Privacy Policy

This is an English translation provided for convenience. The Japanese version is the governing text; if the two differ, the Japanese version prevails.

Noriva LLC (Noriva合同会社, “we”) handles personal information in Sabaki (the “Service”) as set out below.

1. Information we collect

  • Account information (the name, email address and profile picture of your Google account)
  • The content of AWS notification emails you forward to the Service, and metadata extracted from them (AWS account IDs, service names, deadlines and so on)
  • Usage information (access logs and operation logs)
  • What you send through the contact form (your reply address and the message), the circumstances of the submission (the URL and display language of the page you sent it from, and the date and time you agreed to this Policy), and your IP address. The IP address is used for nothing but a daily limit on the number of submissions, which is there to prevent automated posting, and for looking into abuse of the form.
  • A record of your agreement to the Terms of Service and this Policy (the date and time, and the revision date in force when you agreed)

2. Purposes of use

  • To provide the Service: identifying, translating, explaining and delivering notifications
  • To improve the Service, investigate defects and provide support
  • To send important notices

3. Disclosure to third parties and processors

  • We do not provide personal information to third parties without your consent, except where required by law.
  • To provide the Service we entrust processing to the following companies: Amazon Web Services (infrastructure and AI processing), Stripe (payments), Google (authentication) and Slack (the delivery destinations you configure, and our own internal channel where the enquiries and feedback you send us arrive).
  • AI identification, translation and explanation of notifications is performed by Anthropic’s models (Claude) on Amazon Bedrock, provided by Amazon Web Services. We send the body and subject of the forwarded notification. Amazon Bedrock does not use inputs to train models and does not retain them after processing.

4. Retention and deletion

  • The original text of forwarded emails is deleted automatically 90 days after receipt. Summaries and metadata are deleted progressively once the history retention period of your plan has passed.
  • What you send through the contact form is deleted one year after we receive it. The IP address is deleted sooner, thirty days after receipt; the enquiry itself remains for the rest of the year. Where we have judged a submission to be automated, its reply address and its message are deleted at the same thirty days, and only the record that a submission arrived — the date and time, the URL and language of the page it was sent from, and the date and time this Policy was agreed to — remains for the rest of the year. All of these deletions are made in batches by a daily pass, so it can take some days longer for the data to actually go.
  • Separately from the above, the content of your enquiry also arrives as a notification in a Slack channel we use internally. That notification is governed by Slack's own retention setting and is not covered by the one year above. After deletion, the data also remains for a limited time in the disaster-recovery backups described below (logical database backups, for up to 62 days).
  • You can export all of a workspace’s data as JSON from the settings screen at any time.
  • You can close a workspace yourself from the settings screen. Closing deletes groups, notifications, AWS connections, reports and share links, invalidates every member’s session, and deletes the stored email bodies (the originals in S3). If deleting the email bodies fails, the closure itself is aborted, so that data is never left behind in a state where it can no longer be identified.
  • After closure, data remains for a limited time in disaster-recovery backups: logical database backups for up to 62 days, and seven daily generations of storage snapshots. If we restore from these, a closed workspace is deleted again after the restore. Operational logs expire after 30 days.
  • In addition, when you ask us to delete data, we delete the related data within a reasonable period.

5. Analytics and transmission to external parties

  • Our website uses Google Analytics to understand usage and measure advertising, deployed through Google Tag Manager.
  • Information sent: the URL of the page viewed, the referrer (the linking page and campaign parameters), browser and device type, approximate region, and identifiers stored in cookies and similar storage. Names, email addresses and the content of notifications you forward are not sent.
  • Recipient: Google LLC. Its handling of the data is governed by its own privacy policy.
  • We ask for your consent on your first visit and do not measure until you give it (Google Consent Mode is set to “denied” by default).
  • Withdrawing consent: clearing the browser’s stored site data makes us ask again. You can also stop it through your browser’s cookie settings or an ad blocker.
  • Separately, to measure advertising we record the referrer and campaign parameters of your first visit on our own servers. This record is not sent to third parties.
  • The contact form uses AWS WAF’s browser check to prevent automated submissions. Information sent: browser type and behavioural characteristics, and a verification token (stored in a cookie on this site). Recipient: Amazon Web Services, Inc., our infrastructure provider. The content of the form is not part of this check.

6. Security

  • Communications are encrypted with TLS, and stored data is kept on encrypted storage.
  • Connections to AWS are limited to a read-only IAM role. We never obtain or store access keys.

7. Contact

  • For requests to disclose, correct or delete personal information, contact us through the contact form (/en/contact).

Established: 2026-07-05 / Last revised: 2026-09-26 (the reply address and message of a submission judged to be automated are now deleted at thirty days)