Privacy Policy / プライバシーポリシー

Last Updated: September 4, 2026 / 最終更新日: 2026年9月4日

1. Information We Collect / 取得する情報

HishoAI ("the Service") integrates with third-party platforms including Google (including YouTube API Services), TikTok, Meta (Facebook and Instagram), and X (Twitter) via their official APIs. We may collect the following information:

  • Account Information: Email address, name, and authentication identifiers used for login.
  • External Service Integration Data: Access tokens, profile information, page/account identifiers, post and video metadata obtained via APIs when linking with TikTok, Google, Meta (Facebook Pages / Instagram Business), and X.
  • Messaging Data: When the operator connects Meta or X messaging permissions, direct messages, message attachments, sender identifiers (PSID / IGSID / user IDs), and message timestamps sent to the operator's Facebook Page or Instagram Business account are received and stored for internal communication management.
  • Usage Data: Log information and access statistics for service improvement.
  • Cookies and local storage: The Service uses only strictly necessary cookies and browser storage to keep you signed in (authentication session tokens) and to remember interface preferences. The Service does not use advertising or third-party tracking cookies.

HishoAI(以下「本サービス」といいます)は、Google(YouTube API Services を含む)、TikTok、Meta(Facebook および Instagram)、X(Twitter)の公式 API を利用しています。本サービスは、以下の情報を取得する場合があります。

  • アカウント情報: ログインに使用するメールアドレス、氏名、認証識別子。
  • 外部サービス連携情報: TikTok / Google / Meta(Facebook Page / Instagram Business)/ X 連携時に、API 経由で取得するアクセストークン、プロフィール情報、Page / アカウント識別子、投稿・動画メタデータ。
  • メッセージデータ: 運営者が Meta または X のメッセージング権限を連携した場合、Facebook Page / Instagram Business アカウント宛に送信されたダイレクトメッセージの本文、添付ファイル、送信者識別子(PSID / IGSID / user ID)、タイムスタンプを、運営者の内部コミュニケーション管理のために受信・保存します。
  • 利用状況データ: サービスの改善を目的としたログ情報やアクセス統計。
  • Cookie およびローカルストレージ: 本サービスは、ログイン状態の維持(認証セッショントークン)と画面設定の記憶に必要な Cookie・ブラウザストレージのみを使用します。広告用 Cookie や第三者のトラッキング Cookie は使用しません。

2. Purpose of Use / 情報の利用目的

Collected information will be used for the following purposes:

  • Providing SNS post scheduling, publishing, and management functions (including uploading videos to, and managing metadata of, the operator's own YouTube channel).
  • Aggregating direct messages received via Meta and X messaging APIs into a single internal management view for the operator.
  • User verification and customer support.
  • Service improvement, bug fixes, and new feature development.

Collected information will not be used for advertising, profiling of message senders, or any purpose other than those listed above.

取得した情報は、以下の目的で利用します。

  • 本サービスによる SNS 投稿の予約・公開および管理機能の提供(運営者自身の YouTube チャンネルへの動画アップロードおよびメタデータ管理を含む)。
  • Meta および X のメッセージング API 経由で受信したダイレクトメッセージを、運営者の内部管理画面に集約して可視化すること。
  • ユーザー本人確認およびカスタマーサポート。
  • サービスの改善、不具合の修正、および新機能の開発。

取得した情報は、広告配信、送信者のプロファイリング、上記以外の目的には使用しません。

3. TikTok Data Usage / TikTok データに関する特記事項

Data obtained via TikTok API is limited to the scope explicitly authorized by the user. This data is used solely to execute video uploads and publishing as instructed by the user and will not be sold or shared with third parties. Temporary data obtained through the TikTok API (such as access tokens) is kept only for the period for which the individual has consented or the minimum period necessary to provide the app's functions, and will be promptly deleted if the user disconnects the integration.

本サービスが TikTok API を利用して取得するデータは、ユーザーが明示的に許可した範囲内に限定されます。これらのデータは、ユーザーによる動画のアップロードおよび公開指示を実行するためにのみ使用され、第三者に販売または提供されることはありません。また、TikTok API を通じて取得した一時的なデータ(アクセストークン等)は、本人の同意がある期間、またはアプリの機能提供に必要な最小限の期間のみ保持し、ユーザーが連携を解除した場合は速やかに削除します。

4. Meta Platform Data Usage / Meta プラットフォームデータに関する特記事項

Data obtained from Meta's platforms (Facebook Pages and Instagram Business accounts) via the Graph API and Messenger Platform is limited to the scope explicitly authorized by the operator who connects the integration. Specifically:

  • Direct messages and attachments received by the operator's Facebook Page and Instagram Business account are stored solely for the operator's internal communication management.
  • Meta data is never sold, transferred, or shared with third parties for advertising, profiling, or any other secondary purpose.
  • Page-scoped user identifiers (PSID) and Instagram-scoped IDs (IGSID) are stored only to associate incoming messages with the corresponding conversation thread.
  • Access tokens are stored encrypted at rest and are revoked immediately upon disconnection of the integration.
  • Message content is retained as described in Section 7 (Data Retention) and is deleted upon request as described in Section 8 (User Rights and Data Deletion).

The Service complies with Meta's Platform Terms and Developer Policies. Any future expansion of Meta data usage will be reflected in this Privacy Policy before activation.

本サービスが Meta のプラットフォーム(Facebook Pages および Instagram Business アカウント)から Graph API・Messenger Platform を通じて取得するデータは、連携を有効化した運営者が明示的に許可した範囲に限定されます。具体的には:

  • 運営者の Facebook Page および Instagram Business アカウント宛に送られたダイレクトメッセージおよび添付は、運営者の内部コミュニケーション管理のためにのみ保存します。
  • Meta から取得したデータを、広告配信、プロファイリング、その他の二次利用目的で第三者に販売・提供・共有することはありません。
  • Page 単位のユーザー識別子(PSID)・Instagram 単位の識別子(IGSID)は、受信メッセージを対応する会話スレッドに紐付ける目的でのみ保存します。
  • アクセストークンは保存時に暗号化し、連携が解除された時点で即時に失効・削除します。
  • メッセージ本文の保持期間については第 7 条(データ保持期間)、削除の請求については第 8 条(利用者の権利およびデータ削除)を参照してください。

本サービスは Meta の Platform Terms および Developer Policies に準拠して運営されます。Meta データの取り扱いを今後拡張する場合は、運用開始前に本ポリシーへ反映します。

5. YouTube API Services Data Usage / YouTube API サービスに関する特記事項

The Service uses YouTube API Services to let the operator manage the operator's own YouTube channel from a single dashboard. By connecting a YouTube account to the Service, you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.

Through YouTube API Services, the Service accesses and stores the following Authorized Data, limited to the scope explicitly granted on the Google consent screen:

  • Channel and video metadata of the connected channel (channel ID, video IDs, titles, descriptions, tags, localizations, privacy status, publish times, thumbnails) — used to display the channel's videos in the dashboard and to let the operator edit and schedule that metadata.
  • Comments and comment threads on the connected channel's videos — used to display, reply to, moderate, and organize viewer comments.
  • Video uploads — video files, titles, descriptions, and privacy/scheduling settings that the operator explicitly submits are transmitted to YouTube to publish videos on the operator's own channel.
  • OAuth access and refresh tokens — used solely to call YouTube API Services on the operator's behalf.

YouTube API data is used only to provide the functions above to the operator who connected the channel. It is not sold, shared with third parties, used for advertising, or used to build user profiles. The Service does not display YouTube data alongside third-party advertising, and does not use YouTube API data to train or improve artificial intelligence or machine learning models.

Storage and refresh: Cached YouTube metadata and comments are refreshed from YouTube API Services or deleted within 30 days. Access tokens are stored encrypted at rest and are retained only while the integration is connected (see Section 7).

Revoking access: You can disconnect the YouTube integration at any time from the Service's YouTube settings page, which deletes the stored tokens. You can also revoke the Service's access to your Google account at the Google security settings page. Data deletion requests are handled as described in Section 8.

The Service complies with the YouTube API Services Developer Policies.

本サービスは、運営者が自身の YouTube チャンネルを一つの管理画面から運用できるようにするため、YouTube API サービスを利用しています。本サービスに YouTube アカウントを連携することにより、利用者は YouTube 利用規約に拘束されることに同意するものとします。Google によるデータの取り扱いについては Google プライバシーポリシーをご参照ください。

本サービスは YouTube API サービスを通じて、Google の同意画面で明示的に許可された範囲に限り、以下のデータにアクセスし保存します。

  • 連携チャンネルのチャンネル・動画メタデータ(チャンネル ID、動画 ID、タイトル、説明文、タグ、多言語設定、公開設定、公開日時、サムネイル)— 管理画面での動画一覧表示、およびメタデータの編集・予約更新のために使用します。
  • 連携チャンネルの動画に付いたコメントおよびコメントスレッド — コメントの表示、返信、管理、整理のために使用します。
  • 動画アップロード — 運営者が明示的に送信した動画ファイル、タイトル、説明文、公開設定・予約設定を、運営者自身のチャンネルへ公開するために YouTube へ送信します。
  • OAuth アクセストークンおよびリフレッシュトークン — 運営者に代わって YouTube API サービスを呼び出す目的にのみ使用します。

YouTube API のデータは、チャンネルを連携した運営者に対して上記の機能を提供する目的にのみ使用します。第三者への販売・提供、広告目的での利用、利用者プロファイルの作成には使用しません。YouTube のデータを第三者広告と並べて表示することはなく、YouTube API のデータを人工知能・機械学習モデルの学習や改善に使用することもありません。

保存と更新: キャッシュした YouTube のメタデータおよびコメントは、30 日以内に YouTube API サービスから再取得するか削除します。アクセストークンは保存時に暗号化し、連携が有効である間のみ保持します(第 7 条参照)。

アクセスの取り消し: 本サービスの YouTube 設定画面からいつでも連携を解除でき、解除時に保存済みトークンを削除します。また、Google のセキュリティ設定ページから本サービスのアクセス権を取り消すこともできます。データ削除の請求は第 8 条の手続きに従って対応します。

本サービスは YouTube API サービス デベロッパー ポリシーに準拠して運営されます。

6. Third-Party Disclosure and Sub-Processors / データの第三者提供および委託先

Personal information will not be sold, rented, or provided to third parties without the user's consent, except as required by law. No third party serves advertisements or content within the Service.

The Service uses the following infrastructure providers ("sub-processors") solely to host, store, and operate the Service. These providers process data on our behalf under their respective data processing terms:

  • Vercel Inc. — application hosting
  • Supabase Inc. — database and authentication
  • Cloudflare, Inc. — CDN, edge runtime, and object storage (R2)
  • Google LLC — Google Drive storage for archived media (when explicitly enabled by the operator), and YouTube API Services for managing the operator's own YouTube channel (see Section 5)

法令に基づく場合を除き、ユーザーの同意なく個人情報を第三者に販売・賃貸・提供することはありません。本サービス内で第三者が広告やコンテンツを配信することはありません。

本サービスは以下のインフラ事業者(委託先)を利用してサービスをホスト・保存・運用しています。これらの事業者は各社の利用規約・データ処理規約に基づいて、本サービスのためにのみデータを処理します。

  • Vercel Inc. — アプリケーションホスティング
  • Supabase Inc. — データベースおよび認証
  • Cloudflare, Inc. — CDN・Edge ランタイム・オブジェクトストレージ(R2)
  • Google LLC — アーカイブメディアの Google Drive 保存(運営者が明示的に有効化した場合のみ)、および運営者自身の YouTube チャンネル管理のための YouTube API サービス(第 5 条参照)

7. Data Retention / データ保持期間

The Service retains data for the following periods:

  • Account data: Retained for as long as the account is active. Deleted within 30 days after account closure.
  • External service access tokens: Retained only while the integration is connected. Revoked and deleted immediately upon disconnection.
  • Message content and metadata (Meta / X DMs): Retained while operationally necessary for the operator's internal communication management. Deleted within 30 days of a verified deletion request (see Section 8).
  • YouTube API data (cached metadata and comments): Refreshed from YouTube API Services or deleted within 30 days.
  • Server logs: Retained for up to 90 days for security and debugging purposes, then deleted automatically.

本サービスは以下の期間データを保持します。

  • アカウントデータ: アカウントが有効である間保持します。アカウント解約後 30 日以内に削除します。
  • 外部サービスのアクセストークン: 連携が有効である間のみ保持します。連携解除時に即時失効・削除します。
  • メッセージ本文およびメタデータ(Meta / X の DM): 運営者の内部コミュニケーション管理のために運用上必要な期間保持します。第 8 条に基づく削除請求を確認後、30 日以内に削除します。
  • YouTube API データ(キャッシュしたメタデータ・コメント): 30 日以内に YouTube API サービスから再取得するか削除します。
  • サーバーログ: セキュリティおよびデバッグ目的で最長 90 日間保持し、その後自動削除します。

8. User Rights and Data Deletion / 利用者の権利およびデータ削除

Users and individuals whose personal data is processed by the Service have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right of correction: Request correction of inaccurate or incomplete data.
  • Right of deletion: Request deletion of your personal data.
  • Right to withdraw consent: Disconnect any external integration at any time through the Service's settings or by contacting us.

To request deletion of your data, please send an email to [email protected] with the subject line "Data Deletion Request" and include:

  • The platform (Facebook Page, Instagram Business, X, YouTube, etc.) on which you contacted us.
  • Your identifier on that platform (page name, Instagram handle, X handle, etc.).
  • An approximate date range of the messages you wish deleted, or "all messages" if applicable.

We will verify the request and complete deletion within 30 days. Confirmation will be sent to the email address from which the request was made.

本サービスにより個人データを処理される利用者および第三者は、以下の権利を有します。

  • アクセス権: 当方が保持するご本人の個人データの開示請求。
  • 訂正権: 不正確または不完全なデータの訂正請求。
  • 削除権: 個人データの削除請求。
  • 同意撤回権: 本サービスの設定画面または下記連絡先より、いつでも外部連携を解除できます。

データの削除を請求される場合は、[email protected] 宛にメールでご連絡ください。件名を「Data Deletion Request」または「データ削除請求」とし、本文に以下をご記載ください。

  • 当方にコンタクトされたプラットフォーム(Facebook Page、Instagram Business、X、YouTube 等)。
  • 当該プラットフォーム上のご本人の識別子(Page 名、Instagram ハンドル、X ハンドル等)。
  • 削除を希望するメッセージのおおよその期間、または「全件」。

請求内容を確認のうえ、30 日以内に削除を完了し、請求元のメールアドレスへ完了通知をお送りします。

9. Data Security / セキュリティ

The Service implements appropriate technical and organizational security measures to prevent unauthorized access, leakage, loss, or alteration of information. These include encryption of access tokens at rest, transport encryption (TLS) for all API traffic, and access controls on administrative interfaces.

本サービスは、不正アクセス・漏洩・紛失・改ざんを防止するため、技術的および組織的な適切なセキュリティ対策を講じます。具体的にはアクセストークンの保存時暗号化、すべての API 通信における TLS による暗号化、管理画面へのアクセス制御を含みます。

10. Children's Data / 未成年者のデータ

The Service is intended for use by business operators and is not directed to children under 13 (or under 16 in jurisdictions where that age applies). We do not knowingly collect personal data from children. If you believe a child has provided personal data to the Service, please contact us so we can delete it.

本サービスは事業者の利用を想定しており、13 歳未満(該当法域では 16 歳未満)の児童を対象としていません。児童から個人データを意図的に取得することはありません。万一、児童のデータが本サービスに含まれていることが判明した場合は、下記の連絡先までご連絡いただければ削除いたします。

11. Changes to This Policy / 本ポリシーの変更

We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last Updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

本ポリシーは適宜更新されることがあります。重要な変更があった場合は、ページ上部の「最終更新日」を更新します。改定後の継続利用は、改定後のポリシーへの同意とみなされます。

12. Contact Us / お問い合わせ

For inquiries regarding this Privacy Policy, data subject rights requests, or data deletion requests, please contact:
Email: [email protected]

本サービスおよびプライバシーポリシーに関するお問い合わせ、データ主体の権利行使請求、データ削除請求については、以下のメールアドレスまでご連絡ください。
メールアドレス: [email protected]

Back to Login / ログイン画面に戻る