Logic Factory Co., Ltd. manages information handled through firestorage.ai in accordance with this Policy.
1. Operator and Scope
This Policy applies to personal information and user-related information handled through firestorage.ai and its websites, APIs, AI Address, MCP integrations, and other related features (collectively, the "Service") provided by Logic Factory Co., Ltd. ("Logic Factory," "we," "us," or "our").
Third-party services linked from or integrated with the Service are governed by their own privacy policies.
2. Information We Collect
We collect the following information to the extent necessary to provide the Service:
- Account information, including email address, email-verification status, language, time zone, plan, AI Address, and other registration or settings information;
- Authentication information, including password hashes, session information, hashed verification and reset tokens, authentication timestamps, and related security data. We do not store plaintext passwords;
- External authentication information when you choose Google Sign-In, including your Google account identifier, verified email address, basic profile information, and information required to authenticate you;
- User Data, including files uploaded, stored, sent, or shared through the Service, and associated filenames, file types, sizes, retention settings, timestamps, descriptions, tags, sharing settings, and other metadata;
- AI and external-client information, including instructions, identifiers, connection information, and activity history submitted by an AI agent, MCP client, or API;
- Usage and device information, including IP address, user agent, access time, referring page, page and activity history, errors, and security logs;
- Cookies and similar information used for authentication, language, consent settings, and, where you consent, analytics or related optional purposes;
- Support information, including your name, email address, inquiry, and communications with us; and
- Contract and billing information needed after paid features launch. As a general rule, we do not store the full payment-card number or security code handled by our payment provider. Information entered on the current billing-preview screen is not submitted or stored.
3. How We Collect Information
We collect information that you provide through registration, upload, inquiry, or other actions; information generated automatically when you use the Service; and information provided by Google, an AI client, or another third-party service that you authorize to connect.
If you provide another person's information through the Service, you must have the authority or consent required to do so.
4. How We Use Information
We use collected information to:
- register, identify, and authenticate users and issue and manage AI Addresses;
- store, send, receive, share, search, and manage the retention of files and otherwise provide the Service;
- connect with AI agents, MCP clients, APIs, and external services that you authorize;
- send verification, password-reset, security, file-delivery, and other transactional or operational notices;
- respond to inquiries and rights requests and improve support quality;
- detect, prevent, investigate, and address unauthorized access, Terms violations, spam, malware, and other abuse;
- handle incidents, monitor and analyze usage, improve quality, develop features, and prepare operational statistics;
- manage contracts, billing, payment, and accounting after paid features launch; and
- comply with law and orders of courts or authorities and protect our rights, safety, and those of others.
5. Files and AI Integration Data
We process your files and associated metadata only as necessary to provide, maintain, and secure the Service and protect it against abuse. We do not sell your files for advertising purposes or use them to train our own AI models.
When you use an AI agent or external client, files, metadata, and operation results may be sent to or received from that provider at your direction. That provider's terms and privacy policy also apply to its handling of the information.
When a user accesses the firestorage.ai MCP features through ChatGPT or another AI client, files explicitly selected by the user and information required for the requested operation—such as the filename, file type, file size, and retention settings—are transmitted from that AI client to us. We return processing results, file information, share URLs, and other information necessary to complete the operation to the AI client. We do not request or collect conversation history that is unnecessary for providing the MCP features. The AI client provider's terms and privacy policy apply to its handling of information.
6. Google Sign-In
If you use Google Sign-In, we receive your Google account identifier, verified email address, basic profile information, and related authentication information. We use it for login, account creation and linking, account identification, security, and support. We do not request access to Google Drive or Gmail.
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
7. Cookies and Analytics
The Service uses cookies necessary to maintain login state, provide security, remember language, and store your cookie choices. Optional analytics, preference, or marketing cookies are used based on your choices and applicable law.
See our Cookie Policy for cookie categories, purposes, duration, and how to change your settings. Disabling cookies in your browser may prevent parts of the Service from working.
8. Service Providers and Disclosure
We may engage cloud, storage, email delivery, authentication, monitoring, analytics, customer-support, payment, and other providers to process information as necessary to operate the Service. We select providers appropriately and use contracts or other measures to supervise their processing.
We do not disclose personal data to a third party except with your consent; as required or permitted by law; where necessary to protect life, safety, or property; in connection with a business succession; or in another circumstance permitted by applicable law.
9. Sharing at Your Direction
When you create a share link, send a file, or use AI Address or another sharing feature, your selected recipient—or a person who knows the access information—may access files and associated information within the permissions you configure.
You are responsible for managing recipients, access scope, passwords, and access information. A recipient's later handling of shared information may be the recipient's responsibility.
10. International Processing
Cloud and other providers we use may store or process information on servers outside Japan. We take measures required by applicable law, such as contractual safeguards and appropriate review of providers.
11. Retention and Deletion
We retain information for as long as necessary to fulfill its purpose, perform our contract, secure the Service, resolve disputes, and comply with law. Files are handled according to the retention period selected by you or displayed in the Service and your deletion actions.
Email-verification and password-reset tokens and sessions have expiration periods. After an account or information is deleted, limited copies may remain temporarily in backups, audit logs, or records that law requires us to retain.
You can delete your account from the settings screen of the Service. If you have questions about the process, please contact us through the channel listed on our Support and Contact page.
Once account closure is processed, your files, messages, and other User Data become inaccessible both to you and to any third party. The underlying data is erased from our storage within 48 hours. However, for files you received from another user that were provided as a reference to the underlying object of the sender's delivery, only your access to them is removed; that object follows the retention period set for that delivery. Likewise, for files you delivered to another user, the underlying object continues to be handled according to the retention period set for that delivery even after your account is closed. Account closure cannot be undone and the data cannot be restored.
We keep records of uploads, downloads, share URLs being issued or revoked, and sign-ins and sign-outs. These records include your member ID and a truncated IP address (for IPv4 the final octet is removed; for IPv6 only the first 48 bits are kept). They do not include file contents, file names, or email addresses. They are kept for 365 days (1,095 days on business plans). You can review these records yourself under “Activity log” in your dashboard.
Separately, to respond to lawful requests from law enforcement and similar authorities, we keep the unmasked IP address and the browser type (user agent) for uploads, downloads, and sign-ins (including failed sign-ins). A record of a failed sign-in may include a digest of the email address that was entered, used only for correlation. These records are never shown in the Service; only our administrators may view them, solely to respond to lawful requests or for other legitimate purposes, and each viewing is itself recorded. They are kept for 365 days.
We retain both kinds of record after account closure. This is for auditing and accountability: deleting the records themselves would make it impossible to explain afterwards what took place.
12. Security
We use reasonable technical and organizational safeguards, including encryption in transit, hashing of passwords and sensitive tokens, access controls, permission management, logging, monitoring, vulnerability response, and provider management.
No internet transmission or storage system can be guaranteed completely secure. You should use a strong password, safeguard credentials and share links, and secure your devices.
13. Your Rights and Requests
Subject to applicable law, you may request notice of purpose, access to retained personal data or records of third-party disclosure, correction, addition, deletion, restriction or cessation of use, erasure, or cessation of third-party disclosure. We will verify your identity and respond as required by law.
Contact us below for procedures and required documents. We do not charge a fee for these requests.
14. Your Choice to Provide Information
Providing information is voluntary, but if you do not provide information required for the Service, you may be unable to register, authenticate, use file operations, receive support, or use other features.
15. Minors
A minor must obtain consent from a parent or legal guardian before using the Service. We may ask for confirmation of that consent where appropriate.
16. Changes to This Policy
We may update this Policy to reflect changes in law, the Service, or our processing. We will provide notice of material changes through the Service or another appropriate method. An updated Policy applies from the effective date shown when it is published.
17. Contact
Logic Factory Co., Ltd. — Personal Information Protection Manager (Head of Web Business Division)
Logic Factory Building, 2-8-8 Yutenji, Meguro-ku, Tokyo 153-0052, Japan
For privacy inquiries, complaints, and rights requests, please use the contact channel listed on our Support and Contact page.
