← Back to Draw+ for Windows

Draw+ for Windows — Privacy Policy (Handling of Personal Information)

Service: Draw+ (Draw+ for Windows, the "Service")

Established: June 12, 2026 Last revised: June 12, 2026

1. Basic Policy

shokoma (the "Company") recognizes the importance of users' personal information in providing the Service, complies with the Act on the Protection of Personal Information ("APPI") and other applicable laws and guidelines, and handles personal information appropriately in accordance with this Privacy Policy (this "Policy").

The Service is designed around a "local-first" principle: the artifacts you create and edit — diagrams, models, and the like — are, in principle, stored only in local files on your own device. Except for the limited information described below (such as account and billing status), the Company does not collect or retain your artifacts themselves (Section 10).

2. Business Operator Information (Personal Information Handling Operator)

  • Operator: shokoma
  • Address: Disclosed without delay in writing or by email upon request.
  • Representative: Shohei Komatsu
  • Personal Information Protection Manager: Shohei Komatsu
  • Contact: https://shokoma.com/contact

3. Definitions

  • Personal information: "personal information" as defined in Article 2(1) of the APPI — information about a living individual that can identify the specific individual by name, email address, or other description (including information that can be readily collated with other information, thereby identifying the individual).
  • User: anyone who uses the Service (whether or not they have created an account).
  • Account: the user-identifying information tied to an individual user, created by signing up / signing in to the Service.
  • Artifacts: the diagrams, models, nodes, text, and other data that a user creates or edits using the Service.

4. Information We Collect and How

The Company collects the following information to the extent necessary to provide the Service.

4.1 Account Information (Authentication)

The Service's account feature uses Firebase Authentication (provided by Google LLC). When you sign up / sign in, the following is collected:

  • Email address
  • An account identifier assigned by the authentication platform
  • Password (the Company does not retain plaintext passwords; they are managed securely by the authentication platform)
  • Authentication-related metadata such as sign-in timestamps and method

4.2 Payment / Subscription Information

Payments for the Service are processed through the payment platform provided by Stripe (Stripe, Inc. and its affiliates).

  • Payment details such as credit card number, expiration date, and security code are collected and managed directly by Stripe and do not pass through the Company's devices or servers. The Company does not retain this card information.
  • The Company (or its billing-management service) collects and retains only the minimum information needed to determine billing status: an identifier for your account, an identifier issued by the payment platform, and your subscription state and billing period.

4.3 Usage / Diagnostic Information (Telemetry)

Usage and diagnostic information (telemetry) for quality improvement and defect analysis is not sent by default (opt-in). Only if you explicitly enable it in settings may anonymous or pseudonymized usage statistics and error information be collected. In air-gapped environments, telemetry can be fully disabled.

4.4 Information Associated with AI Features

The Service's AI Co-Pilot runs on your device (on-device) by default and does not send diagrams, models, prompts, or the like externally.

  • Only if you voluntarily select (opt in to) a cloud LLM (a language model provided by an external AI vendor) will the prompts you enter and related model information be sent to that external AI vendor. In that case, handling is also subject to that vendor's privacy policy.
  • Unless you select a cloud LLM, using AI features does not transmit your artifacts externally.

4.5 Inquiry Information

If you contact us, we collect the content of your inquiry, your email address, the history of correspondence, and similar information.

4.6 Information Stored Only on Your Device

Artifacts (diagrams, models, etc.), the list of recently opened projects, and locally cached authentication / subscription-status information are stored on your device. These are not sent to the Company's servers and are not collected by the Company.

5. Purposes of Use

  1. To provide the Service, verify identity, and authenticate / manage accounts
  2. To handle subscription sign-up, billing, renewal, cancellation, and status determination (including determining whether the save feature is available)
  3. To charge fees, process payments, and issue receipts / invoices
  4. To respond to user inquiries and provide support
  5. To address defects and to maintain and improve the quality and features of the Service (where telemetry is enabled)
  6. To detect, prevent, and respond to violations of the terms and to misuse
  7. To send important notices (changes to terms / policies, material changes to or failures of the Service, etc.)
  8. To fulfill legal obligations

If the Company handles personal information beyond the above purposes, it will obtain your consent in advance.

6. Provision to Third Parties

The Company will not provide personal information to third parties without your prior consent, except where:

  1. required by law;
  2. necessary to protect a person's life, body, or property and obtaining consent is difficult;
  3. especially necessary to improve public health or promote the sound upbringing of children and obtaining consent is difficult;
  4. necessary to cooperate with a state agency, local government, or their delegate in performing legally prescribed duties, and obtaining consent may impede those duties; or
  5. personal information is provided in connection with a business succession due to a merger or other cause.

7. Subcontractors / External Services

The Company may outsource all or part of the handling of personal information, or integrate with external services, to the extent necessary to achieve the purposes of use, and will exercise necessary and appropriate supervision over such parties. The main external services are:

External serviceProviderMain information handledPurpose
Firebase AuthenticationGoogle LLCEmail address, user UID, authentication metadataAccount authentication / management
Stripe (payments / Customer Portal)Stripe, Inc. and othersPayment details (not retained by the Company), customer ID, billing statusPayment / subscription management
Cloud LLM (only if you opt in)The AI vendor you selectPrompts you enter, etc.Providing AI assistance features

Please refer to each provider's privacy policy regarding their handling of personal information.

8. Retention Period

The Company retains personal information only for the period necessary to achieve the purposes of use or as required by law, and promptly deletes or anonymizes it thereafter. If you delete your account, the Company will delete account-linked information it holds within a reasonable period, except information subject to retention obligations under billing, tax, or other laws.

9. Security Management Measures

  • Delegating authentication and payments to proven external platforms (Firebase Authentication, Stripe) and designing the system so the Company does not retain sensitive information (plaintext passwords, card details)
  • Encryption in transit (HTTPS) and appropriate protection of stored data
  • Minimizing access privileges and limiting the personnel who handle data
  • Keeping authentication / subscription tokens stored locally short-lived and discarding them on sign-out
  • Limiting data retained by the Company to the minimum needed for billing and authentication (data minimization)

10. Local-First Principle (Artifacts Not Transmitted)

The Service stores your artifacts (diagrams, models, etc.) only in local files and does not offer cloud storage or cross-device sync. The Company's servers do not collect or store your model contents, project contents, or telemetry (except when opted in). Signed subscription-status tokens and other data never contain the body of your artifacts.

11. Cookies and Similar Technologies

The desktop application itself does not primarily use cookies in the way a web browser does. However, when a browser is used for payments / Customer Portal (Stripe) or authentication, those external services may use cookies, etc., subject to their respective policies.

12. Your Rights

As provided by law, you may request the following regarding your personal information held by the Company:

  • Notification of the purpose of use
  • Disclosure (including provision of electromagnetic records)
  • Correction, addition, or deletion of content
  • Suspension of use or erasure
  • Suspension of provision to third parties

To make such requests, contact us via the channel in Section 16. After verifying your identity, the Company will respond within a reasonable period in accordance with law.

13. Cross-Border Transfer of Personal Information

Some external services used by the Service (Google, Stripe, the cloud LLM vendor you select, etc.) may process information on servers outside Japan. Please understand in advance that such cross-border transfers may occur when you use the Service and opt in to certain features.

14. Use by Minors

If you are a minor, please use the Service (particularly subscribing to the paid plan) only with the consent of a parent or other legal representative.

15. Changes to This Policy

The Company may revise this Policy in response to changes in law or the Service. For material changes, the Company will provide notice by posting on the Service or by other appropriate means. The revised Policy takes effect when posted on the Service.

16. Contact