Nomicho Privacy Policy (International)
Operator: Chris Hashimoto (橋本クリス), sole proprietor Trade name: Nomicho Address: Disclosed without delay upon request (contact support@nomicho.jp) Contact: support@nomicho.jp Effective date: 2026-09-06 Last updated: 2026-09-06 Version: 1.0
1. Introduction
Nomicho (“the App”) is a personal journal application that helps you record, reflect on, and predict the impact of your own drinking. This policy describes what personal data Chris Hashimoto (“we”, “us”) collects when providing the App to users outside Japan and the United States, how it is used, where it is stored, when it is disclosed, and what rights you have over it.
For the purposes of data-protection law, we are the controller of the personal data described here.
The App is a tool for self-recording and self-reflection. It is not a medical device and does not provide medical advice, diagnosis, or treatment; it does not measure, diagnose, or monitor intoxication or any medical condition (see Terms of Service §4.2 / §4.3).
We are based in Japan. Nomicho is operated by a sole proprietor located in Japan, and the App’s servers are located in Japan. Using the App means your data is transferred to and stored in Japan. See §4.
This policy applies to users whose home region is neither Japan nor the United States. Users in those two countries are served separate policies written to their own law. Home region follows your App Store storefront, falling back to your device’s region setting, not where you happen to be travelling; if it changes, the App will ask you to review and accept the other set of documents.
2. Information we collect
What we collect depends on how you use the App. Most of it never leaves your device.
2.1 Information stored on your device
Some of this is required for core functionality; the BAC profile fields are collected only if you choose to set one up. Stored in a local database (SQLite) on your device. Nothing in this section leaves the device unless you explicitly enable cloud sync.
- Date of birth — used to age-adjust blood alcohol concentration (BAC) estimates. Collected when you set up your BAC profile, not at first launch.
- Body weight and sex — used as coefficients in BAC estimation. The “sex” field asks which physiological response pattern best matches you, not your registered legal sex.
- Height, alcohol-flush tendency, and drinking frequency — further coefficients for the BAC estimate, collected with your BAC profile.
- Drink logs — drink type, volume, ABV, time logged, session metadata, optional notes and feeling tags.
- Acceptance records — which version of these documents you accepted, when, in which language, under which App version, and under which country’s legal regime. Kept as proof of the agreement between us.
2.2 Account information (collected when you sign in)
Signing in is optional. The App is fully usable without an account. You sign in only to attach your data to an account, which is what makes cross-device sync possible (sync itself is a further, separate opt-in). Signing in creates an account record on our authentication service even if you do not turn on sync.
- Sign in with Apple — Apple’s stable user identifier and the email address Apple returns. If you choose “Hide My Email,” that address is an
@privaterelay.appleid.comrelay address; we store it as received and cannot resolve it to your underlying address. Your display name is provided by Apple on the first sign-in only. - Sign in with Google — Google’s stable user identifier, your verified Google email address, and your display name.
- Sign in with LINE — an opaque user identifier specific to the App and, if you have allowed it, your LINE display name. We do not request your email address from LINE, so no LINE email address is stored, and we store no LINE access token: the sign-in confirms your identity only and makes no further calls to LINE.
Email addresses are stored in plain text, not hashed, because they are required for the sign-in flow itself.
One account, multiple sign-in methods. From Settings → Account you can connect more than one provider to a single Nomicho account; the connected methods then share one account and one set of data.
2.3 Information sent unless you opt out
The following are enabled by default. You can opt out of either individually from Settings at any time.
- Crash reports (Sentry) — technical logs sent when the App crashes (OS version, stack trace, anonymous device identifier). Drink data is not sent.
- Product analytics (PostHog) — event logs (screen transitions, button taps) tied to a device-scoped pseudonymous identifier, not to your name, email, or account (§2.4), plus a small set of non-identifying app settings attached to that device profile, such as your language and which features you have switched on. No drink content and no body data is sent, and none of it is ever linked to your account.
2.4 Identifiers and device information
While the §2.3 services are enabled, each issues a device-scoped pseudonymous identifier. These identifiers do not directly identify you.
-
They are used solely to associate crash reports or analytics events with a single device for reliability and product-improvement purposes.
-
Sentry and PostHog do not receive your account identifier (§2.2) or your drink logs from the App.
-
You can rotate to a new identifier by opting out of the service in Settings and reinstalling the App.
-
Push notification token — if you allow notifications, your device receives a token from Firebase Cloud Messaging (Google) that lets us deliver a notification to that device. It identifies the device installation, not you. It is stored with your account when sync is on, and removed when you delete your account or turn notifications off.
The App does not use cookies. The Sentry and PostHog SDKs store the above identifiers in device-local storage.
2.5 What we do not collect
The App does not access contacts, address book, or SMS content; microphone recordings; your photo library except for photos you add yourself (§2.10); or your location except when you turn on the optional location feature (§2.9). The camera is used to scan barcodes and to take photos you choose to attach; nothing is captured without your action.
2.6 Feedback you submit (optional)
If you send feedback from Settings → Feedback, we receive the message you write, an optional category, and an optional contact email if you provide one so we can reply. We also receive your App version, language setting, and a device-scoped identifier. Because sending feedback is an action you take deliberately, this is sent even when cloud sync is off. We use it only to reply to you and to improve the App.
2.7 Apple Health data (optional, iOS only)
If you grant permission, the App reads Apple Health data to auto-fill your BAC profile (sex, date of birth, height, weight) and to refine hangover forecasts using sleep and heart data. If you enable it in Settings, the App also writes your logged drinks (standard-drink count, calories, sugar) to Apple Health.
Apple Health data is processed on your device only. It is never uploaded to our servers, never synced, never sent to any AI provider, and never included in analytics. Health-sourced profile values (weight and so on) become ordinary BAC-profile fields and follow §2.1.
2.8 Our website
Our website is covered by a separate notice on the site itself. In short: we collect an email address only from people who ask to be notified about the App, and use it only for that; we measure page views with cookieless, aggregate analytics; and we set no cookies and do no cross-site or individual-level tracking. The website collects no account or drink data.
2.9 Location data (optional)
Location is off by default, and nothing is captured until you turn it on in Settings. When enabled, the App attaches a place (a label and map coordinates) to drinks you log, and, only if you also choose the “session journey” option, records a simplified route while the App is open during a session. Nothing is recorded in the background or outside a session. You can also type a place by hand at any time without granting location permission.
Location data is stored on your device first. It is uploaded only if you enable cloud sync, in which case it is stored with your other synced data under the same protections (§4.2), included in your data export, and removed by account deletion. Location data is never included in analytics, never sent to any AI provider, and never sold, shared, or disclosed for advertising. You can edit or delete individual place tags, and turning the feature off stops all capture immediately.
2.10 Photos (optional)
You can attach photos to your sessions and drinks, taken with the camera or picked from your photo library. Nothing is captured until you choose to add one. Photos are downscaled and re-encoded, which strips embedded EXIF location data, and stored on your device. They are never sent to any AI provider and never included in analytics.
If you turn on photo backup (a Nomicho Plus feature, off by default, available only while cloud sync is on), your photos are uploaded to private cloud storage accessible only to your account, restored to your other signed-in devices, and removed by account deletion. Deleting a photo in the App also removes its backup copy.
2.11 Lock Screen forecast (optional, iOS only)
The Live Activity is off by default. When you turn it on, the App shows your session on the Lock Screen and in the Dynamic Island. So that the card keeps updating while your phone is locked, which the App cannot do on its own because it does not run in the background, your forecast is sent to our server: the projected BAC curve for the current session, your drink count and grams of pure alcohol, the predicted peak and hangover tier, your pace status if pacing mode is on, and your language setting.
It does not include what you drank, where you were, when you ate, your name, your email, or your account. The record is identified only by a random per-installation identifier and is never linked to an account, so it is sent whether or not you are signed in.
It is retained only while the card is running and deleted when the card ends, and in all cases no later than 2 hours after the session’s projected end time, so that a record still disappears if the App is deleted or never reopened. Turning the Live Activity off deletes it immediately.
3. Why we use your data, and on what legal basis
We use collected data only for the following purposes. The “basis” column states the ground we rely on where your country’s law requires one to be identified, using the terms used in European data-protection law.
| Purpose | Data involved | Basis |
|---|---|---|
| Core App functionality — storing drink logs, estimating BAC, calendar and journal display | §2.1 | Performance of our contract with you (the Terms) |
| Cloud sync across your devices | §2.1, §2.9, §2.10 | Performance of the contract, activated by your opt-in |
| AI reflection cards | Aggregate session metrics (§5.1) | Performance of the contract |
| Account creation and sign-in | §2.2 | Performance of the contract |
| Reliability — crash reports | §2.3, §2.4 | Our legitimate interest in a working App, subject to your opt-out |
| Product improvement — analytics | §2.3, §2.4 | Our legitimate interest in improving the App, subject to your opt-out |
| Push notifications | §2.4 | Your consent, given through the OS permission prompt |
| Apple Health integration | §2.7 | Your explicit consent, given through the OS permission prompt |
| Location tagging | §2.9 | Your consent, given in Settings and the OS permission prompt |
| Photo diary and photo backup | §2.10 | Your consent, given by adding a photo and by enabling backup |
| Lock Screen forecast | §2.11 | Your consent, given by turning the feature on |
| Responding to feedback | §2.6 | Your consent, given by sending it |
| Keeping proof of which documents you accepted | Acceptance records (§2.1) | Our legitimate interest in being able to evidence the agreement |
| Responding to legally compelled requests | As compelled | Compliance with a legal obligation |
Data about your drinking may count as health data in your country. Where it does, we rely on your explicit consent, which you give by choosing to record it. You can withdraw that consent at any time by deleting the data or your account (§6); withdrawal does not affect processing that already happened.
Where we rely on legitimate interests, you have the right to object — see §6.
We do not use collected data for any other purpose. We do not use it for advertising, third-party marketing, profiling for targeted advertising, or repurposing into other services. We do not use it to train AI models, and our AI provider is contractually barred from doing so (§5.1). We make no decisions about you by automated means that produce legal or similarly significant effects.
4. Where your data is stored, and international transfer
4.1 Local storage (default)
By default, all drink records and body information are stored only on your device. They are not accessible to us or to any external party. (The one exception is the Lock Screen forecast in §4.4, if you turn that feature on.)
- Accounts you are no longer signed into. If you sign out of an account on a device and do not sign back into that account on that device for 60 days, its local copy is removed from that device. This is so an account that signed in once, for example on a friend’s phone, does not leave your records there indefinitely. It never affects the account you are currently using: simply not opening the App for a while, however long, deletes nothing. If you use the App without an account, nothing is ever removed this way. Data you had synced re-downloads when you sign back in; anything logged offline and not yet synced cannot be recovered.
4.2 Cloud storage (only when sync is enabled)
Your data is stored in Japan. If you enable sync, the relevant data is stored in:
- Supabase Postgres (Tokyo region,
ap-northeast-1) — drink records, body information, session metadata, and, only if you use the optional location feature, place tags and session route points. Row-Level Security ensures each user can access only their own data. - Supabase Storage (same Tokyo region) — photo image files, only when you enable photo backup (§2.10). Objects are private to your account.
Supabase is operated by Supabase, Inc., a US company, under a Data Processing Agreement, but the App’s data is physically stored in Japan.
4.3 What transferring data to Japan means for you
Japan has a comprehensive privacy statute of general application: the Act on the Protection of Personal Information (APPI), overseen by the Personal Information Protection Commission, an independent regulator. It applies to us as a Japanese operator.
If you are in the European Economic Area or the United Kingdom, this transfer does not depend on contractual safeguards: the European Commission and the United Kingdom have each formally recognised Japan as providing an adequate level of protection for personal data, so data may flow to Japan on the same footing as within Europe.
Some of our service providers are in the United States (§5.1). Adequacy covers the transfer to us in Japan, not those onward transfers, which are made under the Standard Contractual Clauses in each provider’s Data Processing Agreement.
Japanese authorities may compel disclosure of data held in Japan under Japanese legal process. Your rights under §6 are honoured regardless of where the data sits.
4.4 Temporary storage for the Lock Screen forecast
While the Live Activity (§2.11) is enabled, its forecast is stored in Supabase Postgres (Tokyo region). If you are not signed in, this is the only data of yours that exists on any server. If you are signed in with sync turned off, it is the only content of yours on any server: your account record (§2.2) still exists on our authentication service, and your device registration exists if you have enabled notifications (§2.4). It is not linked to an account. Retention is as stated in §2.11.
5. Disclosure to third parties
5.1 Service providers
We engage the following service providers, each acting as our processor. Each processes data only on our instructions and for the purposes listed.
| Provider | Purpose | Data sent | Retention |
|---|---|---|---|
| Anthropic, PBC (US) | Reflection-card text generation | Aggregate session metrics only (drink count, total pure-alcohol grams, category counts, peak feeling, duration, optional hangover-severity estimate). No photos, no free-text notes, no profile or body data, no location. | Under a Zero Data Retention agreement, inputs and outputs are not retained after the request is processed. |
| Supabase, Inc. (US company; data stored in Japan) | Cloud storage for synced data | The §2.1 / §2.9 / §2.10 data you have chosen to sync | While the account is active; deleted on account deletion |
| Sentry (US) | Crash reports | OS info, stack trace, anonymous device identifier | 30 days |
| PostHog (EU) | Product analytics | Event logs and the §2.3 settings flags | 1 year |
| Google LLC / Firebase (US) | Push notification delivery, app attestation, feature configuration | Push notification token, device installation identifier, and the notification text we send you. No drink content, body data, or estimates. | While notifications are enabled |
Sentry and PostHog are each on by default; you can opt out of either individually from Settings.
Calls to Anthropic are routed through a proxy we operate. The App never communicates with Anthropic’s API directly from your device. The proxy enforces rate limits, daily spending caps, and device attestation.
5.2 We do not sell or share your personal data
We have never sold personal data, and we do not share it for behavioural advertising. We do not disclose personal data to advertisers, data brokers, ad networks, or any third party for marketing purposes.
We disclose personal data outside §5.1 only:
- when required by law, such as a valid court order or law-enforcement request; or
- when necessary to protect the life, body, or property of any person and obtaining your consent is not practicable.
5.3 Third-party collection across sites
We do not permit third parties to collect personally identifiable information about your online activities over time and across different websites or online services when you use the App.
6. Your rights
We offer the following rights to every user this policy covers, regardless of which country you live in and whether a given law applies to us by its own terms.
- Access — obtain confirmation of whether we hold data about you, a copy of it, and the information in this policy about how it is used. Settings → Export Data downloads the data you contributed (drink logs, sessions, feeling check-ins, custom presets, BAC profile, acceptance records) as JSON immediately, without contacting us. The export covers everything you contributed except photo image files, which cannot travel in a JSON document: your photos are on your device, and if you use photo backup we will provide the stored image files on request. Operational records (sync state, device registrations, sign-in internals, notification toggles) are not in the export; ask us and we will provide them.
- Rectification — drink logs, notes, place tags, and profile values can be edited directly in the App at any time. For anything you cannot reach in the App, ask us.
- Erasure — Settings → Delete Account. Data on the device is deleted immediately. Cloud data may persist briefly in backups and replicas; full deletion completes within 30 days at the latest. Account identifiers held by your sign-in provider are managed under that provider’s own policies.
- Portability — the JSON export above is a structured, commonly used, machine-readable copy of the data you provided, and you are free to move it elsewhere.
- Restriction — ask us to limit how we use your data while a dispute about its accuracy or our basis for using it is resolved.
- Objection — object to processing we base on legitimate interests (crash reports and analytics). You do not need to write to us to exercise this for either: both can be switched off in Settings at any time, which stops the collection immediately.
- Withdraw consent — for anything we do on the basis of consent (notifications, Apple Health, location, photos, Lock Screen forecast), turn the feature off in Settings or in your OS settings. Withdrawal does not affect processing that already happened.
- No discrimination for exercising a right — we will not deny you service, charge you a different price, or provide a different level of quality because you exercised any right in this section. Nomicho Plus pricing is unaffected by any privacy choice.
How to make a request and how we verify you. Send requests to support@nomicho.jp. Because most of your data is on your device and much of the rest is reachable through the in-App controls above, the fastest route is usually Settings. For requests that require us to act, please write from your registered email address, or include an account identifier sufficient to locate the data. Requests are free. We respond within 30 days, and may extend once by a further 60 days where a request is complex, telling you before we do.
If you are unhappy with our response, please tell us first — most problems are quicker to fix directly. You also have the right to complain to the data-protection authority in the country where you live, where you work, or where you believe the problem occurred, and to seek a remedy through the courts. Complaining to us first is not a precondition.
7. Retention
We keep data only as long as we need it for the purpose it was collected for:
| Data | Kept for |
|---|---|
| Drink logs, sessions, BAC profile, place tags, photos | On your device until you delete them or the App. In the cloud, while your account exists; deleted on account deletion (§6) |
| Account record | While your account exists |
| Acceptance records | While your account exists, and thereafter only as long as needed to evidence the agreement |
| Crash reports | 30 days |
| Analytics events | 1 year |
| Push notification token | While notifications are enabled |
| Lock Screen forecast | While the card is running, and never more than 2 hours after the session’s projected end (§2.11) |
| Feedback you send | Until the matter is resolved and any follow-up is complete |
Local data on a device you have signed out of is removed after 60 days (§4.1).
8. Do Not Track
Some browsers and devices send a “Do Not Track” signal. There is no industry-accepted standard for how to respond to one, and the App does not respond to Do Not Track signals. This is not evasive: the App does not track you across other companies’ sites or apps in the first place, and permits no third party to do so (§5.3).
9. Age and children
The App is for adults of legal drinking age in the country where they live, and it is not directed to children. We do not knowingly collect personal data from anyone below the legal drinking age where they live, or from any child.
If we learn that we have collected personal data from a child, we will delete it. If you believe a child has provided us data, contact support@nomicho.jp.
10. Security
We protect your data with Row-Level Security on every user-owned table, encryption in transit, private-by-default storage objects, and device attestation on calls to our AI proxy. Access to production data is limited to the operator.
No method of transmission or storage is completely secure. If a breach affecting your personal data occurs, we will notify you and any regulator as required by the law that applies to you, without unreasonable delay.
11. Contact
- Email: support@nomicho.jp
- Operator: Chris Hashimoto (橋本クリス), sole proprietor
- Address: disclosed without delay upon request
We respond within a reasonable period, and within the deadlines set by §6 for rights requests.
12. Changes to this policy
We may revise this policy when the law changes, when we add or change features, or when our operations change. The effective date above always reflects the current version, and the revision history below records what changed.
For material changes, we will give notice in the App before the change takes effect, and where you have enabled sync, by email. Continuing to use the App after the effective date means you accept the revised policy.
13. Revision history
| Version | Date | Summary |
|---|---|---|
| 1.0 | 2026-09-06 | Initial version. |