Privacy Policy
Effective date: June 1, 2026
1. Overview
This Privacy Policy describes how Yusuke Utsumi ("I", "me") collects, uses, and protects your information when you use Visto ("the Service"). I am committed to protecting your privacy.
2. Information I Collect
- Account data — email address used for authentication
- Usage data — projects, analysis runs, results, and SCU drafts you create
- Billing data — subscription status and plan (managed by Stripe; I do not store card details)
- API keys — your Google Gemini API key, used only to process your requests and not stored in plaintext
- Log data — Visto Shield canary hit logs (bot access records for your projects)
3. How I Use Your Information
- To provide and improve the Service
- To process payments and manage subscriptions
- To send transactional emails (login codes, billing receipts)
- To run AI analysis using your provided API keys
- To generate Visto Shield canary tokens for your projects
I do not sell your data. I do not use your data to train AI models.
4. Third-Party Services
- Supabase — database and authentication (Tokyo region)
- Stripe — payment processing (PCI-compliant, card data never touches my servers)
- Vercel — hosting and edge infrastructure
- Google Gemini — AI processing via your own API key (BYOK)
Each third party has its own privacy policy. Your API key usage with Google is governed by Google's terms.
5. Data Retention
Your data is retained as long as your account is active. Analysis results and SCU drafts are stored indefinitely until you delete them or close your account. You may request deletion of your account and all associated data at any time.
6. Your Rights
You have the right to access, correct, export, or delete your personal data. To exercise these rights, contact me at the email below. I will respond within 30 days.
7. Security
I implement reasonable security measures including row-level security on the database, HTTPS everywhere, and secure authentication via one-time codes. No method of transmission over the internet is 100% secure, but I take protection of your data seriously.
8. Cookies
The Service uses cookies solely for authentication sessions (Supabase Auth). No tracking or advertising cookies are used.
9. Changes to This Policy
I may update this Privacy Policy from time to time. Material changes will be communicated via email. Continued use of the Service constitutes acceptance.
10. Contact
Privacy questions or data requests: yusuke@meltlight.art