Privacy Policy

Last updated: July 15, 2026

Official Japanese version: プライバシーポリシー

This English version is provided for convenience. If there is any conflict between this English version and the Japanese version, the Japanese version controls. pivop Inc. ("we", "us", or "our") sets out this Privacy Policy for the handling of personal information and related data in Daylo (the "Service").

§ 01Operator Information

  • Operator: pivop Inc.
  • Address: Kinokuniya Building 4F, 1-4-2 Ebisu-Minami, Shibuya-ku, Tokyo 150-0022, Japan
  • Representative / Personal Information Protection Manager: Suguru Katsuyama
  • Contact: hello@pivop.jp

§ 02Nature of the Service

The Service is a free beta service for developers. It retrieves weight-related measurements from smart-scale provider APIs, including Withings and Tanita Health Planet, based on the user's instruction, and exposes normalized data through a REST API and CLI. The Service is not intended to provide medical diagnosis, treatment, advice, weight-loss coaching, health evaluation, or emergency response.

§ 03Information We Collect

We collect the following information to the extent necessary to provide the Service.

(1) Account Information

  • Email address
  • OAuth identifiers and related information when signing in with a Google account
  • Magic link, session, API key, and device authorization information

(2) Measurement Data

  • Weight (weightKg), body fat ratio (fatRatioPercent), measurement time (measuredAt), provider, provider-native measurement ID, retrieval metadata, and information from provider API responses necessary to provide the Service

This information may include sensitive health-related data. We handle it only to the extent necessary to provide the Service.

(3) Provider Connection Information

  • OAuth access tokens, refresh tokens, connection status, and connection timestamps for providers such as Withings and Tanita Health Planet
  • Temporary information such as state values required for OAuth authorization flows

(4) Technical Information and Logs

  • Request IDs (X-Request-Id), access timestamps, IP addresses, user agents, error information, and operational logs related to authentication, data retrieval, and API usage

(5) Contact and Waitlist Information

  • Information the user sends to us by email, GitHub Issues, or other contact methods

§ 04Information We Do Not Collect or Use

  • The Service does not currently collect credit card information or other payment information.
  • The Service has no dedicated fields for age or legal representative information and does not collect that information as registration data.
  • We do not sell user measurement data for advertising purposes.
  • We do not use user measurement data to train AI models.
  • We do not send user measurement data to generative AI APIs such as OpenAI, Google Gemini, or xAI.
  • The CLI local configuration file (~/.config/daylo/config.json) is stored on the user's device. We do not collect that file itself.

If, in the future, we use measurement data linked to an individual for a new purpose such as AI model training, sale, or third-party analytics, we will consider requesting a separate opt-in before that use. If we use information for such purposes without separate consent, our policy is to limit it to aggregated or anonymized information from which an individual cannot reasonably be reconstructed.

§ 05Purposes of Use

  • To provide the Service, authenticate users, issue API keys, support device authorization, and manage sessions
  • To retrieve, store, normalize, and provide measurement data from connected providers based on the user's instruction
  • To connect, update, disconnect, and troubleshoot provider integrations
  • To prevent abuse, maintain security, investigate incidents, and preserve service quality
  • To respond to inquiries and send important notices, including policy or terms updates
  • To create non-identifying statistics and improve or develop the Service

§ 06Disclosure and External Services

We do not disclose personal information to third parties without user consent, except as permitted by law. External services and recipients related to the Service are classified as follows. Information may be processed or stored outside Japan.

(1) Service Providers

We engage or use the following providers to process information to the extent necessary to operate the Service.

  • Cloudflare, Inc. (application runtime, CDN, security, request processing)
  • Turso / libSQL (database)
  • Google LLC (Google OAuth sign-in)
  • Resend (email delivery such as magic links)
  • GitHub, Inc. (when the user joins a waitlist or contacts us through GitHub Issues)
  • Google Workspace (receiving, sending, and storing inquiry emails)

(2) Providers Connected by the User

When a user chooses to connect a provider such as Withings or Tanita Health Planet, we communicate with that provider's API based on the user's authorization. The provider's own terms of service and privacy policy apply to that provider's handling of information.

(3) Disclosure Required or Permitted by Law

We may disclose information to the extent permitted by law when required by law, when necessary to protect a person's life, body, or property and obtaining consent is difficult, or in response to a lawful request from a court, regulator, or other public authority.

§ 07Security Measures

  • Communications are encrypted using TLS.
  • Sensitive information such as provider access tokens is stored in encrypted form.
  • API keys are used for authentication and are designed to be revocable and renewable if compromised.
  • Access to personal data is limited to what is necessary for business purposes.
  • We collect logs for incident investigation and security response, and delete or anonymize information when no longer necessary.
  • When using external services outside Japan, we review their security measures and applicable country-level data protection environment to a reasonable extent.

If you want to confirm details of our security measures, contact hello@pivop.jp. We will respond to a reasonable extent, excluding details that could harm security.

§ 08Retention

  • We retain account information, sessions, and API keys while the account remains active or for as long as necessary for authentication, security, and provision of the Service.
  • We retain measurement data, provider tokens, and internal retrieval state while necessary to provide the Service or until the user deletes the relevant data through daylo disconnect <provider> or DELETE /api/v1/me/data.
  • We retain technical logs, inquiry records, and security response records for periods appropriate to their purposes, including abuse, incident, and security response and legal requirements.
  • Legal acceptance records are limited to the user ID, Terms version, Policy version, acceptance timestamp, and source. We may retain them for a period reasonably necessary to verify contract formation and handle disputes, and delete them when no longer needed.
  • Information in external services may remain according to each service's settings and ordinary deletion cycle. Information in backups may remain until the normal rotation cycle is complete, and we do not promise immediate individual deletion from backups. Access to backups is limited to what is necessary.

When information is no longer necessary for its purpose, we delete it or put it into a form that does not identify individuals in accordance with ordinary operational and backup cycles.

§ 09Deletion, Access, and Correction

Users can delete data or disconnect providers as follows.

  • Disconnect a provider: daylo disconnect <provider> (deletes stored tokens for that provider)
  • Delete measurement and connection data: DELETE /api/v1/me/data (deletes measurement data and all stored provider tokens)
  • Account deletion, access, correction, suspension of use, or suspension of third-party disclosure requests: contact hello@pivop.jp.

DELETE /api/v1/me/data does not delete the account, sessions, API keys, or limited inquiry, security, or backup records, or the minimal legal acceptance records described above. Account deletion is handled separately through the contact above. Even after measurement and connection data deletion or account deletion, minimal legal acceptance records may remain for a period reasonably necessary to verify contract formation and handle disputes, and are deleted when no longer needed.

We will verify identity using the registered email address or another reasonable method and respond within a reasonable period in accordance with applicable law. We will not require excessive identity verification that effectively prevents a request. If information cannot be deleted immediately for legal or security reasons, or remains in backups until the normal rotation cycle, we will explain the reason or how it is handled.

§ 10Cookies and Similar Technologies

We may use cookies and similar technologies for sign-in, session management, security, and abuse prevention. We do not currently use advertising tracking cookies or third-party advertising networks. If we add analytics or advertising features, we will update this Policy.

§ 11Data Breach Response

If leakage, loss, damage, or similar incident involving personal data occurs and legal reporting or user notification is required, we will confirm the facts and take necessary measures, including reporting to the Personal Information Protection Commission of Japan and notifying affected users.

§ 12Changes to This Policy

We may revise this Policy in response to legal changes, changes to external services, or changes to the Service. We will post the content of the changes and the effective date on the Service. For material changes, we will provide reasonable advance notice before the effective date by email or another appropriate method.

§ 13Contact

  • Operator: pivop Inc. / 株式会社pivop
  • Address: Kinokuniya Building 4F, 1-4-2 Ebisu-Minami, Shibuya-ku, Tokyo 150-0022, Japan
  • Representative / Personal Information Protection Manager: Suguru Katsuyama
  • Contact: hello@pivop.jp
← back to daylo