Privacy Policy
How we handle your personal information
Last updated: January 18, 2026
About This Privacy Policy
Leach Inc. ("Company", "we", "us", or "our") respects your privacy and is committed to protecting your personal information when you use Totsugo ("Service").
This Privacy Policy explains what information we collect, how we use, share, and protect it. By using the Service, you agree to the terms of this Privacy Policy.
Information We Collect
Account Information
We collect the following information when you create an account:
- Email address
- Name
- Organization name (optional)
- Profile picture (optional)
Usage Information
We may automatically collect the following information related to your use of the Service:
- IP address
- Browser type and version
- Device information
- Access date and time
- Pages viewed
- Feature usage
Uploaded Content
Documents, files, and chat history that you upload to the Service are stored to provide the Service.
How We Use Information
We use the collected information for the following purposes:
- Providing, maintaining, and improving the Service
- Managing your account
- Providing customer support
- Sending service-related notifications
- Analyzing usage and improving the Service
- Detecting and preventing fraudulent use
- Complying with legal obligations
AI Processing
Documents you upload may be sent to AI service providers that we contract with for AI analysis. These providers handle your data appropriately under contract with us.
Use for Machine Learning and Model Training
We may use documents you upload, chat history, and other usage data (after anonymization or aggregation) for machine learning model training to improve the Service and enhance AI model accuracy. In such cases, personally identifiable information will be removed or anonymized before use in training.
You cannot be identified from data used in training. The scope and methods of data used for training are determined at our discretion.
Information Sharing
We do not share your personal information with third parties except in the following cases:
- With your consent: When we have your explicit consent
- Service providers: With service providers necessary for providing the Service (hosting, payment processing, analytics, etc.)
- Legal requests: In response to legal requirements, court orders, or government requests
- Rights protection: When necessary to protect the rights, property, or safety of us, you, or others
- Business transfers: Information may be transferred in connection with mergers, acquisitions, or business transfers
Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption of communications (SSL/TLS)
- Encryption of stored data
- Access control and authentication
- Regular security audits
- Employee training
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Your Rights
You have the following rights regarding your personal information:
- Right of access: Right to request access to your personal information we hold
- Right to rectification: Right to request correction of inaccurate personal information
- Right to erasure: Right to request deletion of personal information under certain conditions
- Right to restrict processing: Right to request restriction of processing under certain conditions
- Right to data portability: Right to receive your personal information in a structured format
If you wish to exercise these rights, please contact us through the contact form.
International Data Transfers
In providing the Service, your information may be stored and processed on servers outside of Japan. This includes servers of cloud service providers we use.
We take appropriate safeguards for international data transfers to ensure your information is adequately protected.
Data Transfer Destinations
Your data may be stored and processed on servers in the following regions:
- Japan (primary database)
- United States (cloud service provider servers)
- Other regions where service providers operate
Cookies and Tracking Technologies
Use of Cookies
The Service uses cookies and similar tracking technologies to record your usage and improve the Service.
Types of Cookies Used
- Essential Cookies: Required for Service operation (authentication, security, etc.)
- Functional Cookies: Remember your settings and preferences
- Analytics Cookies: Analyze usage through third-party analytics services
Cookie Management
You can disable cookies through your browser settings. However, some features may not be available.
Third-Party Tracking
The Service uses third-party analytics services. These services use their own cookies to collect data. Please review each service's privacy policy for details.
Third-Party Service Providers
We use third-party service providers in the following categories to provide the Service:
Authentication & User Management
Service providers for user authentication, account management, and session management
Database & Storage
Service providers for database management, file storage, and data search
Payment Processing
Payment processing service providers for credit card payments and subscription management
AI & Machine Learning
AI service providers for large language models (LLMs), text embeddings, OCR processing, and document analysis
Analytics & Monitoring
Analytics service providers for web analytics and user behavior analytics
Hosting & Infrastructure
Cloud service providers for frontend and backend API hosting
These service providers handle your data appropriately under contract with us. Please review each provider's privacy policy on their respective websites.
Data Retention
Retention Principles
We retain your personal information for as long as necessary to provide the Service.
Specific Retention Periods
- Account Information: While account is active, and 30 days after account deletion
- Uploaded Files: While account is active, and 90 days after account deletion
- Chat History: While account is active, and 90 days after account deletion
- Usage Logs: Up to 2 years
- Payment Information: As required by law (typically 7 years)
Extended Retention
We may extend retention periods if required by law, for dispute resolution, or for Service operation.
Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If we become aware that we have collected personal information from a child under 13, we will delete such information promptly. Please contact us if you believe we have collected information from a child under 13.
Rights of European Residents (GDPR)
If you reside in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing
We process personal information based on the following legal bases:
- Consent: Processing based on your explicit consent
- Contract Performance: Processing necessary for Service provision
- Legal Obligation: Processing required by law
- Legitimate Interest: Processing based on our legitimate business interests
Additional Rights
- Right to Object: Right to object to processing based on legitimate interests
- Right to Object to Automated Decision-Making: Right to object to fully automated decision-making, including profiling
- Right to Lodge a Complaint: Right to lodge a complaint with a data protection supervisory authority
Data Protection Officer
For GDPR-related inquiries, please contact us through the contact form.
Rights of California Residents (CCPA)
If you reside in California, you have the following rights under the California Consumer Privacy Act (CCPA):
Right to Know
Right to request disclosure of the categories and specific pieces of personal information we collect, use, and share, up to twice per year, free of charge
Right to Delete
Right to request deletion of personal information we have collected, subject to certain exceptions
Right to Opt-Out of Sale
We do not sell your personal information. However, if we sell personal information in the future, you have the right to opt-out of such sales.
Non-Discrimination
We will not discriminate against you for exercising your CCPA rights by denying service or changing prices.
Exercising Your Rights
To exercise your CCPA rights, please contact us through the contact form.
Complaint Procedures
Filing Complaints
If you have privacy-related complaints or concerns, please contact us through the contact form. We will respond within a reasonable period.
Supervisory Authority Complaints
If you reside in the European Economic Area (EEA), you have the right to lodge a complaint with your country's data protection supervisory authority.
Contact
Leach Inc.
9F, Fudanotsuji Square
5-36-4 Shiba, Minato-ku, Tokyo 108-0014, Japan
Website: https://leach.co.jp
Contact Form: https://forms.gle/Putud7QU1JYsHp3M7