Privacy Policy / プライバシーポリシー
本プライバシーポリシーは、新義豊株式会社(以下「当社」)が提供する「SGH Voice」アプリケーション(以下「本アプリ」)における個人情報の取扱いについて説明します。
最終更新日:2026年8月24日(モバイル版とダウンロード登録のプライバシー表示を更新)
本アプリは、マイクを使用して音声を録音します。この録音データは、音声認識(Speech-to-Text)処理のためにのみ使用されます。
ユーザーが入力した API キー(OpenAI / Anthropic / Groq / OpenRouter / ElevenLabs)は、端末内の保護領域に保存されます。iOS版はKeychain、Android版はEncryptedSharedPreferencesを使用します。macOS v2.4.0以降ではKeychainへの移行を進めており、それ以前のmacOS版では ~/.voice-input/config.json にファイルパーミッション600で保管されます。これらのキーが当社のサーバーに送信されることはありません。
カスタム辞書、候補頻度および短い修正ルールの保存先は端末内です。音声認識精度を高めるため、iOS版ではプリセット語彙、ユーザーが追加した語彙および選択中のシーンに関するプロンプトを、録音音声とともに選択されたSTTプロバイダー(OpenAIまたはGroq)へ送信します。Android版でも、プリセット語彙、ユーザーが追加した語彙および選択中のシーンに関するプロンプトを、録音音声とともに選択されたSTTプロバイダーへ送信します。短い修正ルールと候補頻度は送信せず、端末上で処理します。Android版はパスワード欄で音声入力と学習を無効にし、パーソナライズ禁止欄では学習だけを無効にします。Android版では、初回のクラウド処理前にこれらの送信内容をアプリ内で説明し、版管理された同意を取得します。
macOS版では、各回の音声認識結果と最終出力テキストを ~/.voice-input/history.json に保存し、Dashboardで参照・編集・削除できます。iOS版は発話履歴ファイルを作成せず、現在の結果を画面上に一時表示します。Android v2.7.2も完全な発話履歴ファイルを作成せず、個人化に必要な候補頻度と短い修正ルールのみを端末内に保持します。いずれも当社のサーバーには送信されません。
macOS版のスタイルプロファイル再生成は、直近最大100件を端末内で集計し、文章の長さ・句読点・言語混在等の特徴だけを保存します。本文を外部AIへ送信したり、プロファイルに原文を転載したりしません。端末内の診断レポートは内容プレビューを保存せずメタデータのみを記録します。自動トリアージレポートには、ユーザーが編集した短い修正候補が含まれる場合があります。
Android または macOS 版をダウンロードする際、お名前またはニックネーム、メールアドレス、対象プラットフォーム、バージョン、表示言語および登録日時を収集します。これらはダウンロード状況の把握、重要な更新・セキュリティ情報等の必要なご連絡、お問い合わせ対応のために利用し、Google Firebase(Cloud Firestore)に保存します。
用途別に、ユーザーが選択した以下の第三者プロバイダーにデータを送信します:
ダウンロード登録情報の保管には Google Firebase(Cloud Firestore)を利用します。各AIプロバイダーに送信したデータの保存期間と削除方法は、ユーザー自身のプロバイダー契約、アカウント設定および各社のプライバシーポリシーに従います。当社はユーザーのBYOKアカウント内にあるプロバイダー側のデータを直接削除できません。それ以外の第三者への情報提供は行いません。
最新条件:OpenAI Data Controls / Groq Your Data / Anthropic API and Data Retention
連携対象は、各社の契約条件、プライバシーポリシーおよび適用法に基づき、本ポリシーと同等以上の保護を提供するプロバイダーに限定します。ユーザー固有の法人契約やアカウント設定により保護条件が異なる場合、ユーザーは送信前に当該条件を確認し、必要な保護を満たさないプロバイダーを選択しないでください。
本アプリは macOS / iOS / Android 各プラットフォームのマイク権限(NSMicrophoneUsageDescription / android.permission.RECORD_AUDIO)を使用します。この権限は、ユーザーがホットキー押下または録音ボタンを操作した時の音声録音にのみ使用されます。バックグラウンドでの録音は一切行いません。
本アプリは任意機能として「声紋検証」を提供します。有効化すると、ユーザー本人の声から抽出した MFCC 特徴量(80次元の数値ベクトル)が端末内(~/.voice-input/voiceprint.npy)にのみ保存されます。当該データは個人情報保護法上の「要配慮個人情報」に該当する生体識別符号として取り扱い、外部に送信することは一切ありません。
v2.4.0 以降、声紋登録には明示的な同意(オプトイン)が必須となっており、同意なき自動登録は行いません。Dashboard からいつでも削除できます。
後処理 LLM に現在の発話を送信する際、文体や用語の一貫性を保つため、ユーザーの過去発話のうち直近最大3件(音声認識結果と最終結果のペア)を文脈として併せて送信できる機能を提供しています。
v2.4.0 から初期設定では無効(送信件数 0 件)となっており、Dashboard で明示的に有効化した場合のみ動作します。利用時は、過去の発話内容も LLM プロバイダーに送信される点にご留意ください。
医療モード(medical / medical_consultation)を有効にした場合、生成テキストには診療内容・症状・処方等の医療情報が含まれる可能性があります。これらは要配慮個人情報に該当します。
SGH Voice iOS版は、利用者と送信先AIプロバイダーとの間に医療情報処理に必要な契約(BAA / DPA等)が存在することを確認しません。適切な契約と組織内ルールがない限り、特定の患者を識別可能な情報を入力しないでください。ローカルLLM(Ollama)は対応するデスクトップ版でのみ選択できます。
iOS版は音声バックアップ機能を提供せず、録音ファイルを一時領域から削除します。対応するデスクトップ版でユーザーがDashboardから「音声バックアップ先」を明示的に指定した場合のみ、WAVファイルが当該ディレクトリに保管されます。保管された音声の管理責任はユーザーに帰属します。当社のサーバーには送信されません。
~/.voice-input/events.jsonl に、認識成否、レイテンシ、フォアグラウンドアプリの bundle id 等のメタデータのみを記録します。発話内容や音声波形は記録しません。最大 50MB で自動ローテートし、当社のサーバーには送信されません。
フォアグラウンドアプリ識別を無効化したい場合は、Dashboard 設定の「App awareness」をオフにしてください(v2.4.0 から初期設定はオフ)。
選択された API プロバイダーが米国等の日本国外で運用されている場合、当該プロバイダーの契約条件に基づき個人情報が国外移転されます。プロバイダー別の所在国は次の通りです:
本アプリをご利用される際は、当該国の法令に基づく保護水準をご確認ください。
Dashboard 設定 →「すべてのローカルデータを削除」より、以下のローカルデータを一括削除できます:
history.json)events.jsonl)dictionary.json)voiceprint.npy)audio_backup/ 配下の WAV ファイル)stats.json)reports/、auto_triage_report.md)API キーは別途、Dashboard 設定画面より個別に削除できます。
iOS版では、設定画面の「APIキー・辞書・設定を消去」からKeychain内のAPIキー、カスタム辞書および端末内の設定を削除できます。アプリを削除した場合、iOSのアプリ領域にあるデータも削除されます。
ウェブサイトのダウンロード登録情報は、上記利用目的に必要な期間に限って保管し、不要となった情報を定期的に見直します。開示・訂正・削除をご希望の場合は、登録したメールアドレスを明記のうえ、下記窓口までご連絡ください。
AIプロバイダーへ送信済みのデータを削除する場合は、ユーザー自身のプロバイダーアカウントまたは各社の問い合わせ窓口からお手続きください。
プライバシーに関するご質問は、以下までお問い合わせください:
新義豊株式会社(Shingihou Co., Ltd.)
所在地:福岡県福岡市
メール:info@shingihou.com
本隱私權政策說明新義豊株式會社(以下簡稱「本公司」)所提供之「SGH Voice」應用程式(以下簡稱「本應用程式」)如何處理個人資訊。
最後更新:2026 年 8 月 24 日(更新行動版與下載登記的隱私說明)
本應用程式使用麥克風錄製語音。該錄音資料僅用於語音辨識(Speech-to-Text)處理。
使用者輸入的 API 金鑰(OpenAI / Anthropic / Groq / OpenRouter / ElevenLabs)儲存於裝置內保護區域。iOS 版使用 Keychain,Android 版使用 EncryptedSharedPreferences;macOS v2.4.0 起逐步遷移至 Keychain,更早的 macOS 版本則以檔案權限 600 儲存於 ~/.voice-input/config.json。這些金鑰不會被傳送至本公司的伺服器。
自訂詞庫、候選頻率及短修正規則儲存在裝置本機。為提高語音辨識正確率,iOS 版會將預載詞彙、使用者新增詞彙及所選場景提示,與錄音一起傳送至使用者選擇的 STT 服務商(OpenAI 或 Groq)。Android 版也會將預載詞彙、使用者新增詞彙及所選場景提示,與錄音一起傳送至所選 STT 服務商。短修正規則與候選頻率不會上傳,而是在裝置上處理。Android 版會在密碼欄位停用語音與學習,在禁止個人化欄位只停用學習。Android 版會在首次雲端處理前於 App 內說明上述傳送內容,並取得版本化同意。
macOS 版會將每次語音辨識結果與最終輸出文字儲存於 ~/.voice-input/history.json,可從 Dashboard 檢視、編輯、刪除。iOS 版不建立發話歷史檔案,只在目前畫面暫時顯示結果。Android v2.7.2 也不建立完整發話歷史檔案,只在裝置內保存個人化所需的候選頻率與短修正規則。上述資料皆不會傳送至本公司伺服器。
macOS 版重新生成風格 Profile 時,只會在裝置本機彙整最近最多 100 筆紀錄,並保存句長、標點及語言混用等整體特徵;不會將原文傳送給外部 AI,也不會在 Profile 內重現原文。本機健康報告不保存逐字稿預覽,只記錄後設資料;自動分類報告可能包含使用者已編輯的短修正候選。
下載 Android 或 macOS 版本時,本公司會蒐集姓名或暱稱、Email、下載平台、版本、顯示語言及登記時間。資料用於掌握下載狀況、必要的版本或安全通知及回覆詢問,並儲存於 Google Firebase(Cloud Firestore)。
依用途別,使用者所選之以下第三方服務商會接收對應資料:
下載登記資料使用 Google Firebase(Cloud Firestore)保存。送往 AI 服務商的資料,其保存期間與刪除方式依使用者本人的服務商契約、帳號設定及各公司隱私權政策辦理;本公司無法直接刪除使用者 BYOK 帳號內的服務商端資料。除此之外,本公司不會向其他第三方提供資訊。
最新條件:OpenAI Data Controls / Groq Your Data / Anthropic API and Data Retention
本服務僅整合依其契約條款、隱私權政策及適用法律提供與本政策相同或更高資料保護的服務商。若使用者本人的法人契約或帳號設定導致保護條件不同,使用者應在傳送前確認相關條件,且不得選擇未達必要保護水準的服務商。
本應用程式使用 macOS / iOS / Android 各平台之麥克風權限(NSMicrophoneUsageDescription / android.permission.RECORD_AUDIO)。此權限僅在使用者按下熱鍵或錄音按鈕時使用,不會進行任何背景錄音。
本應用程式提供可選之「聲紋驗證」功能。啟用後,從使用者本人聲音抽取的 MFCC 特徵(80 維數值向量)僅儲存於裝置內(~/.voice-input/voiceprint.npy)。該資料屬個人資料保護法上之「特種個人資料 / 生物特徵識別」,本公司不會以任何方式對外傳送。
v2.4.0 起,聲紋註冊必須經過明示同意(opt-in),不會自動註冊。可隨時於 Dashboard 刪除。
在傳送目前發話至後處理 LLM 時,為保持文體與用詞一致性,本應用程式提供將近期最多 3 筆過往發話(語音辨識結果與最終結果配對)作為脈絡一併傳送的功能。
v2.4.0 起預設為關閉(傳送 0 筆),僅在 Dashboard 明示啟用時才會運作。啟用時請留意,過往發話內容亦會傳送至 LLM 服務商。
啟用醫療模式(medical / medical_consultation)時,生成文字可能包含診療內容、症狀、處方等醫療資訊。此屬特種個人資料。
SGH Voice iOS 版不會確認使用者與所選 AI 服務商之間是否具備醫療資訊處理所需的契約(例如 BAA / DPA)。若沒有適用契約與組織內規範,請勿輸入足以識別特定患者的資訊。本機 LLM(Ollama)僅可在支援的桌面版選用。
iOS 版不提供音訊備份功能,錄音檔會從暫存目錄刪除。僅在支援的桌面版中,使用者於 Dashboard 明確指定「音訊備份位置」時,WAV 檔案才會保留於該目錄。所保存音訊的管理責任由使用者承擔。不會傳送至本公司伺服器。
於 ~/.voice-input/events.jsonl 僅記錄辨識成功/失敗、延遲、前景應用之 bundle id 等後設資料。不會記錄發話內容或音訊波形。最大 50MB 自動 rotate,不會傳送至本公司伺服器。
若欲關閉前景應用識別,可於 Dashboard 設定中將「App awareness」關閉(v2.4.0 起預設關閉)。
所選 API 服務商若於日本國外運作(如美國),則個人資料將依該服務商契約條款進行跨境傳輸。各服務商所在地如下:
使用本服務時,請確認所在國法令對應之保護水準。
於 Dashboard 設定 →「刪除所有本機資料」可一次刪除以下本機資料:
history.json)events.jsonl)dictionary.json)voiceprint.npy)audio_backup/ 內之 WAV 檔)stats.json)reports/、auto_triage_report.md)API 金鑰可從 Dashboard 設定頁面個別刪除。
iOS 版可從設定畫面的「清除 API 金鑰、詞庫與偏好設定」刪除 Keychain 內的 API 金鑰、自訂詞庫與裝置內設定;刪除 App 時,iOS App 儲存區中的資料亦會移除。
網站下載登記資料只在上述使用目的所需期間保存,並定期檢視不再需要的資料。如欲查詢、更正或刪除,請於來信中註明登記時使用的 Email,並聯絡下方窗口。
如需刪除已傳送至 AI 服務商的資料,請由使用者本人的服務商帳號或各公司聯絡窗口辦理。
如有隱私權相關問題,請聯繫:
新義豊株式會社(Shingihou Co., Ltd.)
地址:日本福岡縣福岡市
Email:info@shingihou.com
This Privacy Policy describes how Shingihou Co., Ltd. ("we", "us") handles personal information in the "SGH Voice" application ("the App").
Last Updated: August 24, 2026 (mobile and download-registration privacy disclosure update)
The App uses the microphone to record audio. This recording data is used solely for speech-to-text processing.
API keys entered by the user (OpenAI / Anthropic / Groq / OpenRouter / ElevenLabs) are stored in a protected location on the device. iOS uses Keychain and Android uses EncryptedSharedPreferences. Starting with v2.4.0, macOS gradually migrates to Keychain; earlier macOS versions store keys in ~/.voice-input/config.json with file permissions 600. These keys are never transmitted to our servers.
Custom dictionaries, candidate frequency, and short correction rules are stored on the device. To improve speech-recognition accuracy, the iOS version sends built-in vocabulary, user-added vocabulary, and the selected scene prompt to the selected STT provider (OpenAI or Groq) together with the recording. The Android version also sends built-in vocabulary, user-added vocabulary, and the selected scene prompt to the selected STT provider with the recording. Short correction rules and candidate frequency are processed on-device and are not sent. Android disables voice and learning in password fields, and disables learning only in no-personalization fields. Before the first cloud request, Android shows these data categories in the app and records versioned consent.
On macOS, each speech-recognition result and final output text is stored locally in ~/.voice-input/history.json and can be viewed, edited, and deleted from the Dashboard. The iOS version does not create an utterance-history file and displays the current result only in memory. Android v2.7.2 also does not create a complete dictation-history file; it stores only candidate frequency and short correction rules needed for personalization. None of these platforms send this local data to our servers.
On macOS, style-profile regeneration aggregates at most 100 recent entries locally and stores only broad traits such as sentence length, punctuation, and language mixing. It does not send source text to an external AI or reproduce source text in the profile. Local health reports store metadata without transcript previews. The local auto-triage report may contain short correction candidates from entries the user edited.
When you download the Android or macOS release, we collect your name or nickname, email address, target platform, version, display language, and registration time. We use this information to understand download activity, provide necessary release or security notices, and respond to inquiries. The records are stored in Google Firebase (Cloud Firestore).
Depending on the configured purpose, the following third-party providers receive data:
Download registration records are stored using Google Firebase (Cloud Firestore). Retention and deletion of data sent to an AI provider are governed by the user's own provider agreement, account settings, and that provider's privacy policy. We cannot directly delete provider-side data held under a user's BYOK account. We do not share the information with other third parties.
Current terms: OpenAI Data Controls / Groq Your Data / Anthropic API and Data Retention
We integrate only providers that, under their terms, privacy policies, and applicable law, provide the same or greater protection described in this policy. If a user's organization agreement or account settings result in different protections, the user must verify those terms before sending data and must not select a provider that does not meet the required level of protection.
The App uses each platform's microphone permission (NSMicrophoneUsageDescription on macOS/iOS, android.permission.RECORD_AUDIO on Android). This permission is used only when the user presses the hotkey or recording button. No background recording is performed.
The App provides an optional "voiceprint verification" feature. When enabled, MFCC features extracted from the user's voice (an 80-dimension numerical vector) are stored only on the device (~/.voice-input/voiceprint.npy). This data qualifies as biometric data uniquely identifying a natural person under GDPR Art. 9(1), and as "sensitive personal information / 要配慮個人情報" under APPI. It is never transmitted externally.
Starting with v2.4.0, voiceprint enrollment requires explicit consent (opt-in); no automatic enrollment occurs. It can be deleted at any time from the Dashboard.
To preserve stylistic and terminological consistency, the App can attach up to 3 prior dictation pairs (speech-recognition result + final output) as context when sending the current utterance to the post-processing LLM.
Starting with v2.4.0, this feature is disabled by default (0 entries sent). It only operates when explicitly enabled in the Dashboard. When enabled, please note that prior dictation content is also sent to the LLM provider.
When the medical mode (medical / medical_consultation) is enabled, generated text may contain clinical content, symptoms, prescriptions, and similar medical information — which qualifies as sensitive personal information.
SGH Voice for iOS does not verify whether the user has an agreement with the selected AI provider that is appropriate for processing medical information (such as a BAA or DPA). Unless an applicable agreement and organizational policy are in place, do not enter information that can identify a specific patient. Local LLM processing with Ollama is available only in supported desktop versions.
The iOS version does not provide audio backup and deletes recording files from its temporary directory. Only in supported desktop versions, when the user explicitly selects an audio backup directory in the Dashboard, are WAV files retained there. The user is responsible for managing retained audio. No audio is transmitted to our servers.
The App writes metadata only (recognition success/failure, latency, foreground application bundle id, etc.) to ~/.voice-input/events.jsonl. No utterance content or audio waveform is logged. The file auto-rotates at 50MB and is never transmitted to our servers.
To disable foreground-app identification, switch off "App awareness" in the Dashboard (disabled by default starting v2.4.0).
When the selected API provider operates outside Japan (e.g., the United States), personal data is subject to cross-border transfer under that provider's contractual terms. Provider locations:
Please review the data-protection standards applicable in those jurisdictions when using this App.
Via Dashboard Settings → "Delete all local data", you can delete the following local data in one action:
history.json)events.jsonl)dictionary.json)voiceprint.npy)audio_backup/)stats.json)reports/, auto_triage_report.md)API keys can be deleted individually from the Dashboard Settings page.
On iOS, “Clear API Keys, Dictionary, and Preferences” in Settings removes API keys from Keychain and deletes the custom dictionary and on-device preferences. Deleting the app also removes data from the iOS app container.
Website download registration data is retained only as long as needed for the purposes stated above, and records that are no longer needed are reviewed periodically. To access, correct, or delete this data, contact us below and include the email address used for registration.
To delete data already sent to an AI provider, use your provider account or contact that provider directly.
For privacy-related inquiries, please contact:
Shingihou Co., Ltd.
Location: Fukuoka City, Fukuoka, Japan
Email: info@shingihou.com