Privacy Policy

Last updated: 2026-08-09

This Privacy Policy explains how information is handled in TOKIMEKI Diary (the "Service").

Information we collect

The Service stores your AT Protocol / Bluesky account's DID, handle, and profile information (display name and avatar); records from your AT Protocol / Bluesky repository (posts, likes, reposts, etc.); copies of your cloud bookmarks stored in the operator's TOKIMEKI service (references to bookmarked posts and folder names); display caches of third-party public posts you have liked, reposted, or bookmarked; in-app settings; authentication session information; and billing information provided by Stripe for payment processing (plan, subscription status, etc.). Credit card numbers are never stored on the operator's servers and are managed by Stripe.

How we use it

Collected information is used only to provide the Service: displaying and searching your archive, syncing, authentication, billing, and maintaining and improving the Service. Only you, while signed in, can view your synced content; the operator never makes it public to third parties.

Third-party services

The Service uses Vercel (hosting and Vercel AI Gateway), Supabase (database), Railway (sync infrastructure), Stripe (payments), the AT Protocol / Bluesky network (data retrieval from PDS, relays, etc.), and the AI model delivery routes listed in the AI Usage Policy. Information is sent to these services only as necessary to provide the Service. Data is sent to AI models only when a user who has explicitly accepted the separate AI Usage Policy uses an AI feature. Beyond these cases and cases required by law, personal information is never provided to third parties.

Cookies

The Service uses cookies to maintain your sign-in session and to store preferences such as language. No cookies or analytics tools are used for advertising or behavioral tracking.

Retention and deletion

Synced data is retained while your account is active to provide the Service. Posts deleted on AT Protocol / Bluesky are handled under your configured deletion policy. In Settings, you can delete only synced repository data while keeping your account, or delete your TOKIMEKI Diary account and user-owned data. Neither operation deletes your Bluesky / AT Protocol account, PDS repository, or posts. Shared caches collected to display public posts and engagement counts can remain because they are not dedicated to one user. Original data in an external bookmark source is not deleted. On withdrawal, we request deletion of the Stripe Customer, but Stripe can retain invoices, transaction records, and related data for legal, payment-processing, fraud-prevention, or other legitimate purposes.

Contact

For questions about this policy or the handling of personal information, please use the contact listed in the Legal Notice (Act on Specified Commercial Transactions).