Privacy Policy

1. Introduction

"M" / TSUNAGI ("we", "us", or "the Service") recognises the importance of protecting personal information and establishes and observes this Privacy Policy.

This Policy applies to the Service as a whole — not only to our website (m3.tsunagi.app, "the Site"), but also to the applications we publish ("the App"; see "9. How the tuning tool handles information") and to the builds of the applications we provide as an owner feature, called WORKS ("the WORKS builds"; see "10. How the WORKS builds handle information").

2. Definition of personal information

▶︎ What counts as personal information

In this Policy, personal information means the following:

  • Name
  • Email address
  • Telephone number
  • Postal address
  • Vehicle Identification Number (VIN)

The VIN is also a value the App reads from the engine control unit (DME) and displays on screen. How the App handles it is set out in "9. How the tuning tool handles information".

3. Purposes of use

▶︎ How we use personal information

We use personal information for the following purposes:

  • Responding to enquiries and providing information
  • Confirming, shipping and supporting products and services
  • Maintaining records of work performed
  • Reference material in blog articles: we may edit and adapt our correspondence with you (the content of enquiries, consultations, and information relating to work performed) into a form in which you cannot be identified — with your name, contact details, VIN and similar withheld — and publish it in our blog articles or other content, in order to inform other customers and improve the Service. If you would prefer your information not to be used in this way, please let us know in advance.
  • Public listing on "MESH" (/mesh): the handle you enter at payment as a Minds contributor, and the workshop name, address, website URL, contact, social account URLs and logo you register as a Masters node, are published on MESH at your request. A social account is only used to work out which service it belongs to, from the URL’s own domain, so that an icon can be shown; we do not connect to any of those services. A listing has no term and continues unless you ask for it to be withdrawn. Your name, email address and payment details are not published. To have a listing withdrawn, contact "17. Contact (data controller)".
  • Vehicle identification number (VIN): you may enter one on the Minds join form, optionally. Neither we nor the payment processor stores the VIN entered on the form itself. It is converted on our side into a value it cannot be recovered from, and only that value is stored. It is used for one thing: recognising several payments as coming from the same person, so the years and the number shown are that person's. The VIN is never published. A VIN contained in a record sent by a WORKS build, by contrast, is stored as it is, with that record (see "10. How the WORKS builds handle information"). The two are never matched against each other.
  • MILEAGE (where the MILE goes): which lines you chose is stored alongside the record of the payment. Only the total and the number of supporters per line are published; who placed how much on what is not. Some lines ask, in a free-text field, which language or which model you would like; what you write there is not published and is used only to see what to build next.
  • Using owner features, and restoring them: those who have bought MILE are given the owners page "Master" and the owners' builds of the apps (the WORKS builds). For that purpose we store the record of the purchase and a "recovery code", which is what restores access on another device. The recovery code is a random value generated by us and contains nothing about you. Only a value derived from it with a key is used for matching, and the copy shown back to you on Master is stored encrypted. So that you can see and remove the devices you use, we store, for each device, its kind (for example "iPhone · Safari") and the date it was last used. The kind is only a name worked out from what the browser sends; what the browser sends is not itself stored. We also store the email address entered at payment, encrypted, with only a value derived from it with a separate key used for matching. The address is used to contact you about your purchase — nothing else. It is never published, and never used for advertising or for a mailing list. Master is kept in a private store and served only after the buyer has been authenticated; it is not published and not registered with search engines.
  • Keeping what the WORKS builds send, and investigating faults: records sent by a WORKS build are stored so that you can open them on your other devices, and are used to investigate faults in the tools and improve them. The details are in "10. How the WORKS builds handle information".
    Note: where a recovery code, or a link for adding a device, is entered, we briefly store a value derived irreversibly from the connecting IP address, together with a count, so that repeated attempts can be limited (for at most two hours). The IP address itself is not stored, and this value is not linked to any other record.

4. Provision to third parties

▶︎ When we disclose

We do not disclose or provide personal information to third parties except in the following cases:

  • Where you have consented
  • Where required by law
  • Publication on MESH (handle, workshop details) is made at your own request and falls under "where you have consented" above.

5. Disclosure, correction, deletion and suspension of use

▶︎ Responding to your requests

Where you request disclosure, correction, addition, deletion or suspension of use of your own personal information, we will verify your identity and respond promptly. Requests should be directed to the contact in "17. Contact (data controller)".

6. Use of cookies (the Site and the WORKS builds)

This section concerns the Site (m3.tsunagi.app) and the authentication of the WORKS builds. The App uses no cookies at all — see "9. How the tuning tool handles information".

▶︎ Cookies we set ourselves

For the purpose of understanding how the Site is used and improving its content, the Site sets cookies issued by Google Analytics 4 (GA4) — those beginning with _ga and _ga_ — on our own domain.
What is recorded is statistical information: which pages were viewed, time on page, referrer, approximate region, and device and browser type. It does not include information that identifies an individual, such as a name or email address.
We do not use it to serve advertising or to identify individual readers on an ongoing basis.
Details, and how to stop this collection, are given in "8. Analytics and advertising (the Site)".

▶︎ Cookies for owner features

For those who have bought MILE, the Site sets an authentication cookie so that the owners' page "Master" and the owners' builds of the apps can be used.
It is issued at the moment you come back to the Site after paying, and at the moment access is added on another device, either with a link handed over from a device that already has it or with the recovery code. It is issued at no other time.
It holds a random value with no meaning of its own — no name, no email address, nothing about what was bought. It is set so that JavaScript cannot read it (HttpOnly) and is never sent to any domain other than this Site.
Its only use is to confirm that this browser belongs to the person who bought. It is never used to follow what you read, to serve advertising, or to match you against any other site.
It expires 180 days after it was last used. You can delete it in your browser settings, or switch it off at any time with "Sign this device out" (この端末の認証を解除) under Devices (端末) on Master. Other devices can be removed from the same Devices list. Deleting the cookie does not take away what you bought, or the right it carries. On another device, or after deleting it, access can be restored at any time with a link handed over from a device that has it, or with the recovery code shown on Master. Restoring does not require you to receive any email.
When a purchase is started, a separate temporary cookie is set to recognise the browser the payment began in (a random value only; it expires after 24 hours), and a note that a payment is in progress is kept in this browser's local storage. The note exists so that, if you close the page after paying, your purchase is still recognised the next time you open the Site; it is removed once the purchase is recognised, when the payment is cancelled, or after 24 hours.

▶︎ Cookies for the WORKS builds

To confirm that a WORKS build is being used by an owner, each WORKS build sets an authentication cookie on its own address, for that address only. It is issued when you first open the WORKS build and the Site confirms your access. It holds only a random value with no meaning of its own, is set so that JavaScript cannot read it (HttpOnly), and is never sent to any address other than that WORKS build's. It expires 180 days after it was last used. Alongside it, a WORKS build sets a temporary cookie while it is confirming with the Site (encrypted random values only; it expires after 10 minutes), and a cookie recording the date the authentication cookie was last renewed. Using "Sign this device out" (この端末の認証を解除) under Devices on Master also ends the WORKS builds' authentication on that device, within a minute. A WORKS build you have already installed keeps opening, and the data on your device stays usable.

▶︎ Cookies set by third parties

If you click an affiliate link in an article, the affiliate service provider (ASP) and the merchant you are taken to may set cookies in order to measure the referral.
Those cookies are controlled by those companies; we neither obtain nor hold their contents.
Cookies can be disabled in your browser settings.

7. Affiliate programmes (the Site)

This section concerns the Site. The App is provided free of charge, and neither the App nor the WORKS builds contain advertising or affiliate links of any kind.

▶︎ Programmes we participate in

The Site participates in the following affiliate programmes, and may receive a referral fee from the merchant when we introduce a product or service:

  • Rakuten Advertising (LinkShare)
  • Rakuten Affiliate
  • A8.net
  • AliExpress Affiliate Program

▶︎ Disclosure and neutrality

  • Articles containing affiliate links carry a "PR" notice at the top of the body text.
  • Affiliate links carry rel="sponsored" for search engines.
  • Which products we feature, and how we assess them, is our own judgement, regardless of whether a referral fee is involved.
  • Purchasing through a link never changes the price you pay.
  • Referral fees received are put towards the research, development and running costs of the Service.

▶︎ Information we receive

Click and conversion data is aggregated by each ASP; what we receive is only the resulting number of conversions and the amounts. We never receive information that identifies a purchaser.

8. Analytics and advertising (the Site)

This section concerns the Site. Neither the App nor the WORKS builds perform analytics or advertising.

▶︎ The analytics tool we use

The Site uses Google Analytics 4 (GA4), an analytics tool provided by Google.
We use it to understand which pages are read and how much, and to improve our articles and site structure.
For this purpose GA4 uses cookies and records the pages viewed, time on page, referrer, approximate region, and device and browser type.
This data is processed statistically and does not include information that identifies an individual, such as a name, email address or telephone number. Nor do we link this data to personal information entrusted to us through enquiries or otherwise.
For how Google handles this data, please see Google's Policies and Terms.

▶︎ If you would rather not be counted

You can stop this collection at any time, by your own action:

  • Install Google's Google Analytics Opt-out Browser Add-on
  • Disable cookies in your browser settings, or browse in private / incognito mode
  • Delete the cookies stored for this site from your browser settings

None of these will impair your ability to read our content.

▶︎ Advertising

The Service does not currently use any advertising service (such as Google AdSense).
If we introduce one in future, we will update this Policy beforehand and state the name of the service and the purpose of its use.

9. How the tuning tool handles information

▶︎ Applications covered

This section applies to the following applications we publish for everyone ("the App"). It does not apply to the WORKS builds, which are covered by "10. How the WORKS builds handle information".

  • MSS54HP CSL CONVERT /// TUNER (https://mss54hp-csl-convert-tuner.tsunagi.app/)
  • The PWA installed from the above to your home screen
  • The Android application wrapping the above (package name app.tsunagi.e46m3.launcher)

The App is provided free of charge and requires no account registration, sign-in or licence activation.

▶︎ All processing happens inside your browser

There is no server or database operated by us behind the App.
The ECU binaries (BIN) and datalogs (CSV) you load, the tuning data you create, and the information read from your vehicle are all processed and stored on your own device, and are never uploaded anywhere — including to us.

▶︎ What is stored on your device

The App creates the following three databases in your browser's IndexedDB. All of them exist only on your own device:

  • mss54hp-tuner-db — tuning sessions: the 64 KB BASE and TUNED ECU binaries, their paired datalogs, VE maps, tune settings, SHA-256 hashes, flash history, and adaptation-reset records
  • mss54hp-tuner-live — a recovery buffer for a datalog in progress (written roughly every 5 seconds, so that an unexpected browser or tab closure does not lose the recording)
  • mss54hp-tuner-backups — backups of the DME service block (16 KB) taken before erasing

It also stores the following two settings in your browser's localStorage. Neither identifies an individual:

  • e46m3csl:disclaimer-ack — whether you accepted the first-run disclaimer and chose not to show it again
  • The zoom level of the map display

▶︎ Information read from the vehicle (DME)

When connected to a vehicle, the App reads the following from the engine control unit (DME) and displays it on screen:

  • Vehicle Identification Number (VIN), AIF records, software number, and write count (flash counter)
  • Operating data while a datalog is being recorded: engine speed, load, short-term fuel trim (STFT), oxygen sensor values, and coolant temperature

As stated above, these are only stored on your device and are never transmitted.
Furthermore, the App does not obtain location, road speed, odometer reading, or diagnostic trouble codes (DTCs).

▶︎ Connecting to the vehicle

The App communicates with the DME over a K+DCAN cable (using the K-line DS2 protocol) via the following standard browser APIs:

  • Web Serial API (primarily on desktop)
  • WebUSB API (primarily on Android)

In both cases a connection is made only when you explicitly select and authorise the device in the dialog your browser presents. You can revoke that permission at any time from your browser settings.
The App does not access Bluetooth, location, camera or microphone.

▶︎ Exports you initiate

The following happen only when you press a button. They are exports on your own device, not transmissions:

  • Downloading a BIN, a datalog CSV, or a service block. The service block filename contains the Vehicle Identification Number (VIN).
  • Copying the parsed service-block report to the clipboard. That content contains the Vehicle Identification Number (VIN).

Storing and sharing the exported files is under your control. Please bear in mind that they contain the VIN if you share them with a third party.

▶︎ Network communication

The only external communication the App performs is a single request to the App's own address, to check whether a newer version exists. That request contains no identifiers and no parameters of any kind.

Accordingly, the App uses no cookies, no analytics, no advertising, no crash reporting, no cloud synchronisation, and no third-party CDNs or scripts.

▶︎ Hosting

The App is served from GitHub Pages (GitHub, Inc.). The ordinary connection records that accompany serving any website (such as IP addresses) are handled under that company's control, and we have no means of accessing them.

▶︎ How to delete your data

All data the App has stored can be erased by clearing the App's site data (IndexedDB and localStorage) from your browser settings. The retention period is under your control; we set none.

▶︎ Disclaimer regarding use of the App

The App erases and writes to the ECU, and may cause serious consequences including immobilising the vehicle. Use is at your own risk, and we accept no liability whatsoever.
Please use tuning only within legally permitted purposes, such as competition and off-road use. Responsibility for compliance regarding public-road use, emissions and safety standards rests with the user.
For details, see the Terms of Service and "12. Disclaimer".

10. How the WORKS builds handle information

▶︎ Applications covered

This section applies to the WORKS builds of the following applications, which we provide to those who hold the owner features (those who have bought MILE, and owners whose cars we have worked on and whom we have confirmed separately):

  • MSS54HP CSL CONVERT /// TUNER — WORKS (https://mss54hp-csl-convert-tuner-preview.pages.dev/)
  • E46M3 /// MONITORING — WORKS (https://e46m3-monitoring-preview.pages.dev/)
  • E46M3SMG2 /// MAPPING — WORKS (https://e46m3smg2-mapping-preview.pages.dev/)
  • MSS54HP CSL CONVERT /// BOOT — WORKS (https://mss54hp-csl-convert-boot-preview.pages.dev/)
  • E46 M35080 /// MIGRATION — WORKS (https://e46-m35080-migration-preview.pages.dev/)
  • The PWA versions of the above, installed by adding them to a home screen

The WORKS builds are under development, and what they contain changes without notice. Their source code is published under the MIT licence.

▶︎ Confirming access

A WORKS build is delivered only after the Site has confirmed that you can use the owner features. The first time you open one, it passes through the Site to confirm this, and an authentication cookie is set on the WORKS build's own address (see "6. Use of cookies"). The confirmation happens when a new version is fetched or updated. Opening a WORKS build you already have, talking to the car, and using the data on your device need no confirmation.

▶︎ What is sent

So that what you save opens on your other devices, and so that faults can be investigated and the tools fixed, the WORKS builds send the following to our server:

  • Sessions you save: sent when you choose to save one (SYNC; UPLOAD in BOOT).
    • TUNER: drive and idle logs, the BASE BIN read and the TUNED BIN written (64 KB), the vehicle identification number (VIN) and the software number
    • MONITORING: fault-memory (DTC) reads, datalogs (engine speed and other running data), the communication log, and the ECU identification (including the VIN)
    • SMG2 MAPPING: the image read from the SMG II ECU, the ZB number, the manufacturer data, the values you edited, and the read log
    • BOOT: the 1 MiB DME backup (including the VIN, the AIF record and the flash counter) and the log of the session
    • M35080 MIGRATION: the cluster EEPROM image (including the last seven characters of the VIN and the mileage) and the backup, rewrite and restore history
  • Error records: sent automatically — by TUNER after each operation, by SMG2 MAPPING after each read and whenever something fails, and by MONITORING, BOOT and M35080 MIGRATION when something fails. They contain the outcome and any error text, the connection type, transfer timings and retries, an excerpt of the communication, and the identifying values above such as the VIN, software number and ZB number. M35080 MIGRATION's error records also carry the mileage and the bridge (Arduino) firmware version. Without a connection they are kept on the device and sent at the next opportunity.
  • Both carry the app version. The browser type (user agent) is added to both by SMG2 MAPPING and BOOT, and to error records only by M35080 MIGRATION; TUNER and MONITORING do not send it.

The first time you open a WORKS build, the WORKS build itself tells you what it sends and why, and sending starts only after you have seen that. No location, name or email address is sent.

▶︎ Purposes of use

  • So that you can open your records on your other devices (saving and restoring)
  • To investigate faults in the tools and improve them

They are not used for anything else. They are never published, sold or used for advertising, and are never linked with information about the use of the App (the public build).

▶︎ Where it is kept, and who can see it

In a database run by Cloudflare, Inc. (D1, Asia-Pacific region), kept separately per account. Only you and the operator can see what is stored; no other user can.

▶︎ Retention and deletion

You can delete saved sessions and error records in the WORKS build at any time. To have everything deleted, or to stop the use of your data, contact "17. Contact (data controller)" or us on Discord; we will verify your identity and act on it. Even if you do not delete them, records are deleted within 90 days of the owner features ceasing to apply to you, or of the WORKS build being withdrawn.

▶︎ What is stored on your device

A WORKS build stores its records on your device (IndexedDB) and keeps up to the 20 most recent error records it could not send. Deleting that WORKS build's site data in your browser settings removes all of it.

▶︎ Hosting

The WORKS builds are served from Cloudflare Pages (Cloudflare, Inc.).

11. Copyright

▶︎ Rights and quotation

Copyright and portrait rights in the content published by the Service (articles, images, video and so on) belong to us or to the rightful rights holders.
Reproduction without permission is prohibited; quotation requires attribution and a link to the Service.
Where there is a problem, we will respond promptly upon contact from the rights holder.

12. Disclaimer

▶︎ Scope of disclaimer

While we strive to provide accurate information, the content published by the Service may contain errors or out-of-date material. All information we provide (data, manuals and so on) is reference material and carries no guarantee of outcome. Any damage arising from work or decisions made on the basis of that information is entirely the user's responsibility.
We accept no responsibility whatsoever for information or services provided by sites reached through links from the Service.
Problems and faults arising from work performed are entirely the user's responsibility. We will, however, cooperate towards a resolution, with any costs so arising borne by the user.
For oils we sell, judging suitability is the user's responsibility, and we accept no responsibility for problems following use. Damage or loss in transit is subject to the carrier's compensation scheme.

13. Security measures

▶︎ Measures to protect personal information

We take the following security measures in order to handle personal information safely:

  • Encryption of communications, by SSL and similar
  • Management of server access privileges
  • Measures to prevent unauthorised access
  • Security training for administrators
  • Records of the owner features and the WORKS builds are kept separately per account, and every read and write checks who is asking, so that nobody but the owner and the operator can reach them

Our processor Cloudflare, Inc. is a company in the United States; the data of the owner features and the WORKS builds is stored in its Asia-Pacific region. We use it having checked that country's arrangements for the protection of personal information.

14. Outsourcing

▶︎ Subcontracting and personal information

We may outsource part of our operations (server management, payment processing and so on) to external contractors.
Where we do, we conclude a confidentiality agreement with the contractor and supervise them appropriately.

Our principal contractors at present are:

  • Payment processing: Stripe (Stripe, Inc. and Stripe Payments Japan K.K.). The payment pages on this site are operated by Stripe; card numbers and other payment details never pass through our servers.
  • Storage and delivery of MESH data: Cloudflare, Inc. (D1 database and R2 storage, Asia-Pacific region). What is stored is the Stripe transaction identifier, the handle, and the workshop name, address, website URL, contact, social account URLs and logo, and anything written in a line's free-text field. No email address is used for the public MESH listing, and none is ever listed there.
  • Storage and delivery of owner features: Cloudflare, Inc. (as above). The record of a purchase, the encrypted recovery code and the value derived from it for matching, the encrypted email address and the value derived from it for matching, the authentication sessions with each device's kind and date of last use, and the value used to match links for adding a device are stored in D1. Master's articles and files are kept in a separate R2 store that is never published, and are served only after authentication. No external email provider is involved in restoring owner features.
  • Delivery of the WORKS builds and storage of their data: Cloudflare, Inc. (Pages and D1, Asia-Pacific region). Each WORKS build's authentication sessions, and the records described in "10. How the WORKS builds handle information", are stored.

15. Children's privacy

▶︎ Collection of information from children under 13

The Service does not knowingly collect personal information from anyone under 13 years of age.
Should any such collection come to light, we will delete it promptly.

16. International users' rights and cross-border transfers

▶︎ Scope

The App is available worldwide. This section sets out matters applying to users resident outside Japan.

▶︎ Cross-border transfers

As set out in "9. How the tuning tool handles information", data handled in the App never leaves your device. Accordingly, no cross-border transfer of personal data by us arises in connection with use of the App.

Only where you browse the Site may statistical information obtained by Google through GA4 be processed by that company in the United States or elsewhere. For details, see "8. Analytics and advertising (the Site)".

Where you use MESH, payment details may be processed by Stripe, and the details published on MESH stored by Cloudflare, in the United States or elsewhere (see "14. Outsourcing"). Where you use a WORKS build, the records it sends are processed by Cloudflare and stored in its Asia-Pacific region (see "10. How the WORKS builds handle information").

▶︎ If you are in the European Economic Area (EEA) or the United Kingdom

Under the GDPR and the UK GDPR you have the right to request access to, rectification of, erasure of, restriction of processing of, and portability of your personal data, to object to processing, and to lodge a complaint with your local supervisory authority.
We hold personal data subject to these rights only where you have provided it to us directly, such as through an enquiry, or where you use the owner features or the WORKS builds. Please direct requests to "17. Contact (data controller)".

▶︎ If you are in California

We do not "sell" or "share" personal information as those terms are used in the CCPA and CPRA.
For rights to know and to delete, please likewise contact us at "17. Contact (data controller)".

17. Contact (data controller)

▶︎ Controller and contact details

Please direct enquiries about this Policy, and requests for disclosure, correction or deletion of personal information, to:

  • Controller: Kazuhiro Muto ("M" / TSUNAGI)
  • Address: 609-1 Shirasu, Hakushu-cho, Hokuto-shi, Yamanashi 408-0315, Japan
  • Email: kazuhiro.mushi@gmail.com

Full business details are given in the Japanese Specified Commercial Transactions Act disclosure.

18. Changes to this Privacy Policy

▶︎ Review and revision

The Service complies with the laws of Japan, and will review and seek to improve this Policy as necessary.
The current version is published on this page as it is revised.

▶︎ Language versions

This Policy is published in Japanese and in English.
In the event of any discrepancy between the two, the Japanese version prevails.