WonderDays Privacy Policy
WonderDays does not create user accounts. We do not send anniversaries, birthdays, names, or photos to our servers, and process only the minimum information needed to retrieve public information and produce aggregates.
Basic policy
Happy Hack Inc., the personal information handling business operator (2F Shinjuku Entrepreneur Salon Building, 2-12-13 Shinjuku, Shinjuku-ku, Tokyo, Japan; Representative Director: Yoji Minabe), minimizes the information needed to provide WonderDays. The App has no registration or login feature, and we do not register profiles that directly identify users, such as names, email addresses, or telephone numbers, on our servers. We do not sell personal data or use it for advertising or behavioral tracking.
Information kept only on your device
The following information is stored only on your device and is not sent to our servers:
- Anniversary dates, names, start times, icons, and celebration settings
- Your birthday and children's birthdays
- On-device copies of favorited public items, notice read status, and notification settings
- Photos used in anniversary cards
Photos are used only to create cards on your device and are not uploaded to our servers.
Information sent to our servers
We send the following information over HTTPS only as needed to display public content, produce anonymous aggregates, prevent abusive repeated operations, and verify an authentic App:
- All communications: a random installation ID created on the device, the App name, and the App version
- Retrieving public information: the country code derived from the device's regional settings, time zone, display language, and, when needed, a public item ID
- Congratulations operations: one vote and a country code
- Favorite operations: whether a favorite is added or removed and the public item ID
- Write operations: App integrity verification information from App Attest or Google Play Integrity
- Source IP address accompanying a communication: received for a one-minute rate limit, but never stored or written to logs in raw form
We use the installation ID only to prevent duplicate operations and abusive repetition and to verify App integrity. We do not associate it with a name, email address, advertising ID, device-specific ID, device model, or OS version. The country code comes from the device's regional settings and is not a current location obtained from GPS or similar services.
Purposes of processing
- To display public content, notices, total congratulations, and favorite counts
- To reflect congratulations and favorite operations in anonymous aggregate values
- To prevent duplicate operations, abusive repetition, and aggregation from tampered Apps
- To investigate incidents and maintain the security and operation of the service
Information not sent to our servers
We do not send anniversary dates, names, or start times; birthdays; photos; contacts; calendar contents; notification contents; precise location; advertising IDs; IDFA; IMEI; device-specific IDs; device models; or OS versions to our servers. We do not use SDKs for advertising, cross-user behavioral tracking, crash analytics, or usage analytics.
Storage and retention periods
- Raw installation ID: never stored in a database or logs; converted into irreversible, purpose-specific HMAC keys
- Duplicate-prevention HMAC keys derived from the installation ID: no more than 48 hours
- Rate-limit HMAC keys derived from source IP addresses: no more than one minute in server memory
- Single-use challenge for App integrity verification: no more than five minutes
- Verified Android integrity keys: no more than 24 hours
- iOS App Attest registration keys: for as long as needed to continue verifying the authentic App; never associated with an installation ID or public item ID
- Per-minute aggregates, total counters, public content, and notices: retained without association with a person or installation ID
We do not store raw congratulations votes or favorite operations as per-user or per-installation-ID detail records. Aggregate values are not stored in a form that allows an individual user's operation history to be reconstructed.
OS features, App integrity verification, and service providers
We use Apple App Attest on iOS and Google Play Integrity on Android to verify that operations come from an authentic App. Apple or Google's OS and services generate verification information, and we process the information needed to make a determination. Each provider's privacy policy applies to its processing.
We use OS features for photo selection, card saving, sharing, calendar export, and local notifications. If you provide information to a sharing destination or a cloud-synced calendar you select, subsequent processing is governed by the OS settings and the applicable service's policy. Our servers do not receive those photos, calendar events, or notification contents.
We engage Microsoft Azure to operate our servers and Google Cloud for Android App integrity verification. In accordance with applicable law, we select these processors, require appropriate safeguards by contract or other means, and oversee their handling of information. They process information only as needed to provide and secure their services. Processing that Apple or Google carries out for its own purposes is governed by the relevant provider's terms and privacy policy.
How to delete data
Using “Delete all data” in the App deletes anniversaries and other data on the device and discards the installation ID. Events exported to an OS calendar may not be deleted automatically, depending on permissions and the state of the calendar. Our servers do not hold anniversaries, photos, profiles, or operation histories that can be located by specifying a user. Time-limited HMAC keys are deleted after the retention periods above.
Children's data
The App is not directed primarily to children. It can be used to count the number of days since a child's birth, but a child's date of birth and name are stored only on the device and are not sent to our servers. A minor using the App directly must obtain consent from a parent, guardian, or other legal representative where required by applicable law. A parent or guardian may delete on-device data at any time.
Security and disclosure to third parties
We restrict communications to HTTPS and use purpose-specific HMACs, short retention periods, access controls, data-minimized logs, and other appropriate organizational, personnel, physical, and technical safeguards. We do not sell personal data. Except where required by law or where processing is entrusted to the processors identified in this Policy to the extent necessary, we do not disclose personal data we hold to third parties. If a leak or other security incident occurs, we will investigate, contain the impact, and report to authorities and notify affected individuals as required by applicable law.
Legal rights
Depending on applicable law, you may have the right to request notice of purpose, access, correction, completion, deletion, suspension or erasure, cessation of third-party disclosure, restriction of processing, objection to processing, or portability of your personal data held by us, and to lodge a complaint with a supervisory authority. Send requests to wonderdays@happyhack.co.jp with the action requested and the minimum information needed to verify it. Because we do not maintain accounts or individual operation histories, we normally have no server data that can be searched by linking it to a requester. We may ask you to verify your identity only to the extent necessary to respond. We do not charge a fee unless permitted by law and disclosed in advance, will respond within the period required by law, and will not discriminate against you for exercising your rights.
Legal bases and international processing
Where applicable law requires a legal basis for processing, we rely on providing the service at your request for the delivery of public information, and on our legitimate interest in protecting the service for duplicate prevention, rate limiting, App integrity verification, and incident investigation. Where consent is required by law, we process information within the scope of that consent. If a service provider's facilities are located outside your country of residence, information may be processed in another country. In that case, we apply safeguards required by applicable law.
Optional operational support and Stripe
When the app opens the operational support page, it does not add a name, email address, card information, contribution amount, installation ID, anniversary, public item ID, or other on-device data to the URL or send that information to our API. The support page uses no JavaScript, cookies, analytics, or WonderDays API.
After the external browser moves to the Stripe payment page, Stripe collects and processes the name, email address, payment method, contribution amount, IP address, and other information needed to complete the payment, prevent fraud, send an email receipt, and comply with law, under Stripe's terms and privacy policy.
For contribution confirmation, accounting, payment inquiries, fraud response, and legal compliance, we may view the contribution amount, payment time, payment status, the email address used to send the receipt, and other payment information provided in the Stripe Dashboard. We do not associate it with the app installation ID, anniversaries, public item IDs, or other app data, and do not independently copy it beyond the period required for Stripe processing, accounting, or legal compliance.
Changes to this Policy
If we materially change the information we process or the purposes of processing, we will announce the effective date and details of the change in the App or on a public page a reasonable time in advance and apply the change only to processing on or after that date. A change of purpose or other processing that requires consent by law will not apply until the required consent is obtained. Minor wording corrections may apply from the time they are posted.
Contact
For questions or complaints about data handling, requests concerning retained personal data, or requests to correct, remove, or suspend publication of public information, contact the Happy Hack Inc. privacy desk at wonderdays@happyhack.co.jp. We will review the request and respond within a reasonable period in accordance with applicable law.