Last Updated: January 01, 2025
Version: 1.0.0
1. Handling of Personal Information
Ronride Co., Ltd. (the "Company") provides Ronwrite (the "Service"). The Company considers the protection of users' personal information to be an important responsibility. This Privacy Policy explains how the Service collects, uses, and protects personal information.
2. Personal Information Collected
The Service may collect the following personal information:
- Email address, name, nickname
- Profile image
- Academic discipline, PhD status
- School name, grade, class name, student ID (when using organization features)
- Device information (user_agent, device, browser, OS)
- Learning progress data, course completion status
- User-generated content (responses to courses, created texts, learning content, etc.)
- Organization membership information
- When using Google Calendar integration: the connected Google account email address, OAuth access and refresh tokens, and identifiers and confirmation links for calendar events created by the Service
Ronwrite Advocate
When individuals contacted by us as Advocates register via a dedicated link, we may collect: email addresses used for invitation and contact, name, title, affiliation, introduction, website URL, optional profile image, self-declaration of educator status (university faculty or high school teacher), and technical information related to the registration process.
Usage data (usage logs)
For service improvement, enhancing the learning experience, fraud prevention, effectiveness measurement, and academic research, the Service may collect the following usage information. For how such information is handled (purposes of use, provision, storage, and the like), see this section and the later sections of this Policy.
- Date and time of use, session information (start and end, duration of use, number of sessions, and the like)
- Technical information about the device, browser, and OS used (user_agent, device category, and the like)
- Screens viewed, feature usage, and screen transitions (transition information based on screen identifiers and route keys; query strings and the like are generally not included)
- Use of UI elements to which the Service has explicitly assigned operation identifiers on the Service (operation logs; the content of free-text entered in the operation target is not included)
- Time spent on screen, URL at session end, and other usage information
- Use of feedback features (time spent viewing feedback, whether edits were made after feedback, and the like)
- Feedback and evaluations submitted by users on the Service (for providing and improving learning)
Information not included in usage data (usage logs)
- The content of text or answers entered by users is not recorded in research usage logs (submission and storage of learning content is handled separately under "user-generated content" and similar items above)
- Operation logs do not comprehensively record every UI operation for which the Service has not assigned an operation identifier
Regardless of whether you participate in research, decline participation, or withdraw consent to research participation, the Service may collect usage data of the kinds described above to the extent necessary for service operation. For details on handling when you consent to academic research participation, see the Privacy Policy that applies after login.
3. Purpose of Use of Personal Information
The Service uses collected personal information for the following purposes:
- Providing, operating, and improving the service
- User authentication and account management
- Recording and displaying learning progress
- Providing organization features (viewing learning data by organization administrators)
- Responding to inquiries
- Statistical analysis and effectiveness measurement for service improvement
- Fraud prevention and security maintenance
- Sending important notifications
- Analyzing user experience and improving the service (including analysis using anonymized and aggregated usage data)
- Publishing information on the Ronwrite Advocate page and related communications
- Sending invitation and registration emails to Advocates
- Granting launch benefits (free access to all features for educators) and preventing abuse
- Handling requests to remove or correct Advocate listings (including replies to emails we sent)
- Providing Google Calendar integration (adding study schedules to the user's own Google Calendar and displaying connection status)
3-2. Publication on the Ronwrite Advocate Page
Published items: name, title, affiliation, introduction, website URL, and optional profile image.
Not published: contact email addresses, invitation email addresses (if different from published content), and internal educator-benefit management data.
Publication is on the public internet. To request removal or correction, reply to the email we sent regarding Advocate registration.
4. Handling of Learning Data
The Service records and stores users' learning progress data. This data may be used for service improvement and statistical analysis purposes. Learning data may be anonymized and used for statistical and research purposes.
Users have the right to request deletion of their learning data. If you wish to delete your data, please contact us through the inquiry form.
Data Retention Period:The Service stores learning data as long as the account is active. When an account is deleted, related learning data is also deleted. However, anonymized statistical data may continue to be stored for service improvement purposes.
5. Disclosure of Personal Information to Third Parties
The Service will not disclose users' personal information to third parties except in the following cases:
- When the user has consented
- When required by law
- When necessary to protect human life, body, or property
- When using organization features, organization administrators may view learning data
5-2. Use of External Services
The Service uses the following external services, and personal information may be provided to these service providers:
- Social Login Services:When authentication is performed through Google, LINE, GitHub, or Apple ID, authentication information is sent to each service provider. Please refer to each service provider's website for their privacy policies.
- Cloud Storage Services:Files such as profile images may be stored in cloud storage services such as AWS S3.
- Payment Services:For paid plans, we may use Stripe or similar providers; payment data is processed by them and we do not store full card numbers.
- Generative AI Services:When using AI learning features, input necessary for those features may be sent to external AI providers (the OpenAI API). We do not share that content with OpenAI for model training or improvement. Under OpenAI’s API defaults, submitted content is not used to train models. Prompts and responses may nonetheless be retained by OpenAI for up to 30 days for abuse monitoring (or longer if required by law).
- Google Calendar API:If you choose to connect, we send the event title and start/end times to Google to create a study event. See Section 5-3 (Google user data) for details.
These external service providers process personal information in accordance with their respective privacy policies. The Service is not responsible for the handling of personal information by these external service providers.
5-3. Google User Data (Google Calendar Integration)
The Service may connect to Google Calendar only when you explicitly choose to do so. Connection is optional. If you do not connect, the Service does not access Google Calendar user data.
Limited Use. The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Ronwrite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer raw, aggregated, or derived Google Calendar user data to third-party services for creating, training, or improving foundational or generalized AI/ML models. Learning-support AI features (OpenAI API) do not receive Google Calendar user data.
Data accessed
- The Google account email address (to display connection status)
- Permission needed to add study events to calendars you own (scope:
https://www.googleapis.com/auth/calendar.events.owned). We do not use calendar.events (view and edit events on all calendars, including shared calendars), calendar.events.readonly (cannot create events), or calendar.app.created (for secondary calendars created by the app, not the user's primary calendar).
The Service does not list or read your existing calendar events, and does not access calendar content other than study events you ask Ronwrite to create. Events are created only when you instruct the Service to add them.
Purposes of use
- To add study schedules you created in Ronwrite as events on your own Google Calendar
- To display connection status and to prompt reconnection when needed
We do not use Google user data for advertising, profiling, credit decisions, or selling or lending it to third parties outside the Service. We use it only to provide and improve user-facing features. We do not send Google user data to third-party AI services (including OpenAI) and do not use it to train AI models.
Data stored
- OAuth access tokens and refresh tokens (stored only on the server; they are not returned in API responses or sent to the browser)
- Token expiry and the connected Google account email address
- Identifiers of events created by the Service and confirmation links on Google Calendar
Sharing
- To create a study event, we send the event title and start/end times to Google (Google Calendar API)
- We do not send Google Calendar user data (raw, aggregated, or derived) to OpenAI or any other third-party AI/ML service
- We do not sell or lend Google user data to third parties, including advertising providers
- We do not disclose Google user data to third parties except as required by law or with your consent
- Organization administrators cannot access Google Calendar tokens or the calendar events themselves
Your controls and deletion
- You may disconnect Google Calendar in the Service at any time. When you disconnect, we delete the tokens and connection information we store
- Deleting a study schedule in Ronwrite does not delete the event already added to Google Calendar. You can delete that event in Google Calendar
- When your account is deleted, we also delete the Google connection information we hold for that account
6. Security Management of Personal Information (Data Protection Mechanisms for Sensitive Data)
The Service implements the following data protection mechanisms to prevent leakage, loss, damage, and unauthorized access to personal information and sensitive data, including Google user data.
- Encryption in transit: Communications between the Service and users, and between the Service and external services such as Google APIs, are encrypted with HTTPS (TLS).
- Encryption and protection at rest: Personal information and OAuth tokens are stored in an access-controlled cloud environment (AWS, including Amazon RDS in the Tokyo region). Databases are operated with encryption and network isolation.
- Access control: Access to Google user data and authentication tokens is limited to server-side processing of the user's own actions and to the minimum operations staff needed for the business. Tokens are not sent to the client (browser) and are not written to logs.
- Least privilege: Google Calendar integration requests only the scope needed to add study events on calendars you own (
calendar.events.owned). We do not list existing events.
- Logging: Access logs are recorded and managed to detect unauthorized access.
- Retention: OAuth tokens and connection information are kept only while connected and are deleted upon disconnection or account deletion. Learning data is stored while the account is active and deleted when the account is deleted (except anonymized statistical data).
Retention of usage logs (guideline)
- Operational usage logs are generally retained for two (2) years from collection, then deleted or anonymized (research data for consenting users is handled under the post-login Privacy Policy).
7. Cookies and Tracking Technologies
The Service may use cookies and other tracking technologies for the purposes of providing, improving, and analyzing the service. The Service may also use tracking to analyze usage (the information collected is as described in Section 2 under usage data (usage logs) and device information stated in that section). Users can refuse to accept cookies through browser settings, but some service features may become unavailable in such cases.
9. Disclosure, Correction, and Deletion of Personal Information
Users have the right to request disclosure, correction, or deletion of their personal information held by the Service. Signed-in users can download their data and delete their account at Data and privacy. If you cannot sign in, please contact us through the inquiry form.
For rights of users in the EEA, the United Kingdom, or California, see Section 9-2 (GDPR and CCPA/CPRA).
9-2. GDPR and CCPA/CPRA
The primary governing law of the Service is Japanese law, including the Act on the Protection of Personal Information. To the extent applicable, we also comply with the EU General Data Protection Regulation (GDPR) and UK GDPR for users in the European Economic Area (EEA) or the United Kingdom, and with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) for California residents.
Legal bases (GDPR)
- Performance of a contract: providing the account, learning features, and study-schedule management
- Consent: participation in academic research, Google Calendar connection (via Google's consent screen), and optional analytics cookies (if used)
- Legitimate interests: security, fraud prevention, and operational improvement of the Service (we do not use personal information for profiling advertising)
- Compliance with legal obligations
International transfers
- Personal data is stored primarily in Japan (AWS Tokyo region).
- For learning support, text you create in the Service may be sent to the OpenAI API (processed primarily in the United States). We do not share that text for model training; under OpenAI’s API defaults it is not used to train models. It may be retained by OpenAI for up to 30 days for abuse monitoring. Google Calendar user data (raw, aggregated, or derived) is not sent to OpenAI or any other third-party AI/ML service.
- When you connect Google Calendar, we send data to Google only as needed to create the study events you request.
California resident rights (CCPA/CPRA)
Where applicable, you have the right to know, delete, and correct personal information, the right to opt out of the sale or sharing of personal information (including for cross-context behavioral advertising), and the right not to be discriminated against for exercising these rights.
We do not sell or share personal information. We do not sell personal information for monetary consideration, and we do not “share” it for cross-context behavioral advertising.
How to exercise your rights and response times
- While signed in: Data and privacy (download your data and delete your account)
- Requests by email or similar: after identity verification, we will respond within one (1) month under the GDPR, and within forty-five (45) days under the CCPA/CPRA, unless an extension permitted by law applies.
- If you have an active subscription, cancel it before deleting your account. Staff accounts cannot be deleted through this self-service.
- You can disconnect Google Calendar in the app. You can also remove Ronwrite's access in your Google Account permissions.
Cookies
Cookies used to keep you signed in and to protect security are necessary to provide the Service. If we use optional analytics cookies, we will ask for consent; refusing them will not prevent you from using essential features such as signing in.
10. Changes to Privacy Policy
The Service may change this Privacy Policy as necessary. The revised Privacy Policy will take effect when posted on the Service. For material changes, including changes to how we use Google user data, we will notify users by posting on the Service or by email or similar means.
Revision history
- September 2, 2026: Added GDPR and CCPA/CPRA rights, legal bases, international transfers, and a do-not-sell-or-share statement
11. Inquiries
For Advocate listing removal or correction and educator launch benefits, please reply to the email we sent regarding Advocate registration. We will respond within a reasonable scope.
For other inquiries, please use inquiry channels we separately provide (e.g., organization inquiry forms).
Personal Information Manager: Ronride Co., Ltd.