Komadori

Privacy Policy

Enacted: 2026-10-01Last updated: 2026-10-01

Contents
  1. 1. Business Operator and Contact
  2. 2. Information We Collect
  3. 3. Purposes of Use
  4. 4. Sharing Scope (What Is Shown to Users)
  5. 5. Retention Periods
  6. 6. Provision to Third Parties
  7. 7. Entrusting the Handling of Personal Data and Use of External Services
  8. 8. Information on Transfers to Third Parties in Foreign Countries (Cross-Border Transfers)
  9. 9. External Transmissions
  10. 10. Security Measures
  11. 11. Requests for Disclosure, Correction, Cessation of Use, Deletion, and the Like
  12. 12. Age and Information About Minors
  13. 13. Changes to This Policy
  14. 14. Contact for Inquiries
  15. 15. For People in the EEA, the United Kingdom, and Switzerland
  16. 16. For People in the United States

Destingate LLC (Destingate合同会社, "we", "us" or "our") values the personal information and privacy of users of "Komadori for VRChat" (the "Service"), and handles it as set out below, in compliance with Japan's Act on the Protection of Personal Information (the "APPI") and other applicable laws. The Service is an unofficial service and has no affiliation with VRChat Inc. This English version and the Japanese version of this Privacy Policy have equal weight.

1. Business Operator and Contact

2. Information We Collect

The Service collects the following information.

CategoryContentHow it is collected
Discord account informationYour Discord user ID, display name, and username (through Discord login, within the identify scope only. We do not collect your email address, friend list, server information, and so on. The username is stored so that we can tell whether a resident tool connection is really yours, and is not shown to other users)Discord login
Google account informationOnly your Google user ID (the OpenID Connect "sub", an identifier that Google assigns to each user and that does not change), collected when you log in with Google or press "Link Google". The scope is openid only; we do not collect your email address, name, profile picture, contacts, and so on. The display name is a temporary name we assign ("User" followed by 4 characters; it is replaced by your VRChat display name once that is known). You can link Discord and Google either one alone or bothGoogle login
Guest information (users who started without logging in)For users who pressed a button such as "Start without logging in": an internal ID we issue, a temporary display name ("Guest" followed by 4 characters; it is replaced by your VRChat display name once that is known), the time of creation, the time of last use, the number of trial Posts, and a one-way hash made from the IP address at creation time with a salt (a secret value) added (used only to prevent mass creation of fake accounts; we do not store the IP address itself for this purpose). We do not collect Discord or Google informationGuest creation action, resident tool, web
VRChat informationYour VRChat user ID and VRChat display name (your resident tool reads them from VRChat's output log and sends them as a self-declaration. We do not check them by querying VRChat)Resident tool
Language, time zone, and region settingsYour display language; your time zone (a name such as `Asia/Tokyo`, obtained automatically from your browser and changeable on the Account screen); the "NOW!" region derived from it (one of Asia, Europe, or the Americas); and the time offset (difference from Coordinated Universal Time) when a clip was taken. These are used only to adapt notification times and the display language and times to your region. We do not collect location data (such as GPS)Your actions, web, resident tool
Post ContentA 3-second video recording of your VRChat screen (no audio; "NOW!" is the same), a poster image (still image) generated automatically from the video, and, if you have it enabled, a 3-second video (no audio) of the VRChat camera feed (Stream) recorded at the same time, with its poster image (the "selfie"; even if you point the camera at yourself, other users' avatars or names may appear), the time of capture and posting, the world name and ID (can be turned off in the settings), and a caption (the official resident tool and web app currently have no feature to send captions)Resident tool, web
Relationship informationFriend codes; friend requests and friend relationships; friend invite links (the token hash, the random value used to regenerate the link, the last 4 characters of the token, and the expiry. The expiry is 7 days after issue, and expired links are deleted); Group names, invite codes, and members (including the creator of the Group); and a Discord webhook URL that a Group owner has optionally registered (stored as a secret, and displayed partly masked on screen)Your actions
Settings for what invite pages showThe Group owner's choice "Show yesterday's log on the invite page" (default: on); your choices "Do not show my clips on invite pages" (default: off) and "Show my clips on friend invite links" (default: on); the time we showed you notices about these; and whether the guidance shown right after creating a Group has been displayedYour actions, our processing
Information from using the ServiceVotes in Groups (such as "Pick of the day"), the day's title, and the Post information used to calculate badges (badges are not stored; they are calculated on the spot)Your actions, our processing
Notification (Web Push) subscription informationOnly if you turn notifications on: the subscription information issued by your browser (the URL of the Push service run by your browser's vendor (the endpoint), a public key for encrypting the notification body, and an authentication value); the date and time of subscription and of the last delivery; the number of consecutive failures; on/off settings for each type of notification; and a record of notifications sent (type, date and time, and an identifier to prevent duplicate sending; used only to manage the daily cap and prevent duplicates)Your actions (permission in your browser's permission prompt, and "Turn on notifications" on the Account screen or elsewhere)
Information about reports and blocksReports you make (the Post concerned, the reason, and any added description), the users you block, and the operation record of actions we take (such as deleting a Post or suspending a user)Your actions, our processing
Authentication informationSessions for login and for device connection (tokens are stored hashed and have an expiry: 30 days for the web, 365 days for the resident tool); the time a device session was last used; the resident tool's connection code, the device-side secret code, and the code for handing a login over from the resident tool to the web (stored hashed, and expire quickly); and the short confirmation code shown on screen for device approval (stored as is until it expires after 10 minutes)Login, device connection
Communication and access recordsIP address, type of browser and device (User-Agent), request date, time and content, error information, and other records generated in operating the web server. In addition, to prevent abuse (rate limiting), we store in the database for a short time only a one-way hash, made from the IP address (rounded to the first 64 bits for IPv6) with a salt (a secret value) added, together with a count (Section 5). We do not store the IP address itself for rate limiting. Rate limiting for login, device connection, invite lookups, and the like is done by Cloudflare's rate-limiting feature, and we pass it only the same hash, not the IP address itself. For installer downloads, we count only the number per day and per version and do not keep IP addressesCollected automatically
Usage measurement informationOnly if you consent to measurement: the types of screens viewed and actions taken, whether the resident tool's operations succeeded (the type of reason only), an anonymous user ID (an ID made from the internal user ID by a one-way conversion, which no one but us can trace back), the type of browser and device, and the approximate region (as described in Section 9)Web screens, resident tool, our servers
Content of inquiriesThe content of inquiries and reports, and your contact detailsYour communication to us

What we do not collect: screenshot images saved by VRChat, VRChat instance IDs (who you are with and where), the list of other users in an instance, audio, Discord or VRChat passwords, and advertising identifiers. The Service does not use ad-serving tools. We use web analytics (Google Analytics) only if you consent (Section 9).

About Cookies and similar technologies

The Service uses the following cookies. All of them are essential to providing the Service, and we do not use them to track your behavior or for advertising.

We also store the following in your browser (these stay only in your device's browser and are not sent to our servers. You can delete them in your browser settings).

Only if you consent to usage measurement, Google Analytics stores cookies (`_ga`, and those starting with `_ga_`) in your browser. Until you consent, we do not load the Google Analytics script or communicate with Google. Your choice is stored in your browser's localStorage. You can withdraw consent at any time on the web "Account" screen (or in the resident tool's settings); when you withdraw, measurement stops and these cookies are deleted.

3. Purposes of Use

We use the information we collect for the following purposes.

  1. Providing the Service (login, managing Friends and Groups, providing notification times, storing Posts and showing them to members within the sharing scope, features such as the day's title, badges, and voting, and sending browser notifications (Web Push) if you turn notifications on)
  2. Verifying your identity, preventing fraud and impersonation, managing authentication, and preventing misuse such as mass creation of guests (rate limiting by hash values of IP addresses)
  3. Responding to acts that violate the Terms of Service and to reports of rights infringement, and reviewing and deleting Posts
  4. Investigating failures, ensuring security, and stable operation and quality improvement of the Service
  5. Responding to inquiries and to requests for deletion, disclosure, and the like
  6. Showing, within the scope of Section 4, the previous day's Group clips, or the recent clips of the user who issued a friend invite link, so that a person who opens an invite link can decide whether to join or become friends
  7. Necessary communications, such as changes to the Terms of Service and this Policy
  8. Responding as required by law

We will not change the purposes of use beyond the range above. If we change them, we will follow the procedure in Section 13.

4. Sharing Scope (What Is Shown to Users)

Display on invite pages and similar (shown to anyone who knows the link)

A Group invite page (/join/...) and a friend invite link (/f/...) can be opened without logging in by anyone who knows the link. The following is shown to those people.

5. Retention Periods

InformationRetention period
Videos, poster images, and selfies (Post Content)Stored while your account exists. Deleted when you delete a clip or your account (when you delete your account, all Post Content is deleted). The deletions described under "Unused accounts" and "Guests" below also apply. For operational reasons (cost, capacity, safety, and so on), we may shorten the retention period, in which case we will tell you in advance
The day's title and votesSame as Post Content (while the account exists; until the account is deleted)
Information attached to Posts (world name and ID, caption, time)Deleted together with the Post Content
Recording files the resident tool keeps on your PC (those not yet sent or that failed to send, and the one clip kept for the confirmation shown right after posting)They exist only on your PC, and we do not receive them. They are deleted when posted, discarded, after the deadline, at the next recording, or when the tool exits; any that remain are deleted at the next startup (those more than 24 hours old). After a guest has used up the trial number of Posts, that day's recordings are kept on the PC until you register, and are deleted when the day changes (05:00 JST)
Account information (Discord ID, Google user ID, display name, VRChat information) and Friend and Group relationshipsUntil the account is deleted (you delete it in the app, or it is deleted under the Terms)
Records of reportsDeleted 1 year after the response (dismissal, deletion of the Post, or suspension). When the user who made a report deletes their account, the reports they made are deleted immediately. When a reported Post is deleted, the report is closed as needing no action
Block settingsUntil unblocked, or until either account is deleted
Administrators' operation records (moderation log)1 year from the operation. When the target user or the administrator who acted deletes their account, the link to that person is removed (anonymized) and the record is kept. Kept to check that our operational responses are appropriate
Registered accounts that are not in useIf not used for 1 year after the last use, the account and its Post Content and so on are deleted (by a daily scheduled job, in the same way as when you delete your own account). If you have notifications (Web Push) on, we tell you once, about 30 days before deletion (opening the app counts as use and lets you keep the account). If notifications are not available, the account is deleted without advance notice
Guest accounts (users who started without logging in) and their dataIf not used for 30 days after the last use, the account and its Post Content and so on are deleted (by a daily scheduled job, in the same way as when you delete your own account). If you register with Discord, the account follows the retention periods above for regular accounts. If a registered Discord account already exists, the guest's data is merged into that account and the guest account is deleted
Hash of the IP address at guest creationUntil the guest registers with Discord or Google, or until the guest account is deleted (it is erased when you register). Rate-limit counters (these hold only salted hash values, not IP addresses themselves) are deleted by the daily scheduled job after the window length (at most 1 day) has passed, so they remain for about 2 days at most
Time of last useRecorded also for registered accounts so that unused accounts can be deleted (updated at most once an hour). Kept until the account is deleted
Notification (Web Push) subscription information and settingsUntil you turn notifications off, until you delete your account, or until the subscription becomes invalid (deleted on the spot if the Push service reports it as invalid; if delivery keeps failing, we stop sending and delete it after 30 days). Records of notifications sent are deleted after 3 days. It is included in your data export and deleted together with your account
Signed URLs for invite pages10 minutes (not stored; verified from the signature each time). Display settings are kept until the account or Group is deleted
Login handover code2 minutes (deleted on the spot when used; expired ones are deleted by a scheduled job)
Login and device sessionsUntil the expiry. Expired ones are deleted by a scheduled job
Connection codes and device approval codesExpire after a short time (5 minutes for connection codes, 10 minutes for device approval codes) and are deleted by scheduled jobs and the like
Usage measurement information (Google Analytics)Follows the retention setting of Google Analytics (by default, detailed event data is kept for 2 months. We do not extend this). If you withdraw consent, we do not measure from then on
Access recordsFor the period needed for failure response and fraud prevention (follows the retention period of the external service)
Records of inquiriesFor the period needed to respond

Please note that it may take a certain period for deleted data to disappear from backups and caches.

6. Provision to Third Parties

We do not provide personal data to third parties except in the following cases.

  1. When you consent
  2. When required by law
  3. When necessary to protect a person's life, body, or property, and it is difficult to obtain the person's consent
  4. When especially necessary to improve public health or promote the sound upbringing of children, and it is difficult to obtain the person's consent
  5. When it is necessary to cooperate with a government body or the like in carrying out duties prescribed by law, and obtaining the person's consent may impede those duties

Entrustment under Section 7, and entrustment to, or use of, businesses located in foreign countries under Section 8, are not provision to a third party. We do not jointly use personal data.

7. Entrusting the Handling of Personal Data and Use of External Services

To operate the Service, we entrust the handling of personal data to the following businesses, or use their external services. We provide necessary and appropriate supervision of the businesses we entrust.

Entrusted business / service usedCountryPurpose and content
Cloudflare, Inc. (Cloudflare Workers, D1, R2)United StatesHosting of the Service, the database, storage of videos and poster images, and processing of communications. It handles almost all of the information in Section 2
Anthropic, PBC (Claude API)United StatesGenerating "the day's title". Only metadata, such as times, counts, and world names, is sent (see below)
Google LLC (Google Analytics 4)United StatesUsage measurement (only if you consent). Aggregation for quality improvement. What is sent is as described in Section 9
Google LLC, Mozilla Corporation, Apple Inc., Microsoft Corporation (each browser's Push service)United States and othersDelivering notifications (Web Push). Encrypted notifications are sent only to the service of the vendor of the browser in which you turned notifications on (see below)
Google LLC (Login with Google)United StatesLogin (OpenID Connect). At login, we receive only your Google user ID (sub); we do not receive your email address, name, and so on
Discord Inc.United StatesLogin (OAuth2). At login, we receive your Discord user ID and display name. When a Group owner registers a webhook, we also send the morning announcement (see below)

About generating the day's title (Anthropic)

Only where we have enabled it, we send only the following metadata to Anthropic's API to create "the day's title".

We never send your videos or images to AI, or process them with AI. If we do not send anything, or if the API fails, we create the title from the same metadata using rules. Anthropic handles the information it receives through the API in accordance with Anthropic's Commercial Terms and Privacy Policy.

About notifications (Web Push)

We send browser notifications (Web Push) only if you turn notifications on. To turn them on, you must allow them in your browser's permission prompt and then press "Turn on notifications" on the Account screen or elsewhere. At any time, on the "Notifications" section of the Account screen, you can turn them off by type, or for this device entirely.

About the morning announcement to Discord (Webhook)

Only where a Group owner has registered a Discord webhook URL, every morning, for a Group that has a log for the previous day (divided at 05:00 JST), we send the following to that webhook, that is, to Discord Inc. The owner can remove it at any time.

The announcement is shown to Discord users in the channel it is registered to. The owner is responsible for choosing a channel that may be shown to the Group's members. Destinations are limited to webhooks on discord.com / discordapp.com.

8. Information on Transfers to Third Parties in Foreign Countries (Cross-Border Transfers)

Cloudflare, Inc., Anthropic, PBC, Discord Inc., and Google LLC (for Login with Google, and for Google Analytics if you consent to measurement), to which we entrust the handling of personal data or whose external services we use, are located in the United States, and data may be processed and stored on servers in the United States. In addition, because Cloudflare uses data centers around the world, communications may pass through, or be processed in, countries and regions other than the United States.

In addition to the above, by using the Service, you agree to handling in the countries and regions above.

For people who live in the EEA, the United Kingdom, or Switzerland, the following also applies (see Section 15 for details).

9. External Transmissions

In the Service, information about you is sent from your browser or the resident tool to the following external businesses. The Service does not use ad-serving tools or social media share buttons. As a web analytics tool, we use Google Analytics 4 only if you consent.

DestinationInformation sentPurposeWhen it is sent
Discord Inc.
discord.com
Information needed for login (an OAuth2 authorization request. Your browser moves to a Discord page, and Discord authenticates you)Login with a Discord accountWhen you perform the login action
Google LLC
accounts.google.com (browser), oauth2.googleapis.com (sent from our server)
Information needed for login (an OpenID Connect authorization request. Your browser moves to a Google page, and Google authenticates you. Our server sends Google the authorization code and our client ID and secret, and receives your user ID (sub). The scope is openid only)Login with a Google accountWhen you perform the Login with Google or link action (only where we have enabled Login with Google)
Discord Inc.
discord.com (sent from our server)
The content of the morning announcement (as in "About the morning announcement to Discord" above)Announcement to the Discord channel registered by the Group ownerEvery morning for a Group with a registered webhook, and when "Send test" is pressed
Google LLC
Google Analytics 4
(google-analytics.com, googletagmanager.com. The web also loads a script from googletagmanager.com. Only if you consent)
As in "Usage measurement with Google Analytics" belowImproving the quality of the Service (finding defects, understanding where first-time users get stuck, and deciding on improvements)After you consent, when you open or operate a screen (web). When the resident tool's operations such as notifying, recording, and posting happen (sent directly from the Windows resident tool. Only if you consent)
Google LLC (FCM), Mozilla Corporation, Apple Inc., Microsoft Corporation
(each browser's Push service. Sent from our server)
The encrypted body of the notification (as in "About notifications (Web Push)" above), the subscription information (endpoint), and the date and time of sendingDelivering notifications to the browser in which you turned notifications onTo users who turned notifications on, when the notification conditions are met ("NOW!" has been posted by enough people, every morning at 7, or when someone has joined)
Cloudflare, Inc.
(hosting of the Service)
IP address, User-Agent, request content, and other information needed to process communicationsProviding and delivering the Service, and securityWhenever the Service is used

Usage measurement with Google Analytics

Only if you consent, to improve the quality of the Service, we send the following information to Google Analytics 4, provided by Google LLC.

10. Security Measures

To prevent leakage, loss, or damage of personal data, we take measures such as the following.

11. Requests for Disclosure, Correction, Cessation of Use, Deletion, and the Like

  1. Under the APPI, you can request, for the retained personal data we hold about you, notification of the purposes of use, disclosure, correction, addition, or deletion, cessation of use or erasure, and cessation of provision to third parties.
  2. Please send a request to the contact in Section 1, together with information that lets us confirm it is you, such as your Discord account display name and Discord user ID (if you log in with Google, information such as your friend code that identifies the account). After confirming your identity, we will respond within the period prescribed by law. As a rule we do not charge a fee (except where the law provides otherwise).
  3. You can delete your account yourself at any time from the "Account" screen in the app. When you do, your account information, Post Content (videos, poster images, and selfies), votes, Friend and Group relationships, block settings, device connections, notification (Web Push) subscription information, settings and records of sending, friend invite links, reports you made, and records of reports about your Posts are deleted immediately. If you were the owner of a Group, the Group is handed over to the member who joined earliest (the registered Discord webhook is removed). A Group with no other members left is deleted together with the Group (as in the preceding paragraph, it may take a certain period for data to disappear from backups and caches). Operation records of actions we took are kept after removing the link to you. If you cannot do this in the app, please contact us at the contact above.
  4. From the "Account" screen, you can export your own data (profile, Friends and Groups, Post information, votes, reports you made, block settings, and notification subscription information and settings) as JSON (this is one way to make a disclosure request). You can delete individual Posts yourself in the Service.
  5. We also accept at the same contact requests for deletion from people who appear in other users' videos (Article 10 of the Terms of Service). From the "⋯" menu of a Post, you can also report the Post or block the user who posted it.

12. Age and Information About Minors

  1. The Service can be used only by people aged 16 or older. If you are under 16, you may not use the Service. Age is confirmed by your own declaration, based on the notice next to the login or start button; we do not collect your date of birth.
  2. If we learn that we have collected information about a person under 16, we will promptly delete it.
  3. Rules on the handling of children's personal information are expected to be set under the amended APPI. We will review this Policy and the Terms of Service in light of the content of those laws.

13. Changes to This Policy

We may change this Policy in response to changes in law or in the Service. If we make a significant change, we will tell you a reasonable time before the effective date, by posting on the Service's website or by another appropriate method. Changes to the purposes of use are limited to the range reasonably recognized as related to the purposes before the change. The changed content takes effect when it is posted on this page (or on the effective date, if we set one separately).

14. Contact for Inquiries

The contact for inquiries about this Policy and the handling of personal information, and for requests for disclosure and the like, is as follows.

15. For People in the EEA, the United Kingdom, and Switzerland

For people who live in the EEA (European Economic Area), the United Kingdom, or Switzerland, in addition to the other sections of this Policy, we handle personal data as follows. We follow whichever of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection applies.

Controller: Destingate LLC (Japan). Our contact is in Section 14.

Lawful basis for processing: We handle personal data on the following bases.

ProcessingLawful basis
Storing and sharing accounts and clips, and providing notification timesPerformance of a contract (GDPR Article 6(1)(b))
Generating the day's title (we send only metadata to Anthropic)Performance of a contract (Article 6(1)(b))
Fraud prevention, rate limiting, hashing of IP addresses, responding to reports, and security managementLegitimate interests (Article 6(1)(f))
Google Analytics and Web Push notificationsConsent (Article 6(1)(a)). You can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal
Responding as required by lawLegal obligation (Article 6(1)(c))

Your rights: You have the right to ask for access (disclosure), correction, erasure, restriction of processing, data portability (from "Export" on the Account screen you can receive your own data as JSON), to object, and to withdraw consent. Please send requests to the contact in Section 14. After confirming your identity, we will, as a rule, respond within 1 month.

Complaints: If you are dissatisfied with how we handle your data, you can lodge a complaint with a data protection supervisory authority in the country where you live, where you work, or where you believe an infringement took place. If you contact us first, we will respond in good faith.

Cross-border transfers: As described in Section 8.

Automated decision-making: We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you.

Retention periods: As described in Section 5.

Whether providing information is required: If you do not provide the information needed for login (such as Discord or Google identifiers), you cannot use the Service. Providing other information (such as for measurement and notifications) is optional.

Age: The Service can be used only by people aged 16 or older (Section 12).

16. For People in the United States

We do not sell your personal information. We also do not share your personal information for cross-context behavioral advertising (advertising based on your activity across other services).

End

Back to home