プライバシーポリシー
最終更新日:2026年9月16日
1. はじめに
JapanMarketing合同会社(以下「当社」)は、デスクトップアプリおよびサーバから成るサービス「ReplyFive」(以下「本サービス」)において、利用者の情報を以下のとおり取り扱います。本サービスは、会話の本文を保存しない前提で設計されています。
2. 保存しない情報
当社は、次の情報をサーバのデータベース、ログ、分析基盤のいずれにも保存しません。
- 返信の対象となる会話の本文
- 利用者が入力した「伝えたいこと」
- 生成された返信の文面
- 利用者が返信に加えた修正内容
これらの情報は返信の生成目的でのみ処理され、処理後に保持されることはありません。デスクトップアプリはこれらをメモリ上でのみ扱い、パネルを閉じた時点で破棄します。
3. 保存する情報
当社がサーバに保存する情報は、契約の履行および請求に必要な以下の情報に限られます。
- 組織名および管理者のメールアドレス
- 契約プラン、契約状態、席数
- 端末トークンのハッシュ値(SHA-256。トークン自体は保存しません)
- 組織および席ごとの1日あたりの利用回数
- 管理画面で設定された文章ルール(書き出し、署名、使用しない語句など)
4. 端末内に保存される情報
「修正から学習する」機能は初期設定で無効です。利用者が有効にした場合に限り、直近最大30件の修正内容がお使いのMac内だけにAES-GCMで暗号化して保存されます。暗号鍵はmacOSのKeychainに保管されます。返信の生成時には、そのうち直近3件までがサーバへ送られますが、処理完了後に保持されることはありません。また、本機能を無効にしても保存内容は自動では消えず、設定画面の「すべて削除」でいつでも削除できます。
5. 画面の読み取りについて
デスクトップアプリは、利用者がショートカットキーを押した瞬間にのみ、アクセシビリティ機能を用いて、選択中のメッセージ、または前面のウィンドウに表示されている会話を1回だけ読み取ります。画面の常時監視、スクリーンショットの取得、閲覧履歴の記録は一切行いません。
6. 外部サービスと処理を行う国
AIモデル提供者
当社クラウド版では、ReplyFive のサーバは Amazon Web Services の東京リージョンで稼働し、返信の文章の生成には Groq, Inc.(米国に所在する第三者の事業者)がオープンウェイトのモデルで提供する API を利用します。したがって、会話の本文および利用者が入力した内容は、返信を生成する目的で米国内の Groq のサーバへ送信され、処理されます。送信は返信の生成に必要な1回限りで、当社が保存することはなく、モデル提供者が当該データを学習に利用しない契約条件の下で利用しています。
また、返信の種類の判定と、生成結果が入力の意味を保っているかの確認のために、TypeSafe, Inc.(米国に所在する第三者の事業者)の判定専用 API を利用します。このモデルは文章を生成せず、ラベルと確率のみを返します。会話の本文、利用者が入力した内容、および生成された返信は、この判定のために米国内の TypeSafe のサーバへ送信され、処理されます。送信は判定に必要な回数に限られ、当社が保存することはありません。
セルフホスト版では、返信の生成に Amazon Bedrock(東京リージョン)を利用します。TypeSafe による判定は、お客様が自ら API キーを設定した場合に限り有効になります。設定しない限り、通信はお客様ご自身の AWS アカウント内で完結し、本文がアカウント外や国外へ送信されることはありません。本文を国外へ送信できないお客様は、セルフホスト版をご利用ください。
決済
決済処理は Stripe, Inc. が行います。クレジットカード情報は Stripe が直接取得・保持するため、当社がカード番号を保持することはありません。当社が受け取る情報は、契約状態および請求に必要な識別子のみです。
エラー報告
不具合の把握には Functional Software, Inc.(Sentry)を利用しています。送信される情報は、発生箇所、端末の OS 種別、アプリのバージョンなどの技術情報に限られます。会話の本文、入力内容、生成された返信、リクエスト本文、Cookie、認証情報は、送信前にすべて除去されます。
7. Cookie
管理画面では、ログイン状態を保持するためのセッション Cookie のみを使用します。広告や行動追跡、アクセス解析を目的とした Cookie およびトラッキングスクリプトは使用していません。また、公開サイトにも追跡スクリプトは一切設置していません。
8. 保存期間
第3項に定める情報は、契約期間中および法令上必要な期間にわたり保存します。契約終了後は、請求業務および法令上の保存義務がなくなった時点で速やかに削除します。利用回数の記録については、請求処理に必要な期間を経過した後に削除します。
9. 第三者提供
当社は、法令に基づく場合を除き、保有する情報を本人の同意なく第三者へ提供しません。第6項に記載した委託先に対しては、本サービスの提供に必要な範囲に限り情報を取り扱わせます。なお、クラウド版における Groq, Inc. への送信は、第6項のとおり米国に所在する事業者への委託にあたります。
10. 安全管理
通信はすべて TLS により暗号化しています。端末トークンはハッシュ化して保存し、管理画面のセッションは署名付きで安全に管理します。なお、当社クラウド版のサーバは AWS の東京リージョンで稼働しています。
11. 開示等のご請求・お問い合わせ
保有情報の開示、訂正、削除のご請求や、本ポリシーに関するお問い合わせは、下記までご連絡ください。
JapanMarketing合同会社
個人情報取扱責任者:遠藤巧巳
メール:takumi.endoh@japan-marketing.co.jp
12. 本ポリシーの変更
本ポリシーを変更する場合は、本ページに変更後の内容と最終更新日を掲載します。重要な変更を行う場合は、管理画面または登録メールアドレス宛にお知らせします。
Privacy Policy (English)
This is an English translation of the Japanese text above, provided for convenience. If the two differ, the Japanese version governs. Last updated 16 September 2026.
1. Introduction
JapanMarketing LLC (“we”) operates ReplyFive, a desktop application and server (the “Service”). The Service is designed so that the text of your conversations is never stored.
2. What we do not store
We do not write any of the following to a database, a log file, or an analytics system:
- The conversation you are replying to
- The intent you type
- The generated reply
- Any edits you make to it
This text is processed only to produce the reply and is not retained afterwards. The desktop app holds it in memory and discards it when the panel closes.
3. What we store
On the server we keep only what the contract and billing require: your organization name and administrator email address, the plan, subscription state and seat count, SHA-256 hashes of device tokens (never the tokens themselves), daily request counts per organization and seat, and the writing rules configured in the admin console.
4. Data kept on your device
“Learn from my edits” is off by default. If you turn it on, up to 30 of your most recent edits are stored on your Mac only, encrypted with AES-GCM using a key held in the macOS Keychain. When a reply is generated, at most the three most recent of those edits are sent to the server and are not retained after processing. Turning the feature off lets you delete what was stored.
5. Reading the screen
The desktop app uses macOS Accessibility to read the selected message, or the conversation visible in the front window, once, at the moment you press the shortcut. It does not monitor your screen, take screenshots, or keep any history.
6. Third parties and where processing takes place
AI providers. On our cloud plan the ReplyFive server runs on Amazon Web Services in the Tokyo region, and the reply text is generated by Groq, Inc., a third-party provider located in the United States, using an open-weight model. The conversation text and your intent are therefore transferred to Groq's servers in the United States to generate the reply. They are sent once, are not stored by us, and are used under terms that do not permit their use for model training. To classify the kind of reply and to verify that the generated reply keeps your meaning, we also use the classification-only API of TypeSafe, Inc., a third-party provider located in the United States. That model generates no text and returns only labels and probabilities; the conversation text, your intent and the generated reply are transferred to TypeSafe's servers in the United States for those checks and are not stored by us. In self-hosted deployments replies are generated by Amazon Bedrock in the Tokyo region, the TypeSafe step is off unless the customer configures its own API key, and the request stays inside the customer's own AWS account. Customers who cannot send text abroad should use the self-hosted edition.
Payments. Payments are processed by Stripe, Inc. Card details are collected and held by Stripe; we never hold card numbers. We receive only the subscription state and the identifiers needed for billing.
Crash reporting. We use Functional Software, Inc. (Sentry) to diagnose faults. Reports contain technical information such as where the error occurred, the operating system and the application version. Message text, intents, generated replies, request bodies, cookies and credentials are stripped before sending.
7. Cookies
The admin console uses a session cookie to keep you signed in. We use no advertising, tracking or analytics cookies, and the public website carries no tracking scripts at all.
8. Retention
We retain the information in section 3 for the duration of the contract and for any period required by law, then delete it. Request counts are deleted once they are no longer needed for billing.
9. Disclosure
We do not disclose information to third parties except where required by law. The processors named in section 6 may handle it only as necessary to provide the Service.
10. Security
All traffic is encrypted with TLS. Device tokens are stored hashed and admin sessions are signed. Our cloud runs in the AWS Tokyo region.
11. Contact
For access, correction or deletion requests, or any question about this policy: JapanMarketing LLC, attention Takumi Endoh, takumi.endoh@japan-marketing.co.jp.
12. Changes
If we change this policy we will publish the new text and its date on this page, and notify significant changes through the admin console or by email.