Skip to content

Privacy Policy

Draft — last updated October 10, 2026

In case of discrepancy, the Japanese version prevails.

This policy explains what information Kitsuen (“the Service”), operated by [Operator name] (“we”, “us”), handles when you use the website and the installable web app, and why. Kitsuen has no accounts and does not ask for your name, email address or phone number.

In short

  • You can browse the map and the rules guide without registering anything.
  • When you first send something (for example a report), your browser gets a random device token. We store only a hash of it.
  • Your location is used on your device. It is saved on our server only together with a report you send.
  • We do not sell your data, show ads, or use advertising or third-party analytics trackers.

No accounts: the device token

The first time you send something — a report, an answer to a quick check, an edit suggestion, a problem report, a saved spot or a notification setting — our server issues a random secret in a cookie named hs_device. The cookie is HttpOnly (page scripts cannot read it), sent only over HTTPS, and expires after up to 400 days.

On our server we store a hash of the secret, never the secret itself, together with a device record: a random ID, your interface language (used for notification text), a trust value used to weight reports, the time it was created and last used, and a hashed IP address (see below). This device record is how we link your reports, saved spots and contribution statistics to your browser without knowing who you are.

Just viewing the map, spot pages or the rules guide does not create a device record.

Your location

If you allow it, your browser shares your position with the Service. We use it on your device to show where you are, to sort nearby smoking areas, for the in-page walking guide, and to notice when you have arrived (within about 30 m). Location is only read while a Kitsuen page is open; we do not track you in the background and do not keep a location history.

To load smoking areas, the app sends the centre of the map you are looking at (which is your position when the map is centred on you) to our server. After “Not here”, it sends your position to find the next nearest spots. These requests are used to answer you and are not saved in our database.

Your position is saved on our server only in these cases:

  • When you send a report (“Found it”, “Not here”, etc.): your position, its accuracy and the distance to the spot are stored with the report so we can check that it is plausible.
  • While the walking guide is open: if you stay within the arrival radius of the spot for 3 minutes or more, the app sends a quiet “probably here” report with your position. This happens only if your browser already has a device token.

You can deny or revoke location access in your browser settings. The map and the rules guide still work without it.

What you send us

  • Reports: whether a spot was there, the reason if not, your answers to quick checks (ashtray, roof, crowd, etc.), what screen you reported from, your interface language and the time.
  • Edit suggestions: the name, floor and location note you enter.
  • Problem reports about a spot or an edit: the reason and an optional note.
  • Saved spots: which spots you saved.

Names and location notes you write are published on the Service for everyone to read (not linked to you). Please do not include personal information in them. Reports are shown only in aggregate, for example as a confidence label or “last confirmed” date.

Usage events

To understand whether the Service is useful, the app records a small set of events, such as opening the walking guide, tapping “Go”, seeing or answering a quick check card, or going from the rules guide to the map. Each event contains the event name, the spot ID if any, the interface language, a few details (for example which question was answered) and the time. If your browser has a device token, the event is linked to your device record. We also count daily views per spot. We do not use third-party analytics tools.

IP address

We use your IP address to limit how many devices can be registered from one network, to prevent abuse. We store it only as a salted hash (it cannot simply be turned back into the address), with the device record. We do not use IP addresses to guess your location.

Our hosting and network providers may process IP addresses in their own logs for security and operations.

Service providers and other services

We use the following providers to run the Service. Some of them may process data outside Japan.

  • Amazon Web Services (AWS): hosting of the website, API and database, and file storage, in the Tokyo region (ap-northeast-1).
  • Amazon Translate (AWS): location notes that users write are sent to Amazon Translate to create versions in the other languages. Machine translations are marked as such. Spot names are not translated.
  • Web Push: if you turn on notifications, your browser creates a push subscription with its vendor’s push service (for example Google, Apple, Mozilla or Microsoft). We store the subscription’s endpoint address and keys with your device record and use them only to tell you that someone reported one of your saved spots closed.
  • Error monitoring (Sentry): if enabled, technical details about errors (such as the page, browser type and error message) are sent to Sentry so we can fix problems.
  • Map: the map uses OpenStreetMap data packaged by Protomaps and served from our own storage. Map fonts and icons are loaded from protomaps.github.io (GitHub Pages), so your browser connects to GitHub, which receives your IP address and standard request information.

Data stored on your device

Besides the hs_device cookie, the Service stores the following in your browser. It stays on your device unless described elsewhere in this policy.

  • NEXT_LOCALE cookie: your language choice (English or Japanese).
  • Local storage “kitsuen.device”: a flag that this browser has a device token.
  • Local storage “kitsuen.pendingVisit”: the spot you chose “Go” for, the time, and the last position seen during the walking guide, so we can ask “Was it there?” when you come back within 3 hours.
  • Local storage “kitsuen.askedSpots”: spots we already asked you about, so we ask only once.
  • Local storage “kitsuen.lastVisit” and session storage “kitsuen.session”: when you last opened the app, to show how your reports helped since then.
  • Local storage “kitsuen.savedSpots”: an offline copy of your saved spots.
  • Service worker cache: the rules guide, pages you visited and app files, so they work offline.

How we use information

  • To provide the map, reports, saved spots and notifications.
  • To estimate how reliable each spot’s information is.
  • To prevent spam, false reports and other abuse, and to review reported content.
  • To measure and improve the Service.
  • To comply with law and protect the rights and safety of users and others.

Sharing

We do not sell personal information and do not share it for advertising. We share information only with the service providers above to run the Service, when required by law, or when needed to protect the rights, property or safety of users, the public or us. Contributions you make public (spot names and location notes) can be read by anyone.

How long we keep data

  • The device token cookie expires after up to 400 days.
  • Device records, reports and other contributions are kept while the Service operates, because they are the basis of each spot’s reliability. We may delete or anonymise old data when it is no longer needed.
  • A push subscription is deleted when you turn notifications off in the app.
  • Usage events are kept only as long as needed to analyse and improve the Service.

Your choices

  • Browse without sending anything: no device token is created.
  • Deny location access: you can still use the map and the rules guide.
  • Clear this site’s data in your browser: this removes the device token, local storage and offline copies. Your earlier contributions stay on the Service but are no longer linked to your browser, and your contribution statistics are lost.
  • Turn notifications off on the “Me” page or in your browser settings.
  • Contact us at [contact email] for questions or requests about your data. Because we do not know who you are, we may only be able to act on data we can link to your browser.

Security

Connections use HTTPS, the device secret and IP addresses are stored only as hashes, and the database is not reachable from the internet. No system is perfectly secure, but we work to protect the information we hold.

Age

Smoking areas are for people of legal smoking age (20 in Japan). The Service is intended for adults and is not directed at anyone under 20.

Changes to this policy

We may update this policy. We will change the date at the top of this page and, for important changes, show a notice in the Service.

Contact

[Operator name] — [contact email]

Report