Privacy Policy
Last updated: 30 September 2026
This policy explains how Keita Okuizumi (the “Operator”, “we” or “us”), handles the personal data of people who use Mychats.info (the “Service”).
We handle personal data in line with Malaysia’s Personal Data Protection Act 2010 (as amended in 2024), referred to below as the “PDPA”.
1. Information we collect
1.1 Member information
When you sign in with a Google account, we store your email address, display name, profile picture URL, and the date and time you last signed in. Sign-in uses Firebase Authentication (Google).
Firebase Authentication also records your account information (email address, display name, profile picture URL, Google account ID, and the dates and times the account was created and you signed in).
To keep you signed in, we store a sign-in record (the dates and times it was created, last used and expires). Sign-in records do not include information about your device or browser.
1.2 Information members save
- Saved routes (the origin and destination stations, the area, the transport mode, the date and time settings, and the route name)
- Transit search history (origin, destination and search conditions)
1.3 Recent posts (in preparation)
Once this feature becomes available, we will store the following information.
When you post, we store your post name, the area, the line, the station (or stop), the category, the text, the language, the date and time, and an ID that is fixed for each member. Other signed-in members can also read your posts and this ID. Even if you change your post name, posts with the same ID can be recognised as coming from the same member.
We also store your post name and records used to prevent repeated posting (the date, time and ID of your last post, and the number of posts you made that day). These records remain even after your posts are deleted.
When you report a post, we store the ID of the member who reported it, the reason for the report, and the ID and a copy of the reported post (post name, text and the poster’s ID). This copy remains as part of the report record even after the original post is deleted.
1.4 Location
We get your device’s location (latitude, longitude and accuracy) only when you press “Find stations near me”.
Your location is sent to our server to find nearby stations, but it is not stored. It is also not kept in your browser, in your search history or in the URL.
1.5 Connection information
The Service is delivered through Cloudflare. Connection information such as your IP address, browser type, and the date and time is processed by Cloudflare to deliver the Service, prevent misuse and investigate faults.
We use IP addresses temporarily to limit large numbers of requests from the same IP address.
1.6 Information stored in your browser (cookies and similar)
We do not use cookies for advertising or marketing, and we do not use analytics tools (such as Google Analytics).
- sns-locale (cookie): the display language of the site. 1 year
- transit-locale (cookie): the display language of transit search. 1 year
- sns-theme (cookie): your choice of light or dark display. 1 year
- Transit search history (when you are not signed in): only within the current tab (sessionStorage). Up to 12 entries. Deleted when you close the tab
- Your choice of 2D or 3D in route view (localStorage)
- Whether the first-time notice has been shown (localStorage)
- __Host-sns_session (cookie): your sign-in state. It is stored encrypted and cannot be read by scripts on the page. It is deleted when you close the browser (a sign-in is valid for up to 29 days)
- __Host-sns_oauth (cookie): a check used while you are signing in. 10 minutes
1.7 Enquiries
When you send a message through the contact form, your name, email address, subject and message are delivered by email to the person in charge through Formspree, a form-sending service.
On the contact page, Cloudflare Turnstile checks that messages are not sent by bots. For this check, your IP address, browser type and other information about your browser and device are processed by Cloudflare. What you type into the form is not sent to Turnstile.
2. How we use it
We do not use personal data for advertising, and we do not sell it.
Giving us personal data is optional. You can use route search and nearby station search without signing in. If you do not sign in, you cannot use saved routes or save your search history to an account. If you do not allow location access, you can still search by station name.
- To provide the Service (route search, nearby station search, and saving routes and search history)
- To sign you in and tell members apart
- To prevent misuse and limit access
- To investigate and fix faults
- To respond to enquiries
3. How long we keep it
- Member information and saved routes: for as long as your account exists
- You can save up to 20 routes. Saving a 21st route deletes the oldest one
- Search history: the latest 50 entries. Older entries are deleted automatically
- Sign-in records: deleted when you sign out. A sign-in is valid for up to 29 days. Expired records are deleted the next time you sign in; if you do not sign in again, they remain until your account is deleted
- Recent posts (in preparation): posts are deleted over time once they are more than 14 days old (the list shows the last 3 days)
- Post names and repeated-posting records: for as long as your account exists
- Report records: for as long as needed to handle reports and prevent misuse
- Enquiries: deleted once they have been dealt with and the necessary period has passed
- Location: not stored
- Connection information: according to Cloudflare’s retention periods
4. Third-party providers
Except as provided by law, we do not give personal data to third parties without your consent.
- Google (Firebase Authentication, Cloud Firestore): sign-in and storage of member data. Member data in Cloud Firestore is stored in Singapore (asia-southeast1), and account information in Firebase Authentication is stored in the United States
- Cloudflare: delivering the Service and preventing misuse
- Formspree: sending the contact form (name, email address, subject and message)
- Cloudflare Turnstile: checking for bots on the contact page (IP address and information about your browser and device)
- Profile pictures are loaded from Google’s servers, so your IP address is sent to Google when a picture is shown
- Weather comes from weatherz, the Operator’s own weather service (using OpenWeather data). No user information is sent when it is fetched
- When you open a link to Google Maps, Apple Maps or a similar service, that service’s policy applies
5. Transfers outside Malaysia
The Service runs on Cloudflare servers (United States). Member data in Cloud Firestore is stored in Singapore, and account information in Firebase Authentication is stored in the United States. Connections may be processed at Cloudflare locations in other countries. Messages sent through the contact form pass through Formspree (United States). For these reasons, personal data is processed and stored outside Malaysia.
6. Security
Connections are encrypted (HTTPS). Apart from recent posts, member data cannot be read or written by other members. The Operator looks at it only when necessary, such as to deal with faults or reports, or as provided by law.
If a personal data breach occurs, we will report it to the regulator as the law requires. If the breach is likely to have a serious impact on users, we will also inform the people affected.
7. Your rights
Under the PDPA, you can ask to access, correct, stop the use of or delete your personal data, ask to receive it in a form you can take elsewhere (data portability), and withdraw your consent.
What you can do on screen
- Delete search history entries one at a time or all at once
- Delete saved routes
- Sign out
Requests to delete your account or export your data are accepted through the contact form or by email. We will act on them after confirming your identity.
8. Users under 13
If you are under 13, please get your parent’s or guardian’s consent before using the Service.
9. Changes to this policy
If we change this policy, we will announce it on the Service.
10. Operator and contact
- Operator: Keita Okuizumi
- Email: keita@tenki.info
- Server location: United States (Cloudflare)
This policy is shown in 5 languages. If the language versions differ, the Japanese version prevails.