Monoshiri

Privacy Policy

Privacy Policy

Monoshiri (operated by Makoto Kobayashi; the “Operator”) establishes this Privacy Policy regarding the handling of information in “Monoshiri Memo” (the “App”) — a Markdown editor for iPhone, iPad, Mac, Windows and the web — together with the servers the Operator runs for it (collectively, the “Service”). The Japanese text is the original; this page is a reference translation, and the Japanese version governs if the two differ.

Summary

There are three places your notes can live, and we only hold the third.

  • Your own Google Drive — we never receive the contents of your files.
  • A folder on your device (macOS / Windows) — nothing leaves your machine; no request reaches us at all.
  • Team collaboration — your documents are stored on servers we operate. This is the one case where we hold your content.

If you use only Google Drive or a local folder, sections 4 onward do not apply to you: nothing has changed. Team features become active only when you create a team or accept an invitation to one.

1. The Operator and how to reach us

  • Operator: Monoshiri (Makoto Kobayashi)
  • Address: [Address]
  • Person responsible for personal data: [Data protection contact]
  • Contact: [Contact email]
  • Representative in the EU / EEA (GDPR Article 27): [EU representative]

2. When you save to Google Drive

  • Google account information — At sign-in we obtain your email address, display name, profile picture URL and Google Drive user identifier (permissionId), for the purpose of showing the connected account and identifying you within a team.
  • Files on Google Drive — The permission the App requests is drive.file (a limited scope). The App reads and writes only files it created, or files you explicitly select. It never browses or lists your entire Google Drive.
  • Authentication tokens — In the desktop and mobile apps, the refresh token is stored only on your device and never sent to our servers. In the web version it is encrypted and kept in an httpOnly browser cookie; it is not stored on our servers, though it passes through them each time it is refreshed.
  • External access for link previews — When a document contains an external URL, the App fetches publicly available metadata from it to render a preview. In the apps this request comes from your device; in the web version our server makes it on your behalf, so that URL passes through us. We do not store what is retrieved.

The contents of files stored in Google Drive are never sent to our servers. Reading and writing happens directly between your device (or browser) and Google.

3. When you save to a folder on your device (macOS / Windows)

The App reads and writes inside the folder you pick. No request reaches our servers in this mode, and we receive nothing. On macOS, a security-scoped bookmark to that folder is stored on your device so it can be reopened next launch; it never leaves the machine.

4. When you use team collaboration

With team features, we store your documents on servers we operate. This is the most significant difference from the other two modes.

4.1 What we hold

  • Document contents — the text of documents created in a team space, the edit history used for real-time collaboration, and folder/document names and ordering. Edits are sent to the server as you type.
  • Attachments and images — the files themselves that you paste or attach to a document.
  • Account information — your email address, display name (both the one from the linked provider and any you set yourself), profile picture (a provider URL, or an image you upload), linked sign-in methods (currently Google only: the provider’s user identifier and the email address, name and picture it returns), and creation / last-seen timestamps.
  • Team and permission data — team name, members and their roles (owner / admin / member / guest), invitation records (the invited address, who invited, expiry, acceptance), allowed domains and email addresses, and per-document sharing settings.
  • Access logs — as a property of the hosting platform (Cloudflare), request timestamps, IP addresses and user agents are logged for a limited period. We use them to investigate faults and prevent abuse, and for nothing else.

4.2 Why we hold it

To provide collaboration, sharing and search; to decide who may read and write what; to answer your enquiries and investigate faults; to bill for paid plans and contact you about them; and to act on abuse or breaches of the Terms. Not for advertising, and not for behavioural analytics.

4.3 What other members of your team can see

  • Your display name and profile picture — shown in sharing lists, as the last editor, and on your cursor while editing.
  • Your cursor position — anyone with the same document open can see, at all times, where in the document you are looking and typing.
  • Your email address — visible to team owners and admins, and in the sharing list of documents shared with you individually.

You can change your display name at any time from your profile page.

4.4 Invitations

A team administrator can create an invitation link by entering the invitee’s email address. That address is recorded on our servers at that point — entered by the administrator, not obtained by us from anywhere else. The address is not embedded in the invitation URL. Invitations expire after 14 days. We do not currently send invitation emails; administrators pass the link on themselves.

4.5 Relationship to Google Drive

Using team features never moves documents from your Google Drive or your local folder onto our servers. Only documents created inside a team space are held by us.

5. Paid plans and payments

Teams are free for up to five people. From the sixth person onward the price is JPY 300 per person per month [confirm: tax treatment — the pricing page states tax-included]. Contracts are entered into on the web (app.monoshiri.jp) only; we do not use in-app purchases.

Payments are handled by Stripe.

  • Card numbers never pass through our servers. Card details are entered on Stripe’s own pages (Stripe Checkout and the customer portal). We neither receive nor store them.
  • What we send to Stripe: your team name, the billing contact’s email address, the team identifier, and the number of billable seats.
  • What we receive from Stripe: a customer ID, a subscription ID, and the subscription status (active, past due, canceled).
  • Stripe’s own handling is governed by the Stripe Privacy Policy.

6. Where data is stored, and transfers abroad

Data held for team features is stored on Cloudflare, Inc. services: documents and edit history in Durable Objects, account / team / permission metadata in D1, and attachments and images in R2.

The country or region in which it is stored is left to Cloudflare and is not specified by us. It may be stored and processed outside Japan, including in the United States and Europe. Payment data likewise goes to Stripe (United States and Japan), and Google account data to Google (United States and elsewhere).

For users in Japan, this constitutes provision of personal data to a third party in a foreign country under Article 28 of the Act on the Protection of Personal Information; the recipients are Cloudflare, Inc. (US), Stripe, Inc. (US) and Google LLC (US). Information about those countries’ data protection regimes is published by Japan’s Personal Information Protection Commission. Each recipient applies protective measures under its published data processing agreement and standard contractual clauses.

[To confirm with counsel] the data processing agreements with Cloudflare and Stripe, and whether they satisfy the “equivalent standards” test in Article 16 of the enforcement rules. The wording of this section depends on that conclusion.

7. Sharing with third parties

  • We never sell personal data.
  • We do not provide personal data to third parties without your consent, except where required by law (including lawful requests from courts or the police).
  • The companies named in section 6 are processors engaged to provide the Service, and are supervised accordingly.

8. Retention, deletion and leaving

What you can do in the App today: documents and folders you delete go to a trash state (hidden from view, but retained); you can delete your profile picture; and you can unlink a sign-in method, except the last one, which would lock you out.

There is currently no self-service way to delete your account, disband a team, or export everything at once. Write to [Contact email] and we will act on it after verifying your identity.

  • Deleting your account — we delete your account information (email address, display name, profile picture, linked sign-in methods) and your membership records. Documents you wrote in a team space remain with that team, because its other members are still using them. Tell us if you want those removed too.
  • Disbanding a team — we delete that team’s documents, attachments and membership records, and cancel any paid subscription.
  • Exporting — we export the team’s documents as Markdown files and send them to you.

[Decide] the deadline for responding to such requests (for example, within 30 days) and how long deleted data persists in backups.

Team data is retained for as long as the team exists. Invitation records remain after their 14-day expiry. Access logs are retained for the period set by the hosting platform.

9. Your rights

You may request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, or suspension of provision to third parties of your retained personal data (Articles 32–35 of Japan’s Act on the Protection of Personal Information). If you are in the EU / EEA or the UK, you have the rights of access, rectification, erasure, restriction, data portability and objection under the GDPR, and the right to lodge a complaint with a supervisory authority. Write to [Contact email]; we act without undue delay once we have verified your identity, and charge no fee.

10. How we protect it

  • All communication is encrypted (HTTPS / WSS).
  • Only people granted permission in a team can read its documents; changing or revoking a role also invalidates sessions that are already connected.
  • An attachment can only be opened by someone who can read a document that references it, through a URL that expires after five minutes.
  • Refresh tokens are stored only on your device, or in an encrypted httpOnly cookie.
  • Servers run on Cloudflare; the country in which data is stored is determined by Cloudflare, not by us.

11. What we do not do

  • No behavioural analytics, tracking or advertising. There are no third-party analytics or advertising tags in the App or on this site.
  • We do not sell or otherwise provide your personal data to third parties.
  • We do not use the contents of your documents for anything other than providing the Service — and never to train machine learning or AI models.

12. Children

[Decide] whether a minimum age applies to the Service, consistent with COPPA (under 13), the GDPR (under 16, reducible to 13 by member state) and the App Store age rating. The current Terms set no age requirement.

13. Changes

The Operator may revise this Policy as necessary. For significant changes we will give notice in the App or by email in addition to posting here. The revised Policy takes effect when it is posted on this page.

14. Contact

For inquiries regarding this Policy or the handling of personal data, write to [Contact email], or use the contact form.

Last updated: September 8, 2026