Privacy Policy

Effective date: August 8, 2026

The USOM operator ("the operator") handles user information in USOM Mail ("this Service") as described below.

1. Role of This Service

USOM is a mail relay service that, using the USOM email address issued to a user as a point of contact, receives, stores, displays, and relays email between the user and external mail services. Where a user has configured forwarding to an external mail service, mail arriving at USOM may be forwarded to the mailbox the user has designated. Mail sent in reply from that mailbox via USOM may also be relayed to the original sender based on delivery information USOM retains.

Relayed mail may appear, from the sending or receiving mail service, to have been sent from a USOM domain or from the delivery infrastructure USOM uses. USOM is not a service that fully anonymizes the content or delivery path of email.

2. Information Collected

The operator collects the following information to the extent necessary to provide this Service.

  • Identifiers, email addresses, display names, and similar information provided through external authentication such as Google
  • The issued email address, and the sender, recipient, subject, body, HTML, and attachments of email received, sent, or relayed
  • Reply relationships, threads, relay destinations, delivery results, and other information necessary for relaying
  • Logs such as timestamps, IP addresses, and device/browser information associated with login, API use, or mail receipt
  • Information a user provides when making an inquiry
  • Payment and contract information where paid features are provided

3. Purposes of Use

  • Authenticating this Service, issuing email addresses, and receiving, displaying, sending, and relaying email
  • Forwarding to a designated external mail service and identifying the recipient of reply email
  • Responding to incidents, ensuring security, and preventing improper use, spam, phishing, and similar issues
  • Responding to inquiries and sending important notices
  • Analyzing usage, improving features, and maintaining quality
  • Responding to laws, courts, administrative agencies, and other legitimately authorized bodies

4. Handling of Mail Content and Relay Information

After receiving mail, and after determining the recipient and performing any necessary mail analysis, the operator encrypts the body, subject, sender information, and other mail content to be stored before saving it to the database. The information necessary to decrypt the mail is kept split across multiple locations, and no single piece of split information is sufficient to decrypt the mail on its own.

Encrypted mail is temporarily decrypted, using the necessary authority together with the separately stored information, only when required for processing such as display, reply relay, countermeasures against improper use, incident response, or legal compliance. Some information necessary for delivery and management, such as the recipient address, mail ID, thread information, receipt time, and delivery results, may be stored without encryption.

Mail is delivered through multiple systems, including the sending mail service, networks, USOM's receiving infrastructure, and the forwarding mail service. While communication segments may be protected by TLS or similar means, mail is not built on an end-to-end encryption model, and content may be processed and stored under the control of each mail service. USOM also handles mail content for the purposes of receipt processing and relay processing.

Mail content is not used for advertising or for AI training for purposes not disclosed to users.

To perform relaying, the operator processes not only the mail body but also the sender, recipient, reply-to address, Message-ID, receipt time, delivery results, and similar data. Where a forwarding mail service is used, mail content and metadata are also passed to that provider. Handling of information by the forwarding provider is governed by that provider's own terms and privacy policy.

5. Retention Period and Deletion

Collected information is retained for the period necessary to achieve the purposes of use, or for the period required by law. Information deleted by a user, accounts that have withdrawn, and unused email addresses or mail are deleted within a reasonable period, except to the extent necessary for backups, legally required retention, or investigation of improper use.

When an account is deactivated, the association between the email address and its owner is retained to prevent the address from being reused. Mail arriving at that address while it is deactivated is not forwarded, displayed, or stored in the usual manner, and is discarded without the body or attachments being saved. To the extent necessary for operations, the operator may retain minimal records such as the recipient, a hash identifying the sender, the Message-ID, the receipt time, and the reason for discarding.

6. Provision to Third Parties and Outsourcing

The operator will not provide personal data, logs, mail, or other user information to third parties without the individual's consent, except in the following cases:

  • Where required by law
  • Where necessary to protect a person's life, body, or property, and it is difficult to obtain the individual's consent
  • Where provided, to the extent necessary, to a subcontractor required to operate this Service
  • Where necessary to respond to improper use, rights infringement, or an attack on the Service

This Service may use third-party services such as Vercel, Prisma, Cloudflare, and SendGrid for hosting, databases, authentication, email delivery, and similar purposes. These providers may handle information outside Japan.

7. Security Measures and Non-Warranty of the Service

The operator implements reasonable security measures, including access control, encryption, restriction of administrator privileges, audit logging, and vulnerability response. However, the operator does not warrant complete security, continuity, or the delivery, storage, or recovery of mail for any internet-based service. The scope of liability regarding use of the Service is set out separately in the Terms of Service.

8. Review by Administrators

The operator does not ordinarily use mail content for advertising to users or for analysis unrelated to operating the Service. However, the operator may review mail content and related data to the minimum extent necessary to respond to spam, phishing, fraud, malware, rights infringement, attacks on the Service, incidents, or other issues. Information reviewed is not used beyond what is necessary to respond to the issue and to comply with law.

9. User Rights

Users may, in accordance with applicable law, request disclosure, correction, suspension of use, or deletion of their retained personal data. The operator may request information necessary to verify identity when handling such a request.

10. Revisions

The operator may revise this Policy in response to changes in law or to the content of the Service. Material changes will be announced on this Service.

11. Governing Law and Jurisdiction

This Policy is governed by the laws of Japan.

For any dispute arising between a user and the operator in connection with this Service or this Policy, the Tokyo District Court, as designated by the operator, shall have exclusive agreed jurisdiction as the court of first instance.

The Japanese-language version of this Policy is the authoritative text, and versions translated into languages other than Japanese are provided for reference only. If there is any discrepancy between the Japanese version and a translated version, the Japanese version shall prevail. The provisions of this section regarding governing law and jurisdiction apply equally to every language version made available.

12. Contact

For inquiries regarding this Policy, please contact us at the address below.

boq4thqk82@kwonwe.com

OSAKA 2024