K
KALENEXPrivacy Policy

Privacy Policy

Last updated: September 26, 2026

Kojinius ("we", "us") provides the calendar management service "KALENEX" ("the Service"). We are committed to respecting your privacy and appropriately protecting your personal information. This policy explains what information we collect, how we use it, and how we protect it.


1. Information We Collect

1-1. Account Information

When you sign in to the Service via your Google account, we obtain the following information:

  • Email address
  • Display name
  • Profile image URL

1-2. Chatwork Integration (Optional)

If you choose to connect Chatwork, we obtain your Chatwork API token. The token is encrypted with AES-256-GCM before storage and is used only for sending notifications and messages. This integration is optional and can be disconnected at any time from the Settings page.

Google Drive Integration (Optional)

We store your connected Google account identifier, email address, granted permissions, and encrypted authentication tokens. Files you select or create through the Service can be linked to tasks and projects, with names and other metadata retrieved using your own Google permissions. When you choose to save an ordinary attachment or deliverable, we copy it to a shared drive allowed by your organization. We do not collect all Drive contents, search across Drive, or use Drive data with AI. Google user data is not used to train general-purpose AI models.

1-4. Business Data

We collect and store the following data as part of your use of the Service:

  • Calendar events (title, date/time, location, description)
  • Task information (title, description, priority, due date)
  • Attached files (images, documents, videos attached to events, tasks, reports, etc.)

1-5. Usage Logs

We may collect access logs (IP address, User-Agent, timestamp) for service quality improvement and incident response.

1-6. Audit Logs

System administrators (admin / manager roles) record business events (login, file operations, plan changes, MCP integration, etc.) as audit_logs for operational auditing, anomaly detection, and support purposes.

  • Items collected: actor information (uid / email / display name / role / team affiliations), action type (AuditAction), target resource (task / event / file / integration, etc.), IP address, User-Agent, timestamp
  • Purpose: Detecting unauthorized access, supporting customer inquiries, and preserving compliance audit evidence
  • Retention period: 90 days (auto-deleted by Firestore TTL policy)
  • Third-party disclosure: None as a rule. Only in response to formal law-enforcement requests in accordance with applicable law

1-7. Private Spaces and Encryption

A "Private Space" in this Service is a personal area accessible only to you. It is handled as follows:

  • Ordinary private data (not end-to-end encrypted) cannot be viewed by other users, including administrators, due to Firebase Security Rules. However, we may access it through server-side administrative privileges solely for system maintenance, incident response, or as required by law.
  • Private documents you protect with end-to-end encryption (E2E) are encrypted with a passphrase you set. No one — not our servers, our company, nor administrators — can decrypt them except you. The passphrase is never stored on our servers.
  • Files (images, PDFs, etc.) attached in a Private Space are, when E2E is enabled, likewise encrypted with your passphrase and cannot be decrypted by anyone but you (including our company and administrators). Encrypted files cannot be server-side preview-converted or thumbnailed; they are decrypted and displayed on your own device. File names are not encrypted, so do not include sensitive information in file names.
  • If you lose the passphrase for E2E-encrypted data, no one, including us, can recover it (unrecoverable). Please keep separate backups of important information.
  • If you choose to enter special-care-required personal information (e.g., medical history or disabilities, as defined by the Act on the Protection of Personal Information), we recommend storing it in an E2E-encrypted private document or file. We do not use such information for any purpose other than providing the Service and complying with the law.
  • My Number (Specific Personal Information) cannot be handled by this Service due to restrictions under the My Number Act (see Prohibited Activities, Article 3 of the Terms of Service).

1-8. Chat Screen Sharing and Voice Chat

Screen sharing sends connection information to Cloudflare STUN / TURN services to establish or relay connections. When you use voice chat, your display name, audio, and connection information are sent to Daily, our real-time communications provider. By default, the Service does not record or store voice-chat audio or screen-sharing video. If a user separately uses a recording feature, they must obtain consent from every participant.


2. Purpose of Use

We use the collected information solely for the following purposes:

  1. Account authentication and identification
  2. Providing calendar and task management features
  3. Providing chat, screen sharing, and voice chat features
  4. Showing Google sign-in email addresses as contact information to members of the same team on seat maps when the tenant administrator enables email display (enabled by default); partners cannot see them, and they are hidden when disabled
  5. Sending task notifications via Chatwork (connected users only)
  6. Service quality improvement and incident response
  7. Responding to terms of service violations

A Google sign-in email address issued or designated by the user’s organization for work is treated as personal information when linked to the user’s name. We use it for sign-in authentication and, when enabled, as a work contact within the user’s team. No separate consent under Japan’s Act on the Protection of Personal Information is required for its display on a seat map if viewers belong to the same legal entity and the display remains within the purposes originally specified and notified or published. This explanation does not apply to display to users of another legal entity or to use beyond the originally specified purposes.

We do not sell your information. We use the external services listed below as needed to provide the Service and optional integrations described in this policy.


3. Third-Party Services

The Service uses the following third-party services. Please also review their respective privacy policies.

Google Drive

Selected file references and saving to shared drives (when connected)

View Policy

Google Firebase

Authentication (processed in the US), Tokyo database, and profile image storage

View Policy

Google Cloud Storage

Shared file-content storage in Tokyo

View Policy

Vercel

Application delivery, server processing, and incident logs

View Policy

Chatwork

Notification messaging (when connected)

View Policy

Anthropic Claude API

AI task priority analysis (when used)

View Policy

Daily

Real-time voice relay and participant connectivity for voice chat (when used)

View Policy

Cloudflare

Connection establishment and TURN relay for screen sharing (when used)

View Policy

4. Security

We implement the following security measures to protect your data:

  • HTTPS (TLS) encryption for all communications
  • AES-256-GCM encrypted storage of OAuth and API tokens
  • Data access control via Firebase Security Rules
  • Session management via Firebase Authentication
  • CSRF protection using OAuth state, with PKCE and identity verification for Google Drive authorization

5. Data Storage & Deletion

Storage Location

Business data is stored in Google Cloud Firestore in Tokyo; shared file contents, including confidential files, are stored in Google Cloud Storage in Tokyo; and profile images are stored in Cloud Storage for Firebase in Tokyo. Shared files are stored and retrieved through a Tokyo regional endpoint, but resource metadata such as object names and IAM policies is outside that regional guarantee. Firebase Authentication data, including email and IP addresses, is processed in the United States. Data used for integrations, application delivery, and incident response may also be processed outside Japan by the third-party services listed below.

The storage location and sharing of connected Google Drive files follow Google and your organization’s settings. They are outside the Service’s Tokyo storage and end-to-end encryption guarantees. Changing permissions in the Service, unlinking a file, or ending a subscription does not delete existing Drive copies or their Google sharing permissions.

Disconnecting Integrations

When you disconnect Chatwork, any stored API tokens are immediately deleted. You can disconnect from the Settings page.

Disconnecting Google Drive deletes your stored connection tokens for the current tenant. You can revoke Google authorization in your Google Account connections settings. Because revocation also affects other grants to the same Google Cloud project, a tenant-level disconnect does not automatically revoke that authorization.

Account Deletion

If you wish to delete your account, please contact us using the information below. We will delete all personal data within 30 days of receiving your request.


6. Cookies & Local Storage

The Service uses cookies and browser local storage to maintain authentication sessions and save user preferences. We do not use cookies for advertising purposes.


7. Children's Privacy

The Service is not intended for children under the age of 13, and we do not knowingly collect personal information from children under 13.


8. Changes to This Policy

If we make changes to this policy, we will notify you on this page. For significant changes, we will provide in-app notifications or email notifications. Your continued use of the Service after changes constitutes acceptance of the updated policy.


9. Contact Us

For questions about this policy or requests for data deletion, please contact us at:

Kojinius

Email: admin@kojinius.jp

Service URL: https://kalenex.jp