Skip to content
Shiorip

Applies from the public beta launch 2026-10-04

Shiorip Privacy Policy

Contents
1 About this policy2 Information handled3 Purposes4 Link-based sharing5 Cookies and browser storage6 Service providers and international processing7 Disclosure to third parties8 Retention and deletion9 Safeguards10 Individual requests and contact11 Changes and language

This Policy applies from the public beta launch. Display in a restricted environment before launch is for review and does not bring it into effect.

Version: 2026-10-04

Operator display name: usuginus · Contact: contact@shiorip.app

Please contact the address above for the Operator's name, address and other information you are entitled to know under applicable law. The Operator will respond individually to requests from the individuals concerned without undue delay, in accordance with applicable law.

1 About this policy

The operator of Shiorip (the Operator) handles the information described below to provide itinerary creation, editing and sharing. This Policy explains the information handled, its purposes, link-based sharing, retention, deletion and how to contact the Operator.

An account is not required, but no registration does not mean no personal information is processed. Content entered into an itinerary, identifiers needed for editing, support messages and other records may contain personal information.

2 Information handled

InformationMain examples
Itinerary contentTitles, travel dates, plans, locations, details, overviews, notes and URLs you enter. Content may include names or contact details entered by users.
Change and saving recordsHistory, content before and after changes, save times, identifiers and results needed for conflict handling, restoration and duplicate-request prevention.
Access informationSessions, editing permissions and identifiers needed to issue, replace or stop links. Server authentication records store transformed values for verification, rather than raw secret link or session values.
Communication informationRequest times, request IDs, processing results and browser language preferences. Infrastructure providers may also process IP addresses, browser information and similar data to deliver and protect communications.
Support informationNames, email addresses, message contents and correspondence voluntarily supplied when contacting the Operator.

The Service does not offer device-location tracking through location permissions or address-book collection. Locations or information about people that you enter yourself are handled as itinerary content. Image uploads and payment-card entry are not available.

In the beta version, an identifier derived from the IP address supplied by the delivery infrastructure and the UTC date is used for temporary request counting to limit excessive access. This does not guarantee anonymization. The application does not store raw IP addresses in its database or logs. This is separate from the infrastructure provider's own handling of communication information.

3 Purposes

Information is used only as necessary for:

  • Creating, saving and displaying itineraries, and sharing or collaborating at users' direction.
  • Checking editing access, stopping or replacing links, detecting conflicts, retrying saves and displaying or restoring history.
  • Investigating incidents, protecting security, preventing abuse and maintaining the Service.
  • Handling support requests, requests from individuals and reports of rights infringements.
  • Meeting legal obligations and appropriately handling disputes.

The Operator does not sell private itineraries for advertising or provide them to third parties for advertising or AI training. Advertising and third-party analytics SDKs are not currently used. Any new handling of information will be preceded by necessary explanations and legal procedures.

4 Link-based sharing

Anyone who knows a valid viewing link can read saved content. Anyone who joins through a valid editing link can edit content, restore history and manage sharing links. Share links only with the intended recipients, understanding these permissions. Editors can also take actions that affect other people's access.

The Service excludes user itineraries from its search-indexing targets and uses settings to discourage indexing. This is not access control against people who have a link and is not a guarantee that every search engine or republishing website will keep the content out of search results.

Stopping a link does not erase copies already kept by recipients or external services. Obtain necessary permissions and give appropriate explanations when entering information about travel companions or others. Check whether booking references, addresses, telephone numbers and similar details are suitable for every intended recipient.

5 Cookies and browser storage

The Service uses necessary session cookies to recognize a browser with editing access. In the current implementation, a session is valid for 30 days from issuance. If the cookie is lost or the session expires, editing with that session is no longer available; you will need to rejoin through a valid editing link. Authentication expiry and deletion of server records are different things.

Drafts, unresolved save or restoration requests, sharing-screen state and related information are stored in the browser's localStorage or sessionStorage. These mechanisms help protect input and support retries; they are not used for advertising tracking. A local draft does not mean that the content has been saved to the server.

You can clear cookies and site data through browser settings, but doing so may remove unsaved content or editing access. Take care with site data on shared devices. Clearing browser data does not delete itineraries or history already stored on the server. Section 8 addresses retention and deletion of browser records.

6 Service providers and international processing

The Service uses Workers and D1, provided by Cloudflare, Inc. in the United States, for delivery, communication security and itinerary storage. Itinerary content, history, access-verification records and communication information are handled as necessary for these purposes, using services under Cloudflare's terms and applicable data-processing terms.

The primary D1 database is located in the Asia-Pacific region, but storage and processing are not restricted to Japan. Delivery, maintenance, backups and other processing may also occur in the United States and other countries or regions. There is no contractual restriction to fixed processing countries. See Cloudflare's published processing providers and locations and data-processing terms.

Contact emails are forwarded through Cloudflare Email Routing to Gmail, provided by Google LLC in the United States, for receipt and storage. This includes senders' email addresses, message contents and attachments. Email storage is not restricted to Japan and processing may occur in the United States and other countries or regions. Google's handling is also described in its Privacy Policy. Do not send secrets such as editing links, cookies or identity documents unless specifically requested through an appropriate procedure.

The Operator reviews providers' terms, published safeguards and service settings, and limits access as necessary. Information, consent or other measures required by law for international processing will be provided or obtained where required. Publishing this Policy alone does not complete any separately required measures. See also Cloudflare's Privacy Policy for its own handling of communication and related information.

7 Disclosure to third parties

Apart from sharing directed by users and processing entrusted to providers as needed to deliver the Service, the Operator does not disclose personal data to third parties without the individual's consent unless permitted by law. Disclosures required by law or needed to protect life or bodily safety will be assessed under applicable law and limited to what is necessary.

If you follow an external link, that website handles information under its own policies. This Policy does not govern external websites.

8 Retention and deletion

The retention policy is to keep itinerary content and save history until a user deletes the whole itinerary or the Service ends. Travel end dates alone do not trigger automatic deletion. This is not a guarantee of perpetual storage or recovery after an incident; information may also be removed as necessary for legal compliance or abuse prevention. Retention and deletion are limited to what is needed for service provision, secure access management, abuse prevention and legal obligations.

InformationRetention and deletion
Itinerary content and deleted itemsKept until whole-itinerary deletion or the end of the Service. Removed from the live database when whole-itinerary deletion completes. Deleting an individual item may leave its previous content in history or other records.
History and processing records containing contentKept until whole-itinerary deletion or the end of the Service, and removed from the live database on whole-itinerary deletion. History is not automatically deleted based on age or entry count.
Sessions, permissions and reuse-prevention recordsSession authentication expires 30 days after issuance; this is not a record deletion deadline. Whole-itinerary deletion revokes access to that itinerary. Content-free deletion records, creation-request verification records and used-link digests are retained while the Service operates to prevent reuse of old requests or links. There is currently no scheduled cleanup of expired session records.
Local drafts and processing recordsThere is no uniform age-based automatic deletion. Browser site-data controls can remove them, but also remove unsaved input or editing access. This does not erase server-side itineraries or copies on other devices.
Operational and security logsApplication request logs, Workers Logs, Trace and Logpush are disabled. Content, cookies and secret parts of sharing links are not copied into operational records. Counts, errors, capacity and similar aggregate metrics are used for operational checks. Providers' own communication records for delivery and protection follow their policies; the Operator does not set a uniform deletion date for them. Necessary incident records are retained as needed for investigation and legal obligations.
Support correspondenceRetained as necessary for correspondence, legal obligations and disputes. The Operator endeavors to erase personal information when it is no longer needed. No fixed number of days is specified.
BackupsCloudflare D1's automatic recovery history (Time Travel) may retain content from before deletion. Its recovery window is the past 7 days on Workers Free or 30 days on a paid plan. This is not a guarantee of physical erasure from all media at that time. The Operator does not make separate scheduled exports. Whole-database rollback will not be performed until deletions and access revocations can be reliably preserved.

Removing a plan or note from the interface may leave its previous content in history or processing records. Stopping sharing is not deletion. Requests concerning erasure can be made through the channel in Section 10. Information that must legally be retained will be handled according to the relevant basis and necessity.

A user with editing access can delete the entire itinerary from Settings in the editing screen. On completion, content, save history and save-processing records containing content are removed from the live database, and shared links and everyone's editing access are invalidated. Content-free deletion records, creation-request verification records and used-link digests remain as described above to prevent old requests or links from reviving the itinerary.

The draft belonging to the tab performing deletion is cleared where possible. Copies in other tabs, on other devices or retained by third parties cannot all be remotely erased. Backups may retain data under the provider's retention policy. D1 recovery does not promise restoration of an individual itinerary. Deletion does not mean immediate physical erasure from every medium, including backups.

9 Safeguards

The Service uses session- and link-based access control, permission checks on saving, input validation, transformed secret values for verification, HTTPS, request-rate limits and request-size limits. Operational policy includes protecting administrative credentials, not retrieving itinerary content during routine checks, reviewing incidents, usage and incoming contact messages, and stopping acceptance of requests when abnormalities arise.

The Service does not provide end-to-end encryption that prevents the Operator from reading content. People with necessary operational authority may handle information to the extent needed for incident response, rights-infringement reports and similar purposes. Absolute security is not guaranteed, but disclaimers do not waive legal duties to protect information.

If a data breach or similar incident occurs or is suspected, the Operator will take the investigative, containment, corrective, reporting and notification measures required by law for that incident. If notice to affected individuals is legally required but difficult, for example because their contact details are not held, the Operator will take alternative measures meeting the applicable legal requirements. The absence of registration and limitations on support do not waive these duties.

10 Individual requests and contact

Use the editing screen for ordinary itinerary deletion. As a rule, the Operator does not recover editing access on your behalf. However, the absence of an editing link alone is not a blanket reason to reject the statutory personal-information requests described below.

To request information about purposes of use, access, correction, restriction, erasure or other handling of your personal information, contact the Operator through the channel above. Requests will be handled under applicable law. Liability disclaimers do not restrict those rights except where the law permits a restriction.

Ordinary operating instructions and individual data recovery are not provided, and individual replies or response times for general bug reports and suggestions are not promised. See the scope of support in the Terms. This policy does not apply to necessary handling of personal-information complaints, statutory requests or similar matters. These will be handled according to their nature and applicable law, including any statutory deadlines.

To avoid disclosing or deleting someone else's information, the Operator may ask for the minimum information necessary to identify the records and verify your identity. Editing an itinerary does not mean you are the individual concerned by every piece of personal information in it. Do not send raw editing links or session cookies.

Where the anonymous, link-based design makes identification difficult, the Operator will explain the situation and consider an appropriate response under applicable law. This does not promise that editing access or lost content can always be restored. If a request cannot be fulfilled, the Operator will explain the reason as required by law.

11 Changes and language

Changes to information handling and their effective dates will be communicated appropriately, with prior explanation or consent where required. Updating this Policy alone does not authorize unlimited new uses of information previously supplied.

This Policy is provided in Japanese and English. Where the texts differ, the Japanese text will guide interpretation to the extent permitted by law. This does not remove your rights under applicable mandatory law.

Terms of UsePrivacy Policy
日本語English
contact@shiorip.app