プライバシーポリシー
英語版は参考訳です。日本語版との間に齟齬がある場合、日本語版が優先されます。
株式会社meltain (以下「当社」といいます) は、「OwnedAgent」の名称で提供するサービス (以下「本サービス」といいます) において取り扱う個人情報の保護を重要な責務と認識し、 個人情報の保護に関する法律 (以下「個人情報保護法」といいます) その他の関係法令を遵守するとともに、 本プライバシーポリシー (以下「本ポリシー」といいます) に従って個人情報を適切に取り扱います。
1. 事業者情報
- 事業者の名称: 株式会社meltain
- 所在地: 〒150-0043 東京都渋谷区道玄坂1丁目10番8号 渋谷道玄坂東急ビル2F-C
- 代表者: 田島一毅
- 電話番号その他の事業者情報: 法令に基づくご請求があった場合、遅滞なく回答します。その他の運営会社情報は、当社の運営会社情報をご確認ください。
- 個人情報保護に関する問い合わせ窓口: 本サービスのお問い合わせフォーム (担当: 個人情報保護管理者)
2. 取得する情報
当社は、本サービスの提供にあたり、次の情報を取得します。
- アカウント情報: 登録された表示名、メールアドレス、パスワードのハッシュ、認証セッション情報等。Gmail連携を利用する場合は、Googleアカウントのメールアドレス、外部認証アカウントID、OAuthトークン等も取得します。当社は平文のパスワードを保存しません。
- 組織・ワークスペース・プロジェクトに関する情報: 本サービス内で作成または設定される組織名・ワークスペース名 (個人利用時に自動作成されるものを含みます)、メンバー構成、プロジェクト名、共有・権限設定その他の利用状況。
- ユーザーコンテンツ・AI 入力データ: 本サービスに入力・アップロードされるプロンプト、画像、ワイヤーフレーム、コメント、インタビューの回答内容、その他のデータ。
- 生成物: 本サービスが生成する UI デザイン、React / TSX コード、画像、デザイントークン、ペルソナ分析等の出力。
- 契約・利用枠情報: プラン、利用開始日・終了日、利用席数、クレジットの付与・利用履歴等。
- 利用ログ・技術情報: IP アドレス、ブラウザ・デバイスの種類、リファラ、操作ログ、AI 利用に関する処理ログ、Cookie 等の識別子。
- ベータ版に関する情報: 参加状況、利用状況、任意で提供されるアンケート・インタビュー・不具合報告・要望・提案その他のフィードバック内容、および当社とのやり取り。
- お問い合わせ情報: お問い合わせフォーム等を通じて提供される氏名、会社名、メールアドレス、用件、お問い合わせ内容。
3. 取得方法
当社は、ユーザーまたは契約担当者による入力・送信、本サービスの利用に伴う自動的な記録、外部認証サービスとの連携等を通じて、前項の情報を取得します。
4. 利用目的
当社は、取得した個人情報を、次の目的の達成に必要な範囲で利用します。
- 本サービスの提供、維持、本人認証およびアカウント・組織の管理のため。
- AI 機能による生成処理の実行のため。
- 利用契約、請求およびクレジットの管理のため。
- 本サービスの品質改善、新機能の開発、不具合の解析および対応のため。
- ベータ版、検証版その他正式提供前の機能または環境の運営、参加者管理、利用状況の把握、任意で提供されたフィードバックの分析、品質改善および正式版に向けた検討のため。
- 不正利用、不正アクセスその他の不正行為の検知・防止およびセキュリティの確保のため。
- ユーザーサポート、お問い合わせへの対応、およびこれらに必要な範囲で関連する利用状況・プロジェクトデータを確認するため。
- 本サービスに関する重要なお知らせ、規約・ポリシーの変更等の通知のため。
- 本サービスの利用状況の分析、統計データの作成 (個人を識別できない形式に加工して行います) のため。
- 本サービスまたは当社の関連サービスに関する情報のご案内のため (法令上必要な場合または当社が適切と判断する場合は、配信停止の方法を提供します)。
5. AI 機能における入力データの取扱い
- 本サービスの AI 機能の提供のため、ユーザーが入力・アップロードしたデータおよびその処理に必要な情報は、当社が利用する外部 AI プロバイダ (OpenAI、Anthropic、Google、Google Cloud Vertex AI、Amazon Bedrock 等) に対し、API を通じて送信され、生成物の出力のために処理されます。
- AI 機能に関する処理は、各外部 AI プロバイダの仕様、処理地域、モデルの提供形態および当社の設定に従い、日本国外を含む地域で行われる場合があります。
- 各外部 AI プロバイダの API 規約上、送信された入力データおよび生成物は、当該プロバイダのモデルの学習・改善の目的には使用されません。当社も、ユーザーの入力データおよび生成物を、当社の AI モデルの学習・開発の目的には使用しません。将来これに変更が生じる場合は、あらかじめ明示し、必要に応じて同意を得たうえで行います。
- 当社は、本サービスの改善、品質管理、新機能の検討および不正利用防止のため、個人または組織を識別できない統計情報・集計情報を作成し、利用することがあります。
- ユーザーが第三者の個人情報を入力する場合、ユーザーは、当該個人情報の取得および当社を含む外部への提供 (越境移転を含みます) について、自らの責任で適法な根拠を確保するものとします。
6. 安全管理措置
- 当社は、取得した個人情報およびユーザーコンテンツを、Amazon Web Services の日本国内 (東京リージョン / ap-northeast-1) を中心とするクラウド環境において、暗号化のうえ保管します。ただし、AI 処理、認証、メール送信、外部連携その他の処理は、委託先または提供先の所在国・処理地域で行われる場合があります。
- 当社は、保管時および通信時の暗号化、アクセス権限の管理、ログの取得・監視、組織単位でのデータ分離その他の技術的・組織的な安全管理措置を講じます。
- 当社は、個人情報を取り扱う従業者に対し、必要かつ適切な監督を行います。
7. 委託
当社は、利用目的の達成に必要な範囲で、個人情報の取扱いの全部または一部を、クラウドインフラ事業者、AI / 大規模言語モデル提供事業者、メール送信事業者等の委託先 (再委託先を含みます) に委託することがあります。この場合、当社は、委託先について必要かつ適切な監督を行います。
8. 第三者提供
当社は、次のいずれかに該当する場合を除き、あらかじめ本人の同意を得ることなく、個人情報を第三者に提供しません。
- 法令に基づく場合。
- 人の生命、身体または財産の保護のために必要があり、本人の同意を得ることが困難な場合。
- 公衆衛生の向上または児童の健全な育成の推進のために特に必要があり、本人の同意を得ることが困難な場合。
- 国の機関もしくは地方公共団体またはその委託を受けた者が法令の定める事務を遂行することに協力する必要があり、本人の同意を得ることにより当該事務の遂行に支障を及ぼすおそれがある場合。
- 合併その他の事由による事業の承継に伴って個人情報が提供される場合。
9. 外国にある第三者への提供 (越境移転)
当社は、本サービスの提供、AI 処理、認証、インフラ運用、サポート、不正利用防止、利用状況分析および品質改善のため、外国にある第三者に個人データを取り扱わせることがあります。この取扱いは、利用目的の達成に必要な委託、ユーザーまたは組織の指示に基づく処理、本人の同意、契約の履行、法令上認められる根拠、または個人を識別できない統計・集計情報の利用として行われます。
当社は、移転先・委託先について、個人情報保護委員会が公表する情報、各事業者が公表するセキュリティ・プライバシー情報、契約条件その他合理的に入手可能な情報を踏まえて確認し、契約、アクセス制御、暗号化、ログ管理、保存期間の管理、再委託先管理その他の方法により、継続的な安全管理措置が講じられるよう努めます。
| 主な移転先・委託先 | 主な国・地域 | 主な目的 | 主な安全管理措置 |
|---|---|---|---|
| OpenAI, L.L.C. およびその関連会社 | アメリカ合衆国その他同社が処理拠点を置く国・地域 | AI による生成処理、不正利用防止、セキュリティ確保 | API 経由の送信、契約・利用条件による利用目的の制限、当社設定に基づく学習利用の制限、通信の暗号化 |
| Anthropic, PBC およびその関連会社 | アメリカ合衆国その他同社が処理拠点を置く国・地域 | AI による生成処理、不正利用防止、セキュリティ確保 | API 経由の送信、契約・利用条件による利用目的の制限、当社設定に基づく学習利用の制限、通信の暗号化 |
| Google LLC、Google Cloud グループ会社 | アメリカ合衆国、日本、EU その他 Google が処理拠点を置く国・地域 | Google 認証、Google Cloud / Vertex AI、表示品質、利用状況分析、関連するセキュリティ処理 | 契約上のデータ処理条件、アクセス制御、暗号化、Google が公表する安全管理措置 |
| Amazon Web Services, Inc.、AWS グループ会社 | 日本を中心とし、アメリカ合衆国、EU その他 AWS がサポート・処理拠点を置く国・地域 | インフラ、データ保管、バックアップ、ログ管理、Amazon Bedrock 等による AI 処理 | リージョン設定、暗号化、アクセス制御、監査ログ、AWS が公表する安全管理措置 |
| メール送信、分析、ヒートマップその他当社が利用する外部事業者 | 日本、アメリカ合衆国、EU その他各事業者が処理拠点を置く国・地域 | サポート連絡、通知、利用状況分析、UX 改善、障害解析 | 必要最小限の送信、アクセス制御、入力内容のマスキング、契約・設定による目的外利用の制限 |
移転先の国・地域、提供サービス、再委託先および安全管理措置は、各事業者のサービス仕様、当社の設定、法令・規制またはセキュリティ上の理由により変更されることがあります。当社は、必要な情報の把握に努め、法令上必要な場合には本人への情報提供または同意取得を行います。ユーザーが第三者の個人情報を本サービスに入力する場合、ユーザーは、その第三者に対する説明、同意取得その他必要な法的根拠を自ら確保するものとします。
10. 組織・プロジェクトにおける個人情報の取扱い
- 本サービスでは、個人利用の場合も、アカウント作成時にユーザー自身をオーナーとするワークスペース (組織) が作成されます。本ポリシーにおける「組織」は、法人等に限らず、この個人用ワークスペースを含む本サービス上の管理単位をいいます。
- プロジェクト、課金、クレジットおよび関連データは、当該組織を単位として管理されます。個人用ワークスペースでは、当該ユーザーが管理者としてプロジェクトデータを管理します。
- 複数メンバーの組織では、組織の管理者が、当該組織配下のプロジェクトおよびメンバーが作成・保存したデータを閲覧・管理・削除できる場合があります。組織のメンバーは、当該取扱いがあり得ることをあらかじめご了承ください。
- ユーザーが組織への参加、招待の承諾、共有機能の利用等を行った場合、当社は、そのために必要な範囲で、アカウントの表示名、メールアドレス、権限情報等を当該組織の管理者または共有相手に表示することがあります。
- 当社の担当者は、サポート、不正利用防止、セキュリティ確保、障害対応または法令遵守のために必要な範囲で、組織およびプロジェクトに関する情報へアクセスする場合があります。この場合、当社は、アクセス権限の管理、記録その他の必要な安全管理措置を講じます。
11. Cookie 等の利用および外部送信
- 本サービスおよび本ウェブサイトでは、ログインセッションの維持、CSRF 対策、利用状況の分析およびユーザー体験の向上のため、Cookie 等の識別子を利用することがあります。
- 当社は、アクセス解析、ヒートマップ、セッションリプレイその他の分析ツールを導入する場合があります。導入にあたっては、パスワード、決済情報、自由入力欄、機密性の高いプロジェクト内容等が意図せず記録されないよう、マスキング、除外設定、保存期間の制限その他の措置を講じるよう努めます。
- 本サービスの生成物、参考 UI、プレビュー、エクスポート結果またはユーザーが取り込んだコンテンツには、第三者が提供するフォント、画像、アイコン、スクリプト、URL その他の外部リソースへの参照が含まれる場合があります。これらの外部リソースの表示・利用に伴う情報送信および当該リソースの利用条件は、各提供者の条件に従います。
- ユーザーは、ブラウザの設定により Cookie の利用を拒否することができますが、その場合、本サービスの一部の機能が利用できなくなることがあります。
| 送信先 | 送信される可能性のある情報 | 利用目的 |
|---|---|---|
| Google LLC (Google Fonts、Google Analytics 等) | IP アドレス、ブラウザ・デバイス情報、閲覧 URL、リファラ、Cookie 等の識別子、イベント情報 | フォント表示、利用状況分析、マーケティング効果測定、品質改善 |
| ヒートマップ・セッション分析事業者 (Microsoft Clarity、Hotjar または同種サービスを導入する場合) | 閲覧 URL、クリック・スクロール・マウス操作、画面サイズ、ブラウザ・デバイス情報、Cookie 等の識別子、マスキング後の画面表示情報 | UX 改善、導線分析、不具合・表示崩れの調査 |
| 外部 AI プロバイダ、クラウド、CDN、画像・フォント等の外部リソース提供者 | AI 処理に必要な入力データ、生成処理ログ、IP アドレス、ブラウザ情報、リソース取得に必要な URL・技術情報 | 本サービスの提供、AI 処理、表示、配信、セキュリティ確保 |
12. 保有個人データの開示・訂正・利用停止等
- ユーザーは、当社に対し、自己の保有個人データについて、利用目的の通知、開示、内容の訂正・追加・削除、利用の停止・消去または第三者提供の停止を請求することができます。
- ご請求は、本サービスのお問い合わせフォームを通じて受け付けます。当社は、所定の方法により本人 (または正当な代理人) であることを確認のうえ、法令に従い、合理的な期間内に対応します。
- 開示等の請求に関する手数料は、当面徴収しません。将来、手数料を定める場合は、法令に従い、本ポリシー等で事前に公表します。
13. 個人情報の保有期間・削除
- 当社は、利用目的の達成に必要な期間、個人情報を保有し、当該目的を達成した後は、法令により保存が義務付けられる場合を除き、遅滞なく消去するよう努めます。
- ユーザーは、本サービス上の操作により、プロジェクトデータの削除およびアカウントの削除を行うことができます。アカウント削除後、当社は、不正利用防止、再登録制御、問い合わせ対応その他の正当な目的のため、メールアドレスおよび外部認証連携情報等の一部を最大90日間保持することがあります。
- アカウント削除に伴い削除された組織、プロジェクト、ページ、保存画像その他のデータは、アカウントを復旧した場合でも復元されないことがあります。
- 本サービスが生成・保管する保存画像、アップロードファイル等は、本サービス上に定める保持期間の経過後に自動的に削除されることがあります。
- 料金の請求、クレジットの管理、不正利用の防止および法令の遵守のために必要なログ・記録は、利用契約の終了後も、必要な範囲で保持することがあります。
14. 未成年者の利用
本サービスは満18歳以上の方を対象としています。当社は、満18歳未満の方から意図的に個人情報を取得しません。
15. 本ポリシーの改定
当社は、法令の改正その他の必要に応じて、本ポリシーを変更することがあります。重要な変更を行う場合は、本サービス上での掲示または登録されたメールアドレスへの通知その他適切な方法によりお知らせします。
16. お問い合わせ
本ポリシーまたは個人情報の取扱いに関するお問い合わせは、お問い合わせフォームまでご連絡ください。
制定・施行日: 2026年6月16日
株式会社meltain
meltain, Inc. recognizes the protection of personal information handled through OwnedAgent as an important responsibility. We handle personal information in accordance with Japan's Act on the Protection of Personal Information and other applicable laws.
This English version is provided for convenience. The Japanese version is the authoritative version and controls if there is any inconsistency.
1. Business Operator
- Operator: meltain, Inc.
- Address: 2F-C Shibuya Dogenzaka Tokyu Building, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
- Representative: Kazuki Tajima
- Phone number and other company information: we will respond without delay when disclosure is requested as required by law. Please also see our company information.
- Personal information contact: the OwnedAgentcontact form.
2. Information We Collect
We collect the following categories of information to provide the Service.
- Account information: display name, email address, profile image, external authentication account ID, OAuth tokens, authentication session information, and related information obtained from external authentication services such as Google. We do not collect or store a password for the Service.
- Organization, workspace, and project information:organization or workspace names created or configured in the Service, including personal workspaces automatically created for individual use, member structure, project names, sharing and permission settings, and usage status.
- User content and AI input data: prompts, images, wireframes, comments, published experience responses, and other data entered or uploaded to the Service.
- Generated output: UI designs, React / TSX code, images, design tokens, persona analysis, and other outputs generated by the Service.
- Contract and usage allowance information: plan, service start and end dates, seats, and credit grant and usage history.
- Usage logs and technical information: IP address, browser and device information, referrer, operation logs, AI processing logs, and identifiers such as cookies.
- Beta information: participation status, usage status, voluntarily provided survey and interview responses, bug reports, requests, suggestions, other feedback, and communications with us.
- Inquiry information: name, company name, email address, topic, and message content submitted through contact forms or support channels.
3. How We Collect Information
We collect information through user input, automatic records generated by use of the Service, and external authentication integrations.
4. Purposes Of Use
- To provide, maintain, authenticate, and manage accounts and organizations.
- To execute generation and processing through AI Features.
- To manage service contracts, invoicing, and credits.
- To improve quality, develop features, analyze and fix defects.
- To operate beta, test, and other pre-release features or environments, manage participants, understand usage, analyze voluntarily provided feedback, improve quality, and prepare for general availability.
- To detect and prevent abuse, unauthorized access, and security issues.
- To provide support and respond to inquiries.
- To notify users about important service, terms, and policy changes.
- To analyze usage and create statistics in a form that does not identify individuals.
- To provide information about the Service or related services where appropriate.
5. AI Feature Processing
Data submitted for AI Features may be sent through APIs to external AI providers such as OpenAI, Anthropic, Google, Google Cloud Vertex AI, Amazon Bedrock, and other providers we use. Processing may occur outside Japan depending on provider specifications and our settings. Under the API terms of those providers, submitted input and generated output are not used to train or improve their models. We also do not use user input or generated output to train or develop our own AI models.
6. Security Measures
We store personal information and user content in cloud environments centered on Amazon Web Services in Japan, including the Tokyo region, with encryption. AI processing, authentication, email delivery, and external integrations may be handled in countries or regions where our processors or providers operate. We use encryption in storage and transit, access controls, logging, monitoring, organization-level data separation, and other technical and organizational measures.
7. Entrustment
We may entrust processing of personal information to cloud infrastructure providers, AI and LLM providers, email providers, and other contractors or subcontractors as necessary to achieve the purposes of use. We supervise these processors as required.
8. Third-Party Provision
Except where permitted by law, we do not provide personal information to third parties without prior consent. Exceptions include legal requirements, protection of life, body, or property, public health or child welfare, cooperation with public authorities, and business succession such as mergers.
9. Cross-Border Transfers
To provide the Service, perform AI processing, authenticate users, operate infrastructure, provide support, prevent abuse, analyze usage, and improve quality, we may have personal data handled by parties outside Japan. This handling may be conducted as entrusted processing necessary for the purposes of use, processing based on the user's or organization's instructions, consent, performance of a contract, another basis permitted by law, or use of statistical or aggregated information that does not identify individuals.
We review transfer destinations and processors using information published by privacy regulators, security and privacy information published by providers, contractual terms, and other reasonably available information. We seek to maintain ongoing safeguards through contracts, access controls, encryption, logging, retention controls, subprocessor management, and other measures.
| Main recipient / processor | Main countries and regions | Main purposes | Main safeguards |
|---|---|---|---|
| OpenAI, L.L.C. and affiliates | United States and other countries or regions where OpenAI processes data | AI generation, abuse prevention, and security | API transmission, contractual and service-use limits, training-use controls based on our settings, and encryption in transit |
| Anthropic, PBC and affiliates | United States and other countries or regions where Anthropic processes data | AI generation, abuse prevention, and security | API transmission, contractual and service-use limits, training-use controls based on our settings, and encryption in transit |
| Google LLC and Google Cloud group companies | United States, Japan, EU, and other countries or regions where Google processes data | Google authentication, Google Cloud / Vertex AI, display quality, analytics, and security-related processing | Contractual data processing terms, access controls, encryption, and safeguards published by Google |
| Amazon Web Services, Inc. and AWS group companies | Primarily Japan, and the United States, EU, and other countries or regions where AWS provides support or processing | Infrastructure, storage, backups, logging, and AI processing such as Amazon Bedrock | Region settings, encryption, access controls, audit logs, and safeguards published by AWS |
| Email, analytics, heatmap, and other external providers we use | Japan, United States, EU, and other countries or regions where each provider processes data | Support communications, notices, usage analytics, UX improvement, and issue investigation | Data minimization, access controls, masking of inputs, and contractual or settings-based restrictions on secondary use |
Destination countries, services, subcontractors, and safeguards may change due to provider specifications, our settings, legal or regulatory requirements, or security reasons. We seek to maintain necessary information and will provide information or obtain consent where required by law. If users enter personal information about third parties into the Service, users are responsible for providing notices, obtaining consent, or securing any other lawful basis required for that information.
10. Organizations And Project Data
In the Service, an individual user also receives a workspace (organization) owned by that user when an account is created. "Organization" in this policy means the Service-level management unit, including this personal workspace, and is not limited to legal entities. Projects, billing, credits, and related data are managed by organization. In multi-member organizations, administrators may be able to view, manage, or delete data created by projects and members under that organization. If a user joins an organization, accepts an invitation, or uses sharing features, the user's display name, email address, permission information, and related account information may be shown to organization administrators or sharing recipients as necessary. Our staff may access organization and project information only as necessary for support, abuse prevention, security, incident response, or legal compliance.
11. Cookies And External Transmission
We may use cookies and similar identifiers to maintain login sessions, protect against CSRF, analyze usage, and improve the user experience. We may introduce analytics, heatmap, session replay, or similar analysis tools. When doing so, we seek to use masking, exclusions, retention limits, and other measures so that passwords, payment information, free text fields, highly confidential project content, and similar data are not unintentionally recorded.
| Recipient | Information that may be transmitted | Purpose |
|---|---|---|
| Google LLC (Google Fonts, Google Analytics, etc.) | IP address, browser and device information, viewed URLs, referrer, cookie identifiers, and event information | Font display, usage analytics, marketing measurement, and quality improvement |
| Heatmap or session analysis providers, such as Microsoft Clarity, Hotjar, or similar services if introduced | Viewed URLs, clicks, scrolls, mouse movement, screen size, browser and device information, cookie identifiers, and masked screen display information | UX improvement, funnel analysis, and investigation of defects or display issues |
| External AI providers, cloud providers, CDNs, and external resource providers for images, fonts, and similar resources | Input data necessary for AI processing, generation processing logs, IP address, browser information, and URLs or technical information needed to obtain resources | Providing the Service, AI processing, display, delivery, and security |
12. Disclosure, Correction, And Suspension Of Use
Users may request notification of purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision for retained personal data. Requests are accepted through the contact form. We will verify identity and respond within a reasonable period in accordance with law. We do not currently charge a fee for these requests. If we set a fee in the future, we will publish it in advance in accordance with applicable law.
13. Retention And Deletion
We retain personal information for the period necessary to achieve the purposes of use and delete it without delay after those purposes are achieved, except where retention is required by law. After account deletion, certain information such as email address and external authentication identifiers may be retained for up to 90 days for abuse prevention, re-registration control, inquiry handling, or other legitimate purposes.
14. Minors
The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from users under 18.
15. Changes To This Policy
We may update this policy due to changes in law or other needs. Important changes will be announced through the Service, by email, or by other appropriate means.
16. Contact
Questions about this policy or our handling of personal information should be sent through the contact form.
Effective date: June 16, 2026
meltain, Inc.