Privacy Policy

This policy explains how ricrio inc. ("we") handles information about people who use PlainHub (plainhub.dev, app.plainhub.dev, the CLI, and the MCP Server; together, "the Service"). This English version is the governing text. We also provide a Japanese translation.

1. Our approach

The Service doesn't store your files. They are saved only in your own GitHub repository, and their contents never pass through our servers. We collect only the minimum information we need to run and improve the Service.

2. Who we are

ricrio inc. is the controller of the personal information described in this policy. This means we decide why and how it is used.

Controllerricrio inc. (株式会社リクリオ), Japan
Address and representativeSee our company profile (Japanese)
ContactContact form (for requests about your personal information, please say so in your message)

3. What we collect

InformationWhenWhere it's stored
Your GitHub username and the date and timeWhen you open the editor while signed inCloudflare KV
Sign-in counts (event names only: "started", "succeeded", "denied", "failed" — no username, IP address, or repository name)At each step of signing in with GitHubCloudflare Workers Analytics Engine
Page-view statistics (pages viewed, referrer, browser and device type, country or region, etc. — no cookies, and no identification of individuals)When you view the site or the editorCloudflare Web Analytics
Your name, email address, and messageWhen you contact us through our contact formOur contact form

You don't have to give us any of this. But to use the editor, you need to sign in with GitHub, and we then record your username.

4. What we don't collect

5. Why we use it, and our legal bases

We use the information in section 3 for these purposes only. If you are in the European Economic Area (EEA) or the United Kingdom, the right-hand column shows our legal basis under Article 6(1) of the GDPR.

InformationPurposeLegal basis
GitHub username and date/timeTo know how many people use the Service and how often, to improve it, and to investigate and prevent misuseOur legitimate interests in running, improving, and protecting the Service (Art. 6(1)(f))
GitHub access token (passed on, not stored)To sign you in with GitHubNeeded to provide the Service you asked for (Art. 6(1)(b))
Sign-in countsTo find and fix problems with signing inOur legitimate interests in improving the Service (Art. 6(1)(f))
Page-view statisticsTo understand how the site and the editor are usedOur legitimate interests in improving the Service (Art. 6(1)(f))
IP addresses processed by CloudflareTo deliver the Service and protect it from attacksOur legitimate interests in keeping the Service working and secure (Art. 6(1)(f))
Name, email address, and messageTo reply to your inquiryOur legitimate interests in answering you (Art. 6(1)(f)), or steps you asked for before a contract (Art. 6(1)(b))

We have weighed these interests against your rights. We keep the data small, we don't use it for advertising, and we delete it on a fixed schedule (section 6).

6. How long we keep it

7. What's stored on your device

Your browser stores your GitHub token, your AI API key, display settings, the last file you opened, and similar data (in localStorage, etc.). The CLI and MCP Server store the token on your computer at ~/.config/plainhub/token. None of this is sent to us. Signing out of the editor removes your GitHub token from the browser. Clearing the browser's site data removes everything.

8. Other services

9. International transfers

We are based in Japan. We use Cloudflare, Inc. in the United States to store and process the information in section 3. Cloudflare may process and store it in its data centers around the world.

10. Sharing with third parties

We don't share personal information with third parties without your consent, unless the law requires it. Our service provider in sections 8 and 9 works on our behalf, so it doesn't count as a third party here. We never sell personal information.

11. How we protect it

12. Your rights

You can ask us to:

Under Japanese law, you can also ask us to tell you our purposes of use, to stop using or sharing your data, and to disclose records of sharing with third parties.

To make a request, use our contact form (section 2). We will check that you are the person concerned, for example by asking you to show that you control the GitHub account. We will reply without undue delay, and within one month under the GDPR. Username records are deleted after 90 days. After that, we hold nothing that identifies you.

If you are in the EEA or the UK, you can also complain to a data protection supervisory authority. You can do so in the country where you live or work, or where you think the problem happened.

13. Automated decision-making

We don't make decisions about you based only on automated processing, including profiling.

14. Changes to this policy

We may update this policy when laws or the Service change. When we do, we'll announce it on this page and update the revision date.

Effective date: September 30, 2026
Last revised: —

See also: Data Ownership · Security