Privacy Policy

Last updated: August 30, 2026

株式会社ファネルAi (formerly 株式会社ロゴラボ; the “Company,” “we,” “us” or “our”) establishes this Privacy Policy (the “Policy”) concerning the handling of personal information we obtain.

Unless otherwise specified, terms in this Policy have the meanings given in Japan’s Act on the Protection of Personal Information (Act No. 57 of 2003; “APPI”) and related laws.

This Policy describes the handling of information about users, including personal information and user information, in Funnel Ai (the “Service”).

The Service complies with APPI, other applicable laws and guidelines, and the Google API Services User Data Policy.

Use of the Service is also subject to the Terms of Service, guides, help materials, notices and other provisions (the “Supplementary Provisions”), which form part of this Policy.

1. Collection and purposes of use of personal information

We obtain users’ personal information appropriately and use it within the purposes set out in this section.

1.1 Information collected

Examples of information collected and collection methods are listed below. We collect only the minimum necessary information.

1.2 Purposes of use

The Service uses collected information for the following purposes:

The Service may integrate with External Services such as Gmail based on user instructions. Their availability and specifications depend on their providers, and the Service does not guarantee their continued provision.

2. Third-party provision and outsourcing

We do not provide personal information to third parties except:

We may outsource infrastructure, delivery, analysis, customer support and other activities as necessary to operate the Service. We contractually require appropriate security measures and supervise these providers.

Provision and outsourcing involving Google user data and Zoom data are governed by Sections 7 and 8, respectively.

3. Requests for disclosure and other actions

When an individual or their representative requests disclosure, correction, addition, deletion, cessation of use or cessation of third-party provision of retained personal data, we respond appropriately under APPI. We verify identity using our prescribed procedures.

We may withhold all or part of the information if disclosure could harm the life, physical safety, property or other rights of the user or a third party; materially interfere with our business operations; or violate law. We will promptly notify the requester in such cases.

If personal information disclosed to a user is incorrect, we will promptly correct it upon the user’s request.

If we receive a claim that personal information is handled outside its purposes of use or was obtained improperly, we will promptly investigate as necessary and, based on the results, cease use or erase the information (“Cessation of Use”) and notify the user. If Cessation of Use would entail substantial expense or is otherwise difficult, we will take alternative measures necessary to protect the user’s rights and interests.

Users may also revoke OAuth access through their Google account settings.

4. Changes to this Policy

We will announce changes in advance by posting them on our website or sending email. Minor changes that do not materially disadvantage users, including changes resulting from legal amendments, corrections of errors and clarifications, may be announced afterward.

For material changes, such as additional categories of collected data or fundamental changes in purposes of use, we will obtain users’ consent again.

The amended Policy applies when posted on our website, unless we specify a different effective date.

5. Contact

For inquiries about this Policy or personal information handling, contact:

6. Security measures

We implement organizational, personnel, physical and technical security measures to prevent leakage, loss, damage, alteration and unauthorized access.

7. Google user data collected

7.1 Data types and OAuth scopes

Through Google account integration, the Service collects the following data within scopes approved by the user through OAuth.

Gmail data

Google Calendar data

Google Meet meeting metadata

Google Drive data

Google account information

The Service obtains the Google account email address for identity verification and communication, and the display name and profile image for display within the Service.

7.2 Purposes of use

Collected Google user data is used only for:

7.3 Data flow summary

Prompts and responses sent to Gemini API during inference are not retained in logs. Gmail bodies, Calendar details and Meet transcripts are not retained in error logs, AI inference prompt logs or short-term cache layers. See Section 6.

7.4 Third-party provision and outsourcing

The Service does not transfer collected Google user data to third parties, including for advertising, data sales or provision to data brokers for marketing.

However, to provide the Service, we entrust the minimum necessary processing to the following providers. They process data under our instructions and contracts and do not use it for independent purposes.

The Service uses Gemini API under a paid-tier contract. Submitted data is used only to generate inference results and is never used to train AI models, in accordance with Google Cloud’s Generative AI Service Terms.

7.5 Restrictions on human access

Staff are prohibited from reading users’ Google user data, including Gmail bodies, Calendar content and Meet transcripts, except:

All human access is recorded in audit logs and is subject to internal audit.

7.6 Tenant isolation

The Service uses a multitenant design and enforces tenant_id constraints on all database queries and API calls to prevent data leakage between tenants. The technical implementation of tenant isolation has been independently verified in a CASA Tier 2 audit report.

7.7 Google API Services User Data Policy compliance (Limited Use)

The Service complies with the Google API Services User Data Policy, including its Limited Use Policy, when handling information received from Google APIs.

“Funnel Ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.”

Specifically, the Service complies with these four Limited Use conditions:

  1. Limited purposes: Google user data is used only to provide features expressly approved by users, such as email classification, draft generation, calendar synchronization and meeting summaries.
  2. No advertising use: Google user data is not used for advertising, including targeting, profiling or advertising effectiveness measurement.
  3. Restricted human access: staff do not read Google user data except in the limited circumstances in Section 7.5.
  4. Restricted transfers: Google user data is not transferred to third parties other than the essential service providers described in Section 7.4.

8. Zoom integration data

With authorization from users or their organization’s administrator, the Service may obtain Zoom account information, OAuth tokens, meeting information, cloud recordings, transcripts and Webhook events through Zoom integration.

We use this information to create and manage Zoom meetings, coordinate schedules, maintain meeting records, retrieve and display cloud recordings and transcripts and associate them within the customer’s tenant, and maintain integrations, address failures and prevent misuse.

Zoom OAuth access and refresh tokens are stored encrypted using AES-256-GCM. External communications use HTTPS. Webhooks received from Zoom are verified using the Secret Token, x-zm-signature and x-zm-request-timestamp. Zoom data is stored and processed separately for each customer tenant.

When Zoom is disconnected, we invalidate and delete stored OAuth access and refresh tokens and stop acquiring new data from Zoom APIs. Business records already imported are retained until the customer tenant is deleted or the customer requests deletion. We may retain information as necessary for legal compliance, dispute resolution or audits.

We do not sell Zoom data or use it for advertising delivery. We do not provide it to third parties except with user consent, as required by law, or when entrusting minimum necessary processing to providers needed to deliver the Service.

9. Retention and deletion

Even after account deletion, we may retain information for a certain period to the extent necessary for legal compliance, dispute resolution, audits or similar needs.

Retention and deletion conditions for Google user data acquired through the Service are set out below. When OAuth access is revoked or a tenant’s contract is terminated, we stop new data acquisition and, as a rule, delete stored data within 30 days.

Send deletion requests to the contact in Section 5. Content included in Cloud SQL automatic backups is automatically removed by GCP after the backup retention period.

Retention and deletion of Zoom integration data are governed by Section 8.

10. International transfers

Data may be transferred outside Japan through cloud services and similar arrangements. We take necessary protective measures under the laws applicable in the destination jurisdiction.

11. Minors

Minors should obtain a parent or guardian’s consent before using the Service. If we learn that a user is a minor, the Service may take necessary measures.

12. Cookies

Our website uses cookies. You may reject cookies through your browser settings.

13. Access history

Our website records access history to improve services. This may include IP addresses, cookies, browser types, device information and referrers. We use this information for usage statistics, analysis and service improvement, not to directly identify users.