Privacy Policy
Version 2.0 · Effective 2026-05-11
# Privacy Policy
**Living SR&MA Platform**
**Version**: 2.0
**Effective Date**: 2026-05-11
**Last Updated**: 2026-05-11
> This document is the English-language version of the Privacy Policy, which is the **authoritative version**. A Japanese-language translation is in preparation. APPI Article 33 disclosure requests in Japanese can be made via email at info@yukifurukawa.jp. In the event of any conflict or inconsistency between the English and Japanese versions, the **English version shall prevail**.
---
## 1. Introduction
This Privacy Policy describes how Yuki Furukawa ("Operator", "we", "us", "our") collects, uses, stores, and protects your personal information when you use the Living SR&MA Platform ("Platform", "Service").
We are committed to protecting your privacy in compliance with:
- **GDPR** (General Data Protection Regulation) — for users in the European Economic Area (EEA)
- **UK GDPR** and the Data Protection Act 2018 — for users in the United Kingdom
- **APPI** (Act on the Protection of Personal Information) — Japan's personal information protection law
- Other applicable data protection laws
---
## 2. Data Controller
The data controller for the purposes of GDPR, UK GDPR, and APPI is:
**Yuki Furukawa** (古川由己)
Email: info@yukifurukawa.jp
Location: Japan
Operating context: Academic research project
The street address is not published. APPI Article 32 requirements to make the business operator's name and address available are satisfied by providing the address without delay on request to the privacy contact above.
For EEA and UK users: We do not currently maintain an EU representative under GDPR Article 27 or a UK representative under UK GDPR Article 27. We rely on the exemption in Article 27(2): our processing of EEA and UK residents' personal data is occasional, does not include large-scale processing of special categories of data (Article 9) or data relating to criminal convictions and offences (Article 10), and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope, and purposes of the processing. We will appoint representatives if and when our processing no longer meets these conditions.
### 2.1 Controller and Processor Roles
The Operator's role depends on the processing context:
| Processing Context | Role of the Operator | Notes |
|--------------------|----------------------|-------|
| Account registration, authentication, security monitoring, service administration, legal compliance, support, and Operator-side billing records | Controller | The Operator determines the purposes and means of this processing. |
| Project, team, screening, extraction, comment, reference, and knowledge-base content entered or imported by a project owner or project team | Processor | The Operator processes this content on the project owner's instructions to provide the Platform. The project owner, institution, or other organization using the Platform is the controller for this content. |
| Payment checkout and buyer payment data processed by Paddle if paid plans are enabled | Separate controller relationship | Paddle acts as Merchant of Record and controller/seller for buyer payment data. The Operator receives shared buyer and subscription data as a separate controller. Production paid checkout is pending. |
| User research data and PDFs stored in the user's own Supabase project under BYOK | Processor conduit for the project owner; Supabase is selected by the user | The user's own Supabase project is not a Platform subprocessor. The Platform does not store PDFs in Operator-controlled storage. |
**Team visibility.** When you are a member of a project, other members of the same project can view the data entered within that project, including your name and email address, so that the team can collaborate on the review. The Platform processes this data as a processor acting on the project owner's instructions.
Where the Operator acts as a processor, the processing is governed by the [Data Processing Agreement](/legal/dpa), which is incorporated into the [Terms of Service](/legal/tos) and applies automatically to controllers using the Platform.
---
## 3. Information We Collect
### 3.1 Information You Provide Directly
| Data Type | Examples | Purpose |
|-----------|----------|---------|
| Account information | Name, email address, profile picture (via Google OAuth) | Authentication, identification |
| Project data | Reference metadata, screening decisions, extraction data, knowledge base content | Core service functionality |
| BYOK credentials | Supabase URL/keys | Enabling BYOK storage features |
| Communications | Support requests, feedback | Customer support, service improvement |
### 3.2 Information Collected Automatically
| Data Type | Examples | Purpose |
|-----------|----------|---------|
| Log data | IP address, browser type, operating system, access timestamps | Security, debugging, analytics |
| Usage data | Pages visited, features used, session duration | Service improvement |
| Device information | Screen resolution, device type | Responsive design optimization |
### 3.3 Information We Do NOT Collect
- **Patient data**: The Platform handles research metadata (study-level data) only. We do not collect, process, or store individual patient data
- **Payment information**: Paid plans are not currently available in production. If paid plans are introduced, payment processing is expected to be handled by Paddle as Merchant of Record. We will not store credit card numbers or bank account details
- **Sensitive personal data**: We do not intentionally collect data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation (as defined by GDPR Article 9 and APPI "Special Care-Required Personal Information")
### 3.4 Platform Role and User Responsibility
The Platform is a **tool that assists users in organizing PDFs and managing research metadata** for systematic reviews and meta-analyses. The Platform does not independently collect, analyze, or make decisions about research data.
- **All research data provided through the Platform, including screening decisions, extraction data, knowledge-base content, and PDFs stored in the user's own BYOK Supabase project, remains the sole responsibility of the user or project owner.**
- The Platform does not store PDFs in Operator-controlled storage.
- The user is responsible for ensuring that their use of the Platform complies with applicable laws, institutional policies, copyright requirements, and ethical standards.
- The Platform does not verify the accuracy, legality, or appropriateness of user-uploaded content.
- The user assumes all risk associated with hosting research data online, including the risk of unauthorized disclosure or exposure through errors or the actions of third parties.
- Users shall indemnify the Operator against any claims arising from the content they upload to the Platform or their use of the Service.
### 3.5 Sources of Personal Data
Most personal data is provided directly by you when you sign in, configure a project, or use the Platform. Personal data may also be provided by project owners or administrators when they invite collaborators, including collaborator names and email addresses. Personal data may appear in imported bibliographic or reference metadata, including author names, affiliations, correspondence details, acknowledgments, or other study-level metadata. Notice is provided through the invitation flow, login flow, and this Privacy Policy.
---
## 4. How We Use Your Information
### 4.1 Legal Bases for Processing (GDPR)
| Purpose | Legal Basis |
|---------|-------------|
| Providing the Service | Performance of contract (Art. 6(1)(b)) |
| Account authentication | Performance of contract (Art. 6(1)(b)) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Service improvement and analytics | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (if any) | Consent (Art. 6(1)(a)) |
### 4.2 Purpose of Use (APPI)
In accordance with APPI, we specify the following purposes of use for personal information:
1. To provide and operate the Platform
2. To authenticate users and manage accounts
3. To communicate with users regarding the Service (support, updates, notices)
4. To maintain security and prevent unauthorized access
5. To analyze usage patterns and improve the Service
6. To comply with legal obligations
We will not use personal information beyond these specified purposes without obtaining your consent, except as permitted by APPI.
---
## 5. Data Sharing and Third Parties
### 5.1 Service Providers
We share personal information with the following service providers. The full list of subprocessors, including their region and DPA references, is published in the [Subprocessor Registry](/legal/subprocessors):
| Provider | Data Shared | Purpose |
|----------|-------------|---------|
| **Supabase** (Platform database) | Account data, project metadata, references, screening decisions, extraction records, audit data, and Operator-side billing records | Primary production PostgreSQL database in Tokyo (`ap-northeast-1`) |
| **Fly.io** (application runtime) | HTTP request and response payloads, session cookies, authentication tokens, and other data in transit through the application | Running the FastAPI application in Tokyo (`nrt`); no persistent personal-data store |
| **Cloudflare** (R2, Email Routing, KV, Workers) | Logical backup copies of the production database, operational-alert recipient addresses, and limited operational metadata | Cloudflare R2 stores `pg_dump -Fc` backup objects in the default jurisdiction (global edge, region `auto`) on a rolling 30-day retention cycle. Backup objects are protected by Cloudflare server-side encryption at rest; the dumps are not separately client-side encrypted. Cloudflare Email Routing is used for operational alerts. |
| **Brevo** (Sendinblue SAS) | Recipient email address and message body, which may include study titles, author information, invitation links, and notification content | Outgoing transactional email (screening invitations, notifications, magic-link login, the weekly newsletter, and service messages), processed within the European Union (France) |
| **Google OAuth** | OAuth token exchange data, email address, display name, and profile picture URL | User authentication and account profile retrieval. Google may act as an independent controller or processor as applicable to the OAuth processing context. |
| **Paddle** (production pending) | Buyer name, email address, billing address, subscription metadata, payment status, tax information, and payment dispute data | Paid-plan checkout, invoicing, tax handling, payment disputes, chargebacks, and refunds if paid plans are enabled. Paddle acts as Merchant of Record and controller/seller for buyer payment data; the Operator receives shared buyer and subscription data as a separate controller. |
### 5.2 BYOK Third Parties
When you use BYOK (Bring Your Own Key) features, data is shared with providers **you choose**:
- **Your Supabase instance**: User research data and PDF files you store under your own Supabase project
**Important**: Data shared with BYOK providers is governed by **their** respective privacy policies and your own contract with those providers. The Operator acts solely as a conduit for data transmission to BYOK services and assumes no responsibility for the processing performed by these user-selected providers. The user's own Supabase project is not a Platform subprocessor. We recommend reviewing those policies before configuring BYOK features.
### 5.3 We Do NOT
- Sell your personal information to third parties
- Share your data with advertisers
- Use your research data for our own research purposes without your explicit consent
- Provide your data to third parties for their marketing purposes
### 5.4 Legal Disclosure
We may disclose your information if required by law, court order, or government request, or if necessary to protect the rights, property, or safety of the Operator, users, or the public.
---
## 6. Data Storage and Security
### 6.1 Data Location
- **Production PostgreSQL database**: Supabase in Tokyo (`ap-northeast-1`, Japan), accessed through the Supabase session pooler
- **Application runtime**: Fly.io in Tokyo (`nrt`, Japan), processing data in transit only
- **Database backups**: Cloudflare R2 default jurisdiction (global edge, region `auto`), with `pg_dump -Fc` backup objects retained on a rolling 30-day cycle and protected by server-side encryption at rest
- **Transactional email**: Brevo SMTP relay (`smtp-relay.brevo.com`) operated by Sendinblue SAS, with processing within the European Union (France)
- **Operational-alert email routing**: Cloudflare Email Routing
- **BYOK Supabase**: Location determined by your Supabase project configuration
- **PDF storage**: The Platform does not store PDFs in Operator-controlled storage. PDFs are stored in the user's own Supabase project when BYOK storage is configured.
### 6.2 Security Measures
We implement the following security measures:
- HTTPS encryption for all data in transit
- Database encryption at rest
- BYOK credentials encrypted with application-level encryption before storage
- Role-based access control within projects
- Rate limiting to prevent abuse
- Regular security reviews
### 6.3 International Data Transfers
If you are located in the EEA or the United Kingdom, your personal data may be transferred to Japan and, for limited provider access or provider-controlled processing, to the United States, the United Kingdom, or other locations used by the relevant provider. We use the following transfer safeguards:
| Service | Main Processing Location | EEA Transfer Mechanism | UK Transfer Mechanism |
|---------|--------------------------|------------------------|-----------------------|
| **Supabase** (Platform database) | Tokyo (`ap-northeast-1`), Japan; provider is US-based | European Commission Japan adequacy decision for EEA-to-Japan data at rest; 2021 SCCs Module 2 and transfer impact assessment for US-parent access | UK adequacy regulations for Japan where applicable; UK Addendum to the EU SCCs or UK IDTA for restricted transfers involving US-parent access |
| **Fly.io** (application runtime) | Tokyo (`nrt`), Japan; provider is US-based | European Commission Japan adequacy decision for Tokyo runtime processing; 2021 SCCs Module 2 and DPF safeguards for US-parent access | UK adequacy regulations for Japan where applicable; UK Addendum to the EU SCCs or UK IDTA for restricted transfers involving US-parent access |
| **Cloudflare R2 / Email Routing / KV / Workers** | R2 default jurisdiction (global edge, region `auto`); provider is US-based | Cloudflare DPA with EU SCCs; DPF safeguards where applicable | Cloudflare DPA with UK Addendum to the EU SCCs or UK IDTA, as applicable |
| **Google OAuth** | Global; provider is US-based | DPF certification and SCC safeguards; Google may act as an independent controller or processor as applicable | UK Extension to the DPF where applicable and UK Addendum to the EU SCCs or UK IDTA, as applicable |
| **Paddle** (production pending) | United Kingdom / global | EU-UK adequacy decision for EEA-to-UK processing; Paddle DPA and Data Sharing Addendum; SCCs for onward restricted transfers where applicable | UK processing by a UK Merchant of Record; UK Addendum to the EU SCCs or UK IDTA for onward restricted transfers where applicable |
| **Brevo** (Sendinblue SAS) | European Union (France) | Primary hosting and processing within the EU (France/Belgium); onward access by Brevo group sub-processors outside the EEA is covered by the EU-U.S. Data Privacy Framework and SCCs per Brevo's DPA | UK adequacy regulations for the EEA cover UK-to-EU transfers; UK Addendum to the EU SCCs or UK IDTA if an onward restricted transfer is introduced |
**BYOK Supabase storage**: User research data and PDF files may be stored in a Supabase project of your choice, in a region you select. The Operator transmits the data to your selected Supabase project but does not control where it is persisted. You are responsible for ensuring that your chosen region and provider contract meet your applicable data protection requirements.
No LLM provider receives personal data in the current production configuration.
---
## 7. Data Retention
### 7.1 Active Accounts
We retain your data for as long as your account is active and as necessary to provide the Service.
### 7.2 Self-Service Deletion (GDPR Art. 17 / APPI Arts. 34–35)
You can request deletion of your account at any time from the Account Settings page (`/account`). The process operates on a **14-day grace period** that you can cancel at any time during the period:
- **Immediately on request**: BYOK API keys, including Supabase service role keys and any other BYOK secrets if present, are wiped — these cannot wait the grace period because the keys grant ongoing access to third-party data.
- **During the 14-day grace period**: You remain logged in normally and can cancel deletion by visiting the Account Settings page.
- **After 14 days**: Your personal data is anonymized and cannot be recovered. Your user record is replaced with `[deleted user]`, and your identifier is replaced everywhere it appears; in the administrative audit log your IP address and user agent are also erased. What remains is the *content* of records you created, with you detached from them: your past comments, your screening and extraction decisions, the amendment history of those decisions, and the administrative audit entries all stay in place showing `[deleted user]`. We keep those record bodies for legal recordkeeping under GDPR Article 17(3)(e) (legal claims), for applicable cybersecurity audit obligations, and — for review decisions specifically — because deleting them would make your team's published systematic review unverifiable and would break the rest of the team's record (Article 6(1)(f), legitimate interests). See the [Data Retention Policy](/legal/retention) §2.4 for the exact tables and treatment.
### 7.3 Retention Periods
The detailed retention schedule for each data category is published in the [Data Retention Policy](/legal/retention). Highlights:
- **User Data** (project data, screening decisions): Retained while the account is active. Anonymized 14 days after the deletion request.
- **Account information** (email, name): Anonymized 14 days after the deletion request.
- **Administrative and security audit logs**: After 2 years the actor is removed — the user identifier, IP address, and user agent are erased — while the record of what action was taken is kept for legal recordkeeping (Art. 17(3)(e) exception). These logs are append-only, so expiry takes the form of anonymization rather than deletion.
- **Review-decision records** (decision amendments, extraction edit history): Retained for the lifetime of the project, with no time-based expiry, so that the provenance of a systematic review stays verifiable (Art. 17(3)(e) and Art. 6(1)(f)). They are deleted when the project itself is deleted. Your identifier in them is replaced when your account is deleted.
- **Reference status history**: Deleted after 2 years. It contains no personal identifier.
- **Application and error logs**: Application logs are rotated by the hosting provider after approximately 30 days; error and exception logs are retained for up to 90 days.
- **Backup copies**: Production database backups are `pg_dump -Fc` logical backup objects stored in Cloudflare R2 on a rolling 30-day retention cycle. Anonymized or deleted data may persist in backup snapshots until the 30-day rotation deletes the relevant backup object. We do not selectively erase individual records from existing backup snapshots, and we do not restore deleted data from backups except where necessary for disaster recovery.
### 7.4 Legal Retention
We may retain certain data longer if required by law (e.g., tax records, legal dispute evidence).
---
## 8. Your Rights
### 8.1 GDPR and UK GDPR Rights (EEA and UK Users)
If you are located in the EEA or the United Kingdom, you have the following rights:
| Right | Description |
|-------|-------------|
| **Access** (Art. 15) | Request a copy of your personal data |
| **Rectification** (Art. 16) | Request correction of inaccurate data |
| **Erasure** (Art. 17) | Request deletion of your data ("right to be forgotten") |
| **Restriction** (Art. 18) | Request restriction of processing |
| **Portability** (Art. 20) | Receive your data in a structured, machine-readable format |
| **Objection** (Art. 21) | Object to processing based on legitimate interest |
| **Withdraw consent** (Art. 7) | Withdraw consent at any time (where processing is based on consent) |
To exercise these rights, contact us at info@yukifurukawa.jp. We will respond within one month (extendable by up to two further months for complex or numerous requests, in which case we will inform you of the extension and its reasons within the first month).
### 8.2 APPI Rights (All Users in Japan)
Under APPI, you have the right to:
- Request disclosure of your personal information held by us
- Request correction, addition, or deletion of inaccurate personal information
- Request cessation of use or deletion if personal information was obtained improperly or used beyond the specified purpose
- Request cessation of third-party provision
### 8.3 Data Export
All users, regardless of location, can export their User Data through the Platform's built-in export features at any time.
### 8.4 US State Privacy Disclosures
We do not currently meet the applicability thresholds of US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA, the Virginia Consumer Data Protection Act, or similar state statutes (for example, their annual revenue and consumer-volume thresholds). Regardless of applicability, we do not sell or share personal information as those terms are defined under those laws, we do not use personal information for cross-context behavioral or targeted advertising, and we do not use sensitive personal information beyond what is necessary to provide the Service. US residents may contact us at info@yukifurukawa.jp with privacy requests; we honor access, deletion, and correction requests through the same process described in this Policy.
---
## 9. Cookies and Tracking
### 9.1 Essential Cookies
We use session cookies that are strictly necessary for the Platform to function (e.g., authentication session tokens). These cookies cannot be disabled.
### 9.2 Analytics
We currently do not use third-party analytics services or tracking cookies. If we introduce analytics in the future, we will update this Privacy Policy and obtain consent where required.
### 9.3 Browser Tracking Signals
The Platform does not use non-essential tracking cookies or third-party analytics. Because we do not use those tracking technologies, browser "Do Not Track" signals do not change Platform behavior.
---
## 10. Automated Decision-Making and Profiling
We do not subject you to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects (GDPR Article 22 and, to the extent they apply, equivalent concepts under US state privacy laws such as the CPRA's automated decision-making technology rules).
The Platform may surface heuristic suggestions (e.g., screening prioritization or RoB pre-judgments) generated by rule-based algorithms. **All such suggestions are advisory only.** A human reviewer (you or your team) must make and record the final decision. The Platform stores both the algorithmic suggestion and the human decision separately so that the audit trail clearly attributes the final outcome to a person.
If we ever introduce a feature that performs solely automated decision-making with legal or similarly significant effects, we will update this Privacy Policy and obtain explicit consent before enabling it.
---
## 11. Children's Privacy
The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
---
## 12. Data Breach Notification
### 12.1 GDPR and UK GDPR (EEA and UK Users)
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority, including the UK ICO where applicable, within 72 hours of becoming aware of the breach
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms
### 12.2 APPI (Japan)
In the event of a data breach involving personal information, we will:
- Notify the Personal Information Protection Commission (PPC) promptly
- Notify affected individuals promptly
- Take measures to prevent recurrence
### 12.3 United States
In the event of a data breach affecting US residents, we will notify affected individuals in accordance with applicable state data breach notification laws, and will notify state regulators where required (for example, the California Attorney General where 500 or more California residents are affected).
---
## 13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the version number and effective date
- We will notify you through the Platform (e.g., a notification at login)
- We will provide a summary of changes
Your continued use of the Platform after notification constitutes acceptance of the updated Privacy Policy.
---
## 14. Contact and Complaints
### 14.1 Contact
For privacy-related inquiries or to exercise your rights:
**Yuki Furukawa** (古川由己)
Email: info@yukifurukawa.jp
### 14.2 Complaints
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with:
- **EEA users**: Your local data protection supervisory authority
- **UK users**: The UK Information Commissioner's Office (ICO) — https://ico.org.uk/
- **Japan users**: The Personal Information Protection Commission (PPC) — https://www.ppc.go.jp/
---