lacks analytics Privacy Policy
Last updated: 2026-08-03
This Privacy Policy sets out how information is collected, used, and managed in lacks analytics (hereinafter "this service"), a social media analytics tool provided by lacks japan Co., Ltd.
1. Information We Collect
This service collects the information necessary for social media management agency operations within the scope set out below. Information is obtained through the official APIs of social media platforms (Instagram / TikTok / YouTube / Threads), direct input from users, and other lawful data sources.
- Email address and authentication credentials entered when registering to use this service
- Access tokens and refresh tokens of each platform obtained via OAuth connection (stored encrypted on the server side)
- Profile information of connected social media accounts (username, profile image, follower count, etc.)
- Post metadata (caption, thumbnail, body text, publication date and time, video file URL, etc.)
- Insights information (reach, impressions, likes, comments, view count, follower attributes, etc.)
- Instagram direct message (DM) conversation metadata and message bodies (obtained with the instagram_business_manage_messages scope in order to carry out reply operations within the official 24-hour response window and to generate AI reply drafts)
- Instagram and YouTube comment bodies, comment author usernames, and comment reply history (obtained for comment management and AI reply generation)
- Reply bodies, replier usernames, and mention bodies on Threads posts (obtained via the official Threads API and webhook notifications for reply moderation and mention review)
- Data entered by users within this service (scheduled posts, draft posts, comment templates, team member information)
2. Purposes of Use
The information obtained is used only for the following purposes.
- Providing the SaaS features of this service (dashboard analytics, post planning, post publishing, comment management, and DM replies)
- Supporting social media management agency operations and creating performance reports
- Statistical analysis for service improvement (in a form that cannot identify individuals)
- Detection of unauthorized use and support response
- Compliance with legal obligations (tax, accounting, regulatory compliance)
We do not use personal information for the purpose of advertising delivery or sale to third parties.
3. Provision to Third Parties
Each of the following service providers maintains security standards equivalent to or exceeding industry standards, and exchanges only the minimum data necessary to provide this service. We do not provide information to third parties for advertising or marketing purposes.
- Meta Platforms, Inc. (Instagram / Threads API integration)
- TikTok Pte. Ltd. (TikTok Display / Content Posting API integration)
- Google LLC (YouTube Data API integration / generative AI integration)
- Supabase, Inc. (database and authentication infrastructure, Tokyo region)
- Vercel Inc. (web application hosting / CDN)
If we add or change any provider other than the above, we will update this policy and notify users. Where the addition of a provider has a material effect on the rights and obligations of users, we will provide an opportunity for prior notice.
4. Retention Period
The retention period for information is determined as follows, in accordance with the API specifications of the source, business necessity, and the user contract period. Data that has passed its prescribed retention period is automatically deleted.
- OAuth tokens: deleted upon disconnection or termination of the contract
- Instagram / Threads / TikTok Insights data (analytics data such as reach, impressions, and engagement): retained during the contract period (for year-over-year comparison, long-term trend analysis, and strategic decision-making support), deleted within 30 days after termination of the contract
- YouTube-related data (cached caption text, thumbnails, metadata, etc.): up to 30 days from acquisition (short-term cache based on the YouTube Developer Policy)
- Post metadata and profile information: retained during the contract period, deleted within 30 days after termination of the contract
- Daily snapshots: retained during the contract period, deleted within 30 days after termination of the contract
- Data entered by users (scheduled posts, comment templates, etc.): retained during the contract period, deleted within 30 days after termination of the contract
- Backups: physically deleted in turn in accordance with the backup rotation cycle (up to 90 days)
- Instagram / Threads webhook event payloads (including comment bodies and message bodies): up to 30 days from receipt. Automatically deleted after 30 days. Deleted immediately upon receipt of a data deletion request
- Threads reply and mention cache (reply bodies and mention bodies): deleted immediately upon receipt of a data deletion request
5. User Rights
Users have the right to request access to, correction of, deletion of, suspension of processing of, and data portability (export in a standard format) of their own data. Upon completion of identity verification, we will respond as follows.
- Deletion requests: handled in principle within 30 days
- Access and correction requests: handled in principle within 14 days
- Data portability requests (export in a standard format such as CSV): handled in principle within 30 days
For the specific procedure, please see Data Deletion Procedure.
6. Notification in the Event of a Data Breach
In the event of a serious data breach (leakage, loss, or damage of personal information) in this service, we will take the following measures.
- Prompt reporting to the Personal Information Protection Commission (based on the Act on the Protection of Personal Information)
- Prompt notification to affected users (to the registered email address)
- Content of notification: an overview of the breach, the scope of impact, the measures this service will take, and the countermeasures users can take
7. Handling of Minors' Information
This service is a B2B SaaS, and contracting users (social media management agencies) are assumed to be corporate representatives aged 18 or older. This service does not collect personal information directly from minors.
However, insights data obtained through the social media accounts of the client companies that users manage on their behalf may include aggregated values for followers classified as minors by each platform's estimation (for example, the 13-17 age category). Although these are obtained in a statistical form that does not identify individuals, this service handles them under the following policy.
- Aggregated data on minor followers is not used for anything other than the analysis necessary for management agency operations
- It is not used for the purpose of direct targeted advertising or marketing toward minors
- We comply with each social media platform's policy for the protection of minors (Meta's "no access for those under 13", TikTok's "restricted mode for those under 13", YouTube's "Made for Kids", etc.)
- Requests for the deletion of minors' data are handled in the same manner as ordinary deletion requests
8. Cookies and Local Storage
For the purpose of maintaining the logged-in state and saving UI settings, we use httpOnly cookies and the browser's local storage. At present, we do not use third-party cookies for advertising tracking purposes. If we introduce usage analytics tools (such as Google Analytics) for service improvement, we will update this policy and notify users. If cookies are disabled, some features such as maintaining the logged-in state may be restricted.
9. International Data Transfers
The database of this service is stored in Supabase's Tokyo region (ap-northeast-1). Because content delivery passes through Vercel's global CDN, some static assets and request processing may pass through servers outside Japan.
10. About the Use of AI
This service uses third-party generative AI (LLM) services for purposes such as assisting in the generation of draft posts, transcribing video content, calculating content quality scores, and generating reply drafts for comments and DMs. When generating reply drafts, we send to the AI service the body of the comment or DM message concerned and the username of its author or sender. For comment reply drafts, we also send the client company label. This service selects and uses paid plans (such as a paid tier) under which data sent via the API is not used by the AI service provider for the purpose of training generative AI models. The provider of this service (lacks japan Co., Ltd.) also does not use this data to train AI models.
The AI service providers currently in use are as described in "3. Provision to Third Parties". The AI services used may change in the future in line with technological progress, in which case we will update this policy and notify users.
Generated results may contain inaccurate content (so-called hallucinations). Before publishing or using generated results, users should verify and edit the content at their own responsibility.
11. About Data Obtained on Behalf of Others
The primary users of this service are social media management agencies, which obtain and process the information of client companies (and their end users such as followers) on their behalf. The agency bears the primary management responsibility in its relationship with end users, and the provider handles data within the scope of the processing entrusted to it by the agency.
The agency bears responsibility for compliance with the Act on the Protection of Personal Information and other related laws and regulations with respect to information obtained from end users.
12. Applicable Laws
This policy complies with Japan's Act on the Protection of Personal Information. Where a user is a resident of the EU, we operate with reference to the intent of the GDPR; where a user is a resident of the State of California, USA, we operate with reference to the intent of data protection laws such as the CCPA.
In addition, we comply with the terms of use and related policies of each connected platform.
- Meta Platform Terms / Meta Developer Policies (Instagram / Threads)
- TikTok Developer Terms of Service / TikTok API Services Terms
- YouTube API Services Terms of Service / YouTube API Services Developer Policies
- Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy)
- Google Gemini API Terms / Generative AI Prohibited Use Policy
13. Contact
For inquiries regarding this policy, please contact us at the following.
- Provider: lacks japan Co., Ltd.
- Representative: Shunya Hamada
- Address: 2-17-27-401 Makishi, Naha City, Okinawa 900-0013, Japan
- Corporate number: 9360001034333
- Contact email: s-hamada@lacks-japan.com