Privacy Policy
Nexus Inc. (hereinafter referred to as "the Company") establishes the following Privacy Policy regarding the handling of users' personal information in the services provided.
Handling of Personal Information
Article 1: Definition of Personal Information
"Personal information" refers to "personal information" as defined by the Act on the Protection of Personal Information. This includes information that can identify a specific individual through descriptions such as name, date of birth, address, phone number, email address, as well as data related to appearance, fingerprints, voiceprints, and health insurance card insurer numbers.
Article 2: Methods of Collecting Personal Information
The Company collects personal information through the following methods.
- 1.Information provided during registration: name, date of birth, address, phone number, email address, etc.
- 2.Information during service use: operation history, usage status, uploaded files.
- 3.Device information: IP address, browser type, device information.
- 4.Location information: location data obtained during app use.
- 5.Third-party social media services: information provided through Google, Facebook, Twitter, LinkedIn, etc. (hereinafter referred to as "Third-Party Social Media Services").
Article 3: Purposes of Using Personal Information
The Company uses personal information for the following purposes.
- 1.Service provision and operation
- 2.User authentication and identity verification
- 3.Customer support provision
- 4.Analysis of usage and service improvement
- 5.Development of new features and services
- 6.Ensuring security and preventing unauthorized use
- 7.Calculation of fees for paid services
- 8.Compliance with laws and regulations
- 9.Optimization of services using location information
- 10.Provision of integration features through Third-Party Social Media Services
- 11.Other matters incidental to the above purposes
Article 4: Changes to Purposes of Use
The Company will change the purposes of use of personal information only when the change is reasonably recognized as being related to the purpose before the change. When a change occurs, users will be notified through the method prescribed by the Company.
Article 5: Provision of Personal Information to Third Parties
The Company will not provide personal information to third parties without prior consent, except in the following cases.
- 1.When required by law
- 2.When necessary to protect a person's life, body, or property
- 3.When particularly necessary for improving public health or promoting the sound development of children
- 4.When cooperation with national or local government agencies is necessary
The Company may share personal information with subcontractors and partner companies (cloud service providers, analytics service providers, etc.). In such cases, the Company will execute appropriate contracts and ensure thorough information protection.
Information from Third-Party Social Media Services
The Company allows users to create accounts, log in, and use the Service through the following Third-Party Social Media Services.
When a user registers through a Third-Party Social Media Service or otherwise grants the Company access to such service, the Company may collect personal data already associated with the user's Third-Party Social Media Service account, such as the user's name, email address, activities, and contact lists associated with that account.
Users may also have the option to share additional information with the Company through their Third-Party Social Media Service account. If a user chooses to provide such information and personal data during registration or otherwise, the user authorizes the Company to use, share, and store such information in a manner consistent with this Privacy Policy.
Data Protection and Security Management
Article 6: Data Protection
The Company implements the following measures to protect personal information.
- 1.Data encryption
- 2.Utilization of security infrastructure
- 3.Restriction of access privileges
- 4.Regular security audits
- 5.Establishment of data breach response protocols
Article 7: Rights of Personal Information Users
Users have the following rights.
- 1.Request for disclosure of personal information
- 2.Request for correction or deletion
- 3.Request to cease use
- 4.Right to data portability
- 5.Right to withdraw consent
The Company will respond to the exercise of these rights promptly and in good faith.
Service-Specific Handling
Article 8: Service-Specific Handling
- 1.Calendars, events, accounts, and settings
To display, create, edit, notify, and sync calendars and events, we handle calendar information on your device and Google Calendar information obtained and updated through the Google Calendar API. If you connect an external calendar such as Google, that information is also managed in accordance with each service provider's privacy policy.
We use Firebase Authentication and Firestore for account authentication, syncing your profile and app settings, shared calendar features, and saving event templates. Depending on the features you use, we store profile settings, device information, sharing-related information, and event template titles, locations, notes, and repeat and notification settings.
To provide integration and sharing features, we store the authentication credentials required for the Google integration (access tokens and refresh tokens) in Firebase, which we manage. We do not obtain or store your Google account password.
- 2.AI event creation, image analysis, and color suggestions
For AI event creation and analysis, we use the text and images you enter or provide to convert them into event candidates.
For voice input, your device's speech recognition converts speech into text. To create and analyze events, the converted text may be sent to Apple's Private Cloud Compute, or to Google Gemini via Firebase Cloud Functions. How speech recognition is processed depends on your device and OS features and settings.
Text you enter directly and images you provide for event creation are also processed by Apple's Private Cloud Compute, or by Google Gemini via Firebase Cloud Functions. Which processor is used depends on factors such as device support, and simple text may be processed on your device.
Event color suggestions are normally processed on your device on supported devices and OS versions. Available features and processing methods vary by device, OS, and settings.
- 3.Purchases of paid features and entitlements
To verify and restore purchases and manage entitlements to paid features, we use RevenueCat and send information such as user identifiers and purchase information.
- 4.Invitation links and attribution
To create invitation links for shared calendars, carry over invitation information, and measure acquisition channels, we use Firebase Cloud Functions and AppsFlyer. When an invitation link is generated, we send information such as the inviter's display name, the calendar name, the calendar ID, and an invitation token to AppsFlyer. To associate acquisition with app users, we also send the signed-in user's identifier to AppsFlyer. Depending on settings, this processing may also involve device information, identifiers, IP addresses, and information about installs and link usage.
- 5.Reminders and push notifications
To provide event reminders, shared calendar update notifications, and to-do notifications, we use event information on your device, notification settings, and notification tokens. Notifications are sent via Firebase Cloud Messaging (FCM) or Apple Push Notification service (APNs). Shared notifications may include event titles, dates and times, calendar names, display names, and to-do names.
- 6.Usage, errors, performance, configuration delivery, and abuse prevention
To analyze service usage, investigate errors, measure performance, deliver app configuration, and prevent abuse, we use Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config, and App Check. Depending on app launches and feature use, settings, consent, and device environment, we send information such as user identifiers, interaction events, app and device information, errors, performance information, and information needed to verify the app's integrity to each service.
- 7.Advertising
We use Google AdMob to display ads, manage consent, and measure ad performance. Advertising identifiers and similar information are handled according to your consent, device settings, app settings, and usage environment. Ad and consent management are also subject to the policies of the Google AdMob service provider.
You can change permission to use advertising identifiers in your device settings. The paid version stops displaying ads.
- 8.Place search
When you use place search, we send the search terms you enter, the language, and, where needed, a search area based on your current location to the Google Places API to obtain place suggestions and details. The information obtained is used to enter and display event locations.
- 9.URL previews and inquiries
When you use URL previews, your device accesses the URL to obtain metadata such as the page title, description, and images in order to display the preview. The policies of the accessed website also apply.
Communication also occurs when we retrieve information needed to display announcements, help content, profile images, and similar content from their sources, and those sources receive communication information such as your IP address.
When you submit an inquiry, we send the message body, reply email address, reply preference, the signed-in user identifier, app and device information, language settings, Pro status, diagnostic information, attached images, and similar information to Firebase in order to reply and investigate issues. The items sent vary depending on your input and usage environment.
Article 9: AI and Automation
The Company uses AI technology to improve the Service, but does not use users' personal data for training other AI models. The Company also ensures transparency regarding AI processing.
Article 10: Data Deletion
When a user deletes their account or individually requests data deletion, the following process is followed.
- 1.User data deletion: deleted promptly
- 2.Cache data deletion: deleted within 30 days
Article 11: Data Retention Period
The Company retains personal information for the period necessary for service provision or the period required by law. Data whose retention period has expired is appropriately disposed of.
Article 12: International Data Transfers
The Company may process personal information on servers outside Japan. In such cases, the Company complies with the EU General Data Protection Regulation (GDPR) and other international data protection standards. Standard Contractual Clauses (SCC) are applied and protective measures are taken.
Article 13: Use by Minors
The Service requires parental consent for minors. Minors should use the Service only after obtaining parental consent.
Article 14: Data Breach Notification
In the event of a personal information breach, users will be promptly notified and the following measures will be taken.
- 1.Investigation of the extent of damage
- 2.Contacting affected users
- 3.Implementation of measures to prevent recurrence
Other
Article 15: Changes to the Policy
The contents of this Policy may be changed without notice to users, except for matters otherwise stipulated in this Policy or by law. Unless otherwise determined by the Company, the revised Privacy Policy shall take effect from the time it is posted on this website.
Article 16: Contact Information
For inquiries regarding this Policy, please contact the following.
Company name: Nexus Inc.
Contact: contact@nexus-inc.net
Established: September 17, 2025
Last updated: September 28, 2026
Article 17 Additional Provisions for Users in the Republic of Korea
For users in the Republic of Korea, we provide the following additional information in accordance with the Personal Information Protection Act.
- 1.Purposes, items, and retention period
The purposes and items of processing are as described in Articles 2, 3, and 8. We retain personal information until your account is deleted or the purpose of processing is achieved, and then destroy it without delay. However, data held by the following external services is retained and deleted according to the criteria below.
- Firebase Analytics (usage analysis): user-level data is deleted according to the Google Analytics data retention setting (14 months).
- Firebase Crashlytics (error investigation): deletion begins 90 days after collection.
- AppsFlyer (invitation links and attribution): under AppsFlyer's policy, data is generally not retained for more than 24 months.
- 2.Transfer of personal information overseas
We transfer personal information overseas as follows. Transfers take place over the network from time to time as you use the Service.
(1) Outsourced processing and storage necessary to provide the Service
We transfer the following on the basis of outsourced processing and storage necessary to conclude and perform our contract with you, disclosed in this Policy (Article 28-8(1)(3) of the Personal Information Protection Act).
- Google LLC (https://policies.google.com/privacy) / United States, Japan / email address and Google account identifiers; calendars, event templates, and app settings; device information and identifiers; usage history; error and performance information; AI input data; place search terms and search areas; inquiry contents / authentication, settings sync, AI processing, place search, notifications, usage analysis, error investigation, and receiving inquiries
- Apple Inc. (https://www.apple.com/legal/privacy/) / United States / AI input data (when Private Cloud Compute is used), notification tokens and notification contents / AI processing and push notifications
- RevenueCat, Inc. (https://www.revenuecat.com/privacy) / United States / user identifiers and purchase information / verifying and restoring purchases and managing entitlements to paid features
- AppsFlyer Ltd. (https://www.appsflyer.com/legal/privacy-policy/) / storage: European Union; access for support and maintenance: Israel, United States, Germany, United Kingdom, Japan, India, China, Hong Kong / the inviter's display name, calendar name, calendar ID, and invitation token; user identifiers; device information and identifiers; IP addresses; information about installs and link usage / creating invitation links and measuring acquisition channels
Because these transfers are necessary to provide the Service, if you do not want them, please stop using the Service and delete your account. If you refuse them, you cannot use the Service.
(2) Advertising
To display ads and measure ad performance, we send advertising identifiers and similar information to Google LLC (Google AdMob, United States). You choose whether advertising identifiers may be used in your device settings (such as allowing tracking). Even if you refuse, you can still use the Service, and non-personalized ads are displayed. Ads are not displayed in the paid version. Google's processing for advertising is subject to Google's privacy policy.
The retention periods at the recipients are as described in item 1; other data is retained until your account is deleted or the purpose of processing is achieved.
- 3.Destruction of personal information
We destroy personal information without delay when it is no longer needed because the retention period has expired or the purpose of processing has been achieved. Electronic records are deleted in a way that cannot be restored.
- 4.Exercising your rights
You may request access to, correction, deletion, or suspension of processing of your personal information, and withdraw your consent. You may also exercise these rights through an agent. Please contact the contact point in Article 16 by email. We will respond without delay.
- 5.Children under 14
The Service is not directed at children under the age of 14. A child under 14 must obtain the consent of a legal guardian to use the Service. If we learn that we have collected personal information from a child under 14 without the consent of a legal guardian, we will delete it without delay.
- 6.Chief Privacy Officer
Name: 冨永 大二朗 (Representative)
Contact: contact@nexus-inc.net
- 7.Security measures
Our measures to ensure the security of personal information are described in Article 6.
- 8.Remedies for infringement
If you need consultation or remedies regarding infringement of personal information, you can contact the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)