AKANUKE Privacy Policy

Japanese Version / 日本語版

Saigen Inc. (hereinafter "the Company") establishes the following privacy policy (hereinafter "this Policy") regarding the handling of your information in the face-analysis app "AKANUKE" (hereinafter "the App"). Matters not covered by this Policy are governed by the Company's general Privacy Policy.

1. Data We Collect

The App handles the following data:

  • Face photos: the selfies you take. They are stored on your device.
  • Face measurements: facial landmark detection and measurement for scoring are performed entirely on your device using Apple's Vision framework. The resulting measured values (numeric data) and scores are stored on your device.
  • Purchase and abuse-prevention information: App Store-signed purchase information, App Attest public key IDs and assertion counters, and a random in-app account identifier.

The App does not collect contact information such as your name or email address, and does not track you using advertising identifiers.

2. AI Processing of Photos and Data

The App sends data to external AI services as described below, solely to generate face-analysis commentary and AI images.

2-1. What is sent, and to whom
  • Score commentary generation: only the measured values (numeric data) extracted from your face photo on your device and your scores are sent to Cloudflare (our proxy), OpenRouter (routing), and a Google generative-AI model. Your face photo itself is never sent for this feature.
  • AI image generation ("The future you" / hairstyle try-on): only when you use these features, your face photo is sent to Cloudflare (our proxy, including private encrypted redelivery storage) and fal.ai.
  • Abuse prevention and purchase verification: App Attest public key IDs and assertion counters, App Store-signed purchase information, and a random in-app account identifier are sent to Cloudflare (our proxy / Durable Objects) and Apple (certificate-status checks).
2-2. Purpose

The data is used only to generate score commentary and AI images, verify purchase rights, and prevent abuse, replay, and duplicate use. It is not used for advertising or tracking, and is not disclosed to advertising providers. Face data is never shared with or sold to any party other than the processors listed above, which process data on our behalf.

2-3. Training and retention

Our proxy does not store photos, measurements, or purchase JWSs in request logs. We require OpenRouter zero-data-retention and deny data collection, using only compatible model-provider routes. For fal.ai, we disable input/output storage, require private access and automatic expiry within five minutes, and reject public output URLs. To redeliver the same "Future You" result to the same purchase after a connection failure without regenerating it, we temporarily store the result in private Cloudflare storage with application-layer AES-GCM encryption. We delete it after delivery acknowledgement, and also schedule explicit deletion after 24 hours if no acknowledgement arrives; Cloudflare lifecycle processing may take up to approximately another 24 hours after expiry. Only your device keeps a decrypted generated result permanently. Face photos and face measurements are never retained on servers beyond the temporary storage described above.

To prevent duplicate use and abuse, we retain App Attest public key IDs and assertion counters, purchase-consumption markers, and one-way-hashed matching data for random identifiers in Cloudflare Durable Objects. These state records do not contain face photos, generated images, or comment text. The temporary encrypted result described above is kept only in separate private storage.

2-4. International data transfers

The service providers listed above are based in the United States. For each company's privacy practices, please see:

3. Consent and Deletion

The processing described above occurs only after you agree on the consent screen shown at first launch. You can delete photos and records stored on your device at any time in the app's settings. Deleting local data or the app does not remove server-side consumed-purchase markers needed to prevent abuse. You may contact us at the address below to request access to or deletion of server data, except records that must be retained for legal or security reasons.

4. Management of Personal Information
  • The Company maintains the accuracy of personal information and manages it securely.
  • The Company implements appropriate information security measures to prevent the loss, destruction, alteration, or leakage of personal information.
5. Requests for Disclosure, Correction, or Suspension of Use

When the Company receives a request from a customer regarding disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or notification of the purpose of use of personal information, the Company will confirm the identity of the applicant and respond sincerely and promptly in accordance with the Act on the Protection of Personal Information.

6. Changes to This Policy

The Company may revise this Policy as necessary. The revised policy will be published on this page.

Contact Us

For inquiries regarding the handling of personal information in the App, please contact us at contact [at] saigen.co.

Established: August 15, 2026

Saigen Inc.