Nomicho Privacy Policy (United States)
Operator: Chris Hashimoto (橋本クリス), sole proprietor Trade name: Nomicho Address: Disclosed without delay upon request (contact support@nomicho.jp) Contact: support@nomicho.jp Effective date: 2026-09-03 Last updated: 2026-09-03 Version: 1.0
1. Introduction
Nomicho (“the App”) is a personal journal application that helps you record, reflect on, and predict the impact of your own drinking. This policy describes what personal information Chris Hashimoto (“we”, “us”) collects when providing the App to users in the United States, how it is used, where it is stored, when it is disclosed, and what choices you have over it.
The App is a tool for self-recording and self-reflection. It is not a medical device and does not provide medical advice, diagnosis, or treatment; it does not measure, diagnose, or monitor intoxication or any medical condition (see Terms of Service §4.2 / §4.3).
We are based in Japan. Nomicho is operated by a sole proprietor located in Japan, and the App’s servers are located in Japan. Using the App means your information is transferred to and stored in Japan. See §4.
This policy applies to users whose home region is the United States. Users whose home region is Japan are served a separate policy written to Japan’s Act on the Protection of Personal Information. Home region follows your App Store storefront, falling back to your device’s region setting, not where you happen to be travelling; if it changes, the App will ask you to review and accept the other set of documents.
2. Information we collect
What we collect depends on how you use the App. Most of it never leaves your device.
2.1 Information stored on your device
Some of this is required for core functionality; the BAC profile fields are collected only if you choose to set one up. Stored in a local database (SQLite) on your device. Nothing in this section leaves the device unless you explicitly enable cloud sync.
- Date of birth — used to age-adjust blood alcohol concentration (BAC) estimates. Collected when you set up your BAC profile, not at first launch.
- Body weight and sex — used as coefficients in BAC estimation. The “sex” field asks which physiological response pattern best matches you, not your registered legal sex.
- Height, alcohol-flush tendency, and drinking frequency — further coefficients for the BAC estimate, collected with your BAC profile.
- Drink logs — drink type, volume, ABV, time logged, session metadata, optional notes and feeling tags.
- Acceptance records — which version of these documents you accepted, when, in which language, under which App version, and under which country’s legal regime. Kept as proof of the agreement between us.
2.2 Account information (collected when you sign in)
Signing in is optional. The App is fully usable without an account. You sign in only to attach your data to an account, which is what makes cross-device sync possible (sync itself is a further, separate opt-in). Signing in creates an account record on our authentication service even if you do not turn on sync.
- Sign in with Apple — Apple’s stable user identifier and the email address Apple returns. If you choose “Hide My Email,” that address is an
@privaterelay.appleid.comrelay address; we store it as received and cannot resolve it to your underlying address. Your display name is provided by Apple on the first sign-in only. - Sign in with Google — Google’s stable user identifier, your verified Google email address, and your display name.
- Sign in with LINE — an opaque user identifier specific to the App and, if you have allowed it, your LINE display name. We do not request your email address from LINE, so no LINE email address is stored, and we store no LINE access token: the sign-in confirms your identity only and makes no further calls to LINE.
Email addresses are stored in plain text, not hashed, because they are required for the sign-in flow itself.
One account, multiple sign-in methods. From Settings → Account you can connect more than one provider to a single Nomicho account; the connected methods then share one account and one set of data.
2.3 Information sent unless you opt out
The following are enabled by default. You can opt out of either individually from Settings.
- Crash reports (Sentry) — technical logs sent when the App crashes (OS version, stack trace, anonymous device identifier). Drink data is not sent.
- Product analytics (PostHog) — event logs (screen transitions, button taps) tied to a device-scoped pseudonymous identifier, not to your name, email, or account (§2.4), plus a small set of non-identifying app settings attached to that device profile, such as your language and which features you have switched on. No drink content and no body data is sent, and none of it is ever linked to your account.
2.4 Identifiers and device information
While the §2.3 services are enabled, each issues a device-scoped pseudonymous identifier. These identifiers do not directly identify you.
-
They are used solely to associate crash reports or analytics events with a single device for reliability and product-improvement purposes.
-
Sentry and PostHog do not receive your account identifier (§2.2) or your drink logs from the App.
-
You can rotate to a new identifier by opting out of the service in Settings and reinstalling the App.
-
Push notification token — if you allow notifications, your device receives a token from Firebase Cloud Messaging (Google) that lets us deliver a notification to that device. It identifies the device installation, not you. It is stored with your account when sync is on, and removed when you delete your account or turn notifications off.
The App does not use cookies. The Sentry and PostHog SDKs store the above identifiers in device-local storage.
2.5 What we do not collect
The App does not access contacts, address book, or SMS content; microphone recordings; your photo library except for photos you add yourself (§2.10); or your location except when you turn on the optional location feature (§2.9). The camera is used to scan barcodes and to take photos you choose to attach; nothing is captured without your action.
2.6 Feedback you submit (optional)
If you send feedback from Settings → Feedback, we receive the message you write, an optional category, and an optional contact email if you provide one so we can reply. We also receive your App version, language setting, and a device-scoped identifier. Because sending feedback is an action you take deliberately, this is sent even when cloud sync is off. We use it only to reply to you and to improve the App.
2.7 Apple Health data (optional, iOS only)
If you grant permission, the App reads Apple Health data to auto-fill your BAC profile (sex, date of birth, height, weight) and to refine hangover forecasts using sleep and heart data. If you enable it in Settings, the App also writes your logged drinks (standard-drink count, calories, sugar) to Apple Health.
Apple Health data is processed on your device only. It is never uploaded to our servers, never synced, never sent to any AI provider, and never included in analytics. Health-sourced profile values (weight and so on) become ordinary BAC-profile fields and follow §2.1.
2.8 Our website
Our website is covered by a separate notice on the site itself. In short: we collect an email address only from people who ask to be notified about the App, and use it only for that; we measure page views with cookieless, aggregate analytics; and we set no cookies and do no cross-site or individual-level tracking. The website collects no account or drink data.
2.9 Location data (optional)
Location is off by default, and nothing is captured until you turn it on in Settings. When enabled, the App attaches a place (a label and map coordinates) to drinks you log, and, only if you also choose the “session journey” option, records a simplified route while the App is open during a session. Nothing is recorded in the background or outside a session. You can also type a place by hand at any time without granting location permission.
Location data is stored on your device first. It is uploaded only if you enable cloud sync, in which case it is stored with your other synced data under the same protections (§4.2), included in your data export, and removed by account deletion. Location data is never included in analytics, never sent to any AI provider, and never sold, shared, or disclosed for advertising. You can edit or delete individual place tags, and turning the feature off stops all capture immediately.
We do not use geofencing. The App does not establish any virtual boundary around a health care facility, a provider of consumer health services, or any other location, and does not track, collect data from, or send notifications to you based on your proximity to such a place.
2.10 Photos (optional)
You can attach photos to your sessions and drinks, taken with the camera or picked from your photo library. Nothing is captured until you choose to add one. Photos are downscaled and re-encoded, which strips embedded EXIF location data, and stored on your device. They are never sent to any AI provider and never included in analytics.
If you turn on photo backup (a Nomicho Plus feature, off by default, available only while cloud sync is on), your photos are uploaded to private cloud storage accessible only to your account, restored to your other signed-in devices, and removed by account deletion. Deleting a photo in the App also removes its backup copy.
2.11 Lock Screen forecast (optional, iOS only)
The Live Activity is off by default. When you turn it on, the App shows your session on the Lock Screen and in the Dynamic Island. So that the card keeps updating while your phone is locked, which the App cannot do on its own because it does not run in the background, your forecast is sent to our server: the projected BAC curve for the current session, your drink count and grams of pure alcohol, the predicted peak and hangover tier, your pace status if pacing mode is on, and your language setting.
It does not include what you drank, where you were, when you ate, your name, your email, or your account. The record is identified only by a random per-installation identifier and is never linked to an account, so it is sent whether or not you are signed in.
It is retained only while the card is running and deleted when the card ends, and in all cases no later than 2 hours after the session’s projected end time, so that a record still disappears if the App is deleted or never reopened. Turning the Live Activity off deletes it immediately.
3. How we use your information
We use collected information only for the following purposes:
- Core App functionality — storing drink logs, estimating BAC, generating reflection cards, calendar display.
- AI features — generating your reflection cards from session data (§5).
- Cloud sync (optional) — multi-device sync only when you explicitly enable it.
- Reliability and improvement — bug fixes and product improvements based on crash reports and anonymous analytics.
- Feedback — responding to feedback you submit.
- Apple Health integration (optional) — filling in and keeping current your BAC profile, and improving hangover forecasts on your device (§2.7).
- Location tagging (optional) — attaching places, and optionally a session route, to your own logs and recaps (§2.9).
- Photo diary (optional) — attaching photos you add to your own sessions and drinks, and backing them up only when you enable photo backup (§2.10).
- Legal compliance — responding to legally compelled requests from authorities.
We do not use collected information for any other purpose. We do not use it for advertising, third-party marketing, profiling for targeted advertising, or repurposing into other services. We do not use it to train AI models, and our AI provider is contractually barred from doing so (§5.1).
4. Where your information is stored, and cross-border transfer
4.1 Local storage (default)
By default, all drink records and body information are stored only on your device. They are not accessible to us or to any external party. (The one exception is the Lock Screen forecast in §4.4, if you turn that feature on.)
- Accounts you are no longer signed into. If you sign out of an account on a device and do not sign back into that account on that device for 60 days, its local copy is removed from that device. This is so an account that signed in once, for example on a friend’s phone, does not leave your records there indefinitely. It never affects the account you are currently using: simply not opening the App for a while, however long, deletes nothing. If you use the App without an account, nothing is ever removed this way. Data you had synced re-downloads when you sign back in; anything logged offline and not yet synced cannot be recovered.
4.2 Cloud storage (only when sync is enabled)
Your data is stored in Japan. If you enable sync, the relevant data is stored in:
- Supabase Postgres (Tokyo region,
ap-northeast-1) — drink records, body information, session metadata, and, only if you use the optional location feature, place tags and session route points. Row-Level Security ensures each user can access only their own data. - Supabase Storage (same Tokyo region) — photo image files, only when you enable photo backup (§2.10). Objects are private to your account.
Supabase is operated by Supabase, Inc., a US company, under a Data Processing Agreement, but the App’s data is physically stored in Japan.
4.3 What transferring data to Japan means for you
Unlike the United States, Japan has a single comprehensive privacy statute of general application: the Act on the Protection of Personal Information (APPI), overseen by the Personal Information Protection Commission, an independent regulator. It applies to us as a Japanese operator. Japan and the European Union maintain a mutual adequacy finding, meaning each recognizes the other’s regime as providing an equivalent level of protection.
Japanese authorities may compel disclosure of data held in Japan under Japanese legal process. Your rights under this policy (§6) are offered to you contractually and are honored regardless of where the data sits.
4.4 Temporary storage for the Lock Screen forecast
While the Live Activity (§2.11) is enabled, its forecast is stored in Supabase Postgres (Tokyo region). If you are not signed in, this is the only data of yours that exists on any server. If you are signed in with sync turned off, it is the only content of yours on any server: your account record (§2.2) still exists on our authentication service, and your device registration exists if you have enabled notifications (§2.4). It is not linked to an account. Retention is as stated in §2.11.
5. Disclosure to third parties
5.1 Service providers
We engage the following service providers. Each processes data only on our instructions and for the purposes listed.
| Provider | Purpose | Data sent | Retention |
|---|---|---|---|
| Anthropic, PBC (US) | Reflection-card text generation | Aggregate session metrics only (drink count, total pure-alcohol grams, category counts, peak feeling, duration, optional hangover-severity estimate). No photos, no free-text notes, no profile or body data, no location. | Under a Zero Data Retention agreement, inputs and outputs are not retained after the request is processed. |
| Supabase, Inc. (US company; data stored in Japan) | Cloud storage for synced data | The §2.1 / §2.9 / §2.10 data you have chosen to sync | While the account is active; deleted on account deletion |
| Sentry (US) | Crash reports | OS info, stack trace, anonymous device identifier | 30 days |
| PostHog (EU) | Product analytics | Event logs and the §2.3 settings flags | 1 year |
| Google LLC / Firebase (US) | Push notification delivery, app attestation, feature configuration | Push notification token, device installation identifier, and the notification text we send you. No drink content, body data, or estimates. | While notifications are enabled |
Sentry and PostHog are each on by default; you can opt out of either individually from Settings.
Calls to Anthropic are routed through a proxy we operate. The App never communicates with Anthropic’s API directly from your device. The proxy enforces rate limits, daily spending caps, and device attestation.
5.2 We do not sell or share your personal information
We have never sold personal information, and we do not share it for cross-context behavioral advertising. We do not disclose personal information to advertisers, data brokers, ad networks, or any third party for marketing purposes. This has been true for the preceding 12 months and applies to all users, including anyone under 16.
We disclose personal information outside §5.1 only:
- when required by law, such as a valid court order or law-enforcement request; or
- when necessary to protect the life, body, or property of any person and obtaining your consent is not practicable.
5.3 Third-party collection across sites
We do not permit third parties to collect personally identifiable information about your online activities over time and across different websites or online services when you use the App.
6. Your choices and rights
We offer the following rights to every US user, regardless of your state of residence and regardless of whether a given state law applies to us by its own terms.
- Know and access — request the categories and specific pieces of personal information we hold about you, the categories of sources, the purposes, and the categories of third parties to whom we disclose it. Settings → Export Data downloads the data you contributed (drink logs, sessions, feeling check-ins, custom presets, BAC profile, acceptance records) as JSON immediately, without contacting us. The export covers everything you contributed except photo image files, which cannot travel in a JSON document: your photos are on your device, and if you use photo backup we will provide the stored image files on request. Operational records (sync state, device registrations, sign-in internals, notification toggles) are not in the export; ask us and we will provide them.
- Delete — Settings → Delete Account. Data on the device is deleted immediately. Cloud data may persist briefly in backups and replicas; full deletion completes within 30 days at the latest. Account identifiers held by your sign-in provider are managed under that provider’s own policies.
- Correct — drink logs, notes, place tags, and profile values can be edited directly in the App at any time.
- Opt out of sale or sharing — we do not sell or share personal information (§5.2), so there is nothing to opt out of and we display no “Do Not Sell or Share My Personal Information” link. If that ever changes, this policy will change first and the link will appear.
- Limit use of sensitive personal information — we do not use sensitive personal information for any purpose other than providing the App to you.
- Opt out of analytics and crash reporting — either can be disabled individually from Settings at any time.
- Non-discrimination — we will not deny you service, charge you a different price, or provide a different level of quality because you exercised any right in this section. Nomicho Plus pricing is unaffected by any privacy choice.
Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for written proof of authorization and may ask you to verify your identity directly.
Appeals. If we decline a request, you may appeal by replying to our response or writing to the §11 address with “Appeal” in the subject line. We will respond to an appeal within 45 days with a written explanation. If we deny the appeal, you may contact your state Attorney General.
How to make a request and how we verify you. Send requests to support@nomicho.jp. Because most of your data is on your device and much of the rest is reachable through the in-App controls above, the fastest route is usually Settings. For requests that require us to act, please write from your registered email address, or include an account identifier sufficient to locate the data. Requests are free. We respond within 45 days and may extend once by a further 45 days where reasonably necessary, telling you before we do.
7. Consumer health data
Some US state laws treat information about health, including information from which health status can be inferred, as its own category with its own rules. Your drink logs, everything we derive from them, your BAC profile, and any Apple Health readings you let us read all fall inside our view of that category.
Because those laws call for a separate and distinct policy, that is where this is covered: see our Consumer Health Data Privacy Policy, published alongside this one.
The short version, with the full detail in that document: we collect it only to run the features you are using, we never sell it, we disclose it to no one but the service providers who operate the App on our instructions, Apple Health data never leaves your device at all, we use no geofencing, and you can access, export, withdraw consent to, and delete it.
8. Do Not Track and Global Privacy Control
Some browsers and devices send a “Do Not Track” signal. There is no industry-accepted standard for how to respond to one, and the App does not respond to Do Not Track signals. This is not evasive: the App does not track you across other companies’ sites or apps in the first place, and permits no third party to do so (§5.3).
We honor a Global Privacy Control signal where one reaches us as an opt-out of sale or sharing. Because we do not sell or share personal information (§5.2), such a signal requires no change in our handling of your data.
9. Age and children
The App is for adults of legal drinking age. You must be 21 or older to use it, which is the legal drinking age in every US state; a small number of US territories set a lower age, but our own requirement is 21 regardless. The App is not directed to children, and we do not knowingly collect personal information from anyone under 13. We do not knowingly sell or share the personal information of anyone under 16, because we do not sell or share personal information at all.
If we learn that we have collected personal information from a child under 13, we will delete it. If you believe a child has provided us information, contact support@nomicho.jp.
10. Security
We protect your information with Row-Level Security on every user-owned table, encryption in transit, private-by-default storage objects, and device attestation on calls to our AI proxy. Access to production data is limited to the operator.
No method of transmission or storage is completely secure. If a breach affecting your personal information occurs, we will notify you and any regulator as required by the law of your state, without unreasonable delay.
11. Contact
- Email: support@nomicho.jp
- Operator: Chris Hashimoto (橋本クリス), sole proprietor
- Address: disclosed without delay upon request
We respond within a reasonable period, and within the deadlines set by §6 for rights requests.
12. Changes to this policy
We may revise this policy when the law changes, when we add or change features, or when our operations change. The effective date above always reflects the current version, and the revision history below records what changed.
For material changes, we will give notice in the App before the change takes effect, and where you have enabled sync, by email. Continuing to use the App after the effective date means you accept the revised policy.
13. Revision history
| Version | Date | Summary |
|---|---|---|
| 1.0 | 2026-09-03 | Initial version. |