Skip to content

Privacy Policy

SoleKado ("the Service") does not send your work logs or contract information to any server we run. This policy sets out, for the exchanges that do take place — the Google Calendar integration, payment and enquiries — what we obtain, what we use it for, and who we pass it to.

Last updated

This English text is a reference translation provided for convenience. Only the Japanese version, at /legal/privacy/, has legal effect; if the two differ, the Japanese version prevails.

1. How the Service works

The Service is an application for sole proprietors and people working a second job. It records your work logs and turns them into invoices and work reports.

All data is stored in the browser on your own device (IndexedDB). We run no server-side database, so there is no route by which your records could reach us in the first place.

This policy applies to the website and the application served at https://solekado.endots.dev.

We keep no database on any server. Your work logs and contract information never reach us.

2. Information we do not obtain

Everything listed below is handled only on your own device and is never sent to any server we run.

  • The terms of your contracts and the contents of your contract documents
  • Client names, the names of the people you deal with, and their contact details
  • Work logs (start time, end time, breaks, description of the work) and the hours calculated from them
  • Invoice amounts; the contents of invoices, timesheets (稼働明細) and work reports (業務報告書); and the record of what you have submitted
  • Your own business details: name, trade name, address, telephone number, your registration number as an issuer of Qualified Invoices (適格請求書 / Japan's qualified invoice system), and bank account
  • Contract PDFs you import and the text extracted from them
  • Events imported from a calendar
  • Excel templates you register in place of a supported form, and the document files the Service generates

3. Information stored on your device, and who looks after it

The data in section 2 is stored in IndexedDB, which the browser isolates per origin. Files such as Excel templates are kept in the same place.

From "Backup" in Settings you can export all of your data as a single JSON file. That file contains your business details in plain text, including your bank account number. Please take care where you keep it.

Exporting happens only when you ask for it, and you choose where the file goes. We never receive its contents.

We hold no copy. If you clear the site data in your browser, the data cannot be brought back. Exporting regularly is something you need to do yourself.

4. Permissions requested by the Google Calendar integration

The Google Calendar integration is optional. If you do not use it, no connection to Google takes place at all.

When you connect in order to import events, the two read-only scopes below are the only ones we request. Each is used for the purpose stated beside it and for nothing else.

The one write scope (the third row) is requested separately, and only the first time you use "Export work hours to your calendar" (incremental authorisation). It does not appear on the consent screen of anyone who only imports.

https://www.googleapis.com/auth/calendar.events.readonly
Reading events (events.list). Used to bring calendar events in as candidate work logs and as day records. Read-only: the Service can neither change nor delete an event.
https://www.googleapis.com/auth/calendar.calendarlist.readonly
Reading the list of calendars (calendarList.list). Used so that you can choose which calendars to import from. Read-only.
https://www.googleapis.com/auth/calendar.app.created
Requested only if you use "Export work hours to your calendar". Used to create, update and delete events inside the dedicated calendar the Service itself creates ("SoleKado 稼働"), and nowhere else. It grants no access, read or write, to your existing calendars or events.

The write scope reaches only inside the dedicated calendar the Service created for itself. Events in calendars that already existed cannot be read, changed or deleted with it — they cannot even be listed.

5. How we handle information obtained from Google

Events you import are processed entirely inside your browser and stored in IndexedDB on your device. They are not transmitted to us, to our servers, or to any third party.

By default an event is attached to a date as a day record and is not counted towards your hours worked. Counting a meeting as time worked would double-count the hours you then log properly. Whether to bring an event in as work is a choice you make at each import.

If you use "Export work hours to your calendar", the Service creates, updates and deletes events in the dedicated calendar it created, and only when you explicitly ask it to. It touches events in no other calendar.

The Service's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data obtained through the Service is never used to develop, train or improve artificial intelligence or machine learning models. No human reads it, it is never sold, and it is never provided to third parties.

6. Access tokens, and the traffic a connection generates

An access token is held only in the memory of your browser. It is written neither to IndexedDB nor to a cookie, so it is gone once you close the tab.

No refresh token is issued. When a token expires, a new one is obtained the next time you press the button. The Service never goes to fetch events while you are not using it.

When you start a connection, the Google Identity Services script is loaded from accounts.google.com and requests are made to the Google Calendar API (www.googleapis.com). By the nature of that traffic, connection information such as your IP address and browser type reaches Google and is handled under Google's privacy policy.

7. How to revoke the Google permissions

Pressing "Disconnect" in the settings screen discards the access token held on your device. If a token was still being held at the moment you pressed it, the Service also asks Google to revoke the grant.

If no token is being held, however, pressing "Disconnect" only discards on your side. The access token lives solely in the memory of your browser (section 6), so none is held after you reload the page or close the tab. Pressing "Disconnect" in that state leaves the grant in your Google Account in place. The revocation request can also fail on its own.

To revoke with certainty, remove access for SoleKado under "Third-party apps & services" in your Google Account: https://myaccount.google.com/permissions

Revoking does not remove events already brought into your device; they stay there. Delete them from within the app if you no longer want them.

The one way to revoke the grant on the Google side for certain is https://myaccount.google.com/permissions. "Disconnect" in the app only discards on your device if no token is being held at that moment.

8. Reading .ics files

An .ics file exported from Outlook or Apple Calendar is read entirely on your own device. Neither the file nor anything in it is sent anywhere.

9. Handling of contract PDFs

Contract PDFs are read entirely inside your browser. pdf.js and the files it needs to do the work are served from this site, and nothing in the document is sent to an external API or to a large language model (LLM).

The extracted text is only shown on screen; you check it and decide yourself what to carry over onto the contract. The PDF file itself is not stored, and is discarded once reading has finished.

10. Payment (entrusted to Stripe)

Paid plans are sold on the website only, and payment processing is entrusted to Stripe, Inc.

Your card number, expiry date and security code are collected by Stripe directly. We never receive them.

What we obtain at the point of purchase is your email address and the minimum needed to issue and check a licence: the date and time of purchase, the plan, and the payment identifier. Work logs and contract information never travel through the payment route.

Licences are checked on your own device. The Service does not contact us each time you produce a document.

Stripe's handling of what it collects is governed by its own privacy policy (https://stripe.com/privacy).

Paid plans are still in preparation, and we will give notice when they start. Every feature, document output included, is free to use at present. Nothing in this section applies until the plans are on sale.

11. Cookies, browser storage and analytics

The Service uses no cookies for authentication. There is no sign-in mechanism at all.

We have installed no analytics tools (Google Analytics or any other measurement tag). We neither collect behavioural data nor track anyone for advertising.

If we introduce analytics in future, we will revise this policy and give notice on this page before doing so.

The Service uses the three kinds of browser storage below. All of them sit on your own device, and we cannot read any of them.

IndexedDB
Holds everything listed in section 2: contracts, work logs, your business details, calendar settings, document templates and the files the Service generates. It is the only place the Service puts personal data.
localStorage
Remembers one thing only: whether you have dismissed the notice on the introduction site that tells you the way into the app has moved (key solekado.lp.movedNoticeDismissed, holding the marker "1"). No personal data goes in it.
Cache Storage
The Service Worker keeps a copy of pages you have already opened, so that a screen can still be shown offline. What it keeps is the page itself; work logs and other data are not in it, because the data lives in IndexedDB and is loaded after the screen opens.

IndexedDB is the only one of the three that holds personal data. localStorage holds a single marker for a dismissed notice, and Cache Storage holds copies of pages — neither contains work logs or contract information.

12. Traffic that leaves your device

The three kinds of traffic below are the only ones that can leave the Service. No external web fonts, CDNs, advertising or analytics tags are loaded. The typefaces on screen are the ones already installed on the device you are reading with.

The pdf.js worker used to read contract PDFs, and the built-in document templates (Excel), are fetched from this site rather than from any external host. Both are only fetched; nothing is sent with the request.

The Service Worker that lets the app work offline only keeps a copy of pages you have already opened in a cache on your device. That copy is never sent anywhere.

  • Delivery of this site. It is served as static files from Cloudflare Workers, and by the nature of that platform connection information such as your IP address may be logged when you visit.
  • Traffic from your device to Google when you use the Google Calendar integration (sections 4 to 7). Starting a connection loads a script from accounts.google.com, and reading and exporting events send requests to www.googleapis.com.
  • Traffic to Stripe when you buy a paid plan (section 10). Paid plans are still in preparation, so no such traffic occurs at present.

13. Third parties and subcontractors

We do not provide or sell the information we obtain to third parties.

The only work we entrust to others is payment processing, by Stripe, Inc., and delivery of this site, by Cloudflare, Inc. Neither handles your work logs or contract information. Both are located in the United States, so purchase information and the connection information from your visits are processed there.

The Google Calendar integration is traffic between your own device and Google; it does not pass through us. We neither receive your data from Google nor hand your data to Google.

We will comply with a request for disclosure made under the law. What we hold, however, is limited to our correspondence with you and our record of purchases.

14. Retention and deletion

Data stored on your device stays there until you delete it. We set no expiry and delete nothing ourselves, because we cannot reach it.

Clearing the site data (IndexedDB) in your browser erases all of it. It cannot be brought back. Export whatever you need first, from "Backup" in Settings.

Emails you send us are kept as a record of how we dealt with your enquiry, and deleted once they are no longer needed.

15. Contact

For enquiries about this policy or about how personal information is handled, please use the contact details below.

Operator
Innovare 株式会社
Service name
SoleKado
Email address
[email protected]

16. Changes to this policy

Whenever we change the contents, we update the "Last updated" date on this page.

Before we make a substantive change to what we obtain or what we use it for, before we add a Google API scope, and before we introduce analytics, we will give notice on this page.

If a Google API scope changes, we will ask those who are already connected to consent again — in practice, by pressing "Disconnect" in the settings screen and connecting once more. Section 7 explains how to make sure the old grant is really gone.

Back to home