Cairn

Privacy Policy

Last updated: April 20, 2026 · Draft v0.1

Cairn ("the Service") respects your privacy. This Policy describes what personal data we collect, how we use it, and your rights. This is a draft requiring cross-jurisdictional review (GDPR, Japan APPI, CCPA, LGPD) before final launch.

1. Data We Collect

1.1 From Writers

1.2 From Readers

Reading requires no account. No personal data is collected from readers.

2. How We Use Data

DataPurpose
ID documentsVerify real person; prevent duplicate registration
Name, year of birthIdentity verification; extract year-of-birth for public display
CountryPublic meta; regional pricing
EmailService-related communication
Entry textPublic display (core purpose)
IP / UAFraud prevention; regional pricing

3. What Is Made Public

Public

Not Public

4. Third-Party Sharing

We share personal data only with:

  1. Payment providers (Stripe, etc.) for transactions
  2. Cloud infrastructure (Cloudflare, etc.) for encrypted storage/delivery
  3. KYC providers (Onfido, Persona, etc.): under current operations, identity verification is not delegated to a third party. If we delegate in future, this Policy will be amended in advance, and only the minimum necessary data will be shared.
  4. Legal disclosure in response to valid court orders or law enforcement requests
  5. With your explicit consent

All processors operate under GDPR-compliant Data Processing Agreements (DPAs).

5. International Data Transfers

Data is stored redundantly across multiple regions, which may include Japan, the US, and the EU. We rely on Standard Contractual Clauses (SCCs) under GDPR Article 44 et seq. for international transfers.

6. Retention

DataRetention
Entry text and public metaPermanent
ID documents (when voluntarily submitted)Deleted within 90 days of resolving the matter that prompted collection. Up to 7 years if required by Japanese tax/legal record-keeping (per the Income Tax Act bookkeeping retention rules).
Real name, email, card fingerprint (for duplicate detection)Retained while the corresponding entry remains active. Deleted within 30 days if the entry is retracted.
Payment recordsAs required by law (Japan: 7 years)
Access logs (IP/UA)30 days
Email address (contact)For the lifetime of the account

Permanent retention of Entries is the core value of the Service. We delete only under Terms §11.

In normal operation we do not collect ID documents. They are requested only in specific cases of suspected fraud or duplicate registration. Submission is voluntary, and any submitted document is physically deleted from encrypted storage as soon as the retention period above elapses.

7. Your Rights

Under GDPR and equivalent laws, you have the right to:

  1. Access your personal data
  2. Rectification of inaccurate data (Entry text is not rectifiable)
  3. Erasure ("right to be forgotten") under specific conditions per Terms §11
  4. Data portability — receive your data in machine-readable form
  5. Withdraw consent for KYC processing going forward

Contact the operator (see Section 12) to exercise these rights.

8. Security

9. Cookies

We use cookies only to maintain your session during writing. No tracking cookies. No advertising cookies. No third-party analytics (no Google Analytics, etc.).

10. Children's Privacy

  1. We do not collect data directly from children under 16 (proxy registration by guardians excepted).
  2. Proxy registration requires the guardian's confirmation of legal authority over the child.
  3. Upon reaching adulthood, the child may exercise full data access and deletion rights over their data.

11. Changes to This Policy

This Policy may be updated. Material changes are notified to registered email addresses.

12. Contact

The operator's legal name and registered address are not publicly displayed. They will be disclosed without undue delay, in writing or by email, upon request under Japan's Act on Specified Commercial Transactions or other applicable law (a "disclosure-upon-request" model). Please send such requests to the contact address above.

Requests to access, correct, or restrict the use of your personal data, and any other privacy-related enquiries, should also be sent to the address above.