Erlen electronic lab notebook OS

privacy

Privacy policy

How the Erlen sales site (https://erlen.jp) handles the information it collects.

This is a courtesy translation. The Japanese version prevails. (日本語版が正文です) If the two versions differ, the 日本語版プライバシーポリシー is the binding text.

1. What we collect

The only information this site collects today is what you type into the request form for a free setup session (/en/onboarding): your name (required), your email address (required), an optional note about your affiliation or setup, and the time you sent it. It is used to arrange a time and to prepare for the session, nothing else. No automatic confirmation email is sent. (Erlen is free and open source; nothing is sold here.) Information collected through the application form while the product was sold is handled as set out below.

NameRequired. To contact you and to confirm who you are.
Email addressRequired. To send the screening result, the payment link, and the download URL.
AffiliationOptional. Leaving it blank has no effect on screening.
Operating systemRequired. To tailor the setup instructions.
Claude Code experienceRequired. To anticipate where you may get stuck during setup.
Intended use (free text)Required. To judge whether the product fits you, and to improve it.
Answers to the five conditionsRequired. For the automated screening.
Fit check resultOnly if you took the fit check. Only the verdict (fit / conditional / not for you) is carried over.
TimestampRecorded automatically on the server, to keep applications in order.

The answers you give in the fit check (/en/shindan) are never transmitted. The verdict is computed inside your browser, and only that verdict is kept temporarily in the browser.

When the MCP endpoint (/mcp) is used, we record the MCP call log (the tool name and the time). Neither the content nor the arguments of the call are recorded.

This site has no analytics tool installed and uses no advertising cookies. It loads no external fonts and no external scripts.

2. When you sign in to the public demo (read-only) with a Google account

The public demo collects information separate from the application form in section 1 when you sign in with a Google account.

Sign-in uses Google's OpenID Connect, requesting only the openid and email scopes. The server receives only the verified email address contained in the ID token Google returns. It does not collect your name, profile picture, or contacts.

We do not store demo users' information in a database (no row is created per user). The only thing stored is a signed session cookie (erlen_session) kept in your browser, containing your email address and an expiry (30 days). It is removed when you sign out, and nothing is left behind on the server side.

This is used only to keep the read-only session alive and, if misuse occurs, to identify it. We do not use it for advertising or marketing email. Signing in to the demo never causes us to send you email.

The lab notebook, reaction tables, and other records shown in the demo are sample data the developer entered. The demo does not allow creating, editing, or deleting records; every write is rejected by the server.

As on any ordinary website, Cloudflare's standard access logs (IP address, timestamp, and URL) are kept for a short period, the same as for the rest of this site.

3. Purpose of use

  • Arranging a time for a free setup session, and preparing for it
  • Scheduling the session (the preferred slots you send from /meeting), writing up what we discussed in a form where no individual can be identified, and asking you to fill in a survey later — all only for people who agreed to it when they applied
  • Keeping the read-only session of the public demo alive
  • Replying when you write to us
  • Important notices to earlier purchasers (defect announcements and the like)
  • Improving the product and the sales pages (aggregated so that no individual is identifiable)

We use it for nothing else. We do not send marketing blasts.

4. Disclosure to third parties

We do not provide or sell the information we collect to third parties. The exceptions are:

  • When disclosure is required by law
  • When it is necessary to protect a person's life, body, or property and consent is hard to obtain

This site does not process payments. We never receive or store credit card details.

5. Storage and processors

Application data is stored in a Cloudflare D1 database that we manage. This site itself also runs on Cloudflare, so Cloudflare, Inc. is involved in storing the information as our infrastructure provider.

We keep the data for 3 years from our last contact with you, and delete it after that.

6. Requesting disclosure, correction, or deletion

On request from the person concerned, we will disclose, correct, or delete the information we hold. Contact us at the address below in a way that lets us confirm your identity. We accept deletion requests even after purchase (note that after deletion we can no longer reissue your download URL).

7. About the data inside Erlen itself

This is separate from this site's policy, but it matters enough to state plainly. The Erlen instance you build after purchase runs only on your own Cloudflare account. Your lab records, attachments, and user information never pass through our servers, and we cannot read or collect them. There is no telemetry built in.

The only outbound connections Erlen makes are to PubChem (the public API of the US NIH / NLM) when looking up compound information, and to Google's authentication endpoint for login.

8. Contact

For questions about this policy, or to request disclosure or deletion, write to gakushijob@gmail.com.
Business details are in the legal notice.

Established: 16 August 2026 / Last updated: 22 August 2026