Otopict Privacy Policy (Draft)

1. Operator and Scope of This Policy

The operator of Otopict (the "Operator") handles users' information in accordance with this Policy.

This Policy applies to the handling of information in the web service provided under the name Otopict and in related features. Where a user navigates from the Service to an external website, this Policy does not apply to the handling of information at that destination.

2. Information We Collect

The Operator collects the following information in providing the Service.

2.1 Account and Authentication Information

The Operator does not store passwords themselves in the Service's database. Where password authentication is used, credentials are handled by Firebase Authentication. Authentication information is stored both in the Service's database and in Firebase Authentication, and both are within the scope of the physical deletion described in Section 7, Paragraph 3.

2.2 Information Submitted by Users

Audio may contain information about individuals other than the user. Users shall obtain the authority or consent necessary to submit such information to the Service.

2.3 Information Collected Automatically

Sign-in and email verification use Google's Firebase Authentication. In the course of that processing, the user's browser transmits the IP address, browser and device information, and other communication information to Google.

3. Purposes of Use

The Operator uses the information it collects for the following purposes.

  1. Identity verification, authentication, account administration, and prevention of unauthorized sign-in
  2. Audio upload, transcription, content analysis, video generation, editing, preview, and export
  3. Storing and providing projects, Output, and usage history
  4. Administering credit balances and usage volume
  5. Maintaining the Service, investigating failures, improving quality, and ensuring security
  6. Investigating and responding to misuse, breaches of the Terms, infringement of rights, and defects
  7. Responding to inquiries, requests for disclosure, and other communications
  8. Notifying users of material changes, incidents, security matters, and transactions
  9. Performing legal obligations and exercising or defending rights
  10. Creating statistical information processed so that individuals cannot be identified, and improving the Service

The Operator does not use the information it collects for the purpose of training or tuning artificial intelligence models.

Where advertising email or communications for a different purpose are sent, the Operator will obtain the consent required by law or provide a means of opting out.

4. Service Providers and International Transfers

To the extent necessary to provide the Service, the Operator transmits information to, or entrusts its handling to, the following external services. The information transmitted varies with settings, input, and the features used.

  1. The handling of information by each external service is governed by that provider's contractual terms and privacy policy.
  2. Data sent to the OpenAI API is not used to train or improve OpenAI's models unless the Operator expressly opts in to data sharing. Inputs and outputs may nevertheless be retained for up to 30 days for purposes such as abuse monitoring.
  3. The Operator uses settings that do not permit ElevenLabs to use submitted data for model training. Audio and transcripts may nevertheless be retained under that provider's policies for transcription processing, service improvement, troubleshooting, or security.
  4. Audio, images, video, and the database are stored in the Tokyo region (asia-northeast1) of Google Cloud. However, for some operational logs such as access logs, the storage region is not specified.
  5. Provision to the following providers constitutes provision of personal data to a third party in a foreign country.
  1. The provision described in the preceding paragraph is made to providers that have established systems conforming to the standards prescribed in Article 28 of the Act on the Protection of Personal Information. Information about the personal data protection regime of the destination country, the measures taken by the provider, and related matters is available upon request to info@otopict.com.
  2. The Operator selects service providers appropriately and exercises necessary and appropriate supervision through contracts and other means.

5. Disclosure to Third Parties

The Operator does not provide personal data to third parties except in the following cases.

  1. Where the individual has consented
  2. Where required by law
  3. Where necessary to protect a person's life, body, or property and it is difficult to obtain the individual's consent
  4. Where personal data is provided in connection with a business succession
  5. Where, under the Act on the Protection of Personal Information, the case constitutes entrustment, joint use, or another situation not treated as provision to a third party

6. Cookies

  1. The Service uses a session cookie to maintain sign-in state and a cookie to prevent forged requests.
  2. Session cookies are protected using the HttpOnly, Secure, and SameSite attributes and related controls. A sign-in session is valid for up to 14 days.
  3. Interface preferences such as the display language may be stored on the device.
  4. The Service does not use cookies for analytics, advertising, or marketing purposes. If such cookies are added, this Policy will be updated and the necessary consent management put in place.

7. Retention and Deletion

  1. The Operator retains information for the period necessary to achieve the purposes of use and to provide the Service, investigate failures, maintain security, handle disputes, and comply with law. The principal retention periods are as follows.
  1. The timing of deletion of the objects in the preceding paragraph may vary due to updates, duplication, backups, incident response, or legal requirements.
  2. Deletion of a project or an account is first processed as deactivation and logical deletion. To request physical deletion of personal data relating to a closed account, please make a request to info@otopict.com. Following identity verification, the Operator will physically delete the data without delay, except for data that must be retained for legal obligations, misuse investigations, or the preservation of rights.
  3. Access logs and security logs may be retained for a longer period, limited to the period necessary, where required to investigate failures, misuse, security incidents, or legal matters.
  4. Erasure of information from backups may take longer than in the production environment. Information in backups is also deleted within a reasonable period and, in the meantime, is not used for any purpose other than restoration, security, or legal compliance.
  5. Information that must be retained for legal obligations, misuse investigations, or the preservation of rights may be retained, limited to the necessary scope and period.

8. Security Measures

To prevent leakage, loss, or damage of the information it handles, the Operator takes the following security measures.

Organizational measures

Personnel measures

Physical measures

Technical measures

Understanding the external environment

Further details of these security measures are available, to the extent consistent with security, upon request to info@otopict.com.

9. Rights and Request Procedures

Under applicable law, users may request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or cessation of provision to third parties in respect of their retained personal data. Requests for the information on international transfers described in Section 4, Paragraph 6, and for the physical deletion described in Section 7, Paragraph 3, are accepted at the same contact point.

Following identity verification, the Operator responds without delay in accordance with law. Where law permits the Operator not to comply with a request, the Operator will explain the reason to the extent possible.

10. Children

The Service may only be used by persons aged 18 or over.

11. Response to Leakage and Similar Incidents

Where leakage, loss, damage, or another incident involving personal data occurs, the Operator will investigate the scope of impact, prevent its spread, take measures to prevent recurrence, and notify the relevant authorities and affected individuals as required by law.

12. Changes to This Policy

  1. The Operator may change this Policy in response to changes in law, the Service, or the handling of information.
  2. Material changes will be notified before the effective date by display within the Service, by sending to the registered email address, or by another appropriate method.
  3. Where a change requires consent under law, the Operator will obtain that consent separately.

13. Contact

Inquiries regarding the handling of personal information, disclosure of Operator information, complaints, and this Policy may be sent to:

14. Language

This Policy is prepared in a Japanese version and an English version. For users residing in Japan, the Japanese version prevails; for users residing outside Japan, the English version prevails. The non-prevailing version is provided as a reference translation, and in the event of a discrepancy between the two versions, the prevailing version governs.

Revision History

When this Policy is revised, the revision date, the parts revised, and the purpose of the revision are recorded here.