Privacy policy

What Comeyomi collects, why, how long it is kept, and which external services it reaches. A reference translation; the Japanese text is the binding one.

Last updated

This is a reference translation. The Japanese text is the binding version. Where the two differ, the Japanese governs.

1. Operator

KOOFFICE, Inc. Representative Director: Kazuhiro Kubota 3-7-7 Ichikawaminami, Ichikawa, Chiba 272-0033, Japan Contact: support@comeyomi.com

2. What we collect

Use on X

  • The X id, username and display name of whoever summoned the bot
  • Display names, handles, profile image URLs and text in replies to the Space's announcement post
  • Participants' display names and handles, for announcing joins and speaker requests
  • Space and post ids and URLs, and host and co-host ids
  • Time used, for billing measurement

The text of the summoning mention is used only to decide that it is a summon, and is not stored.

Web chat

  • On signing in: X id, username, display name, profile image URL. The access token is not stored
  • Text, images, audio and video you post, hearts, and your reading voice setting
  • A device id (a random value) for viewers who are not signed in

Images, video and recordings are converted on the device before upload, so metadata such as location is not sent.

To show a preview of a posted URL, the server fetches information from the link target. No information about the viewer is sent to that target.

Anonymous participation

When you take part anonymously, other users and the host cannot tell who posted. Internally the post is held against your X account, and that link is deleted when the Space ends.

Where a report is being handled, or where the law requires it, we may identify the poster. For reported posts, the link to the person is retained as a record of how the report was handled.

Reports and blocks

To handle reports and blocks, we process the ids and usernames of the reporter and the subject, the message text and media URLs, and the stated reason. Reports are sent to our Slack.

Paid membership

We obtain the Stripe customer id, contract status and contract period. Card details and the email address used at payment are handled by Stripe and are not stored by us.

Enquiries

We collect the email address and the content of the enquiry.

Analytics, advertising and operational metrics

  • Google Analytics processes page URLs and titles, chat interaction events, and a hash of the X id
  • Article pages carry advertising through Google AdSense
  • As operational metrics we record Space ids, the display name of the person read out, and counts. Error logs may contain the beginning of a read-out message or a display name

3. Why we use it

  • Summoning the bot, joining Spaces and reading aloud
  • Providing the web chat
  • Handling misuse, including reports, blocks and suspension
  • Measuring usage and billing members
  • Responding to faults and improving the service
  • Covering running costs through advertising
  • Answering enquiries

4. Retention

Web chat posts, and the anonymous link

Text, images, audio and video you post, and the link between an anonymous participant and their X account, are deleted when the Space ends. Where the bot disconnects and does not return, within 24 hours at the latest. Media is deleted within 7 days at the latest even where deletion failed or the upload was never posted.

The link between a reported post and the person, however, is retained as a record of how the report was handled.

Summon and reading records

Traces of summons and readings are kept for 14 days.

Sign-in

A sign-in lasts 30 days.

Account, usage, contract and report records

Account information, records of time used, membership contract records, and records of reports, blocks and how they were handled are kept for as long as the purpose requires. We act on deletion requests except for records needed by law or to handle misuse.

5. External services and where they are

We use the following external services. All of these companies are located in the United States.

  • X Corp. — retrieving mentions, posts and Space information, and joining Spaces
  • Cloudflare, Inc. — delivery, database, storage
  • Google LLC — Google Cloud, Google Analytics, Google AdSense
  • Stripe, Inc. — membership payments
  • Slack Technologies, LLC — report notifications to us

Google Cloud is used to run the bot and VOICEVOX on Cloud Run (Tokyo region), and to hold the bot's X sign-in details in Secret Manager. VOICEVOX runs in an environment we manage.

The X id and username are sent to Stripe as customer metadata.

On data-protection regimes in other countries, see the survey pages of Japan's Personal Information Protection Commission (Japanese).

6. Cookies, device storage and transmission

Sign-in and device storage

Sign-in uses an HttpOnly cookie, comeyomi_x_session, valid for 30 days.

Stored on the device: the theme, the device id used when not signed in, the anonymous-participation choice per Space, and the advertising interval. A service worker also caches pages.

Google Analytics

We use Google Analytics to understand usage, collecting information through cookies. Page URLs and titles and chat interaction events are sent to Google. A chat page title contains the host's @handle, and events sent from the server use a hash of the X id as the user identifier (user_id).

To turn off collection by Google Analytics, use the Google Analytics opt-out add-on.

Google AdSense

Article pages carry Google AdSense to cover running costs. Third-party providers including Google may use cookies and serve advertising based on visits to this and other sites.

Personalised advertising can be turned off in Google's ad settings. For turning off third-party providers' cookies, see aboutads.info.

Profile images

Profile images are loaded from X's image servers (pbs.twimg.com).

7. Security measures

We encrypt traffic, restrict access to administrative screens, delete data once its retention period has passed, and manage secrets.

8. Disclosure, correction, suspension and deletion

To request disclosure, correction, suspension of use or deletion, write to support@comeyomi.com. We verify identity through the X account before acting. Retention and deletion are covered in section 4.

9. Revisions

When this policy is reviewed, the current version is published on this page and the last-updated date is changed.