Privacy Policy
SnowWind app & snowwind.org
Operator: YUKIKAZE, K.K.
Effective date: September 1, 2026
This policy covers the SnowWind app and snowwind.org, including local track recording, optional Activity Feed sharing, Buddy sharing, Guardian remote watch, lesson-booking requests, and the Guide directory and console. Different features handle different data: a track kept only on your device is not handled in the same way as a public Feed post, a Guardian session or a Guide enquiry. We do not sell personal data, serve behavioural ads, or include an advertising or analytics SDK.
The short version
- A ski track you record normally stays on your device. Activity Feed sharing is opt-in and defaults to Device only: SnowWind attempts a Feed upload only after you choose Public and confirm. Guardian is a separate opt-in upload.
- Buddy live positions use a realtime presence channel and are not written to SnowWind's position database. Guardian stores submitted positions for a private watch link. A production migration for hard 48-hour access and retention controls has been prepared but is not yet deployed, so the controls described below must not yet be treated as live.
- Guides have business accounts. Guide profiles, review material, enquiries, booking records, messages and payment references are stored on our systems as described below.
- Sending a Guide enquiry or lesson-booking request does not create a customer account, but it does store the contact and trip information needed to handle that request.
- We use the service providers listed below to host the service, operate realtime sharing, send transactional email, process payments and generate optional AI text.
Device-local tracks and settings
Unless you turn on a sharing feature, recorded ski tracks and related logbook entries are stored in local app or browser storage on your device. SnowWind does not receive a copy of the raw track merely because you record it. You can delete local records in the app or remove them by clearing the app's data or uninstalling it.
The app and website may also store local preferences, language choices and safety acknowledgements on your device. Essential cookies are used where needed for functions such as an authenticated Guide-console session; they are not advertising cookies.
Activity Feed sharing
Recording a track and publishing it to the Activity Feed are separate actions. Merely recording a track or opening the share sheet does not upload it. The current SnowWind share sheet defaults to Device only; confirming that choice keeps the recording on the device and does not call the Feed publishing service. SnowWind attempts an upload only after you deliberately select Public and press the public-share control. The public community Feed is shared with the ykhokkaido service, so an accepted public post may appear in either service.
When a public share is accepted, Supabase stores the display name and caption you enter, activity type, an area or mountain inferred from the route where available, the full route as up to 1,000 latitude/longitude points, a sketch of up to 48 route points, distance, descent, top speed, duration, visibility, reaction or comment counts, and creation time. The shared Feed backend can also hold reactions, comments, danger-point markers and photo URLs when a client offers those features. The current SnowWind publishing flow does not send the original timestamps, elevation values or battery readings from the recorded fixes as part of the Feed route.
A public Feed write creates or reuses a Supabase authentication identifier. If you have not linked Google, this is a randomly assigned anonymous user ID rather than a name or email account; the public Feed response does not expose that ID. If you have linked Google, the internal ID is associated with that linked account. Replacing an anonymous session with Google sign-in does not currently merge an older anonymous post into the linked account.
The shared backend recognizes three visibility values. Public posts, their summary sketch and, when opened, their full latitude/longitude route can be read without signing in. Friends posts appear as summary cards, including the route sketch and any photo URLs, in the Feed of accounts connected as friends; the current full-route, reaction and comment endpoints accept public posts only. The friend connection can use a Supabase anonymous authenticated identity and is not technically limited to Google accounts. Private server records, if created by an older version or another shared client, are excluded from the public and friends content APIs and are not returned to their author by the current app APIs; exclusion is not deletion. A connected friend's latest-post time can currently reflect the existence and time of a Private row even though its contents are not returned. The current SnowWind share sheet exposes only Device only and Public—it does not offer a Friends choice and does not provide an in-app list or delete control for server posts.
Before a public upload, you can leave the start-and-finish protection enabled. It removes points within approximately 250 metres of both the first and last fix; it does not blur, randomize or reduce the precision of the remaining coordinates. If the track is too short or trimming would leave no usable line, the current app blocks the public share instead of silently uploading the original exact route. You can turn the protection off and share the exact route, so check the route carefully before doing so.
Buddy realtime sharing
Buddy sharing is opt-in. While you are in a Buddy group, your chosen display name, current position and update time are sent through a Supabase Realtime presence channel to the other people in that group. SnowWind does not write those Buddy positions to a database. Sharing stops when you leave the group, stop sharing or close the relevant session.
Creating a Buddy group stores a small group record in Supabase: the group name you enter, a random invite code and an expiry time. The group becomes unavailable 24 hours after creation. Supabase also issues a temporary anonymous identifier so the device can connect to the group; it is not a Guide account or a customer profile.
Guardian remote watch
Guardian is different from Buddy presence. If you explicitly start Guardian and share its private link, SnowWind stores the Guardian session and its submitted position points in Supabase. A point can include its time, latitude, longitude, elevation, speed and battery reading; the session can include a label, active state and last-seen time. Anyone who obtains the private link can view the available Guardian data, so share it only with people you trust.
Code and database migration `0013_watch_retention.sql` have been prepared for a hard rolling 48-hour watch window, owner-authenticated immediate link revocation and independent scheduled physical cleanup. That migration has not been applied or verified in production as of this policy's effective date. Those stronger controls therefore must not yet be relied on as live. The currently deployed cleanup path may depend on a later Guardian publish, so rows from a stopped session may remain on the server. Until the migration is applied and verified, email us to request deletion of a Guardian session and its points. Stopping a session stops new updates; it does not by itself delete stored points or make an already shared link secret again.
Guide accounts and directory profiles
A guide who uses the Guide console has a business account. We store the guide's email address, name, phone number, preferred language, profile text and photo URL, service areas, languages, login activity, tour and availability information, and Stripe account reference where connected. We also store qualification and liability-insurance information, review notes and review history so the operator can decide whether a listing may be published and keep an audit trail.
The public directory shows only the fields intended for publication, such as the guide's display name, biography, service areas, languages, selected qualification details, tours and enquiry availability. Contact details, insurance policy details, internal review notes and customer records are not intended to appear on the public profile.
Enquiries, bookings and payments
When you send a Guide enquiry, we store the information required to deliver and manage it: your name, email address, optional phone number, requested date, party size, experience, trip wishes, other notes, the selected guide and tour, the quoted amount, status, messages and related timestamps. The selected guide receives the enquiry details, including the contact and experience information needed to assess and answer it.
Lesson-booking requests similarly store the contact, schedule, group, course, resort, rental, transport and note information that you submit. Sending either type of request is not by itself a confirmed booking or a charge.
If Stripe payment is offered after acceptance, Stripe processes the payment and may collect customer and identity information under its own privacy policy. SnowWind stores transaction references and payment status needed to match the payment to the booking, but does not receive or store the full card number. Some accepted trips are paid directly to the guide or at the meeting point instead.
We use Resend to deliver transactional messages. Resend therefore processes the recipient address, subject and message contents, which can include enquiry, booking or payment information. Do not put unnecessary sensitive information in a free-text field.
Optional AI features
The app and website offer optional AI briefing, comparison, fly-through and debrief text. They run only when you request them and use the DeepSeek API. Depending on the feature, SnowWind sends area names, terrain or hazard facts, weather values, user-selected conditions and summary statistics derived from a track. Raw recorded tracks, Guide-account records and booking contact details are not intentionally included in these AI requests.
SnowWind does not write the contents of these AI requests to its application database. DeepSeek receives the request and standard technical information such as the requesting server's IP address, and processes it under its own terms and privacy policy.
Technical information
Cloudflare and other providers necessarily receive standard request information when they deliver the service, such as IP address, time, requested URL, browser or device information and security or error records. We use this information to operate, secure and troubleshoot SnowWind, not for behavioural advertising. Public map, weather and bulletin services may receive similar technical information when your device requests their content directly.
Service providers and recipients
- Cloudflare and Cloudflare D1 — website and API hosting, security, request handling, and storage of Guide accounts, enquiries, booking records, review records and payment references.
- Supabase — optional Activity Feed posts and internal authentication identifiers; Buddy realtime presence, minimal Buddy group records and anonymous connection identifiers; and Guardian sessions and submitted position points.
- Resend — transactional email for enquiries, bookings, authentication links and payment notices.
- Stripe — Checkout and payment processing and, for participating guides, Stripe Connect onboarding, identity checks and payouts.
- DeepSeek — optional AI-generated briefing, comparison, fly-through and debrief text.
- Public map, weather, terrain and bulletin services — including JMA, GSI, Open-Meteo, the Japan Avalanche Network, OpenStreetMap and map-tile providers such as Esri. These sources supply the content identified on the relevant page.
- The guide or lesson provider you contact — receives the request details necessary to respond and provide the requested service.
We do not sell, rent or trade personal data. A provider may process data only for the relevant service and under its own legal terms and privacy practices.
Security
Communications with SnowWind use HTTPS/TLS. Guide authentication links are time-limited and single-use, and authenticated console sessions use protected cookies. Guardian and Buddy invite links are capability links: possession of a valid link or code may provide access, so you should send them only through a channel and to people you trust. No online service can guarantee absolute security.
Retention
- Device-local tracks: remain on the device until you delete them, clear app data or uninstall the app.
- Activity Feed: a Device-only choice remains local and follows the device-local retention above. A public post, or a server-side Friends/Private post created by an older version or another shared client, has no automatic expiry and remains until it is deleted or the service no longer needs it. The current SnowWind app has no per-post server deletion control.
- Buddy positions: pass through realtime presence and are not written to SnowWind's position database. The minimal Buddy group becomes unavailable 24 hours after creation.
- Guardian positions: the code for a hard rolling 48-hour access window, immediate owner revocation and scheduled deletion is prepared, but migration `0013_watch_retention.sql` is not yet deployed. Until it is applied and verified, physical deletion may depend on later publishing and stopped-session records may remain longer; deletion can be requested in the meantime.
- Guide accounts and public profiles: retained while the account or listing is operated and for as long afterwards as reasonably needed for review, security, recordkeeping or a dispute. A guide may request closure or deletion as described below.
- Enquiries, bookings, payment references, review and audit records: retained while needed to handle the request or transaction and afterwards where reasonably necessary for accounting, fraud prevention, security, a dispute or legal obligations. Retention varies by category and purpose; no single fixed period applies to every record.
- Queued transactional messages: after Resend accepts a message, the next successful queue update removes its destination, subject and body. If delivery never succeeds, the next cleanup run after 30 days removes those fields. Queue cleanup currently runs when new transactional work is processed or an operator runs the protected retry task, so removal can be delayed while there is no such activity. The opaque booking link, message kind, timestamps and coarse delivery result may remain with the transaction record.
- Provider records and technical logs: retained according to operational need and the relevant provider's practices.
When a record no longer needs to identify a person, we may delete it or remove identifying fields while retaining non-identifying transaction, security or statistical information.
Your choices and deletion requests
- You can deny or revoke location permission in your device settings.
- You can leave a Buddy group or stop Guardian sharing at any time. This stops future transmission. Because the prepared Guardian revocation and scheduled-cleanup migration is not yet deployed, email us to request removal of an inactive Guardian session, its link and its points.
- You can delete device-local tracks in the app, clear the app's data or uninstall it.
- The SnowWind app does not currently provide in-app deletion of an individual server Feed post or a SnowWind account. To remove a public or historical server-side Feed record, email us with the post ID if available, the display name, approximate posting date and linked-account email if applicable. Posts made under an anonymous ID may require other details sufficient to verify control. If you use the same linked account in the ykhokkaido app, its in-app account-deletion flow requests removal of Feed posts and reactions associated with that authenticated ID before deleting the account; comments on other people's posts may instead remain de-linked. Because individual cleanup steps are best-effort, contact us if you need confirmation that a particular Feed record was removed.
- A guide can ask us to close the Guide account and remove the public listing. A customer can ask about deletion or correction of an enquiry or booking record.
- To make a server-side request, email [email protected] from the relevant address where possible and include the Feed post, Guide, enquiry or booking identifier, or a Guardian label and approximate start time. Do not send card details, passwords, Guardian watch tokens or magic-link tokens. We may ask for enough information to verify that the requester is entitled to control the record.
We will assess the request and delete, correct, restrict or de-identify data where appropriate. We may retain limited information where reasonably necessary to comply with law, preserve transaction or accounting records, prevent abuse, maintain an audit trail, establish or defend legal claims, or resolve an active dispute. We will explain the outcome when we respond; no exception permits us to use retained data for unrelated advertising.
Children
SnowWind is not directed at children under 13, and we do not knowingly collect personal information from them. Backcountry travel and Guide services involve serious risks and are intended to be arranged by adults.
Changes to this policy
If we change this policy, we will update this page and the effective date above. Material changes will be communicated through the app or website when appropriate.
Contact
Questions or requests about this policy or your data: [email protected]
Operator: YUKIKAZE, K.K.