Privacy policy
Version 0.3, effective 7 October 2026.
This policy explains what personal information Anyfront collects, why, how long it is kept, who else handles it, and what you can ask us to do with it. It describes what the systems actually do, in plain English.
Who is responsible
Anyfront is a service of Anystack G.K. (Anystack合同会社), a company registered in Japan. In this policy, “we” and “us” mean Anystack G.K. We decide how and why your personal information is used. That makes us the controller under the UK and EU GDPR, and the business handling it under Japan’s Act on the Protection of Personal Information (the APPI).
- Contact for anything in this policy: aaron@anyfront.co
- Representative: Aaron Culbert
- Our registered address in Japan is provided on request.
The short version
- We collect what we need to answer you, run the free check and do the work you hire us for.
- We do not sell personal information, and we do not use it for advertising.
- Free-check data is deleted after 90 days, unless you keep your report. A report emailed to you as a PDF is also kept with our correspondence.
- Nothing about you or your app is published without your written consent.
- You can ask to see, correct or delete what we hold at any time.
Enquiries, calls and email
When you send a question through the form on this site, email us, book a call or talk to us, we keep:
- your name, email address and company
- what you tell us about your product, stack and goals, and notes from the call
- the language you would like a reply in
- the booking details for the call
We use this to reply, to prepare a proposal and to run any engagement that follows. Under the GDPR, the basis is taking steps you asked for before a contract, or our legitimate interest in answering business enquiries.
A question sent through the form is stored in our online systems for 90 days and emailed to Aaron, so that he can reply to you directly. To stop abuse, the form counts requests using salted hashes of your IP address and email address, one-way fingerprints that expire after 2 days, in the same way as the free check below.
Correspondence that leads to an engagement becomes part of that engagement’s record. If no engagement follows, it is deleted within two years of the last contact, or sooner if you ask.
The free check
When you request a free check online at anyfront.co/check, we store:
- the app URL you submit
- your email address
- a salted hash of your IP address, used to enforce rate limits and to record who took each action in the check’s event log. It is a one-way fingerprint, not the address itself. Your email address and the app’s host are counted the same way for rate limits, and these counters expire after 2 days.
- your source IP address, in the check’s event log, which is kept for 90 days
- the version of the consent text you agreed to, and the time you agreed to it
- the language of the page you asked from, so that its emails and report are in that language
We use your email address to confirm the request and to send your report, the IP fingerprint and event log to stop abuse, and the consent record to show that the check was asked for. Under the GDPR, the basis is your request, and our legitimate interest in preventing abuse.
If you ask Aaron directly and he sets the check up for you online, it is created from a note of how and when you asked rather than from the form, so no IP address or consent record is taken at that point.
The scan reads only what the app serves publicly. It never reads or scans private code. If you show that the app is yours with a read-only repository invite, the invite is used only for that: nothing in the repository is read, copied or stored for the check.
The scan records information about the app, not about its users:
- Findings are stored with their evidence redacted. A leaked key, for example, is recorded as a short prefix, its last four characters and its length, never its full value.
- For databases, the scan records only metadata: table names and row counts, or whether the database is open to the public. Row contents are never read or stored.
- It records response headers, versions and performance measurements. The app’s script files are scanned but not kept.
How long an online check is kept:
- A request that is not confirmed, or whose ownership is not verified, is deleted after 7 days.
- Reports and raw scan data are deleted after 90 days, unless you keep your report. Each version of a report has a PDF of it, which is stored with the report and deleted with it.
- To keep a report, use the “Keep this report” button on its page, or ask us. We then create a portal account for the email address you confirmed, link the report to it, and keep it for the life of that account. The raw scan data behind it is still deleted after 90 days.
- You can ask us to erase a check, and everything recorded about it, at any time.
For an online check, deletion is automatic. A report link stops working on its expiry date, and the stored data is removed shortly after, usually within a few days. The online free-check store has no backups, so once something is deleted it is gone.
Report pages carry no analytics or third-party trackers, and they are not indexed by search engines.
Checks run by hand
When the online check is paused, the form at anyfront.co/check offers to send your request to Aaron as a question instead. Aaron may then run the check by hand, as he does for anyone who asks him directly while it is unavailable. The scan is the same, and so are its limits above: redacted evidence, and only metadata about databases. What differs is this:
- What we keep. Your request is kept as correspondence, as described under “Enquiries, calls and email”, together with how ownership of the app was verified. No IP address, rate-limit counter or consent record is taken.
- Where it is stored. The scanner runs on Aaron’s computer in Japan, and writes its output, meaning the report and a list of the files it fetched, to that computer’s encrypted disk. None of it is stored in our online systems.
- How you get it. The report is sent to you by email, as a PDF. A copy stays in our mailbox with the rest of our correspondence, and is deleted on request like any other email.
- How long it is kept. Aaron deletes the scan output by hand 90 days after the scan, unless you ask us to keep the report. You can ask us to erase it sooner.
Portal accounts and engagements
If you become a client, we hold:
- the names and email addresses of the people on your portal account at app.anyfront.co. Sign-in uses a passkey, or a one-time code emailed through Amazon Cognito. For a passkey, Amazon Cognito keeps a public key and an identifier for it; your fingerprint, face or device PIN never leaves your device. Your session is kept in your browser’s local storage.
- proposals, work requests, comments, reports and their PDFs, handover notes and links to pull requests
- invoices and payment records. Card details stay with Stripe.
We access your code and data only as far as the engagement needs, under the access rules in our terms of service. Local copies are kept on encrypted storage and deleted when the engagement ends. If you choose delegated access in your proposal, we act in your own accounts through a role you grant and can remove. That role may reach personal data held in those accounts, and we use it only as far as the agreed scope needs and only on your instructions.
Under the GDPR, the basis is our contract with you. Account data is kept for the life of the account. Invoices and accounting records are kept for as long as Japanese tax law requires, which is generally seven years.
The website service
For customers of the Anyfront website service, we also hold the site’s content and the change requests sent to us. Where you connect them, we read reporting data from Google Business Profile, Google Search Console and Mailchimp through access you grant and can revoke. Those connection tokens are kept in AWS Secrets Manager under a dedicated encryption key. Draft wording for requested edits, and the weekly digest, are produced with Amazon Bedrock, which processes them in Australia.
Where your data is stored
Portal and website-service data is stored with Amazon Web Services in its Sydney region (ap-southeast-2), encrypted at rest. Records have point-in-time backups kept for 35 days. Files in the portal, such as reports, keep their previous version for 30 days after they are deleted or replaced. So after something is deleted, a copy can remain for up to 35 days.
Online free-check data, and questions sent through the form on this site, are stored in the same region, with no backups. A check run by hand is stored on Aaron’s computer in Japan instead, as described above, and the emails about it are held in Google Workspace.
Analytics on anyfront.co
The marketing pages of anyfront.co use Google Analytics 4 with Consent Mode.
- Advertising storage is denied for every visitor, and no advertising features are used.
- For visitors in the European Economic Area, the UK and Switzerland, analytics storage is denied by default, so no analytics cookies are set. Google may still receive a signal, without cookies, that a page was viewed.
- For other visitors, analytics cookies are set to count visits and see which pages are read.
- Two events are recorded, with no details attached: sending a free-check request or a question, and clicking a booking link.
- Google Analytics never runs on report, confirmation or 404 pages, on any page that is not indexed, or anywhere on app.anyfront.co.
anyfront.co also remembers the currency you choose in your browser’s local storage. It is never sent to us.
You can block analytics cookies in your browser’s settings, or opt out with Google’s browser add-on.
Who else handles your information
We use these providers to run the service. Each handles personal information only to provide its service to us.
| Provider | What for | What it receives |
|---|---|---|
| Amazon Web Services | Hosting and storage, portal sign-in (Amazon Cognito), sending email (Amazon SES), and drafting for the website service (Amazon Bedrock) | What is stored for the portal, the website service, the online free check and questions sent through the site, and the emails we send |
| Email (Google Workspace), Google Analytics 4 and PageSpeed Insights | Emails to and from our anyfront.co addresses; analytics as described above; the app URL, when the PageSpeed Insights check is enabled | |
| Stripe | Payments, invoices and subscriptions | Your billing name, email address and payment details |
| Wise | Bank transfers, if you pay that way | Your payment details |
| [Placeholder: booking tool, to be named once chosen] | Booking calls | Your name, email address and the time you book |
| AI providers | AI-assisted delivery, under business terms that exclude training on inputs | The code and context a task needs, unless you opt out in your proposal |
Transfers across borders
We are a Japanese company, our systems store data in Australia, and several of the providers above are based in the United States. Your information may therefore be handled in Japan, where Aaron works, in Australia and in the United States.
- Under the APPI, where we provide personal information to a third party in another country, we do so with your consent, or where the recipient is bound by contract to protect it to an equivalent standard. On request, we tell you about the privacy laws of the country concerned and the measures the recipient takes.
- Under the UK and EU GDPR, we rely on an adequacy decision where one exists, and otherwise on standard contractual clauses or equivalent safeguards offered by the provider.
Nothing is published without consent
We never publish your name, your app, your findings or anything else about you without your written consent. A case study is a separate, optional request: if you agree to one, it is anonymised unless you consent to more, and you sign off the final text before it appears.
How we look after it
- Data is encrypted in transit and at rest, and the main data store uses its own encryption key.
- Report and confirmation links use long random tokens, and we look each one up by a hash, never by the token itself. For a confirmation link, the hash is all we keep. For a report link, we also keep the token itself, encrypted at rest with the rest of the check, so that we can send you the link again.
- Aaron is the only person with access. Anyone else who works on an engagement does so only with the client’s written agreement and under a written confidentiality agreement.
- Local copies of client code and data are kept on encrypted storage and deleted when the engagement ends.
Your rights
Wherever you are, you can ask us to tell you what we hold about you and how we use it, to correct it, to delete it, to stop using it, or to give you a copy.
- Japan (APPI). You can request disclosure of the personal data we hold about you, including records of providing it to third parties; correction, addition or deletion; and that we stop using it or stop providing it to third parties. If you are not satisfied with our answer, you can contact the Personal Information Protection Commission.
- Australia (Privacy Act 1988), where it applies. You can ask for access to your personal information and for its correction. You can complain to us, and then to the Office of the Australian Information Commissioner.
- UK and EU (GDPR), where they apply. You have the rights of access, rectification, erasure, restriction, portability and objection. Where we rely on your consent, you can withdraw it at any time, without affecting what was done before. You can complain to the Information Commissioner’s Office in the UK, or to the data protection authority where you live in the EU.
To use any of these rights, email aaron@anyfront.co from the address we hold, or tell us how else we can confirm it is you. For a free check, include the app URL. We answer within one month, and we do not charge for it.
Children
Anyfront’s services are for businesses. We do not knowingly collect personal information from children.
Changes to this policy
This policy is versioned and dated, and the version and effective date are shown with it. When it changes in a way that matters, we update both, and we tell clients by email.
This policy is also published in Japanese, at /ja/privacy.