English below ↓ · 日本語が先、英語がその下にあります
プライバシーポリシー
バージョン 2026-09-08 · 最終更新日:2026年9月8日 · 施行日:2026年9月8日
この日本語文はアクセシビリティのために提供される翻訳であり、日本の弁護士による確認を まだ受けていません。確認を受けるまでは、英語版が正文です。相違にお気づきの場合は第1項 の連絡先までお知らせください。訂正します。
要約
あなたは履歴書・レジュメをアップロードします。当方はそれを日本式の 履歴書 と 職務経歴書 に作り変えます。
そのために、アップロードされた書類の内容(ページの画像を含みます)は、日本国外の 人工知能(AI)事業者によって読み取られます。これなしに書類を作ることはできないため、 事前にあなたの同意をいただきます。同意されない自由があり、その場合は書類を作成できま せん。
アカウントをお持ちでない場合、24時間ですべて削除します。お持ちの場合は、 アカウントをご利用の間は保管し、第7項の期間に従って削除します。
当方はあなたに関する情報を販売しません。広告を出しません。クッキーを設置しません。 あなたの書類をAIの学習に使うことはなく、雇用主に見せることもありません。
以下はその詳細です。長いのは、あなたの氏名・住所・生年月日・顔写真が、安心させる言葉 ではなく具体的な説明に値するからです。
1. 当方について
本サービスは、法人ではなく個人が運営しており、resumeforjapan.com を運用してい ます。
運営者の氏名および住所は、ご請求があれば遅滞なく回答します。 法はこれらを公表する ことまでは求めておらず、本人の知り得る状態に置けば足ります(これには本人の求めに応じて 遅滞なく回答する場合が含まれます)。ここに記載していないのは、これが個人の自宅住所で あり、公開しても誰の利益にもならないためです。ご請求いただければお伝えします。
連絡先 — プライバシーに関するお問い合わせ、あなたの情報についてのご請求、および 苦情の受付:privacy@resumeforjapan.com
当方は、個人情報の保護に関する法律(以下「法」)にいう個人情報取扱事業者です。 このページは、法第32条が求める公表にあたります。
2. 取得する情報
2.1 アップロードされた書類
そこに書かれている一切です。項目を選ぶのは当方ではなく、あなたの書類です。実際には 通常、次のものが含まれます。
理由として記載されたもの
のない見出し——健康状態、家族、在留資格、趣味など——があれば、あなたが付けた見出しの まま、あなたの言葉で保管します。
- 氏名。原語の表記と、仮名の読み
- 生年月日、およびそこから計算される年齢
- 性別
- 国籍
- 郵便番号および住所
- 電話番号およびメールアドレス
- 記載されたリンク(ポートフォリオ、コードリポジトリなど)
- 学歴:学校名、学位、専攻、在籍期間
- 職歴:勤務先、役職、部署、期間、職務内容、実績、プロジェクト、および各職を離れた
- 特許、論文、受賞、発表、ボランティア、資格、語学、技能
- その他、書類に記載されている一切の事項を、その見出しのまま。 当方に対応する項目
- 本人希望記入欄に書かれた内容。多くは給与や勤務条件です
当方は、アップロードされたファイルをそのまま保管し、そこから取り出した内容も保管します。 原語の記録と、その日本語訳の双方を保管します。
ファイル名は、あなたのライブラリでのその案件の名称になります。 Alex_Rivera_CV.pdf をアップロードされれば「Alex Rivera CV」として保管します。つまり 通常は、当方がファイルを読む前の時点で、あなたの氏名が当方の記録に入っています。
2.2 顔写真
履歴書用に写真を追加された場合、3:4 に切り出した画像を保管します。あなたが選んだ元の 画像は保管しません。位置情報や撮影機器の情報(EXIF)は、画像を処理する際に破棄します。
2.3 入力された内容
画面上で行われた修正。AIに修正や下書きを求める際に入力された指示。志望動機の方向づけの ために求人票を貼り付けられた場合、その本文は10分間メモリ上に保持されるだけで、当方の データベースには書き込みません。ただし他のものと同様、AI事業者には送られます。
2.4 アカウント
サインインされる場合、サインインの仕組みが発行する識別子、ご契約の内容、および日時を 保持します。当方がパスワードを受け取ることも、保管することもありません。 メール アドレスは、当方が利用するサインインサービスである Amazon Cognito が東京で保持します。 「Google で続ける」を選ばれた場合、Google は Amazon Cognito に、あなたのメール アドレスと Google アカウントの識別子を伝えます。それ以外は伝えません(第5.4項)。
2.5 取得しないもの
IPアドレスやブラウザのユーザーエージェント文字列は記録しません。アクセスログに残るのは、 メソッド、経路、ステータス、所要時間だけです。クエリ文字列も、ヘッダーも、リクエストの 本文も残しません。
クッキーを設置しません。 アクセス解析なし、広告用の画素なし、タグマネージャーなし、 セッション記録なし、エラー追跡サービスなし。フォントは当方のドメインから配信しており、 フォントの配信網があなたの訪問を知ることはありません。
写真や動画も同じです。 トップページの背景動画と写真1点は、以前は Pexels および Unsplash から読み込まれており、これらの事業者にあなたのIPアドレスとブラウザが伝わって いました。2026年9月7日以降は、いずれも当方が複製を保有し、当方のドメインから配信して います。トップページを含め、このサイトのどのページも、表示する素材を他社に要求すること はありません。
2.6 ブラウザに保存されるもの
クッキーは使いません。本サイトがブラウザ自身の保存領域に保存するのは、次のものです。
同じ扱いをしてください。そのブラウザのプロファイルを使える人は、その書類を開けます。
サインイン用ライブラリがブラウザのローカルストレージに保存します。最長30日間 サインインした状態を保つもので、その間にそのブラウザのプロファイルを使える人は、 あなたとしてサインインした状態になります。サインアウトすると削除されます。
消えます。
元のファイルと並べて表示するかどうかです。いずれにも、あなたの書類の内容は含まれ ません。
- サインインせずに作成した書類の鍵。 あとで戻ってくるためのものです。パスワードと
- サインインされた場合は、サインインのトークン。 Amazon Cognito が発行し、その
- 第6項の提供へのあなたの同意。 タブを開いている間だけ保存され、タブを閉じると
- 選択された表示言語と、いくつかの表示の設定。たとえばライブラリの表示幅や、書類を
鍵を含むリンクから書類を開いた場合、アドレス欄からは鍵を取り除きます。そのようなリンク の共有にはご注意ください。持っている人に閲覧を許すものです。
3. 利用目的
次の目的にのみ利用します。
1. アップロードされた書類を履歴書および職務経歴書に変換すること——ファイルを 読み、事実を取り出し、翻訳し、書式に配置すること。 2. 処理すべきでない内容が含まれていないか、アップロードを検査すること。 この検査は運営者が無効にすることができます。無効の場合、アップロードは 検査を経ずに変換されます。 3. ご依頼があった場合に、書類に既に含まれる事実のみから職務要約・志望動機・ 自己PRを下書きし、ご依頼の編集を補助すること。 4. 作成した書類を表示し、編集できるようにし、ダウンロードできるようにすること。 5. あなたのライブラリに書類を保管し、あとで戻ってこられるようにすること。 6. サービスを運営すること——サインイン、料金の収受、不具合の調査、不正利用の防止。 7. お問い合わせに回答すること、および法令を遵守すること。
当方は、あなたの書類をAIモデルの学習・微調整・評価に使いません。本サービスの改善にも 使いません。販売も、貸与も、利用許諾もしません。雇用主・人材紹介会社・エージェントに 送ることは決してありません。 書類を共有したり公開したりする機能は存在しません。 ダウンロードできるのはあなただけです。
将来これらのいずれかを行いたくなった場合は、事前に、別途あなたにお尋ねします。この ページを黙って書き換えて済ませることはしません。
4. 要配慮個人情報
日本法は、人種、信条、社会的身分、病歴、障害、犯罪の経歴、および犯罪により害を 被った事実に関する情報に、特別の保護を与えています。
当方からこれらをお尋ねすることは決してありません。しかし履歴書は自由記述であり、あなた の書類に含まれていることがあります。空白期間の理由として書かれた病歴、障害の申告、 学ばれた宗教系の学校などです。含まれていれば、他の内容と同様に処理され、他の内容と同様 にAI事業者に送られます。
写真については、はっきり述べておく必要があります。 写真それ自体は要配慮個人情報では ありません。しかし日本法は、外見から明らかな身体障害に関する情報を要配慮個人情報として 扱います。したがって写真は、あなたにも当方にもその意図がないまま、要配慮個人情報を運び 得ます。
そのため、要配慮個人情報を含み得る書類をお預かりする前に、別途、明示的に同意をいただき ます。この類型について、法は同意以外の方法を認めていません。
ここで一つ、実際の限界を述べます。 履歴書用にアップロードされた写真は、いかなる AI事業者にも送られません。 送られるのは当方自身の組版ソフトウェアだけで、それがページ に写真を描画します。ただし、アップロードされた書類そのものに写真が印刷されている 場合、そのページは画像に変換され、他のページと同じように読み取られます。その写真は外部 に出ます。
性別と国籍は、日本法にいう要配慮個人情報ではありません。しかし個人情報であり、当方 はそのように取り扱います。いずれも任意です。当方がどちらかを推測することは決してあり ません。書類に記載がなければ空欄のままにします。履歴書には、性別の記載が任意である旨の 法定の注記を印字します。
5. 情報に接する当方以外の者
5.1 アマゾン ウェブ サービス(東京)
当方は AWS の東京リージョンで稼働しています。アップロードされたファイル、取り出された 記録、写真、完成した書類は、暗号化されてそこに保管されます。AWS が内容にアクセスする ことはありません。
メールアドレスとサインインの資格情報は、同じく東京にある Amazon Cognito が保持 します。
当方のウェブサイトは Amazon CloudFront の世界規模の配信網を通じて配信されるため、 あなたのブラウザと当方との間の通信が、日本国外の拠点で処理されることがあります。
5.2 AI事業者
このページで最も重要な記載です。
履歴書を読み、理解し、翻訳する作業は、AIモデルが行います。
当方はこれらのモデルを自ら運用していません。 当方は OpenRouter というサービスに 要求を送っており、OpenRouter は多数のAI事業者のモデルへの接続を提供します。どのモデルが あなたの書類を扱うかは、作業の種類——ページの画像を読むのと文章を翻訳するのとでは必要な モデルが異なります——と、どのモデルが最も良い書類を作るかについての当方自身の検証によって 決まります。
より良いモデルが出てくれば、当方は予告なく、利用するモデルを変更します。 予告なく 変わらないのは、あなたの書類が到達し得る事業者の一覧と、その所在国です。その一覧は下記 のとおりで、これに追加する場合は、事前にこのページを更新します。
あなたの書類は、次のいずれの事業者によっても読まれ得ます。
| 事業者 | 国 |
|---|---|
| OpenRouter(要求を中継するサービス) | アメリカ合衆国 |
| OpenAI | アメリカ合衆国 |
| Anthropic | アメリカ合衆国 |
| アメリカ合衆国 | |
| DeepInfra、Parasail、Novita などのホスティング事業者 | アメリカ合衆国 |
| Mistral AI | フランス共和国 |
| Alibaba(Qwen モデル) | 中華人民共和国/シンガポール共和国 |
| DeepSeek | 中華人民共和国 |
モデルが当方に届く経路について。 当方が利用するモデルのうち Qwen と DeepSeek は、中国の事業者が作成し、どの事業者でも動かせる公開ライセンスのもとで 公表されたものです。個々の要求について OpenRouter がどの事業者を選ぶかにより、これらの モデルは米国のホスティング事業者によって動かされることも、Alibaba や DeepSeek 自身に よって動かされることもあります。当方は要求ごとのその選択を制御していません。両方の 可能性をここに記載しているのは、そのためです。
工程ごとに、何が外部に出るか。
| 工程 | 外部に出るもの |
|---|---|
| ファイルの読み取り | 書類の全ページの画像。アップロードされたままのもので、書類に印刷された写真を含みます |
| 検査 | 書類の全文 |
| 事実の取り出し | 書類の全文 |
| 翻訳 | 翻訳される値、および氏名と住所の全体(ふりがなを作るために必要です)、性別、国籍。生年月日・電話番号・メールアドレス・郵便番号・リンクは、この工程では送られません |
| 「AIで直す」 | 編集中のその値ひとつ。下書きされた文章の場合は、氏名・住所・電話番号・メールアドレス・生年月日を意図的に除いた職歴の要約。加えて、貼り付けられた求人票があればそれ |
書類の組版と描画には、AIを一切使いません。 これは当方のサーバー上で動く通常の ソフトウェアです。この工程で写真と生年月日が外部に出ることがないのは、そのためです。
当方はこれらの事業者に対し、あなたの書類を学習に用いないよう指示し、保持しないサービス を選んでいます。
5.3 Stripe(決済)
パスを購入される場合、お支払いは当方のページではなく Stripe(米国の Stripe, Inc. およびその関連会社)が運営するページで行います。カード情報とメールアドレスは Stripe の ページに入力していただくもので、当方がカード番号を受け取ることはありません。 当方 から Stripe に送るのは、あなたのアカウントを表す無作為の識別子と、選ばれたパスの種類 です。Stripe からは、支払いが完了したかどうかが当方に伝えられます。あなたが Stripe に 提供する情報は Stripe 自身のプライバシーポリシーに従って取り扱われ、アメリカ合衆国 で処理されることがあります(その意味は第6.2項に記載しています)。当方は、各支払いの 記録——パスの種類、金額、日付、Stripe の参照番号——をアカウントとともに保管します。
5.4 Google(サインイン)
「Google で続ける」を選ばれた場合、Google(アメリカ合衆国の Google LLC)は、 あなたが本サイトにサインインしたことを知り、Amazon Cognito にあなたのメールアドレスと Google アカウントの識別子を伝えます。当方が Google に求めるのはそれだけです。これらは Google 自身のプライバシーポリシーに従って取り扱われます。メールで届くコードで サインインされる場合、Google は関与しません。
5.5 それ以外にはいません
アクセス解析事業者、広告配信事業者、データブローカー、メール配信事業者、エラー追跡 事業者のいずれも利用していません。日本の郵便番号検索は、日本郵便が公開するデータの 複製を当方のサーバー上で参照しており、外部に何も送信しません。
外部の診断・トレーシングサービスは利用していません。 2026年9月6日までは、AIへの 呼び出しが米国の事業者にトレースされており、書類の内容がその事業者に複製されていまし た。同日をもって停止し、現在その事業者は何も受け取っていません。変換の失敗を調べる ために残す記録は、東京の当方の AWS アカウント内に書かれ、当該ジョブとともに削除され ます。
6. 外国への提供
日本法は、外国にある第三者へ個人データを提供することを、一定の事項をあらかじめ伝えた うえで本人が同意すべきことと定めています。この項がその事項です。
当方は、書類が処理される前に同意をいただきます。同意されない場合、変換を行うことは できません。変換そのものが提供にあたるからです。
6.1 提供先の国
第5.2項に掲げた事業者へ、次の国に対して提供されます。アメリカ合衆国、 フランス共和国、中華人民共和国、およびシンガポール共和国。
6.2 それらの国の個人情報保護制度
当方は、各国の保護が日本とどう異なるかを、和らげずにお伝えする義務を負っています。
アメリカ合衆国には、日本法に相当する単一の国家的な個人情報保護法がありません。保護 は分野別の連邦法と個々の州法の継ぎはぎであり、あなたの書類がそのいずれかで保護されるか どうかは、事業者と州によります。米国の事業者に対して、日本法があなたに与えているような 開示・訂正・削除を求める全国的な権利は、一般には存在しません。また米国法は、政府当局 が事業者に対し保有するデータの提出を強制することを認めています。その監視権限は米国市民 でない者にも及び、あなたの認識も同意も必要としません。
中華人民共和国には、個人情報保護法(PIPL)という国家的な個人情報保護法があり、開示 ・訂正・削除の権利を与えています。また顔画像を、別途の同意を要する要配慮の類型として 扱っており、その点に限れば日本法より厳格です。しかし、中国法は、サイバーセキュリティ 法・データ安全法・国家情報法のもとで、事業者に対し国家の安全・情報機関への協力と、 保有するデータへのアクセスの提供を義務づけています。 日本の個人情報保護委員会は、 これらの義務および中国のデータ越境移転規制を、あなたの権利利益に重大な影響を及ぼし得る 事項として指摘する調査結果を公表しています。同委員会は DeepSeek についても個別の注意 喚起を公表しており、同社が取得したデータは中国国内のサーバーに保存され、中国の法令の 適用を受ける旨を述べています。中国は、同委員会が日本と同等の水準の保護制度を有すると 認めた国ではありません。
シンガポール共和国には、個人データ保護法(PDPA)という国家的な個人情報保護法があり、 開示および訂正の権利を与えています。同委員会が同等の水準にあると認めた国ではありません。
フランス共和国は欧州連合の一員であり、GDPR の適用を受けます。GDPR について、同委員会 は日本と同等の水準の保護制度を有すると正式に認めています。ここに挙げた中では、あなたの データが日本法に最も近い条件で保護される国です。
いずれの場合も、当方は、これらの事業者に対する適法な政府の要求を妨げることはできず、 それが行われたことを通常は知り得ません。
6.3 提供先が講じている措置
日本法は、各事業者が実際に何を行っているかを、実質に即してお伝えすることを求めています。 2026年9月6日現在の内容は次のとおりです。事業者が公表していない事項については、公表がない 旨をそのまま記します。安心できる空白を残すことはしません。
OpenRouter(アメリカ合衆国)。 すべての要求は、いずれかのモデルに届く前に OpenRouter を通ります。そのため OpenRouter はそれ自体が提供先です。同社は、既定ではプロンプトおよび 出力を記録せず、モデルの学習に用いず、アップロードされた画像を要求の中継に必要な時間を 超えて保持しないと表明しています。不正利用の検知、セキュリティ、課金、法令遵守の場合を 除きます。欧州委員会の標準契約条項を組み込んだデータ処理契約と、自らの委託先の一覧を 公表しています。
OpenAI(アメリカ合衆国)。 OpenAI は、事業者向けAPIに送られた内容を自社モデルの学習 に用いておらず、2023年3月以降そうしていません。これは、入力された内容を学習に用いること がある一般消費者向けの ChatGPT とは異なります。内容は不正利用の確認のために最大30日間 保持され、その後削除されます。OpenAI の従業員、および米国・カナダ・フィリピンにいる 守秘義務を負う専門の委託先が、自動システムが検知した内容を閲覧することがあります。 SOC 2 Type 2、ISO 27001、ISO 27701、ISO 42001 の認証を保有し、誰でもオンラインで受諾 できるデータ処理契約を提供しています。写真について特に述べておくべきことがあります。 アップロードされた画像はすべて、違法な児童虐待画像に該当しないか自動的に走査されます。 走査が画像を検知した場合、OpenAI は人が確認するためにその画像を保持します。これは、より 厳格なプライバシーの選択肢を購入した場合でも行われ、当方が停止させることはできません。
Anthropic(アメリカ合衆国)。 Anthropic の事業者向け規約は、顧客の内容を自社モデルの 学習に用いてはならない旨を定めています。内容は30日以内に削除されます。ただし自動的な安全 機構が検知した場合を除き、検知された内容は最大2年間保持され得ます。同社の従業員が内容を 閲覧できるのは、改ざん記録の残る管理された経路を通じてのみであり、かつ検知があった場合に 限られます。アップロードされた画像は処理の直後に削除され、学習に用いられることはなく、 同社のモデルは写真に写った人物の特定を拒否します。SOC 2 Type 2、ISO 27001、ISO 42001 を 保有し、データ処理契約は商用規約とともに自動的に適用されます。
Google(アメリカ合衆国)。 Google の規約は無償のサービスと有償のサービスとで大きく 異なり、その差は率直に述べるに値します。無償の区分では、Google は送信された内容を 自社製品の改善に利用しており、同社自身の規約が開発者に対して個人情報を送らないよう述べて います。当方は無償の区分を利用していません。 有償のサービスでは、Google はあなたの 内容をモデルの学習に用いず、不正利用の監視のために55日間データを保持します。Google は SOC 2 Type II、ISO 27001、ISO 27017、ISO 27018、ISO 27701、ISO 42001 を保有しています。
Mistral AI(フランス共和国)。 Mistral はフランスの事業者であり、フランスは日本の 個人情報保護委員会が日本と同等の水準の保護制度を有すると認めた国の一つです。したがって、 ここに挙げた事業者の中で、あなたのデータが日本法に最も近い条件で保護されるのはこの事業者 です。標準契約条項、監査権、契約終了から30日以内の削除を含むデータ処理契約を公表し、 ISO 27001、ISO 27701、SOC 2 Type II への適合を表明しています。内容は不正利用の監視のため、 直近30日間保持されます。一点、知っておいていただくべきことがあります。 Mistral は、 Enterprise を除くすべての区分において、既定で入力と出力を自社モデルの学習に利用します。 当方はこれを回避する経路の設定を用いており、学習を許す条件であなたの書類を Mistral に 送ることはありません。
公開ライセンスのモデルを動かす米国のホスティング事業者(DeepInfra、Parasail、Novita など)。これらは Qwen および DeepSeek のモデルを、米国内の自社の設備で動かします。 OpenRouter は、これらの事業者を、プロンプトを保持せず学習にも用いない事業者として記録 しています。
Alibaba(中華人民共和国/シンガポール共和国)。 Qwen への要求が Alibaba Cloud 自身に よって処理される場合、要求はそのシンガポールのエンドポイントに届きます。同エンドポイント のデータセンターは、シンガポールおよび中国にあると記録されています。日本の顧客は、 シンガポール法に基づき Alibaba Cloud (Singapore) Private Limited と契約します。Alibaba は 標準契約条項を含むデータ処理契約を公表し、Model Studio が SOC 2 監査を通過した旨を表明し、 AES-256 でデータを暗号化しています。国際版の文書には顧客データをモデルの学習に用いること はないと記されていますが、これは拘束力のある契約ではなくヘルプページに現れるものです。 また中国本土向けの契約は、「お客様の許諾なく」学習に用いることはない、という書き方に なっています。Alibaba は、保管期間もデータ所在地に関する約束も公表していません。 そのため当方は、同社があなたのデータをどれだけの期間保持するかをお伝えできず、処理が シンガポール内にとどまることを保証することもできません。同社の中国本土向け規約は、自動的 または人手による入力の確認を行う権利を留保しており、国際版の規約はいずれとも述べて いません。
DeepSeek(中華人民共和国)。 DeepSeek への要求が DeepSeek 自身によって処理される場合、 同社のプライバシーポリシーは、個人データを中国において取得・処理・保管すること、および 入力と出力が——非識別化のうえ——自社モデルの学習に用いられ得ることを述べています。 オプトアウトは同社の消費者向けアプリの中にのみ存在し、プログラムからの利用について同等 の制御は文書化されていません。 同社は、保管期間、データ処理契約、 標準契約条項、自らの委託先の一覧、およびいかなるセキュリティ認証も公表して いません。規約は中国本土の法律に準拠し、紛争は杭州で審理されます。また同社の規約は、 本サービスが生体データを含む機微な個人データの処理を想定しておらず利用者は提供すべきで ない旨を述べる一方で、写真から顔認識の特徴量を抽出しないことを別途約束しています。
いずれの事業者にもないもの。 ここに挙げた事業者のデータ処理契約のうち、日本または法に 言及しているものは一つもありません。いずれも欧州・英国・カリフォルニア州の法制度を前提に 書かれており、うち2社にはそもそもそのような契約がありません。また、実際の処理を日本国内で 行っている事業者も一つもありません。1社が日本での保管を提供していますが処理は提供しておらず、 残りは日本国外で処理します。当方が約束できることの限界を知っていただきたいので、これを 記します。
6.4 同意されない場合
アップロードをせずに本サイトを閲覧していただくことはできます。しかし、上記の提供なしに 書類を作成することはできません。同意を撤回される場合はお知らせください。当方が保有する あなたに関するものを、すべて削除します。
7. 保管期間
| 対象 | 期間 |
|---|---|
| アカウントなしで作成された書類 | 最後に開いた時から24時間 |
| 有効なパスのあるアカウント内の書類 | あなたが削除するか、アカウントを閉じるまで |
| パスの期間が終了したアカウント内の書類 | パスの終了、または最後にその書類を開いた時の、いずれか遅い方から30日 |
| パスを一度も購入していないアカウント内の書類 | 最後にアカウントを利用した時、または最後にその書類を開いた時の、いずれか遅い方から30日 |
| 書類がなく、利用されていないアカウント | 最後に利用された時から12か月。その時点でアカウントと、Amazon Cognito にあるメールアドレスを削除します |
| お支払いの記録 | アカウントとともに保管し、アカウントとともに削除します |
| privacy@resumeforjapan.com 宛にいただいたメール | ご請求の記録として、受信から365日 |
| 当方のサーバーログ | 30日 |
| 当方のデータベースのバックアップ | 直近35日分を順次保持(第8項) |
1時間ごとに処理が動き、これらの期限を過ぎたものを削除します。その背後で、保管領域の 規則が、いかなる場合でも180日を超えたファイルを削除します。これは当方自身の誤りに対する 安全網であって、本来の仕組みではありません。
8. 削除
書類はいつでも削除でき、アカウントごと閉じることもできます。 どちらも画面上で行え ます。
いずれの場合も、アップロードされたファイル、両言語の抽出記録、当方が作成したすべての 文書のすべての版、写真、および編集履歴が削除されます。当方は事後に何も残っていないことを 確認し、残っていればそれを不具合として扱います。
例外が一つあり、期間が限られています。 当方のデータベースは、直近35日の任意の 時点に戻せる自動バックアップを保持しています。当方の障害や誤りによって全員の書類が失われる ことのないようにするためです。削除されたものは直ちに稼働中のデータベースから消えますが、 そのバックアップの中には期間が過ぎるまで残ります——削除から最長35日です。バックアップは 暗号化されており、サービスから読むことはできず、サービス全体を障害から復旧する場合にのみ 使います。万一使用した場合は、それ以前に削除されていたものを改めて削除します。アップロード されたファイルと当方が作成した書類は、このバックアップには含まれません。ファイルの保管領域は 過去の版を保持しないためです(第9項)。
既にダウンロードされたファイルは、あなたのコンピューター上に残ります。当方はそれに手を 触れることができません。
サインインせずに作成された書類には削除ボタンがありません。24時間以内に自動的に削除 されます。それより早く削除したい場合は、メールでご連絡ください。
9. 安全管理措置
規律と責任。 ここでの個人データの取扱いについて責任を負う者は、一人です。データを どのように取得・利用・保管・提供・削除してよいかは文書化されており、その変更は意図をもって 行われます。
アクセス。 データに到達できるのは、それを必要とするサービスの部分だけであり、それぞれ 必要な範囲に限定されています。たとえば、古い書類を削除する部分は、削除の時期かどうかを 判断するのに必要なものだけを読み、記録を変更することも、どこかへ送ることもできません。 所有を証明しない書類の要求は、その書類が存在しないかのように応答します。存在を 探ることができないようにするためです。
暗号化。 通信はすべて暗号化されており、暗号化されていない接続は拒否します。保管される ファイルと記録は、保存時にも暗号化されています。
保管。 書類の保管領域は、過去の版を保持しない設定にしています。削除された書類が古い 複製として生き残ることのないようにするためです。
ダウンロード。 ダウンロードのリンクは署名され、5分で失効し、アップロードされた元の ファイルや当方の内部の作業データを指すようにはできず、キャッシュされることもありません。 恒久的に公開されるリンクは、何一つ存在しません。
アップロード。 5MB に制限し、ファイル名ではなく実際の内容によって種類を判定します。
AIに対する制限。 AIは、日付・氏名・ふりがな・住所・電話番号・メールアドレス・リンク・ 写真・性別・国籍・本人希望記入欄を変更できません。AIはあなたの事実を言語と書式の間で移す だけであり、事実を作り出しません。
データの所在。 当方のサーバーは日本にあります。データの一部は、第5項および第6項に 述べたとおりアメリカ合衆国、フランス共和国、中華人民共和国、 シンガポール共和国に送られ、それが何を意味するかは同項に記載しました。
具体的なアクセス制御や侵入対策の内容は公表しません。公表することが、それらを弱めるから です。これ以上の詳細が必要な場合は、お問い合わせください。
10. 当方側で書類を見得る者
本サービスには運営用の管理画面があります。運営者——第1項にいう個人です——はこれを 通じて、本サービスが行った変換を一覧し、その背後にある記録を開くことができます。 アカウントなしで作成された書類も含みます。
これは、失敗した変換の原因を調べられるようにするために存在します。存在することを知って おいてください。
11. あなたの権利
次のことを請求できます。
必要としない場合、漏えい等が生じた場合、当方の取扱いによりあなたの権利利益が害される おそれがある場合を含みます
- 当方があなたの情報を保有する目的の通知
- 当方が保有するあなたに関する情報の開示。電磁的記録での提供を求めることもできます
- 第三者への提供に関する記録の開示
- 事実でない情報の訂正・追加・削除
- 法が定める場合における利用停止・消去、および第三者への提供の停止。当方がもはや
請求の方法。 privacy@resumeforjapan.com 宛に、ご希望の内容と、あなたのデータを 特定できるだけの情報をお送りください。
ご本人であることの確認。 アカウントについては、登録されたメールアドレスによります。 アカウントなしで作成された書類については、その鍵をお持ちであることを示していただく必要が ある場合があります。そうでないと、あなたの書類を他の方の書類と区別できないためです。請求の 内容に見合わない証明を求めることはしません。
代理人。 法定代理人、およびあなたが選任した任意代理人による請求も受け付けます。
期間。 遅滞なく、通常14営業日以内に回答します。
費用。 無料です。いかなる請求についても手数料をいただきません。
請求をお断りする場合は、その旨と理由をお伝えします。
日本国外にお住まいの場合も、これらの権利は同じように適用されます。日本法は、あなたの 国籍や居住地にかかわらず、当方が取り扱う個人情報を保護します。
12. 年齢
本サービスのご利用には、16歳以上であることが必要です。それより下の年齢の方が利用され た場合は、保護者の方から当方にご連絡ください。保有しているものを削除します。
13. AIが書いた文章について
当方が作成する書類のうち3つの部分——職務要約、志望動機、自己PR——は、あなたの 書類に既に含まれる事実のみを用い、ご依頼があった場合にのみ、AIモデルが下書きします。 生成されたものである旨が表示されるので、どの言葉があなたのものでないかが分かります。 それ以外の箇所では、AIはあなたの事実を言語と書式の間で移すだけであり、事実を作り出し ません。
ここで、あなたについて何かが判断されることはありません。 当方はあなたを採点も順位付け も評価もせず、雇用主に何も送りません。当方が作るのは、あなたが読み、編集し、どうするかを 決める書類です。どこかに送る前に、必ずお読みください。あなたの名前が載っている書類です。
14. 不具合が起きた場合
ここにある個人データが漏えい・滅失・毀損した場合、当方は法の定める期限内に、日本の 個人情報保護委員会に報告し、影響を受けた方にお知らせします。履歴書には要配慮個人情報が 含まれることが多いため、影響を受けた方が何人であっても、当方はこの種の事案を報告すべき ものとして扱います。
15. 苦情
まず当方にお知らせください:privacy@resumeforjapan.com。伺わないよりは、伺いたいと 考えています。
ご満足いただけない場合は、個人情報保護委員会に申し出ることができます — https://www.ppc.go.jp/
16. このページの変更
このページを変更した場合、新しい版を新しい日付とともにここに掲示します。既に保有している 情報の使いかたに実質的な影響を及ぼす変更——とりわけ、あなたの書類を新しい目的に利用できる ようにするもの——については、掲示をもって同意があったものとはせず、改めて同意をいただき ます。
あなたが同意した時点のバージョンは、当方の記録に保存されています。
17. 準拠法
本ポリシーには日本法が適用されます。これは、消費者としてのあなたが、居住国の強行法規 による保護を奪われることを意味しません。
本ポリシーは、同一のページに日本語と英語で、日本語を先にして掲示されています。 日本語文はアクセシビリティのために提供される翻訳であり、日本の弁護士による確認をまだ 受けていません。確認を受けるまでは、英語文が正文です。 両者が異なる場合は第1項の連絡先 までお知らせください。翻訳を訂正します。
*制定:2026年9月6日 · 最終改定:2026年9月8日*
Privacy Policy
Version 2026-09-08 · Last updated: 8 September 2026 · In force from: 8 September 2026
In short
You upload a résumé. We turn it into a Japanese 履歴書 and 職務経歴書.
To do that, the contents of your résumé — including images of its pages — are read by artificial-intelligence companies outside Japan. We cannot make your documents without this, so we ask your permission first. You can refuse, and then we cannot make them.
If you do not have an account, we delete everything after 24 hours. If you do, we keep it while your account is in use, and delete it on the timetable in section 7.
We do not sell anything about you. We do not advertise. We set no cookies. We never use your résumé to train anything, and we never show it to employers.
The rest of this page is the detail. It is long because your name, your address, your date of birth and your face deserve specifics rather than reassurance.
1. Who we are
This service is operated by an individual — not a company — operating resumeforjapan.com.
The operator's name and address are provided to anyone who asks, without delay, at the contact address below. The Act does not require them to be printed here: they must be in a state you can come to know (本人の知り得る状態), and the Act says that includes answering without delay when asked. They are not printed because this is a private individual's home address, and publishing it protects nobody. Ask and you will be told.
Contact — for privacy questions, requests about your data, and complaints: privacy@resumeforjapan.com
We are a personal information handling business operator (個人情報取扱事業者) under Japan's Act on the Protection of Personal Information (個人情報の保護に 関する法律, "the Act"). This page is the disclosure Article 32 of that Act requires.
2. What we collect
2.1 The résumé you upload
Whatever is in it. We do not choose the fields; your résumé does. In practice that usually includes:
achievements, projects, and your stated reason for leaving each role
languages, skills
a section we have no field for — health, family, visa status, hobbies — we keep it under the heading you gave it, in your words.
- your name, in its original script and in kana
- your date of birth, and your age calculated from it
- your gender
- your nationality
- your postal code and home address
- your telephone number and email address
- links you list — a portfolio, a code repository
- education: institutions, degrees, fields, dates
- employment: employers, job titles, departments, dates, responsibilities,
- patents, publications, awards, presentations, volunteering, certifications,
- anything else your résumé contains, under its own heading. If your CV has
- whatever you write in 本人希望記入欄, usually salary or conditions
We keep the file you uploaded, unchanged, as well as what we extract from it, and we keep both the original-language record and its Japanese translation.
The filename becomes the name of the job in your library. Upload Alex_Rivera_CV.pdf and we store "Alex Rivera CV". So your name is usually in our records even before we have read the file.
2.2 Your photograph
If you add a photograph for the 履歴書, we store the cropped 3:4 image. We do not keep the original you chose, and location and camera data (EXIF) is discarded when the image is processed.
2.3 What you type
Corrections you make. Instructions you type when asking the AI to fix or draft something. If you paste a job advertisement to aim your 志望動機, that text is held in memory for ten minutes and never written to our database — but it is sent to the AI companies, like everything else.
2.4 Your account
If you sign in, we hold an identifier from the sign-in system, your plan, and timestamps. We never receive or store your password. Your email address is held by Amazon Cognito, the sign-in service we use, in Tokyo. If you choose Continue with Google, Google tells Amazon Cognito your email address and an identifier for your Google account, and nothing else (section 5.4).
2.5 What we do not collect
We do not record your IP address or your browser's user-agent string. Our access logs hold a method, a route, a status and a duration — no query strings, no headers, no request bodies.
We set no cookies. No analytics, no advertising pixels, no tag manager, no session recording, no error-tracking service. Our fonts are served from our own domain, so no font network learns you visited.
The same is true of every picture. The home page's background video and one photograph on it used to be loaded from Pexels and Unsplash, which told those companies your IP address and browser. Since 7 September 2026 they are our own copies, served from our own domain, and no page of this site — the home page included — asks another company for anything it shows you.
2.6 What your browser stores
No cookies. What this site keeps in your browser's own storage is:
it as a password: anyone who can use your browser profile can open that résumé.
its sign-in library in your browser's local storage. They keep you signed in for up to 30 days, and anyone who can use your browser profile in that time is signed in as you. Signing out removes them.
open. Closing the tab forgets it.
example how wide your library is drawn and whether a document is shown beside its original. None of them contains anything from your résumé.
- A key to a résumé made without signing in, so you can return to it. Treat
- If you sign in, your sign-in tokens — issued by Amazon Cognito and kept by
- Your agreement to the transfer in section 6, for as long as the tab is
- Your chosen interface language, and a few display preferences — for
If you open a résumé from a link containing a key, we strip the key from the address bar. Be careful sharing such a link — it grants access to whoever holds it.
3. What we use it for (利用目的)
Only these purposes:
1. converting your résumé into a 履歴書 and 職務経歴書 — reading your file, extracting the facts, translating them, and laying out the documents; 2. screening uploads for content that should not be processed — this step can be switched off by the operator, and when it is off, an upload is converted without being screened first; 3. drafting 職務要約, 志望動機 and 自己PR from facts already in your résumé, when you ask, and assisting edits you request; 4. showing you your documents, letting you edit them, and letting you download them; 5. keeping your résumés in your library so you can return to them; 6. operating the service — signing you in, taking payment, diagnosing failures, preventing abuse; 7. answering you when you write to us, and complying with law.
We do not use your résumé to train, fine-tune or evaluate any AI model. We do not use it to improve this service. We do not sell, rent or licence it. We never send it to employers, recruiters or agencies. There is no feature that shares or publishes your documents. Only you can download them.
If we ever want to do any of this, we will ask you first, separately. We will not do it by quietly editing this page.
4. Sensitive information
Japanese law gives special protection to information about race, creed, social status, medical history, disability, criminal record, and being the victim of a crime.
We never ask for any of it. But a CV is free-form, and yours might contain some — a medical reason for a gap, a disability disclosure, a religious institution you studied at. If it does, it is processed with everything else and sent to the AI companies with everything else.
A photograph needs a specific word. A photograph is not sensitive information by itself. But Japanese law treats a physical disability apparent from someone's appearance as sensitive — so a photograph can carry sensitive information without either of us intending it.
For that reason we ask separately and explicitly for your agreement before taking a résumé that may contain sensitive information. The law allows no alternative to consent for this category.
A real limit worth stating. The photograph you upload for the 履歴書 is never sent to any AI company. It goes only to our own layout software, which draws it onto the page. But if the résumé file you upload has a photograph *printed on it*, that page is turned into an image and read like any other page — so that photograph does leave.
Gender and nationality are not "sensitive information" under Japanese law, but they are personal information and we treat them as such. Both are optional. We never guess either: if your résumé does not say, we leave it blank. On the 履歴書 we print the statutory note that stating your gender is optional.
5. Who else sees your information
5.1 Amazon Web Services — Tokyo
We run on AWS in the Tokyo region. Your uploaded file, the extracted record, your photograph and your finished documents are stored there, encrypted. AWS does not access the contents.
Your email address and sign-in credentials are held by Amazon Cognito, also in Tokyo.
Our website is delivered through Amazon CloudFront's global network, so the connection between your browser and us may be handled at a location outside Japan.
5.2 The AI companies
This is the most important disclosure on this page.
Reading, understanding and translating a résumé is done by AI models.
We do not run these models ourselves. We send our requests to a service called OpenRouter, which provides access to models from many different AI companies. Which model handles your résumé depends on the task — reading images of pages needs a different kind of model from translating text — and on our own testing of which models produce the best documents.
We change which models we use as better ones become available, and we may do so without notice. What does not change without notice is the list of companies your résumé may reach, and the countries they are in. That list is below, and we will update this page before adding to it.
Your résumé may be read by any of the following companies:
| Company | Country |
|---|---|
| OpenRouter (the service that routes our requests) | United States |
| OpenAI | United States |
| Anthropic | United States |
| United States | |
| DeepInfra, Parasail, Novita and similar hosting companies | United States |
| Mistral AI | France |
| Alibaba (Qwen models) | China / Singapore |
| DeepSeek | China |
A note on how models reach us. Two of the models we use, Qwen and DeepSeek, were created by Chinese companies and published under open licences that let any company run them. Depending on which company OpenRouter selects for a given request, these models may be run either by hosting companies in the United States, or by Alibaba or DeepSeek themselves. We do not control that choice on a request-by-request basis, which is why both possibilities are named here.
What is sent, by step:
| Step | What leaves |
|---|---|
| Reading your file | An image of every page of your résumé, as uploaded — including any photograph printed on it |
| Screening | The full text of your résumé |
| Extracting the facts | The full text of your résumé |
| Translating | The translated values, plus your name and full street address (needed to produce ふりがな readings), and your gender and nationality. Your date of birth, telephone number, email address, postal code and links are not sent at this step. |
| "Fix with AI" | The one value you are editing — or, for a drafted section, a summary of your career that deliberately excludes your name, address, telephone number, email address and date of birth. Plus any job advertisement you pasted. |
Laying out and drawing the documents uses no AI at all. That is ordinary software on our own servers, which is why your photograph and date of birth never leave for that step.
We instruct these companies not to use your résumé for training, and we choose services that do not retain it.
5.3 Stripe — payments
When you buy a pass, you pay on a page run by Stripe (Stripe, Inc., United States, and its affiliates), not on ours. You type your card details and email address into Stripe's page; we never receive your card number. We send Stripe a random identifier for your account and which pass you chose, and Stripe tells us whether the payment succeeded. Stripe handles what you give it under its own privacy policy, and may process it in the United States (section 6.2 describes what that means). We keep a record of each payment — the pass, the amount, the date and Stripe's reference for it — with your account.
5.4 Google — signing in
If you choose Continue with Google, Google (Google LLC, United States) learns that you signed in to this site, and tells Amazon Cognito your email address and an identifier for your Google account. We ask Google for nothing more. Google handles this under its own privacy policy. If you sign in with an emailed code instead, Google is not involved.
5.5 Nobody else
No analytics provider, no advertising network, no data broker, no email marketing service, no error-tracking service. Japanese postal-code lookup runs entirely on our own servers from a local copy of Japan Post's published data — using it sends nothing anywhere.
We use no external diagnostic or tracing service. Until 6 September 2026 model calls were traced to a company in the United States, which meant the contents of a résumé were copied to them; that was switched off on that date and they receive nothing. What we keep to investigate a failed conversion is written inside our own AWS account in Tokyo and is deleted with the job.
6. Sending your information outside Japan
Japanese law treats sending personal data to a company in another country as something you must agree to in advance, having first been told specific things. This section is those things.
We ask for your agreement before your résumé is processed. If you do not agree, we cannot convert it, because the conversion is the transfer.
6.1 Where it goes
To the companies listed in section 5.2, in these countries: the United States, France, China and Singapore.
6.2 What protection those countries offer
We are required to tell you how protection in each differs from Japan, and not to soften it.
The United States has no single national data protection law equivalent to Japan's. Protection is a patchwork of sector-specific federal laws and individual state laws, and whether any covers your résumé depends on the company and the state. There is generally no national right for you to demand access to, correction of, or deletion of your data from a US company in the way Japanese law gives you against us. United States law also lets government authorities compel companies to hand over data they hold, under surveillance powers that apply to people who are not US citizens and that do not require your knowledge or agreement.
China has a national data protection law, the Personal Information Protection Law, which does give rights of access, correction and deletion, and which treats face images as a sensitive category requiring separate consent — in that specific respect it is stricter than Japanese law. However, Chinese law also requires companies to assist state security and intelligence authorities and to provide access to data they hold, under the Cybersecurity Law, the Data Security Law and the National Intelligence Law. Japan's Personal Information Protection Commission has published an assessment identifying those obligations, and China's data-localisation rules, as matters that may significantly affect your rights. It has also published a specific notice about DeepSeek, advising that data it acquires is stored on servers in China and is subject to Chinese law. China is not a country the Commission recognises as offering protection equivalent to Japan's.
Singapore has a national data protection law, the Personal Data Protection Act, providing rights of access and correction. It is not a country the Commission recognises as offering equivalent protection.
France is in the European Union and is covered by the GDPR, which the Commission has formally recognised as offering protection equivalent to Japan's. Of all of these, this is where your data is protected on terms closest to Japanese law.
In every case: we cannot prevent a lawful government demand made to these companies, and we would generally not know it had happened.
6.3 What the recipients do to protect it
Japanese law requires us to tell you what each company actually does, in substance. Here it is, as at 6 September 2026. Where a company has not published something, we say so rather than leave a comforting gap.
OpenRouter (United States). Every request passes through OpenRouter before reaching any model, so it is a recipient in its own right. It states that it does not log prompts or completions by default, does not use them to train models, and does not keep uploaded images beyond the time needed to route the request — except for abuse detection, security, billing or legal compliance. It publishes a data processing agreement incorporating the European Commission's standard contractual clauses, and a list of its own suppliers.
OpenAI (United States). OpenAI does not use content sent to its business API to train its models, and has not since March 2023. This differs from the consumer ChatGPT product, which may train on what people type there. Content is kept up to 30 days to check for misuse, then deleted. OpenAI staff, and specialist contractors in the United States, Canada and the Philippines bound by confidentiality obligations, may read content its automated systems flag. It holds SOC 2 Type 2, ISO 27001, ISO 27701 and ISO 42001 certifications and offers a data processing agreement anyone can accept online. One thing specific to photographs: every uploaded image is automatically scanned for illegal child-abuse imagery, and if that scan flags an image, OpenAI keeps it for a person to look at. That happens even where stricter privacy options have been purchased, and we cannot switch it off.
Anthropic (United States). Anthropic's business terms state that it may not train its models on customer content. Content is deleted within 30 days, unless its automated safety systems flag it — flagged material can be kept up to two years. Its staff can read content only through a controlled, tamper-logged access path, and only when something is flagged. Uploaded images are deleted immediately after processing, are never used for training, and Anthropic's model refuses to identify people in photographs. It holds SOC 2 Type 2, ISO 27001 and ISO 42001, and its data processing agreement is accepted automatically with its commercial terms.
Google (United States). Google's terms differ sharply between its free and paid services, and the difference matters enough to state plainly: on the free tier Google does use what is submitted to improve its products, and its own terms tell developers not to send personal information there. We do not use the free tier. On the paid service Google does not use your content to train its models; it keeps data for 55 days to monitor misuse. Google holds SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 27701 and ISO 42001.
Mistral AI (France). Mistral is a French company, and France is one of the countries Japan's Personal Information Protection Commission recognises as offering protection equivalent to Japan's — so of all the companies here, this is the one where your data is protected on terms closest to Japanese law. It publishes a data processing agreement with standard contractual clauses, audit rights and deletion within 30 days of termination, and states compliance with ISO 27001, ISO 27701 and SOC 2 Type II. Content is kept for 30 rolling days to monitor abuse. You should know one thing: Mistral uses inputs and outputs to train its models by default on every tier except Enterprise. We use routing options that avoid this, and we do not send your résumé to Mistral on terms that permit training.
United States hosting companies running open-licence models (DeepInfra, Parasail, Novita and similar). These run the Qwen and DeepSeek models on their own hardware in the United States. OpenRouter records them as not retaining prompts and not training on them.
Alibaba (China / Singapore). Where a Qwen request is served by Alibaba Cloud itself, it reaches its Singapore endpoint, whose datacentres are recorded as being in Singapore and China. A Japanese customer contracts with Alibaba Cloud (Singapore) Private Limited under Singapore law. Alibaba publishes a data processing agreement with standard contractual clauses, states that its Model Studio service has passed a SOC 2 audit, and encrypts data with AES-256. Its international documentation says customer data is never used for model training, though this appears in a help page rather than in a binding agreement, and its mainland Chinese agreement instead says data will not be used for training "without your authorisation". Alibaba publishes no retention period and no data-residency commitment, so we cannot tell you how long it keeps your data or guarantee that processing stays in Singapore. Its mainland terms reserve the right to review inputs by automated or human means; its international terms say nothing either way.
DeepSeek (China). Where a DeepSeek request is served by DeepSeek itself, its privacy policy states that it collects, processes and stores personal data in China, and that inputs and outputs may be used — after de-identification — to train its models. An opt-out exists only inside its consumer app; no equivalent control is documented for programmatic access. It publishes no retention period, no data processing agreement, no standard contractual clauses, no list of its own suppliers, and no security certification of any kind. Its terms are governed by mainland Chinese law with disputes heard in Hangzhou. Its terms also state that the service is not designed to process sensitive personal data including biometric data and that users should not provide it, while separately undertaking not to extract facial-recognition features from photographs.
What none of them has. None of these companies' data processing agreements mentions Japan or the Act — they are written around European, British and Californian law, and two of them have no such agreement at all. And none of them performs the actual processing inside Japan: one offers storage in Japan but not processing, and the rest process elsewhere. We tell you this because we would rather you knew the limits of what we can promise.
6.4 If you would rather not
You can browse this site without uploading anything. But we cannot produce documents without the transfer described above. If you withdraw your agreement, tell us and we will delete everything we hold about you.
7. How long we keep it
| What | How long |
|---|---|
| A résumé made without an account | 24 hours from when you last opened it |
| A résumé in an account with a pass that is running | Until you delete it, or close your account |
| A résumé in an account whose pass has ended | 30 days after the pass ends, or after you last opened the résumé, whichever is later |
| A résumé in an account that has never bought a pass | 30 days after you last used your account, or after you last opened the résumé, whichever is later |
| An account with no résumés in it that has not been used | 12 months after it was last used; the account and its email address at Amazon Cognito are then deleted |
| Your payment records | With your account, and deleted with it |
| Email you send to privacy@resumeforjapan.com | 365 days from when it arrives, as the record of your request |
| Our server logs | 30 days |
| Our database backups | A rolling 35 days (section 8) |
A process runs every hour and deletes what has passed these limits. Behind it, a storage rule removes any stored file older than 180 days regardless — a safety net against our own mistakes, not the intended mechanism.
8. Deleting your information
You can delete any résumé, and you can close your account entirely. Both are in the app.
Either removes the file you uploaded, the extracted record in both languages, every version of every document we made, your photograph, and your edit history. We check afterwards that nothing remains, and treat it as a failure if anything does.
One exception, and it is time-limited. Our database keeps an automatic backup that lets it be rewound to any moment in the last 35 days, so that a fault or a mistake of ours cannot destroy everyone's résumés. What you delete leaves the live database at once, but stays inside that backup until it ages out — at most 35 days after you delete it. The backup is encrypted, is not readable by the service, and is used only to recover the whole service from a failure. If we ever had to use it, we would delete again what had been deleted before. The files you uploaded and the documents we made are not in this backup: our file storage keeps no previous versions (section 9).
Files you have already downloaded stay on your own computer. We cannot reach those.
If you made a résumé without signing in, there is no delete button — it goes automatically within 24 hours. If you want it gone sooner, email us.
9. Keeping it safe (安全管理措置)
Rules and responsibility. One person is responsible for how personal data is handled here. How data may be acquired, used, stored, provided and deleted is written down, and changes to it are deliberate.
Access. Data is reachable only by the parts of the service that need it, each restricted to what it needs — the component that deletes old résumés, for example, reads only what it needs to decide what is due, and cannot change a record or send one anywhere. A request for a résumé that does not prove ownership is answered as though the résumé does not exist, so its existence cannot be probed.
Encryption. Everything is encrypted in transit, and unencrypted connections are refused outright. Stored files and records are encrypted at rest.
Storage. Our document storage keeps no previous versions, deliberately — so a deleted résumé cannot survive as an old copy.
Downloads. A download link is signed, expires in five minutes, cannot be made to point at your original uploaded file or at our internal working data, and is never cached. There are no permanent public links to anything.
Uploads. Limited to 5 MB, and identified by their actual content rather than their filename.
Limits on the AI. The AI cannot alter your dates, name, kana, address, telephone number, email address, links, photograph, gender, nationality or 本人希望記入欄. It moves your facts between languages and formats. It does not invent them.
Where the data is. Our servers are in Japan. Some of your data is sent to the United States, France, China and Singapore, as described in sections 5 and 6, and we have set out there what that means.
We do not publish our specific access controls or intrusion defences, because doing so would weaken them. Ask us if you need more detail than this.
10. Who at our end can see your résumé
This service has an operator console. Through it, the operator — that is, the individual named in section 1 — can list the conversions the service has performed and open the record behind any of them, including résumés made without an account.
It exists so that failed conversions can be diagnosed. You should know it exists.
11. Your rights
You may ask us to:
electronically
circumstances the Act sets out — including where we no longer need it, where there has been a breach, or where our handling risks harming your rights
- tell you the purpose for which we hold your data
- disclose what we hold about you — and you may ask to receive it
- disclose records of any provision of your data to a third party
- correct, add to or delete information that is factually wrong
- stop using, or erase, your data, or stop providing it to others, in the
How to ask. Email privacy@resumeforjapan.com with what you want and enough detail for us to find your data.
Confirming it is you. For an account, we use the registered email address. For a résumé made without an account, we may need you to show you hold its key — otherwise we cannot tell your résumé from anyone else's. We will not ask for more proof than the request warrants.
Agents. A legal representative, or an agent you appoint, may ask on your behalf.
How long. We respond without undue delay, normally within 14 business days.
What it costs. Nothing. We charge no fee for any request.
If we refuse a request, we will tell you and explain why.
If you are outside Japan, these rights apply to you in the same way. Japanese law protects the personal information we handle regardless of your nationality or where you live.
12. Age
You must be at least 16 to use this service. If you are younger and have used it, ask a parent or guardian to contact us and we will delete what we hold.
13. The AI-written sections
Three parts of the documents we produce — 職務要約, 志望動機 and 自己PR — are drafted by an AI model, only from facts already in your résumé, and only when you ask. They are marked as generated, so you can see which words are not yours. Everywhere else the AI moves your facts between languages and formats; it does not invent them.
No decision about you is made here. We do not score, rank or assess you, and we send nothing to any employer. What we produce is a document you read, edit and decide what to do with. Please do read it before sending it anywhere — it carries your name.
14. If something goes wrong
If personal data here is leaked, lost or damaged, we will report it to Japan's Personal Information Protection Commission and tell the people affected, within the deadlines the law sets. Because résumés commonly contain sensitive information, we treat any such incident as reportable however few people it affects.
15. Complaints
Write to us first: privacy@resumeforjapan.com. We would rather hear it than not.
If you are not satisfied, you may complain to the Personal Information Protection Commission (個人情報保護委員会) — https://www.ppc.go.jp/
16. Changes to this page
If we change this page we will post the new version here with a new date. If a change materially affects how we use information we already hold — in particular, anything letting us use your résumé for a new purpose — we will ask your agreement again rather than assume it from a notice.
17. Governing law
This policy is governed by the laws of Japan. This does not deprive you, as a consumer, of the protection of mandatory rules of your own country of residence.
This policy is published in Japanese and English on the same page, Japanese first. The Japanese text is a translation provided for accessibility and has not yet been reviewed by a Japanese lawyer; until it has been, the English text is the operative one. Where the two differ, tell us at the address in section 1 and we will correct the translation.
*Established: 6 September 2026 · Last revised: 6 September 2026*
Policy version 2026-09-08 · このポリシーのバージョン 2026-09-08