This Privacy Policy sets forth the handling of personal information and the locus of responsibility with respect to the services related to the use of “Kumoy” provided by MIERUNE Inc. (the “Operating Company”) (collectively, the “Services”), for the purpose of ensuring that the Operating Company respects the privacy of users using the Services (“Users”) and appropriately manages and operates Users’ personal information.
This Privacy Policy applies to the processing of the personal information of any Users residing in Japan; the Global Privacy Policy (the “Global Privacy Policy”) applies to the processing of the personal information of any Users residing outside Japan; and the “Supplementary Provisions: Processing of Personal Information of Users Residing in California, U.S.,” in addition to the Global Privacy Policy, apply to the processing of the personal information of any Users residing in California, U.S. Please refer to the respective provisions as applicable.
The Operating Company defines the following information as personal information:
The Operating Company shall use personal information for the following purposes:
The Operating Company shall acquire Users’ personal information only to the extent input or operated by Users in using the Services and the services of enterprises entrusted by the Operating Company.
The Operating Company shall endeavor to maintain the accuracy and integrity of personal information and keep it up to date within the scope of the purposes of use as set forth in Article 2, and shall take necessary and appropriate security measures aligned with the current state of the art and rectify the same as necessary in order to prevent any unauthorized access, divulgence, falsification, loss, impairment, etc.
The following are included within the security measures taken by the Operating Company:
Establishment of a basic policy
In order to ensure the proper processing of personal information, the Operating Company has established this Privacy Policy, which shall serve as the basic policy on compliance with the relevant laws, regulations and guidelines, etc., and which sets forth the contact point, etc. for handling questions and complaints.
Security measures
With respect to the organizational control of personal information, the Operating Company has strictly stipulated the method of processing personal information in its internal regulations, thereby ensuring that personal information is processed in accordance with such provisions.
Supervision of employees
The Operating Company ensures, in accordance with its internal regulations, the strict application of its regulations on the processing of personal information.
Supervision of entrustees
When entrusting the processing of personal information to a third party, the Operating Company shall, in accordance with its internal regulations, only entrust such processing to an entrustee which meets the relevant requirements, and shall exercise appropriate control upon such entrustee.
Measures to be taken upon the occurrence of divulgence
In the event of any divulgence, etc. of personal information, the Operating Company shall submit a report to the Personal Information Protection Commission and provide notice to the data subjects in accordance with the applicable laws and regulations.
The Operating Company shall not provide Users’ personal information to any third party without the consent of the User; provided, however, that this shall not apply in cases in which the Operating Company:
The Operating Company shall not process personal information beyond the scope necessary for achieving the purposes of use without the consent of the User; provided, however, that this shall not apply in the following cases:
The Operating Company shall respond to requests from Users for the disclosure (which shall include records of cases in which personal data is provided to, or received from, third parties; the same shall apply hereinafter; a fee of 1,000 yen (excluding consumption tax) per request shall be charged for disclosure), correction, deletion, erasure, suspension of use, suspension of provision to third parties, etc. of such Users’ own personal information. To request the disclosure, correction, deletion, erasure, suspension of use, suspension of provision to third parties, etc. of personal information, please contact the “Point of Contact” set forth in Article 14; provided, however, that the Operating Company may decline to disclose all or part of such information in the following cases:
Users shall warrant to the Operating Company that the contents of their personal information are accurate at all times, and Users shall bear all responsibility for any damage arising from inaccurate personal information.
When a User requests the correction, addition, etc. of his/her personal information, the Operating Company shall confirm that the request has been made by the User him/herself, as well as the accuracy of the contents of the correction, and shall take appropriate measures.
The Operating Company may use cookies on the Services for the purpose of improving the convenience of the Services and keeping track of the usage status thereof. The information acquired and retained through cookies is as follows:
On the Services, the Operating Company collects and uses log data concerning Users’ usage status, etc. for the purpose of providing, maintaining and improving the Services and conducting security management. In addition, as described in the respective sections below, data collection modules are incorporated into the Services. Accordingly, Users’ information (log data and personal information) is provided to the respective providers of such data collection modules (including those located outside Japan).
The Operating Company collects log data concerning Users’ usage status of the Services, through the log data collected by the Operating Company or through the following data collection modules, and provides such log data to the providers of such data collection modules (including those located outside Japan). Such log data is collected for the purposes of improving the convenience of the Services, keeping track of the usage status thereof, and conducting operational management thereof, and shall not be used for any other purposes.
The information collected as log data is as follows:
The Services use Google Analytics, a service provided by Google LLC (“Google”), for the purposes of optimizing content, keeping track of and analyzing Users’ usage status of the Services, and optimizing the distribution of advertisements and measuring their effectiveness.
Google Analytics uses cookies issued by the Services to collect log data. The log data is collected online by Google, then analyzed and transmitted to the Operating Company. This log data is collected anonymously and does not contain any information identifying any specific individual.
Google manages such log data in accordance with Google’s terms of service and privacy policy. Users may refuse such collection by disabling cookies or by using the opt-out tool provided by Google. Please check the settings of your browser or use the following opt-out tool.
Google Analytics Opt-out Browser Add-on download page: https://tools.google.com/dlpage/gaoptout?hl=en
For further details on the terms of Google Analytics, please refer to the following pages:
Google Analytics Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/
Data protection in Google Analytics: https://support.google.com/analytics/answer/6004245?hl=en
Google Privacy Policy: https://policies.google.com/privacy?hl=en
The Services use Wicle, a service provided by PLAID, Inc. (“PLAID”), for the purposes of keeping track of and analyzing Users’ usage status of the Services, conducting marketing, and providing support to Users.
Wicle uses cookies issued by the Services to collect log data. The log data is collected online by PLAID, then analyzed and transmitted to the Operating Company.
The Operating Company transmits Users’ IDs to PLAID as Wicle user profiles and uses them to identify users.
In addition, with respect to session replays acquired through Wicle, the Operating Company acquires and manages them as personal data and uses them for purposes such as handling inquiries and improving the Services.
PLAID manages such log data in accordance with PLAID’s terms of use and privacy policy. Users may refuse such collection by using the opt-out method.
How to configure the Wicle opt-out: https://docs.wicle.io/other/opt-out
For further details on the terms of Wicle, please refer to the following pages:
Wicle Terms of Use: https://wicle.io/terms-of-use
Wicle Privacy Policy: https://wicle.io/privacy-policy
The Services use Sentry, an error monitoring service provided by Functional Software, Inc. (“Sentry Inc.”), in order to collect error log data arising in connection with the use of the Services.
The Operating Company provides Users’ error log data to Sentry Inc. by transmitting it online. Sentry Inc. manages such log data in accordance with Sentry’s terms of service and privacy policy.
The Operating Company transmits Users’ IDs to Sentry Inc. as the Sentry User and uses them to identify users.
For further details on the terms of Sentry, please refer to the following pages:
Sentry Terms of Service: https://sentry.io/terms/
Sentry Privacy Policy: https://sentry.io/privacy/
The Operating Company provides Users’ personal information to the respective providers of the following data collection modules (including those located outside Japan). Such personal information is provided for the purposes of providing the functions of the Services, improving convenience, measuring effectiveness, conducting analysis, etc., and shall not be used for any other purposes.
The Services use Stripe, provided by Stripe, LLC (“Stripe LLC”), for the purpose of conducting payment processing associated with Users’ online purchase of paid subscriptions.
The Operating Company provides Stripe LLC with information related to the organization necessary for a User’s online purchase of a paid subscription, the User’s ID, and other information.
Stripe LLC manages such log data in accordance with Stripe’s terms of service and privacy policy.
Stripe Consumer Terms of Service: https://stripe.com/legal/consumer
Stripe Privacy Policy: https://stripe.com/privacy
The Services use Google Enhanced Conversions, provided by Google LLC (“Google”), for purposes such as distributing advertisements tailored to Users’ interests and preferences and improving the accuracy of advertising effectiveness measurement.
The Operating Company provides Users’ email addresses by hashing them and transmitting them online. Google manages the hashed email addresses in accordance with “About enhanced conversions data usage by Google” and the Google Privacy Policy.
For the terms and details of Google Enhanced Conversions, please refer to the following pages:
About enhanced conversions data usage by Google: https://support.google.com/adspolicy/answer/9755941?hl=en
Google Privacy Policy: https://policies.google.com/privacy?hl=en
The Operating Company shall not bear any responsibility with respect to the handling of personal information by third parties in the following cases:
The Operating Company shall only store personal information for the period required for achieving the purposes of use. Even after a User has deleted his/her account, there may be cases in which the Operating Company stores such information for a certain period to the extent necessary to comply with the laws and regulations, handle claims, conduct payment and accounting procedures, prevent unauthorized use, take security measures, etc.
Please contact the Operating Company at the following point of contact for any inquiries regarding this Privacy Policy.
MIERUNE Inc. Personal Information Protection Representative
Contact Information: Inquiry form
The Operating Company may amend this Privacy Policy without obtaining the consent of Users, by providing appropriate prior notice thereof to Users.
Revised: June 11, 2026
Effective: February 13, 2026
In compliance with the applicable laws and regulations, including, without limitation, Regulation (EU) 2016/679 (General Data Protection Regulation; the “GDPR”), MIERUNE Inc. (the “Operating Company”) stipulates this Global Privacy Policy as follows, concerning the processing of the personal data of any users (meaning users of the Services; “Users”) residing outside Japan in providing “Kumoy,” a cloud service provided by the Operating Company, and any services related to the use thereof (collectively, the “Services”).
The Japan Privacy Policy applies to the processing of the personal data of any Users residing in Japan, and the “Supplementary Provisions: Processing of Personal Information of Users Residing in California, U.S.,” in addition to this Global Privacy Policy, apply to the processing of the personal data of any Users residing in California, U.S. Please refer to the respective provisions as applicable.
The Operating Company shall collect and process the following personal data in relation to the Services:
Personal Data Controller:
MIERUNE Inc.
Address: 3rd Floor, F-60, 8-1-8 Odori Nishi, Chuo-ku, Sapporo, Hokkaido, Japan
Personal Data Protection Manager:
Address: 3rd Floor, F-60, 8-1-8 Odori Nishi, Chuo-ku, Sapporo, Hokkaido, Japan
Email address: privacy@mierune.co.jp
The Operating Company shall use personal data for the following purposes, under the legal basis of Users’ consent, performance of contracts between the Operating Company and Users, fulfillment of legal obligations, or the legitimate interest of performing the Operating Company’s business. The Operating Company shall not make any decisions which may have any legal or similarly significant impact on Users based solely on automated processing, including profiling using personal data.
The Operating Company shall acquire Users’ personal data from the following sources:
The Operating Company shall not provide Users’ personal data to any third party, excluding cases in which the Operating Company:
There may be cases in which the Operating Company transfers Users’ personal data to a third country (such as Japan) other than Users’ country of habitual residence (or outside the EEA for any Users residing within the EEA) in order to achieve the purposes of use as set forth in Article 3 (each such transfer, an “Extraterritorial Transfer”). When conducting an Extraterritorial Transfer of Users’ personal data to a third country, the Operating Company shall transfer the same upon having implemented the safeguards required under the applicable laws and regulations. For example, if a User resides within the EEA, such User’s personal data shall, as a general rule, be transferred upon having executed a set of standard data protection clauses with the receiving party, which shall serve as an appropriate safeguard, in accordance with the GDPR and other applicable laws and regulations of EU/EEA member states, unless the European Commission has decided that the third country ensures an adequate level of data protection. For further information, please contact the Operating Company via the inquiry form provided in Article 13.
The Operating Company shall only store personal data for the period required for achieving the purposes of use as set forth in Article 3.
The period for storing the personal data is determined based on: (i) whether the Operating Company has a continuous relationship with the relevant User; (ii) whether the Operating Company is subject to the obligation to archive such personal data under the applicable laws and regulations; and (iii) whether there is a contract which must be performed between the Operating Company and the relevant User.
Even after a User has deleted his/her account, there may be cases in which the Operating Company continues to store such User’s personal data to the extent necessary to comply with the laws and regulations, handle claims, conduct payment and accounting procedures, and to perform analysis in order to prevent unauthorized use and take security measures, etc.
The Operating Company shall maintain the accuracy and integrity of personal data and keep it up to date within the scope of the purposes of use as set forth in Article 3, and shall take necessary and appropriate security measures aligned with the current state of the art and rectify the same as necessary in order to prevent any unauthorized access, divulgence, falsification, loss or impairment (collectively, “Divulgence, Etc.”).
The following are included within the security measures taken by the Operating Company:
Establishment of a basic policy In order to ensure the proper processing of personal data, the Operating Company has established this Global Privacy Policy, which shall serve as the basic policy on compliance with the relevant laws, regulations and guidelines, etc., and which sets forth the contact point, etc. for handling questions and complaints.
Security measures With respect to the organizational control of personal data, the Operating Company has strictly stipulated the method of processing personal data in its internal regulations, thereby ensuring that personal data is processed in accordance with such provisions.
Supervision of employees
Supervision of entrustees When entrusting the processing of personal data to a third party, the Operating Company shall only entrust such processing to an entrustee which meets the requirements under the applicable laws and regulations, such as through supervision and/or the execution of a contract, and shall exercise appropriate control upon such entrustee.
Measures to be taken upon the occurrence of Divulgence, Etc. In the event of any Divulgence, Etc. of personal data, the Operating Company shall submit a report to the relevant supervisory authorities and provide notice to the data subjects in accordance with the applicable laws and regulations.
Under the applicable laws and regulations, Users may have the following rights with respect to their personal data; provided, however, that if any derogations of rights are established under the applicable laws and regulations, the User’s exercise of such rights may be restricted. Please contact the Operating Company via the inquiry form provided in Article 13 to exercise any of these rights.
In accordance with the applicable laws and regulations, Users may have the right to object to the processing of their personal data at any time. If a User’s personal data is processed for the purpose of direct marketing, such User may have the absolute right to refuse such direct marketing under the applicable laws and regulations. Please contact the Operating Company via the inquiry form provided in Article 13 to exercise this right.
Under the applicable laws and regulations, Users may have the right to withdraw their consent regarding the processing of their personal data at any time. A User’s withdrawal of consent shall not affect the lawfulness of the processing of such User’s personal data which was conducted based on consent before its withdrawal. Please contact the Operating Company via the inquiry form provided in Article 13 to exercise this right.
Users may have the right to lodge a complaint with a supervisory authority in the country of their habitual residence with respect to the Operating Company’s processing of their personal data under the applicable laws and regulations. Users should inquire with the respective supervisory authorities for further information on the applicable procedures.
Please contact the Operating Company at the following point of contact for any inquiries regarding this Global Privacy Policy.
MIERUNE Inc. Personal Data Protection Representative
Point of contact: Inquiry form (Japanese page only)
Effective: June 11, 2026
In accordance with the California Consumer Privacy Act (the “CCPA”), these “Supplementary Provisions: Processing of Personal Information of Users Residing in California, U.S.” (these “Supplementary Provisions”), in addition to the Global Privacy Policy separately set forth, apply to the processing of the personal information of any Users residing in California, U.S. In the case of any discrepancy between the provisions of these Supplementary Provisions and the Global Privacy Policy, the provisions of these Supplementary Provisions shall prevail.
The terms used in these Supplementary Provisions shall have the meanings provided thereto under the Global Privacy Policy and as defined under the CCPA. For the purpose of these Supplementary Provisions, the following terms shall have the following meanings in particular:
The Operating Company has collected the following categories of personal information about Users from the sources set forth in Article 4 of the Global Privacy Policy during the past twelve (12) months, and shall continue to collect such categories of personal information in the future. The Operating Company shall use the collected personal information for the purposes set forth in Article 3 of the Global Privacy Policy, and shall store the same for the period set forth in Article 7 of the Global Privacy Policy. During the past twelve (12) months, the Operating Company has disclosed Users’ personal information to entrustees for the business purposes set forth in Article 5 of the Global Privacy Policy, and plans to disclose the same to entrustees for business purposes in the future as well; provided, however, that the Operating Company has not sold or shared any personal information collected from Users to date, and shall not sell or share the same in the future.
| Categories | Examples |
|---|---|
| Identifiers | Information registered on service accounts; and<br>IP addresses, cookies and other identifiers |
| Categories of personal information as set forth in the California Customer Records Act (Cal. Civ. Code § 1798.80(e)) | Information registered on service accounts |
| Commercial information | Information registered on service accounts |
| Internet or other electronic network activity information | Log data (operating system and browser software data of communication terminals, data related to internet connections, referrers, error logs, IP addresses, URLs browsed and accessed on the Services and the timestamps of the dates and times of such browsing or access, action logs of any clicking, scrolling, input and any other actions performed on the Services, as well as any other server log data) |
| Sensitive personal information | Login data pertaining to Users’ accounts in combination with passwords and other credentials allowing access to such accounts |
Under the CCPA, individual rights are granted to each User in relation to their personal information. Users’ rights under the CCPA and how to exercise such rights are as described below.
Right to request disclosure Users shall have the right to request that the Operating Company disclose certain information to them related to the collection, sharing, disclosure, or use of their personal information. Upon having received and confirmed any request from a User, through which the relevant individual may be identified, the Operating Company shall disclose all or part of the following information to such User:
Right to request deletion Users shall have the right to request that the Operating Company delete any personal information about them which the Operating Company has collected and maintains, except where certain exceptions apply. Upon having received and confirmed any request from a User, through which the relevant individual may be identified, the Operating Company shall delete (and request its entrustees, etc. to delete) such User’s personal information from its records, unless any exceptions apply. The Operating Company may deny a User’s request for deletion if it is necessary for the Operating Company or its entrustees, etc. to maintain such information in order to:
Right to request correction Users shall have the right to request that the Operating Company correct any inaccurate personal information about them which the Operating Company has collected and maintains. Upon having received and confirmed any request from a User, through which the relevant individual may be identified, the Operating Company shall correct (and request its entrustees, etc. to correct) such inaccurate personal information about such User from within its records. The Operating Company may deny a User’s request for correction if it has decided, by evaluating the situation in a holistic manner, that it is more likely that the personal information subject to such request is actually accurate.
Use of sensitive personal information Sensitive personal information which the Operating Company collects (login data of Users’ accounts in combination with credentials such as passwords) is only used or disclosed within the scope of the permissible purposes, such as identity verification and ensuring security. Therefore, the Operating Company does not provide any dedicated link that enables Users to limit the use or disclosure of sensitive personal information.
The Operating Company has not sold or shared Users’ personal information within the past twelve (12) months, and does not plan to sell or share such information in the future. The Services are only targeted for Users who are at least sixteen (16) years of age, and therefore the Operating Company does not plan to sell or share any personal information of any persons regarding whom it has actual knowledge that they are less than sixteen (16) years of age.
The Operating Company shall not discriminate against a User because such User exercised any of their rights under the CCPA. In addition, the Operating Company shall not engage in any of the following acts due to a User’s exercise of such rights, unless otherwise permitted by the CCPA:
Users are requested to contact the Operating Company via the inquiry for provided in Article 13 of the Global Privacy Policy or email address(support@kumoy.io) in order to exercise any of the rights under the CCPA. When making any request to the Operating Company based on any of such rights, a User must provide sufficiently detailed explanations on the subject matter so that the Operating Company can appropriately understand, evaluate, and handle, the request.
Only Users themselves, any persons who are authorized by Users to act on their behalf or who are registered with the Secretary of State of California as their proxies, Users’ entrustees, or Users’ property guardians can make a request regarding Users’ personal information. If permitted under the CCPA, the Operating Company may conduct the procedures for verification of identity and proxy authority required under the CCPA.
Effective: June 11, 2026