sales contact: Ryo Awai. Operator: Kotoba Labs Inc. No DPO or EU-UK GDPR Art. 27 representative is designated at this time.