Home

Privacy Policy

Last updated: 2026-09-29

The operator of CafePicks (the “Operator”) sets out below how it handles users’ information in CafePicks, a cafe search and recommendation service (the “Service”).

This English version is a translation of the Japanese Privacy Policy (日本語), provided for convenience. The Japanese version is the governing text; if the two differ, the Japanese version prevails.

Summary of this policy

  • You can use the Service without creating an account. We hold account information (such as your name and email address) only if you sign in with a Google account.
  • To improve the Service, we record how it is used. These usage records are not linked to your account and do not include your search terms, location, or IP address. You can stop the recording at any time (see 7 below).
  • We do not send your current location coordinates to, or store them on, the Operator’s servers.
  • For analytics, information is sent from your browser to Google Analytics (Google LLC) (see 4 below). It is not used for advertising.
  • For access from the European Economic Area (EEA), the United Kingdom or Switzerland, we neither record usage nor send information to Google Analytics.
  • We do not provide the information we collect to third parties, except where required by law and where it accompanies the entrustment of handling described in 5 below (including to businesses outside Japan).

1. Information we collect

(1) Account information (if you sign in)

  • Your Google account’s display name, email address, profile image URL, and account identifier
  • Information used to keep you signed in (session identifier and expiry, the IP address you connect from, and your browser type)

You can sign in only with a Google account. The Service never holds your password.

(2) Saved cafes and lists (if you sign in)

  • Cafes you have saved (the cafe, when you saved it, and whether it is marked “Visited” or “Favorite”)
  • Lists you have created (the list name, the cafes in it and their order, when it was created, whether it is public or private, and the identifier contained in its sharing URL)
  • The number of times you saved cafes or changed lists that day, to prevent excessive load (this does not include what you changed; the count resets when the date changes)

If you set a list to “public”, anyone who knows its sharing URL can see the list name and the cafes in it without signing in. The shared page does not show your name, email address, or account identifier. The shared page is set not to be indexed by search engines, but we cannot prevent someone who has received the URL from passing it on to others.

You can unpublish, change, or delete a public list at any time from the list screen. Once unpublished, the list can no longer be viewed from that URL, but the sharing URL itself does not change, so if you make the list public again it becomes viewable at the same URL. If you want a URL you shared earlier to stop working, regenerate the sharing URL from the list screen.

(3) What you send us (corrections and cafe requests)

  • Correction reports: the cafe and field concerned, what you reported, the supporting URL, any additional comment, and when you reported it
  • Requests to add a cafe: the cafe name, area and nearest station, a reference URL, any additional comment, and when you sent it
  • If you send them while signed in, your account identifier (used to track their status and to prevent a large number of submissions in a short time)
  • A code derived from the IP address you connect from, which changes every day (used to prevent a large number of submissions in a short time)

For these submissions, we do not store the IP address itself. The code is produced from the IP address and the date by a calculation that cannot be reversed, so the IP address cannot be recovered from the code. Because the code is different on each day, submissions made on different days cannot be linked to each other; the code is used only to associate submissions received on the same day.

We do not copy the content you send (the correction, the cafe name, comments, and URLs) into places the Operator works in, such as GitHub Issues. However, to check the status of submissions and to create database backups, it is handled temporarily on GitHub’s servers (see 5 below), and it is included in database backups (see 5 and 6 below).

(4) Usage records

To understand which features are used and where people stop using the Service, and to improve the Service, we record on the Operator’s servers, together with the date and time, actions such as the following in the Service, whether or not you are signed in. The same content is also sent to Google Analytics (see 4 below).

  • Opening a page (including whether the Service was launched from a home screen icon or opened in a browser)
  • Searches (the type of search, the number of results, and, when you searched by area, which area)
  • Showing recommendations and lists (which section showed how many cafes, and, on the home screen, the cafe shown first in each themed list)
  • Opening a cafe’s details (the cafe, and which screen, list, or map action you opened it from; when opened from a themed list on the home screen, which theme’s list it was in and at which position)
  • Actions on a cafe’s details (sharing, links to the cafe’s Instagram or official website, links to directions or the map), saving and unsaving, marking “Visited” or “Favorite”, and actions related to lists — each including the cafe concerned
  • Signing in with a Google account (whether it was your first sign-in or a later one)
  • Showing the map and filtering the map (the type of filter, the items chosen, the number of cafes after filtering, and pressing the current location button)
  • The map, search, recommendations, cafe details, or saving failing to load or to be applied (which feature)

When you perform one of the actions above on a cafe while its details are open, we also record where you opened those details from (this is not attached to actions on other cafes). We do not record removing a “Visited” or “Favorite” mark.

To count whether the Service is used repeatedly from the same browser, when you first perform one of the actions above we issue a random identifier that carries no meaning, store it in a cookie, and attach it to the records. Because this identifier is different for each browser, what we can count is “return visits from the same browser”, not the number of people. If you delete your browser’s site data, or use another device or browser, you are counted as a different one.

The following information is not included in these records.

  • Which account performed the action (even for actions while signed in, we record only whether you are signed in and, when you sign in, whether it is your first sign-in or a later one; we also do not link the identifier to your name, email address, or account)
  • Search terms, your name, and your IP address
  • Location information (including your current location and the position or range you viewed or moved on the map), and the date and time specified in a map filter
  • List names and sharing URLs, the URLs of links, and the content or URL of errors when something failed to load

For access from the European Economic Area (EEA), the United Kingdom or Switzerland, we do not make these records and do not issue the identifier. We also do not record when the region cannot be determined. When you open a screen of the Service from these regions and an identifier issued earlier remains in your browser, we delete that cookie and also delete the usage records made with that identifier.

You can stop this recording yourself at any time (see 7 below).

(5) Current location

On the Map and Saved screens, we use your device’s location to show your current location on the map and to show the distance to cafes.

  • We start getting your location only when you press the current location button (or, if you have already given permission, when you open those screens). We never ask for permission just because you opened a screen.
  • Once started, we keep getting your location while the Map or Saved screen is displayed, to update the display as you move. We stop when you move to another screen or send the browser to the background.
  • We neither send your current location coordinates to, nor store them on, the Operator’s servers. Distances to cafes are calculated entirely within your browser.
  • When the map is shown around your current location (when you press the current location button, and when you open the Map or Saved screen with permission already given), the map data for that area is obtained from Google. As a result, the area of the map being shown is conveyed to Google, and Google may be able to tell your approximate current location (see 4 below).
  • Your current location coordinates themselves are not stored on your device either. However, after the map has been moved to your current location, the map position around it remains on your device as “the map position last shown” (see 3 below).
  • You can withdraw location permission at any time in your browser settings.

(6) Access logs

Records of access (IP address, date and time of access, browser type, and so on) remain for a certain period on the servers of the Service’s hosting provider (Vercel, see 5 below). The Operator refers to them only to investigate failures.

2. Purposes of use

  • To provide cafe search and recommendations, saved cafes and lists, and to let you carry your saved cafes across devices
  • To provide lists set to public through their sharing URLs
  • To check and correct errors in the listed information, and to consider which cafes to list
  • To understand where visitors come to the Service from (search engines, social media, AI assistants, and so on), how much each feature is used, and where people stop using the Service, and to improve the Service based on this
  • To compile figures for each cafe, such as the number of views and uses of directions, to share with the listed cafes (we share only per-cafe totals, not individual records)
  • To prevent misuse and excessive load
  • To protect and restore data against failures and mistakes, and to investigate failures
  • To respond to inquiries

3. Information stored on your device (cookies, etc.)

The Service uses cookies and browser storage (localStorage and sessionStorage) for the following purposes. The Service itself sets only three kinds of cookies: for sign-in, for usage records, and for the result of the regional check on whether to load Google Analytics. In addition, Google Analytics sets a cookie that identifies your browser. None of these are used to deliver advertising or to track your activity across other websites.

  • Sign-in: cookies for the sign-in process and for keeping you signed in (only if you sign in)
  • Usage records: a cookie that stores the identifier in 1(4) above (it expires 13 months after it is issued, and the expiry is not extended by use; it is not set for access from the European Economic Area (EEA), the United Kingdom or Switzerland)
  • Google Analytics: a cookie that stores the result of the regional check on whether to load Google Analytics and make usage records (it stores only “yes/no”, not the country or region itself, and expires when you close the browser), and a cookie in which Google Analytics stores an identifier for your browser (it is sent to Google; it expires 13 months after it is issued, and the expiry is not extended by use)
  • Information used only on your device: your search history, cafes saved without signing in, display settings (the recommendation sort order, the map position and zoom last shown on the Map screen, a record that you closed the “add to home screen” prompt, and the setting that stops usage recording), and the account identifier used to carry over saved cafes

The sign-in and usage-record cookies are sent only to the Operator’s servers. “Information used only on your device” is not sent to the Operator’s servers. The one exception is cafes saved without signing in: if you sign in while such saved cafes remain on your device, they are sent to the server to carry them over and are added to your saved cafes in 1(2) above. Cafes saved on the same device after signing out are also added in the same way when you sign in again with the same account.

The account identifier used to carry over saved cafes is not your name or email address, but a string the Service assigns to each account. The identifier of the account that last completed carrying over saved cafes on this device is recorded even if there were no saved cafes on the device at sign-in, and it remains on the device after you sign out (so that cafes saved after signing out can be added when you sign in again with the same account). If carrying over does not complete, we also record an identifier showing which account the saved cafes left on the device belong to, and delete it once carrying over completes (so that, if you sign in to a different account on the same device, the previous account’s saved cafes are not added). Neither is sent to the server.

These are removed when you delete your browser’s site data. The usage-record cookie is deleted when you stop recording in 7 below (for Google Analytics cookies, we attempt to delete them). In addition, when you use external services, such as when a map is shown, those services may set cookies.

4. Sending information to external services

Information is sent directly from your browser to the following services. All of them are provided by Google LLC. We have not introduced any tools intended for advertising.

Google Analytics (Google LLC)

  • Information sent: the URL and title of the pages you view (on shared list pages, with the sharing identifier and the list name removed); the site you were viewing just before coming to the Service (major search engines, social media, AI assistants and similar sites are sent by site name only, and others as “other site”; the location of the page, search terms, and the content or identifiers of conversations with AI assistants are not sent); the actions in 1(4) above and the cafe, screen, and where the cafe’s details were opened from (for failures to load, only which feature and which screen); scrolling to the end of a page; pressing a link to an external site (the URL of the link pressed, which is limited to public links the Service shows, such as a listed cafe’s official website, social media, and map directions); the type of device, browser and OS, screen size, and language; whether you are signed in and, when you sign in, whether it is your first sign-in or a later one; the Google Analytics identifier in 3 above; and the IP address that accompanies the communication (Google estimates an approximate region from the IP address and, according to Google, discards the IP address after the estimate without storing it)
  • Information not sent: your name, email address, or anything that identifies which account you use; search terms; location information; list names and sharing URLs; and the content of errors
  • The Operator’s purpose: to understand the relationship between where visitors come to the Service from and which features they then use, and to improve the Service
  • Google’s purpose: to provide and maintain Google Analytics. For details, see Google’s “How Google uses information from sites or apps that use our services” and the Google Privacy Policy
  • In the Google Analytics settings, we have turned off all advertising features (Google signals and ads personalization) and the settings that allow Google to use Google Analytics data for its own products and services (data sharing settings)
  • For access from the European Economic Area (EEA), the United Kingdom or Switzerland, Google Analytics is not loaded and no information is sent to it. The same applies when the region cannot be determined. For this check, we look up the approximate region (country) of the access at the time of the communication (for how the result is stored, see 3 above). Communication with Google for showing maps and for sign-in is not covered by this
  • Besides 7 below, you can also stop the sending with Google’s browser opt-out add-on

Google Maps (Google LLC)

  • Information sent: on screens that show a map, the information in the communication needed to show the map (including the area of the map being shown; when the map is shown around your current location, that area is also conveyed; see 1(5) above)
  • The Operator’s purpose: to show maps
  • Google’s purpose: to provide its map service. For details, see the Google Privacy Policy

Sign-in with a Google account (Google LLC)

  • Information sent: when you choose to sign in, the information needed for the sign-in process
  • Information not sent: the content of cafes and lists saved in the Service, and usage records
  • The Operator’s purpose: to confirm your identity and provide sign-in
  • Google’s purpose: to authenticate Google accounts. For details, see the Google Privacy Policy

5. Provision to third parties and entrustment of handling

The Operator does not provide the information it collects to third parties, except where required by law and where it accompanies the entrustment of handling described in this section.

To operate the Service, we entrust the handling of information to the following businesses. All of them are businesses outside Japan, and as a result of the entrustment, information may pass to businesses outside Japan and be handled outside Japan. This is separate from the direct sending of information from your browser to Google described in 4 above.

  • Vercel Inc. (United States) — delivery of the Service and server-side processing. The information in 1(1)–(4) above is handled on its servers, and the records in 1(6) above remain there. Server-side processing is configured to take place in the Tokyo region, but Vercel and its subprocessors may handle information in the United States and other countries (the locations of the subprocessors Vercel discloses are mainly in the United States)
  • ChiselStrike Inc. (service name Turso, United States) — operation of the database. It stores the information in 1(1)–(4) above. The database is located in the Tokyo region (Amazon Web Services)
  • GitHub, Inc. (United States) — running processes the Operator performs regularly (such as creating database backups, compiling usage records and deleting records past their retention period, and checking the status of correction reports and cafe requests). During these processes, the information in 1(1)–(4) above stored in the database is handled on GitHub’s servers
  • Google LLC (United States) — processing, in Google Analytics, of the information sent as described in 4 above
  • Google Cloud (the contracting party is Google Asia Pacific Pte. Ltd. [Singapore] and its affiliates) — (i) Storage and aggregation of a copy of the information recorded in Google Analytics (the “analysis copy”). The Operator exports it daily from Google Analytics and may use it for analyses that cannot be done in the Google Analytics screens (such as the order of actions within the same visit). The copy contains what Google Analytics recorded (the content of actions, pages, device type, approximate region estimated from the IP address, the Google Analytics identifier, and so on) and does not contain the IP address itself. This is separate from the data sharing settings (use by Google) in 4 above. (ii) Storage of database backups. The information in 1(1)–(4) above is encrypted and then stored in the Tokyo region; it does not include the information used to keep you signed in or the credentials used to link with Google accounts. The analysis copy in (i) is stored and processed within the scope of the Operator’s instructions, under Google Cloud’s data processing terms

With Vercel, our contract, including Vercel’s Data Processing Addendum (DPA), provides that personal data contained in the data the Service entrusts to Vercel is processed in accordance with the Service’s instructions, and sets out security measures, the management of subprocessors, deletion when the contract ends, and so on.

For information on the personal information protection systems of foreign countries, see the information published by the Personal Information Protection Commission of Japan (in Japanese). If you would like to know more about how information is handled by the businesses we entrust it to, please contact us through the contact page.

Making a list public (1(2) above) means you enable its sharing URL through your own action; it is not a provision of information to third parties by the Operator. You can choose whether or not to make a list public.

6. Retention periods

  • Information used to keep you signed in: it expires when its expiry passes or when you sign out
  • Accounts, saved cafes, and lists: kept until you delete them yourself or ask us to delete them
  • Correction reports and cafe requests: kept even after they have been dealt with, to judge whether the same content is duplicated
  • Usage records (1(4) above) on the Operator’s servers: records older than 13 months are deleted, after which we keep only aggregate figures that do not involve individual records
  • Records in Google Analytics: the retention period for user-level and event-level data is set to 14 months, and data past that period is deleted by Google’s monthly process. Aggregated reports and the analysis copy are not covered by this setting
  • The analysis copy (5 above): stored in separate tables for each day, and the table for any day more than 365 days after the date of the records is deleted in a daily check (we also use a setting that automatically deletes each table at its expiry). A deleted table remains, through Google Cloud’s mechanism against mistakes, in a state the Operator can restore for up to 7 days, and then in a state that can be restored only through Google support for up to 7 more days, after which it can no longer be restored. Final erasure from within Google’s systems (such as backups) takes place, in accordance with Google Cloud’s data processing terms, within up to 180 days after the Operator can no longer restore it (except where storage is required by law)
  • Database backups stored in Google Cloud (5 above): scheduled for deletion 35 days after they are created, and deleted automatically. The actual deletion may be delayed. We do not use any mechanism by which the Operator restores deleted backups. Final erasure from within Google’s systems takes place, in accordance with Google Cloud’s data processing terms, within up to 180 days after the Operator can no longer restore them (except where storage is required by law)
  • Database backups kept on the Operator’s device: those more than 35 days after they were created are deleted in a daily check. Deletion may be delayed while the device is not in use

7. Stopping usage recording

You can stop the usage records (1(4) above) and the sending of information to Google Analytics (4 above) at any time with the button below. Stopping them does not limit any features of the Service.

You can stop measurement from the browser on this device. When you stop it, we delete the identifying cookie and also delete the usage records made with that identifier. Sending to Google Analytics also stops, and we attempt to delete the cookies Google Analytics has set on this site (information already sent to Google is not deleted retroactively by this action). This is a setting for each device and browser. On a shared device, it also stops measurement for other people using the same browser.

Current status: Measuring

8. Security measures

  • Communication with the Service is encrypted (HTTPS).
  • Database connection details and credentials for external services are managed so that they are not made public.
  • Database backups stored in Google Cloud are encrypted before being stored, and are never placed in Google Cloud unencrypted. The key for decrypting them is managed by the Operator in a place separate from where the backups are stored.
  • Database backups kept on the Operator’s device are stored on a device whose entire disk is encrypted, and are excluded from backups of that device to external storage.
  • For the businesses we entrust handling to and handling outside Japan, see 5 above.

9. Requests for disclosure, correction, deletion, etc.

If you would like the disclosure, correction, or deletion of your information, or the deletion of your account, please contact us through the contact page. We will respond once we can confirm that the request comes from you.

You can delete or change the following yourself.

  • Information stored only on your device (3 above): delete your browser’s site data
  • Usage records on the Operator’s servers (1(4) above): stop them in 7 above (the records for that browser are also deleted)
  • Lists: from the list screen, make a list private, regenerate its sharing URL, or delete it

Information deleted at your request, or deleted by you (such as saved cafes, lists, and usage records deleted when you stopped them), remains in database backups created before then. We do not delete individual records within backups; backups are deleted when the periods in 6 above have passed.

Google Analytics and the analysis copy. Information already sent is not deleted retroactively even if you stop in 7 above. Because these records contain nothing that leads to you, such as your name or account, we cannot identify the relevant records from your request alone. If you would like them deleted, please contact us with the value of the Google Analytics cookie stored in that browser whose name is exactly “_ga” (not one where “_ga_” is followed by letters and numbers). If we can identify the records corresponding to that value, we will delete that browser’s records from both Google Analytics and the analysis copy (the Operator deletes them from the copy separately). This value indicates a browser, and records left from other browsers or devices are not included. According to Google, deletion in Google Analytics takes up to 63 days to complete. Records deleted from the copy also remain restorable for up to 14 days under the mechanism in 6 above. If you do not know the value, or have already deleted your site data, we cannot identify the records and so cannot respond to a deletion request (those records are deleted when the period in 6 above has passed).

Correction reports and cafe requests sent without signing in contain no information that identifies the sender, so we cannot confirm that a request comes from you and may be unable to respond to individual deletion requests.

10. Public information about cafes we collect for listing

This section concerns the cafes listed in the Service and their public accounts. Both are collected by the Operator and do not involve sending users’ information.

  • Google Maps Platform (Google LLC) — collecting information about listed cafes
  • Meta (Instagram API) — collecting the follower counts of the public Instagram accounts (business and creator accounts) of listed cafes (used only for the order in which cafes are shown and for choosing the next cafes to introduce on a cafe’s details; the follower counts themselves are not shown on the Service’s screens)

11. Use by minors

If you are a minor and sign in to use the Service, please do so with the consent of a parent or guardian.

12. Changes to this policy

The Operator may change this policy as necessary. The changed policy applies from the time it is posted on this page. If there are material changes to the information we collect or the purposes of use, we will announce them in a way that is clear within the Service.

13. Contact for inquiries and complaints

For inquiries and complaints about this policy and the handling of information, please contact us through the contact page.