Privacy Policy
Contents
- 1. Business Operator and Contact
- 2. Information We Collect
- 3. Purposes of Use
- 4. Sharing Scope (What Is Shown to Users)
- 5. Retention Periods
- 6. Provision to Third Parties
- 7. Entrusting the Handling of Personal Data and Use of External Services
- 8. Information on Transfers to Third Parties in Foreign Countries (Cross-Border Transfers)
- 9. External Transmissions
- 10. Security Measures
- 11. Requests for Disclosure, Correction, Cessation of Use, Deletion, and the Like
- 12. Age and Information About Minors
- 13. Changes to This Policy
- 14. Contact for Inquiries
- 15. For People in the EEA, the United Kingdom, and Switzerland
- 16. For People in the United States
Destingate LLC (Destingate合同会社, "we", "us" or "our") values the personal information and privacy of users of "Komadori for VRChat" (the "Service"), and handles it as set out below, in compliance with Japan's Act on the Protection of Personal Information (the "APPI") and other applicable laws. The Service is an unofficial service and has no affiliation with VRChat Inc. This English version and the Japanese version of this Privacy Policy have equal weight.
1. Business Operator and Contact
- Operator: Destingate LLC (Destingate合同会社)
- Contact: ing@digital-sorovider.jp (Japanese or English)
- Under the APPI, we will, on request to the contact above, promptly tell you our address and the name of our representative.
2. Information We Collect
The Service collects the following information.
| Category | Content | How it is collected |
|---|---|---|
| Discord account information | Your Discord user ID, display name, and username (through Discord login, within the identify scope only. We do not collect your email address, friend list, server information, and so on. The username is stored so that we can tell whether a resident tool connection is really yours, and is not shown to other users) | Discord login |
| Google account information | Only your Google user ID (the OpenID Connect "sub", an identifier that Google assigns to each user and that does not change), collected when you log in with Google or press "Link Google". The scope is openid only; we do not collect your email address, name, profile picture, contacts, and so on. The display name is a temporary name we assign ("User" followed by 4 characters; it is replaced by your VRChat display name once that is known). You can link Discord and Google either one alone or both | Google login |
| Guest information (users who started without logging in) | For users who pressed a button such as "Start without logging in": an internal ID we issue, a temporary display name ("Guest" followed by 4 characters; it is replaced by your VRChat display name once that is known), the time of creation, the time of last use, the number of trial Posts, and a one-way hash made from the IP address at creation time with a salt (a secret value) added (used only to prevent mass creation of fake accounts; we do not store the IP address itself for this purpose). We do not collect Discord or Google information | Guest creation action, resident tool, web |
| VRChat information | Your VRChat user ID and VRChat display name (your resident tool reads them from VRChat's output log and sends them as a self-declaration. We do not check them by querying VRChat) | Resident tool |
| Language, time zone, and region settings | Your display language; your time zone (a name such as `Asia/Tokyo`, obtained automatically from your browser and changeable on the Account screen); the "NOW!" region derived from it (one of Asia, Europe, or the Americas); and the time offset (difference from Coordinated Universal Time) when a clip was taken. These are used only to adapt notification times and the display language and times to your region. We do not collect location data (such as GPS) | Your actions, web, resident tool |
| Post Content | A 3-second video recording of your VRChat screen (no audio; "NOW!" is the same), a poster image (still image) generated automatically from the video, and, if you have it enabled, a 3-second video (no audio) of the VRChat camera feed (Stream) recorded at the same time, with its poster image (the "selfie"; even if you point the camera at yourself, other users' avatars or names may appear), the time of capture and posting, the world name and ID (can be turned off in the settings), and a caption (the official resident tool and web app currently have no feature to send captions) | Resident tool, web |
| Relationship information | Friend codes; friend requests and friend relationships; friend invite links (the token hash, the random value used to regenerate the link, the last 4 characters of the token, and the expiry. The expiry is 7 days after issue, and expired links are deleted); Group names, invite codes, and members (including the creator of the Group); and a Discord webhook URL that a Group owner has optionally registered (stored as a secret, and displayed partly masked on screen) | Your actions |
| Settings for what invite pages show | The Group owner's choice "Show yesterday's log on the invite page" (default: on); your choices "Do not show my clips on invite pages" (default: off) and "Show my clips on friend invite links" (default: on); the time we showed you notices about these; and whether the guidance shown right after creating a Group has been displayed | Your actions, our processing |
| Information from using the Service | Votes in Groups (such as "Pick of the day"), the day's title, and the Post information used to calculate badges (badges are not stored; they are calculated on the spot) | Your actions, our processing |
| Notification (Web Push) subscription information | Only if you turn notifications on: the subscription information issued by your browser (the URL of the Push service run by your browser's vendor (the endpoint), a public key for encrypting the notification body, and an authentication value); the date and time of subscription and of the last delivery; the number of consecutive failures; on/off settings for each type of notification; and a record of notifications sent (type, date and time, and an identifier to prevent duplicate sending; used only to manage the daily cap and prevent duplicates) | Your actions (permission in your browser's permission prompt, and "Turn on notifications" on the Account screen or elsewhere) |
| Information about reports and blocks | Reports you make (the Post concerned, the reason, and any added description), the users you block, and the operation record of actions we take (such as deleting a Post or suspending a user) | Your actions, our processing |
| Authentication information | Sessions for login and for device connection (tokens are stored hashed and have an expiry: 30 days for the web, 365 days for the resident tool); the time a device session was last used; the resident tool's connection code, the device-side secret code, and the code for handing a login over from the resident tool to the web (stored hashed, and expire quickly); and the short confirmation code shown on screen for device approval (stored as is until it expires after 10 minutes) | Login, device connection |
| Communication and access records | IP address, type of browser and device (User-Agent), request date, time and content, error information, and other records generated in operating the web server. In addition, to prevent abuse (rate limiting), we store in the database for a short time only a one-way hash, made from the IP address (rounded to the first 64 bits for IPv6) with a salt (a secret value) added, together with a count (Section 5). We do not store the IP address itself for rate limiting. Rate limiting for login, device connection, invite lookups, and the like is done by Cloudflare's rate-limiting feature, and we pass it only the same hash, not the IP address itself. For installer downloads, we count only the number per day and per version and do not keep IP addresses | Collected automatically |
| Usage measurement information | Only if you consent to measurement: the types of screens viewed and actions taken, whether the resident tool's operations succeeded (the type of reason only), an anonymous user ID (an ID made from the internal user ID by a one-way conversion, which no one but us can trace back), the type of browser and device, and the approximate region (as described in Section 9) | Web screens, resident tool, our servers |
| Content of inquiries | The content of inquiries and reports, and your contact details | Your communication to us |
What we do not collect: screenshot images saved by VRChat, VRChat instance IDs (who you are with and where), the list of other users in an instance, audio, Discord or VRChat passwords, and advertising identifiers. The Service does not use ad-serving tools. We use web analytics (Google Analytics) only if you consent (Section 9).
About Cookies and similar technologies
The Service uses the following cookies. All of them are essential to providing the Service, and we do not use them to track your behavior or for advertising.
- A cookie that keeps you logged in (session. 30 days for the web; 7 days for a login handed over from the resident tool)
- Temporary cookies used in the middle of login, login from an invite link, and guest registration (10 minutes)
- A cookie that remembers your choice of display language (`komadori_lang`. 1 year)
We also store the following in your browser (these stay only in your device's browser and are not sent to our servers. You can delete them in your browser settings).
- localStorage / sessionStorage: display settings (home-video-style display on or off), the times at which you dismissed guides and cards (adding to the home screen, a request to turn on notifications, first steps, and so on), the number of visits, the Group you chose last, your choice about usage measurement (below), and temporary markers used during notifications and login
- Service Worker and its cache (Cache Storage): to show screens when you are offline, it stores only the public parts of the screens (the program, design, fonts, and logo). It does not store content that requires login (videos and personal data). It is also used to receive notifications (Web Push)
Only if you consent to usage measurement, Google Analytics stores cookies (`_ga`, and those starting with `_ga_`) in your browser. Until you consent, we do not load the Google Analytics script or communicate with Google. Your choice is stored in your browser's localStorage. You can withdraw consent at any time on the web "Account" screen (or in the resident tool's settings); when you withdraw, measurement stops and these cookies are deleted.
3. Purposes of Use
We use the information we collect for the following purposes.
- Providing the Service (login, managing Friends and Groups, providing notification times, storing Posts and showing them to members within the sharing scope, features such as the day's title, badges, and voting, and sending browser notifications (Web Push) if you turn notifications on)
- Verifying your identity, preventing fraud and impersonation, managing authentication, and preventing misuse such as mass creation of guests (rate limiting by hash values of IP addresses)
- Responding to acts that violate the Terms of Service and to reports of rights infringement, and reviewing and deleting Posts
- Investigating failures, ensuring security, and stable operation and quality improvement of the Service
- Responding to inquiries and to requests for deletion, disclosure, and the like
- Showing, within the scope of Section 4, the previous day's Group clips, or the recent clips of the user who issued a friend invite link, so that a person who opens an invite link can decide whether to join or become friends
- Necessary communications, such as changes to the Terms of Service and this Policy
- Responding as required by law
We will not change the purposes of use beyond the range above. If we change them, we will follow the procedure in Section 13.
4. Sharing Scope (What Is Shown to Users)
- Post Content, display names, and the like are shown to other users who are in a Friend or Group relationship with you. Members of your Friends and Groups can also view the record of days on which you did not post.
- Except for "Display on invite pages and similar" below, Post Content is not made public beyond the Friends and Groups you belong to.
- Invite link previews (on Discord, X, and so on) show only the Group name and the number of members, not members' names. A friend invite link preview includes the display name of the user who issued the link (the link is something the issuer hands to a friend, and the URL contains a hard-to-guess token. The issuer can disable the link at any time). A preview of an older-style link made from a friend code does not include a display name.
- The same applies to selfies (they are delivered to the same scope as videos and poster images, under the same conditions). You can turn them off in the settings; if you do, they are neither recorded nor sent.
- Videos and poster images are delivered only to members of the sharing scope, using the logged-in person's cookie or device token (except for the display on invite pages and similar, below).
Display on invite pages and similar (shown to anyone who knows the link)
A Group invite page (/join/...) and a friend invite link (/f/...) can be opened without logging in by anyone who knows the link. The following is shown to those people.
- Group invite page: Of that Group's clips from the previous day (divided at 05:00 JST), up to 6 "main screen videos" and their poster images play automatically without audio. The previous day's title and the number of clips are also shown. Members' names, world names, and selfies (the Stream video and its poster image) are not shown. If the title contains a world name, it is replaced with a title that does not use the world name. The Group owner can turn this display off at any time on the Group screen (the default is on, including for existing Groups). When it is off, or when there are no clips that can be shown, only a blurred pattern of colors (from which the original picture cannot be made out) and the number of clips are shown.
- Opt-out: You can exclude your own clips from the invite page display of every Group by turning on "Do not show my clips on invite pages" on the Account screen (the default is off. The clips of a user who turned it on are not included in the invite page videos, color patterns, or counts). We tell you how this display works on the screen where you join a Group, and with a one-time notice to users who already belong to a Group.
- Friend invite link: Of the issuing user's clips from the last 7 days, up to 4 "main screen videos" and their poster images play automatically without audio. World names and selfies are not shown (the issuer's display name is shown with the link in any case). The issuer can turn this off at any time with "Show my clips on friend invite links" on the Friends screen or the Account screen (the default is on).
- Clips not shown in either: clips of users who are suspended, and clips that have a report under review. For a person who opens an invite page while logged in, clips of users that person has blocked, and of users who have blocked that person, are also not shown.
- Signed short-lived URLs: These videos and poster images are delivered by signed URLs, separate from normal delivery (which requires login). A URL is issued, when the invite page is opened, only for the clips that can be shown, can be used only for that clip and that part (the main screen video or its poster image), and expires in 10 minutes (it cannot be used for selfies). Anyone who knows a URL can watch that video without logging in until it expires. After it expires, opening the invite page again issues a new URL. This delivery has a per-IP-address rate limit.
- Invite link previews (OGP) do not include video or image URLs.
5. Retention Periods
| Information | Retention period |
|---|---|
| Videos, poster images, and selfies (Post Content) | Stored while your account exists. Deleted when you delete a clip or your account (when you delete your account, all Post Content is deleted). The deletions described under "Unused accounts" and "Guests" below also apply. For operational reasons (cost, capacity, safety, and so on), we may shorten the retention period, in which case we will tell you in advance |
| The day's title and votes | Same as Post Content (while the account exists; until the account is deleted) |
| Information attached to Posts (world name and ID, caption, time) | Deleted together with the Post Content |
| Recording files the resident tool keeps on your PC (those not yet sent or that failed to send, and the one clip kept for the confirmation shown right after posting) | They exist only on your PC, and we do not receive them. They are deleted when posted, discarded, after the deadline, at the next recording, or when the tool exits; any that remain are deleted at the next startup (those more than 24 hours old). After a guest has used up the trial number of Posts, that day's recordings are kept on the PC until you register, and are deleted when the day changes (05:00 JST) |
| Account information (Discord ID, Google user ID, display name, VRChat information) and Friend and Group relationships | Until the account is deleted (you delete it in the app, or it is deleted under the Terms) |
| Records of reports | Deleted 1 year after the response (dismissal, deletion of the Post, or suspension). When the user who made a report deletes their account, the reports they made are deleted immediately. When a reported Post is deleted, the report is closed as needing no action |
| Block settings | Until unblocked, or until either account is deleted |
| Administrators' operation records (moderation log) | 1 year from the operation. When the target user or the administrator who acted deletes their account, the link to that person is removed (anonymized) and the record is kept. Kept to check that our operational responses are appropriate |
| Registered accounts that are not in use | If not used for 1 year after the last use, the account and its Post Content and so on are deleted (by a daily scheduled job, in the same way as when you delete your own account). If you have notifications (Web Push) on, we tell you once, about 30 days before deletion (opening the app counts as use and lets you keep the account). If notifications are not available, the account is deleted without advance notice |
| Guest accounts (users who started without logging in) and their data | If not used for 30 days after the last use, the account and its Post Content and so on are deleted (by a daily scheduled job, in the same way as when you delete your own account). If you register with Discord, the account follows the retention periods above for regular accounts. If a registered Discord account already exists, the guest's data is merged into that account and the guest account is deleted |
| Hash of the IP address at guest creation | Until the guest registers with Discord or Google, or until the guest account is deleted (it is erased when you register). Rate-limit counters (these hold only salted hash values, not IP addresses themselves) are deleted by the daily scheduled job after the window length (at most 1 day) has passed, so they remain for about 2 days at most |
| Time of last use | Recorded also for registered accounts so that unused accounts can be deleted (updated at most once an hour). Kept until the account is deleted |
| Notification (Web Push) subscription information and settings | Until you turn notifications off, until you delete your account, or until the subscription becomes invalid (deleted on the spot if the Push service reports it as invalid; if delivery keeps failing, we stop sending and delete it after 30 days). Records of notifications sent are deleted after 3 days. It is included in your data export and deleted together with your account |
| Signed URLs for invite pages | 10 minutes (not stored; verified from the signature each time). Display settings are kept until the account or Group is deleted |
| Login handover code | 2 minutes (deleted on the spot when used; expired ones are deleted by a scheduled job) |
| Login and device sessions | Until the expiry. Expired ones are deleted by a scheduled job |
| Connection codes and device approval codes | Expire after a short time (5 minutes for connection codes, 10 minutes for device approval codes) and are deleted by scheduled jobs and the like |
| Usage measurement information (Google Analytics) | Follows the retention setting of Google Analytics (by default, detailed event data is kept for 2 months. We do not extend this). If you withdraw consent, we do not measure from then on |
| Access records | For the period needed for failure response and fraud prevention (follows the retention period of the external service) |
| Records of inquiries | For the period needed to respond |
Please note that it may take a certain period for deleted data to disappear from backups and caches.
6. Provision to Third Parties
We do not provide personal data to third parties except in the following cases.
- When you consent
- When required by law
- When necessary to protect a person's life, body, or property, and it is difficult to obtain the person's consent
- When especially necessary to improve public health or promote the sound upbringing of children, and it is difficult to obtain the person's consent
- When it is necessary to cooperate with a government body or the like in carrying out duties prescribed by law, and obtaining the person's consent may impede those duties
Entrustment under Section 7, and entrustment to, or use of, businesses located in foreign countries under Section 8, are not provision to a third party. We do not jointly use personal data.
7. Entrusting the Handling of Personal Data and Use of External Services
To operate the Service, we entrust the handling of personal data to the following businesses, or use their external services. We provide necessary and appropriate supervision of the businesses we entrust.
| Entrusted business / service used | Country | Purpose and content |
|---|---|---|
| Cloudflare, Inc. (Cloudflare Workers, D1, R2) | United States | Hosting of the Service, the database, storage of videos and poster images, and processing of communications. It handles almost all of the information in Section 2 |
| Anthropic, PBC (Claude API) | United States | Generating "the day's title". Only metadata, such as times, counts, and world names, is sent (see below) |
| Google LLC (Google Analytics 4) | United States | Usage measurement (only if you consent). Aggregation for quality improvement. What is sent is as described in Section 9 |
| Google LLC, Mozilla Corporation, Apple Inc., Microsoft Corporation (each browser's Push service) | United States and others | Delivering notifications (Web Push). Encrypted notifications are sent only to the service of the vendor of the browser in which you turned notifications on (see below) |
| Google LLC (Login with Google) | United States | Login (OpenID Connect). At login, we receive only your Google user ID (sub); we do not receive your email address, name, and so on |
| Discord Inc. | United States | Login (OAuth2). At login, we receive your Discord user ID and display name. When a Group owner registers a webhook, we also send the morning announcement (see below) |
About generating the day's title (Anthropic)
Only where we have enabled it, we send only the following metadata to Anthropic's API to create "the day's title".
- What we send: the number of hourly clips, the posting times (hour:minute), the world names with duplicates removed (up to 8; these are names the resident tool read from the VRChat log, whether the world is public or private), the number of people who posted "NOW!" and the number who were late, and the number of members who posted (for Groups). Both the title for one person's day and the title for a Group's day are covered. If there are 2 or fewer clips that day, we send nothing.
- What we do not send: videos and poster images, display names and VRChat names, user IDs, world IDs, and instance IDs, captions, and Discord information.
We never send your videos or images to AI, or process them with AI. If we do not send anything, or if the API fails, we create the title from the same metadata using rules. Anthropic handles the information it receives through the API in accordance with Anthropic's Commercial Terms and Privacy Policy.
About notifications (Web Push)
We send browser notifications (Web Push) only if you turn notifications on. To turn them on, you must allow them in your browser's permission prompt and then press "Turn on notifications" on the Account screen or elsewhere. At any time, on the "Notifications" section of the Account screen, you can turn them off by type, or for this device entirely.
- Types of notification: when "NOW!" has been posted by 2 or more people in a Group; the "Yesterday's log" at 7 every morning (the title and the display name of the user with the most votes); when someone has joined a Group (to the Group owner) and when someone has joined through a friend invite link (to the person who issued the link) (both with the display name of the person who joined); and the advance notice of deletion when a registered account has not been used for 1 year (once, about 30 days before deletion. This one notification is not covered by the per-type off settings. If you turn notifications off altogether, you will not receive it)
- Notification text does not include world names, videos, captions, or the content of other users' Posts. The display name is your VRChat name if known, otherwise your Discord display name (a temporary name for guests). Users you have a block relationship with, and suspended users, are excluded from notifications and from display
- How they are sent: the body of the notification is encrypted with the key of the subscribed device and sent from our servers to the Push service run by the vendor of that device's browser (Google's FCM, and the services of Mozilla, Apple, and Microsoft). The Push service holds the encrypted body until it reaches the device. The Push service cannot read the content of the body. However, the Push service handles the destination endpoint, the date and time of sending, information about our servers, and so on, in accordance with each company's privacy policy
- Limits: at most 3 per person per day (the day divided at 0:00 Japan time; including the deletion notice). We do not send between 2:00 and 7:00 Japan time. One person can register up to 5 devices
- When you dispose of a device, please turn notifications off or set your browser not to allow notifications. If a subscription becomes invalid on the browser side, our server detects it when it tries to send, and deletes the subscription information
About the morning announcement to Discord (Webhook)
Only where a Group owner has registered a Discord webhook URL, every morning, for a Group that has a log for the previous day (divided at 05:00 JST), we send the following to that webhook, that is, to Discord Inc. The owner can remove it at any time.
- What we send: the Group name; the previous day's title (if the in-app title does not include a world name, that title; if it does, a separate title made by rules without using the world name. We do not send anything to AI for the announcement); the number of clips; the number of members who posted; the time slot and number of votes of the clip with the most votes; and a link to a Komadori page. When "Send test" is pressed, we send test text. Only if the owner turns on "Include invite link in the announcement", we also send the join link for that Group (including the invite code) (default: off)
- What we do not send: members' display names, VRChat names, or user IDs; videos and poster images; captions; and world names.
The announcement is shown to Discord users in the channel it is registered to. The owner is responsible for choosing a channel that may be shown to the Group's members. Destinations are limited to webhooks on discord.com / discordapp.com.
8. Information on Transfers to Third Parties in Foreign Countries (Cross-Border Transfers)
Cloudflare, Inc., Anthropic, PBC, Discord Inc., and Google LLC (for Login with Google, and for Google Analytics if you consent to measurement), to which we entrust the handling of personal data or whose external services we use, are located in the United States, and data may be processed and stored on servers in the United States. In addition, because Cloudflare uses data centers around the world, communications may pass through, or be processed in, countries and regions other than the United States.
- The United States has no comprehensive federal personal information protection law equivalent to Japan's APPI. However, there are state laws, rules that businesses set for themselves, and the privacy practices that each company publishes (see the links in Section 7). Information on foreign systems published by Japan's Personal Information Protection Commission can be found on the following page (in Japanese).
- We have concluded, in the form each company provides, contracts and terms (including data processing provisions) under which the entrusted businesses handle personal data in accordance with our instructions.
- We will endeavor to check periodically how these entrusted businesses handle personal data.
In addition to the above, by using the Service, you agree to handling in the countries and regions above.
For people who live in the EEA, the United Kingdom, or Switzerland, the following also applies (see Section 15 for details).
- Transfer of information from you to us (Japan): Japan has received a decision from the EU (and from the United Kingdom) that its level of personal data protection is adequate (an adequacy decision).
- Transfer from us to our entrusted businesses in the United States: this relies on the data processing agreements each company provides (including Standard Contractual Clauses) or on other transfer mechanisms each company uses, such as the EU-U.S. Data Privacy Framework. Each company's mechanism can be checked in the materials that company publishes.
9. External Transmissions
In the Service, information about you is sent from your browser or the resident tool to the following external businesses. The Service does not use ad-serving tools or social media share buttons. As a web analytics tool, we use Google Analytics 4 only if you consent.
| Destination | Information sent | Purpose | When it is sent |
|---|---|---|---|
| Discord Inc. discord.com | Information needed for login (an OAuth2 authorization request. Your browser moves to a Discord page, and Discord authenticates you) | Login with a Discord account | When you perform the login action |
| Google LLC accounts.google.com (browser), oauth2.googleapis.com (sent from our server) | Information needed for login (an OpenID Connect authorization request. Your browser moves to a Google page, and Google authenticates you. Our server sends Google the authorization code and our client ID and secret, and receives your user ID (sub). The scope is openid only) | Login with a Google account | When you perform the Login with Google or link action (only where we have enabled Login with Google) |
| Discord Inc. discord.com (sent from our server) | The content of the morning announcement (as in "About the morning announcement to Discord" above) | Announcement to the Discord channel registered by the Group owner | Every morning for a Group with a registered webhook, and when "Send test" is pressed |
| Google LLC Google Analytics 4 (google-analytics.com, googletagmanager.com. The web also loads a script from googletagmanager.com. Only if you consent) | As in "Usage measurement with Google Analytics" below | Improving the quality of the Service (finding defects, understanding where first-time users get stuck, and deciding on improvements) | After you consent, when you open or operate a screen (web). When the resident tool's operations such as notifying, recording, and posting happen (sent directly from the Windows resident tool. Only if you consent) |
| Google LLC (FCM), Mozilla Corporation, Apple Inc., Microsoft Corporation (each browser's Push service. Sent from our server) | The encrypted body of the notification (as in "About notifications (Web Push)" above), the subscription information (endpoint), and the date and time of sending | Delivering notifications to the browser in which you turned notifications on | To users who turned notifications on, when the notification conditions are met ("NOW!" has been posted by enough people, every morning at 7, or when someone has joined) |
| Cloudflare, Inc. (hosting of the Service) | IP address, User-Agent, request content, and other information needed to process communications | Providing and delivering the Service, and security | Whenever the Service is used |
- To let the operator know signs of fraud, such as a sudden increase in guests, we may send an alert containing only counts and thresholds to a Discord channel of the operator. It does not include any of your personal information (IP address, ID, name, and so on).
- Apart from our servers (the Service), the resident tool (Windows) sends usage information (such as whether operations succeeded; see below) directly to Google Analytics (google-analytics.com), and only if you consent to measurement. If you do not consent, it sends nothing externally. The Google script is not loaded on the resident tool's screens, and no cookies are used. Web fonts (Noto Sans JP, Zen Maru Gothic) are delivered by the Service itself, so there is no communication with a font delivery provider.
Usage measurement with Google Analytics
Only if you consent, to improve the quality of the Service, we send the following information to Google Analytics 4, provided by Google LLC.
- What we send: the type of screen shown (with invite codes and tokens of invite links, friend codes, Group IDs, query strings, and the like removed); the types of button actions and feature use (for example: a login action, copying an invite link, playing a video, whether you voted); the fact that a video could not be played (the type of error); the type of communication error (the broad category of the API concerned and the status); whether the resident tool's operations succeeded and the type of reason for a failure (for example: a notification was shown, recording failed, a selfie could not be taken); whether a post succeeded (only the kind, whether it was late, and whether it had a selfie); the version of the resident tool; the anonymous user ID; and what Google Analytics obtains automatically: the type of browser, device, and OS, the language, the screen size, the approximate region (the IP address itself is not stored, by the design of Google Analytics), and the referring site (for external sites, the domain only)
- What we do not send: display names, VRChat names, Discord user IDs and usernames, friend codes, invite codes, friend invite link tokens, Group names, world names and IDs, captions, Post (clip) IDs, the content of videos and images, and email addresses
- Anonymous user ID: We use an ID made by converting the internal user ID one-way with a secret key that only we know. It is used to tally the same user's use across multiple days and devices, but no one other than us can identify a user from this ID.
- Use for advertising: We do not use information obtained through Google Analytics to serve or personalize ads (Google signals and ads personalization are turned off).
- Consent and withdrawal: We ask on a banner the first time you open a screen ("Agree" or "Decline"), and we do not send anything to Google until you agree. If your browser's "Do Not Track" setting is on, we treat it as a refusal until you choose. You can change your choice at any time from "Usage measurement" on the web "Account" screen and from the resident tool's settings (the web and resident tool choices are stored with your account and are shared). If you decline or withdraw, we do not measure from then on.
- How Google handles it: Google handles information in accordance with Google's privacy policy and related terms. For details, see Google Privacy Policy, Safeguarding your data (Google Analytics), and How Google uses information from sites or apps that use our services. A Google Analytics Opt-out Browser Add-on is also available to disable measurement by Google Analytics per browser.
10. Security Measures
To prevent leakage, loss, or damage of personal data, we take measures such as the following.
- Organizational measures: clearly designating a person responsible for handling, and checking how data is handled
- Personnel measures: training and confidentiality obligations for staff who handle personal data
- Physical measures: storage under the management of the cloud provider (Cloudflare)
- Technical measures: encryption of communications (HTTPS); access control (limiting access to members of the sharing scope); hashing of sessions, connection codes, and login handover codes; signed short-lived URLs for invite page videos (HMAC, 10 minutes, per clip and per part) and rate limiting; CSRF protection that limits writes authenticated by cookies to the same origin; for limiting guest creation, handling IP addresses only after turning them into salted hash values (for other rate limits too, IP addresses are likewise turned into salted hash values before handling and kept only for a short time); and prevention of misuse (connection codes expire quickly and can be used only once)
- Understanding the external environment: we understand the systems of the country where our entrusted businesses are located (the United States) and reflect them in the measures above.
11. Requests for Disclosure, Correction, Cessation of Use, Deletion, and the Like
- Under the APPI, you can request, for the retained personal data we hold about you, notification of the purposes of use, disclosure, correction, addition, or deletion, cessation of use or erasure, and cessation of provision to third parties.
- Please send a request to the contact in Section 1, together with information that lets us confirm it is you, such as your Discord account display name and Discord user ID (if you log in with Google, information such as your friend code that identifies the account). After confirming your identity, we will respond within the period prescribed by law. As a rule we do not charge a fee (except where the law provides otherwise).
- You can delete your account yourself at any time from the "Account" screen in the app. When you do, your account information, Post Content (videos, poster images, and selfies), votes, Friend and Group relationships, block settings, device connections, notification (Web Push) subscription information, settings and records of sending, friend invite links, reports you made, and records of reports about your Posts are deleted immediately. If you were the owner of a Group, the Group is handed over to the member who joined earliest (the registered Discord webhook is removed). A Group with no other members left is deleted together with the Group (as in the preceding paragraph, it may take a certain period for data to disappear from backups and caches). Operation records of actions we took are kept after removing the link to you. If you cannot do this in the app, please contact us at the contact above.
- From the "Account" screen, you can export your own data (profile, Friends and Groups, Post information, votes, reports you made, block settings, and notification subscription information and settings) as JSON (this is one way to make a disclosure request). You can delete individual Posts yourself in the Service.
- We also accept at the same contact requests for deletion from people who appear in other users' videos (Article 10 of the Terms of Service). From the "⋯" menu of a Post, you can also report the Post or block the user who posted it.
12. Age and Information About Minors
- The Service can be used only by people aged 16 or older. If you are under 16, you may not use the Service. Age is confirmed by your own declaration, based on the notice next to the login or start button; we do not collect your date of birth.
- If we learn that we have collected information about a person under 16, we will promptly delete it.
- Rules on the handling of children's personal information are expected to be set under the amended APPI. We will review this Policy and the Terms of Service in light of the content of those laws.
13. Changes to This Policy
We may change this Policy in response to changes in law or in the Service. If we make a significant change, we will tell you a reasonable time before the effective date, by posting on the Service's website or by another appropriate method. Changes to the purposes of use are limited to the range reasonably recognized as related to the purposes before the change. The changed content takes effect when it is posted on this page (or on the effective date, if we set one separately).
14. Contact for Inquiries
The contact for inquiries about this Policy and the handling of personal information, and for requests for disclosure and the like, is as follows.
- Operator: Destingate LLC (Destingate合同会社)
- Contact: ing@digital-sorovider.jp (Japanese or English)
- Under the APPI, we will, on request to the contact above, promptly tell you our address and the name of our representative.
15. For People in the EEA, the United Kingdom, and Switzerland
For people who live in the EEA (European Economic Area), the United Kingdom, or Switzerland, in addition to the other sections of this Policy, we handle personal data as follows. We follow whichever of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection applies.
Controller: Destingate LLC (Japan). Our contact is in Section 14.
Lawful basis for processing: We handle personal data on the following bases.
| Processing | Lawful basis |
|---|---|
| Storing and sharing accounts and clips, and providing notification times | Performance of a contract (GDPR Article 6(1)(b)) |
| Generating the day's title (we send only metadata to Anthropic) | Performance of a contract (Article 6(1)(b)) |
| Fraud prevention, rate limiting, hashing of IP addresses, responding to reports, and security management | Legitimate interests (Article 6(1)(f)) |
| Google Analytics and Web Push notifications | Consent (Article 6(1)(a)). You can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal |
| Responding as required by law | Legal obligation (Article 6(1)(c)) |
Your rights: You have the right to ask for access (disclosure), correction, erasure, restriction of processing, data portability (from "Export" on the Account screen you can receive your own data as JSON), to object, and to withdraw consent. Please send requests to the contact in Section 14. After confirming your identity, we will, as a rule, respond within 1 month.
Complaints: If you are dissatisfied with how we handle your data, you can lodge a complaint with a data protection supervisory authority in the country where you live, where you work, or where you believe an infringement took place. If you contact us first, we will respond in good faith.
Cross-border transfers: As described in Section 8.
Automated decision-making: We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you.
Retention periods: As described in Section 5.
Whether providing information is required: If you do not provide the information needed for login (such as Discord or Google identifiers), you cannot use the Service. Providing other information (such as for measurement and notifications) is optional.
Age: The Service can be used only by people aged 16 or older (Section 12).
16. For People in the United States
We do not sell your personal information. We also do not share your personal information for cross-context behavioral advertising (advertising based on your activity across other services).
End