Privacy Policy
Last updated:
This policy explains how ToMoshiMoshi handles information when you visit the website, create an account, find a business, or ask our AI assistant to make a telephone call to Japan.
1. Who is responsible
ToMoshiMoshi is operated by an individual who is responsible for processing personal data under the trading name ToMoshiMoshi. For privacy questions or requests, contact contact@tomoshimoshi.com. You can request the operator's legal name and address at the same email address; this information will be provided without delay. No account is required to request these details.
2. Information we process and why
Account information includes your account identifier, email address, verification status, and the name or profile image provided by your sign-in provider. We use it to authenticate you, protect your account, associate your activity with you, and send service emails. Auth0 manages authentication; the application does not receive your Google password.
Your saved profile may include given names, surnames, preferred name, age, sex, nationality, and interface language. Call requests include the destination number, business selection, objective, context, instructions, approvals, and replies you provide. We process these details to carry out the request and show its result. Provide only relevant information and obtain permission before submitting someone else's personal data.
Call records include timestamps, status, duration, transcripts, translations, summaries, and any associated credit or payment records. Technical information such as IP address, browser information, errors, and security logs is processed to deliver, secure, and troubleshoot the service. We also process the messages you send to support.
3. Google sign-in
Google sign-in requests only email and basic profile permissions. We use the identity information to create or identify your account and display your profile. We do not request access to Gmail messages, Drive files, calendars, or contacts through sign-in.
We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Access and sharing are limited to providing and securing the features you request, support, and applicable legal obligations. Google account data is not automatically included in telephone conversations; saved profile details are included only when you authorize profile sharing for that call. Information you write into a call request may be used in the call.
4. Calls, AI, and sensitive information
Live call audio is transmitted through the telephone provider and processed by OpenAI to conduct the conversation and generate text. The application stores transcripts, translations, and results in your account; it does not provide an archive of audio recordings. Providers may retain technical or service data under their own terms and configuration.
The assistant is instructed to identify itself as AI and ask the recipient for permission to continue. You choose whether to include saved profile details in each call, and can answer questions or stop a call. Information necessary for your request may be spoken to the recipient. Do not submit passwords, payment-card security codes, government ID documents, or unnecessary medical or other sensitive details. This is not a confidential medical consultation service.
5. Service providers and international processing
We use Auth0 (Okta) for accounts and security; Google for optional sign-in and Maps/Places; Vercel and Railway for hosting; Neon for database storage; Telnyx for telephone calls; OpenAI for conversation, transcription, and translation; and SendGrid (Twilio) for service emails. Stripe processes real payments for prepaid credit, handles payment authentication, and helps prevent fraud. Only information needed for the relevant function is sent to each provider; not every provider receives every category of data.
For example, the call recipient receives what the assistant says, OpenAI processes call content and any authorized profile context, and SendGrid receives the email address and content of service messages. These providers operate infrastructure outside Japan, including in the United States, so information may be processed in countries with different privacy laws. Contact us for further information about the providers and safeguards relevant to your data.
We may disclose information when required by law or necessary to address fraud, security incidents, or legal claims. We do not sell personal information or provide it to advertisers for targeted advertising.
6. Payments and Stripe
Payment details are entered directly on Stripe’s hosted Checkout. Stripe may process your name, email, billing details, payment-method information, IP address and device or fraud-prevention signals under its own privacy policy (https://stripe.com/privacy). ToMoshiMoshi does not receive or store complete card numbers or card security codes.
We send Stripe internal account, purchase and package identifiers, the selected price and return URLs to associate payment with your wallet. We retain transaction identifiers, amounts, currency, status, credit ledger records, and refund/dispute information for fulfillment, support, accounting and fraud prevention. Call transcripts and saved profile details are not included in payment metadata.
7. Cookies, browser storage, and location
We use authentication and security cookies and a language-preference cookie. A short-lived call draft may be stored in browser session storage when changing languages. Blocking essential cookies may prevent sign-in. The application does not currently include advertising trackers.
Maps and business search send search inputs and map interactions to Google. If you choose nearby search and allow the browser's location request, location is used to center the search. You can instead enter an area manually and revoke location permission in your browser. Saved businesses are associated with your account using their place identifiers.
8. Retention and security
Account, profile, and call history remain stored to provide your account and history until you request deletion or we remove them. There is currently no automatic expiry for call history. Records needed for accounting, fraud prevention, disputes, or legal obligations may need to be retained after account closure; backup and provider copies may follow different retention cycles. We assess deletion requests individually and explain any necessary exceptions.
Access controls, authenticated connections, and encrypted transport help protect information. No system is completely secure. Report suspected unauthorized access to contact@tomoshimoshi.com. Avoid sending sensitive call content in a support message when a call identifier will suffice.
9. Your choices and requests
You can edit your profile and remove saved businesses in the application. To request access, correction, a copy, deletion, account closure, or restrictions on use or sharing where applicable, email contact@tomoshimoshi.com from your account address. We may request proportionate identity verification and will respond in accordance with applicable law. Account and call-history deletion currently require a support request rather than an automatic button.
You can revoke Google access through your Google Account's third-party connections settings. Revocation prevents future authorized access but does not itself delete existing ToMoshiMoshi records. You may also contact the competent privacy authority, including Japan's Personal Information Protection Commission, about a concern.
10. Age and changes
The service is intended for adults aged 18 or older. If you believe a child has provided personal information, contact us. We may update this policy as the service changes; the revision date appears above. We will provide notice and request any consent required before materially changing how information is used.