Privacy Policy

This document has been translated from the Japanese original for reference purposes only. In the event of any discrepancy between this translated document and the Japanese original, the original shall prevail.

Pirika, Inc. (the "Company", "we" or "us") sets out below its policies and procedures regarding the collection, use and disclosure of information received through the websites, APIs, third-party sites and other services that we provide (collectively, the "Services"). The Services include "SNS Pirika", which we provide as a smartphone application and a website.

Article 1 (General Provisions)

  1. We collect the personal information of users of the Services (each a "User") by lawful and fair means, with appropriate protective measures in place, and use it for the purposes set out in Article 3. We do not acquire personal information by deception or other improper means.
  2. We comply with the laws and regulations concerning the proper handling of personal information, with guidelines established by national or local government, and with other norms applicable to us and to the conduct of our business. We also review the content of this Privacy Policy from time to time and strive to improve it.

Article 2 (Categories of Personal Information We Collect)

The personal information we collect is as follows.

  1. (1) The name, address, telephone number, gender, date of birth, email address, affiliated company or organization, corporate status, job title, department and other contact details of Users and business partners
  2. (2) A User's account name, password, profile image and other registration information obtained through registration for our Services
  3. (3) Information we obtain in connection with a User's use of our Services (images attached to posts, comments, timestamps, the number, volume and type of collected litter, the number of participants in a cleanup activity, the time spent on a cleanup activity, location information from mobile devices, categories of illegal dumping, feedback between Users on posts, and the like)
  4. (4) Information obtained automatically when a User accesses our sites or applications, such as browser type and version, operating system and platform, as well as service usage history including browsing history
  5. (5) Information contained in inquiries and similar communications
  6. (6) Video footage captured by cameras installed to record littering behavior
  7. (7) Other personal information that we lawfully acquire or hold

Article 3 (Purposes of Use)

We use the personal information described in Article 2 within the scope of the following purposes.

  1. (1) To conduct our business aimed at solving and improving environmental problems, principally the problem of littering
  2. (2) To carry out communications, advertising and research that promote cleanup activities and raise awareness
  3. (3) To provide information on illegal dumping and similar matters to national and local government
  4. (4) To understand how Users use the Services, and to operate, develop and improve the Services
  5. (5) To provide Users with commercial and service information, business communications and other information from companies, national and local government and other bodies that we consider appropriate
  6. (6) To recognize Users, send prizes, and compile and publish rankings and similar information
  7. (7) To respond appropriately to inquiries, complaints and similar communications from Users
  8. (8) With respect to the video footage described in Article 2(6), to analyze littering behavior and litter volumes and to provide such analysis to the managers of the installation sites
  9. (9) For other purposes equivalent or closely related to those set out above

Article 4 (Handling of Personal Information in the Trash Scan Feature of SNS Pirika)

  1. The "Trash Scan" feature is a feature of SNS Pirika which uses optical character recognition (OCR) to read text appearing in a photograph of litter taken by a User and suggests hashtag candidates. The feature uses generative AI (artificial intelligence that produces text and other content from the information provided to it) to produce those suggestions. This Article sets out provisions on the handling of personal information in connection with this feature, in addition to those set out in Articles 2 and 3.
  2. What is transmitted: The full-size photograph, location information and the date and time of capture are not transmitted. The text extracted by OCR, together with reduced-size images cropped from the areas of the photograph where text was detected and their surroundings (the "Cropped Images"), may be transmitted to the Claude API operated by Anthropic PBC, an external service provider (the "AI Provider"). Where text appears across a wide area of the photograph, a substantial part of the photograph may be included in the Cropped Images.
  3. When transmission occurs: Transmission to the AI Provider under the preceding paragraph takes place at the moment the User takes or selects a photograph. Even if the User decides not to complete the post, the transmitted content is stored by us as analytics data used to improve the feature (what we store is set out in paragraph 5).
  4. Protection of personal information: Where the OCR text may contain personal information such as telephone numbers, email addresses, URLs or postal codes, we apply automated masking before transmission to the AI Provider, to the extent technically possible, and exclude from transmission the Cropped Images corresponding to those areas. However, depending on how information appears in the image and on the content of the text, we do not guarantee that all personal information can be completely detected, masked or excluded.
  5. Handling of data: The AI Provider does not use the content of our requests as training data for its models. However, it may retain logs for a certain period for purposes such as detecting improper use, ensuring safety and complying with laws and regulations. Where improper use is suspected, such logs may be retained for a longer period. We do not store the Cropped Images on our servers. As analytics data used to improve the feature, we store the masked text, the suggested hashtags and similar information together with a User identifier. We delete such analytics data one year after it is obtained. The reason we store a User identifier alongside this data is to enable us to identify the relevant data and respond when a User makes a request for disclosure, deletion or similar action.
  6. Opt-out: A User may disable this feature using the switch on the posting screen or the camera screen. While the feature is disabled, no text is read and nothing is transmitted.

Article 5 (Retention Period)

  1. We retain the personal information we collect only for the period necessary to achieve the purposes of use set out in Article 3, and after that period we delete it or render it unusable. Where a retention period is prescribed by law, we retain the information for that period.
  2. The retention of analytics data relating to the Trash Scan feature is governed by Article 4.

Article 6 (Provision to Third Parties)

We do not provide personal information to third parties without the consent of the individual concerned, except in the following cases.

  1. (1) Where required by law
  2. (2) Where necessary to protect the life, body or property of a person and it is difficult to obtain the consent of the individual concerned
  3. (3) Where particularly necessary to improve public health or promote the sound growth of children and it is difficult to obtain the consent of the individual concerned
  4. (4) Where it is necessary to cooperate with a national government body, a local government or a party entrusted by them in carrying out functions prescribed by law, and obtaining the consent of the individual concerned is likely to impede the performance of those functions
Provision to third parties based on the consent of the individual is governed by Article 9 (Handling of Personal Information) of our Terms of Service.

Article 7 (Outsourcing)

  1. We may outsource part of the work of operating the Services to contractors with whom we have entered into confidentiality agreements. A contractor accesses and uses personal information only to the extent necessary to perform the outsourced work. We require our contractors, through Data Processing Addenda (DPAs) and other agreements, to process data in accordance with our instructions, to refrain from using it for other purposes, to implement security measures, and to manage their own subcontractors.
  2. We exercise necessary and appropriate supervision to ensure the secure management of personal information by our contractors. For our principal contractors, please see Article 8 (Use of External Service Providers and Cross-Border Transfers).

Article 8 (Use of External Service Providers and Cross-Border Transfers)

  1. Use of external service providers
For the provision and operation of the Services, we use the following principal external service providers as contractors that process Users' personal information in accordance with our instructions for the purpose of providing the Services.

ProviderPurposeLocation of processing
Google LLC (Google Cloud)Application servers, databases, image storage and data analytics infrastructure for SNS PirikaUnited States
Anthropic PBC (Claude API)Generation of hashtag suggestions for the Trash Scan featureUnited States
Amazon Web Services Japan G.K.Delivery of posted images and similar content for SNS Pirika (content delivery network). Storage of data is not includedJapan (for delivery purposes, content may be temporarily copied to servers in various locations, including outside Japan)
  1. Information on the personal data protection regime of the United States
The United States does not have a personal data protection regime recognized by the Personal Information Protection Commission of Japan as being of a standard equivalent to that of Japan. In addition, the United States has no comprehensive federal personal data protection statute; regulation is primarily sector-specific and state-specific. Furthermore, in certain circumstances, access to information by government authorities may be permitted under applicable law.

  1. Security measures taken by each provider
(Google Cloud)

The Google Cloud Data Processing Addendum applies to Google Cloud. That DPA provides, among other things, that Google will process customer data in accordance with our instructions for the purpose of providing the services, and addresses security measures, management of subprocessors, assistance with data subject requests, and Standard Contractual Clauses for certain international data transfers. Through the application servers, databases, image storage and analytics infrastructure of SNS Pirika, posted images, comments, location information, account information and similar data may be stored and processed on servers located in the United States.

(Anthropic)

For Anthropic PBC, a Data Processing Addendum is incorporated into Anthropic's Commercial Terms of Service, and that DPA applies to us by virtue of our agreement to those Commercial Terms. In addition, although the content of API requests is not used as training data for models, logs may be retained for a certain period for purposes such as detecting improper use, ensuring safety and complying with laws and regulations.

(Amazon Web Services Japan)

For Amazon Web Services Japan G.K., the AWS Customer Agreement and the AWS Service Terms apply, and those agreements incorporate data processing conditions covering, among other things, processing in accordance with our instructions, security measures and management of subcontractors. What we entrust to this provider is the delivery of posted images and similar content; storage of data is not included (storage takes place in Google Cloud as described above). When content is delivered, it may be temporarily copied to delivery servers in various locations, including outside Japan.

  1. Ongoing verification
We verify on a regular basis how the measures described in the preceding paragraph are implemented by these external service providers, and we provide the necessary information to Users upon request.

Article 9 (Security Measures)

We endeavor to prevent and remedy unauthorized access to, and the loss, leakage, destruction or damage of, your personal information, and we implement security control measures. Where improvements to our security measures are found to be necessary, we remedy them promptly. We also educate all of our employees so that they understand the importance of personal information and handle it appropriately.

Article 10 (Requests for Disclosure and Other Rights)

  1. If a User wishes to request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure or suspension of provision to third parties of their own personal information under the Act on the Protection of Personal Information or related laws and regulations, please contact us using the details set out in Article 12 (Contact).
  2. After confirming the content of the request, we will take appropriate action. We will respond to requests for disclosure in writing or by a method agreed with the User, and will communicate the results of other measures by telephone, email or similar means. A prescribed fee may apply.

Article 11 (Changes to This Policy)

  1. We may change this Policy as a result of amendments to laws and regulations, changes to the content of the Services or for other reasons.
  2. Where we make a material change to this Policy, we will notify Users by means of an in-application notice or another appropriate method. Unless we specify otherwise, the amended Policy takes effect when it is published on our website.

Article 12 (Contact)

For inquiries regarding the Privacy Policy of Pirika, Inc., please contact us at the address below.

Pirika, Inc.
1-4-7 Kudankita, Chiyoda-ku, Tokyo 102-0073, Japan
Fujio Kojima, President and Representative Director
info@pirika.org

Effective date: August 1, 2012
Last revised: September 1, 2026