Privacy Policy / プライバシーポリシー

Last Updated: June 28, 2026 / 最終更新日: 2026年6月28日

1. Information We Collect / 取得する情報

HishoAI ("the Service") integrates with third-party platforms including Google, TikTok, Meta (Facebook and Instagram), and X (Twitter) via their official APIs. We may collect the following information:

  • Account Information: Email address, name, and authentication identifiers used for login.
  • External Service Integration Data: Access tokens, profile information, page/account identifiers, post and video metadata obtained via APIs when linking with TikTok, Google, Meta (Facebook Pages / Instagram Business), and X.
  • Messaging Data: When the operator connects Meta or X messaging permissions, direct messages, message attachments, sender identifiers (PSID / IGSID / user IDs), and message timestamps sent to the operator's Facebook Page or Instagram Business account are received and stored for internal communication management.
  • Usage Data: Log information and access statistics for service improvement.

HishoAI(以下「本サービス」といいます)は、Google、TikTok、Meta(Facebook および Instagram)、X(Twitter)の公式 API を利用しています。本サービスは、以下の情報を取得する場合があります。

  • アカウント情報: ログインに使用するメールアドレス、氏名、認証識別子。
  • 外部サービス連携情報: TikTok / Google / Meta(Facebook Page / Instagram Business)/ X 連携時に、API 経由で取得するアクセストークン、プロフィール情報、Page / アカウント識別子、投稿・動画メタデータ。
  • メッセージデータ: 運営者が Meta または X のメッセージング権限を連携した場合、Facebook Page / Instagram Business アカウント宛に送信されたダイレクトメッセージの本文、添付ファイル、送信者識別子(PSID / IGSID / user ID)、タイムスタンプを、運営者の内部コミュニケーション管理のために受信・保存します。
  • 利用状況データ: サービスの改善を目的としたログ情報やアクセス統計。

2. Purpose of Use / 情報の利用目的

Collected information will be used for the following purposes:

  • Providing SNS post scheduling, publishing, and management functions.
  • Aggregating direct messages received via Meta and X messaging APIs into a single internal management view for the operator.
  • User verification and customer support.
  • Service improvement, bug fixes, and new feature development.

Collected information will not be used for advertising, profiling of message senders, or any purpose other than those listed above.

取得した情報は、以下の目的で利用します。

  • 本サービスによる SNS 投稿の予約・公開および管理機能の提供。
  • Meta および X のメッセージング API 経由で受信したダイレクトメッセージを、運営者の内部管理画面に集約して可視化すること。
  • ユーザー本人確認およびカスタマーサポート。
  • サービスの改善、不具合の修正、および新機能の開発。

取得した情報は、広告配信、送信者のプロファイリング、上記以外の目的には使用しません。

3. TikTok Data Usage / TikTok データに関する特記事項

Data obtained via TikTok API is limited to the scope explicitly authorized by the user. This data is used solely to execute video uploads and publishing as instructed by the user and will not be sold or shared with third parties. Temporary data obtained through the TikTok API (such as access tokens) is kept only for the period for which the individual has consented or the minimum period necessary to provide the app's functions, and will be promptly deleted if the user disconnects the integration.

本サービスが TikTok API を利用して取得するデータは、ユーザーが明示的に許可した範囲内に限定されます。これらのデータは、ユーザーによる動画のアップロードおよび公開指示を実行するためにのみ使用され、第三者に販売または提供されることはありません。また、TikTok API を通じて取得した一時的なデータ(アクセストークン等)は、本人の同意がある期間、またはアプリの機能提供に必要な最小限の期間のみ保持し、ユーザーが連携を解除した場合は速やかに削除します。

4. Meta Platform Data Usage / Meta プラットフォームデータに関する特記事項

Data obtained from Meta's platforms (Facebook Pages and Instagram Business accounts) via the Graph API and Messenger Platform is limited to the scope explicitly authorized by the operator who connects the integration. Specifically:

  • Direct messages and attachments received by the operator's Facebook Page and Instagram Business account are stored solely for the operator's internal communication management.
  • Meta data is never sold, transferred, or shared with third parties for advertising, profiling, or any other secondary purpose.
  • Page-scoped user identifiers (PSID) and Instagram-scoped IDs (IGSID) are stored only to associate incoming messages with the corresponding conversation thread.
  • Access tokens are stored encrypted at rest and are revoked immediately upon disconnection of the integration.
  • Message content is retained as described in Section 6 (Data Retention) and is deleted upon request as described in Section 7 (User Rights and Data Deletion).

The Service complies with Meta's Platform Terms and Developer Policies. Any future expansion of Meta data usage will be reflected in this Privacy Policy before activation.

本サービスが Meta のプラットフォーム(Facebook Pages および Instagram Business アカウント)から Graph API・Messenger Platform を通じて取得するデータは、連携を有効化した運営者が明示的に許可した範囲に限定されます。具体的には:

  • 運営者の Facebook Page および Instagram Business アカウント宛に送られたダイレクトメッセージおよび添付は、運営者の内部コミュニケーション管理のためにのみ保存します。
  • Meta から取得したデータを、広告配信、プロファイリング、その他の二次利用目的で第三者に販売・提供・共有することはありません。
  • Page 単位のユーザー識別子(PSID)・Instagram 単位の識別子(IGSID)は、受信メッセージを対応する会話スレッドに紐付ける目的でのみ保存します。
  • アクセストークンは保存時に暗号化し、連携が解除された時点で即時に失効・削除します。
  • メッセージ本文の保持期間については第 6 条(データ保持期間)、削除の請求については第 7 条(利用者の権利およびデータ削除)を参照してください。

本サービスは Meta の Platform Terms および Developer Policies に準拠して運営されます。Meta データの取り扱いを今後拡張する場合は、運用開始前に本ポリシーへ反映します。

5. Third-Party Disclosure and Sub-Processors / データの第三者提供および委託先

Personal information will not be sold, rented, or provided to third parties without the user's consent, except as required by law.

The Service uses the following infrastructure providers ("sub-processors") solely to host, store, and operate the Service. These providers process data on our behalf under their respective data processing terms:

  • Vercel Inc. — application hosting
  • Supabase Inc. — database and authentication
  • Cloudflare, Inc. — CDN, edge runtime, and object storage (R2)
  • Google LLC — Google Drive storage for archived media (when explicitly enabled by the operator)

法令に基づく場合を除き、ユーザーの同意なく個人情報を第三者に販売・賃貸・提供することはありません。

本サービスは以下のインフラ事業者(委託先)を利用してサービスをホスト・保存・運用しています。これらの事業者は各社の利用規約・データ処理規約に基づいて、本サービスのためにのみデータを処理します。

  • Vercel Inc. — アプリケーションホスティング
  • Supabase Inc. — データベースおよび認証
  • Cloudflare, Inc. — CDN・Edge ランタイム・オブジェクトストレージ(R2)
  • Google LLC — アーカイブメディアの Google Drive 保存(運営者が明示的に有効化した場合のみ)

6. Data Retention / データ保持期間

The Service retains data for the following periods:

  • Account data: Retained for as long as the account is active. Deleted within 30 days after account closure.
  • External service access tokens: Retained only while the integration is connected. Revoked and deleted immediately upon disconnection.
  • Message content and metadata (Meta / X DMs): Retained while operationally necessary for the operator's internal communication management. Deleted within 30 days of a verified deletion request (see Section 7).
  • Server logs: Retained for up to 90 days for security and debugging purposes, then deleted automatically.

本サービスは以下の期間データを保持します。

  • アカウントデータ: アカウントが有効である間保持します。アカウント解約後 30 日以内に削除します。
  • 外部サービスのアクセストークン: 連携が有効である間のみ保持します。連携解除時に即時失効・削除します。
  • メッセージ本文およびメタデータ(Meta / X の DM): 運営者の内部コミュニケーション管理のために運用上必要な期間保持します。第 7 条に基づく削除請求を確認後、30 日以内に削除します。
  • サーバーログ: セキュリティおよびデバッグ目的で最長 90 日間保持し、その後自動削除します。

7. User Rights and Data Deletion / 利用者の権利およびデータ削除

Users and individuals whose personal data is processed by the Service have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right of correction: Request correction of inaccurate or incomplete data.
  • Right of deletion: Request deletion of your personal data.
  • Right to withdraw consent: Disconnect any external integration at any time through the Service's settings or by contacting us.

To request deletion of your data, please send an email to [email protected] with the subject line "Data Deletion Request" and include:

  • The platform (Facebook Page, Instagram Business, X, etc.) on which you contacted us.
  • Your identifier on that platform (page name, Instagram handle, X handle, etc.).
  • An approximate date range of the messages you wish deleted, or "all messages" if applicable.

We will verify the request and complete deletion within 30 days. Confirmation will be sent to the email address from which the request was made.

本サービスにより個人データを処理される利用者および第三者は、以下の権利を有します。

  • アクセス権: 当方が保持するご本人の個人データの開示請求。
  • 訂正権: 不正確または不完全なデータの訂正請求。
  • 削除権: 個人データの削除請求。
  • 同意撤回権: 本サービスの設定画面または下記連絡先より、いつでも外部連携を解除できます。

データの削除を請求される場合は、[email protected] 宛にメールでご連絡ください。件名を「Data Deletion Request」または「データ削除請求」とし、本文に以下をご記載ください。

  • 当方にコンタクトされたプラットフォーム(Facebook Page、Instagram Business、X 等)。
  • 当該プラットフォーム上のご本人の識別子(Page 名、Instagram ハンドル、X ハンドル等)。
  • 削除を希望するメッセージのおおよその期間、または「全件」。

請求内容を確認のうえ、30 日以内に削除を完了し、請求元のメールアドレスへ完了通知をお送りします。

8. Data Security / セキュリティ

The Service implements appropriate technical and organizational security measures to prevent unauthorized access, leakage, loss, or alteration of information. These include encryption of access tokens at rest, transport encryption (TLS) for all API traffic, and access controls on administrative interfaces.

本サービスは、不正アクセス・漏洩・紛失・改ざんを防止するため、技術的および組織的な適切なセキュリティ対策を講じます。具体的にはアクセストークンの保存時暗号化、すべての API 通信における TLS による暗号化、管理画面へのアクセス制御を含みます。

9. Children's Data / 未成年者のデータ

The Service is intended for use by business operators and is not directed to children under 13 (or under 16 in jurisdictions where that age applies). We do not knowingly collect personal data from children. If you believe a child has provided personal data to the Service, please contact us so we can delete it.

本サービスは事業者の利用を想定しており、13 歳未満(該当法域では 16 歳未満)の児童を対象としていません。児童から個人データを意図的に取得することはありません。万一、児童のデータが本サービスに含まれていることが判明した場合は、下記の連絡先までご連絡いただければ削除いたします。

10. Changes to This Policy / 本ポリシーの変更

We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last Updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

本ポリシーは適宜更新されることがあります。重要な変更があった場合は、ページ上部の「最終更新日」を更新します。改定後の継続利用は、改定後のポリシーへの同意とみなされます。

11. Contact Us / お問い合わせ

For inquiries regarding this Privacy Policy, data subject rights requests, or data deletion requests, please contact:
Email: [email protected]

本サービスおよびプライバシーポリシーに関するお問い合わせ、データ主体の権利行使請求、データ削除請求については、以下のメールアドレスまでご連絡ください。
メールアドレス: [email protected]

Back to Login / ログイン画面に戻る