Privacy Policy
Last updated: August 13, 2026 (version 1)
This page explains what information FTFT (From Tanu-chan, For Tanu-chan) handles and how we protect it. We have tried to write it in plain language.
Who runs this site
This site is run as a non-profit personal project. There are no ads and nothing is sold. You can reach us at contact@tanuchan.org. If the project incorporates as a legal entity, the entity name will be added to this page.
What information we collect
For regular browsing we collect only anonymous totals, such as how many times a page was viewed. We do not build records that identify individual visitors. The contact form sends us what you typed. For Letters we handle the letter text, your anonymous access code, consent records, and safety device data (your IP address is never stored as-is, only in a scrambled form that cannot be reversed). For volunteers we hold an email address and a profile. Data from on-device features like the Memory Jar is never sent to our servers.
What we use it for
Aggregate data is used only to improve the site. Contact messages are used only to reply and follow up. Letter text is reviewed only for the pre-delivery safety check and for urgent-situation response. Device data is used only to keep suspended people from re-entering. We use nothing for any other purpose, and never for advertising.
Information about your mental state
Letters can contain very sensitive content about your mental state (what the law calls special care-required personal information). We handle only what you choose to write yourself, based on the consent you give before using the feature. We never try to draw it out of you.
Who reads the letters
Letters are reviewed for safety by the operator (internal only) before delivery. No outside company staff read them. Every review is logged so it can be proven afterwards. The full mechanism is public on our transparency page.
Companies we share data with
We never share data for sale or advertising. To run the site we use services from the companies below.
| Company | Country | What is shared | Purpose |
|---|---|---|---|
| Google (Google Cloud / Firebase) | Data is stored in Japan (Tokyo region). Sign-in authentication may be processed on Google servers outside Japan, such as the US | Letter contents, volunteer account information such as email addresses, and anonymous aggregate counts | Used as our database and sign-in system |
| Anthropic | United States | For Letters, the text of each letter for a pre-delivery safety check, together with that exchange's recent letters as context for the check (normally the last 8; when one person has sent many in a row, the context reaches back to include the other person's most recent letter). Also, only when a reader taps 'See translation', the text of that letter | For automated safety screening, and for translation only when a reader chooses it. Under the API terms, content sent is not used to train AI models |
| Brevo | France (EU) | Alert emails sent to the operator in urgent situations. These can include an excerpt of a letter for safety reasons | To reliably deliver urgent-response notifications |
| Vercel | A US company. Our server processing runs in the Tokyo region | All traffic needed to serve the site, as our hosting provider | To host and run the site |
| Formspree | United States | What you type into the contact form | To deliver contact-form messages to the operator |
| Mapbox | United States | Connection information such as your IP address when a map is shown | To display the map on the places pages |
Data sent to companies outside Japan
As the table shows, some processing happens on servers of US and EU companies. Each case is work we entrust to run the site, under terms that include confidentiality. For the automated safety check of letters (Anthropic, a US company), we ask for your separate consent before you start. The list of what your browser sends directly to outside companies is on our External Transmission page.
How long we keep things
Retention periods for each kind of information are as follows.
| Information | Kept for |
|---|---|
| Letters (the messages) | Fully deleted 12 months after the exchange ends |
| Letters safety records (review logs, access logs, suspension records) | As long as needed to run the service safely |
| Memory Jar and other on-device data | Never sent to our servers. It stays on your device only |
| Site analytics (anonymous totals) | Kept as totals. They contain nothing that can identify a person |
| Contact-form messages | As long as needed to respond |
Requesting access, correction, or deletion
You can request access to, correction of, or deletion of your information at any time by writing to contact@tanuchan.org. We aim to reply within two weeks. Takedown requests for published content go to the same address, and every request and outcome is logged. Note that letter writers use only an anonymous access code, so even the operator holds nothing that can identify them. If you lose your code, there is no way to verify the link between you and those letters.
If a leak ever happens
If a data leak ever occurs, we follow our incident procedure to contain it immediately, report to Japan's Personal Information Protection Commission as required by law, and notify the people affected.
Revision history
- August 13, 2026: first version published