Privacy Policy

Nexus Inc. (hereinafter referred to as "the Company") establishes the following Privacy Policy regarding the handling of users' personal information in the services provided.

Handling of Personal Information

Article 1: Definition of Personal Information

"Personal information" refers to "personal information" as defined by the Act on the Protection of Personal Information. This includes information that can identify a specific individual through descriptions such as name, date of birth, address, phone number, email address, as well as data related to appearance, fingerprints, voiceprints, and health insurance card insurer numbers.

Article 2: Methods of Collecting Personal Information

The Company collects personal information through the following methods.

  1. 1.Information provided during registration: name, date of birth, address, phone number, email address, etc.
  2. 2.Information during service use: operation history, usage status, uploaded files.
  3. 3.Device information: IP address, browser type, device information.
  4. 4.Location information: location data obtained during app use.
  5. 5.Third-party social media services: information provided through Google, Facebook, Twitter, LinkedIn, etc. (hereinafter referred to as "Third-Party Social Media Services").

Article 3: Purposes of Using Personal Information

The Company uses personal information for the following purposes.

  1. 1.Service provision and operation
  2. 2.User authentication and identity verification
  3. 3.Customer support provision
  4. 4.Analysis of usage and service improvement
  5. 5.Development of new features and services
  6. 6.Ensuring security and preventing unauthorized use
  7. 7.Calculation of fees for paid services
  8. 8.Compliance with laws and regulations
  9. 9.Optimization of services using location information
  10. 10.Provision of integration features through Third-Party Social Media Services
  11. 11.Other matters incidental to the above purposes

Article 4: Changes to Purposes of Use

The Company will change the purposes of use of personal information only when the change is reasonably recognized as being related to the purpose before the change. When a change occurs, users will be notified through the method prescribed by the Company.

Article 5: Provision of Personal Information to Third Parties

The Company will not provide personal information to third parties without prior consent, except in the following cases.

  1. 1.When required by law
  2. 2.When necessary to protect a person's life, body, or property
  3. 3.When particularly necessary for improving public health or promoting the sound development of children
  4. 4.When cooperation with national or local government agencies is necessary

The Company may share personal information with subcontractors and partner companies (cloud service providers, analytics service providers, etc.). In such cases, the Company will execute appropriate contracts and ensure thorough information protection.

Information from Third-Party Social Media Services

The Company allows users to create accounts, log in, and use the Service through the following Third-Party Social Media Services.

When a user registers through a Third-Party Social Media Service or otherwise grants the Company access to such service, the Company may collect personal data already associated with the user's Third-Party Social Media Service account, such as the user's name, email address, activities, and contact lists associated with that account.

Users may also have the option to share additional information with the Company through their Third-Party Social Media Service account. If a user chooses to provide such information and personal data during registration or otherwise, the user authorizes the Company to use, share, and store such information in a manner consistent with this Privacy Policy.

Data Protection and Security Management

Article 6: Data Protection

The Company implements the following measures to protect personal information.

  1. 1.Data encryption
  2. 2.Utilization of security infrastructure
  3. 3.Restriction of access privileges
  4. 4.Regular security audits
  5. 5.Establishment of data breach response protocols

Article 7: Rights of Personal Information Users

Users have the following rights.

  1. 1.Request for disclosure of personal information
  2. 2.Request for correction or deletion
  3. 3.Request to cease use
  4. 4.Right to data portability
  5. 5.Right to withdraw consent

The Company will respond to the exercise of these rights promptly and in good faith.

Service-Specific Handling

Article 8: Service-Specific Handling

  1. 1.Calendars, events, accounts, and settings

To display, create, edit, notify, and sync calendars and events, we handle calendar information on your device and Google Calendar information obtained and updated through the Google Calendar API. If you connect an external calendar such as Google, that information is also managed in accordance with each service provider's privacy policy.

We use Firebase Authentication and Firestore for account authentication, syncing your profile and app settings, shared calendar features, and saving event templates. Depending on the features you use, we store profile settings, device information, sharing-related information, and event template titles, locations, notes, and repeat and notification settings.

To provide integration and sharing features, we store the authentication credentials required for the Google integration (access tokens and refresh tokens) in Firebase, which we manage. We do not obtain or store your Google account password.

  1. 2.AI event creation, image analysis, and color suggestions

For AI event creation and analysis, we use the text and images you enter or provide to convert them into event candidates.

For voice input, your device's speech recognition converts speech into text. To create and analyze events, the converted text may be sent to Apple's Private Cloud Compute, or to Google Gemini via Firebase Cloud Functions. How speech recognition is processed depends on your device and OS features and settings.

Text you enter directly and images you provide for event creation are also processed by Apple's Private Cloud Compute, or by Google Gemini via Firebase Cloud Functions. Which processor is used depends on factors such as device support, and simple text may be processed on your device.

Event color suggestions are normally processed on your device on supported devices and OS versions. Available features and processing methods vary by device, OS, and settings.

  1. 3.Purchases of paid features and entitlements

To verify and restore purchases and manage entitlements to paid features, we use RevenueCat and send information such as user identifiers and purchase information.

  1. 4.Invitation links and attribution

To create invitation links for shared calendars, carry over invitation information, and measure acquisition channels, we use Firebase Cloud Functions and AppsFlyer. When an invitation link is generated, we send information such as the inviter's display name, the calendar name, the calendar ID, and an invitation token to AppsFlyer. To associate acquisition with app users, we also send the signed-in user's identifier to AppsFlyer. Depending on settings, this processing may also involve device information, identifiers, IP addresses, and information about installs and link usage.

  1. 5.Reminders and push notifications

To provide event reminders, shared calendar update notifications, and to-do notifications, we use event information on your device, notification settings, and notification tokens. Notifications are sent via Firebase Cloud Messaging (FCM) or Apple Push Notification service (APNs). Shared notifications may include event titles, dates and times, calendar names, display names, and to-do names.

  1. 6.Usage, errors, performance, configuration delivery, and abuse prevention

To analyze service usage, investigate errors, measure performance, deliver app configuration, and prevent abuse, we use Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config, and App Check. Depending on app launches and feature use, settings, consent, and device environment, we send information such as user identifiers, interaction events, app and device information, errors, performance information, and information needed to verify the app's integrity to each service.

  1. 7.Advertising

We use Google AdMob to display ads, manage consent, and measure ad performance. Advertising identifiers and similar information are handled according to your consent, device settings, app settings, and usage environment. Ad and consent management are also subject to the policies of the Google AdMob service provider.

You can change permission to use advertising identifiers in your device settings. The paid version stops displaying ads.

  1. 8.Place search

When you use place search, we send the search terms you enter, the language, and, where needed, a search area based on your current location to the Google Places API to obtain place suggestions and details. The information obtained is used to enter and display event locations.

  1. 9.URL previews and inquiries

When you use URL previews, your device accesses the URL to obtain metadata such as the page title, description, and images in order to display the preview. The policies of the accessed website also apply.

Communication also occurs when we retrieve information needed to display announcements, help content, profile images, and similar content from their sources, and those sources receive communication information such as your IP address.

When you submit an inquiry, we send the message body, reply email address, reply preference, the signed-in user identifier, app and device information, language settings, Pro status, diagnostic information, attached images, and similar information to Firebase in order to reply and investigate issues. The items sent vary depending on your input and usage environment.

Article 9: AI and Automation

The Company uses AI technology to improve the Service, but does not use users' personal data for training other AI models. The Company also ensures transparency regarding AI processing.

Article 10: Data Deletion

When a user deletes their account or individually requests data deletion, the following process is followed.

  1. 1.User data deletion: deleted promptly
  2. 2.Cache data deletion: deleted within 30 days

Article 11: Data Retention Period

The Company retains personal information for the period necessary for service provision or the period required by law. Data whose retention period has expired is appropriately disposed of.

Article 12: International Data Transfers

The Company may process personal information on servers outside Japan. In such cases, the Company complies with the EU General Data Protection Regulation (GDPR) and other international data protection standards. Standard Contractual Clauses (SCC) are applied and protective measures are taken.

Article 13: Use by Minors

The Service requires parental consent for minors. Minors should use the Service only after obtaining parental consent.

Article 14: Data Breach Notification

In the event of a personal information breach, users will be promptly notified and the following measures will be taken.

  1. 1.Investigation of the extent of damage
  2. 2.Contacting affected users
  3. 3.Implementation of measures to prevent recurrence

Other

Article 15: Changes to the Policy

The contents of this Policy may be changed without notice to users, except for matters otherwise stipulated in this Policy or by law. Unless otherwise determined by the Company, the revised Privacy Policy shall take effect from the time it is posted on this website.

Article 16: Contact Information

For inquiries regarding this Policy, please contact the following.

Company name: Nexus Inc.

Contact: contact@nexus-inc.net

Established: September 17, 2025

Last updated: September 28, 2026

Article 17 Personal Data Protection for Users in Singapore

For users in Singapore, the following additional information applies under the Personal Data Protection Act 2012 (PDPA).

We have appointed a Data Protection Officer. The Data Protection Officer can be contacted at contact@nexus-inc.net.

You may withdraw consent to the collection, use, or disclosure of your personal data by contacting us at the email address above. Upon receiving notice of withdrawal, we will stop the relevant collection, use, and disclosure. Withdrawal may make related features, such as cloud sync or shared calendars, unavailable.

You may request access to or correction of personal data we hold about you. We will respond as soon as practicable. If we cannot respond within 30 days, we will inform you within those 30 days when we expect to respond.

When we transfer personal data outside Singapore to service providers described in Article 8, we will take appropriate steps, including contractual or other arrangements, to ensure the transferred data is protected to a standard comparable to that under the PDPA.

Article 18 Language Versions

This Privacy Policy is provided in English and Simplified Chinese. In the event of any inconsistency between the two versions, the English version shall prevail.