プライバシーポリシー
本プライバシーポリシーは、ビジネスパーソン向けAI名刺管理・企業リサーチツール「PixWork」(以下「本アプリ」)の開発者(以下「運営者」)が、ユーザーの情報をどのように取り扱うかについて、Google APIから取得するデータの取り扱いを含めて説明するものです。
本アプリは、連絡先データを端末とユーザー自身のGoogleスプレッドシートに保存する「ローカルファースト」設計です。スプレッドシートの行データ(顧客情報)は運営者のプロキシサーバーを経由せず、端末とGoogleのAPIとの間で直接同期されます。運営者のサーバーに保存されるのは、アカウント情報、課金・利用状況、および Google Sheets 連携を有効化した場合の暗号化されたリフレッシュトークンのみです(詳細は以下の各章をご覧ください)。
1. アクセスするGoogleユーザーデータ
- Googleログインのアカウント情報: GoogleアカウントID・メールアドレス・表示名・アバターURL。PixWorkアカウントの作成・管理に使用します。
- Google Sheets連携(任意・初期状態は無効): チーム同期を明示的に有効化した場合のみ、最小権限スコープ drive.file だけを要求します。このスコープでアクセスできるのは、(a) PixWorkが作成したスプレッドシートと、(b) ユーザーが公式のGoogle Pickerで明示的に選択したスプレッドシート(本人所有・他の人から共有されたもの・共有ドライブ上のものを含む)のみです。
- 選択ファイルの限定的なメタデータ(ファイルID・名前・MIMEタイプ・ゴミ箱状態・編集可否)。選択内容の検証に使用します。
- 選択シート内の「Contacts」「Companies」シートのセル内容。双方向同期に使用します。
Googleドライブ内の無関係なファイルを閲覧・列挙・アクセスすることはありません。通常のログインだけでは、Drive/Sheetsのアクセス許可を要求しません。
2. Googleユーザーデータの利用方法
- 端末と、ユーザーが作成・選択したスプレッドシートとの間での連絡先・企業情報の双方向同期(競合検出を含む)にのみ使用します。読み書きは、ユーザーが指示した同期操作のみです。
- Googleユーザーデータを広告、与信・融資判断、汎用AI/MLモデルの学習・改善に使用することはありません。
- スプレッドシートの内容がAIプロバイダーへ自動送信されることはありません。連絡先・企業の「リサーチ」「Company Brief」をユーザーが明示的にタップした場合のみ、その企業名だけが検索クエリとしてPixAppsプロキシ経由でリサーチプロバイダー(Web検索およびGeminiモデル)へ送信されます。
3. データの送信経路
- スプレッドシートの行データは、端末上のアプリとGoogleのAPIとの間をTLSで直接送受信されます。PixAppsプロキシサーバーは行データを受け取りません。
- PixAppsプロキシが受け取るもの: ログイン時のGoogle IDトークン、セッショントークン、Sheets連携有効化時の一回限りの認可コード、AI文字抽出のためにユーザーが送信したスキャン画像(リアルタイム処理後、直ちに破棄)、およびユーザーが明示的にリサーチを実行した場合の企業名クエリです。
- アナリティクス・クラッシュレポート(Firebase)には、利用イベント(画面名・件数・所要時間・成否フラグ)と、Firebaseが割り当てるアプリインスタンス・端末識別子が送信されます。アクセストークン・リフレッシュトークン・認可コード・スプレッドシートID・セル内容をアナリティクスへ送信することはありません。
4. データ保護とトークンの保管
- すべての通信はTLS(HTTPS)で保護されます。
- アクセストークンは短命で、端末内にのみ保持されます。
- Googleリフレッシュトークン: Google Sheets連携を有効化した場合のみ、AES-GCMで暗号化のうえサーバーデータベース(Cloudflare D1)に保存されます。これはGoogle Sheetsアクセスのサイレント更新(再認可の手間の回避)のためだけに使用され、連携解除またはアカウント削除まで保持され、その時点でGoogleへの失効(ベストエフォート)と削除が行われます。通常のログインだけでは作成されません。
- アクセストークン・リフレッシュトークン・認可コード・セル内容を本番ログへ記録することはありません。
5. その他の収集データ
- アカウントデータ: GoogleアカウントID・メール・表示名・アバターURL・プラン(ティア)・API利用回数をサーバーデータベースに保存します。
- スキャンした内容: スキャン画像はリアルタイムAI処理後に直ちに破棄され、運営者のサーバーには保存されません。抽出テキスト・連絡先・サムネイル・QRコードは端末内(IndexedDB/LocalStorage)にのみ保存されます。未解析の名刺写真(「あとで解析」を選んだ場合、オフラインで撮影した場合、解析に失敗した場合など)は、解析が完了するかユーザーが削除するまで、アプリ内のローカルデータベース(IndexedDB)にのみ保存され、端末の写真アプリへ自動保存されることはありません。
- 課金情報: サブスクリプション・購入の状態は、RevenueCatおよびApple/Googleにより処理されます。
6. 保持と削除
- 端末内: 連絡先・抽出テキスト・サムネイル・未解析の名刺写真(スキャン待ちキュー)・設定・選択中のスプレッドシートID・短命のアクセストークン。
- サーバー: アカウント情報、課金・利用状況、および(Sheets連携時のみ)暗号化リフレッシュトークン。
- Google Sheets連携の解除(設定 → チーム同期): サーバー保存のリフレッシュトークンの失効(ベストエフォート)と削除、ローカルのアクセストークンの削除、シート選択の解除が行われます。Googleスプレッドシート本体とローカルの連絡先は削除されず、以後同期APIは呼ばれません。
- アプリ内での連絡先削除はソフト削除であり、チームスプレッドシートに Status = Deleted として同期されます(行自体はシートに残ります)。これはローカルデータの恒久削除とは異なります。
- ローカルデータの削除: 設定 → システム → 危険ゾーンの「ローカルデータを削除」で、端末内の全ローカルデータ(連絡先・企業情報・スキャン待ち・設定・セッション・トークン・連携シートの選択)を恒久削除できます。Googleドライブ上のスプレッドシート本体とサーバー上のアカウントは残ります。
- アカウント削除(設定 → 危険ゾーン): サーバー上のアカウント・利用記録・購入付与記録・リフレッシュトークンを完全に削除し(Googleへの失効はベストエフォート)、端末内データも消去します。決済事業者(Apple/Google/RevenueCat)は法令・会計・不正防止のため、各社のポリシーに基づき記録を保持する場合があります。
- スプレッドシートは常にユーザー自身のGoogleアカウントに残ります。PixWorkがGoogle Sheetsファイルを削除することはありません。
7. 第三者サービス
- Google Cloud & API: 認証(Googleログイン)、Google Picker、同期機能のためのGoogle Sheets/Drive API。
- AI・検索プロバイダー(PixAppsプロキシ経由): 画像文字抽出・企業ブリーフのためのGeminiモデル、企業リサーチのためのWeb検索API(Tavily)。いずれもスキャンやリサーチ等、ユーザーの明示操作時のみ呼び出されます。PixWork自身がユーザーのデータを汎用AI/MLモデルの学習・改善に使用することはありません。プロバイダー側でのデータの取扱いは各プロバイダーの規約に従います。
- RevenueCat / Apple / Google Play: 課金・サブスクリプション管理。
- Firebase Analytics / Crashlytics: アプリインスタンス識別子を伴う利用イベント・クラッシュ情報(連絡先の内容やトークンは含まれません)。
8. 広告(無料プランのみ)
- 無料(Free)プランでは、一部の画面に Google Mobile Ads SDK(AdMob)によるバナー広告を表示します。PixWork Plus プランではバナー広告を要求・表示しません。
- Google Mobile Ads SDK は、ユーザーの同意状態やOSの設定に応じて、Google自身のプライバシーポリシーの下で広告関連情報(端末情報・アプリ識別子等)を処理する場合があります。
- 初期版では非パーソナライズ広告(NPA)のみを要求します。
- 名刺画像・連絡先・OCR結果・会社情報を広告ターゲティングへ渡すことはありません。
- Google Workspace API から得たデータを広告目的に利用することはありません。
- 地域によっては、Google の User Messaging Platform(UMP)同意フォームおよびアプリ内の設定「広告のプライバシー設定」から、広告のプライバシー選択を管理できます。
9. お客様の権利
お住まいの地域の法令(GDPRを含む)に基づき、個人データへのアクセス、訂正、削除、処理の制限・異議、および同意の撤回の権利があります。削除はアプリ内(第6章)から直接実行できるほか、サポートへのご連絡でも承ります。
10. ポリシーの変更
運営者は、法改正や機能追加に伴い、本ポリシーを改定することがあります。重要な変更がある場合は、アプリ内の通知または公式サイトにて告知します。
Privacy Policy
Welcome to PixWork. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what data PixWork ("the App", operated by "the Operator", "we") accesses, how it is used, where it is transferred, how it is protected, and how you can delete it, including our handling of data received from Google APIs.
The App follows a local-first design: your contacts live on your device and in your own Google Sheets. Spreadsheet row data (your customer records) does not pass through the PixApps proxy server — it syncs directly between your device and Google's APIs. What our servers store is limited to your account record, billing/usage state, and — only if you enable Google Sheets sync — an encrypted Google refresh token (see the sections below).
1. Google User Data We Access
- Google Sign-In identity: your Google account ID, email address, display name, and avatar URL, used to create and manage your PixWork account.
- Google Sheets integration (optional, off by default): if you explicitly enable Team Sync, PixWork requests the drive.file scope only. This per-file scope lets PixWork access only (a) spreadsheets PixWork itself creates for you, and (b) spreadsheets you explicitly select through the official Google Picker — including sheets you own, sheets shared with you, and sheets in a Shared Drive.
- Limited file metadata of the selected spreadsheet (file ID, name, MIME type, trash status, and edit capability), used to validate your selection.
- Cell contents of the
ContactsandCompaniessheets inside the spreadsheet you created or selected, used for two-way sync.
PixWork does not browse, list, or access unrelated files in your Google Drive. Sign-in alone never requests any Google Drive or Google Sheets access.
2. How We Use Google User Data
- Two-way synchronization of contact and company records between your device and the spreadsheet you created or selected (including conflict detection). PixWork performs only the reads/writes you direct.
- We do not use Google user data for advertising, for creditworthiness or lending decisions, or to train or improve generalized AI/ML models.
- Spreadsheet contents are not automatically forwarded to any AI provider. Only when you explicitly tap "Research" / "Company Brief" is that company's name (only) sent as a search query via the PixApps proxy to our research providers (web search and the Gemini model). This never happens automatically.
3. Data Transfer
- Spreadsheet row data travels directly between the app on your device and Google's APIs over TLS. The PixApps proxy server does not receive your spreadsheet row data.
- The PixApps proxy receives: your Google identity token at sign-in, your session token, the one-time Google authorization code when you enable Sheets sync, scanned images you submit for AI text extraction (processed in real time and immediately discarded), and — only when you explicitly request research — the company-name query.
- Analytics and crash reporting (Firebase) receive usage events (screen names, counts, durations, success/failure flags) together with app-instance and device identifiers assigned by Firebase. Access tokens, refresh tokens, authorization codes, spreadsheet IDs, and spreadsheet cell contents are never sent to analytics or crash reporting.
4. Data Protection & Token Storage
- All network communication uses TLS (HTTPS).
- Access tokens are short-lived and kept on your device only.
- Google refresh token: created only when you enable Google Sheets sync — never at plain sign-in. It is encrypted with AES-GCM and stored in our server database (Cloudflare D1), used solely to silently renew your Google Sheets access so you do not have to re-authorize repeatedly. It is retained until you disconnect Google Sheets or delete your account, at which point it is revoked with Google (best effort) and deleted.
- Access tokens, refresh tokens, authorization codes, and spreadsheet cell contents are never written to production logs.
5. Other Data We Collect
- Account data: Google account ID, email, display name, avatar URL, subscription tier, and API usage counts, stored in our server database.
- Scanned content: scanned images are processed by AI in real time and immediately discarded; they are not stored on our servers. Extracted text, contact details, thumbnails, and QR codes are stored locally on your device (IndexedDB/LocalStorage). Card photos that have not been analyzed yet — for example when you choose "Analyze Later", scan while offline, or an analysis attempt fails — are kept only on your device, in the app's local database (IndexedDB), until they are analyzed or you delete them; they are never automatically saved to your device's photo library.
- Transaction data: subscription and purchase state processed via RevenueCat and Apple/Google.
6. Retention & Deletion
- On your device: contacts, extracted text, thumbnails, unanalyzed card photos awaiting analysis (the pending-scan queue), settings, the selected spreadsheet ID, and the short-lived Google access token.
- On our servers: your account record, billing/usage data, and — only when Sheets sync is enabled — the encrypted refresh token.
- Disconnect Google Sheets (Settings → Team Sync): revokes (best effort) and deletes the server-stored refresh token, deletes the local access token, and clears the selected spreadsheet ID. Your Google Sheets file and your local contacts are NOT deleted, and no further sync calls are made.
- Deleting a contact in the app is a soft deletion: it is synchronized to the team spreadsheet as
Status = Deleted; the row itself remains in the sheet. This is different from permanent deletion of your local data. - Local data deletion: Settings → System → Danger Zone → "Delete Local Data" permanently deletes all PixWork local data on the device (contacts, companies, pending scans, settings, session, tokens, and the linked-sheet selection). The spreadsheet in your Google Drive and your server account remain.
- Account deletion (Settings → Danger Zone): permanently deletes your account record, usage records, purchase-grant records, and the stored refresh token from our servers (the refresh token is also revoked with Google, best effort), and clears local device storage. Records required for legal, accounting, or fraud-prevention purposes may be retained by our payment processors (Apple/Google/RevenueCat) under their own policies.
- Your spreadsheets always remain in your own Google account. PixWork never deletes your Google Sheets files.
7. Third-Party Services
- Google Cloud & APIs: authentication (Google Sign-In), Google Picker, and the Google Sheets/Drive APIs for the sync feature.
- AI & search providers (via the PixApps proxy): the Gemini model for image text extraction and company briefs, and a web search API (Tavily) for company research. These are invoked only by your explicit actions (scanning, research). PixWork itself does not use your data to train or improve generalized AI/ML models; how a provider handles submitted data is governed by that provider's own terms.
- RevenueCat / Apple / Google Play: subscription and purchase management.
- Firebase Analytics / Crashlytics: usage events and crash data with app-instance identifiers; never contact contents or tokens.
8. Advertising (Free plan only)
- The Free plan uses the Google Mobile Ads SDK (AdMob) to display banner ads on selected screens. The PixWork Plus plan does not request or display banner ads.
- The Google Mobile Ads SDK may process advertising-related information (such as device information, app identifiers, and coarse signals) depending on your consent status and OS-level settings, under Google's own privacy policy.
- In the initial release, PixWork requests non-personalized ads (NPA) only.
- We never pass business card images, contacts, OCR results, or company information to ad targeting.
- Data obtained from Google Workspace APIs is never used for advertising purposes.
- Where required by your region, you can manage your ad privacy choices via Google's User Messaging Platform (UMP) consent form and the in-app "Ad Privacy Options" entry (Settings).
9. Your Legal Rights
Depending on your jurisdiction (including the GDPR), you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to withdraw consent at any time. You can exercise deletion directly in the app (Section 6) or contact support.
10. Policy Changes
We may revise this Privacy Policy as laws change or features are added. Significant updates will be announced via in-app notice or our website.
お問い合わせ Contact Us
本プライバシーポリシーに関するご質問は、以下までご連絡ください。 If you have any questions about this Privacy Policy, please contact us at:
📧 Email: [email protected]
🏢 Developer: Yosuke Suzuki