Privacy Policy
Last updated: August 4, 2026
1. Introduction
This is a reference translation of the Japanese original. In the event of any discrepancy between this English version and the Japanese version, the Japanese version shall prevail.
Speria Inc. (“we,” “us,” or “our”) sets out below how personal information is handled in “torqee” (including the mobile application, the web application, and the API; the “Service”) in this Privacy Policy (this “Policy”).
This Policy explains the types of information we collect in connection with the Service, the purposes for which we use it, our entrustment of processing and our disclosures to third parties, and the rights available to users.
2. Our Role Under This Policy
The Service records business conversations and provides transcription and AI-based analysis. Because of this, the Service handles information relating to the following three parties.
- Customer — a corporation or other organization that has entered into a service agreement with us
- User — an individual who belongs to a Customer and has been issued an account for the Service
- Conversation participant — a person who takes part in a conversation recorded by a User through the Service (for example, a visiting client or a counterparty in a business meeting)
Of these, the conversation audio, its transcript, and the content generated from them (collectively, “Conversation Data”) constitute personal information managed by the Customer, and we process it as a service provider entrusted by the Customer. Except for the creation of statistical information set out in Article 5, we do not use Conversation Data beyond the scope of the Customer’s instructions.
By contrast, account information, authentication-related information, and information about how the Service is used are collected by us and handled under our own responsibility.
Notifying conversation participants of the purpose of use or publicly announcing it, notifying them that recording is taking place, obtaining their consent where required under applicable law, and taking any other necessary measures are the responsibility of the Customer and the User. Because we have no direct contact with conversation participants, we do not obtain consent directly from them. This is also set out in Article 5 of the Terms of Service.
Conversations may also contain special care-required personal information (sensitive personal information), such as information about health conditions or beliefs. Obtaining the consent of the individual required in order to acquire such information, and taking any other necessary measures, are likewise the responsibility of the Customer and the User.
3. Information We Collect
We collect the following information.
Information we collect ourselves
| Category | Contents | How it is collected |
|---|---|---|
| Account information | Email address, display name | Registered by the Customer’s administrator, or entered by the User |
| Authentication information | Identifier in the authentication system, login sessions, IP address, user agent, records of one-time password issuance | Recorded automatically by the server at login |
| Organization and workspace information | Organization name, workspace name, memberships and roles | Registered by the Customer’s administrator |
| Device information | Device type, battery status (used to control uploads), language and region settings | Collected automatically by the application |
| Usage information | Features used, AI service provider, model identifier, number of tokens processed, processing time | Recorded automatically when the Service is used |
| Error information | Error contents, where the error occurred, device information, user identifier | Collected automatically when an error occurs |
Information we process as entrusted by the Customer (Conversation Data)
| Category | Contents | How it is collected |
|---|---|---|
| Conversation audio | Recorded audio data | When a User starts a recording |
| Transcripts | Utterance contents, speaker identification, timestamps, recognition confidence | Generated automatically from the audio |
| Information accompanying a recording | Session labels and memos (these free-text fields may contain information about the person you are meeting or about your clients), records of recording interruptions (the reason for and time of an interruption such as an incoming call or an alarm) | Entered by the User, and recorded automatically by the application |
| AI-generated content | Meeting notes, summaries, checklists, structured analyses, and conversations with the AI during a recording | Generated automatically from transcripts |
| Context information | Descriptions of the business, and descriptions of the User’s role and area of expertise | Entered by the User |
| Agent conversations | Chat message bodies, attached files | Entered by the User |
| Knowledge information | Documents extracted from conversations, terms and their definitions | Extracted automatically from conversations, and edited by Users |
4. Information We Do Not Collect
We do not collect the following information in the Service.
- Location data
- Photographs or video captured with the camera
- Contacts or calendar information
- Telephone numbers
- Credit card numbers or other payment information
- Advertising identifiers
The Service also does not use push notifications, social login (such as authentication via a Google account or Apple ID), third-party analytics tools, or advertising software development kits.
5. How We Use Information
We use the information we collect for the following purposes.
- To transcribe conversation audio and display it with speakers distinguished
- To generate meeting notes, summaries, checklists, and other analyses from the contents of conversations
- To present information that assists Users during a recording
- To explain terms that appear during a conversation
- To answer Users’ questions based on accumulated information
- To accumulate insights obtained from conversations as knowledge and make them searchable
- To measure usage of the Service and issue invoices under the applicable agreement
- To investigate the causes of failures and to maintain and improve the quality of the Service
- To create and use statistical information processed into a form that cannot identify any specific individual, in order to maintain and improve the quality of the Service (such statistical information will not be used in any manner that could identify the Customer or a conversation participant)
- To detect and prevent misuse of the Service
- To authenticate Users and to send important notices regarding the Service
- To respond to inquiries
- To respond to requirements under applicable laws and regulations
6. Entrustment to AI Service Providers
The Service entrusts processing to the following companies for transcription and AI-based analysis. With respect to Conversation Data that we handle as entrusted by the Customer, these companies are further subcontractors.
| Subcontractor | Country | Information handled | Purpose of entrustment |
|---|---|---|---|
| ElevenLabs, Inc. | United States | Conversation audio | Transcription of audio and speaker identification |
| Anthropic, PBC | United States | Transcript contents, context information, agent conversation contents, knowledge information | AI-based analysis and generation |
| Google LLC | United States | Same as above | Same as above |
With respect to this entrustment, we have confirmed the following.
- None of these subcontractors use the disclosed information to train AI models. For ElevenLabs, Inc., we have disabled the use of our data for training in our account settings. For Anthropic, PBC, its commercial API terms provide that customer content is not used to train models. For Google LLC, the terms applicable to paid services apply, under which prompts and responses are not used to improve its products.
- The retention period for disclosed information is, in principle, 30 days for Anthropic, PBC, and 55 days by default for Google LLC.
- Each subcontractor offers a data processing agreement that incorporates Standard Contractual Clauses (SCCs), and we disclose information in accordance with those terms.
- We impose on each subcontractor obligations equivalent to those set out in this Policy and the Terms of Service, and exercise necessary and appropriate supervision over them.
The absence of use for training and the retention periods described in this Article are based on each company’s terms and on our settings as of the date this Policy was last updated. If they change, we will amend this Policy and notify the Customer.
The Customer’s administrator can select, for each feature, whether Anthropic, PBC or Google LLC is used, through the settings screen of the Service. For certain features, however, the provider is fixed.
7. Other Subcontractors
We entrust operations to the following companies in order to provide the Service.
| Subcontractor | Country | Information handled | Purpose of entrustment |
|---|---|---|---|
| Cloudflare, Inc. | United States | Conversation audio, attached files, Service traffic | Provision of storage and execution infrastructure |
| Chiselstrike, Inc. (Turso) | United States | Information stored in the database | Provision of database infrastructure |
| Functional Software, Inc. (Sentry) | United States | Error contents, device information, user identifier | Investigation of failures |
| Mailgun Technologies, Inc. (part of the Sinch AB (publ) group) | United States | Email addresses, the body of messages sent | Sending authentication and invitation emails |
| Brave Software, Inc. | United States | Search queries for terms that appear during a conversation | Retrieval of reference material for explaining terms |
What we disclose to Brave Software, Inc. is limited to the words used to search for a term that appeared in a conversation. We do not disclose conversation audio, full transcripts, or any other Conversation Data. Brave Software, Inc. publicly states that it retains search queries for a maximum of 90 days and then deletes them.
External integrations by Users
If a User enables the Service’s external integration features (such as integration with external applications via the Connect API or MCP, or the configuration of webhooks), Conversation Data will be sent to the destination specified by that User.
We are not responsible for how information is handled at the integration destination. The selection and management of integration destinations are the responsibility of the Customer.
8. Transfers to Third Parties Outside Japan
The subcontractors listed in Articles 6 and 7 are all companies located in the United States. Because this constitutes a transfer to a third party in a foreign country under the Act on the Protection of Personal Information of Japan (the “APPI”), we handle such transfers as follows.
- We have entered into data processing agreements incorporating Standard Contractual Clauses (SCCs) with these subcontractors, and have established the framework necessary to ensure that they continuously take measures equivalent to those that a personal information handling business operator is required to take under Chapter IV, Section 2 of the APPI (“Equivalent Measures”).
- We regularly confirm the status of each subcontractor’s implementation of the Equivalent Measures, as well as the existence of any system in the relevant foreign country and any other information that may affect that implementation. If we confirm that an impediment to implementation has arisen, we will take the necessary action, and if it nevertheless remains difficult to ensure continued implementation, we will cease transfers to that subcontractor.
- At the request of a Customer or an individual, we will provide information about the Equivalent Measures taken by our subcontractors, the method by which we confirm them, whether any impediment to their implementation exists, and any other necessary information. Please direct such requests to the contact set out in Article 14.
- As for Brave Software, Inc., that company takes the position that search queries are not personal data, and it expressly excludes search queries from the scope of its data processing agreement. What we disclose to that company is limited to the words used to search for a term that appeared in a conversation, and it publicly states that it retains such queries for a maximum of 90 days before deleting them.
- With respect to Conversation Data, the provision of information to individuals (conversation participants) concerning transfers to third parties outside Japan, and any other related response, are to be carried out by the Customer that manages that Conversation Data. We will provide the information the Customer needs in order to do so.
9. Retention
We retain the information we collect for the following periods.
| Information | Retention period |
|---|---|
| Conversation Data | For as long as the service agreement with the Customer remains in effect. After the agreement ends, we delete it from our production systems within the period specified in the individual agreement (or, where the individual agreement does not so provide, within 90 days after termination) |
| Account information, organization and workspace information | Deleted within 90 days after the end of the service agreement |
| Authentication information and access records | One year from collection |
| Error information | 90 days from collection |
| Usage information | The period necessary for billing and tax purposes (or, where a period is specified by law, that period) |
Information contained in backups, other copies, and audit logs will be erased in due course upon expiry of the retention period we define, following deletion from the production environment.
Where there is a statutory retention obligation, where retention is necessary to prevent misuse or to resolve a dispute, or where there is another legitimate reason, we may continue to retain information to the extent necessary.
10. Security Measures
We take the following measures to prevent leakage, loss, or damage to the information we collect, and otherwise to manage it securely.
- We have obtained certification for our information security management system (ISMS / ISO/IEC 27001) and operate our management framework accordingly
- We separate databases by workspace so that information is not commingled with that of other Customers
- We encrypt communications, and information at rest is also encrypted
- We limit the personnel who can access information to the minimum necessary and manage access privileges
- We retain records of access to, and operations on, the information
- We maintain internal rules for the handling of personal information and provide training to our personnel
- Where we entrust the handling of personal information, we have established criteria for selecting subcontractors and exercise necessary and appropriate supervision over them
Understanding of the external environment
As set out in Articles 6 and 7, we handle personal data in the United States.
In the United States, there is no comprehensive federal law on the protection of personal information; the matter is instead governed by state laws and sector-specific legislation. There are also systems under which government agencies may obtain information. We have taken these systems for the protection of personal information in the United States into account in implementing the security measures described above and the measures set out in Article 8.
11. Requests for Disclosure, Correction, or Suspension of Use
Where a User or their representative requests disclosure, correction, addition or deletion of contents, suspension of use, erasure, or cessation of disclosure to third parties of retained personal data (collectively, a “Request”), we will respond in accordance with applicable law.
Upon receiving a Request, we will conduct the necessary investigation without delay and, in accordance with applicable law, delete the relevant information from, or suspend its use in, our production systems. Information contained in backups, other copies, and audit logs will be erased in due course upon expiry of the retention period we define, following deletion from the production environment.
However, we may continue to retain information to the extent necessary in any of the following cases.
- Where there is a statutory retention obligation
- Where retention is necessary to prevent misuse or to resolve a dispute
- Where there is another legitimate reason for continued retention
Conversation Data constitutes personal information managed by the Customer and does not fall within our retained personal data. Accordingly, we will direct any Request from a conversation participant to the Customer that manages the relevant Conversation Data. We will take the necessary action based on that Customer’s instructions.
Please direct Requests to the contact set out in Article 14. We will respond after verifying your identity.
12. Cookies
In the web application, we use cookies that are necessary to maintain a User’s authenticated state.
We do not use cookies for analytics or advertising purposes. We have not deployed third-party analytics tools or advertising software development kits.
In the mobile application, authentication credentials are stored in the device’s secure storage (the iOS Keychain and the Android Keystore), and settings such as display language are stored on the device.
13. Changes to This Policy
We may change this Policy due to changes in law, changes to the Service, or for other reasons.
Where we make a change, we will post the amended contents and the effective date on this page. For changes that have a material effect on Users, we will separately notify the Customer or the User before the effective date.
14. Contact Us
For inquiries regarding this Policy or the handling of personal information, and for the requests set out in Article 8, Paragraph 3 and Article 11, please contact us at:
- Company name: Speria Inc. (株式会社Speria)
- Representative: Makoto Nakata, Representative Director and CEO
- Address: EAT PLAY WORKS 4F, 5-4-16 Hiroo, Shibuya-ku, Tokyo 150-0012, Japan
- Contact: inquiry@speria.jp