Last updated: February 5, 2026
1. Purpose of Processing Personal Information
- Member management: identity verification, service provision, fraud prevention
- Service provision: ledger, OCR, budget management, AI analysis
- Marketing (optional): announcements of new services
2. Personal Information Collected
2.1 Required Items
| Category | Items |
|---|---|
| Registration | Email, password, name |
| Service use | Access logs, IP, device information |
2.2 Financial Information (separate consent)
- Income/expense records
- Receipt images and OCR-extracted data
- Budget settings
- Asset information (optional)
All financial information is stored encrypted with AES-256.
3. Retention and Destruction
| Category | Period | Basis |
|---|---|---|
| Member information | Until withdrawal | Service provision |
| Financial transaction records | 5 years | Electronic Financial Transactions Act |
| Access logs | 3 months | Protection of Communications Secrets Act |
4. Provision to Third Parties
In principle, we do not provide information without consent. Exceptions:
- Prior user consent
- Requests under applicable laws
5. Security Measures
- Encryption: financial information encrypted with AES-256
- Access control: principle of least privilege
- Security systems: firewall and IDS operation
6. Rights of Data Subjects
- Request to access personal information
- Request to correct errors
- Request for deletion
- Request to suspend processing
7. Personal Information Protection Officer
Email: privacy@starium.site
8. Changes to This Policy
Changes will be announced 7 days in advance.
Supplementary Provisions
This policy takes effect on February 5, 2026.