This Privacy Policy explains how SolloMi株式会社 ("Sollo," "we," "us," or "our") collects, uses, shares, and protects personal information when you use Menyu, our menu-reading and translation app (the "App"). Menyu is operated by Sollo and is a separate product from the Sollo app and website; this Policy covers Menyu only. For the Sollo app and website, see the Sollo Privacy Policy. This Policy is designed to comply with Japan's Act on the Protection of Personal Information (個人情報の保護に関する法律, the "APPI") and other applicable data protection law. Capitalized terms not defined here have the meaning given in the Menyu Terms of Service.

Sollo is SolloMi株式会社, a company incorporated in Japan on 21 August 2026 (会社法人等番号 0110-01-180064), with its registered office in Shibuya-ku, Tokyo. For the purposes of the APPI, SolloMi株式会社 is the personal information handling business operator (個人情報取扱事業者) responsible for the personal information described in this Policy. Its registered address and representative director are set out in the Contact Us section below and on our Company Information page.

1. Scope of This Policy

This Policy applies to everyone who uses Menyu, wherever they are located. Menyu is built for travelers and residents who need to read a restaurant menu written in a language they do not know. It is used most often away from home.

Menyu does not require an account. When you first open the App it signs in anonymously, which creates an identifier used to keep your own scans separate from everyone else's, and you can use the entire App this way, with no username or password. Everything described below is linked to that anonymous identifier, not to your name, unless you choose to sign in, described next.

If you choose, you can sign in with Apple or Google to create an account. This is optional and never required; declining or skipping it has no effect on what the App does. Signing in shares your email address and, once, your name with us (see Section 2.4).

2. Information We Collect

2.1 Information Created by Using the App

2.2 Information Collected Automatically

2.3 Health-Related Information (要配慮個人情報)

Allergen selections may constitute "Special Care-Required Information" under Article 2(3) of the APPI, because they can indicate a health condition. We collect them only from your own explicit choice to set them, we keep them on your device by default, and we transmit them only in the narrow circumstance described in Section 2.1. Your allergen and dietary selections are never sent to our AI provider. Allergen matching against a menu happens on your device, after the translation comes back.

2.4 If You Sign In

Signing in with Apple or Google is optional; Menyu works fully as a guest without it, as described in Section 1. If you choose to sign in:

Signing out ends your account session and gives the App a fresh anonymous identifier; it does not delete anything you had while signed in (see Section 11).

3. What We Do Not Collect

Menyu does not collect any of the following:

4. How We Use Your Information

5. AI Processing of Menu Photos and Feedback

When you scan a menu, the photograph is sent to our own server and then forwarded to a third-party large-language-model ("LLM") API provider, which reads the text in the image and produces the translated menu. We currently use the Alibaba Cloud Model Studio (DashScope) API, running a Qwen model, for this purpose. Your photograph is transmitted to that provider and processed there to produce the result, under that provider's API terms. We may change which provider or model we use as the product develops; if we do, we will update this Policy to name the new provider.

When you scan a menu, alongside the photograph we send only what the model needs to read it well: the language you want the menu translated into, a count of the text lines our on-device text recognizer found, the language the text appears to be in, and the country you are in. Separately, each night we send a batch of recent usage statistics and feedback text to the same AI provider so it can summarize what has changed. Before it is sent, an automated pattern match replaces email addresses, links, ID-like strings and long runs of digits with placeholders, and the batch does not carry your account, your email address, or the scan a note refers to. That matching is automatic, so it catches the common shapes of these things rather than every one — please do not put personal details in a feedback note. We do not send your allergen selections, your GPS coordinates, your device identifier, or your scan history to the AI provider.

Our own servers, which handle the orchestration around the model, are hosted by a cloud infrastructure provider acting as our service provider for hosting and computing (an "entrustment" under Article 27, paragraph 5(i) of the APPI); that provider processes data on our behalf and does not use it for its own purposes. The LLM API provider described above is a separate company that processes your photograph to generate the result.

A menu photo is an ordinary photo, so anything visible in the frame is uploaded along with it. If you would rather not send your surroundings, frame the shot on the menu itself.

6. Improving Menyu's Accuracy

Reading a photographed menu is error-prone, and the main way we make it better is by studying real scans that went wrong. We therefore retain menu photographs and the results produced from them, and we review them, including by hand, to find misread prices, missed dishes, and incorrect translations, and to check whether a change to the App or to the model actually helped.

We use this material to evaluate and improve Menyu itself. We do not sell it, and we do not supply it to third parties to train their own models. It is sent to our AI provider only in the ordinary course of producing your result, as described in Section 5.

7. Sharing a Menu

Menyu lets you create a link to a translated menu so you can send it to the people you are eating with. This only happens when you ask for it. When you do:

Ordering together at a table. Menyu also lets a host start a table order from a scanned menu that other people join from their own phone's browser, by link, by QR code, or by typing a four-character table code. If you join a table order, the nickname, avatar and any allergies you enter are shared with everyone at that table and deleted within a day of the table closing; the host's phone and the table's staff page show who ordered what. A table closes three hours after it starts, or sooner if the host ends it. Joining a table does not create an account and is not linked to one.

Beyond shared links and table orders, Menyu has no user-to-user features. Nothing you scan is visible to another user unless you create a link or start a table.

8. How We Share Your Information

We do not sell your personal information. We share it only as described below.

9. Cross-Border Data Transfers

Our hosting, storage and AI infrastructure run on servers located outside Japan, menu photographs are transmitted outside Japan to be read, feedback text — including a note left on a thumbs-down rating — is transmitted outside Japan for nightly analysis by the same AI provider (Section 5), feedback you send us or a note on a thumbs-down rating — including any photos — is transmitted outside Japan to be posted to our team's private Discord channel (Section 8), and the feedback form's anti-spam check transmits your IP address and device signals to Cloudflare outside Japan (Section 8). Where this is the case, we rely on one of the mechanisms recognized under Article 28 of the APPI: your consent, given after we disclose the destination country and the protections in place; confirmation that the recipient maintains a personal information protection system equivalent to the APPI, which we monitor at least once a year; or transfer to a country or region recognized by Japan's Personal Information Protection Commission as offering an adequate level of protection. You can ask us at any time, using the contact details in Section 16, which countries our current providers operate in and which of these mechanisms applies.

10. Data Retention

We keep different categories of information for different lengths of time. The table below reflects what our systems actually do today. You can end this early for most categories using the in-App delete control described in Section 11. But deleting does not mean the same thing for every category: some are removed outright, and others are kept, permanently disconnected from you, because we use them in aggregate to improve reading accuracy (Section 6). The table notes which applies; Section 11 explains why.

Category Retention period
Menu photographs Kept until deleted: either by you, using the in-App control (Section 11), or by asking us; deletion removes the photographs outright. Outside of that, we do not currently delete menu photographs automatically, because they are the material we use to improve reading accuracy (Section 6). We are building automatic deletion on a schedule; once it is in place, this Policy will be updated to state the period.
Scanned menus, dishes, prices and translations Kept until deleted, so that your scan history remains available to you and a previously read menu can be recognized again. If you delete your account or data (Section 11), this category is disconnected from your identifier rather than deleted, so we can keep using it in aggregate to improve reading accuracy.
Location recorded with a scan Kept for as long as we keep the menu it belongs to, on the same disconnect-rather-than-delete basis.
Staff-acknowledgement records, including allergens shown Kept until deleted, either by you (Section 11) or by asking us. Because this reflects a health-related choice, deleting it removes the record outright.
Diagnostics for failed or partial scans The diagnostic record is deleted automatically 90 days after it is created, or sooner and disconnected from your identifier if you delete your account or data (Section 11). No photographs are attached to it. If the scan still produced a menu, that menu's photographs fall under the menu photograph row above.
Crash reports Deleted automatically 90 days after they are recorded, or disconnected from your identifier sooner if you delete your account or data (Section 11).
Shared menu links The link expires 24 hours after creation; the frozen copy is deleted 30 days after that, or immediately if you delete your account or data (Section 11).
Table orders (nickname, avatar, allergies, dishes ordered) Deleted within 24 hours of the table closing (a table closes three hours after it starts, or sooner if the host ends it). The table’s own record is kept for 30 days after that, to measure quality: the number of people and dishes, the restaurant name, the menu that was scanned, and the account that started the table. No guest’s nickname, avatar or allergies remain in it.
Usage events and device information Kept until deleted, and used to measure quality and detect abuse. If you delete your account or data (Section 11), we keep this category but remove the device and session identifiers from it, so it can no longer be linked to you.
Feedback messages and photos Feedback records (including any email address you gave us) are deleted automatically 180 days after they are created, or immediately if you delete your account or data (Section 11). Photos attached to feedback are stored in private storage and, like menu photographs, are not otherwise deleted automatically.
Your account (if you signed in): email and name Kept for as long as you keep the account. Deleting your account (Section 11) deletes it outright, including the email address and name a provider shared with us when you signed in.

11. Your Rights and Deleting Your Data

Subject to identity verification and any applicable legal exceptions, you have the right to request disclosure of the personal information we hold about you and the purposes for which we use it; to request correction or deletion of it; to request that we stop using or providing it; to be informed of the categories of cross-border recipients and the protections in place; and to complain to us or to Japan's Personal Information Protection Commission (PPC). If you reside outside Japan you may have additional rights under your local law, such as the GDPR if you are in the EEA or UK, which we will honor to the extent they apply to our processing.

You can delete your data directly in the App, whether you signed in or not. Open Settings and tap Account, then Delete account (or Delete my data, if you never signed in). This is permanent and cannot be undone; there is no grace period. It deletes: your scan history, your feedback (including any email address attached to it), your shared-menu links, your allergen-acknowledgement records, every menu and feedback photograph tied to you, and, if you signed in, your account itself, including the email address and name a provider shared with us. It also clears the App's own local copy of your menus, preferences, and history on your device.

Some data survives deletion, but only in a form that no longer identifies you. The dishes, prices, and translations produced from your scans, plus usage and diagnostic records, are permanently disconnected from your identifier rather than deleted outright, because we use this material in aggregate to keep improving how accurately Menyu reads menus (Section 6). Once disconnected this way, it cannot be linked back to you, reattached to a future account, or singled out as belonging to any one person. Under the APPI and the GDPR alike, information that can no longer identify anyone is treated as anonymized rather than personal information, so it falls outside the deletion right described above.

Because Menyu does not require an account, the information we hold about a guest is linked only to the anonymous identifier the App created on that device; deleting the App does not by itself delete that information, and reinstalling the App can reconnect you to the same records. If you would rather not use the in-App control, or want to confirm what we hold before deciding, contact us using the details in Section 16 and we will act on your request, subject to identity verification.

12. Data Security

Information is transmitted over encrypted connections (HTTPS/TLS). Menu photographs are held in private storage that is not publicly accessible, other than the deliberately shared, expiring copies described in Section 7. Database access is restricted per user so that one user's scans cannot be read by another. No system is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your rights or interests, we will notify you and the PPC as required by applicable law.

13. Children's Privacy

Menyu is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have done so, we will delete it. If you are under the age of majority where you live, please use Menyu with the involvement of a parent or guardian.

14. International Users

Menyu is operated from Japan and is designed to be used while traveling. Wherever you use it, your information will be processed in Japan and, as described in Section 9, in other countries where our service providers operate.

15. Changes to This Policy

We may update this Policy from time to time. If we make a material change, we will provide notice through the App or by other reasonable means before the change takes effect.

16. Contact Us

Questions, requests, or complaints about this Policy or our handling of your personal information can be directed to:

SolloMi株式会社
オーベル代官山DE, 3-4-14 Ebisu-minami, Shibuya-ku, Tokyo, Japan
東京都渋谷区恵比寿南三丁目4番14号 オーベル代官山DE

Representative Director
Tan Jet Son(タン・ジェット・ソン)

Company number (会社法人等番号)
0110-01-180064

Data Protection Contact
info@sollo.my

Supervisory Authority
Personal Information Protection Commission (PPC), Japan
ppc.go.jp

If you are not satisfied with our response, you may file a complaint directly with the PPC.