Detecto
APPI

Cross-border processing, disclosed and consented to.

The Act on the Protection of Personal Information (個人情報の保護に関する法律) requires that data subjects consent to cross-border processing in plain language. Detecto carries the disclosure as a first-class surface in the product, not buried in legal pages.

What we do

Five concrete commitments under APPI.

Disclosure
First-scan disclosure modal

Cross-border processing is disclosed before the first submission, in plain language, with the regions named.

Consent
Consent is reversible

Reversible from /settings. Revoking stops further scans until consent is re-granted; existing data is governed by the retention policy.

Retention
Private by default

Your reports and scanned content are stored privately to your account on every plan, never public unless you share. Ephemeral mode stores nothing.

Disclosure
Subprocessor list canonical

Single canonical subprocessor list maintained by code-and-content PRs to prevent drift.

Subject rights
Access, correction, deletion

APPI rights honored. 30-day response window on data subject requests routed to privacy@detecto.co.

Records
Consent records auditable

Consent logged with the timestamp and the scan that triggered the disclosure. Available to the account owner.

What we ask the user to consent to

  • That the submission may be processed by third-party processors outside Japan, named generically (compute, detection, authentication, billing, observability).
  • That the third-party processors operate in the regions named on the disclosure modal (currently US, EU).
  • That detection runs server-side and your report, including the content you scanned, is stored privately to your account, never public unless you create a share link. Ephemeral mode stores nothing.
  • That the consent record is logged and reversible from /settings.

What changes when consent is revoked

Revoking consent stops further scans for the account or session. Existing detection outputs are retained per the retention policy on the account. Your reports and scanned content are stored privately by default, and can be deleted.

Data subject rights under APPI

Access, correction, deletion, suspension of use, and third-party-disclosure restriction. Email privacy@detecto.co with a request. We respond within 30 days.

Subprocessor list

The canonical subprocessor list lives at /privacy-and-retention. We update it via code-and-content PRs so the list cannot drift from what’s actually wired in.

Related

Privacy and security posture, written down.