プライバシーポリシー

制定日:2026年10月9日 / English version

masc-harness 運営事務局(以下「運営者」)は、企業向け Web アプリ「masc-harness」(以下「本サービス」)と、このサイトで扱う個人の情報を、次のとおり取り扱います。

1. 対象

このポリシーは、本サービスを使う契約企業のスタッフ(以下「利用者」)の情報と、このサイトを見た方の情報を対象にします。

契約企業が本サービスに登録する顧客・見込み客の情報は、運営者が契約企業から預かって扱うものです。その扱いは、契約企業との契約と、契約企業のプライバシーポリシーに従います。

2. 受け取る情報

このサイト(masc-harness.com)は、運営者が独自に設定した Cookie やアクセス解析を使っていません。サイトは Cloudflare 社のサーバーから配信しており、配信のために閲覧者の IP アドレスなどが Cloudflare 社に届きます。

3. 使う目的

4. Google・Microsoft のカレンダーとの連携

利用者が設定画面で「連携する」を選び、Google または Microsoft の画面で許可したときだけ、次のことを行います。

Google から受け取る許可は、ログインの確認(openid)、メールアドレス(userinfo.email)、本サービスが作ったカレンダーだけを扱う権限(calendar.app.created)の 3 つです。Microsoft から受け取る許可は、openid・email・offline_access・Calendars.ReadWrite の 4 つです。Calendars.ReadWrite はカレンダー全体に及ぶ権限ですが、本サービスは、作ったカレンダーとその中の予定にだけ使います。

Google のユーザーデータの扱い:本サービスが Google API から受け取った情報の使用と他のアプリへの転送は、Limited Use(限定使用)の要件を含む Google API Services User Data Policy に従います。

Google・Microsoft から受け取った情報は、カレンダー連携の提供・管理と、その安全のためだけに使います。売ったり、広告に使ったり、AI のモデルの学習に使ったりしません。本サービスを動かすためのサーバー(Cloudflare 社)に保存することを除き、第三者に渡しません。人が読むのは、利用者が読む対象を特定してはっきり同意した場合、安全上の問題(不正な使い方など)を調べるのに必要な場合、法令を守るために必要な場合だけです。

契約企業の管理者は、設定画面で、各スタッフの連携の状態(連携した Google・Microsoft アカウントのメールアドレス、つながっているか、最後に同期した時刻など)を見られます。外のカレンダーの中身は、本サービスが読まないため、管理者にも見えません。

5. 保存と安全管理

6. 第三者への提供

法令で認められた場合を除き、本人の同意なく第三者に渡しません。Google から受け取った情報は、さらに 4 の Limited Use の決まりの範囲でだけ扱います。本サービスを動かすために、Cloudflare 社(サーバー)と、利用者が連携を選んだ場合の Google 社・Microsoft 社(カレンダー)を使います。

7. 連携を外すとき・情報を消すとき

8. 開示・訂正・削除のご依頼とお問い合わせ

ご自身の情報の開示・訂正・利用停止・削除のご依頼、このポリシーへのお問い合わせは、下記までご連絡ください。ご本人であることを確かめたうえで、すみやかに対応します。

運営
masc-harness 運営事務局 菅 泰志
所在地
北海道札幌市豊平区
メール
nanc.taishikan@gmail.com

9. 改定

このポリシーを変えるときは、このページで知らせます。大きな変更は、本サービスの画面でもお知らせします。

Privacy Policy (English)

Effective: October 9, 2026

The masc-harness office (“we”) operates masc-harness, a business web application used only by staff of contracted companies (“users”). This policy explains how we handle personal information. Customer and lead data that a contracted company enters into masc-harness is processed on behalf of that company under its contract and its own privacy policy.

Information we collect

  • User account information: name, email address, role, and sign-in and activity logs.
  • Calendar sync (only when a user connects): the email address and account ID of the connected Google or Microsoft account, OAuth tokens, granted scopes, the IDs of the calendar and events created by masc-harness, the times of the events written and their mapping to masc-harness appointments, and sync status (processing times and errors).
  • Activity records: connecting, reconnecting and disconnecting (for security).

This website (masc-harness.com) does not set its own cookies or use analytics. It is served by Cloudflare, which receives visitors' IP addresses and similar data to deliver the pages.

How we use information

  • To provide masc-harness and verify signed-in users.
  • To write a user's appointments to Google or Microsoft calendars when the user chooses to connect.
  • To prevent misuse and investigate failures.
  • To respond to inquiries.

Google and Microsoft calendar sync

Only when a user chooses to connect and grants permission, masc-harness creates one secondary calendar named “masc-harness” in the user's account and writes the user's assigned appointments into it. Each event is titled 予定あり (Japanese for “Busy”); the original title, location, notes and attendee names are not written. What is written: date and time (or all-day), the 予定あり title, a fixed notice with a link to that day in masc-harness, the free/busy/out-of-office and private flags, and an identifier used for syncing.

Sync is one-way, from masc-harness to the external calendar, and covers appointments from 14 days before to 120 days after today by default (adjustable by an administrator). Events that drop out of the range on the past side as time passes are left as they are. If an administrator shortens the future side of the range, or an appointment is moved beyond it, events that fall outside it are deleted. When an appointment changes or is removed, masc-harness updates or deletes only the events it created. masc-harness does not read the contents of any other calendars or events, or any mail or contacts. On Microsoft, to find the calendar and events it created, masc-harness retrieves only the IDs of items carrying its own identifier.

Google scopes: openid, userinfo.email and calendar.app.created. Microsoft permissions: openid, email, offline_access and Calendars.ReadWrite. Although Calendars.ReadWrite covers all of the user's calendars, masc-harness uses it only for the calendar it created and the events in it.

masc-harness's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data received from Google or Microsoft is used only to provide and manage the calendar sync described above and to keep it secure. We do not sell it, use it for advertising, or use it to train AI models, and we do not transfer it to third parties other than storing it on the servers that run the service (Cloudflare). Humans do not read it unless the user has given explicit consent for specific data, it is necessary for security purposes (such as investigating abuse), or it is necessary to comply with applicable law.

Administrators of the contracted company can see each staff member's connection status in the settings screen (the connected Google or Microsoft email address, whether it is connected, and the last sync time). The contents of external calendars are not visible to administrators, because masc-harness does not read them.

Storage and security

Data is stored on Cloudflare servers, which may be located outside Japan. OAuth tokens are encrypted at rest. Access to masc-harness is limited to staff authorized by the contracted company, with per-role access controls. We may keep backups for recovery; tokens remain encrypted in them.

Sharing

We do not share personal information with third parties without consent, except as permitted by law. We use Cloudflare (hosting) and, when a user connects, Google and Microsoft (calendar). Data received from Google is further limited by the Limited Use requirements above.

Disconnecting and deletion

Users can disconnect at any time from the settings screen. When disconnection completes, we delete the connected account information, tokens and event mapping. If external clean-up temporarily fails, it is retried automatically and the tokens are kept only until it finishes. For Google we also attempt to revoke the grant; you can always revoke it yourself as described below. The user chooses whether to keep or remove the “masc-harness” calendar: removing it also deletes any events the user added to it; a kept calendar is no longer updated or cleaned up by masc-harness and is managed by the user. If a calendar chosen for removal remains because of an external error, please delete it in Google Calendar or Outlook. Activity records of connecting and disconnecting and records of data-erasure processing are kept for security and verification until the contract with the company ends. Temporary sign-in data is deleted by a scheduled job one day after it expires. Revoking access only on the Google or Microsoft side does not delete the data held by masc-harness (the connection shows as needing sign-in again); disconnect in masc-harness or contact us to delete it. Access can also be revoked from Google Account permissions or Microsoft account app permissions (work accounts: My Apps). To request deletion of your data, contact us at the address below; after verifying your identity we delete it promptly (except the activity records above). Copies in recovery backups are removed as the backups are replaced.

Contact

masc-harness office (Taishi Kan), Sapporo, Hokkaido, Japan — nanc.taishikan@gmail.com

We will post any changes to this policy on this page.