JP.Company Inc. (the "Company") sets out below how personal information is handled in Workers Chat (the "Service").
The Service is a chat tool used by companies (each a "Client Company") to communicate with the staff working that day (each a "User").
1. Information We Collect
For Users, the Service collects the following.
- Display name (it does not have to be your real name — use the name you want to be called on site)
- Selected language
- The text of messages you send, and their machine translations
- Photos you send
- Status reports such as arrival, running late, or feeling unwell, together with their timestamps
- Your device language setting (used only to choose the initial display language)
- The temporary join token and its usage timestamps (stored in a cookie on your device)
- Where the Client Company has issued individual join links, the name and other roster details the Client Company registered for that link
The display name is optional. If you join without entering one, the Service automatically assigns a placeholder such as "Staff 1".
A Client Company may issue a different join link for each person. Where it does so, the Client Company can link the messages, status reports, and one-to-one consultations of a person who joined through that link to the name and other roster details it holds for them. This is equally true if you leave the display name blank or use a display name that differs from your real name. Roster names are visible only to the administrators of the Client Company that issued the link, and are never shown to other Users. The join screen and other User-facing screens do not indicate whether a link is an individual one.
Your display name and the content of your messages are visible to the other Users at the same site. Roster names are not shown to other Users.
For Users, the Service does not collect the following.
- Email address
- Phone number
- Postal address
- Date of birth
- Identity documents or identity-verification photographs
For Administrators (representatives of a Client Company), we collect the name (display name), email address, and authentication information (passwords are stored hashed; the Company does not hold them in plain text).
2. Purposes of Use
We use the information collected for the following purposes.
- To enable communication, status sharing, and private consultations at the work site on the day
- To automatically translate messages and announcements into each User's language
- To let Administrators see who is attending and run the work site
- To prevent misuse, investigate incidents, and improve the quality of the Service
- To respond to obligations under applicable laws
We do not use this information for advertising, and we do not sell it to third parties.
3. Disclosure to Third Parties and Transfers Outside Japan
The Service transmits information to the external providers listed below. All of these providers' servers are located outside Japan (primarily in the United States), so this constitutes a cross-border transfer of personal data.
For machine translation, we transmit the text of messages and announcements to the following providers.
- Google LLC (USA) — Gemini API, used as the primary translation processor.
- Groq, Inc. (USA) — Groq API, used as a fallback when the request to Google fails.
Only the message text and the target language codes are sent; display names, work site names, and photos are not sent. If both providers fail, the original text is shown as-is.
We also use the following providers to operate the Service.
- Supabase Inc. (USA) — database and file storage, and the authentication platform. Message text, photos, display names, status reports, and Administrator account information are stored here.
- Vercel Inc. (USA) — application hosting and runtime. Data passes through this platform in transit.
- Resend (USA) — sending email to Administrators (invitations, password resets, and similar). Recipient email addresses and message bodies are transmitted. We do not send email to Users.
Other than the above, we do not provide personal data to third parties without the individual's prior consent, except where required by law.
4. Retention and Deletion
Information is stored per work site (chat room) and automatically becomes unavailable and is deleted as follows.
- After the scheduled end time, Users can no longer send new messages.
- Two hours after the scheduled end time, Users can no longer view that work site.
- Once the retention period set by the Client Company (30 days by default) has passed, a finished work site is deleted in full, including messages, photos, announcements, and participant information. This deletion is permanent and cannot be reversed.
For misuse investigation and legal compliance, operation records (timestamp, actor, and action) may be retained for a period after the above deletion. These records do not contain message text or photos.
5. Security Measures
We take the following measures to protect the information we collect.
- All communication is encrypted (HTTPS).
- Photos are kept in private storage and are served only to participants or Administrators of that work site, via a time-limited signed URL. URLs cannot be reached by guessing.
- Photos are re-encoded on upload, and capture metadata (EXIF), including capture time and location, is not retained.
- Database access is restricted to the application; direct external access is blocked.
- Administrators can only see their own company's information and cannot reach other companies' data. Users can only see the work sites they joined.
- User join tokens are stored hashed; the Company does not hold them in plain text.
6. Requests for Disclosure, Correction, or Deletion
We respond to requests from individuals to disclose, correct, add to, delete, or stop using their retained personal data.
Because the Service does not collect email addresses or other contact details for Users, we generally cannot identify a User on our own. Users should therefore make such requests through the representative at the company they work for. You may also contact our desk directly (in that case, we may confirm your identity with the company you worked for).
Administrators may contact our desk directly. The contact details are on the "Contact" page of this site.
7. Use of Cookies
The Service uses cookies for the following purposes.
- To keep Administrators signed in
- To remember the work site a User has joined, so that reopening the URL does not require joining again
- To remember the selected display language
The Service does not use cookies for advertising or behavioural targeting. If you disable cookies in your browser, the Service will not work correctly.
8. Changes to This Policy
We may revise this Policy in response to changes in law or in the Service. If we do, the revised contents and the effective date will be posted on this page. For significant changes, we will notify Client Companies in advance.
9. Contact
For questions about this Policy or about how personal information is handled, please use the contact details on the "Contact" page of this site.