WhyRead Privacy Policy

Last updated: August 21, 2026

Effective date: May 7, 2026

Cafigla LLC (Japanese name: 合同会社カフィグラ; address: 395-1-306 Iwakura Hanazono-cho, Sakyo-ku, Kyoto, Japan) ("we") provides WhyRead (the "Service") and sets out how we handle users’ personal information and other user information ("User Information") in this Privacy Policy (this "Policy").

Our contact email is info@cafigla.com.

Scope

  1. 1.This Policy applies to User Information we handle in connection with use of the Service. The Service includes our website and mobile apps, as well as browser extensions (for example, an extension for Google Chrome).
  2. 2.If a separate privacy-related notice appears in the Service or on our website, that notice forms part of this Policy.

Information We Collect

In providing the Service, we may collect the following User Information.

  1. 1.Account information. When you log in to the Service, we obtain identifiers, display names, email addresses, avatar image URLs, and similar data through authentication providers (Google LLC (United States) or X Corp. (United States)). We do not retain plaintext passwords ourselves.
  2. 2.Saved content. URLs, titles, site names, and image URLs of articles, books, and similar items you save to the Service; text such as save reasons (Why) and notes; URLs or text linked as sources; save timestamps; read/unread and other statuses.
  3. 3.Information related to AI summaries. Article body text or portions thereof obtained to generate AI summaries (including text extracted from HTML retrieved by crawling), generated summary text, and usage counts and history of the AI summary feature.
  4. 4.Payment information. When you subscribe to a paid plan, customer IDs, subscription IDs, plan identifiers, contract status, billing-period end dates, and similar data obtained through our payment processor, Stripe, Inc. (United States). Details of payment methods such as credit card numbers are processed by Stripe; we do not retain those details.
  5. 5.Usage and log information. Access timestamps, IP addresses, user agents, referrers, in-Service operation history, error information, and similar data. When you use the mobile app (provided via Capacitor), we may collect device and environment information needed to provide the Service, such as OS and app versions.
  6. 6.Cookies, local storage, and on-device storage. To maintain authentication sessions, store settings, and ensure security, we may use browser cookies or local storage, extension storage provided by browser extensions (for example, chrome.storage), and secure on-device storage provided by the OS in the mobile app (for example, iOS Keychain).

How We Use Information

We use collected User Information within the following purposes.

  1. 1.Providing, maintaining, and improving the Service (including feature development, quality improvement, and usage analysis)
  2. 2.Identity verification, authentication, and account management
  3. 3.Providing paid plans, billing, and contract management
  4. 4.Providing the AI summary feature (including transmission to external AI services)
  5. 5.Responding to inquiries, complaints, and disputes
  6. 6.Preventing, investigating, and responding to misuse and violations of the terms
  7. 7.Complying with laws and responding to requests from public authorities
  8. 8.Purposes incidental to the above

Sharing with Third Parties

  1. 1.We will not provide User Information to third parties except in any of the following cases:
    • You have consented
    • Required by law
    • Necessary to protect a person’s life, body, or property, and it is difficult to obtain your consent
    • Especially necessary to improve public health or promote the sound development of children, and it is difficult to obtain your consent
    • Necessary to cooperate with a national or local government, or a party entrusted by them, in performing legally prescribed duties, and obtaining your consent may impede those duties
  2. 2.Notwithstanding the preceding paragraph, provision to processors or to third parties located in a foreign country may occur as described in Sharing and Processors and International Processing.

Sharing and Processors

To the extent necessary to provide the Service, we may entrust all or part of the handling of User Information to the following providers (each belonging to a group primarily headquartered in the United States). We endeavor to select and supervise processors appropriately.

Please refer to each provider’s website for their privacy policies and related documents.

  1. 1.Supabase Inc. (United States) — database, authentication infrastructure, and Edge Functions (server-side processing)
  2. 2.Vercel Inc. (United States) — hosting of the web application
  3. 3.OpenAI, L.L.C. (United States) — generation of AI summaries (portions of article text and similar data may be transmitted; see International Processing and AI Summaries)
  4. 4.Stripe, Inc. (United States) — payment processing for paid plans
  5. 5.Google LLC (United States) — OAuth login (Google accounts)
  6. 6.X Corp. (United States) — OAuth login (X accounts)
  7. 7.Apple Inc. (United States) — distribution of the iOS app and processing incidental to app distribution
  8. 8.Google LLC (United States) — distribution of the Android app (Google Play) and processing incidental to app distribution
  9. 9.Umami Software, Inc. (United States) — website analytics (Umami Cloud; page views. No cookies are used)

International Processing

※ URLs may change due to revisions. Please check the Commission’s latest publications.

  1. 1.Among the processors listed above, if data is stored or processed outside Japan (primarily in the United States), User Information may constitute a provision to a third party located in a foreign country.
  2. 2.The principal data-processing regions we designate for the Service are as follows:
    • Supabase: Tokyo region (ap-northeast-1)
    • Vercel: Tokyo region (hnd1)
    • Umami Cloud: United States region
    • However, due to incident response, redundancy, CDN delivery, operational needs, or similar reasons of each provider, data may be processed or temporarily stored in other regions.
  3. 3.Under Article 28 of Japan’s Act on the Protection of Personal Information (the “APPI”), when providing personal data to a third party in a foreign country, we make available information on the personal-information protection systems of that country as published pursuant to rules of the Personal Information Protection Commission (for example, by referring to the Commission’s website), and we provide information on the security measures we take through this Policy or notices in the Service.
  4. 4.Example of reference information: Personal Information Protection Commission, “Provision of Personal Data to a Third Party in a Foreign Country” (https://www.ppc.go.jp/)
  5. 5.Examples of information that may be transmitted when providing data to OpenAI: article text, URLs, metadata, and similar data to the extent needed to generate summaries. Processing is subject to OpenAI’s terms of use and privacy policy.

AI Summaries

  1. 1.AI summaries are automatically generated using generative AI services provided by OpenAI, L.L.C.
  2. 2.In the course of generating a summary, some or all of the text of saved articles and similar content may be sent to OpenAI.
  3. 3.We do not warrant the accuracy, completeness, or currency of AI summaries. You use generated results at your own responsibility.

Security Measures

We take organizational, personnel, physical, and technical security measures to prevent leakage, loss, or damage of User Information and otherwise to manage it securely. Technical measures include encryption of communications (HTTPS), access control via row-level security (RLS) in the database, management of secrets via environment variables, and least-privilege access.

Retention

  1. 1.We retain User Information for the period necessary to provide the Service, or the period required by law, whichever is longer.
  2. 2.If you request deletion of your account, we will delete or anonymize the data within a reasonable period. However, information we are legally required to retain, or data that technically remains in backups for a period, may persist. After that period, we endeavor to delete or anonymize it.

Your Rights

  1. 1.For requests under the APPI and other laws for disclosure, correction, addition, deletion, suspension of use, erasure, disclosure of records of third-party provision, and similar requests (“Disclosure Requests”), please contact us at info@cafigla.com.
  2. 2.We may ask you to cooperate with identity-verification procedures we designate.
  3. 3.We will respond within a reasonable period in accordance with applicable law. If we cannot fulfill a request, we will explain the reason.
  4. 4.At present, the Service does not include an in-product account-deletion (withdrawal) feature. If you wish to delete your account, please email info@cafigla.com. We will inform you individually of when deletion will be completed.

Cookies and Local Storage

  1. 1.The Service may use cookies, local storage, or on-device storage in the mobile app to maintain authentication, improve convenience, and ensure security.
  2. 2.On the Service’s website, we use analytics provided by Umami Software, Inc. (United States) (Umami Cloud) to understand usage. This analytics does not use cookies. It collects the path viewed, referrer, browser and device type, approximate region, and similar data. We do not use it for advertising or to track behavior across other websites.

Browser Extensions

  1. 1.If you use a browser extension we provide, you may link it with your WhyRead account. In connection with linking, the extension may store authentication tokens, API endpoints, display email addresses, and other information needed for linking in extension storage on your device (for example, chrome.storage).
  2. 2.When you instruct the extension to save a page, the extension sends the page URL, title, and other information needed to save, as well as any save reason (Why) or notes you entered, to the Service’s servers. This information is handled as saved content under Information We Collect.
  3. 3.If you choose to use AI summaries in the extension, that information is handled in accordance with AI Summaries and other AI-summary provisions of this Policy.
  4. 4.The extension does not continuously collect web browsing history without your action, record keystrokes, or read the contents of unrelated websites.
  5. 5.Communications between the extension and the Service’s servers are encrypted (HTTPS) and otherwise subject to the security measures described in Security Measures.

Minors

Handling of User Information of minors (persons under 18 years of age) follows the Terms of Service. Where consent of a legal representative is required, we may ask you to cooperate to the extent we request.

Changes to This Policy

  1. 1.We may change this Policy when we determine it necessary, including due to legal amendments or changes to the Service.
  2. 2.The revised Policy takes effect when posted in the Service, or on an effective date we otherwise specify.
  3. 3.If you use the Service after a change, you are deemed to have agreed to the revised Policy.

Contact

For inquiries about this Policy or our handling of User Information, please contact info@cafigla.com.