最終更新日 / Last updated: 2026年8月15日 (August 15, 2026)
freeCareer LMS(以下「本サービス」)は、ユーザーの個人情報を適切に保護し、 安全・安心なサービスを提供することを基本方針としています。
freeCareer LMS (the "Service") is an online learning management system that protects user personal information and provides a safe learning environment.
本サービスは以下の情報を収集します:
We collect: name and email address, learning logs and assignment submissions, Google OAuth access / refresh tokens for Google Calendar integration, and the Google Calendar event IDs that correspond to booked meetings.
本サービスは Google Calendar API を利用して以下の機能を提供します:
取得した Google Calendar データは面談の予約管理にのみ使用し、 第三者への提供やマーケティング目的での利用は一切行いません。
The Service uses the calendar.events scope solely to create and delete the calendar events that represent booked coaching meetings, and the calendar.freebusy scope solely to read busy / free time ranges of a coach so that students can pick an open slot. No event titles, descriptions, locations, or attendees are read or stored. Google user data is never sold, never shared with third parties, and never used for advertising.
本サービスは、Google Calendar から取得したセンシティブデータおよび OAuth トークンを保護するため、以下のメカニズムを実装しています:
All data is encrypted in transit with TLS 1.2+. OAuth access and refresh tokens are encrypted with AES-256-GCM at the application layer before being written to our database, which additionally runs on managed infrastructure with encryption at rest; encryption keys are stored as server-side environment variables, separately from the database. Freebusy responses are never persisted, and for calendar events we store only the event ID of events the Service itself created — never their content. Access is restricted by row level security plus server-side authorization checks; the service role key that can bypass RLS is available only on the server and is never shipped to the browser. Google user data is not read by humans except with the user's explicit consent, for security purposes, or as required by law.
OAuth tokens are retained only while the Google Calendar integration is connected. When a user disconnects the integration from the settings page, the Service calls Google's token revocation endpoint and immediately deletes the stored access and refresh tokens. Freebusy data is never stored. Calendar event IDs are retained only for the lifetime of the corresponding meeting record and are deleted when the meeting is cancelled. If a user requests account deletion, all Google user data — including OAuth tokens and calendar event IDs — is deleted from our database and backups within 30 days. Users may request deletion at any time by contacting soumu@unari.co.jp, and may revoke the Service's access at any time at https://myaccount.google.com/permissions.
本サービスによる Google API から受け取った情報の使用および他アプリへの転送は、Google API サービスのユーザーデータに関するポリシー(限定的な使用に関する要件を含む)に準拠します。
具体的には、Google Calendar から取得したデータについて以下を遵守します:
英文(原文): This application's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
本サービスは、法令に基づく場合を除き、ユーザーの同意なく個人情報を第三者に提供しません。 Google ユーザーデータを第三者に販売・譲渡することはありません。
We do not disclose personal information to third parties without user consent, except as required by law. Google user data is never sold or transferred to third parties.
本プライバシーポリシー、データの開示・削除に関するご質問は、以下までご連絡ください。