プライバシーポリシー
最終更新: 2026年7月11日
きざむは「触り心地」を大事にする、付箋のためのタスクボードです。同じ姿勢で、あなたのデータも静かに扱います。付箋の中身は、通常はあなたの端末の中にだけ残ります。Cloudの同期またはクラウドひかえを自分で有効にした場合だけ、その対象データを保存のために送信します。匿名計測には送りません。
1. 端末の中に保存されるもの
作成した付箋・構造・設定は、お使いのブラウザの localStorage に保存されます。Cloudの同期またはクラウドひかえを有効にしない限り、付箋・タスク名・メモ・構造の文字は私たちの保存先へ送られません。対応ブラウザでは、保存が自動削除されにくくなるよう永続ストレージを申請します。ブラウザのデータを消すと、これらも消えます。Proでは、設定メニューの「書き出し」からバックアップを取れます。
2. アカウントとCloud
アカウント登録・ログインには Clerk を使います。Clerk は、メールアドレスなど、登録・本人確認・ログインに必要な情報を取り扱います。アカウントは任意で、ログインしなくても端末内の機能を使えます。
Cloudの端末間同期を有効にした場合、盤面・構造・付箋・タスク名・メモ・完了履歴・習慣・設定など、端末間でそろえるために必要なデータをCloudflare上に保存します。クラウドひかえを有効にした場合は、これらを含む状態JSONをCloudflare R2に保存し、最新1件と日次7日分を保持します。ライセンスキー、購入情報、決済情報は、同期データおよびクラウドひかえには含めません。
通信はTLSで保護され、保存先では保存時に暗号化されます。ただし、Cloudの同期データおよびクラウドひかえはエンドツーエンド暗号化ではありません。運営者は、利用者本人から依頼されたサポート、障害・不正利用・セキュリティ事故の調査、または法令上必要な対応のため、必要な範囲で技術的に内容へアクセスできます。通常の運用で内容を閲覧せず、分析、広告、AI学習またはPostHogによる計測には利用しません。
Cloudをオフにすると、新しい同期または保存だけが止まり、保存済みデータは消えません。同期データは「同期データを削除」、クラウドひかえは「クラウドのひかえを削除」から削除できます。ほかの端末で同期またはクラウドひかえが有効なままの場合、その端末から新しいデータが作成されることがあります。
Cloudの契約終了後、クラウド上の同期データおよびクラウドひかえは30日間保持し、その後順次削除します。30日以内にCloudを再開した場合は、保持中のデータを引き継げます。利用者が明示的に削除した場合は、30日を待たず削除します。退会時は、アカウントに紐づく同期データおよびクラウドひかえを7日以内に削除します。
3. 計測(アクセス解析)について
使い心地を直すために、匿名のごく最小限の利用状況だけを PostHog で計測しています。具体的には:
- 送るのは操作の「種類」と「数」、公開ページの閲覧、タブが表示されていた時間、スクロール到達度などです(例: 付箋を作った/完了した/集中を始めた、盤面/構造の切り替え、階層の段数、件数、分数)。
- 価格ページでは、どのアプリ内導線から開いたか、よくある質問のどの項目を開いたか、購入手続きを開始・完了したかを計測します。質問本文、決済情報、メールアドレス、ライセンスキーは送りません。
- 付箋の本文・タスク名・メモなどの文字は一切送りません。
- 計測上では、アカウントへの紐づけや個人を特定する処理(identify)は行いません。端末ごとのランダムな匿名IDだけが使われます。
- クリックの自動収集(autocapture)と画面の録画はオフです。
- 計測は、きざむの公開サイト上でのみ行います。
計測データは PostHog Inc.(米国)に保存されます。送信先・処理の詳細は PostHog のプライバシー方針をご覧ください。
4. Cookie・ローカルストレージ
付箋データの保存と、匿名の計測IDの保持のために、ブラウザのローカルストレージと Cookie を使います。広告目的の Cookie は使いません。
5. 第三者サービス
- Cloudflare Pages・Workers・D1・KV(配信・バックエンド・ライセンス台帳) — ページ配信やAPI通信に伴い、アクセス元のIPアドレス等が通信ログとして扱われることがあります。
- Cloudflare D1・R2(端末間同期・クラウドひかえ) — 有効にした利用者の同期データおよび状態JSONを保存します。
- Clerk(アカウント認証) — 登録・本人確認・ログインに必要な情報を取り扱います。
- Google Fonts(書体配信) — 文字の表示のため、Google のサーバーからフォントを読み込みます。
- PostHog(上記の匿名計測)。
- Paddle(決済・サブスクリプション管理) — 販売事業者(Merchant of Record)として購入、継続請求、解約、返金および税の処理を行います。決済情報は Paddle が取り扱います。
- Resend(メール送信) — ライセンスキー再送時のみ、送信先メールアドレスと署名ライセンスキーを送信に使います。付箋本文・タスク名・構造の文字は送りません。
6. 購入に関する情報
購入およびCloudサブスクリプションの決済は Paddle(Paddle.com Market Limited/英国)が販売事業者(Merchant of Record)として行い、カード情報などの決済に必要な情報は Paddle が取り扱います。きざむ側では、ライセンスとCloud利用権の確認、ライセンスキー再送、契約状態の反映および問い合わせ対応に必要な範囲で、購入日時、購入プラン、サブスクリプションの状態、決済状態、購入時のメールアドレス等を扱う場合があります。Paddle における情報の取り扱いは、Paddle のプライバシー方針に従います。
7. あなたができること(オプトアウト)
- ブラウザの「サイトデータを削除」で、保存された付箋・匿名IDをいつでも消せます。
- 同期とクラウドひかえはいつでもオフにできます。オフだけでは保存済みデータは消えません。「同期データを削除」または「クラウドのひかえを削除」で明示的に削除できます。
- 退会すると、アカウントに紐づく同期データおよびクラウドひかえを7日以内に削除します。
- ブラウザのトラッキング防止機能や広告ブロッカーで、計測の読み込み自体を止められます。
- 困ったとき・消してほしいデータがあるときは、下記までご連絡ください。
8. 改定・連絡先
内容を変えたときは、この日付を更新します。お問い合わせは 感想・不具合フォーム を基本の窓口としています。メールは support@kizamutasks.app まで。返信が必要な内容については、入力いただいたメールアドレス宛にご連絡する場合があります。返信は、きざむサポート用のメールアドレスから届きます。
Privacy Policy
Last updated: July 11, 2026
Kizamu is a sticky-note task board built around feel. We treat your data the same quiet way. Note contents normally remain only on your device. They are sent for storage only when you explicitly enable Cloud sync or cloud backup, and are never sent to anonymous analytics.
1. Stored on your device
Your notes, structure, and settings are saved in your browser's localStorage. Unless you enable Cloud sync or cloud backup, note text, task names, memos, and structure text are not sent to our storage. On supported browsers, Kizamu requests persistent storage so the data is less likely to be removed automatically. Clearing your browser data removes it. With Pro, you can back up via "Export" in the settings menu.
2. Accounts and Cloud
Kizamu uses Clerk for account registration and login. Clerk processes email addresses and other information needed for registration, identity verification, and login. Accounts are optional; on-device features remain available without logging in.
When you enable cross-device Cloud sync, data needed to keep devices aligned—including boards, structures, notes, task names, memos, completion history, habits, and settings—is stored on Cloudflare. When you enable cloud backup, a state JSON containing this data is stored in Cloudflare R2; Kizamu keeps the latest backup and seven daily backups. License keys, purchase information, and payment information are not included in sync data or cloud backups.
Transfers are protected with TLS, and stored data is encrypted at rest. Cloud sync data and cloud backups are not end-to-end encrypted. The operator can technically access content only as reasonably necessary for support requested by the user, investigation of outages, misuse, or security incidents, or compliance with legal obligations. Content is not viewed in ordinary operations or used for analytics, advertising, AI training, or PostHog measurement.
Turning Cloud off stops new syncing or uploads but does not delete stored data. Use "Delete sync data" or "Delete cloud backups" to delete it. If sync or cloud backup remains enabled on another device, that device may create new cloud data.
After a Cloud subscription ends, cloud sync data and cloud backups are retained for 30 days and then deleted in due course. If you resume Cloud within 30 days, you can continue with the retained data. Data you explicitly delete is deleted without waiting for that period. Sync data and cloud backups linked to an account are deleted within seven days after account deletion.
3. Analytics
To improve the feel of the app, we collect minimal, anonymous usage data with PostHog:
- Only the type and count of actions, public page views, time while the tab was visible, and maximum scroll depth (e.g. note created/completed, focus started, board/structure changes, depth levels, counts, and minutes).
- On the pricing page, we measure which in-app entry was used, which FAQ item was opened, and whether checkout was started or completed. We do not send FAQ text, payment details, email addresses, or license keys.
- No note text, task names, or memos are ever sent.
- Analytics does not link events to your account or identify you. It uses only a random anonymous per-device ID.
- Autocapture and session recording are off.
- Analytics runs only on Kizamu's public website.
Analytics data is stored by PostHog Inc. (USA).
4. Cookies & local storage
Used to store your notes and the anonymous analytics ID. No advertising cookies.
5. Third parties
- Cloudflare Pages, Workers, D1, and KV (delivery, backend, and license ledger) — request logs may include your IP address.
- Cloudflare D1 and R2 (cross-device sync and cloud backup) — store sync data and state JSON for users who enable them.
- Clerk (account authentication) — processes information needed for registration, verification, and login.
- Google Fonts (typefaces) — fonts are loaded from Google's servers.
- PostHog (the anonymous analytics above).
- Paddle (payments and subscription management) — acts as Merchant of Record for purchases, recurring billing, cancellations, refunds, and tax. Payment data is handled by Paddle.
- Resend (email delivery) — only when resending a license key, used to send the destination email address and signed license key. Note text, task names, and structure text are not sent.
6. Purchase information
Payments for purchases and Cloud subscriptions are processed by Paddle (Paddle.com Market Limited, UK) as the Merchant of Record; card and other payment details are handled by Paddle. Kizamu may process purchase time, plan, subscription status, payment status, and purchase email only as needed to verify licenses and Cloud access, resend a license key, reflect contract status, and provide support. Paddle's handling of your data is governed by Paddle's privacy policy.
7. Your choices
- Clear site data in your browser to remove stored notes and the anonymous ID.
- Turn sync and cloud backup off at any time. Turning them off does not delete stored data; use "Delete sync data" or "Delete cloud backups" to delete it explicitly.
- Deleting your account deletes its sync data and cloud backups within seven days.
- Use tracking protection or an ad blocker to stop analytics from loading.
- Contact us below for any data request.
8. Changes & contact
We update the date above on any change. The feedback and bug form is our primary contact channel. You can also email support@kizamutasks.app. If your message needs a reply, we may contact the email address you entered. Replies will come from a Kizamu support email address.