Privacy policy
Effective date: October 1, 2026
Noabase provides tools for working with your images and text. We explain what stays on your device and which actions send information to our servers, and use that information only as needed.
1. Scope and operator
This policy applies to all services provided by Noabase (including those not listed on the Tools page) and to shared features such as login and contact forms. Section 2 describes the information handled by each service. When we add a service, we update Section 2 and the tool list. External websites are governed by their own policies.
Operator: Noabase (operated by an individual)
For questions about personal information, use Send feedback on any page. On mobile service pages, it is in the Site information menu at the top right. If you need a reply, include your contact details, such as an email address, in your message.
The operator's name and address will be disclosed without delay upon request. Please contact us using the method above.
Internal testing pages, such as the thumbnail template generation tool, are outside the scope of this policy. When generation is requested in that tool, the entered text and selected images are sent to OpenAI.
2. Information handled and purposes of use
- Thumbnail editing data
- Entered text, imported images, layouts, and formatting are saved in your browser so you can edit and resume work. Normal editing and export do not upload this work to our servers. Selecting a template sends its identifier to count how often it is used.
- PDF and Character Counter
- PDF loading, editing, and conversion take place in your browser. The PDF files and your input are not sent to our servers for processing. Loaded PDFs, images, and edits are automatically saved in IndexedDB in your browser so you can resume work. Character Counter text, history, and selection state are also saved in your browser for this purpose.
- Scheduling
- Event names, descriptions, locations, map URLs, items to bring, proposed dates and times, invitee names, respondent names, responses, comments, and information managing editing permissions are saved on our servers to share, respond to, and update events. Invitee names and the list of people who have not responded are shown only to the organizer. Proposed dates and times in drafts are also sent for automatic saving. Anyone who knows the shared link can view the event; the visibility of respondent names and comments depends on the organizer's settings. Aggregate results and the number of responses are shown even when individual responses are visible only to the organizer. Keep management links only with those managing the event. If you request an email reminder on the day before an event, we store your email address, consent and verification status, and delivery status. The address is not disclosed to other respondents or the organizer and is used for verification emails and reminders. Reminder registration and delivery are currently unavailable because a sender has not been configured.
- Send feedback
- We save submitted content, report type, service, submission time, and handling status to investigate issues, respond, and improve the services. Do not include personal or confidential information that is unnecessary for responding.
Feedback drafts are saved in the current tab's sessionStorage so they remain available when you change languages or reload the page. They are kept only for that tab's session and deleted after your feedback is submitted successfully.
- Connection and operation information
- When you connect to our services, we handle information needed for communication, such as IP addresses. We may handle information needed to check operation, prevent misuse, and investigate failures. We do not collect your input for advertising.
- Analytics (Google Analytics and Microsoft Clarity)
- We use Google Analytics 4 and Microsoft Clarity to understand how the site is used and improve usability. They collect viewed pages (excluding URL query strings and fragments; individual parts of scheduling event URLs are masked), page titles when opened, referrers, access times, browser and device types, screen size, approximate region, page interactions (clicks, taps, scrolling, and mouse movements), and page appearance. Except on the home and legal pages, all screen text and images are masked in Clarity recordings. Neither service receives your loaded PDFs or images, entered text, or scheduling event details and responses. Clarity is not loaded on scheduling pages. Neither is loaded for visitors from the European Economic Area (EEA), the United Kingdom, or Switzerland. The visitor's country is based on Cloudflare's estimate from the IP address.
- Traffic measurement (Cloudflare Web Analytics)
- Cloudflare Web Analytics, provided by Cloudflare which delivers Noabase pages, measures viewed pages, referrers, access times, browser and device types, and page loading speed. It does not store cookies or other data on your device. Cloudflare injects it while delivering pages, so it loads regardless of region or Global Privacy Control (GPC) settings.
3. Cookies and browser storage
Your Japanese or English language preference is saved in a cookie that expires after one year.
We use cookies and browser storage to remember display settings, resume work, and retain editing permissions. Character Counter settings cookies expire one year after saving. For analytics, Google Analytics uses cookies (_ga and names beginning with _ga_, lasting up to two years). Microsoft Clarity uses cookies (_clck for one year and _clsk for one day) and cookies on Microsoft's domains, such as MUID. Cloudflare Web Analytics does not use cookies. There is no uniform automatic deletion deadline for work and text stored in the browser.
You can delete each service's site data in your browser settings. Doing so may remove saved work, text, settings, and scheduling editing permissions. Save any needed work and management links first. Deleting data on your device does not delete schedules or reports already submitted to our servers.
4. Retention and deletion
Storage periods in the browser depend on the service and type of data. Data with no automatic expiry, such as text in Character Counter, remains until you delete it or your browser clears it.
PDFs opened on task pages such as merge and split expire one hour after their last use and are deleted the next time you open a PDF page. You can delete them immediately using Start over or Choose another file in the notice shown when reopening the previous PDF. Data automatically saved in the PDF editor expires 24 hours after its last use and is deleted the next time you open a PDF page. Clear all deletes it immediately and also deletes the PDF stored for task pages.
Clearing your browser's site data also deletes these records. Storage limits or automatic browser cleanup may prevent saving or restoration, so download files you need. Downloaded files remain on your device.
Scheduling data expires 180 days after its last update. Expired data becomes unavailable and is deleted progressively when the server processes stored data. Organizers can delete events and responses; respondents can delete their own responses while responses are open. Reminder registration can be canceled from the response page or the unsubscribe link in a reminder email. Unverified registrations expire after 24 hours. Verified registrations are deleted when canceled, when the response or event is deleted, or when the event expires. Expired registrations are removed by periodic server processing. Reports currently have no automatic deletion after a set number of days. Request deletion using the contact method in Section 1. If retention is required by law or for a dispute, we will explain why.
5. AI training, third-party disclosure, and external transmission
Selecting Google Calendar, Share on LINE, or Share by email in Scheduling passes event information such as the name, date and time, location, map URL, items to bring, description, and response link to the selected external service or email app. Opening a map link takes you to that service. Before enabling reminder email delivery, we will list the delivery provider and information sent on this page.
We do not use images, text, PDFs, or responses you enter or submit to train AI models. We do not sell this content or use it to select advertising audiences.
We do not disclose personal data to third parties without consent, except where permitted by Japan's Act on the Protection of Personal Information, such as disclosures required by law. Viewing through shared scheduling links is a feature users choose to share information.
For analytics, the information described under Analytics and Traffic measurement in Section 2 is sent to the following providers. They handle the information under their own policies.
- Google LLC (Google Analytics 4; advertising features and Google Signals are disabled): Google privacy policy. To stop transmission, use the Google Analytics Opt-out Browser Add-on.
- Microsoft Corporation (Microsoft Clarity): Microsoft privacy statement
- Cloudflare, Inc. (Cloudflare Web Analytics; no cookies): Cloudflare privacy policy
If you enable Global Privacy Control (GPC) in your browser, Noabase does not load Google Analytics or Microsoft Clarity. The services remain usable if you delete or reject cookies.
To prevent automated bulk submissions, we use Cloudflare Turnstile only when submitting feedback or creating a scheduling event. Information such as your IP address, browser type, connection characteristics, and current page is sent to Cloudflare to verify human interaction. As this is needed to protect submissions, it applies even in the EEA and when GPC is enabled. For details, see the Turnstile privacy addendum.
We do not use advertising or payment tags. Before introducing advertising, login, payments, external processing, or similar features, we will explain the recipients, information sent, purposes, storage and opt-out methods, and obtain consent where required. Task pages that open your images or text do not load advertising scripts.
6. Security
We restrict access to stored information as needed and work to prevent unauthorized access, leaks, and tampering through input validation and permission checks. When outsourcing processing, we check the provider's practices and provide necessary supervision. If a breach occurs, we report it and notify affected parties as required by law.
7. Access, correction, and restriction of use
You may request notice of purposes of use, disclosure, correction, restriction of use, deletion, or cessation of third-party disclosure of your personal data. Contact us using the method in Section 1 and identify the service and data concerned. We verify identity as necessary and respond in accordance with law. If we cannot fulfill a request, we explain why. Do not post passwords or management links publicly.
8. Changes
We update this page when our data handling changes. Important changes are announced on the site before they take effect. Where consent is legally required, we obtain it before making the change.