Privacy
Updated 29 September 2026
hanai operates from Cagayan de Oro, Philippines. We use the information you provide to review your project, communicate with you and deliver agreed work. Contact jession@hanai.dev about your information.
What we collect
The answers you type into the request form, the files you upload, your email address, and the messages you exchange with us about your request. Security and operational records also help us protect accounts, limit abuse and diagnose failed requests. There is no analytics script, error-tracking SDK or advertising pixel on the site.
Cookies and browser storage
Necessary storage supports functions you request, including sign-in, uploads and saving your idea while you move into the studio. We use no analytics or advertising cookies.
- Sign-in cookies: hanai_client and hanai_operator
- These keep authenticated sessions secure. Client sessions last up to 30 days and renew with activity. Operator sessions expire after 12 hours of inactivity or 7 days in total. Signing out ends the session.
- Upload access: hanai_upload
- This necessary cookie authorizes access to your draft uploads. Its 30-day lifetime renews when you edit the draft.
- Your storage choice: hanai_consent
- This necessary cookie records the choice shown in the consent form for 180 days. It contains no unique visitor identifier.
- Your idea: hanai-draft
- When you continue with an idea, localStorage keeps your draft on this browser so you can resume after signing in. It is removed after you create the project or clear browser data. The old hanai-theme appearance preference is no longer used and is removed when you load the site.
Open Cookie settings in the footer to review storage and save a necessary-only choice. This does not sign you out or delete your draft. Clearing browser data also clears saved drafts and choices. If storage is blocked, the site cannot remember them.
Services that help us operate
Railway hosts the application, Supabase provides the database and file storage, and Resend delivers transactional email. These providers handle the information needed for those services. Processing may take place outside your country.
Cloudflare Turnstile checks browser and network signals to protect our forms from automated abuse. See Cloudflare’s privacy policy for its processing details.
How your files are stored
Uploads are private. They are never publicly readable, never listed anywhere, and can only be opened through short-lived links issued after we check that the person asking is you or us. We treat everything you send as confidential business material, because that is usually exactly what it is.
Every uploaded file is checked against its actual contents before it becomes available. A file that isn’t what it claims to be is deleted rather than stored.
One deliberate exception
The screenshots in a snapshot email are stored at public web addresses. They have to be: Gmail and Outlook cannot sign in to fetch an image, so a private link would show up as a broken image in your inbox.
Those addresses are random and unguessable, and they are never listed or linked from anywhere public. Anyone with the image address, including someone you forward the email to, can see the screenshots. Your uploaded files are never treated this way.
How long we keep it
If you start a request and never submit it, we delete it and anything you uploaded to it 30 days after you last edited it. We email you a warning 7 days before that happens, with a link to pick it back up. Any edit resets the clock.
Submitted requests are kept so we have a record of the work, until you ask us to delete them.
Getting your data deleted
Ask from your settings page and we’ll erase your requests, your files and your messages within 30 days. We keep a short record of what was deleted and when, so we can prove the deletion happened.
You can also contact us to ask for access to your information or to correct it, or to raise a concern about how it is used. Applicable privacy rights depend on your circumstances. You can raise a concern with the Philippine National Privacy Commission or your relevant privacy authority.
We send transactional email only: a confirmation when you submit, a question when we have one, and your snapshot when it’s ready. You can turn off progress updates in settings. Essential messages, including sign-in links and delivery notices, remain enabled so you can access your account and your work.
Questions about any of this? Email jession@hanai.dev or reply to any email we send you.