Privacy Policy

Last updated: July 8, 2026

This is an English reference translation provided for convenience. In the event of any discrepancy between this translation and the Japanese version, the Japanese version shall prevail.

Finsense, Inc. (the "Operator") sets forth this Privacy Policy (this "Policy") regarding the handling of users' personal information and Google user data in the business management service "nextax" (the "Service") provided by the Operator, as follows.

1. Information We Collect

The Service collects the following information.

  • Account information: information required for registration and authentication, such as name, email address, affiliated firm, and role.
  • Business data: information that users create and store on the Service, such as tasks, document requests, client information, and emails.
  • Google integration information: the linked email address and the access tokens used to provide the integration features, obtained when a user connects a Google account (see §3 for details).
  • Usage information: information necessary to provide and improve the Service, such as access logs, operation history, cookies, and device information.

2. Purposes of Use

  • To provide the Service and to verify identity and authenticate users
  • To store, display, and manage the business data created by users
  • To send emails to clients from the user's own Gmail account
  • To import, display, and summarize email exchanges with clients, and to store document files in the firm's Google Drive (see §3 for availability and details)
  • To prevent unauthorized use and ensure security
  • To respond to inquiries and provide important notices
  • To improve service quality and develop new features

3. Handling of Google User Data (Important)

When a user connects a Google account, the Service accesses Google user data, to the extent explicitly authorized by the user, through Google OAuth 2.0. The permissions (scopes) requested by the Operator, together with their purpose and the scope of data involved, are set out in the table below. With respect to the handling of Google user data, this section takes precedence over the other provisions of this Policy.

Of the scopes below, gmail.readonly, gmail.modify, and drive.file are features that become available when a firm that integrates with Google Workspace enables them from the settings screen (opt-in per firm and per user). The features currently available to all users are openid / email / profile and gmail.send. Details of each feature are set out in §3-1 through §3-3.
ScopePurposeScope of DataAvailability
openid / email / profileFor login and identity verification (signing in with a Google Account; confirming the email domain when joining a firm).The Google Account identifier, email address, and basic profile information such as name.Available
https://www.googleapis.com/auth/gmail.sendTo send emails to clients from the user's own Gmail account.The content of emails sent by the user (composed by the user). We do not view, read, delete, or modify the inbox.Available
https://www.googleapis.com/auth/gmail.readonlyTo import email exchanges with clients registered by the firm into the Service, for use in per-client thread views, AI summaries, and other practice-management features.Headers, body, and attachments of emails that match the firm's registered client contacts or email domains (see §3-1).Available (enabled by opt-in at Workspace-integrated firms)
https://www.googleapis.com/auth/gmail.modifyTo apply organizational labels to the user's own Gmail account for imported emails.Only the addition and removal of labels on the user's own mailbox (see §3-2).Available (enabled by opt-in at Workspace-integrated firms)
https://www.googleapis.com/auth/drive.fileTo store document-request files in folders created by the Service, for firms that connect Google Drive.Limited to files and folders created or uploaded through the Service (see §3-3).Available (enabled by opt-in at Workspace-integrated firms)
nextax's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements, for all of the scopes above (openid, email, profile, gmail.send, gmail.readonly, gmail.modify, and drive.file).

Specifically, the Operator complies with the following with respect to Google user data.

  • We use the data obtained solely to provide the features corresponding to each scope (identity verification, sending email, importing and displaying/summarizing client-related email, applying organizational labels, and storing document files).
  • We never use the data for advertising purposes, and we never sell it to third parties. Sharing, transfer, and disclosure to third parties are limited to the cases set out in §3-5.
  • We never use Google user data to develop, improve, or train generative AI or any other machine-learning models — with or without the user's consent. In particular, we do not use Google Workspace API data to develop, improve, or train generalized AI and/or ML models. Data processed by the AI summarization feature is used solely for inference to generate summaries.
  • We do not allow humans to read the data, except where we have first obtained the user's affirmative agreement to view specific data, where necessary for security purposes (such as investigating a bug or abuse), where necessary to comply with applicable law, or where the data (including derivations) is aggregated and anonymized and used for internal operations.
  • We store authentication credentials such as access tokens in encrypted form and manage them under appropriate access controls.

Users may disconnect the integration at any time from the integration settings within the Service ("Gmail Integration" and "Google Drive Integration"). Users may also revoke the Service's access from their Google Account security settings. After disconnection, the access token held by the Operator is invalidated and deleted.

3-1 Handling of gmail.readonly

gmail.readonly is a feature that lets a staff member connect their own Gmail account to automatically import email exchanges with clients, for firms that integrate with Google Workspace. This feature becomes available when a firm that integrates with Google Workspace enables it. For users who enable this feature, we take the following privacy-conscious approach to importing email.

  • Metadata-first screening: When importing email, we first retrieve only header information (such as sender and recipient) and determine whether it matches a client contact or email domain registered by the firm. We do not retrieve the body of emails that do not match (such as personal correspondence).
  • Body retrieved only for matching email: Only for emails determined to match a client do we retrieve the body and attachments, which we store for the firm's practice management.
  • Limited purpose of use: We use the data obtained solely to provide per-client thread views, AI-generated summaries, and other practice-management features.
  • Explicit user consent: This feature is enabled only when the individual staff member explicitly consents on the Google authorization screen (per-user opt-in). Consent may be withdrawn at any time.
  • Handling upon disconnection or departure: If the integration is disconnected, or the user leaves the firm, further email import stops. The handling of already-imported data is as set out in §3-4.

3-2 Handling of gmail.modify

gmail.modify is used to organize imported email. This feature is available to firms that enable it from the settings screen.

  • The only change made is the application of organizational labels (e.g., "Nextax/Client Name") to the user's own Gmail account.
  • We never delete email or modify its content or attachments.
  • This feature can be turned on or off on a per-user basis.
  • Because the label-management-only scope (gmail.labels) does not technically allow labels to be applied to individual messages, we use gmail.modify as the minimum permission required. We never use gmail.modify to delete emails, modify their content, or send emails.

3-3 Handling of drive.file

drive.fileis used, for firms that connect Google Drive (Shared Drive), to switch the storage location for document-request files to the firm's own Google Drive. Access is limited to folders and files created by the Service; we never access other, pre-existing files or folders in the user's Google Drive. Firm users belonging to a firm that connects Google Drive are, in principle, required to sign in via Google Single Sign-On, except for users individually exempted by the firm's administrator; owners cannot be exempted (see Terms of Service §4).

3-4 Retention and Deletion

Imported email data is retained, like other business data handled by the Service, to the extent necessary to achieve the purposes of use, as set out in §7 (Retention Period). Invalidation and deletion of access tokens upon disconnection are as set out at the beginning of this section; however, disconnecting the integration does not automatically delete already-imported email data, which continues to be retained as the firm's business records. To request deletion of imported email data, please contact us as set out in §8 (Requests for Disclosure, Correction, Deletion, etc.). Even after a user leaves the firm, imported email continues to be retained by the firm as a business record, accessible only to the parties involved in the original exchange (deletion requires a request under §8).

3-5 Sharing, Transfer, and Disclosure of Google User Data

The Operator never sells Google user data to third parties. Except in the cases set out below, we do not share, transfer, or disclose Google user data to any third party. We never provide Google user data to advertisers, data brokers, or similar parties under any circumstances.

  • Transfer to service providers (processors): Solely to the extent necessary to provide the Service, Google user data is stored and processed on the infrastructure of the following service providers, which are bound by confidentiality and data-protection obligations: Supabase, Inc. (database, authentication, and storage infrastructure; credentials such as access tokens are stored in encrypted form), Amazon Web Services (processing infrastructure for the AI summarization feature; used solely for inference to generate summaries — Google user data is never used to train AI models), and Vercel Inc. (application hosting and delivery infrastructure; data may be processed transiently for page rendering and file relay but, except for standard operational log retention, is not stored persistently). These providers do not use the data for their own purposes.
  • Transmission to external notification integrations enabled by the user: Only where the user has enabled the Slack notification integration, information contained in notifications (such as email subject lines and comment excerpts) is sent to Slack Technologies LLC to deliver those notifications. Data of users who have not enabled the integration is never sent to Slack. Notifications are delivered to the user's (firm's) own Slack workspace, and Slack Technologies LLC does not use this information for its own purposes.
  • Display within the user's firm (core functionality): Imported emails and stored files are displayed to authorized users within the firm to which the user belongs (for emails, limited to the parties involved in the exchange). This is the very purpose for which users use the Service, and the data is never made available to parties outside the firm.
  • Transmission at the user's direction: where data is sent to a counterparty based on the user's own action or instruction, such as sending an email to a client via gmail.send.
  • Legal requirements: where required by law, or where necessary to protect the life, body, or property of a person and it is difficult to obtain the user's consent.
  • With the user's explicit consent: in addition to the above, where the user has explicitly consented.

If the Operator adds or changes the recipients or processing infrastructure for Google user data, we will update this Policy and provide notice in advance.

4. Provision to Third Parties

The Operator does not provide collected personal information to third parties except in any of the following cases.

  • Where the user has given consent
  • Where required by law
  • Where necessary to protect the life, body, or property of a person and it is difficult to obtain the user's consent

Notwithstanding the above, the sharing, transfer, and disclosure of Google user data to third parties is governed by §3-5.

5. Use of External Services

The Service uses the following external services to provide the Service. The handling of data by each service is governed by the privacy policy of the respective provider.

  • Google LLC (OAuth authentication; email sending via the Gmail API)
  • Supabase, Inc. (database, authentication, and storage infrastructure)
  • Amazon Web Services (AI processing infrastructure for features such as AI summaries; see §3-5 for details)
  • Vercel Inc. (application hosting and delivery infrastructure)
  • Slack Technologies LLC (notification delivery; only where the user has enabled the Slack integration; see §3-5 for details)
  • Resend (delivery infrastructure for system emails such as invitations and inquiries; not used to process Google user data)

6. Security Measures

The Operator takes necessary and appropriate measures—such as encryption of communications, management of access permissions, and encrypted storage of credentials—to prevent the leakage, loss, or damage of the information collected and to otherwise manage it securely. In the unlikely event of an incident such as a data leak, we will promptly notify affected users and the relevant authorities in accordance with applicable law.

7. Retention Period

The Operator retains information to the extent necessary to achieve the purposes of use, and promptly deletes or anonymizes information that is no longer needed. Access tokens related to Google integration are invalidated and deleted upon disconnection or when they are no longer needed. When a service agreement is terminated, business data — including imported email data — is deleted within 90 days of termination, except where retention is required by law.

8. Requests for Disclosure, Correction, Deletion, etc.

Users may request the disclosure, correction, suspension of use, or deletion of their own personal information held by the Operator. Please direct such requests to the contact listed in §10.

9. Changes to this Policy

The Operator may revise this Policy in response to changes in laws or in the content of the Service. When making material changes, the Operator will provide notice by appropriate means, such as posting on the Service.

10. Contact

For inquiries regarding this Policy, please contact us below.

  • Operator: Finsense, Inc.
  • Address: Yamato Bldg. 4F #405, 1-6-16 Kanda-Izumicho, Chiyoda-ku, Tokyo 101-0024, Japan
  • Contact: contact@finsense.co.jp