WonderDays Privacy Policy
WonderDays does not create user accounts. We do not send anniversaries, birthdays, names, or photos to our servers, and process only the minimum information needed to retrieve public information and produce aggregates.
Basic policy
HappyHack Inc., the personal information handling business operator (2F Shinjuku Entrepreneur Salon Building, 2-12-13 Shinjuku, Shinjuku-ku, Tokyo, Japan; Representative Director: Yoji Minabe), minimizes the information needed to provide WonderDays. The App has no registration or login feature, and we do not register profiles that directly identify users, such as names, email addresses, or telephone numbers, on our servers. We do not sell personal data or use it for advertising or behavioral tracking. Dates and times entered into the official website's planner, calculations, and export selections are handled in browser memory and are not sent to our API. The hosting provider may process connection information such as IP addresses when delivering the website.
Information handled on your device
The following information is handled on your device and is not sent to our servers. Data stored in SQLite may be included in OS backups and restored on a new device running the same OS, depending on OS settings. Photos selected for cards are temporary.
- Anniversary dates, names, start times, icons, and celebration settings
- Your birthday and children's birthdays
- On-device copies of favorited public items, notice read status, and notification settings
- Photos used in anniversary cards
Photos are used only to create cards on your device and are not uploaded to our servers.
Information sent to our servers
We send the following information over HTTPS only as needed to display public content, produce anonymous aggregates, prevent abusive repeated operations, and verify an authentic App:
- All communications: a random installation ID created on the device, the App name, and the App version
- Retrieving public information: the country code derived from the device's regional settings, time zone, display language, and, when needed, a public item ID
- Congratulations operations: one vote and a country code
- Favorite operations: whether a favorite is added or removed and the public item ID
- Write operations: App integrity verification information from App Attest or Google Play Integrity
- Source IP address accompanying a communication: used for the one-minute common rate limit and the separate ten-minute limits on challenge issuance and Android verification decoding; never stored or written to logs in raw form. When enabled, Android verification decoding also has UTC daily limits of 200 attempts per installation ID and 2,000 per source IP address.
We use the installation ID only to prevent duplicate operations and abusive repetition and to verify App integrity. We do not associate it with a name, email address, advertising ID, device-specific ID, device model, or OS version. The country code comes from the device's regional settings and is not a current location obtained from GPS or similar services.
Purposes of processing
- To display public content, notices, total congratulations, and favorite counts
- To reflect congratulations and favorite operations in anonymous aggregate values
- To prevent duplicate operations, abusive repetition, and aggregation from tampered Apps
- To investigate incidents and maintain the security and operation of the service
Information not sent to our servers
We do not send anniversary dates, names, or start times; birthdays; photos; contacts; calendar contents; notification contents; precise location; advertising IDs; IDFA; IMEI; device-specific IDs; device models; or OS versions to our servers. We do not use SDKs for advertising, cross-user behavioral tracking, crash analytics, or usage analytics.
Storage and retention periods
- Raw installation ID: never stored in a database or logs; converted into irreversible, purpose-specific HMAC keys
- Duplicate-prevention HMAC keys derived from the installation ID: no more than 48 hours
- Rate-limit HMAC keys derived from source IP addresses: no more than one minute for the common limit and no more than ten minutes for the separate challenge and Android decoding limits, in server memory. When enabled, daily Android decoding HMAC keys derived from installation IDs and source IP addresses remain in server memory until the next UTC midnight, for no more than 24 hours.
- Single-use challenge for App integrity verification: no more than five minutes
- Verified Android integrity keys: no more than 24 hours
- iOS App Attest registration keys: for as long as needed to continue verifying the authentic App; never associated with an installation ID or public item ID. No fixed expiry is set. Clearing restored security state before service resumes, or rotating the request HMAC secret, makes the existing registration unusable.
- Per-minute aggregates, total counters, public content, and notices: retained without association with a person or installation ID
We do not store raw congratulations votes or favorite operations as per-user or per-installation-ID detail records. Aggregate values are not stored in a form that allows an individual user's operation history to be reconstructed.
The 48-hour and 24-hour deletion periods above apply to the live database. Automatic point-in-time backups of the database may retain earlier copies of these keys for up to 35 days. If a backup is restored, short-lived security keys are deleted before the service resumes. Scheduled deletion pauses during a manual Azure service stop. Expired database keys are deleted and checked before the service resumes.
OS features, App integrity verification, and service providers
We use Apple App Attest on iOS and Google Play Integrity on Android to verify that operations come from an authentic App. Apple or Google's OS and services generate verification information, and we process the information needed to make a determination. Each provider's privacy policy applies to its processing.
We use OS features for photo selection, card saving, sharing, calendar export, and local notifications. If you provide information to a sharing destination or a cloud-synced calendar you select, subsequent processing is governed by the OS settings and the applicable service's policy. Our servers do not receive those photos, calendar events, or notification contents.
We engage Microsoft Azure to operate our servers and Google Cloud for Android App integrity verification. In accordance with applicable law, we select these processors, require appropriate safeguards by contract or other means, and oversee their handling of information. They process information only as needed to provide and secure their services. Processing that Apple or Google carries out for its own purposes is governed by the relevant provider's terms and privacy policy.
How to delete data
Using “Delete all data” in the App deletes anniversaries and other data on the device and discards the installation ID. Events exported to an OS calendar may not be deleted automatically, depending on permissions and the state of the calendar. Our servers do not hold anniversaries, photos, profiles, or operation histories that can be located by specifying a user. Time-limited HMAC keys are deleted after the retention periods above.
Children's data
The App is not directed primarily to children. It can be used to count the number of days since a child's birth, but a child's date of birth and name are stored in the App on the device and are not sent to our servers. A minor using the App directly must obtain consent from a parent, guardian, or other legal representative where required by applicable law. A parent or guardian may delete on-device data at any time.
Security and disclosure to third parties
We restrict communications to HTTPS and use purpose-specific HMACs, short retention periods, access controls, data-minimized logs, and other appropriate organizational, personnel, physical, and technical safeguards. We do not sell personal data. Except where required by law or where processing is entrusted to the processors identified in this Policy to the extent necessary, we do not disclose personal data we hold to third parties. If a leak or other security incident occurs, we will investigate, contain the impact, and report to authorities and notify affected individuals as required by applicable law.
Legal rights
Depending on applicable law, you may have the right to request notice of purpose, access, correction, completion, deletion, suspension or erasure, cessation of third-party disclosure, restriction of processing, objection to processing, or portability of your personal data held by us, and to lodge a complaint with a supervisory authority. Send requests to wonderdays@happyhack.co.jp with the action requested and the minimum information needed to verify it. Because we do not maintain accounts or individual operation histories, we normally have no server data that can be searched by linking it to a requester. We may ask you to verify your identity only to the extent necessary to respond. We do not charge a fee unless permitted by law and disclosed in advance, will respond within the period required by law, and will not discriminate against you for exercising your rights.
Legal bases and international processing
Where applicable law requires a legal basis for processing, we rely on providing the service at your request for the delivery of public information, and on our legitimate interest in protecting the service for duplicate prevention, rate limiting, App integrity verification, and incident investigation. Where consent is required by law, we process information within the scope of that consent. If a service provider's facilities are located outside your country of residence, information may be processed in another country. In that case, we apply safeguards required by applicable law.
Optional operational support and Stripe
When the app opens the operational support page, it does not add a name, email address, card information, contribution amount, installation ID, anniversary, public item ID, or other on-device data to the URL or send that information to our API. The support and completion pages use JavaScript for language selection. They do not use cookies, analytics, or the WonderDays API.
After the external browser moves to the Stripe payment page, Stripe collects and processes the name, email address, payment method, contribution amount, IP address, and other information needed to complete the payment, prevent fraud, send an email receipt, and comply with law, under Stripe's terms and privacy policy.
For contribution confirmation, accounting, payment inquiries, fraud response, and legal compliance, we may view the contribution amount, payment time, payment status, the email address used to send the receipt, and other payment information provided in the Stripe Dashboard. We do not associate it with the app installation ID, anniversaries, public item IDs, or other app data, and do not independently copy it beyond the period required for Stripe processing, accounting, or legal compliance.
Changes to this Policy
If we materially change the information we process or the purposes of processing, we will announce the effective date and details of the change in the App or on a public page a reasonable time in advance and apply the change only to processing on or after that date. A change of purpose or other processing that requires consent by law will not apply until the required consent is obtained. Minor wording corrections may apply from the time they are posted.
Contact
For questions or complaints about data handling, requests concerning retained personal data, or requests to correct, remove, or suspend publication of public information, contact the HappyHack Inc. privacy desk at wonderdays@happyhack.co.jp. We will review the request and respond within a reasonable period in accordance with applicable law.