CairoPlus · Site Inspector / Recipe Cost

プライバシーポリシー
Privacy policy

2026年9月9日更新 · Updated September 9, 2026

日本語

提供者は株式会社CairoPlus(cairo-plus)です。このポリシーは Site Inspector と Recipe Cost、および任意の Cairo cloud 同期サービスに適用します。お問い合わせは info@cairo-plus.com で受け付けます。

Site Inspector と Recipe Cost は、端末内機能に加えて任意のクラウド同期を提供します。本ポリシーは、アカウント、保存データ、購読確認と削除に関する情報の扱いを説明します。利用可能な購入プランと条件は Google Play の購入画面で確認してください。

1. 端末内で扱う情報

利用者が入力・選択した情報を、各機能を提供するために処理・保存します。

端末内の機能はクラウドアカウントなしで利用できます。写真は利用者が起動するカメラアプリを通じて撮影し、画像や文書は利用者が選んだファイルを読み込みます。連絡先一覧、SMS、通話履歴、端末の位置情報、マイク音声は取得しません。ただし、選択した写真や文書の原本に撮影時刻や位置などの埋込み情報が含まれる場合があり、原本の保存・バックアップ・共有にその情報が残ることがあります。位置情報を削除する機能としては使用しないでください。

2. 共有、広告、外部サービス

アプリ内データを販売しません。アプリに広告や広告 ID の取得、提供者向けの利用状況解析はありません。Recipe Cost の ML Kit による Google 向け診断情報は次項のとおりです。

ファイルの取込先、書出し先、共有先は Android の選択画面で利用者が指定します。選択した保存先、受け取りアプリ、印刷サービスは各サービスのポリシーに従って情報を扱います。Google Play と Android が扱う決済・配信・診断情報にも、それぞれのポリシーが適用されます。

3. Recipe Cost の納品書読取りと仕入価格

Recipe Cost 0.5.0 は Google ML Kit の日本語・ラテン文字の読取り機能を端末内に含みます。画像と読取結果は端末内で処理され、ML Kit がこれらを Google へ送信することはありません。一方、SDK は端末・アプリ情報、インストール単位の識別子、処理時間、入出力の大きさ、画像形式・解像度、API の版、処理の種類、エラーコードなどの診断・利用状況情報を HTTPS で Google へ送信します。Google は API の運用・改善などのために扱います。詳しくは ML Kit のデータ開示、ML Kit の規約とプライバシー、Google のプライバシーポリシーをご覧ください。

仕入価格の取得を実行すると、利用者が指定した HTTPS アドレスへ接続します。配信元は要求先アドレスや IP アドレスなどの通信情報を自身のポリシーに従って扱います。この取得機能はレシピ・在庫・販売記録をアップロードせず、表示された価格は利用者が確認して適用します。仕入価格の定期自動更新は行いません。

4. 任意のクラウド同期

接続先が設定された版で「今すぐ同期」を選ぶか、自動アップロードを有効にすると、使用しているアプリの現在の保存済みの作業内容、業務記録、保存済みの下書き、対応する関連ファイルを HTTPS で Cairo cloud へ送信します。写真、署名、帳票ひな型、納品書画像なども、保存内容に含まれていれば対象になります。別の「プロジェクト」一覧に保存したスナップショットと、画面上の未保存の編集は含みません。同期やコピーの置換を選ぶ前に作業を保存してください。

自動アップロードは利用者が有効にした場合にアプリを開いている間に行い、再ログイン後は改めて有効にする必要があります。保存内容はアカウントとアプリごとに分離します。同時変更がある場合、コピーの置換前に選択が必要です。提供者のサーバーは送信内容を読み取れるため、エンドツーエンド暗号化ではありません。接続先が未設定の版は作業内容をアップロードしません。

5. アカウントと認証

クラウドの認証・同期・不正利用防止のため、メールアドレス、ランダムなアカウント識別子、端末名、IP アドレスを含む通信情報を扱います。メールアドレスはログイン識別子として使い、本人確認メールを送りません。復旧には利用者が保管する一度限りの復旧コードを使い、メールの再設定リンクは提供しません。

サーバーではパスワードをソルト付きハッシュ、端末のセッションと復旧コードをハッシュとして保存します。端末のセッションは Android Keystore を使って暗号化し、作業バックアップと Android のバックアップには含めません。ログアウトしても端末内の作業内容と復旧用コピーは残ります。不正要求を抑えるため、IP アドレスやメールアドレスなどから SHA256 で作った識別子と要求の集計数を DynamoDB に保存し、2 時間の有効期限を設定します。期限後の物理的な削除は AWS により非同期で行われます。標準構成では利用状況解析や HTTP アクセスログを設けません。障害の確認や再試行のための運用ログと失敗処理の記録は 7 日の保持設定とし、必要最小限の要求・作業・アカウント識別子を扱います。パスワード、復旧コード、購入トークン、署名付き URL、作業本文はログへ記録しません。

6. 保存地域、保護、バックアップ

Cairo cloud は Amazon Web Services(AWS)の東京リージョンで運用するサーバーレス構成です。アカウントや保存版などの管理情報を DynamoDB、作業内容のアーカイブを非公開の S3 に保存し、処理に Lambda と API Gateway を使用します。DynamoDB と S3 は保存時に暗号化され、サービスとの通信は HTTPS を使います。提供者はアクセス権を制限して運用します。

大きなアーカイブは、アプリが短時間だけ有効な署名付き URL を受け取り、非公開の S3 へ直接送受信します。URL は所持者が利用できる一時的なアクセス情報です。提供者は URL を公開ログへ載せず、利用者も他者へ転送しないでください。サーバーが内容と変更の競合を確認してから正式な保存版にします。署名期限までに開始した転送は期限後も続く場合があります。

DynamoDB の継続バックアップは 過去 7 日間を復元対象にする設定です。保存データ全体が必ず 7 日で削除されるという意味ではありません。S3 はオブジェクトの版管理を有効にし、正式に保存した作業版は利用者による削除まで保持します。未確定の一時アップロードには現行版・過去版とも 1 日を基準とする期限処理を設定していますが、削除は非同期で、処理時刻を保証しません。手動で取り出した運用コピーは自動で失効せず、担当者が必要性と削除を管理します。

バックアップは公開しない環境で検査し、削除済みアカウントの記録と照合します。過去のアカウントをそのまま公開環境へ戻さず、旧パスワード、セッション、復旧コードを無効化して隔離します。必要なデータの個別回復は本人確認後に行い、削除済みアカウントを復活させません。管理情報のバックアップだけでは削除済みの S3 ファイルを回復できない場合があり、回復の成功や所要時間を保証するものではありません。

7. 任意のクラウド定期購入

クラウド契約はアプリの買い切り購入と別の任意オプションです。支払いは Google Play が処理します。アプリとサーバーは確認・復元・不正利用防止のため、商品 ID、購入トークン、購入状態と日時、有効期限、個人情報を直接含まないアカウント識別子を扱います。この識別子を Google Play へ渡し、購入をクラウドアカウントに対応付けます。

サーバーは Google に更新・失効・返金を確認し、購入の受領確認を行うため、購入トークンを保存します。カード情報をアプリ内で入力・保存しません。解約後も端末内の機能と記録を利用でき、既存のクラウドコピーをダウンロード・削除できます。古いクラウド版は利用者が削除するまで残り、容量や版数の上限に達すると空きができるまで新しいアップロードを停止します。

8. クラウドアカウントの削除

アプリ内のアカウント削除、または クラウドアカウント削除ページから、パスワードを確認して削除できます。両アプリで同じアカウントを使う場合、削除はそのアカウントの Site Inspector と Recipe Cost の両方に及びます。削除を受け付けるとアカウントを無効にして以後の認証付き操作を拒否し、クラウドデータと全履歴、購入確認情報、セッション、復旧コードなどの消去を進めます。

発行済み署名付き URL の期限、開始済みの転送、削除作業の再試行などにより、ファイルの物理的な消去が完了するまで時間がかかる場合があります。DynamoDB の継続バックアップや過去の運用コピーにも、削除が即時反映されるわけではありません。残るコピーは上記の保護・保持・隔離復元の管理対象です。保存や削除については info@cairo-plus.com にお問い合わせください。

クラウドアカウントの削除は Google Play の定期購入を解約しません。Google Play で別途解約してください。Google 側の購入記録、端末内の作業、既にダウンロード・共有したファイルも削除しません。必要な情報を先に取り出し、外部コピーは各保存先で管理してください。

9. 端末内の保存、引継ぎ、削除

記録と取り込んだ媒体はアプリ専用領域に保存します。取消しや復元に備えた履歴・スナップショット・媒体のコピーが残る場合があります。端末を替える前に必要な情報をバックアップまたは書き出してください。Android の自動バックアップや自動端末移行には依存しません。

アンインストール、または Android の設定でアプリのストレージを消去すると、専用領域の記録・履歴・媒体が削除されます。自分で書き出したファイル、外部バックアップ、共有相手のコピー、クラウドアカウントは別途削除してください。ZIP の整合性検査は暗号化ではありません。画面ロックや端末の暗号化設定を使い、書き出す内容と共有先を確認してください。提供者は端末内だけにある記録を遠隔で閲覧・復元できません。

10. お問い合わせと変更

問い合わせメールに含まれる情報は、返信・調査・保存や削除の相談への対応に使用します。必要な情報だけをお送りいただき、パスワード、復旧コード、購入トークンをメールで送らないでください。窓口:info@cairo-plus.com。

データの扱いを変更する機能や運用を提供する場合は、このポリシーとアプリ・ストアの開示を更新します。

English

The provider is 株式会社CairoPlus (cairo-plus). This policy applies to Site Inspector and Recipe Cost and optional Cairo cloud sync. Contact us at info@cairo-plus.com.

Site Inspector and Recipe Cost offer optional cloud sync alongside their on-device tools. This policy explains how account information, saved work, subscription verification and deletion are handled. Check the Google Play purchase screen for available plans and terms.

1. Information used on your device

We process and store information you enter or select to provide each app’s functions.

Local functions do not require a cloud account. Photos are captured through the camera app you open, and document or image imports read files you select. These apps do not access your contact list, SMS, call history, device location or microphone recordings. However, selected original photos or documents may contain embedded capture times or locations. Keeping, backing up or sharing originals may preserve that information; these apps are not location-metadata removal tools.

2. Sharing, advertising and external services

We do not sell app data. The apps have no advertising, advertising-ID access or provider usage analytics. Google receives ML Kit diagnostics from Recipe Cost as described below.

You choose import sources, export destinations and receiving apps through Android. Selected storage providers, receiving apps and print services handle information under their own policies. Google Play and Android also handle payment, distribution and diagnostic information under their respective policies.

3. Recipe Cost invoice recognition and supplier prices

Recipe Cost 0.5.0 bundles Google ML Kit’s Japanese and Latin text recognition. Images and recognized text are processed on your device and are not sent to Google by ML Kit. The SDK sends diagnostic and usage metrics over HTTPS, including device and app information, per-installation identifiers, processing latency, input/output sizes, image format and resolution, API versions, event types and error codes. Google uses these metrics to operate and improve its APIs. See ML Kit’s data disclosure, ML Kit Terms & Privacy and Google’s Privacy Policy.

When you request supplier prices, the app connects to the HTTPS address you supplied. That supplier receives the requested address and network information such as your IP address under its own policy. This download feature does not upload recipes, inventory or sales records. You review prices before applying them. Supplier feeds are not refreshed periodically.

4. Optional cloud sync

In a build with a configured service, choosing Sync now or enabling automatic uploads sends the app’s current saved workspace, business records, saved drafts and supported linked files over HTTPS to Cairo cloud. Photos, signatures, report templates and invoice images are included when they are part of that saved work. Snapshots in the separate Projects list and unsaved screen edits are not included. Save your work before syncing or choosing a replacement copy.

Automatic uploads operate while the app is open if you enable them, and require a new opt-in after signing in again. Stored work is separated by account and app. Concurrent changes require a choice before replacing a copy. The provider’s server can read uploaded content; this is not end-to-end encryption. A build without a configured service does not upload workspace content.

5. Accounts and authentication

For authentication, sync and abuse prevention, the service processes your email address, random account identifier, device name and network information including your IP address. Email is a login identifier; no verification email is sent. Recovery uses the one-time codes you save, not an emailed reset link.

Passwords are stored on the server as salted hashes. Device sessions and recovery codes are stored as hashes. The session on your device is encrypted using Android Keystore and excluded from workspace archives and Android backups. Signing out keeps local work and recovery copies. To limit abusive requests, DynamoDB stores identifiers derived from IP addresses, email addresses or similar inputs using SHA256, together with request counts and a two-hour expiry. AWS performs physical deletion asynchronously after expiry. The standard configuration has no usage analytics or HTTP access logs. Operational error logs and failed-work records are configured for seven-day retention and contain the minimum request, job and account identifiers needed to investigate or retry work. Passwords, recovery codes, purchase tokens, signed URLs and workspace content are not logged.

6. Hosting, protection and backups

Cairo cloud uses a serverless deployment in Amazon Web Services (AWS), Tokyo Region. Account and version metadata are stored in DynamoDB, workspace archives in private S3, and processing uses Lambda and API Gateway. DynamoDB and S3 encrypt stored data, and communication with the service uses HTTPS. The provider restricts operational access.

For large archives, the app receives a short-lived signed URL and transfers data directly to or from private S3. These URLs provide temporary access to anyone who possesses them. The provider does not place them in public logs; do not forward them to others. The server checks archive content and concurrent changes before publishing a saved version. Transfers started before a signature expires may continue afterward.

DynamoDB continuous backups are configured for a seven-day recovery window. This does not mean all stored data is deleted within seven days. S3 object versioning is enabled, and published workspace versions are retained until you delete them. Uncommitted staging uploads have one-day lifecycle rules for both current and previous object versions. Expiration is asynchronous, not a guaranteed deletion time. Manually extracted operational copies do not expire automatically; the operator manages their continued need and deletion.

Backup recovery is checked in an isolated environment and reconciled with deleted-account records. Old account databases are not republished unchanged. Old passwords, sessions and recovery codes are invalidated and the recovered copy remains isolated. Necessary data is recovered individually after identity verification; deleted accounts are not reinstated. A metadata backup alone may not recover an S3 file already deleted. Successful recovery and recovery times are not guaranteed.

7. Optional cloud subscriptions

A cloud subscription is optional and separate from the one-time app purchase. Google Play processes payments. For verification, restoration and abuse prevention, the app and server process product IDs, purchase tokens, purchase status and times, expiry, and an opaque account identifier. That identifier is sent to Google Play to bind the purchase to your cloud account.

The server retains purchase tokens to check renewals, expiry and refunds with Google and acknowledge purchases. Card details are not entered or stored in the app. After cancellation, local tools and records remain available, and existing cloud copies can be downloaded or deleted. Older cloud versions remain until you delete them. Reaching a storage or version limit stops new uploads until space is available.

8. Deleting your cloud account

After password confirmation, you can delete your account in the app or on the cloud account deletion page. If both apps use the same account, deletion covers that account’s Site Inspector and Recipe Cost data together. When deletion is accepted, the account is disabled and subsequent authenticated operations are denied. Removal of cloud archives and history, purchase-verification records, sessions, recovery codes and related records then proceeds.

Physical file removal can take time because of existing signed URLs, transfers already in progress or retries of deletion work. Deletion is not immediately reflected in DynamoDB continuous backups or older operational copies. Remaining copies are subject to the protection, retention and isolated-recovery controls described above. Contact info@cairo-plus.com about retention or deletion.

Deleting the cloud account does not cancel a Google Play subscription. Cancel separately in Google Play. Deletion also does not remove Google’s purchase records, local work, or files already downloaded or shared. Export anything you need first, and manage external copies at their respective destinations.

9. Local retention, transfer and deletion

Records and imported media are kept in app-private storage. Undo history, saved snapshots and media copies may remain for recovery. Before changing devices, back up or export what you need. Do not rely on Android automatic backup or automatic device transfer.

Uninstalling the app or clearing its storage in Android settings deletes its private records, history and media. Separately delete exported files, external backups, copies held by recipients and your cloud account. ZIP integrity checks are not encryption. Use screen locks and device encryption, and review exported contents and recipients. The provider cannot remotely view or restore records that exist only on your device.

10. Contact and changes

Information in support emails is used to reply, investigate and address retention or deletion requests. Send only what is needed; do not email passwords, recovery codes or purchase tokens. Contact: info@cairo-plus.com.

If features or operations change how information is handled, we will update this policy and the app and store disclosures.