Privacy Policy
Last updated: October 11, 2026
Article 1 (Introduction)
Synfortech (“we”) handles users’ information in “AnsGrape” (including its Chrome and Edge extensions, website and API; the “Service”) in accordance with this policy.
This policy explains in plain terms what information we handle, why, who it is passed to, and how long we keep it.
Article 2 (Information we collect)
The Service collects and stores the following.
- Account information: your email address. If you log in with Google or Apple, the identifier and email address those companies provide. The date and version of the terms you accepted. Your current plan.
- Login information: when you logged in, how (email code or link, passkey, Google, Apple), where (web or extension), the type of browser and OS, and when you last used it. For passkeys we store only the public key, an identifier, a device name (browser and OS type), and when it was created and last used. The private key never leaves your device and we do not have it.
- What you enter or capture: your questions to Ask AI and the answers, files you attach, and problems you capture with the extension and others (selected text, or an image of the area you outline) with the answer, explanation, subject, confidence and time taken.
- Note content: the name of the note, material you add (pasted text, text and page numbers extracted from files or URLs), transcripts of recordings (with times), memos, photos and “important” / “lost here” marks, summaries and key terms, and your questions and the answers in the note. Text and photos are encrypted when stored.
- Recorded audio: when storage is available, we store the audio of your note recordings and the audio files you upload (there is no setting; it is always stored). Each audio file is encrypted with its own key and placed in external object storage. Using your microphone requires your browser’s permission.
- Feedback: the “good” or “bad” rating you give an answer, and the question and answer you rated. Rating is an action that shares that question and answer with us to improve the service.
- Your “Help improve the service” setting: on or off, and when you turned it on. It is off by default. Only while it is on, we keep a record of which features interest you (for example, opening a “coming soon” feature page or pressing a feature you can’t use yet) — who, which feature and when only, with no content.
- Usage counts: your daily usage count and monthly Genius count, which are needed to manage plans.
- Note usage and storage: the monthly count of note AI checks (summaries, questions and so on) and the amount of stored audio. We need this record to manage per-plan limits.
- Phone number: to prevent abuse, after you log in we ask you to confirm your phone number (an SMS code). We store only an irreversible keyed hash of it, the line type (mobile, landline and so on) and the country calling code (81 for Japan) — not the number itself. A phone number can be used by one account only. To limit repeated attempts we keep, for 30 days, hashes of the IP address, device identifier and phone number together with the time of each attempt.
- Contact messages: what you enter in the contact form — your name, email address, country or region, reason and message. If you are logged in, we attach your account ID, registered email address and plan.
- Subscription and purchase information: when you buy a paid plan or Drops — the state of your subscription (plan, period, renewal date, whether a free trial was used), payment history (amount and date), customer and subscription identifiers from the payment provider, and an identifier of the card (not the card number) so a free trial cannot be used twice.
- Date of birth: to confirm your age, after phone confirmation we ask you to enter your year, month and day (the fields start empty). We store the date you enter and the version of the notice we showed, encrypted. You cannot change it yourself (if it is wrong, contact us and our staff will check and correct it). If you are under 13 you cannot register, and we discard what you entered and the account. We use it only to confirm your age and to limit purchases and ask for a guardian’s confirmation for users under 18 — never for advertising.
- Guardian’s email address: when a user under 18 makes a purchase above a certain amount, the email address entered for the guardian’s confirmation. We use it only to send the confirmation email and record the result. It is stored encrypted and not used for any other purpose.
- Purchase confirmation records (evidence): at the time of a purchase of a paid plan or Drops — the age class and date of birth, the consent record (version and time), the guardian’s confirmation result, the 3-D Secure result, and the item, amount and time. We use it to check payment disputes (chargebacks) and refunds.
- Drops and reward records: the history and balance of Drops granted, spent and expired, and records such as login streaks and friend invitations.
- Invitation anti-abuse records: when you enter a friend-invitation code, the country determined from the IP address you are connecting from (the country code only — the IP address itself is not stored), the country determined from your device’s time zone, and the result of checking whether many sign-ups are bunched together in a short time. We may not grant the reward (Drops) for an invitation that looks suspicious. If you do not understand why a reward was not granted, please contact us at the address in Article 17.
- Promo code usage records: which code was used and when, and the Drops or free plan period it gave (to prevent a code being reused and to count how campaigns are used).
- AI usage records: for each request, the model used, the amount processed (tokens), an estimate of the cost, the time, and an identifier of the conversation or answer it belongs to (so we can understand usage per answer). They do not include the content of questions or answers. When you delete a conversation or history item, the link to it is removed. They are not shown in your screens.
- Storage for reusing answers: to answer the same question quickly we store a lookup value made from the question and its answer. It is not linked to your account.
- Technical information: server access logs (IP address, time, the URL requested, browser type and so on). We use them to prevent abuse and investigate failures, and delete them automatically after about two weeks.
Article 3 (Information we do not collect)
We do not collect or store the following.
- The URL or title of the pages you browse, or your browsing history. The extension reads page content on your device to show its icon and to capture the area you choose, but never sends the URL or title (or anything else about the page) to our servers.
- Your location (such as GPS), contacts or advertising ID. The extension also does not read what is typed into password fields.
- Credit card numbers. When you buy a paid plan or Drops, our payment provider (Stripe) receives them directly; they do not pass through our servers and we do not store them.
The extension sends selected text or images only when you act (the selection menu, a shortcut, outlining an area, asking from the address bar and so on). If you turn on “real-time” mode, it sends text each time you select it (it is off by default). If you turn on “Show AI search on Google”, it sends your search words only when you press the AnsGrape card shown on Google search pages (it is off by default, and the page URL is not sent).
Article 4 (How we use information)
We use the information we collect for the following purposes.
- Logging you in, verifying who you are and managing your account
- Preventing abuse by confirming your phone number (including making sure one phone number is not used by several accounts)
- Confirming your age from your date of birth, and limiting purchases by users under 18 (including purchase limits and a guardian’s consent and confirmation)
- Preventing abuse of friend invitations (including checking whether sign-ups are bunched together in a short time, and whether the country you connect from clearly conflicts with your device’s time zone or phone country)
- Handling payments and managing subscriptions for paid plans and Drops, and the related emails (before a free trial ends, notice of the amount before renewal, receipts and so on)
- Providing answers, explanations and chat (including sending content to an external AI — see Article 7)
- Showing and keeping your history, and managing usage counts and plans
- Preventing and investigating abuse and violations of the terms, and keeping the Service safe
- Responding to inquiries (support) and sending important notices
- Improving the accuracy of answers and the quality of the Service — limited to ratings you give (feedback) and the content and usage of users who turned on “Help improve the service” (Article 6)
- Complying with laws and regulations
We do not use it to serve advertising. We also do not use your content to train AI models ourselves, and we do not sell it to third parties.
Article 5 (When our staff may read your content)
Our operations staff read your questions, answers, captured content and history only in the following cases, and for no other purpose.
| Situation | What may be read | Conditions |
|---|---|---|
| You rate an answer (good or bad) | The question and answer you rated | Rating is what sends the feedback. If you don’t rate, we don’t read it. |
| “Help improve the service” is on | Chats and answers created after you turned it on | Off by default. You can turn it off at any time, and from that moment we can no longer read it. |
| You ask us for support | Content related to your request | Only when you have asked. |
| Investigating abuse or security issues | Content needed for the investigation | We record the reason and read only what is necessary. |
| Complying with the law | Content needed to comply | We record the reason and read only what is necessary. |
Only staff we have authorized can read it. We record when, who, which content and for what reason.
These conditions do not apply to aggregated figures that cannot identify you (such as counts of usage or ratings).
Article 6 (Feedback and helping improve the service)
Rating answers (good or bad) and “Help improve the service” are ways to make answers more accurate and the Service better.
- Rating (feedback): when you rate an answer, the question and answer you rated are shared with us. If you clear a rating, we no longer read it from then on.
- Help improve the service: you can turn it on or off at any time in your account settings. It is off by default. While it is on, (1) we keep a record of which features interest you and (2) our staff may read chats and answers created after you turned it on to improve the service. When you turn it off, they stop being collected or read from that moment.
- Neither is used to train AI models, for advertising, or sold to third parties.
Even when we read content to improve the service, only staff we have authorized can do so, and we keep a record.
Article 7 (AI providers and other external services)
To generate answers, we send your questions, captured problems and the content of attached files to a company that provides an external AI model. Answers are generated by one AI provider in the United States and double-checked by a second AI provider, also in the United States. We may change providers based on accuracy, speed and cost; if the country where your data is processed changes, we will add it to this policy.
Only when you turn on “Web search” (the globe icon), search terms based on your question are passed through the AI provider’s web search feature to an external search service, to look up current information. When it is off (the default), nothing is searched.
We send content to AI providers through their API under terms and settings that keep it from being used to train their models. Content shared through ratings or “Help improve the service” (Article 6) is not handed to AI providers for training either.
To keep answers accurate and fast, an answer that a second AI has confirmed may be reused for other users who ask the same problem. We store only a one-way scrambled value of the problem (it cannot be turned back into your text) together with the answer and explanation, and nothing that links it to the person who asked. Questions with images and very long texts (over 2,000 characters) are not included. An entry is deleted 90 days after it was last used, and when an answer gets a 👎 it is removed from reuse.
For notes, to create summaries, answer questions about a note and handle “Called on!”, we send the relevant passages of that note and the most recent transcript to the same AI providers. Answers to note questions may also be checked against their evidence by a second AI provider (the one that double-checks answers, in the United States), in which case the answer and the evidence passages are sent too. The recorded audio itself is never sent to an AI provider (only when you transcribe an audio file with “Upload audio” is that file’s audio sent, for transcription, to the same United States provider that double-checks answers).
When you use your browser’s speech recognition (the Web Speech API), depending on the browser the audio may be sent to the browser’s provider (for example Google for Chrome, Apple for Safari) to be turned into text. That processing is done by the browser’s provider, not by us. In browsers that can recognize speech entirely on the device, it is processed on the device.
The Service uses the following external services. These companies handle information on our behalf and within our instructions.
| Provider | Information passed | Purpose | Country |
|---|---|---|---|
| Cloudflare, Inc. | Traffic to the website and API (including its content), IP address; encrypted recorded audio files when audio saving is available | Relaying and protecting traffic (DNS, CDN, attack protection), and storing recorded audio | United States and other locations worldwide |
| Resend (Resend, Inc.) | The recipient address and body (code or link) of login emails and guardian confirmation emails | Sending login emails and guardian confirmation emails | United States |
| External AI model providers (two) | Questions, captured problems and the content of attached files (one provider generates the answer; the other double-checks it) | Generating answers and explanations, and double-checking answers | United States |
| Google LLC, Apple Inc. (coming soon) | The identifier and email address they provide | Verifying you for “Log in with Google / Apple” | United States |
| Stripe (Stripe, Inc.) | Email address and what you bought (plan, amount). Card details are entered by you directly on Stripe’s page and never reach us | Payments for paid plans and Drops, and managing subscriptions | United States and other locations |
| Twilio Inc. | Your phone number (to send the confirmation SMS and check the line type; we do not keep the number after confirmation) | Confirming your phone number (SMS) and detecting internet-phone numbers | United States and other locations |
Because these companies are outside Japan, your information may be processed outside Japan.
Article 8 (Disclosure to third parties)
We do not provide your personal information to third parties without your consent, except:
- When required by law
- When necessary to protect a person’s life, body or property and it is difficult to obtain your consent
- When especially necessary to improve public health or to foster the sound growth of children and it is difficult to obtain your consent
- When we must cooperate with a government body or local authority carrying out duties set by law, and obtaining your consent would hinder those duties
Providing information to the companies in Article 7 is not disclosure to a third party. If our business is transferred, the successor will handle information in accordance with this policy.
Article 9 (Cookies and browser storage)
The Service does not use cookies or scripts for advertising or for tracking your behavior through analytics. It stores the following in your browser.
- A cookie that keeps you logged in (ag_session). It is deleted when you log out, and lasts at most 30 days.
- Your language and appearance choices, the state of the Genius switch, and temporary information during login (the browser’s localStorage and sessionStorage). Also a random identifier per device (ag_device) used only to limit repeated phone-confirmation attempts.
- A temporary copy of a question you typed on the top page, carried through login (it expires after 30 minutes and is removed once used).
- What the extension stores: your login information (token), settings, icon position, and the host names of sites you hid it on (on your device only).
Article 10 (Retention and deletion)
- Chat and solve history, attachments and ratings: kept until you delete them or delete your account. You can delete history one item at a time or all at once. If you continue a solved problem as a chat, the problem and answer (including its image) are also copied into your chat history; you can delete that copy separately from the chat.
- Notes (material, transcripts, memos, photos, summaries and the note chat): kept until you delete the note or delete your account. There is no cap on the number of notes or the amount of text.
- Recorded audio: there is no retention period. The stored audio file is deleted when you delete the note, delete only the audio, or delete your account (if a deletion fails, it is retried until it succeeds). The amount you can store has a per-plan limit.
- Records of which features interest you, and your “Help improve the service” setting: kept until you delete your account. When you turn the setting off, we stop recording from then on.
- Feedback when you leave (your reason and free-text comment): saved only if you send it, and not linked to your email address or any account. Please do not write personal information.
- Phone confirmation: the keyed hash, line type and country calling code are kept until you delete your account. The records of confirmation attempts (hashes of IP address, device identifier and phone number, and the time) are deleted after 30 days.
- Invitation anti-abuse records (country codes and the result of the check): kept together with the invitation record and deleted when you delete your account.
- Contact messages: deleted one year after we finish handling them (open ones are kept until handled). Your name, email address and message are stored encrypted. When you delete your account, the link to the account and the account details attached to the message (registered email address and plan) are erased.
- Subscription and purchase records: when you delete your account, your Stripe subscription is cancelled immediately and your customer information at Stripe is deleted. Payment records (amount and date) that remain with us and Stripe are kept, not linked to the account, for the period required by accounting and tax law.
- Date of birth and purchase confirmation records (evidence): stored encrypted until you delete your account, and erased when you do (only the amount and date of payments remain, not linked to the account). If you could not register because you are under 13, we discard what you entered immediately.
- Guardian’s email address: deleted 90 days after the guardian’s confirmation is decided (approved, declined or expired). The confirmation link can be used only once and expires after 24 hours.
- Free-trial usage records: to stop one person using a trial repeatedly we keep the phone-number hash, card identifier and dates for up to 3 years, even after you delete your account.
- AI usage records (model used, amount processed, estimated cost): deleted after about 13 months (400 days). They do not include the content of questions or answers. When you delete your account, the link to the account is removed.
- Storage for reusing answers: deleted 90 days after it was last used. It is not linked to any account.
- Drops, usage counts, rewards and invitation records: all deleted when you delete your account.
- Promo codes: codes we hand out when you leave are stored only as a keyed hash and are not linked to any account. Codes we issue ourselves are stored as a keyed hash for lookup and also encrypted so that our staff can manage them. When a code is used, Drops or a free period on a plan is added to that account, and we record which account used it and when. We can stop a code immediately. Deleting your account deletes its usage records and free plan periods.
- Deleting your account: you can do this at any time from “Account” in the app. It deletes all data tied to the account — login information, passkeys, history, attachments, ratings, usage counts, interest records and settings.
- Login state: the web lasts at most 30 days and the extension at most 90 days. Logging out ends that device immediately. Login codes expire after 10 minutes and a login attempt after 15 minutes.
- Server access logs: deleted automatically after about two weeks.
- Records of staff actions: who read or changed which user’s content, when and for what reason, without the content itself. We keep them, even after you delete your account, to prevent abuse and for accountability.
If you don’t know how to delete something, or you can’t log in to your account, contact us at the address in Article 17.
Article 11 (Security)
To prevent leaks and unauthorized access we take measures such as the following.
- Traffic is encrypted (HTTPS).
- Personal and confidential information is encrypted (AES-256-GCM) when stored in the database. This covers login email addresses, the content of chats and solutions, attachments and their names, the name, email address and message in contact messages, feedback when you leave, and so on. The encryption keys are kept separately from the database, so if the database alone were leaked the content could not be read.
- Phone numbers are not encrypted but stored only as an irreversible keyed hash (the original number is not kept).
- Secret values used to log in (session tokens, login codes) are not stored as they are; we store only values used to check them.
- For passkeys we store only the public key.
- In the staff console, content that does not meet the conditions in Article 5 is not shown, and reading it requires a reason and a record. Viewing and actions are limited to people we have authorized and are recorded.
- Login attempts and emails sent are rate-limited.
- When we entrust information to an outside company, we check that it is handled appropriately.
However, no transmission or storage over the internet can be guaranteed to be completely secure.
Article 12 (Your rights)
You may ask us to disclose, correct, add to or delete the personal information we hold about you, or to stop using or erase it. You can do the following yourself in the app.
- Delete history (one item or all)
- Turn “Help improve the service” on or off
- Add or remove login methods (email, Google, Apple), and add or delete passkeys
- Delete your account (deletes all your data)
For any other request, contact us at the address in Article 17. After confirming it is you, we will respond without delay in accordance with the law.
Article 13 (How the extension handles information)
Information handled by the extension distributed through the Chrome Web Store and Edge Add-ons is used only to provide and improve the features visible to you (providing answers). We do not use it for advertising, sell it to third parties, or use it to determine creditworthiness or for lending. This follows the Chrome Web Store User Data Policy, including the Limited Use requirements.
People read it only in one of the following cases.
- You have clearly agreed (by sending a rating, turning on “Help improve the service”, or asking for support)
- It is necessary to investigate abuse or security issues
- It is necessary to comply with the law
- It is aggregated so that it cannot identify you and used for internal operations
Article 14 (Extension permissions and what they are for)
The permissions the extension needs and what they are used for:
- Running on all sites (the on-page icon and selection menu): capturing the text you select and showing the answer. You can hide it on a per-site basis.
- Capturing an image of the visible tab (outline to solve): only when you act, it temporarily captures the visible tab and sends only the area you chose.
- Storage: keeps your login information and settings on this device.
- Login authentication (identity): opens the login screen and receives the result.
- Side panel and right-click menu: showing answers and acting on selected text.
Article 15 (Minors)
If you are under 18, please use the Service with the consent of a parent or guardian.
Article 16 (Changes)
We may change this policy. We will announce important changes on the Service. The revised policy applies from the time it is posted on this page.
Article 17 (Contact)
For questions about this policy or how we handle personal information, and for requests under Article 12, contact:
Synfortech “AnsGrape” privacy contact: [email protected]
Operator: Synfortech (person responsible: Keisuke Kanda)
Address: Kabutocho Dai-6 Hayama Bldg. 4F, 17-2 Nihonbashi Kabutocho, Chuo-ku, Tokyo 103-0026, Japan
If you need our telephone number to make a request, we will provide it on request, without delay.