Skip to content
ひなた — hinata baby log 日本語
← Back to Hinata

Privacy Policy

Last updated: August 8, 2026

This is a courtesy translation. The Japanese original governs. 日本語の原文が正式な規約です。

Hinata (the "Operator") handles personal information in the childcare-record app "Hinata," its related websites, and accompanying features (collectively, the "Service") in accordance with this Policy. Because records about a baby and their family require particular care, we emphasize data minimization, limited purposes, accurate explanations, and appropriate safeguards.

Article 1 (Operator and Scope)

This Policy applies to the Operator's handling of personal information in the Service. The name of the business handling personal information is "Hinata." We will provide the Operator's address and, where applicable, representative's name without delay upon a verified request. Contact us at support@hinata.jp. External services are also governed by their providers' policies.

Article 2 (Information We Handle)

Depending on the features you use, the Service handles the following information on your device or in the Operator's systems. Not all information is always sent to the cloud.

  • Account information: email address, display name, authentication-provider identifiers, authentication method, and session information.
  • Family and caregiver information: Family membership, display name, relationship label, profile photo, invitations, and authorization information.
  • Baby profile: name, name reading, date of birth, sex, height, weight, and profile photo.
  • Childcare records: nursing, bottle feeding, sleep, diapers, temperature, symptoms, growth, solid foods, pumping, bathing, vaccinations, clinic visits, memos, journal entries, photos, entry times, and edit history.
  • Device and technical information: operating system, app version, per-device public key, settings, request ID, operational state, error codes, communication times, IP address, and other information needed for security and delivery.
  • Support information: email address, message content, attachments, and support history.

Article 3 (How We Obtain Information)

We obtain information from your entries, your selection of photos or audio, sharing by Family members, integrations with authentication services such as Apple, support requests, and automatic technical processing when you use the Service. Baby information is entered or shared by a caregiver. The Operator does not obtain content that is processed only on your device.

Article 4 (Purposes of Use)

We use information only as necessary for the following purposes:

  • Identity verification and management of authentication, Family membership, device keys, and accounts.
  • Providing childcare records, journals, charts, Family sharing, encrypted synchronization, notifications, and other features you choose.
  • Preventing misuse, maintaining security, responding to failures, and performing content-free operational monitoring.
  • Responding to support requests, sending important notices, and complying with legal obligations.
  • Improving quality and performance using aggregate information that does not contain individual or Family content.

Article 5 (Baby and Family Information)

Childcare records may contain health-related information and, depending on their content, information requiring special care under applicable law. You must confirm that you have lawful authority to enter, synchronize, or share information about a baby or another family member and have obtained any required consent. We do not use this information beyond what is necessary to provide the features you select.

Article 6 (On-Device Storage and Encrypted Sync)

Childcare records are first saved in a database on your device. Sensitive Baby and Family content selected for synchronization is encrypted on the device before it is sent to the cloud. The cloud stores ciphertext and only the minimum metadata needed for authentication, synchronization, conflict handling, and operations. The Operator does not receive a usable Family decryption key for routine synchronization. This does not mean that all data is stored only in Japan or that encryption is end-to-end without exception.

Article 7 (Family Sharing, Third-Party Disclosure, and Processors)

If you invite someone to your Family, that Family member can access the shared Family data. The Operator does not disclose personal data to a third party except with the individual's consent, as required by law, when necessary to protect a person's life, body, or property and consent is difficult to obtain, or as otherwise permitted by law. If we engage cloud, authentication, email-delivery, support, or other processors, we limit processing to what is necessary for the purpose and require appropriate protection through contracts and supervision.

Article 8 (Processing Outside Japan and External Services)

The Service uses external services such as Cloudflare, Apple, and Google Fonts, and information may be processed or stored outside Japan. The Operator does not guarantee Japan-only data residency. When required by law, we will provide information about the destination country, its privacy regime, and protective measures, and obtain any required consent. When an external service handles personal data, we require protections equal to or stronger than this Policy and appropriately supervise the provider.

Article 9 (Voice Logging and AI Features)

In the ordinary voice-logging flow, audio, transcripts, and pre-save suggestions are processed temporarily on your device, and only childcare records you confirm are saved. The public version currently does not enable a feature that sends Baby or Family records to a cloud AI service. Before offering a cloud AI feature in the future, we will update this Policy, disclose the recipient, data sent, purpose, retention period, and deletion method, and obtain any required consent. Exceptions for internal testing are governed by a separate disclosure and consent for eligible participants.

Article 10 (Website)

The official website does not use cookies, advertising trackers, or analytics services. Cloudflare may process IP addresses, access times, requested paths, and communication headers to deliver and protect the website. When your browser loads display fonts from Google Fonts, it sends Google an IP address and communication headers. The Operator does not use this information to create advertising profiles.

Article 11 (Retention and Deletion)

We retain information only as long as necessary to fulfill its purpose, maintain security, synchronize and back up data, resolve disputes, and comply with legal obligations, after which we delete or de-identify it. Retention differs for on-device data, synchronized records, deletion history, account information, support messages, and operational records. The in-app option to erase data on this device removes local data and sign-in state only; it does not delete cloud account information. Deleting an individual record, an entire Family, and an account are separate procedures.

Article 12 (Your Rights)

You or your lawful representative may request notice of purpose, access to retained personal data, correction, addition, deletion, restriction of use, erasure, or suspension of third-party disclosure as provided by law. Contact support@hinata.jp. After verifying the request, we will explain the applicable legal, technical, and Family-sharing boundaries and respond within a reasonable period. If the law does not permit us to fulfill a request, we will explain why.

Article 13 (Security Measures)

The Operator uses handling rules, access restrictions, authentication and authorization checks, encryption in transit, on-device encryption of sensitive cloud content, separation of keys, content-free operational logs, processor selection and supervision, incident response, and other safeguards appropriate to the risk. Upon request, we will explain these measures to the extent that doing so does not impair security.

Article 14 (Changes and Contact)

We will update this Policy when applicable law, features, or data practices change. We will clearly notify you of a material change in the app or on the official website before it takes effect and obtain renewed consent when required. For questions, complaints, or requests about personal information, contact support@hinata.jp.

We do not use Baby or Family data for advertising, sale to third parties, model training, or unrelated product analysis. Any such use would require separate explicit consent and a newly approved data-handling decision.

If you have any questions, please contact us at support@hinata.jp.

← Back to Hinata
ひなた · BABY LOG
Terms of Use Privacy Policy Contact

No cookies. No trackers.

© 2026 Hinata