Privacy policy
What Comeyomi collects, why, how long it is kept, and which external services it reaches. A reference translation; the Japanese text is the binding one.
Last updated
This is a reference translation. The Japanese text is the binding version. Where the two differ, the Japanese governs.
1. Operator
KOOFFICE, Inc. Representative Director: Kazuhiro Kubota 3-7-7 Ichikawaminami, Ichikawa, Chiba 272-0033, Japan Contact: support@comeyomi.com
2. What we collect
Use on X
- The X id, username and display name of whoever summoned the bot
- Display names, handles, profile image URLs and text in replies to the Space's announcement post
- Participants' display names and handles, for announcing joins and speaker requests
- Space and post ids and URLs, and host and co-host ids
- Time used, for billing measurement
The text of the summoning mention is used only to decide that it is a summon, and is not stored.
Web chat
- On signing in: X id, username, display name, profile image URL. The access token is not stored
- Text, images, audio and video you post, hearts, and your reading voice setting
- A device id (a random value) for viewers who are not signed in
Images, video and recordings are converted on the device before upload, so metadata such as location is not sent.
To show a preview of a posted URL, the server fetches information from the link target. No information about the viewer is sent to that target.
Anonymous participation
When you take part anonymously, other users and the host cannot tell who posted. Internally the post is held against your X account, and that link is deleted when the Space ends.
Where a report is being handled, or where the law requires it, we may identify the poster. For reported posts, the link to the person is retained as a record of how the report was handled.
Reports and blocks
To handle reports and blocks, we process the ids and usernames of the reporter and the subject, the message text and media URLs, and the stated reason. Reports are sent to our Slack.
Paid membership
We obtain the Stripe customer id, contract status and contract period. Card details and the email address used at payment are handled by Stripe and are not stored by us.
Enquiries
We collect the email address and the content of the enquiry.
Analytics, advertising and operational metrics
- Google Analytics processes page URLs and titles, chat interaction events, and a hash of the X id
- Article pages carry advertising through Google AdSense
- As operational metrics we record Space ids, the display name of the person read out, and counts. Error logs may contain the beginning of a read-out message or a display name
3. Why we use it
- Summoning the bot, joining Spaces and reading aloud
- Providing the web chat
- Handling misuse, including reports, blocks and suspension
- Measuring usage and billing members
- Responding to faults and improving the service
- Covering running costs through advertising
- Answering enquiries
4. Retention
Web chat posts, and the anonymous link
Text, images, audio and video you post, and the link between an anonymous participant and their X account, are deleted when the Space ends. Where the bot disconnects and does not return, within 24 hours at the latest. Media is deleted within 7 days at the latest even where deletion failed or the upload was never posted.
The link between a reported post and the person, however, is retained as a record of how the report was handled.
Summon and reading records
Traces of summons and readings are kept for 14 days.
Sign-in
A sign-in lasts 30 days.
Account, usage, contract and report records
Account information, records of time used, membership contract records, and records of reports, blocks and how they were handled are kept for as long as the purpose requires. We act on deletion requests except for records needed by law or to handle misuse.
5. External services and where they are
We use the following external services. All of these companies are located in the United States.
- X Corp. — retrieving mentions, posts and Space information, and joining Spaces
- Cloudflare, Inc. — delivery, database, storage
- Google LLC — Google Cloud, Google Analytics, Google AdSense
- Stripe, Inc. — membership payments
- Slack Technologies, LLC — report notifications to us
Google Cloud is used to run the bot and VOICEVOX on Cloud Run (Tokyo region), and to hold the bot's X sign-in details in Secret Manager. VOICEVOX runs in an environment we manage.
The X id and username are sent to Stripe as customer metadata.
On data-protection regimes in other countries, see the survey pages of Japan's Personal Information Protection Commission (Japanese).
6. Cookies, device storage and transmission
Sign-in and device storage
Sign-in uses an HttpOnly cookie, comeyomi_x_session, valid for 30 days.
Stored on the device: the theme, the device id used when not signed in, the anonymous-participation choice per Space, and the advertising interval. A service worker also caches pages.
Google Analytics
We use Google Analytics to understand usage, collecting information through cookies. Page URLs and titles and chat interaction events are sent to Google. A chat page title contains the host's @handle, and events sent from the server use a hash of the X id as the user identifier (user_id).
To turn off collection by Google Analytics, use the Google Analytics opt-out add-on.
Google AdSense
Article pages carry Google AdSense to cover running costs. Third-party providers including Google may use cookies and serve advertising based on visits to this and other sites.
Personalised advertising can be turned off in Google's ad settings. For turning off third-party providers' cookies, see aboutads.info.
Profile images
Profile images are loaded from X's image servers (pbs.twimg.com).
7. Security measures
We encrypt traffic, restrict access to administrative screens, delete data once its retention period has passed, and manage secrets.
8. Disclosure, correction, suspension and deletion
To request disclosure, correction, suspension of use or deletion, write to support@comeyomi.com. We verify identity through the X account before acting. Retention and deletion are covered in section 4.
9. Revisions
When this policy is reviewed, the current version is published on this page and the last-updated date is changed.