Privacy Policy
Last Updated: October 4, 2026
Article 1 (Basic Policy and Scope)
This English version of the Privacy Policy is an official translation provided for convenience, and in the event of any conflict or inconsistency between the Japanese version and the English version, the Japanese version shall prevail. Velpha Inc. (the "Company") handles all user data collected through "Velpha" (including pre-registration, associated websites, and applications, whether preview or official release; collectively, the "Service") in strict compliance with the Act on the Protection of Personal Information of Japan (the "APPI"), related ministerial guidelines, and this Privacy Policy (this "Policy"). The statutory terms "personal information," "personal data," and "retained personal data" used herein shall have the meanings ascribed to them under the APPI.
Article 2 (Categories of Information Collected)
The Company collects the following categories of information depending on the user's utilization of the Service: 1. Pre-Registration Data Email address, confirmation timestamp, assigned registration number, referral sources and milestone counts, optional questionnaire responses (investment experience, brokerages used, asset management challenges), responses and output of the Investing Habits Quiz, referring URL/UTM parameters, and cryptographic session tokens used to maintain registration state. 2. Account and Financial Portfolio Data Email address, user identifiers, profile attributes, authentication credentials, country of residence, birth year, investment objectives, investment horizon, risk tolerance metrics, liquid asset allocation, cash reserve thresholds, target accumulation amounts, detailed security holdings (tickers/codes, quantities, acquisition cost basis), transaction histories, simulation scenarios, and configuration settings. This includes information entered directly or retrieved via user-authorized external API synchronizations. 3. AI Feature Interaction Data User prompts submitted to AI assistants, UI contextual state sent with prompts, AI-generated analytical responses, dialogue histories, and usage metrics. Prior to transmission and persistent storage, personal identifiers (email addresses, phone numbers) and sensitive financial digits (brokerage account numbers) are subject to automated data masking. 4. Environmental and Telemetry Logs IP addresses, cookie identifiers, access timestamps, visited URLs, referring endpoints, device hardware specifications, operating systems, browser versions, interaction events, error reports, and latency telemetry. Distinct handling of voluntary behavioral analytics versus essential diagnostic logging is governed by Articles 4 and 8. 5. Customer Support Communications Feedback submissions, inquiry contents, email contact points, and attachments. Users are instructed never to transmit login passwords, verification codes, or financial institution credentials. 6. Diagnostic Assessment Data Responses to and results of the Investing Habits Quiz and ephemeral browser cookie identifiers, processed independently of whether the user pre-registers. Assessment data is handled separately from direct personal identifiers.
Article 3 (Purposes of Use)
The Company processes collected information within the scope necessary to achieve the following purposes: (1) Administering pre-registration, verification, release updates, digital Launch Pass issuance, referral tracking, community milestone rewards, assessment-driven onboarding, and anonymous distribution statistics; (2) Managing user account registration, identity authentication, login sessions, and account preference persistence; (3) Recording financial holdings and transactions, conducting asset allocation and P&L analysis, executing portfolio simulations, and synchronizing with authorized third-party calendars; (4) Generating contextual AI analytical responses, maintaining conversation threads, and monitoring usage quotas; (5) Delivering customer support, investigating and resolving technical failures, preventing fraudulent or abusive activity, maintaining information security, and ensuring platform reliability; (6) Conducting statistical research and behavioral telemetry pursuant to user consent under Article 4 to enhance algorithmic accuracy and UI/UX design; and (7) Ensuring compliance with statutory obligations, protecting proprietary rights, and resolving legal disputes. Any material alteration of the purposes of use will remain within a reasonably related scope, with advance notification or publication on the Service.
Article 4 (Service Improvement Analytics and Opt-Out Mechanism)
1. Overview Participation in behavioral telemetry and data analytics intended for service enhancement ("Analytics") is entirely voluntary. Although active by default in the current application, users may exercise their right to opt out at any time. A saved opt-out preference remains permanently effective across future updates. 2. Procedure for Adjusting Settings Users may opt out by navigating to "Settings" → "Personalization" → "Data Use" in the application, toggling "Analytics" off, and selecting "Save Preferences." Toggling the switch alone without confirming save does not commit the preference. Users may re-enable analytics at any time via the same interface. 3. Scope of Analytics Halted This setting governs behavioral tracking via Google Analytics within the authenticated application. Upon saving the off setting, the screen reloads and further telemetry for subsequent sessions is terminated. If the user accesses the application across multiple browser tabs or devices, reloading those interfaces applies the opt-out preference. 4. Essential Processing Maintained Opting out of Analytics does not impair core platform capabilities (asset recording, portfolio simulations, AI interactions). Core functional processing—including risk analysis derived from portfolio inputs, authentication, security controls, statutory compliance records, and infrastructure error and latency monitoring via Datadog—continues as essential operational processing (see Article 8 for technical specifications). 5. Treatment of Historical Records Opting out does not retroactively expunge historical aggregated metrics or anonymized telemetry. Requests for deletion of retained personal data should be directed to the contact desk in Article 7. Fully aggregated, non-personally identifiable statistics may continue to be utilized. This setting operates independently from pre-registration notices and external calendar integrations. To unsubscribe from announcements, contact contact@velpha.ai from the registered address. 6. Public Website Measurement Policy On public pages (pre-registration, quiz, legal pages), Google Analytics measurement is enabled by default. Scripts do not load when the browser has a saved off choice. You can enable or disable measurement from "Cookie Settings" in the footer. The choice is stored in a cookie for 180 days per browser and domain; after it expires, the default applies again. Authenticated in-app Analytics preferences are managed separately. Public-page settings never turn a saved off in-app preference on.
Article 5 (Subcontracting, Provision to Third Parties, and User Sharing)
1. Subcontracting The Company may subcontract operational functions—including user authentication, cloud infrastructure hosting, database management, transactional email delivery, performance monitoring, and AI inference processing—to specialized third-party service providers. Subcontractors are selected based on strict information security standards and subjected to ongoing contractual oversight. 2. Restrictions on Third-Party Provision The Company will not disclose or provide personal data to third parties without prior user consent, except as permitted under the APPI or other applicable statutes. Transfers of personal data to foreign entities are executed in accordance with statutory requirements, ensuring adequate contractual safeguards and equivalent protective measures. Current foreign vendors and processing locations are set forth in Article 6. 3. External Integrations Where a user explicitly authorizes integration with third-party tools (such as Google Calendar), relevant parameters are transmitted within the approved scope. Integrations may be disconnected at any time via application settings or the external provider's permission portal. 4. Public Information Sharing Registration numbers, Launch Pass graphics, milestone badges, and referral URLs published by users via social media sharing functions enter the public domain. Referrers receive aggregated referral counts; individual identities or email addresses of referred parties are never revealed. Users must never disclose authentication links or tokens publicly.
Article 6 (Security Control Measures, Cross-Border Data Processing, and Retention Period)
1. Security Control Measures The Company enforces comprehensive organizational, personnel, physical, and technical safeguards to prevent unauthorized access, leakage, loss, or damage to personal data, including granular role-based access controls, TLS/SSL transport encryption, encrypted storage at rest, continuous audit logging, and regular employee compliance training. 2. Cross-Border Processing and Subcontractors Personal data is primarily hosted within domestic data centers (Amazon Web Services Tokyo Region). However, to deliver resilient, high-grade functionality, the Company utilizes cloud services provided by entities located in the United States, whereby certain processing occurs on servers outside Japan: • Authentication & Account Management: Clerk, Inc. (USA) • Frontend Content Delivery: Vercel Inc. (USA) • Transactional Email Delivery: Resend, Inc. (USA) • Bot Mitigation & DDoS Protection: Cloudflare, Inc. (USA) • Observability & Performance Monitoring: Datadog, Inc. (USA) • Behavioral Usage Analytics: Google LLC (USA) • AI Inference Infrastructure: Amazon Web Services, Inc. (Amazon Bedrock) For AI features, input prompts, prior conversational context, and necessary financial parameters (tickers, risk-return statistics) are processed via Amazon Bedrock. Processing regions are assigned dynamically based on computational load and cannot be designated to a single jurisdiction in advance; however, user data is contractually excluded from model re-training. The Company confirms data protection regimes and executes appropriate data transfer agreements. 3. Retention Period and Account Erasure The Company retains personal data only for the duration required to fulfill specified purposes. Upon account deletion, registered assets, transaction histories, preferences, and AI conversation logs are permanently and irreversibly purged from production databases. In-app AI logs remain stored until individual deletion by the user or overall account termination. Authorized personnel may access dialogue records solely to resolve reported defects, investigate security anomalies, or address formal inquiries. Following account or pre-registration termination, limited records may be retained to satisfy statutory obligations, enforce fraud prevention, or address disputes. Residual backup archives are overwritten in standard operational cycles. Expired records are securely destroyed or converted into irreversibly anonymized statistical aggregates.
Article 7 (Procedures for Requests for Disclosure, Correction, Suspension of Use, etc.)
Pursuant to the APPI, users hold the right to request disclosure, correction, addition, deletion, suspension of use, erasure, or cessation of third-party provision regarding their retained personal data and third-party transfer records. Requests may be submitted to contact@velpha.ai and will be processed without undue delay following statutory identity verification. Where legal exceptions apply, the Company will promptly communicate the rationale. In-app analytics preferences can be adjusted directly pursuant to Article 4. AI interaction threads can be removed individually within the conversation interface, and account deletion may be initiated under "Settings" → "Account." For pre-registration cancellation or email unsubscription, please contact the support desk from the registered address.
Article 8 (Use of Cookies and Statutory Disclosures on External Data Transmission)
The Service deploys cookies and similar technologies for session integrity, usability enhancement, security validation, and telemetry. Responses and results of the Investing Habits Quiz are stored in local browser cache for persistence and synchronized with a browser cookie identifier on the server to aggregate overall distribution statistics. These records exclude direct identifiers such as names or email addresses, linking to an email address only if saved concurrently with pre-registration or completed in an authenticated session. In accordance with the Telecommunications Business Act of Japan (External Transmission Regulations), disclosures regarding external service integrations (tags/SDKs) are specified below. Disabling cookies via browser settings may restrict authentication and core features.
Clerk | Authentication & Identity Management
Recipient: Clerk, Inc. Transmitted Data: Account identifiers (email address), session tokens, IP address, device and browser attributes. Purpose: User authentication, session management, identity verification, anti-hijacking controls. Classification: Essential infrastructure for service operation (exempt from voluntary Analytics opt-out).
Cloudflare Turnstile | Fraud Prevention & Bot Mitigation
Recipient: Cloudflare, Inc. Transmitted Data: IP address, browser/device telemetry, interaction timestamps, page verification parameters. Purpose: Prevention of automated bot attacks, spam submissions, and credential abuse. Classification: Operates on public registration and inquiry forms (exempt from voluntary Analytics opt-out).
Datadog RUM | Application Performance & Error Monitoring
Recipient: Datadog, Inc. Transmitted Data: Visited URLs (query parameters and fragment identifiers stripped), session identifiers, browser/device metrics, error stacks, rendering latency. Session replay is explicitly disabled on sensitive pages (pre-registration, quiz, legal, authentication). Purpose: Real-time detection and resolution of platform crashes, latency bottlenecks, and stability maintenance. Classification: Essential diagnostic infrastructure (continues regardless of voluntary Analytics opt-out).
Google Analytics / Google Tag Manager | Behavioral Usage Analytics
Recipient: Google LLC Transmitted Data: Cookie identifiers, accessed paths, page flow sequences, referring domain origins, client device parameters, pseudonymized internal analytics tokens. Direct personal identifiers, financial balances, and raw quiz answers are never transmitted. Purpose: Aggregated traffic analysis, UI/UX optimization, and feature engagement evaluation. Classification: Public-page measurement is enabled by default and stops when the browser has a saved off choice. You can change it in the footer's "Cookie Settings"; the choice is stored in a cookie for 180 days. Authenticated in-app measurement requires a saved on Analytics preference, which public-page settings never change (see Article 4 for opt-out instructions).
Modifications to external recipients or transmitted categories will be reflected in periodic updates to this Policy.
Article 9 (Business Operator Information, Inquiries, and Policy Amendments)
Personal Information Handling Business Operator: Velpha Inc. Head Office: 1-12-4 Ginza, Chuo-ku, Tokyo 104-0061, Japan Representative Director: Shusuke Takamizawa Contact Desk: contact@velpha.ai The Company reserves the right to amend this Policy in response to statutory revisions, technological developments, or operational requirements. Amended versions will be published on the Service with an updated effective date. Material alterations will be communicated via email or prominent on-site notice. Amendments to this Policy will not automatically revert an active analytics opt-out preference.