The operator of MADE CENTRAL ("we", "us") sets out below this Privacy Policy (this "Policy") concerning the handling of users' personal information in the web application "MADE CENTRAL" (the "Service").
Article 1 (Information we collect)
In providing the Service, we collect the following information.
- Account and authentication information: email address, display name (nickname), profile image, password (stored with irreversible encryption / hashing), one-time tokens used for email verification and password changes, the dates and times the account was created and updated, and session information used to keep you logged in. Where you use an external linked service such as Google, we collect the identifier (ID), profile information, access token and similar provided on the basis of your consent.
- Payment and subscription information: your subscription status, contract period, and the IDs required for integration with our payment processor (Stripe), such as the customer ID and subscription ID. Actual payment details such as credit card numbers and security codes are obtained and securely managed directly by Stripe, and are never stored in our database.
- Content you create or upload: the text of threads and posts (titles, descriptions and so on), thread settings (public or private status, invite codes and so on), the uploaded files themselves, and the accompanying metadata (original file name, file size, MIME type, hash value used for duplicate detection, storage path on the server, dates and times and so on).
- Usage history and activity data: action logs within the Service (the type and target of actions such as uploads, downloads and views, the date and time of execution and so on), together with additional information (metadata) as necessary. This includes aggregated data such as the "download record from other users" needed to calculate the bonus allowance. Data view history is stored and displayed for the most recent month only.
- Technical information: to maintain the security of the Service and understand how it is used, we automatically collect log information such as IP addresses, browser type, operating system, and access dates and times. We also use a bot countermeasure service (Cloudflare Turnstile) to protect against unauthorized access and automated bots, and when you submit a form, data such as your IP address, browser information and interaction patterns is sent to the provider of that service (Cloudflare, Inc.). As a rule, this log information is stored for a certain period and then appropriately erased. However, for users whose accounts we have deleted (forced withdrawal) because of a violation of the Terms of Service or similar, we may continue to retain the IP address information they used, for the purpose of applying the measure preventing re-registration (access restriction) under those Terms.
- [Personal information of minors] Where a minor user uses the Service and provides personal information, they shall do so only after obtaining the consent of their legal representative (such as a person with parental authority).
Article 2 (Purposes of use)
We use the information we collect for the following purposes.
- To send important notices about the Service (including communications relating to account management, such as sending identity verification codes for password resets and password changes), announcements, and responses to enquiries
- To manage the upload and download limits of each plan, and to calculate and apply the bonus allowance based on download records
- To display the various histories (posts, views, downloads) on a user's My Page
- To process payment of fees through Stripe and manage billing
- To monitor and respond to conduct violating the Terms of Service (however, as to data inside private threads, in accordance with the Terms of Service we do not as a rule actively monitor it except in cases such as a report)
- To protect the Service from unauthorized access and attacks by bots
Article 3 (Provision to third parties and outsourcing)
Except as provided by laws and regulations, we do not provide personal information to third parties without obtaining the user's prior consent. The following cases are exceptions.
- Where we provide the necessary information to our payment processor (Stripe) in order to process payment of fees
- Where we outsource the handling of personal information to external providers for the purpose of providing the Service and operating its systems. This includes using cloud servers and delivery services of providers located outside Japan (mainly in the United States and similar) for storing and processing data and for delivering system email (such as password reset notices). In such cases, we outsource only to providers that take appropriate safety management measures, having ascertained the personal information protection regime of the country concerned. Specifically, we use the following external services.
- Stripe, Inc. (United States): payment processing
- Cloudflare, Inc. (United States): application hosting, file storage and delivery, bot countermeasures
- Turso (United States): database operation
- Resend (United States): delivery of system email
(For the personal information protection regimes of each country, please refer to information published by Japan's Personal Information Protection Commission and similar sources.)
Article 4 (Management of information, and information users publish themselves)
- We implement appropriate security measures to prevent leakage or loss of the information we collect. Specifically, we take technical and organizational safety management measures such as encryption of communications (SSL/TLS), irreversible encryption (hashing) of stored passwords, and access restrictions on the database.
- Text a user posts in a "public thread" on the Service, the 3D data they upload, and profile information such as their display name become public information that all users can view and obtain. In a "private thread" as well, they are viewable by the other participating users. Please take care not to include personal information that should be kept private, whether your own or a third party's (such as names, addresses or telephone numbers), in this content. We bear no responsibility whatsoever for trouble arising from information a user has written themselves and thereby made viewable by others.
Article 5 (Use of cookies, access analysis and similar)
The Service uses cookies for the purposes of keeping users logged in, managing sessions and ensuring security. The cookies we use are limited to those that are indispensable to providing the Service safely. The Service also uses Cloudflare Turnstile for bot countermeasures, and that service may use cookies or similar technologies to the extent necessary for security. This is indispensable to providing the Service safely and is not intended to track user behaviour.
Apart from the above, we do not currently use access analysis tools such as Google Analytics for the purpose of tracking or profiling user behaviour, nor third-party cookies for delivering advertising. Even if we introduce access analysis tools in future in order to improve quality or investigate defects, we will not carry out behavioural tracking in a form that identifies individuals, nor provide data to third parties for advertising purposes.
You may refuse to accept cookies through your browser settings, but in that case you will be unable to log in to the Service or use its main functions.
Article 6 (Disclosure, correction and deletion of personal information, and handling of data)
- Users may check and correct their account information, and delete their account (withdraw), from the settings screen or My Page on the Service. Once the withdrawal procedure is complete, the related account information (such as the email address and password) is promptly deleted or anonymized. However, information that is difficult to delete immediately due to the design of the system, such as backup data, is erased after the retention period we specify has elapsed. In addition, solely for the purpose of implementing the restriction on re-registration after withdrawal set out in the Terms of Service (7 days after withdrawal), we retain only an irreversible hash value calculated from the email address used at withdrawal for 7 days after withdrawal, and delete it automatically once that period has elapsed (we do not retain the email address itself).
- Threads, posts and uploaded file data deleted by a user or a thread owner on the Service are deleted immediately from the live servers and cannot be restored. However, they may remain for a certain period in regular system backup data and similar.
- When a user carries out the withdrawal procedure themselves, they may choose whether 3D data they posted in the past and their posts in threads are erased completely from the system, or continue to be retained in an anonymized state that cannot identify the individual (displayed as "withdrawn user" or similar). However, if the operator forcibly deletes an account because of a violation of the Terms of Service or similar, all related data is erased completely without prior notice.
Article 7 (Changes to this Privacy Policy)
We may change this Policy as necessary. The revised Privacy Policy takes effect from the time it is posted within the Service. However, where we make an important change for which the user's consent is required by law, we will obtain the user's consent in advance by the method we specify.
Article 8 (Contact desk)
For enquiries about this Policy, and for requests for disclosure and similar under the Act on the Protection of Personal Information, please use the contact details below. Where you request disclosure of personal information, we may charge a fee we specify (set within a reasonable range taking actual costs into account). We will explain the detailed procedure at the contact desk. (We operate the Service as a sole proprietor; as to the operator's name, address, telephone number and similar, we will disclose them without delay upon request, in accordance with the provisions of the "Notation based on the Act on Specified Commercial Transactions" page.)
Email: app.madecentral@gmail.com
Contact form: /en/contact
Established July 6, 2026
Revised July 28, 2026