Nomicho Privacy Policy (International)

Operator: Chris Hashimoto (橋本クリス), sole proprietor Trade name: Nomicho Address: Disclosed without delay upon request (contact support@nomicho.jp) Contact: support@nomicho.jp Effective date: 2026-09-06 Last updated: 2026-09-06 Version: 1.0


1. Introduction

Nomicho (“the App”) is a personal journal application that helps you record, reflect on, and predict the impact of your own drinking. This policy describes what personal data Chris Hashimoto (“we”, “us”) collects when providing the App to users outside Japan and the United States, how it is used, where it is stored, when it is disclosed, and what rights you have over it.

For the purposes of data-protection law, we are the controller of the personal data described here.

The App is a tool for self-recording and self-reflection. It is not a medical device and does not provide medical advice, diagnosis, or treatment; it does not measure, diagnose, or monitor intoxication or any medical condition (see Terms of Service §4.2 / §4.3).

We are based in Japan. Nomicho is operated by a sole proprietor located in Japan, and the App’s servers are located in Japan. Using the App means your data is transferred to and stored in Japan. See §4.

This policy applies to users whose home region is neither Japan nor the United States. Users in those two countries are served separate policies written to their own law. Home region follows your App Store storefront, falling back to your device’s region setting, not where you happen to be travelling; if it changes, the App will ask you to review and accept the other set of documents.

2. Information we collect

What we collect depends on how you use the App. Most of it never leaves your device.

2.1 Information stored on your device

Some of this is required for core functionality; the BAC profile fields are collected only if you choose to set one up. Stored in a local database (SQLite) on your device. Nothing in this section leaves the device unless you explicitly enable cloud sync.

2.2 Account information (collected when you sign in)

Signing in is optional. The App is fully usable without an account. You sign in only to attach your data to an account, which is what makes cross-device sync possible (sync itself is a further, separate opt-in). Signing in creates an account record on our authentication service even if you do not turn on sync.

Email addresses are stored in plain text, not hashed, because they are required for the sign-in flow itself.

One account, multiple sign-in methods. From Settings → Account you can connect more than one provider to a single Nomicho account; the connected methods then share one account and one set of data.

2.3 Information sent unless you opt out

The following are enabled by default. You can opt out of either individually from Settings at any time.

2.4 Identifiers and device information

While the §2.3 services are enabled, each issues a device-scoped pseudonymous identifier. These identifiers do not directly identify you.

The App does not use cookies. The Sentry and PostHog SDKs store the above identifiers in device-local storage.

2.5 What we do not collect

The App does not access contacts, address book, or SMS content; microphone recordings; your photo library except for photos you add yourself (§2.10); or your location except when you turn on the optional location feature (§2.9). The camera is used to scan barcodes and to take photos you choose to attach; nothing is captured without your action.

2.6 Feedback you submit (optional)

If you send feedback from Settings → Feedback, we receive the message you write, an optional category, and an optional contact email if you provide one so we can reply. We also receive your App version, language setting, and a device-scoped identifier. Because sending feedback is an action you take deliberately, this is sent even when cloud sync is off. We use it only to reply to you and to improve the App.

2.7 Apple Health data (optional, iOS only)

If you grant permission, the App reads Apple Health data to auto-fill your BAC profile (sex, date of birth, height, weight) and to refine hangover forecasts using sleep and heart data. If you enable it in Settings, the App also writes your logged drinks (standard-drink count, calories, sugar) to Apple Health.

Apple Health data is processed on your device only. It is never uploaded to our servers, never synced, never sent to any AI provider, and never included in analytics. Health-sourced profile values (weight and so on) become ordinary BAC-profile fields and follow §2.1.

2.8 Our website

Our website is covered by a separate notice on the site itself. In short: we collect an email address only from people who ask to be notified about the App, and use it only for that; we measure page views with cookieless, aggregate analytics; and we set no cookies and do no cross-site or individual-level tracking. The website collects no account or drink data.

2.9 Location data (optional)

Location is off by default, and nothing is captured until you turn it on in Settings. When enabled, the App attaches a place (a label and map coordinates) to drinks you log, and, only if you also choose the “session journey” option, records a simplified route while the App is open during a session. Nothing is recorded in the background or outside a session. You can also type a place by hand at any time without granting location permission.

Location data is stored on your device first. It is uploaded only if you enable cloud sync, in which case it is stored with your other synced data under the same protections (§4.2), included in your data export, and removed by account deletion. Location data is never included in analytics, never sent to any AI provider, and never sold, shared, or disclosed for advertising. You can edit or delete individual place tags, and turning the feature off stops all capture immediately.

2.10 Photos (optional)

You can attach photos to your sessions and drinks, taken with the camera or picked from your photo library. Nothing is captured until you choose to add one. Photos are downscaled and re-encoded, which strips embedded EXIF location data, and stored on your device. They are never sent to any AI provider and never included in analytics.

If you turn on photo backup (a Nomicho Plus feature, off by default, available only while cloud sync is on), your photos are uploaded to private cloud storage accessible only to your account, restored to your other signed-in devices, and removed by account deletion. Deleting a photo in the App also removes its backup copy.

2.11 Lock Screen forecast (optional, iOS only)

The Live Activity is off by default. When you turn it on, the App shows your session on the Lock Screen and in the Dynamic Island. So that the card keeps updating while your phone is locked, which the App cannot do on its own because it does not run in the background, your forecast is sent to our server: the projected BAC curve for the current session, your drink count and grams of pure alcohol, the predicted peak and hangover tier, your pace status if pacing mode is on, and your language setting.

It does not include what you drank, where you were, when you ate, your name, your email, or your account. The record is identified only by a random per-installation identifier and is never linked to an account, so it is sent whether or not you are signed in.

It is retained only while the card is running and deleted when the card ends, and in all cases no later than 2 hours after the session’s projected end time, so that a record still disappears if the App is deleted or never reopened. Turning the Live Activity off deletes it immediately.

We use collected data only for the following purposes. The “basis” column states the ground we rely on where your country’s law requires one to be identified, using the terms used in European data-protection law.

PurposeData involvedBasis
Core App functionality — storing drink logs, estimating BAC, calendar and journal display§2.1Performance of our contract with you (the Terms)
Cloud sync across your devices§2.1, §2.9, §2.10Performance of the contract, activated by your opt-in
AI reflection cardsAggregate session metrics (§5.1)Performance of the contract
Account creation and sign-in§2.2Performance of the contract
Reliability — crash reports§2.3, §2.4Our legitimate interest in a working App, subject to your opt-out
Product improvement — analytics§2.3, §2.4Our legitimate interest in improving the App, subject to your opt-out
Push notifications§2.4Your consent, given through the OS permission prompt
Apple Health integration§2.7Your explicit consent, given through the OS permission prompt
Location tagging§2.9Your consent, given in Settings and the OS permission prompt
Photo diary and photo backup§2.10Your consent, given by adding a photo and by enabling backup
Lock Screen forecast§2.11Your consent, given by turning the feature on
Responding to feedback§2.6Your consent, given by sending it
Keeping proof of which documents you acceptedAcceptance records (§2.1)Our legitimate interest in being able to evidence the agreement
Responding to legally compelled requestsAs compelledCompliance with a legal obligation

Data about your drinking may count as health data in your country. Where it does, we rely on your explicit consent, which you give by choosing to record it. You can withdraw that consent at any time by deleting the data or your account (§6); withdrawal does not affect processing that already happened.

Where we rely on legitimate interests, you have the right to object — see §6.

We do not use collected data for any other purpose. We do not use it for advertising, third-party marketing, profiling for targeted advertising, or repurposing into other services. We do not use it to train AI models, and our AI provider is contractually barred from doing so (§5.1). We make no decisions about you by automated means that produce legal or similarly significant effects.

4. Where your data is stored, and international transfer

4.1 Local storage (default)

By default, all drink records and body information are stored only on your device. They are not accessible to us or to any external party. (The one exception is the Lock Screen forecast in §4.4, if you turn that feature on.)

4.2 Cloud storage (only when sync is enabled)

Your data is stored in Japan. If you enable sync, the relevant data is stored in:

Supabase is operated by Supabase, Inc., a US company, under a Data Processing Agreement, but the App’s data is physically stored in Japan.

4.3 What transferring data to Japan means for you

Japan has a comprehensive privacy statute of general application: the Act on the Protection of Personal Information (APPI), overseen by the Personal Information Protection Commission, an independent regulator. It applies to us as a Japanese operator.

If you are in the European Economic Area or the United Kingdom, this transfer does not depend on contractual safeguards: the European Commission and the United Kingdom have each formally recognised Japan as providing an adequate level of protection for personal data, so data may flow to Japan on the same footing as within Europe.

Some of our service providers are in the United States (§5.1). Adequacy covers the transfer to us in Japan, not those onward transfers, which are made under the Standard Contractual Clauses in each provider’s Data Processing Agreement.

Japanese authorities may compel disclosure of data held in Japan under Japanese legal process. Your rights under §6 are honoured regardless of where the data sits.

4.4 Temporary storage for the Lock Screen forecast

While the Live Activity (§2.11) is enabled, its forecast is stored in Supabase Postgres (Tokyo region). If you are not signed in, this is the only data of yours that exists on any server. If you are signed in with sync turned off, it is the only content of yours on any server: your account record (§2.2) still exists on our authentication service, and your device registration exists if you have enabled notifications (§2.4). It is not linked to an account. Retention is as stated in §2.11.

5. Disclosure to third parties

5.1 Service providers

We engage the following service providers, each acting as our processor. Each processes data only on our instructions and for the purposes listed.

ProviderPurposeData sentRetention
Anthropic, PBC (US)Reflection-card text generationAggregate session metrics only (drink count, total pure-alcohol grams, category counts, peak feeling, duration, optional hangover-severity estimate). No photos, no free-text notes, no profile or body data, no location.Under a Zero Data Retention agreement, inputs and outputs are not retained after the request is processed.
Supabase, Inc. (US company; data stored in Japan)Cloud storage for synced dataThe §2.1 / §2.9 / §2.10 data you have chosen to syncWhile the account is active; deleted on account deletion
Sentry (US)Crash reportsOS info, stack trace, anonymous device identifier30 days
PostHog (EU)Product analyticsEvent logs and the §2.3 settings flags1 year
Google LLC / Firebase (US)Push notification delivery, app attestation, feature configurationPush notification token, device installation identifier, and the notification text we send you. No drink content, body data, or estimates.While notifications are enabled

Sentry and PostHog are each on by default; you can opt out of either individually from Settings.

Calls to Anthropic are routed through a proxy we operate. The App never communicates with Anthropic’s API directly from your device. The proxy enforces rate limits, daily spending caps, and device attestation.

5.2 We do not sell or share your personal data

We have never sold personal data, and we do not share it for behavioural advertising. We do not disclose personal data to advertisers, data brokers, ad networks, or any third party for marketing purposes.

We disclose personal data outside §5.1 only:

5.3 Third-party collection across sites

We do not permit third parties to collect personally identifiable information about your online activities over time and across different websites or online services when you use the App.

6. Your rights

We offer the following rights to every user this policy covers, regardless of which country you live in and whether a given law applies to us by its own terms.

How to make a request and how we verify you. Send requests to support@nomicho.jp. Because most of your data is on your device and much of the rest is reachable through the in-App controls above, the fastest route is usually Settings. For requests that require us to act, please write from your registered email address, or include an account identifier sufficient to locate the data. Requests are free. We respond within 30 days, and may extend once by a further 60 days where a request is complex, telling you before we do.

If you are unhappy with our response, please tell us first — most problems are quicker to fix directly. You also have the right to complain to the data-protection authority in the country where you live, where you work, or where you believe the problem occurred, and to seek a remedy through the courts. Complaining to us first is not a precondition.

7. Retention

We keep data only as long as we need it for the purpose it was collected for:

DataKept for
Drink logs, sessions, BAC profile, place tags, photosOn your device until you delete them or the App. In the cloud, while your account exists; deleted on account deletion (§6)
Account recordWhile your account exists
Acceptance recordsWhile your account exists, and thereafter only as long as needed to evidence the agreement
Crash reports30 days
Analytics events1 year
Push notification tokenWhile notifications are enabled
Lock Screen forecastWhile the card is running, and never more than 2 hours after the session’s projected end (§2.11)
Feedback you sendUntil the matter is resolved and any follow-up is complete

Local data on a device you have signed out of is removed after 60 days (§4.1).

8. Do Not Track

Some browsers and devices send a “Do Not Track” signal. There is no industry-accepted standard for how to respond to one, and the App does not respond to Do Not Track signals. This is not evasive: the App does not track you across other companies’ sites or apps in the first place, and permits no third party to do so (§5.3).

9. Age and children

The App is for adults of legal drinking age in the country where they live, and it is not directed to children. We do not knowingly collect personal data from anyone below the legal drinking age where they live, or from any child.

If we learn that we have collected personal data from a child, we will delete it. If you believe a child has provided us data, contact support@nomicho.jp.

10. Security

We protect your data with Row-Level Security on every user-owned table, encryption in transit, private-by-default storage objects, and device attestation on calls to our AI proxy. Access to production data is limited to the operator.

No method of transmission or storage is completely secure. If a breach affecting your personal data occurs, we will notify you and any regulator as required by the law that applies to you, without unreasonable delay.

11. Contact

We respond within a reasonable period, and within the deadlines set by §6 for rights requests.

12. Changes to this policy

We may revise this policy when the law changes, when we add or change features, or when our operations change. The effective date above always reflects the current version, and the revision history below records what changed.

For material changes, we will give notice in the App before the change takes effect, and where you have enabled sync, by email. Continuing to use the App after the effective date means you accept the revised policy.

13. Revision history

VersionDateSummary
1.02026-09-06Initial version.