Service: Draw+ (Draw+ for Windows, the "Service")
Established: June 12, 2026 Last revised: August 16, 2026
shokoma (the "Company") recognizes the importance of users' personal information in providing the Service, complies with the Act on the Protection of Personal Information ("APPI") and other applicable laws and guidelines, and handles personal information appropriately in accordance with this Privacy Policy (this "Policy").
The Service is designed around a "local-first" principle: the artifacts you create and edit — diagrams, models, and the like — are stored by default in local files on your own device. Except for the limited information described below (such as account and billing status), and any project you explicitly choose to save to cloud storage under your own account, the Company does not collect or retain your artifacts themselves (Section 10).
The Company collects the following information to the extent necessary to provide the Service.
The Service's account feature uses Firebase Authentication (provided by Google LLC). When you sign up / sign in, the following is collected:
Payments for the Service are processed through the payment platform provided by Stripe (Stripe, Inc. and its affiliates).
Usage and diagnostic information (telemetry) for quality improvement and defect analysis is not sent by default (opt-in). Only if you explicitly enable it in settings may anonymous or pseudonymized usage statistics and error information be collected. In air-gapped environments, telemetry can be fully disabled.
By default, the Service's AI Co-Pilot commands are handled by a rule-based interpreter built into the application. It runs on your device, is not a generative AI model, and does not send diagrams, models, prompts, or the like externally. The application labels output produced this way as not AI-generated.
If you contact us, we collect the content of your inquiry, your email address, the history of correspondence, and similar information.
Artifacts (diagrams, models, etc.), the list of recently opened projects, and locally cached authentication / subscription-status information are stored on your device. These are not collected by the Company, other than a project you explicitly choose to save to cloud storage under your own account (see section 10).
If you use the built-in feature for reporting AI output you consider inappropriate, the report you submit — including the reported output, any description you add, and the technical context needed to investigate it — is transmitted so it can reach our support contact. You can submit a report whether or not you are signed in.
If the Company handles personal information beyond the above purposes, it will obtain your consent in advance.
The Company will not provide personal information to third parties without your prior consent, except where:
The Company may outsource all or part of the handling of personal information, or integrate with external services, to the extent necessary to achieve the purposes of use, and will exercise necessary and appropriate supervision over such parties. The main external services are:
| External service | Provider | Main information handled | Purpose |
|---|---|---|---|
| Firebase Authentication | Google LLC | Email address, user UID, authentication metadata | Account authentication / management |
| Cloud Firestore (only if you use cloud save) | Google LLC | Contents and metadata (name, timestamps, size) of projects you explicitly save, stored under your own account | Personal-account cloud storage and cross-device access to your own projects |
| Stripe (payments / Customer Portal) | Stripe, Inc. and others | Payment details (not retained by the Company), customer ID, billing status | Payment / subscription management |
| Cloud LLM (only if you opt in) | The AI vendor you select | Prompts you enter, and the model you are working on | Providing AI assistance features |
Please refer to each provider's privacy policy regarding their handling of personal information.
The Company retains personal information only for the period necessary to achieve the purposes of use or as required by law, and promptly deletes or anonymizes it thereafter. If you delete your account, the Company will delete account-linked information it holds within a reasonable period, except information subject to retention obligations under billing, tax, or other laws.
The Service stores your artifacts (diagrams, models, etc.) in local files on your own device by default, and that path is complete on its own. Telemetry is not collected except when you opt in, and signed subscription-status tokens and other data never contain the body of your artifacts.
If you are signed in, you may additionally choose to save a project to cloud storage held under your own account (Cloud Firestore, provided by Google LLC). The following applies to that optional feature:
If you do not sign in, or do not use the cloud save feature, no artifact of yours is transmitted.
The desktop application itself does not primarily use cookies in the way a web browser does. However, when a browser is used for payments / Customer Portal (Stripe) or authentication, those external services may use cookies, etc., subject to their respective policies.
As provided by law, you may request the following regarding your personal information held by the Company:
To make such requests, contact us via the channel in Section 16. After verifying your identity, the Company will respond within a reasonable period in accordance with law.
Some external services used by the Service (Google, Stripe, the cloud LLM vendor you select, etc.) may process information on servers outside Japan. Please understand in advance that such cross-border transfers may occur when you use the Service and opt in to certain features.
If you are a minor, please use the Service (particularly subscribing to the paid plan) only with the consent of a parent or other legal representative.
The Company may revise this Policy in response to changes in law or the Service. For material changes, the Company will provide notice by posting on the Service or by other appropriate means. The revised Policy takes effect when posted on the Service.