www.sakimura.org Privacy Notice
Revised: July 14, 2026
This Privacy Notice explains how user information is handled on www.sakimura.org (the “Site”) and what information is transmitted from users’ devices to destinations outside the Site.
1. Operator and Contact Information
Operator: Nat Sakimura
Contact: @_Nat on X
Do not include passwords, private keys, tokens, addresses, telephone numbers, email addresses, or other non-public information in public posts on X. If you need to communicate privately, please use X only to let us know that you need to do so.
2. Information Collected and Purposes of Use
The Site collects or processes information to the extent necessary for the following purposes:
- Providing the Site, investigating failures, preventing unauthorized access, and ensuring security
- Accepting and displaying comments and detecting spam
- Delivering translated pages, related content, images, programs, and other materials
- Aggregating view counts for posts and pages and usage of sharing buttons
- Auditing site changes, login attempts, and other administrative operations
- Responding to inquiries and requests for disclosure, correction, deletion, and similar actions
For these purposes, the Site’s web server may record the source IP address, date and time of access, requested URL and query string, HTTP method, response status, User-Agent, Referrer, and similar information in access logs. Ordinary access logs are rotated daily and retained for 45 generations. If logs are separately preserved for disaster recovery or a security investigation, they are retained only for the period necessary for that purpose.
3. External Transmission and External Services
When a page is displayed or a particular feature is used, information may be sent from the browser to the external services listed below. In general, the recipient processes information accompanying HTTP communications, such as the IP address, date and time, User-Agent, Referrer, and the URL accessed or of the resource retrieved.
| Recipient | Purpose of Use | Information That May Be Transmitted and Conditions of Transmission |
|---|---|---|
Automattic / WordPress.com (c0.wp.com, i0.wp.com, etc.) |
Delivery of JavaScript, CSS, and images; related posts; WordPress.com login; administrator notifications; site change history; and VaultPress Backup | Ordinary communications data, pages viewed, and resources retrieved. For related posts, article text, categories, tags, and similar information may be processed by WordPress.com. For Activity Log, information about site changes and administrative operations may be processed by WordPress.com. VaultPress Backup transmits and stores the WordPress database, uploaded files, plugins, themes, settings, and other data. For administrators who are logged in, additional communications may occur with the WordPress.com notifications iframe, Gravatar, s0.wp.com, widgets.wp.com, and other services. |
GTranslate Inc. (GTranslate TDN, tdns5.gtranslate.net, etc.) |
Generating, caching, and delivering translated pages under /en/ and elsewhere |
The translated page URL and query string, IP address, User-Agent, Referrer, HTTP headers, and similar information. Because the GTranslate proxy is technically capable of forwarding cookies, Authorization headers, and request bodies, do not enter confidential information into forms at translated URLs. |
| Akismet / Automattic | Detecting comment spam | Comment text, commenter name, email address, commenter URL, IP address, User-Agent, Referrer, URL of the post receiving the comment, comment type, and other information necessary for spam detection. This occurs only when a comment is submitted. |
| X Corp. | Displaying attribution for X (formerly Twitter) posts and providing links to the original post, sharing function, and contact account | X posts in articles are delivered from the Site as static quotations of text stored on the Site. When a page is displayed, the Site does not load programs, iframes, APIs, or images from X, and the user’s browser does not connect to X. If the user clicks an original-post link, sharing button, or contact link, the user is taken to X. At that point, X may process the IP address, date and time, User-Agent, Referrer, destination URL, cookies, and other information stored in the browser. |
Google LLC / YouTube (youtube.com, youtube-nocookie.com, ytimg.com, googlevideo.com, etc.) |
Playing videos embedded in articles | For articles containing YouTube videos, the Site initially delivers a local thumbnail and play button, and the user’s browser does not connect to YouTube when the page is displayed. If the user operates a play button labeled “Playing this video will connect to YouTube,” an iframe from youtube-nocookie.com and the images, video, and other resources needed to deliver the video are loaded. At that time, Google/YouTube may process the IP address, date and time, User-Agent, Referrer, page displayed, video identifier, cookies, and other information stored in the browser. |
On July 14, 2026, official embeds of X posts on public posts/pages were replaced with static quotation displays delivered from the same origin. The Site now displays only text and source links and does not automatically reproduce or externally reference images hosted on X. Existing YouTube embeds were also changed so that a connection is made only after the playback action described above.
The sharing buttons for Facebook, X, Pinterest, LinkedIn, LINE, and other services, as well as the X contact link in Section 1, are ordinary links. They do not communicate with those services when the page is displayed. The user is taken to the selected service only upon clicking a link. The privacy policy of that service applies after the user navigates to it.
A re-audit using an anonymous browser on July 14, 2026 covered 12 standard pages and observed no communications with Google Analytics, Google/Amazon display advertising, Disqus, stats.wp.com, or pixel.wp.com. In a rendering audit of the bodies of 1,209 public posts/pages conducted the same day, 174 locations in 234 items containing YouTube references had been converted to the local-thumbnail method, and no YouTube iframes or external resource attributes were observed in the initial HTML. Anonymous-browser testing of representative articles containing both Gutenberg embeds and legacy direct iframes also found 0 Google/YouTube communications before playback; connections to youtube-nocookie.com and other services began only after the playback action. For X, the 32 articles contained 59 embeds, which were converted to static quotations, and a full rendering audit confirmed 0 X official scripts, iframes, images, or other X-related resource attributes. After the GTranslate page cache was cleared, representative articles were tested in Japanese on desktop and mobile and in all 8 configured translation languages; both X-related requests and X-related resource attributes numbered 0. This notice will be updated if the services or transmission conditions change in the future.
For details about purposes of use, retention periods, countries of processing, and other matters relating to external services, please consult the documents of the respective companies.
- WordPress.com Privacy Policy
- Jetpack Privacy Center
- GTranslate Privacy Policy
- GTranslate Terms of Service
- Akismet Privacy Policy
- Information Transmitted to Akismet
- X Privacy Policy
- Google Privacy Policy
- YouTube Terms of Service
4. Pages Translated by GTranslate
The Site uses a paid service from GTranslate Inc. to provide translated pages, primarily under /en/. Access to translated pages is processed through GTranslate’s Translation Delivery Network (TDN). GTranslate may retrieve the source page from the Site and cache and deliver the source text or translated result.
For every language configured in GTranslate, the Site applies measures that redirect or block login, administration, API, search, comment submission, and public AJAX routes under translated URLs to the canonical URL before they reach GTranslate. However, these measures do not guarantee coverage of future configuration changes or routes that have not been identified. Do not enter passwords, authentication tokens, confidential information, or personal information into forms or search fields at translated URLs. Use only the canonical /wp-login.php to log in to WordPress.
No GTranslate-specific cookies were observed in a new browser context on public pages. However, if the browser already has first-party cookies for the Site, they may be sent through the GTranslate route as headers of a translation request. The actual fields processed by GTranslate, the retention periods for individual logs and caches, its subprocessors, and the scope of transmission to machine translation providers cannot be determined from the company’s public documents alone.
/sd-jwt-decoder/ is an application that runs in the browser. /en/sd-jwt-decoder/ redirects to the original URL. Testing with a dummy string on July 14, 2026 found no transmission of the entered value through HTTP, Fetch/XHR, Beacon, WebSocket, the console, or an error-reporting service. This does not, however, constitute a recommendation to enter a private key, a real SD-JWT, or personal information.
5. Comments and Akismet
Only logged-in users may post comments, and comments are disabled by default on new posts. However, some existing posts and pages accept comments, and submitted comments, display names, dates and times of posting, and similar information may be made public.
When a comment is submitted, the information described in Section 3 may be sent to Akismet for spam detection. Akismet’s official documentation states that most spam-related data is retained for between 2 weeks and 90 days. To request deletion or correction of a past comment, please contact us using the method in Section 1.
6. Site Search
Because search terms are included in the URL query string as the s parameter, they may remain in browser history, web server logs, and the Referrer. Do not enter confidential or personal information in the search field.
Jetpack Stats was disabled on July 14, 2026. An anonymous-browser re-audit after it was disabled found no transmission of search terms to stats.wp.com, pixel.wp.com, or other third parties. For all languages configured in GTranslate, searches performed at translated URLs are redirected to the canonical Japanese search URL.
7. Local View and Share-Click Counts
To display popular posts and pages, the Site uses local counting provided by NAT Share Buttons and NAT Local Popular Posts. When an ordinary WordPress post or page is displayed, the browser sends a same-origin POST request containing the post ID to /wp-admin/admin-ajax.php on the Site.
The counting database stores the post ID, date, and count, and deletes daily counts older than 32 days. A cumulative view count for each post is retained separately. To limit views of the same post from the same IP address over 1 hours to 1, a one-way-transformed identifier for rate limiting is stored temporarily. Raw IP addresses are not stored in the view-count table, and temporary identifiers expire after approximately 1 hours. Ordinary access logs, however, record the information described in Section 2.
For clicks on sharing buttons, the Site may record the post ID, the name of the destination service, and the date and time of the click. The user navigates to the sharing service upon clicking the link.
8. Cookies and Browser Storage
An audit using new, unauthenticated browser contexts on July 14, 2026 found no cookies on ordinary public pages or translated pages. Ordinary WordPress pages use sessionStorage entry wpEmojiSettingsSupports to detect emoji support.
On the WordPress login page, the following first-party cookies are set to check functionality and support WordPress.com login. After login, WordPress authentication cookies and other cookies are also used.
wordpress_test_cookiejetpack_sso_original_requestjetpack_sso_nonce
You can delete or restrict cookies and stored data through your browser settings, but doing so may prevent login and other functions from operating correctly.
9. Administrative Activity Logs and Backups
The Site uses Jetpack Activity Log and Simple History, which runs on the server, to monitor site changes and conduct security audits.
Simple History may record in the WordPress database the action performed, date and time, user ID, username, email address, anonymized IP address, and other information needed to review events involving posts, pages, media, plugins, themes, settings, users, login attempts, and other administrative operations. Local history is retained for 30 days, and viewing and configuration are restricted to administrators. Detective Mode, which additionally stores detailed request URIs, GET/POST data, User-Agent strings, backtraces, and similar information, is disabled, as are weekly email reports and RSS feeds.
The ordinary functionality of Simple History does not transmit audit logs to external services. Jetpack Activity Log synchronizes events relating to site changes and administrative operations with WordPress.com. VaultPress Backup transmits and stores the WordPress database and site files on Automattic’s systems. Consequently, comments, audit logs, and other WordPress data may remain in backups even after the source data has been deleted. The retention periods and deletion conditions for individual items in VaultPress are governed by the subscription management interface or Automattic’s documentation.
As a separate failure domain, the WordPress database and site files are backed up to the operator’s local NAS every 6 hours. NAS snapshots are created every 6 hours, with retention of the latest 24 hours, 14 daily generations, 8 weekly generations, 12 monthly generations, and the initial baseline snapshot. Encrypted backups to a Google Workspace shared drive are planned but had not begun operation as of July 14, 2026.
10. Security Measures
The Site implements TLS, access controls, security safeguards, spam prevention, log auditing, and other measures. Access to backups is limited to persons and devices for whom it is operationally necessary. However, the security of communications or storage on the internet cannot be guaranteed completely.
Do not enter passwords, private keys, authentication tokens, or other confidential information in comments, searches, forms at translated URLs, or public contact channels.
11. Disclosure, Correction, Deletion, and Other Requests
To request disclosure, correction, addition, deletion, suspension of use, erasure, suspension of provision to third parties, or similar action concerning your information held by the Site under applicable law, please contact us using the method in Section 1. We may confirm the minimum information necessary to verify your identity.
For information held by GTranslate, you may also use the company’s Live Chat or info@gtranslate.net. For information held by Akismet and Automattic, you may also use the contact points listed in their respective privacy policies.
12. Revisions
This notice will be revised in response to changes in services, settings, or laws and regulations. Important changes will be announced on this page.
Revised: July 14, 2026
Revision History
- Initial version: December 15, 2010
- Version 2: July 11, 2012
- Version 3: July 15, 2014
- Version 4: July 14, 2026 — Comprehensive revision of the handling of actual external transmissions, translation, comments, local counting, cookies, audit logs, and backups
- Addendum to Version 4: July 14, 2026 — Added information about transmissions on display caused by embeds of X posts and YouTube videos remaining in past articles, and noted that migration was in progress
- Version 4, Addendum 2: July 14, 2026 — Changed YouTube embeds to use local thumbnails and connect only after a click, and reflected the results of a rendering audit of all public posts/pages
- Version 4, Addendum 3: July 14, 2026 — Replaced official X embeds with local static quotations and reflected the results of testing in all configured languages after clearing the GTranslate cache
