Etymon Privacy Policy

Effective Date: 1st June, 2026
Last Updated: 18th August, 2026

Glyph Inc. ("Company," "we," "us," or "our") establishes this Privacy Policy ("Policy") to explain how we collect, use, store, share, and protect user information in connection with "Etymon" and related websites, applications, APIs, verification pages, and other related services collectively referred to as the "Service."

Etymon is a service designed to help users create verifiable records for digital files and other digital content, including records relating to existence at a specific point in time, registration history, integrity, and related verification data. The Service does not guarantee the truthfulness, legality, copyright ownership, or other rights status of any registered content.

This Policy explains the types of information we collect, the purposes for which we use such information, how we share information, the rights and choices available to users, and the security measures we take.


1. Information We Collect

We may collect the following types of information in connection with the Service.

1.1 Information You Provide to Us

We may collect information that you provide when you create an account, log in, contact us, subscribe to a plan, change settings, request support, or otherwise use the Service.

This may include:

1.2 Information Automatically Collected Through Use of the Service

When you use the Service, we may automatically collect certain information, including:

We use this information to provide the Service, ensure security, prevent misuse, respond to errors and incidents, improve the Service, and analyze usage.

In connection with files and other digital content registered by users, the Service may collect, generate, and store information including:

We do not store registered files themselves on a public blockchain. However, hash values, ledger records, anchor information, and other data required for verification may be recorded in a tamper-resistant manner.

1.4 Payment and Subscription Information

If we provide paid plans, subscriptions, or other paid features, we may collect or process information including:

We may use Stripe or other payment processors to process payments. As a general rule, detailed payment method information such as credit card numbers is collected and managed directly by the payment processor, and we do not directly store such information. However, we may receive and store information necessary to provide the Service, such as payment status, billing history, and plan information.

1.5 Information Obtained Through Third-Party Service Integrations

If you log in using an external service account or connect the Service with a third-party service, we may receive information provided by that external service.

This may include:

We use this information to provide login functionality, verify identity, manage accounts, provide integration features, and ensure security.


2. Purposes of Use

We use collected information for the following purposes:

  1. To provide, operate, maintain, and improve the Service
  2. To register accounts, verify identity, authenticate logins, and manage accounts
  3. To create and provide verification records, ledger records, receipts, certificates, and verification pages for registered files
  4. To enable third parties to verify registered files or verification records
  5. To create separately encrypted Publications and apply recipient, permission, expiration, password, attribution, and revocation settings
  6. To provide support, respond to inquiries, verify identity, and send important notices
  7. To detect, prevent, investigate, and respond to violations of terms, unauthorized access, fraudulent registrations, impersonation, spam, and security threats
  8. To respond to system failures, errors, crashes, and security incidents
  9. To process payments, manage billing, administer subscriptions, calculate fees, and confirm payment status
  10. To analyze usage of the Service and improve functionality, quality, and user experience
  11. To send notices regarding new features, updates, important changes, campaigns, and other information related to the Service
  12. To comply with laws, regulations, court orders, administrative requests, and requests from public authorities
  13. To respond to disputes, infringement claims, legal claims, unlawful acts, and misuse
  14. To protect the rights, property, and safety of the Company, users, third parties, and the public
  15. For purposes incidental or related to the above

3. Handling of Registered Files, Hash Values, Ledger Records, and Blockchain Anchors

Etymon is designed to create records that can later be verified in relation to files and other digital content registered by users.

The Service may create hash values, registration timestamps, signature information, ledger records, receipts, certificates, anchor information, and other verification data related to registered files.

We do not store registered files themselves on a public blockchain. However, to enhance tamper-resistance and verifiability, part of the ledger records managed by us, or summaries of such records, Merkle roots, hash values, anchor information, or similar data may be recorded on public blockchains or other external ledgers.

Some of this information may, by its nature, be impossible to modify or delete later. In particular, transactions, anchor information, hash values, or other data recorded on a public blockchain cannot be modified or deleted by us alone.

However, with respect to account information, display information, registered files, sharing links, and other information stored on servers managed by us, we may delete, make private, disable, or otherwise process such information within the limits of applicable laws, contracts, and technical or operational constraints.


4. Encrypted Files, Publications, and Reports

4.1 Encrypted Registered Files

Registered Files are encrypted on the user's device before upload. We store encrypted file bytes and the verification, account, billing, and operational metadata needed to provide the Service. The Service is designed so that we do not hold usable decryption material for original file content. Etymon support cannot reset lost content keys.

4.2 Publications

When a user chooses to publish, the client prepares a separate encrypted copy with a separate key and uploads that Publication with the selected thumbnail, metadata, proof information, and access policy. The complete Sharing Link may carry client-side secret material needed for browser decryption.

A recipient with the complete Sharing Link may view, download, store, copy, or re-share content within the selected policy. Revocation stops future access through Etymon but cannot retrieve complete links, keys, decrypted content, screenshots, or copies already saved by recipients.

4.3 Content Reports

When a viewer submits a report, the browser automatically creates a sanitized, re-encoded JPEG preview from content already inspectable on that publication page. The report includes that preview, the reported title, category, optional details, publication and item identifiers, and a keyed one-way digest derived from the reporter's IP address. The report record does not store the reporter's raw IP address.

Authorized Etymon administrators may inspect the report and preview only to investigate the reported content, enforce the Terms, protect users and the Service, document moderation decisions, handle appeals or repeat abuse, and respond to legal claims. Cloud hosting and managed database providers process this data only as needed to host and secure the reporting and administration systems.

We retain unresolved reports and their previews while they are in the moderation queue. After resolution, they remain in the moderation record for appeals, repeat-abuse prevention, security, disputes, and legal compliance. The Service does not currently apply a fixed automatic deletion period to these records; they are deleted or anonymized when no longer necessary under Section 10.


5. Sharing and Disclosure of Information

We may share or disclose user information in the following cases.

We may share information with third parties designated by the user based on the user's consent.

5.2 As Necessary to Provide the Service

We may provide information to contractors, cloud service providers, payment processors, authentication service providers, analytics service providers, support vendors, and other external service providers to the extent necessary for providing, operating, maintaining, improving, securing, analyzing, and supporting the Service.

In particular, cloud application hosting, managed database, and object-storage providers may process account identifiers, encrypted file bytes, metadata, reports, previews, and operational logs; email-delivery providers may process recipient addresses and message content; and payment processors may process billing identifiers and transaction status. They receive only the categories needed for their assigned function.

We require such service providers to manage information appropriately through contracts or other appropriate means.

5.3 For Payment Processing

We may provide necessary information to Stripe or other payment processors for payment processing, billing management, fraud prevention, refunds, accounting, and related purposes.

5.4 For Verification and Sharing Features

If you use verification pages, certificates, receipts, sharing links, or other sharing or verification features, we may display or provide registered files, verification records, metadata, hash values, registration timestamps, public key information, verification results, and other related information to third parties to the extent necessary to provide such features.

5.5 As Required by Law

We may disclose user information when necessary to comply with laws, regulations, court orders, administrative requests, lawful inquiries from investigative authorities, or other legal obligations.

5.6 To Protect Rights, Safety, and Property

We may disclose user information if we determine that disclosure is necessary to protect the rights, property, or safety of the Company, users, third parties, or the public. This includes responding to misuse, security incidents, fraud, rights infringement, and unlawful acts.

5.7 In Connection with Business Transfers

If we are involved in a merger, company split, business transfer, share transfer, financing, reorganization, bankruptcy, or similar transaction, user information may be transferred to relevant parties or successors for the purpose of considering, executing, or completing such transaction.


6. If We Provide Business or Organization Features

If we provide features for companies, organizations, research institutions, media organizations, enterprises, or other entities in the future, organization administrators may be able to view or manage information relating to users belonging to that organization, including account information, usage status, registration history, access permissions, sharing settings, verification records, and other information.

Such features may include:

In such cases, information of users belonging to an organization will be handled in accordance with the contract with the relevant organization, administrator settings, terms of use, individual agreements, and other applicable conditions.


7. External Transmission of User Information

We may use cookies, SDKs, tags, scripts, and similar technologies for the purpose of providing and improving the Service, ensuring security, processing payments, analyzing usage, providing user support, and other related purposes. As a result, information stored on the user's device or information transmitted from the user's device may be sent to servers operated by us or external service providers.

Information that may be externally transmitted includes:

The external services used by us, the information transmitted, the purposes of use, and the purposes of use by recipients are set forth in the Appendix.

At present, we use Stripe for payment processing and Country.is for approximate IP-based location lookup. Information necessary for payment processing, billing management, fraud prevention, refunds, confirmation of payment status, and other payment-related operations may be transmitted or provided to Stripe. An IP address may be transmitted to Country.is to obtain an approximate city, region, country, and coordinates for internal operational analytics. Coordinates retained by us for this purpose are reduced in precision.

For other external services, we will update the Appendix or this Policy when their introduction is confirmed.


8. Use for AI and Machine Learning

We do not use the contents of files registered by users with the Service for training generative AI models or other machine learning models without the user's consent.

We may analyze statistical information, log information, metadata, and usage data that do not include the contents of registered files for the purpose of improving the Service, ensuring security, preventing misuse, responding to errors, and analyzing usage.

However, if we obtain the user's explicit consent, or if permitted by applicable law, we may use information in accordance with separately specified conditions.


9. User Rights and Choices

Users may, in accordance with applicable laws, request disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or other handling of their personal information held by us.

Users may be able to change registration information, visibility settings, sharing links, notification settings, and other settings through account settings or other methods designated by us.

However, the following types of information may be subject to restrictions on modification, deletion, suspension of use, or non-disclosure due to their nature:

When we receive a request from a user, we will verify the identity of the requester and respond within a reasonable period in accordance with applicable laws.


10. Retention and Deletion of Information

We retain collected information for as long as necessary for the provision of the Service, performance of contracts, legal compliance, accounting, security, prevention of misuse, dispute resolution, audit purposes, and other legitimate purposes.

Even after an account is deleted or use of the Service ends, we may retain the following information to the extent necessary:

When information is no longer necessary, we will delete, anonymize, disable, or otherwise appropriately process such information by reasonable means.


11. Security

We take reasonable and appropriate security measures to prevent leakage, loss, damage, unauthorized access, misuse, alteration, and loss of user information.

Such measures may include:

However, no method of transmission over the Internet or electronic storage is completely secure. Users are responsible for appropriately managing their passwords, authentication information, private keys, decryption keys, sharing links, and other sensitive information.

Original Registered Files are encrypted under user-held content keys. If a user loses every enrolled device and all usable Secure Recovery or Local Backup material, we cannot reset those keys, and the Registered Files may become impossible to decrypt or view.


12. Use by Minors

The Service is generally intended for users who have reached the age required to validly enter into contracts in their respective jurisdictions.

If a minor uses the Service, the minor must obtain the consent of a parent or other legal representative. If we become aware that a minor is using the Service without the consent of a legal representative, we may suspend the account, delete information, or take other necessary measures.


13. International Transfer of Information

For the purpose of providing the Service, storing data, processing payments, authentication, security, analytics, support, and other related purposes, we may store, process, or transfer information to cloud service providers, payment processors, contractors, or other third parties located outside Japan.

In such cases, we will take necessary and appropriate measures in accordance with applicable laws.


14. Use of Cookies and Similar Technologies

We may use cookies, local storage, session storage, and similar technologies to provide the Service, maintain login sessions, ensure security, analyze usage, improve the Service, and enhance user experience.

Users may refuse or delete cookies through browser settings. However, if cookies are disabled, some features of the Service may not function properly.


15. Third-Party Websites and Services

The Service may include links to, or integration features with, websites, services, or applications operated by third parties.

We are not responsible for the handling of personal information, content, security, terms of use, or privacy policies of third-party websites or services. Users should review the privacy policies and terms of use of such third-party services before using them.


16. Changes to This Policy

We may change this Policy due to changes in laws, changes to the Service, technical changes, operational needs, or other reasons.

If we change this Policy, we will notify or publish the changes and the effective date by posting them on the Service, sending an email, or using other appropriate methods.

Unless otherwise specified by us, the revised Policy will take effect when posted on the Service or on the effective date notified by us.

If users continue to use the Service after the Policy has been changed, they may be deemed to have agreed to the revised Policy.


17. Governing Law and Language

This Policy is governed by and interpreted in accordance with the laws of Japan.

If there is any inconsistency or discrepancy between the Japanese version and any version in another language, the Japanese version shall prevail unless otherwise expressly stated.


18. Contact

For inquiries regarding this Policy, or for requests regarding disclosure, correction, deletion, suspension of use, or other handling of personal information, please contact us at:

Company Name: Glyph Inc.
Address: 313-30 Mugio, Yakushima-cho, Kumage-gun, Kagoshima-ken, Japan 891-4402
Representative: CEO Takashi Fuchigami
Contact: [email protected]


Appendix: External Transmission Services

The Service may use the following external services.

External Service Provider Purpose of Use Information That May Be Transmitted Purpose of Use by Recipient
Stripe Stripe, Inc. and its affiliates Payment processing, billing management, subscription management, fraud prevention, refunds Name, email address, billing information, payment amount, payment date and time, payment status, IP address, device information, and other information necessary for payment processing Payment processing, billing management, fraud prevention, legal compliance, and service provision
Country.is Country.is hosted service (Line of Flight open-source project) Approximate regional analytics and active-use visualization IP address IP-to-location lookup and operation of the lookup service

We will update this Appendix as necessary when external services are added, changed, or discontinued.