1. Controller and scope
JKRSP LTD is the controller for personal data described in this policy. This policy covers the public Hiraku website, Better Auth account and session operations, transactional email and the early-access waiting list. It does not describe future child-device services that are not commercially available.
The company number, registered office, place of registration and public privacy contact are shown above.
2. Public website and infrastructure
The static site is delivered through Amazon Web Services (AWS) S3 and CloudFront. Those services necessarily receive ordinary request data such as IP address, request time, requested path, browser/network headers and security signals to deliver and protect the site. Hiraku does not currently enable persistent CloudFront access logging for the public static site.
Authenticated API requests run through AWS API Gateway and Lambda. Operational application logs are retained in AWS CloudWatch for 30 days. Logs are used for availability, security and fault investigation, not advertising.
3. Plausible analytics
On production public pages, Hiraku uses Plausible Analytics to understand aggregate traffic and a small conversion funnel. The configured Plausible script does not set analytics cookies, use local storage, create persistent cross-day identifiers or provide advertising profiles. It records page path, referrer and supported campaign parameters, browser/operating-system/device categories and approximate location derived from the request IP. Plausible says the raw IP and full user agent are not stored and its daily measurement identifier is rotated.
Hiraku sends only the documented events and coarse properties such as locale and CTA placement. We deliberately do not send email, account or device identifiers, child information, school, authentication tokens or identity-bearing URL parameters. Plausible is disabled in local development unless explicitly enabled.
This description explains the present configuration; it is not a blanket claim that every analytics setup is exempt from consent requirements. JKRSP LTD keeps the UK/EU e-privacy assessment and Plausible contract/DPA position under review.
4. Account and waiting-list data
To create and secure an account, Better Auth stores the email address, a one-way password hash, email-verification status, account timestamps, sessions and related operational security data in Hiraku’s Postgres database hosted by Neon. Hiraku supplies the same neutral display name for every waiting-list account and does not ask for a personal name.
After a verified sign-in, Hiraku stores a waiting-list record containing the Better Auth user ID, selected market/locale and join time. The waiting-list table does not duplicate the email address. Hiraku does not ask for a child’s name, school, date of birth, precise location, phone model or other child data.
5. Email
AWS Simple Email Service (SES) sends verification and password-reset messages from accounts@hiraku.mobile. It also processes limited operational notifications needed to run the early-access flow. Email delivery metadata may be processed by AWS for delivery, security, bounce and complaint handling.
We may send the relevant waiting-list update that you requested by joining. Unrelated promotional campaigns will require a separately reviewed lawful route and, where required, consent; none are part of the present flow.
6. Purposes and legal bases
We process account, verification and waiting-list data to take the steps you request when joining and to provide the waiting-list service (contract or steps before a possible contract, where applicable). We process proportionate security, availability and abuse-prevention data for our legitimate interests in operating a safe service and protecting users and JKRSP LTD.
We use aggregate Plausible measurement for the legitimate interest of understanding and improving the public site, subject to the separate e-privacy assessment noted above. Where law requires consent for a particular communication or technology, legitimate interests will not replace that consent.
7. Retention
Account and waiting-list data is kept while the waiting list is active or until you ask for deletion. If JKRSP LTD closes the programme, waiting-list membership and unused account data will be deleted within 12 months unless a limited record is reasonably needed for legal, security or dispute purposes. Better Auth verification and session records follow their configured operational lifetimes.
AWS CloudWatch application logs are configured for 30 days. Plausible aggregate analytics retention follows the Plausible account configuration, which must be recorded during the vendor review.
8. Sharing, processors and international processing
Data is shared only as needed with infrastructure and service providers: AWS for hosting, API operation, logs and transactional email; Neon for Postgres hosting; and Plausible for public-site analytics. Better Auth is software running within Hiraku’s API and database, not a separate hosted identity provider in this setup.
Hiraku’s AWS application components are configured in the London region, with CloudFront providing global delivery. Neon and Plausible may process data outside your country; JKRSP LTD reviews provider regions, subprocessors, DPAs and transfer safeguards as account settings and services change. Plausible states that website visitor analytics are processed and stored in the EU.
9. Children and profiling
The waiting-list account is intended for a parent or other adult decision-maker. Hiraku does not perform child behavioural tracking, read child messages or content, build advertising profiles, use session replay, or send child/device activity to Plausible. The age and parental-consent position for any future child-facing service requires a separate review before that service exists.
10. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent where consent is used, and complain to a data-protection authority. These rights can be subject to legal limits.
Send privacy or account-deletion requests to the legal/privacy contact shown above. We may need to verify your identity before acting on a request.
11. Updates
We will update this policy when the service, providers or legal assessment changes. The page will show the effective date, and material changes affecting account holders will be communicated where appropriate.
Processor information
Plausible visitor-data policy · AWS privacy information · Neon privacy policy