Otopict Privacy Policy (Draft)
- Effective date:
[Set on publication] - Last updated:
[Set on publication]
1. Operator and Scope of This Policy
The operator of Otopict (the "Operator") handles users' information in accordance with this Policy.
- Service: Otopict
- Name of the personal information handling business operator: Disclosed without delay upon request to
info@otopict.com - Address: Disclosed without delay upon request to
info@otopict.com - Representative or person responsible for operations: Disclosed without delay upon request to
info@otopict.com - Contact:
info@otopict.com
This Policy applies to the handling of information in the web service provided under the name Otopict and in related features. Where a user navigates from the Service to an external website, this Policy does not apply to the handling of information at that destination.
2. Information We Collect
The Operator collects the following information in providing the Service.
2.1 Account and Authentication Information
- Email address
- Display name
- User identifier issued by Firebase Authentication
- Authentication method, email verification status, and other information necessary for authentication
The Operator does not store passwords themselves in the Service's database. Where password authentication is used, credentials are handled by Firebase Authentication. Authentication information is stored both in the Service's database and in Firebase Authentication, and both are within the scope of the physical deletion described in Section 7, Paragraph 3.
2.2 Information Submitted by Users
- Uploaded audio files and their metadata
- Voices, statements, speaker information, and other contents contained in the audio
- Project names, titles, settings, and edits
- Transcripts, chapter structures, scenes, captions, image candidates, and other generated or edited data
- Exported videos
- Information contained in inquiries
Audio may contain information about individuals other than the user. Users shall obtain the authority or consent necessary to submit such information to the Service.
2.3 Information Collected Automatically
- IP address
- Browser, device, and operating system information
- Access logs such as access time, request destination, response status, and processing time
- Logs relating to jobs, errors, generation processing, and misuse
- Cookies and similar identifiers
Sign-in and email verification use Google's Firebase Authentication. In the course of that processing, the user's browser transmits the IP address, browser and device information, and other communication information to Google.
3. Purposes of Use
The Operator uses the information it collects for the following purposes.
- Identity verification, authentication, account administration, and prevention of unauthorized sign-in
- Audio upload, transcription, content analysis, video generation, editing, preview, and export
- Storing and providing projects, Output, and usage history
- Administering credit balances and usage volume
- Maintaining the Service, investigating failures, improving quality, and ensuring security
- Investigating and responding to misuse, breaches of the Terms, infringement of rights, and defects
- Responding to inquiries, requests for disclosure, and other communications
- Notifying users of material changes, incidents, security matters, and transactions
- Performing legal obligations and exercising or defending rights
- Creating statistical information processed so that individuals cannot be identified, and improving the Service
The Operator does not use the information it collects for the purpose of training or tuning artificial intelligence models.
Where advertising email or communications for a different purpose are sent, the Operator will obtain the consent required by law or provide a means of opting out.
4. Service Providers and International Transfers
To the extent necessary to provide the Service, the Operator transmits information to, or entrusts its handling to, the following external services. The information transmitted varies with settings, input, and the features used.
| Service | Main purpose | Information that may be handled |
|---|---|---|
| Google Cloud | API execution, database, storage of audio, images, and video, job execution, logs | Account information, User Content, Output, logs |
| Firebase Authentication | Sign-in and identity verification | Email address, credentials, user identifier (including, where a Google account is used to sign in, that account's email address and display name) |
| ElevenLabs | Audio transcription | Uploaded audio, time-limited URL for retrieving the audio, language and processing settings |
| OpenAI | Generation of chapters, scenes, text, charts, and verification of image candidates | Transcripts, project settings, intermediate text and structure, images and related information |
| Wikimedia Foundation services | Search and retrieval of images and related information used in videos | Search terms, image identifiers, access information |
| Vercel | Delivery of the web interface and proxying to the API | IP address, browser information, access logs, cookies, and other communication information |
- The handling of information by each external service is governed by that provider's contractual terms and privacy policy.
- Data sent to the OpenAI API is not used to train or improve OpenAI's models unless the Operator expressly opts in to data sharing. Inputs and outputs may nevertheless be retained for up to 30 days for purposes such as abuse monitoring.
- The Operator uses settings that do not permit ElevenLabs to use submitted data for model training. Audio and transcripts may nevertheless be retained under that provider's policies for transcription processing, service improvement, troubleshooting, or security.
- Audio, images, video, and the database are stored in the Tokyo region (asia-northeast1) of Google Cloud. However, for some operational logs such as access logs, the storage region is not specified.
- Provision to the following providers constitutes provision of personal data to a third party in a foreign country.
| Recipient | Country | Information provided |
|---|---|---|
| OpenAI | United States | Transcripts, project settings, intermediate text and structure, images and related information |
| ElevenLabs | United States | Uploaded audio (retrieved via a time-limited URL), language and processing settings |
| Vercel | United States | IP address, browser information, access logs, and other communication information |
- The provision described in the preceding paragraph is made to providers that have established systems conforming to the standards prescribed in Article 28 of the Act on the Protection of Personal Information. Information about the personal data protection regime of the destination country, the measures taken by the provider, and related matters is available upon request to
info@otopict.com. - The Operator selects service providers appropriately and exercises necessary and appropriate supervision through contracts and other means.
5. Disclosure to Third Parties
The Operator does not provide personal data to third parties except in the following cases.
- Where the individual has consented
- Where required by law
- Where necessary to protect a person's life, body, or property and it is difficult to obtain the individual's consent
- Where personal data is provided in connection with a business succession
- Where, under the Act on the Protection of Personal Information, the case constitutes entrustment, joint use, or another situation not treated as provision to a third party
6. Cookies
- The Service uses a session cookie to maintain sign-in state and a cookie to prevent forged requests.
- Session cookies are protected using the HttpOnly, Secure, and SameSite attributes and related controls. A sign-in session is valid for up to 14 days.
- Interface preferences such as the display language may be stored on the device.
- The Service does not use cookies for analytics, advertising, or marketing purposes. If such cookies are added, this Policy will be updated and the necessary consent management put in place.
7. Retention and Deletion
- The Operator retains information for the period necessary to achieve the purposes of use and to provide the Service, investigate failures, maintain security, handle disputes, and comply with law. The principal retention periods are as follows.
| Information | Retention period |
|---|---|
| Audio, images, intermediate artifacts, and video stored in object storage | Automatically deleted once 365 days have passed since storage |
| Account information, projects, transcripts, and other generated or edited data | Until account closure. Treatment after closure is described in Paragraph 3 |
| Access logs and security logs | 30 days from collection |
| Inquiry records | Three years from the final response |
- The timing of deletion of the objects in the preceding paragraph may vary due to updates, duplication, backups, incident response, or legal requirements.
- Deletion of a project or an account is first processed as deactivation and logical deletion. To request physical deletion of personal data relating to a closed account, please make a request to
info@otopict.com. Following identity verification, the Operator will physically delete the data without delay, except for data that must be retained for legal obligations, misuse investigations, or the preservation of rights. - Access logs and security logs may be retained for a longer period, limited to the period necessary, where required to investigate failures, misuse, security incidents, or legal matters.
- Erasure of information from backups may take longer than in the production environment. Information in backups is also deleted within a reasonable period and, in the meantime, is not used for any purpose other than restoration, security, or legal compliance.
- Information that must be retained for legal obligations, misuse investigations, or the preservation of rights may be retained, limited to the necessary scope and period.
8. Security Measures
To prevent leakage, loss, or damage of the information it handles, the Operator takes the following security measures.
Organizational measures
- A person responsible for the handling of personal data is designated, and arrangements are in place to review how it is handled.
- Procedures for reporting and responding to incidents involving personal data are established.
Personnel measures
- Persons handling personal data are informed of the applicable precautions.
- Where work involving the handling of personal data is outsourced, it is governed by a contract that includes confidentiality terms.
Physical measures
- Personal data is handled in cloud databases and object storage managed by service providers, and no copies beyond those necessary for operations are kept on the Operator's devices.
Technical measures
- Separation and minimization of access rights and service accounts
- Encryption of communications and file access via time-limited URLs
- Protection of authentication cookies and CSRF countermeasures
- Restriction of access to databases and storage
- Dedicated management of secrets
- Review of logs, incidents, and unauthorized access
Understanding the external environment
- Some of the providers entrusted with handling personal data are located in the United States. The Operator implements the measures above having understood the personal data protection regime of the United States.
- In the cloud services used by the Operator, some operational logs may be stored outside Japan.
Further details of these security measures are available, to the extent consistent with security, upon request to info@otopict.com.
9. Rights and Request Procedures
Under applicable law, users may request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or cessation of provision to third parties in respect of their retained personal data. Requests for the information on international transfers described in Section 4, Paragraph 6, and for the physical deletion described in Section 7, Paragraph 3, are accepted at the same contact point.
- Contact:
info@otopict.com - Required details: registered email address, the content of the request, and information necessary for identity verification
- Method of response: as a rule, by email to the registered email address
- Fee: none
Following identity verification, the Operator responds without delay in accordance with law. Where law permits the Operator not to comply with a request, the Operator will explain the reason to the extent possible.
10. Children
The Service may only be used by persons aged 18 or over.
11. Response to Leakage and Similar Incidents
Where leakage, loss, damage, or another incident involving personal data occurs, the Operator will investigate the scope of impact, prevent its spread, take measures to prevent recurrence, and notify the relevant authorities and affected individuals as required by law.
12. Changes to This Policy
- The Operator may change this Policy in response to changes in law, the Service, or the handling of information.
- Material changes will be notified before the effective date by display within the Service, by sending to the registered email address, or by another appropriate method.
- Where a change requires consent under law, the Operator will obtain that consent separately.
13. Contact
Inquiries regarding the handling of personal information, disclosure of Operator information, complaints, and this Policy may be sent to:
- Service: Otopict
- Email:
info@otopict.com
14. Language
This Policy is prepared in a Japanese version and an English version. For users residing in Japan, the Japanese version prevails; for users residing outside Japan, the English version prevails. The non-prevailing version is provided as a reference translation, and in the event of a discrepancy between the two versions, the prevailing version governs.
Revision History
When this Policy is revised, the revision date, the parts revised, and the purpose of the revision are recorded here.
[Set on publication]Established