Nomicho Privacy Policy (United States)

Operator: Chris Hashimoto (橋本クリス), sole proprietor Trade name: Nomicho Address: Disclosed without delay upon request (contact support@nomicho.jp) Contact: support@nomicho.jp Effective date: 2026-09-03 Last updated: 2026-09-03 Version: 1.0


1. Introduction

Nomicho (“the App”) is a personal journal application that helps you record, reflect on, and predict the impact of your own drinking. This policy describes what personal information Chris Hashimoto (“we”, “us”) collects when providing the App to users in the United States, how it is used, where it is stored, when it is disclosed, and what choices you have over it.

The App is a tool for self-recording and self-reflection. It is not a medical device and does not provide medical advice, diagnosis, or treatment; it does not measure, diagnose, or monitor intoxication or any medical condition (see Terms of Service §4.2 / §4.3).

We are based in Japan. Nomicho is operated by a sole proprietor located in Japan, and the App’s servers are located in Japan. Using the App means your information is transferred to and stored in Japan. See §4.

This policy applies to users whose home region is the United States. Users whose home region is Japan are served a separate policy written to Japan’s Act on the Protection of Personal Information. Home region follows your App Store storefront, falling back to your device’s region setting, not where you happen to be travelling; if it changes, the App will ask you to review and accept the other set of documents.

2. Information we collect

What we collect depends on how you use the App. Most of it never leaves your device.

2.1 Information stored on your device

Some of this is required for core functionality; the BAC profile fields are collected only if you choose to set one up. Stored in a local database (SQLite) on your device. Nothing in this section leaves the device unless you explicitly enable cloud sync.

2.2 Account information (collected when you sign in)

Signing in is optional. The App is fully usable without an account. You sign in only to attach your data to an account, which is what makes cross-device sync possible (sync itself is a further, separate opt-in). Signing in creates an account record on our authentication service even if you do not turn on sync.

Email addresses are stored in plain text, not hashed, because they are required for the sign-in flow itself.

One account, multiple sign-in methods. From Settings → Account you can connect more than one provider to a single Nomicho account; the connected methods then share one account and one set of data.

2.3 Information sent unless you opt out

The following are enabled by default. You can opt out of either individually from Settings.

2.4 Identifiers and device information

While the §2.3 services are enabled, each issues a device-scoped pseudonymous identifier. These identifiers do not directly identify you.

The App does not use cookies. The Sentry and PostHog SDKs store the above identifiers in device-local storage.

2.5 What we do not collect

The App does not access contacts, address book, or SMS content; microphone recordings; your photo library except for photos you add yourself (§2.10); or your location except when you turn on the optional location feature (§2.9). The camera is used to scan barcodes and to take photos you choose to attach; nothing is captured without your action.

2.6 Feedback you submit (optional)

If you send feedback from Settings → Feedback, we receive the message you write, an optional category, and an optional contact email if you provide one so we can reply. We also receive your App version, language setting, and a device-scoped identifier. Because sending feedback is an action you take deliberately, this is sent even when cloud sync is off. We use it only to reply to you and to improve the App.

2.7 Apple Health data (optional, iOS only)

If you grant permission, the App reads Apple Health data to auto-fill your BAC profile (sex, date of birth, height, weight) and to refine hangover forecasts using sleep and heart data. If you enable it in Settings, the App also writes your logged drinks (standard-drink count, calories, sugar) to Apple Health.

Apple Health data is processed on your device only. It is never uploaded to our servers, never synced, never sent to any AI provider, and never included in analytics. Health-sourced profile values (weight and so on) become ordinary BAC-profile fields and follow §2.1.

2.8 Our website

Our website is covered by a separate notice on the site itself. In short: we collect an email address only from people who ask to be notified about the App, and use it only for that; we measure page views with cookieless, aggregate analytics; and we set no cookies and do no cross-site or individual-level tracking. The website collects no account or drink data.

2.9 Location data (optional)

Location is off by default, and nothing is captured until you turn it on in Settings. When enabled, the App attaches a place (a label and map coordinates) to drinks you log, and, only if you also choose the “session journey” option, records a simplified route while the App is open during a session. Nothing is recorded in the background or outside a session. You can also type a place by hand at any time without granting location permission.

Location data is stored on your device first. It is uploaded only if you enable cloud sync, in which case it is stored with your other synced data under the same protections (§4.2), included in your data export, and removed by account deletion. Location data is never included in analytics, never sent to any AI provider, and never sold, shared, or disclosed for advertising. You can edit or delete individual place tags, and turning the feature off stops all capture immediately.

We do not use geofencing. The App does not establish any virtual boundary around a health care facility, a provider of consumer health services, or any other location, and does not track, collect data from, or send notifications to you based on your proximity to such a place.

2.10 Photos (optional)

You can attach photos to your sessions and drinks, taken with the camera or picked from your photo library. Nothing is captured until you choose to add one. Photos are downscaled and re-encoded, which strips embedded EXIF location data, and stored on your device. They are never sent to any AI provider and never included in analytics.

If you turn on photo backup (a Nomicho Plus feature, off by default, available only while cloud sync is on), your photos are uploaded to private cloud storage accessible only to your account, restored to your other signed-in devices, and removed by account deletion. Deleting a photo in the App also removes its backup copy.

2.11 Lock Screen forecast (optional, iOS only)

The Live Activity is off by default. When you turn it on, the App shows your session on the Lock Screen and in the Dynamic Island. So that the card keeps updating while your phone is locked, which the App cannot do on its own because it does not run in the background, your forecast is sent to our server: the projected BAC curve for the current session, your drink count and grams of pure alcohol, the predicted peak and hangover tier, your pace status if pacing mode is on, and your language setting.

It does not include what you drank, where you were, when you ate, your name, your email, or your account. The record is identified only by a random per-installation identifier and is never linked to an account, so it is sent whether or not you are signed in.

It is retained only while the card is running and deleted when the card ends, and in all cases no later than 2 hours after the session’s projected end time, so that a record still disappears if the App is deleted or never reopened. Turning the Live Activity off deletes it immediately.

3. How we use your information

We use collected information only for the following purposes:

  1. Core App functionality — storing drink logs, estimating BAC, generating reflection cards, calendar display.
  2. AI features — generating your reflection cards from session data (§5).
  3. Cloud sync (optional) — multi-device sync only when you explicitly enable it.
  4. Reliability and improvement — bug fixes and product improvements based on crash reports and anonymous analytics.
  5. Feedback — responding to feedback you submit.
  6. Apple Health integration (optional) — filling in and keeping current your BAC profile, and improving hangover forecasts on your device (§2.7).
  7. Location tagging (optional) — attaching places, and optionally a session route, to your own logs and recaps (§2.9).
  8. Photo diary (optional) — attaching photos you add to your own sessions and drinks, and backing them up only when you enable photo backup (§2.10).
  9. Legal compliance — responding to legally compelled requests from authorities.

We do not use collected information for any other purpose. We do not use it for advertising, third-party marketing, profiling for targeted advertising, or repurposing into other services. We do not use it to train AI models, and our AI provider is contractually barred from doing so (§5.1).

4. Where your information is stored, and cross-border transfer

4.1 Local storage (default)

By default, all drink records and body information are stored only on your device. They are not accessible to us or to any external party. (The one exception is the Lock Screen forecast in §4.4, if you turn that feature on.)

4.2 Cloud storage (only when sync is enabled)

Your data is stored in Japan. If you enable sync, the relevant data is stored in:

Supabase is operated by Supabase, Inc., a US company, under a Data Processing Agreement, but the App’s data is physically stored in Japan.

4.3 What transferring data to Japan means for you

Unlike the United States, Japan has a single comprehensive privacy statute of general application: the Act on the Protection of Personal Information (APPI), overseen by the Personal Information Protection Commission, an independent regulator. It applies to us as a Japanese operator. Japan and the European Union maintain a mutual adequacy finding, meaning each recognizes the other’s regime as providing an equivalent level of protection.

Japanese authorities may compel disclosure of data held in Japan under Japanese legal process. Your rights under this policy (§6) are offered to you contractually and are honored regardless of where the data sits.

4.4 Temporary storage for the Lock Screen forecast

While the Live Activity (§2.11) is enabled, its forecast is stored in Supabase Postgres (Tokyo region). If you are not signed in, this is the only data of yours that exists on any server. If you are signed in with sync turned off, it is the only content of yours on any server: your account record (§2.2) still exists on our authentication service, and your device registration exists if you have enabled notifications (§2.4). It is not linked to an account. Retention is as stated in §2.11.

5. Disclosure to third parties

5.1 Service providers

We engage the following service providers. Each processes data only on our instructions and for the purposes listed.

ProviderPurposeData sentRetention
Anthropic, PBC (US)Reflection-card text generationAggregate session metrics only (drink count, total pure-alcohol grams, category counts, peak feeling, duration, optional hangover-severity estimate). No photos, no free-text notes, no profile or body data, no location.Under a Zero Data Retention agreement, inputs and outputs are not retained after the request is processed.
Supabase, Inc. (US company; data stored in Japan)Cloud storage for synced dataThe §2.1 / §2.9 / §2.10 data you have chosen to syncWhile the account is active; deleted on account deletion
Sentry (US)Crash reportsOS info, stack trace, anonymous device identifier30 days
PostHog (EU)Product analyticsEvent logs and the §2.3 settings flags1 year
Google LLC / Firebase (US)Push notification delivery, app attestation, feature configurationPush notification token, device installation identifier, and the notification text we send you. No drink content, body data, or estimates.While notifications are enabled

Sentry and PostHog are each on by default; you can opt out of either individually from Settings.

Calls to Anthropic are routed through a proxy we operate. The App never communicates with Anthropic’s API directly from your device. The proxy enforces rate limits, daily spending caps, and device attestation.

5.2 We do not sell or share your personal information

We have never sold personal information, and we do not share it for cross-context behavioral advertising. We do not disclose personal information to advertisers, data brokers, ad networks, or any third party for marketing purposes. This has been true for the preceding 12 months and applies to all users, including anyone under 16.

We disclose personal information outside §5.1 only:

5.3 Third-party collection across sites

We do not permit third parties to collect personally identifiable information about your online activities over time and across different websites or online services when you use the App.

6. Your choices and rights

We offer the following rights to every US user, regardless of your state of residence and regardless of whether a given state law applies to us by its own terms.

Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for written proof of authorization and may ask you to verify your identity directly.

Appeals. If we decline a request, you may appeal by replying to our response or writing to the §11 address with “Appeal” in the subject line. We will respond to an appeal within 45 days with a written explanation. If we deny the appeal, you may contact your state Attorney General.

How to make a request and how we verify you. Send requests to support@nomicho.jp. Because most of your data is on your device and much of the rest is reachable through the in-App controls above, the fastest route is usually Settings. For requests that require us to act, please write from your registered email address, or include an account identifier sufficient to locate the data. Requests are free. We respond within 45 days and may extend once by a further 45 days where reasonably necessary, telling you before we do.

7. Consumer health data

Some US state laws treat information about health, including information from which health status can be inferred, as its own category with its own rules. Your drink logs, everything we derive from them, your BAC profile, and any Apple Health readings you let us read all fall inside our view of that category.

Because those laws call for a separate and distinct policy, that is where this is covered: see our Consumer Health Data Privacy Policy, published alongside this one.

The short version, with the full detail in that document: we collect it only to run the features you are using, we never sell it, we disclose it to no one but the service providers who operate the App on our instructions, Apple Health data never leaves your device at all, we use no geofencing, and you can access, export, withdraw consent to, and delete it.

8. Do Not Track and Global Privacy Control

Some browsers and devices send a “Do Not Track” signal. There is no industry-accepted standard for how to respond to one, and the App does not respond to Do Not Track signals. This is not evasive: the App does not track you across other companies’ sites or apps in the first place, and permits no third party to do so (§5.3).

We honor a Global Privacy Control signal where one reaches us as an opt-out of sale or sharing. Because we do not sell or share personal information (§5.2), such a signal requires no change in our handling of your data.

9. Age and children

The App is for adults of legal drinking age. You must be 21 or older to use it, which is the legal drinking age in every US state; a small number of US territories set a lower age, but our own requirement is 21 regardless. The App is not directed to children, and we do not knowingly collect personal information from anyone under 13. We do not knowingly sell or share the personal information of anyone under 16, because we do not sell or share personal information at all.

If we learn that we have collected personal information from a child under 13, we will delete it. If you believe a child has provided us information, contact support@nomicho.jp.

10. Security

We protect your information with Row-Level Security on every user-owned table, encryption in transit, private-by-default storage objects, and device attestation on calls to our AI proxy. Access to production data is limited to the operator.

No method of transmission or storage is completely secure. If a breach affecting your personal information occurs, we will notify you and any regulator as required by the law of your state, without unreasonable delay.

11. Contact

We respond within a reasonable period, and within the deadlines set by §6 for rights requests.

12. Changes to this policy

We may revise this policy when the law changes, when we add or change features, or when our operations change. The effective date above always reflects the current version, and the revision history below records what changed.

For material changes, we will give notice in the App before the change takes effect, and where you have enabled sync, by email. Continuing to use the App after the effective date means you accept the revised policy.

13. Revision history

VersionDateSummary
1.02026-09-03Initial version.