Privacy Policy

Nexus Inc. (hereinafter referred to as "the Company") establishes the following Privacy Policy regarding the handling of users' personal information in the services provided.

Handling of Personal Information

Article 1: Definition of Personal Information

"Personal information" refers to "personal information" as defined by the Act on the Protection of Personal Information. This includes information that can identify a specific individual through descriptions such as name, date of birth, address, phone number, email address, as well as data related to appearance, fingerprints, voiceprints, and health insurance card insurer numbers.

Article 2: Methods of Collecting Personal Information

The Company collects personal information through the following methods.

  1. 1.Information provided during registration: name, date of birth, address, phone number, email address, etc.
  2. 2.Information during service use: operation history, usage status, uploaded files.
  3. 3.Device information: IP address, browser type, device information.
  4. 4.Location information: location data obtained during app use.
  5. 5.Third-party social media services: information provided through Google, Facebook, Twitter, LinkedIn, etc. (hereinafter referred to as "Third-Party Social Media Services").

Article 3: Purposes of Using Personal Information

The Company uses personal information for the following purposes.

  1. 1.Service provision and operation
  2. 2.User authentication and identity verification
  3. 3.Customer support provision
  4. 4.Analysis of usage and service improvement
  5. 5.Development of new features and services
  6. 6.Ensuring security and preventing unauthorized use
  7. 7.Calculation of fees for paid services
  8. 8.Compliance with laws and regulations
  9. 9.Optimization of services using location information
  10. 10.Provision of integration features through Third-Party Social Media Services
  11. 11.Other matters incidental to the above purposes

Article 4: Changes to Purposes of Use

The Company will change the purposes of use of personal information only when the change is reasonably recognized as being related to the purpose before the change. When a change occurs, users will be notified through the method prescribed by the Company.

Article 5: Provision of Personal Information to Third Parties

The Company will not provide personal information to third parties without prior consent, except in the following cases.

  1. 1.When required by law
  2. 2.When necessary to protect a person's life, body, or property
  3. 3.When particularly necessary for improving public health or promoting the sound development of children
  4. 4.When cooperation with national or local government agencies is necessary

The Company may share personal information with subcontractors and partner companies (cloud service providers, analytics service providers, etc.). In such cases, the Company will execute appropriate contracts and ensure thorough information protection.

Information from Third-Party Social Media Services

The Company allows users to create accounts, log in, and use the Service through the following Third-Party Social Media Services.

When a user registers through a Third-Party Social Media Service or otherwise grants the Company access to such service, the Company may collect personal data already associated with the user's Third-Party Social Media Service account, such as the user's name, email address, activities, and contact lists associated with that account.

Users may also have the option to share additional information with the Company through their Third-Party Social Media Service account. If a user chooses to provide such information and personal data during registration or otherwise, the user authorizes the Company to use, share, and store such information in a manner consistent with this Privacy Policy.

Data Protection and Security Management

Article 6: Data Protection

The Company implements the following measures to protect personal information.

  1. 1.Data encryption
  2. 2.Utilization of security infrastructure
  3. 3.Restriction of access privileges
  4. 4.Regular security audits
  5. 5.Establishment of data breach response protocols

Article 7: Rights of Personal Information Users

Users have the following rights.

  1. 1.Request for disclosure of personal information
  2. 2.Request for correction or deletion
  3. 3.Request to cease use
  4. 4.Right to data portability
  5. 5.Right to withdraw consent

The Company will respond to the exercise of these rights promptly and in good faith.

Service-Specific Handling

Article 8: Service-Specific Handling

  1. 1.Calendars, events, accounts, and settings

To display, create, edit, notify, and sync calendars and events, we handle calendar information on your device and Google Calendar information obtained and updated through the Google Calendar API. If you connect an external calendar such as Google, that information is also managed in accordance with each service provider's privacy policy.

We use Firebase Authentication and Firestore for account authentication, syncing your profile and app settings, shared calendar features, and saving event templates. Depending on the features you use, we store profile settings, device information, sharing-related information, and event template titles, locations, notes, and repeat and notification settings.

To provide integration and sharing features, we store the authentication credentials required for the Google integration (access tokens and refresh tokens) in Firebase, which we manage. We do not obtain or store your Google account password.

  1. 2.AI event creation, image analysis, and color suggestions

For AI event creation and analysis, we use the text and images you enter or provide to convert them into event candidates.

For voice input, your device's speech recognition converts speech into text. To create and analyze events, the converted text may be sent to Apple's Private Cloud Compute, or to Google Gemini via Firebase Cloud Functions. How speech recognition is processed depends on your device and OS features and settings.

Text you enter directly and images you provide for event creation are also processed by Apple's Private Cloud Compute, or by Google Gemini via Firebase Cloud Functions. Which processor is used depends on factors such as device support, and simple text may be processed on your device.

Event color suggestions are normally processed on your device on supported devices and OS versions. Available features and processing methods vary by device, OS, and settings.

  1. 3.Purchases of paid features and entitlements

To verify and restore purchases and manage entitlements to paid features, we use RevenueCat and send information such as user identifiers and purchase information.

  1. 4.Invitation links and attribution

To create invitation links for shared calendars, carry over invitation information, and measure acquisition channels, we use Firebase Cloud Functions and AppsFlyer. When an invitation link is generated, we send information such as the inviter's display name, the calendar name, the calendar ID, and an invitation token to AppsFlyer. To associate acquisition with app users, we also send the signed-in user's identifier to AppsFlyer. Depending on settings, this processing may also involve device information, identifiers, IP addresses, and information about installs and link usage.

  1. 5.Reminders and push notifications

To provide event reminders, shared calendar update notifications, and to-do notifications, we use event information on your device, notification settings, and notification tokens. Notifications are sent via Firebase Cloud Messaging (FCM) or Apple Push Notification service (APNs). Shared notifications may include event titles, dates and times, calendar names, display names, and to-do names.

  1. 6.Usage, errors, performance, configuration delivery, and abuse prevention

To analyze service usage, investigate errors, measure performance, deliver app configuration, and prevent abuse, we use Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config, and App Check. Depending on app launches and feature use, settings, consent, and device environment, we send information such as user identifiers, interaction events, app and device information, errors, performance information, and information needed to verify the app's integrity to each service.

  1. 7.Advertising

We use Google AdMob to display ads, manage consent, and measure ad performance. Advertising identifiers and similar information are handled according to your consent, device settings, app settings, and usage environment. Ad and consent management are also subject to the policies of the Google AdMob service provider.

You can change permission to use advertising identifiers in your device settings. The paid version stops displaying ads.

  1. 8.Place search

When you use place search, we send the search terms you enter, the language, and, where needed, a search area based on your current location to the Google Places API to obtain place suggestions and details. The information obtained is used to enter and display event locations.

  1. 9.URL previews and inquiries

When you use URL previews, your device accesses the URL to obtain metadata such as the page title, description, and images in order to display the preview. The policies of the accessed website also apply.

Communication also occurs when we retrieve information needed to display announcements, help content, profile images, and similar content from their sources, and those sources receive communication information such as your IP address.

When you submit an inquiry, we send the message body, reply email address, reply preference, the signed-in user identifier, app and device information, language settings, Pro status, diagnostic information, attached images, and similar information to Firebase in order to reply and investigate issues. The items sent vary depending on your input and usage environment.

Article 9: AI and Automation

The Company uses AI technology to improve the Service, but does not use users' personal data for training other AI models. The Company also ensures transparency regarding AI processing.

Article 10: Data Deletion

When a user deletes their account or individually requests data deletion, the following process is followed.

  1. 1.User data deletion: deleted promptly
  2. 2.Cache data deletion: deleted within 30 days

Article 11: Data Retention Period

The Company retains personal information for the period necessary for service provision or the period required by law. Data whose retention period has expired is appropriately disposed of.

Article 12: International Data Transfers

The Company may process personal information on servers outside Japan. In such cases, the Company complies with the EU General Data Protection Regulation (GDPR) and other international data protection standards. Standard Contractual Clauses (SCC) are applied and protective measures are taken.

Article 13: Use by Minors

The Service requires parental consent for minors. Minors should use the Service only after obtaining parental consent.

Article 14: Data Breach Notification

In the event of a personal information breach, users will be promptly notified and the following measures will be taken.

  1. 1.Investigation of the extent of damage
  2. 2.Contacting affected users
  3. 3.Implementation of measures to prevent recurrence

Other

Article 15: Changes to the Policy

The contents of this Policy may be changed without notice to users, except for matters otherwise stipulated in this Policy or by law. Unless otherwise determined by the Company, the revised Privacy Policy shall take effect from the time it is posted on this website.

Article 16: Contact Information

For inquiries regarding this Policy, please contact the following.

Company name: Nexus Inc.

Contact: contact@nexus-inc.net

Established: September 17, 2025

Last updated: September 28, 2026

Article 17 Additional Provisions for Users in the Republic of Korea

For users in the Republic of Korea, we provide the following additional information in accordance with the Personal Information Protection Act.

  1. 1.Purposes, items, and retention period

The purposes and items of processing are as described in Articles 2, 3, and 8. We retain personal information until your account is deleted or the purpose of processing is achieved, and then destroy it without delay. However, data held by the following external services is retained and deleted according to the criteria below.

  1. 2.Transfer of personal information overseas

We transfer personal information overseas as follows. Transfers take place over the network from time to time as you use the Service.

(1) Outsourced processing and storage necessary to provide the Service

We transfer the following on the basis of outsourced processing and storage necessary to conclude and perform our contract with you, disclosed in this Policy (Article 28-8(1)(3) of the Personal Information Protection Act).

Because these transfers are necessary to provide the Service, if you do not want them, please stop using the Service and delete your account. If you refuse them, you cannot use the Service.

(2) Advertising

To display ads and measure ad performance, we send advertising identifiers and similar information to Google LLC (Google AdMob, United States). You choose whether advertising identifiers may be used in your device settings (such as allowing tracking). Even if you refuse, you can still use the Service, and non-personalized ads are displayed. Ads are not displayed in the paid version. Google's processing for advertising is subject to Google's privacy policy.

The retention periods at the recipients are as described in item 1; other data is retained until your account is deleted or the purpose of processing is achieved.

  1. 3.Destruction of personal information

We destroy personal information without delay when it is no longer needed because the retention period has expired or the purpose of processing has been achieved. Electronic records are deleted in a way that cannot be restored.

  1. 4.Exercising your rights

You may request access to, correction, deletion, or suspension of processing of your personal information, and withdraw your consent. You may also exercise these rights through an agent. Please contact the contact point in Article 16 by email. We will respond without delay.

  1. 5.Children under 14

The Service is not directed at children under the age of 14. A child under 14 must obtain the consent of a legal guardian to use the Service. If we learn that we have collected personal information from a child under 14 without the consent of a legal guardian, we will delete it without delay.

  1. 6.Chief Privacy Officer

Name: 冨永 大二朗 (Representative)

Contact: contact@nexus-inc.net

  1. 7.Security measures

Our measures to ensure the security of personal information are described in Article 6.

  1. 8.Remedies for infringement

If you need consultation or remedies regarding infringement of personal information, you can contact the following organizations.