haane logo haane
JA EN ES
Home

haane Privacy Policy

Version: 1.0
Effective Date: February 18, 2026


1. Introduction

Tokyo IT Co., Ltd. (hereinafter referred to as "the Company") places great importance on protecting the personal information of customers using the haane service (hereinafter referred to as "the Service"), and complies with the Act on the Protection of Personal Information and related laws and regulations to handle it appropriately.

2. Use of Cookies

2.1 Types of Cookies Used

This Service uses only essential cookies necessary for providing the service. We do not use any cookies for tracking, advertising, or analytics purposes.

2.2 Purpose of Essential Cookies

Essential cookies used in this service are used only for the following purposes:

  • Session Management: Maintaining login status and session management
  • Security: Protection against CSRF (Cross-Site Request Forgery) attacks
  • Functionality: Storing information necessary for providing basic service features

2.3 Details of Cookies Used

Cookie Name Purpose Expiration
app_session Session management, maintaining login status 2 hours (browser session)
XSRF-TOKEN Protection against CSRF attacks 2 hours (browser session)
haane_trusted_device For the "Trust this device" feature in two-factor authentication (2FA) 30 days

2.4 Cookie Management

You can disable cookies through your browser settings, but please note that some features of this service may not function properly if you do so.

3. Information We Collect and Its Content

This service collects the following information for the purpose of providing and improving the service.

(1) Information about Counselors (Personal Information)

  • Name, nickname
  • Email address

(2) Information about Clients

  • Nickname, pseudonym
  • Chief complaints, background information, and other related information

(3) Information Related to Service Usage

  • Consultation history and session records between counselors and clients
  • Other information generated in connection with AI analysis and service provision

(4) Access Log Information

When accessing the landing page of this service, the following information is automatically recorded:

  • IP Address: The IP address of the access source
  • Access Date and Time: The date and time of site access
  • User Agent: Information about the browser or device being used

Purpose of Collection: This information is collected to prevent unauthorized access, ensure security, and properly operate the service.

Retention Period: Access logs are stored for 6 months from the date of recording and are automatically deleted thereafter.

Third-Party Provision: Access log information will not be provided to third parties except when required by law.

4. Purpose of Using Personal Information

Collected personal information will be used for the following purposes:

  • Providing, operating, and maintaining this service
  • Identity verification during login
  • Responding to customer inquiries
  • Improving the service and developing new features
  • Addressing violations of terms of service
  • Notifying important announcements regarding this service (maintenance, terms changes, service disruptions, etc.)
  • Detecting and preventing unauthorized access
  • Investigating and responding to security incidents
  • Access control and proper service operation

5. Use of Third-Party Services

The Company uses the following external services for the provision and operation of this service. The Company entrusts the handling of information specified in Section 3 after entering into appropriate contracts with these contractors or confirming that the contractors comply with appropriate security standards.

5.1 AI Analysis Service (Google Gemini API)

This service uses the Gemini API (paid version) that complies with Google Cloud Platform's enterprise standards. For detailed data protection policies, please refer to Google Cloud's Privacy Policy. This ensures that transmitted data is not used for AI training.

5.2 Outsourcing to External Service Providers

In accordance with the Act on the Protection of Personal Information, when we provide personal data to contractors outside Japan, we do so on the basis of either obtaining the data subject's consent, providing to a country recognized as having an adequate level of protection, or having contractual measures in place with the contractor that ensure equivalent protection.

The Company uses the following external services for the provision and operation of this service. In connection with this, some of the user's personal data (name, email address, access logs, consultation content, etc.) may be provided to or entrusted to the servers of each service provider (in Japan, the United States, etc.).

【Overseas (Outside Japan) Contractors】

  • AI Advisory Function: Google LLC (United States)
  • Email Delivery: Mailgun Technologies, Inc. (United States)
  • Security & Content Delivery: Cloudflare, Inc. (United States)

【Domestic Contractors】

  • Server Infrastructure: SAKURA internet Inc. (Japan)
  • Server Infrastructure: KAGOYA JAPAN Inc. (Japan)

The Company provides data to the minimum extent necessary after entering into appropriate contracts with these contractors or confirming that the contractors comply with appropriate security standards.

6. Provision of Personal Information to Third Parties

The Company will not provide personal information to third parties without customer consent, except as required by law. However, provision to contractors specified in Section 5 does not constitute third-party provision under this section.

7. Security Management of Personal Information

The Company implements the following security measures to prevent leakage, loss, or damage of personal information.

(1) Technical Security Measures

  • Encryption of sensitive information (consultation records, chief complaints, etc.) stored in the database
  • Encryption of communication channels (SSL/TLS)
  • Access control and log management

8. Disclosure, Correction, Suspension of Use, and Deletion of Personal Information

  1. When requested by an individual to disclose, correct, add to, or delete their personal information, the Company shall promptly disclose, correct, or delete such information to the individual.

  2. Users may request the Company to suspend the use of or delete their personal information. If the Company determines that such request meets the requirements under applicable laws of each country, the Company shall delete such personal information within a reasonable scope and appropriate period in accordance with the law.

  3. Notwithstanding the preceding paragraph, if the information is subject to retention obligations under laws and regulations, or is essential for providing services or preventing unauthorized use, the Company may not be able to comply with deletion requests. In such cases, the Company shall endeavor to protect users' rights by implementing alternative measures such as suspension of use.

  4. Specific procedures (contact information, etc.) for exercising the rights stipulated in this article shall be accepted through the inquiry contact specified in this Policy.

【Handling of Client (Counselee) Information】

Contact Point for Requests: If clients wish to disclose, correct, or delete their information, please contact the Contractor (counselor or counseling office) who acquired and holds the information directly. In this service, client information (nicknames, age groups, gender, counseling records, etc.) entered and registered by Contractors is acquired and managed primarily by the Contractors.

Limitation on Identity Verification: The Company is entrusted with storing this information by Contractors and does not possess any information that directly identifies individuals, such as real names, addresses, or phone numbers of clients. Therefore, if clients contact the Company directly, we cannot verify their identity and cannot respond to such requests.

9. Changes to Privacy Policy

The Company may change this privacy policy in accordance with changes in laws or business operations. The revised privacy policy will take effect when posted on this page.

10. Language

This Privacy Policy is originally written in Japanese. In the event of any discrepancy in interpretation between the translated version and the Japanese version of this Privacy Policy, the Japanese version shall always prevail.

11. Relationship with Terms of Service

Matters not specified in this Policy shall be governed by the provisions of the Terms of Service.

12. Contact Information

Seller Name: Tokyo IT Co., Ltd.
Personal Information Protection Officer: Masato Oya
Address: 〒140-0014 3F Agora Oimachi, 1-6-3 Oi, Shinagawa-ku, Tokyo, Japan
Email: [email protected]
Phone: 050-1740-3731
Contact Form: https://haane-ai.net/contact


Effective Date: February 18, 2026

Back to TOP
Privacy Policy | Terms of Service | Specified Commercial Transaction Act | Contact

Operated by: Tokyo IT Co., Ltd.

© 2026 haane. All rights reserved.