Privacy Policy

Last updated: July 15, 2026

XFE (“we,” “us,” or “our”) establishes this Privacy Policy (the “Policy”) regarding the handling of user information in the application “MissionDraft” (the “App”) provided by us and any related services provided in connection with the App (collectively, the “Service”). In this Policy, “User Information” means personal information, User Content, usage information, device information, diagnostic information, purchase information, and any other information acquired or processed in connection with use of the Service.

1. Basic Policy

We respect user privacy, comply with the Act on the Protection of Personal Information and other applicable laws and regulations, and handle User Information appropriately. In order to provide the rich text editor, document management, data synchronization, in-app purchases, AI chat features, backend communication, and other features of the Service, we may acquire, store, use, and transmit User Information to the extent necessary.

2. Scope of Application

This Policy applies to the handling of User Information in the Service. When the Service moves to or integrates with external services, external websites, the App Store, iCloud, CloudKit, external LLM providers, payment services, or similar services, the handling of information by those services is governed by the terms of use and privacy policies established by their respective providers.

3. Information We Collect

We may collect the following information to the extent necessary to provide the Service.

3.1 Account and Authentication Information

  • User IDs, anonymous IDs, installation IDs, and other identifiers
  • Access tokens, refresh tokens, and other authentication information
  • App Attest and other information necessary for device authentication and abuse prevention
  • Subscription or purchase status information
  • Information related to account deletion, login, authentication, and restoration

Authentication information, anonymous IDs, installation IDs, and other identifiers may be stored in the device Keychain. Depending on your device settings, some of this information may also be synchronized through iCloud Keychain.

3.2 Purchase and Subscription Information

  • Information related to purchases, subscriptions, one-time purchases, and restoration through the App Store
  • Transaction IDs
  • Signed transaction information issued by Apple
  • Purchased product IDs, subscription status, expiration dates, and renewal status
  • Paid plan status managed on the backend

We do not directly acquire credit card numbers or other detailed payment method information for payments made through the App Store.

3.3 User Content

The Service may handle the following information that you create, save, edit, import, send, upload, or synchronize:

  • Document text
  • Rich text data
  • Images and attachments
  • Tags, projects, and metadata
  • Document history and revision information
  • Markdown and other imported data
  • Information entered into or attached to AI chat

Document data may be stored or synchronized on your device or in your iCloud / CloudKit environment. When you use the AI chat feature, messages, attachments, related information, selected document content, or other information necessary to provide the feature may be sent to our servers and external LLM providers.

3.4 AI Chat Information

To provide the AI chat feature, we may acquire, store, and transmit the following information:

  • Messages entered by you
  • Responses generated by AI
  • Chat history
  • Chat context IDs
  • Attachment content, file names, file formats, file sizes, and metadata
  • Selected AI models, inference settings, and other chat feature settings
  • Logs necessary for abuse prevention, usage limits, and troubleshooting

Images and other attachments sent to AI chat will, in principle, be deleted sequentially after 30 days from transmission. However, the timing of deletion may vary due to system processing, backups, troubleshooting, legal compliance, abuse investigations, and similar reasons. Chat history may be stored on our servers for purposes such as displaying conversation history, providing the Service, preventing abuse, and troubleshooting. However, we do not guarantee permanent storage of chat history.

3.5 Device, Usage, and Diagnostic Information

We may collect the following information for providing and maintaining the Service, ensuring security, and troubleshooting:

  • Device type, OS version, and App version
  • IP address
  • Communication dates and times, request information, and response information
  • Crash logs, error logs, and performance information
  • Feature usage and settings information
  • Information necessary to detect abuse, excessive access, and security anomalies

The App may use Firebase Crashlytics for crash analysis and troubleshooting. In this case, diagnostic information necessary for crash analysis, such as stack traces at the time of a crash, exception information, App version, OS version, device type, crash date and time, Firebase installation ID, and Crashlytics Installation UUID, may be sent to Google LLC.

The App may also use Firebase Analytics or Google Analytics for Firebase to understand usage, maintain and improve quality, and troubleshoot issues. In this case, information necessary for analytics, such as App launches, screen transitions, feature usage, device information, and App version, may be sent to Google LLC.

3.6 Inquiry Information

When you contact us, we may collect the following information:

  • Name or display name
  • Email address
  • Inquiry content
  • Attachments
  • Response history

4. Purposes of Use

We use collected information for the following purposes:

  • To provide, maintain, protect, troubleshoot, and ensure the security of the Service
  • To create, save, display, edit, synchronize, and restore documents
  • To provide the AI chat feature, generate responses, display chat history, and process attachments
  • To authenticate accounts, manage login status, and identify users
  • To provide subscriptions, one-time purchases, and paid features, and to verify and restore purchase status
  • To detect and prevent abuse, violations of terms, security breaches, and excessive load
  • To handle failures, perform maintenance, respond to inquiries, and provide support
  • To respond based on the Terms of Use, Privacy Policy, and laws
  • To notify users of important announcements, maintenance, specification changes, security information, and similar matters
  • To analyze usage, failure information, and statistical information in a form that does not identify individuals, and to improve the Service
  • To respond to legitimate requests from laws, courts, administrative agencies, the App Store, and external service providers

5. Third-Party Services and External Transmission

The Service may integrate with the following third-party or external services:

  • Apple, App Store, StoreKit, iCloud, and CloudKit
  • Google LLC, Firebase, Firebase Crashlytics, and Firebase Analytics
  • External LLM providers or AI-related services
  • OpenAI, Google, Anthropic, xAI, and other AI service providers
  • Cloud infrastructure, hosting, database, storage, and network-related services
  • Authentication, abuse prevention, and security-related services
  • Email, inquiry handling, and support-related services

We may send, store, entrust processing of, or share User Information with these external services to the extent necessary to provide the Service. External service providers may be located outside Japan. In such cases, User Information may be processed, stored, or accessed outside Japan.

6. Provision to Third Parties

We do not provide personal information to third parties without user consent, except in the following cases:

  • When the user has given consent
  • When processing is entrusted to external service providers, contractors, cloud services, or AI service providers to the extent necessary to provide the Service
  • When required by law
  • When necessary to protect a person’s life, body, or property, and obtaining user consent is difficult
  • When particularly necessary for improving public health or promoting the sound development of children
  • When cooperation with national agencies, local governments, courts, administrative agencies, or similar authorities is necessary
  • When necessary to respond to violations of the Terms of Use, abuse, security breaches, or infringement of rights
  • When necessary in connection with business transfer, merger, succession, or other change in the operator of the Service

7. Data Retention Period

We retain collected information for the period necessary to achieve the purposes of use or for the period required by law. The main retention periods are as follows:

  • Account information, authentication information, and paid plan status: for the period necessary to provide the Service
  • Chat history: for the period necessary for providing the Service, displaying history, preventing abuse, troubleshooting, and similar purposes
  • Attachments sent to AI chat: in principle, deleted sequentially after 30 days from transmission
  • Purchase, subscription, and transaction-related information: for the period necessary for payment, restoration, refunds, accounting, and legal compliance
  • Inquiry information: for the period necessary to respond to inquiries and prevent recurrence of issues
  • Server logs, security logs, and diagnostic information: for the period necessary for maintenance, troubleshooting, and security
  • Crash-related information and associated identifiers sent to Firebase Crashlytics: retained for 90 days in accordance with Firebase specifications, after which the deletion process begins

If you complete the account deletion process, we will, except where retention is required by law, abuse investigations, payment or refund handling, security measures, backup management, or other reasonably necessary purposes, delete data related to you stored on our servers, in principle, within 30 to 90 days. Data stored on your device or in your iCloud / CloudKit environment may be under your own control.

8. User Management, Deletion, and Requests

You may request confirmation, correction, deletion, account deletion, or suspension of use of your own information through the App or by a method specified by us. After verifying your identity, we will respond to such requests in accordance with the law and within a reasonable scope. However, we may be unable to comply with all or part of a request in the following cases:

  • When retention is required by law
  • When necessary for abuse prevention, security measures, dispute handling, payment or refund handling
  • When deletion or extraction is technically difficult
  • When the request may harm the rights or interests of other users, third parties, or us
  • When immediate deletion is difficult due to backups, logs, external service processing, or similar reasons

9. Security

We implement reasonable security measures to prevent unauthorized access to, leakage, loss, alteration, destruction, or other misuse of User Information. However, because internet communication, devices, cloud services, and external services involve inherent risks, we do not guarantee complete security of information. You are responsible for managing your own device, Apple ID, iCloud, authentication information, and backups.

10. Notes on Using AI Chat

Information entered into the AI chat feature may be sent to our servers and external LLM providers. We do not use your document text, chat content, or attachments to train our own AI models. However, information sent to external LLM providers may also be subject to the terms and privacy policies of those external LLM providers. When entering or attaching information to AI chat, you should take care regarding the following:

  • Do not improperly send personal information, confidential information, or trade secrets of third parties
  • Exercise caution when handling information requiring professional judgment, such as medical, legal, tax, investment, financial, or similar information
  • AI outputs are not guaranteed to be accurate, complete, or up to date
  • When using AI outputs, you are responsible for reviewing their contents

11. Information of Minors

If a minor uses the Service, the minor must obtain consent from a parent or other legal representative. Parents or other legal representatives must review the contents of the Service, transmission of information to external services in the AI chat feature, the conditions for paid features, and this Policy before consenting to the minor’s use.

12. Cookies, Advertising, and Tracking

The Service may use cookies, similar technologies, logs, and identifiers in connection with websites, support pages, and external service integrations. We may use these technologies within the scope of the purposes described in this Policy for providing the Service, authentication, security, understanding usage, and troubleshooting. Separately from tracking for third-party advertising purposes, we may use Firebase Crashlytics, Firebase Analytics, and other analytics or diagnostic services for providing and maintaining the Service, quality maintenance and improvement, troubleshooting, and understanding usage. At present, we do not conduct tracking for third-party advertising purposes within the App. If we conduct tracking for third-party advertising purposes in the future, we will comply with applicable laws, App Store rules, Apple’s App Tracking Transparency, and other necessary procedures.

When there is a legitimate request from laws, courts, administrative agencies, investigative agencies, the App Store, or external service providers, we may disclose, retain, or use User Information to the extent necessary. We may also use or disclose User Information to the extent necessary to protect the rights, property, or safety of us, users, or third parties.

14. Changes to This Privacy Policy

We may change this Policy as necessary. When making important changes, we will endeavor to notify users through the App, website, or other appropriate means. The revised Policy will apply from the effective date specified by us. If you continue to use the Service after the changes, you are deemed to have agreed to the revised Policy.

15. Contact

For inquiries regarding this Policy, requests for disclosure, correction, deletion, suspension of use of personal information, or other requests, please contact us at:

Operator: Hiromitsu Yamauchi

Address: 6F N&E BLD., 1-12-4 Ginza, Chuo-ku, Tokyo, Japan

Email: hiro@xfe.tokyo

Website: https://xfe.tokyo/