プライバシーポリシー
最終更新日:2026年9月20日
1. はじめに
JapanMarketing合同会社(以下「当社」)は、デスクトップアプリおよびサーバから成るサービス「ReplyFive」(以下「本サービス」)において、利用者の情報を以下のとおり取り扱います。会話等の本文を ReplyFive サーバのデータベース・ログ・分析基盤に保存しない設計です。端末内の保存と外部 AI による処理は第4〜6項で説明します。
2. 保存しない情報
当社は、次の情報をサーバのデータベース、ログ、分析基盤のいずれにも保存しません。
- 返信の対象となる会話の本文
- 利用者が入力した「伝えたいこと」
- 生成された返信の文面
- 利用者が返信に加えた修正内容
これらの情報は返信生成のためにサーバで処理します。ここでの「保存しない」は ReplyFive サーバへの本文保存を指し、同意後の端末内暗号化記録や外部 AI への送信まで否定するものではありません。パネルを閉じても、端末内の保存済み記録は削除されません。
3. 保存する情報
サーバには、契約、端末管理、運用とサービス改善のために以下の情報を保存します。
- 組織名および管理者のメールアドレス
- 契約プラン、契約状態、席数
- 端末トークンのハッシュ値(SHA-256。トークン自体は保存しません)
- 組織および席ごとの1日あたりの利用回数
- 管理画面で設定された文章ルール(書き出し、署名、使用しない語句など)
- 端末名・利用者が登録した表示名、設定・文体ラベル、本文を含まない利用イベント・修正量等の数値、認証・招待・紹介・課金の識別情報
- 第7項の条件を満たす Web 計測の識別子・流入情報・許可/拒否状態
4. 端末内に保存される情報
新規インストール時や同意を撤回した状態では、会話・返信本文の収集を開始しません。現在の説明に明示的に同意した後、設定と組織ポリシーで許可された機能だけが動作します。「返信の記録」「会話の記録」の設定値は既定でオンですが、同意前に実効化される意味ではありません。同意の撤回は読み取りと進行中の取得・生成・挿入処理を停止し、古い処理結果は再同意しても使用しません。
返信の記録は、入力した意図・生成文・最終文・アプリ名・相手の識別キー等を端末内に AES-GCM で暗号化して直近最大30件保存します。生成時は関連する最大10件を送信し、サーバが最大3件を選んで文章化に使います。会話記録とは別の保存領域です。組織は文脈取得や返信例の利用を禁止できます。設定をオフにすることや同意の撤回だけでは保存済みファイルは消えません。設定の各「すべて削除」で会話記録と返信記録をそれぞれ削除できます。削除はアプリの記録を対象とし、OS や利用者のバックアップの消去まで保証しません。
macOS は Keychain、Windows は現在の利用者アカウントの DPAPI で暗号鍵・端末トークンを保護します。Linux は Secret Service(libsecret / GNOME Keyring 等)を優先し、利用不能・保存失敗・4秒の応答期限超過時は所有者のみ読み書きできるファイル(0600)へ退避します。この代替ファイル内の秘密値は OS 保管庫で暗号化されていないため、同じ利用者権限でファイルを読めるプログラムからは保護されません。記録本文のファイル自体は AES-GCM で暗号化します。
鍵が取得できない場合、既存の暗号化記録を復号できないことがあります。現行クライアントには新しい鍵を作成する経路があり、鍵の保存失敗後や再起動後に記録を復元できる保証はありません。鍵の利用不能時の停止・復旧の実機確認を公開前の確認項目としています。
5. 画面の読み取りについて
同意・組織ポリシー・設定・OS権限が許可する場合、前面のチャットやメールの会話領域を読み取ります。macOS は Accessibility、Windows は UI Automation、Linux は AT-SPI 等の OS 機能を使います。前面アプリや会話の変化を検知する収集処理と、ショートカットによる取得があります。「ショートカット時の1回だけ」という動作ではありません。会話履歴は相手ごと最大200発言、最新50人を端末内に暗号化して保持し、生成時には末尾最大5,000文字を文脈として送信します。
会話テキストを取得できないアプリでは、OS権限と対応機能の範囲で画面領域から文字認識する場合があります。取得画像を記録ファイルとして保存する機能はありません。対応するアプリ・OS・画面権限によって取得範囲は異なります。会話記録をオフにすると背景収集を停止しますが、同意と組織ポリシーで許可された手動取得は別に動作します。同意を撤回すると手動取得も停止します。
6. 外部サービスと処理を行う国
AIモデル提供者
当社クラウド版では、ReplyFive のサーバ(返信の生成処理と、組織・端末の管理情報の保存)は米国の Amazon Web Services(オレゴンリージョン)で運用しています。会話の本文および生成した文章はサーバに保存しません。サインインに用いるアカウント情報は Amazon Web Services の東京リージョンに保存します。返信の文章の生成には Groq, Inc.(米国に所在する第三者の事業者)がオープンウェイトのモデルで提供する API を利用します。したがって、会話の本文および利用者が入力した内容は、返信を生成する目的で米国内の Groq のサーバへ送信され、処理されます。送信内容には、生成に必要な会話・意図・表示名・選択された返信例等が含まれます。再試行や安全な文面への整形により複数回処理する場合があります。提供者側の保持・学習利用の条件は、契約と運用設定によって異なるため、ReplyFive サーバでの本文非保存と同一の保証ではありません。
セルフホスト版はお客様の AWS 環境等で稼働し、設定した Groq または Amazon Bedrock に本文を送ります。AWS 参照構成は東京を既定としますが、処理先はリージョン・モデル/推論プロファイル・プロバイダー設定に依存します。セルフホストだけで国内処理やアカウント内完結を保証するものではなく、国外送信を禁止する場合は配置と推論先を別途確認します。
決済
決済処理は Stripe, Inc. が行います。クレジットカード情報は Stripe が直接取得・保持するため、当社がカード番号を保持することはありません。当社が受け取る情報は、契約状態および請求に必要な識別子のみです。
エラー報告
不具合の把握には Functional Software, Inc.(Sentry)を利用しています。送信される情報は、発生箇所、端末の OS 種別、アプリのバージョンなどの技術情報に限られます。会話の本文、入力内容、生成された返信、リクエスト本文、Cookie、認証情報は、送信前にすべて除去されます。
アクセス解析と広告の効果測定
当社は公開サイト(replyfive.app)および管理画面において、Google LLC(Google アナリティクス、Google 広告)、Meta Platforms, Inc.(Meta ピクセル)、OpenAI(ChatGPT 広告)のタグを設置しています。これらの事業者へ送信される情報は、ページの閲覧、ダウンロードボタンのクリック、サインインや契約完了などの出来事と、Cookie や広告の識別子に限られます。会話の本文、入力内容、生成された返信、メールアドレス、氏名は送信しません。
管理画面へのサインイン時には、Google アナリティクスの匿名識別子と流入情報を組織の記録と結び付け、経路を集計します。また、当社サーバは直近30日以内の有効な許可状態と識別子があり、その後の拒否がない場合に限り、トライアル開始や契約状態の変化などの出来事を Google アナリティクスへ送信します(本文やメールアドレスは含みません)。これらの処理は米国で行われる場合があります。
7. Cookie
管理画面では、ログイン状態を保持するためのセッション Cookie を使用します。アクセス解析と広告の効果測定のため、第6項に記載したタグも Cookie を使用します。また、広告経由の流入を把握するため、URL のパラメータや流入元ドメインを当社ドメインの Cookie(rf_attr_first は90日間、rf_attr_last は30日間)に保存します。
Web 計測は本番 SaaS の対象ホストとサーバ設定で許可された場合に限定し、管理画面では認証後に動作します。ブラウザの欧州等のタイムゾーン、Global Privacy Control または Do Not Track による制限がある場合、広告流入 Cookie を読み書きせず、Google・Meta・OpenAI のタグも読み込みません。タイムゾーンは所在地の確定情報ではありません。制限が検出されない場合に計測を許可する実装であり、この判定を利用者が広告に明示同意した証拠として扱いません。端末本文の収集同意とは別の判定です。
ブラウザでの拒否状態は認証済みセッションからサーバにも伝えます。保存に失敗した拒否は成功扱いにせず、再試行が必要です。保存済みの拒否は他のサーバでも参照します。ただし送信済みのデータを取り消すことはできず、ブラウザの Cookie 削除だけでサーバに拒否を伝えることはできません。Cookie はブラウザの設定により拒否や削除が可能です。また、Google アナリティクスによる計測は、Google が提供するオプトアウト アドオンを利用して無効にすることもできます。
8. 保存期間
本文を含まないサービス利用イベントは、サーバの運用設定に従って保持します(既定400日、0を明示した場合は無期限)。期限が来たイベントは API の表示と集計から除外します。DynamoDB の物理削除は非同期で通常数日の猶予があるため、その間は保存領域に残る場合があります。設定変更時は既存レコードの移行も必要です。以前の設定で既に期限切れのレコードは、保持期間を延長しても復元しません。
第3項に定める情報は、契約期間中および法令上必要な期間にわたり保存します。契約終了後は、請求業務および法令上の保存義務がなくなった時点で速やかに削除します。利用回数の記録については、請求処理に必要な期間を経過した後に削除します。
9. 第三者提供
当社は、法令に基づく場合を除き、保有する情報を本人の同意なく第三者へ提供しません。第6項に記載した委託先に対しては、本サービスの提供に必要な範囲に限り情報を取り扱わせます。なお、クラウド版におけるサーバの運用(Amazon Web Services)ならびに Groq, Inc. への送信は、第6項のとおり米国に所在する事業者への委託にあたります。
10. 安全管理
クラウド版の公開接続は TLS を使用します。ローカル開発・セルフホストの TLS 終端は配置設定に依存します。端末トークンはハッシュ化して保存し、管理画面のセッションは署名付きで安全に管理します。クラウド版の計算処理・組織/端末データベースは米国オレゴン、認証アカウント基盤は東京に分かれています(第6項)。
11. 開示等のご請求・お問い合わせ
保有情報の開示、訂正、削除のご請求や、本ポリシーに関するお問い合わせは、下記までご連絡ください。
JapanMarketing合同会社
個人情報取扱責任者:遠藤巧巳
メール:takumi.endoh@japan-marketing.co.jp
12. 本ポリシーの変更
本ポリシーを変更する場合は、本ページに変更後の内容と最終更新日を掲載します。重要な変更を行う場合は、管理画面または登録メールアドレス宛にお知らせします。
Privacy Policy (English)
This is an English translation of the Japanese text above, provided for convenience. If the two differ, the Japanese version governs. Last updated 20 September 2026.
1. Introduction
JapanMarketing LLC (“we”) operates ReplyFive, a desktop application and server (the “Service”). ReplyFive is designed not to persist conversation or reply text in its server database, logs or analytics. Device storage and external AI processing are described in sections 4–6.
2. What we do not store
We do not write any of the following to a database, a log file, or an analytics system:
- The conversation you are replying to
- The intent you type
- The generated reply
- Any edits you make to it
The server processes this text to generate replies. “Not stored” here means no text persistence in ReplyFive server storage; it does not exclude consented encrypted device records or transmission to an AI provider. Closing the panel does not delete saved device records.
3. What we store
Server records support contracts, device management, operations and service improvement: your organization name and administrator email address, the plan, subscription state and seat count, SHA-256 hashes of device tokens (never the tokens themselves), daily request counts per organization and seat, and the writing rules configured in the admin console. We also store device names and user-submitted display names, preferences and style labels, text-free usage events and edit counts, authentication/invitation/referral/billing identifiers, and the web measurement identifiers, attribution and permission/denial state described in section 7.
4. Data kept on your device
A new installation, or an installation with withdrawn consent, does not start collecting conversation or reply text. Collection requires explicit acceptance of the current explanation and the relevant settings, organization policy and OS permissions. Reply records and conversation records have an on preference by default; that preference does not authorize collection before consent. Withdrawal stops capture and pending capture/generation/insertion work; accepting again does not authorize old results.
Reply records contain the intent, generated and final text, app name and contact identifier, encrypted with AES-GCM on the device, up to 30 recent records. Up to 10 related examples may be sent for generation, with at most 3 selected by the server. Conversation history is stored separately. Organizations can prohibit context capture or use of reply examples. Turning a feature off or withdrawing consent does not delete existing files: use each “Delete all” control for conversation and reply records. Deletion covers the app records, not copies in OS or user backups.
macOS protects keys and device tokens with Keychain; Windows uses DPAPI for the current user account. Linux prefers Secret Service (libsecret / GNOME Keyring, for example) and falls back to an owner-readable/writable file (0600) if it is unavailable, a write fails, or a call exceeds four seconds. Secrets in that fallback file are not encrypted by an OS vault and are accessible to programs with the same user's file access. The record content file itself remains AES-GCM encrypted.
If a key is unavailable, existing encrypted records may be unreadable. Current clients can generate a new key in this situation; successful recovery after a key-storage failure or restart is not guaranteed. Native verification of key-unavailable stop and recovery behavior remains a pre-publication check.
5. Reading the screen
With consent, organization policy, settings and OS permissions allowing it, the app reads the foreground chat or email conversation area using macOS Accessibility, Windows UI Automation, or Linux AT-SPI and related OS facilities. It observes foreground/conversation changes and also supports shortcut-triggered capture; reading is not limited to one capture per shortcut. Up to 200 messages per contact for the latest 50 contacts are kept encrypted on the device. Generation sends at most the last 5,000 characters as context.
When text is unavailable, supported clients may recognize text from a screen area within the available OS permissions. There is no feature that saves those captured images as record files. Coverage varies by app, OS and permission. Turning conversation records off stops background collection; permitted manual capture remains separate. Withdrawing consent stops manual capture too.
6. Third parties and where processing takes place
AI providers. On our cloud plan the ReplyFive server (reply generation and the storage of organization and device records) runs on Amazon Web Services in the United States (Oregon region); conversation text and generated replies are never stored on the server, and sign-in account records are kept in the Tokyo region. The reply text is generated by Groq, Inc., a third-party provider located in the United States, using an open-weight model. The conversation text and your intent are therefore transferred to Groq's servers in the United States to generate the reply. Requests can also contain display names and selected reply examples, and retries or safety reformatting can cause more than one processing call. Provider retention and training use depend on the provider contract and configuration; our server non-storage policy is not the same guarantee. Self-hosted deployments send text to the configured Groq or Amazon Bedrock provider. The AWS reference defaults to Tokyo, but processing depends on region, model/inference profile and provider settings. Self-hosting alone does not guarantee domestic or account-confined processing; deployments prohibiting international transfer must verify the actual inference destination.
Payments. Payments are processed by Stripe, Inc. Card details are collected and held by Stripe; we never hold card numbers. We receive only the subscription state and the identifiers needed for billing.
Crash reporting. We use Functional Software, Inc. (Sentry) to diagnose faults. Reports contain technical information such as where the error occurred, the operating system and the application version. Message text, intents, generated replies, request bodies, cookies and credentials are stripped before sending.
Analytics and ad measurement. The public website (replyfive.app) and the admin console load tags from Google LLC (Google Analytics, Google Ads conversion tracking), Meta Platforms, Inc. (Meta Pixel) and OpenAI (ChatGPT Ads measurement pixel). What these tags send is limited to page views, clicks on the download button, the completion of sign-in, device connection and paid subscription, and browser or ad identifiers (cookie IDs, ad click IDs). Message text, intents, generated replies, e-mail addresses and names are never sent to these providers. When you sign in to the admin console, the anonymous Google Analytics identifier and the referral information described in section 7 are linked to your organization's record so that we can measure the path from free trial to paid subscription; our server reports trial start, device connection and subscription changes to Google Analytics only with a valid permission state and identifier in the previous 30 days, without a later denial (without message text or e-mail addresses). These providers may process the data in the United States.
7. Cookies
The admin console uses a session cookie to keep you signed in. The tags described in section 6 use cookies for analytics and ad measurement. To attribute visits to advertising, we also store URL parameters such as utm_* and ad click IDs (gclid, fbclid and similar) together with the referring domain in first-party cookies on our domain (rf_attr_first for 90 days, rf_attr_last for 30 days).
Web measurement is limited to enabled production SaaS hosts and, in the admin console, authenticated sessions. A restricted European or related browser time zone, Global Privacy Control, or Do Not Track prevents attribution-cookie reads/writes and loading of Google, Meta and OpenAI tags. Time zone is not verified location. The implementation permits measurement when these restrictions are absent; that derived permission is not evidence that the user explicitly opted in to advertising. This is separate from consent to desktop text collection.
A denied browser state is also sent through an authenticated session to the server. A denial that cannot be persisted is not acknowledged as successful and needs a retry. Persisted denials are read by other server instances. Already-sent data cannot be recalled, and deleting browser cookies alone does not notify the server of denial. You can block or delete cookies in your browser settings, and you can disable Google Analytics with the opt-out add-on provided by Google.
8. Retention
Service usage events contain no message text. Their retention is controlled by the server configuration (400 days by default; 0 explicitly selects unlimited retention). Events are excluded from API results and analytics when that period expires. Physical deletion by DynamoDB TTL is asynchronous and usually follows within a few days, so expired records can remain in storage during that interval. Changing the setting also requires migrating existing records; records already expired under their previous policy are not restored.
We retain the information in section 3 for the duration of the contract and for any period required by law, then delete it. Request counts are deleted once they are no longer needed for billing.
9. Disclosure
We do not disclose information to third parties except where required by law. The processors named in section 6 may handle it only as necessary to provide the Service.
10. Security
Public cloud connections use TLS; local development and self-hosted TLS termination depend on deployment settings. Device tokens are stored hashed and admin sessions are signed. Cloud compute and organization/device databases are in Oregon, United States; the authentication account service is in Tokyo (section 6).
11. Contact
For access, correction or deletion requests, or any question about this policy: JapanMarketing LLC, attention Takumi Endoh, takumi.endoh@japan-marketing.co.jp.
12. Changes
If we change this policy we will publish the new text and its date on this page, and notify significant changes through the admin console or by email.