Privacy Policy
Last updated: September 1, 2026 · Effective: September 1, 2026
OFFICE KAMIYA Inc. respects your privacy. This Privacy Policy explains how we collect, use, and handle information in the web application "AWAI."
1. Information We Collect
1-1. Account Information
You can sign in to the Service using either an email address and password, or a Google / Microsoft account via social login. Depending on the sign-in method, we obtain the following information:
- Email address
- Display name
- Firebase UID (authentication identifier)
In addition, when you delete your account we generate and retain a hashed value of your email address and related records for a limited period, so that a registration benefit is not granted twice if you register again (see "7-2. Information retained after account deletion").
1-2. User-Provided Data
- Conversation text (AI conversations, meeting transcripts, etc.)
- Conversation titles
- Meeting audio and camera video (not stored as files — see "2-2")
Conversation text and titles are processed as necessary for providing the Service and stored on our servers.
1-3. Automatically Collected Information
- Usage data (point usage, analysis count) — for quota management
- IP address — temporarily recorded for security purposes (where it forms part of a consent record, it is retained for the period set out in "7-2")
- Browser identification (User-Agent) — for recording consent to these Terms and Policies (see "7-2")
- Browsing information (pages viewed, referrer, device and browser type, approximate location), identifiers such as cookies, and in-service interaction events with their accompanying details (the screen and kind of interaction, conversation and analysis identifiers, error codes, the amount and quantity in a purchase flow, and the like) — for analytics and advertising features (see "5-1")
2. Data Processing
2-1. Text processing
Entered text is sent to and processed by the Google Gemini API for the following purposes:
- Thought structure extraction, classification, and summarization
- Text vectorization (Embedding)
- Cluster analysis and report generation
All of the above processing involves sending text data to the Google Gemini API.
2-2. Meeting audio and video
In the meeting feature, participants' audio and camera video are sent and received through LiveKit Cloud (LiveKit, Inc.), the real-time communication platform.
Audio is sent to the Google Gemini API for transcription and simultaneous interpretation. When interpretation is enabled, the generated interpretation audio is delivered to the other participants through LiveKit Cloud.
We do not store audio or video as files. Audio is processed in real time; what is stored on our servers is the resulting transcript and its analysis. No recording is created, so it cannot be played back later.
We do not configure any reproduction of the speaker's own voice — interpretation audio uses the provider's standard synthetic voice. Speakers are distinguished by the participant ID issued by the communication platform; we do not extract voiceprints or other biometric features from audio.
Transcription and interpretation are generated automatically and we do not guarantee their accuracy.
2-3. How Google handles this data
We use the paid tier of the Gemini API, and data we send is not used to improve or develop Google's models. However, Google retains logs for a limited period for detecting and preventing violations of its usage policies, and for any legally required disclosures.
For details, please review the Gemini API Terms of Service.
3. Sharing and Public Exposure of Diagnosis Results
When a user explicitly generates a share URL, a portion of the thinking type diagnosis result becomes accessible to any third party who knows the URL.
Information that is public via the share URL:
- Diagnosis result card (job name, polarized axes, signature moment, character image, thinking story, kindred minds, fitting roles, etc.)
- Thought node structure (coordinates in 3D space, classifications, relational edges)
- OGP image (preview image for social media sharing)
Information that is not included in the share URL:
- The original conversation text (your input)
- Summary text of each node
- Vector representations (Embeddings)
- Account information (email, display name, etc.)
Share URLs are generated only when the user explicitly performs a share action within the UI. If the corresponding conversation is deleted, the share URL is invalidated at the same time.
4. Payment Processor
Order processing for paid plans is handled by Stripe, Inc. We do not have access to full credit card numbers. We only receive necessary transaction information (name, email, order ID, country). For details on how Stripe handles your payment information, please refer to Stripe's Privacy Policy.
5. External Services We Use and Where Data Goes
We use the following external services to operate the Service:
- Google LLC (United States) — Processing of text and audio (Gemini API). Sent: conversation text, meeting audio
- LiveKit, Inc. (United States) — Real-time communication for meetings. Relayed: audio and camera video. We do not use any recording feature
- Google LLC (United States) — Account authentication (Firebase Authentication). Email address, display name, authentication identifier
- Google Cloud (Japan region) — Servers and database
- Cloudflare, Inc. — Website delivery
- Resend (United States) — Sending notification emails. Email address
- Google LLC (United States) — Analytics and advertising features (Google Tag Manager / Google Analytics / Google Ads). Sent: browsing information, identifiers such as cookies, interaction events with their accompanying details (see "5-1")
For payments, see "4. Payment Processor."
Transfers to providers located outside Japan are made under appropriate safeguards, including standard contractual clauses. You may request a copy of those safeguards, and information about the destination country, its data protection framework, and the measures taken by the recipient, from the contact in "10. Contact."
Other than transfers made in connection with entrusted processing, we do not provide personal data to third parties without your consent. What is sent to Google for analytics and advertising features is as set out in "5-1"; it does not involve providing Google with the personal data we hold (account information or conversation text).
5-1. Analytics and Advertising Features
We use Google Analytics through Google Tag Manager to measure how pages on the Service are viewed. Measurement uses first-party cookies set by Google Analytics (such as _ga).
We also use the following two Google Analytics Advertising Features:
- Google signals — For users who are signed in to a Google account and have turned on Google's "Ads Personalization," their use of the Service is associated with information Google holds about them. As a result, usage across multiple devices and browsers, together with estimated age, gender, and interests, is reflected in our analytics reports.
- Remarketing — We may serve ads on Google's advertising network to people who have visited the Service.
In these features, the first-party cookies (or equivalent identifiers) described above may be used together with third-party cookies (or equivalent identifiers) that Google holds for advertising. The associated information may be used by Google for cross-device analysis and for ads personalization.
What is sent to Google through these features is browsing information, identifiers such as cookies, and in-service interaction events with their accompanying details (the screen and kind of interaction, conversation and analysis identifiers, error codes, the amount and quantity in a purchase flow, and the like); we do not include information that directly identifies you, such as your name or email address. What we see are aggregated reports; we do not receive information from Google that identifies individual users. We do not use or provide the conversation text you enter, or its analysis results, for advertising.
Regions — We do not enable these advertising features for access from the European Economic Area (EEA), the United Kingdom, or Switzerland. Until we have a mechanism in place to obtain your consent, we do not, in those regions, associate data using cookies or similar identifiers, personalize ads, or carry out remarketing. The Google tag does, however, send browsing information (including the URL of the page you are viewing) to Google. Advertising features are enabled for access from other regions.
How to opt out — The following are available. What each one stops differs:
- Turn off "Ads Personalization" in your Google account's Ads Settings (My Ad Center) — the association and ads personalization described above then no longer take place
- Install the Google Analytics Opt-out Browser Add-on — this stops measurement by Google Analytics itself
- Delete or block cookies in your browser settings
For how Google handles this data, see How Google uses information from sites or apps that use our services.
6. Legal Basis for Processing (GDPR/CCPA Compliant)
We process minimal personal data based on "necessity for contract performance" and "legitimate interests." Purposes:
- Providing the Service and account management
- Technical support
- Service improvement
- Advertising measurement and delivery (except access from the EEA, the United Kingdom, and Switzerland; see "5-1")
- Tax and accounting obligations
7. Data Retention and Deletion
Retention periods by data category:
- Meeting audio and camera video: Not stored (processed in real time; no files are created)
- Transcripts and analysis results: While your account is active
- Account information: While your account is active (for handling after deletion, see "7-2")
- Server logs: 30 days (certain administrative activity records: 400 days)
- Browsing information collected by analytics: Per the Google Analytics data-retention setting (not stored on our servers; see "5-1")
- Payment information: Held by Stripe, Inc. (we never hold card numbers)
- Information retained after account deletion: As set out in "7-2" (1 year for the re-registration check and the point-balance restore; 5 years for consent records)
We do not operate any automatic deletion after a fixed period. You can delete conversations, analysis results, and your account at any time from Settings (except transaction records required by tax law).
When you delete data, it is removed from our database immediately (except as set out in "7-2. Information retained after account deletion"). It remains for a limited period in backups kept for disaster recovery, but we do not use those backups for any purpose other than recovery.
7-1. Meeting records
What you say during a meeting is stored as part of that meeting's record. That record is stored under the host's account.
If a participant other than the host deletes their account, the link between their account and their remarks is removed, but the remarks themselves remain as part of the record, so that it does not become incomplete for the other participants (the display name shown during the meeting remains in the record).
If the host deletes their account, the entire record of that meeting is deleted, including the remarks of the other participants.
A meeting's record can be deleted by the meeting's host. If you would like your own remarks deleted, please contact the host of that meeting, or our support desk. We handle such requests individually.
7-2. Information retained after account deletion
Even after you delete your account, the following information is not deleted and is retained for the periods stated below.
To prevent a registration benefit from being granted twice, we retain the account identifier (Firebase UID), a hashed value of the email address, and the deletion date for 1 year from deletion. The hashed value is used solely to check whether a registrant is the same person; we do not retain the original email address itself. We delete these records once the year has passed, after which a new registration becomes eligible for the registration benefit again.
To restore your point balance, and only where you delete your account while a paid plan period is still running, we retain the balance of points granted by the subscription as of the deletion, for 1 year from deletion. It is used to restore that balance if you sign in again with the same account. We delete this record once the year has passed.
To record your consent to these Terms and Policies, we retain the user identifier, the version number and version hash of what you consented to, the date and time of consent, the IP address, and the browser identification (User-Agent) for 5 years. It is used to establish the facts if consent is later disputed.
We do not use these records for any purpose other than those above. If you request deletion, there are cases where we cannot comply, in light of the purposes and retention periods above; in that case, please raise it with the contact in "10. Contact" and we will handle it individually.
We implement industry-standard security measures.
8. Handling of Minors' Data
- The Service is not designed to receive direct data submissions from children under the age of 13.
- When a minor aged 13 to 17 uses the "Guest Mode" feature under direct parental supervision, any conversation text and diagnosis results entered are stored under the supervising parent's (host's) account.
- Control and the right to delete such data reside with the parent. We do not accept disclosure or deletion requests directly from minors; such requests must be made through the parent.
- Parents may delete conversations and diagnosis results generated in Guest Mode at any time, in the same manner as their own data.
9. Your Rights
Depending on your jurisdiction, you have the following rights:
- Access and Data Portability: Download your transcripts and analysis results (thought nodes) in JSON format via the "Export Data" function in Settings. Because a meeting's record is stored under the host's account, meetings you joined as a participant are not included in your own export. If you need that content, please contact the host of the meeting or our support desk
- Rectification: You can request correction of inaccurate information
- Erasure (Right to be Forgotten): You can delete your data via "Delete Account" in Settings. See "7. Data Retention and Deletion" for what deletion covers
10. Contact
OFFICE KAMIYA Inc.
#403 27-1, Matoba, Shimizu-cho, Sunto-gun, Shizuoka-ken, JAPAN 411-0907
Email: [email protected]
Regarding transfers to providers located outside Japan, you may request a copy of the safeguards in place, as well as information on the name of the destination country, the data protection framework of that country, and the measures taken by the recipient, from the contact above.