Privacy Policy
This document is a draft before publication and may change.
This Privacy Policy explains how IMAFUL LAB ("we" or "us") handles information about users of IMAFUL (the "Service").
1. Who we are and how to contact us
Operator: IMAFUL LAB
Privacy inquiries: support@imaful.com
2. Information we collect
- Account information: your email address and login information (passwords are not stored in readable form)
- Date of birth: used to check that you are old enough to use the Service. It is not shown to other users
- Consent records: when you agreed to the Terms of Service and Privacy Policy and which versions, and when you confirmed parental or guardian consent if you are under 18
- Profile: name, @ID, icon, header image and bio
- Posts: photos, captions, tags of friends who were with you, and reactions
- Friend connections: friends, friend requests, blocks, and nicknames that only you can see
- Messages: the content and time of one-to-one messages with friends, and how far you have read (not shown to the other person)
- Reports: what was reported, the reason and any details. For a reported message, a copy of the message as it was when reported
- Notifications: in-app notifications (type, the other user and read status) and your notification settings
- Inquiries: the content of your inquiry and the email address we reply to
- Connection logs: the systems of the providers we use may record the time of access, IP address and similar information to keep the Service secure
We use the camera to take photos for posts and profile images. We use your photo library only when you choose a profile icon or header image, and when you save a QR code.
3. Information we do not collect
We do not collect your phone number, gender, address, location or contacts (address book). We remove location data (such as EXIF) from post photos before saving them.
We do not track you for advertising, and we do not use third-party analytics or advertising tools.
4. How we use information
- To provide the Service (login, showing and delivering profiles, posts, messages and notifications, and friend features)
- To confirm your identity and that you are old enough to use the Service
- To handle reports, prevent violations of our Terms and abuse, and keep the Service safe
- To respond to inquiries and to investigate and fix problems
- To send important notices about the Service
- To comply with the law
5. What other users can see
- Your name, @ID, icon and bio are shown to your friends and in @ID search. Your header image and posts are shown to your friends.
- Your date of birth, email address and login method are never shown to other users.
- Messages can generally be seen only by the sender and the recipient. However, as explained in section 6, we may review them when handling reports.
- People are not told who reacted to their posts, who reported them or who blocked them.
6. Review by us
To keep the Service safe, we review reported posts, profiles, messages and similar content to the extent needed to handle reports.
- For a reported message, we keep a copy of the message as it was when reported. The copy remains even if the sender later unsends the message.
- We do not read conversations unrelated to a report, and we do not routinely read messages.
- Only authorized staff protected by two-factor authentication and similar measures can review this content.
- Where required by law, we may review and provide information to the extent necessary.
7. Sharing with third parties
We do not provide your personal information to third parties without your consent, except where required by law. We never sell your information.
8. Service providers and processing outside Japan
We use the following providers to store and process information. Some of them are based outside Japan, and your information may be processed on servers outside Japan. We review each provider’s terms and agreements so that they protect information to a standard equivalent to this Policy, and we let them handle only the information they need.
- Supabase: login, database and server processing
- Cloudflare: image storage (R2, a private store; time-limited URLs are issued only for display) and delivery of our public pages (terms, policies, support and similar pages)
- Resend: sending authentication emails (email verification, password reset and email address changes)
9. Retention and account deletion
You can request account deletion in the app under Settings > Delete account, or from our account deletion web page.
- Once you request deletion, your profile and posts are immediately hidden from other users.
- For 30 days after your request, you can cancel the deletion and restore your account by logging in to the same account.
- After 30 days, we permanently delete your account (login information and email address), profile (name, @ID, icon, header image and bio), date of birth and consent records, posts and photos (including the stored image files), tags, reactions, friends, friend requests, blocks and nicknames, messages, and notifications and notification settings. Once permanently deleted, they cannot be restored.
- Messages are deleted as whole conversations that the deleted account took part in. The other person will no longer be able to see them either.
We keep the following records even after an account or the original post or message is deleted, for safety, abuse prevention, handling reports, keeping a record of our moderation actions, and handling disputes and legal requirements. When you delete your account, your ID in these records is replaced with a reference that is not linked to you, and your @ID is no longer shown. Your profile, icon and similar information are not kept.
- Report records (what was reported, the reason, details, status and dates): in principle, up to 3 years after the report is resolved
- Copies of reported messages as they were when reported: in principle, up to 1 year after the report is resolved
- Records of actions taken by us: in principle, up to 3 years after they are recorded
- Where needed to deal with legal requirements, disputes or safety issues, we may keep records longer, only for as long as necessary.
- If you made a report, your information is separated from the report record when you delete your account.
When you delete a post, it is no longer shown to other users. Photo files of deleted posts and earlier profile images are removed from storage when your account is permanently deleted. It may take some time for deleted information to be removed from our providers’ backups.
10. Security
We take security measures to prevent unauthorized access, leaks and tampering, including access restrictions, encrypted connections, private image storage and two-factor authentication for staff.
11. Age
The Service is for people aged 15 and over. People under 15 cannot register. If we learn that we have collected information from someone under 15, we will take appropriate action. If you are under 18, you must have permission from a parent or legal guardian to use the Service.
12. Your requests
You can ask us to disclose, correct, stop using or delete your personal information. Contact us at support@imaful.com. We will respond after confirming your identity. You can also edit your profile in the app, and request account deletion in the app or from our account deletion web page.
14. Changes to this Policy
We may change this Policy as needed. We will announce important changes in the app or by other means.