Notice: This is a reference translation provided for convenience. The Japanese version is the authoritative text. In case of any discrepancy between this translation and the Japanese version, the Japanese version shall prevail.
Chapter 1. General Provisions
Article 1 (Purpose)
VorEdge Inc. (the “Company”) establishes this Privacy Policy (this “Policy”) in compliance with the Act on the Protection of Personal Information (the “APPI”) and other applicable laws and regulations, in order to appropriately handle the personal information of users in connection with the service “BotShade” (the “Service”) provided by the Company.
Article 2 (Definitions)
Unless otherwise defined, terms used in this Policy shall have the meanings ascribed to them in the Terms of Service of the Service. Terms such as “personal information,” “personal data,” “retained personal data,” and “sensitive personal information” used in this Policy shall have the meanings ascribed to them under the APPI.
Article 3 (Scope of Application)
- This Policy applies to the handling of personal information obtained by the Company through the Service.
- As provided in Chapter 14, Article 6 of the Terms of Service, the Service is, in principle, provided to individuals residing in Japan or corporations having their principal offices in Japan. With respect to use by residents outside Japan, the Company does not warrant that it has complied with all additional protection requirements imposed by the personal information protection laws of such country or region (including the EU General Data Protection Regulation, the UK Data Protection Act, the California Consumer Privacy Act of the United States, the Personal Information Protection Law of the People’s Republic of China, and other laws).
Article 1 (Personal Information Handling Business Operator)
- Corporate Name: VorEdge Inc.
- Address: Nishi-Shinjuku Mizuma Bldg. 2F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
- Representative: Shun Watanabe
Article 2 (Personal Information Protection Manager)
The Company appoints a personal information protection manager to ensure the appropriate handling of personal information. Inquiries should be directed to the contact in Chapter 16 of this Policy.
Article 1 (Information Directly Provided by Users)
The Company collects the following information from Users in the contexts of user registration, inquiries, subscription to Paid Plans, and the like.
- Email address
- Authentication information (public key information and credential identifier for WebAuthn / FIDO2 passkey authentication, identifiers obtained from social login providers, and the like. The Company does not collect or store User passwords)
- Discord account information (username, user ID, avatar image, server membership information, and the like)
- Information provided at the time of inquiries (name, email address, content of inquiry, and the like)
- Configuration information created and registered by the User within the Service (Bot settings, commands, response templates, distribution messages, and the like)
- Prompts, contextual information, reference materials, and the like that Users input to BotShader (the AI feature) (“AI Input Data”)
Article 2 (Information Automatically Collected)
The Company automatically collects the following information in connection with the use of the Service.
- IP address, browser information, device information, OS information, referrer
- Access logs, operation logs, error logs
- Identifiers, session information, and the like obtained through Cookies and similar technologies
- Bot operation logs in the Service (Bot responses on Discord, command execution history, and the like)
Article 3 (Information Obtained from Third Parties)
The Company may obtain personal information from third parties in the following cases.
- Discord account information provided through Discord OAuth or the like
- Payment processing results provided by the payment service provider (Stripe). The Company does not obtain credit card numbers themselves.
Article 4 (Non-Collection of Sensitive Personal Information)
The Company does not intend to obtain sensitive personal information (such as race, creed, social status, medical history, criminal record, history of being a crime victim, or other personal information requiring special care) in providing the Service. Users are requested not to include sensitive personal information in the input fields of the Service, inquiries, AI Input Data, or otherwise.
Chapter 4. Methods of Collection
As provided in Chapter 14, Article 6 of the Terms of Service, the Company provides the Service, in principle, to Users in Japan, and the handling of personal information under this Policy is conducted in accordance with the APPI. The Company collects personal information by one of the following methods.
- Direct provision by Users through registration, input, upload, and the like to the Service
- Automatic collection through Cookies and other automatic collection technologies
- Provision from third-party services (Discord, Stripe, and the like) based on User consent
Chapter 5. Purpose of Use
The Company uses the collected personal information within the scope of the following purposes.
- For the provision, operation, maintenance, and improvement of the Service
- For user registration, identity verification, authentication, and access management to the Service
- For response generation and processing based on input in BotShader (the AI feature)
- For billing of fees and other consideration and payment processing
- For responding to User inquiries, requests, and support requests
- For communicating about maintenance, important notices, notices of revisions to the terms, and the like related to the Service
- For providing information about new features, updates, and related services of the Service (including the Company’s advertising and promotional emails)
- For detection, investigation, and response to violations of the Terms of Service or unauthorized use
- For the creation of statistical data (after processing into a form from which individual users cannot be identified) and use thereof for improvement of the Service or development of new services
- For responses to laws and regulations, court orders, or requests from administrative agencies
- For purposes incidental to the foregoing
Users may stop receiving advertising and promotional emails through settings within the Service, the inquiry contact, or procedures within the distributed emails.
Chapter 6. Provision to Third Parties
Article 1 (Restriction on Provision to Third Parties)
The Company shall not provide personal information to third parties without obtaining the prior consent of Users, except in the following cases.
- Where required by laws and regulations
- Where necessary for the protection of human life, body, or property, and obtaining the consent of the person is difficult
- Where particularly necessary for improving public health or promoting the sound development of children, and obtaining the consent of the person is difficult
- Where it is necessary to cooperate with a national or local government agency or a person entrusted by such agency in carrying out matters prescribed by laws, and obtaining the consent of the person may impede the performance of such matters
- Where personal data is provided in connection with the Company’s business succession (merger, corporate division, business transfer, and the like)
Article 2 (Provision to Outsourcing Parties)
The Company may outsource all or part of the handling of personal data to outsourcing parties within the scope necessary for achieving the purpose of use. Provision to outsourcing parties does not constitute provision to third parties under the APPI. For details of outsourcing parties, please refer to Chapter 7 and Chapter 8.
Chapter 7. Outsourcing Parties
Article 1 (List of Outsourcing Parties)
The Company outsources the handling of personal data to the following entities for the provision of the Service.
| Outsourcing Party | Main Outsourced Business | Location |
|---|
| Stripe, Inc. | Payment processing, invoice issuance | United States / Ireland |
| Cloudflare, Inc. | Content delivery, DDoS protection, edge processing, DNS | United States |
| Vercel Inc. | Hosting of dashboard and website | United States |
| Sentry (Functional Software, Inc.) | Error monitoring, failure detection | United States |
| Resend, Inc. | Transactional email delivery | United States |
| DeepInfra, Inc. | Inference processing for the AI feature (BotShader) (open-source models such as DeepSeek) | United States |
| OpenAI, L.L.C. | Inference processing for the AI feature (BotShader) (GPT series, etc.) | United States |
| Anthropic, PBC | Inference processing for the AI feature (BotShader) (Claude series, etc.) | United States |
| Google LLC | Access analytics (Google Analytics, and the like) | United States |
| Uptime Robot Service Provider Ltd. | Uptime monitoring of the Service | United States |
| Discord, Inc. | Bot operation through the Discord platform and acquisition / integration of Discord account information | United States |
| Xserver Inc. | Server infrastructure for application operation | Japan |
| Contabo GmbH | Server infrastructure for application operation | Germany |
Discord, Inc. is the operator of the Discord platform that forms the basis of the Service, and has the nature of both an outsourcing party and an integration platform inseparable from the Service. For the handling of data on Discord, please also refer to Discord’s privacy policy.
Outsourcing parties may change as necessary for the operation of the Service. In the event of material changes, we will notify you through revisions to this Policy.
Article 2 (Supervision of Outsourcing Parties)
The Company shall, by contract or other appropriate means, exercise necessary and appropriate supervision of outsourcing parties to ensure the safe management of personal data.
Article 3 (Regarding Technical Infrastructure)
The Company operates its database infrastructure on the server infrastructure listed in the table in Article 1 of this Chapter (Xserver Inc. and Contabo GmbH), under the Company’s management. No personal data of Users is provided to the operating entities of the database infrastructure.
Chapter 8. Provision of Personal Data to Third Parties Located in Foreign Countries
Article 1 (Consent to Cross-Border Transfers)
As stated in Chapter 7, the Company’s outsourcing parties include entities located in foreign countries. By using the Service and agreeing to this Policy, Users consent to the Company’s provision of personal data to third parties located in the following countries.
Article 2 (Countries of Destination and Personal Information Protection Systems Therein)
| Destination Country | Information on the Country’s Personal Information Protection System |
|---|
| United States | The United States does not have a comprehensive federal law generally regulating personal information protection. Sector-specific federal laws (such as those covering healthcare and finance) and state laws (such as California’s CCPA / CPRA) coexist. For details, please refer to the Survey on Personal Information Protection Systems in Foreign Countries published by the Personal Information Protection Commission. |
| Germany (EU) | Germany is subject to comprehensive regulation regarding the handling of personal data under the EU General Data Protection Regulation (GDPR) and its domestic data protection legislation. The EU has entered into a mutual adequacy framework with Japan, ensuring a level of protection equivalent to that of Japan. |
| Ireland (EU) | As with Germany, protection is provided in accordance with the EU General Data Protection Regulation (GDPR). |
Article 3 (Ensuring Compliant Frameworks)
In providing personal data to third parties located in foreign countries, the Company requires such third parties to implement measures equivalent to the safety management measures based on the APPI and other applicable laws, through contracts and the like.
Chapter 9. Handling of Personal Data in BotShader (AI Feature)
Article 1 (Overview of BotShader)
“BotShader” is an AI assistant feature, including AI chat functionality, provided within the Service. When a User uses BotShader, the prompts, contextual information, reference materials, and the like voluntarily input by the User (“AI Input Data”) are sent to a third-party AI provider designated by the Company.
Article 2 (AI Providers and Their Locations)
The Company outsources the inference processing of BotShader to the following AI providers. AI Input Data is processed on the infrastructure of each provider, all located in the United States.
| AI Provider | Main Models Provided | Location |
|---|
| DeepInfra, Inc. | Open-source models such as DeepSeek | United States |
| OpenAI, L.L.C. | GPT series, etc. | United States |
| Anthropic, PBC | Claude series, etc. | United States |
Article 3 (AI Models Used)
On each AI provider’s infrastructure, multiple AI models are used depending on the purpose. These models include those developed by entities whose developers are located outside Japan (such as in the United States or the People’s Republic of China). As a specific example, on DeepInfra we use open source models developed by DeepSeek (DeepSeek Inc., People’s Republic of China); on OpenAI we use models such as the GPT series; and on Anthropic we use models such as the Claude series.
However, all of these models are executed on each AI provider’s infrastructure located in the United States, and User AI Input Data is not sent to the country where the model developer is located, such as the People’s Republic of China.
The AI models used, and the allocation among them, may change from time to time based on improvements to the Service, the availability of models, and the balance of performance and cost.
Article 4 (Scope of Use of AI Input Data)
- The Company and each AI provider shall not use AI Input Data beyond the scope necessary for the processing requested by the User (such as response generation).
- The Company and each AI provider shall not use AI Input Data as training data for any AI model of the Company or any third party. The Company selects, as AI providers, entities that publicly commit to a policy of not using API inputs for training.
- Conversation history that a User has on BotShader is stored on the Company’s servers for the purpose of allowing the User to refer to, search, and delete it again. Users may delete their own conversation history through operations on the dashboard.
- Each AI provider does not use inference data for training purposes or store it for a long period. However, providers may temporarily retain processing data as a short-term cache or short-term retention for the purpose of optimizing inference performance (such as fast response to identical or similar requests) or for anti-abuse purposes (such as short-term retention for Trust & Safety).
Article 5 (User Responsibility)
Users are requested not to include the following information in AI Input Data.
- Personal information of third parties, confidential information, intellectual property rights, or other information that may affect the rights or interests of third parties
- Sensitive personal information
- Information whose handling is restricted by law
If a User includes any of the foregoing information in AI Input Data, the responsibility for the handling of such information shall be borne by the User, and the Company shall not be liable for any resulting damages (except in cases of willful misconduct or gross negligence by the Company).
Chapter 10. Retention Period and Deletion of Personal Data
Article 1 (Retention Period)
The Company retains personal data only for the period necessary to achieve the purpose of use. Approximate retention periods for specific items are as follows.
- Account information (email address, authentication information, Discord integration information, and the like): During the period the User uses the Service
- User Content such as Bot settings, commands, and response templates: During the period the User uses the Service
- Conversation history of BotShader: During the period the User uses the Service (deletable by the User)
- Access and request logs accumulated on Vercel: Up to 30 days from acquisition
- Operation logs, error logs, and the like accumulated on the Company’s operational servers: In principle, up to 12 months from acquisition
- Payment-related information: After the completion of the transaction, for the period prescribed by tax law and other applicable laws
Article 2 (Deletion after Withdrawal)
When a User withdraws from the Service, the Company shall delete the User’s account and User Content 24 hours after the date of withdrawal, in accordance with Article 3 of Chapter 4 of the Terms of Service. The foregoing shall not apply to information whose retention is required by law, information necessary for handling disputes, or information remaining in backups.
Chapter 11. Safety Management Measures
The Company shall take necessary and appropriate measures for the safety management of personal data, including prevention of leakage, loss, or damage. An overview of specific measures is as follows.
- Organizational safety management measures: Establishment of a manager responsible for the handling of personal data; establishment of systems for inspection and audit of the handling of personal data
- Personnel safety management measures: Training of officers and employees regarding the handling of personal data; thorough enforcement of confidentiality obligations
- Physical safety management measures: Management of areas where personal data is handled; prevention of theft or loss of equipment, electronic media, documents, and the like
- Technical safety management measures: Access control for personal data; adoption of passwordless authentication using WebAuthn / FIDO2 passkeys; encryption during communication and storage; prevention of unauthorized access; response to vulnerabilities; acquisition and monitoring of logs
- Understanding of external environment: Understanding the personal information protection systems of foreign countries when handling personal data therein, and implementing necessary measures
For more detailed inquiries regarding the specific content of safety management measures, please contact the inquiry contact in Chapter 16.
Chapter 12. Cookies and Similar Technologies
Article 1 (Use of Cookies)
The Service may use Cookies and similar technologies for the purpose of enhancing user convenience, maintaining authentication, analyzing usage, improving the Service, and the like.
Article 2 (Use of Access Analytics Tools)
The Company uses the following access analytics tools to understand the usage of the Service and to improve the Service.
- Google Analytics: An access analytics service provided by Google. This tool uses Cookies to analyze user behavior, and during such use, IP addresses and the like are collected. At the time of transmission from the Company, such information is, on its own, information that does not allow identification of any specific individual (information that may fall under “personal-related information” under the APPI). However, depending on the manner of handling by Google, such information may be obtained by Google as personal data. The Company shall take measures necessary in accordance with applicable laws in using this tool. For information on how data is collected and processed, please refer to Google’s Privacy Policy and the Google Analytics Terms of Service. To disable analysis by Google Analytics, please use the Google Analytics Opt-out Browser Add-on.
Article 3 (Use of Error Monitoring Tools)
The Company uses the error monitoring service provided by Sentry for failure detection and quality improvement of the Service. Through this tool, access information at the time of error occurrence, browser / OS information, the URL where the error occurred, and the like are automatically sent to Sentry’s servers.
Article 4 (Disabling Cookies)
Users may disable Cookies by changing the settings of their web browsers. However, if Cookies are disabled, some features of the Service (such as maintaining login state) may not be available.
Article 1 (Right to Request Disclosure, etc.)
- Users may, based on the APPI, request notification of the purpose of use, disclosure (including disclosure of records of third-party provision), correction, addition, deletion, suspension of use, and suspension of third-party provision (collectively, “Disclosure, etc.”) of their own personal data held by the Company.
- Users may, at any time, withdraw consent that they have provided to the Company under this Policy or through a separate procedure. Withdrawal of consent takes effect only prospectively and does not affect the lawfulness of any handling of personal data carried out before the withdrawal.
Article 2 (Method of Request)
- Requests for Disclosure, etc. should be made to the inquiry contact in Chapter 16. The Company shall, after confirming that the requester is the person in question, respond promptly in accordance with the APPI and other applicable laws.
- When making a request for disclosure, Users may specify the method of disclosure (delivery of a written document, provision in electronic record format, etc.). The Company shall, except where excessive costs would be incurred or where there are other reasonable grounds, disclose the information by the specified method.
- The Company shall respond to requests for Disclosure, etc. in principle within 30 days from the date of receipt of the request. Where the content of the request is complex or where there are other reasonable grounds, the response period may be extended, and in such cases, the User shall be notified of the extension and the reason therefor.
Article 3 (Fees)
Fees for requests for Disclosure, etc. shall be free of charge.
Article 4 (Non-Response to Requests)
The Company may refuse all or part of a request for Disclosure, etc. in any of the following cases. In such cases, the Company shall notify the requester of the fact and the reason promptly.
- Where there is a risk of harming the life, body, property, or other rights or interests of the person or a third party
- Where there is a risk of significantly impeding the proper conduct of the Company’s business
- Where it would violate laws and regulations
Article 1 (Use by Minors)
As provided in Article 5 of Chapter 2 of the Terms of Service, the Service is not intended for use by persons under the age of 13. Minors aged 13 or older but under 18 shall obtain the prior consent of their legal representative (such as a parent or guardian) before using the Service and providing personal information.
Article 2 (When Collection of Personal Information from a Minor Is Discovered)
If the Company discovers that it has collected personal information from a User under the age of 13, the Company shall promptly take measures to delete such personal information.
Chapter 15. Changes to the Privacy Policy
Article 1 (Minor Changes)
The Company may give effect to changes that benefit Users or that are minor (including correction of typographical errors, clarification of expressions, changes of names due to organizational changes, and additions or changes to outsourcing parties) by giving notice within the Service or on the website.
Article 2 (Material Changes)
- Where the Company makes changes that may have a material impact on the rights or interests of Users, such as items of information collected, purposes of use, provision to third parties, or provision to third parties located in foreign countries (“Material Changes”), the Company shall notify Users of the content of the changes and the effective date at least 30 days before the effective date, by means within the Service, to the registered email address, on the website, or by other appropriate means.
- For changes that require explicit consent from the User under applicable laws (such as changes that exceed the scope reasonably related to the original purpose of use, new third-party provisions, or new provisions to third parties located in foreign countries), the Company shall obtain explicit consent from such User by the effective date, and the changes shall not apply to Users who do not consent.
- For Material Changes not falling under the preceding Paragraph, the Company shall obtain explicit consent from Users as necessary.
Article 3 (Disagreement with Changes)
If a User does not agree to the content of a Material Change, the User may suspend the use of the Service and withdraw by the effective date. A User who continues to use the Service after the effective date shall be deemed to have agreed to the Material Change. However, changes that require explicit consent under Paragraph 2 of the preceding Article shall not apply to Users who do not consent.
Article 1 (Inquiry Contact)
Inquiries, requests for Disclosure, etc., opinions, and complaints regarding this Policy or the handling of personal information should be directed to the following contact.
Article 2 (Complaints to the Personal Information Protection Commission)
Users may also lodge complaints with the Personal Information Protection Commission regarding the Company’s handling of personal information. For details, please refer to the website of the Personal Information Protection Commission (https://www.ppc.go.jp/).