[scan_id:stg_578s|PRIVACY]
>v2026-08-02 · 2026-08-02
01PRIVACY_POLICY

Privacy Policy

【要記入:運営者名/法人名】 ("we") sets out below how personal data is handled in Stegogram (the "Service"). The Service handles data about two kinds of people: registered users (campaign creators) and participants (people who decode campaigns).

1. Operator

Name: 【要記入:運営者名/法人名】

Address: 【要記入:所在地】

Representative: 【要記入:代表者名】

Contact: 【要記入:問い合わせ用メールアドレス】

2. Data we collect (registered users)

·Email address, display name, interface language

·Authentication identifier (Firebase UID)

·If two-factor authentication is enabled, its configuration and backup codes (stored hashed or encrypted)

·Signed-in device details: user agent, IP address, last used time — collected to detect new devices and guard against unauthorised access

·Subscription plan and Stripe customer identifier

·If you create an organisation: organisation name, legal name, country, currency, tax registration number and invoice details

·Images you upload and the campaign information you enter

·Organisation activity history (member changes, role changes, billing changes)

3. Data we collect (participants)

Depending on campaign settings and what the participant does:

·Email address — only where the creator has enabled collection, and only if entered; it is optional

·Nickname, if entered

·Decode records: when it was decoded, decode rank, reward claim status

·A share token, and the referring participant identifier when arriving via an invite

·Records of actions on the campaign (views, analysis runs)

·Discussion posts and the display name used, if you post

Decoding and claiming a reward do not require entering an email address.

4. Purposes

·Operating the Service, verifying identity, managing accounts

·Running campaigns and granting rewards to participants

·Producing analytics and statistics

·Detecting and preventing unauthorised access

·Billing and payment

·Responding to enquiries and sending important notices

·Improving the Service

5. Disclosure to third parties and processors

We do not disclose personal data to third parties except:

·With your consent

·Where required by law

We use the following providers to operate the Service, and data is transmitted to them:

·Google LLC (Firebase Authentication): authentication — email address, authentication identifier

·Stripe, Inc.: payment processing — email address and payment details. Card data is collected directly by Stripe; we never hold it

·Amazon Web Services, Inc.: media storage, where the S3 driver is enabled

·Email delivery provider: verification and notification emails

These providers may operate servers outside Japan, in which case personal data is transferred abroad.

6. Sharing participant data with campaign creators

Email addresses entered by participants, and their decode records, are made available to the creator of that campaign through:

·Display in the creator’s dashboard

·CSV download by the creator

Campaign creators handle participant personal data on their own responsibility, separately from us. Please contact the relevant creator regarding their handling.

7. Cookies and on-device storage

We store the following on your device (local storage, session storage, cookies):

·Authentication token, to keep you signed in

·Language preference

·Device identifier, to detect new devices for two-factor authentication

·Guide state, to control first-run tips and the checklist

·Participant identifier and referral token, to record campaign participation

These support the Service’s functionality. We do not use them for third-party advertising tracking.

8. Retention

Registered user data is kept while the account exists.

Participant data is kept while the relevant campaign exists; deleting a campaign deletes the associated participant records.

Where law requires records to be retained (e.g. transaction records), we keep them for the period required.

9. Your rights

On request we will disclose, correct, restrict or delete the personal data we hold about you. Contact 【要記入:問い合わせ用メールアドレス】.

Registered users can edit some of their information directly in the dashboard.

Participants wishing to have their data deleted may contact us or the relevant campaign creator.

10. Security

Traffic is encrypted.

We do not hold passwords; they are managed by our authentication provider (Firebase).

Two-factor secrets and backup codes are stored encrypted or hashed.

Organisation features restrict access according to the member’s role.

11. Changes to this policy

We may revise this policy.

For material changes we will notify you in the Service and ask you to agree again.