Privacy Policy
Disclaimer: This English translation is provided for convenience only. The original Japanese version of this Privacy Policy is the legally binding document.
Last Updated: August 22, 2026
Preamble
New Summer Inc. (hereinafter "the Company") establishes the following privacy policy (hereinafter "this Policy") regarding the handling of all personal information processed through the AI conversation application "KidTalk" (hereinafter "the Service") provided by the Company, for its users (primarily parents or legal guardians of children, hereinafter "Guardians").
Although the Service is designed for children (individuals under 18 years of age, hereinafter the same) as the primary users, the contractual relationship is established with the Guardian, and the Service becomes available upon the Guardian's agreement to this Policy.
The Company complies with applicable laws, including Japan's Act on the Protection of Personal Information (hereinafter "APPI"), the EU General Data Protection Regulation (hereinafter "GDPR"), the U.S. Children's Online Privacy Protection Act (hereinafter "COPPA"), and the California Consumer Privacy Act (hereinafter "CCPA"), to manage personal information appropriately and securely.
Article 1 (Business Operator Information and Data Protection Officer)
The Company's name and contact information are as follows:
- Corporate Name: New Summer Inc.
- Registered Address: 3F, Navi Shibuya V, 5-5, Maruyama-cho, Shibuya City, Tokyo, Japan
- Data Protection Officer: info@kidtalkapp.com
For inquiries regarding the handling of personal information and requests to exercise various rights, please contact the Data Protection Officer (DPO) above. The Company will respond within a reasonable period (in principle, within 30 days) after receiving the request.
Article 2 (Scope of Application)
This Policy applies to all personal information and quasi-personal information acquired and processed by the Company in connection with the use of the Service. Although the Service is designed for children, the contractual party with the Company is the Guardian, and children shall use the Service under the Guardian's consent and supervision.
This Policy also applies to personal information collected through the contact form on the Company's marketing website (kidtalkapp.com).
This Policy does not apply to websites, applications, or services operated by third parties (including those linked from the Service).
Article 3 (Applicable Laws)
The Company complies with the following laws according to the user's location and applicable governing law.
| Region | Primary Applicable Law | Abbreviation |
|---|---|---|
| Japan | Act on the Protection of Personal Information (Amended in 2020) | APPI |
| EU / EEA | General Data Protection Regulation (EU) 2016/679 | GDPR |
| USA (Federal) | Children's Online Privacy Protection Act | COPPA |
| USA (California) | California Consumer Privacy Act / CPRA | CCPA / CPRA |
Article 4 (Types of Personal Information Collected)
The Company collects the following information only to the extent necessary for providing the Service.
- Account Information
- Email address (of the Guardian)
- User ID (system-generated)
- Password (held by the authentication layer; the Company never collects or stores the password itself)
- Child profiles registered by the Guardian (nickname, age band, display colour)
- Display language preference, and optional context about the child voluntarily entered by the Guardian
- Voice and Conversation Data
- Voice input from the child (maximum 10 seconds per recording)
- The text transcribed from that audio, and the AI-generated reply text (conversation history)
- The most recent few exchanges, sent as context so that follow-up questions work
The Service has no separate speech-recognition stage. The audio is sent directly to the generative AI model, which transcribes it and composes the reply in a single operation.
- Usage Information
- Daily conversation counts (used to enforce the per-plan usage limit)
- IP address (used for abuse prevention and rate limiting)
- Device information (OS, browser, model, etc.)
- Server-side access logs and error logs
- Payment Information
Payment processing is handled by the third-party payment processor Stripe, Inc. (USA). The Company does not directly collect or store sensitive payment information such as credit card numbers. The Company only acquires the customer identifier issued by Stripe and information related to subscription status.
- Contact Enquiry Information
If you use the contact form on the Company's website, we collect your name, email address, subject, and the content of your enquiry.
Article 5 (Purpose of Use)
The Company uses the collected personal information only for the following purposes. If the information is to be used beyond the scope of these purposes, the Guardian's prior consent will be obtained.
- Providing and operating the Service (including transcription, AI response generation, and speech synthesis)
- User authentication and account management
- Enforcing the per-plan daily conversation limit
- Displaying conversation history to the Guardian (Premium plan)
- Maintaining and improving service quality (based on statistical, anonymized analysis)
- Preventing fraudulent use and ensuring security
- Responding to user inquiries and providing customer support
- Fulfilling legal obligations and exercising rights
- Billing and payment management
Article 6 (Legal Basis for Processing: GDPR Art. 6 & 9)
The processing of personal data for EU/EEA residents is based on the following legal grounds:
| Purpose of Processing | Legal Basis (GDPR Article) | Basis Details |
|---|---|---|
| Service Provision & Operation | Art. 6(1)(b) | Performance of a contract |
| Child's Voice Data Processing | Art. 6(1)(a) & Art. 8 | Consent from Guardian |
| Fraud Prevention & Security | Art. 6(1)(f) | Legitimate interests |
| Legal Compliance | Art. 6(1)(c) | Compliance with a legal obligation |
| Quality Improvement (anonymized) | Art. 6(1)(f) | Legitimate interests |
Article 7 (Special Handling of Voice Data)
Voice data, being particularly sensitive information within the Service, is handled strictly as follows:
- Recording Length Limit: Each recording is capped at 10 seconds. The Service does not perform long or continuous recording.
- Direct Processing: Voice data is sent directly to a generative AI service on Google Cloud without passing through a separate speech-recognition service; transcription and reply generation happen in a single operation. The resulting reply text is then converted to audio by a speech-synthesis service on the same platform.
- Principle of Non-Storage: The Company's API server is stateless. Received audio is held in working memory only for as long as it takes to generate the reply, and is never written to disk, object storage, or a database. The synthesised reply audio is likewise not stored.
- Processing Location: AI response generation and speech synthesis are performed on servers located in Japan (Tokyo).
- Not Used for Model Training: The Company uses Google Cloud under enterprise terms, and children's voice and conversation data are not used to train Google's generative AI models.
- Explicit Third-Party Transmission: Voice data is sent to Google Cloud for AI processing. Appropriate Data Processing Addendums (DPAs) are in place with such third parties.
- Storage of Conversation Text: The transcribed text and the reply text are stored as conversation history within the Guardian's own dedicated area of the database. Access is restricted to that account by database security rules. Viewing this history inside the app is a Premium plan feature; regardless of plan, Guardians may request disclosure under Article 13.
- Prohibition of Use for Other Purposes: Voice and conversation data are not used for purposes other than generating AI responses and displaying history to the Guardian (e.g., selling to third parties, ad targeting).
Article 8 (Handling of Children's Personal Information: COPPA Compliance)
As the Service is primarily targeted at children under 13, it complies with the requirements of the U.S. Children's Online Privacy Protection Act (COPPA).
- Verifiable Parental Consent
The Company obtains explicit consent from the Guardian before collecting or processing personal information from a child under 13. Consent is obtained when the Guardian personally creates an account using an email address and password and agrees to this Policy and the Terms & Conditions at that point. The Service does not permit anonymous conversations; every conversation is recorded against the Guardian's account. Consent may be withdrawn by deleting the account within the app or by contacting the address in Article 18.
- Guardian's Rights
Guardians can exercise the following rights regarding their child's personal information:
- Request access to the child's collected personal information.
- Request correction or completion of the child's personal information.
- Request deletion of the child's personal information.
- Request to stop further collection or use of the information.
To exercise these rights, please send a written request (including electronic methods) to the DPO at info@kidtalkapp.com. The Company will respond within a reasonable period after verifying your identity.
- Minimum Necessary Collection
The Company collects only the personal information necessary to provide the Service (principle of data minimization). The only information required about a child is a nickname and an age band; the Company never asks for directly identifying information such as a full name, photograph, or address.
Article 9 (Provision to Third Parties)
The Company does not provide personal information to third parties, except in the following cases:
- To Service Providers: When outsourcing necessary operations for the Service (e.g., cloud computing, payment processing), information is provided to the minimum extent necessary. Contracts concerning the protection of personal information are concluded with these providers.
- Based on Legal Requirements: When requested by courts, investigative bodies, or other public institutions based on laws and regulations.
- With Guardian's Consent: When explicit prior consent is obtained from the Guardian.
- Business Succession: In the event of a business transfer through merger, company split, or other reasons (limited to cases where protection equivalent to this Policy is ensured by the successor).
Key data processors include:
- Google LLC / Google Cloud Japan (cloud services): AI response generation, speech synthesis, application hosting, user authentication, database, usage analytics (Google Analytics), abuse prevention (reCAPTCHA), and delivery of contact-form email
- Stripe, Inc. (USA): Payment processing and subscription management
A current list of our processors, including the individual services used, is available on request from the contact point in Article 18.
Article 10 (International Data Transfer)
The core processing of the Service — AI response generation, speech synthesis, and the hosting of the API server and application — is performed on servers located in Japan (Tokyo). However, cloud services such as user authentication, the database, and usage analytics, together with payment processing by Stripe, Inc. (USA), may involve servers and processors located outside Japan. The Company takes the following protective measures for such international data transfers:
- For EU/EEA Residents: Conclusion of Standard Contractual Clauses (SCCs) as defined by the European Commission.
- For UK Residents: Conclusion of the International Data Transfer Agreement (IDTA) approved by the UK ICO.
- For Other Regions: Fulfilling procedures for providing data to third parties in foreign countries based on the APPI.
Google Cloud and Stripe, which we use, have obtained security certifications (e.g., ISO 27001) applicable to such international transfers, ensuring an adequate level of protection.
Article 11 (Data Retention Period)
The Company retains personal information only for the period necessary to achieve the purpose of use. The main data retention periods are as follows:
| Data Type | Retention Period | Notes |
|---|---|---|
| Original Voice Data | Not stored (held in memory during processing only) | Never written to disk or storage |
| Conversation History (transcript and reply text) | During the service usage period | Deleted immediately on account deletion |
| Account Information and Child Profiles | During the service usage period | Deleted immediately when the Guardian deletes the account in the app (residual copies in backups for up to 30 days) |
| Daily Conversation Counts | During the service usage period | Deleted immediately on account deletion |
| Server Logs (access and error) | Up to 90 days | For security and quality purposes |
| Contact Enquiries | As long as needed to resolve the enquiry | May be retained for a period as a record of the exchange |
| Payment Records | Period required by law (generally 7 years) | For tax and accounting laws |
Article 12 (Security Management Measures)
The Company takes the following measures to prevent leakage, loss, or damage of personal information and to otherwise manage its security:
- Technical Security Measures
- Encryption of communications (TLS 1.2 or higher)
- Encryption of stored data (Google Cloud default encryption, AES-256 equivalent)
- Database security rules restricting access so that each user can reach only the data under their own account
- Recording and monitoring of access logs
- Monitoring of vulnerability advisories and updating of dependencies
- Organizational Security Measures
- Access control based on the principle of least privilege
- Regular education and training for personnel handling personal information
- Establishment and operation of personal information handling regulations
- Maintenance of an Incident Response Plan
- Physical Security Measures
- The Company operates no server hardware of its own; data is stored and processed in Google Cloud data centres. Physical security, including data centre access control, is provided by Google under certifications such as ISO/IEC 27001.
- Appropriate management and disposal of company devices and recording media
In the event of a security incident, the Company will notify the supervisory authorities and affected data subjects within the period prescribed by applicable law.
Article 13 (User Rights)
Guardians (and data subjects of children they represent if residing in the EU/EEA) have the following rights:
| Right | Description | Legal Basis |
|---|---|---|
| Right of Access | Request access to your personal data. | GDPR Art. 15 / APPI / CCPA |
| Right to Rectification | Request correction of inaccurate data. | GDPR Art. 16 / APPI |
| Right to Erasure ('Right to be Forgotten') | Request deletion of your personal data. | GDPR Art. 17 / APPI / COPPA |
| Right to Restrict Processing | Request the restriction of certain processing. | GDPR Art. 18 |
| Right to Data Portability | Request data in a structured, commonly used format. | GDPR Art. 20 / CCPA |
| Right to Object | Object to processing based on legitimate interests. | GDPR Art. 21 |
| Right to Withdraw Consent | Withdraw consent at any time for processing based on consent. | GDPR Art. 7(3) / APPI |
To exercise these rights, please contact the DPO at info@kidtalkapp.com. We will respond within 30 days (extendable to 60 days for valid reasons). EU/EEA residents also have the right to lodge a complaint with a supervisory authority.
Article 14 (Management of Guardian Consent)
To start using the Service, Guardians must provide explicit consent for the following:
- The collection of the child's voice data and its use for AI processing.
- Transmission to cloud services (like Google Cloud) necessary for providing the Service.
- The use of AI technologies (such as large language models) employed by the Service.
- The entire content of this Policy.
Consent can be withdrawn by the Guardian at any time. Withdrawal of consent may affect the future use of the Service. To withdraw consent, please contact the DPO at info@kidtalkapp.com.
Article 15 (Cookies and Other Tracking Technologies)
The Service may use cookies and other tracking technologies ("Cookies") for the following purposes:
- Session management and maintaining login status (essential; includes browser storage used by the authentication layer).
- Analyzing service usage (Google Analytics).
- Detecting and preventing unauthorized access (reCAPTCHA on the contact form).
We do not use cookies for advertising purposes or third-party behavioral tracking. You can change your cookie settings from your device's browser settings, and you can disable Google Analytics measurement using the opt-out browser add-on provided by Google. However, disabling essential cookies may prevent some features of the Service from functioning.
Article 16 (Policy Revision)
The Company may revise this Policy due to changes in laws, services, or other reasons. For significant changes, we will notify you of the changes and their effective date in advance through a notice within the Service or by email (generally 30 days prior to the effective date).
Your continued use of the Service after the effective date of the revised Policy will constitute your agreement to the revised Policy. For significant changes, we may ask for the Guardian's re-consent.
Revision of August 22, 2026: This Policy was updated to match the current system architecture. The main changes concern the handling of voice data following the removal of the separate speech-recognition stage (Articles 4 and 7), where data is processed (Article 10), retention periods and what happens on account deletion (Article 11), the list of data processors (Article 9), and the description of security measures (Article 12).
Article 17 (Governing Law and Jurisdiction)
The interpretation and application of this Policy shall be governed by the laws of Japan. Disputes concerning this Policy shall be subject to the jurisdiction of the courts of Japan. However, if GDPR or other mandatory laws apply, they shall be followed.
Article 18 (Contact Information)
For questions about this Policy, consultations about the handling of personal information, or to exercise your rights, please contact the following:
- Operator: New Summer Inc., 3F, Navi Shibuya V, 5-5, Maruyama-cho, Shibuya City, Tokyo, Japan
- Data Protection Officer (DPO): info@kidtalkapp.com
- Supported Languages: Japanese, English
- Business Hours: Weekdays 9:00 AM - 6:00 PM JST
- Response Target: In principle, within 30 days
End
New Summer Inc.
Date of Enactment: May 5, 2026
Date of Last Revision: August 22, 2026