The operator of MADE CENTRAL ("we", "us") sets out below this Privacy Policy (this "Policy") concerning the handling of users' personal information in the web application "MADE CENTRAL" (the "Service").
Article 1 (Information we collect)
In providing the Service, we collect the following information.
- Account and authentication information: email address, display name (nickname), profile image, password (stored in irreversibly encrypted / hashed form), one-time tokens and verification codes used for email verification and password changes, the dates and times the account was created and updated, the date and time the password was last changed, and session information used to keep you signed in. Where you use an external linked service such as Google, we collect the identifier (ID), profile information, access token and similar provided with your consent.
- Two-factor authentication information: if you enable two-factor authentication, the secret key shared with your authenticator app, whether it is enabled or disabled, and your recovery codes (stored only as irreversible hash values for comparison; the codes themselves are not stored).
- Records of consent: for the Terms of Service and this Policy, the version number of the document you consented to, the date and time of consent, the display language of the screen on which you consented, and the route of consent (new registration, registration via an external linked service, or renewed consent following a revision). We also store records of the consent given on the confirmation screens shown when creating or joining threads and when sending or receiving data (the type of action, the type of confirmation screen, additional information such as the thread concerned, and the date and time).
- Payment and subscription information: subscription status, contract period, the IDs needed to work with our payment processor (Stripe) such as the customer ID and subscription ID, and records of the processing of notifications from Stripe (the notification identifier, its type, the processing result and the date and time). Actual payment details such as credit card numbers and security codes are collected and securely managed directly by Stripe and are never stored in our database.
- Content you create or upload: the text of threads and posts (titles, descriptions and so on), thread settings (public/private status, invite codes and so on), the uploaded files themselves, and their accompanying metadata (original file name, file size, MIME type, hash value used for duplicate detection, storage path on the server, dates and times and so on). We also store the results of file safety inspections (the file hash value, the version of the inspection criteria, the outcome and reason, and the inspection date and time).
- Usage history and activity data: action logs within the Service (the type and target of actions such as upload, download and viewing, the date and time of execution and so on) and additional information (metadata) as required. This includes aggregate data such as "downloads by other users", which is needed to calculate bonus allowances. We also store counters used to administer the various limits set out in the Terms of Service (uploads, downloads, posts, password changes, email address changes and so on).
- Reports, notifications and enquiries: the content of reports of rights infringement and similar made by other users (the target, the category of reason, the details, the reporter, the processing status, and the date and time), the content and read status of notifications displayed to you within the Service, and, where you contact us through the enquiry form, your name, email address, the category of your enquiry and its content.
- Information used for access restrictions: the IP address last used by a user whose account we deleted for violating the Terms of Service (forced withdrawal), and a hash value calculated from the email address of a user who withdrew voluntarily, used to restrict re-registration for a limited period.
- Records of deletion processing: where a cancellation or deletion request to an external service (the payment processor, the file storage service or the email delivery service) arising from a withdrawal or data deletion does not complete because of a communication failure or similar, we temporarily store the minimum information needed to retry (the identifier of the target, the email address in the case of stopping email delivery, the number of attempts, and a summary of the failure). These are deleted once processing is complete.
- Technical information: to maintain the security of the Service and to understand how it is used, we automatically collect log information such as IP addresses, browser type, operating system and access date and time. To protect against unauthorised access and automated bots we use a bot protection service (Cloudflare Turnstile); when you submit a form, data such as your IP address, browser information and interaction patterns is sent to its provider (Cloudflare, Inc.).
- [Personal information of minors] Where a minor uses the Service and provides personal information, they shall do so only after obtaining the consent of their legal representative (such as a person with parental authority) in advance.
Article 2 (Purposes of use)
We use the information we collect for the following purposes.
- To send important notices about the Service (including account-related communications such as password resets and identity verification codes for password changes, as well as communications about outages and maintenance, significant changes to the Service or its features, and revisions to the Terms of Service or this Policy), announcements, and responses to enquiries
- To administer the upload and download limits of each plan, and to calculate and apply bonus allowances based on download records
- To display the various histories (posts, views, downloads) on your My Page
- To process payments and manage billing through Stripe
- To inspect whether uploaded files would place an excessive load on viewers' devices and whether they contain harmful programs
- To confirm and record whether you have consented to the Terms of Service and this Policy and which version you consented to, so that we can prove it where required by law
- To monitor and respond to conduct that violates the Terms of Service (however, in accordance with the Terms of Service we do not, as a rule, actively monitor data inside private threads except where a report is made)
- To protect the Service from unauthorised access and bot attacks, and to restrict re-registration by violators
- To send news about new features and information about campaigns and discounts to those who have consented to receive them
Article 3 (Handling of email)
- The email we send you falls into three categories.
- Email necessary to provide the Service: email address verification, password resets, verification codes, notices of changes to your registered email address, replies to enquiries and so on. These are essential to your use of the Service and cannot be turned off (except by deleting your account).
- Important notices about the Service: outages and maintenance, significant changes to the Service or its features, revisions to the Terms of Service or this Policy, price changes, and notices about discontinuation of the Service. These are not for advertising or promotional purposes, and because they affect your rights or your use of the Service, we may send them to all registered users at once. They cannot be turned off (except by deleting your account).
- Email containing advertising or promotion: news about new features, campaigns, discount offers and so on. We send these only to those who have consented to receive them on the settings screen.
- By default you do not receive email containing advertising or promotion. We do not treat registering an account, completing email verification, or using the Service as consent to receive such email.
- If you have consented to receive them, you can stop receiving them at any time from the settings screen. When you do so, we exclude your email address from delivery of email containing advertising or promotion. Note that in order to send the important notices described above, your email address is retained as a contact in our email delivery service for as long as your account exists (it is deleted when you delete your account).
Article 4 (Provision to third parties and outsourcing)
Except where required by law, we do not provide personal information to third parties without obtaining your prior consent. The following cases are exceptions.
- Where we provide the information necessary to our payment processor (Stripe) in order to process payment of fees
- Where we outsource the handling of personal information to external providers for the purpose of providing the Service and operating our systems. This includes using cloud services of providers located outside Japan for data storage and processing and for the delivery of email. The external services we currently use are as follows.
- Stripe (payment processing): subscription payments and billing management. The information provided is your email address, your identifier and your subscription details.
- Cloudflare (application hosting, file storage and delivery, bot protection): the runtime environment of the Service, storage of uploaded files, and bot detection on form submission.
- Turso (database operation): storage of the data set out in Article 1 of this Policy, other than the files themselves.
- Resend (email delivery): delivery of email necessary to provide the Service and of email to those who have consented to receive it. The information provided is your email address, display name and the body of the email.
- Google (sign-in via an external linked service, and receipt of enquiry email): the feature that lets you sign in with a Google account, and the operation of our enquiry email address (Gmail).
- [Provision to third parties in foreign countries] Each of the services above is provided by a company based outside Japan (mainly in the United States), and your information may be stored and processed outside Japan. We outsource only after reviewing the privacy policies and data processing terms published by these providers, and we confirm through our contracts and the settings each provider offers that security measures are in place. If you would like details of the legal entity contracting for each service, the specific countries or regions in which data is stored, or the content of the data processing agreements, please contact our contact desk and we will tell you what we know. Note that systems for the protection of personal information in foreign countries may differ from those in Japan; please refer to information published by the Personal Information Protection Commission of Japan and similar sources.
Article 5 (Retention periods)
We retain the information we collect only for the period necessary to achieve the purpose of use, and delete it automatically once that period has passed. The main retention periods are as follows.
| Account information, posts and files | Until you withdraw or delete them. Treatment on withdrawal is set out in Article 7. |
|---|
| Data view history | The most recent month (31 days). Older entries are deleted automatically. |
|---|
| Upload and download history | While the account exists (it is used to calculate limits and bonuses). Deleted on withdrawal. |
|---|
| Records of consent (consent log) | One year from the record. On withdrawal we delete them without waiting for that period to elapse. |
|---|
| Records of Stripe notifications | 90 days for those processed successfully. Those that failed are kept until the cause has been investigated. |
|---|
| Limit counters | Short-term limits: 24 hours from the last update. Yearly limits (password and email address changes): up to two years. |
|---|
| Hash value for post-withdrawal re-registration restriction | 7 days from withdrawal, then deleted automatically. |
|---|
| IP address kept after a forced withdrawal | For as long as the re-registration restriction needs to continue. If you would like it lifted, please contact the contact desk. |
|---|
| Records used to retry deletion | Until deletion or cancellation at the external service completes (deleted at that point). If it has not completed after the prescribed number of attempts, kept until the cause has been investigated. |
|---|
| Content of enquiries | In our mailbox, for as long as we need to refer to it after handling the enquiry. |
|---|
| Server access logs | The period set by our hosting provider (Cloudflare). We do not separately retain them for longer. |
|---|
| Backups | Data remains for a certain period in the backups taken by our database and file storage providers. We cannot erase these immediately by our own action. |
|---|
Article 6 (Managing information, and information you make public yourself)
- We implement appropriate security measures to prevent leakage and loss of the information we collect. Specifically, we take technical and organisational safety measures including encryption of communications (SSL/TLS), irreversible encryption (hashing) of passwords and two-factor authentication recovery codes, access restrictions on the database and the administration screens, and separate management of credentials for external services.
- Text you post to a "public thread" on the Service, 3D data you upload, and profile information such as your display name become public information that any user can view and obtain. In a "private thread" too, other participating users can view them. Please take care not to include personal information that should be kept private (your own or a third party's name, address, telephone number and so on) in this content. Except where caused by our wilful misconduct or gross negligence, we bear no responsibility for trouble arising from information you have written yourself and made viewable by others.
Article 7 (Treatment on withdrawal and deletion)
- You can check and correct your account information, and delete your account (withdraw), from the settings screen and My Page on the Service. When withdrawing, you may choose whether the data and posts you have made remain in anonymized form (displayed as "withdrawn user" or similar) or are erased completely from the system.
- [If you choose complete erasure] We delete your account information, authentication information, two-factor authentication secret key and recovery codes, the IDs linking you to our payment processor, your IP address, usage history, notifications, records of consent, posts and uploaded files.
- [If you choose to remain in anonymized form] Your posts and files remain, but your email address, display name, profile image, password, external service link information, session information, two-factor authentication secret key and recovery codes, the IDs linking you to our payment processor, notifications and records of consent are deleted or replaced with anonymous values. Where an account has no posts or files at all, there is nothing to keep anonymously, so it is erased completely regardless of your choice.
- [How deletion actually works] The records in our database are deleted as part of the withdrawal procedure. From that point the information can no longer be accessed through the normal paths of the Service. Deletion of the files themselves from the file storage service (Cloudflare R2) and of your address from the delivery list of the email service (Resend) involves communication with external services and may therefore not complete immediately if there is a communication failure. In that case we retain the minimum information needed for deletion and retry automatically every hour. We therefore do not warrant that data is "erased completely and immediately": deletion normally completes within a few minutes, and at the latest within a few days even if a failure persists.
- [Backups] Even after the deletion in the preceding paragraph has completed, data remains for a certain period in the backups taken by our database and file storage providers. These are erased as each provider's retention period expires, and we cannot erase them immediately by our own action.
- [Information retained for a period after withdrawal] Solely for the purpose of implementing the post-withdrawal re-registration restriction (7 days after withdrawal) set out in the Terms of Service, we retain only a hash value calculated from the email address used at withdrawal, for 7 days after withdrawal, after which it is deleted automatically (we do not retain the email address itself). This hash value works by producing the same value for the same email address, which lets us check whether an address has already withdrawn; the email address cannot be reconstructed directly from the value. It is, however, possible to check whether the value matches a candidate address that is already known. We do not use this value for any purpose other than the re-registration restriction.
- Threads, posts and uploaded files deleted by a user or a thread owner are handled in the same way as in the preceding paragraphs. Data that has been deleted cannot be restored.
- Where we forcibly delete an account for a violation of the Terms of Service or similar, all related data is erased without prior notice. However, for the purpose of applying the re-registration restriction, we continue to retain the IP address described in Article 1, paragraph 8. That record does not include the deleted user's email address or any other information identifying them.
Article 8 (Cookies, access analysis and similar)
The Service uses cookies for the purposes of keeping you signed in, managing sessions and ensuring security. The cookies we use are limited to those that are essential to providing the Service safely. The Service also uses Cloudflare Turnstile for bot protection, and that service may use cookies or similar technologies to the extent necessary for security. These are essential to providing the Service safely and are not intended to track user behaviour.
Apart from the above, we do not currently use access analysis tools such as Google Analytics for the purpose of tracking or profiling user behaviour, nor third-party cookies for advertising. Even if we introduce access analysis tools in future to improve quality or investigate defects, we will not track behaviour in a way that identifies individuals, nor provide data to third parties for advertising purposes.
You may refuse cookies through your browser settings, but in that case you will not be able to sign in to the Service or use its main functions.
Article 9 (Procedure for requests for disclosure and similar)
- Under the Act on the Protection of Personal Information, you or your agent may request notification of the purpose of use, disclosure (including disclosure of records of provision to third parties), correction, addition or deletion of content, suspension of use or erasure, or suspension of provision to third parties, in respect of the personal data we hold about you.
- Please make your request to the contact desk in Article 10, stating clearly what you are requesting. Note that you can change your display name and email address, and delete posts, files and your account, yourself from the settings screen of the Service without going through this request procedure.
- [Identity verification] To confirm that a request comes from you, we ask as a rule that you contact us from the email address registered with us. If you cannot use that address, we will verify your identity by means we consider reasonable, such as asking you to tell us information about the account (when you registered, your display name, your recent usage and so on). For a request made by an agent, we will confirm the authority to act by means such as a power of attorney.
- [How and when we reply] We will reply by email to the requester's email address, as a rule within two weeks of receiving the request. If the investigation takes longer, we will tell you so and give you an expected timescale in advance.
- [Fees] For requests for notification of the purpose of use and for disclosure, we may charge a fee of 1,000 yen (tax included) per request. Where a fee applies, we will tell you in advance that it applies, the amount and how to pay, and proceed only once you agree. No fee is charged for requests for correction, addition or deletion, suspension of use or erasure, or suspension of provision to third parties.
- [Where we cannot comply] We may be unable to comply with a request where disclosure is not permitted by law, where we cannot confirm that you are the person concerned, or where doing so would seriously hinder the proper operation of the Service. In such a case we will tell you so and give our reasons.
Article 10 (Contact desk)
For enquiries about this Policy and for requests for disclosure and similar under the Act on the Protection of Personal Information, please contact us at the following. (We operate the Service as a sole proprietor. The operator's name, address and telephone number are stated on the "Notation based on the Act on Specified Commercial Transactions" page.)
Email: app.madecentral@gmail.com
Contact form
Article 11 (Changes to this Policy)
- We may change this Policy in response to changes in the law or in the content of the Service.
- Where we make a change, we will announce the content after the change and the time at which it takes effect by posting on the Service. Minor changes (corrections of wording, reflection of factual matters and so on) take effect from the time they are posted.
- Where we change the purpose of use beyond the scope that can reasonably be regarded as related to the purpose before the change, or otherwise make a change for which your consent is required by law, we will make the announcement in the preceding paragraph at least 14 days before the time of effect and will also ask for consent to the revised Policy, for example on a screen shown at login. If you do not consent, you may delete your account (withdraw).
- We retain the content of this Policy as it stood before each revision, together with the revision date, so that you can check it afterwards. If you would like to see an earlier version, please contact the contact desk.
Established July 6, 2026
Revised August 10, 2026