FTFT

Privacy Policy

Last updated: August 13, 2026 (version 1)

This page explains what information FTFT (From Tanu-chan, For Tanu-chan) handles and how we protect it. We have tried to write it in plain language.

Who runs this site

This site is run as a non-profit personal project. There are no ads and nothing is sold. You can reach us at contact@tanuchan.org. If the project incorporates as a legal entity, the entity name will be added to this page.

What information we collect

For regular browsing we collect only anonymous totals, such as how many times a page was viewed. We do not build records that identify individual visitors. The contact form sends us what you typed. For Letters we handle the letter text, your anonymous access code, consent records, and safety device data (your IP address is never stored as-is, only in a scrambled form that cannot be reversed). For volunteers we hold an email address and a profile. Data from on-device features like the Memory Jar is never sent to our servers.

What we use it for

Aggregate data is used only to improve the site. Contact messages are used only to reply and follow up. Letter text is reviewed only for the pre-delivery safety check and for urgent-situation response. Device data is used only to keep suspended people from re-entering. We use nothing for any other purpose, and never for advertising.

Information about your mental state

Letters can contain very sensitive content about your mental state (what the law calls special care-required personal information). We handle only what you choose to write yourself, based on the consent you give before using the feature. We never try to draw it out of you.

Who reads the letters

Letters are reviewed for safety by the operator (internal only) before delivery. No outside company staff read them. Every review is logged so it can be proven afterwards. The full mechanism is public on our transparency page.

Companies we share data with

We never share data for sale or advertising. To run the site we use services from the companies below.

CompanyCountryWhat is sharedPurpose
Google (Google Cloud / Firebase)Data is stored in Japan (Tokyo region). Sign-in authentication may be processed on Google servers outside Japan, such as the USLetter contents, volunteer account information such as email addresses, and anonymous aggregate countsUsed as our database and sign-in system
AnthropicUnited StatesFor Letters, the text of each letter for a pre-delivery safety check, together with that exchange's recent letters as context for the check (normally the last 8; when one person has sent many in a row, the context reaches back to include the other person's most recent letter). Also, only when a reader taps 'See translation', the text of that letterFor automated safety screening, and for translation only when a reader chooses it. Under the API terms, content sent is not used to train AI models
BrevoFrance (EU)Alert emails sent to the operator in urgent situations. These can include an excerpt of a letter for safety reasonsTo reliably deliver urgent-response notifications
VercelA US company. Our server processing runs in the Tokyo regionAll traffic needed to serve the site, as our hosting providerTo host and run the site
FormspreeUnited StatesWhat you type into the contact formTo deliver contact-form messages to the operator
MapboxUnited StatesConnection information such as your IP address when a map is shownTo display the map on the places pages

Data sent to companies outside Japan

As the table shows, some processing happens on servers of US and EU companies. Each case is work we entrust to run the site, under terms that include confidentiality. For the automated safety check of letters (Anthropic, a US company), we ask for your separate consent before you start. The list of what your browser sends directly to outside companies is on our External Transmission page.

See the External Transmission page

How long we keep things

Retention periods for each kind of information are as follows.

InformationKept for
Letters (the messages)Fully deleted 12 months after the exchange ends
Letters safety records (review logs, access logs, suspension records)As long as needed to run the service safely
Memory Jar and other on-device dataNever sent to our servers. It stays on your device only
Site analytics (anonymous totals)Kept as totals. They contain nothing that can identify a person
Contact-form messagesAs long as needed to respond

Requesting access, correction, or deletion

You can request access to, correction of, or deletion of your information at any time by writing to contact@tanuchan.org. We aim to reply within two weeks. Takedown requests for published content go to the same address, and every request and outcome is logged. Note that letter writers use only an anonymous access code, so even the operator holds nothing that can identify them. If you lose your code, there is no way to verify the link between you and those letters.

If a leak ever happens

If a data leak ever occurs, we follow our incident procedure to contain it immediately, report to Japan's Personal Information Protection Commission as required by law, and notify the people affected.

Revision history

  • August 13, 2026: first version published