個人情報保護方針
プライバシーポリシー
制定・最終更新:2026年7月23日
Webの閲覧・検索・投稿・保存は無料で、MCPには一度限りの試用と提供予定のProがあります。 ログインはFirebase Authenticationを通じたGoogle認証で行い、AIコナスはGoogleのパスワードを受け取りません。認証後、提供元が確認したメールアドレス等を本人識別に利用し、アプリDBにはメールアドレスそのものではなく復元困難なハッシュ値を保存します。Proの販売と実決済はまだ稼働していません。
1. 基本方針
AIコナス運営者(以下「運営者」)は、個人情報保護法その他の関係法令を守り、利用者の情報を必要な範囲で適正に取り扱います。取得時には利用目的を明示し、目的外利用を行いません。
2. 現在のβで扱う情報
Web画面の検索語、実行ガイドへ入力した回答、コピー内容はサーバーへ送信しません。ログイン時は、Firebase Authenticationを通じてGoogleアカウントを認証し、Firebaseが発行する署名付きIDトークンから認証済みメールアドレスとアカウント固有IDの提供を受けます。サーバーは署名・発行先・有効期限・Googleログイン由来であることを確認し、本人識別とマイページ表示に利用します。Googleのアクセストークンや更新トークンは要求・保存しません。アプリDBへはメールアドレスそのものを保存せず、メールアドレスから作成した復元困難なハッシュ値、Firebaseアカウント固有ID、作成・更新時刻、利用回数、契約状態、接続キーのハッシュ値を保存します。ブラウザには署名・有効期限付きのログインCookieを安全属性付きで保存します。パスワードは受け取りません。ホスティング事業者が安全確保や障害対応のためIPアドレス、時刻、通信情報等の技術ログを処理する場合があります。ブラウザのlocalStorageには、表示言語、最近使った方法のIDと日時、保存した方法のID(最大30件)、同じ日に閲覧数を重複送信しないための方法ID、業務パックのID・現在工程・完了時刻・次回日、利用者が明示的に保存した投稿下書きを保存する場合があります。後述する匿名の閲覧数集計または改善計測へ任意参加した場合を除き、これらの利用内容はサーバーへ送信しません。端末内の値は、利用者が削除するかブラウザ設定から消去するまで残ります。保存から30日を超えた下書きは、次にAIコナスを開いた時に削除します。ブラウザ設定からいつでも消去できます。共有端末では保存しないでください。
投稿時にログイン済みであることを確認し、タイトル、本文、原文言語、自作か参考情報かの区分、任意の元URL、仮名利用者ID、公開・認定状態、作成・更新時刻を保存して直ちに公開します。投稿者本人はログイン中に編集・削除できます。AIコナス認定は公開とは別に運営者が定期確認し、認定した投稿だけにマークを表示します。削除後は公開利用を停止し、関連する評価とレビューを削除します。ただし法令、安全対応またはバックアップ上必要な記録が限定的な期間残る場合があります。
個人を識別しないアクセス集計
辞典とループ設計画面では、直近数分に閲覧しているブラウザセッションの概算を表示します。ブラウザが作ったランダムIDはサーバー側で復元困難な値へ変換し、元のID、氏名、メールアドレス、入力内容は保存しません。記録は最終通信から最大4分で期限切れとなり、表示は実人数ではなくアクティブなブラウザセッションの概算です。
Google Analyticsは計測IDが設定され、かつ利用者が画面上で同意した場合だけ読み込みます。URLの検索条件とフラグメント、AIコナスの利用者ID、メールアドレス、投稿、検索語、入力内容は送信せず、広告パーソナライズとGoogleシグナルは無効にします。同意しなくても全機能を利用できます。
公開ページの利用状況を把握するため、閲覧日、ページの大分類、参照元の大分類、ページ表示回数をサーバー側で日ごとに集計します。Cookieやブラウザ保存領域を使った分析識別子は発行せず、検索語、URLのクエリやハッシュ、投稿・入力本文、生のIPアドレス、ユーザーエージェント、メールアドレス、個人・端末を識別する値、生の参照元URLは分析DBへ保存しません。日をまたいだ個人の行動追跡、新規・再訪判定、広告利用は行いません。集計値は運営改善のため400日以内保持します。bot、共有回線、配信キャッシュ等の影響を受けるため、実人数ではなくページ表示回数として扱います。
各方法のカードには、詳細を開いた回数を閲覧数として表示します。サーバーへ保存するのは日、方法ID、方法バージョン、合計回数だけで、ブラウザID、アカウント、IPアドレス、検索語、入力内容とは結び付けません。同じ端末からの過度な重複を減らすため、ブラウザ内に当日閲覧済みの方法IDを保持します。閲覧数は実人数ではありません。
任意の業務パック改善計測
業務パック画面でログイン中の利用者がチェック欄を自ら選んだ場合に限り、サーバーは認証済みアカウントから秘密saltを使って仮名参加IDを作ります。改善イベントへ保存するのは、生のメールアドレスではなくこの仮名ID、業務パックID、必要な場合の方法ID、開始・完了種別、所要秒、結果区分です。1周完了後、利用者が任意で「普段より15分以上短縮できた」と回答した場合は、その回答も保存します。入力本文、検索語、資料、成果物、氏名、連絡先、顧客情報、決済情報は含めません。未参加、通信失敗、回答しないことによる機能制限はありません。
参加は画面からいつでも解除できます。解除すると新しいイベント送信を止め、ログイン中は本人の仮名IDに対応する受信済みイベントの削除も要求します。保持期間は通常30日で、設定上も90日を超えません。ホスティング事業者の技術ログは別途、安全確保に必要な期間処理される場合があります。
利用後の星評価
評価はログインなしで利用でき、ブラウザが作ったランダムIDから秘密のソルトで作る仮名ID、方法ID、方法バージョン、1〜5の星数、低評価時の定型理由、作成・更新時刻を保存します。生のブラウザID、メールアドレス、入力本文、検索語、AIの出力は含めません。自由記述レビューはログイン後に送信した場合だけ仮名ID、方法ID、言語、本文、審査状態、作成・更新時刻を保存し、運営確認後に公開します。同じブラウザの評価は1方法バージョンにつき1件とし、後から変更できます。星の平均は5件以上から表示します。
お問い合わせ
お問い合わせフォームでは、種別、件名、本文、返信先メールアドレス、対応状態、受付・更新時刻を保存します。返信先メールアドレスはアプリケーションで暗号化してから保存し、許可された運営者だけが管理画面で確認できます。お問い合わせ対応、本人確認、安全対応、法令上必要な記録のために利用し、対応完了後は必要な期間を超えて保持しません。パスワード、カード番号、秘密鍵、第三者の個人情報は入力しないでください。
本番開始後に取得する可能性がある情報
- メールアドレス、表示名、認証情報、居住国、18歳以上であることの確認
- 閲覧、検索、保存、投稿、更新、接続機能の利用履歴
- 利用者が送信する方法、説明、URL、フィードバック
- IPアドレス、ブラウザ、端末種別、Cookie等の識別子、障害ログ
- 有料機能のプラン、請求・支払状況
パスワードを導入する場合は平文保存せず、安全な認証基盤または適切なハッシュ化を利用します。カード番号は原則として決済事業者が取り扱います。
3. 利用目的
- 本人確認、ログイン、アカウント管理
- 辞典、保存、投稿、更新、AI接続等の提供
- 問い合わせ、重要なお知らせ、不正利用への対応
- 品質、安全性、検索精度の改善
- 料金請求、契約管理、法令上必要な記録
広告メールは、法令上必要な場合に別途同意を得て送ります。会員登録への同意と混在させません。
4. 安全管理・委託・第三者提供
アクセス制御、暗号化、権限管理、ログ確認等、情報に応じた安全管理措置を講じます。認証、ホスティング、決済、分析等を委託する場合は委託先を選定・監督します。法令に基づく場合等を除き、本人の同意なく個人データを第三者へ提供しません。国外のクラウド等を利用する場合は、必要な情報提供または同意取得を行います。
AI接続
目的に合う方法を選ぶために必要な短い情報だけを扱い、会話全文や秘密情報を要求しません。MCPの送信操作は接続先AIが行うため、送信前に各AIの表示する内容と権限も確認してください。受け取った目的を広告やAIモデル学習へ利用しません。
5. 開示・訂正・削除等
本人は、法令に従い、保有個人データの利用目的の通知、開示、訂正、利用停止、消去等を請求できます。本人確認後、法令に従って対応します。
開示・訂正・削除等は、お問い合わせフォームから請求できます。必要に応じて本人確認を行います。現在のβではマイページからログアウトできます。
6. 保存期間・未成年者・変更
情報は利用目的または法令上必要な期間だけ保持し、不要になった情報は安全に削除します。未成年者は必要に応じて保護者の同意を得てください。本ポリシーの重要な変更は適用開始前に通知し、必要な場合は追加の同意を得ます。
Governing version: The Japanese version is authoritative if a translation conflicts, without limiting mandatory rights under applicable law.
PERSONAL DATA PROTECTION POLICY
Privacy Policy
Issued and last updated: July 23, 2026
Web browsing, search, posting, and saves are free; MCP has a one-time trial and a planned Pro plan. Sign-in uses Google through Firebase Authentication. AI Konas never receives the Google password. A provider-verified email or identifier is used for identification; the application database stores a non-reversible email hash rather than the address itself. Pro sales and live payments are not active.
1. Current beta data
Web search terms, personalization answers, and copied guides are not transmitted to the server. At sign-in, Firebase Authentication authenticates the Google account and supplies a signed Firebase ID token containing a verified email and account-specific ID. The server verifies its signature, audience, issuer, expiry, and Google sign-in provider. AI Konas does not request or store Google access or refresh tokens. The application database stores the Firebase account ID, a non-reversible email hash, account timestamps, usage counts, subscription state, and connection-key hashes; it does not store the email address itself or receive a password. A signed, expiring login Cookie is stored in the browser with security attributes. The hosting provider may process IP address, time, and technical request logs for security and reliability. The browser may store the display language, a recent method ID and date, up to 30 IDs of methods you choose to save, method IDs used to avoid duplicate view-count submissions on the same day, business-pack ID, current step, completion times and next-run date, plus a contribution draft only when you choose to save it. Except for the anonymous aggregate view count described below or when you optionally join improvement measurement, these usage values are not sent to the server. Device values remain until you delete them or clear browser storage. A draft older than 30 days is deleted the next time AI Konas is opened. Do not save on a shared device.
When you submit, the service checks that you are signed in, stores the title, body, original language, authorship type, optional source URL, pseudonymous user ID, publication and certification states, and timestamps, and publishes the post immediately. Only the signed-in author may edit or delete it. AI Konas certification is a separate periodic operator review; only certified posts receive the mark. Deletion removes the public post and related ratings and reviews, although limited records may remain when required for law, safety handling, or backups.
Access counts without personal identification
The library and Loop Studio show an approximate count of browser sessions active in the last few minutes. A random browser ID is irreversibly transformed on the server; the raw ID, name, email, and entered content are not stored. Records expire no more than four minutes after the last heartbeat. This is an approximate session count, not verified people.
Google Analytics loads only when a measurement ID is configured and you explicitly consent. URL queries and fragments, AI Konas user IDs, email, contributions, searches, and entered content are not sent. Ad personalization and Google signals are disabled. Declining does not limit features.
To understand use of public pages, the server aggregates the viewing date, broad page category, broad referrer category, and page-view count by day. Analytics does not issue a Cookie or browser-storage identifier and does not store search terms, URL queries or fragments, contribution or input text, raw IP addresses, user agents, email addresses, personal or device identifiers, or raw referrer URLs in the analytics database. We do not track a person across days, classify new or returning visitors, or use these counts for advertising. Aggregates are retained for no more than 400 days. Because bots, shared networks, and delivery caches may affect the count, it is described as page views rather than people.
Each method card may display how many times its detail view has been opened. The server stores only the day, method ID, method version, and aggregate count; it does not link this count to a browser ID, account, IP address, search term, or entered content. The browser keeps method IDs viewed that day to reduce repeated submissions from the same device. The displayed count is not a count of unique people.
Optional business-pack improvement measurement
Only after you actively select the checkbox while signed in, the server derives a pseudonymous pilot ID from the authenticated account using a secret salt. Pilot events store that ID—not the raw email—plus the business-pack ID, method ID where required, start or completion type, duration and result. After a full run, we also store an optional answer only when you choose “saved at least 15 minutes.” Improvement events do not include input text, search terms, source documents, outputs, names, contact details, customer information, or payment details. Declining, a network failure, or skipping the question never limits features.
You can leave from the screen at any time. Leaving stops new events and, while signed in, sends a request to delete events for your pseudonymous ID. Retention is normally 30 days and cannot be configured beyond 90 days. Hosting-provider technical logs may be processed separately for the period needed for security and reliability.
Post-use star ratings
Ratings work without sign-in. We store a pseudonymous ID derived from a random browser ID with a secret salt, method ID and version, a one-to-five star value, a fixed reason for lower ratings, and timestamps. The raw browser ID, email address, input text, search terms, and AI output are not stored. Written reviews require sign-in and are published only after moderation. One current rating is kept per browser, method, and version and can be changed later. The star average appears after at least five ratings.
Contact requests
The contact form stores the topic, subject, message, reply email, handling status, and timestamps. The reply email is encrypted by the application before storage and is visible only to the authorized operator in the private inbox. This data is used to handle the request, verify identity where needed, address safety issues, and keep legally required records. Do not submit passwords, payment-card numbers, secret keys, or another person's personal data.
2. Data after live launch
Live features may process account details, authentication data, usage and device logs, submitted content, support communications, and subscription status. Passwords will not be stored in plain text. Payment card data will normally be handled by a payment provider.
3. Purposes
- Authentication and account administration
- Search, saving, contribution, update, and AI connection features
- Support, security, fraud prevention, and important notices
- Quality, safety, and discovery improvements
- Billing, contracts, and legally required records
Marketing consent will be optional and separate.
4. Security, processors, and AI connections
We apply appropriate access controls, encryption, permission management, and monitoring. Providers may support authentication, hosting, payments, and analytics under oversight. Personal data will not be disclosed without consent unless permitted by law. Required information or consent will be provided before international transfers. MCP is designed to use only the short information needed to select a method. Because the connected AI initiates the request, review the data and permissions shown by that provider before enabling it. MCP goals are not used for advertising or model training by AI Konas.
5. Rights, retention, and contact
Subject to applicable law, you may request access, correction, suspension, or deletion through the contact form. Identity verification may be required. Data will be kept only as long as needed for stated purposes or legal obligations. The account page supports sign-out.
6. Minors and changes
Minors should obtain guardian consent where required. Material changes will be announced before they apply, and additional consent will be obtained when required.