Member privacy notice
FSR Membership Privacy Notice
1. Who is responsible and how to contact us
Future Stack Reviews is operated by Future Stack LLC (Japanese legal name: 合同会社Future Stack). We are responsible for deciding how membership information is used. Our representative is Takashi Fujino, Representative Member. Our address is Osaka Ekimae No. 2 Building 12-12, 1-2-2 Umeda, Kita-ku, Osaka, Japan.
For membership privacy requests, contact support@future-stack-reviews.com (mailto:support@future-stack-reviews.com). You can use this address without signing in. The company privacy contact, contact@future-stack.co.jp (mailto:contact@future-stack.co.jp), also remains available.
This notice explains membership at future-stack-reviews.com, including registration, sign-in, Saved reading, Watch, data requests and account closure. Read it alongside the FSR Privacy Policy (https://future-stack-reviews.com/privacy/) for public-site use and the Company Privacy Policy (https://future-stack.co.jp/en/privacy/) for the company's common privacy framework. For membership-specific details, use this notice; it does not reduce rights under applicable law. Changes to another company or site policy do not by themselves expand the purposes described here.
2. Information and purposes
Information — Where it comes from and why we use it
Email address, email-verification result, sign-in identifier and authentication information — You and our sign-in provider. These establish control of the email address and connect sign-in to the correct member. Passwords are handled by the authentication service, rather than stored in the FSR membership database.
Internal member identifier, authentication link, account status and relevant times — Our membership service. These maintain the account and enforce its current access status. The authentication link can relate records to a person; it is not anonymous data.
Age declaration, document versions and content references, acceptance and acknowledgement times — Your registration choices and the documents shown to you. These record the eligibility declaration, Terms agreement and Privacy acknowledgement. The ordinary age check does not collect a birth date or identity document.
Session records, provider-issued session credentials, expiry and revocation information, temporary form and sign-in records — Your browser, our service and the authentication provider. These maintain sign-in, protect requests and prevent invalid or repeated actions.
Saved article references and times — Your Saved reading actions. These provide your private reading list and its removal controls.
Followed article, published update references and read/unread state — Your Watch actions and updates published by FSR. These provide your Watch inbox. Watch is not continuous monitoring of all changes at a vendor and does not send email notifications in this release.
Closure requests, authentication-provider identifiers and processing records — Your requests, the linked sign-in account and our handling. These let us stop access, identify the correct authentication record for deletion, record the result, resume interrupted processing and prevent a restored copy from reactivating a closed account.
Support messages, addresses and attachments — What you send and our replies. These let us answer inquiries, verify requests proportionately and resolve problems. Please do not send passwords or authentication codes.
Encrypted recovery copies and limited backup records — Copies of the membership records and supporting configuration needed for controlled recovery, with generation, integrity and processing records. These help us recover after loss without treating a backup as permission to reopen a closed account.
Technical and security records — Requests to FSR and its providers can generate IP addresses, request times, browser or device information and access or error records. These support delivery, fault diagnosis and abuse prevention. Provider records and ordinary membership records have different scopes.
Required authentication and account information is needed to provide membership. If you do not provide it, we cannot create or maintain the account. Save and Watch are optional. The initial free limits are five saved articles and one watched article from the available catalogue. Unlock is not offered in this release. Public articles remain available under their public access conditions.
Membership information is separate from corporate clients' confidential records. Registering does not authorize us to publish your reading list, enroll you in marketing, or use your private member information in a corporate engagement. Privacy acknowledgement is not blanket consent to every kind of processing.
Where a law requires a legal basis, we distinguish providing your requested account and reading tools under the membership agreement; protecting the service and maintaining proportionate evidence for our legitimate interests; and processing required by a specific legal obligation. Our security and recordkeeping interests must be balanced against your rights. A use that requires consent will have a separate choice. Withdrawing that consent does not retrospectively invalidate earlier lawful processing. This paragraph does not turn all processing into consent-based processing.
3. Age and availability
Membership is intended for people aged 18 or over worldwide, where they can legally enter the agreement and we can lawfully provide the service. This condition does not transfer our legal responsibilities to members or certify that every country's requirements are identical. If you believe an ineligible person's information has been collected, contact member support so that we can investigate and apply an appropriate restriction or deletion.
4. Providers and international handling
We use Logto Cloud, operated by Silverhand Inc., for authentication and email verification. For the end-user information it processes on our instructions, Logto describes itself as a processor. Its separate handling of its own business customers' information is described in its Privacy Policy (https://logto.io/terms/privacy-policy) and Data Processing Addendum (https://logto.io/terms/dpa).
Hostinger provides our website and membership database hosting. Member-support correspondence uses Hostinger Premium Business Email. The support address is an alias connected to our existing mailbox. Relevant provider terms are the Hostinger Privacy Policy (https://www.hostinger.com/legal/privacy-policy) and Data Processing Addendum (https://www.hostinger.com/legal/dpa).
Our authentication tenant uses Logto's Japan region. This is a storage-region setting, not a guarantee that all related processing stays in Japan. Logto describes global edge processing and exceptions for security and support. Hosting and email also involve their respective providers and service arrangements. A provider's general list of subcontractors does not mean that every listed company receives every member's information.
We use a dedicated shared drive in our corporate Google Workspace for encrypted membership backups. A dedicated Google service account transfers and checks those files. We encrypt the backup content before upload and keep the recovery key outside that Drive. Google also processes the storage and service metadata needed to provide the service. See Google's Cloud Data Processing Addendum (https://cloud.google.com/terms/data-processing-addendum/). Encryption does not make the information anonymous or remove our responsibilities.
A protected local Mac is used for restricted administration and recovery checks. A recovery copy of the backup key and its context is kept in Apple Passwords for access from authorized Apple devices; the membership archive is not stored there. Apple describes iCloud Keychain synchronization as end-to-end encrypted in its Apple Account and Privacy information (https://www.apple.com/legal/privacy/data/en/apple-id/).
Provider processing may involve countries outside Japan. We do not claim that selecting Japan for authentication places hosting, email, Google storage or all support and security operations in Japan.
For outsourced membership processing involving providers outside Japan, we use contractual data-protection arrangements together with our access, retention and request-handling controls to maintain protection equivalent to that required under Japanese law. We review the arrangements and relevant changes at least annually and when significant changes arise. If continued protection cannot be ensured, we take corrective measures or stop the affected transfer. You may contact member support for information about the arrangements, relevant countries, our checks and any identified obstacles and responses. You may also request any copies of safeguards available under applicable law. We may limit disclosure of sensitive security details while explaining the protections. Accepting the Member Terms is not consent to unspecified overseas transfers.
We may disclose information when required by law or where a lawful, necessary and proportionate response is needed to protect rights, investigate abuse or address a security incident. This is not permission to disclose all member records for an unrelated purpose.
5. Cookies and sign-in
FSR sets the following membership cookies on future-stack-reviews.com. They support requested sign-in and account actions; they are not advertising cookies.
Cookie — Purpose — Browser limit
__Host-FSR_MEMBER_SESSION_V2 — Recognize the signed-in member session — Up to 30 days from sign-in
__Host-FSR_MEMBER_FORM_V3 — Protect a particular form and its submission — 10 minutes
__Host-FSR_MEMBER_LOGIN_FLOW_V2 — Complete registration, sign-in or reauthentication — 5 minutes
These cookies use Secure, HttpOnly and SameSite=Lax protections. Blocking them can prevent membership functions from working. Authentication-provider and other public-site cookies are separate; this table is not an inventory of every cookie used across WordPress, embedded content or provider pages. Public-site processing is covered by the FSR Privacy Policy (https://future-stack-reviews.com/privacy/).
A member session expires after seven days without activity and no later than 30 days after sign-in. Up to five devices can remain signed in. Signing in on another device does not itself sign out an existing device. Data download and account closure require qualifying reauthentication less than 10 minutes earlier. Logout, revocation or account closure can end access sooner. Cookie expiry, loss of permission to use a record and physical deletion of that record are separate events.
6. Retention and deletion
These are normal operating limits for records under FSR's control. We remove information sooner when it is no longer needed and respect any shorter applicable requirement.
Record — Normal retention limit and starting point
Ordinary account and authentication connections, Save and Watch records — As needed during membership; delete as soon as possible and normally within seven calendar days after accepting a verified closure request. Access stops when the request is accepted. Seven days is an upper limit, not a waiting period.
Member sessions and associated credentials — Unusable for FSR access on accepted closure; revoke and remove normally within the same seven calendar days. These are not long-term audit evidence.
Normal security, authentication and connection logs under FSR's control — Up to 30 calendar days from the event.
Ordinary support messages and attachments — Up to 90 calendar days after resolution. We remove unnecessary attachments earlier and review unresolved cases rather than retaining them indefinitely without review.
Minimal agreement and acknowledgement evidence — Up to one calendar year after acceptance of a verified closure request.
Minimal closure and personal-data request handling evidence — Up to one calendar year after the relevant processing is completed.
Normal FSR-managed backups — Up to 30 calendar days after creation, including copies retained for ordinary verification. Restored copies must have deletion and access restrictions reapplied before returning to service.
The backup service is scheduled to create an encrypted recovery copy every six hours. This is an operating schedule, not a guarantee of continuous availability or recovery to an exact point in time. Routine expiry processing removes eligible backups from FSR-controlled storage at the 30-day limit. If a fault or an unresolved operation prevents expiry, we restrict use, investigate and complete the required action; we do not silently change the retention period. Specific preservation holds follow the separate controls below.
If ordinary records are deleted on day seven, the last backup containing them may remain for another 30 days: normally up to 37 days after accepted closure. Evidence kept for a separate purpose follows its own limit. These periods do not promise immediate erasure from every provider backup.
We keep a limited deletion record while it is needed to stop remaining copies from restoring a closed account into use. It contains internal account and authentication-link references, a revocation generation, request and acceptance references, and environment context. It does not contain names, email addresses, reading lists or authentication credentials. Its release depends on accounting for relevant copies and any specific preservation hold; it is not automatically removed merely because another record reaches its retention deadline.
A specific legal obligation, dispute or security incident may require restricted preservation. We document the information affected, purpose, responsible decision, access restrictions, next review and release condition. A hold is not a reason to keep all information indefinitely.
FSR account deletion, deletion of the associated authentication record, and expiry of provider backups are distinct steps. A responsible operator identifies the FSR-related authentication record, checks whether another service would be affected, performs the appropriate provider action and records its outcome. While this work is pending, FSR access remains stopped. A receipt for the FSR request is not confirmation that the provider step has finished. We keep provider identifiers only as needed for that action or a documented preservation requirement, then reduce the record to the minimum evidence needed to explain the result.
Provider-controlled security records and residual copies follow applicable service arrangements and legal obligations. In particular, removing an encrypted file from our Drive does not mean every residual copy in Google's systems disappears at that moment. Google's published data-processing terms describe a separate deletion process. Our FSR retention limits do not, on their own, guarantee that those separate copies expire at the same time. We do not delete an unrelated or shared sign-in account merely because FSR membership closes.
Removing a saved article, signing out and closing your account have different effects. Use account closure (https://future-stack-reviews.com/fsr-member/delete), or contact support if the screen is unavailable. Copies you download and keep yourself are under your control.
7. Security
The membership implementation encrypts its main stored member records and temporary sign-in records, restricts its private configuration files, and keeps deletion records outside the membership database. The Company Privacy Policy (https://future-stack.co.jp/en/privacy/) describes our common security framework and contact route for further information. These statements do not mean every provider copy uses the same storage design. No system can be guaranteed free from security risk.
Only authorized operational access is permitted to the backup storage and recovery material. A verified backup is not automatically returned to service: we must account for later closure and access restrictions before reopening membership. Where that cannot be established, recovered member access remains closed.
We assess suspected incidents and take containment, recovery and notification steps required by the applicable circumstances and law. Please send security or privacy concerns to member support without including passwords or verification codes.
8. Your requests and choices
You can use Your membership data (https://future-stack-reviews.com/fsr-member/data) to download the available member records as fsr-member-data.json. It includes your account status and associations, agreement records, Saved reading, Watch and closure information available to the service. It excludes passwords, session credentials and access tokens. It is not a complete copy of every provider, support or site record, and using it does not replace your right to make a broader request.
Depending on the law that applies, you may request information or access, correction, erasure or cessation of use or disclosure, restriction, portability, or objection to particular processing. You may withdraw consent where processing relies on it and raise a complaint with the competent authority. These rights have legal conditions and exceptions; our retention schedule does not remove them. Japan's authority is the Personal Information Protection Commission (https://www.ppc.go.jp/en/). Where applicable, you may also complain to your local data protection authority.
Contact support even if you cannot sign in or no longer accept a revised agreement. We will seek only verification reasonably needed to protect the person concerned, clarify the request where needed, and explain any decision not to fulfil it fully and the available complaint route. An ordinary email alone does not authorize disclosure or closure. We do not make accepting new Terms a condition of exercising a statutory privacy right.
You may write in your preferred language. We may ask to clarify a translation or continue in English or Japanese. For ordinary inquiries, we aim to send an initial reply within three business days, excluding weekends and public holidays in Japan. Disruptions may delay that initial reply, and resolution may take longer. Statutory deadlines for privacy requests take precedence over this support guideline; where GDPR applies, the normal response period is one calendar month, with an extension only under its applicable conditions and notice requirements.
The membership service does not use your private reading list to make solely automated decisions with legal or similarly significant effects about you. Its automatic controls enforce account status, session security and stated feature limits. If you believe access has been restricted incorrectly, ask member support to review it.
9. Changes
We identify the published version and effective date of this notice and retain published versions in the membership document history (https://future-stack-reviews.com/fsr-member/documents). Material adverse changes affecting membership are normally explained at least 30 days in advance through membership notices (https://future-stack-reviews.com/fsr-member/notices), with the effective date and an opportunity to request data and close the account. An urgent legal or security measure may need to take effect earlier; we explain it as soon as we can lawfully and safely do so.
A notice or continued use does not supply a separate consent that the law requires. We will provide any required further information and obtain any required consent before the corresponding new processing begins.