個人情報保護方針
プライバシーポリシー
制定・最終更新:2026年7月20日
現在は閲覧・辞典、無料アカウント、読み取り専用MCP、利用後評価のβです。 ログインはChatGPTの認証画面で行い、AIコナスはパスワードを受け取りません。認証後、ChatGPTから渡されるメールアドレスを本人識別に利用し、アプリDBにはメールアドレスそのものではなく復元困難なハッシュ値を保存します。本番投稿、有料機能、実決済はまだ稼働していません。
1. 基本方針
AIコナス運営者(以下「運営者」)は、個人情報保護法その他の関係法令を守り、利用者の情報を必要な範囲で適正に取り扱います。取得時には利用目的を明示し、目的外利用を行いません。
2. 現在のβで扱う情報
Web画面の検索語、実行ガイドへ入力した回答、コピー内容はサーバーへ送信しません。ログイン時は、ChatGPTから認証済みメールアドレスの提供を受け、本人識別とマイページ表示に利用します。アプリDBへはメールアドレスそのものを保存せず、メールアドレスから作成した復元困難なハッシュ値、作成・更新時刻、利用回数、契約状態、接続キーのハッシュ値を保存します。パスワードは受け取りません。ホスティング事業者が安全確保や障害対応のためIPアドレス、時刻、通信情報等の技術ログを処理する場合があります。ブラウザのlocalStorageには、表示言語、最近使った方法のIDと日時、保存した方法のID(最大30件)、業務パックのID・現在工程・完了時刻・次回日、利用者が明示的に保存した投稿下書きを保存する場合があります。改善計測へ任意参加した場合を除き、これらの利用内容はサーバーへ送信しません。端末内の値は、利用者が削除するかブラウザ設定から消去するまで残ります。保存から30日を超えた下書きは、次にAIコナスを開いた時に削除します。ブラウザ設定からいつでも消去できます。共有端末では保存しないでください。
個人を識別しないアクセス集計
公開ページの利用状況を把握するため、閲覧日、ページの大分類、参照元の大分類、ページ表示回数をサーバー側で日ごとに集計します。Cookieやブラウザ保存領域を使った分析識別子は発行せず、検索語、URLのクエリやハッシュ、投稿・入力本文、生のIPアドレス、ユーザーエージェント、メールアドレス、個人・端末を識別する値、生の参照元URLは分析DBへ保存しません。日をまたいだ個人の行動追跡、新規・再訪判定、広告利用は行いません。集計値は運営改善のため400日以内保持します。bot、共有回線、配信キャッシュ等の影響を受けるため、実人数ではなくページ表示回数として扱います。
任意の業務パック改善計測
業務パック画面でログイン中の利用者がチェック欄を自ら選んだ場合に限り、サーバーは認証済みアカウントから秘密saltを使って仮名参加IDを作ります。改善イベントへ保存するのは、生のメールアドレスではなくこの仮名ID、業務パックID、必要な場合の方法ID、開始・完了種別、所要秒、結果区分です。1周完了後、利用者が任意で「普段より15分以上短縮できた」と回答した場合は、その回答も保存します。入力本文、検索語、資料、成果物、氏名、連絡先、顧客情報、決済情報は含めません。未参加、通信失敗、回答しないことによる機能制限はありません。
参加は画面からいつでも解除できます。解除すると新しいイベント送信を止め、ログイン中は本人の仮名IDに対応する受信済みイベントの削除も要求します。保持期間は通常30日で、設定上も90日を超えません。ホスティング事業者の技術ログは別途、安全確保に必要な期間処理される場合があります。
利用後の「役に立った」評価
ログイン中に評価すると、認証済みメールアドレスから秘密のソルトで作った仮名ID、方法ID、方法バージョン、役に立ったかどうか、役に立たなかった場合の定型理由、作成・更新時刻を保存します。生のメールアドレス、入力本文、検索語、AIの出力は評価データに含めません。βでは自由記述レビューを受け付けません。1人・1方法バージョンにつき1件とし、後から変更できます。集計値は少数票の偏りを補正し、5件未満はランキングへ表示しません。
本番開始後に取得する可能性がある情報
- メールアドレス、表示名、認証情報、居住国、18歳以上であることの確認
- 閲覧、検索、保存、投稿、更新、接続機能の利用履歴
- 利用者が送信する方法、説明、URL、フィードバック
- IPアドレス、ブラウザ、端末種別、Cookie等の識別子、障害ログ
- 有料機能のプラン、請求・支払状況
パスワードを導入する場合は平文保存せず、安全な認証基盤または適切なハッシュ化を利用します。カード番号は原則として決済事業者が取り扱います。
3. 利用目的
- 本人確認、ログイン、アカウント管理
- 辞典、保存、投稿、更新、AI接続等の提供
- 問い合わせ、重要なお知らせ、不正利用への対応
- 品質、安全性、検索精度の改善
- 料金請求、契約管理、法令上必要な記録
広告メールは、法令上必要な場合に別途同意を得て送ります。会員登録への同意と混在させません。
4. 安全管理・委託・第三者提供
アクセス制御、暗号化、権限管理、ログ確認等、情報に応じた安全管理措置を講じます。認証、ホスティング、決済、分析等を委託する場合は委託先を選定・監督します。法令に基づく場合等を除き、本人の同意なく個人データを第三者へ提供しません。国外のクラウド等を利用する場合は、必要な情報提供または同意取得を行います。
AI接続
目的に合う方法を選ぶために必要な短い情報だけを扱い、会話全文や秘密情報を要求しません。MCPの送信操作は接続先AIが行うため、送信前に各AIの表示する内容と権限も確認してください。受け取った目的を広告やAIモデル学習へ利用しません。
5. 開示・訂正・削除等
本人は、法令に従い、保有個人データの利用目的の通知、開示、訂正、利用停止、消去等を請求できます。本人確認後、法令に従って対応します。
開示・訂正・削除等の受付方法は、問い合わせ窓口の公開前にマイページへ追加します。現在のβではログアウトできますが、アカウント削除の受付はまだ開始していません。
6. 保存期間・未成年者・変更
情報は利用目的または法令上必要な期間だけ保持し、不要になった情報は安全に削除します。未成年者は必要に応じて保護者の同意を得てください。本ポリシーの重要な変更は適用開始前に通知し、必要な場合は追加の同意を得ます。
Governing version: The Japanese version is authoritative if a translation conflicts, without limiting mandatory rights under applicable law.
PERSONAL DATA PROTECTION POLICY
Privacy Policy
Issued and last updated: July 20, 2026
This beta provides browsing, the method library, free accounts, a read-only MCP endpoint, and post-use ratings. Authentication takes place on ChatGPT. AI Konas never receives your password. After authentication, the email address forwarded by ChatGPT is used to identify you; the application database stores a non-reversible hash rather than the email address itself. Live contributions, paid features, and payments are not active.
1. Current beta data
Web search terms, personalization answers, and copied guides are not transmitted to the server. At sign-in, ChatGPT forwards a verified email address for identification and account display. The application database stores a non-reversible email hash, account timestamps, usage counts, subscription state, and connection-key hashes; it does not store the email address itself or receive a password. The hosting provider may process IP address, time, and technical request logs for security and reliability. The browser may store the display language, a recent method ID and date, up to 30 IDs of methods you choose to save, business-pack ID, current step, completion times and next-run date, plus a contribution draft only when you choose to save it. Except when you optionally join improvement measurement, these usage values are not sent to the server. Device values remain until you delete them or clear browser storage. A draft older than 30 days is deleted the next time AI Konas is opened. Do not save on a shared device.
Access counts without personal identification
To understand use of public pages, the server aggregates the viewing date, broad page category, broad referrer category, and page-view count by day. Analytics does not issue a Cookie or browser-storage identifier and does not store search terms, URL queries or fragments, contribution or input text, raw IP addresses, user agents, email addresses, personal or device identifiers, or raw referrer URLs in the analytics database. We do not track a person across days, classify new or returning visitors, or use these counts for advertising. Aggregates are retained for no more than 400 days. Because bots, shared networks, and delivery caches may affect the count, it is described as page views rather than people.
Optional business-pack improvement measurement
Only after you actively select the checkbox while signed in, the server derives a pseudonymous pilot ID from the authenticated account using a secret salt. Pilot events store that ID—not the raw email—plus the business-pack ID, method ID where required, start or completion type, duration and result. After a full run, we also store an optional answer only when you choose “saved at least 15 minutes.” Improvement events do not include input text, search terms, source documents, outputs, names, contact details, customer information, or payment details. Declining, a network failure, or skipping the question never limits features.
You can leave from the screen at any time. Leaving stops new events and, while signed in, sends a request to delete events for your pseudonymous ID. Retention is normally 30 days and cannot be configured beyond 90 days. Hosting-provider technical logs may be processed separately for the period needed for security and reliability.
Post-use helpfulness ratings
When a signed-in person rates a method, we store a pseudonymous ID derived from the authenticated email with a secret salt, method ID and version, whether it helped, a fixed reason code when it did not help, and creation and update times. Rating data does not contain the raw email address, input text, search terms, or AI output. The beta does not accept free-text reviews. One current rating is kept per person, method, and version, and it can be changed later. Rankings adjust for small samples and do not display a method until at least five ratings are available.
2. Data after live launch
Live features may process account details, authentication data, usage and device logs, submitted content, support communications, and subscription status. Passwords will not be stored in plain text. Payment card data will normally be handled by a payment provider.
3. Purposes
- Authentication and account administration
- Search, saving, contribution, update, and AI connection features
- Support, security, fraud prevention, and important notices
- Quality, safety, and discovery improvements
- Billing, contracts, and legally required records
Marketing consent will be optional and separate.
4. Security, processors, and AI connections
We apply appropriate access controls, encryption, permission management, and monitoring. Providers may support authentication, hosting, payments, and analytics under oversight. Personal data will not be disclosed without consent unless permitted by law. Required information or consent will be provided before international transfers. MCP is designed to use only the short information needed to select a method. Because the connected AI initiates the request, review the data and permissions shown by that provider before enabling it. MCP goals are not used for advertising or model training by AI Konas.
5. Rights, retention, and contact
Subject to applicable law, you may request access, correction, suspension, or deletion. Data will be kept only as long as needed for stated purposes or legal obligations. The account page supports sign-out. A request channel and account deletion process will be added before broader account features open.
6. Minors and changes
Minors should obtain guardian consent where required. Material changes will be announced before they apply, and additional consent will be obtained when required.