This English translation is provided for reference only. If there is any discrepancy between the two versions, the Japanese version shall prevail.
Privacy Policy
Last updated: August 29, 2026
This Privacy Policy explains the information that VRCPersona (hereinafter the "App") collects and uses. By using the App, you are deemed to have agreed to this Policy. Please also review the Terms of Use.
This Policy is written on the premise of version 1.0.0 of the App. Some features are not included in earlier versions; the headings of the relevant items are marked "version 1.0.0 and later". In addition, where a feature itself exists but the handling of data differs by version, this is stated in the relevant text.
1. Information We Collect
1-1. Discord Authentication Information
At login, we use Discord OAuth2 (identify scope) to verify your identity. We obtain the following information from Discord and store it on the VRCPersona server (hereinafter the "Server").
- Discord user ID
- Discord username
We do not store the Discord access token on the Server.
1-2. VRChat Account Linking
To link your VRChat account, we use a nonce verification method. The App temporarily sets a verification code issued by the Server in the pronouns field of your VRChat profile, and the Server's service account reads that value to verify the link. After verification is complete, the pronouns field is automatically restored to its original value. Your VRChat authentication token is never transmitted to the Server.
1-3. VRChat User Information
- VRChat user ID
- Display name
- Friend list (friend_ids)
These are used to provide friend management features.
The friend list (friend_ids) is used for access control of the status-sharing feature. Only users included in your friend list can view your status. The friend list is automatically deleted from the Server one day after the last synchronization.
1-4. Location Information
When you use the status feature of friend groups, your current world ID and instance ID are shared with group members. This sharing is optional and is transmitted only when you set a status.
In addition, the Server records whether status sharing is online and the time of the last update. Unlike the world ID and instance ID, these are returned to users of the App who have registered you as a friend, regardless of whether you have set a status and regardless of group conditions.
1-5. License Information
- BOOTH order number (entered by you when authenticating a paid license; it may also be obtained through the purchase notification email from BOOTH — see Section 4-1)
- IP address (recorded and retained at the time of license activation to prevent fraudulent use)
1-6. App Settings
If you use the setting to launch the App automatically when Windows starts, it is registered in the OS startup. You can disable this setting at any time from within the App.
1-7. Reading VRChat Log Files
To provide notification and auto-save features, the App reads the log files output by VRChat (%LOCALAPPDATA%Low\VRChat\VRChat). VRChat can be launched with separate profiles at the same time, in which case a separate log file is created for each running copy of VRChat. The App reads the log files in this folder regardless of whether they belong to the account you are signed in to in the App (the most recent file for each account is covered). The information obtained is as follows:
- Player join/leave events (display name, user ID)
- Information about prints and stickers (print ID, sticker inventory ID, and the display name and VRChat user ID of the person who placed it)
- In-game events (shader errors, audio device changes, etc.)
- Your own joining and leaving, and information about the world and instance you are in (world ID, world name, instance identifier)
- Events within the instance (information about videos played, portal generation, and the like)
This information is processed only within your PC and is never transmitted to the Server. However, if you have configured a Discord Webhook or XSOverlay as a notification destination, display names and world information are transmitted as notification content. As for notifications of players joining and leaving, the notification itself is disabled by default and, when enabled, targets only your friends by default; however, if you change the target to non-friends or to everyone in the settings, the display names of people who are not your friends (people who merely happened to be in the same instance) are also transmitted.
Of the above, information is saved as a record only if you have enabled the feature described in Section 1-9. If it is disabled, the information is processed on the spot for display and notifications only and is not saved.
Only the logs of the account you are signed in to in the App are used for on-screen display and notifications. Logs belonging to other accounts are saved as records only, if you have enabled the feature described in Section 1-9; they are never shown on screen or in notifications.
1-8. Automatic Saving of Prints and Stickers
If you enable the automatic saving of prints and stickers, image data is obtained through the VRChat API and saved to a local folder that you specify (if you do not specify one, to VRCPersona\Prints and VRCPersona\Stickers within your Pictures folder, in subfolders created by year and month of capture). The saved data is retained only within your PC and is never transmitted to the Server.
Images saved or displayed by this feature or by the image cache may include copyrighted works created or posted by other users (and captured images may incidentally include the likeness of third parties, etc.). These images are saved only within your PC and are never transmitted to the Server. However, reproduction, publication, provision to third parties, or redistribution that exceeds the scope of private use under copyright law may infringe copyright or other rights. Please use saved images within the scope permitted by law, and handle them at your own responsibility.
1-9. Local Activity Recording (disabled by default; version 1.0.0 and later)
To provide features such as play-time statistics and an activity timeline, and only if you enable it in the settings, records concerning your use of VRChat are saved to a database on your PC (vrcpersona.db). This feature is disabled by default and operates only when you enable it. All records are stored solely within your PC; the developer cannot view them, and they are not transmitted to the Server or any other external destination.
The main content recorded is as follows:
- Your own activity: worlds visited and play time, and events within instances (playback of videos and the like, portal generation, in-game events, etc.). If you use more than one VRChat account on the same PC, activity from accounts you are not signed in to in the App is also saved, together with the VRChat user ID indicating which account each record belongs to
- Records of people who were in the same instance: records of joining and leaving (display name, user ID, date and time, duration of stay). This covers everyone present as output to VRChat's log, regardless of whether they are your friends
- Changes in your friends' situation: changes in friends' online status, movement, status, and profile (avatar, self-introduction, etc.), as well as friends being added or removed, changes of display name, and changes of trust level
- Instance crowding: for the instances where your friends are staying, and for the instance where you yourself are staying, changes over time in the number of people present, the capacity, and the number of people waiting to enter. The App also records an identifier of which instance it is (the world ID, the instance identifier, and the instance name) together with the date and time. It does not retrieve or store a list of the occupants
- The content of notifications received from VRChat (separately from this feature, the notification history is stored on your device as described in Section 3-1, regardless of whether this feature is enabled)
- Content you have entered yourself: memos attached to worlds, avatars, and users, and your local avatar favorites and their categories
- Data imported from the external application VRCX (only if you import it through your own action)
Regarding instance crowding, the App simply records the instance information it already retrieves in order to display your friends' current locations (the number of people present and the capacity, as provided by VRChat). No additional requests are made to VRChat for the purpose of this recording. The App does not retrieve or store a list of who was present. Note that the instance identifier recorded may contain the VRChat user ID of the person who created that instance.
VRChat can be launched with separate profiles at the same time (for example, alongside a sub-account). The App determines which VRChat account each log file belongs to and records them separately by account, so that records do not become mixed while multiple copies of VRChat are running. Only the records of the account you are currently signed in to in the App are displayed on screen, but records of other accounts are also saved to the database on your PC. If you share a single PC with another person and both use the same Windows account, records of that person's use of VRChat may also be saved. All saved records remain solely within your PC and are never transmitted externally.
You can stop recording or completely delete the saved database at any time from the App's settings screen (completely deleting it also deletes the memos and local favorites described above).
1-10. Detection of Running Processes (version 1.0.0 and later)
If you enable "Suppress Windows notifications while XSOverlay is running" in the notification settings, the App refers to the list of processes running on your PC in order to determine whether XSOverlay is running. Only the matching of process names is used for this determination, and this information is processed only within your PC and is never stored or transmitted externally.
In addition, if you have enabled Discord Rich Presence (Section 9-14), and also when you perform the action of joining a friend's instance, the App checks in the same way whether VRChat itself (VRChat.exe) is running. This is so that an incorrect display does not remain while VRChat is not running, and so that the join action can be switched appropriately. This check also involves only the matching of process names, is processed solely within your PC, and is never stored or transmitted externally.
1-11. Album Viewing (Reading the Photo Folder; version 1.0.0 and later)
The album feature reads the photo folder on your PC so that you can browse and view the photos you have taken in VRChat from within the App. The location read is one of the following: (1) a folder you have specified on the settings screen; (2) the save destination described in VRChat's configuration file (%LOCALAPPDATA%Low\VRChat\VRChat\config.json); or (3) if neither is available, VRChat's default save destination (the VRChat folder inside your Pictures folder). The App also reads the Prints and Stickers folders beneath them, as well as the automatic save destination for prints and stickers used by this App (Section 1-8; this can be turned off in the settings). Within the folders that are read, the App searches for image files including those in subfolders. For the purpose of determining the save destination, the App refers to the photo-related items in that configuration file (picture_output_folder and picture_output_split_by_date).
The information read from photo files is as follows. Of these, the world ID, the world name, and the user ID of the person who took the photo are embedded into the image by VRChat at the time of capture (when VRChat's "Save Metadata" setting is enabled). The display name of the person who took the photo (for prints and stickers, its creator) and the date and time of capture are also read from the file name given by VRChat when no embedded information is present. The image resolution, file size, file path, and modification date are obtained from the file itself.
- The ID and name of the world where the photo was taken
- The display name and user ID of the person who took the photo
- The date and time of capture, the image resolution, the file size, and the file path
What is read is saved as an index in a file within the app data folder (album_index.json) in order to speed up list display, together with reduced-size images (thumbnails) for display within the app data folder (album_cache). All of these are stored solely within your PC; the developer cannot view them, and they are not transmitted to the Server or any other external destination. The album feature never uploads the photos themselves to the developer's server. (For uploading images to VRChat through your own action, please refer to Section 9-1.)
For photos in which world information is not embedded in the image (for example, when "Save Metadata" is disabled on the VRChat side, when the photo was taken in a private world, or when the information was lost by passing through image editing software), the App estimates and displays the world by comparing the time of capture against the local activity records (Section 1-9; disabled by default), but only if you have enabled that feature. This estimation is performed only when such records exist, and the fact that it is an estimate is clearly indicated on screen. Similarly, the App may restore and display, from those records, the display names of people who were in the same instance at the time the photo was taken.
Photos may contain works created and posted by other users, or the appearance of other users. As with Section 1-8, you must use them within the scope permitted by law and handle them at your own responsibility.
Thumbnails can be deleted at any time from the settings screen (Album). The index is a file within the app data folder (album_index.json) and can be erased by deleting that file (Chapter 5). In addition, if you move a photo to the Recycle Bin from the album feature, the actual file on your PC is moved to the OS Recycle Bin (this is not complete deletion).
1-12. Records of Consent
When you consent to the Terms of Use, this Privacy Policy, or the handling of data when using server features, we store the type and version (effective date) of the document or matter you consented to, together with the date and time of consent, linked to the account you are signed in with. This is done only to the extent necessary to record the fact of your consent and to determine whether renewed consent is required when the Terms or this Policy are revised. These records are deleted together with the account (Chapter 5).
1-13. VR Overlay (paid feature; disabled by default; version 1.0.0 and later)
If you enable the feature that displays your friend list and the like inside VR, the App connects to SteamVR (OpenVR) in order to determine where to place the display, and refers to the position and orientation of your headset and controllers. In addition, in order to display within VR and on the SteamVR dashboard, the App uses the Windows screen capture facility to capture only the App's own window. It does not capture the screens of other applications or your desktop as a whole.
This information is used only on the spot for display purposes; it is neither stored nor transmitted externally. This is a paid feature and is disabled by default. You can disable it at any time from the settings screen.
1-14. Detecting the VRChat Launch File (version 1.0.0 and later)
To provide the feature for opening a friend's instance, the App refers to the Windows registry (the registration of the vrchat:// protocol handler, and Steam's installation location) in order to determine where the launch program bundled with VRChat (launch.exe) is located. Only the installation path information is referred to; it is processed solely within your PC and is never transmitted externally. You can also specify the path manually on the settings screen (if you specify it manually, that path is saved as a setting).
1-15. Detecting an External App's Database (version 1.0.0 and later)
To let you know that the records described in Section 1-9 can be carried over from the external app VRCX, the App checks whether the database file that VRCX uses by default (on Windows, %APPDATA%\VRCX\VRCX.sqlite3) exists when you open the database screen. This check is also performed when the feature described in Section 1-9 is not enabled.
The check looks only at whether the file is present and how large it is; it does not read the contents of the file. The contents are read only when you choose to import them. The result of this check is processed solely within your PC, and is neither stored nor transmitted externally.
2. Purposes of Use of Data
- Providing VRChat friend management features
- Providing friend group and status features
- License authentication and prevention of fraudulent use
- Stable operation and improvement of the service
- Recording your consent to the Terms and this Policy, and determining whether re-consent is required
We use the collected information only for the above purposes and do not use it for purposes unrelated to providing the App's features, nor do we sell it to third parties.
3. Where Data Is Stored
3-1. The User's PC (Local)
- Cache of VRChat friend information
- Cache of information such as users, worlds, groups, and events (the file tauri_cache.json within the App's cache folder)
- Notification settings (LocalStorage)
- Input history of status messages, and of invite messages and invite requests (LocalStorage; up to 20 entries each for the invite-related ones)
- History of notifications received from VRChat (LocalStorage; up to 500 entries, including the sender's display name, VRChat user ID, and message body, and also stored per signed-in account)
- Local friend groups and world groups and their members (VRChat user IDs) (LocalStorage)
- VRChat authentication token and cookies (files within the app data directory)
- Authentication information and display names for multiple accounts (app data directory)
- Cache of block/mute lists (LocalStorage)
- Local activity records, and the memos and local favorites you have entered yourself (vrcpersona.db / only if the feature is enabled)
- The album index (album_index.json / photo paths, capture dates and times, world information, etc.)
- Album thumbnails and preview images (album_cache)
- Cache of thumbnail images of friends, worlds, avatars, and the like (image_cache within the app data folder; it can be deleted from the settings screen (Storage))
- Session information for the VRCPersona server (a refresh token; it is erased when you log out or when your account is deleted)
- The master key used to encrypt local authentication information (the OS credential store, such as Windows Credential Manager). This encryption is a feature of version 1.0.0 and later. In earlier versions, authentication information is not encrypted and this master key is not created
- The App's operation logs (files in the logs folder; see Section 5-2 for details)
3-2. The Server
- Discord ID and display name
- VRChat user ID and display name
- VRChat link verification information (nonce verification records)
- Friend list
- Friend groups and member information
- Group status (including location information, online state, and the time of the last update)
- License information (BOOTH order number, IP address)
- Refresh token for JWT authentication
- Error reports (only if the user has enabled them)
- Records of consent (the type and version of the document consented to, and the date and time)
The Server operates on Hetzner Cloud (Germany/Finland).
Germany and Finland are EU member states, and the EU General Data Protection Regulation (GDPR) applies. The EU is a region that Japan's Personal Information Protection Commission has recognized as being "at a level equivalent to that of Japan in protecting the rights and interests of individuals" (mutual adequacy recognition between Japan and the EU).
Having understood the personal information protection systems of that region, we implement security control measures such as encryption of communications and access control.
Furthermore, with respect to Hetzner Cloud (operated by Hetzner Online GmbH), which serves as the operating platform for the Server, the developer entrusts the handling of personal data (constituting a data processor under the GDPR) and has concluded a Data Processing Agreement (DPA) pursuant to Article 28 of the GDPR.
4. Provision to Third Parties
We do not provide or sell collected personal information to third parties, except in the following cases:
- When there is a request for disclosure based on laws and regulations
- When the user has given consent
Note that access to the VRChat API uses the user's own authentication information. However, only for the nonce verification during VRChat account linking, the Server's service account is used to retrieve that VRChat user's public profile, of which the pronouns field is used for verification. The retrieved profile information is not stored.
4-1. Entrustment of the Handling of Personal Data
In operating the App, we may entrust part of the handling of personal data to external contractors within the scope necessary to achieve the purposes of use. We exercise necessary and appropriate supervision over such contractors in accordance with the Act on the Protection of Personal Information (APPI, Japan).
Server infrastructure (Hetzner, Germany/Finland): operation of the Server and storage of data
Relay of communications and access analytics (Cloudflare): relaying communications and analyzing access to this website
Operational monitoring notifications (Discord): delivery of operational notifications for the purpose of detecting failures and fraudulent use (the transmitted content may include an internal user identifier of this service, your VRChat user ID, your BOOTH order number, and IP addresses rounded to the network level (for IPv4 only the last octet is masked; for IPv6 only the first three groups are kept); it does not include names, email addresses, display names, or complete IP addresses — see Section 9-11 for details)
Receipt and automated processing of purchase notification emails (Google LLC): receiving purchase notification emails from BOOTH and automatically extracting the order number from them
Of these, those that constitute entrustment do not fall under provision to third parties under Article 27, Paragraph 1 of the APPI, pursuant to Article 27, Paragraph 5, Item 1 of the same Act. The handling of personal data in foreign countries associated with such entrustment and the security control measures therefor are as described in Chapters 3, 12, and 13.
Except in the above cases and cases based on laws and regulations, we do not provide personal data to third parties without the consent of the individual.
5. Data Retention and Deletion
The data stored on the Server has the following retention periods set for each type. Data that exceeds the period is automatically deleted or anonymized.
- Friend list (friend_ids): automatically deleted one day after the last synchronization
- Location information (world ID, instance ID): automatically cleared one hour after the last update (only the world ID and instance ID are erased; the online state and the time of the last update remain)
- Error reports: automatically deleted 30 days after transmission
- IP address at the time of license activation: automatically anonymized 180 days after activation (only the IP address is deleted; the activation record is retained)
- Nonce verification records (unverified): expire 10 minutes after creation and are deleted one day later
- Nonce verification records (verified): automatically deleted 7 days after verification
- Sessions (refresh tokens): expire and are deleted after 30 days
- Records of consent: retained for the life of the account (deleted together with the account)
- Entire user account: the account and related data are automatically deleted 120 days after last use
- Local data: deleted if you select "Delete application data," which is displayed at uninstallation. Because this item is off by default, if you uninstall without selecting it, data may remain in the app data folder (such as %APPDATA%\com.sasaken1102s.vrcpersona). If you select that option,
%LOCALAPPDATA%\com.sasaken1102s.vrcpersona(which holds the items stored in LocalStorage, such as notification settings, input history, notification history, and local groups) is deleted together with the app data folder. If you uninstall without selecting it, please delete both folders manually. In addition, delete the various caches from the settings screen (Storage) — together with the history database in version 1.0.0 and later — and the saved authentication information from the saved account list on the login screen. Album thumbnails (Section 1-11) can also be deleted individually from the settings screen (Album). For the album index (album_index.json), please delete that file within the app data folder. Note that the master key stored in the OS credential store for encryption in version 1.0.0 and later is not deleted by deleting the app data folder or by uninstalling. To remove it completely, delete the App's credential (com.sasaken1102s.vrcpersona / vrcpersona_master_key) from Windows Credential Manager. In addition, if you uninstall without signing out, the authentication token (com.sasaken1102s.vrcpersona / vrchat_auth_token) may also remain in the same place, so please delete it as well
When using server features (Discord linking, friend groups / status sharing, etc.), you are asked to review the handling of data on the in-app consent confirmation screen, and we carry out such processing only if you consent. Storage on the Server, and processing on servers located within Europe (the EU) that the developer uses as a contractor, are described in Section 3-2 and Chapter 13 of this Policy. Even if you do not consent, you can continue to use local features such as VRChat friend management. In addition, transmission of error reports is disabled by default and occurs only if you separately and explicitly enable it. The "consent by use" at the beginning of this Policy means general consent to this Policy as a whole, premised on these individual consents.
You can have data on the Server deleted by contacting us at the address in Chapter 11. In version 1.0.0 and later, you can also delete it yourself, immediately, from the App's settings screen (Settings > General Settings > Account).
5-1. Server Logs and Backups
- Access logs: To ensure security, detect unauthorized access, and investigate failures, the VRCPersona server and the proxy positioned in front of it (Cloudflare) record access logs, including the IP address of the access source, as communications arrive. These logs are rotated by a certain capacity and period and are automatically overwritten and deleted in sequence. We do not use such IP addresses, by themselves, for the purpose of identifying specific individuals.
- Operational monitoring: To ensure stable operation of the service and prevent fraudulent use, at times such as new registrations, license authentication, authentication errors, and concentrations of access, we may send to a monitoring channel managed by the operator the type of event, an internal user identifier of this service, and IP addresses rounded to the country/network level, as well as—depending on the event—your VRChat user ID and your BOOTH order number (this does not include names, email addresses, display names, or complete IP addresses). For details such as the destination and purpose of use, please refer to the section "Notifications for Operational and Security Monitoring" in Chapter 9.
- Backups: For disaster recovery, we take a database backup once a day and retain it for up to 120 days. Even data that has been deleted or anonymized after the respective retention periods described in this Chapter have elapsed may remain in backups within this retention period.
5-2. The App's Operation Logs (Within Your PC; version 1.0.0 and later)
So that you can check the situation yourself when a problem occurs, the App records its operation logs only within your PC. These logs are never transmitted automatically to the developer or to the Server.
- Storage location: the App's log folder (on Windows,
%LOCALAPPDATA%\com.sasaken1102s.vrcpersona\logs). You can open it from "Open log folder" on the settings screen (Settings > General Settings > Troubleshooting) - Recorded content: the scope necessary to trace the course of operation, such as startup and shutdown, success or failure of communications, five-minute counts of WebSocket events and API calls, and the content of errors
- Retention period: up to 30 days. In addition, if the total size exceeds approximately 30 MB, the oldest files are automatically deleted
- How to delete: you can delete them at any time from "Delete logs" on the settings screen (Settings > General Settings > Troubleshooting). You may also delete the log folder above directly
Immediately before being written to a file, the logs pass through automatic masking, and authentication information (cookies, tokens, etc.), email addresses, webhook URLs, search keywords, and file paths containing your PC username are replaced with redaction marks. VRChat user IDs are not recorded, and world IDs and group IDs are shortened to a form that retains only their leading portion.
6. User Rights
- You can have your own data stored on the Server deleted by requesting this at the address in Chapter 11. If your VRChat account has been linked, in version 1.0.0 and later you can also delete it yourself from the App's settings screen (Settings > General Settings > Account). Deleting it also deletes related data such as friend groups, statuses, license activation records, and records of consent
- If you cannot delete it yourself, or if you wish to confirm the content of the data stored, you may request this from the developer
- You can deactivate a paid license yourself from the App's settings screen
- If you do not use the App for 120 days, your account and related data are automatically deleted
- For the procedures for requests such as disclosure, correction, suspension of use, suspension of provision to third parties, and disclosure of records of provision to third parties, as well as the method of identity verification and fees, please refer to Section 12-3
7. Use of Cookies and Access Analytics
- The App itself: uses cookies for VRChat API authentication
- This website: does not use cookies for authentication, advertising, or similar purposes. Note that we use Cloudflare Web Analytics as a cookieless access-analytics tool (see details below).
On this website, we use Cloudflare Web Analytics, provided by Cloudflare, Inc., to understand how the site is used and to improve content. This service does not use cookies or other client-side storage functions, and it collects statistical information such as page views, referral sources, pages viewed, browser, OS, device type, country-level information, and performance metrics. The operator of this site does not use such analytics results for personal identification or for tracking the behavior of individuals. For details, please review the Cloudflare Privacy Policy.
For users in the European Economic Area (EEA), the United Kingdom, or other GDPR-applicable jurisdictions, the legal basis for the above processing is the legitimate interests of the operator of this site in understanding how the site is used and improving it safely and continuously (GDPR Art. 6(1)(f)). Because this analytics does not use cookies and does not perform tracking for the purpose of personal identification, we do not, in principle, obtain consent. The retention period of such analytics data, or the criteria for determining the retention period, follows the retention policy that Cloudflare publishes with respect to that service.
Cloudflare, Inc. is a business located in the United States, and user information may be processed in countries where Cloudflare, Inc. and its affiliates and contractors are located. Where a transfer from the EEA, the United Kingdom, or Switzerland to a third country occurs, it is carried out under the Data Processing Agreement (DPA) concluded with Cloudflare pursuant to Article 28 of the GDPR, the EU Standard Contractual Clauses, the UK Addendum, and other applicable safeguards. If you wish to obtain copies of these, please contact us at the contact address in Section 11. For users' rights of access, deletion, objection, and other rights, please refer to Section 6.
The GDPR/UK GDPR-compliant handling of access analytics on this website is a measure taken in case these regulations apply, in view of the fact that this site may be accessed from all over the world. Such handling is limited to the access analytics of this website; it does not indicate any intention to offer or direct the App (including paid features) to residents of the European Economic Area (EEA), EU member states, or the United Kingdom, and it does not change the restrictions on eligible users set forth in Chapter 1 (Eligible Users) of the Terms of Use.
8. Error Reports
To improve the stability of the App, and only with the user's consent, the App transmits the following information to the Server when an error occurs:
- Type and content of the error
- The stack trace
- Where the error occurred (file path, line number, column number)
- The hierarchy of screen components (the component stack)
- App version
- OS information (User-Agent)
- The screen within the App where the error occurred (the screen path)
- For communication errors, the HTTP status code and HTTP method of the response
- An identifying hash used to group identical errors
Before transmission, we perform sanitization (removal) so that the transmitted data does not include personal information such as your VRChat ID or PC username. In versions earlier than 1.0.0, this processing is applied only to the error content and the stack trace. As a result, other items, such as the path of the file where the error occurred, may still contain your PC username. In version 1.0.0 and later, it is applied to all of the text information transmitted. However, error reports are stored on the Server in association with the account you are logged in with. This is to efficiently deduplicate identical errors and investigate the causes of problems that occur in specific environments.
This feature is disabled by default. A consent confirmation is displayed at first launch, and transmission occurs only if the user explicitly enables it. You can change this at any time from the settings screen (Settings > General Settings > Data Transmission).
Note that the error reports described in this Chapter involve transmission to the Server, and are distinct from the App's operation logs described in Section 5-2 (which are recorded only within your PC and are not transmitted externally).
9. External Transmission (Integration with External Services)
The App and the VRCPersona server transmit data to the following external services for the provision of features and for operation.
9-1. VRChat API (VRChat Inc.)
- Destination: api.vrchat.cloud / pipeline.vrchat.cloud
- Information transmitted: authentication cookies, friend information, profiles, world and instance information, and image data that you have chosen to upload through the App together with any accompanying description and date/time (VRChat+ gallery, icons, emoji and stickers, prints, and images for avatars and worlds that you manage)
- Purpose of use: providing App features such as friend management and status display, and obtaining friends' real-time status
9-2. VRCPersona Server
- Destination: api-vrcpersona.sasaken1102s.net
- Information transmitted: Discord/VRChat user IDs and display names, friend list (the user IDs of all of your VRChat friends; only the IDs of users registered with the App are stored on the Server), the names, colors, and icons of your friend groups and their membership (the VRChat user IDs of the friends you have added to a group; the IDs of people who do not use the App are also stored — see Chapter 14), location information (when sharing status), the body of the status message of a group status (when setting a status), error information (only with consent), BOOTH order number (when authenticating a license), App version information (attached to each request to the Server), and the type, version, and date and time of documents you have consented to
- Purpose of use: user authentication, synchronization of friend data, group status sharing, error tracking, license management, delivery of in-app announcements and link settings, and recording of consent status
In addition to at startup, the App periodically (approximately every 30 minutes) retrieves in-app announcements and link settings automatically from this server while it is running. This retrieval is performed without association with the account you are signed in with, and the only information transmitted is the App version and your source IP address. Even if it cannot be retrieved, the App remains available, as it displays the content stored on your PC.
(This destination is the backend API of the App. For communications to this website (vrcpersona.sasaken1102s.net), please refer to 9-13.)
9-3. Discord API (Discord Inc.)
- Destination: discord.com
- Information transmitted: the parameters of the authorization request (application ID, redirect destination, the scope of permissions requested (identify), and a session identifier), and your own Discord login session held by the browser
- Purpose of use: identifying users through Discord OAuth2 authentication
The authorization code issued after you approve is passed from Discord, via the browser, to the developer's server, which exchanges it with Discord for an access token. The App itself never sends the authorization code to Discord.
9-4. Discord Webhook (only when configured by the user)
- Destination: the Discord Webhook URL configured by the user
- Information transmitted: notification content such as display names (including, depending on your settings, the display names of people other than your friends who happened to be in the same instance), status changes, and world movements
- Purpose of use: providing the notification feature configured by the user
9-5. GitHub (GitHub Inc.)
- Destination: github.com (distribution of update information and update programs)
- Information transmitted: requests to retrieve the update information file and the update program, and the source IP address (this does not include account information or information that identifies an individual)
- Purpose of use: to check whether a new version of the App is available, and to obtain the update program if you choose to update
The App automatically checks for updates at startup (including before you log in) and approximately every 30 minutes while running. GitHub, Inc. is a business located in the United States.
9-6. XSOverlay (Local Communication)
- Destination: local network (UDP, 127.0.0.1)
- Information transmitted: the notification title and body (the body may include the display names of friends or of others who happened to be in the same instance, as well as world names)
- Purpose of use: displaying notifications within VR (only if configured by the user)
9-7. VRChat Image CDN (VRChat Inc.)
- Destination: files.vrchat.cloud / d348imysud55la.cloudfront.net / assets.vrchat.com
- Information transmitted: image retrieval requests (image URLs) and the source IP address
- Purpose of use: obtaining and displaying thumbnail images of friends, worlds, avatars, etc.
(All of these are hosts operated by the same VRChat Inc. as the VRChat API in 9-1.)
9-8. Avatar Name Resolution Service (avtrdb)
- Destination: api.avtrdb.com
- Information transmitted: the avatar's file ID and the source IP address (this does not include account information or information that identifies an individual)
- Purpose of use: to supplementarily query and display the names of avatars in certain formats
9-9. Favicon Retrieval Service (Google LLC)
- Destination: www.google.com (favicon retrieval endpoint)
- Information transmitted: the domain name of a link written in the profile of a VRChat user shown in the App (not limited to your friends; this includes world authors, users you have blocked, and others) or in a group, and the source IP address
- Purpose of use: to display the favicon (icon) of the linked site when showing user or group information
9-10. Google Calendar Integration (only when performed by the user)
- Destination: www.google.com (calendar registration screen)
- Information transmitted: the date and time, title, and description of an event that the user has chosen to add to the calendar
- Purpose of use: to open the registration screen in the browser when the user selects "Add to Google Calendar"
9-11. Notifications for Operational and Security Monitoring (Server-Side)
To ensure stable operation of the service and prevent fraudulent use, when certain events (new registration, license activation, authentication errors, concentrations of access, etc.) occur on the Server, we may send notifications to a monitoring channel managed by the operator (using Discord). This is done, separately from the notification Webhook that you configure yourself (9-4), for the purpose of the operator operating and monitoring the service.
- Destination: a monitoring channel managed by the operator (using the Webhook feature of Discord, Inc.)
- Information transmitted: the type of event, an internal user identifier of this service (a random UUID), IP addresses rounded to the network level (for IPv4 only the last octet is masked; for IPv6 only the first three groups are kept), depending on the event, your VRChat user ID (when VRChat account linking completes or when link verification fails) and your BOOTH order number (when a license is activated or when activation fails), and, when an error occurs on the Server, the type of the error, its message body and stack trace, together with the HTTP method and path of the request concerned (the query string is removed). That path may contain the identifier of the group operated on or a VRChat user ID. This does not include names, email addresses, display names, or complete IP addresses.
- Purpose of use: detecting service failures, preventing fraudulent use and unauthorized access, and security monitoring
This processing is based on the legitimate interest of operating the service safely, and it is not used for tracking or profiling the behavior of users. Discord, Inc. is a business located in the United States, and this information may be processed in the United States. For the handling of the provision of personal data to businesses in the United States, please also refer to Chapter 13.
9-12. Checking the Official VRChat Status (version 1.0.0 and later)
- Destination: status.vrchat.com (VRChat's official status page, provided through Statuspage of Atlassian, Inc. of the United States)
- Information transmitted: status information retrieval requests and the source IP address (this does not include account information or information that identifies an individual)
- Purpose of use: to determine and display whether the issue is a failure or maintenance on VRChat's side when the connection with VRChat is unstable
9-13. VRCPersona Official Website (Retrieving Policy Version Information)
- Destination: vrcpersona.sasaken1102s.net (this website)
- Information transmitted: requests to retrieve version information of the Terms of Use and Privacy Policy, and the source IP address (this does not include account information or information that identifies an individual)
- Purpose of use: to check whether the Terms of Use or Privacy Policy have been revised, and to display in the App a request for re-consent upon revision and advance notice of future revisions
The App automatically retrieves policy version information from this website on startup and also periodically while running (approximately once per hour), so that we can notify you of upcoming revisions before their effective date. Even if it cannot be retrieved, the App remains available, as the determination is made using information stored on your PC. This website is served through the delivery infrastructure (Cloudflare Pages) of Cloudflare, Inc. of the United States. For the handling of the provision of personal data to businesses in the United States, please also refer to Chapter 13, and for access analytics of this website, Chapter 7.
9-14. Discord Rich Presence (only if enabled by the user; version 1.0.0 and later)
- Destination: the Discord application running on your PC (Discord Inc.)
- Information transmitted: the name of the world you are in, the world's thumbnail image URL, the number of people present in that instance and its capacity, the status message you have set in VRChat, your VRChat status (whether Join Me / Active / Ask Me / Busy), the time you entered that instance, the ID of the world you are in (transmitted as a link to the world's page whenever the world name is displayed), and the instance identifier (transmitted in any of the following cases: (a) when you are in a Public or Group Public instance; (b) when the display-content setting is set to always show everything; (c) when the "Invite me" button is enabled (excluding Invite, Invite+, and Private instances). In cases (a) and (b) it is used by Discord to determine who is in the same party and is not shown on Discord's screen; from the identifier sent for this purpose, the VRChat user ID of the person who created the instance is removed. In case (c) it is shown on Discord's screen as part of the button's link URL)
- Purpose of use: to display your VRChat play status on your own Discord profile
This feature is disabled by default, and transmission begins only if you explicitly enable it on the settings screen. Transmission is made to the Discord application running on your PC and does not pass through the developer's server. The Discord application then displays what it receives, via Discord's servers (United States), to your Discord friends and to members of servers you have in common. The developer's server is not part of this path, but that does not mean the content stays within your PC. The handling of the transmitted information is governed by Discord's privacy policy, and the range of people who can see it depends on your own Discord settings (activity privacy settings).
Friends' display names and friends' location information, as well as VRChat login information and authentication tokens, are not included. Information handled on the VRCPersona Server (friend groups, statuses, etc.) is likewise not included. The identifier of a Friends or Friends+ instance contains the VRChat user ID of the person who created that instance; however, when you are staying in an instance created by another user, that person's ID is never transmitted.
Restrictions by instance type
To prevent your location from reaching an unintended audience, the content transmitted is restricted by default as follows.
- Public, Group Public: world name, number of people present, thumbnail image URL
- Friends, Friends+, Group, Group+: world name and number of people present (the thumbnail image URL is not transmitted)
- Invite, Invite+, Private: only "Playing VRChat" (the world name is not transmitted)
These restrictions can be changed from the settings screen. If you select the option to always show everything, then regardless of the instance type—including Invite, Invite+, and Private instances—the same content as for Public above (world name, thumbnail image URL, number of people present, and capacity) is transmitted, together with the world ID and the instance identifier.
Restrictions by VRChat status
While your VRChat status is set to "Ask Me" or "Busy," by default the App does not transmit your current location (world name, image, number of people present) and displays only "Playing VRChat." You can change from the settings screen how far down the status list your location continues to be displayed.
"Invite me" button (disabled by default)
If enabled, a link to VRChat's official instance page (vrchat.com) is displayed in your Discord presence. The App does not send invitations on your behalf, and whether someone can join is governed by VRChat's own access control. This button is not displayed for Invite, Invite+, or Private instances; for Friends and Friends+ instances it is displayed only for instances you created yourself; and it is displayed only when your VRChat status is "Join Me" or "Active." These conditions are not relaxed by the display-content settings described above.
The button's link contains the ID of the world you are in and the instance identifier. For Friends and Friends+ instances, this identifier contains the VRChat user ID of the person who created that instance, and removing it from the link would make the instance impossible to identify. For this reason, the button is displayed only for instances you created yourself, so that the ID contained is your own. While you are staying in an instance created by another user, the button is not displayed.
Other
While streamer mode is enabled, the App does not transmit the world name, the status message, or the status display. While VRChat is not running, the display is cleared. You can disable this feature at any time from the settings screen.
9-15. Local HTTP API for External Tool Integration (paid feature; disabled by default)
For integration with external tools, and only if you enable it on the settings screen, the App opens HTTP endpoints that accept connections solely from within your PC (127.0.0.1), allowing other applications to retrieve information from the App and to send it instructions.
- Destination: an application or web page running on your PC that you have permitted to connect, connecting to a local port (by default 127.0.0.1:11020 for receiving and 127.0.0.1:11021 for sending)
- Information transmitted: friends' VRChat user IDs, display names, online status, status messages, platform, current location (world ID / world name / instance identifier, instance type, region, number of people present, capacity), time spent at the same location, and avatar thumbnail image URLs; the names, colors, icons, and storage location of your friend groups and the IDs of their members; the group status you have set (its color and message body); the content of notifications received from VRChat; and your own user ID, display name, and current location. Depending on the options specified in a request, this may also include detailed user information obtained from VRChat, the VRChat groups a user belongs to, their public worlds, and the list of mutual friends
- Purpose of use: to pass information held by the App to an external tool you have installed (such as a streaming overlay), and to receive instructions from such a tool, for example to change your status
This is a paid feature and is disabled by default. Listening begins only if you explicitly enable it on the settings screen. Listening and responding are completed within your PC (127.0.0.1) and do not pass through the developer's server. However, if the requested information is not held within the App when optional parameters are specified, the App queries the VRChat API (Section 9-1) in response to that request. In addition, in version 1.0.0 and later, the name given by the external tool is appended to the identifying information (User-Agent) that the App sends when it queries VRChat.
Access control differs depending on the version you are using. In version 1.0.0 and later, access requires an authentication token issued by the App; access from browsers is denied entirely by default, and only the origins you add on the settings screen are permitted. In versions earlier than 1.0.0, these controls do not exist. While this feature is enabled, any program running on the same PC, and any web page opened in a browser, may obtain the information above without authentication. Please enable it only in an environment you trust.
The information passed through this feature includes the display names and real-time locations of your friends (including those who do not use the App). In version 1.0.0 and later, handing the authentication token to a third party has the same meaning as handing over that information. Please choose the tools and origins you permit at your own responsibility, and limit them to those you trust.
10. Changes to This Policy
This Policy may be changed in response to amendments to laws and regulations, additions or changes to features, changes in the actual state of operation, and the like.
Any change to the purposes of use is made within the scope that can reasonably be recognized as having relevance to the purposes of use before the change. If we change the purposes of use beyond that scope, newly acquire personal data, expand the scope of provision to third parties or provision to third parties located in foreign countries, or make other changes that have a material effect on users, we will make known the content after the change and the effective date, by the effective date, through appropriate means such as in-app display, this site, or X, and, when required by law, we will obtain consent anew.
Minor changes that do not fall under the above take effect from the time the content after the change is posted on this site.
11. Contact
For inquiries regarding this Policy, please contact us at the following:
- X (Twitter): @sasaken_1102s
- Email: sasakenforpal@gmail.com
12. Matters Concerning Retained Personal Data
12-1. Operator Information
The App is developed and operated by an individual developer (ささけん@). The name and address of the personal information handling business operator under the APPI will be answered without delay upon request from the individual (please contact the inquiry address in Chapter 11).
12-2. Purposes of Use of Retained Personal Data
As set forth in Chapter 2. If you wish to be notified of the purposes of use of retained personal data by which you are identified, you may make a request through the procedure in Section 12-3.
12-3. Requests for Disclosure, Correction, Suspension of Use, etc.
With respect to your retained personal data, you may request notification of the purposes of use, disclosure, correction, addition, or deletion of the content, suspension of use or erasure, suspension of provision to third parties, and disclosure of records of provision to third parties.
- Where to make requests: the inquiry address in Chapter 11
- Identity verification: to prevent impersonation, we may verify that you are the individual using, for example, the Discord account you are logged in with.
- Fees: for requests for notification of the purposes of use and disclosure (including disclosure of records of provision to third parties), we may charge a fee within a reasonable range that takes actual costs into account, per request (other requests such as correction and suspension of use are free of charge).
- Response: after confirming the content of the request, we will respond without delay.
12-4. Measures Taken for Security Control
- Organizational measures: the operator ascertains the status of the handling of personal data and manages records concerning the handling.
- Technical measures: we implement TLS encryption of communications, access control (JWT authentication and privilege management), rate limiting, and hashed storage of refresh tokens, among others.
- Supervision of contractors: we entrust the operation of the Server to Hetzner Cloud (Germany/Finland), select contractors appropriately, and exercise necessary and appropriate supervision.
- Understanding of the external environment: personal data stored on the Server is kept in the EU (Germany and Finland), and we implement security control measures having understood the EU's personal information protection system (the GDPR and the mutual adequacy recognition between Japan and the EU). Because some external services (Cloudflare, Discord, etc.) are located in the United States, the handling of personal data in that country is as described in Chapter 13.
12-5. Where to Lodge Complaints
We accept complaints and consultations regarding the handling of the App's personal information (including retained personal data) at the inquiry address in Chapter 11.
13. Provision of Personal Data to Third Parties Located in Foreign Countries
For the provision of features and for operation, the App and the Server may have businesses in the following countries and regions handle personal data, or may provide personal data to them.
Germany and Finland (EU) — server hosting (Hetzner). The EU is designated, under the rules of Japan's Personal Information Protection Commission, as a region that has a personal information protection system at a level equivalent to that of Japan (the mutual adequacy recognition between Japan and the EU). Therefore, we position handling within the EU as not falling under "provision to a third party located in a foreign country" as referred to in Article 28 of the APPI.
The United States of America
- Cloudflare, Inc. — relay (reverse proxy) of communications to this Server and this website, and access analytics. In connection with the relay of communications, personal data (various IDs, display names, IP addresses, etc.) may be handled along the communication path. Based on the Data Processing Agreement (DPA), Standard Contractual Clauses (SCC), and the like concluded with the company, we endeavor to ensure a system that conforms to the standards prescribed by the rules of the Personal Information Protection Commission.
- Discord, Inc. — authentication via Discord OAuth, and notifications for operational monitoring of the Server (at times such as new registration, authentication errors, and security detection, we send to the operator's monitoring channel the type of event, an internal user identifier of this service, and rounded IP addresses, as well as—depending on the event—your VRChat user ID and your BOOTH order number; this does not include names, email addresses, display names, or complete IP addresses; see the section "Notifications for Operational and Security Monitoring" in Chapter 9).
Because the United States is not designated under the rules of the Personal Information Protection Commission, provision to the above U.S. businesses may be subject to Article 28 of the APPI. If you wish to be provided with an overview of the personal information protection system in the destination country (the United States) and information on the measures taken by the recipient, please contact the contact address in Chapter 11.
Note that, regarding the legal positioning of whether these cross-border transfers constitute entrustment (Article 27, Paragraph 5, Item 1 of the APPI) or provision to a third party located in a foreign country (Article 28 of the same Act), we will scrutinize the descriptions in this section as necessary, in light of future operational circumstances and confirmation by experts.
14. About Information Concerning Friends
Because the App is an application for managing your VRChat friends, in the course of providing its features it handles information such as the display names and online status of your friends (including those who do not use the App). This is used to provide features—such as friend management, notifications, and group display—that enable you yourself to use VRChat more comfortably. In addition, if you enable the local activity recording feature (Section 1-9; disabled by default), the display names and VRChat user IDs of people who were in the same instance as you—including people who are not your friends—are recorded within your PC as the join/leave records output to VRChat's log. In addition, the display names and VRChat user IDs of senders included in notifications received from VRChat (such as friend requests) are stored within your PC as notification history, regardless of whether the feature in Section 1-9 is enabled (see Section 3-1).
Information handled only within your PC: if you enable the local activity recording feature (Section 1-9; disabled by default), the information described in Section 1-9 is recorded only within your PC. This is stored solely within your PC; the developer cannot view it, and it is not transmitted to the Server or any other external destination. You can stop or delete the records at any time through the App's settings or by uninstalling.
In addition, the App records changes over time in the number of people present, the capacity, and the number of people waiting to enter for the instances where your friends are staying (Section 1-9). These are aggregate figures such as the number of people present, together with an identifier of which instance it is; they do not include a list of the occupants (that identifier may contain the VRChat user ID of the person who created the instance). Furthermore, the album feature (Section 1-11) reads and displays the display name and user ID of the person who took a photo, as embedded in the image or as read from the file name (for prints and stickers, the information of their creator), and the estimation of the world and the display of "people who were there with you" are performed by restoring them from the local activity records only if you have enabled that feature. All of these are processed solely within your PC and are not transmitted to the Server or any other external destination.
Information passed to external tools you have permitted: if you enable the local HTTP API for external tool integration (Section 9-15; a paid feature, disabled by default), applications and web pages on your PC that you have permitted to connect can retrieve information such as your friends' display names, online status, and real-time current location (world and instance). The scope of what is passed and the recipients are determined by your own settings. This communication is completed within your PC and does not pass through the developer's server; however, please check with the provider of each tool regarding how the information is handled after it is passed on.
Information transmitted by Discord Rich Presence: the feature described in Section 9-14 does not transmit your friends' display names or location information. The identifier of a VRChat instance may contain the VRChat user ID of the person who created it; however, that ID is removed from the identifier used to determine who is in the same party, and the "Invite me" button is displayed only for instances you created yourself, so that other users' IDs are not conveyed to the audience of your Discord presence.
Information remaining in the App's operation logs: the App's operation logs described in Section 5-2 may, in the course of tracing the operation, record counts of changes in friends' status and identifiers of the worlds and groups where friends are located. These are recorded in a form that does not include friends' display names or VRChat user IDs (identifiers retain only their leading portion), and are stored only within your PC. They are not transmitted externally.
Information handled on the Server: for access control so that only friends can view your status, the App transmits your VRChat friend list (the list of your friends' VRChat user IDs) to the Server. Of the list it receives, the Server stores only the IDs of persons already registered with the App and discards the other IDs without storing them. The stored IDs are automatically deleted one day after the last synchronization. In addition, we retain the VRChat IDs of members you have registered in friend groups.
Requests from friends themselves: This applies not only to friends but also to anyone who was in the same instance as a user of the App. If a friend themselves wishes to confirm or delete information about themselves retained on the Server, please contact the contact address in Chapter 11 (we will respond after verifying identity). Note that, with respect to local records that exist only within a user's PC, the developer cannot technically handle them, so you must contact that user themselves.
15. Target Age
Use of the App requires a VRChat account. VRChat does not permit use by persons under 13 years of age, and the App likewise does not contemplate use by persons under 13. Minors who are 13 or older but under 18 should use the App with the consent of a parent or guardian.