Privacy Policy
Nexus Inc. (hereinafter referred to as "the Company") establishes the following Privacy Policy regarding the handling of users' personal information in the services provided.
Handling of Personal Information
Article 1: Definition of Personal Information
"Personal information" refers to "personal information" as defined by the Act on the Protection of Personal Information. This includes information that can identify a specific individual through descriptions such as name, date of birth, address, phone number, email address, as well as data related to appearance, fingerprints, voiceprints, and health insurance card insurer numbers.
Article 2: Methods of Collecting Personal Information
The Company collects personal information through the following methods.
- 1.Information provided during registration: name, date of birth, address, phone number, email address, etc.
- 2.Information during service use: operation history, usage status, uploaded files.
- 3.Device information: IP address, browser type, device information.
- 4.Location information: location data obtained during app use.
- 5.Third-party social media services: information provided through Google, Facebook, Twitter, LinkedIn, etc. (hereinafter referred to as "Third-Party Social Media Services").
Article 3: Purposes of Using Personal Information
The Company uses personal information for the following purposes.
- 1.Service provision and operation
- 2.User authentication and identity verification
- 3.Customer support provision
- 4.Analysis of usage and service improvement
- 5.Development of new features and services
- 6.Ensuring security and preventing unauthorized use
- 7.Calculation of fees for paid services
- 8.Compliance with laws and regulations
- 9.Optimization of services using location information
- 10.Provision of integration features through Third-Party Social Media Services
- 11.Other matters incidental to the above purposes
Article 4: Changes to Purposes of Use
The Company will change the purposes of use of personal information only when the change is reasonably recognized as being related to the purpose before the change. When a change occurs, users will be notified through the method prescribed by the Company.
Article 5: Provision of Personal Information to Third Parties
The Company will not provide personal information to third parties without prior consent, except in the following cases.
- 1.When required by law
- 2.When necessary to protect a person's life, body, or property
- 3.When particularly necessary for improving public health or promoting the sound development of children
- 4.When cooperation with national or local government agencies is necessary
The Company may share personal information with subcontractors and partner companies (cloud service providers, analytics service providers, etc.). In such cases, the Company will execute appropriate contracts and ensure thorough information protection.
Information from Third-Party Social Media Services
The Company allows users to create accounts, log in, and use the Service through the following Third-Party Social Media Services.
When a user registers through a Third-Party Social Media Service or otherwise grants the Company access to such service, the Company may collect personal data already associated with the user's Third-Party Social Media Service account, such as the user's name, email address, activities, and contact lists associated with that account.
Users may also have the option to share additional information with the Company through their Third-Party Social Media Service account. If a user chooses to provide such information and personal data during registration or otherwise, the user authorizes the Company to use, share, and store such information in a manner consistent with this Privacy Policy.
Data Protection and Security Management
Article 6: Data Protection
The Company implements the following measures to protect personal information.
- 1.Data encryption
- 2.Utilization of security infrastructure
- 3.Restriction of access privileges
- 4.Regular security audits
- 5.Establishment of data breach response protocols
Article 7: Rights of Personal Information Users
Users have the following rights.
- 1.Request for disclosure of personal information
- 2.Request for correction or deletion
- 3.Request to cease use
- 4.Right to data portability
- 5.Right to withdraw consent
The Company will respond to the exercise of these rights promptly and in good faith.
Service-Specific Handling
Article 8: Service-Specific Handling
- 1.Calendars, events, accounts, and settings
To display, create, edit, notify, and sync calendars and events, we handle calendar information on your device and Google Calendar information obtained and updated through the Google Calendar API. If you connect an external calendar such as Google, that information is also managed in accordance with each service provider's privacy policy.
We use Firebase Authentication and Firestore for account authentication, syncing your profile and app settings, shared calendar features, and saving event templates. Depending on the features you use, we store profile settings, device information, sharing-related information, and event template titles, locations, notes, and repeat and notification settings.
To provide integration and sharing features, we store the authentication credentials required for the Google integration (access tokens and refresh tokens) in Firebase, which we manage. We do not obtain or store your Google account password.
- 2.AI event creation, image analysis, and color suggestions
For AI event creation and analysis, we use the text and images you enter or provide to convert them into event candidates.
For voice input, your device's speech recognition converts speech into text. To create and analyze events, the converted text may be sent to Apple's Private Cloud Compute, or to Google Gemini via Firebase Cloud Functions. How speech recognition is processed depends on your device and OS features and settings.
Text you enter directly and images you provide for event creation are also processed by Apple's Private Cloud Compute, or by Google Gemini via Firebase Cloud Functions. Which processor is used depends on factors such as device support, and simple text may be processed on your device.
Event color suggestions are normally processed on your device on supported devices and OS versions. Available features and processing methods vary by device, OS, and settings.
- 3.Purchases of paid features and entitlements
To verify and restore purchases and manage entitlements to paid features, we use RevenueCat and send information such as user identifiers and purchase information.
- 4.Invitation links and attribution
To create invitation links for shared calendars, carry over invitation information, and measure acquisition channels, we use Firebase Cloud Functions and AppsFlyer. When an invitation link is generated, we send information such as the inviter's display name, the calendar name, the calendar ID, and an invitation token to AppsFlyer. To associate acquisition with app users, we also send the signed-in user's identifier to AppsFlyer. Depending on settings, this processing may also involve device information, identifiers, IP addresses, and information about installs and link usage.
- 5.Reminders and push notifications
To provide event reminders, shared calendar update notifications, and to-do notifications, we use event information on your device, notification settings, and notification tokens. Notifications are sent via Firebase Cloud Messaging (FCM) or Apple Push Notification service (APNs). Shared notifications may include event titles, dates and times, calendar names, display names, and to-do names.
- 6.Usage, errors, performance, configuration delivery, and abuse prevention
To analyze service usage, investigate errors, measure performance, deliver app configuration, and prevent abuse, we use Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config, and App Check. Depending on app launches and feature use, settings, consent, and device environment, we send information such as user identifiers, interaction events, app and device information, errors, performance information, and information needed to verify the app's integrity to each service.
- 7.Advertising
We use Google AdMob to display ads, manage consent, and measure ad performance. Advertising identifiers and similar information are handled according to your consent, device settings, app settings, and usage environment. Ad and consent management are also subject to the policies of the Google AdMob service provider.
You can change permission to use advertising identifiers in your device settings. The paid version stops displaying ads.
- 8.Place search
When you use place search, we send the search terms you enter, the language, and, where needed, a search area based on your current location to the Google Places API to obtain place suggestions and details. The information obtained is used to enter and display event locations.
- 9.URL previews and inquiries
When you use URL previews, your device accesses the URL to obtain metadata such as the page title, description, and images in order to display the preview. The policies of the accessed website also apply.
Communication also occurs when we retrieve information needed to display announcements, help content, profile images, and similar content from their sources, and those sources receive communication information such as your IP address.
When you submit an inquiry, we send the message body, reply email address, reply preference, the signed-in user identifier, app and device information, language settings, Pro status, diagnostic information, attached images, and similar information to Firebase in order to reply and investigate issues. The items sent vary depending on your input and usage environment.
Article 9: AI and Automation
The Company uses AI technology to improve the Service, but does not use users' personal data for training other AI models. The Company also ensures transparency regarding AI processing.
Article 10: Data Deletion
When a user deletes their account or individually requests data deletion, the following process is followed.
- 1.User data deletion: deleted promptly
- 2.Cache data deletion: deleted within 30 days
Article 11: Data Retention Period
The Company retains personal information for the period necessary for service provision or the period required by law. Data whose retention period has expired is appropriately disposed of.
Article 12: International Data Transfers
The Company may process personal information on servers outside Japan. In such cases, the Company complies with the EU General Data Protection Regulation (GDPR) and other international data protection standards. Standard Contractual Clauses (SCC) are applied and protective measures are taken.
Article 13: Use by Minors
The Service requires parental consent for minors. Minors should use the Service only after obtaining parental consent.
Article 14: Data Breach Notification
In the event of a personal information breach, users will be promptly notified and the following measures will be taken.
- 1.Investigation of the extent of damage
- 2.Contacting affected users
- 3.Implementation of measures to prevent recurrence
Other
Article 15: Changes to the Policy
The contents of this Policy may be changed without notice to users, except for matters otherwise stipulated in this Policy or by law. Unless otherwise determined by the Company, the revised Privacy Policy shall take effect from the time it is posted on this website.
Article 16: Contact Information
For inquiries regarding this Policy, please contact the following.
Company name: Nexus Inc.
Contact: contact@nexus-inc.net
Established: September 17, 2025
Last updated: September 28, 2026
Article 17 Personal Data Protection Matters for Users in Taiwan
For users located in Taiwan, we hereby disclose the following in accordance with the Personal Data Protection Act (PDPA) of the Republic of China (Taiwan):
- 1.Name of the collecting entity: Nexus Inc.
- 2.Purpose of collection: To provide calendar services, process paid features (aircal Pro), and improve service quality and usage analysis
- 3.Categories of personal data collected: Email address, Google account identification information, calendar data, event templates, app settings, device identifiers, usage history, purchase information, AI input data (text and images you enter), place search terms and search areas, inquiry contents, and diagnostic information
- 4.Period, region, recipients, and method of use: During your use of the Service, processed and used by automated means by us and the following companies in Japan and in the countries or regions where each company's servers are located
- Google (Firebase, Google Cloud, Gemini, Places API, AdMob)
- Apple (Private Cloud Compute, Apple Push Notification service)
- RevenueCat, Inc. (purchase verification and entitlement management; data is stored in the United States)
- AppsFlyer (invitation links and attribution)
- 5.Rights you may exercise: Under Article 3 of the PDPA, you may request to inquire about or review, obtain copies of, supplement or correct, request cessation of collection, processing, or use of, and request deletion of your personal data. To exercise these rights, please contact us using the contact information in this policy
- 6.Consequences of refusing to provide data: If you refuse to provide necessary personal data, you may be unable to use all or part of the Service
- 7.International transfer: You agree that we may transfer your personal data to Japan and to the countries or regions where the servers of each company listed in item 4 are located (including the United States) for processing and storage
- 8.Notification of personal data incidents: In the event of theft, alteration, damage, loss, or leakage of personal data, we will notify you in accordance with the PDPA
Article 18 Language Versions
The Traditional Chinese version of this Privacy Policy is the authoritative version. Versions in other languages are provided for reference only. In the event of any inconsistency between language versions, the Traditional Chinese version shall prevail.