Reference translation. The Japanese version is the operative, published document and prevails in the event of any discrepancy.
Effective date: 9 September 2026
Last updated: 9 September 2026
WPIC Technology Japan LLC ("we" or "us") collects and processes the personal information of users ("Users") of Ano (あの), the creator community we operate at https://ano.wpic.ai, together with the application forms, emails and web applications provided as part of it (collectively, the "Services").
We are the personal information handling business operator under the Act on the Protection of Personal Information (the "APPI") in respect of personal information obtained through the Services.
Ano introduces creators to the brands that engage us (each a "Brand Partner"). Where a Brand Partner obtains and processes personal information in its own right — for example after a creator agrees to work with that partner — that processing is governed by the Brand Partner's own privacy policy, not this one.
This Policy applies only to data processing carried out by us and does not apply to the privacy practices of third parties. We accept no responsibility for data processing by third parties, including where the Services contain links to third-party websites or services.
Separate privacy policies may apply to some Services. Where they do, they will be posted on the relevant website or otherwise provided in connection with that Service.
We take privacy, security and online safety seriously, and handle all personal information with care and in accordance with applicable laws and guidelines.
Name: WPIC Technology Japan LLC (WPIC Technology Japan 合同会社)
Registration number: 010403020634
Address: 4F Landwork Aoyama Building, 2-7-26 Kita-Aoyama, Minato-ku, Tokyo 107-0061
Representative: Jacob Cooke
Contact point for personal information (enquiries, requests and complaints): ano@wpic.co (weekdays 10:00–17:00 JST, excluding weekends and public holidays)
Website: https://wpic.co/
We collect (1) User Data and (2) Technical Data. Technical Data is not normally used to identify an individual, but an individual may be identified from it alone or in combination with User Data. In such cases we handle the combined data as personal data.
(1) User Data
(i) Name
(ii) Email address
(iii) Confirmation that the User is 18 or over, and the age band selected
(iv) Gender, where the User chooses to provide it
(v) Region of residence
(vi) Social media platforms used, account handles, and the follower band selected
(vii) Links to public posts, videos and other work the User submits as examples
(viii) Interests and product categories the User selects
(ix) Whether the User is open to paid collaborations, and whether they are interested in becoming an ambassador
(x) Where we send a gift or product: recipient name, postal code, address and telephone number
(xi) Where we pay a fee: bank name, branch, account type, account number, account holder name, and invoice registration number where the User has one
(xii) Records relating to agreements, including electronic signature records
(xiii) Content submitted to us in connection with a collaboration, and any accompanying usage permissions
(xiv) Correspondence with us and our record of it, including emails and replies
(xv) Other personal data voluntarily provided by the User
User Data is obtained directly from the User as a rule, through the application form or in correspondence. Where a User gives us a social media handle, we may also view the information that account makes publicly available in order to assess the application.
We do not obtain or retain payment card numbers, security codes or expiry dates. Fees are paid by bank transfer using the details the User provides.
(2) Technical Data
(i) IP address
(ii) Browser type and version
(iii) Language settings
(iv) Approximate regional location inferred from the IP address
(v) Operating system, platform and device information
(vi) URL clickstream within the Services (including referral to, within and away from the Services), and date and time
(vii) Pages and areas viewed within the Services
(viii) Cookie identifiers and advertising identifiers
(1) Use of cookies
The Services may use cookies to provide site functionality, remember the state of a form, understand usage and improve the Services.
The information transmitted externally by cookies and similar technologies, the recipients, and their purposes are set out in (2) below.
Cookies can be disabled through your browser settings, but if you do, some functions of the Services may not be available.
You may also stop transmission to individual recipients using the opt-out mechanisms listed in (2) below.
(2) External transmission of user information
The Services transmit information stored on the User's terminal to external parties as set out below, together with the recipient, the information transmitted, the recipient's purpose, and how to stop it.
Recipient: Google LLC (Google Tag Manager, and the measurement tags configured within it, including Google Analytics)
Information transmitted: Cookie identifiers, IP address, pages viewed, referrer and browsing behaviour within the Services
Recipient's purpose: Access analysis, statistical reporting and improvement of the Services
How to stop: Google Analytics opt-out add-on (https://tools.google.com/dlpage/gaoptout), Google ad settings, or browser settings
Google Analytics is loaded through Google Tag Manager and is used for access analysis. Nothing is transmitted to Google until the User accepts analytics cookies in the banner shown on first visit; before that, and for a User who declines, no request is made to Google and no analytics cookie is set. Google Consent Mode signals default to denied, and accepting grants analytics storage only. A User can change that choice at any time through the "Cookie settings" link in the site footer. See the Cookie Policy for detail.
No advertising or remarketing tags are deployed on the Services. If one is added, this chapter will be updated before it starts firing, and Users will be asked for their choice again.
(3) Provision of personal-related information to third parties
We do not currently provide cookie identifiers, advertising identifiers or browsing history to advertising providers. If we begin to do so, and the recipient is anticipated to acquire such information as personal data, we will confirm in advance that the User's consent has been obtained, and we will update this Policy first.
We use personal data for the following purposes:
(i) receiving and assessing applications to join Ano, and communicating the outcome;
(ii) verifying identity, and verifying that a User is 18 or over;
(iii) introducing creators to Brand Partners and proposing collaborations, and administering those collaborations;
(iv) sending gifts and products, and arranging delivery;
(v) preparing, sending and administering agreements, including by electronic signature;
(vi) calculating and paying fees, issuing and receiving invoices, and complying with the related tax and accounting obligations;
(vii) responding to enquiries and providing support;
(viii) sending important notices, including changes to terms and notices relating to a collaboration;
(ix) where the User has consented, sending information about Ano and about opportunities, campaigns and newsletters;
(x) receiving, reviewing and using content the User submits in connection with a collaboration, within the permissions the User has given;
(xi) operating, maintaining, improving and analysing use of the Services, and producing statistics;
(xii) detecting and preventing impersonation, unauthorised access, fraudulent applications and other misuse;
(xiii) conducting surveys and satisfaction research;
(xiv) complying with legal, tax and accounting obligations and maintaining statutory books and records;
(xv) exercising our rights, performing our obligations, and handling disputes and legal proceedings; and
(xvi) activities incidental to the above.
We may use Technical Data and other anonymised and aggregated data to produce statistics and reports. These contain no personal data.
If we change a purpose of use, we will do so only within a scope reasonably deemed relevant to the purpose before the change, and we will notify Users or announce the change on the Services.
We implement the following measures to prevent leakage, loss or damage of personal data.
(1) Formulation of a basic policy
We have established a basic policy, including this Policy, covering compliance with applicable laws and guidelines and the point of contact for questions and complaints.
(2) Internal rules for handling personal data
We maintain internal rules setting out handling methods, responsible persons and scope of responsibility at each stage of acquisition, use, storage, provision, deletion and disposal.
(3) Organisational measures
We appoint a person responsible for handling personal data, define the scope of personnel handling personal data and the data they handle, and maintain a reporting line for identified or suspected breaches. We maintain means of ascertaining how personal data is being handled.
(4) Personnel measures
We make employees aware of the requirements applying to the handling of personal data and include confidentiality obligations in our employment rules.
(5) Physical measures
We take measures to prevent theft or loss of devices, electronic media and documents containing personal data, and where these are carried outside our premises, measures so that personal data is not readily discernible.
(6) Technical measures
Access to the Ano back office is restricted to authorised WPIC personnel, requires an individual account and password, and is limited by role. We deploy protections against unauthorised external access and malicious software. Communications with the Services are encrypted using TLS. We regularly test our websites, systems and other assets for security vulnerabilities.
(7) Understanding of the external environment
We store personal data on servers located in Japan. Certain service providers we engage for email delivery, electronic signature and analytics are located in the United States and may store or access personal data there. We implement security control measures having ascertained the personal information protection regime in those countries.
We may outsource all or part of the handling of personal data to the extent necessary to achieve the purposes of use, including to:
- cloud hosting providers
- email delivery and inbound email providers
- electronic signature providers
- delivery carriers and warehouse and logistics providers, for sending gifts and products
- analytics providers
- other providers necessary for our operations
We select service providers against appropriate criteria and require by contract that they limit their use of personal data to the purpose of the appointment and comply with privacy and security standards at least equivalent to this Policy, and we exercise necessary and appropriate supervision over them.
Where a User provides personal data directly to a third party via a link in the Services, that processing is governed by the third party's own policies and standards.
We share personal data within our organisation only to the extent reasonably necessary for the performance and development of the Services.
We provide personal data to a Brand Partner only where the User has consented to be introduced to that partner, or to a specific collaboration, and only to the extent necessary for it. Before a User is introduced, we will make clear which partner is involved and what will be shared.
Apart from that, we do not provide personal data to third parties without prior consent except where:
- required by law or by a court order;
- necessary to protect the life, body or property of an individual and it is difficult to obtain consent;
- particularly necessary for improving public health or promoting the sound growth of children and it is difficult to obtain consent;
- necessary to cooperate with a national or local government body, or a party commissioned by such a body, in performing statutory duties, and obtaining consent would impede those duties;
- necessary to detect, prevent or address fraud, or security or technical issues; or
- personal data is transferred in connection with a merger or other business succession. In that case we will continue to ensure confidentiality and, where the data becomes subject to a different privacy policy, we will notify affected Users as soon as reasonably possible.
Provision incidental to outsourcing under Chapter 7 does not constitute provision to third parties under the APPI. Wherever possible, we will notify Users of provision to third parties and the associated processing.
We do not retain personal data beyond the period permitted by law and necessary for the provision of the Services or related purposes. Retention periods vary by the nature of the information and the purpose of processing. Principal periods are:
- Application data for creators we work with: for the duration of the relationship, and 3 years thereafter
- Application data where no collaboration follows: 2 years from the application
- Agreements, fee and payment records, and invoices: 7 years, as required for tax and accounting purposes
- Correspondence and support records: 3 years after the matter is closed
- Newsletter registration data: until the User unsubscribes, or 3 years from last engagement
- Access logs and Technical Data: up to 14 months from collection
- Submitted content: for the period covered by the usage permission the User gave
Thereafter we do not retain data beyond the period required or permitted by law, or reasonably necessary for internal reporting and reconciliation. Where a User requests deletion, we delete or anonymise the personal data within a reasonable period.
Users, or their authorised agents, may make the following requests in relation to retained personal data.
(1) Rights
- Notification of the purpose of use
- Disclosure, including disclosure of third-party provision records and provision in electronic form
- Correction, addition or deletion of contents
- Cessation of use or erasure
- Cessation of provision to third parties
- Withdrawal of consent where processing is based on consent
- Restriction of processing
- Receipt of personal data in a structured, commonly used format and transfer of that data to a third party
- Cessation of use of personal data for direct marketing, market research and profiling
Where consent is withdrawn, processing is restricted or cessation of use is requested, some functions of the Services may become unavailable, and we may be unable to introduce the User to a collaboration.
(2) How to make a request, and identity verification
Contact us in writing or by email at ano@wpic.co, providing your name, address, telephone number and a copy of valid identification (driver's licence, health insurance card, or My Number Card with the individual number redacted). For agent requests, please also provide documentation evidencing authority and a copy of the agent's identification. We may ask for additional information necessary to verify identity.
(3) Fees
We do not charge a fee for requests for notification of the purpose of use or for disclosure.
(4) Where we cannot comply
We may be unable to comply where doing so is prohibited by law, would risk harm to the life, body, property or other rights and interests of the User or a third party, would seriously impede the proper conduct of our business, or would violate other laws. We will notify the User of that fact and the reason. We may also refuse requests that are manifestly repetitive, excessive or clearly unfounded.
(5) Deletion requests
To request deletion of your personal data or your Ano record, please contact ano@wpic.co. Other than information we are required by law to retain, the relevant personal data will be deleted within 30 days. Copies remaining on backup systems may not be deleted immediately, but are deleted as soon as reasonably practicable.
If an incident occurs involving leakage, loss or damage of personal data of the kind prescribed under the APPI and its enforcement rules, we will report to the Personal Information Protection Commission and notify affected individuals without delay in accordance with law. Where an incident may adversely affect Users' privacy, we will also notify other affected parties and the relevant authorities as soon as possible.
Complaints
Please direct comments, questions and complaints about our handling of personal information to the contact point in Chapter 2. If you consider that our handling of personal data breaches applicable law, you may also make a submission to the supervisory authority, the Personal Information Protection Commission.
PPC APPI Consultation Line: 03-6457-9849
Website: https://www.ppc.go.jp/
We do not belong to an authorised personal information protection organisation.
Ano is open only to Users aged 18 or over, and we ask Users to confirm this when they apply. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it. A parent or guardian who believes we hold data about a person under 18 may contact ano@wpic.co and we will respond in accordance with law.
Please also refer to our Terms of Use, and to the Cookie Policy, for the terms on which the Services are provided.
We may amend this Policy to reflect changes in our data processing practices, changes in law, or as otherwise required. The current version is posted on the Services. Where we make material changes or reduce Users' rights, we will give prior notice.
Where a Brand Partner is located outside Japan and the User has consented to be introduced to that partner, we may provide personal data to it overseas. An outline is set out below.
Recipient: the Brand Partner named to the User at the time consent is sought
Country of location: notified to the User at the time consent is sought
Information provided: name, email address, social media handles, follower band, and the work samples and content relevant to the collaboration, to the extent necessary for it
Purpose: assessing and administering the collaboration
Data protection regime of that country: notified to the User at the time consent is sought
Measures taken by the recipient: we contract with the recipient to ensure, by appropriate and reasonable methods under the APPI, the implementation of measures corresponding to the eight OECD Privacy Guidelines principles
Further information is available on request from the contact point in Chapter 2.
We also use service providers based outside Japan for the operation of the Services, including the email delivery, electronic signature and analytics providers referred to in Chapters 4, 6 and 7, and those providers may store or access personal data outside Japan. We take the measures necessary to ensure personal data is appropriately protected under the APPI and other relevant laws, and where necessary we contract with those providers to secure appropriate safeguards.
WPIC Technology Japan LLC