Privacy Policy

Last updated: April 14, 2026

1. Introduction

QuizJam ("the Service", URL: castgamingkit.com) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use it, and how we manage it.

2. Information We Collect

2-1. Information Obtained via OAuth Authentication

The Service obtains the following information through Google or X (formerly Twitter) OAuth authentication.

  • Display name (nickname)
  • Profile image URL
  • Email address (for Google; may not be obtained for X)
  • Authentication provider user ID

The Service uses OAuth authentication only and does not obtain or store your Google or X password.

2-2. Information Collected During Service Use

  • Quiz question data created or submitted by the user
  • Plan and ticket purchase history
  • Quiz session usage history (number of questions, categories, etc.)
  • Country code of access origin (IP-based information provided by Vercel; IP addresses themselves are not stored)

2-3. Payment Information

  1. Credit card and payment information is processed directly by our payment processors, KOMOJU (DEGICA Co., Ltd.) and Stripe, Inc. Credit card numbers and other sensitive payment details are never stored on our servers.
  2. Only payment processor customer IDs (KOMOJU customer ID or Stripe customer ID) are stored in our database for the purpose of managing subscriptions and purchase history.
  3. For details on how payment information is handled, please refer to:

3. Purpose of Information Use

We use the collected information for the following purposes.

  • User authentication and account management
  • Providing, operating, and improving the Service
  • Payment processing and subscription management
  • Content moderation of submitted quiz questions
  • Service improvement through usage analysis
  • Prevention of unauthorized use

4. Disclosure to Third Parties

We do not provide users' personal information to third parties except in the following cases.

  • When the user has given consent
  • When required by law
  • When necessary for integration with external services required for Service operation (see "5. External Service Integrations" below)

5. External Service Integrations

The Service uses the following external services. Please also review their respective privacy policies.

ServicePurposeInformation Sent
SupabaseAuthentication & DatabaseAccount information, quiz data
KOMOJU (DEGICA Co., Ltd.)Payment processingEmail address, payment information
Stripe, Inc.Payment processingEmail address, payment information
Anthropic (Claude)AI question generation & moderationQuiz generation requests, submitted content
VercelHostingAccess logs (including country code)
GoogleOAuth authenticationAuthentication tokens
X (Twitter)OAuth authenticationAuthentication tokens

6. Entrusted Third Parties and Cross-Border Transfer

We entrust the handling of personal data to the following third parties for the operation of the Service. Some of these entities are located outside Japan (in the United States).

ProviderLocationPurpose
Supabase, Inc.United StatesDatabase & Authentication
Vercel, Inc.United StatesWeb Hosting
Anthropic, PBCUnited StatesAI Question Generation & Moderation
OpenRouterUnited StatesAI Question Generation (backup)
KOMOJU (DEGICA Co., Ltd.)JapanPayment Processing (Japan)
Stripe, Inc.United StatesPayment Processing (International)

Cross-Border Transfer to the United States

  1. By using the Service, you consent to the transfer of your personal data to the above third parties located in the United States.
  2. Each provider maintains appropriate security measures in accordance with their privacy policies:
  3. You may withdraw this consent at any time by contacting support@castgamingkit.com, though this may affect your ability to use the Service.

7. Cookies

The Service uses cookies to maintain authentication state. The cookies used are as follows.

  • Authentication Cookie: Required to maintain login state (Supabase Auth)
  • Admin Authentication Cookie: Used for admin panel access (valid for 24 hours)

The Service does not use advertising tracking cookies or third-party cookies.

8. Data Storage & Security

  • Data is stored in Supabase (PostgreSQL database on AWS).
  • Row Level Security (RLS) is applied to the database, ensuring users can only access their own data.
  • All communications are encrypted via HTTPS (TLS).
  • Admin panel access uses two-factor authentication (OAuth + PIN).

9. Data Retention Period

User account information is retained as long as the account is active. If you wish to delete your account, please contact us. After deletion, personal information will be erased within a reasonable period. However, this does not apply when retention is required by law.

10. User Rights

Users have the following rights.

  • Right to request disclosure of their personal information
  • Right to request correction or deletion of personal information
  • Right to request cessation of use of personal information
  • Right to request account deletion

To exercise these rights, please contact us using the information provided below.

11. Minor's Information

The Service is not intended for use by persons under the age of 13. If we become aware that a person under 13 is using the Service, we may delete the relevant account and associated data.

Users between the ages of 13 and 17 must obtain parental or guardian consent before purchasing tickets or subscribing to the Pro plan. The Company may request proof of parental consent where deemed necessary.

12. Changes to This Policy

This policy may be revised as necessary. If significant changes are made, we will notify users through the Service. The revised Privacy Policy takes effect upon posting on this page.

13. Contact

For inquiries regarding this policy, please contact us at support@castgamingkit.com.

Operator: Takao Matsumoto (Trading as: CastGamingKit)

Contact: support@castgamingkit.com