Privacy Policy
Last updated 12 May 2026
Orihon K.K. ("Orihon", "we") provides offline reading infrastructure to comics and manga publishers. This policy explains what personal information we handle, why, and what you can ask us to do about it. It covers this website and the Orihon service, and it follows Japan's Act on the Protection of Personal Information (the "APPI").
1. Who we are
Orihon K.K. is a company incorporated in Japan, with its office in Kuramae, Taitō-ku, Tokyo. We are the personal information handling business operator responsible for the data described here. For privacy questions, contact privacy@orihon.dev.
2. Two different relationships
We handle personal information in two distinct roles, and it matters which one applies:
- On our own account — for people who contact us, evaluate the product, or administer a publisher account. That is the information you give us directly, and we decide the purpose of using it.
- As an entrusted party — for data that passes through the service on behalf of a publisher. The publisher decides what its app sends us; we handle it under their instructions and only to run the service.
3. What we handle and why
| Information | Purpose of use |
|---|---|
| Name, email, publisher, and anything you type into our contact form | To reply to you and to decide whether to onboard your publisher. |
| Account details for publisher administrators | To operate the service, issue API keys, and bill where applicable. |
| Service logs — IP address, timestamp, request path, response status, bytes transferred, user agent | To deliver volumes, keep the service up, investigate abuse, and diagnose faults. |
We do not run advertising, we do not sell personal information, and we do not build cross-site profiles. The site itself sets no cookies and pulls in no third-party scripts or fonts.
4. Reader data
Our SDK is designed to need as little as possible about a reader. The service resolves content against a publisher identifier, a channel, and an opaque reader token the publisher issues. We do not ask for names, email addresses, or device advertising identifiers, and we would rather publishers did not send them. Where a publisher does entrust personal information to us, the publisher decides its purpose and their own privacy notice governs it.
5. Retention
- Service logs — 30 days, then deleted.
- Contact enquiries — up to 24 months, so we remember prior conversations.
- Account records — for the life of the account, plus any period we are required to keep records under Japanese tax and company law.
6. Entrusted parties and third-party provision
We deliberately keep this list short, and we supervise the parties we entrust with data.
| Party | Purpose |
|---|---|
| Our hosting provider (Japan) | Runs the delivery endpoint and stores volume bundles. |
| Our email provider | Delivers and receives correspondence. |
We do not otherwise provide personal information to third parties except with your consent or where the APPI permits it. We'll tell affected publishers before entrusting their data to a new party.
7. Your rights
Under the APPI you may ask us to disclose the personal information we hold about you, to correct, add to, or delete it, and to stop using or providing it where the law allows. There is no charge for a reasonable request. Email privacy@orihon.dev and we'll respond within a reasonable period after confirming your identity. If a publisher is responsible for the data, we'll pass your request to them and help them answer it. You may also consult the Personal Information Protection Commission if you have a concern we can't resolve.
8. Handling across borders
We operate in Japan, so information you send us is handled here. Readers of our publishers' apps are all over the world; where a publisher entrusts us with personal information from another country, we handle it in Japan under our agreement with them and take the measures the APPI requires for such transfers.
9. Security
Traffic is encrypted end to end in transit. Only the people who need production access have it, gated behind hardware security keys. We're a small team, and we don't claim certifications we don't hold; if you need specifics for a vendor review, ask and we'll tell you straight. To report a vulnerability, see our security.txt.
10. Changes
If we change this policy materially we'll update the date above and, for anything that affects a live integration, tell publisher administrators directly.