メインコンテンツへスキップ

Privacy Policy

256 GIKEN Co., Ltd. (“we,” “us,” or “our”) sets out below how the iOS app “Koedori” (the “App”) handles information.

Effective: August 16, 2026 / Last updated: August 18, 2026

Japanese / Service information / Terms of Use

1. Core approach

The App's recording, ordinary transcription, on-device titles, summaries and minutes, search, playback, and similar features run on your iPhone as core features. By default, recordings, transcripts, summaries, and other Content of yours, together with location history, are not sent to our servers.

Koedori Plus Cloud Processing runs only when you select a record and an action and proceed from its confirmation screen, or, for a feature you enable through its confirmation screen, only within the scope described for that feature. The encrypted audio Vault is off by default and operates only after you explicitly enable it in Settings. Usage sharing is also off by default.

2. Controller

The controller of the information described in this Policy is 256 GIKEN Co., Ltd., PLAT295, 1-7-9 Narihira, Sumida-ku, Tokyo 130-0002, Japan. Submit privacy questions or rights requests through the contact form on our website.

3. Information we handle

Depending on the features you use, we handle:

  • On-device records: recordings, transcripts, titles, summaries, minutes, speaker names, calendar overlays, location history, and other content the App creates on your device. These are generally stored on the device.
  • Content sent for Cloud Processing: the recording or transcript text confirmed for that action or covered by a feature you have enabled. If you separately enable calendar context, this may include the title of a relevant calendar event. Location is not sent for Cloud Processing.
  • Anonymous server-account information: a random identifier generated by the device, anonymous user and session identifiers, and the IP address and user agent needed to secure a session.
  • Subscription information: App Store product and transaction identifiers, subscription status, expiration, Sandbox or Production environment, and the link to the device's random identifier. We do not receive card details.
  • Cloud-usage records: opaque record and job identifiers, action type, audio duration, usage amount, processing state, timestamps, and fault category.
  • Vault management information: ciphertext identifiers, type, size, verification values, storage state, and timestamps. The Vault holds recordings only; titles, summaries, and other text are not included.
  • Optional usage information: when you enable usage sharing, feature counts, duration or size bands, outcome categories, device capabilities, and locale. It does not include free-form text, audio, transcripts, summaries, calendar content, locations, or coordinates.

No name or email registration is required. We nevertheless treat random identifiers, IP addresses, voice, and other information as personal data where they can identify a person alone or in combination with other information.

4. Purposes and legal bases

We process the information above for the following purposes. In the EEA, UK, and other places that require us to identify a legal basis, the applicable bases are shown in parentheses.

  1. verifying subscriptions, providing Plus features, and enforcing usage allowances (performance of a contract);
  2. performing the cloud transcription, summaries, minutes, speaker organization, or other processing you select (performance of a contract and your affirmative action);
  3. storing, retrieving, and recovering encrypted audio and applying the post-subscription Vault lifecycle (performance of a contract);
  4. making retries idempotent, preventing double counting and abuse, investigating faults, and operating the Service safely (our and our customers' legitimate interests);
  5. optional usage sharing, calendar-title transmission, location, and other optional features that you enable (consent); and
  6. complying with valid legal, regulatory, or court requirements (legal obligation).

You may stop consent-based processing at any time in the App or iOS Settings without affecting processing that occurred before withdrawal. Disabling an optional feature does not prevent use of Core Features unrelated to it.

5. Cloud Processing, processors, and disclosures

Cloud-processing content is sent over TLS to our server. To provide the Service, we engage providers of cloud infrastructure, speech recognition, language processing, analytics, and similar services to handle information on our behalf. In addition, depending on the features you select, Apple's App Store, Maps, iCloud Keychain, speech recognition, and on-device-model services handle information.

We send each processor only the minimum information needed to perform the selected feature. Through contracts or other appropriate measures, we require processors to act on our instructions, restrict secondary use, protect confidentiality and security, manage subprocessors, and assist with deletion. We select services, terms, or settings that do not permit Your Content to be used to train a processor's general-purpose models. A processor may nevertheless retain limited records for abuse detection, safety, or legal compliance under its service terms.

We do not use processor features for logging, tracking, or profiling that are not needed to provide the Service. We do not sell personal data or disclose it to third parties except with your consent, as a processor needs it, as required for a corporate transaction, or as required by law.

6. Retention and deletion

We retain information only for the period needed under the following periods or criteria:

  • On-device records: until you delete them or your selected on-device audio-retention period expires.
  • Cloud-processing content and results: deleted without undue delay after processing completes. Results awaiting retrieval by you, and data whose processing could not be completed, are likewise deleted without undue delay once they are no longer needed.
  • Anonymous account, purchase linkage, and usage records: while the account exists and as needed to provide Plus, enforce allowances, make retries safe, investigate faults, or prevent abuse. Deleting your data in the cloud in the App deletes the information linked to that account.
  • Vault ciphertext: bulk retrieval remains available for 30 days after subscription lapse, after which the Vault freezes. Individual retrieval remains available until deletion, and ciphertext is deleted six months (180 days) after lapse. Account deletion queues it for immediate deletion, with scheduled retries after a failure.
  • Optional usage information: for the period needed for statistical analysis; deleted once no longer needed.
  • Deletion markers and notification-deduplication records: without linking them to the former account, name, email, or Your Content, for as long as needed to prevent silent account recreation, duplicate notification processing, or abuse. We periodically review that need.

Deleted data may remain temporarily in disaster-recovery backups until overwritten through the ordinary retention cycle and is not used for any other purpose. We may segregate and retain information for only as long as required by law, to establish or defend legal claims, or to resolve a dispute.

7. Encrypted audio Vault (optional, Koedori Plus)

The Vault is off by default. Once you enable it in Settings, the App encrypts recordings on your device before uploading them automatically. The Vault holds recordings only; titles, summaries, and other text remain on your device. The decryption key remains on your device and in iCloud Keychain; we do not keep it. We and our storage provider receive ciphertext, and we cannot decrypt it on our own. Only where you request Cloud Processing for a recording you have stored in the Vault is the key for decrypting that recording sent together with the processing request. We do not store that key and use it solely for the processing you requested.

If you lose the decryption key, we cannot recover the ciphertext. Keep necessary data on a device or another location that you control.

8. International processing and transfers

We are established in Japan. Handling outside Japan falls into two categories.

Storage and execution infrastructure

The storage and execution infrastructure for the Service is supplied by providers established in the United States, and their facilities are located in the United States and other countries. Those providers are contractually barred from handling the content of the information stored with them, and we maintain that position through access controls and other measures. We keep ourselves informed of the personal-data protection regimes in those countries and take the security measures that are necessary and appropriate.

Cloud Processing providers (speech recognition and language processing)

For Cloud Processing, we provide the content of the record you selected to providers established in the United States. We do so on the basis of your consent to provision to a third party in a foreign country, given on the confirmation screen the App displays when you use Cloud Processing or enable such a feature. That screen links to this Policy and the Terms of Use and asks you to review this section before deciding whether to consent.

  • Country of the recipient: United States
  • Personal-data protection regime in that country: the United States has no comprehensive federal statute governing the private sector generally, and it has regimes for government access to information that may affect the rights and interests of individuals.
  • Measures taken by the recipient: we select providers that have implemented measures corresponding to all eight principles of the OECD Privacy Guidelines.

You may ask about the specific handling through our contact form.

9. Your choices and rights

Subject to applicable law, you may ask us for notice of processing purposes, access, correction, completion, deletion, suspension, restriction, data portability, objection, or cessation of third-party disclosure relating to your information. You may withdraw consent prospectively where processing relies on consent. You may also complain to the data-protection authority where you live.

You can delete on-device records in the App and delete your data in the cloud from Settings. Apple manages the subscription separately, so account deletion does not cancel it; cancel through App Store subscription settings.

Submit a request through our contact form. To avoid disclosing another person's information, we may verify a request concerning an anonymous account using an identifier on the device or an Apple-signed transaction. We respond without undue delay, ordinarily within 30 days, and will explain any extension permitted by law.

The Service does not make solely automated decisions that produce legal or similarly significant effects concerning you.

10. Security

We use technical and organizational measures appropriate to the nature and risk of the information, including encrypted transport, access controls, least privilege, disabled body logs and caching, on-device encryption, deletion queues and retries, monitoring, and processor management. We do not possess the Vault decryption key.

If a data incident occurs and applicable law requires notice, we will provide information about its effects, our response, and steps you can take as required by law.

11. Device permissions and other communications

  • Microphone: recording.
  • Speech Recognition: on-device transcription on supported devices.
  • Calendar: reading events for timeline overlays when enabled. The App does not create, change, or delete events.
  • Location: on-device recording of places when enabled. Coordinates may be sent to Apple's map service to display maps or resolve place names.
  • Notifications: notices about the state of a recording. All notifications are issued on the device; we do not send push notifications.
  • iCloud Keychain: secure synchronization of the Vault decryption key and device identifier among compatible devices belonging to your Apple Account.

The App communicates with our server to verify subscription status and provide Plus features. That communication does not include recordings, transcripts, or other Content of yours. It also communicates with Apple and other distribution providers to download and update the App, process purchases, and obtain on-device models. If you connect an external device, the App communicates with it over Bluetooth. You can review each permission in iOS Settings.

12. Minors

A minor or anyone who cannot independently give valid consent must obtain consent from their parent or legal representative before using the App. If we learn that we collected a minor's information without legally required consent, we will take reasonable steps to verify the circumstances and delete it or take other required action.

13. Changes and contact

When we revise this Policy, we update the last-updated date on this page and the in-app display. Before a new purpose, a material change in recipients, or another change that materially affects your rights takes effect, we will provide an in-app notice and obtain renewed consent where required by law.

For questions, please use the contact form on our website.