- No account required: Suguwari has no sign-up or login. Member names and amounts are not collected as account information. The contact form receives your optional name, optional reply email, and message only when you submit it.
- Calculation data stays on your device before the result screen: While you are entering the split, member names and amounts are stored within your device (browser) and are not sent to the operator's servers.
- Suguwari attempts to prepare a share link on the result screen: When a valid result with at least two members and a payment is displayed, Suguwari sends the bill-splitting data over an encrypted connection to a server (Cloudflare) to prepare a short link in the share area. If storage succeeds, the data can be stored before you copy or send the link, including when you never send it. A "link everyone can use" is stored only after you choose to create it. Both types are kept for 90 days and then deleted automatically. There is no login authentication on the link; anyone who knows the URL can view its contents.
- What each measurement service tells us: Google Search Console provides aggregate search impressions, clicks, queries, pages, and countries. Some anonymised queries may be omitted for privacy. Cloudflare Web Analytics provides cookieless aggregate page-view, visit, and performance information. These services alone do not tell us whether someone completed a split, what they used Suguwari for, or whether a short share link was issued.
- Usage and attribute information we collect and how we use it: This service may collect information about usage and attributes in a form that does not identify you (such as the display language, a coarse market candidate inferred from the region in your browser settings, aggregate analytics, and purpose categories) and use it to improve the service, produce statistics, for advertising and marketing, and to provide it to third parties in a non-identifying form. We do not collect information that identifies you, such as your name or contact details, and do not use such information for these purposes.
- Product-improvement data we record: Product-event collection is designed to be disabled by default. After security checks for both APIs, legal review, these Japanese and English disclosures, and owner approval, production has run with
PRODUCT_METRICS_ENABLED=truesince July 16, 2026 and currently collects the following five event types. Values with whitespace or different letter case do not enable it. Cloudflare Pages environment-binding changes take effect through a redeployment. While disabled, the optional-purpose API returns 503 and short sharing still succeeds but writes no successful-issuance event. While enabled, we record one successful-issuance event when a valid short share link is issued. If you answer the optional question on the result screen, we record one purpose (meal, trip, shared home, event, shared gift/purchase, or other), the app language, and a coarse market candidate inferred on your device from the region in your browser settings. You can use every feature without answering, and there is no free-text field. We also record three anonymous events to improve the hand-off experience: a share link was opened (only its static or shared-link type), a split was newly created, and a recipient went on to create their own split, each as a single count. These likewise never include names, amounts, member or event names, shared content, short IDs, or URLs, and are not used to estimate individuals or headcount. Write-side anonymous events are lightly rate-limited using a key derived from your IP with an HMAC secret of at least 32 characters; the raw IP is not stored. Cloudflare Analytics Engine automatically adds server receipt time and sampling information, but the admin view does not expose individual timestamps. The provider's current retention is three months, and the admin view reads only the latest 90 days. These are directional event metrics that may include duplicates or bots. A link-issuance count is not a count of actual sends or people. The mix of optional response events does not tell us how many distinct people answered or the mix of all users. Google Analytics 4 (GA4) tags are not currently installed and are separate from these five events. For an emergency stop or rollback, we remove or disable the flag and redeploy the default-off version through the approved release process. We do not treat collection as stopped until the optional-purpose API returns 503, short sharing succeeds with zero event writes, and the admin view reports collection disabled. - Data we do not store in product-improvement events: We do not store names, email addresses, contact messages, member names, event titles, payment labels, amounts, currencies, split adjustments, individual shares, shared payloads, short IDs, raw URLs or referrers, IP addresses, User-Agent, Accept-Language, cookies, user IDs, device IDs, session IDs, fingerprints, client timestamps, location data, or free text in the product-event dataset or application logs. To discourage abuse, the short-share API and the everyone-can-add live-link API keep separate keys in the forms
rl:${raw IP}andrl:live:${raw IP}, plus a count and fixed-window reset time, and evaluate fixed 60-second windows. Their physical KV expiry is set to 60 seconds after the last allowed update. The optional-purpose API transforms the IP supplied by Cloudflare using HMAC-SHA256 with a sufficiently random secret of at least 32 characters and keeps the derived key, count, and fixed-window reset time for a fixed one-hour window. On each allowed update its physical expiry is set to the remaining window, subject to KV's 60-second minimum, so it is at most one hour after the last allowed update. None is written to the product-event dataset or application logs or used to count or track people. These are simple sequential deterrents, not strict concurrent limits; Cloudflare's edge protection is not a strict global limit either. If the secret, IP, or store needed for optional-purpose data is unavailable, only that API returns 503; calculation, results, and sharing continue. Cloudflare may process IP addresses and similar request metadata for delivery, security, and request handling. - Admin access and small groups: The product-improvement admin view is available only to authorised operators through Cloudflare Access. It shows weekly weighted estimated event counts and aggregate purpose and market breakdowns, not raw-event lists or per-person histories. A market-by-purpose breakdown is hidden when its weighted estimated event count is below 10. Ten does not mean ten people and is not a guarantee of anonymity.
- Legal classification: This design is intended to avoid storing information that identifies or tracks a person in the product-improvement dataset. It is not a guarantee that the data is legally classified as "anonymous" or "non-personal" in every jurisdiction.
- Service providers and sharing: We use the Cloudflare and Google services described above for hosting, delivery, and measurement. We do not sell or provide data in a form that identifies you, except to service providers as needed to operate the service or as required by law. Usage and statistical information processed into a form that does not identify you may be provided to third parties for the purposes described above.
- Contact: Please reach us through the contact form. Your optional name, optional reply email, and message are used only to review the request, notify the operator, and reply. The server-side copy is deleted automatically after 30 days, and notification emails are kept only as long as needed to handle the request. We temporarily use your IP address for a fixed one-hour, five-request spam limit and store the key, count, and window reset time. We do not include the IP in the contact record or notification email. Physical expiry is set to at most one hour after the last allowed update.
This document is a translation. The Japanese version shall prevail. See the Japanese privacy policy.