ハナサイト
How it worksLINE & voiceSamplesFeaturesPricingFAQ
JAEN
Log inTry it free

Contents

  1. 1. Where data is stored
  2. 2. Encryption in transit
  3. 3. Accounts and login
  4. 4. Keys, passwords and other secrets
  5. 5. How we use AI
  6. 6. Publishing and previews
  7. 7. Servers and operations
  8. 8. Backups
  9. 9. Payment information
  10. 10. What we do not do
  11. 11. If there is a data leak
  12. 12. Reporting a security problem

Other documents

  • Terms of use
  • Privacy policy
  • Commercial disclosure
  • Cookies and analytics
  • Security
  • Company

Legal

Security

Enacted: 8 October 2026Version: 2026-10-08

This English text is a reference translation. The Japanese version is the binding one and prevails if the two differ. 日本語版

Contents
  1. 1. Where data is stored
  2. 2. Encryption in transit
  3. 3. Accounts and login
  4. 4. Keys, passwords and other secrets
  5. 5. How we use AI
  6. 6. Publishing and previews
  7. 7. Servers and operations
  8. 8. Backups
  9. 9. Payment information
  10. 10. What we do not do
  11. 11. If there is a data leak
  12. 12. Reporting a security problem

What Hanasite does to protect your information and your website, as concretely as we can — and what we do not do.

1. Where data is stored#

  • The Service's servers (database, uploaded files, sites, backups) are in a data centre of Hetzner Online GmbH 【To be confirmed:server location (planned: Finland)】. We are in a test and trial phase and plan to move to servers in Japan; we will tell you when we do.
  • AI processing happens at OpenAI and Anthropic in the United States.
  • Your site's code is also kept in a private repository on GitHub (United States).
  • The Service is run by staff of Masterbek LLC (Republic of Uzbekistan).

Details by country are in “Transfers to and handling in other countries” of the privacy policy.

2. Encryption in transit#

  • All traffic to the Service and to sites is encrypted (HTTPS); site certificates are obtained and renewed automatically.
  • Login cookies are sent only over encrypted connections.

3. Accounts and login#

  • Passwords are stored only as one-way hashes, never the password itself.
  • Login links that open the Studio from a LINE chat expire after 10 minutes and work only once.
  • When you log in with LINE, our server checks the ID token LINE issued with LINE itself.
  • Logins, sign-ups and password resets are rate-limited.
  • Deleting your account requires typing your e-mail address (or, for accounts without one, a code shown on screen) and your password if you have set one. You are then logged out on every device at once.

4. Keys, passwords and other secrets#

  • Keys your site needs (API keys of external services …) are entered in a dedicated secure form and stored encrypted in the database.
  • If you give a password, API key, card number or the like in chat or by voice, we store that part masked and do not send it to the AI. We cannot catch everything, so always use the secure form for secrets.
  • We cannot delete messages already sent on LINE, so please do not send secrets there.

5. How we use AI#

  • The AI builds sites in an isolated environment per task. It contains no other customers' data and none of the keys the Service uses with AI providers — only a temporary key issued per task with a usage limit.
  • We do not use your content or conversations to train AI models. The OpenAI and Anthropic APIs we use state in their terms that they do not use the data sent to them for training.
  • Sites the AI makes are not published until you have checked them and chosen to publish. Publishing, restoring an earlier version, deleting a site and similar actions happen only after you confirm.
  • When we read pages from URLs you give us, we only access public internet addresses, never our internal network.

6. Publishing and previews#

  • Previews (drafts) open only on an address that contains a random string unique to your site. Only people who know the address can open it — and anyone you share it with can. Previews are set not to be indexed by search engines.
  • When a preview page links to or loads something from another site, the browser does not pass the preview's address on.
  • “Issue a new preview link” in Settings gives the preview a new address at any time; the old one stops working.
  • Your site's forms detect spam. Spam is not deleted automatically but filed under “Spam” in your inbox, where you can delete it at any time.

7. Servers and operations#

  • The servers accept only the traffic needed (web and administrative connections), block repeated failed logins automatically and apply security updates automatically.
  • The Service is checked automatically every minute, each published site every five minutes.
  • Notices to our operators (sign-ups, payments, incidents …) contain no customer personal information.
  • Only staff who need it for operations and support can access the servers and the admin 【To be confirmed:list of people with access; two-factor authentication for the admin】.

8. Backups#

  • The database and files are backed up daily; seven days are kept on the server.
  • Encrypted backups are also kept somewhere other than the server 【To be confirmed:off-site backup location; restore drill】.
  • Backups are deleted after at most 30 days, so data you deleted leaves them within 30 days.

9. Payment information#

  • You enter card numbers directly on the payment provider's page or input field; they never pass through our servers and we do not store them.
  • 3-D Secure authentication is used when you register a card.
  • Notifications from the payment provider and from LINE are accepted only after their signature or shared secret is checked, and a duplicate is never processed twice.

10. What we do not do#

  • We hold no third-party security certification (ISMS, PrivacyMark, SOC 2 …).
  • There is no 24/7 support by staff; what is available around the clock is the AI support. Problems are detected automatically, but staff respond mainly on business days (e-mails are answered within 2 business days as a rule).
  • Data is not stored and processed only in Japan (see “Where data is stored” above).
  • Previews cannot be password-protected (they are protected by their hard-to-guess address).

11. If there is a data leak#

If personal information leaks or may have leaked, we act to limit the damage and investigate the cause. Where the legal criteria are met, we report to the Personal Information Protection Commission and notify the people affected.

Person responsible: 【To be confirmed:name and title】

12. Reporting a security problem#

If you find a vulnerability or notice suspicious e-mails or access, write to Loading… with “Security” in the subject. A staff member reviews every report.

Enacted: 8 October 2026

Other documents

  • Terms of use
  • Privacy policy
  • Commercial disclosure
  • Cookies and analytics
  • Security
  • Company

Back to top

ハナサイト

Talk your shop's website into shape.

Powered by Bekito

Product

  • How it works
  • Samples
  • Pricing
  • FAQ

Legal & contact

  • Terms of use
  • Privacy policy
  • Commercial disclosure
  • Cookies and analytics
  • Security
  • Company

Sold by 株式会社Bekito · Developed and operated by Masterbek LLC

株式会社Bekito 〒170-0013 東京都豊島区東池袋2丁目62番8号 BIGオフィスプラザ池袋1206

© 2026 株式会社Bekito