Privacy Policy
Last updated: 2026/5/31
1. Operator
This service, "birthplot" (the "Service"), is operated by Yu Nakamura (the "Operator").
Contact: [email protected]
2. Information we collect
Guest use: your date of birth, time of birth, place of birth, family information (sibling structure, family age band), upbringing (number of moves, childhood pet, etc.), and other profile information you enter are stored only in your browser (localStorage) and are not sent to or stored on the Operator’s servers.
Account use (optional): if you register an account, your email address and any profile information you choose to save are stored on our authentication and database platform (Supabase).
Location: only if you allow current location for the "Today’s weather" feature, your latitude/longitude is sent to a weather service (Open-Meteo). Otherwise a representative coordinate of your birthplace (city level) is used.
Cookies and browsing data: the Service may collect cookies and other device and browsing information for ad serving, analytics, and service improvement.
Analytics: the Service may use Google Analytics (provided by Google LLC) to collect access information such as visit time, viewed pages, referrer, device/browser information, approximate region, anonymized IP address, and user identifier (via cookies).
Although your date/time/place of birth do not constitute "special-care personal information" under Japanese APPI, we treat them as highly personal data and handle them with care equivalent to sensitive data.
3. Purposes of use
We use the information collected for the following purposes:
(1) Providing the Service and generating results, including 12-axis computation, interpretation text generation, compatibility, daily insights, friend features, and share images
(2) Collecting usage statistics and improving service quality (using Google Analytics and similar tools)
(3) Serving advertisements (using Google AdSense and similar tools)
(4) Preventing unauthorized access and spam
(5) Responding to inquiries and rights requests
(6) Future notifications to authenticated users (Phase 2 and beyond)
4. Use of AI services
Currently the Service does not use external generative AI services (LLMs) for generating results or interpretation text. All results are generated deterministically from pre-authored interpretation templates.
If we use external AI services in the future, we will amend this policy and announce it on the Service in advance.
5. Cookies, advertising and analytics
The Service may display advertisements from third-party vendors including Google (e.g., Google AdSense).
These vendors may use cookies to serve ads based on your prior visits to this and other sites.
You can opt out of Google’s use of advertising cookies via Google Ads Settings (adsettings.google.com). You can opt out of other third-party vendors’ cookies at www.aboutads.info.
For analytics, the Service may use Google Analytics (provided by Google LLC). Google Analytics uses cookies to collect access information. We use it in accordance with Google Analytics settings, including IP anonymization.
To opt out of Google Analytics, please install the official Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout).
For Google Analytics’ terms and privacy policy, please see Google’s pages (https://marketingplatform.google.com/about/analytics/terms/ and https://policies.google.com/privacy).
You can accept or reject cookies via the cookie banner on this site. If you reject, personalized ads and Google Analytics tracking cookies will not be loaded, but some features may not work properly.
You can change your cookie preferences at any time via the "Cookie settings" link displayed at the bottom of every page. Changes take effect on the next page load.
6. Third-party disclosure and entrusted processing
Except as required by law, we do not sell or provide your personal information to third parties.
The Service entrusts parts of its operation to the following providers; this constitutes "entrusted processing" of personal information. We require these providers to safeguard personal information by contract.
・Supabase Inc. (US): authentication, database, server functions
・Cloudflare Inc. (US): hosting, CDN, security
・Google LLC (US): Google Analytics (web analytics), Google AdSense (advertising)
・Open-Meteo (Austria, EU): weather information (optional feature)
7. International data transfers
Because some of the providers above are based outside Japan, certain personal data is processed outside Japan.
Location, data, and legal basis for the main providers:
・Supabase Inc.: US (region: Tokyo) / authentication and profile data / SCCs, user consent
・Cloudflare Inc.: US (global CDN) / access logs and delivery traffic / EU-US Data Privacy Framework, SCCs
・Google LLC: US / cookies, access information, advertising identifiers / EU-US Data Privacy Framework, user consent
・Open-Meteo: Austria (within EU) / latitude/longitude (only when the optional feature is used) / EU adequacy decision
For information on each country’s privacy regime, please see the overview published by the Personal Information Protection Commission of Japan (https://www.ppc.go.jp/).
8. Storage period and deletion
We retain the data we collect for the following periods:
・Guest data in localStorage: retained until you delete it via your browser settings or the deletion features in the Service
・Account / profile data: retained while the account is active; deleted (including backups) within 90 days after account closure
・Google Analytics data: 26 months (GA4 default)
・Server access logs: 90 days
・Records of inquiries and rights requests: 1 year after the matter is resolved
To request deletion of your account information, please contact [email protected]. After identity verification, we will complete deletion within the period above.
9. Your rights (access, rectification, erasure, etc.)
You may exercise the following rights regarding your personal data:
(1) Right of access — to confirm what data we hold
(2) Right to rectification, completion, or erasure
(3) Right to restrict or object to processing and third-party disclosure
(4) Right to disclosure of third-party disclosure records (Japanese APPI Art. 33)
(5) Right to data portability (GDPR-subject users only) — you can export your data in JSON format from your account page
(6) Right to withdraw consent at any time for processing based on consent
(7) Right to object to automated decision-making and profiling (GDPR Art. 22)
How to exercise: email [email protected] with the subject "Rights request" and include your name, registered email, the right(s) you wish to exercise, and identity verification (send from the registered email or by other agreed means).
We will respond within 30 days of identity verification. No fee will be charged.
10. When entering information about a third party
When you enter a third party’s date of birth or birth information for the compatibility or friends features, you are responsible for obtaining their prior explicit consent.
If we receive an access or deletion request from the third party, we will respond within a reasonable scope with your cooperation.
The Operator is not responsible for disputes arising from information entered without consent.
11. Legal basis and rights for EEA / UK / Switzerland / California and other residents
For users subject to the EU GDPR, UK GDPR, or Swiss FADP, we process personal data on the following legal bases:
・Service provision (axis computation, results, account management): performance of a contract (GDPR Art. 6(1)(b))
・Analytics and service improvement: legitimate interests (Art. 6(1)(f))
・Personalized advertising and Google Analytics: consent (Art. 6(1)(a))
・Legal compliance: legal obligation (Art. 6(1)(c))
You may withdraw consent for consent-based processing at any time via the cookie banner.
If you reside in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your national data protection supervisory authority — for example, the Irish Data Protection Commission (https://www.dataprotection.ie/), the French CNIL (https://www.cnil.fr/), the UK ICO (https://ico.org.uk/), or the Swiss FDPIC (https://www.edoeb.admin.ch/).
If you reside in California (USA), you may exercise the rights provided under the CCPA / CPRA, including the right to opt out of the sale or sharing of personal information, the right to deletion, the right to know, and the right not to be discriminated against for exercising your rights. The Service does not currently sell personal information.
If you reside in mainland China, you may exercise the rights provided under the Personal Information Protection Law (PIPL), including the right to be informed, the right to decide, the right to access and copy, the right to data portability, the right to correct and supplement, the right to deletion, the right to withdraw consent, the right to request explanation, and other statutory rights.
Residents of other jurisdictions, including South Korea (PIPA) and Brazil (LGPD), may also exercise rights under their respective national laws. Please contact us for details.
12. Complaint contact
For complaints or inquiries regarding the handling of personal information, please contact us at:
・Contact: [email protected]
・Responsible person: Yu Nakamura (Operator of the Service)
・Reception: by email at any time; initial response within 14 days as a rule
If your concern cannot be resolved through the above contact, you may file a complaint with the Personal Information Protection Commission of Japan (https://www.ppc.go.jp/).
The Service is not currently a member of any accredited personal information protection organization.
13. Data breach response
If the Operator detects a personal data breach (including leakage, loss, destruction or other security incident), we will promptly investigate the facts and the cause.
Where the breach is likely to result in a high risk to the rights and freedoms of affected users, we will notify those users by email or through an announcement on the Service, as a rule within 72 hours of detection (in line with GDPR Art. 33).
Where reporting to the Personal Information Protection Commission of Japan or another supervisory authority is required, we will report in accordance with applicable law.
14. Revisions
The Operator may revise this policy as needed.
The revised policy takes effect when posted on the Service. Material changes will be announced in advance on the Service.
15. Contact
For questions about this policy, please contact [email protected].