Cross-border processing, disclosed and consented to.
The Act on the Protection of Personal Information (個人情報の保護に関する法律) requires that data subjects consent to cross-border processing in plain language. Detecto carries the disclosure as a first-class surface in the product, not buried in legal pages.
Five concrete commitments under APPI.
Cross-border processing is disclosed before the first submission, in plain language, with the regions named.
Reversible from /settings. Revoking stops further scans until consent is re-granted; existing data is governed by the retention policy.
Your reports and scanned content are stored privately to your account on every plan, never public unless you share. Ephemeral mode stores nothing.
Single canonical subprocessor list maintained by code-and-content PRs to prevent drift.
APPI rights honored. 30-day response window on data subject requests routed to privacy@detecto.co.
Consent logged with the timestamp and the scan that triggered the disclosure. Available to the account owner.
What we ask the user to consent to
- That the submission may be processed by third-party processors outside Japan, named generically (compute, detection, authentication, billing, observability).
- That the third-party processors operate in the regions named on the disclosure modal (currently US, EU).
- That detection runs server-side and your report, including the content you scanned, is stored privately to your account, never public unless you create a share link. Ephemeral mode stores nothing.
- That the consent record is logged and reversible from /settings.
What changes when consent is revoked
Revoking consent stops further scans for the account or session. Existing detection outputs are retained per the retention policy on the account. Your reports and scanned content are stored privately by default, and can be deleted.
Data subject rights under APPI
Access, correction, deletion, suspension of use, and third-party-disclosure restriction. Email privacy@detecto.co with a request. We respond within 30 days.
Subprocessor list
The canonical subprocessor list lives at /privacy-and-retention. We update it via code-and-content PRs so the list cannot drift from what’s actually wired in.