本文へスキップ
Geo Index

Privacy Policy

Last updated: 2026-10-07 Version: 2026-09-29

This English text is provided for reference. If there is any inconsistency between the English and Japanese texts, the Japanese text prevails.

Unbowed Inc. (in formation) ("we," "us," or "our") handles personal information in Geo Index (the "Service") appropriately and in compliance with the Act on the Protection of Personal Information of Japan (APPI) and other applicable laws and guidelines. This Privacy Policy (this "Policy") sets out how we do so. This English version is provided for reference only; if there is any inconsistency between the English and Japanese versions, the Japanese version prevails.

Business Operator

Name: Unbowed Inc. (in formation)

Address: N&E BLD. 6F, 1-12-4 Ginza, Chuo-ku, Tokyo 104-0061, Japan

Representative: Disclosed without delay, within 48 hours of your request.

Contact for privacy inquiries: support@geoindex.app

Unbowed Inc. is in formation (incorporation planned for November 2026). Until its incorporation is registered, its founder is responsible for operating the Service. Upon incorporation, Unbowed Inc. will succeed to the rights and obligations relating to the Service.

Until the incorporation is registered, the founder handles personal information in the Service in accordance with this Policy, and references to "we," "us," or "our" in this Policy include the founder during that period. When Unbowed Inc. succeeds to the business of the Service upon incorporation, the personal information will be transferred together with the business and will continue to be handled within the purposes of use set out in this Policy.

Personal Information We Collect

We collect the following personal information in providing the Service. We do not obtain personal information by deception or other improper means.

  • Account information: name, email address, profile image, company name, and the organizations and workspaces you belong to and your roles in them. Sign-in is provided through Auth0, our authentication provider, and we do not collect or store passwords. If you sign in with a Google account (through Auth0), we receive your name, email address, profile image, and Google account identifier from Google.
  • Payment information (for paid plans): billing details, subscribed plan, and payment history. Credit card information is collected and processed by our payment processor, Stripe; we do not store card numbers or other card data.
  • Usage logs: IP address, browser type (User-Agent), referrer, activity history, access timestamps, and other information generated through your use of the Service.
  • Access records for AI-optimized pages we serve: visitors' IP address, User-Agent, requested domain and path, and timestamp. We record these mainly to measure whether AI crawlers reach those pages.
  • Information we receive when you connect Google Search Console (on a paid plan, when a user consents): the email address and identifier of the connected Google account, tokens issued by Google, and aggregated Search Console values. See "Data Accessed Through Your Google Account" below for details.
  • Information obtained through cookies and similar technologies (as described under "Cookies and Similar Technologies" and "External Transmission of User Information" below).
  • Information you provide when contacting us (such as your name, email address, and the content of your inquiry).

Purposes of Use

We use the personal information we collect to provide the Service, verify identity and authenticate users, process payments, respond to inquiries, improve the Service and analyze usage, measure the effectiveness of advertising and promotion, prevent misuse, and comply with law. The purposes are set out in detail under "Purposes of Use in Detail" at the end of this Policy.

When the Service performs analyses (such as citation analysis and content optimization), it sends data to AI providers (OpenAI, Anthropic, and Google). What we send consists of items such as analysis prompts and the public content of the target pages; the Service is designed so that account information and other customer personal information are not included. However, anything you enter in input fields such as prompts is sent as entered, so please do not enter personal information in those fields.

Data read from Search Console is not sent to AI providers (see "Data Accessed Through Your Google Account" below).

Security Measures for Personal Data

We take the following measures to prevent the leakage, loss, or damage of personal data.

  • Basic policy: We have adopted this Policy and handle personal information in compliance with applicable laws and guidelines.
  • Organizational measures: We have appointed a Personal Information Protection Manager with clear responsibility for handling personal information, and we maintain procedures for reporting and responding to actual or suspected data breaches.
  • Personnel measures: We require everyone who handles personal data to keep it confidential and handle it properly.
  • Physical measures: Personal data is managed on cloud services, and physical security of the facilities relies on the controls of each cloud provider.
  • Technical measures: We use authentication through Auth0, access controls by organization and workspace, row-level access restrictions in our database, encryption in transit (HTTPS), and logging and monitoring of security events. Before information is sent to our error-monitoring service (Sentry), email addresses, IP addresses, cookies, and similar data are removed.
  • Understanding of the external environment: We handle personal data in Japan and the United States. Our database that stores account information (Supabase) and our backend infrastructure (Google Cloud) are located in a region in Japan (Tokyo). We take our security measures with an understanding of the U.S. personal information protection regime described under "Transfers to Third Parties in Foreign Countries" below.

Retention Periods for Retained Personal Data

We retain personal data only for as long as needed to achieve the purposes of use, except where the law requires us to retain it for longer.

We retain account information while your account is active and, after the account is deleted, delete it or process it so that individuals can no longer be identified without delay. However, records of measures and their results are not deleted, so that they cannot be altered afterward; instead, fields that may contain personal information are masked. Payment, accounting, and tax information is retained until the retention period required by law has passed.

We have set the following retention periods for logs, and records older than these periods are deleted. At present, records past their retention period are detected and counted daily, and automatic deletion is being extended to each log type in stages.

Other logs and records of inquiries are retained for periods we set according to their type and are deleted after those periods expire.

  • Access records for AI-optimized pages we serve (IP address, User-Agent, etc.): 400 days
  • Security logs (IP address, User-Agent, records of input screening, etc.): 365 days
  • Records of sign-ins made on a user's behalf for support (email addresses of the administrator and the user, IP address, etc.): 730 days

Provision to Third Parties

We do not provide personal data to third parties without your prior consent, except in the following cases.

  • Where required by law
  • Where necessary to protect a person's life, body, or property and it is difficult to obtain your consent
  • Where especially necessary to improve public health or promote the sound development of children and it is difficult to obtain your consent
  • Where necessary to cooperate with a national or local government body, or a party entrusted by one, in performing duties prescribed by law, and obtaining your consent would likely impede the performance of those duties
  • Where we entrust the handling of personal data to a service provider to the extent necessary to achieve the purposes of use
  • Where personal data is provided in connection with the succession of a business through a merger, company split, business transfer, or otherwise

Entrustment of Personal Data Handling

We may entrust all or part of the handling of personal data to service providers to the extent necessary to achieve the purposes of use. We choose providers that handle personal data appropriately, set the terms of entrustment by contract or terms of service, and supervise them as necessary and appropriate.

Our main service providers and the work entrusted to them are as follows.

  • Auth0: sign-in (authentication), including sign-in with a Google account, which goes through Auth0
  • Stripe: payments and billing
  • Supabase: database
  • Google Cloud: backend infrastructure
  • Vercel: website delivery and usage analytics
  • Cloudflare: delivery of AI-optimized pages and retrieval of pages for analysis
  • Sentry: error monitoring (only information from which personal information has been removed is sent)
  • Langfuse: logging of AI calls (designed not to include customer personal information)
  • AI providers (OpenAI, Anthropic, and Google): analyses such as citation analysis (designed not to include customer personal information)

Transfers to Third Parties in Foreign Countries

To provide the Service, we entrust the handling of personal data to, or provide personal data to, businesses located in the United States. By agreeing to this Policy when you register, you consent to the following cross-border transfers.

Destination country: United States of America

Recipients and main personal data transferred: Auth0 (authentication: name, email address, profile image, account identifier); Stripe (payments: billing and payment information); Vercel and Cloudflare (delivery: access information such as IP address and User-Agent); Google (Google Analytics: access information such as cookie identifiers and browsing history)

U.S. personal information protection regime: The United States has no comprehensive federal law on the protection of personal information. The handling of personal information is governed by sector-specific federal laws such as the Federal Trade Commission Act and by state laws such as the California Consumer Privacy Act (CCPA). For details, see the survey of foreign personal information protection systems published by Japan's Personal Information Protection Commission.

Measures taken by recipients: Each recipient sets out measures to protect personal information in its data processing terms (DPA) and privacy policy.

OpenAI, Anthropic, Google (Gemini API), Langfuse, and Sentry are also located in, or process information in, the United States, but the Service is designed so that the information sent to them does not include customer personal information.

External Transmission of User Information

On the Service's websites, programs provided by the following businesses cause information to be sent from your device to those businesses. We publish the recipients, the information sent, and the purposes of use as required by the Telecommunications Business Act of Japan. Before anything is sent, we remove email addresses, sharing tokens, payment session IDs, URLs being analyzed, prompts, and similar values from page URLs.

  • Google LLC (Google Analytics, including its link with Google Ads): URL and title of pages viewed, referrer, cookie identifiers, IP address, device and browser information, types of actions such as sign-up and purchase, and advertising source and click identifiers. Purposes: usage analytics and measuring advertising effectiveness.
  • Vercel Inc. (Vercel Web Analytics and Speed Insights): URL of pages viewed, referrer, device and browser information, page performance measurements, and types of actions. Purposes: usage analytics and improving page performance.
  • Functional Software, Inc. (Sentry): error details and where they occurred, browser information, and performance measurements. Email addresses, IP addresses, cookies, and similar data are removed before sending. Purpose: detecting and fixing defects.

Data Accessed Through Your Google Account (Google Search Console)

In workspaces on a paid plan, and only when a user consents with their own Google account, we read Google Search Console data with that user's permissions. Connecting is optional; all other features of the Service work without it.

Permissions requested: confirming your Google account identifier and email address (openid, email), and viewing Search Console data (webmasters.readonly). We do not request permission to change Search Console settings.

Data we read: From Search Console, impressions and clicks by date (aggregated values) and the list of properties you can view. We do not read data at the level of individual people.

Data we store: the aggregated values above, the name of the property you select, the email address and identifier of the connected Google account, the scope of the permissions granted, and the refresh token issued by Google. The refresh token is stored encrypted, and access tokens are not stored. The list of properties is used only to show the selection screen and is not stored in our database.

Purpose: We use the data only to show it on the screens of the connected workspace and to compare the periods before and after the initiatives that workspace records. We do not use it to compare with or aggregate across other customers, to improve the Service, or for advertising.

AI providers: We do not send the data to AI providers (OpenAI, Anthropic, or Google).

Third parties: We do not provide or sell the data to third parties. The data is stored in the database and backend infrastructure that our service providers listed above (Supabase and Google Cloud) operate in Japan. Where required by law, we will respond in accordance with law.

Access by our staff: Our staff view the data only when needed for support with your consent, for security, or to comply with law.

Disconnecting and deletion: In the workspace settings, you can disconnect each property and also remove each Google account with "Disconnect". A Google account that is not attached to any property can be removed the same way. When you remove a Google account, or disconnect every property that uses it, we delete the stored refresh token. If no connection in any other workspace uses the same Google account, we also send Google a request to revoke the access. Aggregated values already read are kept after you disconnect so that the record of before-and-after comparisons remains intact. When the account of an organization's owner is deleted, the refresh tokens and the email addresses and identifiers of Google accounts stored for that organization's connections are also deleted. To have the aggregated values deleted, please contact us at the address below.

Revoking at Google: You can revoke the access you granted to the Service at any time from your Google Account settings (see https://support.google.com/accounts/answer/13533235 ). After you revoke it, reading stops and the screen shows that reconnection is needed.

Moving to the Free Plan: In a workspace that moves from a paid plan to the Free Plan, we stop reading data. Stored data and the refresh token are kept, and reading resumes when the workspace returns to a paid plan. You can still disconnect while on the Free Plan.

Limited Use: Geo Index's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. The policy is available at https://developers.google.com/terms/api-services-user-data-policy .

Your Requests Concerning Retained Personal Data (Disclosure, Correction, Suspension of Use, etc.)

You may request notification of the purposes of use, disclosure, correction, addition, or deletion of content, suspension of use or erasure, and cessation of provision to third parties of the retained personal data we hold about you. We will respond in accordance with law after confirming that the requester is you or your duly authorized agent.

Please send Requests by email to support@geoindex.app. You can also delete your account yourself from the settings screen after signing in.

When an account is deleted, we delete the related data we manage or process it so that individuals can no longer be identified. Information stored with our authentication provider (Auth0) and payment processor (Stripe) is deleted separately under our procedures (except information we are required by law to retain).

The procedures are described in detail under "Procedures for Requests Concerning Retained Personal Data" at the end of this Policy.

Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, make the Service easier to use, analyze usage, and measure advertising effectiveness. We use Google Analytics for analytics and advertising measurement, and Google collects usage information through cookies. Google's handling of that information is described in Google's policy (https://policies.google.com/technologies/partner-sites).

You can stop measurement by Google Analytics with the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout). You can change settings for the ads you see in Google's ad settings (https://adssettings.google.com/).

You can also refuse cookies in your browser settings. If you do, some features of the Service, including sign-in, may not work.

Children and Users Outside Japan

The Service is intended for business use and is not directed at children.

We handle the personal information of people living outside Japan in accordance with this Policy as well. If the laws of your country or region give you additional rights, please contact us at the address below, and we will respond in accordance with applicable law.

Changes to This Policy

We may change this Policy in response to changes in law or in the Service. The revised Policy takes effect when it is posted on the Service.

If we make a material change to this Policy, we will give notice by posting the change and its effective date on the Service or by other means. Where the law requires your consent for a change, or for other important changes, we will ask for your consent again.

Contact

Please direct inquiries, questions, and Requests about this Policy or our handling of personal information to the following contact.

Contact: support@geoindex.app

Purposes of Use in Detail

We use the personal information we obtain only to the extent necessary to achieve the following purposes. If we need to use personal information beyond these purposes, we will obtain your prior consent, except where permitted by law.

  • To provide the Service, verify identity, authenticate users, and manage accounts (including invitations to organizations and workspaces and the management of permissions)
  • To bill, collect payment for, and account for fees
  • To send notices and important communications about the Service and to respond to inquiries
  • To improve the quality of the Service, develop new features, and analyze usage (including statistical processing)
  • To measure the effectiveness of advertising and promotion of the Service
  • To prevent misuse, maintain security, and protect our rights and property
  • To comply with laws and with requests from government authorities

Procedures for Requests Concerning Retained Personal Data

You may make the following requests to us regarding retained personal data we hold about you ("Requests"): notification of the purposes of use; disclosure (including disclosure of records of provision to third parties); correction, addition, or deletion of content; suspension of use or erasure; and cessation of provision to third parties.

Please submit Requests by email to support@geoindex.app. You may also delete your account (erasing your retained personal data) yourself from the settings screen after signing in.

We will respond to Requests without delay and in accordance with law after confirming that the requester is you or your duly authorized agent. To verify your identity, we may ask you to contact us from your registered email address or to submit identification documents. If an agent makes a Request, we will ask for a document (including an electronic record) evidencing the agent's authority.

We will make disclosures by providing electronic records (such as files in JSON format), by delivering documents in writing, or by another method you designate. If disclosure by the method you designate would involve substantial cost or would otherwise be difficult, we will notify you and make the disclosure by delivering documents in writing.

We do not charge a fee for Requests for notification of the purposes of use or for disclosure.

If we cannot comply with a Request under applicable law, or if we take a measure different from the one requested, we will notify you of that fact and the reason without delay.

Personal Information Protection Manager and Complaints

The person responsible for managing our handling of personal information, and the contact for complaints and inquiries, are as follows.

Personal Information Protection Manager: Disclosed without delay, within 48 hours of your request.

Contact for complaints, inquiries, and Requests: support@geoindex.app

We will endeavor to respond appropriately and promptly to complaints and inquiries about our handling of personal information.

Accredited Personal Information Protection Organization

We are not a member of any accredited personal information protection organization.

If we join such an organization in the future, we will add its name and its contact for complaint resolution to this notice.