Privacy Policy
2026-09-24
This Privacy Policy explains how personal information is handled in eunoos, a service that copies calendar availability according to synchronization rules configured by the user.
1. Operator, scope and contact
Information about the operator is available at https://uniquex.co.jp/about. Inquiries and requests concerning personal information are accepted at privacy@eunoos.com.
eunoos is currently provided to residents of Japan. It is not offered to residents of the EEA or the United Kingdom.
2. Information we collect
We collect or process the following information in connection with the service:
- Account and authentication information, including display name (provided by Google or Microsoft at signup, or entered by you), email address, Google or Microsoft account identifier, account creation time, session information and information temporarily required for OAuth authentication.
- Connected-account information, including account and calendar identifiers, display names, time zones, OAuth access and refresh tokens, and token expiry times.
- Synchronization settings, including source and destination calendars, privacy mode, title template, filters, synchronization period, processing status and copy mappings.
- Calendar event information required for synchronization, including start and end times, availability, recurrence and status. Depending on the privacy mode and event, this may also include the title, description, location and attendee email addresses.
- For a collection calendar, eunoos stores the complete event representation received from each connected source, including the content listed above, for up to 365 days of its synchronization window. This allows a different privacy choice to be applied when sending the event to each connected destination.
- Usage and security information, including synchronization time and result, internal identifiers, error information that excludes event bodies, request metadata and other records required for stable and secure operation.
- Access and effectiveness measurement information, consisting only of the UTC day or week, a pre-approved landing-page variant, source, campaign, event type, call-to-action placement and aggregate request count. The marketing database does not store IP addresses, User-Agent strings, referrers, full URLs, search terms, cookies or device identifiers, user identifiers, advertising click identifiers, Google account information or calendar information. During authentication, the approved categories are associated with a random OAuth state for no more than 10 minutes; no per-person event history is retained.
- Product-usage aggregate information, consisting only of the UTC day, an event type (setup consent, whether the setup converted, a zero-reflection outcome) and a first-sync duration bracket, each as aggregate counts. These aggregates are derived from synchronization outcomes as counts only, retain no per-person correspondence and store no calendar contents or identifiers.
- Inquiry information, including the sender’s email address, name, message, attachments and delivery information.
3. Purposes of use
We use the information described above for the following purposes:
- To register and authenticate users and manage sessions and connected accounts.
- To read and write calendar information and perform, retry and manage synchronization according to settings selected by the user.
- To provide account, connection and data deletion functions.
- To maintain, protect and improve the reliability of the service; investigate failures; prevent unauthorized use; and enforce these Terms of Service.
- To measure aggregate requests to landing-page variants and aggregate starts and completions of the sign-in flow by approved source and campaign, and to evaluate and improve advertising content, service explanations and the path to starting the service. We do not use this information for per-person profiling, retargeting or personalized advertising.
- To measure, as aggregate counts only, how long the first synchronization takes after consent and how often a completed setup results in zero reflected copies, and to evaluate and improve the setup experience. This information is not used for per-person profiling or advertising.
- To respond to inquiries and requests concerning personal information and to keep records necessary for those responses.
- To comply with laws and regulations and protect the rights and safety of users, third parties and the operator.
4. Google API data
eunoos accesses Google identity information for sign-in and Google Calendar information only after the user authorizes the requested scopes. Google Calendar information is used only to perform the synchronization rules configured by the user and related service functions.
eunoos’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information received from Google APIs is not sold, used for advertising, or used to train or improve generalized machine-learning or artificial-intelligence models.
Google account identifiers, email addresses, ID-token contents, OAuth tokens and Google Calendar information are not used for advertising or acquisition measurement and are not joined to campaign information. Product-usage aggregates derived from synchronization outcomes contain counts only, retain no per-person correspondence, are never joined to campaign information and are not provided to an advertising or analytics provider. An OAuth completion is recorded only as an aggregate count of successful eunoos sign-in processing and is not provided to an advertising or analytics provider.
5. Service providers and third-party disclosure
The operator uses Cloudflare, Inc. for hosting, content delivery, database, queue, security-log, server-side access-aggregation, email-routing and AI-gateway functions, Google LLC for sign-in, Google Calendar integration and receipt of routed inquiry emails, Microsoft Corporation for sign-in and Microsoft 365 calendar integration, and OpenAI, L.L.C. for generating the draft of a scheduling request from the text the user enters in that consultation.
For the OpenAI draft, only the text the user entered in that consultation and the operator’s instructions (including proposed values and calendar references) are sent through Cloudflare AI Gateway. Calendar contents, information about other participants and account identifiers are not sent. The gateway keeps a log of each request and response, including the text sent, for up to six months so that the operator can investigate failures, after which the log is deleted. OpenAI processes this information under its API data-usage terms and does not use it to train its models. Each service provider receives only the information necessary for the relevant function and is subject to appropriate oversight as required by applicable law.
When a user configures a destination calendar, eunoos writes the selected information to that calendar at the user’s direction. The information is then also handled under the account permissions and terms applicable to that destination.
Except for outsourcing, user-directed processing, business succession, or another case permitted by law, we do not disclose personal data to a third party without the individual’s prior consent. We do not sell personal data or provide it to data brokers, advertising networks or analytics providers.
6. Processing outside Japan
Cloudflare, Google, Microsoft and OpenAI operate infrastructure and use group companies and subprocessors in multiple countries. Personal data may therefore be processed outside Japan when we use their services.
The operator confirms the relevant data-protection systems and provider safeguards and exercises necessary and appropriate oversight in accordance with the Act on the Protection of Personal Information. Information the operator can provide concerning overseas processing is available upon request at the contact address above.
7. Retention and deletion
We retain personal information only for as long as necessary for the purposes stated in this Policy. Account information is retained until account deletion, and connection information, OAuth tokens, synchronization settings and active copy mappings are retained while the relevant connection is active.
Provider event records are removed after the connection is deleted and are also periodically reduced by retention controls. Deleted events created directly in the eunoos internal calendar and records used to prevent recreation of a deleted copy are retained for 30 days so that deletion can be undone, and synchronization and failed-job records for 90 days. Sessions expire within 30 days and after 14 days of inactivity; temporary OAuth information expires after 10 minutes.
Active events stored in a collection calendar are retained while that collection calendar and its relevant connection remain active. Deleting the collection calendar hides it immediately and starts removal of its connections and provider-side copies; encrypted records needed to complete asynchronous cleanup may remain until that cleanup and the applicable retention period finish.
Daily aggregate access and effectiveness counts and daily product-usage aggregates are retained for 90 days, and weekly access aggregates generated from the former for 13 months. The approved landing-page and campaign categories associated with an OAuth state expire after no more than 10 minutes and are deleted when the state is consumed or by subsequent scheduled cleanup. Aggregate counts have no per-person correspondence and therefore cannot be searched or deleted for an individual user.
Inquiry correspondence is ordinarily retained for no more than three years after the last exchange. Information may remain temporarily in backup or recovery history until it is overwritten under the provider’s retention cycle. We may retain information for a longer period when required by law or reasonably necessary to resolve a dispute or security incident.
8. Cookies and similar technologies
eunoos uses only cookies necessary for authentication, session maintenance and protection of OAuth flows. We do not use cookies, localStorage, fingerprinting, browser beacons or third-party advertising or analytics tags for access and effectiveness measurement. Measurement uses ordinary requests to fixed eunoos URLs and server-side aggregate counting; it does not cause the user’s device to send measurement data to an advertising or analytics provider. If necessary cookies are disabled, sign-in and calendar connection may not function.
9. Security measures
The operator takes necessary and appropriate organizational and technical measures, including access control, separation of user data, encryption of OAuth tokens and event bodies at rest, hashing of session tokens, management of encryption keys as server-side secrets, and controls intended to prevent sensitive content from being included in logs.
If a personal data incident occurs, we investigate and contain it and report to the Personal Information Protection Commission and notify affected individuals when required by law.
10. User requests
Users may disconnect a calendar or delete their eunoos account from the service. Disconnecting stops synchronization and starts deletion of the relevant tokens, metadata, stored provider events, managed-copy records, settings, and copies created in destination calendars. Some remote copies may remain if deletion fails at the provider.
Requests for notification of purpose, disclosure of retained personal data or third-party provision records, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or other rights available under applicable law may be submitted to privacy@eunoos.com. We may verify the requester’s identity and may decline all or part of a request where permitted by law, in which case we will explain the reason as required.
11. Changes to this Policy
The operator may revise this Policy in response to changes in the service or applicable law. The revised Policy and its effective date will be posted and, when required by law or appropriate in light of the change, advance notice will be provided or consent obtained.