Security Policy
Last updated: August 31, 2026
This Policy states the basic security practices that apply to each application provided by Sanary. Applications that handle particularly sensitive information may be subject to additional app-specific policies.
Basic Approach
Sanary (the “Services”) may handle personal information and user data, including records, content, projects, and source code. Sanary therefore treats data protection as an important priority.
Although Sanary applies reasonable safeguards, no internet transmission can be guaranteed to be completely secure.
Rights in User Data
Rights in records, content, projects, source code, and other user data that a user enters, creates, registers, or manages belong to the user or the lawful rights holder.
- Sanary does not view, analyze, or sell user data without authorization.
- Sanary does not use user data for advertising targeting.
- Sanary does not use user data to train Sanary’s own AI models.
See the AI Usage Policy for processing performed by AI service providers.
Communications Security
- Where internet communications are used, Sanary applies encryption appropriate to the application and platform, such as HTTPS (TLS).
- Authentication information is stored and managed using security mechanisms appropriate to the application and platform.
- For web services, Sanary uses mechanisms such as HttpOnly cookies where appropriate and designs its services not to store personal information or authentication credentials in localStorage.
Data Storage
- Data covered by server-based applications is stored with appropriate protection in an environment designated by Sanary, such as the AWS Japan Region (ap-northeast-1).
- Local First applications manage data primarily on the user’s device or in a storage location controlled by the user.
- Sanary Build does not collect or store user projects or source code on Sanary servers.
- Sanary applies appropriate encryption and access controls to server-side databases and backups.
Access Control
The following measures apply to services that use server or account functionality:
- access to user data requires authentication through a service-appropriate identity provider, such as AWS Cognito, Apple, or Google;
- APIs and other server functions validate authentication tokens or other authorization information;
- each component receives only the permissions necessary for its function, following the principle of least privilege;
- user data is segregated and controlled to prevent unauthorized access by other users; and
- operator access to data is limited to legitimate operational needs and is logged.
Reporting Vulnerabilities
If you discover a security issue, report it through the contact form (info@sanary.jp). Sanary will promptly investigate and respond to the report.
Revision History
- August 31, 2026: Updated the scope of communications, storage, and access-control provisions for Local First and native applications, including Sanary Build.
- August 8, 2026: First published as a common Security Policy, separating and consolidating common provisions from the Sanary Log security policy.