MAPRISE (Operator: KANAMORI Toshiki) ("we", "us") complies with Japan's Act on the Protection of Personal Information and related laws, and handles user personal information appropriately. This policy sets out how personal information is handled in the MAPRISE service (maprise.jp).
1. Information We Collect
- Account information (registered users only): Email address, Google account details (name, profile picture — only when using Google OAuth), selected plan
- Usage data: Map interaction history (viewport, zoom level, selected layers), AI chat input and responses (stored for registered users only), the parameters and content of generated PDF reports
- Technical data: IP address, browser type, OS version, session ID (sessionStorage, cleared on tab close)
- Anonymous guest identifier: used only when you submit an AI question from the homepage without logging in (stored in localStorage and a cookie — see "9. Cookies and Local Storage")
2. How We Use Your Information
- To provide and operate the Service, including authentication and security management
- To save and display AI chat history (registered users only)
- To manage subscriptions and process billing (after paid plans launch)
- To respond to support requests and inquiries
- To analyze usage in aggregate (after anonymization)
- To improve the Service and develop new features
- To comply with applicable laws
3. AI Chat and Personal Information
The AI chat feature uses Amazon Bedrock (Anthropic Claude).
- Inputs are processed within Japan.
- Use of inputs for model improvement follows Anthropic's data usage terms (default settings do not use customer data for model training).
- Bedrock Guardrails filters inappropriate content.
- Guest user chat content is not stored on the server.
4. Data Sharing
We do not share personal data with third parties except:
- With your consent
- When required by law (court orders, lawful requests from authorities)
- With service providers under confidentiality obligations
5. Third-Party Services
| Service | Purpose | Region | Privacy Policy |
|---|---|---|---|
| Amazon Web Services (AWS) | Infrastructure, auth (Cognito), AI (Bedrock), storage (DynamoDB/S3) | Japan (Tokyo / Osaka) | aws.amazon.com |
| Anthropic (Claude) | AI chat processing (via Bedrock) | within Japan | anthropic.com |
| Stripe | Payment processing (after paid plans launch) | United States (PCI DSS compliant) | stripe.com |
| OAuth authentication (only when Google login is selected) | Per Google's terms | policies.google.com | |
| Google Analytics (Google LLC) | Web analytics (understanding usage and improving the Service) | Per Google's terms | policies.google.com |
| Sentry | Error and performance monitoring (detecting and investigating issues; on error only, may capture session replay — a screen recording with text and images masked by default) | Per Sentry's terms | sentry.io |
6. Data Retention
| Data type | Retention period |
|---|---|
| Account information | 30 days after account deletion, then progressively deleted (except data we are required to retain by law)** |
| AI chat history | Plan-dependent (Free: No user-accessible history* / Starter: 30 days / Pro: 6 months / Business: 3 years / Enterprise: coming soon (timing TBD)). See the feature comparison on the pricing page for details. Retained for registered users only. |
| PDF report generation logs | Up to 1 year** |
| Data you created or saved (saved views, my properties, exported CSV/GeoJSON) | Retained while your account is active. After account deletion, kept for 30 days and then progressively deleted (except data we are required to retain by law)** |
| Operation history (records of data exports and refund requests) | Up to 180 days**. If you delete your account, kept for 30 days after deletion and then progressively deleted. |
| Payment and AI-credit transaction records | Retained after account deletion (not subject to deletion). We are currently confirming whether these records are subject to a legal retention requirement under accounting/tax law, and will continue to retain them until that confirmation is complete. After account deletion, the user ID contained in these records is replaced with an irreversible substitute value so that no specific user can be identified. |
| Access logs (IP, etc.)*** | Up to 90 days |
| Session information | Cleared immediately on tab close (sessionStorage) |
7. Security
- All traffic encrypted with TLS 1.2 or higher (CloudFront + ACM)
- Authentication managed by AWS Cognito (OAuth 2.0/OIDC + PKCE)
- Access control follows the AWS IAM principle of least privilege
- Bedrock Guardrails for inappropriate-content filtering
- Access to personal data is limited to staff with a business need
8. Your Rights
Under Japan's Act on the Protection of Personal Information, you may request:
- Disclosure of personal data we hold about you
- Correction, addition, or deletion of inaccurate data
- Suspension of use or erasure (in case of out-of-purpose use or improper acquisition)
- Suspension of disclosure to third parties
Please contact info@maprise.jp. After identity verification, we will respond within the legally required period.
9. Cookies and Local Storage
The Service uses the following storage:
- sessionStorage: temporary auth tokens, language preference, decoded user information (email address, name, etc.) cached for on-screen display during your authenticated session — the same account information already disclosed in "1. Information We Collect" — and the read/dismissed status of AI credit usage notifications (maprise.credits.notify.*) (cleared on tab close)
- localStorage: Used to remember that you have acknowledged the disclaimer for the seismic simulation feature, the chat panel width (maprise_chat_width), cross-tab connection control (maprise_ws_lock_hb), whether you have dismissed the beta announcement banner (version-tracked), a display cache of AI credit consumption history (maprise.credits.*.consumed, tracking monthly usage — the read/dismissed status of related notifications is stored separately in sessionStorage, as noted above), your language preference (lang), and an anonymous guest identifier (maprise_anon_identityId) issued when you submit an AI question from the homepage without logging in — a random identifier issued by AWS Cognito that contains no name, email address, or other directly identifying information. It persists until you clear your browser's storage; contains no other personally identifiable information.
- Cookies: CloudFront session cookies; cookies set by Google Analytics for usage measurement (see "13. Transmission of User Information to Third Parties"); and a cookie corresponding to the anonymous guest identifier above (maprise_anon_uuid), valid until 23:59 Japan time on the day it is issued and extended each time you use the feature again that day. Both maprise_anon_identityId and maprise_anon_uuid are used solely to track usage counts and prevent abuse by guest users of the AI question feature, and contain no personally identifying information such as your name or email address.
10. Minors
The Service is not intended for users under 13. If we discover an account belonging to someone under 13, we will delete it.
11. Changes to this Policy
We may update this policy as needed. Material changes will be notified to registered users by email in advance. The latest version is always posted on this page.
12. Related Laws and References
This Privacy Policy is operated in compliance with the following laws and guidelines. Please refer to the source URLs for the latest official versions.
| Law / Guideline | Issuer | Source URL |
|---|---|---|
| Act on the Protection of Personal Information (APPI; April 2022 version, April 2024 amendments) | MIC e-Gov Law Search | https://laws.e-gov.go.jp/law/415AC0000000057 |
| PPC Guidelines (General Rules / Cross-border Data Transfer) | Personal Information Protection Commission | https://www.ppc.go.jp/personalinfo/legal/ |
| Guidelines on the Act on the Protection of Personal Information | Ministry of Economy, Trade and Industry | https://www.meti.go.jp/policy/it_policy/privacy/ |
Response to Data Breach (Reporting to PPC and Notification to Subjects)
- Preliminary report: within 3-5 days (60 days if for fraudulent purposes)
- Final report: within 30 days (60 days if for fraudulent purposes)
13. Transmission of User Information to Third Parties
We use the web analytics service "Google Analytics" to understand how the Service is used and to improve it. As a result, your user information (cookie identifiers, pages viewed, IP address, etc.) is transmitted to Google LLC. The transmitted information does not include data that directly identifies you, such as your name, address, or email address.
If you do not wish your information to be sent to Google Analytics, you can stop transmission and use through your browser settings or the "Google Analytics Opt-out Browser Add-on" provided by Google. Opt-out add-on: https://tools.google.com/dlpage/gaoptout
This section is published as a disclosure regarding the external transmission of user information under Japan's Telecommunications Business Act.
Privacy Contact
MAPRISE — Privacy Officer
Email: info@maprise.jp
Hours: Weekdays 10:00–18:00 JST (excluding weekends and Japanese public holidays)