Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how yopuru ("we", "us", "our") handles user information collected through the website www.yopr.net and its subdomains (the "Service"), in accordance with the Japanese Act on the Protection of Personal Information (the "APPI"), the Telecommunications Business Act, and other applicable laws.
1. Information We Collect
We collect the following information. Items such as IP addresses that are not personal information by themselves are treated as personal information when readily linkable to an account.
- Account information: email address, display name, password (irreversibly hashed using an industry-standard algorithm), Google account subject ID, GitHub user ID, username, name and avatar URL, and email-verified status.
- Anonymous identifier: a randomly generated UID assigned to guest sessions.
- Usage data: chat messages, blog comments, bug reports, AI generation prompts and outputs.
- Language preference: detected from your browser or selected manually.
- Technical data: IP address, user agent, referrer, access timestamps.
- Cookies / localStorage: authentication session tokens and display preferences.
- Video calls: audio, video, Peer IDs and network connection information. Peer IDs are stored in browser localStorage.
- URL shortening: original URLs, short codes, creator UID and IP address, creation times, access counts, access referrers, user-agent hashes, safety checks and abuse records.
2. Purposes of Use
- To operate the Service, authenticate users, and maintain sessions
- To process text for translation features (a portion of submitted content is sent to third-party APIs for AI processing — see Section 4)
- To detect and prevent abuse and spam (hCaptcha, rate limiting, IP-based controls)
- To improve service quality, investigate issues, and produce usage statistics
- To respond to inquiries
- To comply with applicable law
Video calls send Peer IDs and related information to the connection server and use Google STUN servers to discover connectivity. Audio and video are sent to the other participant using WebRTC. Depending on the connection, your IP address may be disclosed to that participant. The Service’s call interface has no feature for recording calls to the server. We cannot control recording by the other participant using separate means.
URL shortening uses the information listed above for link creation, redirects, usage statistics and abuse prevention. When Google Safe Browsing integration is configured, the original URL is sent to Google for safety checks.
3. Retention Period
- Account information: retained while the account is active. Upon a deletion request, deleted within a reasonable period (in principle within 30 days).
- Chat messages and blog comments: deleted alongside an account deletion request. Content quoted in other users' posts is reviewed individually when a deletion request is received. Removing a display name or unlinking an account does not necessarily prevent identification from the content itself.
- Server access logs: up to 6 months. May be extended as needed for incident investigation.
- Bug reports: deleted approximately one year after resolution.
- Novel generation inputs and outputs: handled within the browser page and in memory while the Service’s generation API processes the request. The generation API does not store the text in a database, files or application logs. Reloading the browser page clears the story held on that page. Retention and training by OpenRouter and inference providers are separate and require verification for each provider and account setting (Sections 4 and 5).
- Backups: the storage location, retention period and timing of deletion-request propagation are currently unverified. Hosting the production service in Tokyo does not establish that backups are stored in the same location.
4. Disclosure of External Transmission (Telecommunications Business Act, Article 27-12)
The Service transmits user information to the following third parties. Each handles the data under their own privacy policy.
| Recipient | Data transmitted | Purpose / Provider · Country |
|---|---|---|
| Google Analytics | IP address, UA, page URL, Cookie ID, events | Web analytics Google LLC (USA) Privacy Policy |
| Google Sign-In | Authentication request, Google ID Token | Login authentication Google LLC (USA) Privacy Policy |
| GitHub OAuth | Authentication request, GitHub user ID, username, name, avatar URL, and email address | Login authentication GitHub, Inc. (USA) Privacy Statement |
| Discord OAuth | Authentication request, Discord user ID, username, display name, avatar URL, and verified email address | Login authentication Discord Inc. (USA) Privacy Policy |
| UptimeRobot status badge | IP address, browser and device information, and access time | Service-status display UptimeRobot s. r. o. (Slovakia) Privacy Policy |
| hCaptcha | IP address, UA, browser metadata, challenge response | Bot detection Intuition Machines, Inc. (USA) Privacy Policy |
| OpenRouter | Theme, characters, generation instructions, the full story for continuations, model selection and generation settings; sent by the Service’s server (the generation API does not forward the user’s IP address, browser information or login token) | AI generation OpenRouter Inc. (USA) Privacy Policy |
| Google STUN | Connection information such as source IP address and port | Video call connectivity discovery Google LLC (United States) Privacy Policy |
| Google Safe Browsing (when configured) | Original URL being shortened | URL safety checks Google LLC (United States) Privacy Policy |
For novel generation, OpenRouter also forwards the input and generation instructions described above to the provider running inference for the selected model. Free models are selected automatically, so the model and inference provider are not fixed. Retention and training conditions vary by provider and settings. See OpenRouter's explanation of provider data handling.
5. Cross-Border Transfer (APPI Article 28)
We transfer personal data to third parties located outside Japan as follows. Viewing this Policy or continuing to use the Service alone is not treated as consent to cross-border transfers. For novel generation, the generation page explains the information sent and the variable recipients, and requests checkbox consent before sending.
- United States — Google LLC, GitHub, Inc., Intuition Machines, Inc., OpenRouter Inc., Oracle Cloud Infrastructure (hosting in the Tokyo region, Japan)
The country listed above refers to the providers' location, not the location of data storage. The Service uses the Tokyo region of Oracle Cloud Infrastructure in Japan for hosting.
For information on the U.S. data-protection regime, please consult the resources published by the Personal Information Protection Commission of Japan. See the links in Section 4 for each provider’s data handling information. The hosting region confirmed by the operator is Tokyo, Japan. We have not uniformly verified providers’ certifications and their scope, or retention, training and protection measures for each downstream inference provider used by OpenRouter.
Free models are selected automatically based on availability and required capabilities at request time, so we cannot identify the actual inference provider or its country before sending. For reference, see the current free model list and provider information on each model page. Model developers and inference providers are not necessarily the same entity. We are still verifying the list of candidate providers’ countries, privacy systems and protection measures.
6. Security Measures
- Organizational: the operator is the designated person responsible for personal data handling.
- Personnel: the operator maintains awareness of proper personal-data handling.
- Physical: data hosted for the Service is stored in physically secured data centers in the Tokyo region of Oracle Cloud Infrastructure, Japan.
- Technical: traffic is encrypted with HTTPS / TLS, passwords are hashed, authentication tokens have a limited lifetime, and database access is restricted to authenticated credentials.
- Awareness of external environments: we use the Tokyo region in Japan for hosting. Sections 4 and 5 describe overseas transmissions and the status of our checks. Verification of downstream inference providers’ countries’ privacy systems and protection measures is not complete.
7. Breach Notification
If a security incident involving personal data (loss, leak, damage, etc.) occurs, we will promptly notify affected users and report to the Personal Information Protection Commission of Japan in accordance with the APPI and applicable guidelines.
8. Disclosure to Third Parties
We do not disclose your personal information to third parties except in the following cases:
- With your consent
- When required by law (court orders, lawful requests by police, etc.)
- To protect life, body, or property where it is impractical to obtain consent
- When sharing the minimum necessary data with service providers (Oracle Cloud and the providers in Section 4) needed to run the Service
9. Your Rights
You may request that we:
- Disclose the personal data we hold about you (including by electronic means)
- Correct, add to, or delete inaccurate information
- Cease use or erase data (APPI Article 35: including in cases of breach, completion of purpose, or improper acquisition)
- Stop sharing your data with third parties
- Disclose third-party-provision records (APPI Article 33(5))
- Delete your account
Please contact us using the address below. We will verify your identity and respond within a reasonable timeframe (in principle within 30 days).
10. Cookies and Similar Technologies
To maintain authenticated sessions, the Service stores authentication tokens in your browser's localStorage. You can clear these via the logout button or your browser's storage settings. Google Analytics 4 uses cookies and similar technologies to collect access information. According to Google, IP addresses are used to derive location information and then discarded before the data is stored. You may disable cookies in your browser, though some features may be limited as a result.
11. Pseudonymized / Anonymized Data
We do not currently create or handle pseudonymized or anonymized personal information as defined by the Japanese APPI. Hiding display names or unlinking accounts alone is not treated as establishing these legal categories. Information that still identifies an individual continues to be handled as personal information. If we begin creating or handling these statutory categories, we will update this Policy and publish the required disclosures.
12. Children's Privacy
Under Section 3 of the Terms, users under 18 need a legal guardian's consent to the agreement to use the Service. Where consent to personal-information processing is required, we assess whether the user can understand and judge its consequences in light of the information involved and the nature of the Service. If the user lacks sufficient capacity, consent must be obtained from a parent or other legal guardian. If we discover processing without required consent, we will take necessary action, including suspending use or deleting the information.
13. Changes to This Policy
We may revise this Policy from time to time. Material changes will be posted on this page with their effective date. Where a change in processing requires renewed consent under applicable law, we will obtain that consent separately rather than treating continued use as consent.
14. Complaints and Contact
For complaints or inquiries about how we handle personal information, please contact us. We will respond in good faith and without undue delay.
Personal-information handler: yopuru (sole proprietor)
Contact: umemotoy032@gmail.com
Privacy officer: the operator
The operator's full name and address will be disclosed without delay upon a lawful request, in accordance with applicable law.
If unresolved, you may also contact the Personal Information Protection Commission of Japan (https://www.ppc.go.jp/).