MONJI+

User Support

Your go-to support page for troubleshooting and getting the most out of MONJI+

Privacy Policy

ALAKI Inc. (“ALAKI,” “we,” “us,” or “our”) establishes this Privacy Policy (the “Policy”) to explain how we collect, use, disclose, store, protect, and otherwise handle personal information and other user information in connection with the MONJI website-production and website-operations support service, and the websites, applications, integrations, extensions, and other related services operated by us (collectively, the “Service”).
Business use only. The Service is intended for business and organizational use and is not intended for personal or household use.
Restricted Regions. The Service is not offered in the countries and regions identified in our then-current Restricted Regions List. Users and Team Customers must comply with the eligibility and Restricted Regions requirements in the then-current MONJI Terms of Service (the “Terms”).

1. Scope, Definitions, and Privacy Roles

1. This Policy applies to information relating to Users, persons invited to use the Service, visitors to the Service or related websites, persons who contact us, and other individuals whose information is processed in connection with the Service (collectively, “Individuals”).
2. “Personal Information” means personal information, personal data, or comparable information relating to an identified or identifiable individual that is protected under applicable privacy or data-protection law. Terms such as “personal data,” “retained personal data,” and “personal-related information” have the meanings given by applicable law, including Japan’s Act on the Protection of Personal Information (“APPI”), where applicable.
3. Cookies, IP addresses, device information, browsing history, usage history, and similar information may not identify an individual by themselves, but may constitute personal-related information or Personal Information when combined with other information.
4. For purposes of this Policy, a “User” is an individual MONJI account holder; a “Team” is a collaboration unit in the Service; a “Team Customer” is the corporation, sole proprietor, or other business entity that is the business user of a Team; and a “Paid Plan Agreement” is an agreement for a paid MONJI plan applicable to a Team. These descriptions are provided for this Policy and do not alter contractual definitions under the then-current Terms.
5. “Customer Content” means feedback comments, target webpage URLs, screenshots, images, attachments, Wiki content, shared materials, Project reference data, AI chat inputs and conversation history, and other content, data, or information created, registered, stored, transmitted, or processed through the Service by or for Users or Team Customers.
6. An “AI Client” means a generative-AI service, AI client, or other external tool selected by a User and connected to MONJI. “AI Integration Features” means integration functionality provided by MONJI using MCP, APIs, plugins, extensions, or similar technical methods. “Write Operations” means supported operations that create, register, modify, delete, change status, assign responsibility, or otherwise change data or state in MONJI.
7. For account administration, contracting, billing, support, security, fraud and abuse prevention, website analytics, legal compliance, and other purposes for which ALAKI determines the purposes and means of processing, ALAKI acts as the controller, business, or equivalent responsible party to the extent applicable law uses such concepts.
8. For Personal Information contained in Customer Content that ALAKI processes on behalf of a Team Customer in providing the Service, ALAKI may act as a processor, service provider, contractor, or equivalent role. Where its scope requirements are met, the then-current MONJI Data Processing Addendum (the “DPA”) applies to that processing.
9. Other capitalized terms not defined in this Policy have the meanings given in the then-current Terms where the context requires. A reference to the Terms or DPA does not cause a later version of either document to take effect before its stated effective date.

2. Information We Collect

We may obtain information directly from Individuals, automatically through use of the Service, or from payment providers and other external services. Depending on how the Service is used, the information may include the following.
2.1 Account and Profile Information
  • Email address; MONJI-issued User identifiers; and name, country, time zone, company name, job title, profile image, and other profile information that a User chooses to enter or configure.
2.2 Team, Project, and Invitation Information
  • Invitee email addresses; Team and Project identifiers; membership information; roles; permissions; settings; and other information required to operate Teams and Projects.
2.3 Contract, Billing, and Payment Information
  • Plan, contract status, amounts billed, billing name, address, postal code, country, billing email address, payment status, payment-provider customer identifiers, card brand, last four digits of a card, and other information reasonably necessary to administer billing and payments.
  • Full card numbers, expiration dates, and security codes are generally transmitted directly from the Individual’s browser to Stripe through Stripe technologies. ALAKI does not obtain or store full card numbers or card security codes.
  • For transactions using Stripe Managed Payments, Stripe or its applicable affiliate may act as merchant of record and may collect additional information required for payment, identity verification, KYC, sanctions screening, tax, refunds, or chargebacks under Stripe’s terms.
2.4 Customer Content
  • Feedback comments, target webpage URLs, screenshots, images, attachments, Wiki content, shared materials, Project reference data, AI chat inputs and conversation history, and other information created, registered, stored, or transmitted through the Service by or for Users or Team Customers.
2.5 External-Service and Integration Information
  • External-service identifiers, connected services, authentication and authorization information, permissions granted, connection and last-use timestamps, identifiers issued by external services, Google Analytics property identifiers, and other information required for integrations.
2.6 Usage, Device, and Security Information
  • IP address, User-Agent, cookies and similar identifiers, browser and operating-system information, access timestamps, page views, operation history, feature usage, error information, internal User/Team/Project identifiers, access logs, authentication and authorization logs, and information concerning suspicious access or security events.
2.7 Communications and Support Information
  • Email address, name, company name, inquiry content, attachments, and other information provided when an Individual contacts us for support, requests, complaints, or other communications.
2.8 Information Received from External Services
  • Payment results, authentication results, Google Analytics information within the scope authorized by the User, and other information supplied by an external service when the User chooses to connect that service.

3. Purposes of Use

We use the information described above only to the extent reasonably necessary for the following purposes:
1. to register and identify Users, authenticate access, and administer accounts;
2. to provide Teams, Projects, feedback, Wiki, file sharing, and other Service functionality;
3. to process paid-plan applications, contracts, billing, payments, taxes, and related administration;
4. to provide AI chat, proofreading, OCR, AI Integration Features, and other functionality using AI or external services;
5. to respond to inquiries, support requests, complaints, and other communications;
6. to send important notices concerning the Service, security, functionality, incidents, contracts, and billing;
7. to provide information about ALAKI services, features, campaigns, seminars, and related offerings, subject to any consent, opt-out, or other procedure required by applicable law;
8. to understand and analyze use of the Service and improve quality, usability, performance, and functionality;
9. to detect, investigate, prevent, and respond to unauthorized access, misuse, Terms violations, fraud, abuse, security issues, and other conduct that may interfere with the proper and secure operation of the Service;
10. to investigate, recover from, and prevent recurrence of failures, bugs, and other technical issues;
11. to comply with law, respond to governmental or judicial requests, preserve or exercise rights, resolve disputes, and protect legitimate rights and interests;
12. to create statistics that do not identify Individuals for Service operations, analysis, and business decision-making; and
13. for purposes incidental to the purposes above.

4. Customer Content and Internal Access

1. Customer Content may include Personal Information of Users and Personal Information, confidential information, or other information relating to a Team Customer’s customers, business partners, employees, contractors, or other third parties.
2. We handle Customer Content only to the extent reasonably necessary to provide, operate, maintain, secure, support, and properly administer the Service, and as otherwise permitted or required by applicable law or the applicable agreement.
3. Access by ALAKI directors, officers, employees, or personnel to the substance of Customer Content is generally limited to situations such as: responding to a User’s support request; investigating or resolving bugs or incidents; investigating or responding to security issues, unauthorized access, or misuse; investigating Terms violations or other improper use; complying with law or responding to governmental or judicial authorities; resolving disputes; or where review is reasonably necessary to provide, maintain, recover, or secure the Service.
4. We do not ordinarily review the body of Customer Content for the sole purpose of routine usage analytics. Where reasonably possible, Service analytics use feature counts, operation history, error information, and other data that does not require routine review of the body of Customer Content.
5. ALAKI does not use Customer Content to train general-purpose AI or machine-learning models as part of ordinary Service operations unless the relevant Team Customer separately and expressly authorizes such use. This does not govern how a User-selected external AI service handles information after receiving it; Section 7 applies to such services.

5. Service Providers, Subprocessors, and Other External Providers

1. We use external providers, may entrust them with processing, and may provide them with information to the extent reasonably necessary for cloud infrastructure, storage, payments, email delivery, AI functionality, security, analytics, and other Service operations.
2. Principal providers and service categories currently used in operating the Service include:
  • Google Cloud Platform, Google Cloud Storage, and Google Cloud Vision API — cloud infrastructure, databases, file storage, OCR, and related processing;
  • Stripe and its applicable affiliates — credit-card payments, subscription management, Managed Payments, merchant-of-record services where applicable, payment fraud prevention, tax, refunds, chargebacks, and related payment processing;
  • Twilio SendGrid — transactional and other Service-related email delivery;
  • OpenAI API — AI chat, text analysis, proofreading or typo detection, and other in-product AI functions; and
  • Cloudflare, Inc. — CDN, WAF, edge delivery, and security functionality.
3. We select and oversee providers in accordance with applicable law and take contractual, security, and other measures that are reasonably necessary and appropriate for the services they perform and the information they process.
4. A User-selected AI Client, connector, or other External Service is not, merely because the User connects it to MONJI, a Subprocessor engaged by ALAKI. The subsequent handling of information by that external service is governed by Section 7 and the external provider’s own terms and privacy policy.

6. International Processing and Restricted Regions

1. The Service is operated primarily from Japan, but external providers and their subprocessors may store, process, or access information outside Japan where reasonably necessary to provide cloud infrastructure, email delivery, payments, AI functionality, security, support, or other Service functions.
2. Where applicable law requires information, consent, a transfer mechanism, contractual safeguards, verification of protective measures, or other steps for an international transfer, we will take the measures required by that law.
3. Because providers may use distributed processing, global security operations, support functions, disaster recovery, or subprocessors, it may not be possible to identify in advance every country or region in which information may be processed.
4. Where applicable law requires us to understand the privacy-law environment of a foreign country or take other security-management measures, we will do so as required by law.
5. Where applicable law requires Individual-specific information or consent before an international disclosure or transfer, we will not treat publication of this Policy alone as a substitute for that legally required step.
6. The Service is not offered in the Restricted Regions identified in the then-current Restricted Regions List. Users and Team Customers must not use the Service in a manner prohibited by the then-current Terms, Restricted Regions List, or applicable law, including any use or processing that ALAKI has expressly identified in those documents as unsupported or prohibited.

7. AI Features and External-Service Integrations

1. The Service may use AI and machine-learning-related services, including the OpenAI API and Google Cloud Vision API.
2. For AI chat, we may send to the OpenAI API, to the extent necessary to provide the feature, the User’s input, conversation history from the same session, and MONJI reference information necessary to generate a response.
3. For proofreading, typo detection, or OCR functionality, screenshots or other images may be sent to Google Cloud Vision API or another image-processing service, and text extracted from such images or other information necessary for processing may then be sent to the OpenAI API or another processing service.
4. The Service may provide integration functionality using the Model Context Protocol (“MCP”), APIs, or other technical methods that allow a User to connect an AI client or other external service selected by that User (an “AI Client” or “External Service”).
5. When a User authorizes a connection, the AI Client or External Service may, within the permissions shown by ALAKI, the permissions the User has in MONJI, and the integration functionality then actually provided by MONJI, obtain information from MONJI or create, register, modify, delete, change status, or otherwise operate on information in MONJI.
6. Information supplied to an AI Client or External Service through an integration may include feedback captures, comments, and other Customer Content and may contain Personal Information, customer information, confidential information, trade secrets, unpublished information, or other third-party information. Information may also be sent from an authorized AI Client or External Service to MONJI and may be created, registered, modified, stored, or otherwise processed in MONJI.
7. For AI Integration Features and other integrations, we may collect and record the connected service, permissions granted, connection time, access time, access target, operation performed, result, acceptance of applicable terms, and other information to the extent reasonably necessary for secure operation, misuse prevention, incident investigation, and other Service operations.
8. After a User-selected AI Client or External Service obtains information from MONJI, that provider’s terms, privacy policy, data-use rules, retention practices, AI-training practices, onward disclosures, and processing locations may apply. Disconnecting the service does not necessarily delete information that the external provider obtained before disconnection.
9. ALAKI does not control the subsequent handling of information by a User-selected External Service. Users and Team Customers are responsible for reviewing the external provider’s terms and privacy policy and for ensuring that they have any rights, consents, approvals, or other legal basis required to allow that external service to obtain or use the information.

8. Cookies and Direct Browser Transmissions to External Providers

1. We may use cookies and similar technologies to provide the Service, improve usability, maintain security, process payments, and analyze usage.
2. At the date of this Policy, the Service uses mechanisms through which a browser may transmit information directly to external providers. The principal recipients, information transmitted, and purposes are described below.
8.1 Google LLC — Google Analytics 4 / Google Tag Manager
Information transmitted: IP address, User-Agent, cookies and similar identifiers, browsing and usage information, MONJI-issued User identifiers, Team and Project identifiers, plan category, and other information reasonably necessary to measure and analyze Service usage.
ALAKI purpose: measuring use of MONJI and related websites, access analytics, analyzing feature usage, and improving the Service.
Recipient purpose: providing, maintaining, protecting, and improving Google Analytics services and other purposes described by Google in its applicable terms and privacy documentation.
MONJI-issued User identifiers sent to Google Analytics do not themselves contain a name, email address, or other information that directly identifies an Individual.
8.2 Google LLC — Google reCAPTCHA
Information transmitted: IP address, User-Agent, cookies, device information, mouse/keyboard interactions, and other usage or behavior information reasonably necessary for abuse and bot detection.
ALAKI purpose: detecting and preventing bots, automated abuse, unauthorized access, and other improper use and protecting the security of the Service.
Recipient purpose: providing and maintaining reCAPTCHA, maintaining security, detecting threats, and preventing and responding to fraud, abuse, and misuse.
reCAPTCHA may be used on account registration, login, password reset, feedback authentication, and other screens, including certain public screens that may be used by persons who do not have a MONJI account.
8.3 Stripe — Stripe.js / Payment and Fraud-Prevention Technologies
Recipient: Stripe and the applicable Stripe affiliate for the relevant transaction or payment flow.
Information transmitted: card number, expiration date, security code and other card information necessary for payment; IP address; and other information reasonably necessary for payment processing, authentication, fraud prevention, or compliance.
ALAKI purpose: securely transmitting payment-card information directly to Stripe without storing full card information on ALAKI servers, processing payments, and preventing misuse or fraud.
Recipient purpose: payment processing and related payment services, fraud and suspicious-transaction detection and prevention, security, identity or KYC checks where applicable, tax and merchant-of-record functions where applicable, and compliance with legal and regulatory obligations.
8.4 Cloudflare, Inc. — CDN / WAF / cdnjs and Related Services
Information transmitted: IP address, User-Agent, Referer information, and other information reasonably necessary for network communications and security.
ALAKI purpose: delivering MONJI content and frontend libraries quickly and reliably and protecting communications, availability, and Service performance.
Recipient purpose: providing, operating, and maintaining Cloudflare CDN, WAF, cdnjs, and related services; maintaining performance, stability, and availability; and detecting, preventing, and responding to unauthorized access, security threats, and other improper or unlawful activity.
3. Individuals may be able to limit cookies through browser settings or other controls. Doing so may prevent all or part of the Service from functioning correctly.

9. Browser Storage

1. In addition to cookies, the Service may use IndexedDB and other browser-provided storage.
2. Information stored in browser storage may include random identifiers used to identify login sessions, recent target-page URLs used to assist feedback entry, settings for recommended-browser notices, MONJI-issued User identifiers, and other configuration information reasonably necessary for the Service to function properly.
3. Certain information, such as recent URL history, may be used only on the Individual’s device for input assistance and may not be transmitted to ALAKI servers.
4. Deleting or disabling browser storage may cause all or part of the Service to stop functioning correctly.

10. Disclosures and Sharing

1. We do not disclose Personal Information to an unaffiliated third party except in the following circumstances: with the Individual’s consent; as required or permitted by law; where necessary to protect life, physical safety, or property and consent is difficult to obtain; where otherwise permitted under public-health, governmental, judicial, or comparable legal exceptions; where the User instructs or authorizes disclosure to a User-selected external service and the required consent or other lawful basis exists; or where otherwise permitted by applicable law.
2. Processing entrusted to a service provider or Subprocessor within the scope necessary to achieve the purposes described in this Policy, or disclosure in connection with a merger, corporate reorganization, or other lawful business succession, is handled in accordance with applicable law and is not treated as a third-party disclosure where the applicable law so provides.
3. We do not sell Personal Information. We also do not share Personal Information for cross-context behavioral advertising as those terms are defined under California law.

11. Retention and Deletion

1. We retain information for the period reasonably necessary to achieve the purposes described in this Policy and for legal compliance, fraud and abuse prevention, security, billing and payment administration, audits, dispute resolution, backups, and other legitimate purposes.
2. When we determine that information is no longer necessary for the purposes for which it is retained, we will delete, de-identify, or otherwise appropriately handle the information in accordance with applicable law and our then-current operational standards.
3. Deletion of an account or termination of use does not necessarily result in immediate deletion of all information. We may retain information for as long as reasonably necessary for legal obligations, security, fraud and abuse prevention, audit, dispute resolution, backups, or other legitimate purposes.
4. Customer Content and Customer Personal Data associated with a terminated Paid Plan Agreement are handled in accordance with the Terms and, where applicable, the DPA. We do not guarantee restoration of data that has been deleted under those documents.

12. Security Measures

1. We implement technical and organizational measures reasonably appropriate to the nature of the information and the risks of processing to help prevent unauthorized access, loss, destruction, alteration, or disclosure.
2. Measures may include governance and handling procedures; limiting personnel access to Personal Information and Customer Content to business-necessary circumstances; identity, authentication, authorization, and permission controls; encryption in transit and other measures for secure transmission; logging and monitoring; personnel supervision; service-provider security review; incident-response measures; and measures required by applicable law for international processing.
3. We may withhold details of security measures where public disclosure could reasonably impair the security of ALAKI, the Service, Users, Team Customers, or third parties.
4. Where applicable law requires us to provide an Individual with information about security measures, we will provide the information to the extent and in the manner required by law.

13. Privacy Rights and Requests

1. Depending on applicable law, an Individual may have rights concerning Personal Information for which ALAKI acts as the responsible controller or equivalent party, including rights to request notice of purposes, access or disclosure, correction, addition, deletion, restriction or cessation of use, erasure, cessation of third-party disclosure, or disclosure of records concerning third-party disclosure.
2. Requests may be submitted through the contact information in Section 17. We may specify a reasonable procedure and request information or documentation reasonably necessary to verify the requester’s identity or authority and to process the request.
3. Where applicable law permits a fee for a request, including certain requests for notice of purposes or disclosure, we may charge a reasonable fee taking into account actual costs and administrative burden. If a fee is charged, we will provide information about the amount, payment method, and other required details.
4. We will respond to requests in accordance with applicable law. We may deny all or part of a request where the legal requirements are not met, we have no legal obligation to comply, or applicable law otherwise permits refusal or limitation. Where applicable law requires notice of a refusal or other determination, we will provide that notice as required.
5. If a request primarily concerns Customer Personal Data that ALAKI processes on behalf of a Team Customer, the requester should generally contact the relevant Team Customer or organization. ALAKI may refer such a request to that organization and will provide assistance to the extent required under the DPA and applicable law.

14. California and Other U.S. State Privacy Rights

1. If an Individual is entitled to rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), or another applicable U.S. state privacy law, ALAKI will provide the rights and procedures required by that law.
2. For Personal Information that ALAKI processes for its own purposes, categories may include identifiers; commercial and transaction information; Internet or other electronic network activity; professional or employment-related information; communications and support information; and other information described in Section 2. Customer Content may contain additional categories, including sensitive information, depending on what a Team Customer or User chooses to submit.
3. ALAKI does not sell Personal Information or share Personal Information for cross-context behavioral advertising. We do not use Sensitive Personal Information for the purpose of inferring characteristics or for other purposes that create a “Right to Limit” under the CCPA/CPRA, except to the extent permitted by law for Service delivery, security, and other permitted purposes.
4. California residents may have rights to know or access Personal Information, request deletion or correction, opt out of sale or sharing where applicable, use an authorized agent, and be free from unlawful discrimination for exercising privacy rights. Additional details, request methods, and applicable timelines are provided on our then-current “Your Privacy Choices” page.
5. We honor valid opt-out preference signals, including Global Privacy Control (“GPC”), to the extent required by applicable law. Because we do not currently sell or share Personal Information for cross-context behavioral advertising, there is currently no such sale or sharing from which to opt out.
6. We do not respond to browser “Do Not Track” (“DNT”) signals unless applicable law requires otherwise.

15. Third-Party Sites, Forms, and Related Services

1. The Service and ALAKI websites may contain links to websites, services, applications, forms, or resources provided by third parties. If an Individual moves to an external service or supplies information to it, the external provider’s terms and privacy policy apply to that subsequent handling.
2. Where a separate privacy notice or privacy explanation is provided for a specific MONJI-related service, extension, form, or feature, that separate notice also applies to the extent relevant.

16. Changes to This Policy

1. We may revise this Policy in response to changes in law, the Service, functionality, external providers, security requirements, or other circumstances.
2. When we revise this Policy, we will publish the revised content and its effective date through the Service, our website, or another method we consider appropriate.
3. Where applicable law requires notice, information, consent, or another procedure in connection with a change, we will follow the procedure required by that law. Continued use of the Service does not by itself replace any consent or procedure that applicable law requires us to obtain.

17. Company Information and Contact

Questions, complaints, and privacy-rights requests concerning this Policy or ALAKI’s handling of Personal Information may be directed to the following contact.
Company
ALAKI Inc.
Address
Osaka Eki-mae No.3 Bldg. 2F-Room5,6
1-2-2 Umeda, Kita-Ku Osaka-City,
Osaka Pref, 530-0001 Japan
Representative
Yuji Yamauchi
Privacy Manager
Yuji Yamauchi
Privacy Contact
This Policy is the governing English-language privacy policy for the global English version of MONJI. If a translation of this Policy is made available for convenience, the English version controls to the extent permitted by applicable law.

Version History

  • Version 1.0 — December 3, 2025 (JST), Established and effective
  • Version 2.0 — September 18, 2026 (JST), Revised and effective
DateChanges
December 3, 2025Version 1.0 — Last updated December 3, 2025 (JST).
September 18, 2026Version 2.0 — Revised and effective September 18, 2026 (JST). Updated and clarified the handling of personal information to reflect MONJI’s AI/MCP integration features and current service operations, including AI Client and external-service integrations, cookies, and direct browser transmissions to external providers.