Privacy Policy
How personal information is handled when you use TenkaCloud (the "Service"). The Japanese version at /privacy.html is the legally binding original; this English version is provided for reference.
1. Information we collect
To provide the Service and respond to inquiries, we may collect the following.
- Inquiry information: name, organization, contact email, inquiry type, and the body of your inquiry (collected via a Google Form). The form is presented on this site, but what you enter is sent from your browser straight to Google's servers and never passes through the Service's own infrastructure.
- Operator account information: the email address and username of operators who sign in to the Service (System Admin / Tenant Admin / Operator). Stored in Amazon Cognito, our identity provider.
- Operation audit logs: a record of operator actions, including the actor identifier (Cognito sub) and username (= email), the action / target / outcome, the source IP address and User-Agent, and the timestamp. Kept for security auditing and unauthorized-access investigation.
- Event operation data: participant data (= team name / display name), submission logs, and scoring history for events you run on the Service. Stored on the Service's SaaS infrastructure (= AWS) and automatically deleted 7 days after the event ends. Note that we do not create individual participant accounts (name / email); teams authenticate with a short-lived per-team key, so no information directly identifying an individual participant is collected.
- Access logs: IP address, User-Agent, referrer, etc. for visitors to the landing page and the portal. Retained per the standard logging policies of GitHub Pages / Amazon CloudFront.
- Browser demo interaction data: onboarding display variant, step shown, hint reveal, submission result, and elapsed time to completion. Answer text, flags, and team keys are not sent to Google Analytics.
2. Purpose of use
- Replying to inquiries and providing quotes.
- Operating the Service, responding to incidents, and security auditing.
- Statistical analysis to improve the Service (= in a form that does not identify individuals).
- Compliance with legal requirements (= legitimate requests from police, courts, etc.).
3. Disclosure to third parties
We do not disclose personal information to third parties without your consent, except as required by law. Data may, however, be stored on the following cloud providers (= used as infrastructure; not for content inspection):
- Amazon Web Services, Inc. (= SaaS infrastructure provider)
- GitHub, Inc. (= landing page delivery and OSS repository host)
- Google LLC (= contact-form response storage and analytics for the landing page and browser demo)
4. Retention
- Inquiry information: 2 years after the engagement ends.
- Operator account information: until the account is removed.
- Operation audit logs: 90 days by default; 365 days on hosted plans with SOC2-style requirements (configured via
AUDIT_RETENTION_DAYS). Automatically deleted afterwards. - Event participant data: 7 days after the event ends. Automatically deleted afterwards.
- Access logs: Standard retention of AWS / GitHub.
5. Disclosure, correction, and deletion requests
To request disclosure, correction, or deletion of your personal information, please contact us via the contact channel below. After identity verification, we will respond promptly in accordance with applicable laws.
6. Cookies / tracking
The landing page and browser demo (portal-demo) use Google Analytics 4 (gtag.js) for traffic analysis and onboarding improvement and set Google Analytics cookies (e.g. _ga). In addition to pages viewed, approximate region, and device/browser, the demo sends the assigned display variant, step ID, hint reveal, submission result, and elapsed time to Google LLC, which processes the data on our behalf. Answer text, flags, and team keys are not sent; the data is used only for aggregate journey analysis. The production participant portal does not load this Google Analytics measurement. The demo uses localStorage for A/B assignment and session management. You can opt out via your browser settings or Google's opt-out add-on (= as of 2026-07).
7. Revisions
This Policy may be revised in response to changes in law or in the Service. Material revisions will be notified by posting to this page.
8. Contact
For privacy-related inquiries, please contact us via:
- Operator: BULL LLC (合同会社BULL), operator of TenkaCloud
- Channel: GitHub Discussions or the contact form on the landing page