⚠️ This site is NOT tax advice — it is a tool to help you prepare your own filing. Always verify amounts before submitting.

TaxNinja JP

Privacy Policy

Last reviewed: 2026-04-22

TaxNinja JP ("we", "us") is a document-preparation tool for foreign residents of Japan. This policy explains what personal information we handle, why, how long we keep it, and the rights you have under Japan's Act on the Protection of Personal Information (個人情報保護法 / APPI) and the My Number Act (行政手続における特定の個人を識別するための番号の利用 等に関する法律 / 番号法).

1. What we collect

  • Account basics: email, chosen name, hashed password.
  • Tax-return inputs: residency status, postal code, income amounts, wizard answers, ledger entries, and any receipts or withholding-slip numbers you enter.
  • My Number (個人番号): collected only with your explicit opt-in, used solely to populate the main return, stored encrypted, purgeable on demand.
  • Technical logs: IP, user-agent, timestamps for sign-in, package generation, and feature-flag changes — kept for 90 days for security.

2. Why we use it (利用目的)

Solely to generate your tax-return document package and operate the service. We do not sell, rent, or otherwise monetize your data. We do not use it for advertising or profiling.

3. How long we keep it

  • Tax-year records: until you delete the tax year, or until you delete your account.
  • Generated PDFs: regenerated on demand — we do not retain the rendered file server-side.
  • My Number: deleted within 24 hours of package generation, or immediately upon request.
  • Audit logs: 90 days rolling.

4. Third parties

We do not share your personal information with third parties except to the extent required by law or by a clearly labeled integration you opt into (e.g. Moneytree LINK bank sync, currently disabled by default).

5. Your rights under APPI

You can request disclosure, correction, suspension of use, or deletion of your personal information at any time. Use the dashboard → settings to export or delete your data (contact details published by the site administrator when configured).

6. Security measures (安全管理措置)

Passwords are hashed with bcrypt. Sessions are JWTs delivered as httpOnly SameSite=strict cookies. Database traffic is confined to the container network. My Number, when collected, is encrypted at rest with a key separate from the general application key. See Security for details.

7. Children

The service is intended for adults. Users under 18 should only use it with a guardian.

8. Changes

We will announce material changes at least 30 days before they take effect, in-app and by email.

Data protection officer (個人情報保護管理者): contact details pending publication by the site administrator.

Important: This site is NOT tax advice — it is a tool to help you prepare your own filing.