← Back to homeMaison Saika Tokyo

Privacy Policy

Effective Date: [To be set when published] Last Updated: April 28, 2026 Version: 1.3


1. Introduction

SkinCura Tokyo ("we," "us," "our," or "SkinCura") is committed to protecting your privacy and handling your personal data with the highest standards of care. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our personalized skin diagnosis service (the "Service") through our website skincuratokyo.com (the "Site").

By using our Service, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy.

This Policy is designed to comply with:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act) of India
  • The Act on the Protection of Personal Information (APPI) of Japan
  • General best practices for data protection

2. Who We Are (Data Controller / Data Fiduciary)

SkinCura Tokyo is operated by HadAI Works LLC (合同会社 HadAI Works), a limited liability company organized under the laws of Japan, with its principal place of business in Tokyo, Japan. The trademark "SkinCura Tokyo" is owned and operated by HadAI Works LLC.

Data Controller / Data Fiduciary:

  • Entity: HadAI Works LLC (合同会社 HadAI Works)
  • Representative Member: Tomoko Watanabe
  • Location: Tokyo, Japan
  • Contact: privacy@skincuratokyo.com

For the purposes of the DPDP Act, HadAI Works LLC acts as the "Data Fiduciary" determining the purpose and means of processing your personal data.

3. Information We Collect

3.1 Account and Contact Information

  • Full name
  • Email address
  • Phone number (used for WhatsApp communication and to link future diagnoses for progress tracking)
  • City and country of residence
  • Age group (we require you to be 18 years or older)

3.2 Health and Lifestyle Information (Questionnaire)

  • Self-reported skin type, concerns, and sensitivities
  • Current skincare products and routines
  • Known allergies and ingredient intolerances
  • Lifestyle information (sleep, stress, diet, exercise, hydration, alcohol, smoking)
  • Occupation and general environmental exposure
  • Hormonal and general health notes relevant to skin
  • Budget range and skincare goals

3.3 Photographs (Sensitive Personal Data)

As part of the diagnosis, you upload up to seven (7) photographs of yourself:

  • Six facial photographs (front, left side, right side, T-zone, left cheek, right cheek)
  • One photograph of the underside of your wrist (used for skin undertone reference)

These photographs are treated as sensitive personal data under both the DPDP Act and the APPI.

3.4 Payment Information

When you make a purchase, your payment information (card details, UPI details, bank account information) is processed directly by our payment processor.

Currency and Processing

SkinCura Tokyo is operated from Japan, and payments are currently processed in USD ($) via Stripe. The INR (₹) amounts displayed on our website are approximate, for reference only. The exact INR amount charged to your account depends on your bank's USD-INR exchange rate at the time of transaction, plus any foreign transaction fees your bank may apply. We are working to enable direct INR billing through Razorpay in the future.

Data Storage

SkinCura does not store your full payment card numbers or banking credentials on our servers. We retain only transaction metadata (amount, date, transaction ID, plan purchased).

3.5 Technical Information

  • IP address
  • Device type, browser type, and operating system
  • Pages visited, time spent, and referral source
  • Cookies and similar tracking technologies

4. How We Use Your Information

4.1 Primary Purposes (Essential)

  • To create and operate your account
  • To provide the skin diagnosis service you purchased
  • To allow our certified Skin Curators to review your photographs and questionnaire
  • To generate your personalized skin report
  • To send you service-related communications via email and WhatsApp
  • To process payments and prevent fraud
  • To provide customer support
  • To link your current diagnosis with past diagnoses (when using the same phone number) for tracking your skin's progress over time, particularly for Beauty Monthly subscribers

4.2 Secondary Purposes (with your explicit consent)

  • To send you marketing communications about new products, offers, or features
  • To use anonymized and aggregated data to improve the quality of our Service

You can withdraw consent for secondary purposes at any time without affecting the primary service.

5. Photograph and Sensitive Skin Data Handling

5.1 Who Can Access Your Photographs

  • The assigned SkinCura certified Skin Curator who creates your report
  • Technical administrators subject to strict confidentiality agreements
  • OpenAI API (see Section 6), if your plan uses AI-assisted report drafting

Your photographs are never shared with other customers or used in public marketing without your separate explicit consent.

5.2 AI Processing

If you use a plan that includes AI-assisted drafting, photographs are sent to OpenAI via API with Zero Data Retention (ZDR) option enabled. The AI-generated draft is always reviewed and edited by a human Skin Curator before delivery.

5.3 Retention and Deletion of Photographs

Photographs are stored in encrypted cloud storage (Supabase Storage) and retained for as long as your account is active, plus up to 24 months after account closure. You may request immediate deletion at any time by contacting privacy@skincuratokyo.com.

6. Third-Party Service Providers

We share limited data with the following third parties:

Service ProviderPurposeLocation
SupabaseDatabase and file storageAWS ap-south-1 (Mumbai)
VercelWebsite hostingGlobal CDN
StripePayment processingUnited States
OpenAIAI-assisted report drafting (with ZDR)United States
Email providerTransactional email deliveryGlobal
WhatsApp (Meta)Customer communicationGlobal

We do not sell your personal information to any third party.

7. International Data Transfers

Your personal data will be transferred across borders as part of providing our Service. We ensure all cross-border transfers comply with applicable law under the DPDP Act and the APPI. By using our Service, you explicitly consent to these cross-border data transfers.

8. Data Retention

Data CategoryRetention Period
Account informationActive account + 24 months after closure
Questionnaire responsesActive account + 24 months after closure
PhotographsActive account + 24 months after closure (sooner on request)
Diagnostic reportsActive account + 24 months after closure
Payment records7 years (Japanese tax law requirement)
Communication logs24 months
Technical logs12 months

For Beauty Monthly subscribers, your past diagnostic records are retained to provide month-over-month progress tracking. You may opt out of progress tracking at any time by contacting privacy@skincuratokyo.com.

9. Your Rights

Under the DPDP Act, the APPI, and other applicable laws, you have:

  • Right to Access your data
  • Right to Correction of inaccurate data
  • Right to Deletion / Erasure
  • Right to Withdraw Consent for optional processing
  • Right to Grievance Redressal (acknowledgment within 7 business days, resolution within 30 days)
  • Right to Nominate (DPDP Act): nominate a person to exercise your rights in case of death or incapacity

To exercise your rights, contact privacy@skincuratokyo.com. We may verify your identity before processing the request.

10. Cookies and Tracking Technologies

We use cookies to maintain your session, remember preferences, and analyze traffic patterns. You can control cookies through your browser settings.

11. Data Security

We implement technical and organizational safeguards including:

  • Encryption in transit (TLS/HTTPS) and at rest (AES-256)
  • Access controls limiting data access to authorized personnel
  • Regular security audits
  • Staff training on data protection
  • Incident response procedures

In the event of a personal data breach posing risk to your rights, we will notify you and the relevant Data Protection Authority within 72 hours as required under the DPDP Act.

12. Children's Privacy

Our Service is intended exclusively for individuals 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If you believe we may have collected data from a minor, please contact privacy@skincuratokyo.com.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For significant changes, we will notify you via email at least 30 days before the changes take effect, and request re-consent for any new purposes requiring consent.

14. Complaints and Regulatory Authorities

If we have not addressed your privacy concerns adequately, you may lodge a complaint with:

  • In India: The Data Protection Board of India (once operational under the DPDP Act)
  • In Japan: Personal Information Protection Commission (https://www.ppc.go.jp/en/)

15. Contact Us

Grievance Officer: Tomoko Watanabe (Representative Member, HadAI Works LLC) Email: privacy@skincuratokyo.com Response commitment: Acknowledgment within 7 business days; resolution within 30 days


This Privacy Policy was originally drafted on April 19, 2026, updated on April 26, 2026 to reflect that HadAI Works LLC operates SkinCura Tokyo as its trademark and service brand, and updated on April 28, 2026 to disclose phone-number-based progress tracking for Beauty Monthly subscribers.