Privacy Policy
Last updated: October 3, 2026
This Privacy Policy explains how deeply.tokyo (“Deeply”, “we”, “us”) collects, uses, stores and shares information when you use our service at deeply.tokyo and related pages (the “Service”). The Service is operated by susuROBO KK in Japan. By using the Service you agree to the practices described here and to our Terms of Service.
1. Information we collect
Account information
- Email sign-up: your email address and a password. Passwords are handled by Google Cloud Identity Platform; we never see or store them in plain text.
- Sign in with Google: see Section 2.
- Whether your email address is verified, how you signed in, and when your account was created.
Profile information you give us
- Whether you are joining as a visitor or as a local host, your first name, and your gender.
- Who you would like to be matched with (women, men or anyone).
- Visitors: the cities you plan to visit, your travel dates, the country you are travelling from, your Japanese level, other languages you speak, and the scenes and interests you choose or type in.
- Hosts: your city, the neighbourhoods you know, the scenes you can show visitors, and the languages you speak.
- Profile setup: your birth date, country of birth, height, occupation and self-introduction.
Identity and age verification
Everyone on Deeply must be 20 or older and pass an identity and age check before they can like or message other members. This check is carried out by our verification provider, Didit (Didit Inc., data processed in the European Union). You submit your ID document and a selfie directly to Didit, which reads the document and compares the selfie with the document photo (a liveness and face-match check). We receive the result of the check, your date of birth, and the type and issuing country of the document. We do not receive or store images of your ID document, your selfie or any biometric data.
Messages, reviews and reports
When the matching features are available: likes you send and receive, messages between you and other members, reviews you write or receive, and reports you make or that are made about you.
Technical and usage information
- Marketing parameters from the link you arrived through, such as UTM tags and ad click identifiers from Google or Meta, the website or AI assistant that referred you, the page you landed on, and your browser language, so we can tell which channels bring people to Deeply.
- Server logs with your IP address, browser type and request times, used for security and debugging and kept for up to 30 days.
- Browser storage that keeps you signed in (see Section 6).
2. Information we receive from Google
If you choose Sign in with Google, Google shares the following with us, with your permission:
| Scope | Data | How we use it |
| openid | A unique Google account identifier | To link your Google account to your Deeply account and sign you in. |
| email | Your email address and whether it is verified | As your account identifier, for sign-in, and to contact you about your account and important changes to the Service. |
| profile | Your name and profile picture | To fill in your first name if you leave it blank, and to personalise the Service. |
We do not request access to your Gmail, Google Drive, Contacts, Calendar or any other Google data, and we do not receive your Google password.
Limited Use. Deeply’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:
- use Google user data only to provide and improve the user-facing features of Deeply described above;
- do not sell Google user data, and do not use or transfer it for advertising, including personalised or retargeted ads;
- do not use Google user data to develop, improve or train generalised AI or machine-learning models;
- do not allow humans to read Google user data unless you give us permission, it is needed for security or to comply with law, or it has been aggregated and anonymised for internal operations.
3. How we use information
- To create and run your account, and to sign you in.
- To suggest matches between visitors and hosts based on city, dates, scenes, languages and match preferences.
- To verify identity and age, keep members safe, review reports, and prevent fraud, abuse and touting.
- To contact you about your account, your trip, and important changes to the Service.
- To understand, in aggregate, how people find and use Deeply and to improve it, including measuring which of our own marketing channels work.
- To comply with legal obligations.
Your gender and match preference are used only for matching. Because a match preference can reveal information about your private life, we treat it as sensitive: it is never shown publicly, never used for advertising, and you can change or delete it at any time.
We do not sell your personal information.
4. How we share information
With other members
When matching is available, members you can match with will see parts of your profile: first name, profile photo, gender, age, height, country of birth, occupation, self-introduction, cities, languages, Japanese level, scenes and interests, and for hosts, neighbourhoods. Visitors’ travel dates are shown to hosts in the same city. We calculate your age from your birth date; we never show other members your birth date, email address, ID document, match preference or the country you are travelling from.
With service providers
We share information with providers that process it on our behalf to run the Service, under contracts that limit their use of it:
| Provider | Purpose | Data involved |
| Google Cloud (Identity Platform, Cloud Run, Cloud Functions, Cloud SQL) | Sign-in, hosting, databases | All categories above |
| Didit (identity verification, EU) | ID and age checks | ID document, selfie, date of birth |
| Zoho Mail | Email we send and receive | Your email address and messages you send us |
| Google Fonts, jsDelivr | Delivering fonts and the sign-in library to your browser | IP address, browser information |
Google user data received through Sign in with Google is shared only with Google Cloud Identity Platform and our database hosting as needed to sign you in.
We may also disclose information if required by law, to protect the rights, safety and property of our members or others (for example, to respond to an emergency or a police request about a meetup), or as part of a merger, acquisition or sale of assets, in which case this Policy will continue to apply to your data.
5. Storage, security and retention
Your data is stored on Google Cloud in Japan (Tokyo region). Some providers listed above process data in other countries, including the United States; where they do, we rely on their contractual safeguards. Data is encrypted in transit (HTTPS/TLS) and at rest, and access is restricted to personnel who need it to run the Service, using least-privilege permissions, multi-factor authentication and access logging.
We keep your account and profile data for as long as your account is active. When you delete your account, we delete or anonymise your personal information within 30 days, except where we must keep it longer to meet legal obligations, to resolve disputes, or to keep a record of verification results and safety reports that led to an account being removed. Aggregated, anonymised statistics may be kept indefinitely.
6. Cookies and similar technologies
We use browser storage that is necessary to keep you signed in. We do not currently use analytics or advertising cookies. If we add them, we will update this Policy and ask for your consent where the law requires it. You can delete browser storage in your browser settings; doing so will sign you out.
7. Your choices and rights
- Access and correction: you can ask for a copy of your data or ask us to correct it.
- Deletion: you can ask us to delete your account and associated data by emailing max@deeply.tokyo from your account email address.
- Revoking Google access: you can remove Deeply’s access at any time at myaccount.google.com/permissions. This stops future sign-ins with Google; to delete data we already hold, request deletion as above.
- Emails from us: you can stop non-essential emails at any time by replying “unsubscribe” or using your mail app’s unsubscribe button. We will still send emails about your account and safety.
Depending on where you live (for example, under Japan’s Act on the Protection of Personal Information, the EU/UK GDPR, or California law), you may have additional rights, such as withdrawing consent, objecting to or restricting processing, data portability, or complaining to a data-protection authority. Where we rely on consent, for example for your match preference, you can withdraw it at any time. We will respond to requests within 30 days.
8. Age requirement
Deeply is only for people aged 20 or older. We do not knowingly collect personal information from anyone under 20. If we learn that someone under 20 has created an account, we will delete it.
9. Changes to this Policy
We may update this Policy from time to time. We will post the new version on this page and change the “Last updated” date. If the changes are significant, we will notify you by email or in the Service before they take effect.
10. Contact
Questions or requests about this Policy or your data: max@deeply.tokyo.
Operator: susuROBO KK, Japan. Our address and the name of our representative are available on request at the same address.
If this Policy is translated, the English version prevails, except where Japanese law requires otherwise.
プライバシーポリシー
最終更新日:2026年10月3日
本プライバシーポリシーは、deeply.tokyo(以下「Deeply」または「当社」)が、deeply.tokyo および関連ページで提供するサービス(以下「本サービス」)において、個人情報をどのように取得、利用、保管、提供するかを説明するものです。本サービスは日本のsusuROBO株式会社が運営しています。本サービスを利用することで、本ポリシーおよび利用規約に同意したものとみなされます。
1. 取得する情報
アカウント情報
- メールアドレスでの登録:メールアドレスとパスワード。パスワードは Google Cloud Identity Platform が管理し、当社が平文で閲覧・保存することはありません。
- Googleでのログイン:第2条をご覧ください。
- メールアドレスの確認状況、ログイン方法、アカウント作成日時。
ご本人が入力するプロフィール情報
- ビジター(旅行者)とホスト(地元の方)のどちらで登録するか、名前(ファーストネーム)、性別。
- マッチングを希望する相手(女性・男性・どちらでも)。
- ビジター:訪問予定の都市、旅行日程、出発国、日本語レベル、その他の使用言語、選択または入力した興味・ジャンル。
- ホスト:お住まいの都市、詳しいエリア、案内できるジャンル、使用言語。
- プロフィール設定:生年月日、出身国、身長、職業、自己紹介。
本人確認・年齢確認
Deeplyを利用できるのは20歳以上の方のみで、他の会員に「いいね」やメッセージを送る前に、全員が本人確認と年齢確認を受ける必要があります。確認は本人確認事業者のDidit(Didit Inc.、データは欧州連合で処理)が行います。本人確認書類と顔写真はご本人からDiditに直接提出され、Diditが書類を読み取り、顔写真と書類の写真を照合します(生体検知・顔照合)。当社が受け取るのは確認結果、生年月日、書類の種類と発行国のみで、本人確認書類や顔写真の画像、生体情報を受け取ったり保存したりすることはありません。
メッセージ・レビュー・通報
マッチング機能の提供開始後:送受信した「いいね」、会員間のメッセージ、投稿または受け取ったレビュー、ご本人による通報およびご本人に関する通報。
技術情報・利用状況
- アクセス元リンクのマーケティング用パラメータ(UTMタグ、Google・Metaの広告クリックID)、参照元のウェブサイトやAIアシスタント、最初に開いたページ、ブラウザの言語設定。どの経路から利用者が訪れているかを把握するために使用します。
- IPアドレス、ブラウザの種類、アクセス日時を含むサーバーログ。セキュリティと不具合調査のために使用し、最長30日間保管します。
- ログイン状態を保持するためのブラウザ内ストレージ(第6条参照)。
2. Googleから受け取る情報
Googleでログインを選択した場合、ご本人の許可のもと、Googleから以下の情報を受け取ります。
| スコープ | 情報 | 利用目的 |
| openid | Googleアカウントの固有ID | GoogleアカウントとDeeplyアカウントを紐付け、ログインするため。 |
| email | メールアドレスと確認状況 | アカウントの識別、ログイン、アカウントや本サービスの重要な変更に関するご連絡のため。 |
| profile | 名前とプロフィール画像 | 名前が未入力の場合の補完と、本サービスの表示を個人に合わせるため。 |
Gmail、Googleドライブ、連絡先、カレンダーなど、その他のGoogleデータへのアクセスは求めず、Googleのパスワードを受け取ることもありません。
限定的な使用(Limited Use):Google APIから受け取った情報の当社による使用および移転は、Limited Use要件を含むGoogle API Services User Data Policyに従います。具体的には、当社は以下を遵守します。
- Googleユーザーデータは、上記の本サービスの機能の提供および改善にのみ使用します。
- Googleユーザーデータを販売せず、パーソナライズ広告やリターゲティング広告を含む広告目的で使用・移転しません。
- Googleユーザーデータを汎用的なAI・機械学習モデルの開発、改善、学習に使用しません。
- ご本人の許可がある場合、セキュリティや法令遵守のために必要な場合、または集計・匿名化して社内で利用する場合を除き、Googleユーザーデータを人が閲覧することはありません。
3. 利用目的
- アカウントの作成・管理およびログインのため。
- 都市、日程、ジャンル、言語、マッチング希望に基づき、ビジターとホストのマッチング候補を提案するため。
- 本人確認・年齢確認、会員の安全確保、通報への対応、ならびに不正利用・迷惑行為・客引き行為の防止のため。
- アカウント、旅行、本サービスの重要な変更についてご連絡するため。
- 利用者がDeeplyを知った経路や利用状況を統計的に把握し、本サービスを改善するため(当社自身のマーケティング施策の効果測定を含みます)。
- 法令上の義務を履行するため。
性別とマッチング希望はマッチングのためにのみ使用します。マッチング希望は私生活に関わる情報を示す可能性があるため、当社はこれを機微な情報として扱い、公開せず、広告には一切使用しません。いつでも変更・削除できます。
当社が個人情報を販売することはありません。
4. 第三者への提供
他の会員への表示
マッチング機能の提供開始後、マッチング対象となる会員には、プロフィールの一部(名前、プロフィール写真、性別、年齢、身長、出身国、職業、自己紹介、都市、言語、日本語レベル、ジャンル・興味、ホストの場合は詳しいエリア)が表示されます。ビジターの旅行日程は、同じ都市のホストに表示されます。年齢は生年月日から算出して表示し、生年月日、メールアドレス、本人確認書類、マッチング希望、出発国が他の会員に表示されることはありません。
業務委託先
本サービスの運営のため、利用を制限する契約のもとで、以下の委託先に情報の取扱いを委託しています。
| 委託先 | 目的 | 対象となる情報 |
| Google Cloud(Identity Platform、Cloud Run、Cloud Functions、Cloud SQL) | ログイン、ホスティング、データベース | 上記のすべての情報 |
| Didit(本人確認、EU) | 本人確認・年齢確認 | 本人確認書類、顔写真、生年月日 |
| Zoho Mail | メールの送受信 | メールアドレス、当社宛てのメッセージ |
| Google Fonts、jsDelivr | フォントとログイン用ライブラリの配信 | IPアドレス、ブラウザ情報 |
Googleでのログインにより受け取ったGoogleユーザーデータは、ログインに必要な範囲でGoogle Cloud Identity Platformおよび当社のデータベースとのみ共有します。
このほか、法令に基づく場合、会員その他の方の権利・安全・財産を保護するために必要な場合(例:緊急時や、会員同士の待ち合わせに関する警察からの照会への対応)、または合併・買収・事業譲渡に伴う場合に情報を開示することがあります。事業譲渡の場合も、本ポリシーは引き続き適用されます。
5. 保管・安全管理・保存期間
データはGoogle Cloudの日本(東京リージョン)に保管されます。上記の委託先の一部は米国を含む他国でデータを取り扱うことがあり、その場合は各社の契約上の保護措置に依拠します。データは通信時(HTTPS/TLS)および保管時に暗号化され、アクセスは本サービスの運営に必要な担当者に限定しています。
アカウントとプロフィールの情報は、アカウントが有効な間保管します。アカウントを削除した場合、30日以内に個人情報を削除または匿名化します。ただし、法令上の義務の履行、紛争の解決、またはアカウント削除の原因となった本人確認結果・通報記録の保持のために必要な場合は、より長く保管することがあります。集計・匿名化した統計情報は無期限に保管することがあります。
6. Cookie等の利用
当社は、ログイン状態の保持に必要なブラウザ内ストレージを使用しています。現在、分析用・広告用のCookieは使用していません。今後導入する場合は、本ポリシーを更新し、法令上必要な場合は同意を取得します。ブラウザの設定からストレージを削除できますが、その場合はログアウトされます。
7. 安全管理措置
当社は、個人情報保護法に基づき、以下の安全管理措置を講じています。
- 基本方針の策定:個人データの適正な取扱いのため、本ポリシーを定め公表しています。
- 組織的安全管理措置:個人データの取扱責任者を定め、法令違反や漏えい等を把握した場合の報告・対応体制を整備しています。
- 人的安全管理措置:個人データを取り扱う担当者に対し、秘密保持と適正な取扱いについて周知しています。
- 物理的安全管理措置:個人データは物理的な安全対策が講じられたGoogle Cloudのデータセンターに保管し、端末の紛失・盗難に備えた対策を行っています。
- 技術的安全管理措置:アクセス権限を必要最小限に制限し、多要素認証、通信・保管時の暗号化、アクセスログの記録を行っています。
- 外的環境の把握:個人データは主に日本で保管しています。米国の委託先で取り扱われる場合は、米国の個人情報保護制度を把握したうえで安全管理措置を講じています。
8. 開示等の請求
ご本人は、保有個人データの利用目的の通知、開示(第三者提供記録の開示を含みます)、訂正・追加・削除、利用停止・消去・第三者提供の停止を請求できます。アカウントのメールアドレスから max@deeply.tokyo までご連絡ください。ご本人確認のうえ、30日以内に対応します。同意に基づく取扱い(マッチング希望など)については、いつでも同意を撤回できます。
Googleアカウントの連携は myaccount.google.com/permissions からいつでも解除できます。解除後も当社が保有するデータの削除をご希望の場合は、上記のとおりご請求ください。
EU・英国にお住まいの方はGDPRに基づく権利(データポータビリティ、異議申立て、監督機関への苦情申立て等)を、米国カリフォルニア州にお住まいの方は同州法に基づく権利を有する場合があります。
9. 年齢制限
Deeplyは20歳以上の方のみご利用いただけます。20歳未満の方の個人情報を意図的に取得することはありません。20歳未満の方のアカウントが判明した場合は削除します。
10. 外部送信について
本サービスでは、電気通信事業法に基づき、以下のとおり利用者の端末から外部へ情報を送信しています。
| 送信先 | 送信される情報 | 目的 |
| Google LLC(Google Fonts:fonts.googleapis.com、fonts.gstatic.com) | IPアドレス、ブラウザ情報、参照元ページ | ウェブフォントの表示 |
| jsDelivr(cdn.jsdelivr.net) | IPアドレス、ブラウザ情報 | ログイン用ライブラリの配信 |
| Google LLC(Identity Platform:identitytoolkit.googleapis.com、securetoken.googleapis.com、deeply-510520.firebaseapp.com) | メールアドレス、認証情報、IPアドレス、ブラウザ情報 | アカウント登録・ログイン |
11. 本ポリシーの変更
当社は本ポリシーを随時改定することがあります。改定後の内容は本ページに掲載し、「最終更新日」を更新します。重要な変更の場合は、効力発生前にメールまたは本サービス上でお知らせします。
12. お問い合わせ
本ポリシーや個人情報の取扱いに関するお問い合わせ:max@deeply.tokyo
運営者:susuROBO株式会社(日本)。所在地および代表者の氏名は、上記宛てにご請求いただければ遅滞なく回答します。
本ポリシーの日本語版と英語版の内容に相違がある場合は英語版が優先します。ただし、日本の法令により日本語版が優先される場合はこの限りではありません。