mykura
Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how Initial S, Inc. (“Initial S,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects information when you use mykura, Kura-chan, a MeCloud device, KuraClaw software, our websites, and related services (collectively, the “Service”).
Contents
- Scope and Processing Overview
- Core Service Processing
- Communication-Channel Processing
- Connected-Service Processing
- AI Processing and Provider Choice
- How We Use Information
- Storage and Retention
- How We Disclose Information
- International Data Transfers
- Security
- Your Choices and Rights
- Children's Privacy
- Changes to This Policy
- Contact Us
1. Scope and Processing Overview
The Service combines software running on your MeCloud device with cloud services and third-party services. Some information remains on your device, while other information is transmitted to cloud infrastructure or a service provider when needed for the feature you use.
This Policy groups processing by the function that causes it:
| Processing category | When it applies | Principal destinations |
|---|---|---|
| Core Service processing | When you register, connect a device, maintain a subscription, use cloud infrastructure, request support, or operate the Service | MeCloud, Initial S, AWS, Stripe, Resend, and other operational providers |
| Communication-channel processing | When you communicate with Kura-chan through LINE, Slack, Telegram, WeChat/Weixin, or another channel | The channel provider, MeCloud, and, for LINE, Initial S’s AWS environment |
| Connected-service processing | When you authorize Google, Microsoft, GitHub, or another supported service | The connected service, MeCloud, and Initial S’s AWS authorization infrastructure |
| AI processing | When you use conversations, search, recognition, extraction, transcription, summarization, or knowledge-organization features | Kura AI, your selected AI provider, or a feature-specific AWS or third-party service |
Choosing your own AI provider changes the route for ordinary AI requests. It does not disable Core Service processing, communication-channel processing, connected-service authorization, or AWS-hosted processing separately required by a feature.
2. Core Service Processing
Core Service processing supports accounts, devices, subscriptions, security, support, and operation of the Service. Depending on the parts of the Service you use, we process:
- account details, such as your name, email address, account identifier, authentication information, and account status;
- subscription, plan, billing, invoice, transaction, and payment-related identifiers, with payment-card details processed by our payment provider;
- device identifiers and names, software versions, device certificates, connection state, and device-to-account relationships;
- IP address, browser and operating-system information, timestamps, website activity, feature usage, quotas, performance, error, security, and diagnostic information;
- support requests, feedback, related contact information, and relevant account or channel identifiers; and
- messages, files, images, audio, video, instructions, and information derived from them when you submit that content to a feature.
We use AWS to operate account authentication, device registration and connectivity, subscription and usage controls, cloud storage, security, and related operational services. Stripe processes payments and may provide us with customer, subscription, invoice, and transaction identifiers. When you submit feedback or an inquiry, our AWS service may process the inquiry, account ID, email address, plan, relevant LINE identifiers, and timestamps, and Resend may deliver the inquiry to our support team.
KuraClaw also stores user files, conversation state, memories, search indexes, and structured records on your MeCloud device. Derived records may contain information extracted from submitted content, such as contact information extracted from a business card. A derived record can remain on the device independently of the source image or file and must be deleted separately where the product provides separate deletion controls.
3. Communication-Channel Processing
You may communicate with Kura-chan through services such as LINE, Slack, Telegram, or WeChat/Weixin. The channel provider processes your messages and files before they reach Kura-chan and processes Kura-chan’s replies before they reach you.
Channel handling differs:
- LINE: Kura-chan communicates with you through a LINE Official Account using the LINE Messaging API. Incoming and outgoing messages and files are relayed through Initial S’s AWS infrastructure. The relay processes message content and metadata, LINE user and conversation identifiers, device and account identifiers, reply and quote information, delivery status, and file references. Files may be stored temporarily in Amazon S3 while being transferred between LINE and your MeCloud device.
- Slack, Telegram, and WeChat/Weixin: KuraClaw generally connects from your MeCloud device directly to the channel provider. Content can still be sent to Initial S’s AWS environment or an AI provider when you invoke an applicable cloud or AI feature.
- Other channels: the path depends on the integration. We will update this Policy if a new channel materially changes our data practices.
Using your own AI provider does not bypass the channel path. In particular, LINE messages and files continue to pass through Initial S’s AWS relay before any ordinary AI-provider selection is applied.
Initial S personnel do not routinely review your LINE chat history. If you expressly ask us to investigate or provide support concerning your message history, only authorized personnel may manually access and process the portion of that history reasonably necessary to fulfill your request. We may also permit limited access where required by law or reasonably necessary to investigate or respond to a security incident.
Your use of a channel remains subject to that provider’s privacy policy and terms. If an employer, school, or other organization provides the channel, its owner or administrator may control, access, export, or retain messages under its own policies. You are responsible for reviewing the rules that apply to your account or workspace.
For more information, review the LINE Privacy Policy, Slack Privacy Policy, Telegram Privacy Policy, and Tencent privacy policies.
4. Connected-Service Processing
You choose whether to connect a third-party service and which permissions to grant. We process the account, authorization, scope, service, and connection-status information needed to maintain the connection and perform the operations you request.
For Google and Microsoft connections, Initial S’s AWS service stores refresh tokens and related connection metadata and provides short-lived access tokens to your device. For GitHub, the AWS service stores installation and account metadata and creates short-lived installation tokens. Your device generally uses those tokens to request authorized content directly from the connected provider.
Retrieved content is generally processed or stored on your MeCloud device. Content that you select for an AI-powered task may also be sent to Kura AI or to the AI provider you configure, according to Section 5.
Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising. Human access is limited to cases permitted by that policy.
Microsoft information is processed according to the permissions you grant and the features you request. Review the Microsoft Privacy Statement.
GitHub information is processed according to the permissions or installation access you grant and the features you request. Review the GitHub Privacy Statement.
Disconnecting a service stops future access but does not automatically delete copies already stored on your device, records subject to a retention period, or information retained independently by the connected provider.
5. AI Processing and Provider Choice
AI-powered processing includes ordinary conversations and tool use, image and document understanding, structured extraction, embeddings and semantic search, transcription and summarization, and Archive Palace or Memory Kura knowledge organization. The content processed depends on the feature and may include prompts, conversation history, system instructions, tool definitions, tool calls and results, images, files, audio, transcripts, search queries, connected-service content selected for the task, model settings, and account or device identifiers.
Kura AI
“Kura AI” means the AI service provided by Initial S through its cloud infrastructure, including its AWS-hosted broker and models invoked through Amazon Bedrock. When you use Kura AI for an ordinary conversation, relevant request content is sent to that broker, and the result is returned to your device. Initial S’s AWS application may retain request, response, usage, and diagnostic records as described in Section 7.
Kura AI is also used for certain feature-specific operations even when your ordinary conversational AI provider is configured differently.
Your own API key
If you configure credentials for your own AI provider, ordinary AI requests are generally sent directly from your MeCloud device to the provider endpoint or proxy endpoint you configure and are not routed through the Kura AI broker. KuraClaw stores those credentials in your device configuration.
Depending on the request, your provider may receive prompts, conversation history, system instructions, tool definitions, tool calls and results, images, files, and other selected content. Its logging, retention, model-training, security, and international-transfer practices are governed by its terms, privacy policy, contractual arrangements, account settings, and any proxy you configure. You are responsible for protecting and revoking your credentials and for ensuring that you are authorized to submit the selected content.
Features that still use AWS when you use your own API key
Your own API key replaces only the applicable ordinary AI-model request. The following processing paths remain separate:
| Feature | Processing that still occurs |
|---|---|
| Image or text embeddings, including photo indexing and semantic search | Prepared image copies, search queries, or selected text are sent to Initial S’s AWS embedding service, which invokes an embedding model through Amazon Bedrock; returned vectors and indexes are stored on your device |
| Archive Palace or Memory Kura curation | Selected documents, memory or wiki text, and curation instructions are sent through the Kura AI broker to Amazon Bedrock |
| Photo-document recognition | Prepared document images and recognition instructions are sent through the Kura AI broker to Amazon Bedrock |
| Structured record extraction | Images or extracted text used to create records such as receipts or business cards are sent through the Kura AI broker to Amazon Bedrock |
| Audio or video transcription | Source media is uploaded temporarily to Amazon S3 and made available to AssemblyAI; results return through Initial S’s AWS service |
| Transcript summarization | Transcript text and summarization instructions are sent through the Kura AI broker to Amazon Bedrock |
For LINE voice messages, Initial S’s AWS service may obtain the audio from LINE, submit it to AssemblyAI, receive the transcript, and route the transcript to your device. AssemblyAI’s training and retention practices depend on the applicable contract and account settings. See its Privacy Policy and data retention and model training documentation.
We do not use your content to train AI models developed or operated by Initial S.
Initial S does not use AI to infer or derive sensitive personal information from your content for profiling, advertising, eligibility decisions, or other purposes unrelated to the feature you request. If you expressly ask Kura to recognize, extract, transcribe, summarize, organize, or otherwise process content that contains sensitive personal information, AI processing may identify or derive that information only as necessary to fulfill your request.
Third-party AI and transcription providers process content under their own service terms, contractual arrangements, account settings, and privacy practices. Their training and retention practices may differ.
6. How We Use Information
We use information to:
- create and administer accounts, subscriptions, connected devices, channels, and connected services;
- receive, route, process, and deliver messages, files, and requested results;
- perform the AI and cloud-assisted features described in this Policy;
- process payments and enforce feature or usage limits;
- provide support and respond to feedback;
- diagnose errors, secure the Service, prevent abuse, and maintain reliability;
- understand aggregate usage and improve the Service; and
- comply with law and enforce our agreements.
Initial S does not sell your personal information.
7. Storage and Retention
The following periods reflect current product behavior. Expiration and deletion may take additional time to complete, and we may retain information longer when reasonably necessary for security, fraud prevention, dispute resolution, legal compliance, or the establishment or defense of legal claims.
| Data | Location | Typical retention |
|---|---|---|
| User files, connected-service content, conversation state, memories, indexes, and derived structured records stored by KuraClaw | MeCloud device | Until you delete the applicable data, reset the device, or remove the applicable feature data; deleting a source file does not necessarily delete a separately stored derived record |
| Local channel diagnostic logs containing inbound and outbound payloads | MeCloud device | Approximately 30 days |
| LINE message log used for routing, reply resolution, and support | AWS | Approximately 7 days |
| LINE pending reply-routing data | AWS | Approximately 30 minutes; some voice-routing context approximately 1 hour |
| LINE relay files and files uploaded for delivery | Amazon S3 | Lifecycle expiration after approximately 1 day |
| Media uploaded for the transcription workflow | Amazon S3 | Lifecycle expiration after approximately 1 day |
| Transcription job metadata | AWS | Approximately 7 days |
| Kura AI request ledger, including ordinarily sized request and response content, usage, and diagnostic fields | AWS | Approximately 90 days |
| User-configured AI provider credentials | MeCloud device configuration | Until removed, replaced, or the applicable device configuration is deleted |
| OAuth connection credentials and metadata | AWS | Until you disconnect the integration or ask us to delete them, subject to backup, security, and legal requirements |
| Account, device, subscription, billing, support, security, and operational records | AWS and relevant service providers | While needed to provide the Service and afterward as reasonably necessary for the purposes described in this Policy |
Operational logs may include identifiers, errors, and request or response information. We limit access to personnel and service providers who need it for operations, security, or support.
Data held by channel providers, connected services, payment providers, AI providers, and other third parties is retained under their own policies and your settings with them.
8. How We Disclose Information
We may disclose information:
- to AWS and vendors that process information for us, including Stripe for payments, AssemblyAI for transcription, and Resend for support email delivery;
- to communication-channel providers to receive or deliver your messages;
- to an AI provider you select when necessary to perform your request;
- to connected services you direct KuraClaw to access or update;
- to a workspace owner or administrator where the channel or connected service is controlled by an organization;
- when required by law or when reasonably necessary to protect rights, safety, security, and the integrity of the Service;
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate notice and safeguards; or
- with your direction or consent.
We do not sell or rent your personal information.
9. International Data Transfers
Initial S is located in Japan. Our service providers and communication, AI, transcription, payment, and connected-service providers may process information in Japan, the United States, and other countries. Those countries may have privacy laws different from those where you live. Where required, we use appropriate contractual or other safeguards for international transfers.
10. Security
We use technical and organizational safeguards designed to protect information, including access controls, encrypted network transport, private cloud storage, short-lived access tokens where supported, and device credentials for AWS IoT connections. No transmission or storage system is completely secure, and we cannot guarantee absolute security.
You are responsible for securing your MeCloud device, channel and connected-service accounts, credentials, network, and workspace permissions. Keep software up to date, use strong and unique passwords, and enable multi-factor authentication where available.
11. Your Choices and Rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, and to withdraw consent where processing is based on consent.
You may:
- manage or delete locally stored information on your MeCloud device;
- disconnect supported channel or connected-service integrations;
- configure an available AI provider; and
- contact us to request access to or deletion of information held in our cloud systems.
Deleting a cloud account does not itself erase data stored on your MeCloud device or information retained independently by a channel provider, connected service, or other third party. Some cloud records may remain until their scheduled expiration or for the legal, security, and operational reasons described in Section 7.
To exercise a privacy right, email info@mykura.ai. We may need to verify your identity and may deny or limit a request where permitted by law.
12. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Additional age or parental-consent requirements may apply in your country and to the communication channel you use. If you believe a child has provided personal information in violation of applicable requirements, contact us so we can investigate and take appropriate action.
13. Changes to This Policy
We may update this Policy as the Service or applicable law changes. We will post the revised Policy and update its date. If a change materially affects how we use personal information, we will provide additional notice where appropriate or required.
14. Contact Us
For privacy questions or requests, contact:
Initial S, Inc. (mykura)
Email: info@mykura.ai
Address: Daiwa Akihabara Bldg, 2-19-23 Kanda Sudacho, Chiyoda-ku, Tokyo 101-0041, Japan