EmTrip Cocoro Cross (Web) — Privacy Policy
Last updated: September 15, 2026
EmTrip Inc. (“we”) collects and processes personal information for EmTrip Cocoro Cross (Web) (the “Service”) as described below, in accordance with the Act on the Protection of Personal Information (Japan).
1. Information We Collect
- Session identifier: a temporary ID tied to your browser (including in guest mode)
- Account information (signed-in mode only): email address, identifier from authentication provider
- Service usage: chat history with owner AI, store selection, language used, access timestamps, IP address, device/browser info, cookies
- Logs / diagnostics for incident analysis and abuse prevention
- Information carried over from Cocoro Cross on LINE (only if you open the handover link we send you): “conversation memory” created from what you yourself said in your LINE conversations (see “3-4.”)
We do not collect special-category data (race, beliefs, medical history, etc.).
2. Purpose of Use
- Provide the Service (owner AI personalization, multilingual support)
- Conversation-memory personalization (recording part of what you tell us to make future owner AI conversations more natural; see “3-3.”)
- Carrying over conversations from Cocoro Cross on LINE (so that people who talked with an owner's AI on LINE can continue where they left off on the Web; only if you open the link we send you; see “3-4.”)
- Save conversation history (signed-in users only)
- Customer support, incident response, quality improvement, abuse prevention
- New feature announcements and campaigns (you can opt out anytime)
- Compliance, terms enforcement, rights protection
- Anonymized aggregation for next-generation AI research (separate consent for third-party provision)
- Creating and providing reports to partner stores (based on your conversations with that store's Owner AI, so that the store can receive them; see “6.”)
3. Guest Mode Data Handling
- Even in guest mode, conversation logs are stored on our servers (Supabase Asia North-East region) for service quality improvement.
- Guest logs are identified by an anonymous random session ID that cannot identify you personally.
- You cannot list or retrieve past conversation history through the UI. However, to make conversations more natural, the owner AI may internally reference part of your past conversations when replying (see “3-3. Conversation Memory”).
3-2. Return Marker (Anonymous Revisit Measurement)
Cocoro Cross stores an anonymous marker (a random identifier) in your browser so that, when you return from the same device, we can recognize that you came back. The marker is a random code that does not, by itself, identify you. It is used only within our servers and never shared with third parties. We do not use it for advertising tracking. It is simply a marker to honor the relationship that continues after your trip.
- Stored in: our own cookie (cx_did) in your browser. It is issued by our server and stored in a form that browser scripts cannot read (HttpOnly). It lasts up to 400 days so that we can recognize you as the same person across the before/after of your trip (previously it was stored in your browser's localStorage, which in some environments was cleared after about 7 days). It works only on the same device/browser and does not carry over across devices, data clearing, or private browsing.
- Purpose: only to recognize revisits from the same device (service quality and relationship-continuity measurement).
- Third parties: none.
- If you sign in: the marker becomes linked to the same records as your account (e.g., email) and, to that extent, is treated as part of your personal data (account rights follow “9.” below). If you stay a guest, the marker remains anonymous.
- Not retroactive: Web usage before this marker was introduced (past conversations) carries no visitor_id and cannot be linked afterward. Measurement applies only to usage after introduction/rollout. The one exception is the handover from Cocoro Cross on LINE (“3-4.”): if you yourself carry it over, the “conversation memory” created from your past LINE conversations becomes linked to this device's marker. Past conversations on the Web are never linked retroactively.
- Opt out: you can stop it anytime with the button below. Stopping (1) deletes the marker stored on this device, (2) disassociates this device's anonymous marker (visitor_id) on our servers so it is no longer linked to past revisit data, and (3) halts any further measurement on this device. The conversation logs themselves are retained for service quality (anonymous when you are a guest; linked to your account when signed in); their deletion and the exercise of rights over a signed-in account are handled via the channel in “9. Your Rights” below.
International (incl. EU) pre-/post-trip use: The Service may be used from outside Japan. Some jurisdictions (e.g., the EU under ePrivacy rules) require prior consent to store identifiers on a device. We currently address this through the disclosure in this Policy and the opt-out above, and may add a prior-consent mechanism as our regions and scale expand.
3-3. Conversation Memory (Personalization)
To make future conversations more natural, Cocoro Cross may store part of what you tell us in the Service as “memory” and use it in the owner AI's replies. This works whether or not you are signed in (for guests it is linked to the anonymous return marker [visitor_id] above; when signed in, it is linked to your account). For how memory carried over from Cocoro Cross on LINE is handled, see “3-4.”
- What we remember: things you yourself mention in conversation about the shop, the season, or experiences (e.g., a brand you like, a product you tried last time, an upcoming visit).
- What we do not remember: we do not store special-category or sensitive matters such as health, beliefs, politics, religion, or family circumstances. Nor does the AI infer and “guess” things you have not told us.
- How it is used: we use it as a cue to what you yourself said, e.g., “You mentioned ___ before.” Memory that has aged is treated tentatively—by confirming rather than asserting.
- Retention: conversation memory expires automatically 13 months after your last conversation, whether or not you are signed in. If you are signed in, it is also deleted upon withdrawal or your deletion request.
- Stop / delete: stopping the “return marker” above stops new memory from being created on this device and disassociates it from stored memory. Deletion of specific memories or account-linked memory is handled via the channel in “9.” below.
- Third parties: we never provide memory to third parties. Partner shops receive only aggregated, summarized information that does not identify individuals (see “5.”).
3-4. Carrying Over Conversations from Cocoro Cross on LINE
If you have talked with an owner's AI on Cocoro Cross via LINE, we may send you a link on LINE so you can continue where you left off on the Web. The purpose is simply so that you are not treated as a first-time stranger.
- The handover happens only when you open the link. If you do not open it, nothing happens and nothing changes. The link is valid once.
- What is carried over: “conversation memory” created from what you yourself said in your LINE conversations (the same kind as “3-3.” above; e.g., a brand you like, a gift you were looking for). Each memory records the date you actually said it.
- What is not carried over: the LINE conversations themselves (the message text) are not moved to the Web. You cannot read back past exchanges in the Web interface. We also exclude special-category or sensitive matters such as health, beliefs, politics, religion, or family circumstances, as well as anything the AI inferred that you did not tell us.
- Your data on LINE: conversations stored on the LINE side remain as they were. The handover neither deletes nor alters them.
- This is not a third-party disclosure: Cocoro Cross on LINE and on the Web are the same service, and this handover is internal to us. No personal data is provided to any third party outside our company.
- Retention: carried-over memory expires automatically 13 months after your last conversation, as in “3-3.” The 13 months are counted from the date you actually said it, not from the date it was carried over.
- Stop / delete: stopping the “return marker” in “3-2.” also disassociates carried-over memory. If you do not want the handover at all, simply do not open the link. Deletion of memory already carried over is handled via the channel in “9.” below.
- Please do not forward the link: it contains a code used to carry over your memory. If you forward it, the recipient may receive your memory. The link does not contain your LINE user ID.
3-5. Information from Cocoro Cross on LINE (service discontinued)
- Cocoro Cross for LINE has been discontinued. We continue to hold the conversations and related information we received while it was running.
- That information is not subject to joint use with partner stores (Section 6). We do not provide it to partner stores.
- To request disclosure, deletion, or suspension of use for information we hold, please contact us at Section 11.
4. Cookies
We use cookies and similar technologies for stable operation, analytics, and abuse prevention. You can disable cookies in your browser settings, but some features may become unavailable.
5. Third-Party Disclosure
- We do not disclose personal information to third parties without your consent, except as required by law, for emergency protection of life or property, or where the disclosure falls under service operation outsourcing or joint use.
- We may provide a partner store with aggregated or summarized information about your conversations with that store, as well as the content of those conversations themselves. We do this as joint use under Section 6. We do not provide your contact details, your account information, or your conversations with other stores.
6. Outsourcing & Joint Use
- We outsource to cloud providers (Supabase, Vercel), authentication (Google), AI (OpenAI), and payment processors. We require confidentiality contracts and security measures.
- Content sent to OpenAI API is governed by OpenAI's data handling policy and is not used for AI model retraining.
- Bot protection: We use Cloudflare Turnstile to prevent abusive automated access. When you use the Service, technical information about your browser and connection is sent to Cloudflare to determine whether the access is human or automated. This processing is governed by the Cloudflare Turnstile Privacy Addendum. Turnstile does not track your conversation content or use it for advertising.
Joint Use
We jointly use personal data relating to your conversations with a partner store's Owner AI together with that store. In accordance with Article 27, Paragraph 5, Item 3 of Japan's Act on the Protection of Personal Information, we disclose the following.
- Items jointly used: the content of your conversation with that store's Owner AI (your messages and the AI's replies), its date and time, the language used, and aggregated or summarized information derived from that conversation
- Scope of joint users: EmTrip Inc. and the partner stores listed on our website at https://cocorocross.emtrip.io/#partners
- Purpose of use by joint users: for the partner store to respond to inquiries and requests addressed to it, and to maintain and improve the accuracy of what its Owner AI conveys
- Party responsible for management: EmTrip Inc. (1-7-8 Chuo, Okinawa City, Okinawa 904-0004, Japan / Representative Director: Kenichi Yonaguni). See also our Notice Based on the Act on Specified Commercial Transactions
- Not jointly used: your contact details, your account information, and your conversations with other partner stores are excluded
- Conversations subject to joint use: those on or after September 1, 2025. Conversations on Cocoro Cross for LINE (service discontinued) are not included
- Effective date: September 30, 2026. We will not share any conversation content with partner stores before that date
- Partner stores may not use what they receive for any purpose beyond those stated above (including building marketing lists). We impose this by contract with each partner store
- To stop joint use, please contact us at Section 11. When you ask us to stop, we also require the partner store to delete what it received
7. International Transfer
The Service supports inbound tourists and multilingual users. Personal data may be transferred to overseas providers (e.g., OpenAI in the US, Vercel in the US). Information about the destination country's system and provider security will be provided in this policy or in individual consent screens.
8. Security Measures
- Organizational: minimum access privileges, log auditing, vendor management
- Personnel: confidentiality, training, access revocation upon departure
- Technical: encryption, TLS, Supabase Auth-based authentication, Row Level Security for data isolation
9. Your Rights
You may request disclosure, correction, addition, deletion, suspension of use, or suspension of third-party provision of your personal data, including your conversation memory (3-3.) and memory carried over from LINE (3-4.). Contact us via the channel below.
10. Minors
Minors must obtain parental consent to use the Service. We do not provide alcohol-related suggestions to anyone under 20.
11. Contact
- Responsible person: Kenichi Yonaguni
- Email: info@emtrip.io (10:00–17:00 JST, weekdays)
12. Revisions
If we revise this Policy, we will announce it within the Service. Material changes will be notified individually.
Revision of September 15, 2026: we added “Joint Use” with partner stores (Section 6), the corresponding purpose in Section 2, and what we provide in Section 5. We will share conversation content with partner stores only on or after September 30, 2026 (effective date), never before it. You can stop joint use at any time via Section 11.
